logo

NJP

The importance of using your 10-K as part of your risk program

Import · Jul 28, 2023 · video

thank you everybody for joining us this is a very very pertinent topic and I'm very happy to be joined by the iron Authority team um Karina Clover and hartaj Condola um they're going to be talking about the importance of using your 10K as part of your risk program before we we get into the meat of this I wanted to um let the the speakers introduce themselves so Katrina can you tell us a little bit about yourself uh Karina yes I'm the Chief Executive Officer of irm authority I've been in I.T since April 1989 and in the governance space for over 20 years now and uh very very excited to be part of irm authority is of the top of this year nice nice heartage yeah sure thing Teresa well I was going to say good morning but good morning good evening afternoon depending on where depending on where you are I'm heartache Candela Chief technology officer so I've been on the search now platform since about Fuji released around that time so about seven eight years now and yeah I head up our technology technology Consulting team so yeah happy to be here and get in the demo after the presentation yeah absolutely you know that's the nice thing about this presentation you're going to give you a little bit of insight into what they're going to be talking about and how you can actually find the information to be able to put into your GRC program but then we're going to show you what it actually looks like so stick around for that um but before we jump into it there's a couple of housekeeping tips that I would like to point out um you are automatically placed in mute but we want to make this interactive if you've got questions if you've got comments please use the Q a panel we want to make sure we get those answered the session will be recorded it will be up on our YouTube playlist it will be on our community we've got links there for you and when the session ends there may be a survey that you're prompted for if you have time we appreciate it if you could take the survey we're not going to take the full hour we have here um but you know we appreciate your time and we appreciate you being here so without further Ado then I would like to turn it over to Karina to kick us off thanks thank you and um I am going to take myself off camera because I get very very animated sewn for people with one monitor might be a little bit more difficult so we're going to record this for uh just to have the uh content uh tell the story about what it means to all right so we're going to be going through really so we've separated this content in kind of three sections so the content the presentation that I'm going to be going through the demo that hartaj is going to be going through we've left some time for Q a um we're all here to talk about 10ks of course right the things that are disclosed to the Securities Exchange Commission in order to get to that point though we kind of have to take a little bit of a helicopter ride right we've got to go a little bit high level and we have to take a look at some of the high level components that are really um kind of framing our environment where we can capture those 10ks so this stack here of the kind of the basic pieces of the platform is really what we're mostly going to be talking about here in the presentation the scoping of the these pieces and then some of the records that are created that's going to be talked about during the demo but we want to focus in on this 10K piece that lives right in here and it talks to the pieces right in here right so we do want to see how how kind of the demo reflects all of this and how easy it is to really show everything in the demo but right now we're going to be really talking about this left piece so we're going to walk through that risk framework putting in the 10ks and looking at some of those external influences that we have to build that risk framework and that risk program inside your company we're going to walk through the authority documents again external to your company we're going to go out looking for those and we're going to bring them into our platform right so basically on the left hand side we have a lot of influences outside of our company that we're going to bring in and then the right hand side is really our uh our platform already the way that it's working so let's go ahead and take a look at really what the content is of this left column a little bit deeper so when we're going to come off of our helicopter right here in a minute um so our Authority document is what influences our company these are always external always uh could they consist of two pieces right the first piece is regulation what do you have to do you have to do it are you going to get in a lot of trouble this is HIPAA sarbanes-oxley glba if you're Financial gdpr um if you know all of the the other consumer privacy things globally we have some uh some some things for some folks from around the world also there's Frameworks uh best practices methodologies whatever your company wants to call them these are these are things you're not going to get in trouble for if you don't do right your nists your cosos your eye tools so so that combination of Regulation and framework those live in your Authority documents and there's sections underneath every Authority document those are called citations and the second piece are your own published documents inside your company they're very influenced by those Authority documents right but they are really your operating principles for your company they tell folks what to do what's expected of them we're going to go into a little bit more of that as we get further into this presentation but um really they align up to those author Authority documents but that main control objective is the thing that's measurable the thing that you want to collect evidence on to hand over to your Auditors and say look we're following our own published documents we're following our policies and procedures and standards look at the evidence we've gathered for it and the the auditor is going to like hug you and take you to lunch and and be very happy with the evidence you've collected against your own published documents your risk framework is kind of a combination of internal and external right so externally we're actually gonna the next section we're gonna go into is we're going to look at a lot of the external influences that we have out there and the environment fantastic recommendations on how to establish our own risk management program in our company uh internally remember the prior slide we're going to connect up to that control objective because what we want to do is we want to measure when that control objective fails do we care a lot or do we really not care at all and that is actually a consideration that we can make as we're establishing all of this and and sometimes you know sometimes we care a lot and sometimes we don't and it's really up to us to decide when we make those published documents so we're gonna now next go into a few industry recognized sources uh you're probably going to recognize some of them and I'm going to go through them just as recommendations that you can kind of think about to to consider as you're establishing your risk management program um basically yes so at the top button here is we usually go into uh starting with authority documents but here we're going to go ahead and start with risk framework and that's what we're going to look at there's a lot to look at so let's start with nist uh nist has a framework called 837. it's called the risk management framework it's based on CSF controls so nist is a National Institute of Standards and Technology you know more than 20 years around very ingrained in the industry um I I kind of want to point to if people know anything about this CSF right it's a collection of controls and they basically talk about some of the objectives that you want to establish in your environment you can take these guidances and you actually can build those internal published documents against that guidance this framework includes a process and basically when you're when your outcome matches that nist CSF control objective you've met the task now I want to bring little bit attention to this word task here and and the word control that I've used to describe the outcome the right hand side of the screen is a screenshot from within nist publication um nomenclature is really really important with servicenow because uh you know servicenow for those of you in the environment uses the words task uses the words controls he uses or his control objective as does a lot of the industry Frameworks out there and a lot of the nomenclature that's used regularly in a lot of the Frameworks we're going to be talking about so when I say the word tasks in the column here in the dark blue this is the task is defined by nist to show that particular task they've defined as successful and the control that they've defined on the right hand side outcome is the control that they've defined in their CSF framework that you need to meet to have that task that they've defined to be successful so it's just um kind of we're not in the servicenow space right now as we're looking at this so another source for uh for a risk definition is is yet another nist guidance now 853a is called a controls based risk framework and really it's a collection of controls and it's very very long um again controls the word that nist uses right so for us in service now these would be citations so when we consider 853 a is our Authority document the controls they provide is our citation so we went to the system right and really um this focuses on this Center section here called an assessment and it gives you guidance on how do you prepare for that assessment conduct the assessment and then what do you do after that assessment and again these controls very useful for if you want to establish publish your internal documents right all of that guidance information for your company to operate all of those functional requirements this is all going to be basically this framework gives you guidance on how to do that and and at the same time again that Nirvana moment is when you have your control objective right so those those things that we're doing in our policies meeting and engaging our risk value for when something is not done how much do we care that you know that is kind of uh how we measure that risk long term so a next one uh many of you have probably seen this this is a really great graph um this is published by the world economic Forum back in January they published this once a year it's actually a 98-page report and I'm I'm gonna say that everything that's referenced in this deck is available in one of the closing slides of this deck and I saw Teresa already went ahead and and published this deck out to everyone um very very useful I and on the right hand side I just went ahead and published kind of like the largest you know five circles here useful from a perspective of if you're establishing that risk management program in your company you want to look also not only at the size of the risk but how the risks correlate to each other very useful to maybe prompt some thoughts and say okay well you know let me let me kind of walk this line and see what else maybe I'm not thinking of as I establish that program and how can I maybe think about some of the other connecting risk areas that would make me have a better stronger posture against risk in general um Teresa did you want to kind of chime in on this one a little bit I I this is one of my favorite slides I think um I think that a lot of people don't realize how inner related risks are and how by you know one risk can actually influence another or lead to another and I think this visual I'm a very visual person this very you know visual really reinforces that fact that you know your wrists are not in isolation so um I just I love this I love this graph we did get a question that came in about the nist um slides you just had up though just really quick is it used in addition to rev5 can you just tell us that so I'm gonna go back this is actually rev five so 853a is actually used mostly by um kind of in the federal space very very heavily um and so um so 853 this particular slide is from is is the Rev 5 version of 853 perfect perfect thank you sure all right and so that's the world economic Forum all right and so the next one is isaka so one of my all-time favorite um kind of you know beings or or entities or I don't know what you know they're they're actually the information systems audit and Control Association they've actually developed cobit and cobit is just a fantastic framework to use in reference they have a really great um you know here's where you are today a short term and a longer term goal framework that's very all-encompassing uh came to the U.S 1967 uh they they also um they have just a lot of guidance a lot of certification so just a really great kind of uh resource point so they've kind of taken some common risks that we see out there right and they overlaid it with I.T so so so basically when you when you look at it you say okay how do I run I.T uh how do I deliver value to my business for my tea how do I secure I.T how do I execute projects in it and so when you kind of look at just the business of I.T um the risks that are out there how do they overlay into I.T and so the the only other thing is um a pretty good and well-encompassing framework on the on the risk piece so um so so so another recommended framework here to consider uh because they cut they have they have uh environmental risk in here they kind of consider everything um so isaka has partnered with IIA which is the internal um International internal Auditors and they are going to have a GRC Summit in Vegas uh next month uh so we're going to be there uh we're also going to be in black hat and that information is available also in the reference slide down below so look at the end of the day a lot of sources ISO is a favorite one right there's over 24 000 certifications that ISO offers uh 31 000 is just a just one for risk management you know sometimes companies need certs to go get other customers you know they they're they're going to go get a customer and the other customer says the potential customer says well we won't work with you until you go get assert from ISO so you know 9001 is a qms or a 27 000 ranges for it very very recognized globally uh and so this is a just a staple and a standard for uh for for for providing you guidance on establishing that risk management program you know Koso so back when I was working with Koso 20 years ago it kind of looked like a bit of a Rubik's Cube and back in 2017 they made it into this beautiful Arrow they decided to kind of put a heightened focus on strategy and performance um acosa is very heavily used in the financial industry uh they are also referenced by icfr um and that's actually I aicpa guidance we're going to actually be talking that about that as one of our Authority documents later on in this presentation uh but but also great points to consider here right um the CIS used kind of all over all over different Industries right so um so basically kind of to kind of summarize this whole available influences out there that you can glean from as far as establishing your risk program right uh select something that really as close as possible aligns with your company but expect that you're going to take that guidance and you're going to kind of make it uh your own uh as you as you actually customize it to your own um your own environment and your own company and maturity and size and Industry Teresa did you have something else on this um yeah I mean I think one of the things that we have in service now is sometimes it's difficult to get all the citations or controls in and you know just wanted to let people know they could look at the accelerators the cyber security controls accelerator technology controls accelerator um socks content pack um CIS of several different accelerators that we have even got a cloud accelerator coming out um so that's there to help you get these citations get your controls created the um we do have one more question real quick to finish up this this section on Frameworks can you use multiple Frameworks together Frameworks together absolutely and and you should look at Several of them to make sure you haven't missed anything so that the program you put together in your company Suits You right so so consider a lot of them Yuka you don't have to adopt every single recommendation from every every single line from every single framework inside your company but you should read through them to see what did I miss so that the program that you build for your company is as thorough as possible and that it applies to you yeah absolutely and so you can adopt nist 839 and nist 853 you would just need to make sure that that you didn't duplicate any of the controls so right so so that's a very important point with risk Frameworks and with other uh Frameworks uh that are other authority documents not risk specific ones like we have here right it's very very important to remember that they're written to be vague nebulous generic applicable across multiple Industries applicable across multiple companies and sizes of companies it doesn't matter what kind of Technology you have they're written to be vague by Design so the problem is you cannot take those vague guidances adopt them into your company and expect people to execute against them they won't be able to they're written vague they're written vaguely right so you have to actually take them and say okay now I take this guidance and now I put into my own published document so just an example off the top of my head every single Authority document out there is going to say have Change Control okay well one company's change control their cab could meet once a week a different companies could meet twice a week and a different companies could be once a month right so you so you're meeting the objective of have Change Control but your own specific company will have their own detailed documented control objectives that you're going to be able to measure against yeah absolutely you have to make it your own one final quick question about nist um very specifically would you say that you could use missed 839 instead of rev5 or are they do they need to be used together you can use either or you you don't have to use them together you don't have to use these together at all you can just reference them one against the other if you're if you're in the federal space you're probably going to want to lean towards 853 5 you know um if uh the you can you can use I you can use any of the myths really they really take the public already published controls all that nist does is it says here's some controls and make sure and what you need to do with those controls is reflect them in your published policies and then that's what you build your internal measurements against and that's what you collect your internal evidence against perfect thank you now are we going to talk about the 30 documents now no we get to really no we're still in the risk piece and and we get we now it gets even more fun on the risk piece because now we talk about why we really have to do this so take a big sigh everyone because we're going to look at something that the Securities Exchange Commission has told us to do if you're publicly traded um the Securities Exchange Commission has said well you know if you're a publicly traded company you're going to take people's money you have to disclose publicly your financial State and so um you have to file this form called a 10K and that's why we're here right you have to follow this form called a 10K annually or you can do this uh same kind of form quarterly called a 10-q and they were even nice enough to give all of us guidance on like how to do this again these forms are all available at the bottom of this presentation and so what we did was we really only focused on this one section called the risk factor risk factors and um you can you can go to the SEC and you can yourself when you have nothing better to do go and research these all on your own absolutely this is public information and we went ahead and we kind of found this company that we sort of sterilized and we focused only on this one section called the risk factor now before we really get into this I have to say uh we we did sterilize some of this information you're not going to be able to find out what company this was based on these screenshots because we we don't want to point anyone out in specific but what as we were looking through these of course we were thinking to ourselves man you know gosh look at all of these different risks we we just started wondering what can we do inside our company to to kind of alleviate some of these risks right what excuse me what can we do functionally what can we what kind of operations or what kind of controls can we put in place that would make some of these um kind of risks be reduced right um you know you get to something like this down here and you think wow will a third party provider so let's talk for a minute about third-party providers right um how do we strengthen our vendor Management program how do we better vet that trainer that that that Vendor Manager that vendor that we're actually using for our services right maybe we should create a program where we're asking who their critical vendors are right are they passing any of our data to their vendors do you do we know how much of our data they're backing up for us and how long they're keeping it do are we asking those questions are we asking do they have cyber insurance coverage on our stuff I mean if they have our data like who has access to who not only who has access to it but who has privileged access to it how many of those people have privileged access to it I was working with a vendor ones who basically um with a with a questionnaire said I uh we have 27 admins that have administrative access to your data on our side I said why what are you guys doing that you need 27 administrative level people having access to my data what are you guys doing I mean after some negotiations we got it down to six but I mean the fact that you're even asking most people don't even ask right another really big one and and really I encourage everyone to check this is breach notifications right a lot of contracts say that that vendors are required to notify you of a breach within up to six months check it seriously because um when you first arrange that relationship with that vendor uh have it be a 72 hour notification follow gdpr standards right because that's a 72 hour notification upon knowledge so check all of the things because right now a lot of our data is not sitting with us anymore and those I mean Marriott was leaking for two and a half years and lost 500 million passports before anyone even knew that they lost all of this data I mean the leaks are happening all the time so a line like this being disclosed on a 10K right so as I read this I'm thinking okay well let's tighten up that vendor Management program and maybe this risk is going to disappear off this 10K filing Teresa do you have anything to add to that no I mean I think you covered it you know third-party risk is is really critical you know just given the news just recently there's there's various you know penalties reputation damage um associated with it it's it is one of the most important aspects of managing your risk that gets overlooked by a lot of organizations yeah so we kept reading um and we um uh we you know we saw a lot of ESG so really interesting right so a lot of companies are required to establish an ESG program and I can tell from all of the reading that we're really in our infinancy infancy infancy anyway and and just the early stages of ESG programs kind of all the way around um you know over time I'm expecting that these risk statements are going to really elaborate material topics but right now um right now they're very vague and and we're hoping that these kind of ESG programs are become very integrated hopefully of course using servicenow right we we are totally equipped to handle all of that and and do the full integration but um just kind of a call out on ESG pretty pretty interesting just to notice this pattern of everybody's disclosing uh any uh you know their ESG risks and so finally we get to really the the 10K item that we are going to be talking about specifically here in this webinar this company actually really did identify a material weakness in their internal control over financial reporting and and because this is a publicly traded company they are required to abide by sarbanes-oxley and um this is what we're going to be talking about in our actual demo here right so and this is what we're all here for so I'm going to kind of recenter the applicability of our columns here right so we're talking about risk so some of the things we've done so far right so we looked at all of the other Frameworks and definitions out there you know we chose one or some or or combination we looked at the 10ks out there for our company and we we selected uh you know the ones that we care about or maybe all of them we should be tracking all of them really at the end of the day um and then we also have our own control objectives remember they're they're from the block up right they're from the published documents up there but we're gonna actually right now hop over to the authority documents because right now what's fresh in our head is the sarbanes-oxley stuff and then uh we're going to go over into the internally published documents next any questions before we move into the authority documents no we've we've I've been answering a few questions I mean the one point is that you know looking at your 10K you may need to you may not be able to remove certain things so I mean I think it's it's it is important to look to see if you can remove them and you should check to make sure everything is there um but definitely you know the legal department is the place to go for that but no I think the one question just everyone knows ESG is environmental social and governance um that is something that's that's gotten very very hot recently and a lot of organizations especially in the Mia are needing to comply with various regulations it's still and it's somewhat it's somewhat infancy so the regulations are not as um as clear-cut um but it is something that everyone should be watching that should be on your radar absolutely in Europe is uh you know just like they were ahead of the game with gdpr and kind of set the Precedence uh they're also ahead of the game with the SG so um yeah and they're actually making some of the regulations law so all right so let's head over to our Authority documents and of course I think it's no surprise we selected sarbanes-oxley uh right uh the assumptions in using this is uh were publicly traded we have to abide by sarbanes-oxley we filed the 10K which we just saw and inside every single Authority document there are sections right and there are kind of components and those sections are called citations in the servicenow platform so uh the citation that we chose for our example was section 302 we were kind of toggling between 302 and 404. um so we decided on 302 because they do specifically talk about internal controls so um we do want to take all of our citations in our Authority document that combination and again and we want to have that influence our internal published documents and so um we had to pick another one right because uh again vague language right generic vague language for all publicly traded companies right and so we have to make this our own but we need we need that second Authority document right now and so the second Authority document we basically picked was icfr this is um called icfr some people call it I see ofr it's a publication by uh aicpa and again our assumption is that the company we're talking about uses this guideline um this is the document that really references coso remember that Arrow diagram that we saw um the very very heavily leveraged framework mostly for financial organizations because they have to abide by sarbanes-oxley right for their financial reporting so it's kind of like the symbiance so um so we we again Authority documents kind of like the top right sections underneath so the sections underneath are called citations in the sections underneath we selected was this one uh that really discusses entity level controls so kind of again to reiterate citations are associated to control objectives within our own published documents so citations are outside published documents control objectives are our inside documents um what you want to do when you structure these is you want our internal control objectives to kind of Traverse up to citations and you want one control objective to satisfy many citations because then when you continue to Traverse up your Authority documents show completion more and more the more of your citations are complete the more of a complete score your Authority document gets right so any we're actually done with the authority document sections any questions on that no I think this was this is I think you're you're you're rolling right along I think this is really valuable okay so we are done with our external influences we've got sarbanes-oxley and sarbanes-oxley 302 is our citation and then icfr and paragraph 22 as our Citation for that we're on our last section guys our own internally published documents okay so we created a pretend document so I'm going to highlight pieces of this please don't be overwhelmed by the screen I do want to First bring your attention to the word policy and quotes in the header the reason why it's in quotes is because it's the name of the table in servicenow uh what it really is is it's a published document it can be a procedure a standard a template it can be a policy as well a process it is whatever provides guidance to the folks who do the work that's all it is so what you want is the workers who do the work to acknowledge the stuff that's in this published document they need to know what's expected of them you want to do that acknowledgment campaign one of the most beautiful things about servicenow is all of your policy document all of your published documents your policy statements your templates all of those are actually contained inside the platform which is just phenomenal because when when you talk to clients and they say oh well you know our documents are over here in Confluence or some other platform why right because your documents actually contain those measurable pieces that you're actually going to create into the measurable components that you want to collect evidence on pull them into the platform that's what it's there for right so so you're basically saying to the worker okay here's the thing you're testing here's the thing you're acknowledging this is what we're expecting you to do and the the worker goes okay cool I I got it I've signed off so when you go to that worker and you say hey can you provide me evidence for that they go here you go here's the evidence and then when you write these documents you just align them up there to those Authority documents and the citations remember are sarbanes-oxley right are all of our documents that we are our risk Frameworks that we looked at in the first section you're aligning all of that to your published documents and you're just giving your people instructions on how to succeed at their job and what's expected of them when they're when they're being asked to gather evidence everybody wins so on the second page of this really I want to just give some examples on really how to create that control objective so just your basic real simple basic core things that you want to look out for who who does it well how often does it happen what does the output look like and here's where we align the risk remember that very first high level slide right if I don't do this thing how badly do I care so here's some examples of words you can use in your published documents the word trigger I can measure that I know how to define that I know the condition under which a trigger happens a business justification I can have a form I can have a checkpoint I can have a something tangible that I can trace I can collect as evidence put it in that collect it for that auditor to look at so they don't come and Bug my team for it it's already going to be there for the auditor to look at an approval already there for the auditor to look at I'm following my guidelines these are my control objectives we're highlighting a review quarterly so now I know that I have an approval quarterly a quarterly review that I can go put into my into my evidence Gathering folder and there it is for the auditor they won't bug my team and say hey can you go pull those emails for me right so so these are really important kind of words that you can use to establish those control objectives and so again I'm going to say we want to write them to reinforce those Authority documents and so when that Authority document says I have to have different rules to do my financial reconciliation I'm going to put that in here and then I'm going to say here's how I'm going to measure it I'm going to review it and approve it but if something goes wrong what do I do right I mark it as high in the risk registry so now I can actually track it right now I can actually watch it come alive and and put mitigating controls on it before it shows up in my 10K I I can actually try trace it in the system okay I think I've taken more than enough time uh we're done with this piece right here uh we're done with the internal published documents um these are all of the references that I've used in this deck uh we uh and you have a copy of all of this again I'm going to bring us back to this uh kind of where we started write our quick helicopter we're going to come up we're going to look at this whole picture we're done with this section and I'm now going to hand it over to hartaj for the demo all right jump in really quick honestly before you do that because we do have one question okay I'm actually going to weigh in on this first and then I'll let you weigh in on it but the question is do you recommend keeping all of the policies regardless of I.T or others in servicenow policy management because most companies already keep all the policies outside the service now in SharePoint as a gold source so my humble opinion here is most most of the time you do want to keep them in service now even if most companies keep them in SharePoint the the challenge with SharePoint is it's very hard to make sure that you are updating them on a regular basis do you have a approval flow that you go through can you prove that you've actually updated this are people able to collaborate more easily and weigh in on these these different um policy changes that you want to make is everyone aware of it if you keep it in servicenow prod in servicenow policy management you can do all of those things you can set up a schedule so that it automatically needs to be reviewed every year so you're certain that you're keeping in your in your your management system current policies and it gives you a way to collaborate you can use word you can use red marks on your policies and everyone can do this so you're collaborating through the system and there's a record of that um so that's my opinion Karina do you have anything else no I actually I and I actually think the the slide that's on my screen right now is a perfect um perfect actual answer for that very question because the center uh kind of the published documents the center block on the left column if I don't have my control objectives out of my published documents in the platform and there's in some other system I can't do what hartaj is about to show us I can't take those control objectives and measure them Downstream I I I can't get a flag that says something's wrong there it's a it's absolutely impossible to to actually create the full governance risk and compliance program for my company if I have my policies sitting elsewhere because they they're not alive if I pull them into servicenow the pieces inside become alive and now I can actually collect evidence against them and have that evidence be stacked and stored all of those people that you have right now running around and Gathering that evidence for when the Auditors come can can be doing more valuable things when you allow servicenow to do that for you because that's what it's built for because that's the job that I had 20 years ago yeah I I think that's one of the most one of the first things that companies should do is take their policies and put them in servicenow so they can consolidate them in one place so anyway why don't we switch over to heartage so we can see this in action yeah yeah sounds good all right let me go ahead and can everyone see my screen here the service now logged in that's great okay so I am logged in right now with myself for Taj candola I have the role of a risk manager so this is our risk overview dashboard so before we get started here um with Karina we looked at different risk Frameworks um and then we looked specifically around a 10K and some of the risk statements that you know companies would file on their 10K and then we looked at the authority documents related to those and then we looked at our internal documents um related to those risk factors so we're going to go through the same process here within the tool to kind of see where that lives and what where it is in the application and I think the key thing here is just how everything is connected together so the first thing here this is um this is an overview of all of our risks we've got this heat map it's Dynamic I can scroll over drill down on specific risks I can see my more likely risks up here the less likely and then on the right hand side I can see by category Financial operational I.T as you can see it's for for this company it's pretty much all Financial so I'll go ahead and click on financial here and it's gonna go directly to the risk registry so in this risk registry we have a lot of different risks and we'll drill down on the first one right here so I'm going to go ahead and click on that risk so this risk right here I'll I'll kind of read it out it says we have identified material weaknesses in our internal controls over financial reporting so um for those of you that may have seen her you might have missed it on when we were highlighting the 10K and those risk statements this was one of those uh risk statements on the 10K filing so the importance here is what you file what you followed the SEC what you file those risk statements can also be put within a tool and you can actually monitor those risks as well so for this specific risk let's talk about kind of the different sections what are we tracking how are we using this kind of boots on the ground so um the first one is ownership an owner needs to be identified for every risk here it's myself I'm the risk owner the second one is an assessment so there are different types of Assessments um you can configure and set up in service now for this specific one at 10K Financial assessment was conducted if I scroll down on the screen I can see who took this assessment I can get that information and we also have the responses to the assessment so let's go ahead and click on one of those responses and take a look um I'm not going to go through all the questions here but it's essentially when it comes to your risk uh risk appetite one of the ways you determine that is with the qualitative and quantitative aspects so this is the qualitative you know are the roles involved in fulfilling this requirement clearly articulated yes or no um can there be any violations of segregation of Duties in this case no so it goes on and this is based on your responses here that's factored in the risk uh risk score and How likely this risk is the second part is the scoring so this is the financial size so there's the quantitative side as well where we track and calculate scores based on the financial aspect of risks the next one is our response so anytime you have a risk uh it's in service now but this is also industry standard there's four things you can do with that risk you can accept that risk and if we chose to accept it it would require you to say a justification of why we're choosing to accept this um you can avoid the risk and if you avoid the risk you would be required to enter the avoidant steps here you can transfer the risk to you know an insurance a vendor and you can capture their information if that's the response we choose then in this example we chose to mitigate the risk so when you mitigate it you set up a plan here says we plan to set up controls to monitor our material weaknesses related to financial reporting so this risk we're going to mitigate we're going to mitigate what's happening so this covers the risk management side let's take a step and look at the let's take a step back and look at the authority documents and walk through those as well so in there's another application simply put it's called Authority documents we have a few here Karina mentioned socks icfr let's go ahead and drill down on icfr here and underneath icfr it's got information about this Authority document and down here it's got citations so one of the citations it has is entry level controls I'll go ahead and click on this one here and we can see the verbiage um in this Authority document and we can see what relates to our controls here one of the things I'll highlight inside this it says right here controls over the period ending Financial reports and processes so that's going to become relevant when we look at our internal documents we want to make sure we cover these as well so now I'll go ahead and go to our policies table as you can see there are many policies in here I'll pick just the first one Financial reconciliation so let's take a look at this policy and see what we've been captured internally so on this policy um it says I'll just kind of read a little bit of it um because it is of vital importance to our company that the financial statements our company follows with the FCC fairly represent the financial conditions of our company here and this published document will will support and establish the maintenance of effective internal control because in this case just as a reminder we filed with the SCC and our 10K that we've identified material weaknesses in all of our internal controls so if I scroll down here we have control objectives and what the control objectives have are the specific policy statements um that we can that are actionable that we can monitor against so I'll go ahead and click on one of our policy statements here which is a control objective um and it it's really staying kind of the same thing but as as far as establishing maintenance of the effective controls we have to make sure they're effective so if I look down here when it comes to that policy statement it's connected to other tables other parts of the application it's connected to the policy it's connected to the citation so we can see the linkage with that it's connected to the risk statement and it's connected to underneath the control objective you have What's called the control this is the operational control that's actually going to be monitoring and monitoring um your environment it can be automated it can send a task to someone to actually check and monitor so I'll go ahead and click on this control here so one of the key things I'll highlight is this is in the monitoring state so this is it has in this case it's also my software Dodge but this could be someone in a different department somewhere else Whoever has that ownership and the other key thing I'll highlight here is the frequency so this is quarterly so it's really up to each company to specify how often they're going to monitor the annual could be monthly um quarterly kind of doing a quarterly check here to validate um that this is something we're actually doing is how this company has it set up here uh I'll pause for just a moment to see Teresa is there any questions so far yeah there's a one question here um are you workspace oh great question so there's two different views right so if I look over here under workspaces there is a risk workspace so um we're showing the specific applications from a different view so we can see how they all connect together and then when it comes to a risk manager doing their day job the operational side there is the risk management workspace which is a different view you can also use typically the risk workspace is used when you have tasks you need to respond to within the system and um we're just showing a different view of the system here so you can see where how the different applications connect together that's a that's a good question yeah perfect and then the last one here is um you showed the financial the 10K Financial assessment was that something that you created or did you use that one of the assessments that comes with the platform or to make some minor modifications to it yeah great question no we created that so there's there's the default risk framework that you have and a lot of companies start with the default one but we we set that up I and I think um I'll kind of expand on the answer there it's good to start with the default ones until you understand your company gets understanding of how to use questionnaires and so forth but um you know in this example the companies use servicenow for a while they want more specific questions um so that they can get better inputs based because they know their business better than anyone so we we set up that questionnaire we we configured those questions um we can configure those questions to get a more granular and more accurate representation of our risks for what we're looking for here yeah I just want to add really quickly I mean the configuring the questionnaires is really simple if you haven't done it before it's really went pretty much a drag and drop interface so it's not an onerous task you're not coding you're not doing anything like that so just this kind of an aside um it is something very simple to do and as heartache says it's something that you might want to do after you have gotten to a point where you've identified things that are not met on the out of the box questionnaires yeah yeah absolutely so um the last thing I'll say here is um here's the control in this case the control has passed if it did for any reason fail as in there was a concern I'm gonna go back to our dashboard here um it would show up as an issue and your risk posture would change from less likely to more likely if controls fail because you're mitigating your risk through those controls so I think the other thing I want to highlight here is it's all Dynamic um we kind of we see the dashboard here and we saw kind of behind the current the different applications that are driving this data so you can immediately take action on any risks and through the questionnaires through the qualitative response through the controls controls can be automated and configured pretty simple within the system to kind of connect everything together and and proactively find issues awesome well I I know we're a top of the hour here um so thank you Karina and hartaj and thank you for all of you folks that that hung in with us and and were able to enjoy this wonderful webinar

View original source

https://www.youtube.com/watch?v=pjhbZVs5U84