Opportunities and risks of a data-driven organization (3)

Opportunities and risks of a data-driven organization (3)

By Richard Arthurs FCPA, FCMA, Partner, Enterprise Risk Services at MNP

Internal Audit and Governance Brief (Part 3)

Considerations for a data-driven internal audit team

The highest-performing internal audit teams will incorporate data analytics and related insights into their portfolio of strategic priorities. The following are future-oriented strategic considerations for efficient internal audit teams:

  • Strategic alignment: The internal audit activity should focus on supporting the organization’s strategy and enterprise risk management success. Data analytic insight can provide valuable decision support. For example, many executives and boards use data analytic visual dashboards to compare actual results against strategic targets over multiple years.
  • Stakeholder engagement and trust: Internal audit optimizes value when it earns the right to be a trusted advisor to the board and executive. Accurate insight from analytics can fuel this engagement and trust.
  • Agility: Internal audit must optimize value with limited resources and budget. Agility optimizes efficiency and can minimize business disruption. Analytics can provide high-value efficiency by leveraging powerful business intelligence software. For example, using readily available software like Power BI allows for the analysis of an entire population of data, a function which may be impossible to do manually.
  • Leading and adapting to change: Most industries are experiencing internal and external change at a faster pace than ever before in history. Analytics can be set up as a continuous monitoring system, providing red flags as early warning of potential issues, including changes that may have weakened controls. Many large corporations use these systems to monitor employee retention and turnover statistics, issuing early warnings when turnover reaches a certain level. This allows the organization to address any root causes proactively and mitigate additional turnover.
  • Working in a virtual world: Internal audit must be able to operate effectively in all environments (in an office, in working teams, as individual contributors, with clients, virtually) without seeing a major disruption in the efficiency or quality of work.
  • Digital transformation: Continuous investment in technology, data, and innovation has made it critical for internal audit, boards, and leaders to recognize when even greater transformation is needed for the organization to exploit additional benefits from the change while not allowing controls to weaken. Analytics are often used to test the integrity of data moving from legacy systems to new digital systems.
  • Data analytics and insight: It is critical that internal audit has equal or better data analytics and insight capability versus all other functions within the organization, or internal audit will put itself at risk of not having equal or better insight than the business in delivering assurance and advisory engagements. For example, business leaders may have more accurate insight than an internal audit if the business uses analytics and an internal audit does not.

In summary, it is obvious that internal audit can unlock significant value for the board, executive, and audit committee by using data analytics and related insight. However, it is critical to avoid the unethical collection and use of data. Lastly, it is important for internal audit to embrace the fact that analytics can play a role in all future-oriented leading practices, and it is a very effective way of detecting and investigating fraud.

CASE 1: NORTEL NETWORKS CORPORATION

Nortel Networks Corporation, once a leading Canadian telecommunications and networking equipment company, faced a significant corporate scandal due to financial fraud in the mid-2000s. The company’s financial troubles were detected and prosecuted through a combination of financial data analysis, whistleblowers, and investigations by regulatory authorities. Here’s an overview of how data played a role in detecting and prosecuting fraud at Nortel:

  1. Financial data analysis:
    • Nortel’s financial statements and reports were analyzed by auditors and forensic accountants. These professionals scrutinized the company’s financial data for irregularities and inconsistencies.
    • Financial data analysis revealed that Nortel had engaged in various accounting manipulations and fraudulent practices. This included improperly recognizing revenue, misclassifying expenses, and inflating profits.
  2. Whistleblower information:
    • Whistleblowers within the company played a crucial role in exposing the fraud. Some Nortel employees and insiders were aware of the accounting irregularities and decided to report them.
    • The information provided by these whistleblowers, including documents, emails, and internal communications, helped investigators understand the scope of the fraudulent activities.
  3. Investigations by regulatory authorities:
    • Regulatory bodies, such as the Ontario Securities Commission (OSC) in Canada and the U.S. Securities and Exchange Commission (SEC), launched investigations into Nortel’s financial practices.
    • These agencies requested access to the company’s financial records, communications, and documents. They also interviewed employees and executives as part of their investigations.
    • The regulatory authorities relied on the collected data and evidence to build their case against Nortel.
  4. Legal proceedings:
    • The information and evidence gathered during the investigations were used to bring legal actions against Nortel and its executives, including former CEO Frank Dunn and other high-ranking officers.
    • The legal cases included allegations of securities fraud, accounting fraud, and misleading investors. The prosecutors relied on data and financial records to support their claims.

In 2007, Nortel reached a settlement with regulatory authorities to pay a significant fine and accept various remedial measures without admitting or denying wrongdoing. The company later filed for bankruptcy.

Some former Nortel executives faced criminal charges and were convicted. They were held accountable for their involvement in the company’s financial fraud.

In summary, data played a crucial role in detecting and prosecuting fraud at Nortel. Financial data analysis, information from whistleblowers, investigations by regulatory authorities, and legal proceedings all relied on data to uncover and build a case against those responsible for the fraudulent practices at the company. These efforts eventually led to legal actions, settlements, and convictions in connection with the Nortel fraud scandal.

CASE 2: LIVENT INC.

Livent Inc. was a Canadian live entertainment company founded by Garth Drabinsky and Myron Gottlieb. In the late 1990s, Livent became embroiled in one of the most prominent corporate fraud scandals in the entertainment industry, which ultimately led to the detection and prosecution of the fraud.

Here’s how data was used to detect and prosecute fraud at Livent:

  1. Financial statements analysis:
    • The initial red flag was raised when auditors and regulators reviewed Livent’s financial statements. Irregularities in the financial statements included inflated revenue figures, understated expenses, and manipulated profits. This raised suspicions about the company’s financial health and led to a deeper investigation.
  2. Whistleblower reports:
    • Several former employees of Livent, including some with financial and accounting roles, came forward with allegations of fraudulent activities within the company. These whistleblowers provided information that triggered investigations by law enforcement and regulatory agencies.
  3. Forensic accounting:
    • Forensic accountants were brought in to conduct detailed examinations of Livent’s financial records. They used data analysis techniques to identify inconsistencies and irregularities, such as discrepancies between reported and actual revenues and expenses. This analysis helped uncover the extent of the fraud.
  4. Document examination:
    • Investigators combed through various financial documents, contracts, and communication records to trace the flow of funds and identify any incriminating evidence of fraudulent activities. This involved reviewing a substantial amount of data to establish a clear trail of wrongdoing.
  5. Witness testimonies:
    • Witnesses, including former Livent employees, were interviewed and asked to provide information about their roles in the fraud. Their testimonies added to the evidence and helped build a case against the individuals responsible for the fraud.
  6. Collaboration with regulatory bodies:
    • The investigation into Livent’s fraud involved collaboration with regulatory authorities, such as the OSC and the SEC. These agencies had access to additional data and resources to aid in the prosecution.
  7. Legal action:
    • Based on the findings of the investigations and the evidence collected, legal action was taken against the individuals responsible for the fraud.
    • In 1999, Garth Drabinsky and Myron Gottlieb, the co-founders of Livent, were charged with multiple counts of fraud and other offences.

Livent’s founders were prosecuted in court, where the collected data and evidence were presented to support the charges. The individuals were found guilty of their involvement in the financial fraud.

The Livent case is an example of how data, financial analysis, whistleblower reports, forensic accounting, document examination, and cooperation with regulatory bodies can be used to detect and prosecute corporate fraud. The combination of these investigative techniques helped uncover fraudulent activities and hold the individuals responsible accountable for their actions.


Part 1 of the Internal Audit and Governance Brief, which discusses the opportunities of data analytics in internal audit, appears in Dividends Summer 2024 and can be found online here.

Part 2 of the Internal Audit and Governance Brief, which discusses the risk related to the increased use of data analytics by internal audit, can be found online here.


Richard Arthurs FCPA, FCMA is a Partner in Enterprise Risk Services at MNP and MNP’s National Internal Audit Leader based in Calgary. Richard has deep industry experience in the utilities/energy, consumer goods, retail, technology, telecommunications, not-for-profit, and public sectors, and over 30 years of experience assisting complex global organizations with their internal audit, governance, risk management, IT audit, data analytics, ethics, and compliance needs. Leveraging his experience leading internal audit and risk projects in more than 60 countries, Richard has a global perspective on the issues businesses face. He has worked with renowned organizations and has a proven track record of achieving cost-effective, value-added solutions to manage priority risks and improve business processes and controls.



Discover more from Digital Dividends

Subscribe now to keep reading and get access to the full archive.

Continue reading