Editor's Note: This article is a contributed piece from a business management consulting firmStoneTurnpartner Greg Buchanan, Managing Director Michael Costa, and Manager Ed Levy. The views expressed in this article are solely those of the authors.

The pandemic has brought challenges to the compliance and internal audit functions of many enterprises. Although the way of working has changed, the mission of compliance and internal audit professionals remains the same: to identify and manage business risks. To this end, enterprises must continuously strengthen compliance programs, update risk assessments, adjust audit plans and priorities, and customize internal control measures.

For most enterprises, these internal challenges are exacerbated by resource streamlining and the emergence of external factors. However, compliance and internal audit functions must still provide assurance to senior management and the board of directors that measures have been taken to mitigate significant risks.

Data Analytics and a Risk-Based Approach

Data analytics enables enterprises to adopt a risk-based approach, prioritizing efforts on areas where problems are likely to occur. Organizations that rely on random sampling to test internal controls or substantive testing of high-risk transactions often struggle to obtain meaningful findings or valuable audit results—this is akin to looking for a needle in a haystack.

Even before the COVID-19 pandemic, data analytics was already creating value in compliance work. A typical example is its application inidentifying college admissions fraudTherefore, it is not surprising that regulators are increasinglyturning to data analyticsin their investigations.

In fact, the latest guidance update from the U.S. Department of Justice (DOJ) on the effectiveness of corporate compliance programs encourages prosecutors to examine whether compliance and control personnel have adequate access to data (directly or indirectly) to monitor compliance programs in a timely manner. These questions indicate that the DOJ expects companies to provide compliance-related data to the Chief Compliance Officer and the compliance function, and to remove "barriers to accessing relevant data sources."

Given that compliance and internal audit functions are increasingly "doing more with less," the following provides practical guidance: the importance of direct data access, how to maximize the value of data analytics by connecting disparate data sources, and how data analytics can enhance efficiency and effectiveness at this critical juncture.

Data Sources and Direct Data Access

Remote testing has become the new normal, which also foreshadows the way internal audit teams can expect to work in the future. Collecting, integrating, and analyzing key datasets to perform compliance or internal audit procedures is crucial.

For example, certain data fields can be used to identify high-risk transactions, and the results provide valuable subset information. Internal audit teams can then determine the most appropriate audit procedures to reach conclusions.

Not all data sources are equally reliable. Data quality is the core of data analytics. Data analytics—especially direct access and data queries—is a key component that second and third line of defense personnel should consider to achieve their objectives.

We have observed that enterprises often rely on local business units to provide information on data sources used for their daily tasks. However, front-end system users often do not fully understand the complexity of data tables, which may only be correctly accessed through back-end queries. This common mistake can expose enterprises to significant risks, such as drawing audit conclusions based on incomplete or inaccurate information.

Direct access to key underlying databases can mitigate this potential issue. Compliance professionals and internal auditors work directly with IT personnel to ensure the accuracy and completeness of information. Furthermore, direct data access can reduce the execution time of testing procedures from days or weeks to minutes or hours, as this stage (i.e., the initial data collection phase) no longer requires business unit personnel to act as intermediaries.

At the same time, compliance professionals and internal auditors can interact with appropriate IT experts to understand data limitations or anomalies, thereby determining their impact on the project scope.

Connecting Disparate Data Sources

Perhaps the most significant impact of data analytics on compliance assessments and internal audit effectiveness lies in integrating disparate data sources.

Case Study: Anti-Corruption Risks for Multinational Companies

Multinational companies that use third parties (including agents, sales representatives, consultants, intermediaries, and distributors) may face significant risks under anti-corruption laws. These companies should regularly review interactions and payments with these third parties identified as high-risk to ensure compliance with anti-corruption laws and company policies.

To monitor and review such activities, multiple data sources must be considered, such as the company's accounting system, expense reimbursement system, due diligence databases, and more. To more effectively review these datasets, compliance and internal audit teams should use data analytics to assess whether the following anomalies require further investigation:

  • Was due diligence/bid review conducted on suppliers before transacting with them?
  • Are third parties charging prices above fair market value? (This may indicate bribery payments.)
  • Are transactions involving government officials monitored in accordance with specific country regulations and internal policies?
  • Have high-risk transactions (such as discounts and commissions) been assessed for reasonableness?

Companies should also consider other high-risk factors, such as potential conflicts of interest and other risks identified during the risk assessment process. Data analytics tests are then tailored to these specific risks. For example, compliance and internal audit teams may want to compare the supplier master file with the employee information system to determine whether conflicts of interest exist. If an employee has an ownership interest in a company supplier, this should raise red flags.

In summary, many data analytics tests can be performed using key information available to the company to mitigate risks. However, this information may be scattered across different data sources, so understanding these sources and connecting the information is crucial.

Improving Testing Methods

Risk-Based Testing vs. Random Testing.Data analytics enables compliance and internal audit personnel to select key transactions for testing based on a risk-based approach, rather than selecting them randomly. Risk-based testing demonstrates that the organization is effectively managing risks in accordance with its risk appetite. For example, if a company wants to assess a specific anti-corruption risk, it should monitor and test transactions involving government officials in high-risk countries, including specific transaction types (such as cash payments) and other attributes of concern.

Clearly, companies need to determine appropriate quantitative (e.g., round amounts) and qualitative factors (e.g., involvement of high-risk third parties) to prioritize risks and identify high-risk transactions requiring further analysis. Using data analytics is the most efficient and effective way to achieve this.

Repeatability.Initially establishing data analytics test parameters requires some effort. Understanding system databases and data structures may involve a learning curve, and system-specific nuances need to be examined. Additionally, key data analytics tests to identify critical red flags must be created for the first time. However, every subsequent compliance assessment or internal audit will benefit from these efforts, as future work can build on a solid foundation. Repeatability in this sense not only increases efficiency but also establishes a process that enables different data analysts to obtain the same or similar results.

Conclusion

Remote work is likely to continue for the foreseeable future, giving us a glimpse of the new normal. Traditional random sampling and on-site testing methods will almost certainly evolve into approaches that increasingly adopt remote, risk-based audit procedures. Therefore, it is crucial for enterprises to leverage data analytics to address current and future compliance and internal audit challenges.