Posted by Mark Brousseau
Multi-function printers (MFPs) – devices that can print, fax, copy and scan documents – continue to experience tremendous growth, Daniel Schmidt, product marketing manager, Kofax, told attendees at Kofax Transform 2011 Americas this morning in San Diego.
Schmidt cited statistics from IDC that the MFP market grew by 18 and 22 percent last year, representing a total market of 13 million MFP devices, compared to just 800,000 document scanners.
Despite this tremendous growth, most organizations have an opportunity to further reduce their operations costs by leveraging and extending MFPs as part of their business processes, Schmidt said.
Realizing these costs savings, Schmidt said, are as easy as 1-2-3:
1. Consolidate control of MFPs.
2. Leverage MFPs for distributed scanning.
3. Integrate MFPs into a scan-to-process initiative.
Consolidate
At most organizations, MFPs are fax-enabled via individual telephone lines, Roman Swoboda, vice president, business communications, Kofax told attendees. In cases where a company has thousands of deployed MFPs – possibly across the globe – this means thousands of individual telephone lines.
Swoboda said this type of MFP deployment creates a number of issues, including the tremendous costs associated with the individual phone lines (a single line costs up to $500, Swoboda noted), the lack of document tracking and archival, and the limited security over who can send faxes and where.
“A better approach is to connect the MFPs to a centralized infrastructure where faxes are sent in a consolidated and very structured way,” Swoboda said. This offers a number of advantages, including improved tracking and compliance, lower costs (fewer “trunk lines”), and the ability to leverage a consolidated platform. One company that consolidated its MFP infrastructure was able to eliminate up to two-thirds of its analog lines, delivering payback in six to eight months, Swoboda said.
Optimize
Another opportunity for improving MFP deployments is to extend the process to create searchable PDFs, as well as documents that can be archived. Schmidt suggested companies scan documents in remote offices and send them to a central archive. This reduces the costs of transporting documents between locations, eliminates the opportunity for lost document, improves information security, and enables the end-user to leverage all of the benefits of data capture, including bar code recognition.
Integrate
To maximize their MFP deployments, organizations should integrate the devices with their business processes. Schmidt said this approach can reduce processing time from days to minutes, in turn, providing more timely information that can enhance customer service. It also lowers processing costs, including labor and shipping costs; creates an audit trail for tracking documents end-to-end and improving compliance efforts; and improves security, providing complete document control.
What do you think?
Showing posts with label compliance. Show all posts
Showing posts with label compliance. Show all posts
Monday, January 17, 2011
Friday, November 12, 2010
The Top 5 Compliance Issues That Smolder Beneath The Surface
By Dan Wilhelms
When firefighters arrive at a burning building, their first priority (of course) is to knock down the visible flames. Yet experienced firefighters know that when those flames are extinguished, the job isn’t done yet. That’s the time they go in and start looking for the hidden flames – the smoldering materials in a ceiling or behind a wall that could suddenly erupt and engulf them when they’re not expecting it. They know those hidden fires can be the most dangerous of all simply because they can’t be seen until it’s too late.
For the past few years, IT and compliance managers have been like those firefighters first arriving on the scene. You’ve been putting out the compliance fires – the big issues that have been burning brightly since SOX legislation was passed in the early part of the millennium. You’ve done a good job too, creating a new compliance structure where roles are defined, segregation of duties (SOD) is the standard and transactions are well-documented.
Yet just like those firefighters, the job isn’t finished yet. There are still all kinds of compliance issues that, while not as visible as the first ones you tackled, can still create a back-draft that will burn your organization if you’re not careful. Following are five of the most pressing (and potentially dangerous).
Excessive access – With the complexity of the security architecture that is part of modern ERP systems, it’s easier than you might think to accidentally give some users access to potentially sensitive transactions that might be far outside their job descriptions. Access is usually assigned by the help desk, and in the heat of battle, with many pressing issues, they may not be as careful about assigning or double-checking authorizations as they should be. When that occurs, it can lead to all types of dangers.
Imagine a parts picker in the warehouse being given access to every SAP transaction in the organization (which has happened, by the way). In that instance, the warehouse worker started running and looking at transactions (including financial transactions) just out of curiosity. But what if he’d had a different agenda? He could have changed the data, either accidentally or maliciously, or executed a fraudulent transaction, creating a serious compliance breech.
Even if he didn’t change anything, there’s still a productivity issue. After all, if he’s busy running a myriad of SAP transactions, he’s not busy picking orders.
Excessive access is not the type of issue that will show up in a SOD report. The best way to address it is by installing governance, risk and compliance (GRC) software that makes managing security and authorization easier. The software should also provide you with tools that help you measure and monitor actual system usage so you can see whether the things users are doing and the places they’re going within the system are appropriate to their job requirements. Having automated systems in place is particularly important in smaller enterprises that usually do not have the resources for a lot of manual inspection.
Access to sensitive data – Users don’t necessarily need access to a broad variety of data to pose a risk; they just need access to particular data. For example who can open and close posting periods. Who can view HR salary and benefits information? Again, this is nothing that is likely to show up on a SOD report, yet it’s a very real risk.
We’ve all heard the stories about how a certain soft drink manufacturer’s formula is better-guarded than the launch codes for nuclear weapons. Imagine if the formula was sitting on the ERP system and the wrong person was given access to it – or given access to payroll, HIPAA or other sensitive information.
One key to controlling access to sensitive data, of course, is to exercise more care when assigning authorizations. This is called preventative controls. It’s also important to use reverse business engineering tools to see who does have access to sensitive transactions, whether that access is appropriate, and what they did with the information once they had it. This is called detective controls. It’s like following the smoke to discover where the hidden fire is.
Poor segregation of duties – Although SOD has already been mentioned, some organizations are not familiar with what it is and its purpose. Let’s look at the nuclear missiles analogy again. In order to launch, there are two keys controlled by two different people. Two keys are used to assure that no one person has control of the missiles in case someone decides to “go rogue.”
It’s the same with financial transactions in an enterprise. You don’t want one person to be able to create a vendor in your SAP system and then initiate payment of that same vendor; you’re just asking people to steal from you.
That’s why it’s important to have value-added tools that analyze user access against the enterprise’s SOD rulebook and flag any conflicting functions. An ongoing analysis will point out any areas of risk so they can be remediated, and keep you informed should the situation change.
Of course, in a smaller organization, conflicting duties may not be avoidable. Everyone is expected to wear multiple hats, and sometimes those hats do not allow for proper segregation. In those instances, you need to have tools that can monitor actual transactions and report against them so you can see if a compliance violation is occurring. In other words, if someone has to carry both keys, you know when they’ve inserted them both into the control panel through mitigating controls.
Even with the proper tools, it’s unlikely you’ll ever bring SOD conflicts down to zero. But you can get awfully darned close, and keep an eye on what happens from there.
Introduction of malicious programs into production systems – The modern reality is that ERP systems are rarely steady state. Often enterprises have multiple initiatives going on that introduce new data, configuration and programs into the production systems.
With lean staffing and urgent deadlines, often changes are not properly tested or audited. In other words, they don’t use proper change management. A developer who has the means to do it, the motive to do it and knows whether he/she can get away with it can wreak all kinds of havoc by including malicious code along with legitimate code when new applications are moved into production. Malicious code can download sensitive data, create fraudulent transactions, delete data or crash the systems.
It is critical to have a second person reviewing any changes at every step of the way. What that means is the person who requests the change can’t be the person who develops it; the developer can’t be the person who tests it; the person who tests it can’t be the same person who migrates it into production. In other words, transport development and approvals cannot be given by a single person – instead, an independent approver or even a committee must be controlling the entire process.
Change management duties need to be segregated and managed throughout the entire process. Even if not malicious, poorly coded, untested programs can result in a catastrophic outage. Given that in a large enterprise an hour of downtime can cost $1 million, it’s easy to see why proper change management is worth the investment.
Emergency access – In large ERP environments, there’s always the chance that emergency maintenance of production systems will need to be performed. When it does, and the enterprise is dialing 9-1-1, someone needs to be given emergency “super user” access to everything in the system. Such emergency maintenance is often by outside parties (e.g. the software vender or 3rd party consultants).
The problem is these emergency all-access passes aren’t always tracked very well. Everyone is so fixed on putting out the fire – for example unlocking a sales order that has frozen the entire system – that they never think about documenting what transactions were performed or what data was changed. The risk is increased by the widespread use of generic “firefighter” user IDs whereby the individual performing the actions isn’t definitively known.
You’d like to think that the person you give super user access to can be trusted. But blind trust is what has gotten other enterprises into trouble in the past. The person with full access may make other changes while he/she is in there – either accidentally or on purpose. You need to be able to monitor who has all-access and what they do while they have it.
It is critical to have tools that allow you to track what these super-users do while they’re in the system. Not just for the day-to-day operation of the business, but for the auditors as well. When auditors see someone has been given this additional emergency access, their job is to immediately assume the person did something nefarious. It will be your job to prove they didn’t. You’ll need to show why access was granted, what was done while the person was in there, when/how long the person was in the system, what changes were made and when the person exited.
While it’s important to put out the big compliance blazes, keep in mind those are the ones that are also easy to see. Once they’re under control, take a tip from the professional firefighters and be sure to check for the smaller, smoldering flashpoints. It’s your best insurance against getting burned.
Dan Wilhelms is President and CEO of SymSoft Corporation (www.controlpanelGRC.com, the makers of ControlPanelGRC, professional solutions for compliance automation. He can be reached at dwilhelms@sym-corp.com.
When firefighters arrive at a burning building, their first priority (of course) is to knock down the visible flames. Yet experienced firefighters know that when those flames are extinguished, the job isn’t done yet. That’s the time they go in and start looking for the hidden flames – the smoldering materials in a ceiling or behind a wall that could suddenly erupt and engulf them when they’re not expecting it. They know those hidden fires can be the most dangerous of all simply because they can’t be seen until it’s too late.
For the past few years, IT and compliance managers have been like those firefighters first arriving on the scene. You’ve been putting out the compliance fires – the big issues that have been burning brightly since SOX legislation was passed in the early part of the millennium. You’ve done a good job too, creating a new compliance structure where roles are defined, segregation of duties (SOD) is the standard and transactions are well-documented.
Yet just like those firefighters, the job isn’t finished yet. There are still all kinds of compliance issues that, while not as visible as the first ones you tackled, can still create a back-draft that will burn your organization if you’re not careful. Following are five of the most pressing (and potentially dangerous).
Excessive access – With the complexity of the security architecture that is part of modern ERP systems, it’s easier than you might think to accidentally give some users access to potentially sensitive transactions that might be far outside their job descriptions. Access is usually assigned by the help desk, and in the heat of battle, with many pressing issues, they may not be as careful about assigning or double-checking authorizations as they should be. When that occurs, it can lead to all types of dangers.
Imagine a parts picker in the warehouse being given access to every SAP transaction in the organization (which has happened, by the way). In that instance, the warehouse worker started running and looking at transactions (including financial transactions) just out of curiosity. But what if he’d had a different agenda? He could have changed the data, either accidentally or maliciously, or executed a fraudulent transaction, creating a serious compliance breech.
Even if he didn’t change anything, there’s still a productivity issue. After all, if he’s busy running a myriad of SAP transactions, he’s not busy picking orders.
Excessive access is not the type of issue that will show up in a SOD report. The best way to address it is by installing governance, risk and compliance (GRC) software that makes managing security and authorization easier. The software should also provide you with tools that help you measure and monitor actual system usage so you can see whether the things users are doing and the places they’re going within the system are appropriate to their job requirements. Having automated systems in place is particularly important in smaller enterprises that usually do not have the resources for a lot of manual inspection.
Access to sensitive data – Users don’t necessarily need access to a broad variety of data to pose a risk; they just need access to particular data. For example who can open and close posting periods. Who can view HR salary and benefits information? Again, this is nothing that is likely to show up on a SOD report, yet it’s a very real risk.
We’ve all heard the stories about how a certain soft drink manufacturer’s formula is better-guarded than the launch codes for nuclear weapons. Imagine if the formula was sitting on the ERP system and the wrong person was given access to it – or given access to payroll, HIPAA or other sensitive information.
One key to controlling access to sensitive data, of course, is to exercise more care when assigning authorizations. This is called preventative controls. It’s also important to use reverse business engineering tools to see who does have access to sensitive transactions, whether that access is appropriate, and what they did with the information once they had it. This is called detective controls. It’s like following the smoke to discover where the hidden fire is.
Poor segregation of duties – Although SOD has already been mentioned, some organizations are not familiar with what it is and its purpose. Let’s look at the nuclear missiles analogy again. In order to launch, there are two keys controlled by two different people. Two keys are used to assure that no one person has control of the missiles in case someone decides to “go rogue.”
It’s the same with financial transactions in an enterprise. You don’t want one person to be able to create a vendor in your SAP system and then initiate payment of that same vendor; you’re just asking people to steal from you.
That’s why it’s important to have value-added tools that analyze user access against the enterprise’s SOD rulebook and flag any conflicting functions. An ongoing analysis will point out any areas of risk so they can be remediated, and keep you informed should the situation change.
Of course, in a smaller organization, conflicting duties may not be avoidable. Everyone is expected to wear multiple hats, and sometimes those hats do not allow for proper segregation. In those instances, you need to have tools that can monitor actual transactions and report against them so you can see if a compliance violation is occurring. In other words, if someone has to carry both keys, you know when they’ve inserted them both into the control panel through mitigating controls.
Even with the proper tools, it’s unlikely you’ll ever bring SOD conflicts down to zero. But you can get awfully darned close, and keep an eye on what happens from there.
Introduction of malicious programs into production systems – The modern reality is that ERP systems are rarely steady state. Often enterprises have multiple initiatives going on that introduce new data, configuration and programs into the production systems.
With lean staffing and urgent deadlines, often changes are not properly tested or audited. In other words, they don’t use proper change management. A developer who has the means to do it, the motive to do it and knows whether he/she can get away with it can wreak all kinds of havoc by including malicious code along with legitimate code when new applications are moved into production. Malicious code can download sensitive data, create fraudulent transactions, delete data or crash the systems.
It is critical to have a second person reviewing any changes at every step of the way. What that means is the person who requests the change can’t be the person who develops it; the developer can’t be the person who tests it; the person who tests it can’t be the same person who migrates it into production. In other words, transport development and approvals cannot be given by a single person – instead, an independent approver or even a committee must be controlling the entire process.
Change management duties need to be segregated and managed throughout the entire process. Even if not malicious, poorly coded, untested programs can result in a catastrophic outage. Given that in a large enterprise an hour of downtime can cost $1 million, it’s easy to see why proper change management is worth the investment.
Emergency access – In large ERP environments, there’s always the chance that emergency maintenance of production systems will need to be performed. When it does, and the enterprise is dialing 9-1-1, someone needs to be given emergency “super user” access to everything in the system. Such emergency maintenance is often by outside parties (e.g. the software vender or 3rd party consultants).
The problem is these emergency all-access passes aren’t always tracked very well. Everyone is so fixed on putting out the fire – for example unlocking a sales order that has frozen the entire system – that they never think about documenting what transactions were performed or what data was changed. The risk is increased by the widespread use of generic “firefighter” user IDs whereby the individual performing the actions isn’t definitively known.
You’d like to think that the person you give super user access to can be trusted. But blind trust is what has gotten other enterprises into trouble in the past. The person with full access may make other changes while he/she is in there – either accidentally or on purpose. You need to be able to monitor who has all-access and what they do while they have it.
It is critical to have tools that allow you to track what these super-users do while they’re in the system. Not just for the day-to-day operation of the business, but for the auditors as well. When auditors see someone has been given this additional emergency access, their job is to immediately assume the person did something nefarious. It will be your job to prove they didn’t. You’ll need to show why access was granted, what was done while the person was in there, when/how long the person was in the system, what changes were made and when the person exited.
While it’s important to put out the big compliance blazes, keep in mind those are the ones that are also easy to see. Once they’re under control, take a tip from the professional firefighters and be sure to check for the smaller, smoldering flashpoints. It’s your best insurance against getting burned.
Dan Wilhelms is President and CEO of SymSoft Corporation (www.controlpanelGRC.com, the makers of ControlPanelGRC, professional solutions for compliance automation. He can be reached at dwilhelms@sym-corp.com.
Sunday, November 7, 2010
SharePoint and eDiscovery Readiness
Posted by Mark Brousseau
When it comes to eDiscovery readiness, getting involved in their organization’s SharePoint initiatives should be a top priority for records managers, Martin Tuip, senior technical product marketing manager, Iron Mountain Digital, said during a presentation today at the ARMA Annual Conference in San Francisco.
SharePoint broke the $1 billion revenue mark last year, and has continued to rise past that total this year, making it the hottest-selling server-side product ever for Microsoft, Tuip said, adding that many organizations are planning to deploy SharePoint 2010 or have already done so.
“But the problem at many organizations is that SharePoint initiatives are being driven by IT, without much involvement from records managers. IT and records managers need each other,” Tuip said. “All of the content in SharePoint might have to retained, depending on your business.”
“From a legal perspective, eventually you will have a matter that will require information out of SharePoint. Those lawsuits will eventually come,” Tuip predicted. “Export functionality is available in SharePoint, but in an extremely limited fashion.” Records managers need to be proactive about working with their IT team to prepare for these inevitable eDiscovery actions, Tuip explained.
“You know that this is coming down the line,” Tuip said.
The first step in implementing SharePoint governance, Tuip said, is to determine what is going to be a vital record for your organization. Then get IT involved in setting the governance standards and determining how to implement them. Organizations can leverage their existing infrastructure to provide for seamless retention of SharePoint content, or “pick a new product that can assist with all of your retention concerns,” Tuip said. He warned that, “eDiscovery is risky. The problem with eDiscovery is that content hides in multiple places. That’s why organizations need an eDiscovery application that provides comprehensive enterprise-wide search queries of the most requested ESI types. A proper eDiscovery application can significantly reduce the collection time associated with lawsuits.”
Tuip concluded: “I love SharePoint. I think that it’s a phenomenal solution. But records managers need to understand that it doesn’t have eDiscovery capabilities, and they’ll have to work with IT to determine how to deal with that.”
What do you think?
When it comes to eDiscovery readiness, getting involved in their organization’s SharePoint initiatives should be a top priority for records managers, Martin Tuip, senior technical product marketing manager, Iron Mountain Digital, said during a presentation today at the ARMA Annual Conference in San Francisco.
SharePoint broke the $1 billion revenue mark last year, and has continued to rise past that total this year, making it the hottest-selling server-side product ever for Microsoft, Tuip said, adding that many organizations are planning to deploy SharePoint 2010 or have already done so.
“But the problem at many organizations is that SharePoint initiatives are being driven by IT, without much involvement from records managers. IT and records managers need each other,” Tuip said. “All of the content in SharePoint might have to retained, depending on your business.”
“From a legal perspective, eventually you will have a matter that will require information out of SharePoint. Those lawsuits will eventually come,” Tuip predicted. “Export functionality is available in SharePoint, but in an extremely limited fashion.” Records managers need to be proactive about working with their IT team to prepare for these inevitable eDiscovery actions, Tuip explained.
“You know that this is coming down the line,” Tuip said.
The first step in implementing SharePoint governance, Tuip said, is to determine what is going to be a vital record for your organization. Then get IT involved in setting the governance standards and determining how to implement them. Organizations can leverage their existing infrastructure to provide for seamless retention of SharePoint content, or “pick a new product that can assist with all of your retention concerns,” Tuip said. He warned that, “eDiscovery is risky. The problem with eDiscovery is that content hides in multiple places. That’s why organizations need an eDiscovery application that provides comprehensive enterprise-wide search queries of the most requested ESI types. A proper eDiscovery application can significantly reduce the collection time associated with lawsuits.”
Tuip concluded: “I love SharePoint. I think that it’s a phenomenal solution. But records managers need to understand that it doesn’t have eDiscovery capabilities, and they’ll have to work with IT to determine how to deal with that.”
What do you think?
Monday, July 12, 2010
Economic risks of data overload
By Ed Pearce (epearce@egisticsinc.com) of eGistics (www.eGisticsinc.com)
When data pours in by the millisecond and the mountain of information builds continuously, professionals inevitably cut corners and go with their 'gut' when making decisions that can impact financial markets, medical treatments or any number of time sensitive matters, according to a new study from Thomson Reuters. The study indicates that when faced with unsorted, unverified "raw" data, 60 percent of decision-makers will make "intuitive" decisions that can lead to poor outcomes.
Many government regulators have flagged increased financial risk-taking, which can be traced in some degree to imperfectly managed data, as a contributor to the recent financial crisis. Moreover, the world is awash with data -- roughly 800 exabytes -- and the velocity of information is increasing, Thomson Reuters says.
The challenge is that the staffing and investment needed to ensure that information and information channels are trusted, reliable and useful is not keeping pace. In fact, it is estimated that the information universe will increase by a factor of 44; the number of managed files by a factor of 67; storage by a factor of 30 but staffing and investment in careful management by a factor of 1.4.
"The solution to data overload is to provide decision makers with what Thomson Reuters calls Intelligent Information: better organized and structured information, rapidly conveyed to the users preferred device," says David Craig, executive vice president and chief strategy officer.
Fortunately, as the Thomson Reuters study notes, the same technological revolution that has resulted in the explosion of information also opens the way to new and improved tools for providing intelligent information: better organized and structured information, rapidly conveyed to the user's preferred device.
"We must use the benefits of the information technology revolution to minimize its risks. This is a joint task that the private sector and governments must closely focus on if we are to avoid systemic crises, in the future, whether we speak of finance, healthcare delivery, international security and a myriad of other areas," comments Craig.
How is your organization managing information overload?
When data pours in by the millisecond and the mountain of information builds continuously, professionals inevitably cut corners and go with their 'gut' when making decisions that can impact financial markets, medical treatments or any number of time sensitive matters, according to a new study from Thomson Reuters. The study indicates that when faced with unsorted, unverified "raw" data, 60 percent of decision-makers will make "intuitive" decisions that can lead to poor outcomes.
Many government regulators have flagged increased financial risk-taking, which can be traced in some degree to imperfectly managed data, as a contributor to the recent financial crisis. Moreover, the world is awash with data -- roughly 800 exabytes -- and the velocity of information is increasing, Thomson Reuters says.
The challenge is that the staffing and investment needed to ensure that information and information channels are trusted, reliable and useful is not keeping pace. In fact, it is estimated that the information universe will increase by a factor of 44; the number of managed files by a factor of 67; storage by a factor of 30 but staffing and investment in careful management by a factor of 1.4.
"The solution to data overload is to provide decision makers with what Thomson Reuters calls Intelligent Information: better organized and structured information, rapidly conveyed to the users preferred device," says David Craig, executive vice president and chief strategy officer.
Fortunately, as the Thomson Reuters study notes, the same technological revolution that has resulted in the explosion of information also opens the way to new and improved tools for providing intelligent information: better organized and structured information, rapidly conveyed to the user's preferred device.
"We must use the benefits of the information technology revolution to minimize its risks. This is a joint task that the private sector and governments must closely focus on if we are to avoid systemic crises, in the future, whether we speak of finance, healthcare delivery, international security and a myriad of other areas," comments Craig.
How is your organization managing information overload?
Saturday, February 20, 2010
Compliance and Outsourcing
By Mark Brousseau
While new compliance, security and privacy regulations are likely to take a bigger bite out of operations budgets this year, most organizations believe they can meet the stricter rules without having to outsource their payments and document processing. Just 20 percent of respondents to a recent TAWPI Question of the Week said new compliance, security and privacy regulations would force their organization to consider outsourcing. Sixty-five percent of respondents said the tougher regulations wouldn't force them to consider, and 15 percent of respondents said they weren't sure.
The time and cost associated with meeting compliance, security and privacy regulations continues to rise -- giving pause to any company entrusted with sensitive data that must be stored and shared.
"Regulatory compliance is very expensive and extremely time-consuming," says R. Edwin Pearce (epearce@egisticsinc.com), executive vice president of sales and corporate development for eGistics, Inc. "Companies have two choices for meeting regulatory demands for privacy and security: assume the full expense of the resources and time associated with meeting each regulation, or work with an outsource provider that can spread the costs of meeting the regulations across its customer base."
Pearce also believes that organizations should ask themselves whether it makes sense to go through the cost and trouble of becoming compliant, when there are outsource providers that already are.
"Companies don't necessarily have to absorb the full capital burden of meeting various certification and compliancy tests," Pearce explains. "For example, organizations that store images and data for multiple years may have to meet PCI, SAS 70 and HIPAA regulations. Rather than engineer a data center environment that meets all of these requirements -- including policy and procedural standards -- it may make better sense for the organization to partner with a compliant outsource provider."
"The result is faster compliance, at a significantly lower cost," Pearce adds.
With new regulations on the horizon, this is a decision more organizations will have to make.
What do you think?
While new compliance, security and privacy regulations are likely to take a bigger bite out of operations budgets this year, most organizations believe they can meet the stricter rules without having to outsource their payments and document processing. Just 20 percent of respondents to a recent TAWPI Question of the Week said new compliance, security and privacy regulations would force their organization to consider outsourcing. Sixty-five percent of respondents said the tougher regulations wouldn't force them to consider, and 15 percent of respondents said they weren't sure.
The time and cost associated with meeting compliance, security and privacy regulations continues to rise -- giving pause to any company entrusted with sensitive data that must be stored and shared.
"Regulatory compliance is very expensive and extremely time-consuming," says R. Edwin Pearce (epearce@egisticsinc.com), executive vice president of sales and corporate development for eGistics, Inc. "Companies have two choices for meeting regulatory demands for privacy and security: assume the full expense of the resources and time associated with meeting each regulation, or work with an outsource provider that can spread the costs of meeting the regulations across its customer base."
Pearce also believes that organizations should ask themselves whether it makes sense to go through the cost and trouble of becoming compliant, when there are outsource providers that already are.
"Companies don't necessarily have to absorb the full capital burden of meeting various certification and compliancy tests," Pearce explains. "For example, organizations that store images and data for multiple years may have to meet PCI, SAS 70 and HIPAA regulations. Rather than engineer a data center environment that meets all of these requirements -- including policy and procedural standards -- it may make better sense for the organization to partner with a compliant outsource provider."
"The result is faster compliance, at a significantly lower cost," Pearce adds.
With new regulations on the horizon, this is a decision more organizations will have to make.
What do you think?
Labels:
compliance,
computer security,
data privacy,
Ed Pearce,
eGistics,
HIPAA,
hosted solutions,
Mark Brousseau,
outsourcing,
PCI,
SaaS,
SAS 70,
TAWPI
Wednesday, January 13, 2010
Growing Data Center Challenges
Posted by Mark Brousseau
Data center managers could be facing even more pressure. R. Edwin Pearce (epearce@egisticsinc.com), executive vice president of sales and corporate development for eGistics, Inc. (www.egisticsinc.com), explains:
Just when data center and IT managers assumed things couldn’t get any worse, along comes a report from Gartner predicting that the critical issues facing data centers – namely, technology, space and energy challenges – will worsen in 2010. Coupled with the tremendous cost pressures brought on by the economic downturn, the Gartner report should provide a heightened sense of urgency for data center and IT managers looking for pragmatic ways in which to deal with their operations issues.
In its report, Gartner provides several tips for helping reduce data center costs:
• Eliminate those systems that are underutilized or old
• Consolidate multiple sites
• Better manage energy and facilities costs
• Better manage people costs
• Delay the procurement of new assets
To be sure, these are all sound strategies. But savvy data center managers already have implemented (or at least considered) these strategies in response to the economic downturn. In other words, most data centers may have already squeezed as much savings as possible from their infrastructure.
Responding to the data center challenges that Gartner predicts requires a different approach.
Hosted Archive and Delivery
A better strategy is to leverage a hosted image and data archive to address today’s today data center challenges. Able to support images and data from any source, in virtually any format, a hosted archive provides authorized users with access to business information, anytime and anywhere via the Internet. Further, hosted archive solutions can integrate easily into an organization’s existing operations and IT environment, underlying a heterogeneous applications infrastructure.
Assuming companies partner with a provider that leverages redundant Tier 1 state-of-the-art facilities using national communications firms, hosted solutions offer other benefits compared to in-house:
Totally Variable Expense – Hosted archive solutions require no capital investment; customers typically are charged a one-time load fee to add documents. And when an array fills up, or a server must be replaced, it’s the hosted archive vendor’s problem.
Improved Compliance and Security – No one can argue the alphabet soup of stiffer regulatory requirements to control information. Leveraging a hosted redundant archive solution allows companies to offload much of this burden on their vendor. To address the compliance and security issues a vendor must use facilities that are SAS-70 I and II certified, HIPAA compliant, provide audit trails on all activity, and puts stringent controls on access.
Solution Flexibility –Hosted archive solutions vendors already are adept in providing services for multiple applications, processes and document types, and with distributed environments. Most vendors also have the ability to deliver tailored solutions that an internal IT department may not have the expertise to develop. Similarly, hosted solutions can be rapidly installed, and applications quickly added.
Scalability – The performance of in-house archives deteriorates with high volumes and the addition of applications. But there are hosted solutions that archive tens of billions of documents – growing by hundreds of millions per month – with no negative impact. What’s more, the ability to scale hosted archive load rates depending on needs opens unprecedented opportunities for companies who need scalability and availability during times of peak demand, but also need to keep their costs low.
Guaranteed Performance – By virtue of their redundancy and automatic failover, most hosted solutions providers will offer service level agreements (SLAs) guaranteeing 99.999 percent availability – or just 26 minutes of downtime per year. That’s piece of mind.
This all adds up to a comprehensive solution that can help organizations meet worsening data center challenges, while laying a solid foundation that can improve corporate agility and enhance service.
What do you think? Post your comments below.
Data center managers could be facing even more pressure. R. Edwin Pearce (epearce@egisticsinc.com), executive vice president of sales and corporate development for eGistics, Inc. (www.egisticsinc.com), explains:
Just when data center and IT managers assumed things couldn’t get any worse, along comes a report from Gartner predicting that the critical issues facing data centers – namely, technology, space and energy challenges – will worsen in 2010. Coupled with the tremendous cost pressures brought on by the economic downturn, the Gartner report should provide a heightened sense of urgency for data center and IT managers looking for pragmatic ways in which to deal with their operations issues.
In its report, Gartner provides several tips for helping reduce data center costs:
• Eliminate those systems that are underutilized or old
• Consolidate multiple sites
• Better manage energy and facilities costs
• Better manage people costs
• Delay the procurement of new assets
To be sure, these are all sound strategies. But savvy data center managers already have implemented (or at least considered) these strategies in response to the economic downturn. In other words, most data centers may have already squeezed as much savings as possible from their infrastructure.
Responding to the data center challenges that Gartner predicts requires a different approach.
Hosted Archive and Delivery
A better strategy is to leverage a hosted image and data archive to address today’s today data center challenges. Able to support images and data from any source, in virtually any format, a hosted archive provides authorized users with access to business information, anytime and anywhere via the Internet. Further, hosted archive solutions can integrate easily into an organization’s existing operations and IT environment, underlying a heterogeneous applications infrastructure.
Assuming companies partner with a provider that leverages redundant Tier 1 state-of-the-art facilities using national communications firms, hosted solutions offer other benefits compared to in-house:
Totally Variable Expense – Hosted archive solutions require no capital investment; customers typically are charged a one-time load fee to add documents. And when an array fills up, or a server must be replaced, it’s the hosted archive vendor’s problem.
Improved Compliance and Security – No one can argue the alphabet soup of stiffer regulatory requirements to control information. Leveraging a hosted redundant archive solution allows companies to offload much of this burden on their vendor. To address the compliance and security issues a vendor must use facilities that are SAS-70 I and II certified, HIPAA compliant, provide audit trails on all activity, and puts stringent controls on access.
Solution Flexibility –Hosted archive solutions vendors already are adept in providing services for multiple applications, processes and document types, and with distributed environments. Most vendors also have the ability to deliver tailored solutions that an internal IT department may not have the expertise to develop. Similarly, hosted solutions can be rapidly installed, and applications quickly added.
Scalability – The performance of in-house archives deteriorates with high volumes and the addition of applications. But there are hosted solutions that archive tens of billions of documents – growing by hundreds of millions per month – with no negative impact. What’s more, the ability to scale hosted archive load rates depending on needs opens unprecedented opportunities for companies who need scalability and availability during times of peak demand, but also need to keep their costs low.
Guaranteed Performance – By virtue of their redundancy and automatic failover, most hosted solutions providers will offer service level agreements (SLAs) guaranteeing 99.999 percent availability – or just 26 minutes of downtime per year. That’s piece of mind.
This all adds up to a comprehensive solution that can help organizations meet worsening data center challenges, while laying a solid foundation that can improve corporate agility and enhance service.
What do you think? Post your comments below.
Labels:
archive,
compliance,
data center,
eGistics,
Mark Brousseau,
PCI compliance,
TAWPI
Tuesday, November 17, 2009
California Fast-Tracks Healthcare EDI
Posted by Mark Brousseau
California regulations for electronic workers' compensation billing slated for publication before end of this year are likely to see fast-tracked implementation, according to Jopari Solutions, a supplier of medical EDI connectivity and transmission for the property and casualty industry.
EBilling is a key initiative the California Insurance Commissioner and Division of Workers' Compensation officials say is essential, along with other benchmark recommendations, to streamline the state's workers' compensation system, rein in medical costs and keep employer costs down. This past week, the Commissioner rejected any recommended increase in California's workers' compensation pure premium rate.
California's eBill regulations will specify an 18-month phase-in period for workers' compensation payers to acquire the ability to process eBill transactions, after regulations get signed into law. n addition, California is adopting uniform electronic claim and remittance standards similar to those mandated in Texas and Minnesota, which are supported by national standards organizations.
Facilitating rapid transition by carriers is the fact that national and regional health care provider networks are eager to expand electronic bill submissions with payers into their California markets. A large percentage of local health care practices today also exchange electronic health insurance claims, payments and remittance, or have medical transaction ready EDI billing software. Compressed timely payment deadline for clean electronic bills under California eBill rules - fifteen days as opposed to forty-five days for uncontested paper bills - is another factor expected to put early pressure on carriers by their medical services trading partners.
As Jopari CEO JR "Steve" Stevens and veteran industry observer Peter Rousmaniere point out in a new whitepaper, The E-billing Transformation, the community of beneficiaries from the switch to electronic transmission of bills and supporting documentation, or attachments, goes beyond state agencies pushing for administrative simplification, better data and more stakeholder accountability. Stevens and Rousmaniere indicate, "Conventional transmission methods, heavily dependent on mail, faxing and scanning, impose delays and error rates which leading medical bill review firms estimate as upwards of 20 percent or more. Electronic submission largely sweeps away these defects." They explain that, "Claims payers should therefore approach e-billing not simply as a way of shaving the burdens of managing paper flow -- they should use e-billing to sweep away obstacles to improving the management of medical care."
Stevens and Rousmaniere conclude that payers undertaking early compliance initiatives will strengthen themselves competitively, both in California and nationally. Carriers slow to adopt electronic transmission methods, however, will remain burdened by antiquated workflow; unable to reduce delays and errors in the handling of medical information; and be handicapped in their attempts to control spiraling medical costs, they say.
What do you think?
California regulations for electronic workers' compensation billing slated for publication before end of this year are likely to see fast-tracked implementation, according to Jopari Solutions, a supplier of medical EDI connectivity and transmission for the property and casualty industry.
EBilling is a key initiative the California Insurance Commissioner and Division of Workers' Compensation officials say is essential, along with other benchmark recommendations, to streamline the state's workers' compensation system, rein in medical costs and keep employer costs down. This past week, the Commissioner rejected any recommended increase in California's workers' compensation pure premium rate.
California's eBill regulations will specify an 18-month phase-in period for workers' compensation payers to acquire the ability to process eBill transactions, after regulations get signed into law. n addition, California is adopting uniform electronic claim and remittance standards similar to those mandated in Texas and Minnesota, which are supported by national standards organizations.
Facilitating rapid transition by carriers is the fact that national and regional health care provider networks are eager to expand electronic bill submissions with payers into their California markets. A large percentage of local health care practices today also exchange electronic health insurance claims, payments and remittance, or have medical transaction ready EDI billing software. Compressed timely payment deadline for clean electronic bills under California eBill rules - fifteen days as opposed to forty-five days for uncontested paper bills - is another factor expected to put early pressure on carriers by their medical services trading partners.
As Jopari CEO JR "Steve" Stevens and veteran industry observer Peter Rousmaniere point out in a new whitepaper, The E-billing Transformation, the community of beneficiaries from the switch to electronic transmission of bills and supporting documentation, or attachments, goes beyond state agencies pushing for administrative simplification, better data and more stakeholder accountability. Stevens and Rousmaniere indicate, "Conventional transmission methods, heavily dependent on mail, faxing and scanning, impose delays and error rates which leading medical bill review firms estimate as upwards of 20 percent or more. Electronic submission largely sweeps away these defects." They explain that, "Claims payers should therefore approach e-billing not simply as a way of shaving the burdens of managing paper flow -- they should use e-billing to sweep away obstacles to improving the management of medical care."
Stevens and Rousmaniere conclude that payers undertaking early compliance initiatives will strengthen themselves competitively, both in California and nationally. Carriers slow to adopt electronic transmission methods, however, will remain burdened by antiquated workflow; unable to reduce delays and errors in the handling of medical information; and be handicapped in their attempts to control spiraling medical costs, they say.
What do you think?
Labels:
Brousseau,
compliance,
EDI,
healthcare payments automation,
HPAS,
TAWPI
Thursday, October 1, 2009
ERM ROI
Posted by Mark Brousseau
With widespread acceptance that deficiency in risk management was a leading contributor to the credit crisis, these could be happy days for Enterprise Risk Management (ERM) and its advocates. With that new-found popularity will come accountability though; a request that ERM proves its real worth. Ascribing a quantifiable value to ERM may be difficult – but not impossible as Mike Nolan of KPMG’s Advisory practice explains.
As a concept, Enterprise Risk Management has now been with us for some time yet the concerns over how to quantify its effectiveness refuse to disappear.
Many people have become accustomed to judging ERM in qualitative, ‘softer’ terms. In this regard, it’s hard to argue against its effectiveness, resulting as it does in enhanced risk identification and prioritization, a common risk language, improved risk and controls optimization, better risk monitoring and reporting as well as contributing to strengthening risk governance and culture.
However, in today’s currently cost-obsessed environment, assessment against intangible KPIs is unlikely to satisfy those business leaders intent on gauging exactly what the return on investment is; what value their current — or proposed — ERM program generates.
As more companies consider implementing ERM as a way of avoiding the risk management failures which precipitated the current crisis, the good news is that I believe ERM is quantifiable.Such quantification may not be easy; there’s no single formula and the results may not even be perfect — but surely this is preferable to the insistence that ERM can only be measured qualitatively. Such a reassurance might just convince a few more skeptics to head down the ERM route.
If you think about what ERM delivers, there are actually plenty of quantifiable outputs; decreased variability in financial results for example, as well as reduced hedging, insurance and capital costs. These equate directly to improved cash flow which, when coupled with a reduced discount rate (arising from reduced earnings volatility and an improved reputation within the investment community), results in enhanced company value. The metrics are there; it’s just a question of turning them into a final assessment which quantifies that all-important return on investment.
Let’s consider those metrics more closely, starting with capital costs first. With rating agencies paying increasing attention to companies’ ERM frameworks, deficiencies or over-performance in this area can be equated to a quantifiable impact on a company’s ability to access capital and on the cost of capital. Secondly, hard cost savings can be delivered by an ERM program which streamlines existing risk efforts and highlights redundant and inefficient risk activities (e.g. identification / assessment, aggregation and validation processes). Again, another quantifiable metric.
Insurance and hedging costs can be the most tangible cost elements in managing specific risks. ERM can help to optimize and reduce these costs by more clearly identifying underlying risk exposures, existing offsets and potential redundancies and inefficiencies.
Estimating earnings variability may be a complex task but can feasibly be undertaken both before and after ERM risk mitigation activities in order to demonstrate the impact and value of the ERM program.
Harder to quantify are the investment opportunities which can arise from ERM implementation but this does not mean the potential ‘up-side’ of ERM should simply be ignored. ERM enables companies to make smarter, proactive decisions, based on a better understanding of their current risk profile and their appetite for taking onboard more risk in pursuit of competitive advantage.
ERM is about optimizing risk in accordance with your risk tolerances and setting limits; not simply minimizing risk. Applying a risk lens and risk metrics to a business opportunity, in addition to the growth metric analysis, is likely to result in improved investment decisions. ERM can assist in identifying opportunistic areas of your business that would benefit from investment.
When thought of in these terms, the value of ERM looks far more quantifiable than has often been perceived. There is no simple formula for generating that final value but it should be an aggregate of performance in the areas mentioned above.
For too long, ERM has been considered solely in compliance terms, perceived similarly to existing internal audit, legal, environmental and finance compliance activities. Its presence was designed to assuage risk concerns from external stakeholders, directors and ratings agencies alike. It should now be seen in a more proactive light.
The credit crisis has refocused attention on to this area of business. ERM’s ‘standing’ in the risk world may have gone up but, with all expenditure now scrutinized down to the last dollar, it will have to properly prove its worth; something which it has traditionally struggled to do.
Thankfully, it may not prove as difficult a task as some would have us believe.
What do you think? Post your comments below.
With widespread acceptance that deficiency in risk management was a leading contributor to the credit crisis, these could be happy days for Enterprise Risk Management (ERM) and its advocates. With that new-found popularity will come accountability though; a request that ERM proves its real worth. Ascribing a quantifiable value to ERM may be difficult – but not impossible as Mike Nolan of KPMG’s Advisory practice explains.
As a concept, Enterprise Risk Management has now been with us for some time yet the concerns over how to quantify its effectiveness refuse to disappear.
Many people have become accustomed to judging ERM in qualitative, ‘softer’ terms. In this regard, it’s hard to argue against its effectiveness, resulting as it does in enhanced risk identification and prioritization, a common risk language, improved risk and controls optimization, better risk monitoring and reporting as well as contributing to strengthening risk governance and culture.
However, in today’s currently cost-obsessed environment, assessment against intangible KPIs is unlikely to satisfy those business leaders intent on gauging exactly what the return on investment is; what value their current — or proposed — ERM program generates.
As more companies consider implementing ERM as a way of avoiding the risk management failures which precipitated the current crisis, the good news is that I believe ERM is quantifiable.Such quantification may not be easy; there’s no single formula and the results may not even be perfect — but surely this is preferable to the insistence that ERM can only be measured qualitatively. Such a reassurance might just convince a few more skeptics to head down the ERM route.
If you think about what ERM delivers, there are actually plenty of quantifiable outputs; decreased variability in financial results for example, as well as reduced hedging, insurance and capital costs. These equate directly to improved cash flow which, when coupled with a reduced discount rate (arising from reduced earnings volatility and an improved reputation within the investment community), results in enhanced company value. The metrics are there; it’s just a question of turning them into a final assessment which quantifies that all-important return on investment.
Let’s consider those metrics more closely, starting with capital costs first. With rating agencies paying increasing attention to companies’ ERM frameworks, deficiencies or over-performance in this area can be equated to a quantifiable impact on a company’s ability to access capital and on the cost of capital. Secondly, hard cost savings can be delivered by an ERM program which streamlines existing risk efforts and highlights redundant and inefficient risk activities (e.g. identification / assessment, aggregation and validation processes). Again, another quantifiable metric.
Insurance and hedging costs can be the most tangible cost elements in managing specific risks. ERM can help to optimize and reduce these costs by more clearly identifying underlying risk exposures, existing offsets and potential redundancies and inefficiencies.
Estimating earnings variability may be a complex task but can feasibly be undertaken both before and after ERM risk mitigation activities in order to demonstrate the impact and value of the ERM program.
Harder to quantify are the investment opportunities which can arise from ERM implementation but this does not mean the potential ‘up-side’ of ERM should simply be ignored. ERM enables companies to make smarter, proactive decisions, based on a better understanding of their current risk profile and their appetite for taking onboard more risk in pursuit of competitive advantage.
ERM is about optimizing risk in accordance with your risk tolerances and setting limits; not simply minimizing risk. Applying a risk lens and risk metrics to a business opportunity, in addition to the growth metric analysis, is likely to result in improved investment decisions. ERM can assist in identifying opportunistic areas of your business that would benefit from investment.
When thought of in these terms, the value of ERM looks far more quantifiable than has often been perceived. There is no simple formula for generating that final value but it should be an aggregate of performance in the areas mentioned above.
For too long, ERM has been considered solely in compliance terms, perceived similarly to existing internal audit, legal, environmental and finance compliance activities. Its presence was designed to assuage risk concerns from external stakeholders, directors and ratings agencies alike. It should now be seen in a more proactive light.
The credit crisis has refocused attention on to this area of business. ERM’s ‘standing’ in the risk world may have gone up but, with all expenditure now scrutinized down to the last dollar, it will have to properly prove its worth; something which it has traditionally struggled to do.
Thankfully, it may not prove as difficult a task as some would have us believe.
What do you think? Post your comments below.
Labels:
banking,
billing,
compliance,
enterprise risk management,
ERM,
KPMG,
Mark Brousseau,
TAWPI
Thursday, July 30, 2009
Federal Red Flags Rule Goes Into Effect August 1
Posted by Mark Brousseau
Beginning Aug. 1, 2009, hospitals and health care providers that extend any sort of credit to their customers - even something as simple as sending a bill at the end of the month - will need to have a documented, board-approved Red Flag compliance strategy in place to help combat medical identity theft.
Grant Thornton, LLP notes that the Red Flags Rule, a component of the Fair and Accurate Credit Transactions (FACT) Act signed into law in December 2003, requires that financial institutions and creditors in a number of industries implement a plan to identify, detect and respond to attempts to use stolen identity information.
"This rule is completely different from policies you have in place to protect sensitive information," says Randy Green, a principal in Grant Thornton LLP's Advisory Services group. "Instead, this regulation is designed to prevent thieves who have somehow acquired another person's identity - via medical records or otherwise - from using it to commit fraud. The rule requires you to identify all of the indicators that might tip you off to possible identity theft, implement appropriate preventive and detective controls, and react appropriately."
While the Rule has been in effect since November 2008, enforcement by the Federal Trade Commission (FTC) will begin Aug. 1 of this year. Initially, the FTC may assess retroactive penalties for violations, require additional compliance reporting from companies and obtain an injunctive compliance order. Further violations could result in a visit to federal district court and a fine of up to $16,000 per individual occurrence of identity theft.
"After Aug. 1, 2009, any occurrence of medical identity theft at your hospital or business exposes you to an FTC investigation," said Green. "We believe that enforcement of this rule will be complaint-driven, and given the staggering number of identity thefts, there will be no shortage of complaints."
"In summary, the Red Flags Rule is likely to become the standard of care that all hospitals and health care providers will need to provide to prevent medical identity theft," concluded Green. "Skipping red flags compliance will expose you to real regulatory, reputational and litigation risks."
How has your organization prepared for the Red Flags Rule?
Beginning Aug. 1, 2009, hospitals and health care providers that extend any sort of credit to their customers - even something as simple as sending a bill at the end of the month - will need to have a documented, board-approved Red Flag compliance strategy in place to help combat medical identity theft.
Grant Thornton, LLP notes that the Red Flags Rule, a component of the Fair and Accurate Credit Transactions (FACT) Act signed into law in December 2003, requires that financial institutions and creditors in a number of industries implement a plan to identify, detect and respond to attempts to use stolen identity information.
"This rule is completely different from policies you have in place to protect sensitive information," says Randy Green, a principal in Grant Thornton LLP's Advisory Services group. "Instead, this regulation is designed to prevent thieves who have somehow acquired another person's identity - via medical records or otherwise - from using it to commit fraud. The rule requires you to identify all of the indicators that might tip you off to possible identity theft, implement appropriate preventive and detective controls, and react appropriately."
While the Rule has been in effect since November 2008, enforcement by the Federal Trade Commission (FTC) will begin Aug. 1 of this year. Initially, the FTC may assess retroactive penalties for violations, require additional compliance reporting from companies and obtain an injunctive compliance order. Further violations could result in a visit to federal district court and a fine of up to $16,000 per individual occurrence of identity theft.
"After Aug. 1, 2009, any occurrence of medical identity theft at your hospital or business exposes you to an FTC investigation," said Green. "We believe that enforcement of this rule will be complaint-driven, and given the staggering number of identity thefts, there will be no shortage of complaints."
"In summary, the Red Flags Rule is likely to become the standard of care that all hospitals and health care providers will need to provide to prevent medical identity theft," concluded Green. "Skipping red flags compliance will expose you to real regulatory, reputational and litigation risks."
How has your organization prepared for the Red Flags Rule?
Wednesday, February 20, 2008
Epic Scam At D.C. Tax Office
Posted by Mark Brousseau
An interesting article from today's Washington Post:
Tab in Scam At Tax Office In D.C. Nears $50 Million
By Carol D. LeonnigWashington Post Staff WriterWednesday, February 20, 2008; A01
Federal authorities think that nearly $50 million was stolen in an embezzlement scheme run out of the D.C. tax office, more than double the amount they had previously uncovered, four sources close to the investigation said.
The corruption at the D.C. Office of Tax and Revenue went undetected much longer than initially thought, the sources said, extending back almost 20 years. In addition to tracking the missing money, authorities are looking into gifts suspected of being provided to co-workers and others by the woman accused of leading the scam, former tax office manager Harriette Walters.
The scheme is the largest corruption case in the city's history. Witnesses have told investigators that Walters, who is accused of issuing larger and larger bogus tax refund checks over the years, lavishly spread the wealth, the sources said.
Security guards got cash, office mates got free meals and virtually anyone who made a request got something, said the sources, who spoke on condition of anonymity because the investigation is ongoing.
Two of the sources, who are familiar with the accounts of witnesses, said the gifts included $35,000 to a co-worker who wanted to remodel her house, $25,000 in cash and luxury gifts to an assistant whom Walters began mentoring and $15,000 each to help two co-workers' daughters pay for renovations and credit card bills.
Walters repeatedly lent huge chunks of cash to colleagues with no requests for repayment, the two sources quoted witnesses as saying. And, said the sources, citing witnesses, Walters paid for her goddaughter's college tuition and a New Jersey home for $855,000. The goddaughter's attorney declined to comment on the case.
Since Walters was arrested in November, authorities have issued subpoenas for financial records, interviewed dozens of witnesses and built a more complete picture of what happened, the sources said.
Prosecutors told a judge soon after Walters was arrested that they had confirmed she had helped steal $20 million in fraudulent refund checks since 2004. But the estimated losses have been growing as federal investigators have delved further into records at the Office of Tax and Revenue and found dozens more fraudulent checks made out to city employees. Sources said that the total is nearing $50 million.
In early December, a Washington Post analysis found that $44.3 million in suspicious property tax refund checks had been issued by the office from 1999 to 2007, the period for which computerized city records were available. The Post identified 160 checks that lacked court orders required for legitimate large refunds and were made out to companies that were either fictitious or were not due a tax refund.
The higher the official theft total, the greater the potential penalty faced by Walters and the nine other people charged in the case.
Authorities are scrutinizing the activities of at least 40 people who have not been charged and are trying to determine whether they received things of value or were involved in financial transactions with those accused of being conspirators, according to interviews and documents reviewed by The Post. Those people are largely city employees who signed off on refund paperwork and others who received the gifts in question.
Witnesses have told authorities in recent weeks that Walters and a small cadre of friends began issuing bogus refund checks for modest amounts and erasing property tax bills as early as 1989.
They told authorities that Walters told them that, by manipulating the manual, paper-based records of the office, they could prevent supervisors and computer tracking systems from checking behind them, the sources said.
Walters, 51, a 25-year tax office employee, remains jailed without bond on charges that she and others generated fraudulent property tax refund checks and used doctored paperwork and front companies to cash them. Her attorney, Steve Tabackman, declined to discuss the case.
"In the midst of an ongoing investigation, we're simply not in a position right now to comment on The Post's reporting," Tabackman said.
Only one other tax office employee has been charged in the case: Diane Gustus, 54, a tax specialist who worked under Walters. Gustus's attorney, A. Scott Bolden, said he has been independently researching who received things of value from Walters.
"The gift-giving and cash-giving was so prevalent, it should be embarrassing to the D.C. government that this culture was allowed to exist and expand," Bolden said.
Bolden confirmed that the Gustus family received cash and valuable gifts from Walters. He said that his clients weren't aware that the money and gifts were tainted and that Walters told co-workers she inherited considerable wealth from family in the Virgin Islands.
"The government says they got things," Bolden said. "My response is: Who didn't?"
The new details raise more questions about the level of supervision in the Office of the Chief Financial Officer, which failed to detect the fraud in the largest agency under its umbrella. In the past decade, mostly under the leadership of Natwar M. Gandhi, the office has spent more than $100 million on a new computer system for the tax office and at least $1 million a year on external city audits.
The potential penalties in the case are growing, even as lawyers say that some defendants are in plea negotiations. Those charged in a conspiracy to steal $20 million to $50 million would face an estimated 15 to 20 years in prison under federal sentencing guidelines. Those charged with helping to steal $50 million or more could face as much as 30 years.
Federal prosecutors in the District and Maryland, where many of the banking transactions took place, have said they are determined to get back as much of the missing money as possible.
Court records show that prosecutors are also trying to determine which city employees knew or should have known that they were close to a massive crime in progress.
William Sullivan, a criminal defense lawyer and former prosecutor, predicted that authorities will try to criminally charge some gift recipients under the legal theory of "willful blindness." In those cases, Sullivan said, prosecutors must show evidence that the defendants intentionally ignored "red flags" that would make a reasonable person suspect a crime.
Based on witness accounts, there were signs of trouble. Walters took young women in her office, even those she knew only casually, on four-figure shopping sprees at Saks and Neiman Marcus and picked up the tab, according to information provided to authorities. Witnesses have told investigators that Walters also gave hundreds of dollars, over time, to security guards outside the tax agency's North Capitol Street office, the sources familiar with the probe said.
It was not unusual, sources said, for Walters to give a wad of cash to her assistant to buy breakfast or lunch for her 15-member office -- two or three times a week.
Some of the missing city money went toward buying property in the Washington area, New Jersey and the Caribbean, prosecutors have said, as well as for luxury cars, Louis Vuitton handbags and gambling trips to Atlantic City and Las Vegas.
The houses and cars can be sold by the government to reclaim some of the money for taxpayers, and the designer goods will probably bring some fraction of their original purchase prices at public auction. Much of the money is gone forever, investigators said.
Alethia Grooms, a former D.C. government employee who is among those charged in the case, has told authorities about what might be the beginnings of the scheme, her attorney, Kevin McCants, confirmed.
As early as 1990, McCants said, Walters told Grooms and a few other friends about how they could get free city money through bogus tax refund checks. Walters said there was no backup computer system to notice the manipulated checks, McCants said.
Grooms got a check for a little more than $4,000 in 1990, records show. McCants said she is "very remorseful" but didn't continue taking city money or know about the ongoing scam until Walters contacted her in 2003 trying to cash another refund check.
"She was dumbfounded that Harriette had been doing it on a continuing basis all this time," McCants said. "She thought this was done a couple of times and then it was over. But then she learned it had been going on uninterrupted, and the stakes had grown obviously much higher."
Staff writer Paul Duggan, database editor Dan Keating and staff researcher Meg Smith contributed to this report.
An interesting article from today's Washington Post:
Tab in Scam At Tax Office In D.C. Nears $50 Million
By Carol D. LeonnigWashington Post Staff WriterWednesday, February 20, 2008; A01
Federal authorities think that nearly $50 million was stolen in an embezzlement scheme run out of the D.C. tax office, more than double the amount they had previously uncovered, four sources close to the investigation said.
The corruption at the D.C. Office of Tax and Revenue went undetected much longer than initially thought, the sources said, extending back almost 20 years. In addition to tracking the missing money, authorities are looking into gifts suspected of being provided to co-workers and others by the woman accused of leading the scam, former tax office manager Harriette Walters.
The scheme is the largest corruption case in the city's history. Witnesses have told investigators that Walters, who is accused of issuing larger and larger bogus tax refund checks over the years, lavishly spread the wealth, the sources said.
Security guards got cash, office mates got free meals and virtually anyone who made a request got something, said the sources, who spoke on condition of anonymity because the investigation is ongoing.
Two of the sources, who are familiar with the accounts of witnesses, said the gifts included $35,000 to a co-worker who wanted to remodel her house, $25,000 in cash and luxury gifts to an assistant whom Walters began mentoring and $15,000 each to help two co-workers' daughters pay for renovations and credit card bills.
Walters repeatedly lent huge chunks of cash to colleagues with no requests for repayment, the two sources quoted witnesses as saying. And, said the sources, citing witnesses, Walters paid for her goddaughter's college tuition and a New Jersey home for $855,000. The goddaughter's attorney declined to comment on the case.
Since Walters was arrested in November, authorities have issued subpoenas for financial records, interviewed dozens of witnesses and built a more complete picture of what happened, the sources said.
Prosecutors told a judge soon after Walters was arrested that they had confirmed she had helped steal $20 million in fraudulent refund checks since 2004. But the estimated losses have been growing as federal investigators have delved further into records at the Office of Tax and Revenue and found dozens more fraudulent checks made out to city employees. Sources said that the total is nearing $50 million.
In early December, a Washington Post analysis found that $44.3 million in suspicious property tax refund checks had been issued by the office from 1999 to 2007, the period for which computerized city records were available. The Post identified 160 checks that lacked court orders required for legitimate large refunds and were made out to companies that were either fictitious or were not due a tax refund.
The higher the official theft total, the greater the potential penalty faced by Walters and the nine other people charged in the case.
Authorities are scrutinizing the activities of at least 40 people who have not been charged and are trying to determine whether they received things of value or were involved in financial transactions with those accused of being conspirators, according to interviews and documents reviewed by The Post. Those people are largely city employees who signed off on refund paperwork and others who received the gifts in question.
Witnesses have told authorities in recent weeks that Walters and a small cadre of friends began issuing bogus refund checks for modest amounts and erasing property tax bills as early as 1989.
They told authorities that Walters told them that, by manipulating the manual, paper-based records of the office, they could prevent supervisors and computer tracking systems from checking behind them, the sources said.
Walters, 51, a 25-year tax office employee, remains jailed without bond on charges that she and others generated fraudulent property tax refund checks and used doctored paperwork and front companies to cash them. Her attorney, Steve Tabackman, declined to discuss the case.
"In the midst of an ongoing investigation, we're simply not in a position right now to comment on The Post's reporting," Tabackman said.
Only one other tax office employee has been charged in the case: Diane Gustus, 54, a tax specialist who worked under Walters. Gustus's attorney, A. Scott Bolden, said he has been independently researching who received things of value from Walters.
"The gift-giving and cash-giving was so prevalent, it should be embarrassing to the D.C. government that this culture was allowed to exist and expand," Bolden said.
Bolden confirmed that the Gustus family received cash and valuable gifts from Walters. He said that his clients weren't aware that the money and gifts were tainted and that Walters told co-workers she inherited considerable wealth from family in the Virgin Islands.
"The government says they got things," Bolden said. "My response is: Who didn't?"
The new details raise more questions about the level of supervision in the Office of the Chief Financial Officer, which failed to detect the fraud in the largest agency under its umbrella. In the past decade, mostly under the leadership of Natwar M. Gandhi, the office has spent more than $100 million on a new computer system for the tax office and at least $1 million a year on external city audits.
The potential penalties in the case are growing, even as lawyers say that some defendants are in plea negotiations. Those charged in a conspiracy to steal $20 million to $50 million would face an estimated 15 to 20 years in prison under federal sentencing guidelines. Those charged with helping to steal $50 million or more could face as much as 30 years.
Federal prosecutors in the District and Maryland, where many of the banking transactions took place, have said they are determined to get back as much of the missing money as possible.
Court records show that prosecutors are also trying to determine which city employees knew or should have known that they were close to a massive crime in progress.
William Sullivan, a criminal defense lawyer and former prosecutor, predicted that authorities will try to criminally charge some gift recipients under the legal theory of "willful blindness." In those cases, Sullivan said, prosecutors must show evidence that the defendants intentionally ignored "red flags" that would make a reasonable person suspect a crime.
Based on witness accounts, there were signs of trouble. Walters took young women in her office, even those she knew only casually, on four-figure shopping sprees at Saks and Neiman Marcus and picked up the tab, according to information provided to authorities. Witnesses have told investigators that Walters also gave hundreds of dollars, over time, to security guards outside the tax agency's North Capitol Street office, the sources familiar with the probe said.
It was not unusual, sources said, for Walters to give a wad of cash to her assistant to buy breakfast or lunch for her 15-member office -- two or three times a week.
Some of the missing city money went toward buying property in the Washington area, New Jersey and the Caribbean, prosecutors have said, as well as for luxury cars, Louis Vuitton handbags and gambling trips to Atlantic City and Las Vegas.
The houses and cars can be sold by the government to reclaim some of the money for taxpayers, and the designer goods will probably bring some fraction of their original purchase prices at public auction. Much of the money is gone forever, investigators said.
Alethia Grooms, a former D.C. government employee who is among those charged in the case, has told authorities about what might be the beginnings of the scheme, her attorney, Kevin McCants, confirmed.
As early as 1990, McCants said, Walters told Grooms and a few other friends about how they could get free city money through bogus tax refund checks. Walters said there was no backup computer system to notice the manipulated checks, McCants said.
Grooms got a check for a little more than $4,000 in 1990, records show. McCants said she is "very remorseful" but didn't continue taking city money or know about the ongoing scam until Walters contacted her in 2003 trying to cash another refund check.
"She was dumbfounded that Harriette had been doing it on a continuing basis all this time," McCants said. "She thought this was done a couple of times and then it was over. But then she learned it had been going on uninterrupted, and the stakes had grown obviously much higher."
Staff writer Paul Duggan, database editor Dan Keating and staff researcher Meg Smith contributed to this report.
Sunday, February 10, 2008
Compliance Drives Automation
By Mark Brousseau
Many document automation vendors will tell you that compliance and audit issues are a major part of the business case for unstructured documents solutions, and the results of a recent Question of the Week on the TAWPI Web site confirm it.
Forty-nine percent of respondents to the online survey said that compliance and audit issues are playing a “very big” role in their need for unstructured documents solutions, while another 29 percent of respondents said compliance and audit issues were a “somewhat big” component. This means that compliance and audit issues were a significant factor in the need for unstructured documents solutions at 78 percent of the organizations that responded.
Just 18 percent of respondents said compliance and audit issues were a “somewhat small” issue in their need for unstructured documents solutions, while only 4 percent said they were a “very small” factor.
What is the story at your organization? E-mail me at m_brousseau@msn.com.
Many document automation vendors will tell you that compliance and audit issues are a major part of the business case for unstructured documents solutions, and the results of a recent Question of the Week on the TAWPI Web site confirm it.
Forty-nine percent of respondents to the online survey said that compliance and audit issues are playing a “very big” role in their need for unstructured documents solutions, while another 29 percent of respondents said compliance and audit issues were a “somewhat big” component. This means that compliance and audit issues were a significant factor in the need for unstructured documents solutions at 78 percent of the organizations that responded.
Just 18 percent of respondents said compliance and audit issues were a “somewhat small” issue in their need for unstructured documents solutions, while only 4 percent said they were a “very small” factor.
What is the story at your organization? E-mail me at m_brousseau@msn.com.
Labels:
audit,
Brousseau,
compliance,
TAWPI,
unstructured documents
Wednesday, January 30, 2008
The Compliance Challenge
By Mark Brousseau
If compliance challenges make you feel like a hamster running on a wheel, you’re not alone. Compliance costs grew significantly faster than net income for the financial institutions in a recent survey by the Deloitte Center for Banking Solutions. While compliance spending as a percentage of net income for the financial institutions surveyed were 2.83 percent in 2002, by 2006 it had grown to 3.69 percent, the survey of top 50 banks found. The indirect costs of compliance management are much greater, but more difficult to precisely measure.
The Deloitte Center for Banking Solutions also found that as costs have risen, financial institutions appear to have responded more by applying people to monitor compliance rather than focusing on process improvement and technology to manage it.
For instance, 95 percent of the financial institutions surveyed said their executives were much more involved in compliance management than in the past, with 40 percent saying that the time devoted to compliance had increased by more than 25 percent.
What do you think? E-mail me at m_brousseau@msn.com.
If compliance challenges make you feel like a hamster running on a wheel, you’re not alone. Compliance costs grew significantly faster than net income for the financial institutions in a recent survey by the Deloitte Center for Banking Solutions. While compliance spending as a percentage of net income for the financial institutions surveyed were 2.83 percent in 2002, by 2006 it had grown to 3.69 percent, the survey of top 50 banks found. The indirect costs of compliance management are much greater, but more difficult to precisely measure.
The Deloitte Center for Banking Solutions also found that as costs have risen, financial institutions appear to have responded more by applying people to monitor compliance rather than focusing on process improvement and technology to manage it.
For instance, 95 percent of the financial institutions surveyed said their executives were much more involved in compliance management than in the past, with 40 percent saying that the time devoted to compliance had increased by more than 25 percent.
What do you think? E-mail me at m_brousseau@msn.com.
Labels:
banks,
Brousseau,
compliance,
financial services,
TAWPI
Tuesday, January 8, 2008
Compliance A Major Lockbox Focus
By Mark Brousseau
Driven by more stringent internal controls and external mandates, Paul Diegelman (paul.diegelman@regulusgroup.com), vice president, business development executive, at Regulus, expects increased interest from lockbox clients in compliance this year.
“All companies rely on their internal controls, among other things, to ensure financial statement accuracy,” Diegelman told me. “Corporations are becoming increasingly focused on the task of remittance processing, to ensure that the internal or external remit processors have adequate controls in place, and that those controls are tested to ensure adequacy.”
Diegelman added that external mandates, such as HIPAA for healthcare and Regulation AB for financial services companies, are increasing the compliance requirements for internal and external processors alike.
Similarly, Diegelman foresees increased adoption of formal programs, such as ISO17799, that help control data security variables. These must include physical site access, encryption of data at rest, certain hiring policies, and penetration testing, among others, he said.
“A tremendous amount of sensitive information is managed by internal and external remittance processors,” Diegelman noted. “Looking at recent media reports, we know that breaches of this data bring significant reputation and financial risk to the holder of the data. Companies must now have some sort of documented and tested program to ensure that sensitive data is protected.”
What do you think? E-mail me at m_brousseau@msn.com.
Driven by more stringent internal controls and external mandates, Paul Diegelman (paul.diegelman@regulusgroup.com), vice president, business development executive, at Regulus, expects increased interest from lockbox clients in compliance this year.
“All companies rely on their internal controls, among other things, to ensure financial statement accuracy,” Diegelman told me. “Corporations are becoming increasingly focused on the task of remittance processing, to ensure that the internal or external remit processors have adequate controls in place, and that those controls are tested to ensure adequacy.”
Diegelman added that external mandates, such as HIPAA for healthcare and Regulation AB for financial services companies, are increasing the compliance requirements for internal and external processors alike.
Similarly, Diegelman foresees increased adoption of formal programs, such as ISO17799, that help control data security variables. These must include physical site access, encryption of data at rest, certain hiring policies, and penetration testing, among others, he said.
“A tremendous amount of sensitive information is managed by internal and external remittance processors,” Diegelman noted. “Looking at recent media reports, we know that breaches of this data bring significant reputation and financial risk to the holder of the data. Companies must now have some sort of documented and tested program to ensure that sensitive data is protected.”
What do you think? E-mail me at m_brousseau@msn.com.
Labels:
Brousseau,
compliance,
lockbox,
remittance,
TAWPI
Subscribe to:
Posts (Atom)