Jim Kaplan'saudnet.gif (4937 bytes)  

newslogo.gif (7197 bytes)
ASK (Auditors Sharing Knowledge) for Progress

March 2007

Prior AuditNet-L Newsletters

The AuditNet-l Newsletter is sponsored by: PricewaterhouseCoopers TeamMate

"PricewaterhouseCoopers TeamMate is a database-driven audit management system that streamlines the audit process by providing integrated tools for documentation, report generation and file sharing."

2007 Fraud Summit at SuperStrategies April 23, 2007 Las Vegas, NV The2007 Fraud Summit is packed with up-to-the-minute information on what every internal auditor should know about fraud in 2007. Held in conjunction with SuperStrategies, the Fraud Summit will give you the practical tools and useful insights you need to fight fraud.

SuperStrategies: The Audit Best-Practices Conference April 24-26, 2007 Las Vegas, Nevada The SuperStrategies tradition of excellence continues as high-level, hands-on audit pros share tried-and-true solutions and new approaches. With a program packed with real-world approaches, you will gain usable strategies from every session.

 

 

what
job title, keywords
where
city, state, zip

 

logo.jpg (1604 bytes)

 Accounting Procedures for Internal Control

 

AuditNet® Community

Sponsor News!

The AuditNet® community has grown by leaps and bounds thanks to your continued support. Yes it is hard to imagine but it has been more a decade since this community was created!  Support AuditNet® by supporting our sponsors. Without sponsor and affiliate advertising and contributions from the AuditNet® community everyone would have to pay for use of this site.

logo.jpg (1604 bytes)

This month check out Pentana software for audit professionals, including integrated risk and audit management, staff scheduling and information security questionnaires.

Remember! Clicking on sponsored ads and visiting their sites helps support AuditNet®. 


Visa PCI – Complying with Payment Card
Industry Standards

By Jack Bess
KnowledgeLeader Contributing Writer

Whether it is a neighborhood pizzeria or a giant chain of retail stores, any merchant that handles transactions by credit card is required to meet security standards established two years ago by the payment card industry (PCI). Security breaches at pizzerias are not likely to make headlines, but that is not the case with larger businesses.

Click here for the rest of the story!

This article was contributed by Protiviti KnowledgeLeader, an online service providing tools, templates, and other resources for internal audit and risk management. Free trials available at www.knowledgeleader.com. For a limited time KnowledgeLeader memberships are available for the reduced rate of $595 per year. Tell them you heard about it from AuditNet.org.


Resume Tune-Ups

by Robbie Miller Kaplan

When Every Space Counts!

Despite differences in credentials, experience, and accomplishments, your resume has something in common with every other resume; your personal history must fit on one to two pages. How you use this space determines your résumé’s destiny; whether it sparks a hiring manager’s interest or finds its way into the discard pile.

For the rest of the tune-up click here!

Get a Free Resume Analysis!

AuditNet Adds a New Career Feature: The Resume Tune-Up.

Nationally recognized resume expert and author of How to Say It In Your Job Search, Robbie Miller Kaplan will select one auditor resume each month and suggest ways to transform the resume from passable to powerful.

If you would like your resume to be considered for a tune-up, please e-mail it to Ms. Kaplan. You will be notified by e-mail if your resume is selected. You will need to make yourself available via e-mail to answer a few questions with a tight deadline.  Ms. Kaplan will send a critique and suggestions to the individual selected and a summary Resume Tune-Up will appear in the monthly newsletter column.  If selected you give AuditNet the right to display your resume for the column.


AuditNet® What's New This Month?

AuditNet forges new relationships with professional associations and accounting sites to provide auditors with access to audit work programs.

Access to Free AuditNet Audit Programs Through AccountingWeb

AccountingWeb registered users may now access the free audit programs section of AuditNet without having to register and login through AuditNet. AccountingWeb offers free registration for their excellent accounting news service. Get all your accounting news delivered directly to your inbox. This is an excellent digital knowledge resource service and the price is right. As a bonus you will have transparent access to AuditNet and be able to view and download all the free audit programs. What could be easier?

Go to AccountingWeb now and register.

Fraud News Feed

Go to the AuditNet Fraud Resource Center and check out the fraud news feed to keep up to date with media reported fraud happenings. 

New Advertiser

Welcome to Global Best Practices® from PricewaterhouseCoopers, an online resource used by auditors to benchmark business process performance, identify areas of strength, opportunity, and risk, and study best practices that support process improvement. A process classification framework, qualitative and quantitative benchmarking tools, risk and controls information, and comprehensive best practices reports are included in the knowledge base.

Visit the site today and check out this excellent resource!

Audit Programs

The audit programs section of AuditNet requires registration in order to access.  New audit program contributions are available only to paid subscribers or on a one-for-one exchange basis. However 181 standard management audit programs were added this month to the free content thanks to Professor Andrew Chambers of the UK. There are over 38,000 registered users. A multi-user subscription rate was added to the individual subscription program to the premium content. Organizations that need more than 2 staff members accessing the service will benefit from this new rate. There are new additions to the premium audit programs available as an alternative for those auditors that are unable to contribute material to AuditNet®. Site licenses are also available for organizations with more than 15 users.

The best way to find all the resources on the site is by going to the Virtual Library or use the site search.


SERVICES OF TECHNICAL CONSULTANTS
[FOR JOINT-VENTURE MEGA PROJECTS]

by Gursharan Singh

1.1 The traditional understanding of Consultancy Services referred to employment of

  • Architects
  • Engineers [C&S/M&E]
  • Quantity Surveyors

Or commonly known as Technical Consultancy Services

1.2 Laws, Procedures and Guidelines have been formulated and been in existence for many decades in most countries. These cover, among others,

  • Terms & Conditions of Appointment
  • Basis & method of computation of professional fees & other claims
  • Scope of Services to be provided
  • Responsibilities of Clients and Consultants
  • Categorization of various types of Projects [Buildings/Infrastructure]

1.3 Regulatory authorities were established to monitor the services of the technical professionals to ensure that all involved parties complied with the provisions of the laws. There were provisions for protection of clients and they had recourse for redress in the event of any disputes.

Click here for the rest of the article!


IIA Technology Audit Guide Series

New Guide Released

Guide 6: Managing and Auditing IT Vulnerabilities

Chief audit executives (CAEs) and internal auditors who want to learn more about managing and auditing IT vulnerabilities are in luck. The IIA has just released its sixth guide in its Global Technology Audit Guide® (GTAG®) series, Managing and Auditing IT Vulnerabilities. The 24-page guide was developed to help CAEs and internal auditors ask the right questions of IT security staff when assessing the effectiveness of their vulnerability management processes. The guide recommends specific management practices to help an organization achieve and sustain higher levels of effectiveness and efficiency and illustrates the differences between high- and low-performing vulnerability management efforts.

Each Global Technology Audit Guide (GTAG) will be written in straightforward business language to address timely issues related to information technology management, control, or security. GTAG will be a ready resource series for chief audit executives to use in the education of members of the board and audit committee, management, process owners, and others regarding technology-associated risks and recommended practices.

Previous Guides:


AuditNet® Fraud Auditing Corner
CONSTANT WARNING
An Interview with Sherron Watkins

By Dick Carozza

Though the main Enron characters have received their prison sentences, there's no closure for corporate fraud. Sherron Watkins, Enron's sentinel, describes the debacle's details and warns that it could happen again.

This article is from Fraud Magazine, the professional magazine of the Association of Certified Fraud Examiners and is a regular feature of AuditNet under a new cooperative relationships and partnership with professional associations in the interest of sharing resources for the benefit of the global AuditNet® community. .

For the rest of the article from the latest ACFE Fraud Magazine click here.


EDPACS Makes Article Archives Available

EDPACS is a monthly audit, control, and security newsletter with ~24 pages of content in each issue. It is the world's longest running IT Audit newsletter now into its 35th year!

Going forward, EDPACS will be focused on four key areas, that is, providing comprehensive articles regarding Governance, Audit, Control, and Security. For more info click here

For a limited time EDPACS will make their archived articles available to the audit community free of charge. Take advantage of this opportunity to research and check out what EDPACS has to offer.

Dan Swanson, President and CEO, Dan Swanson & Associates and an AuditNet contributor was recently named the new editor (part time) of EDPACS. Kudos to Dan on his new position! If you are interested in writing for EDPACS then contact Dan at dswanson_2005@yahoo.com


AuditNet® Conference & Training News

Want to announce your professional association conference to the global audit community? Send us conference name, date and URL details. (A reciprocal link to AuditNet is required).

2007 Fraud Summit at SuperStrategies*

2007 ACFE Fraud Conferences and Training

2007 IIA Conferences and Training

* indicates events where Jim Kaplan is speaking


Need Help in Passing the CCSA Exam?

Then check out the CCSA Study System published by Pleier Corporation.

Using the "McKeever CCSA Study System" will improve users' probability of successfully passing the IIA CCSA exam by teaching users to answer the type of questions typically presented on the CCSA exam. Additionally, this system helps users identify CCSA domains that require their additional study and lists references useful for any additional study.

The "McKeever CCSA Study System" is available in 2 versions - a 288-page spiral-bound workbook and CD-ROM (for those who prefer clicking a mouse to turning pages) - for details click here!

Opportunities to Share Your Knowledge and Earn Royalties

Pleier Corporation is still seeking additional authors to publish on CD and earn royalties.

AuditNet's last posting resulted in the publishing of "A Practitioner's Guide to Performance Auditing" by Muhammad Akram Khan - see  and "Auditing IT Infrastructures" by Alan Oliphant.

Pleier Corporation is looking for additional authors who have quality and quantity of Internal Audit-related material appropriate for an entire CD title.

Pleier Corporation would especially like to publish a CD on Contract/Construction Auditing by an author with practical experience and an ability to communicate that information for distribution on CD or DVD.

Available topics continue to grow especially with new authors from AuditNet like Muhammad Akran Khan and Alan Oliphant.

Publish your own CD or DVD to earn royalties and receive worldwide exposure.

Available titles currently completed include:

21st Century Audit Management
A Practitioner's Guide to Performance Auditing
Auditing Fraud
Auditing IT Infrastructures
Auditing Purchasing and Contracts
Control Self Assessment
Internal Auditor Toolkit
Modern Integrated Audit Approach
Risk Management: Best Practices
Risk Management and Risk Assessment
Systems Analysis and Design

INTERESTED IN PUBLISHING

For additional information email pleier@pleier.com or call Joe Pleier at (949) 830-1575.

DISCOUNTS TO AUDITNET READERS

As a reminder, Pleier Corporation offers 10 % discounts to AuditNet readers at www.pleier.com.  To take this discount order online and enter the word AUDITNET in the coupon field at checkout.


Check out Training on CD

A Practitioner's Guide to Corruption Auditing

Exceeding Expectations for Internal Auditors


Registered User Free Tools

Internal Audit Manual (Coming Soon)

AMIGO (Audit Management and Information Guidance Software)

The Perils of Mount Must Read

SOXERM

AuditNet Monographs

Premium User Tools

Sarbanes-Oxley, IT and Management Audit Programs

The Auditor's Guide to Internet Resources 2nd edition

Sarbanes-Oxley Section 404 Compliance for IT Managers 2nd Edition

Procedure Guidelines and Controls Documentation

Cobit 4th Edition Domain Quiz


Coming Attractions!

AuditNet is working with professional associations to provide access to the audit program inventory. Stay tuned!

The AuditNet Monograph Series  provides useful guides for all levels of auditors from juniors right up to audit directors. As soon as I can make some time I will be working on new guides for Sarbanes-Oxley, internal controls and Internet for auditors and other relevant subjects. These guides will be available to registered subscribers. If you are interested in developing a monograph on a contract basis, contact us.

Watch for new articles on Sarbanes-Oxley, Information Security, Software Auditing, CAATTs, and more from contributors. Reviews are in the works for more audit and SOx books. Watch the newsletter for more products, services and tools for auditors. Have an idea for a column? Contact us.

AuditNet® continues adding new specialized resources for auditors. Watch the newsletter and keep checking the Library page for updates and new resources.

 

Ask the Auditor

Each month I select one question submitted to Ask the Auditor and provide an answer using the same digital tools and techniques that I recommend to all auditors. 

Q: What is the recommended placement of the internal audit function within an organization with regards to reporting structures, as laid out in the audit guidelines?

A: The IIA s International Standards for the Professional Practice of Internal Auditing
(Standards) require that the chief audit executive (CAE) report to a level within the organization that allows the internal audit activity to fulfill its responsibilities. The IIA believes strongly that to achieve necessary independence, the CAE should report functionally to the audit committee or its equivalent. For administrative purposes, in most circumstances, the CAE should report directly to the chief executive officer of the organization.

For more information on reporting structures go to the IIA website.


Heard on the Net!

Online Discussion Forums for Auditors

Perhaps one of the most underutilized resources for internal auditors are online discussion forums. These online communities are a powerful tool for auditors as they provide the opportunity to ask questions, share experiences, and find resources. Check out the IIA Discussion Forums or the AuditNet Discussion Forums and see the ways that others are using them.

Thanks for your support and until next month!

If you have a tip on how you are using the Internet or software applications for auditing contact us. Watch for more Internet boot camp tips from the auditing Internet guru!


Audit Work Programs Corner

Register Now!

Free Access to the Premium Section for New Audit Programs Shared!

Access to the free audit program section now requires registrationThe following audit programs, ICQs, checklists or working papers were added this month. They are available on a 1 for 1 exchange for an original audit work program not currently in the inventory. If you unable to share audit programs then consider subscribing to the premium content which provides you with access free and premium content 24/7/365.  For a limited time AuditNet is offering free access to the premium content section. Contribute an original audit work program not currently in the inventory and receive 2 months free access to the premium content. Contribute 5 programs and receive a subscription for one year. (Offer only available for new programs submitted).

E-Books for Subscribers to the Annual Audit Programs

  1. Commitments & Contingencies Risk Control Matrix (Mar 07)

  2. End of Period Financials Risk Control Matrix (Mar 07)

  3. Hire to Pay Risk Control Matrix (Mar 07)

  4. Inventory Risk Control Matrix (Mar 07)

  5. Information Technology Risk Control Matrix (Mar 07)

  6. Order to Cash Risk Control Matrix (Mar 07)

  7. Purchase to Pay Risk Control Matrix (Mar 07)

  8. Soft Controls Internal Controls Risk  Matrix (Mar 07)

  9. Sarbanes Oxley Audit Review-Portuguese (Mar 07)

  10. Sarbanes Oxley Governance Risk-Portuguese (Mar 07)


Looking to Earn Some Extra $$?

Lots of Inquiries but No One Stepping Up to the Plate

AuditNet is interested in developing a series of SOx or industry related audit programs for organizations. If anyone is interested in writing audit programs, ICQs, questionnaires, or control matrices on a work for hire basis please contact me. If you may know of anyone who would be interested in this as well please pass along my contact information.


Global Best Practice Papers

Treasury and Working Capital Management

 

PricewaterhouseCoopers Global Best Practices will provide an article each month highlighting research. This month the featured article is on  treasury and working capital management.

In this new paper, Best practices for treasury and working capital management, we share insights into the ways leading companies take advantage of myriad opportunities to strengthen cash flow, settle payments quickly, reduce working capital liabilities, negotiate favorable payment terms with suppliers, establish clear accountability in accounts payable and receivable, and increase the value of collections personnel.

Click here for Best practices for treasury and
working capital management
.


AccountingWeb News

E-mails As Evidence: Business Owners Face New Procedures

AccountingWEB.com - Feb-22-2007 - Changes in federal employment law may change the way you and your employees store e-mails and e-messages, but Business & Legal Reports reports that one of the key changes facing small business owners this year is not a change in law at all.

For the rest of the story click here!

To register to receive AccountingWeb news click here! (Editors note: AccountingWeb registered users will soon have transparent access to the AuditNet free audit programs)


AuditNet Sarbanes-Oxley News

Low Cost SOX Compliance Readiness Tool
Exclusively for AuditNet

Looking for a low cost ($100) solution for SOX compliance? The Compliance Readiness Tool™ allows organization’s to evaluate the effectiveness of their information technology environment and controls in relation to section 404 of SOX and the Committee of Sponsoring Organizations (COSO) internal control framework.

For more information click here!

There are plenty of articles in the news on the topic of Sarbanes Oxley. Here is a link to a site that does the research and provides you with links to all the relevant stories.

Sox-Online


AuditNet Career Center

Auditors Looking for Jobs!

Companies Looking for Auditors!

The Matching Service for Auditors!

Go to the AuditNet® Career Center now for the latest job opportunities and career-related information and tools. 24 hours a day, 7 days a week you have the ability to not only look at available jobs, but you can also post your resume, apply for open jobs, research companies and obtain career advice. If you are in the market for a new job, make AuditNet® your first stop to check out what's available.

If your company has any audit job vacancies that you are looking to fill, have your HR people contact AuditNet® to post the job and search for candidates.

This is just another benefit of using AuditNet® as your one stop shop for all your audit and career resources.


AuditNet® CAATT Corner

Automate Your Internal Controls

By Richard B. Lanza, CPA/CITP, CFE, PMP

Overwhelmed by the documentation and testing requirements of the Sarbanes-Oxley Act? Consider these tips to automate your efforts.

For the tips click here!

UPCOMING WEBINARS

March 20, 2007 Develop a Risk Universe for Excel Spreadsheets& Using Microsoft Excel as an Audit Tool

March 22, 2007 Power Excel Webinar


 

AuditNet® Book Reviews

 

 


AuditNet® Software Compliance Audit Corner

 

Hasta La Vista

This will make life interesting for some and a nightmare for the IT Audit team and the IT HelpDesk.

“Register within 30 days or the lights might go out on your career if you don't have a valid version ............ “

For a career limiting move make sure that you don’t let staff install Vista in your office hacked and cracked. If you do then see how long you survive in the IT industry!”

For the rest of the story click here!

Monograph on Software Compliance Auditing: Looking for a Career Change?

Registered users can read the complete monograph by clicking here!

Registered AuditNet users can send for 20 free software compliance articles. Login to your account and click on the link to receive the articles by email.

Also the following articles should interest you!

Microsoft has started a program recently in UK that has wide reaching implications for smaller and medium sized organizations, that auditors need to be aware of to minimize risk.

More details can be seen by clicking here!


Your Secret Weapon in the War on Fraud

White-Collar Crime Fighter brings you expert strategies and actionable advice from the most prominent experts in the fraud-fighting business. Each month you’ll learn about the latest frauds, scams and schemes... and the newest and most effective fraud-fighting tools, techniques and technologies you can put to work immediately to protect your organization.

Click here for the latest e-newsletter and subscription details.


The AuditNet® Audit Bookstore Corner

Looking for books on auditing related topics? We suggest using the AuditNet® bookstore. The bookstore focuses on Internal Audit but includes other related subjects as well. AuditNet® uses Amazon to power the bookstore so each purchase you make through this link helps support AuditNet®.

How to Say It When You Don't Know What to Say  The Right Words for Difficult Times

By Robbie Miller Kaplan

As auditors we constantly interact with diverse stakeholders such as colleagues, managers, employees and others. Frequently we encounter people dealing with challenging and difficult times that may or may not be related to work. Our reaction to these situations is conveyed in our behavior both nonverbal and verbal.

For the rest of the review click here.


FREE! The Auditor's Guide to Internet Resources 2nd Edition

Interested in a free copy of The Auditor's Guide to Internet Resources, 2nd Edition? Write an article for the next newsletter on how you are integrating the Internet in auditing. If your article is selected, I will send you an electronic copy of the book. Contact us for details.


AuditNet® Vendor News

Check here for the latest news from our AuditNet® sponsors!

ACL News

Caseware-Idea News and Events

Paisley Consulting press releases

Pentana news and announcements

TeamMate news and events


Dan's Internal Audit Corner

Each month Dan Swanson, a senior security and internal audit professional will provide his list of recommended resources for AuditNet readers. You can reach Dan at his website or by clicking here.

Auditing for Fraud “Thought Leadership”
- (Because bad things are happening).

The function of education is to teach one to think intensively and to think critically... Intelligence plus character – that is the goal of true education.
— Martin Luther King Jr.


We need to address fraud in all its many forms !!!

Some companies have significantly lower levels of misappropriation of assets and are less susceptible to fraudulent financial reporting than others. Why? Because they aggressively take steps to prevent and detect fraud, end of story (it’s that simple). At these exemplary companies, management is responsible for designing and implementing systems and procedures for the prevention and detection of fraud—and, along with the board of directors, for ensuring a culture and environment that promotes honesty and ethical behavior.

Some key questions to consider:

For the questions and resources click here.
Have another great month.
Best regards.
Dan Swanson


Fraud News

Need to keep up with fraud news and happenings? There are several options available. One is to subscribe to the free ACFE FraudInfo E-newsletter.

Another free resource is the Auditing & Fraud News. Service for research professionals. Constantly updated news and information about Business & Companies. Go to FraudNet and click on the link Click Here for Fraud News.


Sustaining SOX Compliance

Tripwire has made available for free download it's Whitepaper on implementing IT controls that deliver long-term competitive advantages and SOX compliance. There are also other documents available for download on this page however they require registration.

Click here for the link page!


AuditNet® Resource List

Please let us know of links that are not working!

Click here for the latest update!


         



 



Revised: January 14, 2008