Effectively manage internal controls and comply with financial control regulations
all right here we go thank you all for joining us um I am very happy to be joined by Rahul rosdan today who is one of our Premier solution Consultants Rahul would you like to introduce yourself hey hi everyone this is Rahul can you hear me right now yeah yeah good yeah thanks Teresa so here in servicenow I look after the risk and ESU business and today we'll be talking about internal controls predominantly on the financial space and how a framework like socks can help streamline that entire process for you guys so with that uh over to you Teresa wonderful um so we're glad to have everybody here um we've got the Q a button at the very bottom down there we want you to use that we want to make this interactive we want to get your questions answered please feel free to ask those questions um we're also going to be putting in the chat a couple of links to register for additional webinars and the link to the playlist for um to be able to see this webinar on demand and to see other other webinars on demand so I think you've got an amazing slide deck that you're going to go through first Rahul and then do a demo for us correct that's right so are you able to see that absolutely so hello folks uh an honor basically to help you guys here to understand what we have done so far uh in service now on the financial control side of things so as you can see here when we talk about internal controls in a regulated space uh predominantly we are looking at ID operations and not to forget the financial control set as well now we all know that servicenow was driven out of an ID space we have a foothold to understand what kind of it landscape needs to be there to run your change management controls your configuration controls when we talk about operations we look at your operational risk from a regional standpoint how your Regional teams are operating and how those incidents are then aggregated to mature your risk posture however we also feel that Financial control set which are born out of your internal controls which are required for your financial reporting uh wizard is an example is about socks where uh you all would have heard about Enron the collapse which took place a decade before and the basic reason was uh material weakness in their accounting principle of misstatement happening due to uh duplicated voices of examples like not good bookkeeping principles and all of that so what we are looking here is to give you one single view or a page where you can not only look at your ID operation but your financial control set as well and with this we basically connect your first second and third line and give one simple transactional screen to manage and monitor the day and tasks which are happening on the application so it's a struggle for a financial control head to look at the internal controls across their businesses uh when you look at a large Enterprise they are dissected into legal entities functions departments spanning across HR uh businesses uh your tax department your accounting department your share services and then you would want to run a program to make sure all your businesses are abiding to the controls which have been internally created by your financial processes right it's hard to identify the business areas and the control gaps because of the volume of the control set in itself you're talking about for a large oil and gas company around 15 000 controls for a large Bank about 10 to 12 000 controls which are need to be tested year in and split between different quarters so the share volume in itself becomes cumbersome for an organization to process them and manage all of that and that's why a framework is much more required to streamline that process now framework can help your financial directors your head of internal controls to plan how they want to internally align their control set and basically departmentalize each and every process so that by the end of the year they can certify uh that all their controls are compliant and thus move on to the next physical and basically redo the process again so with that what we have identified is that there is a gap in the market in terms of giving you the right framework and thus service now has come up with their Control Management framework which can help build that bridge so in this slide we'll talk about how that control management framework can help you identify your control set operate those controls uh scope those controls monitor them and then report it on a regular basis on your right hand side of the screen you can see the initial phase of the control maturity model in which you would want to Define your control set now these control sets are born out of your processes and your financial processes typically are ordered to purchase record uh invoicing and all of those processes are basically created as part of a process narrative program where you do your mapping of your processes and out of those processes you internally create a control register which then can be split into icfrs which are basically of socks required controls and then within that you can have your key controls and non-key controls those key controls then can be further split into manual automated automated with ICF are automated without icfr and thus your whole control register is Bond once you identify your control set you then run an assessment exercise which is more of a control owner confirmation in that view you are engaging your first line to actually do the control owner certification of the controls which are not have which don't require heavy resource utilization to do an operating Effectiveness or a design Effectiveness test these are majorly the controls which are light in nature and you typically have evidences stored in them in your central Repository military to just confirm that the control is effective as is it is so we are talking about those smaller set of controls which don't need a rigorous testing so once that controls owner confirmation is done and let's say 40 of your controls have been attested you then scope to identify how would you want to phase out the rest 60 percent of control which need to be tested every quarter or every year these can be your access management controls your segregation of Duty controls your itgc controls in which you want to identify the applications if you have placed the right access on them or not so once you Scope your controls you then would run your key financial application system program where you would want to identify the key financial applications where the data is stored in terms of how that has managed from a previous year uh Constitution to the next fiscal year in the sense if there is a application which has changed you were using Cooper to manage your uh accounting entries you have moved from Cooper to backline so in that case with that movement uh is your processes being changed over from One Financial system to another and if so what is the Sox assessment impact on that movement so it's very important to understand your key financial application landscape and once you do that then it becomes easy for you to design your operating and design Effectiveness template around those financial applications and that's where you would engage your testing team to do your rigorous oede testing they will be required to collect samples on those financial applications and then those samples would help them Drive the result for their control test now the journey doesn't stop there once your testing team has done it uh what we do in service now is monitor that control using our indicator templates now these indicator templates are run on the system on a frequency basis which basically means that this is a continuous process a continuous control monitoring process which not only can be run on the data in housed in the platform in the sense you have your ID ticketing system you have your common management database which is cmdb sitting in service now we can run the programs on that and give you the result back we can also run the system the control maturity program on external systems like Cooper Blackline saps of the world where you have your accounting data sitting and we can run the program or our indicators there and fetch the result back into our system and that's here we are talking about the continuous control monitoring on the external data uh we also talk about not replacing a system like sap but koi existing with them when you talk about control analytics which basically means that we are planning to move the data from sap uh into servicenow and then you can run your analytics program on servicenow data itself to give you that intelligence back whether the control is on the regular basis uh attested or not the classic example of this can be a change limit now there is a limit identified at Kuba system that whenever a gifting policy is set up and if there is a breach in a gifting policy we want to understand that who has authorized that approval and if the authority person is part of my Active Directory Group then only I would be able to authorize that change otherwise I need to alert the control owner that somebody is trying to mess with that system so with this example we can actually rely on Koopa to give us that data inside servicenow and run that indicator which can give us that Insight if somebody has actually changed and if has changed whether those change logs can tell us if the changed Authority is part of the active directory and if it is part of the active directory and part of the approval group then process that change otherwise alert the control owner so that real-time intelligence is only possible when you have a scripted indicator available on service now which runs not only on servicenow platform but also on an external system like Koopa so once the control monitoring is done the last part in a process becomes your Assurance you as part of the Assurance you would want to run the certification exercise which can be in US 3.24.4 302 precisely happens in a once in a fiscal year 404 typically happens on a quarterly basis on your automated control so we do certifications on the entity basis where the entity is nothing but the organizations or the entities where the VPS or the directors or the entity can come to the system and attach their control saying all the controls are effective and if not there is a plan of action to make those controls who are not effective be effective as we roll over to the next fiscal so you can manage your certification results into our system by capturing that control set which are tied back to your organization so from there on you can actually report all of that using our out of the box to voting capabilities and then send out that report to your internal and external Auditors for their referencing and evidence collection so Rahul it strikes me that you know this is a lot of stuff and the primary value that we're offering is the have a giving people a system a product to allow them to to manage this workflow and step them through the different stages so they don't have to know what to do next is that do you agree or or I think you're you were right on on the framework so all of this is a step-by-step Playbook which is now available on servicenow and a Persona based application where uh stocks administrator would be able to do all the six operations versus a control performer would be able to do couple a tester would be able to do a couple of things and that way we are giving them whole Playbook experience by providing a role-based access security as well yeah best practices and guidance I think that that is a a huge value here for the servicenow product so with that let's zero in from a larger scope of a life cycle uh framework to a continuous monitoring framework uh I think I have already touched on this subject how you can Define your control and then do the self-assessment scoping uh and then operate your controls from a design and operating Effectiveness into different phases of testing period and then monitor the control using our indicator templates and then at the end assure your controls by conducting certification exercises or reporting your control compliance posture so with this whole uh setup you can make sure that it's no longer a resource intensive exercise where you have to allocate resources to do your control testing rather we are moving to a much more automated state of control maturity where the system takes care or does the heavy lifting for you and I think also you know to that to the point there is the systems are going to heavy lifting for you but you're also getting more near real-time information so you know you're not waiting for hours or days or weeks to be able to figure out something went wrong the the one of the true value of this um beyond the you know automation is the fact that you get you get more visibility more quickly into changes in your environment absolutely now we tend to forget like what controls are right like why why do we have controls we have controls to make sure that our facilities are up and running uh we have controls to make sure that the vendors and the services provide the vendors are of higher quality so uh so service now looks at that entity model and not just focuses on one single departmentalized control set rather the whole ecosystem of your organization and then gives you that automation capability to then focus on one such business area and then automate it so that you can actually crawl walk and run when you are tackling your business needs these can be gdpr requirements running on certain processes born out of Europe or these these can be sock compliance of your us entity that way you can pick what you need comply with it on our irm system and then move to the next stage so here uh we explain how our control a life cycle or the integrated risk management flow Works uh this diagram is basically to capture that levels of controls starting from the authority document or regulations which you feed into our system from an I.T point of view these can be your sock nists uh ISO Authority documents or regulations which can be externally bought in by content providers like UC EF which we integrate with and once that regulatory bodies are set you can then break down those regulation into citations or standards create your own internal policy sets identify your strategic control objectives and then system distributes that controls objectives into control instance this is by identifying your entity set now these entities can be think of entities as a basket and that basket has group of toys right a group of uh puzzle is one box set a group of uh small toys is one basket set in that case that group can be your uh critical business applications your crown jewels your departments your entities your locations now this these different sets can then merge with your control objectives and create one is too many control instances so I can look at one itgc control which is gonna check on my key financial account system to see if there is an unauthorized access and I'm looking at my crown jewels to protect them so these ground Jewels can be my strategic applications like Oracle sap sales force and I want to make sure that there is no unauthorized access on these systems or it can be your data center providers like Azure or AWS so what the system does is it takes that one control objective which is unauthorized access and then automatically creates that five control instances and once those control instances are created it applies the control indicator which you want to run at a strategic level these indicators can be checking uh the people who have access to the system and if they have access to the system and comparing that with the actual logs and then reflecting back into the control if you don't see any unauthorized access you keep the control as compliant and as soon as you see an unauthorized access happening on the system uh with a unique sys ID you then alert the control owner so that they can take the necessary action to remediate that issue so all of that is only possible if you have that control hierarchy same goes for the risk if you have your risk Frameworks statements or themes identified at your strategic level or at your board level and then you set the tone at the top and then distribute that risk statement into actual risk instances to your Regional teams for them to then plan on how they want to mitigate that risk identify their inherent risks apply the control environment and then get the residual risk out of it based on which then they can drive the risk response tasks which can be to mitigate that or avoid if the risk appetite threshold is below the uh if there is residual risk is below then the uh risk appetite we can actually avoid that risk and not spend enough resources to mitigate it so that's the integrated risk management portfolio and within one single product you can solve your Enterprise risk needs your operational risk needs your stocks needs your compliance needs and your cyber needs and that's where this one single uh platform can be possible and Powerful to not only solve one single use case but apply all the use cases which are there for first line second and third line we talked about how we uh we can accelerate with the service now offering now this is just a picture to call out what all we have in our irm and risk which is basically about his portfolio which is constituted of irm uh business continuity operational resilience uh vendor risk and environmental social governance product in itself so you on the top line you can see all the solutions which are born out of the now platform uh and at the bottom layer you can see the single database on top of a multi-instance setup where we have domain separation enabled to secure the content if it is required for your gdpr requirements and then you can have that domain separation possible on your platform to segregate the data the now platform then gives you the capability to orchestrate your workflow uh automate it from an Evidence collection point of view we have document intelligence available now to scan your documents for sockman software reporting and then you can actually alert your vendor system that their sockman report has been outdated and they need to give you the latest sock 1 report and this whole process is now automated in our system by process flow designers which can actually read those sock one reports which are available on our evidence register and then alert the team members accordingly so that is our portfolio of risk which is now ever expanding uh in the next release you might be able to see corporate compliance as one of our use cases where we will be talking about how we can solve your ethics and conflict of interest use cases so with that I think uh it's a good point for me to jump to the application and actually present how the Frameworks looks like in the real time that sounds fantastic yeah this is there's a lot of um as part of the different accelerators or content packs we have built in a lot of capabilities like indicator templates and um and uh test plan templates and things like that oh look at that you're at your socks administrator screen I see it it looks great thanks Jason so now uh a good call out that this socks management screen is basically something which you can configure yourself right this is the landing page of a fox administrator within your organization uh if they're not happy with the dashboard view what they see here they could easily go configure their workspace drag and drop the reports or dashboards which they want to see as soon as they jump on the application you can clearly see the socks timeline uh we all are aware that for a socks time frame which typically starts from April to March for some of our customers here in Europe wizard is a customer here in uh back in us might have the cycle from January till December so however the cycle is you can easily configure the concept Remains the Same as we had explained in the framework that you initially do your scoping bit and then you do your control owner confirmation and then you phase out your testing as you go forward so this view explains that timeline you can expand that timeline to actually see what are the different engagements you are running within that period you can focus on that phase of testing and see how that phase of testing is going on you can look at all the engagements when we talk about engagements we are looking at those phased testing where the auditor or the stocks administrator is responsible to manage that program you can track all your stocks tasks which have gone out to your control owners to your control performers to your testing team via one single screen you can capture all the issues which have come out of that control Assurance program and out of those issues which all have escalated to a deficiency that are caused by a material weakness and all of this is only possible if you have planned your whole socks program for each of your groups or locations as we have already discussed uh so you can actually cluster multiple organizations and do one socks planning for them or you can split your socks planning and focus it on uh region by region in this case we are taking an example in which we are focusing on per business area and trying to comply all the financial controls against that business area so in the landing page you saw the dashboard view icon as a group manager or a Sox Administration administrator can also see all my tasks and because I manage my team I can also look at the group tasks in this sense how my control owners are performing how my regional heads or socks leads are performing and can actually manage their tasks reassign them delegate them and all of those capabilities are available what else I can see on The View as a socks admin is the tasks as I said you can manage your task and your team's task you can look at the issues overview how the issues are panning up when you move on from one phase to the year end phase and if you want to allocate certain issues to a particular group assign them identify those issues what are the actions taken place to remediate those issues you can take those constructive decisions via this dashboard so this gives you that real-time Insight which Teresa was talking about you can also identify the trend analysis quarter by quarter how your issues are raised which period can you see the peak of issues where you can then allocate right resources whenever you are planning your socks exercise now coming to the list report and this is where the Playbook experience comes back to which we were talking about initially that how servicenow can give you that step-by-step guide in the sense for you to make your process easier what you see on the screen are the list of entities uh as I said these entities can be classified into different groups in this case these entities are departments you can group your entities as ground Jewels applications for your I.T General control testing you can group your entities as locations if you want to run your gdpr assurance and so on for our socks process flow we have classified our entities into departments in this case you can see all the Departments uh you can go inside each department and can actually see what kind of entities or control set that department has which the which of those controls are being run how many have been attested how many are in draft stage not tested and so on uh and there are a bunch of information available Associated to that particular entity you can see how many issues are running inside that entity how many policy exceptions that entity has identified and so on moving back using this breadcrumb to our list View the second important thing is to have your own process registered uh you can see here that internally uh this particular socks admin has identified their process registers they have captured their fixed assets which are born out of record to report they have identified this particular process is mapped to a particular policy within their Authority document chain you can see the policy history how that process has changed over a period of time to which all entities this process applies to and how many control objectives you want to be adhered as part of this policy so you can actually run the whole exercise like that uh through a process uh information once your process map is done then you identify using that process map what are the controls which are going to be tagged to your process uh again this is the internal control Set uh which you would want to curate for your socks Assurance program now this internal control view can be different if you are looking from a socks exercise or your own internal control register let's take an example here the one which we have for dividends so what we are seeing here is uh all dividends received from joint ventures uh Associates and Investments are reconciled to approved joint venture dividend proposal which basically means is uh in nutshell that we see there are companies who are in brink of uh bankruptcy but they are still paying out dividends to their shareholders which doesn't make sense and as part of uh Financial control guidelines the accounting principle if you are not in a healthy State you can actually stop sending out uh dividends to your shareholders it's a pain but that's a necessity we have seen companies doing that and then there is a huge penalty Associated or assigned to them because of those wrong uh uh actions the reason they are wrong is because that action then stipulates in the market that you are still performing good and your stock prices are always escalated which is not actually right and you are not in the right place so that's a serious uh issue and then to subside that issue you have a control in place to identify if uh the financial author group within your business is not able to sustain dividends then those dividends should not go out now for that control I want to run that control against all my entities uh which are basically doing the bookkeeping against in my organization so what I did here is I looked at the control objective I looked at my entity type which is that cluster of those entities or organizations in this that cluster or that basket has nine entities what my system does is it automatically creates that control set as we said it creates those control instances and then assigns those control instances to each of those entities and then you can look at your control and then run your attestation on those controls that's where you would basically confirm to the control whether that control is actually working or not from a control owner point of view going back to our list View and see this is all the control sets which the system would Auto create as control instance is tagged to a particular entity you can also see the financial account registers which you are maintaining uh these Financial account registers are then tagged back to your control uh need be a material weakness identified as part of control testing that material weakness can always go back to the financial control to identify if there is a profit loss uh rational behind that when I say that I'm talking about a material weakness which is basically corresponding to a potential loss in your financial account General edges and then you have a compensating control applied to then mitigate that Financial loss so this financial account registered then helps you manage all your books the next framework uh step in this journey is to then actually execute your self-assessment and this is where I can as admin as engage my control uh leads or control owners to perform this step so as an admin I have a view of all the controls as you can see here there are 312 controls in my system and I want to run a controller confirmation on that I can as an admin filter out a particular control group so I can say I want to focus on Turkey apply that control set I can see there are 14 controls which are associated to Turkey check them and send out for attestations and then there would be attestations which will then go out to all those control owners automatically so as an admin this whole action becomes very easy in three clicks I was able to send out bulk control attestations to all my first line control owners now from this view offers socks admin let's look at the view of a control owner who would then perform this control attestation or in this case a control owner confirmation so I have here Jacob Williams who is a control owner and representing the first line now from a first line point of view uh the control owner would have their own view as I said uh all of this is based on a role-based Access Control uh Jacob here can only see the controls which he or she is responsible to they can only see their control assessments which are open they can only see the issues which they have raised as part of their control test and then the controls which they have Exempted and are no longer required to test for this fiscal year in financial controls group not every control needs to be tested every year there are certain automated controls or it General controls which needs to be only tested once in three years once in two years so you can exempt control on a year-to-year basis now once I have identified my control assessment I can then take up that control assessment and do that actual control owner confirmation so here the control owner would come I would view the screen uh they will get an email notification with the form link they don't have to do the steps which I just showed you via their report but they can directly go through the email click on the link and do the control Runner confirmation uh they they would see this assessment form uh they will say uh are you aware of an instance is where the control was not operating effectively that is was there a deficiency I will say yes then provide the details for the deficiency if no then the conditional question goes out and then I just certify that control to be compliant now this whole template which you see on the screen can be configured by you uh in our system we have various config configured templates in the sense my question can change to have is the control effective from effective to it can change to is are are you compliant with the control yes or no and then I can also pop up an Evidence uh a question where I have to push an Evidence as a file to certify that the control is effective what I'm trying to say here is based on your business needs the questionnaires can be templatized on a servicenow platform so in this case I submit the control and my attestation is done you can see the real time change on the state has completed and if I go back to my control set the control becomes uh effective now that is how your control self assessment exercise takes place we also saw how you can bulk attest to them we saw the view of a control owner and a testing a control by looking there at their own set of controls and they're testing them one by one so you have both the capabilities to bulk a test and attest as a one single control now once we move from control owner confirmation stage where we have self-declared the control to be effective I then move to the key financial application scoping and as this exercise entails uh to understand where or my financial data is sitting because we are looking at a financial controller exercise in this particular demo I'll be focusing on the applications where my financial data is sitting so first I would have to scope uh as part of my exercise what all Financial applications I am using so I kick start a scoping exercise where I see the key financial applications based out of my process so here you can see that the system use the cmdb as a reference and then identified the processes which are there in my process register and then looked at the controls which are related to the process and then brought that process control mapping and as part of that mapping I can actually see what are the identified systems where my data is sitting in this case it is sitting in sap Hana or plasma and so on so I would run a scoping exercise right now to understand if the applications which have been identified are correctly addressed or there is a change in the application so if there's a change in the application I will say yes the application has changed and I will confirm what is the new application uh is there any robotic process automation running on that application if not I give the rational behind it now why all of this is required the answer is to identify if there is a change in the application and if there is a change in the application I might have to run a socks assessment against that application to make sure that IT addresses all the basic requirement from an IIT General controls perspective uh whether the data rest is encrypted data motion is encrypted how I am making sure that the segregation of Duties are enabled and so on that's why the scoping exercise becomes very crucial you can always add new processes as your process grows or your application landscape grows you can always edit by double clicking this field and editing it in this case I have opened the view from an admin which I have ex secured the right for but from a ID administrator point of view you would be able to edit the field and then enable the system so let's go back once the scoping is done what the system does is it identifies the differential of the application which has been bought new from the previous fiscal to the current fiscal and then identify and run an assessment program against that new application so in this case cache up is a new system on which I want to then run an assessment exercise I see that this is a new application I identify whether there are automated key controls which are going to be run in this application otherwise if it is a manual control I will choose what kind of manual controls are going to run if there are system generated reports then I'll capture what are the reports which are going to take place what else I will do is I have a workflow Associated where I will run the workflow to make sure that the socks assessment is approved by my reviewers and directors as a group so here you are basically calling out the group not just a one single person and any person in that group can pick up the task and approve it I can also capture the ID details and identify how many instances are running on this particular financial application uh what kind of vendor is supporting that whether sockmon soccer report is available or not and if there are interfaces Associated what kind of interfaces I'm using to do my integration and all of this is important because once you have this then you can only truly identify what are the risks Associated to these new applications which you have scoped in and that's where you then identify the risk associated to that and then do or perform a risk assessment against those financial applications which you have scoped in so once your financial assessment is done for your financial new Financial applications or change management of those financial applications you move on to do your stock scoping which typically starts from April you do your phase one phase two mid-year and year-end stock scoping now as part of stock scoping what we do is we bucket your socks into different plans and these plans can run for a dedicated region uh in this case let's say Finance is my business group and I want to run a stocks Assurance against that business group so what I do is I look at my business group I look at the engagements which are being run and I execute those engagements within the application uh another example is this particular planning for OTC group so in this OTC group I have tagged four engagements to it now the system has the intelligence to Auto create these engagements for you as part of the flow designer in this sense you can have phase one phase two mid-year or year-end data sets created and what does that mean truly is that you have now tried to engage your testing team to conduct your phase one testing so if I click on phase one what I see here is uh what are the business unit within My OTC uh which are the regions where the otcs are placed uh within my organization and I want to make sure that there is no unauthorized access on those otcs so I look at Istanbul as one of the hubs where I want to run this exercise what my system does is it automatically pulls the risks and controls Associated to that region and then Auto creates that control set which I would have to run on that particular OTC so all of this is automated the system also creates the test plans based on the test templates I have identified for doing an operating Effectiveness and a design Effectiveness and then I can choose from these test plans which all I would want to migrate and then create an audit task to actually test the control sets for others where I have already the evidences I can then just skip those control test and focus on the differential and that's the power of the system where you can reduce the resource intensive effort which you typically do I see there's a question here that's right let's see um oh the actually the question is about having a recording of the session we absolutely are going to have a recording of the session I will put that in the um chat here very shortly thanks Teresa so yeah coming back to the audit task uh so you can see here the audit tasks now are gone out to the actual testing team who are going to then run uh these sample based testing which we talked about on uh your operating and design Effectiveness and that's how now we will engage the third persona in our use case we are a control performer or a control test lead would actually test the control uh from their testing list now this is George who is the control test Lead Supervisor and he manages all the control tests which are coming to their testing team so here you can see a test which has gone out to them which is to review the change management policy or review the configuration log document to see if for that particular application somebody is trying to have an unauthorized access so you can actually go inside that control test which is in this case an audit task bond out of your phased testing and they can go ahead and uh confirmed that this uh is a working all progress state or you have completed the test as part of that control performance uh within that particular page you also get to see uh what kind of design test you are doing uh what is the expectation set by the test template uh what kind of assessment procedure needs to be run and you qualify whether the control is effective or not effective uh if the design is effective then you decide whether the control is operating effective or not again if if the control is effective and the uh so if the design is not effective and the control is effective and you try to publish it the system automatically throws an error saying your if you're operating effectively design is not effective you cannot be operating effectively so those kind of validations are in place to protect your testing cycle uh when your testing teams are actually looking at both design and operating Behavior you can also capture the work notes you can capture additional documents settings in this sense you can tag that particular test to a particular domain whether it's an itgc test or a socks you know test or a four not test so you can tag it so that your reporting becomes easier uh what else you can do is you can capture your indicator results along with the test you have done you can raise observations as part of your oede testing these observation can then naturally translate into issues or deficiencies in our issue register or deficiency register so the process is simple you get a brand new observation form and that observation form over a period of time can be identified as a Control operating failure or design failure and then can once you charge that with your triaging group the result of that observation can be that it is confirmed as an existing issue or then escalated to a deficiency which needs to be fixed before the year end Financial of year-end test so this was how the testing team would engage and do the actual test again they will be notified via email and then be able to perform the test uh so we saw how the scoping is done by us coping you can do phase one phase two phase three phase four scoping uh all this is this was an example to talk about four phases if your organization has a different phase you can always configure it to have that additional phase applied and then scope in your controls based on the rules you create in this system once your scoping is done your testing team does the testing your Assurance is done you can then move on to see how you can continuously monitor that control now this is where uh the powerful Automation in service now comes in handywhere once your physical test is done by your testing team how intelligent is the system to then do the automated test in this case we are taking example of Koopa the Koopa approval chain log and you can see here this chain log script is actually looking at the approval limit and if the approval limit is beyond certain value then the system alerts the control owner by sending out an email to them that there is a bridge of an approval limit and the person who has authorized it is not part of your Active Directory Group how do you do that so we have as Teresa said we have indicator templates to support that business case so in this case the template is looking at uh the value which is coming from Cooper tables so we have uh tables created within our system which are integrated with Koopa using integration Hub the integration Hub is a rest API based system which can engage with any external system uh we have pre-built 200 spokes uh where the code is already written to get the data out from that external system push it into a servicenow table and then run your indicators on that in this case you can see there is an approval change log table which has both limit change and the change history who has changed it the system then understands the data consumes it matches the data with the active directory to look at the Risk Managers group and if that risk manager user is qualified then set the value as pass otherwise set the value has failed which basically means if the data which is coming out from that external system is not correct then the execution which would happen on a frequency in this case daily would fail and then these control owner would be alerted by an email so this was an example of a scripted indicator we have manual indicators which can run on any particular table you can specify the supporting data by looking at the table you can look at the data fields and you can set a Target on your system and if the target is not achieved this the got indicator would automatically fail so you have various methods to run continuous control Assurance on servicenow platform and I think it's worth mentioning we know this is an example for Koopa right but if you've got another application that you need to pull data in from we use sap a lot for for financial reporting you know we could integrate with other applications it doesn't have to be just this one we that's the again the power of the platform is it's very flexible in that instance thanks there's I think that was a good point talking about other systems so Koopa is something which uh we have scope spokes for similar to sap similar to backline where we can automatically integrate that and you can see here the visualization power now as soon as the limit got breached uh there are visualizations in place to identify those kind of approval limit changes you can see the number of approval changes which have opened have happened over a period of time the system then captures from the chain logs what are the different changes what are the document IDs and this becomes the unique reference ID between servicenow and Cooper table and you can actually monitor the users who have actually changed that and Via our kpis which we have driven out on Koopa you can actually capture all the states and issues which have borne out of the Cooper because of the continuous changes on their change limit and the system then automatically creating incident in our itsm system system to then manage that through an I.T ticketing flow you can also see the incident tracking which I was just talking about how the system then creates that incidence and then there was a peak during the onboarding of that application then because of on production there were a lot of multiple changes by the HR team on the limit that's why there was a peak and now it has subsidized over the last few quarters uh you can see the change incidents which have captured as part of Koopa you can see the different indicators then showing you that real-time Insight on the incident responses which have been taken place on this uh incidents coming out of Cooper as well so this real time uh detail then gives you the information to do your next step uh as I said you can then capture your issues coming out of our system uh these issues then can have their own actions uh Associated you can have slas against those actions uh you have your own workflow which comes with that issue program you can see an issue getting created analyzed responded reviewed and then closed once your all your actions are mitigated the issue is tagged back to a control test against which the issue was identified or the issue can be an ad hoc issue in the system as well uh not all issues are deficiencies but certainly all deficiencies are issues these deficiencies are the ones which are LED because of material weakness and impacting your financial accounts so you can actually see all your deficiency list here and then manage the actions associated with that deficiency as well uh one of the processes when you hit your ear and would be change management exercise where some of the issues actions might be to change the control description or change the control attributes so we have a change management process in which you can go ahead and identify your control objectives or your controls which you would want to change you can execute the change on the system in this sense you can change the description uh control attributes and then run the approval exercise to manage that change management so all of that is tracked via the system through a change management process and then once you do that you get the true rackum which is your risk uh and control Matrix you get the entire breakdown of all your risks from processes to the controls to the control objectives and the control performance captured in this report you can always edit the columns bring back additional attributes which you want from your data set back to your Rackham and then also play around with this report to export into different formats uh group the results into different groups groupings of entities control owner set and so on you also get a control log to manage the changes what you have done between different phases so you can see and pick the control creation date testing date and see the new and old value if there are attributes being changed within the controls you can focus on certain attribute values at looking at okay I want to just focus on in scope for socks are there controls which have been scoped in for socks over the last one year you can then use this support to focus on that particular control set as well so this Frameworks then helps helps you conceptualize how your socks flow should work and at the end your certification is something which your uh uh Enterprise head would run in this case uh this is the certification template uh it which would a director or a VP of a particular region or a location or an organization within your tree structure or group would then execute on they provide their statement here submit and then the attestation gets completed and you can see the attestation being done here for the entity called group called customer success so that way your attestations are done and your data is then rolled out into your group financial reporting and as part of this reporting you can then filter out your different entities I can look at my result of Istanbul Turkey and focus on that result by geography how my control are being effective how many controls are in scope for socks how many controls are effective with terms of compliance audit status what is the different engagements what are the statuses of those engagements how many are still in scope status how many phase testings are completed and then which phase of testing is pending I can look at my modified set of controls as well from a Sox Assurance point of view there is an easy view here on change logs as well you can actually manage what kind of changes I have taken place how many controls were Exempted if I'm a socks administrator I want to focus on the Exempted controls as well to understand if those control needs to be tested in the next fiscal how many controls are non-compliant and then a summary of all of all your control set in terms of how many were used for self-assessment Harmony went through a detailed attestation exercise where OE and E was identified and then your scope for the entire socks audit program so this visualization is one visualization as I said our platform gives you a lot many visualization if I have to go back to my dashboard view these are the multiple applications which the system gives you from an irm perspective but we are talking about socks so I might be using socks compliance or compliance overview or order scoping for my visualization needs and this then brings back uh to our uh framework that as servicenow platform we not only support your it operations but also your financial controls and using our uh work spaces you can actually get a framework created out of your system which will then take you from step one to step Z or step a to step Z and perform that whole Assurance exercise so I'll take a pause uh if there are any questions I'm happy to answer them that was a fantastic demo um amazing people there's no questions that in the question um list right now that people you know please you know those of you listening if you have questions please add a question you know we're happy to take them we want to make sure that that we get them answered for you but that was so complete and I actually have never seen it from from A to Z like that before so it really it really showed the flow and how we do help guide people through the different stages um building and back best practices so we we're about at time I don't see any questions I want to thank you so much Rahul for that amazing presentation an incredible demo thank you all for joining us um this recording will be up on the playlist I have the link in the chat in about 48 hours and there's a lot of other um webinars we have coming up that are just like this so please feel free to uh to sign up for those that link is also in the chat um I still don't see any questions so I'm going to go ahead and close it out and again thank you thank you everyone for for being here and again thank you Rahul thanks everyone thanks Cheers Cheers
https://www.youtube.com/watch?v=nY312Ia7Ghs