Find White Papers
Home
About Us
List Your Papers
    
> Prodiance Corp. > Fraud Prevention & Detection for Mission Critical Spreadsheets

Fraud Prevention & Detection for Mission Critical Spreadsheets

White Paper Published By: Prodiance Corp.

According to Baseline Consulting, approximately 32% of corporate data is contained in enduser computing (EUC) applications and approximately 68% is stored in IT controlled applications. These EUCs – primarily spreadsheets, PC databases (e.g. Access databases), BI reports, and word documents – are often stored on employee desktops and corporate file shares, and for the most part, are uncontrolled. They lack the proper safeguards and controls one would expect with IT controlled applications, including documentation, version control, back-up and archival, change control, testing, security and access control, and more.



Tags : 
prodiance, end-user computing (euc), risk assessment, automation, monitoring, spreadsheet, link migration, networking

Prodiance Corp.
Published:  Dec 22, 2008
Type:  White Paper
Length:  13 pages









Fraud Prevention & Detection
for Mission Critical Spreadsheets White Paper

October 2008 P-01513, Revision A












Prodiance White Paper
Table of Contents
Table of Contents ........................................................................................................................... 1 
Uncontrolled UDAs Leave Door Open for Fraud ........................................................................... 2 
Auditor Guidance ........................................................................................................................... 3 
Preventing & Detecting Spreadsheet Fraud .................................................................................. 3 
Prodiance Enterprise Spreadsheet Manager Solution .................................................................. 5 
The Bottom Line ........................................................................................................................... 11 
Take the Next Step! ..................................................................................................................... 11 
About Prodiance .......................................................................................................................... 12 
Fraud Prevention & Detection 1 Prodiance White Paper
Uncontrolled UDAs Leave Door Open for Fraud
According to Baseline Consulting, approximately 32% of corporate data is contained in end-user computing (EUC) applications and approximately 68% is stored in IT controlled applications. These EUCs - primarily spreadsheets, PC databases (e.g. Access databases), BI reports, and word documents - are often stored on employee desktops and corporate file shares, and for the most part, are uncontrolled. They lack the proper safeguards and controls one would expect with IT controlled applications, including documentation, version control, back-up and archival, change control, testing, security and access control, and more. 
 
 
When these uncontrolled spreadsheets are used in key financial processes such as closing the books, account reconciliation, revenue recognition, and financial and management reporting, then organizations face significant risk and exposure. Aside from non-compliance, a high probability of error, and operational risk, uncontrolled spreadsheets and EUCs present a safe haven for fraud and even "cooking the books." There are many well documented stories of spreadsheet errors and fraud cases available on the internet. All one has to do is search Google using the keywords "spreadsheet error" and over 4,900,00 hits are returned.  
In a recent fraud case involving spreadsheets, the CFO of a software technology company used hidden rows and columns of data and invisible cells (e.g. white font on white background) to conceal financial data and falsify financial statements. The fraud was undetected for a period of 5 years. The scam eventually cost the company more than $437 million in market capitalization and caused its stock price to drop from $29.41 to $12.31 per share between February and April 2006. You can read more on this story on the CFO Magazine web site at: http://www.cfo.com/article.cfm/11779964?f=related. Other cases of spreadsheet error and fraud have been documented by the European Spreadsheet Risks Interest Group (EuSpRIG): http://www.eusprig.org/stories.htm. 
 
Fraud Prevention & Detection 2 Prodiance White Paper
Auditor Guidance
Leading tax and audit firms recommend that organizations automate the spreadsheet controls environment to help prevent and detect spreadsheet fraud, while establishing sustainable governance. Both preventative and detective controls are recommended, along with a lifecycle approach to managing spreadsheets. Organizations can certainly implement this lifecycle process via manual efforts, but this requires employees to take on additional tasks and often breaks down over time. By leveraging technology, organizations can automate many aspects of spreadsheet management and control, from discovery and inventory, to risk assessment, remediation, management and contro... [download for more]

Browse Technology Topics

Data Center

Virtualization, Cloud Computing, Infrastructure, Design and Facilities, Power and Cooling, Green Computing  
    

Data Management

Application Integration, Analytical Applications, Business Intelligence, Configuration Management, Database Development, Data Integration, Data Mining, Data Protection, Data Quality, Data Replication, Database Security, EDI, SOAP, Service Oriented Architecture, Web Service Management, Data Warehousing  
    

Enterprise Applications

Application Integration, Application Performance Management, Best Practices, Business Activity Monitoring, Business Analytics, Business Integration, Business Intelligence, Business Management, Business Metrics, Business Process Automation, Business Process Management, Call Center Management, Call Center Software, Change Management, Corporate Governance, Customer Interaction Service, Customer Relationship Management, Customer Satisfaction, Customer Service, EBusiness, Enterprise Resource Planning, Enterprise Software, EProcurement, Extranets, Groupware Workflow, HIPAA Compliance, IP Faxing, IT Spending, Marketing Automation, Performance Testing, Product Lifecycle Management, Project Management, Return On Investment, Risk Management, Sales & Marketing Software, Sales Automation, Server Virtualization, Simulation Software, Supply Chain Management, System Management Software, Total Cost of Ownership, Video Conferencing, Voice Recognition, Voice Over IP, Workforce Management, Incentive Compensation, Spend Management, Manufacturing Execution Systems, International Computing  

Human Resource Technology

Human Resources Services, Payroll Software, Time and Attendance Software, Workforce Management Software, Financial Management, Employee Monitoring Software, Employee Training Software, Recruiting Software/Services, Employee Performance Management, ELearning, Benefits Management, Expense Management  
    

IT Career Advancement

Cisco Certification, Microsoft Certification, Linux Certification, Network Security Certification, Software Development Certification  

IT Management

Employee Performance, ITIL, Productivity, Project Management, Software Compliance, Sarbanes Oxley Compliance, Service Management, Desktop Management  
    

Knowledge Management

Collaboration, Collaborative Commerce, Contact Management, Content Delivery, Content Integration, Content Management System, Corporate Portals, Customer Experience Management, Document Management, Information Management, Intranets, Messaging, Records Management, Search And Retrieval, Search Engines, Secure Content Management, SLA  

Networking

Active Directory, Bandwidth Management, Convergence, Distributed Computing, Ethernet Networking, Fibre Channel, Gigabit Networking, Governance, Grid Computing, Infrastructure, Internetworking Hardware, Interoperability, IP Networks, IP Telephony, Local Area Networking, Load Balancing, Migration, Monitoring, Network Architecture, Network Management, Network Performance, Network Performance Management, Network Provisioning, Network Security, OLAP, Optical Networking, Quality Of Service, Remote Access, Remote Network Management, Server Hardware, Servers, Small Business Networks, TCP/IP Protocol, Test And Measurement, Traffic Management, Tunneling, Utility Computing, VPN, Wide Area Networks, Green Computing, Cloud Computing, Power and Cooling, Data Center Design and Management, Colocation and Web Hosting  
    

Platforms

AS/400, Domino, Linux, Microsoft Exchange, Oracle, PeopleSoft, SAP, Siebel, Solaris, Tivoli, Unix, Web Sphere, Windows, Windows Server  

Security

Access Control, Anti Spam, Anti Spyware, Anti Virus, Application Security, Auditing, Authentication, Biometrics, Business Continuity, Compliance, DDoS, Disaster Recovery, Email Security, Encryption, Firewalls, Hacker Detection, High Availability, Identity Management, Internet Security, Intrusion Detection, Intrusion Prevention, IPSec, Network Security Appliance, Password Management, Patch Management, Phishing, PKI, Policy Based Management, Security Management, Security Policies, Single Sign On, SSL, Secure Instant Messaging, Web Service Security, PCI Compliance, Vulnerability Management  
    

Software Development

.NET, C++, Database Development, Java, Middleware, Open Source, Software Outsourcing, Quality Assurance, Scripting, SOAP, Software Testing, Visual Basic, Web Development, Web Services, Web Service Security, XML  

Storage

Backup And Recovery, Blade Servers, Clustering, IP Storage, ISCSI, Network Attached Storage, RAID, Storage Area Networks, Storage Management, Storage Virtualization, Email Archiving, Data Deduplication  
    

Wireless

802.11, Bluetooth, CDMA, GPS, Mobile Computing, Mobile Data Systems, Mobile Workers, PDA, RFID, Smart Phones, WiFi, Wireless Application Software, Wireless Communications, Wireless Hardware, Wireless Infrastructure, Wireless Messaging, Wireless Phones, Wireless Security, Wireless Service Providers, WLAN  
Search