Dependence on IT service providers requires specific risk management
These days, many companies no longer obtain key IT services entirely in-house, but instead through external service providers. This may, among other things, considerably simplify the operation of the IT infrastructure, however, it also leads to dependencies that are not easily controllable. When service providers operate infrastructure, maintain applications or process personal information and data relevant to financial reporting, their processes have a direct impact on security, compliance and, to some extent, also on the audit of the annual financial statements.
Why IT service providers are increasingly being spotlighted and …
In many companies, service providers undertake tasks that are of vital importance for ongoing business operations. The services that are provided usually include the operation of ERP systems, cloud applications, databases or IT infrastructure components. At the same time, the responsibilities are shared among several persons. Normally, responsibility for the processes remains with the company while the individual activities are carried out by the service provider.
… need to be taken into account in risk management
IT third-party relationship management (abbreviated to IT TPRM) denotes an area of risk management that is directed at outsourced IT services and presents potential risks transparently. Here, transparency is all the more important because technical dependencies on the IT service provider in day-to-day operations (so-called vendor lock-in) frequently only become apparent in the case of malfunctions/outage, a change of service provider or missing evidence in the context of external audits.
Relevance of the problem in the case of auditing and …
The most important factor for the audit of the annual financial statements is whether the outsourced IT processes have an impact on audit-relevant systems, data or controls. If key IT controls are the responsibility of the service provider, then a purely internal viewpoint is frequently not sufficient. In that case, the services performed at the IT service provider, the controls that are in place and the appropriate evidence will also have to be taken into account. In this context, ISA 402 in particular may become relevant because if the services of an organisation are used then sufficient appropriate audit evidence will be required as part of the audit of the annual financial statements.
… the governance system
Furthermore, from a governance, risk and compliance (GRC) perspective, aspects such as governance, responsibilities and risk management are of crucial importance. Companies should be informed about the critical IT service providers, i.e., among other things, have available the agreements and evidence of the services to be provided, as well as being in possession of a list of the persons who are responsible for the in-house monitoring of the provision of the services. This facilitates risk classification and allows measures to be tracked more accurately.
The four “building blocks” of structured IT service provider management
Effective IT TPRM does not have to be unnecessarily complex. For small and medium-sized enterprises, in particular, a more streamlined but consistently maintained approach may already provide considerable added value. Here, four elements have proven to be especially helpful:
Register of IT service providers
First of all, a register of IT service providers ensures that there is a comprehensive overview of the relevant IT service providers. The following information may be recorded there: name of the service provider, type of service, systems concerned, contractual basis, data processed, contact person and a risk level. This classification is a useful tool for distinguishing critical IT service providers from less essential service providers.
RACI-Matrix
The use of a RACI-Matrix (responsible, accountable, consulted, informed, cf. Fig. 1) serves the purpose of clearly allocating responsibilities. In the case of outsourced IT processes, in particular, there is frequently a lack of documentation of how tasks are shared between the company and the IT service provider. The matrix creates transparency with regard to the respective responsibilities and bolsters the effectiveness of the collaboration.
Fig. 1: RACI-Matrix
Risk register
In the risk register there is an assessment of the material risks arising from the relationship with the IT service provider. In this context, the relevant factors are, in particular, the vendor lock-in, the potential scope of a malfunction, the criticality of the application concerned as well as the relevant controls that are in place (cf. Fig. 2 Heatmap = presentation form that uses colour for the visualisation of data). On this basis, risks can be prioritised and measures can be derived.
Fig. 2: Heatmap
Regular risk analysis
IT service provider risks change over time owing to new systems, sub-contractors or regulatory requirements. For this reason it is essential to carry out a review of the assessment at regular intervals in order to identify changes at an early stage, to follow up outstanding measures and to keep responsibilities up to date.
Benefits for companies and auditing
Structured IT TPRM creates transparency with regard to IT service providers, their services and risks. Companies will be better able to manage critical dependencies, clearly allocate responsibilities and identify missing evidence early on.
A structured body of evidence likewise offers advantages for audits. Existing controls and documentation enable a more effective assessment of IT governance issues, such as, access rights, change management, operational processes and external IT service provider controls.