• Visitors can check out the Forum FAQ by clicking this link. You have to register before you can post: click the REGISTER link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below. View our Forum Privacy Policy.
  • Want to receive the latest contracting news and advice straight to your inbox? Sign up to the ContractorUK newsletter here. Every sign up will also be entered into a draw to WIN £100 Amazon vouchers!

Anyone here ever been audited ?

Collapse
X
  •  
  • Filter
  • Time
  • Show
Clear All
new posts

    Anyone here ever been audited ?

    by KP MG , on development and release procedures

    I have a month to get prepared
    (\__/)
    (>'.'<)
    ("")("") Born to Drink. Forced to Work

    #2
    yes, don't sweat it - most of them are clueless and following a prescriptive outdated mandate IMO.

    Do your research on what they are there to audit and what they will be looking for - but in my experience of audits from KPMG (on release management and security) they'll always find something to mark as "needs improvement" ; otherwise they aren't selling their auditing services as having any value.

    Cards on the table, I HATE AUDITORS ...... It's easy to tell people how to do things "by the book" and properly, when you have no real life implementation skills of doing it at all.

    Comment


      #3
      Not personally, an ex-colleague was auditted a few months ago. They absolutely ripped his procedures apart, completely humiliated before the boss came in & had him shot on KP MG's say so.

      Not that, that will happen to you of course.
      What happens in General, stays in General.
      You know what they say about assumptions!

      Comment


        #4
        Originally posted by EternalOptimist View Post

        by KP MG , on development and release procedures ...
        Why are you under this obligation? Can't you just tell them to get stuffed?

        Or is it a prerequisite of some contract?
        Work in the public sector? Read the IR35 FAQ here

        Comment


          #5
          Originally posted by Scoobos View Post
          Cards on the table, I HATE AUDITORS ...... It's easy to tell people how to do things "by the book" and properly, when you have no real life implementation skills of doing it at all.
          My last experience of them was in minicomputer days and they couldn't understand why we didn't keep logs of every single character typed on the main console, like what ICL mainframes gave you.

          Not impressed really.
          Behold the warranty -- the bold print giveth and the fine print taketh away.

          Comment


            #6
            Before the audit
            Go through all your procedures and make sure they're not missing anything
            Make sure that the written procedures and what actually is done are the same - or at least there's no evidence of violation
            Find any violations of procedures and fix them (or bury them under the patio)
            If there any explainable anomalies - record the explanation and keep it to hand.

            During the audit
            Never volunteer information.
            If asked questions that you cannot answer immediately, tell them you'll get back to them on it.
            If a question needs some investigation, do it when they're not in the room.

            After the audit
            Go through the findings and challenge where necessary.
            Down with racism. Long live miscegenation!

            Comment


              #7
              Originally posted by NotAllThere View Post
              Before the audit
              Go through all your procedures and make sure they're not missing anything
              Make sure that the written procedures and what actually is done are the same
              Find any violations of procedures and fix them
              If there any explainable anomalies - record the explanation and keep it to hand.

              During the audit
              Never volunteer information.
              If asked questions that you cannot answer immediately, tell them you'll get back to them on it.
              If a question needs some investigation, do it when they're not in the room.

              After the audit
              Go through the findings and challenge where necessary.
              For EO to understand, replace words Auditor with Police and Audit with Interview.
              What happens in General, stays in General.
              You know what they say about assumptions!

              Comment


                #8
                Originally posted by Scoobos View Post
                yes, don't sweat it - most of them are clueless and following a prescriptive outdated mandate IMO.

                Do your research on what they are there to audit and what they will be looking for - but in my experience of audits from KPMG (on release management and security) they'll always find something to mark as "needs improvement" ; otherwise they aren't selling their auditing services as having any value.

                Cards on the table, I HATE AUDITORS ...... It's easy to tell people how to do things "by the book" and properly, when you have no real life implementation skills of doing it at all.
                External auditors, been there and really it was that bad. It was a scam and glad I moved into IT

                Internal auditors can be useful though

                When I did it I warned of lax security that could lead to fraud, and when someone was found to be defrauding the organisation was tried to be implicated as a whistle blower

                I managed it when I was younger, and found a lot of business processes that were outdated and/or pointless

                Now I'd be too cynical to do it, but then I genuinely thought I was helping the organisation
                Doing the needful since 1827

                Comment


                  #9
                  Not All There is correct. If there is one bit of advice that you MUST stick to it's;

                  Never, ever, ever volunteer information.
                  ...my quagmire of greed....my cesspit of laziness and unfairness....all I am doing is sticking two fingers up at nurses, doctors and other hard working employed professionals...

                  Comment


                    #10
                    Originally posted by EternalOptimist View Post
                    by KP MG , on development and release procedures

                    I have a month to find a new contract
                    You know it makes sense
                    While you're waiting, read the free novel we sent you. It's a Spanish story about a guy named 'Manual.'

                    Comment

                    Working...
                    X