top banner

Control Chatter                                                   August 2020
News that Control Professionals Need to Know


 Quick Links
In This Issue
Internal Control and Customer Service Inconsistency
Affiliate News..
Digital Transformation - Regulator Issues $80 Million Penalty for Not Doing It Right
The IIA's New Three Lines of Defense Model Misses The Mark
Why the business world is about to need compliance officers more than ever.
Police to move on Experian cyber suspect
Wells Fargo's chief compliance officer quits as bank revamps risk team
Corp's lapses led to huge losses
ISO Standards for Information and Data Protection
How to adapt compliance frameworks to the 'new normal'
A Long Time Coming: DOJ Issues First FCPA Advisory Opinion in Six Years
 
HELP US IMPROVE INTERNAL CONTROL SYSTEMS WORLDWIDE
PARTNERS WANTED: 

Facebook Join My List Logo
The Internal Control Institute™ (ICI) improves organizational Internal Control worldwide by providing training, products and services and individual Professional Certifications recognized internationally. The Institute's Board of Advisors has determined it would like to further expand into areas where it is not directly represented. ICI provides world-class programs and its intellectual property to affiliates free of charge and shares all program revenue with them. If your organization is interested in partnering with ICI to earn revenue while you contribute to the development of the internal control profession worldwide please contact Dr. Michael Pregmon, Jr., Chief Operations Officer, by email at: [email protected] or by phone at 727-538-4113 in the USA. 
Test your Knowledge of Internal Control
The Internal Control Institute has developed a CICS Common Body of Knowledge Mini-Assessment that helps an individual determine their knowledge as it relates to governance and control practices. Results point out areas of knowledge that may require additional training and experience. The assessment also provides a measurement to the individual's readiness for CICS certification. The assessment measures core knowledge in eight critical areas including: Internal Control - Principles, Terms and Concepts, Internal Control Environment, Risk Management, Assessing Application Controls, Business System Control Assessment, Risk Assessment, Internal Control Measurement and Reporting, and Governance Practices
 Internal Control online courses
ici logo
Start becoming an Internal Control professional today!
The ICI "Certification Series" has been completely updated and is available online to everyone around the world! Course content prepares individuals to design and/or assess internal control and to assist management in installing internal control processes. In addition, the series prepares candidates for the Certified Internal Control Specialist (CICS) Examination.
To review the course catalog click here: ICI Course Catalog
To register for one or all of the online training programs click here:  
Online course pricing has been reduced by over 70% 
Internal Control and Customer Service Inconsistency
By Michael Pregmon, Jr., Ph.D., CICP
COO and Managing Director
Dr. Michael Pregmon, Jr.
COO and Managing Director 
It has been stated many times in this space that problems and failures in business operations often can be attributed to poor internal control practices. We know that definitively! Yet we go on repeatedly accepting the consequences and assume these failures are a normal part of doing business. This is absurd! And it is an excellent example of management ineptness. Even worse, when we accept these shortfalls and feel correcting them will cost money, that spells "disaster." This is particularly true when it concerns customer service.
 
Interestingly as customers and consumers ourselves, we are personally mindful of the importance of customer service. Certainly, we will not continue patronizing a business that provides inferior customer service. Then why should that occur in our own business?
 
It has been echoed many times that customers most often will not tell you your business "stinks." They just leave. The sphere of customer service not only pertains to retail operations, it applies equally as well to clients, patients, residents, patrons, etc. In fact, in the healthcare industry, delivered service is even more critical because of the life or death, or serious injury implications. In the health care business "timing" becomes most important in patient and/or resident customer service care.
 
Customer service inconsistency, particularly over a period of time, is indicative of some more critical issues. Unfortunately, inept management often fails to recognize the signal. The fact that the customer service goal is occasionally met, lures the company's leaders into a false sense of accomplishment. And as indicated above, customers will rarely say anything before they leave.
 
Repeated service inconsistency is symptomatic of three particular organization ills. These are:
  1. Organization structure flaws
  2. Process control failures
  3. Staffing challenges
 
These can often be "fixed" without increasing cost. All it takes is some common sense and a measure of fortitude. Sometimes not all three issues may be contributing to inconsistent customer service. In the health care industry, such as in hospitals, skilled nursing centers and assistant living facilities, service inconsistency is even more critical because of the increased health risk. Aside from this added risk exposure, it is just good business to provide your customers with an effective service level to promote the success of your business.
 
How consistent is the service level you deliver to your customers? Is your customer service level something you are truly proud of? Are you recognized in your industry as a company who delivers high quality customer service?
 
Because of space constraints in this newsletter, we will address each of the above concerns individually in the next newsletter editions.

ICI ANNOUNCEMENTS
ICI Affiliate News:


The Internal Control Institute is conducting certification training in a classroom and online formats for the internationally recognized CICS (Certified Internal Control Specialist) certification in internal control. Information on these programs regarding dates and schedules can be found on the Events tab on our Website (Events) or directed to the affiliate named below:

Botswana:
ICI has entered into an agreement with Internal Control Institute of Botswana (ICI Botswana":) as its representative for Products, Services and Internal Control Certifications (CICS/CICP) in this territory. ICI Botswana will be responsible for all development activities in this area, including professional training and Certification.  Individuals or companies interested in internal control training or Certification should contact:
Humphrey Chawafambira

Brazil:
Training Plans :

Belo Horizonte - 21 to 25 September
Rio de Janeiro - 5 to 8 October

For more details on planned training please visit the website below, or send a message to Mr. Eduardo Person Pardini. 

 
Cameroon:

ICI has entered into an agreement with Internal Control Institute of Cameroon ("ICI Cameroon") as its representative for Products, Services and Internal Control Certifications (CICS/CICP) in this territory. ICI Cameroon will be responsible for all development activities in this area, including professional training and Certification.  Individuals or companies interested in internal control training or Certification should contact:Contact: Eric Kamegne


China: 
Online CICS training and exams are being conducted due to COVID-19.  The next course runs from
12 August to 6 September 2020.

Individuals or companies interested in internal control training and Certification should contact: 
Mr. Qiu Jianting of CCSIT
Room 1039, Block A, Jinmao Building, No. 18, 
Xizhimenwai Street,
Xicheng District, Beijing, China
Zip Code: 100044
Mobile phone: 13810588109

Europe: 


Training Plans :

ICI Belgium has started the CICS session in French with 22 participants.
Next sessions are planned in Brussels:
  • Dutch: October 2nd 2020
  • French : January 2021
For more information on scheduled training and exams please contact Mr.Yves Dupont of ICI Belgium at: 
  
India
For more information on upcoming activities in this area please contact Mr. Summit Goyal of ICI India at :
Phone: +91 9810575613


Myanmar and Cambodia:
Better Business Governance - APAC PTE LTD (BBG) has become a representative for Products, Services and Internal Control Certifications (CICS/CICP) in Myanmar and Cambodia. Better Business Governance will be responsible for all development activities, including professional training and Certification.  For more information on upcoming activities in this area please contact:
Better Business Governance
Mr. Sanjeev Gathani
1 Claymore Drive
#08-14, Orchard Towers (Rear Block)
Singapore 229594
  
Mexico:
For more information on upcoming activities in this area please contact the following:
Antonio Salas Hernandez CICP, Email: [email protected] 
Joaquin Prendes Herrera, Email: [email protected] 

Middle East:
The CICS exam is now being provided in Arabic. Osool Training and Consulting has courses and testing available in Egypt, Jordan, Libya, Muscat, Sudan, Qatar, the United Arab Emirates, Kuwait and Palestine. 

Training Plans: 

30 August - 3 September 2020 - Amman, Jordan
13 - 17 September 2020 - Muscat, Oman
18 - 22 October 2020 - Amman, Jordan

Interested applicants in the region should contact Osool for scheduling for future programs. For additional information on scheduled ICI Certification and program sessions, please contact:
Lina Salameh
Assistant General Manager
OSOOL for Training & Consulting
Mob Oman:  +968 95 98 98 20
Mob Jordan: +962 7 99589666
Tel:   +962 6 5927171 Ext. 107
Fax:  +962 6 5927172

Nigeria: 
Leadway Consulting conducts CICS training sessions and examinations in Nigeria. For more information on upcoming activities in Nigeria  please contact:
Mr. Joel Aluko  [email protected]


Pakistan:

For more information on activities in Pakistan individuals or companies should contact : Muhammad Farooq Hammodi
E-Mail: nardac_k@yahoo.com


Romania:

ICI Romania is planning a CICS course session on October 5 - 7, 2020 and an examination on November 9, 2020.



For more information on activities in Romania contact : 
Cosmin Serbanescu at the National Institute for Internal Control in Romania.
Tel: + 40 752 525 525

 

Singapore, Malaysia, Indonesia and Taiwan China:
ICI has entered into an agreement with GRC Consultancy Pte Ltd. (ICI Singapore, Malaysia, Indonesia and Taiwan) as its representative for Products, Services and Internal Control Certifications (CICS/CICP) in those territories. 

Individuals or companies interested in internal control training or Certification should contact:
General enquiries for all 4 markets - [email protected]
Singapore - Mr. Bob Seetoh - [email protected]
MalaysiaMr. Melvin Beh[email protected]
IndonesiaMr. Melvin Beh - [email protected]
Taiwan China - Mr. Bob Seetoh - [email protected]


Tunisia

ICI has entered into an agreement with Business and Financial Consulting company in the Republic of Tunisia (hereinafter referred to as "ICI BFC" as its representative for Products, Services and Internal Control Certifications (CICS/CICP) in the Republic of TunisiaICI BFC will be responsible for all development activities in this area, including professional training and Certification.  Individuals or companies interested in internal control training or Certification should contact:
Contact: Nadia Yaich

Turkey:

For more information on activities being planned please contact:



Ms. Ilknur Tunc,  VP - [email protected]
Dr. Bertan Kaya - [email protected]
GOP Mahallesi, İran Caddesi, Karum İs Merkezi
No:21, D Blok, 4. Kat, D:398-399
06700
Kavaklıdere/Çankaya/Ankara
+90 (312) 4425015 T
+90 (533) 4474444 D
 
Vietnam:
Training Plan:
Course name
start day
duration
CICS®
preparation

4 days
On Saturday and Sunday
08:30
am - 12:00 am
13:30
pm - 17:00 pm
10/10/2020
 
For more information on upcoming activities in Vietnam please contact: NGUYEN THANH TUNG (MBA. M.Eng, PhD.) Director, FMIT Institute of Financial Management & Information Technology,  Level 5, 126 Nguyen Thi Minh Khai Street, Ward 6, District 3, HCMC, Viet Nam
Office: 848 3803 5020 - 848 3512 9371 - 848 3512 7652

Zimbabwe:
The Internal Control Institute Of Zimbabwe will be running CICS Classes on the following dates:    
          27-30 October 2020
          8-11   December 2020

For more information on activities being planned please contact:
Dr. Proctor Nyemba at: [email protected]
Internal Control Chatter  
Each month the staff of The Internal Control Institute reviews hundreds of articles related to Internal Control and Corporate Governance. Here are brief summaries of some of the top articles (along with links to the original article) that may be of interest to you.
Digital Transformation - Regulator Issues $80 Million Penalty for Not Doing It Right
By Jose Abarca, Romaine MarshallJon Washburn 
jdsupra.com
August 18, 2020
Digital transformation refers to the process of leveraging technology, people and processes to innovate or stay competitive. The main driver of this process is often data. For a vivid illustration see "Data Never Sleeps,"an infographic released by Domo, a leading business analytics company. While executing digital transformation the right way can lead to great success (think Google, Facebook, and Amazon), overlooking pitfalls associated with potential legal obligations - most notably, cybersecurity and data privacy - can have the opposite effect, harming an organization's reputation and its balance sheet. On August 6, 2020, the Office of the Comptroller of the Currency ("OCC") assessed an $80 million penalty against bank Capital One for what it determined was a failure to implement effective cybersecurity prior to migrating information technology to the cloud. This failure was exposed in July 2019 when Capital One announced that an outside individual gained unauthorized access to information belonging to 100 million individuals in the United States and approximately six million in Canada.
The IIA's New Three Lines of Defense Model Misses The Mark
August 25, 2020
Corporate governance and compliance is not as hard as everyone tries to make it. Much of management theory, risk management, and theories surrounding corporate operations is intuitive.Be wary of those who try to complicate issues, especially when it comes to professionals. We all bear some responsibility when it comes to legal, compliance, forensic accounting, management and other professional services. We have a duty to provide practical advice that is accessible and easily applied to specific problems. Professionals that follow this basic axiom provide important support and advance the cause of corporate governance. Professionals that complicate the issue by developing complex (and oftentimes incomprehensible) solutions and then solving their self-created complicated answer are doing their profession and their clients a serious disservice. The Institute of Internal Auditors recently announced revisions to its three-lines of defense model for corporate governance and risk management. The IIA has adopted a new framework with little justification, and in the end, has hurt its credibility.
Why the business world is about to need compliance officers more than ever
In December 2013, when I returned home after spending nearly 14 months in federal prison, I was naturally exuberant to have my freedom back. But soon after my release, my Probation Officer, Kimberly Gorton, slammed the brakes on my enthusiasm. It turned out she was right, and I was wrong. All I knew in those first post-prison days was that I wanted to take full advantage of life anew, without delay. I'll never forget my excitement when I was invited to give a keynote address at a major compliance event in DC just four months after my release. I needed my Probation Officer's approval, which I thought would be perfunctory, to travel from my home in Connecticut to DC, but that call did not go at all as I expected. She said, "Mr. Bistrong, you just got home, and my ability to allow you to travel outside the district is based on trust, and trust gets built over time. So, the answer is no."
Police to move on Experian cyber suspect
By WARREN THOMPSON
AUGUST 20, 2020 
Experian Africa expects the suspect responsible for a data breach that exposed the personal information of as many as 23.4-million South Africans will be arrested and charged as early as Friday, the company says. The hack is also said to have exposed 800,000 businesses, according to the SA Banking Risk Information Centre, a nonprofit organisation set up by the major lenders to combat bank-related organised crime. Experian collects credit data about clients from banks and other businesses. SA has the third-highest number of cybercrime victims in the world with about R2.2bn lost each year through fraudulent activities carried out via the internet, according to professional services company Accenture.
Wells Fargo's chief compliance officer quits as bank revamps risk team
bankingdive.com
Aug. 14, 2020
Wells Fargo's compliance function will be crucial as the bank tries to put behind it the 12 enforcement actions with which it began the year. Some stem from the 2016 fake accounts scandal that has cost the bank $3 billion in fines. But the bank's reputation has suffered upon allegations of other shady practices. Customers claimed last month the bank placed their mortgage accounts in forbearance without their knowledge. The bank has also been accused of "deceptively" collecting "hundreds of millions of dollars" in service fees. The Federal Reserve imposed a $1.95 trillion asset cap on the bank in 2018, which Bloomberg data estimates has cost the bank $220 billion in market value.
Corp's lapses led to huge losses, says audit report
By Express News Service
August 22, 2020 
The local fund audit report of the Kochi Corporation for the 2018-19 financial year has revealed serious lapses by the civic body's administration and said it led to heavy losses. Released on Thursday, the report also found serious financial irregularities under various heads, including tax collection and waste management. The report said the corporation's inefficiency in implementing online tax collection significantly affected its revenue. Due to the non-implementation of the facility, a lion's share of revenue collection continued to be done through manual receipts which led to leakage of funds, it said. It also found that receipts that were audited and cancelled years ago were misused for tax collection. The report said `4.5 lakh was missing in the books by writing a fake receipt number in the booking register of Mattanchery Town Hall and Kalvathi community hall. It is also alleged that the receipt books used during the audit period were not given to the audit department for inspection. The report also pointed towards lack of coordination between various departments and shortcomings in internal control. 
ISO Standards for Information and Data Protection
Information and data are key elements for an organization's daily operations and, as such, they need to be protected properly. This is easily seen through the evolution of contracts, laws, and regulations to include information security clauses. However, proper protection does not mean much in terms of how to go about it, and contracts, laws, and regulations often do not provide much detail, either.As a result, many organizations don't know where to start, and this can negatively impact their operational performance ans compliance capabilities. Fortunately, there are several solutions on the market that can help. In this article, we'll present some elements of the ISO 27k series, which can provide guidance on how to implement and maintain a sustainable information and data protection environment.
How to adapt compliance frameworks to the 'new normal'
Consultancy.asia
August 17, 2020 
A key risk of remote working and travel restrictions is a weakening of existing compliance controls and hindrance to forensic investigations. With the prevention of in-person site visits, interviews and access to original documentation, internal audits and investigations are facing major challenges and delays. To stay in control, companies are advised to put in place a 'Compliance Continuity Plan' and adapt existing compliance frameworks and policies. 
A Long Time Coming: DOJ Issues First FCPA Advisory Opinion in Six Years
August 18, 2020
 The Department of Justice issued a Foreign Corrupt Practices Act ("FCPA") Advisory Opinion-the first of its kind in nearly six years. The DOJ's opinion advised a U.S. investment company that the transaction fee is paid to a foreign state-owned bank's subsidiary would not trigger an FCPA enforcement action. The FCPA generally prohibits United States' companies or individuals from giving or offering bribes to foreign officials to obtain or retain business. The FCPA required the Attorney General to create a procedure that allows companies to seek guidance on specific FCPA compliance concerns, thus the DOJ FCPA Opinion Procedure was born. Companies can ask the DOJ whether "specified, prospective-not hypothetical-conduct" violates the FCPA.
Control Quotes
"Tell me and I forget. Teach me and I remember. Involve me and I learn." -
Benjamin Franklin

Help Keep Everyone Informed...
If you see a news story concerning internal control or corporate governance that you feel is important for other professionals to know please send it to us .
ABOUT ICI
 
ici logoThe Internal Control Institute™ (ICI) is a worldwide organization  devoted exclusively to internal control and corporate governance. The Institute is dedicated to the development of world-class educational programs and best practice guidelines on internal control and corporate governance, based on the Sarbanes-Oxley Act and the COSO internal control framework.  Visit us on the web at the Internal Control Institute
Control Chatter is a monthly news summary of the top stories concerning internal control and corporate governance.  Control Chatter is prepared by the staff of Internal Control Institute for the benefit of their members and associates. Please consider it for your personal use or pass it on to associates who may have an interest in one or more of the topics by clicking on the Forward email button below.