360 likes | 463 Views
The Strategic Importance of IT for SAIs. Paul Mantelaers. Vilnius, June 16th, 2005. 1 Short introduction: 1.a Background of the seminar 1.b The IT Self Assessment project. 3 Seminar programme. Agenda. 2 Strategic importance of IT for SAIs. Agenda. 1 Short introduction:
E N D
The Strategic Importance of IT for SAIs Paul Mantelaers Vilnius, June 16th, 2005
1 Short introduction: • 1.a Background of the seminar • 1.b The IT Self Assessment project • 3 Seminar programme Agenda • 2 Strategic importance of IT for SAIs Strategic Importance of IT for SAI's
Agenda • 1 Short introduction: • 1.a Background of the seminar Strategic Importance of IT for SAI's
IT WG Moscow, May 2002 launched Training Strategy Rome, Oct, 2003 The Hague, Oct, 2002 1st meeting Copenhagen, Nov, 2003 IT training 8th meeting IT Self Assessment IT seminar Portugal, 2004 Bern, March 2004 2nd meeting Lisbon, Oct, 2004 Seminars ‘SAIs in control of IT’ Vilnius, June 2005 1.a Background of the seminar Training Committee Strategic Importance of IT for SAI's
Agenda • 1 Short introduction: • 1.a Background of the seminar • 1.b The IT Self Assessment project • The initiation • The activities • The product Strategic Importance of IT for SAI's
1.b The IT Self Assessment Project Initiation (The Hague, Oct. 2002): • Objective: • develop a self assessment tool for all SAIs; • CobiT-based. • Enable to measure the maturity of IT control of our own offices; action list. • Pilot countries. • Project organisation (6 countries, diversity). Strategic Importance of IT for SAI's
1.b The IT Self Assessment Project Why a self assessment? • It allows « proximity ». Evaluation is carried out by the people: • who know the subject • who are interested in solving the problems • It is confidential. The organization is in control of the results and their distribution. • External moderation encourages the people to speak freely. Strategic Importance of IT for SAI's
1.b The IT Self Assessment Project Why Control Objectives for Information and related Technology? • CobiT is a well accepted standard • CobiT can be downloaded free from www.isaca.org • CobiT is also available in French, German and Spanish • but our group wanted to be sure that CobiT is the best choice ... Strategic Importance of IT for SAI's
1.b The IT Self Assessment Project Activities (Jan. 2003 – Aug. 2003) • Various papers (concepts, requirements, etc.) • Studies of other tools: • ISO 9001 • European Foundation for Quality Management (EFQM) Excellence Model • ITIL / Process Maturity Self-Assessment & Action Plan • CMM Capability Maturity Model • Common Assessment Framework (CAF):result of the cooperation among EU Ministers responsible for Public Administration Strategic Importance of IT for SAI's
1.b The IT Self Assessment Project • Contact with specialists: • Philips (The Netherlands), • Swisslife (Switzerland), • Prof. W. van Grembergen (University of Antwerp) • Keep it simple! E-mail; two meetings Version 1 (August 2003); pilots: October 2003 – November 2003 Version 2 (February 2004); pilot: March 2004) ITWG (Bern) Strategic Importance of IT for SAI's
1.bThe IT Self Assessment Project The product (Bern, March 2004): • A tested CobiT-based methodology for IT Self Assessment, in terms of: • A way of working: steps • A way of modelling: graphs/tables • A way of supporting: spreadsheets • A way of presenting: slide-show • A way of preparing; instructions • Ready to be used by (and to be improved based on experiences of) IT WG members and other SAIs Strategic Importance of IT for SAI's
Two dimensions of the analysis: • Business processes (users) • Most important processes in achieving goals; IT-support? • IT-processes (IT-staff) • Most important? Maturity levels IT-1 IT-M Business process 1 Business process N 1.bThe IT Self Assessment Project Key: alignment between business and IT Communicate! Strategic Importance of IT for SAI's
1 Short introduction: • 1.a Background of the seminar • 1.b The IT Self Assessment project Agenda • 2 Strategic importance of IT for SAIs Strategic Importance of IT for SAI's
2 Strategic Importance of IT Strategic Importance of IT for SAI's
2 Strategic Importance of IT Strategic Importance of IT for SAI's
2 Strategic Importance of IT for SAIs • Group discussion • Two questions: • 1: Why is(n’t) IT important for SAIs? • 2: If yes: what does that mean? • Time • Group formation Strategic Importance of IT for SAI's
Plenary discussion • Topic 1: Why is(n’t) IT important for SAIs? Strategic Importance of IT for SAI's
1 IT 2 Why is(n’t) IT important for SAIs? Decision makers Auditor (SAI) 1 Auditee: 2 Central Government+ Strategic Importance of IT for SAI's
Audit programme Policy framework selection planning preparation Audit proposal implementation Report of findings Four-way consultation Report design reporting Draft report Publication text Clearance procedure Presentation publication Why is(n’t) IT important for SAIs? • 1. SAI: • Mission, objectives • Primary processes: • Audit process • Knowledge exchange • Secondary processes: • Personnel • Finance • IT Strategic Importance of IT for SAI's
Why is(n’t) IT important for SAIs? 1. SAI: High Banking SAI Information intensity of the product Cement industry Oil refinery Low Low High Information intensity of the process Strategic Importance of IT for SAI's
Benefits of IT….. and risks • Increased productivity • Improved quality of products (user satisfaction) • Improved decision-making ability • Enhanced communication (internal and external) • Enhanced goodwill of employees • Risks: huge investments, expectations vs. reality, vulnerability, system shutdowns, poor integration, manage service providers, not enough training…. Strategic Importance of IT for SAI's
1 IT 2 Why is(n’t) IT important for SAIs? Decision makers Auditor (SAI) 1 Auditee: 2 Central Government+ Strategic Importance of IT for SAI's
G2G: G2C: Why is(n’t) IT important for SAIs? 2. AUDITEE: Strategic Importance of IT for SAI's
Why is(n’t) IT important for SAIs? 2. AUDITEE: • Has a very high information intensity (process and product) • Any audit involves information (processing) and will increasingly involve IT(-auditing) • Benefits of IT…. and risks • IT-control maturity? Strategic Importance of IT for SAI's
Why is(n’t) IT important for SAIs? CONCLUSION: IT is important for SAIs because: • Their primary and secondary processes can benefit from the application of IT. IT contributes to organisational performance. Risks need to be managed. • In their auditing work, SAIs will be increasingly faced with IT. Strategic Importance of IT for SAI's
Plenary discussion • Question 2: If IT is important for SAI’s: what should that bring about? Strategic Importance of IT for SAI's
SAI AUDITEE IT If yes: what does that mean? Point of departure: Strategic Importance of IT for SAI's
SAI AUDITEE IT If yes: what does that mean? • SAIs should organize their: • IS-function • IS-function: the totality of activities (and accompanying resources) that needs to be performed to provide for IS Strategic Importance of IT for SAI's
SAI AUDITEE IT If yes: what does that mean? • SAI’s should organize their: • IS-function • IS-audit-function • IS(-audit)-function: the totality of activities (and accompanying resources) that needs to be performed to provide for IS(-audits) Strategic Importance of IT for SAI's
IS-function: Structure Structure Structure Skills Systems Skills Skills Systems Systems Strategy Strategy Strategy Staff Staff Style Style Shared values Shared values Staff Style Shared values IS-audit-function: If yes: what does that mean? Organize: SAI: Strategic Importance of IT for SAI's
Organize the IS-function • 4 domains: • Planning and organization • Acquisition and implementation • Delivery and support • Monitoring • Guideline to (re-)determine the level of control over IT Strategic Importance of IT for SAI's
Organisational units: staff - line • Organisation (SAI): externalise: Organize the IS Audit function Three design decisions: • Positions: pure (specialise)– mixed (integrate)? Strategic Importance of IT for SAI's
Summary • IT is important for SAIs due to: • the information intensity of their own processes and products • the importance of IT for their auditees • That is why SAIs need to: • organize their IS-function; performing an IT Self-Assessment • organize their IS-audit-function Strategic Importance of IT for SAI's
1 Short introduction: • 1.a Background of the seminar • 1.b The IT Self Assessment project • 3 Seminar programme Agenda • 2 Strategic importance of IT for SAIs Strategic Importance of IT for SAI's
IS function IS-audit function Massimo Magnini Dainius Jakimavicius Rune Johannessen IT Self Assessment IS Auditing Day 2: Børre Lagesen Erik Guldentops Day 1: CobiT CobiT 3 Seminar programme Importance of IT for SAIs Strategic Importance of IT for SAI's
Summary • IT Self Assessment is necessary! Strategic Importance of IT for SAI's