Well, hello everyone, and thank you for attending today's webinar where we are going to do a case study around digital transformation for SOX internal audit and compliance. My name is Ernest Anunciacion. I'm going to be your host and moderator today. Before we get started, I do want to cover off on a few housekeeping items. At the bottom of your screen, you're going to see multiple application engagement tools for your disposal. All of these are going to enable you to resize and move some of the windows around, so feel free to play around with that and maximize the amount of space that you have on your desktop. You can also expand the slide area to maximize it to full screen by clicking on the arrows in the top right corner.
If you have any questions throughout this presentation today, submit them through that Q&A engagement tool on the bottom left side of your screen. We're going to try and get to as many of these as we can throughout the presentation, but if a more robust and fuller answer is required or if we run out of time, we'll be sure to email you those responses at a later date. So, please note that we are capturing all of your questions. Now, for those of you who are looking to receive CPE credit for today, note that we are going to ask you four CPE multiple choice questions throughout the presentation. Receiving that credit is going to be dependent upon submitting at least three answers to four of those questions, as well as attending the full duration.
If you're watching this in a group, it's highly advised that you sign in or log in individually so that you are ensuring that you're going to get that credit. The questions will appear within the slide window, and there's going to be a limited amount of time. We want to make sure that everybody has ample time to submit answers to those questions, so just be ready for when those questions appear. Once you've met those CPE requirements, your certificate will be available via download in the CPE certificate engagement tool on the screen. We'll also send it in a post-event email. Unfortunately, if you have any technology issues and you're disconnected from the presentation, or if there's anything else that happens that prevents you from qualifying, we're not able to issue that CPE, as well as if you miss those polling questions.
Again, want to reiterate to be on alert for those. Finally, when you do have a moment, there are some survey questions on the right side of the screen there of the presentation. If there are more than five questions, you may need to scroll down. Let's be sure to provide that feedback. So, let's go ahead and jump into our introduction. Once again, I'm Ernest Anunciacion. I'm part of our product marketing team here at Workiva. I've been with the company for a little over four and a half years now, and I come away after being a practitioner in the space of audit risk and compliance. I was a former Chief Audit Executive. I've worked with a number of GRC tools in the past. I've done everything from Sarbanes-Oxley, internal controls, enterprise risk management, and public accounting.
With me today, I am joined by a couple of gentlemen and scholars who are going to take us through that journey of digital transformation. I'll turn it over to Bill here from Clearview Group. Bill, do you want to do a quick introduction to the audience here?
Sure. Thank you, Ernest, and thank you everyone for joining us today. My name's Bill Hatcher. I'm a Senior Manager with Clearview Group, and also serve as the president of the Northern Virginia chapter of the Institute of Internal Auditors. I spend a lot of my time in the world that Ernest described of internal audit, Sarbanes-Oxley, and IT advisory services. I have about 13 years of experience there on the professional services side. Just like a quick tidbit about how Clearview fits into today's case study. Clearview offers full service of consulting services, including fully outsourced and co-sourced engagements for SOX compliance. It was really through those fully outsourced SOX compliance engagements that we were looking for a tool that could help us facilitate the process from end to end for our clients.
From documentation requests and collection, to testing, to handoff to the external auditors. So, we went through a very similar kind of requirements exercise that Robert will describe in just a moment. We came across Workiva as the tool that worked best for us. Once we really got comfortable in the tool, it seemed logical that we should provide that same offering to our clients. We became certified implementation partners with Workiva, where we not only use the tool for our own fully outsourced engagements, but we also helped implement the tool for our clients that either perform the SOX engagements themselves or had us in a co-source capacity. Look forward to talking through more of that implementation process with you all, and thanks for joining us today.
Thanks for that, Bill. The man of the hour here, the man, the myth, the legend, Robert Schmollinger. Would you like to do a quick introduction for the audience?
Yeah, sure, Ernest. Thanks. I'm Robert Schmollinger. I am got 25 years of experience working with governance, risk, and controls. Most recently, I led the internal audit function at a global software company and partnered with Workiva and Clearview to implement the Wdesk tool to basically enhance and finalize our transformation effort at my former employer. So, that's the story we're going to be telling today. With that, I think we have a polling question before we get started.
The first polling question.
What organizational function? Oh, sorry about that.
Go right ahead. Yeah, you got to love these live ones. Go right ahead, Bill. Go ahead with the question.
Yeah. What organizational function do you represent?
As we give folks a few seconds here. Whether you're part of internal audit, compliance, enterprise risk management, external audit, go ahead and submit your polling questions there, and I think we've captured just about all of them. Let's go ahead and shift gears now and talk about the agenda for today's presentation. We started off with the introductions. We'll give you a little bit of an overview right now in terms of the landscape that we're seeing from kind of a risk management perspective. Then from there, we'll shift gears into the case study, where Robert will talk about his implementation at that software company, not just from a technology standpoint, but also the process fixes and then the consultation that Clearview was able to provide.
We're going to get into the latter part of our presentation, which we'll cover off on what the implementation process looks like, and Bill will go into details of the different phases involved there. Obviously, with any presentation, we'll wrap it up at the end with questions and answers. First section for today, the digital transformation overview. Robert, do you want to give a high-level talk track around what we're seeing within the market and how that complexity and the risk landscape looks today?
Yeah. I'll give the historical perspective. As I stepped into the role in 2016 at my former employer, we were looking at a complete redesign of the internal audit function, and I was looking that to go through and make changes to both people, process, and tools, all three of them. When I got there, the function itself was separate from the Sarbanes-Oxley program management office, which was separate from the enterprise risk management process, which was actually managed by our legal department. There was no connection with our process owners who were actually executing the accounting transactions within the organization and creating the evidence that my team eventually would test for compliance reasons for SOX or for internal audit purposes. In addition, you layer in the emerging risks of GDPR in 2016.
The new rev rec standard, ASC 606, had not yet been implemented, and it had a huge impact on our company as a software development and sales company. Then, you also had all the existing risks that go into just the day-to-day operations. We were going through that, and in addition, the company specifically was looking to transition from an on-prem software that was managed by the clients to a cloud-based solution and become a software-as-a-service, SaaS tool, that would be managed out of the cloud. When you do those types of things and you're getting ready to make those types of changes, you increase a number of risks, specifically the cybersecurity risk around your client data and how you manage that and make sure it's protected.
So, that's what I faced when I stepped into the role in 2016, and my first order of business was to go through and assess my people. We started looking at process and tools. Once I had the team that I wanted, I then started looking at different tools to support how we wanted to execute and the process that we wanted to put into place. We went through an evaluation process, landed on the Workiva Wdesk tool as the one that was the best fit for our organization. I don't know if you want to add a little bit more color around the risk profiles that you're seeing in the broader market, we were definitely facing some very specific risks. GDPR was emerging. The new rev rec standard was going to have a big impact on us.
Oh, by the way, we were changing the way we were doing business. It was a very stable, well-managed organization, and we had no issues at the time.
Yeah. Robert, you bring up some of those things from a regulatory standpoint. You know, that environment is always under scrutiny, and obviously, organizations are under the microscope. But then, you take into consideration other external factors that may not have been part of your risk assessment originally. Let's rewind back. When we first did this presentation back in January, as Bill mentioned, he's the president of the Northern Virginia chapter. That was pre-COVID, and so, the conversation around what some of those externalities look like has fundamentally changed drastically over that course of time.
When you think about some of the initiatives that you had internally, and then you factor in all of the other things that are happening in the outside world, whether it is new accounting regulations, if it's new mandates and compliance laws that are coming into place, I think the kicker there is that risk landscape is so complex. For organizations who are looking to streamline their processes, looking to get ahead of risk, starting off, like you said, with first your people, then getting into your process and tools, that's something that we've seen quite a bit within the industry in terms of a framework to get into more operational excellence and efficiencies.
One of the other things that we want to highlight here with the audience is when you think about the impact of a certain risk, whether it be something catastrophic or something that makes headline news, we want to quantify that impact, what it means, not just in terms of dollars and cents to the organization or shareholder valuations, but there's also a reputational element there. So, we pulled a few of the headlines that have come out from newspapers over the past year and a half here, just to give the gravity and the scope, the depth and the breadth of what companies are facing in this time. Robert, any thoughts in terms of what we've seen in these headlines? Ultimately, I think as a former CAE, one of our missions is to stay out of the newspapers.
Yeah. I think reputation risk is something that more and more boards and audit committees are starting to factor into their considerations when it comes to how they want to manage the overall, I guess, portfolio of risk. They're really worried about when their name gets dragged into the headlines in a negative way. I know that there's the saying that there's no such thing as bad publicity, but I think if you ask Wells Fargo and some of the other folks who have had compliance issues in the recent past, I think they would argue with that. From a specificity perspective for the entity that we were working with, we actually had two items that acted as trigger points for our executives and audit committee.
One was an issue with some inappropriate behavior by a subsidiary in Latin America, and we ended up having to do a fairly extensive investigation into the business operations in our Brazilian subsidiary. Then, in 2018, we went through the SOX evaluation and ended up identifying a material weakness within our internal control framework. When we came out of that material weakness at the end of 2018, I had gotten everybody's attention and had a tremendous amount of support to go through and work with you guys and with Clearview to make the process work better, and that was the final push that tipped my audit committee to go ahead and approve the implementation and spending the money to bring Wdesk into the organization. That, again, you hate to see negative things be the reason for why you do it.
But unfortunately, I think that's where we end up a lot of times is you got to get your hand slapped or get yourself in some trouble before you're going to take action. It's unfortunate, hopefully those of you that are on the webcast today can persuade your audit committees and executives to maybe take action before something negative happens.
Yeah. Too many times do we become victim of being more reactive versus proactive. There's nothing quite as a forcing function like having an ethics violation or a fraud investigation, you know, headline news like this, or even a material weakness or a control deficiency coming up in your financial statements, right? I think one of the biggest challenges today when we look back at that risk landscape and the complexity of it, that is the fact. Right? Managing that risk in today's environment is complicated, and we've seen a lot of strategic priorities and organizational objectives being forced to shift in ways that people have never imagined before. Even looking at those fundamental business models are being forced to innovate.
Based on some data that we have gathered through multiple surveys, a lot of teams feel like they're focusing way too much time on efforts on things that don't necessarily add that value to the organization. When you think about gathering data to support your testing or evidence, babysitting document requests, or perhaps even doing the wrong audits, going back to the whole COVID and the global pandemic, how many of us had something that massive on your risk assessments? I think the worst part about it today is that the tools that people are using have failed to change with those times. There's this latent source of discontent with the technologies that are currently available today. You don't get visibility into the information that you need in order to become trusted business advisors.
So, Robert, I think you had a great example there where, look, you got the audit committee's attention, and this became a priority for what you were doing at that company. I'm interested though, Robert, you know, we like to talk about universal process challenges. Does this look familiar to you at all?
Oh, yeah. When you think about the different systems and processes that I inherited when I got to this organization, it was something that made my head spin when I started trying to figure out where data sources were, what was the source of truth? The most frustrating thing that I've had was when we would go through and my team would execute a set of tests against the data that were provided to us by the process owners, and we'd get through our test, and then the process owners would sheepishly come to us and say, "Oh, I'm sorry. I gave you the wrong schedule.
Okay
Kind of, okay, well, that's a couple of hours worth of work down the drain. Then we basically had to redo everything and you know, it's one of those things that as an audit leader, you want to pull your hair out. I think the other thing is, you also have to worry about when you have questions about the authenticity and the data sources, then you've got to worry about, well, how much trust and confidence do the process owners have in the data that they're using on a day-to-day basis.
One thing that I really, I think we'll talk a little bit about benefits on the back half of the presentation, but one of the things that was really good for us as a team was we started closing things down so that if we had a single source, it would populate throughout the tool, and we didn't have to worry about whether or not somebody had gone back in and updated a RACM because, or I'm sorry, a risk and control matrix, because we had made a change on a process document within one of the individual process flows. Those types of things were also very frustrating internally, and those were self-inflicted wounds because we were using SharePoint and Excel and Word for all of the documentation for the SOX processes and controls.
You'd have these great Visio flow charts, these narratives that were written up in Word. You'd have flow charts that were in Visio, and then your risk and control matrix was in an Excel document. Well, none of those things were connected, every time you made a change, you'd have to go through and make sure that all the other documents that were attached to wherever you made the change, that they were updated and updated appropriately. It was very time-consuming, back to your point, where instead of doing analysis and evaluating controls, my team was spending a lot of time making sure that our documentation was in sync across three or four different platforms of software. That was extremely frustrating when we first got into the organization and started trying to make things more efficient and better.
So again, this is one of those things where I think that inefficiency is difficult to articulate in a way that resolves in dollars and cents. Once we had the new tool, it was very easy to show the CFO and the audit committee what we were doing, because we had the tool, and now that we didn't have to herd the cats of documentation, we were able to be more efficient and bring more work to the table and do more analysis, do more in-depth analysis around controls, which added value to the organization. It's really hard to sit there and put a dollar sign in front of that when you're not doing it.
Theoretically, I knew that we were spending a lot of time keeping all the documentation in sync, but it was difficult to quantify, and that's one of those things that I think anyone who wants to go down this journey should definitely think about how much work are you doing to keep all of your Microsoft documentation in sync. Even if you've got a good tool like SharePoint to keep it housed and secure and version-controlled, it's still difficult to make sure that the change you make in a process narrative flows through to the flow chart appropriately and the risk and control matrix, and ultimately to your testing documentation.
Yeah, Robert.
Oh, go ahead, Bill.
I would just add to what you said that I think some of those efficiencies we gained actually led to more quality, too, because there's not hesitation to make updates when they're available. I think in some cases, maybe additional information is available, but there could be hesitation that I don't want to add that to the narrative because then I'll have to add it to the RCM, and it's not out of laziness. It's out of wanting to focus where your time counts the most. So, I think that the linked data that we'll talk about is really not just efficiencies, but also contributes to quality in the documentation.
That's a great segue when we talk about those disconnected processes, the disconnected documents and data within the system. It really leads to these unintended consequences. Whether it's introducing more risk or perhaps creating inefficiencies, not only to the teams involved, but the company as a whole, this ties back to some of the challenges of managing that risk landscape that we talked about earlier. Let's get into our second polling question here for the audience. This question is, which of the following best describes your role? And so you see the four options there. We'll give people a little bit of time to enter whether you're a Staff or Senior, perhaps you're at that Manager or Senior Manager level, Director or Senior Director, or VP and above. We'll give a few seconds here before we get into the next part of our presentation.
Bill, are you clicking? Stop clicking. We got to give people the ample time to get their poll questions out there. You might be on mute.
Thanks, Ernest. I was submitting my answer.
There you go. Okay, let's get into the next portion, and we're going to change it up just a little bit here and do a panel discussion. We're going to throw some questions over to Robert that folks are interested in. When we talk about this digital transformation, what did it really entail? We're getting in some of the weeds. Robert did a great job of laying the foundation and the history and the genesis for the project, but let's get into and put some meat on the bones here. So first question here, Robert, talk a little bit more about what the previous risk management environment looked like for that company that you mentioned earlier. What was the current state at that point in time before you went into the digital transformation initiative?
Right. When I landed at the organization, there was a separate risk assessment process that was being done by the internal audit function to come up with their internal audit plan for the year. There was a SOX risk assessment that was done to help drive and prioritize the work within the compliance program, the SOX compliance program. Then there was a third enterprise risk assessment process that was done that was managed by the legal department that looked at broader, more strategic risks, but also got into some of the more tactical risks that the internal audit function was looking at. Unfortunately, there wasn't cohesive and collaboration between the three business units. So you might have internal audit risk ranking something as being a lower risk, where the enterprise risk management team might have come back with it as being a higher risk.
You also had some discrepancies between the way the financial team was looking at the SOX risk and the way the internal audit function was looking at it. It definitely created some confusion amongst the stakeholders in the organization. They were wondering why did internal audit say that this wasn't a high risk, but yet it's being tested for SOX purposes? Why were the enterprise risk management folks looking at something and asking for a risk management plan when internal audit has said that they weren't going to include it on their annual audit plan for the year? So those types of things were certainly, again, causing confusion within the organization and really diminishing the value that people saw from all three of the different groups and the risk assessments that they were doing.
One of the first process changes that I was able to work through within the organization was to sync all of those up, and ultimately, I became the person, and my internal audit team was solely responsible for the risk assessment process in the organization. We used a top-down where we started with an enterprise risk approach, and then slowly peeled the onion back until we got to very specific financial statement risks that drove the Sarbanes-Oxley compliance program, but also helped direct the other internal audit efforts for the year outside of Sarbanes-Oxley. That was, I think, a big win. It took us about 18 months-24 months to get there, but that was a big win from when I landed in 2016.
That's great. I think following up on that then, Robert, what was the impetus for embarking on digital transformation? Why digital transformation, what were some of the requirements that fed into the initiative?
Well, like I said before, when I stepped into the role, we had basically separate tools for the internal audit team, for the Sarbanes-Oxley team, for the enterprise risk management team. We also had our process owners and the stakeholders within our finance and accounting function who were housing their data in a completely separate and different location as well. There was definitely some crossed wires because of all the differences in the tools that were being used. The other thing, and we talked about that a little bit as well, that even within the internal audit function, the tools that we were using to collect and use as our evidence for our testing and our work, it was Microsoft products. Hold on, I got to stop. My cat is trying to get in the room. These are great things to do live.
Hopefully, we can cut that out. All right.
You got to love COVID.
Yeah. Anyway, the idea was that even within the internal audit team, we had tools that were not synced up. So, we were using Microsoft Office products like Word and Excel, Visio, and if you made a change in one, you'd have to manually go through and make changes in others. Quite honestly, in 2016 and 2017, when we were talking about this, that didn't make a whole lot of sense to me, given the fact that the Wdesk tool was out there were other tools that were out there where you could make a change once and it would flow through the rest of the documentation. That to me was a big effort.
The other thing is from a time of a speed to get things done, if we could create a process where we could get electronic data into our testing tools and we didn't have to wait on our stakeholders and the process owners to push that data over to us, A, that would make it quicker, and then B, we could also, we had a little bit more confidence that the data we were pulling was the data that we wanted, and that when we conducted our tests and conducted our work, that there was going to be a good outcome on that work. As far as the requirements go, given that landscape where I wanted to see a change made once flew through the documentation, where I wanted my stakeholders to be able to access and potentially become more of the owners of the process documentation.
One aspect that I haven't talked about was the fact that the SOX program management office, which was really just one person with some contract help during busy times, that program management office became the de facto owner for process documentation. What we had on a number of occasions were stakeholders who were actually executing the processes, who started to get irritated because the documentation the auditors were using to evaluate the controls were out of date and hadn't been updated. It wasn't any one person's fault, it was just the fact that it just wasn't clear as to who was responsible to make sure that those documents were updated. So, because nobody was responsible, no one did it. The other requirement I wanted was to make sure that people who were executing the processes, those stakeholders, they would have access to the documentation.
They would have the ability to go in and make conditional changes to documentation, and then my team in the internal audit, they could go through and evaluate those changes, make sure that they were appropriate, that they met the appropriate criteria for control objectives and risk mitigation factors, and essentially act as quality assurance around the documentation. That was another key factor for us. The other thing was ease of use. My team, the background, most of them had never used an audit management tool before. I had had previous experience with Wdesk and a couple of others in other assignments and with other clients when I was doing consulting work. I knew what we were getting into, but my team was fairly naive around what they were going to be doing and how to use those tools.
I wanted something that they felt comfortable with and felt like it made sense to them, and it made sense with the process and the approach that we were taking to both our internal audit work as well as our Sarbanes-Oxley work. Those were kind of the key requirements. The last thing that we were trying to determine was, how do we show that there was going to be value? That's one where Again, it's difficult to put a dollar and cents. What I didn't want to say is, "Hey, if I implement this tool, I'll be able to reduce my head count by X." To me, that's not one of the benefits of implementing an audit management tool.
Really, what I want is my team to be able to do better analysis, get deeper into the processes because they don't have to do as much of the busy work to determine that the work is good and that the testing is sufficient and appropriate. So I think, I'm not sure if I got all the requirements, Ernest, but I think those were the keys and the highlights.
Could I add one for you, Robert?
Unfortunately, I didn't memorize my requirement document from when we did the initial approach a couple of years ago.
I bet you Bill remembers it. What's up, Bill?
Yeah. Robert, I recall, I know your company had a large global footprint, so a lot of users in different locations, and I think that becomes even more relevant in the current pandemic environment. So, just wondered if you could expound on that a little bit.
Yeah. Bill, thanks. This is why you partner, right? Somebody's always reminding you of something you might have forgotten.
Charging for it.
Sure, that's a great point, Bill. That's a great point.
That'll be $5.
Because we had locations in Europe, Asia, Latin America, as well as North America, where we had accounting functions, where there were Sarbanes-Oxley key controls being executed, and having a tool that was easily accessible, not only by my team when they're in those locations, but by those process owners and those stakeholders that were in those foreign locations, yeah, that made life very, very easy, especially when we went to the COVID shutdown earlier this year, and we had to all work remotely. My team had already been doing that for almost a year, and our stakeholders had already been using the tool in that manner for almost a year.
It's a great benefit, but it was one that I think we knew that we wanted to have it, but I don't think we knew how good it was until we got to March and April of this year.
Absolutely. All right, guys, I think in the interest of time, let's get into the next polling question because I know Bill is itching to go through the implementation process. So, question number three for the audience is, what function does your internal audit team report into? You got some options here. Does it report into the CFO/controller? Is it the Chief Compliance Officer or a compliance function? Is it the CIO or somewhere within IT? Is it directly into the CEO, or is it other? We understand most organizations have the internal audit team directly reporting into the audit committee chair and the audit committee. This is not a trick question. We mean more of the dotted line functionality or administrative function into the organization. We'll give you a few seconds here to input your questions for this polling question.
I would say, who does your CAE's performance review at the end of the year or whenever you guys do them?
That's a much more eloquent way of asking.
Yeah. I've never had an audit committee chair provide me a performance review, and I've had three CAE roles.
I actually had an audit committee chair provide input into my performance review, and that was pretty interesting to get that feedback. But yeah, most people don't get that.
Yeah. The feedback, yes, but never directly sitting down with me and saying, "Okay, you got a five, Robert, because you were excellent this year.
You got to ask for it sometimes, Robert. All right. I think that's enough time there. Hopefully, everybody submitted their answers. Let's get into the next part of our presentation, where we will go through the implementation process. Bill, why don't you walk us through some of the milestones, and then we'll get into each of the phases as we go on here.
Sure. Thank you, Ernest. Robert, you can keep me honest, too, if anything comes to mind that I don't mention as we go. But this first slide is just showing an overview of the different implementation milestones that we'll talk through. When we do these projects, we try to divide them into four distinct phases. The kickoff is really our time to meet your team and understand your control environment, perform some discovery there, so we know how many controls, how many locations, who are we going to work with as far as the testers, the control owners, and just getting a feel for the landscape. We dive right into the project setup, so implementing the database, understanding the kind of reporting that the CAE and other stakeholders are going to want out of the system.
I think in that phase, it was really powerful in Robert's case study, especially, where we were able to generate metrics for the audit committee directly out of the system so that we weren't always having to put pencils down and pivot to Excel spreadsheets and tabulate our status and put it into a PowerPoint. Anyways, we got to a point that you could really go from work product to reporting instantly, and that's the kind of power that we want to unlock here. The third phase is training, so training not just the internal audit team, but also the users that are going to be providing PBCs. A really nice thing about Workiva is they have a Wdesk University, which automates a lot of that training, but it's not just static training.
It actually has interactive case studies that you can go in and attach a PBC and make sure you understand where to actually click. That, I think, is very powerful. Then we do some, obviously, UAT and troubleshooting, because maybe the way it's designed out of the box is not the way Robert and team wanted it to work, and we're able to manipulate some things and customize it to the user. The last phase is really just getting started in the tool. As with anything, it's an ongoing world. So, we at some point do hand off some of the administrative tasks to the customer success manager at Workiva. The customer success manager is with us, though, throughout the implementation. I know, Robert, you knew our point person, Laura, by first name and had her email, and I think that relationship worked really well.
Throughout the whole project, there's ongoing weekly status meetings, ongoing communication of where we are in the plan. The idea is that there are no surprises, and that we can get the tool up and running the way the customer wants. It's not just an out-of-the-box upload your RCM and you're done. That last part is the overview. Yep.
Yeah. Bill, I was just going to say, if handle this implementation like you would any other system implementation. Use some rigor. But I want to say, we took approximately six weeks, maybe even less than that, from basically getting the contract signed and everything finalized through our legal, which we'll talk about in a second, to actually having the system up and running and ready to go. If you've got a plan, you've got some rigor around it definitely makes it a lot easier. I would not advocate that you go in and try to iterate by just dropping the system, flipping the switch on and figuring out how you're going to go. One of the other benefits, and I'll let you get to your next slide, because I think in that next slide, we talk a little bit about the kickoff phase and the discovery phase.
That was a great piece for my team because it really challenged us as far as the status quo and what were we doing from a SOX perspective. I think we should be explicit. We implemented the SOX piece to the Wdesk tool first, we're talking a little bit about when we have these conversations right now, it's essentially the all around our Sarbanes-Oxley process. Anyway, this kickoff and discovery phase really helped us challenge our status quo.
Great. Thanks, Robert. You mentioned the kickoff and discovery slide that we'll cover here. I think really you covered some of the big points here, that a typical implementation takes us about six weeks to 10 weeks. Like we said before, there can still be iterations on that work product. That's usually about the amount of time from kickoff to actually working in the tool. In that process, you also want to consider your different stakeholders and get them involved at the right points in time. It may be often they'll roll it out in a couple of phases. First, you get your audit team up and running and familiar with the tool before you start inviting other stakeholders in, just so that when they come with questions and want that first-hand experience, you're up and running there.
We have this example project plan, but we definitely sit down and customize that to understand any timeline dependencies that the client has.
Yeah. Bill, I would add that getting that stakeholder involvement, so your global controller, your CFO, the different directors, the folks that are actually doing the work within the accounting team, making sure that you're familiarizing them with the tool, and you just don't drop it on their heads when you're done and expect them to be able to work with it. I think that was a key for us as well, is we did a good job of making sure that we communicated with non-internal audit stakeholders and making sure that they got their input into the system.
Yep. On the next slide with the project set up data assessment. Really what we're talking about here is the concept of good data versus bad data. Oftentimes in Excel, you can get away with fields that haven't been normalized and maybe don't have data validation controls. But part of the setting up the environment in Wdesk, where it really empowers linked data and being able to use these references from your process documentation to your control documentation to your exception reporting, is getting all that information standardized. When I say that, I mean using the same nomenclature is a good example. Does a control pass or fail, or is it ineffective or effective? Just locking in on that standard verbiology. Also, it's defining those meaningful relationships between the data. I know in Robert's environment, we mentioned that they had a global footprint, multi-location.
Sometimes you had one process that operated in multiple locations. Sometimes you had multiple locations operated in one process. We were really able to sit down with him and his team and unlock those relationships and streamline the data. I think I just want to stress there that this isn't just taking your current environment and putting it into the tool. I think what I'd like to brag a little bit for our team, I think what we were able to do, because we worked hand in hand with Robert's team as a co-source partner, is we were able to really rationalize the control environment and say, "Hey, this one risk, now that we've got all the data in, this one risk is mapped to six key controls." Is that appropriate?
Should we tailor these risks so they're a little more specific, or maybe can we rationalize some of these controls as non-key? We were able to achieve a lot of efficiencies by sitting down, and this was a good opportunity to perform that thought process.
Yeah, Bill. So, from the earlier comment about challenging the status quo, it was in phase II where we really got down to brass tacks and determined what key controls we wanted to assess and evaluate. We were able to reduce the number of key controls in our environment from somewhere around 250, closer to 200, and really narrow our testing to a much more focused and, I think, better set of key controls for financial statement purposes.
Yep. I'd agree. I think, Robert, further to that, a lesson we learned here is when you're implementing the SOX compliance tool, to the extent possible, it's best to implement in that Q1, Q2 area before all the walkthroughs start and a lot of the changes start flowing in and the testing's in process. I think it really allows you to take a step back and spend time with those kinds of considerations. When you're in the heat of battle of testing, it can still be done, but just best practice-wise, I think that early part of the year, if you're a 12/31 year-end, would be the best time to sit down and go through this process.
Absolutely. Unfortunately, we had some issues with our legal department and some privacy issues around the tool. When I talk about getting stakeholders involved early, I would recommend to everyone that you talk to your data privacy owners and champions and make sure that they're comfortable because you are going to have some data that's in the tool, and you want to make sure that you've got all your bases covered there. We were able to get over it, but it took us a little bit longer than we thought, and unfortunately, that pushed us on our calendar, and we were implementing at the same time we were doing walkthroughs, which I would certainly not recommend to anybody.
Yeah. We got through it. I agree. This next slide on the project setup, data import, and field test, don't want to exhaust the details on this slide, but really it's showing the five different segments of information within the tool. So, you have your data, which is really your RCM and your process narratives and flows. It's where you keep the information itself. The reports can become very powerful when you tailor them to, like I mentioned before, specific audit committee needs and what the Chief Audit Executive cares most about. A lot of times that's making sure we know number of controls by phase and what the status is as far as tested and what's in the review queue and what's been provided to external audit. All of that can be automated at the touch of a button.
Then, you have your testing tab, which really organizes the test records. It makes sure you have all the fields that you want to track for your test, so sample methodology, sample size. Some of that can be automated so that if you select an annual control, it automatically fills out some of the other fields saying we're going to test one sample. The dashboards are very powerful. The dashboards are tailored to each individual user, and you can go in and see at any given time, these are the tasks in my to-do list. Robert, I know when it got into that heavy review season and you and I were passing work papers back and forth, that those dashboards were really helpful to sit down.
When you finally got a quiet hour to sit down and say, "What all's in my queue?" At the touch of a button, you could see exactly what controls were waiting for you. I mentioned.
Yeah.
Yeah. Go ahead, Robert.
I was just going to say, Bill, pre-COVID, that was awesome because if I had a team in Europe, they could get their work done, and I'd be reviewing their work papers in the afternoon in Virginia or on the East Coast, and they would come in first thing in the morning, and all my comments would be there for them, and they'd be able to knock them out before I'd get into the office in the following morning. So yeah, it's great to be able to just see exactly what you need to look at from a review perspective.
Right. If you're providing review comments, you can use the @ symbol to tag an individual team member to the comment. If Robert maybe was reviewing a person's work paper, but he wanted input from his director of internal audit, he could tag her, and she would get a notification saying, "Come look at this." For better or worse, it even can send you email notifications to your phone when Robert's reviewing your work papers. It's a very powerful collaborative tool. Then on the project setup report development slide, Robert, I think this would be a good one for you to speak to, but I mentioned just the ability to tailor these reports to the organization.
For some organizations, maybe you want your status by location, maybe you want it by test phase, maybe you want all those views, and maybe your audit committee is interested in the 10,000-foot view. I know audit committees are interested in progress by control count. Robert, maybe you could add some color here, but I think we were able to get to some very powerful reporting metrics out of the tool.
Yeah. Bill, so the reporting tools within Wdesk allow you to tailor it. I would put together. We had information that we had for the CFO. We had information that we had for the global controller and her direct reports. The other thing, our organization, the software that we developed was business intelligence software. Internally, we used our own tool to do a lot of the management reporting, and Wdesk was flexible enough to create an API where we could push the data into our internal management tool and then create dashboards for our executives using our internal management process. Again, the reporting tools within Wdesk are great, and we use some of those, but it also has enough flexibility that you can create whatever you need within your own organization with APIs and other integrations.
Yeah. I personally found that invaluable as a manager on engagement when you get that question, where are we on testing? Suddenly all the activities you had planned for the afternoon, you need to stop and put the pencils down and understand where everyone is. Wdesk enables you, like Robert said early on, to focus on the job that's providing the most value and not necessarily always that kind of retrospective. Once we got that up and running, I feel like we really turned a corner on efficiencies.
Yeah. It was not nearly as onerous to do that analysis as it had been in the past, right?
Right
You had a very quick visual picture that popped up and said, "Here's the testing by status. Here's where individual testers are with the work assigned to them." You could drill down into it. It made life much easier from my perspective as the leader, to be able to see the forest and the trees.
Right. Yeah. We could just focus on really the dependencies, the critical path, and the issues. So, I think that was a great output. On phase III training, I think we already spoke to most of this, but upfront, you have Workiva University, which is an online self-service interactive training, and that gets you, I'd say, 75% of the way there. Then between our implementation team and the ongoing support from the customer success managers, you definitely get to the 110% of the user. I think, Ernest, that's probably all I wanted to cover on the training, unless, Ernest, did you want to add anything on the customer success manager roles?
One of the things that we pride ourselves on as a company is the service levels that we provide to our customers. You mentioned that CSM, or customer success manager, really becomes an extension of our customers' teams. I've gotten feedback in the past where they've said, "I don't know if Lindsay works for our company or if they work for Workiva." Definitely take advantage of them and service, in terms of not just questions that can be asked, and they serve as a first point of contact, whether it be on new features that are coming out, if it is help with building documentation or setting up a data model. It's one area we can't overemphasize enough.
Awesome.
Yeah.
The last slide is.
Tremendous amount of value in the CSMs and all the way around, you guys did a great job working together and making sure that we got through the process.
Yep. The last phase is really just getting started. Go ahead, Ernest.
Yeah, no. Why don't you cover off on this last slide here, Bill?
Yeah. It's really just the handoff. So now we give you the keys to drive, and part of that is making sure you've established the right admin roles so that you can grant permissions to your users appropriate to their duties. As any kind of SOX compliance person, we all know the story there. It's establishing those ongoing admins. We were able to create really a frictionless experience at Robert's former employer, which enabled single sign-on. Wdesk, no one wants another user ID and password to remember. Part of getting their company on board, one of the requirements that was a must-have was single sign-on capabilities, and we were able to roll that out. That was really it, Ernest, was just getting it out to the stakeholders and then you're still there as a CSM to provide support if there are any issues.
Thanks for letting me walk through that.
I appreciate that, Bill. Let's get to our final CPE question here. We've been talking a lot about technology. We're interested to learn more about the primary tools that your organization uses to support the compliance and internal audit process. Three options there. Are you still using desktop applications like Microsoft Office, maybe some Google Docs? Perhaps you have a point solution software like MKinsight or TeamMate, or the last option there being a broader GRC application. Give you guys a few seconds here as you're putting your answers in. As that's going on, I do want to thank Bill from Clearview and Robert for providing the context here. I think it's a tremendous story when you think about the three legs of this stool.
You have a company that has some pain points and some challenges that they've highlighted, looking to change their people, process, and technology. You have a consulting firm like Clearview with a number of their clients in similar industries and best practices, working with a technology company such as Workiva to help really fortify and streamline a digital transformation overview. I'll open it up. Any other parting comments, because I know we're running over time. We won't be able to get to all the questions here or any of the questions, so we'll follow up via email. Bill, Robert, any other last comments here before we wrap up?
Bill, you go first.
Don't be shy. Come on, guys.
Just thanking you guys for the opportunity, and like Ernest said, we're available if you have any questions. I know we didn't get into the tool itself very much, so if you ever want to see a demo there, we're glad to do that or provide examples of the kinds of dashboards or test plans that are enabled within Wdesk. Thank you all.
I would just like to add that, as auditors, we're being challenged all the time to be more efficient and to get to more things. If you're still using, whether it's Microsoft Office, Google Docs, non-audit management tools to try and manage your function, you certainly should explore the audit tool world and find something that allows you to automate the process. We were able to find efficiencies that really allowed my team to dig deeper and do better analysis and become better auditors. While I had mentioned earlier that you can't necessarily put a price tag on that, they certainly are stronger and we're doing more valuable work for our organization. So again, I strongly advocate that if you are still using the early 21st-century tools, that you start looking for something that's a little bit newer and more automated.
Thanks for that. Again, guys, thank you very much to Bill and to Robert. Apologies to Mike Rost, but we are all out of time here. For any of the questions that you did submit, and appreciate everybody that did, we will respond via email. If you have any more questions, get them in there in the engagement tool, and we'll be happy to respond. Finally, for the CPE credit, for those of you who qualified, you can download that certificate now in the engagement tool. We'll also send that as a post-event email that you'll receive later today. Thanks everyone for attending, and stay classy, humanoids.