Riskonnect Case Studies
Sarbanes-Oxley (SOX) Management: Fortune 200 Diversified Outsourcing Services Provider
Sarbanes-Oxley (SOX) Management
Fortune 200 Diversified Outsourcing Services Provider
Automate and standardize Sarbanes-Oxley (SOX) compliance to make process
more efficient, accountable and accurate
Big Four consulting firm – ongoing engagement – and spreadsheets
Managing 800 key SOX controls with no master matrix. Inability to identify most
current and accurate individual control assessment status for lines of business
and locations. Different standards of documentation. Unclear whether risks have
been addressed or even assessed. Trying to determine a single source of truth
depended on e-mails and then manual data aggregation and normalization. As a
result, status meetings couldn’t be held more than bi-monthly, and preparing for
them took a quarter of that time period. A team of four was spending 300 to 500
hours a year, just to try and track status.
In a field of vendors that the company described as generally “over-complicated, costly to modify and loaded with time-wasting analytics that looked cool but in the end weren’t usable for SOX”, Riskonnect was chosen.
Riskonnect addressed the company’s unique challenges and successfully developed and implemented a solution at an affordable price. “Not only was the cost of implementation reasonable, but it’s annual cost is also very reasonable,” said the company. “I don’t think you can get a bigger bang for your buck than you can with Riskonnect … competitors try to sell you more than you really need.”
More than just affordable, design and implementation was fast. “We hit a very aggressive deadline. We started with a blank sheet of paper in January and we were using the tool in April.”
With the success of the Riskonnect SOX compliance solution, the company expanded its relationship to include internal audit – a capability that is in the process of being implemented. “We want to be able to conduct any kind of audit, track results, manage issues and report through the solution.” The company conducts more than 1,000 audits a year globally, and expects “to have an even broader impact with this implementation.” A key benefit for the company ? The ability to link internal audit to the risk and control libraries already in place for SOX compliance, “so we can pick up SOX and regular audit issues as well.” Additionally, the company is confident that the new solution is “going to improve our reporting and our efficiency.”
Diverse Supplier Compliance
The company has also expanded the Riskonnect solution to help it manage Supplier Diversity compliance. “This is another complex project. It’s challenging to track requirements, monitor contracts and ensure timely and accurate reporting.”
“But this is what Riskonnect was built for – effective reporting and dashboarding.”
Even beyond what Riskonnect is providing on its integrated risk management platform, the company is building its own capabilities on that foundation as well. The company built a monitoring system for inventory exception reporting in the U.S. which enables it to run analytics on inventory turns and values monthly at its thousands of locations around the world. The solution features continuous monitoring with trigger-based notifications.
The company has realized “substantial savings” in its first year of using the Riskonnect solution for SOX compliance. The need for external support has been reduced dramatically, control testing is now more flexible and can fit around relevant staff schedules, and the solution gives the company the ability to plan more efficiently resulting in a material reduction in the cost of compliance.
“Year over year, we have been able to reduce our costs over 30% while at the same time increasing our scope.”
And those status reports and meetings? One person now spends less than 100 hours annually, including top-level audit committee reporting. And those reports are now able to be created and distributed far more frequently: bi-weekly instead of the previous bi-monthly. Key to the company across all of its Riskonnect solutions is the focus on actionable analytics over vanity metrics.
“Analytics is a hot topic, but the key benefit is being able to follow up on those results. Riskonnect is a tool that allows you to easily follow up, resolve and close out exceptions that are identified through process and analytics. It’s not just about fancy tools.”
Take Riskonnect for a Test Drive
Discover why we're the leaders in Integrated Risk Management by scheduling a demo today!