Instead it is lawyers and accountants working for these big auditing companies.
GDPR is good but the absolute insanity of how GDPR is being applied cannot be understated.
161–170 of 303 posts
Instead it is lawyers and accountants working for these big auditing companies.
GDPR is good but the absolute insanity of how GDPR is being applied cannot be understated.
Earlier quoted context omitted.
Audit results are taken very seriously by companies operating in heavily regulated industries that intend to stay in business, so healthcare, finance, insurance etc. If you are a team lead doing programming for one of these sorts of companies and the auditors come round with some findings, I promise you that you need to take it deadly seriously. I've seen engineers fired for cause by the board of directors of a fortu…
What does "failing to do so" look like most times, if you don't mind me asking?
It means delaying or coming up with excuses for why you can't have security concerns remediated within the agreed upon time frame. Regardless of the technical challenges involved.
Audit remediations are not the kind of projects where delays are acceptable. You absolutely must drop everything else you've got going on in those situations if you even remotely get a hint that the project might be behind.
The reason here is that your boss and your bosses' boss can't save you. If bad audit results come back you can bet the C suite had an emergency meeting discussing how to explain them to the board and the timeframe for getting them fixed. And you can bet they made some sort of commitment.
There are hundreds of millions to billions of dollars on the line in insurance premiums and future legal process in some cases. Oftentimes cyber insurance will mandate some kind of timeframe for remediation upon notification of a security issue. So you'll get hit with penalties well before the next audit if you delay. You don't want to be the programmer(s) that missed a deadline there.
Earlier quoted context omitted.
I mean, fair, but when even the Americans are saying to let the investors lose their shirts, you might want to at least think about it.
This isn't about investors, it's about creditors.
Though, I don't think the distinction really matters within the context of my point. Both investors and creditors are exchanging money for a bet on future profit derived from the company being solvent in the future and having extra money to either pay back debts or pay out dividends.
My point is that America tends to get a lot of flak for rigging the system in favor of those with excess money (some of it is even fair). My point is that if you want to structure your system past what we're willing to do, you may want to stop and think for a second about if that's what you really want.
Now, if you want to protect the money of people with extra money to lend out, that's absolutely fine. It's a completely internally consistent position. But my understanding is that it's not that popular of a position, so I'm surprised the system is set up this way.
> Auditors insist that their services cannot be treated as a guarantee that accounts are truthful, and note that sophisticated frauds are by their nature difficult to spot. As someone who knows nothing about this area, I don't understand why audits won't always detect fraud. I would naively assume that auditors have access to all financial accounts and records of cash flows and they make sure they all add up and are…
The vast majority of auditors are only 3 year or less years out of school. They don't even know how a corporation is run at that point, so how are they supposed to catch anything suspicious.
Earlier quoted context omitted.
My partner works at one of these big four companies and the way she puts it - they essentially function as outsourced expertise for governments the world over - essentially expert functions have been hollowed out of state governments and into the private sector and thus there is really no expertise within the national government level to handle complex tax and accounting situations and they are instead all outsourced…
Yeah but then the experts at the big 4 are 23 year old grads with no experience. I don't get it.
Earlier quoted context omitted.
This article is about auditing, your comments appear to be about consulting / advisory businesses. Otherwise, I mostly agree, though I don't support a ban. It's a complex topic - companies are free to waste money how they want, and even governments do need real advice. It's just too bad they pick such shitty advisors to support decisions they've already made instead of actually seeking good advice.
Yes, companies should be free to waste their money as they want. However, auditors serve a purpose and that is to identify any fraudulent activities. In the case of Wirecard, EY failed at this.
OTOH, the monetary penalties where a bit on the light side so maybe that also balances out the rather harsh ban.
> Auditors insist that their services cannot be treated as a guarantee that accounts are truthful, and note that sophisticated frauds are by their nature difficult to spot. As someone who knows nothing about this area, I don't understand why audits won't always detect fraud. I would naively assume that auditors have access to all financial accounts and records of cash flows and they make sure they all add up and are…
There are different types of audit. I expect that EY does not have access to numbers and any account information. You give away as least information as you can because you cannot just trust auditing team from some 3rd party not to use that data in collusion with your competitors. What I expect they do have access to is documentation for procedures and processes. They audit for example if all procedures are written do…
I think it's even worse: the shift manager checks list to see if the toilet is clean, but they don't actually look at the toilet.
Also, from a dynamics perspective, this is a lot like the insurance industry. In the insurance industry you can underestimate risk during the good times, take profits, and then go bankrupt in the bad times. In auditing you can spend a lot of money being extremely thorough - you'll lose all your customers because you're expensive and painful. So instead you lower your standards, you're cheap, you're easy to work with, and it's easy for a fraudster to slip through, in the 1 in a 1000 chance that happens the regulator comes down on you like a tonne of bricks. Well ok, but was EY less competent than McKinsey or did they just get unlucky that they're the poor bastards who stepped on the landmine?
Well, maybe in this case we should learn from the insurance industry and institute some sort of fund that all auditors pay into that pays out in the case that fraud is discovered.
Earlier quoted context omitted.
They are "professional scapegoats" IMO, companies pay them to take the blame and their business model seems to be: collect fees, do an "audit", pay the fine, keep the spread.
No. This is nonsense. You audit accounts that are falsified and give thumbs up: you close shop, are held liable for damages and could go to prison. Auditing companies are crucially important for a working economy. Bank loans, bonds, equity markets would all be chaos and fraud mayhem without them.
We might as well turn "audits" over to the short sellers like Hindenburg Research, at least they make money by exposing rotten accounts rather than hiding them.
The fact that being an activist short seller has become a business model in the last ~8 years tell you how bad the likes of EY are.
Earlier quoted context omitted.
This isn't about investors, it's about creditors.
Also fair, I used the wrong word there. Though, I don't think the distinction really matters within the context of my point. Both investors and creditors are exchanging money for a bet on future profit derived from the company being solvent in the future and having extra money to either pay back debts or pay out dividends. My point is that America tends to get a lot of flak for rigging the system in favor of those wi…
Nope, that's still just investors.
Creditors are not people who made bets on the company's future profits. Creditors are people who the company made legally binding contracts with to pay them. For example people who provided products and services who are getting stiffed. Also: taxes due.
Even a bank loan is not a bet on the company's future profits. A bank loan is a contract that says you will repay the money lent, with interest. Irrespective of profitability.
Which is why a limited liability company usually can't get credit unless it is also guaranteed by someone else. Because with no outside guarantees, it would be a bet. (Yes, convertible bonds exist, but different topic).