Four Steps to Reducing the Cost of Compliance

Published: July 1, 2009 | No Comments

Want to reduce the cost of compliance? Mike Hoefgen outlines four steps related to controls testing that can help strip out both cost and complexity from your compliance process.

Divide and conquer has been the mantra of compliance in many organizations. Typically the finance department drives Sarbanes-Oxley compliance. The Information Technology department focuses on ISO 27000, COBIT or other IT-specific best practices. Other departments might be focused on privacy regulations such as state privacy or HIPAA requirements. And it doesn’t stop there. Each industry has its own set of best practices.

Given this state of affairs, how can you reduce the cost of compliance?

Let’s focus on the largest contributor to the ongoing cost of compliance: control testing.

Step 1: Consolidate ALL of your controls into one list.

For this to be effective you must get every compliance group to contribute. The easier you make it for these groups to participate the better your results. Gather all of those spreadsheets, word documents and diagrams into a central repository so you can visualize what you have. What is the minimum information you should gather about those controls?

  • Control Name
  • Brief Description
  • Control Owner
  • Related department, business unit, and/or business process, asset
  • Why is the control there? (Supporting a regulation? Protecting a company asset?)

Controls List 

Step 2: Now that you have the controls in one place, start looking for similarities between them.

Look for opportunities to remove duplicates. Quite often SOX controls and IT controls do the same thing but for different regulations. Why have two (or more) when one will work? Combine similar controls into one. Modifying a control to be stronger may remove the necessity for a second comparable control. Getting the idea? Having fewer controls reduces the complexity of your control framework and makes it easier to manage. It also reduces the time needed to verify and test those controls.

To make this step easier consider using a control framework like the Unified Control Framework . They have already mapped nearly 350 regulations and best practices to a set of control objectives. This makes it much easier to rationalize your controls across a range of regulations, thereby helping to minimize redundant or highly overlapping controls. In addition, this approach makes it dramatically simpler to meet the needs of future or evolving regulations, since your existing rationalized controls are likely to be applicable to these new requirements.

 RiskBubbleChart_640x305

 Step 3: Determine the ideal testing frequency for your set of controls.

Now that you have a rationalized list of controls, how often do they need to be tested? How do you decide which ones get tested monthly vs. quarterly vs. yearly? Using a risk assessment of your controls will help you answer those questions.

A risk-based approach focuses testing on areas of greatest risk. It also reduces the unneeded work to implement controls for no/low risk areas. This avoids spending absurd amounts of time (and money) on low risk areas. The best way I have seen to identify your largest risks is using a bubble chart with likelihood and impact of the risks being the x and y axis. Each bubble represents a risk. The highest risks are generally in the upper right corner.

 

Step 4: Find ways to automate what you can.

In a previous step, we reduced manual labor by reducing the number of controls that need to managed and tested. Many controls are manual in nature, such as having someone manually review transactions. Automating some of the controls is another way to curb the cost of compliance. Continuous monitoring provides companies a means to transform manual process controls and automate them as system controls. Continuous monitoring saves labor costs associated with performing and testing the control while improving its reliability, which in turn minimizes the risk.

To recap, start the process by breaking down the silos between compliance groups and consolidate your controls into a central repository. Then, decrease the number of your controls by eliminating duplicates and combining similar controls. Next, use a risk-based approach to prioritize your controls testing activities. Lastly, apply automated controls where it makes sense to reduce the effort, while increasing speed and accuracy of your testing activities.

Tags: , , , , ,

Read Post & CommentsShare/Save/Bookmark

By: Mike Hoefgen
Mike Hoefgen has been helping clients solve business problems for over 20 years. Mike is currently a Principal Consultant with CA, Inc working with the Governance business unit and is based in Seattle. Mike holds a Bachelor of Science degree in electrical engineering from University of Wisconsin, Madison. When not helping clients and writing... Read More...

Jun 29 09

KRIs and KPIs: The Alphabet Soup Approach to Risk Management

Sumner Blount explains how key risk and performance indicators – also known as KRIs and KPIs – play a key role in effectively measuring and managing risk across the enterprise.

Read MoreShare/Save/Bookmark

Jun 24 09

GRC and Grandma’s Advice

Mike Hoefgen suggests listening to some good advice offered up by Grandma – learn from the mistakes of others – in this post recapping the Countrywide scandal.

Read MoreShare/Save/Bookmark

Jun 22 09

The Fed’s Focus on Cybersecurity and Financial Controls

Allan Gajadhar shares his thoughts on the US Federal Government’s focus on cybersecurity and financial controls, and why GRC practitioners should be paying attention.

Read MoreShare/Save/Bookmark

Jun 18 09

SearchSecurity.com on The Basics of Enterprise GRC Project Management

In this post, Sumner Blount points to a recent SearchSecurity.com article on the basics of GRC project management by Forrester analyst Chris McClean.

Read MoreShare/Save/Bookmark

Jun 17 09

Lean GRC: Eliminating Waste

Inspired by the principles of Lean Thinking, Sumner Blount offers insights on applying one of the key Lean concepts - eliminating waste - to the discipline of GRC.

Read MoreShare/Save/Bookmark

Jun 15 09

Expert Q and A: HCL on HITECH and HIPAA

In this guest Q&A, Abhishek Ramavat of HCL Technologies, offers insights on the recently announced changes to HIPAA security and privacy provisions under the new HITECH Act.

Read MoreShare/Save/Bookmark

Jun 11 09

ISACA Celebrates 40 Years and Evolves its Strategy

Yves Le Roux provides an overview of ISACA’s 40 year history and shares thoughts on the organization’s new strategy for COBIT 5.0.

Read MoreShare/Save/Bookmark

Jun 10 09

Webcast Update: CA and OCEG on Increasing Compliance Efficiency through Lean GRC

CA and OCEG webcast on June 17 will focus on ways to increase compliance efficiency by leveraging Lean GRC strategies.

Read MoreShare/Save/Bookmark

Jun 8 09

Risk Management and Enterprise GRC: A Quick and Informal Comparison

Sumner Blount offers up a comparison of Enterprise Risk Management and GRC solutions, and answers this common question: “If I already have ERM, why do I need GRC?”

Read MoreShare/Save/Bookmark

Jun 5 09

Recap: Five-part Video Blog Series with Scott Mitchell of OCEG

Check out this post for links to all five of our video blogs featuring Scott Mitchell of OCEG.

Read MoreShare/Save/Bookmark

Jun 3 09

The Four Main Principles of Lean GRC

Sumner Blount explains the four main principles of Lean GRC, highlighting how companies can leverage the concepts of Lean Manufacturing and Lean IT to help streamline compliance and risk management efforts across the enterprise.

Read MoreShare/Save/Bookmark

Jun 2 09

Video Blog: Getting Lean with GRC

Peter Stapleton outlines the basic concept of LeanGRC in this video blog.

Read MoreShare/Save/Bookmark

May 28 09

The New French Anti-piracy Law

Yves Le Roux examines the controversial French anti-piracy law, known as HADOPI, which allows a new government agency in France to cut-off consumer access to the Internet for suspected piracy violations. Could this law spread around the world?

Read MoreShare/Save/Bookmark

May 27 09

CA Experts Presenting Five Sessions at Compliance Week Conference

Five separate sessions at this year's Compliance Week Conference will feature CA's Rob Zanella, VP of IT compliance and security, and Patricia Prince-Taggart, SVP, managing attorney (and former deputy chief compliance officer).

Read MoreShare/Save/Bookmark

May 26 09

What I Learned About Risk Management from Risk Managers

Sumner Blount recaps interesting anecdotes from risk managers at a recent RIMS-sponsored risk management seminar in Boston.

Read MoreShare/Save/Bookmark

May 20 09

New Technology Report from The Butler Group

Sumner Blount recaps a recent technology report from The Butler Group highlighting CA GRC Manager 2.0.

Read MoreShare/Save/Bookmark

May 19 09

Is the EU Data Protection Directive Old-fashioned and Out of Date?

A recent review of the 1995 EU Data Protection Directive points to its strengths and weaknesses and a conference this week in Brussels may lead to changes in the directive. Yves Le Roux provides an overview.

Read MoreShare/Save/Bookmark

May 18 09

CA Session at Interop: The GRC Easy Button

Chris Boswell will present a session on GRC best practices at Interop Las Vegas on Thursday, May 21 at 11:30 am PT.

Read MoreShare/Save/Bookmark

May 14 09

Video Blog: Scott Mitchell of OCEG on Untangling the Web of Frameworks

In the final installment of our 5-part video blog series, Scott Mitchell, CEO of OCEG, shares his thoughts on untangling the web of risk and compliance frameworks.

Read MoreShare/Save/Bookmark