IT Governance Effectiveness
IT Governance Effectiveness
IT Governance Effectiveness
September 2015
Your Presenter
Gordon Braun
Managing Director within Protiviti's Kansas City Office
Member of Protiviti's global IT Effectiveness and Control Team
16+ years in information technology, internal audit, and risk consulting
spanning a variety of industries, including healthcare, financial
services, and consumer products, among other industries
Experienced in a broad range of projects, from short-term audits and
assessments to full-scale process re-engineering and system
implementation programs
~ At least dozen projects specifically categorized as IT governance-
ish in the last 5 years
Gordon.braun@Protiviti.com
913.661.7406 - office
IT Changes with
Collaboration is Key
Increased Demand
Strengthening IT Asset
and Data management
Standard 2110-A2:
The internal audit activity must
assess whether information
technology governance of the
organization sustains and
supports the organizations
strategies and objectives.
IT governance (ITG) is defined as the processes that ensure the effective and efficient use
of IT in enabling an organization to achieve its goals.
- IT Governance Institute
Realization
of Value Optimized
Key Takeaway: "Optimized" is not an
Proposition
appropriate target for most organizations
Managed
Process Maturity
Defined
Repeatable
Initial /
(Example)
Ad hoc
IT Governance Audit
Description
There is no formally documented process by which IT projects are requested, evaluated, and approved.
Some corporate entities and Divisions indicated that they provide business case-related information, but
there is no required format to enable consistent review of projects on an equal basis. Additionally, there
are no defined criteria by which projects are evaluated to ensure that they are in alignment with the
organizations strategic objectives. Finally, there is no process that validates the achievement of benefits
after project completion.
Quotes
Its a disjointed process
There doesnt appear to be an apples to apples comparison between projects
In my opinion, there is no organized process for selecting projects for funding
Within our Division, we have a well-defined process for evaluating and prioritizing projects, but I dont
feel like thats taken into consideration when IT projects are selected by Corporate
Were told that certain projects arent approved due to lack of funding, but nobody has ever come
back to us to ask for additional funds
Description
The IT organization regularly reports performance metrics to Senior Leadership. However, recipients do
not consider the metrics to be reflective of overall IT performance. Additionally, most indicated that
positive actions and achievements completed by the CIO organization are not adequately communicated
or celebrated.
Quotes
The metrics that we see from IT indicate that everything is great, but I can tell you that based on my
organization, that is not the case
They are either measuring the wrong things, or the things they are measuring arent being valued
correctly
While their metrics may reflect things like ticket closures, what it fails to capture is the fact that
people do anything they can to not call the service desk due to the frustrations that they experience
IT doesnt celebrate their achievements - when they increased the VPN capacity, which was a great
thing for the organization, it wasnt communicated at all
Action Plan Recommendations
Solicit feedback from Corporate functions and departments to establish new metrics that would be
more useful or representative of the value of the services they receive.
Evaluate the existing metrics reported by IT and determine if there are either additional data points
that can be communicated, or changes to existing data points which would more accurately portray
level of service.
Implement a mechanism to communicate IT achievements to the organization (i.e. email, intranet
notice, etc.)
Internal Audit did not review any of the costs that were incurred to fund
the achievement of benefits, nor was the overall ROI considered.
Benefit Type Organizatio Benefit Benefit FY20xx FYxx Actual Actual FY20xx FY20xx
n Accruing Operating Begins (Planned) Benefits Benefits vs. (Planned) (Planned)
Benefit Function FQ/FYYY Planned
Direct & XYZ Business FQ1/20xx $330,619 $727,844 $397,225 $1,068,709 $1,662,156
Measurable Process
Operations
Performance Measurement -
Projects
This document contains confidential material proprietary to Protiviti Inc. ("Protiviti"), a wholly-owned subsidiary of Robert Half International Inc.
("RHI"). RHI is a publicly-traded company and as such, the materials, information, ideas, and concepts contained herein are non-public, should be used
solely and exclusively to evaluate the capabilities of Protiviti to provide assistance to your Company, and should not be used in any inappropriate manner
or in violation of applicable securities laws. The contents are intended for the use of your Company and may not be distributed to third parties.