CRM Work Programs
CRM Work Programs
Association
[Link]
[Link]/auditprograms
Table of Contents
Audit Work Programs
1. Sales Risks
2. Marketing Risks
3. Customer Interaction Center and Field Service Risks
4. Data Management Risks
5. Integration Risks
6. Channel Management and Integration Risks
7. Telecommunication Infrastructure Risks
8. Security Risks
9. Project Management Risks
10. Benefit Realization
11. Organizational Change Management
12. Privacy Risks
[Link]/auditprograms
1.
The following work program will help address the sales risks within the organization. Those
auditing, reviewing or advising on controls in a CRM project will need to select tasks from the
work program and consider the key issues raised in the IT Governance Institute publication Risks
of Customer Relationship Management as part of their preparation. The work program should not
be used as a checklist of best practice, but as a selection of examples of good practice that can be
applied. By using the work programs blindly, there is a risk of losing the confidence of the auditee
and even of missing the largest risks in the project, due to the peculiarities of each project.
Therefore, work programs should be used as guidance with the specific knowledge of the
organization and risks added to them.
Note: A business objective may be listed more than once because it has multiple risks and
corresponding control objectives. Note disclaimer.
Business
Objective
Risk
Control
Comments/
Results/
W/P Ref.
[Link]/auditprograms
COBIT
Reference
PO1
PO3
PO6
PO11
M1
Business
Objective
Risk
Control
The organization
develops long-term
and profitable
customer
relationships.
The organization
may pursue nearsighted
relationships and
unprofitable
customers.
Procedures and
incentives for sales
personnel focus on
building long-term
relationships with
customers.
Management commits
appropriate resources to
the development of longterm customer
relationships.
Customer profitability is
measured and factored
into customer strategies.
Both financial and
nonfinancial
motivational techniques
and incentives are used
to reward and encourage
positive behavior that
aligns with the
organizations sales
strategy.
Realistic sales goals and
targets are created at the
organizational level and
also at an individual
level for each sales
person.
Progress against sales
goals and targets is
measured on a periodic
basis and feedback is
provided on an
organizational level and
individual level.
Participation in teambased selling is
encouraged within the
organization and is part
of each sales persons
performance assessment
criteria.
Sales personnel
work together as a
team.
Information may
not be shared
across the sales
team.
Conflicting
behavior within
the team may
exist.
There may be loss
of revenue.
Comments/
Results/
W/P Ref.
[Link]/auditprograms
COBIT
Reference
PO6
M1
PO7
M1
PO10
Business
Objective
Risk
Control
PO7
Roles and
responsibilities are
segregated to
increase selling
efficiency.
PO4
The organizational
structure reflects
the segmentation
of key customer
market segments.
Information about
customers is
disseminated
effectively
throughout the
organization.
Interdepartmental
The organizational
structure is designed to
provide a clear division
between sales personnel
and support personnel.
The support personnel
are effectively utilized to
reduce the amount of
administrative time for
sales personnel.
The sales
organizational structure
is designed to reflect
the segmentation of
key customer markets
and is continually
reevaluated as markets
evolve.
Sales personnel work
in teams that cross
departmental
boundaries to facilitate
knowledge sharing and
effective
communication about
all critical interactions
for a given customer
account.
Sales personnel
actions may be
focused on
short-term goals
(e.g., quick
sales) rather than
long-term
strategic goals
(e.g., building
customer
relationships and
long-term
profitable
customers).
Sales personnel
may spend too
much time on
noncustomerfacing
administration,
reducing the
time spent
engaged in salesrelated activities.
Sales resources
may be
misdirected.
communication
may be limited
and may impact
the
organizations
ability to share
knowledge
across all
customer
touchpoints.
Comments/
Results/
W/P Ref.
[Link]/auditprograms
COBIT
Reference
PO1
PO11
Business
Objective
Risk
Control
Channel
conflicts may
lead to wasted
resources and
missed sales
opportunities.
Succession
strategies minimize
the impact of
employee turnover.
Lack of
succession
planning could
result in a failure
to retain
intellectual
capital and
customer
contacts in the
event of sales
personnel
turnover, which
is typically very
high.
Comments/
Results/
W/P Ref.
[Link]/auditprograms
COBIT
Reference
PO1
M1
PO7
Business
Objective
Risk
Profitability is
regularly
monitored.
Revenue and
product forecasts
are updated in a
timely manner.
Compensation
plans are in
alignment with
corporate sales
objectives.
Control
Comments/
Results/
W/P Ref.
Potential
Sales managers regularly
profitability and
assess profitability by
value may not be
major accounts,
understood for
territories, and
major accounts,
locations/divisions
territories,
within the organization
locations and
and the results are
divisions.
communicated to all
relevant sales personnel
and management.
Reports on margin per
customer are a regular
activity to improve
profitability on low
margin customers (or to
cease trading with those
customers).
Inappropriate
Account plans are
targeting and
developed, and they
budgets may be
include profitability and
made for key
forecast information to
accounts.
assist in compiling
budgets for key account
targeting activities.
Cost of targeting and
managing the account
should be measured.
Inaccurate
Revenue and product
revenue and
forecasting information
product forecasts
is regularly updated and
may be made.
reflects the latest market
trends.
Significant deviations
from the original
forecast are investigated
to understand the impact.
There may be an The sales compensation
inability to
plan is designed to
motivate sales
reward sales
personnel to
performance in
achieve
alignment with corporate
corporate sales
sales objectives.
goals.
The sales personnel are
motivated to achieve
corporate sales goals and
objectives.
[Link]/auditprograms
COBIT
Reference
PO6
DS6
M1
DS11
DS6
PO9
PO11
Business
Objective
Risk
Control
Ineffective sales
skills may not be
addressed.
Lack of
understanding of
sales strategy,
goals and
objectives may not
be addressed.
Lack of
understanding of
organization
background,
product
information and
organization
policies may not
be addressed.
Difficulty in
identifying
performance
trends or problems
may occur.
There may be an
inability to
respond quickly to
changing market
conditions.
Appropriate training
resources are available to
ensure sales personnel
have the necessary skills
to sell and build
profitable customer
relationships.
Sales personnel are
provided regular
training.
Sales curriculum is
developed in conjunction
with sales management
on current topics,
policies, strategies, etc.
PO7
PO10
Sales performance is
regularly monitored to
assess sales personnel
performance, trends for
market segments, sales
personnel and key
customer accounts.
Key Performance
Indicators (KPIs)
including margin
analysis and customer
satisfaction ratings, are
monitored to actively
manage the sales
process.
M1
AI6
Sales performance
is actively
monitored.
Comments/
Results/
W/P Ref.
COBIT
Reference
[Link]/auditprograms
Business
Objective
Risk
Control
Sales management
supports sales
goals and
objectives.
Ineffective sales
teams or wasted
resources in
opportunities that
are not in
alignment with
sales goals and
objectives may
occur.
Lost opportunities
may occur.
Markets and
customer segments
are appropriately
targeted.
Inappropriate
market segments
may be targeted.
The sales
organization may
not focus enough
effort on the most
profitable
accounts.
Uninformed
decisions about
where to focus
sales efforts may
be made.
The performance of
sales management is
linked to sales goals and
objectives.
Sales personnel are
evaluated and
remunerated against the
sales objectives.
Sales opportunities are
linked to the sales goals
and objectives to ensure
that they are in
alignment with sales
goals and objectives
before time and
resources are spent
pursing the
opportunities.
Key market segments
are analyzed and the
most profitable accounts
identified.
Sales efforts are focused
where they will have the
greatest results.
Accurate and
complete market
segment data are
available to sales
personnel.
Changing sales
channels may
not be identified,
which may result
in lost sales
opportunities.
Comments/
Results/
W/P Ref.
[Link]/auditprograms
COBIT
Reference
DS1
PO11
DS1
DS8
DS7
DS8
M1
Business
Objective
Risk
Control
Sales opportunities
are recorded
completely,
promptly and
accurately.
Lost sales
opportunities may
occur.
Incomplete or
invalid sales
opportunity
information may
be obtained.
DS9
DS9
Only viable
opportunities are
pursued.
Sales opportunities
are only recorded
once.
Leads may be
incorrectly
classified and,
therefore, sales
opportunities
result in wasted
sales efforts.
Duplicate sales
opportunities may
be recorded.
Distortion of the
sales pipeline/
forecast may
occur.
Comments/
Results/
W/P Ref.
[Link]/auditprograms
COBIT
Reference
DS11
PO2
AI2
PO2
10
Business
Objective
Risk
Control
All sales
opportunities are
appropriately
evaluated.
Valid sales
opportunities may
not be pursued.
Invalid sales
opportunities may
be pursued.
Lessons learned
may not be
captured to better
identify and
quality
opportunities.
Management reviews
dismissed sales
opportunities for
appropriateness, lessons
learned, etc.
Formal criteria are used
to analyze each
opportunity and perform
an objective assessment
of whether to pursue the
opportunity. The criteria
should include a costbenefit analysis of the
opportunity.
Opportunities are
assessed against the
formalized criteria
before being rejected or
accepted.
Reasons are captured for
rejected opportunities.
High-level deadlines and
action plans are
developed for qualified
sales opportunities.
Comprehensive sales
opportunity data are
stored within the CRM
system.
Information is available
to qualify sales.
The CRM tracks
customer transaction
history and makes this
information readily
available during
opportunity analysis.
All required
information is
available to assist
with qualifying an
opportunity.
Information
necessary to
qualify a sales
opportunity may
not be available.
Customer history is
used to predict
future buying
patterns.
Customer
buying history
may not be
available to
assist in
analyzing sales
opportunities
Comments/
Results/
W/P Ref.
[Link]/auditprograms
COBIT
Reference
PO6
PO9
AI4
DS9
PO2
DS3
11
Business
Objective
Risk
Control
Comments/
Results/
W/P Ref.
[Link]/auditprograms
COBIT
Reference
DS3
PO9
PO10
DS11
AI1
12
Business
Objective
Risk
The appropriate
sales personnel
pursue sales
opportunities in a
timely manner.
Customer
requirements are
confirmed.
Control
Comments/
Results/
W/P Ref.
[Link]/auditprograms
COBIT
Reference
PO3
PO11
AI4
AI4
PO11
13
Business
Objective
Risk
Control
Customer
requirements are
realistic.
PO11
AI4
DS3
The customer is
offered the
correct/complete
product/service.
Unrealistic
customer
requirements
may lead to the
organizations
inability to
deliver, resulting
in an unsatisfied
customer and
potentially the
loss of the sales
opportunity.
Customers may
not be offered
the correct
product/service
or the complete
solution to their
needs.
DS8
Up-selling and
cross-selling
opportunities are
identified.
Opportunities to
up-sell/cross-sell
products/service
s to the customer
may not be
identified or
pursued.
Products/services data
are available and are
accurate and complete.
Guidance is distributed
for helping sales
personnel identify
solutions to meet the
customers needs.
Sales personnel are
trained in how to upsell/cross-sell
products/services.
The CRM application
automatically suggests
potential up-sell/crosssell opportunities.
The CRM application
provides tools/reports to
help management
actively monitor the
sales pipeline.
Management actively
monitors the sales
pipelines and tracks
opportunities and the
action items by date to
ensure timely follow-up.
Comments/
Results/
W/P Ref.
[Link]/auditprograms
COBIT
Reference
DS8
PO1
DS13
M1
14
Business
Objective
Risk
Control
Resources are
allocated to each
opportunity
according to its
size and
importance to the
organization.
Senior sales
personnel may
spend too much
time on minor
opportunities.
Junior sales
personnel may
pursue major
accounts.
Customer
requirements
may be
misunderstood.
Comments/
Results/
W/P Ref.
[Link]/auditprograms
COBIT
Reference
PO6
DS13
AI1
AI4
DS3
15
Business
Objective
Risk
Control
Nonstandard
quotes are
accurately
prepared.
Nonstandard
quotes may be
inaccurately
prepared and
may not be
authorized.
Quotes may be
created or
amended by
unauthorized
personnel that
could result in
an inappropriate
commitment to
sell goods or
services to
customers.
Quotes may be
created without a
specified time
period.
Therefore, the
organization
may be obligated
to provide the
product/service
at a locked price
indefinitely into
the future which
could result in
sales at lower
than the
effective market
price.
Access to create
quotes is restricted
to authorized
personnel.
Comments/
Results/
W/P Ref.
COBIT
Reference
AI4
DS13
DS5
[Link]/auditprograms
DS5
16
Business
Objective
Risk
Control
Proposals are
created accurately
and completely.
Proposals may
be prepared
incompletely or
inaccurately.
Therefore, they
may not address
the customers
needs.
Proposals are
created in a timely
manner.
The proposal
addresses the
customers
requirements.
Products/services
are easily
distinguished from
competitors.
Proposals may
not be prepared
in a timely
manner,
resulting in
forfeited sales
opportunities.
The proposal
may not respond
to the RFP or the
customers
requirements.
Comments/
Results/
W/P Ref.
COBIT
Reference
Proposal creation
procedures are
enforced and stipulate
the required
information for each
type of proposal.
Sales personnel are
trained in the
preparation of
proposals.
A quality review is
conducted of proposal
in which the proposals
are reviewed against
the original
requirements to ensure
that all the customer
requirements are met.
Proposal timelines are
identified and followed
during the creation of
proposals.
AI2
DS7
PO8
[Link]/auditprograms
PO1
AI1
PO6
AI1
17
Business
Objective
Risk
Control
Current product
pricing and
information is
available to sales
personnel.
AI3
DS3
DS5
The benefits of
winning the
proposal exceed
the cost of proposal
preparation.
A cost-benefit analysis
is prepared prior to
creating proposals to
ensure that the sales
are profitable.
There are mechanisms
to capture the full cost
of a bid/proposal
Only authorized
personnel can create or
modify proposals.
The CRM application
populates pricing and
other critical information
into the proposal
template.
Proposals are reviewed
and approved by
management.
PO6
DS1
Sales personnel
may not have
access to the
latest pricing and
product
information,
which could
result in
misleading
information
being supplied to
customers.
The cost of
preparing the
proposal may
exceed the profit
of the sale.
Proposals are
changed only by
authorized
personnel.
Inappropriate
changes may be
made to
proposals, which
may result in
inconsistent and
inaccurate
information
being presented
to customers.
Comments/
Results/
W/P Ref.
COBIT
Reference
DS5
DS9
[Link]/auditprograms
18
Business
Objective
Risk
Control
Customer
questions and
objections are
answered in a
timely manner.
Customer
questions or
objections may
not be
addressed,
resulting in a
lost sales
opportunity.
Sales personnel
may not be
familiar with
corporate
guidelines for
negotiating and
closing sales
transactions.
Procedures and
methodologies exist for
answering customer
questions and objections.
Sales personnel solicit
customer feedback as
part of the sales process
to identify customer
questions and objectives
not communicated.
For lost customers there
is a process for capturing
reasons why the
customer ceased trading
with the organization.
Market research or other
independent
organizations are
employed to
interview/discuss issues
with the lost customer
(control for loss of major
accounts only).
Sales personnel are
provided with
appropriate training for
negotiating and closing
sales.
Corporate guidelines
exist and are
communicated to sales
personnel for negotiating
and closing sales
transactions.
Comments/
Results/
W/P Ref.
[Link]/auditprograms
COBIT
Reference
DS4
DS8
AI1
DS7
AI4
19
Business
Objective
Risk
Control
Inactive sales
opportunities are
closed.
Inactive
opportunities
may remain
open in the
pipeline,
distorting the
sales forecast or
diverting sales
personnels
attention from
more profitable
sales leads.
Contract terms
and conditions
may be
misunderstood
or disputed by
the customer.
Important
contractual
clauses may be
omitted, thereby
exposing the
organization to
significant risk.
Comments/
Results/
W/P Ref.
Procedures include a
search for existing sales
orders before the entry
of a new sales order.
The CRM system detects
potential duplicate sales
orders.
Sales orders may Sales orders are entered
not be entered
promptly when received.
into the system
Monitoring controls are
in a timely
in place to analyze the
manner,
timeliness of order
resulting in
processing.
delays for the
customer.
[Link]/auditprograms
COBIT
Reference
AI4
M1
PO4
DS1
DS5
DS11
PO6
PO8
M1
20
Business
Objective
Risk
Customers calls
are answered
promptly.
Orders are
processed
accurately and
completely.
Control
Comments/
Results/
W/P Ref.
[Link]/auditprograms
COBIT
Reference
AI1
AI4
DS11
M1
DS8
DS9
M1
21
Business
Objective
Risk
Order pricing,
discounts and
payment terms are
approved.
Control
Orders may be
processed with
unauthorized
pricing,
discounts or
terms of
payment.
Customer orders
are controlled by
credit limits.
A customers
credit limit may
not be checked
prior to order
processing
which may
expose the
organization to
unnecessary risk
of bad debts.
Processing Internet Sales Orders
Comments/
Results/
W/P Ref.
[Link]/auditprograms
COBIT
Reference
AI2
DS5
DS11
M1
AI2
DS5
22
Business
Objective
Risk
Customers
personal
information is
protected.
Internet customers
are differentiated to
enable unique
needs to be met.
Control
The privacy of
customer
information
collected on the
web site may not
be safeguarded,
resulting in a
loss of customer
confidence.
Internet
customers may
not be identified
uniquely.
Internet customers
are authenticated.
Comments/
Results/
W/P Ref.
A formal privacy
policy governs the
treatment of customer
personal information.
The privacy policy is
communicated to all
customers via the web
site and has been
independently certified
(e.g., BetterWeb, CPA
WebTrust).
The system is
customized to identify
Internet users and
provide a tailored
environment for each
customer (e.g., access
to order history,
favorite links).
Internet procedures are
linked into the core
business to allow
customers the ability
to choose their channel
preference for returns,
future sales, sales
support, customer
service, etc.
Password standards
and controls are
enforced by the system
(e.g., minimum
password lengths,
disallowed common
passwords).
Each Internet session
timeouts after a
minimum period of
inactivity.
[Link]/auditprograms
COBIT
Reference
PO6
PO8
DS11
AI2
AI4
DS5
23
Business
Objective
Risk
Control
Service delays
and interruptions
may occur.
Internet sales
initiatives are
effective at
generating sales
with existing
customers and for
obtaining new
customers.
The
effectiveness of
Internet sales
initiatives may
not be measured.
The Internet
sales channel
may not be used
to its full
potential.
Insufficient and
inaccurate
information
about products
and services may
be available on
the web site.
Page links may
fail, resulting in
customer
abandonment.
Comments/
Results/
W/P Ref.
Server capacity is
appropriate for
maximum anticipated
customer volumes.
Server capacity is
constantly monitored
to identify potential
problems before they
occur.
Use of the web site is
monitored to assess its
effectiveness (e.g.,
abandon rates, repeat
customers).
Feedback is solicited
from customers about
the web site.
Web site improvement
recommendations are
prioritized regarding
the impact on sales,
cost-benefit, etc.
Improvement
recommendations are
incorporated into the
web site to make it a
more effective sales
channel.
Content management
software is used to
ensure that web site
product and service
data are accurate,
complete, current and
comprehensive.
All web site links and
operations are tested
prior to
implementation for
functionality and
stickiness.
[Link]/auditprograms
COBIT
Reference
DS1
M1
M1
AI4
AI6
DS8
DS9
AI5
24
Business
Objective
Risk
Web site
transactions are
valid.
Control
Web site
transactions may
be not verified
or authorized.
Fraudulent
transactions may
be processed.
Internet order
information may
not be complete
or accurate.
DS5
DS11
DS5
M1
Unauthorized
individuals may
process Internet
orders.
COBIT
Reference
Comments/
Results/
W/P Ref.
[Link]/auditprograms
DS5
25
Business
Objective
Risk
Control
Customer credit
card data are
secured from
unauthorized use.
Customer credit
card data may
not be
encrypted, which
could result in
credit card
information
being
compromised.
Delays may
occur in
shipping and
invoicing,
increasing the
potential for
cancelled orders
and customer
dissatisfaction.
Comments/
Results/
W/P Ref.
Contact information is
provided in the event
the customer needs to
call about a processing
error.
Shopping cart
information is
maintained to ensure
the sales order is
completely and
accurately captured.
The Internet order
entry system requires
that all key fields be
entered before the
order can be
submitted.
Customers are notified
if any required data are
missing.
Customer credit card
information is
protected during
transmission from the
web site by encryption
technology (e.g., 128
bit SSL encryption).
Credit card data are
stored in a secured
encrypted database
within the organization
and access is restricted
to authorized
personnel only.
The web site and CRM
application are
integrated.
Front- and back-office
systems are integrated.
Interface monitoring
controls ensure the
accuracy and
completeness of all
data transfers between
systems.
[Link]/auditprograms
COBIT
Reference
DS5
DS10
DS5
PO8
AI1
PO8
DS3
26
Business
Objective
Risk
Control
If customers do
not log out the
session, the
session may
remain active
after they have
left their
terminal.
Unauthorized or
fraudulent
transactions may
occur.
Processing Telephone Sales/Telesales
Stock availability
is confirmed with
the customer.
Customer sessions
are terminated after
they have logged
out.
Comments/
Results/
W/P Ref.
[Link]/auditprograms
COBIT
Reference
DS3
M1
DS8
DS11
DS5
27
Business
Objective
Risk
Telesales strategies
are properly
communicated to
sales personnel.
Telesales activities
are controlled and
monitored to
ensure goals are
met.
Control
Telesales
strategies may
not be properly
communicated
to sales
personnel.
Telesales
activities may
not be monitored
properly and,
therefore, sales
goals are not
met.
Comments/
Results/
W/P Ref.
[Link]/auditprograms
COBIT
Reference
AI4
PO1
M1
DS11
28
Business
Objective
Risk
Telesales personnel
are properly
trained and their
activities
monitored to
ensure their
conduct and
performance best
represent the
company in
meeting its
telesales
objectives.
Control
Comments/
Results/
W/P Ref.
Telesales
The company trains and
personnel may
routinely monitors the
not be
activities of telesales
adequately
personnel. Training may
trained. As a
include:
result, potential
- Use of sales
sales may be lost
literature
or optimum
- Responses to
customer
common questions /
satisfaction may
objections
not be achieved.
- Use of call scripts
- Increased emphasis
on listening
- Building rapport
- Understanding of
products and/or
services and how
they best fit the
customers buying
motives (e.g.,
financial benefits,
security,
convenience, sex
appeal, pleasure, and
acceptance).
Monitoring activities
may include:
- Periodic review of
sales calls
- Comparing actual to
budgeted goals
[Link]/auditprograms
COBIT
Reference
DS7
M1
29
Business
Objective
Risk
Sales personnel
identify and
manage their
objectives and
goals for each call.
Control
Customers are
contacted only
once per sales
opportunity.
Telesales
personnel may
inadvertently
contact a
customer that
has already been
contacted or
closed.
Comments/
Results/
W/P Ref.
[Link]/auditprograms
COBIT
Reference
PO1
DS1
PO9
DS5
30
Business
Objective
Risk
Control
Telesales personnel
utilize electronic
call worksheets
to ensure proper
information and
gathering of
information is
performed for each
prospect.
Call worksheets
may not be
utilized to track
telesales
activities.
Telesales personnel
interact with
customers in a
knowledgeable and
consistent manner.
Untrained or
inexperienced
telesales
personnel may
be inconsistent
or unknowledgeable. As a result,
customer
interactions may
not be
appropriate.
Environment is
free from excessive
noise to ensure
communication
between the
customers and
telesales personnel
is clear.
Customers may
not be able to
hear or
understand
telesales
personnel.
Comments/
Results/
W/P Ref.
[Link]/auditprograms
COBIT
Reference
PO9
M1
DS7
DS8
PO6
31
Business
Objective
Risk
Telesales personnel
are trained to
gather and analyze
customer
information to
ensure customers
needs/wants are
met successfully.
Telesales personnel
are trained to
ensure product/
service fits
customers needs.
Control
Customer needs
may not be
addressed
/identified fully,
resulting in loss
sales.
Comments/
Results/
W/P Ref.
[Link]/auditprograms
COBIT
Reference
DS7
PO7
DS7
PO7
32
Business
Objective
Risk
Control
Comments/
Results/
W/P Ref.
COBIT
Reference
DS5
Telesales
Telesales personnel
personnel may
have access to critical
not have access
customer information
to critical
to allow them to
customer
review and analyze
information.
customer information.
Note: Please refer to the Processing Sales Order section for additional telesales order controls and the
Customer Service section for additional controls for managing telesales personnel within the interaction
center.
Delivering Goods to the Proper Location at the Right Time
Goods are
AI2
Deliveries may
Deliveries completed
deliveries could
before the end of the
occur.
period are posted to
update the inventory
balances.
Goods are
DS1
Backorders and
Management
delivered to the
DS10
incomplete
periodically reviews
proper location at
orders may not
the list of backorders
the right time.
be processed
and releases them for
when items
processing.
become
available,
resulting in lost
sales and
customer
dissatisfaction.
Telesales personnel
are given
appropriate access
to customer
information.
[Link]/auditprograms
33
Business
Objective
Risk
Goods are
delivered to the
proper location at
the right time.
Goods are
delivered to the
proper location at
the right time.
Control
Comments/
Results/
W/P Ref.
Deliveries may
Goods can be posted for
not be processed
a delivery only if the
in the correct
following prerequisites
accounting
are fulfilled:
period if
- The data in the
procedures are
delivery must be
not established
complete.
to verify cutoff
- Picking must have
of shipments.
been completed for
This would
all items in the
result in
delivery.
misstated
Once a delivery has been
inventory and
processed, the following
cost of goods
functions occur:
sold, and a
- Stock quantities are
failure to invoice
updated.
the customer for
- Balance sheet
the sale.
accounts are
evaluated and
updated.
- Requirements are
reduced.
- The invoice is
processed.
Access to
Access to delivery
delivery
functions is restricted
processing
to delivery personnel.
functions may
not be restricted
to users in the
shipping
department, to
prevent
unauthorized
deliveries and
unauthorized
changes.
[Link]/auditprograms
COBIT
Reference
AI2
DS9
DS11
DS5
34
Business
Objective
Risk
Goods are
delivered to the
proper location at
the right time.
Goods are
delivered to the
proper location at
the right time.
Goods are
delivered to the
proper location at
the right time.
Goods are
delivered to the
proper location at
the right time.
Control
Comments/
Results/
W/P Ref.
[Link]/auditprograms
COBIT
Reference
DS11
DS10
DS10
PO6
M1
DS7
DS10
DS13
35
Business
Objective
Risk
Control
Goods are
delivered to the
proper location at
the right time.
Shipments may
not be accurate.
Comments/
Results/
W/P Ref.
authorized customer
order or delivery
documentation prior to
loading.
Order picking is
undertaken to ensure that
stock is picked on a
FIFO basis.
Goods dispatched
document is issued for
all deliveries.
Goods dispatched
documents are prenumbered and
sequentially controlled.
Order documents are
pre-numbered and
missing documents are
investigated promptly.
Key performance
indicators are:
- Order accuracy
- Percentage pick
accuracy
- Number of expedited
or emergency orders
by cause
A formal process exists
for verifying loads for
shipment (correct goods/
quantities and no
damage/mislabeling).
Packing materials,
containers and
procedures give
consideration to the
nature of the product and
method of delivery to
safeguard products.
Goods are checked for
accuracy, damage and
proper labeling/packing
prior to loading.
[Link]/auditprograms
COBIT
Reference
PO6
36
Business
Objective
Risk
Control
Goods are
delivered to the
proper location at
the right time.
Goods are
delivered to the
proper location at
the right time.
Shipping
documentation
may not be
accurate.
Comments/
Results/
W/P Ref.
[Link]/auditprograms
COBIT
Reference
PO6
PO11
AI2
PO4
DS7
DS13
37
Business
Objective
Risk
Control
Goods are
delivered to the
proper location at
the right time.
Foreign or other
unique customer
shipments may
not be delivered
to the customer
on time to the
right location.
Comments/
Results/
W/P Ref.
ensure proper
preparation, approval
and accountability over
bills of lading, air bills,
manifests or the
equivalent.
Final shipping
documents drive
customer billings as pick
tickets were updated
during loading.
Shipping documents are
cross-referenced
properly to the document
authorizing the
shipment.
Controls ensure goods
are shipped in
accordance with agreed
delivery term.
Appropriate procedures
exist for obtaining and
filing signed documents
and recording of seals on
all loaded trucks.
Key performance
indicators are:
- Undeliverable
shipments by cause
- Billing disputes by
customer/cause/
location
- Delivery document
accuracy percentage
- Credit memos by
cause
Formal processes exist
for preparing/processing
documentation for
foreign/other unique
customer shipments.
Export arrangements and
requirements are
separately determined
and take into account
methods of
transportation, packing
[Link]/auditprograms
COBIT
Reference
DS13
AI1
PO6
38
Business
Objective
Risk
Control
Comments/
Results/
W/P Ref.
COBIT
Reference
requirements, etc.
Export documentation
clearly defines when title
passes and when
responsibility for
insurance passes to the
importer.
Procedures are adequate
to ensure that all
necessary documents are
forwarded to customers
so that they are received
before goods arrive.
Customs classifications
for materials are
accurately defined for
customs purposes.
Applicable export
permits are obtained for
all shipments as
necessary.
Shipments classified as
containing hazardous
materials have required
transport/safety
documentation.
Controls in place for
return of signed
manifests documenting
final disposition on
hazardous loads.
[Link]/auditprograms
39
Business
Objective
Risk
Control
Goods are
delivered to the
proper location at
the right time.
Customer
shipments may
not be tracked
properly.
Goods are
delivered to the
proper location at
the right time.
Customers may
not be
communicated
with promptly
about goods
damaged, lost or
stolen in transit.
Comments/
Results/
W/P Ref.
[Link]/auditprograms
COBIT
Reference
DS13
PO4
PO8
M1
DS13
40
Business
Objective
Risk
Control
Comments/
Results/
W/P Ref.
[Link]/auditprograms
COBIT
Reference
DS1
DS1
41
Business
Objective
Risk
Customer sales
information is
completely and
accurately input.
Control
Customer sales
information may
be entered
inconsistently or
incompletely.
Requests may by
categorized
inconsistently,
resulting in
inaccurate
routing and/or
reporting.
Inquiries may be
categorized
inconsistently,
resulting in
untimely
resolution and
inaccurate
reporting.
Comments/
Results/
W/P Ref.
[Link]/auditprograms
COBIT
Reference
DS7
AI4
DS7
42
Business
Objective
Risk
Adequate
information is
captured about
customer inquiries.
Insufficient detail
as to nature of the
request may be
captured in initial
contact with
customer.
Control
Inquiries are
appropriately
prioritized, so that
they are addressed
in an appropriate
manner.
Inquiries may be
prioritized
inappropriately.
Inquiry resolution
information is
captured.
Sales personnel
may not provide
complete
descriptions of
how issues are
resolved.
Therefore,
request
resolution
information is
not available to
answer
subsequent
questions.
Comments/
Results/
W/P Ref.
[Link]/auditprograms
COBIT
Reference
DS7
DS7
AI1
M1
DS9
43
Business
Objective
Risk
Inquiries and
requests are
appropriately
closed.
Customers are
satisfied with the
request resolution.
Control
Inquiries and
requests may not
be closed
properly;
therefore, the
requests remain
open on the
system and
continue to be
worked on by
other employees.
Request
resolutions may
be closed
without the
customer being
satisfied with the
response.
Comments/
Results/
W/P Ref.
Procedures are
defined on how and
when to
appropriately close
a request or inquiry.
Monitoring
controls exist to
monitor open
requests or
inquiries to ensure
that they are closed
in a timely manner.
Customers are
surveyed
periodically to
determine
satisfaction. The
surveys include
feedback on system
accessibility, frontline
professionalism
and overall
satisfaction with
the way their calls
are handled.
When customers email addresses are
available, they are
e-mailed a
confirmation that
their request has
been closed and the
customers have the
ability to provide
feedback. Mail
confirmation is sent
if e-mail is
unavailable.
[Link]/auditprograms
COBIT
Reference
DS13
M1
DS1
44
Business
Objective
Risk
Customer feedback
is quantified and
analyzed on a
proactive basis.
Control
Sales personnel
may not be
effective in
handling
customer
inquiries.
Comments/
Results/
W/P Ref.
Management
notifies appropriate
individuals that a
complaint was filed
for their area of
responsibility.
Management and
the responsible
individual
determine and
implement an
action plan to avoid
the noted complaint
in the future.
The action plans
are documented
and monitored.
[Link]/auditprograms
COBIT
Reference
AI5
DS1
M1
45
2.
The following work program will help manage marketing risks within the organization. Those
auditing, reviewing or advising on controls in a CRM project need to select tasks from the work
program and consider the key issues raised in the IT Governance Institute publication Risks of
Customer Relationship Management as part of their preparation. The work program should not be
used as a checklist of best practice, but as a selection of examples of good practice that can be
applied. By using the work programs blindly, there is a risk of losing the confidence of the auditee
and even of missing the largest risks in the project, due to the peculiarities of each project.
Therefore, work programs should be used as guidance and specific knowledge of the organization
and risks should be added to them.
Note: A business objective may be listed more than once because it has multiple risks and
corresponding control objectives. Note disclaimer.
Business
Objective
Risk
Marketing Strategy
New product and
services offerings
are defined
accurately and
clearly.
Control
Comments/
Results/
W/P Ref.
Target audience
Expected revenue
stream
Time period
Cost
A process is in place
for gathering and
documenting the
technical specifications
and intended uses and
functional information
for products and
services, including, at a
minimum:
Product wear-out
rates
[Link]/auditprograms
COBIT
Reference
PO1
AI4
AI6
46
Business
Objective
Risk
Control
A process is in place
for the continual
generation and review
of new product and
service ideas.
DS3
Products are
available to ensure
a successful new
launch.
DS1
DS3
Market information
and research aids in
determining product
pricing.
PO10
DS5
Product pricing is
commensurate with
market conditions
and product
positioning.
Access is properly
restricted.
Organization
may not meet
sales and
marketing goals
because new
product and
service offering
possibilities are
not identified.
Product or
retailer
marketing
campaigns may
not consider
production
schedules or
inventory levels
resulting in
delays in product
delivery.
Contractual
defaults or
customer
dissatisfaction
may result.
Pricing may not
be appropriate
for product or
service
positioning,
resulting in a
loss of sales.
Pricing lists,
marketing
templates and
literature may be
altered without
authorization.
Comments/
Results/
W/P Ref.
[Link]/auditprograms
COBIT
Reference
47
Business
Objective
Risk
Control
Product
effectiveness is
monitored.
New product or
service offerings
may not be
measured,
resulting in the
inability to
determine the
success of the
new product or
service.
Comments/
Results/
W/P Ref.
[Link]/auditprograms
COBIT
Reference
M1
DS11
AI1
48
Business
Objective
Risk
Control
Competitor product
and service
offerings are
identified and their
impact on the
organizations own
product and service
range is fully
assessed.
Customer feedback
and survey
responses are
accurate.
The organization
may lose a
competitive
advantage by not
identifying a
competitors
changes in its
product and
service
offerings.
Inaccurate
customer
feedback and
responses to
marketing
surveys may
lead to
inaccurate
understanding of
customer wants
and needs.
Comments/
Results/
W/P Ref.
Regular comparison of
product and service
offerings is performed
against identified
competitors, and
improvements are
made to product and
service offerings, as
appropriate.
Procedures exist to
ensure that marketing
surveys and customer
feedback are accurate
and that questions are
not leading (i.e. forcing
or encouraging the
customer to answer a
certain way).
Customer feedback is
incorporated into the
processes to improve
products and services.
Regulatory barriers Regulatory
Regulatory barriers are
relevant to entering
barriers may
identified and assessed
a market are
delay or prevent
by marketing personnel
clearly understood.
entry into
and are taken into
markets
consideration when
significantly.
working with research
and development for
new products and
services.
Marketing Strategy Research and Execution (Market Segmentation)
Customer needs
Information about Marketing surveys are
and wants are
targeted consumers
used to understand
understood
may be poor or
customer needs and
completely.
unavailable.
wants. These surveys
contain information such
Customer
as:
expectations may
- Demographics
not be understood
- Preference
properly.
- Buying habits
[Link]/auditprograms
COBIT
Reference
DS3
PO3
AI4
AI5
PO10
PO8
DS1
49
Business
Objective
Risk
Control
Comments/
Results/
W/P Ref.
COBIT
Reference
DS1
Unclear or
Marketing personnel
outdated market
periodically evaluate
segment
existing market segment
definitions may
definitions.
lead to inefficient
Segment definitions are
campaigns and
updated periodically as
target marketing.
the market changes.
Marketing
PO5
Marketing dollars Marketing prioritizes
segments are
may be spent on
market segments based
prioritized and
market segments
on the organizations
campaigns are
that do not need
strategic plan, highest
appropriately
incentives
return, growth potential,
targeted to
provided or that
competitive advantage,
maximize return on
are not part of
etc.
investment for
managements
Campaigns are
marketing
strategic plan for
prioritized and targeted
expenditures.
targeting
toward the most
customers.
profitable market
Fewer sales leads
segments.
may be generated
as a result of
inappropriate
campaign
targeting.
Marketing Strategy Research and Execution (Marketing Campaign Planning and Execution)
Efficient
AI1
Inefficient and
Campaign management
campaigns are
ineffective
software and processes
conducted
campaigns,
are used to effectively
leveraging
which do not
plan, execute, track and
technology to
maximize the
analyze marketing
effectively
organizations
campaigns.
automate and
marketing
Marketing personnel
inform the
investment
measure each
processes of
dollars, may be
campaigns return-onplanning,
executed.
investment, time-toexecuting, tracking
market, campaign
and analyzing
execution, etc.
marketing
campaigns.
Market segments
are clearly and
properly defined.
[Link]/auditprograms
50
Business
Objective
Risk
Control
Comments/
Results/
W/P Ref.
COBIT
Reference
AI4
Clearly defined metrics
PO10
and objectives are in use
to track and review
campaign effectiveness
and return on
investment.
Management uses the
objectives and metrics to
assess campaign
effectiveness.
Metrics to consider
tracking are:
- Costs
- Return on
investment
- Customer response
- Customer action
Lessons learned are
tracked for both
successful and
unsuccessful campaigns,
and the lessons are
incorporated into future
campaigns.
Marketing Strategy Research and Execution (Capturing and Analyzing Marketing Strategy
Effectiveness)
The organization
PO2
Data mining techniques
Marketing
efficiently and
and software are used to
information that
effectively
analyze customer data.
has been
analyzes customer
Data mining techniques
gathered may
information.
may include:
not provide
- Product affinity
value.
analysis
- Customer retention
and vulnerability
- Customer
acquisition life cycle
- Price optimization
- Risk management
Data modeling
techniques are regularly
reviewed to optimize
interpretation of existing
data.
Campaign
effectiveness is
measured through
the use of clearly
defined metrics
and objectives.
Ineffective
campaigns may be
repeated due to
poor or undefined
metrics and
objectives.
Effective
campaigns may
not be detected
and therefore they
are not repeated.
[Link]/auditprograms
51
Business
Objective
Risk
Control
The marketing
strategy is
continually refined
based on new
customer data.
AI1
PO1
Management approval
procedures are in place
to select and review
marketing service
providers.
Formal vendor selection
and management
methodology is used.
Procedures to monitor
vendor viability and
creditworthiness are
used.
Periodic competitive
rebidding is required.
DS1
DS2
DS2
Vendor Management
Marketing service
providers meet
quality, quantity,
price, delivery or
other requirements.
Marketing
strategies and
campaigns may
not be effective
for current and
future trends.
Advertising
agencies, market
research
organizations and
other marketing
service providers
may not provide
value for services
purchased.
Organization
policy may not
require that service
providers be
selected through a
formal process,
using objective
criteria.
Contractual terms
may not be clear,
favorable to the
organization,
properly
enforceable or
competitive.
Vendor work meets Vendor quality
quality and
standards may
delivery standards.
differ in material
ways from those of
the marketing
organization,
leading to
substandard work.
Comments/
Results/
W/P Ref.
[Link]/auditprograms
COBIT
Reference
52
Business
Objective
Risk
Supervision of the
vendor by the
marketing
organization may
be difficult (if the
vendor is
physically remote).
Vendor employees
may breach
organization
standards related
to information
security and
confidentiality.
The vendor could
cease operations,
with resultant
losses or costs
related to
replacement of
services.
Marketing projects
may not be
managed properly.
Technology Management
Organization
Organization
technology
technology
infrastructure and
infrastructure and
design should be
design may not be
fully supportive of
capable of
all beneficial
supporting
marketing
competitive
activities.
marketing
activities such as
Internet web pages
or call centers.
Control
Comments/
Results/
W/P Ref.
COBIT
Reference
[Link]/auditprograms
PO2
AI2
53
Business
Objective
Risk
Implementation of
the technology
may fail. This may
be attributable to a
number of reasons,
including lack of
integration skill,
lack of user
involvement in the
implementation
project,
inappropriate
systems
architecture and
others.
Users may fail to
accept the new
system, in most
cases, because user
requirements were
not captured and
integrated into the
design properly.
Technology may
become obsolete,
due to rapid
change.
Benefits may not
be realized or may
be substantially
less than expected.
Legal and Regulatory
Marketing
Consumers
campaigns and
purchasing
literature meet
products based on
legal and
false or misleading
regulatory
claims may be able
restrictions.
to sue for damages
and regulatory
agencies may
intervene to stop
practices regarded
as misleading to
consumers.
Trademark
development may
infringe on the
Marketing
technology
implementations
are successful.
Control
Comments/
Results/
W/P Ref.
COBIT
Reference
AI1
AI3
PO1
PO5
A consistent review by
legal counsel of
marketing policies for
legal and regulatory
compliance, false
advertising, new
trademarks (trademark
infringement), customer
communications, etc., is
performed.
Time for legal review is
designed into an end-toend marketing process.
Proactive legal review is
exercised in the
PO8
[Link]/auditprograms
54
Business
Objective
Risk
Control
property rights of
other
organizations.
Materials similar
to another
organizations may
confuse
consumers, which
could lead to
litigation and
damages.
Adverse court
decisions related to
an organizations
trademarks and
materials may
require complete
rebranding and
repositioning, with
a total loss of the
organizations
initial marketing
investment.
Substantial cost
overruns related to
discarded print
runs, overtime,
vendor rush fees
and related costs
may be an issue.
Competition and
antitrust concerns
may be an issue.
Comments/
Results/
W/P Ref.
COBIT
Reference
development of
marketing materials, to
remove the task from the
project critical path.
Consumer Privacy
[Link]/auditprograms
55
Business
Objective
Risk
Control
Comments/
Results/
W/P Ref.
Marketers that
Privacy policies and
do not comply
procedures should be
with privacy
implemented and include
laws and
areas such as unsolicited
regulations may
customer contact and
increase the risk
disclosure of customer
of litigation,
information.
damages and
Cultural differences
adverse impacts
between countries are
to operations due
considered.
to regulatory
Marketers must establish
injunctions.
clear policy guidelines
for unsolicited messages,
which should include
classification of
messages by type and
channel, policy
regarding message
frequency, and
provisions for customer
opt-in and opt-out.
A policy regarding
message type or class
enables organizations to
differentiate policy
according to the purpose
and intent of the
message.
For additional privacy risks and controls, refer to the privacy work program, 12. Privacy.
Fraud and Unlawful Conversion
Fraud and unlawful Trade promotions, Basic risk management
conversion are
cash rebates,
controls, such as dual
prevented.
coupons,
approval, separation of
sweepstakes,
duties and independent
loyalty programs
audit, are a part of the
and other practices
marketing process where
may not comply
significant payments are
with fraud and
made to other parties.
unlawful
Incentive promotions
conversion
designed to reward
regulations
customers for specific
Misuse and abuse
behavior, such as making
of marketing funds
a purchase, are designed
may be an issue.
with controls to ensure
that reward payments are
Fraud may be an
earned and claimants are
issue
qualified to earn the
Compliance with
privacy laws and
regulations is
practiced.
[Link]/auditprograms
COBIT
Reference
PO8
M3
AI1
AI4
PO4
DS5
DS11
56
Business
Objective
Risk
Control
Organizations that
do not ensure that
benefit claims are
supported by proof
of eligibility risk
spending program
funds in a manner
that does not
effectively
influence
consumer
behavior.
incentive.
Proof of purchase is
required for
disbursement.
Aggregate claims are
matched to sales.
Analysis of claims
incidence by channel,
vendor, sales rep and
other key dimensions
can reveal a
disproportionate
incidence of claims
meriting further
investigation
Claims are checked
randomly, to validate
that claims are properly
earned and documented
Machine procedures are
used for random printing
and insertion of winning
tickets or coupons. In the
absence of machine
procedures, control over
winning tickets should
be based on dual
approval, employee
rotation and separation
of duties.
Security printing and
paper may be used to
reduce fraudulent
duplication of winning
tickets.
Mailing lists are seeded
with names supplied by
an independent listmonitoring agency, so
that the agency can track
the incidence of
communications to the
seed list by source, and
report findings to the list
owner.
Comments/
Results/
W/P Ref.
COBIT
Reference
[Link]/auditprograms
57
Business
Objective
Risk
Control
Comments/
Results/
W/P Ref.
COBIT
Reference
DS11
Communications Procedures are clearly
DS13
and offerings
defined and followed to
may not be
ensure that a market
reaching the
channel will link
target customers
customers to products
through the
appropriately.
appropriate
Communications and
channels,
offerings are sent to
resulting in
customers based on their
inefficient
preferences. For
marketing costs
example, a customer
and reach.
who prefers direct e-mail
promotions may only
want to receive e-mail
promotions and therefore
other channels may not
be effective (i.e.,
telesales, TV).
Marketing channel Marketing
AI1
Procedures are put in
analysis is
channel data
place to review
complete.
may be
marketing channel
incomplete,
information to ensure
resulting in an
that it is complete.
inaccurate
picture of
channel
effectiveness.
To further address channel management risks, refer to work program 6. Channel Management and
Integration Risk.
Marketing Literature Development and Fulfillment
Marketing
channels are
selected to align
the right customers
with the right
products.
[Link]/auditprograms
58
Business
Objective
Risk
Marketing
information and
content are
accurate.
Literature
requirements and
needs are defined
and addressed
completely.
Only authorized
changes to
literature are made.
Control
Comments/
Results/
W/P Ref.
Marketing
Marketing information is
content may be
verified for accuracy
inaccurate, or
prior to releasing the
contain false or
marketing literature and
misleading
communication to the
claims (e.g.,
customer.
claims
Management reviews
inconsistent with
marketing content to
product design
ensure that the marketing
or performance).
claims can be met (e.g.
product promises,
product availability, etc.)
Marketing content
complies with laws,
regulations and
organization policies on
business ethics, codes of
conduct and conflict of
interest to prevent
damage to the
organization's reputation.
Literature
Formal procedures exist
requirements
for gathering and
may not be
assessing literature
defined
requirements.
completely,
Marketing personnel
resulting in
ensure that all beneficial
ineffective
types of literature and
literature.
literature content are
developed and available
for products and
services.
Unauthorized
The ability to change
changes may be
printed or web-based
made to printed
literature is limited to
or web-based
appropriate personnel
literature.
and approved properly.
Version control
procedures are in place
for controlling updates to
literature files.
[Link]/auditprograms
COBIT
Reference
M1
PO8
AI4
DS5
DS11
59
Business
Objective
Risk
Control
Literature is
distributed
effectively and
properly tracked.
Requested
literature may
not be
distributed
properly to
customers or
prospects.
Customer feedback
is considered
during literature
design and update.
Literature is up to
date. Old literature
is destroyed on a
timely basis.
Customer
feedback may
not be
incorporated into
literature
updates or
development of
new literature,
resulting in lost
opportunities to
improve
literature quality.
Documents that
are outdated may
not be identified
and destroyed in
a timely manner.
Comments/
Results/
W/P Ref.
COBIT
Reference
The organization
utilizes collateral
management
technology or
sufficient manual
processes to fill
literature requests
from customers and
prospects accurately
and in a timely
manner.
Customer feedback is
reviewed formally and
incorporated into new
literature during
literature development
and update processes.
DS11
Literature preparation
personnel monitor
documents on an
ongoing basis to
ensure outdated
literature is identified
and removed from
circulation.
M1
[Link]/auditprograms
PO11
60
3.
The following work program will help manage customer interaction centers and field service
risks. For detailed work programs on the telecommunication equipment within interaction
centers, see work program 7, Telecommunication Infrastructure. Any person auditing,
reviewing or advising on controls in a CRM project will need to select tasks from the
work program and to consider the key issues raised in the IT Governance Institute
publication Risks of Customer Relationship Management as part of their preparation. The
work program should not be used as a checklist of best practice, but as a selection of
examples of good practice that can be applied. By using the work programs blindly, there
is a risk of losing the confidence of the auditee and even of missing the largest risks in the
project, due to the peculiarities of each project. Therefore, work programs should be used
as guidance, and specific knowledge of the organization and risks should be added to it.
Note: A business objective may be listed more than once because it has multiple risks and
corresponding control objectives. Note disclaimer.
Business
Objective
Risk
Control
Comments/
Results/
W/P Ref.
[Link]/auditprograms
COBIT
Reference
DS3
AI5
AI6
61
Business
Objective
Risk
Control
The interaction
center provides
customers a
positive and
reinforcing
experience when
using telephone
self-service.
Customer calls
may be dropped
once the call
enters the
IVR/CTI systems.
Network connections
between the CTI or IVR
systems and the backend database system
have sufficient
bandwidth to
accommodate customer
information requests.
Network connections
between the CTI or IVR
systems and the backend database are
monitored.
An alternative IVR
system is made available
in the event the back-end
database is unavailable
to ensure the customers
time is not wasted.
The IVR is easy to use
for requesting
information, such as
account information, and
manual intervention is
minimized for simple
self-service questions.
Customers may
zero out of the
IVR rather than
use automated
assistance because
the IVR is
confusing or
difficult to use.
Callers may
Callers are updated
become impatient
periodically with the
and dissatisfied
expected wait time while
with the
on hold.
organization due
Callers are provided
to inability to
alternative methods of
determine length
communicating with the
of hold time or due
organization, such as the
to excessive hold
web site, nonpeak hours,
times.
etc.
Callers waiting in
the queue are given
information on
expected wait time.
Comments/
Results/
W/P Ref.
[Link]/auditprograms
COBIT
Reference
AI3
DS4
DS13
DS3
DS3
62
Business
Objective
Risk
Web form/e-mail
requests are routed
to the correct
personnel for
response.
Web form/e-mails
are easily
integrated and read
by e-mail
management
software.
Customer requests
are immediately
acknowledged,
enhancing
customers
experience and
perception of using
chat for service.
Customer requests
are routed within
the interaction
center based on
nature of request
and workload.
Control
Comments/
Results/
W/P Ref.
[Link]/auditprograms
COBIT
Reference
DS13
DS11
DS13
DS1
DS13
M1
DS13
63
Business
Objective
Risk
Customer
information is
input completely
and accurately.
Customer
information is
input completely
and accurately.
Only authorized
personnel create
new customer
records.
Requests are
routed
appropriately and
reports on requests
are accurate.
Control
Comments/
Results/
W/P Ref.
[Link]/auditprograms
COBIT
Reference
AI5
DS11
PO7
DS7
DS11
DS5
PO4
DS1
64
Business
Objective
Risk
Control
Requests are
routed
appropriately and
reports on requests
are accurate.
Adequate
information is
captured on the
service request.
Service requests
are prioritized
appropriately, so
that they are
addressed in an
appropriate
manner.
Requests may be
categorized
inconsistently,
resulting in
untimely
resolution and
inaccurate
reporting.
Insufficient
detail as to
nature of the
request may be
captured in
initial contact
with customer.
Comments/
Results/
W/P Ref.
[Link]/auditprograms
COBIT
Reference
DS13
PO7
DS7
PO7
DS7
DS11
65
Business
Objective
Risk
Control
Customer service
levels are
accurately reflected
in the system.
Customers
service levels
may not be
recorded
appropriately in
the system.
Customers are
provided
appropriate
service.
Customer
expectations for
the level of
service they will
receive may not
be managed
appropriately.
Comments/
Results/
W/P Ref.
[Link]/auditprograms
COBIT
Reference
DS5
DS7
AI5
DS1
DS7
DS13
66
Business
Objective
Service request
resolution
information is
captured.
Risk
Control
Comments/
Results/
W/P Ref.
communicating service
levels.
A report is processed
periodically to identify
customers without a
service level or with
service levels that do not
match their current
service level.
Appropriate action is
taken to update service
levels.
The request resolution
field is configured as
required to ensure proper
documentation.
Contact center managers
perform quality
assurance on closed
service requests to
ensure the resolution is
documented adequately
and the customers
request was
appropriately satisfied.
For example, senior
managers regularly listen
in on live or recorded
calls for each front-line
worker to ensure that the
resolution is accurate
and documented
uniformly and
completely.
[Link]/auditprograms
COBIT
Reference
PO11
DS9
67
Business
Objective
Risk
Control
Comprehensive
documentation
standards exist.
Inadequate or
inconsistent
documentation
standards may
lead to a
difficulty in
retrieving
solutions to
problems.
Requests are
closed
appropriately.
Requests may
not be closed
properly;
therefore, the
requests remain
open on the
system and
continue to be
worked on by
other employees.
Comments/
Results/
W/P Ref.
Documentation
standards are defined
to ensure
comprehensive
documentation of the
resolution. Standards
include guidelines for
referencing related case
analysis, diagnostic
Q&A, decision trees,
search engines for
repositories of
technical documents,
FAQs and known
customer service
solutions, etc.
Procedures are defined
on how and when to
appropriately close a
request.
Monitoring controls
exist to monitor open
requests to ensure that
they are closed in a
timely manner.
[Link]/auditprograms
COBIT
Reference
PO11
AI4
AI4
M1
68
Business
Objective
Risk
Comments/
Results/
W/P Ref.
Customers are
surveyed periodically
to determine
satisfaction. The
surveys include
feedback on system
accessibility, front-line
professionalism and
overall satisfaction
with the way their calls
are handled.
When customers email address is
available, they are emailed a confirmation
that their request has
been closed and the
customers have the
ability to provide
feedback. Mail
confirmation is sent, if
e-mail is unavailable.
Customer feedback Customer
Management notifies
is quantified and
service may not
appropriate individuals
analyzed on a
be effective.
that a complaint was
proactive basis.
filed for their area of
responsibility.
Management and the
responsible individual
determine and
implement an action
plan to avoid the noted
complaint in the future.
The action plans are
documented and
monitored.
Services address
The needs of
Customer focus groups
the needs of all
specific
are used to determine
groups within the
customers may
the needs of specific
customer base.
not be met.
customer groups and
how well those needs
are being met.
Customer Interaction CenterOut Bound Processes
Customers are
satisfied with the
request resolution.
Control
Request
resolutions may
be closed
without the
customer being
satisfied with the
response.
[Link]/auditprograms
COBIT
Reference
AI4
DS1
DS8
M1
DS1
69
Business
Objective
Risk
Control
The system
automatically
reschedules calls for
busy signals and noanswers.
CSRs effectively
communicate the
organizations
message.
Comments/
Results/
W/P Ref.
[Link]/auditprograms
COBIT
Reference
AI1
AI2
AI1
AI2
AI1
AI2
70
Business
Objective
Risk
resolved in a
timely manner.
Requests are
resolved in a
timely manner.
Control
Comments/
Results/
W/P Ref.
COBIT
Reference
The system
customers
history.
automatically flags
potential duplicate
customer records during
entry.
Customer
Pick lists and field
information may
masks are used to
be entered
validate data entry (i.e.,
inconsistently or
pick lists for titles,
incompletely.
preferences, states, field
masks for phone
numbers, ID numbers
and credit card
numbers).
Key fields are required
to be entered.
Unapproved
Access to add new
customer records
customer information is
may be created.
restricted to appropriate
personnel.
DS9
Field service
Assignment rules are
cases may not be
designed appropriately
correctly routed
to consider geographical
to the field, e.g.,
location, employee
an incorrect field
expertise and availability
office.
when proposing
potential field service
personnel.
Procedures exist to
reroute incorrect
routings to another
office.
Field service
Adequate escalation
requests may be
procedures route cases to
assigned to
a higher level of
unavailable or
management if the cases
overworked
are not addressed in a
personnel.
specified period of time.
PO4
AI4
DS10
[Link]/auditprograms
DS11
DS11
DS5
AI4
DS10
71
Business
Objective
Risk
Requests are
resolved in a
timely manner.
Requests are
resolved in a
timely manner.
Reliable and
meaningful
information is
available for field
service request
resolution times.
Control
Comments/
Results/
W/P Ref.
[Link]/auditprograms
COBIT
Reference
PO4
AI1
DS5
DS!0
DS8
DS7
DS11
72
Business
Objective
Risk
Requests are
resolved in a
timely manner.
Customers are
satisfied with field
service request
resolutions.
Feedback is
utilized to provide
enhanced
solutions.
Control
Comments/
Results/
W/P Ref.
[Link]/auditprograms
COBIT
Reference
DS9
DS8
DS10
DS8
PO5
DS6
73
Business
Objective
Risk
Control
Customers are
appropriately
charged or not
charged for field
service calls.
DS6
Field service
inventories are
protected and
monitored
adequately.
DS9
DS11
Field service
performance is
understood and
measurable.
Performance
metrics may not
be calculated
due to
inconsistent
request closing
procedures.
Quality levels
may not be met,
resulting in poor
customer
satisfaction.
Lack of
appropriate
warranty-related
information
might result in
customers being
charged
inappropriately
or not charged
for the cost of
the repairs.
Field service
inventories may
be overstated as
a result of poor
parts
management.
Comments/
Results/
W/P Ref.
COBIT
Reference
AI4
DS7
PO11
PO10
PO11
[Link]/auditprograms
74
Business
Objective
Risk
Proprietary and
confidential
information is
properly restricted.
Solution
information is upto-date and easily
retrievable.
Control
Comments/
Results/
W/P Ref.
[Link]/auditprograms
COBIT
Reference
PO6
AI4
DS5
DS11
DS5
DS9
75
Business
Objective
Risk
Solution
information is upto-date and easily
retrievable.
Solution
information is up
to-date and easily
retrievable.
Solution
information is upto-date and easily
retrievable.
Solution
information is upto-date and easily
retrievable.
Control
Comments/
Results/
W/P Ref.
Ineffective
Customer feedback
solutions may be
regarding specific field
repeated for the
service solutions is fed
same problem.
into the solutions
knowledge database.
Field service personnel
also can propose
amendments or changes
to solutions.
Subject matter experts
review these
amendments and
changes and incorporate
them as appropriate.
The CSR may not The request resolution
provide a
field is configured as
description of how
required to ensure proper
the issue was
documentation.
resolved.
Management monitors
An inability to
solution information and
capture important
issue resolutions.
request resolution
information may
exist.
Inadequate or
Documentation
inconsistent
standards are defined to
documentation
ensure comprehensive
standards may lead
documentation of the
to a difficulty in
resolution. Standards
retrieving
include guidelines for
solutions to
referencing related case
problems.
analysis, diagnostic
Q&A, decision trees,
search engines for
repositories of technical
documents, FAQs and
known customer service
solutions, etc.
New solutions
CSRs are encouraged to
may not be
propose new solutions in
documented as
the solutions database
needed, resulting
and are recognized for
in a lack of
their effort.
knowledge
sharing between
CSRs.
[Link]/auditprograms
COBIT
Reference
DS11
DS13
DS9
M1
AI1
PO11
DS11
76
Business
Objective
Risk
Control
Solution
information is upto-date and easily
retrievable.
DS13
Solution
information is upto-date and easily
retrievable.
Responsibility and
accountability for
creating and maintaining
product and service
information are defined.
Product and service
information is stored in
an easily accessible and
searchable format.
CSRs may provide Return instructions are
customers
available online to the
inaccurate
CSRs.
information.
CSRs are trained
Customers may
appropriately on return
not follow return
policies and procedures.
and replacement
procedures
therefore their
returns are
rejected.
DS3
DS13
Solution
information is upto-date and easily
retrievable.
Policies and
procedures for
returns and
replacements are
followed.
Ineffective
solutions may be
repeated for the
same problem.
Problem
resolution data
may be
maintained
inconsistently.
Employees may
not be able to
extract knowledge
solutions in an
efficient manner.
Comments/
Results/
W/P Ref.
COBIT
Reference
PO1
PO3
AI4
DS7
People Management
[Link]/auditprograms
77
Business
Objective
Risk
Customers are
satisfied with the
level of service.
Customer requests
are responded to
efficiently.
Customer requests
are responded to
efficiently.
Control
Comments/
Results/
W/P Ref.
[Link]/auditprograms
COBIT
Reference
PO7
DS7
DS7
DS11
DS7
DS1
DS7
78
Business
Objective
Risk
Control
Training
initiatives may
be executed
poorly.
Personnel may
not be trained to
meet customer
needs
effectively.
A dedicated training
group is an integral part
of a successful
interaction center
operation.
Technical training
programs are delivered
by experienced subjectmatter experts to ensure
the skill and knowledge
transfer of information is
current and relevant.
Training programs are
subject to a beta test or
pilot test to solicit CSR
end-user feedback and
improve the training
program.
Formal training agendas
are prepared and
approved by
management.
Training curriculum
includes systems,
products, call types,
customer handling and
telephone skills.
CSRs are involved in
developing training
courses and management
approves course content.
Multiple training
methods are used,
including written tests,
telephone interviews and
role-playing to provide
comprehensive
scenarios.
Comments/
Results/
W/P Ref.
[Link]/auditprograms
COBIT
Reference
PO7
PO10
DS7
PO7
DS7
DS13
79
Business
Objective
Risk
Control
Customer
service needs
and workloads
may not allow
sufficient time
for proper
training.
Training may
not enhance
productivity.
Customers are
satisfied with the
service.
Customers may
be treated with
disrespect.
Customer requests
are responded to
efficiently.
Customers are
satisfied with the
service.
Customer requests
are responded to
efficiently.
Insufficient
detail as to the
nature of the
request may be
captured in
initial contact
with customer.
Customer
expectations for
the level of
service they will
receive may not
be managed
appropriately.
Service requests
may be routed to
inappropriate
individuals,
delaying
resolution.
Comments/
Results/
W/P Ref.
COBIT
Reference
DS1
DS7
PO7
DS1
DS13
[Link]/auditprograms
AI4
AI5
DS7
DS10
DS13
DS7
80
Business
Objective
Risk
Control
Customer service
representatives are
well trained.
Personnel may
not be trained to
manage
assignment or
workflow rules.
Contact center
personnel may
be inefficient
due to a poor
physical
environment.
PO7
PO8
DS12
Physical conditions
are sufficient to
allow interaction
center personnel to
operate effectively.
Comments/
Results/
W/P Ref.
[Link]/auditprograms
COBIT
Reference
81
Business
Objective
Risk
Workloads are
managed
effectively to
ensure high-quality
customer service.
Workloads are
effectively
managed to ensure
high-quality
customer service
while minimizing
costs.
Workloads are
managed
effectively to
ensure high-quality
customer service.
Control
Comments/
Results/
W/P Ref.
The interaction
Workload is forecast 12center may be
18 months in the future
inefficient and in
and is adjusted quarterly,
constant
monthly and weekly
response mode.
based upon current
information.
Attrition and training are
factored in the forecast
equation.
Forecasting accuracy is
tracked weekly and
monthly, in hopes of
achieving accuracy
within a +/- 2 percent
range.
In addition, periods of
excellent service levels,
not poor service, are
leveraged for goal
setting.
Workflow management
and work queue
management are used to
monitor agents
workload and to take
action to avoid backlogs
or bottlenecks from
developing.
All resources
Workload balance
may not be
efficiency strategies
leveraged for
include:
efficiency.
- Site consolidations
- Workload
balancing between
multiple interaction
centers
- Staggered shifts by
15-minute intervals
- Availability of parttime workers.
CSRs may
Contact center
become
managers monitor
overburdened
workloads of CSRs
and unable to
and take action to
answer customer
reassign requests to
requests in a
smooth the workload.
timely manner.
[Link]/auditprograms
COBIT
Reference
DS1
DS3
DS7
AI4
DS3
DS1
DS3
82
Business
Objective
Risk
Workloads are
managed
effectively to
ensure high-quality
customer service.
Workloads are
managed
effectively to
ensure high-quality
customer service.
Workloads are
managed
effectively to
ensure high-quality
customer service.
Workloads are
managed
effectively to
ensure high-quality
customer service.
The contact center
is managed
efficiently to
ensure high-quality
customer service
while minimizing
costs.
Control
Comments/
Results/
W/P Ref.
Contact center
interaction times are
tracked, monitored and
reviewed to help
ensure interaction
center efficiency.
[Link]/auditprograms
COBIT
Reference
DS3
DS3
DS3
DS1
DS1
DS3
83
Business
Objective
Risk
Control
Feedback may
not be compiled
to implement
continuous
improvement of
organization
practices.
Contact center
management
may not analyze
commonality
among service
requests,
forgoing any
potential
efficiency gains
from
incorporating
common service
request
information.
Personnel
monitoring may
be perceived
negatively by
personnel.
Comments/
Results/
W/P Ref.
Customer feedback is
summarized and used
to make decisions
regarding employee
incentives, policy and
procedure, resource
allocation and skill
needs.
Common service
requests are reported
in overall interaction
center statistical
information.
Common service
request resolution
information is
incorporated into the
web site FAQ
information and also in
the IVR.
CSRs are made aware
periodically of the
most common service
requests, to ensure
they are able to
efficiently answer
customer inquiries.
Policies state that the
primary purpose of
monitoring is to
identify individual
training needs as part
of an organizationwide
continuous
improvement effort.
[Link]/auditprograms
COBIT
Reference
DS3
DS1
DS1
84
Business
Objective
Risk
Control
DS1
DS3
Front-line
personnel
satisfaction may
not be valued
and
incorporated.
Customer
problems may
not be handled
efficiently.
Senior managers
regularly listen in on live
calls to stay in touch
with the customer and
with the effectiveness of
their interaction center
operations. For example,
team leaders typically
should monitor five to
ten calls per front-line
personnel per month.
Both silent/remote and
side-by-side monitoring
are used.
Team leaders shadow
front-line personnel for a
day to better understand
call operations, job
procedures, working
conditions and customer
expectations.
Front-line personnel
satisfaction is measured
as routinely as customer
satisfaction.
Comprehensive annual
surveys are compared to
specifically targeted
weekly and monthly
surveys to ensure
continuous
improvement.
Tracking of methods
utilized for problem
resolution is performed
to analyze effective vs.
ineffective methods.
Employee skills
may not be
updated
regularly in the
system.
PO7
Comments/
Results/
W/P Ref.
[Link]/auditprograms
COBIT
Reference
DS1
DS2
DS10
85
Business
Objective
Risk
Control
Requests
(including web
form and e-mail
requests) may
not be assigned
to appropriate
personnel in a
timely manner,
resulting in
customer
dissatisfaction.
Contact center
management monitors
outstanding requests
(including web form and
e-mail requests) to
ensure service requests
are addressed in a timely
manner.
Management monitors
average resolution time
for service requests.
DS1
M1
Outsourcing
arrangements
may not meet
expectations
resulting in poor
customer
service,
unresolved
customer needs,
etc.
DS2
M1
M1
DS3
DS13
Outsourcing
Outsourcing
arrangements are
managed properly.
Comments/
Results/
W/P Ref.
[Link]/auditprograms
COBIT
Reference
86
Business
Objective
Risk
Control
Comments/
Results/
W/P Ref.
COBIT
Reference
taken:
- Proportion of
callers to receive a
busy tone due to no
telecommunication
- Proportion of
callers to receive a
busy tone due to
operational policies
during the busy and
other hours
- Proportion of calls
that are abandoned
by department and
service line
- Length of time
customers have to
wait for an agent
when they are the
targets of an
outbound call (best
practice is zero and
acceptable
performance with
power dialer is 1
percent)
- The proportion of
average call
handling time to
talk time (best
practice is 95
percent or better)
- Proportion of
handling time to
information
system wait time
between screens,
for searches, etc .
(Best practice is
less than 5 percent
of contact time)
- Proportion of talk
time that is wasted
where the
customer or agent
is waiting or
something to
happen (best
practice allows 10
[Link]/auditprograms
87
[Link]/auditprograms
88
4.
The following work program will help manage data risks for customer relationship management.
Any person auditing, reviewing or advising on controls in a CRM project will need to select tasks
from the work program and to consider the key issues raised in the IT Governance Institute
publication Risks of Customer Relationship Management as part of their preparation. The work
program should not be used as a checklist of best practice, but as a selection of examples of good
practice that can be applied. By using the work programs blindly, there is a risk of losing the
confidence of the auditee and even of missing the largest risks in the project, due to the
peculiarities of each project. Therefore, work programs should be used as guidance and specific
knowledge of the organization and risks added to it.
Note: A business objective may be listed more than once because it has multiple risks and
corresponding control objectives. Note disclaimer.
Business
Objective
Risk
Control
Comments/
Results/
W/P Ref.
A strategy exists to
exploit data in the
organizations
possession to support
core business objectives.
Future CRM initiatives
are discussed by senior
management and
communicated to the
data team so that future
data needs can be
evaluated.
The data strategy is
formally documented
and approved by senior
management.
Senior management
views data management
as a strategic business
issue that is important to
the success of the
business.
Data management and
data quality are
discussed at senior level
management meetings.
The use of external data
from a third-party
vendor is reviewed.
[Link]/auditprograms
COBIT
Reference
PO1
DS2
89
Business
Objective
Risk
Control
Comments/
Results/
W/P Ref.
AI1
PO4
DS8
AI4
90
Excessive costs
may occur in
changing data
definitions and
structures.
Data needs may
not be met.
COBIT
Reference
[Link]/auditprograms
DS11
Business
Objective
Risk
Control
Comments/
Results/
W/P Ref.
A lack of focus
Roles and
may exist
responsibilities for data
regarding data
quality are identified
quality, resulting
clearly. For example, the
in poor data
roles and responsibilities
quality.
are documented and
communicated to the
user on an annual basis.
A formal group is
responsible for data
quality within the
organization.
There is one person or a
group of people
responsible for the
quality of data within
each business unit or key
category of information.
There is one person or
group of people
responsible for
responding when
problems are
encountered with data
within each business unit
or key category of
information.
Data may not be Management has
organized and
established categories of
understood.
data by level of
importance to the
business.
COBIT
Reference
PO11
PO10
PO2
Data
[Link]/auditprograms
91
Business
Objective
Risk
Sufficient audit
trails exist.
Control
Comments/
Results/
W/P Ref.
Research and
An audit trail is
forensics may
maintained in enough
not be able to be
detail to allow
performed due to
management to monitor
a lack of audit
the data warehouse
trails.
activities, transactions,
etc., and to meet the
needs of various internal
and external regulations.
Periodic, scheduled
audits are performed and
documented to verify
that established
procedures are being
followed.
An audit trail is
maintained in enough
detail and for an
adequate period of time
to allow management to
monitor the data
warehouse activities,
transactions, etc., and to
meet the needs of
various internal and
external regulations.
Preservation for a long
period is one of the most
important aspects of
audit trails (in many
cases also required by
regulation).
[Link]/auditprograms
COBIT
Reference
DS10
DS11
M4
PO8
92
Business
Objective
Risk
Data quality is
monitored.
Control
Comments/
Results/
W/P Ref.
[Link]/auditprograms
COBIT
Reference
PO11
DS8
DS11
PO2
DS11
PO4
DS5
93
Business
Objective
Risk
Control
Comments/
Results/
W/P Ref.
COBIT
Reference
[Link]/auditprograms
94
Business
Objective
Risk
Access to data is
restricted.
Control
Comments/
Results/
W/P Ref.
[Link]/auditprograms
COBIT
Reference
DS5
PO6
DS5
DS11
95
Business
Objective
Risk
Comments/
Results/
W/P Ref.
COBIT
Reference
DS11
96
Control
An inability to
make business
decisions due to
lack of data may
exist.
[Link]/auditprograms
Business
Objective
Risk
Control
A thorough review
has been
completed of the
existing data to be
converted.
Errors or
anomalies in the
old system may
not be identified
fully, and
corrections may
not be managed
properly.
The data
conversion system
design has
specified the
means to reconcile
both the old system
(internally) and the
old system to new
system on
commencement of
live production.
Balances from
the old system
may not be
transferred
properly to the
new system.
Comments/
Results/
W/P Ref.
[Link]/auditprograms
COBIT
Reference
DS5
DS11
AI1
AI4
AI5
M4
97
Business
Objective
Risk
Control
The data to be
converted from the
old system to the
new system have
been defined
properly.
Balances from
the old system
may not be
transferred
properly to the
new system.
Comments/
Results/
W/P Ref.
or phased
implementation,
procedures for the
different types of
reconciliations required
are identified.
Acceptance criteria, to
determine whether the
data conversion process
has been completed
successfully, are
defined and agreed
upon.
The responsibility for
sign-off and audit of
completion of the
conversion process is
defined and agreed
upon.
The documentation and
supporting materials to
be retained, as proof of
conversion, are defined.
A match exists between
all of the old system data
elements and the new
system data elements to
determine what will be
converted, what will not
be converted and what
will need to be created.
Requiring selection
criteria, purge criteria
and translation rules are
clearly identified,
documented and agreed
upon with users.
The validation of the old
data to the new system is
specified and agreed
upon.
Timing for the data
conversion is defined
and agreed upon with
users.
Issues of one-to-many
[Link]/auditprograms
COBIT
Reference
AI5
DS4
DS9
98
Business
Objective
Risk
Control
The protection,
adherence to and
maintenance of
data standards
may be
insufficient to
ensure the
integrity and
successful
operation of
systems.
Comments/
Results/
W/P Ref.
and many-to-one
conversions are resolved.
Field length and value
are analyzed.
The old system history,
the means of retention
(e.g., tape) and the
duration for which it is
to be held are defined.
Decisions are made in
relation to any redundant
data.
The means of formally
closing the old system
are defined.
The approach to data
cleanup is thoroughly
planned to ensure that
dependencies between
data items are
maintained.
Data items to be
amended and enhanced
are identified.
Criteria are agreed upon
for determining the data
conversion rules.
The tools/programs used
to effect changes to data
are tested and are
reliable.
An auditable trail of the
changes applied is
produced for
management review and
sign-off by the data
owner or nominated
deputies.
All changes applied are
reversible or can be
backed out by using
back-up copies of the
data.
Changes are never
applied directly to
production data.
[Link]/auditprograms
COBIT
Reference
AI5
AI6
DS11
99
Business
Objective
Risk
Control
Comments/
Results/
W/P Ref.
The protection,
Different means may be
adherence to and
used to create/convert
maintenance of
data for the new system,
data standards
such as developing
may be
custom programs or the
insufficient to
use of master file bulk or
ensure the
mass conversion tools
integrity and
(e.g., provided in the
successful
data warehouse or CRM
operation of
application). It is
systems.
necessary to ensure:
- If custom programs
are written, the
development and
testing process
follows the normal
system development
life cycle.
- If a scanning device
is to be used to
create data, it is fully
tested to determine
capacity, accuracy
and the contents of
file outputs.
- If a mass or bulk
conversion tool is
used, it is fully
specified and
documented, and
capacity needs
determined and
tested.
- If the data are keyed,
the input programs
are tested
appropriately and
data are verified on
input.
- If the data are keyed
by a third party (e.g.,
service bureau),
proper instructions
and input validation
must be specified.
- If data are acquired,
they are loaded onto
[Link]/auditprograms
COBIT
Reference
AI4
AI5
DS2
DS11
100
Business
Objective
Adequate project
management of the
data conversion
process is in place.
Risk
Errors or
Control
anomalies in the
old system may
not be identified
fully, and
corrections may
not be managed
properly.
Comments/
Results/
W/P Ref.
[Link]/auditprograms
COBIT
Reference
PO9
PO10
DS5
101
Business
Objective
Risk
Adequate testing
procedures for the
data conversion
system are in
place.
Sufficient training
and support exists
for data
warehouses.
Control
Comments/
Results/
W/P Ref.
The protection,
Unit, component, string
adherence to and
and system testing of all
maintenance of
parts of the data
data standards
conversion systems are
and testing may
completed in the same
be insufficient to
comprehensive manner
ensure the
as in a normal systems
integrity and
implementation.
successful
The testing to be
operation of
completed includes all of
systems.
the different means that
will be used in the
conversion process.
Depending on the
implementation strategy
used, this testing process
is completed on more
than one occasion.
Insufficient
Sufficient resources are
maintenance and
available to provide
support may occur
support and training of
for the data
data warehouse
warehouse.
personnel, end users, etc.
End users may not Staff members with
understand how to
responsibility for data
use the data
are trained in areas such
warehouse and,
as company knowledge
therefore, reject it.
systems, data quality,
and data ownership
responsibilities.
A structure exists by
which users can report
data problems to the data
and IT support
personnel.
There are documented
service level agreements
(SLAs) between
providers and users for
data deliverables.
[Link]/auditprograms
COBIT
Reference
AI5
DS1
DS7
102
5.
The following work program will help manage the integration risks for customer relationship
management. Any person auditing, reviewing or advising on controls in a CRM project will need
to select tasks from the work program and to consider the key issues raised in the IT Governance
Institute publication Risks of Customer Relationship Management as part of their preparation. The
work program should not be used as a checklist of best practice, but as a selection of examples of
good practice that can be applied. By using the work program blindly, there is a risk of losing the
confidence of the auditee and even of missing the largest risks in the project, due to the
peculiarities of each project. Therefore, the work program should be used as guidance and
specific knowledge of the organization and risks added to it.
Note: A business objective may be listed more than once because it has multiple risks and
corresponding control objectives. Note disclaimer.
Business
Objective
Data Consistency
Data are consistent
between systems.
Data Quality
Quality data are
maintained
between the
systems.
Risk
Control
Lack of
uniformity
across connected
systems may
cause conflicts
among the
applications.
When
combining
information
from multiple
systems into one
CRM
application, the
risk of
inaccurate data
may arise.
Inaccurate data
leads to lack of
user buy-in, loss
of customers,
and failure of
CRM adoption.
Comments/
Results/
W/P Ref.
COBIT
Reference
AI2
AI5
DS10
A comprehensive data
quality administration
or steering committee
can lead to the
institution of companywide data standards.
Data validation tools
are used to validate
data quality. Using
tools to periodically
identify and resolve
data quality issues
immediately can
mitigate the risk for
larger data quality
issues in the future.
Data quality linkage
among systems is
defined, maintained
AI5
AI6
DS10
[Link]/auditprograms
103
Business
Objective
Risk
Control
Data Structure
Data structures are
uniform between
systems.
Connectivity
Connectivity is
maintained to
allow data access
and transfer
between systems.
Comments/
Results/
W/P Ref.
COBIT
Reference
and measured.
Once a data quality
administration program
is implemented, the
following controls are
implemented as part of
the program:
- Concurrent access
that allows logic to
be updated with
many applications
linked to one
database/source
- Validation checks
- Data entry controls
- Change procedures
Without a standard
customer profile,
customer
information may
not be consistent
between systems.
Data loss and
inaccuracies may
occur.
PO2
DS11
PO9
PO11
AI5
When
combining
information
from multiple
systems into one
[Link]/auditprograms
104
Business
Objective
Risk
Control
CRM
application, the
risk of
inaccurate data
may arise.
Inaccurate data
leads to lack of
user buy-in, loss
of customers and
failure of CRM
adoption
Vendor Management
The CRM product
meets functionality
requirements and
the integration
effort is
reasonable.
Vendors are
researched
thoroughly to
understand the
integration effort.
Integration may
be too costly or
difficult.
Comments/
Results/
W/P Ref.
COBIT
Reference
[Link]/auditprograms
AI1
AI2
AI1
AI2
105
Business
Objective
Risk
Due diligence
performed by the
company to ensure
that the product
meets
requirements, the
vendor and
product are stable,
etc., may be
inadequate.
There may be a
lack of quality of
support from the
vendor, therefore,
when issues arise;
the vendor may
not be responsive.
System Maintenance/Manageability
System
A change in one
documentation is
area may affect
maintained.
numerous
connected systems,
cascading into
voluminous reworking and retesting of
previously
established
connectivity.
Potential system
downtime, data
and productivity
loss, and
reconfiguration
struggles may
occur.
Vendor
performance meets
the needs.
Control
Comments/
Results/
W/P Ref.
COBIT
Reference
Proper research is
performed on CRM
vendors to identify
integration and
functionality issues that
may exist within the
product itself.
Prior to purchasing a
vendor product,
management performs a
thorough check of the
vendor including
reference checks,
financial position check,
escrow agreements, etc.
AI1
AI2
DS9
A system maintenance
and modifications
strategy is developed,
including periodic
releases of changes to
customers, change
approval, modification
rules (vanilla vs.
modifications allowed),
etc.
Systems documentation
is maintained for
integration issues
encountered on the
project, e.g.,
connectivity difficulties.
Changes to systems,
applications and
connectivity adapters are
recorded to help transfer
knowledge to future
systems administrators.
PO6
PO11
AI1
AI6
[Link]/auditprograms
106
Business
Objective
Risk
Control
System
obsolescence is
avoided.
Technical
obsolescence may
occur.
There may be a
lack of vendor
support for older
systems.
AI3
AI4
DS9
Post-upgrade
testing is
performed.
DS11
Interfaces are
manageable.
When systems
are processing
smoothly
without incident,
administrators
may feel that
post-upgrade
testing is an
unnecessary
step. Therefore,
testing may not
be performed
thoroughly.
Interfaces may
grow
exponentially
because of the
number of
applications that
need to be
integrated for the
CRM solution.
Changes in one
application may
ripple through
other systems,
potentially
delaying data
movement.
Comments/
Results/
W/P Ref.
[Link]/auditprograms
COBIT
Reference
AI3
AI5
PO11
107
Business
Objective
Risk
System Performance
The system is
The amount of
scalable.
data being
transferred,
acceptable speed
of data transfer or
the number of
concurrent users
may increase, thus
increasing
uncertainty about
stability and
response time.
The system may
be unstable,
resulting in loss of
data, loss of
productivity and
user
dissatisfaction.
Data are updated in CRM users may
a timely manner.
not be able to
access customer
data in a timely
manner.
Control
Comments/
Results/
W/P Ref.
COBIT
Reference
PO9
AI5
DS11
A proper assessment
based on industry,
volume and number of
users is performed to
determine if data needs
to be processed in real
time or with batch
processing.
By taking this hybrid
approach to data flow
and minimizing the realtime processing needed,
an organization may
avoid system
performance risks and
still meet user needs.
DS3
DS7
[Link]/auditprograms
108
Business
Objective
Risk
Control
Comments/
Results/
W/P Ref.
[Link]/auditprograms
COBIT
Reference
DS4
109
Business
Objective
Risk
Control
Comments/
Results/
W/P Ref.
[Link]/auditprograms
COBIT
Reference
PO7
AI4
DS1
110
6.
The following work program will help in channel management and in managing the integration
risks for customer relationship management. Any person auditing, reviewing or advising on
controls in a CRM project will need to select tasks from the work program and to consider the
key issues raised in the IT Governance Institute publication Risks of Customer Relationship
Management as part of their preparation. The work program should not be used as a checklist of
best practice, but as a selection of examples of good practice that can be applied. By using the
work programs blindly, there is a risk of losing the confidence of the auditee and even of missing
the largest risks in the project, due to the peculiarities of each project. Therefore, work programs
should be used as guidance, and specific knowledge of the organization and risks should be added
to it.
Note: A business objective may be listed more than once because it has multiple risks and
corresponding control objectives. Note disclaimer.
Business
Objective
Channel Strategy
Channel strategy
provides profitable
customer
relationships.
Risk
Control
Messages across
channels may not
be consistent.
Each channel or
department may
operate
independently, i.e.,
silo behavior.
Channels may not
match the demands
from primary
customer segments
of the
organization.
Comments/
Results/
W/P Ref.
COBIT
Reference
PO1
[Link]/auditprograms
111
Business
Objective
Risk
Control
Consistent
information is
provided across
channels.
Information
regarding product
availability,
features and price
may not be
consistent across
channels.
Customers may
not know what
price, promotion
and general
experience to
expect each time
they contact what
they perceive to be
the same
organization.
Each sales
channel is
treated as a
separate
operating unit
and configured
as a separate
organization,
which may
generate
conflicting
information and
sometimes may
create competing
brands.
Inexperienced
CSRs may not
understand the
functionality,
policies and
procedures of all
channels (e.g.,
Internet, kiosks,
telemarketing,
face-to-face
sales, etc).
Cross-functional teams
compare information
across channels.
Changes to information
are considered and
agreed upon across all
channels.
AI2
DS11
DS7
CSRs understand
functionality,
policies and
procedures across
channels.
Comments/
Results/
W/P Ref.
[Link]/auditprograms
COBIT
Reference
112
Business
Objective
Risk
Control
Data are
normalized across
all channels.
Data and
customer
feedback may
not be obtained
from all relevant
channels.
Silo CRM
solutions may have
been built to
service new
customer-facing
channels.
Inconsistent
service,
information and
procedures across
channels may
exist.
Up-to-date
Customers may
information is
make repeated
available.
attempts to get
tasks completed.
Customer Experience
Customers are
Customers may
provided with a
not be provided
variety of channels.
with the right
variety of
channels;
therefore, they
cannot interact
with the
organization
using their
preferred
channel.
Comments/
Results/
W/P Ref.
[Link]/auditprograms
COBIT
Reference
DS11
DS11
AI6
DS11
M1
113
Business
Objective
Risk
Control
Customers
interaction occurs
through their
preferred channels.
Customer channel
preferences are
understood and future
contact with customers is
via their preferred
channel.
Customers have the
freedom to interact with
the organization via
multiple channels, and
they are not restricted to
only one or two
channels.
Organizations fully
explore new
communication or
distribution media to
understand how they fit
into their overall CRM
picture before offering
the media to their
customers.
DS8
DS13
PO7
DS6
Customers
interaction may
not be
communicated
via their
preferred
channel.
Organizations may
rush to the next
communication or
distribution
medium out of
competitive
necessity before
studying how it
will fit into their
overall CRM
picture.
Customer
experience may
not be satisfied
despite the
addition of new
channels.
Channel
development may
be unbridled,
therefore wasting
resources.
Leverage of Customer Information
Cross-selling
Cross-selling
opportunities are
opportunities
identified.
may not be
identified due to
inadequate
information
across channels.
The organizations
channels enhance
the customer
experience.
Comments/
Results/
W/P Ref.
Channel information is
consolidated and
reviewed for possible
cross-selling
opportunities.
[Link]/auditprograms
COBIT
Reference
DS7
DS8
114
Business
Objective
Risk
Control
Customer
profitability is
measured across
channels.
Customer analysis is
performed to identify the
least and most profitable
customers across sales
channels.
Priority queuing is used
to move less-profitable
customers to channels
that cost less to service.
Profitability
information may
not be shared
across channels;
therefore,
management
will not have a
full view of the
customer.
Comments/
Results/
W/P Ref.
[Link]/auditprograms
COBIT
Reference
DS6
115
7.
The following work program will help manage the telecommunication infrastructure risks for
customer relationship management. Any person auditing, reviewing or advising on controls in a
CRM project will need to select tasks from the work program and to consider the key issues
raised in the IT Governance Institute publication Risks of Customer Relationship Management as
part of their preparation. The work program should not be used as a checklist of best practice, but
as a selection of examples of good practice that can be applied. By using the work programs
blindly, there is a risk of losing the confidence of the auditee and even of missing the largest risks
in the project, due to the peculiarities of each project. Therefore, work programs should be used
as guidance, and specific knowledge of the organization and risks should be added to it.
Note: A business objective may be listed more than once because it has multiple risks and
corresponding control objectives. Note disclaimer.
Business
Objective
Call Handling
Calls are received,
routed and handled
properly resulting
in prompt
resolution.
Risk
Control
Calls may be
blocked.
Calls may be
dropped.
Calls may be
misdirected.
Unauthorized
database access
may occur.
Comments/
Results/
W/P Ref.
ACD implementations
are tested properly to
ensure they are coded
correctly to route calls
to the proper agent, to
provide correct
announcements to a
caller and to place calls
into voice mail.
Only trained personnel
can make changes to
ACDs and those
changes are tested in a
controlled environment
at offpeak times.
Other controls include
properly configuring
the tables that
indicating to the longdistance telephone
organization where toll
free 800 numbers
should terminate.
[Link]/auditprograms
COBIT
Reference
AI3
AI5
AI6
DS7
DS9
116
Business
Objective
Implementation
Telecommunications infrastructure
is implemented
properly.
Risk
Control
Applications and
systems may fail
from incorrect
configurations or
inadequate
engineering.
Changes may
falsely appear to
be successful,
and are later,
during call center
peak operations,
found out to be
defective.
Data
communications
and voice
communications
may not be
coordinated
properly.
Redundancy may
not be built into
the systems.
Agents may not
be comfortable
with
modifications to
call flows or
their work
menus.
Response time
degradations
may exist.
Comments/
Results/
W/P Ref.
Software is tested to
detect programming
errors.
Software is tested to
ensure it operates as
intended in a live
environment.
Modifications made
subsequent to initial
testing are retested.
Systems and
applications are backed
up prior to installation.
Implementations are
authorized and signedoff by management.
Application features are
documented.
Users are trained on the
software.
Acceptance testing and
operations (e.g., backup
and recovery) testing
are performed.
Formal change
management
procedures exist.
[Link]/auditprograms
COBIT
Reference
AI3
AI5
AI6
117
Business
Objective
Efficiency
Customer
interaction center
operations and
systems are
efficient.
Risk
Control
Serious service
level impairment
and excess costs
may exist.
The contact
center may not
be organized and
tooled
effectively so
workers have to
get up for
faxing, obtaining
reference
material, and
performing other
business
functions away
from their
workstation.
DS1
Customer
interaction
center operations
may be
interrupted.
Customers may
be dissatisfied.
Costs may be
excessive.
DS2
Business Continuity
Business continuity
and disaster
recovery plans can
recover systems
and operations
quickly.
Comments/
Results/
W/P Ref.
[Link]/auditprograms
COBIT
Reference
M1
DS4
118
Business
Objective
Risk
Control
Comments/
Results/
W/P Ref.
COBIT
Reference
[Link]/auditprograms
119
Business
Objective
Security
Physical security
exists over the
PBX room, adjunct
equipment and
wiring closets.
Risk
Control
Service may be
disrupted
intentionally.
Equipment and
wiring may be
damaged
accidentally.
Unauthorized
access to
confidential
information
(e.g., voice mail
data) may be
granted.
Users and
telephones are
assigned only the
level of telephony
access needed for
employees to
perform their work.
Users whose
duties do not
require longdistance dialing
may make
unauthorized
domestic and
international
long distance
personal calls at
the
organizations
expense.
Telephones in
lobby areas,
conference
rooms and other
public areas may
not be restricted,
so they may be
used to make
Comments/
Results/
W/P Ref.
[Link]/auditprograms
COBIT
Reference
PO4
DS12
DS5
DS12
120
Business
Objective
Risk
Control
unauthorized
long distance
calls.
Comments/
Results/
W/P Ref.
COBIT
Reference
for testing
purposes. It can
also be used to
perpetrate toll
fraud.
3) If it is required for
business purposes,
only trained
operators should
have the trunk-totrunk feature that
allows them to
connect an
incoming caller to
an outbound trunk.
This feature is
commonly used to
perpetrate toll
fraud.
4) Conference room
phones should not
have international
dialing privileges.
Profiles are developed
for broad classes of
positions, including
contractors,
administrative
assistants, executives,
switchboard operators
and the standard
profile for most
employees. These
profiles relate to
classes of service and
other determinants of
functionality.
[Link]/auditprograms
121
Business
Objective
Risk
Control
Password controls
exist for the PBX,
voice mail and
other adjunct
equipment.
Unauthorized
personnel may
dial into the
PBX
maintenance
port and obtain
the superuser
ID(s) via a
password
cracking utility.
With this level
of access,
telephone
records may be
destroyed, and
critical system
parameters could
be changed.
Changing
parameters, such
as class of
service, may
shutdown the
PBX.
Confidential
information left
in employees
voice mail boxes
may be obtained
and greetings
may be altered
maliciously.
Comments/
Results/
W/P Ref.
Standard good
practices for passwords
are used for all users,
administrative users
and super users,
including:
- Adequate password
length
- Hard-to-guess
sequences
- Elimination of
installation default
passwords
- Published policies
and procedures for
all users
- Mandatory
password changes
every 60-90 days
[Link]/auditprograms
COBIT
Reference
DS5
122
Business
Objective
Risk
Control
Inactive or unused
resources are
deleted.
Unauthorized
individuals may
utilize
abandoned or
unused voice
mail boxes for
illegal and
untraceable
activities.
Analog lines
connected to
modems may be
used to break
into computer
systems by
bypassing the IP
firewall via the
voice network,
and then
compromising
ID passwords to
enter the PBX or
voice mail and
shutdown
services.
Comments/
Results/
W/P Ref.
Using telephony
management tools,
assets are reviewed for
currency and last date
of use. Unused
facilities are made
inactive or reused. For
example, voice mail
boxes and IDs of
terminated employees,
unused or unneeded
analog lines, modem
facsimile lines, and
telephone extensions
are removed.
IDs are examined for
good practices, such as
avoidance of common
names, etc.
[Link]/auditprograms
COBIT
Reference
DS5
DS13
123
Business
Objective
Risk
Control
Security
parameters may
be set to default
or uncontrolled
values.
Intruders may
easily penetrate
the PBX and
commit toll
fraud by illegally
selling the
organizations
long-distance
services to
others without
the
organizations
knowledge or
authorization.
Unauthorized
personnel may
place longdistance and
international
calls, causing the
organization,
instead of the
individual who
placed the calls,
to incur
fraudulent
charges for the
calls.
Comments/
Results/
W/P Ref.
[Link]/auditprograms
COBIT
Reference
AI3
DS5
124
Business
Objective
Risk
Control
Telecommunications
documentation is
secured.
Specific functions
that are known to
create
vulnerabilities are
reviewed to ensure
that if they are not
disabled,
management has
made a conscious
decision to keep
them active based
on business needs.
Trunk access
codes, the
maintenance
port dial-in
number, and
other sensitive
information may
be obtained
internally and
used for
unauthorized
penetration of
the PBX.
Hackers may use
the call forward
external feature
to perpetrate toll
fraud. They may
accomplish this
by having an
accomplice call
forward phones
to an
unauthorized
domestic or
international
location, then
call that
extension so
they are
forwarded to the
intended
number.
Hackers may
penetrate users
voice mail, enter
a two digit code,
get dial tone and
make calls
anywhere in the
world.
Comments/
Results/
W/P Ref.
COBIT
Reference
Manual documentation
containing critical,
security-related
information is stored
in locked cabinets.
Sensitive electronic
documentation on CDROMs is protected
adequately with
passwords and other
standard security
measures.
AI4
DS5
Management
periodically review the
security structure of the
PBX, voice mail and
adjuncts to ensure that
excessive permissions
are not granted.
Examples include:
- Blocking area
codes where no
business is
conducted
- Eliminating the
ability to get dial
tone from voice
mail
- Eliminating the
call forward
external feature on
most telephones
- Limiting call-out
features within the
data center
- Limiting lobby
telephones to local
calls only
PO2
PO4
AI6
DS5
[Link]/auditprograms
125
Business
Objective
Risk
Control
Unauthorized
individuals may
obtain the range
of telephone
numbers used in
an organization
and war dial to
identify the PBX
maintenance
port.
Using password
crackers and
other techniques,
hackers may
penetrate the
PBX and voice
mail systems.
A break-in may
occur and not be
detected until the
volume of toll
fraud activity
becomes
significant
enough to cause
obvious
problems, such
as excessive
busy signals,
indicating all
trunks are being
used for
unauthorized
traffic.
Comments/
Results/
W/P Ref.
[Link]/auditprograms
COBIT
Reference
PO4
AI2
AI4
DS13
PO2
M1
126
Business
Objective
Risk
Control
Alarm systems
provide real-time
alerts that
operational
problems or
unusual events,
possibly
fraudulent, are in
progress.
Telecom
expenditures are
monitored.
Unauthorized
access may be
gained to the
PBX
maintenance
port by repeated
attempts to crack
the ID/password
combinations.
Unauthorized
attacks may not
be detected.
Operational
malfunctions
may not be
detected, so
telephone
service may be
interrupted.
Employees may
incur large
internal
telephone
charges for the
organization by
frequently
placing personal
calls to longdistance or
international
locations.
Telecom charges
may be
summarized at a
high level so that
their
inappropriate or
fraudulent
activity is not
detected.
Comments/
Results/
W/P Ref.
COBIT
Reference
PBX management
software monitors both
potential fraudulent
activities as well as
operational
malfunctions, such as
failed trunk lines or
PBX call flow
interruption.
Procedures exist for
promptly investigating
and resolving
fraudulent activities
and operational
malfunctions.
AI4
DS5
DS10
Charge-back reports
are produced every
month showing
telecom expenditures
at the departmental
level to identify
charges that indicate
either internal abuse or
external toll fraud.
Managers review
charges via a browser
and are able to quickly
identify suspicious
activity or charges.
Telecom charge-back
reports are produced
with sufficient detail to
enable detection of
inappropriate or
fraudulent activity.
Examples of reports
include calls to tollfraud hot spots, the top
20 long duration calls
and the top 20 most
expensive calls.
DS1
DS6
M1
[Link]/auditprograms
127
Business
Objective
Risk
Control
External
monitoring
provides a second
line of defense
against toll fraud.
Unauthorized
individuals,
having thwarted
the
organizations
internal barriers
to toll fraud,
may have free
reign to the PBX
and pass
thousands of
calls through the
victim PBX,
resulting in very
large longdistance or
international
charges.
Unauthorized
individuals may
commit toll
fraud.
The PBX may
be compromised
resulting in a
large financial
loss.
Security restricts
access to sensitive
powerful functions.
As a last line of
defense, the
organization
maintains toll fraud
insurance.
Comments/
Results/
W/P Ref.
[Link]/auditprograms
COBIT
Reference
M1
DS5
PO8
128
8.
The following work program will help perform a high-level security audit and manage the
security risks for customer relationship management. Any person auditing, reviewing or advising
on controls in a CRM project will need to select tasks from the work program and to consider the
key issues raised in the IT Governance Institute publication Risks of Customer Relationship
Management as part of their preparation. The work program should not be used as a checklist of
best practice, but as a selection of examples of good practice that can be applied. By using the
work programs blindly, there is a risk of losing the confidence of the auditee and even of missing
the largest risks in the project, due to the peculiarities of each project. Therefore, work programs
should be used as guidance and specific knowledge of the organization and risks added to it.
Note: A business objective may be listed more than once because it has multiple risks and
corresponding control objectives. Note disclaimer.
Business
Objective
User Management
Default accounts
are safeguarded.
Risk
Control
Comments/
Results/
W/P Ref.
Default accounts
The default accounts
may be
(e.g., administrator and
compromised.
guest accounts) are
Since default
renamed immediately
accounts are
after installation to an
widely known,
unidentifiable name.
these are usually
Passwords for default
the first accounts
accounts are changed to
that an intruder
a not easily guessed
will attempt to use.
password, e.g., a long
Many of these
password containing
accounts have
both alpha and numeric
powerful system
characters.
access; therefore,
Accounts are disabled if
intruders can gain
they are not being used.
extensive system
access.
If default accounts
are not renamed,
an attacker may
launch a brute
force attack to
guess passwords
for these default
accounts.
[Link]/auditprograms
COBIT
Reference
PO4
AI3
DS5
129
Business
Objective
Risk
Control
Groups contain
only appropriate
users.
Naming
conventions are
established and
followed for all
user accounts (e.g.,
end users,
contractors,
consultants and
vendors).
Accounts for
individuals who are
no longer employed
or have a
When
unnecessary
users are
assigned as
members of
groups that have
extended
privileges, they
may use this
enhanced ability
to compromise
the security of
the system and
gain
unauthorized
access to
sensitive system
data.
Users may not
be easily
identified, so
unusual activity
may not be
identified.
Comments/
Results/
W/P Ref.
Standard naming
conventions are
established and
consistently followed for
naming each type of
user, so that users within
each group can be
identified easily.
Temporary accounts
used for contractors,
consultants and vendors
follow an identifiable
naming convention that
allows these accounts to
be easily identified and
purged if warranted.
Domain security
All existing groups
may be
within a specific
compromised, as
domain are
security
documented according
personnel are not
to corporate policy.
familiar with
authorized vs.
unauthorized
users.
Existence of
Procedures exist to
accounts that are
promptly remove
no longer needed
unneeded user
increases the risk
accounts from the
[Link]/auditprograms
COBIT
Reference
PO4
DS5
M1
DS5
DS10
AI3
DS5
PO7
AI2
AI4
DS5
130
Business
Objective
requirement for
system access are
deleted.
Risk
that
unauthorized
personnel may
gain
inappropriate
access via these
accounts and it
would not be
identified as
unusual activity.
Extraneous,
unneeded user
accounts may be
created.
Security
administrators may
not know the
background of
users assigned to
user IDs;
therefore, it may
be difficult to
understand if user
activities are
appropriate.
Control
Comments/
Results/
W/P Ref.
[Link]/auditprograms
COBIT
Reference
DS5
131
Business
Objective
Risk
Control
Passwords are
secured within the
registry.
The automatic
logon option may
embed the
password of
accounts in the
registry in clear
text; therefore,
passwords may be
compromised.
The default
password may
exist within the
registry and,
therefore, be
compromised.
A malicious user
may gain access
to system
resources used
by these
accounts.
AI#
DS5
DS5
DS7
DS10
PO6
Privileged user
passwords are not
widely distributed.
The
effectiveness of
passwords for
sensitive or
critical accounts
may be
weakened due to
excessive
distribution.
Comments/
Results/
W/P Ref.
[Link]/auditprograms
COBIT
Reference
DS5
132
Business
Objective
Risk
Control
Comments/
Results/
W/P Ref.
Password Management
Default passwords Application
The administrator is
supplied with
default passwords
interviewed to ensure
software packages
may be widely
that all default passwords
are changed upon
known and
have been renamed
installation.
therefore the
and/or disabled if the
default user IDs
account is not being
are easy targets for
used.
attacks.
Unauthorized
access may be
obtained if these
passwords are not
changed.
Passwords are
Passwords may
Temporary passwords do
unique.
be easily
not remain in use. All
guessable,
new users are required to
resulting in
change their password
unauthorized
upon their initial login.
access to the
Generic or predictable
system.
passwords are not used
as an initial password.
Each new account is
created with a unique
and difficult-todetermine password.
The administrator
The system or
The administrator
password is
user accounts
password can be
available for
may be locked
obtained in the event of
emergencies.
and an
an emergency.
administrator
The administrator
account may not
passwords are stored in a
be available,
physically secure
resulting in
location on and offsite.
significant
downtime.
[Link]/auditprograms
COBIT
Reference
AI3
DS5
DS5
DS4
DS5
DS10
133
Business
Objective
Risk
Accounts are
locked to prevent
invalid logon
attempts.
Control
Comments/
Results/
W/P Ref.
[Link]/auditprograms
COBIT
Reference
PO6
AI3
DS5
DS7
PO6
DS5
134
Business
Objective
Risk
Control
Data classification is a
primary driver for
determining the proper
security measures
needed.
By mapping the data to
data owners and
understanding the data
classifications,
management are able to
determine what groups
of users need access to
data.
This data classification
feeds into the design of
security roles that are
eventually configured
into the system.
User-level overrides of
password policies are not
allowed for any user
accounts, except for
service accounts.
Strong password
controls restrict
access to the
system.
Unauthorized
access to data
may occur.
Comments/
Results/
W/P Ref.
Group Management
Local and global
Network and
User accounts are
groups simplify
security
logically grouped
network and
administration
through the use of global
security
may be ineffective.
groups in the
administration.
authentication domain.
Users are grouped
according to similar job
functions, departments
or access requirements.
[Link]/auditprograms
COBIT
Reference
PO2
PO4
DS5
DS5
PO4
DS5
DS11
135
Business
Objective
Risk
Control
Naming
conventions are
established and
followed for all
global and local
groups.
Nonstandard,
unauthorized
groups may not be
identified easily.
Unauthorized
access may occur.
Standard naming
conventions are set for
each type of user group.
Each user group can be
identified easily.
Global groups have
different naming
standards than local
groups.
Groups are named,
identifying the type of
group, group purpose,
and department.
No unnecessary
additional groups exist
on the system.
Other than the built-in
global groups, no global
groups exist outside of
the authentication
domains.
Comments/
Results/
W/P Ref.
[Link]/auditprograms
COBIT
Reference
DS5
DS9
DS11
136
Business
Objective
Risk
Control
Comments/
Results/
W/P Ref.
[Link]/auditprograms
COBIT
Reference
AI2
DS5
DS11
AI2
DS5
137
Business
Objective
Risk
Control
Comments/
Results/
W/P Ref.
[Link]/auditprograms
COBIT
Reference
PO4
DS5
DS5
M3
PO8
DS5
DS13
M3
DS5
DS13
138
Business
Objective
Risk
Control
Comments/
Results/
W/P Ref.
[Link]/auditprograms
COBIT
Reference
PO4
PO11
AI5
AI6
DS9
PO6
DS5
139
Business
Objective
Risk
Control
Only legitimate
jobs are scheduled.
The scheduled
service may
allow an
unauthorized
user to execute
malicious code
as an
administrator
Operational Resilience
Disaster recovery
and business
continuity plans
exist.
System redundancy
and contingency
plans are used.
An uninterrupted
power supply is
used for critical
systems.
Comments/
Results/
W/P Ref.
Critical
Disaster recovery polices
operations and
exist for recovering
systems may not
critical operations and
be recoverable in
systems in the event of
the event of a
a disaster.
disaster.
An organizationwide
disaster recovery plan
exists. The plan is
updated frequently and
tested periodically.
Hardware
System redundancy (e.g.,
failures may lead
mirroring, load
to the loss or
balancing) and
corruption of
contingency plans are
critical data.
established for critical
servers (e.g., web server
for an e-business).
Data and
An uninterrupted power
systems may be
supply is used for all
lost or corrupted
critical systems. This
in the event of a
provides power for the
power loss.
system to be shut down
in the event of power
loss or degradation.
[Link]/auditprograms
COBIT
Reference
DS10
DS11
DS13
DS4
DS4
DS4
DS12
140
Business
Objective
Risk
Networking
Workstation and
time restrictions are
enforced.
Unauthorized
personnel may
gain access to
systems during
nonpeak hours
when user IDs are
dormant.
Unauthorized
personnel may
gain access to
systems through
unattended user
logon sessions.
Control
Comments/
Results/
W/P Ref.
COBIT
Reference
Incremental daily
backups and
weekly/monthly fullsystem backups are
performed for all critical
systems.
The administrator and
business lead determine
the frequency and
completeness of backups
(e.g., incremental, partial
or full).
Daily and weekly/
monthly backups are
stored in a secured
offsite location.
DS4
DS11
DS5
[Link]/auditprograms
DS5
141
Business
Objective
Risk
Physical Access
Physical access to
the data center is
strictly controlled.
Unauthorized
personnel may
have physical
access to the data
center, and
therefore, access to
the system
consoles and
operations
information.
Security Policies and Procedures
A general security
Without a full risk
risk assessment is
assessment, critical
performed.
systems and
applications may
not be identified
and secured
properly.
A security
Users who are not
awareness program
reminded of good
exists.
security practices
may create
security violations
inadvertently or
intentionally.
A data
classification
structure is
identified clearly.
Without a data
classification
system, it may be
difficult to
dedicate
appropriate
resources to
protect high-value
data.
Employees may
not understand
security policies
and procedures,
and therefore,
they may cause
security
violations
inadvertently or
intentionally.
Control
Comments/
Results/
W/P Ref.
COBIT
Reference
DS9
DS11
DS12
DS13
PO9
A formal security
awareness program
exists and is updated
regularly.
All new employees must
sign an employee
information security
policy when hired.
A data classification
system exists and all
departments and
employees understand
how to apply the
classification system
(e.g., stamping
documents, watermarks).
PO6
PO7
DS5
[Link]/auditprograms
PO2
DS5
PO6
PO7
DS5
142
Business
Objective
Risk
A standard profile
exists for PC
configurations to
ensure consistency.
Control
Comments/
Results/
W/P Ref.
COBIT
Reference
PO7
DS7
PO7
DS5
organization are
communicated
immediately to the
administrator and exemployees are removed
promptly from the
system.
A security team or
system administrator
exists and is completely
dedicated to the security
of the corporate network
and infrastructure.
[Link]/auditprograms
PO6
DS5
DS13
M4
DS9
DS13
143
Business
Objective
Risk
Control
Comments/
Results/
W/P Ref.
activities are
limited, controlled
and monitored.
Administrator activities
activities, which
may not be
are limited, controlled
detected.
and monitored.
For high-volume
Volumes of
System logging (e.g.,
systems, automated
logging data may
inherent to the system or
monitoring tools
be produced daily.
third-party tools) is
are utilized.
Without automated
performed.
tools to flag
possibly
inappropriate
access, it may go
unnoticed.
Internet Information Server
The latest Internet
If the version of
The most current version
information server
the operating
of the operating system
program directory
system or
and application contain
structure is
applications is
processing and security
installed.
not current,
enhancements.
unauthorized
The most recent security
users may be able
patches have been
to exploit
applied to the servers.
weaknesses.
Only required
Unnecessary
The Internet information
server extensions
server extensions
servers application is
are used.
may expose the
configured to check for
IIS server to
the existence of URLs
unnecessary
before passing them on
attacks.
to the systems DLLs.
Only required DLLs are
mapped for the server.
Firewall Configuration
Only authorized
Unauthorized
Only authorized ports are
ports are allowed
personnel may
open on the firewall
on the firewalls.
attempt to
based on the
compromise the
requirements of the
firewall or other
applications within the
network devices
environment.
by targeting
specific ports or
services.
[Link]/auditprograms
COBIT
Reference
DS5
DS13
M1
DS8
DS10
DS13
PO3
AI3
DS5
DS5
DS11
DS5
144
Business
Objective
Risk
Control
Comments/
Results/
W/P Ref.
Unauthorized
Online business
personnel may
transactions are
sniff unencrypted
encrypted.
transactions.
In the event of a
Critical firewalls are
hardware failure,
designed to provide 100
users may not be
percent uptime through
able to access
fail-over or fault
resources (e.g.,
tolerance.
Internet).
Segregation of Duties/Application-based Security
Access to sensitive
Unauthorized
Incompatible duties
and powerful
access to CRM
are separated properly
transactions is
functions may
within the CRM
restricted properly.
exist.
system and other
applications, for
example:
- The ability to
create a customer
and process a
credit
- The ability to
create a vendor
and approve
marketing
expenditures
- The ability to
physically
access/take spare
parts and process
spare parts
inventory
adjustments
Access to
sensitive/powerful
master data and
transactions, for
example, prices and
credit limits which could
be used to support fraud
and collusion with a
customer, is restricted
properly within the CRM
system.
Online business
transactions are
encrypted (e.g.,
SSL).
Critical firewalls
are configured with
fail-over or fault
tolerance
capabilities.
[Link]/auditprograms
COBIT
Reference
DS5
DS5
PO4
DS5
145
9.
The following work program will help control the project management risks of a customer
relationship implementation project. Any person auditing, reviewing or advising on controls in a
CRM project will need to select tasks from the work program and to consider the key issues
raised in the IT Governance Institute publication Risks of Customer Relationship Management as
part of their preparation. The work program should not be used as a checklist of best practice, but
as a selection of examples of good practice that can be applied. By using the work programs
blindly, there is a risk of losing the confidence of the auditee and even of missing the largest risks
in the project, due to the peculiarities of each project. Therefore, work programs should be used
as guidance, and specific knowledge of the organization and risks should be added to it.
Note: A business objective may be listed more than once because it has multiple risks and
corresponding control objectives. Note disclaimer.
Business
Objective
Risk
Project Initiation
Senior
management
reviews the project
charter and plan
and approves the
Senior
management may
not support the
project.
The project may
not be in
alignment with
business
objectives and
goals.
Control
Comments/
Results
W/P Ref.
[Link]/auditprograms
COBIT
Reference
PO1
PO10
146
Business
Objective
Risk
Control
Comments/
Results
W/P Ref.
The project
management team
should adhere to the
business case, taking
into consideration
priority objectives set
and approved by senior
management.
The project team
always refers back to
the CRM values to
guide the decisionmaking process.
A strong configuration
and change
management process
used when changing
scope.
The scope is altered
only with executive
approval and a thorough
analysis of the impact
of scope changes.
[Link]/auditprograms
COBIT
Reference
PO10
AI6
DS9
147
Business
Objective
Risk
The project
contains welldefined business
justification,
budget, scope,
dates and key
resources.
Control
Comments/
Results
W/P Ref.
[Link]/auditprograms
COBIT
Reference
PO4
PO10
PO5
PO6
PO10
148
Business
Objective
Risk
Control
A steering
committee
oversees the
project.
A steering
committee
oversees the
project.
Comments/
Results
W/P Ref.
not meet
objectives,
milestones or
budget.
committee is defined
clearly. A determination
is made as to whether
the committee has
approval authority or is
in a guidance mode
with approval authority
vested in the managers,
especially for the
following items:
Project schedule
Project standards
Project personnel
assignments
Project deliverables
If the project is to be
managed through a
senior management
position, this reporting
line and accountability
should be established
and agreed.
The project may A steering committee
not meet
is established that has
objectives,
representation from all
milestones or
the business functions
budget.
involved in using,
operating and setting
policy for the
proposed system. The
following types of
personnel are
considered for
membership in the
committee:
- Senior
management
depends on
whether
management
wishes to delegate
steering committee
roles or perform a
hands-on function
- Information
[Link]/auditprograms
COBIT
Reference
PO4
PO10
PO4
PO10
149
Business
Objective
Risk
Control
Comments/
Results
W/P Ref.
COBIT
Reference
systems personnel
representing
database
administration, data
administration, ecommerce,
application
development,
security, etc.
Key end-users
representing major
functional areas
and consisting of
strong individuals
with key
understanding of
business
Technology
personnelwith
key understanding
of the new
technology and its
impact on the
organization
[Link]/auditprograms
150
Business
Objective
Risk
Internal and
external project
dependencies are
identified and
monitored.
All project
dependencies may
not be identified or
monitored.
Therefore,
misunderstood or
undetected project
dependencies may
negatively impact
the project.
Dependencies are
managed
effectively.
A common
approach for
project
administration is
utilized.
Issues raised by
dependencies
may not be
resolved,
increasing the
risk of project
failure.
Separate and
inconsistent
approaches may
be used for the
administration of
different
projects.
Control
Comments/
Results
W/P Ref.
COBIT
Reference
PO1
AI3
AI6
AI8
PO6
PO10
Procedures and
standards are in place
for:
- New project
definition and
scope
- Common project
tools (i.e., MS
Project)
- Project-related
travel and
accommodation
- Diary management
for key project
personnel
[Link]/auditprograms
PO1
PO10
151
Business
Objective
Risk
The impact of
changes to the
project scope and
timeline may not
be identified before
implementation.
Changes may be
made without
proper
authorization.
Excessive changes
may negatively
impact project
timing and scope.
Control
Comments/
Results
W/P Ref.
COBIT
Reference
PO10
AI6
PO10
AI2
[Link]/auditprograms
152
Business
Objective
Risk
Control
Comments/
Results
W/P Ref.
COBIT
Reference
through a formal
change request
procedure, the plan is
revised and the new
tasks are baselined.
The baseline process
saves the original
estimates and schedule
for comparison against
the working schedule,
which allows slippage
and/or gain to be
monitored easily.
Project performance and
progress is monitored
against the plan to
provide an early
warning of potential
issues when milestones
are not met within the
specified timeframe.
Cost Management
Costs are controlled
to stay within the
project budget.
Initial assessments of
interfaces, data
conversion efforts,
customization and
expertise are
determined to ensure
that project costs are
managed and the
budget is realistic.
Formal proven
methodologies are used
for planning resources,
planning and estimating
costs, and budgeting
and monitoring costs.
[Link]/auditprograms
PO5
PO10
AI6
153
Business
Objective
Risk
Control
Comments/
Results
W/P Ref.
[Link]/auditprograms
COBIT
Reference
PO6
PO10
PO10
154
Business
Objective
Risk
Documents are
produced and
changed according
to project
standards.
Control
Project team
members may
create documents
without
following
consistent
standards.
Comments/
Results
W/P Ref.
[Link]/auditprograms
COBIT
Reference
AI4
PO11
155
Business
Objective
Risk
Control
Comments/
Results
W/P Ref.
COBIT
Reference
PO7
PO10
DS2
[Link]/auditprograms
156
Business
Objective
Risk
Control
Comments/
Results
W/P Ref.
[Link]/auditprograms
COBIT
Reference
PO1
PO9
PO10
PO6
PO10
PO11
157
Business
Objective
Risk
Quality Management
Project outcome
meets or exceeds
customer
requirements.
The project is
closed formally
without significant
open items.
Control
Comments/
Results
W/P Ref.
[Link]/auditprograms
COBIT
Reference
PO10
PO11
M1
PO10
158
Business
Objective
Risk
Control
Comments/
Results
W/P Ref.
Technology Management
Vendor
Vendors may not A vendor management
performance is
adhere to
process is defined and
monitored against
contract
consistently applied
contract
specifications.
throughout the project to
specifications.
include:
- High-level and
detailed definition of
requirements
- Quality standards
- Quantification of
risk associated with
hiring the vendor
- Competitive
tendering
- Contract
requirements
- Vendor performance
monitoring
- Deliverable(s)
acceptance only if
the final product
meets or exceeds
expectations
[Link]/auditprograms
COBIT
Reference
PO10
DS1
DS2
159
Business
Objective
Risk
Regulatory Compliance
The CRM project
Control
The CRM
project and/or
CRM solution
may not be
implemented in
compliance with
regulations and
security and
privacy
requirements.
Comments/
Results
W/P Ref.
[Link]/auditprograms
COBIT
Reference
PO8
PO10
160
Business
Objective
Cultural differences
are considered
when developing
and implementing
the CRM solution.
Risk
Control
When CRM
solutions are
implemented
across borders,
or globally,
additional
complexities
may be
introduced. For
instance, cultural
and economic
differences may
make strategies
and solutions
that work in one
country not
practical for
other countries.
Comments/
Results
W/P Ref.
Careful attention
should be paid to
cultural differences
and a representative
from each country is
included in defining
the CRM strategy/
vision, business case,
analysis, design, etc.
[Link]/auditprograms
COBIT
Reference
PO6
PO7
PO10
DS1
161
10.
The following work program will help to ensure that the organization is realizing the benefits
from the customer relationship management implementation project. Any person auditing,
reviewing or advising on controls in a CRM project will need to select tasks from the work
program and to consider the key issues raised in the IT Governance Institute publication Risks of
Customer Relationship Management as part of their preparation. The work program should not be
used as a checklist of best practice, but as a selection of examples of good practice that can be
applied. By using the work programs blindly, there is a risk of losing the confidence of the auditee
and even of missing the largest risks in the project, due to the peculiarities of each project.
Therefore, work programs should be used as guidance and specific knowledge of the organization
and risks added to it.
Note: A business objective may be listed more than once because it has multiple risks and
corresponding control objectives. Note disclaimer.
Business
Objective
Risk
Control
Comments/
Results
W/P Ref.
A business case is
developed for the CRM
project.
The business case clearly
identifies desired
business benefits.
The business case
prioritizes the
organizations
objectives.
The business case
presents the expected
return on investment
(ROI) and expected
payback period.
[Link]/auditprograms
COBIT
Reference
PO1
PO5
PO10
162
Business
Objective
Risk
Accountability is
assigned for
achieving each
benefit.
Control
Comments/
Results
W/P Ref.
Monitoring Benefits
Benefits
monitoring is a
continuous process
throughout the
project lifecycle.
Project decisions
Accountable individuals
may be made
are part of the extended
without regard to
project team and are
the original project
involved actively.
objectives and
Project decisions are
values.
reviewed against
The final project
potential impact to
output may not
anticipated benefits.
meet expectations.
[Link]/auditprograms
COBIT
Reference
PO10
PO5
PO9
PO10
163
Business
Objective
The indicators are
identified for
measuring success.
Risk
Control
Comments/
Results
W/P Ref.
[Link]/auditprograms
COBIT
Reference
M1
PO10
164
11.
The following work program will help to ensure that the organization is managing the
organizational changes from the customer relationship management implementation project. Any
person auditing, reviewing or advising on controls in a CRM project will need to select tasks
from the work program and to consider the key issues raised in the IT Governance Institute
publication Risks of Customer Relationship Management as part of their preparation. The work
program should not be used as a checklist of best practice, but as a selection of examples of good
practice that can be applied. By using the work programs blindly, there is a risk of losing the
confidence of the auditee and even of missing the largest risks in the project, due to the
peculiarities of each project. Therefore, work programs should be used as guidance and specific
knowledge of the organization and risks added to it.
Note: A business objective may be listed more than once because it has multiple risks and
corresponding control objectives. Note disclaimer.
Business
Objective
Risk
Control
project
lack of focus and
workstream to
activities to
address
address
organizational
organizational
change.
change
No one may be
assigned
responsibility or
accountability for
organizational
alignment.
All activities
necessary to
achieve
organizational
change may not be
completed.
Comments/
Results/
W/P Ref.
Change management
activities are included in
the overall project
planning activities for
the CRM
implementation.
Change management
timelines and milestones
are incorporated in the
project plan.
The change management
team is included in all
project team meetings.
The same level of
reporting and monitoring
of change management
activities is required as
with all other project
workstreams.
[Link]/auditprograms
COBIT
Reference
AI6
PO6
165
Business
Objective
Risk
Control
Change
management
requirements for
the CRM
implementation
are defined.
If the extent of
Project Strategy
The project
strategy delivers
quick wins, if
needed, to
encourage morale
and adoption.
Sustained
organizational
commitment and
support to the
initiative may
wane over time,
without
demonstration of
quick wins that
clearly show the
benefits of CRM
to the
organization.
Comments/
Results/
W/P Ref.
CRM implementation
and its intended business
results are articulated.
The changes (process,
systems, organizational
structure, staffing, etc.)
that may be required are
identified.
An owner for each of
defined change is
identified.
The change owner is
engaged as early as
possible in the
implementation.
The organization is
COBIT
Reference
PO1
PO4
AI6
PO10
focusing on delivering
quick wins when
planning for the project
to help ease user
adoption and build
excitement for the new
solution.
Demonstrable
improvement to the
process, or peoples
ability to contribute to
the projects end goal,
are shown.
Quick wins are
communicated and
celebrated to maintain
momentum and
encourage continued
change support.
[Link]/auditprograms
166
Business
Objective
Risk
Control
The timing of
organizational
change activities is
closely aligned
with project
activities and
timelines.
Organizational
Plan activities in
change activities
may not be done in
coordination with
implementation
activities and
communication.
An attempt at
addressing
organizational
change may be
made only at the
time of, or after,
system rollout.
Project Sponsorship
Leadership is
engaged in change
management
initiative.
Management
support may not
be obtained;
therefore, it is not
sustained during
the
implementation.
Comments/
Results/
W/P Ref.
COBIT
Reference
AI6
PO10
PO1
in of the required
changes is obtained.
Senior management
commitment to and
support of change
management activities
that will be carried out to
prepare the organization
are obtained.
A sponsor who will be
personally vested to
ensure project success is
identified.
[Link]/auditprograms
167
Business
Objective
Risk
Control
Comments/
Results/
W/P Ref.
[Link]/auditprograms
COBIT
Reference
PO3
PO4
AI6
PO6
AI3
AI5
AI6
DS4
DS7
DS8
168
Business
Objective
Risk
Control
implementation.
Comments/
Results/
W/P Ref.
management
expertise
Project
management
methodology
Program
management
Project tools
Project planning,
monitoring,
milestones
Project controls
Project scope and
approach
Vendor and
contractor
management and
deliverables
Project staffing
Project training
Project
communication
Technical risks
Hardware and
software design
methods
System
architecture
design methods
Networking
acceptance
procedures
Performance,
sizing and
availability
acceptance
procedures
Disaster
recovery and
business
continuity plans
Functional risks
Requirements
definition
methods
Business process
design methods
Data management
[Link]/auditprograms
COBIT
Reference
DS10
PO9
PO10
169
Business
Objective
Risk
Control
Comments/
Results/
W/P Ref.
COBIT
Reference
methods
and
usability
Legacy system
integration
methods
Program change
management
- Executive
sponsorship
Alignment with
other initiatives
Commitment
Executive Support
Sponsorship
- User acceptance
testing approach and
results
Conference room
pilot
Test environment
Test data
Test approach
Validation and
sign-offs
- Organizational risks
Organizational
alignment
Release integration
Business process
redesign
methods
Organizational
change
management
Business process
change
integration
approach
Skill gap analysis
and retraining
Documentation
- Operational and
production support
Problem resolution
and escalation
User support (help
desks, etc.)
Reliability
[Link]/auditprograms
170
Business
Objective
Risk
Control
Comments/
Results/
W/P Ref.
IT
Organizational
change addresses
the appropriate
areas such as
training,
organizational
restructure and
employee
readiness.
production
support plans
Documentation
- End-user training
and pilot
Training program
Training schedules
and participants
Trainees feedback
The organizations
training needs have been
assessed.
Adequate training in line
with the organizations
requirements is planned.
CRM champions are
identified who will help
communicate the
benefits of CRM
throughout their
respective section of the
organization.
Changes in functional
responsibilities are
identified and plans exist
for any necessary
organization restructure.
COBIT
Reference
[Link]/auditprograms
PO7
171
Business
Objective
Communication
Organizational
change includes
constant education
and
communication
with employees
and sustained
stakeholder
management.
Risk
There may be a
A change vision is
understood.
Control
lack of
communication
with employees,
users and
customers.
Communication
may be provided
without context to
implementation
activities and
implications.
The business case
and benefits may
not be
communicated
clearly with the
message of
upcoming change.
Rumors of project
activities and
implications may
be apparent prior
to any formal
communication.
Users may be
apprehensive of
the changes that
will occur and do
not understand the
overall impact.
Users may reject
the changes.
Comments/
Results/
W/P Ref.
A communication
framework exists,
addressing information
needs at all levels.
Existing communication
channels are utilized to
leverage the
organizations
infrastructure.
Steps are identified to
encourage regular
dialogue with the user
community. Questions
are encouraged and
feedback solicited as
early as possible, and
throughout the
implementation.
User concerns are
addressed, to minimize
speculation.
A strategic vision is
COBIT
Reference
PO6
PO11
PO1
developed and
communicated within
the project team and the
organization. The vision
is comprehensive and
operational so
employees understand
the overall impact and
also how it will impact
their job function.
A compelling change
story exists for the
organization, functions
impacted and specific
employee roles.
[Link]/auditprograms
172
Business
Objective
Training
Employees and
customers receive
the proper
training.
Risk
Control
Training is planned
teach workflow,
processes, internal
controls (e.g.,
approvals and
monitoring
controls), and new
roles and
responsibilities.
Problems with
integrity of
transactions,
quality of data,
timeliness of
input, lack of
consistency in
monitoring
controls, etc., may
exist.
Functional Roles, Skills and Security
The organizational Employees may
structure changes
reject the changes
are understood.
due to lack of
understanding.
Incorrect security
may exist.
Incompatible
duties may not be
segregated
properly.
Training may not
be built properly.
Employees may
not have the right
COBIT
Reference
PO7
sufficiently with
adequate time allotted
and training materials to
support the users.
Various teaching
methods are used to
promote retention of
information.
The training includes the
users role in the new
organization, the new
processes and their
responsibilities, in
addition to how to use
the system.
Roles and
responsibilities are
defined clearly.
Comments/
Results/
W/P Ref.
An organizational
reporting structure
exists.
Employees roles and
their corresponding
performance measures
are clearly
communicated.
Integrated workgroups
are used to develop the
new solution to ensure
a clear crossdepartmental
understanding.
Roles and
responsibilities are
developed early in the
implementation project
to ensure ample time
for security, training
and documentation of
new responsibilities.
Role-based application
security is built and
users have access only
[Link]/auditprograms
PO4
PO7
PO7
PO10
DS5
DS7
173
Business
Objective
Risk
Control
able to obtain
reject new data
useful
sharing models.
management
Management
information and
information and
data from the
Comments/
Results/
W/P Ref.
COBIT
Reference
to transactions and
information they need
for business purposes.
A segregation of duties
matrix ensures that
incompatible duties are
properly segregated.
Training is in place for
all functional roles and
include interaction with
other roles/departments
and the overall business
processes, workflows,
and corresponding
impacts.
Skill and training gaps
are identified early in
the implementation to
ensure that employees
can be properly trained.
Employees can earn
incentives for
maintaining accurate and
timely information in the
new systems.
An understanding of the
benefits to the
organization and to
specific groups of
employees from
maintaining accurately
and timely information is
communicated.
[Link]/auditprograms
DS10
174
Business
Objective
Risk
Control
Comments/
Results/
W/P Ref.
COBIT
Reference
PO4
M1
PO11
management techniques
to drive the right
behavior are used. These
include rewards for the
project team and end
users to encourage that
the system be
implemented on time, on
budget and according to
expectations, and then
adopted by end-user
departments.
[Link]/auditprograms
175
12.
The following work program will help to manage the privacy risks surrounding customer
relationship management. Any person auditing, reviewing or advising on controls in a CRM
project will need to select tasks from the work program and to consider the key issues raised in
the IT Governance Institute publication Risks of Customer Relationship Management as part of
their preparation. The work program should not be used as a checklist of best practice, but as a
selection of examples of good practice that can be applied. By using the work programs blindly,
there is a risk of losing the confidence of the auditee and even of missing the largest risks in the
project, due to the peculiarities of each project. Therefore, work programs should be used as
guidance and specific knowledge of the organization and risks added to it.
Note: A business objective may be listed more than once because it has multiple risks and
corresponding control objectives. Note disclaimer.
Business
Objective
Access
Employees access
to personal and
sensitive
information within
the CRM system is
controlled
appropriately.
Employee access
to personal
information is
reviewed on a
regular basis.
Risk
Inappropriate
access to personal
information may
result in misuse of
the information
and
noncompliance
with the
organizations
privacy notice and
policies and
procedures.
Employees may
have inappropriate
access to personal
information due to
changes in job
status or
responsibilities.
Control
Comments/
Results/
W/P Ref.
Employees access to
personal information is
limited to the
information they need to
perform their job
functions.
A business case is
required before
employees receive
access to sensitive
information. For
example, all access
requests are reviewed
and formerly approved
(signature) before a user
is granted access to the
system.
Regular reviews of
employee access to
personal information
within the CRM system
are performed. The
reviews are designed to
determine whether
access levels should be
adjusted based on
employees current job
responsibilities.
[Link]/auditprograms
COBIT
Reference
PO2
DS5
DS11
PO7
DS5
DS11
176
Business
Objective
Risk
Sensitive personal
information
collected and
maintained in the
CRM system is
secured.
Personal
information may
be unsecured and
accessed by
inappropriate
parties, which
could result in
noncompliance
with the
organizations
privacy notice.
Physical controls
Unauthorized use
protect against
of customer
identity theft.
accounts may
result in
financially
unrecoverable
losses for the
organization.
Note: although
electronic access is
growing in
importance, access
to paper
documents by
improper
individuals still
poses a great risk
of identity theft.
The use of
Overuse of
government issued
identifiers issued
identifiers, such as
by national
social security
authorities
numbers, is
increases the risk
assessed and
of identity theft
limited.
and may make
customers
uncomfortable
with their privacy.
Control
Comments/
Results/
W/P Ref.
Strong authentication
and authorization
controls, firewalls,
operating system
controls, and encryption
standards secure
sensitive personal
information.
[Link]/auditprograms
COBIT
Reference
DS5
DS11
DS9
DS12
PO8
PO9
177
Business
Objective
Best practice user
and caller
identification
methods are in
place.
Risk
Without
appropriate
authentication
procedures,
organizations may
provide personal
customer
information to
inappropriate
parties.
Regulatory Compliance
The organization
Organizations may
identifies the
be unaware of the
privacy legislation
privacy legislation
that it is subject to
they are subject to
for all the
and may not be
countries and
able to meet
territories in which
regulatory
it operates.
requirements.
The organization
implements
compliance
programs for
applicable privacy
legislation.
The organization
monitors
compliance with
privacy legislation
on an on-going
basis.
Control
Organizations that
do not implement
appropriate
compliance
programs may
misuse customer
information and be
subject to
regulatory action.
Lack of
monitoring may
lead to
noncompliance
with privacy
legislation.
Comments/
Results/
W/P Ref.
On a regular basis,
review changes to caller
authentication questions.
Caller authentication
questions are those
questions that the
customer can provide the
answer to, but would be
difficult for a stranger to
answer.
Internal or external
[Link]/auditprograms
COBIT
Reference
DS5
DS11
PO8
PO3
PO4
PO8
PO6
PO8
M1
178
Business
Objective
Risk
Control
Comments/
Results/
W/P Ref.
The privacy
management team is a
part of the system
change methodology.
Working with the
development team, it
develops a test or set of
standards that must be
met before system
changes that may impact
customer privacy are
implemented.
The individual(s)
responsible for
reviewing changes are
independent of
marketing, IT, and
functional areas that
made the change request.
A formal method for
tracking relevant
emerging legislation is in
place.
Possible functional
changes are discussed
with IT to ensure that the
system changes are
made at the most
opportune time in the
development cycle.
[Link]/auditprograms
COBIT
Reference
PO6
AI6
PO4
PO8
AI6
179
Business
Objective
Risk
Control
Comments/
Results/
W/P Ref.
COBIT
Reference
A privacy organizational
structure is developed
and implemented at the
organization.
The structure is staffed
with individuals who are
knowledgeable about
privacy issues, provided
with authority to
implement the necessary
privacy procedures and
given appropriate
funding.
PO7
PO4
PO8
PO7
[Link]/auditprograms
180
Business
Objective
Disclosure
The organizations
privacy notice
accurately
describes its
practices regarding
the collection of
personal
information.
The organization
monitors
compliance with
its privacy notice.
Risk
Personal
information that is
collected from
consumers and
entered in the
CRM system may
not follow the
collection
practices outlined
in the
organizations
privacy notice.
Customers may
not want to
transact with an
organization if
they do not know
how their
information will
be used and
secured.
Control
Comments/
Results/
W/P Ref.
[Link]/auditprograms
COBIT
Reference
PO6
PO8
DS5
PO8
AI4
DS5
M1
M4
181
Business
Objective
Risk
CSRs process
customer optin/opt-out requests
in a timely and
accurate manner.
Customer
information may
be used
inappropriately.
Customer
dissatisfaction and
regulatory
oversight may
occur.
Control
Comments/
Results/
W/P Ref.
[Link]/auditprograms
COBIT
Reference
PO4
PO6
PO7
DS5
DS7
PO6
PO8
AI4
182
Business
Objective
Risk
Control
Improper privacy
messaging may
occur, which may
contribute to
identity theft and
improper opt-out
procedures.
Comments/
Results/
W/P Ref.
[Link]/auditprograms
COBIT
Reference
PO6
PO7
183