0% found this document useful (0 votes)
13 views183 pages

CRM Work Programs

crm

Uploaded by

Pravin Sinha
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOC, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
13 views183 pages

CRM Work Programs

crm

Uploaded by

Pravin Sinha
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOC, PDF, TXT or read online on Scribd

Information Systems Audit and Control

Association
[Link]

Systems Audit and Control Association & Foundation

Risks of Customer Relationship


Management

A Security, Control and Audit Approach


Audit Work Programs
Information Systems Audit and Control Association
With more than 28,000 members in more than 100 countries, the Information Systems Audit and Control Association
(ISACA) ([Link]) is a recognized worldwide leader in IT governance, control, security and assurance.
Founded in 1969, ISACA sponsors international conferences, publishes the Information Systems Control Journal,
develops international information systems auditing and control standards, and administers the globally respected
Certified Information Systems Auditor (CISA ) designation earned by more than 34,000 professionals since
inception, and Certified Information Security Manager (CISM) designation, a groundbreaking credential earned by
5,000 professionals in its first two years.
IT Governance Institute
The IT Governance Institute ([Link]) was established in 1998 to advance international thinking and standards in
directing and controlling an enterprises information technology. Effective IT governance helps ensure that IT supports
business goals, optimizes business investment in IT, and appropriately manages IT-related risks and opportunities. The
IT Governance Institute offers symposia, original research and case studies to assist enterprise leaders and boards of
directors in their IT governance responsibilities.
Purpose of Audit Programs and Internal Control Questionnaires
One of ISACAs goals is to ensure that educational products support member and industry information needs.
Responding to member requests for useful audit programs, ISACAs Education Board has released audit programs and
internal control questionnaires for member use through K-NET. These check lists were developed for a recently
released publication Risks of Customer Relationship Management A Security, Control and Audit Approach available
in the ISACA bookstore.
Control Objectives for Information and related Technology
Control Objectives for Information and related Technology (COBIT) has been developed as a generally applicable and
accepted standard for good information technology (IT) security and control practices that provides a reference
framework for management, users, and IS audit, control and security practitioners. These audit work programs
reference key COBIT control objectives.
Disclaimer
ITGI, ISACA and the author of this document have designed the publication primarily as an educational resource for
control professionals. ISACA makes no claim that use of this product will assure a successful outcome. The publication
should not be considered inclusive of any proper procedures and tests or exclusive of other procedures and tests that are
reasonably directed to obtaining the same results. In determining the propriety of any specific procedure or test, the
controls professional should apply his/her own professional judgment to the specific control circumstances presented
by the particular systems or information technology environment. Users are cautioned not to consider these audit
programs and internal control questionnaires to be all-inclusive or applicable to all organizations. They should be used
as a starting point to build upon based on an organizations constraints, policies, practices and operational environment.

Copyright IT Governance Institute 2003

[Link]/auditprograms

Table of Contents
Audit Work Programs
1. Sales Risks
2. Marketing Risks
3. Customer Interaction Center and Field Service Risks
4. Data Management Risks
5. Integration Risks
6. Channel Management and Integration Risks
7. Telecommunication Infrastructure Risks
8. Security Risks
9. Project Management Risks
10. Benefit Realization
11. Organizational Change Management
12. Privacy Risks

Copyright IT Governance Institute 2003

[Link]/auditprograms

1.

Sales Risks Work Program

The following work program will help address the sales risks within the organization. Those
auditing, reviewing or advising on controls in a CRM project will need to select tasks from the
work program and consider the key issues raised in the IT Governance Institute publication Risks
of Customer Relationship Management as part of their preparation. The work program should not
be used as a checklist of best practice, but as a selection of examples of good practice that can be
applied. By using the work programs blindly, there is a risk of losing the confidence of the auditee
and even of missing the largest risks in the project, due to the peculiarities of each project.
Therefore, work programs should be used as guidance with the specific knowledge of the
organization and risks added to them.
Note: A business objective may be listed more than once because it has multiple risks and
corresponding control objectives. Note disclaimer.
Business
Objective

Risk

Control

Comments/
Results/
W/P Ref.

Sales Strategy and Management


The sales strategy
Market intelligence on
The organization
plans for current
current and future
may not
and future market
market conditions is
appropriately
conditions.
gathered and factored
anticipate and plan
into the development of
for changes in
sales strategies.
market conditions.
An integrated sales Individual
Communication exists
strategy is adopted
between all key
departments within
throughout the
departments to ensure
the organization
entire organization.
that all relevant input is
may pursue
incorporated into setting
conflicting and
the strategic direction.
counter-productive
The sales strategy is
sales strategies.
communicated to all
sales personnel.
The sales personnel are
enticed to act in
accordance with the
overall sales strategy via
sales metrics and
incentives.

Copyright IT Governance Institute 2003

[Link]/auditprograms

COBIT
Reference
PO1
PO3

PO6
PO11
M1

Business
Objective

Risk

Control

The organization
develops long-term
and profitable
customer
relationships.

The organization
may pursue nearsighted
relationships and
unprofitable
customers.

Procedures and
incentives for sales
personnel focus on
building long-term
relationships with
customers.
Management commits
appropriate resources to
the development of longterm customer
relationships.
Customer profitability is
measured and factored
into customer strategies.
Both financial and
nonfinancial
motivational techniques
and incentives are used
to reward and encourage
positive behavior that
aligns with the
organizations sales
strategy.
Realistic sales goals and
targets are created at the
organizational level and
also at an individual
level for each sales
person.
Progress against sales
goals and targets is
measured on a periodic
basis and feedback is
provided on an
organizational level and
individual level.
Participation in teambased selling is
encouraged within the
organization and is part
of each sales persons
performance assessment
criteria.

Sales personnel are Sales goals and


motivated to
targets may not be
achieve sales goals
met.
and targets.

Sales personnel
work together as a
team.

Information may
not be shared
across the sales
team.
Conflicting
behavior within
the team may
exist.
There may be loss
of revenue.

Copyright IT Governance Institute 2003

Comments/
Results/
W/P Ref.

[Link]/auditprograms

COBIT
Reference
PO6
M1

PO7
M1

PO10

Business
Objective

Risk

Control

Reward criteria for


sales personnel are
in alignment with
the organizations
overall strategic
direction.

Sales personnel rewards


are set to motivate
performance that is
consistent with corporate
sales objectives.
Staff actions are
monitored to detect
incongruent sales
activities.

PO7

Roles and
responsibilities are
segregated to
increase selling
efficiency.

PO4

The organizational
structure reflects
the segmentation
of key customer
market segments.

Information about
customers is
disseminated
effectively
throughout the
organization.

Interdepartmental

The organizational
structure is designed to
provide a clear division
between sales personnel
and support personnel.
The support personnel
are effectively utilized to
reduce the amount of
administrative time for
sales personnel.
The sales
organizational structure
is designed to reflect
the segmentation of
key customer markets
and is continually
reevaluated as markets
evolve.
Sales personnel work
in teams that cross
departmental
boundaries to facilitate
knowledge sharing and
effective
communication about
all critical interactions
for a given customer
account.

Sales personnel
actions may be
focused on
short-term goals
(e.g., quick
sales) rather than
long-term
strategic goals
(e.g., building
customer
relationships and
long-term
profitable
customers).
Sales personnel
may spend too
much time on
noncustomerfacing
administration,
reducing the
time spent
engaged in salesrelated activities.
Sales resources
may be
misdirected.

communication
may be limited
and may impact
the
organizations
ability to share
knowledge
across all
customer
touchpoints.

Copyright IT Governance Institute 2003

Comments/
Results/
W/P Ref.

[Link]/auditprograms

COBIT
Reference

PO1

PO11

Business
Objective

Risk

Control

Sales channels are


complementary.

Channel
conflicts may
lead to wasted
resources and
missed sales
opportunities.

Succession
strategies minimize
the impact of
employee turnover.

Lack of
succession
planning could
result in a failure
to retain
intellectual
capital and
customer
contacts in the
event of sales
personnel
turnover, which
is typically very
high.

Sales channels have


clearly defined
boundaries.
All channel conflicts are
identified and resolved
to gain efficiencies,
allow effective multichannel integration, and
increase revenue and
customer satisfaction.
Performance metrics are
based on a balanced
scorecard (e.g.,
recognizing sales made
for other channels) so
that channels are
working together rather
than competing.
A succession plan is in
place for all key roles
or responsibilities
within the sales
organization.

Copyright IT Governance Institute 2003

Comments/
Results/
W/P Ref.

[Link]/auditprograms

COBIT
Reference
PO1
M1

PO7

Business
Objective

Risk

Profitability is
regularly
monitored.

Account plans are


developed to
determine sales
effort and
investment.

Revenue and
product forecasts
are updated in a
timely manner.

Compensation
plans are in
alignment with
corporate sales
objectives.

Control

Comments/
Results/
W/P Ref.

Potential
Sales managers regularly
profitability and
assess profitability by
value may not be
major accounts,
understood for
territories, and
major accounts,
locations/divisions
territories,
within the organization
locations and
and the results are
divisions.
communicated to all
relevant sales personnel
and management.
Reports on margin per
customer are a regular
activity to improve
profitability on low
margin customers (or to
cease trading with those
customers).
Inappropriate
Account plans are
targeting and
developed, and they
budgets may be
include profitability and
made for key
forecast information to
accounts.
assist in compiling
budgets for key account
targeting activities.
Cost of targeting and
managing the account
should be measured.
Inaccurate
Revenue and product
revenue and
forecasting information
product forecasts
is regularly updated and
may be made.
reflects the latest market
trends.
Significant deviations
from the original
forecast are investigated
to understand the impact.
There may be an The sales compensation
inability to
plan is designed to
motivate sales
reward sales
personnel to
performance in
achieve
alignment with corporate
corporate sales
sales objectives.
goals.
The sales personnel are
motivated to achieve
corporate sales goals and
objectives.

Copyright IT Governance Institute 2003

[Link]/auditprograms

COBIT
Reference
PO6
DS6
M1

DS11

DS6
PO9

PO11

Business
Objective

Risk

Control

The sales force


receives
appropriate
training to develop
their sales skills.

Ineffective sales
skills may not be
addressed.
Lack of
understanding of
sales strategy,
goals and
objectives may not
be addressed.
Lack of
understanding of
organization
background,
product
information and
organization
policies may not
be addressed.
Difficulty in
identifying
performance
trends or problems
may occur.
There may be an
inability to
respond quickly to
changing market
conditions.

Appropriate training
resources are available to
ensure sales personnel
have the necessary skills
to sell and build
profitable customer
relationships.
Sales personnel are
provided regular
training.
Sales curriculum is
developed in conjunction
with sales management
on current topics,
policies, strategies, etc.

PO7
PO10

Sales performance is
regularly monitored to
assess sales personnel
performance, trends for
market segments, sales
personnel and key
customer accounts.
Key Performance
Indicators (KPIs)
including margin
analysis and customer
satisfaction ratings, are
monitored to actively
manage the sales
process.

M1
AI6

Sales performance
is actively
monitored.

Comments/
Results/
W/P Ref.

COBIT
Reference

Identify and Qualify Opportunities

Copyright IT Governance Institute 2003

[Link]/auditprograms

Business
Objective

Risk

Control

Sales management
supports sales
goals and
objectives.

Ineffective sales
teams or wasted
resources in
opportunities that
are not in
alignment with
sales goals and
objectives may
occur.
Lost opportunities
may occur.

Markets and
customer segments
are appropriately
targeted.

Inappropriate
market segments
may be targeted.
The sales
organization may
not focus enough
effort on the most
profitable
accounts.
Uninformed
decisions about
where to focus
sales efforts may
be made.

The performance of
sales management is
linked to sales goals and
objectives.
Sales personnel are
evaluated and
remunerated against the
sales objectives.
Sales opportunities are
linked to the sales goals
and objectives to ensure
that they are in
alignment with sales
goals and objectives
before time and
resources are spent
pursing the
opportunities.
Key market segments
are analyzed and the
most profitable accounts
identified.
Sales efforts are focused
where they will have the
greatest results.

Accurate and
complete market
segment data are
available to sales
personnel.

Sales channels are


regularly evaluated
for viability.

Changing sales
channels may
not be identified,
which may result
in lost sales
opportunities.

Copyright IT Governance Institute 2003

Comments/
Results/
W/P Ref.

Market segment data


are collated in a central
repository that is
accessible to relevant
sales personnel.
Market segment data
are accurate, complete
and updated on a
timely basis.
Sales channels are
regularly re-evaluated
to reflect changes in
market conditions and
customer demand.

[Link]/auditprograms

COBIT
Reference
DS1

PO11

DS1
DS8

DS7
DS8

M1

Business
Objective

Risk

Control

Sales opportunities
are recorded
completely,
promptly and
accurately.

Lost sales
opportunities may
occur.
Incomplete or
invalid sales
opportunity
information may
be obtained.

All sales opportunities


are identified and
recorded in a timely
manner so that the sales
team and management
are aware of all potential
opportunities.
Key dates are recorded
to prioritize more
immediate opportunities
and also ensure stale
opportunities are
removed from the list.
Experienced sales
personnel identify
opportunities and make
assumptions on the basis
of the information
identified.
A centralized
information repository is
used to assist in the
accurate identification of
sales opportunities.
The CRM application
requires key fields to be
entered before allowing
the opportunity to be
saved.
Data entry is reviewed
for reasonableness.
Leads/potential sales
opportunities are
analyzed prior to being
pursued.

DS9

Sales personnel search


for existing opportunities
before entering a new
opportunity.
System controls identify
potential duplicate
records.

DS9

Only viable
opportunities are
pursued.

Sales opportunities
are only recorded
once.

Leads may be
incorrectly
classified and,
therefore, sales
opportunities
result in wasted
sales efforts.
Duplicate sales
opportunities may
be recorded.
Distortion of the
sales pipeline/
forecast may
occur.

Copyright IT Governance Institute 2003

Comments/
Results/
W/P Ref.

[Link]/auditprograms

COBIT
Reference

DS11
PO2
AI2

PO2

10

Business
Objective

Risk

Control

All sales
opportunities are
appropriately
evaluated.

Valid sales
opportunities may
not be pursued.
Invalid sales
opportunities may
be pursued.
Lessons learned
may not be
captured to better
identify and
quality
opportunities.

Management reviews
dismissed sales
opportunities for
appropriateness, lessons
learned, etc.
Formal criteria are used
to analyze each
opportunity and perform
an objective assessment
of whether to pursue the
opportunity. The criteria
should include a costbenefit analysis of the
opportunity.
Opportunities are
assessed against the
formalized criteria
before being rejected or
accepted.
Reasons are captured for
rejected opportunities.
High-level deadlines and
action plans are
developed for qualified
sales opportunities.
Comprehensive sales
opportunity data are
stored within the CRM
system.
Information is available
to qualify sales.
The CRM tracks
customer transaction
history and makes this
information readily
available during
opportunity analysis.

All required
information is
available to assist
with qualifying an
opportunity.

Information
necessary to
qualify a sales
opportunity may
not be available.

Customer history is
used to predict
future buying
patterns.

Customer
buying history
may not be
available to
assist in
analyzing sales
opportunities

Copyright IT Governance Institute 2003

Comments/
Results/
W/P Ref.

[Link]/auditprograms

COBIT
Reference
PO6
PO9
AI4

DS9
PO2

DS3

11

Business
Objective

Risk

Control

Comments/
Results/
W/P Ref.

Sales opportunities Experienced sales


may not be
personnel are
accurately
responsible for
qualified or
qualifying and
quantified.
quantifying
opportunities according
The risks inherent
to established guidelines.
to opportunities
The risks associated with
may not be
correctly assessed,
opportunities are
resulting in
identified, documented
incorrect decisions
and factored into the
to pursue
assessment of
opportunities.
opportunities.
Clear rules on qualifying
sales opportunities are
set down and all
employees are made
aware of them.
The value of sales
Sales personnel Opportunity estimates
opportunities is
may inflate
are reviewed
accurately
opportunity
periodically and
recorded.
values to meet
validated.
personal
Estimated revenues are
objectives
compared against actual
revenues on a periodic
basis. The comparison is
used to provide more
realistic revenue
estimates for future
opportunities.
Pursuing Qualified Opportunities and Submitting Proposals
Sales opportunities
are accurately
qualified.

Copyright IT Governance Institute 2003

[Link]/auditprograms

COBIT
Reference
DS3

PO9
PO10

DS11
AI1

12

Business
Objective

Risk

The appropriate
sales personnel
pursue sales
opportunities in a
timely manner.

Sales opportunities The CRM system


may not be
workflow routines or
distributed and
manual procedures route
pursued in a timely
sales opportunities to the
manner.
correct sales people in a
timely manner.
Sales opportunities

Procedures are in place


may not be
assigned to the
to ensure the timely
correct sales
follow-up of all
personnel.
opportunities.
Staff review sales
opportunities in a timely
manner and
communicate any issues
with the routing of sales
opportunities.
Realistic action plans are
assigned to
opportunities, with the
responsibilities clearly
defined.
Customer
Procedures are in place
requirements
for identifying,
may be
verifying, clarifying and
misunderstood.
modifying customer
requirements.
Requirements are
reviewed to determine if
they can be met by the
organization.
Procedures exist for
communicating and
resolving unfulfilled
requirements with the
customers.
Once finalized, customer
requirements are
documented in the CRM
system for all sales
personnel to reference.

Customer
requirements are
confirmed.

Control

Copyright IT Governance Institute 2003

Comments/
Results/
W/P Ref.

[Link]/auditprograms

COBIT
Reference
PO3
PO11
AI4

AI4
PO11

13

Business
Objective

Risk

Control

Customer
requirements are
realistic.

There are systems and


procedures in place to
validate customer
requirements (e.g.,
delivery dates,
product/service needs)
prior to customer
confirmation.

PO11
AI4
DS3

The customer is
offered the
correct/complete
product/service.

Unrealistic
customer
requirements
may lead to the
organizations
inability to
deliver, resulting
in an unsatisfied
customer and
potentially the
loss of the sales
opportunity.
Customers may
not be offered
the correct
product/service
or the complete
solution to their
needs.

DS8

Up-selling and
cross-selling
opportunities are
identified.

Opportunities to
up-sell/cross-sell
products/service
s to the customer
may not be
identified or
pursued.

Products/services data
are available and are
accurate and complete.
Guidance is distributed
for helping sales
personnel identify
solutions to meet the
customers needs.
Sales personnel are
trained in how to upsell/cross-sell
products/services.
The CRM application
automatically suggests
potential up-sell/crosssell opportunities.
The CRM application
provides tools/reports to
help management
actively monitor the
sales pipeline.
Management actively
monitors the sales
pipelines and tracks
opportunities and the
action items by date to
ensure timely follow-up.

The sales pipeline


is actively
monitored in a
timely manner.

The sales pipeline


may not be
monitored actively.
Reporting and
analysis of the
sales pipeline may
be unsatisfactory,
resulting in lost
sales
opportunities.

Copyright IT Governance Institute 2003

Comments/
Results/
W/P Ref.

[Link]/auditprograms

COBIT
Reference

DS8

PO1
DS13
M1

14

Business
Objective

Risk

Control

Resources are
allocated to each
opportunity
according to its
size and
importance to the
organization.

Senior sales
personnel may
spend too much
time on minor
opportunities.
Junior sales
personnel may
pursue major
accounts.

The time allocated to


pursuing sales
opportunities is
proportionate to the
importance of the
account/opportunity.
Junior sales personnel
are assigned to minor
accounts. When junior
sales personnel work on
major accounts, a senior
sales person oversees all
account activities.
Senior sales personnel
are allocated to major
accounts with smaller
accounts handled by
junior sales personnel,
automated self-service
sales functionality or
administrative sales
support personnel.
The RFP is reviewed to
determine whether
customer requirements
are clearly defined and
can be met by the
organization.
Procedures are in place
for identifying,
verifying, clarifying
and modifying
customer requirements.
Procedures exist for
communicating and
resolving unfulfilled
requirements with the
customers.
Once finalized,
customer requirements
are documented in the
CRM system for all
sales personnel to
reference while
working on the RFP.

The request for


proposal (RFP) is
reviewed prior to
allocating
resources to the
preparation of a
response.

Customer
requirements
may be
misunderstood.

Copyright IT Governance Institute 2003

Comments/
Results/
W/P Ref.

[Link]/auditprograms

COBIT
Reference
PO6
DS13

AI1
AI4
DS3

15

Business
Objective

Risk

Control

Nonstandard
quotes are
accurately
prepared.

Nonstandard
quotes may be
inaccurately
prepared and
may not be
authorized.

Quotes may be
created or
amended by
unauthorized
personnel that
could result in
an inappropriate
commitment to
sell goods or
services to
customers.
Quotes may be
created without a
specified time
period.
Therefore, the
organization
may be obligated
to provide the
product/service
at a locked price
indefinitely into
the future which
could result in
sales at lower
than the
effective market
price.

Access to create
quotes is restricted
to authorized
personnel.

Quotes are valid


for a specified
period of time
only.

Copyright IT Governance Institute 2003

Comments/
Results/
W/P Ref.

COBIT
Reference

Procedures are in place


to guide the
preparation and
authorization of
nonstandard quotes.
Management must
review and authorize
all nonstandard quotes
over a specified
threshold.
Access to create or
maintain quotes in the
CRM/sales system is
restricted to authorized
personnel.

AI4
DS13

The CRM application


requires the entry of an
effective time period
for all quotes.

DS5

[Link]/auditprograms

DS5

16

Business
Objective

Risk

Control

Proposals are
created accurately
and completely.

Proposals may
be prepared
incompletely or
inaccurately.
Therefore, they
may not address
the customers
needs.

Proposals are
created in a timely
manner.

The proposal
addresses the
customers
requirements.

Products/services
are easily
distinguished from
competitors.

Proposals may
not be prepared
in a timely
manner,
resulting in
forfeited sales
opportunities.
The proposal
may not respond
to the RFP or the
customers
requirements.

The key reasons


why customers
should buy from
the organization
may not be
clearly
articulated,
resulting in a
lost sales
opportunity.

Copyright IT Governance Institute 2003

Comments/
Results/
W/P Ref.

COBIT
Reference

Proposal creation
procedures are
enforced and stipulate
the required
information for each
type of proposal.
Sales personnel are
trained in the
preparation of
proposals.
A quality review is
conducted of proposal
in which the proposals
are reviewed against
the original
requirements to ensure
that all the customer
requirements are met.
Proposal timelines are
identified and followed
during the creation of
proposals.

AI2
DS7

All proposals are


subject to quality
review by management
before being forwarded
to the customer to
ensure the original
customer requirements
are met.
The CRM application
can create comparisons
with competitor
products.
The key value
proposition for buyers
is clearly articulated
and communicated to
sales personnel and
customers.

PO8

[Link]/auditprograms

PO1
AI1

PO6

AI1

17

Business
Objective

Risk

Control

Current product
pricing and
information is
available to sales
personnel.

Pricing and product


information is stored in
a centralized CRM
database and is easily
accessed by all
authorized sales
personnel for use
during the sales
process.

AI3
DS3
DS5

The benefits of
winning the
proposal exceed
the cost of proposal
preparation.

A cost-benefit analysis
is prepared prior to
creating proposals to
ensure that the sales
are profitable.
There are mechanisms
to capture the full cost
of a bid/proposal
Only authorized
personnel can create or
modify proposals.
The CRM application
populates pricing and
other critical information
into the proposal
template.
Proposals are reviewed
and approved by
management.

PO6
DS1

Sales personnel
may not have
access to the
latest pricing and
product
information,
which could
result in
misleading
information
being supplied to
customers.
The cost of
preparing the
proposal may
exceed the profit
of the sale.

Proposals are
changed only by
authorized
personnel.

Inappropriate

changes may be
made to
proposals, which
may result in
inconsistent and
inaccurate
information
being presented
to customers.

Comments/
Results/
W/P Ref.

COBIT
Reference

DS5
DS9

Negotiating Terms and Closing Sales

Copyright IT Governance Institute 2003

[Link]/auditprograms

18

Business
Objective

Risk

Control

Customer
questions and
objections are
answered in a
timely manner.

Customer
questions or
objections may
not be
addressed,
resulting in a
lost sales
opportunity.

Sales personnel are


trained in
negotiating and
closing sales.

Sales personnel
may not be
familiar with
corporate
guidelines for
negotiating and
closing sales
transactions.

Procedures and
methodologies exist for
answering customer
questions and objections.
Sales personnel solicit
customer feedback as
part of the sales process
to identify customer
questions and objectives
not communicated.
For lost customers there
is a process for capturing
reasons why the
customer ceased trading
with the organization.
Market research or other
independent
organizations are
employed to
interview/discuss issues
with the lost customer
(control for loss of major
accounts only).
Sales personnel are
provided with
appropriate training for
negotiating and closing
sales.
Corporate guidelines
exist and are
communicated to sales
personnel for negotiating
and closing sales
transactions.

Copyright IT Governance Institute 2003

Comments/
Results/
W/P Ref.

[Link]/auditprograms

COBIT
Reference
DS4
DS8
AI1

DS7
AI4

19

Business
Objective

Risk

Control

Inactive sales
opportunities are
closed.

Inactive
opportunities
may remain
open in the
pipeline,
distorting the
sales forecast or
diverting sales
personnels
attention from
more profitable
sales leads.

Contract terms and


conditions are
drafted that are
clear and satisfy
both parties.

Contract terms
and conditions
may be
misunderstood
or disputed by
the customer.
Important
contractual
clauses may be
omitted, thereby
exposing the
organization to
significant risk.

Procedures enforce the


close of inactive leads on
a regular basis.
Aged reports of
opportunities sorted by
customer, salesperson,
territory, channel, etc.,
are available both to
clean up old prospects
and to identify areas of
poor sales performance
(i.e., where leads are not
being followed up).
Standard contract terms
and conditions are
prepared and used by
sales personnel.
Legal personnel are
involved in any unusual
contract negotiations.
Only qualified legal
personnel make
amendments to contracts.

Comments/
Results/
W/P Ref.

Processing Sales Orders


Sales orders are
Duplicate sales
only processed
orders may be
once.
received and/or
processed.

Sales orders are


processed in a
timely manner.

Procedures include a
search for existing sales
orders before the entry
of a new sales order.
The CRM system detects
potential duplicate sales
orders.
Sales orders may Sales orders are entered
not be entered
promptly when received.
into the system
Monitoring controls are
in a timely
in place to analyze the
manner,
timeliness of order
resulting in
processing.
delays for the
customer.

Copyright IT Governance Institute 2003

[Link]/auditprograms

COBIT
Reference
AI4
M1

PO4
DS1

DS5
DS11

PO6
PO8
M1

20

Business
Objective

Risk

Orders are created


with reference to a
quote (if
applicable).

Phone orders are


routed to the
appropriate
personnel.

Customers calls
are answered
promptly.

Orders are
processed
accurately and
completely.

Open orders and


orders in error are
corrected in a
timely manner.

Control

Comments/
Results/
W/P Ref.

Sales orders may The CRM system


not reference the
automatically links the
corresponding
quotes to the sales order,
quotes, which
or provides a list of
could result in
possible quotes from
pricing errors or
which to reference the
deviations.
sales order.
Lost revenue or Procedures govern the
customer
creation of sales orders
dissatisfaction
based on quotes,
may occur.
whenever possible.
Phone orders
The system
may not be
automatically routes
routed to the
the caller to the
appropriate
appropriate sales
personnel.
personnel or
appropriate manual
Lost revenue or
procedures exist.
customer
dissatisfaction
may occur.
Customer calls
Call wait times are
may not be
actively monitored and
answered and
appropriate remedial
responded to
action taken if wait
promptly.
times exceed a
predetermined
Lost business or
maximum response
customer
time.
dissatisfaction
may occur.
Incomplete or
The sales order
inaccurate orders
processing system is
may occur.
configured to enforce
the entry of all
Lost revenue or
required fields
customer
necessary to
dissatisfaction
completely process the
may occur.
sales order.
Open orders and
Open orders and
orders that have
orders with errors are
errors may not
monitored actively by
process in a
sales personnel.
timely manner.
Lost sales and
customer
dissatisfaction
may occur.

Copyright IT Governance Institute 2003

[Link]/auditprograms

COBIT
Reference
AI1
AI4

DS11

M1
DS8

DS9

M1

21

Business
Objective

Risk

Order pricing,
discounts and
payment terms are
approved.

Control

Orders may be
processed with
unauthorized
pricing,
discounts or
terms of
payment.

Customer orders
are controlled by
credit limits.

A customers
credit limit may
not be checked
prior to order
processing
which may
expose the
organization to
unnecessary risk
of bad debts.
Processing Internet Sales Orders

Copyright IT Governance Institute 2003

Comments/
Results/
W/P Ref.

The CRM application


controls customer
credit limits.
Changes to pricing,
discounts and payment
terms require
management approval.
Prices may only be
changed within preestablished limits.
Management must
approve all changes
outside these limits.
Where ERP and CRM
systems interact there
is a single process for
determining the price
(i.e., either the ERP
system or the CRM
system is used for
determining the price).
Regular monitoring of
prices is carried out by
review of pricing
master data and actual
margin achieved per
order, to identify
possible pricing errors
(or salesperson
override).
The CRM/sales order
system validates that
the customer credit
limit has not been
exceeded prior to
processing the order.
Only authorized
personnel can override
credit limits.

[Link]/auditprograms

COBIT
Reference
AI2

DS5
DS11
M1

AI2
DS5

22

Business
Objective

Risk

Customers
personal
information is
protected.

Internet customers
are differentiated to
enable unique
needs to be met.

Control

The privacy of
customer
information
collected on the
web site may not
be safeguarded,
resulting in a
loss of customer
confidence.

Internet
customers may
not be identified
uniquely.

Internet customers
are authenticated.

Web site security


may not provide
adequate online
security.
Compromised
customer
confidentiality
and fraudulent
transactions may
occur.

Copyright IT Governance Institute 2003

Comments/
Results/
W/P Ref.

A formal privacy
policy governs the
treatment of customer
personal information.
The privacy policy is
communicated to all
customers via the web
site and has been
independently certified
(e.g., BetterWeb, CPA
WebTrust).
The system is
customized to identify
Internet users and
provide a tailored
environment for each
customer (e.g., access
to order history,
favorite links).
Internet procedures are
linked into the core
business to allow
customers the ability
to choose their channel
preference for returns,
future sales, sales
support, customer
service, etc.
Password standards
and controls are
enforced by the system
(e.g., minimum
password lengths,
disallowed common
passwords).
Each Internet session
timeouts after a
minimum period of
inactivity.

[Link]/auditprograms

COBIT
Reference
PO6

PO8
DS11

AI2
AI4

DS5

23

Business
Objective

Risk

The web servers


can accommodate
the anticipated
volume of traffic.

Control

Service delays
and interruptions
may occur.

Internet sales
initiatives are
effective at
generating sales
with existing
customers and for
obtaining new
customers.

The
effectiveness of
Internet sales
initiatives may
not be measured.
The Internet
sales channel
may not be used
to its full
potential.

The web site


contains
comprehensive and
up-to-date
information on
products/services.

Insufficient and
inaccurate
information
about products
and services may
be available on
the web site.
Page links may
fail, resulting in
customer
abandonment.

Copyright IT Governance Institute 2003

Comments/
Results/
W/P Ref.

Server capacity is
appropriate for
maximum anticipated
customer volumes.
Server capacity is
constantly monitored
to identify potential
problems before they
occur.
Use of the web site is
monitored to assess its
effectiveness (e.g.,
abandon rates, repeat
customers).
Feedback is solicited
from customers about
the web site.
Web site improvement
recommendations are
prioritized regarding
the impact on sales,
cost-benefit, etc.
Improvement
recommendations are
incorporated into the
web site to make it a
more effective sales
channel.
Content management
software is used to
ensure that web site
product and service
data are accurate,
complete, current and
comprehensive.
All web site links and
operations are tested
prior to
implementation for
functionality and
stickiness.

[Link]/auditprograms

COBIT
Reference
DS1
M1

M1
AI4
AI6
DS8

DS9
AI5

24

Business
Objective

Risk

Web site
transactions are
valid.

Internet orders are


processed
accurately and
completely.

Control

Web site
transactions may
be not verified
or authorized.
Fraudulent
transactions may
be processed.
Internet order
information may
not be complete
or accurate.

Customer credit card


details are verified
with banks; additional
fraud prevention
processes are in place.

DS5
DS11

The CRM application


requires key fields to
be entered before the
order can be saved.
Field validations are
performed on key
fields.
Reports are monitored
to identify incomplete
transfer of data from
the web site front end
to the order processing
system.
Order confirmations
are sent to customers.
User authentication
procedures exist to
validate the identity of
customers.
Customer payment and
address data are
validated.

DS5
M1

Unauthorized
individuals may
process Internet
orders.

Copyright IT Governance Institute 2003

COBIT
Reference

Only valid sales


orders are
processed via the
Internet.

Comments/
Results/
W/P Ref.

[Link]/auditprograms

DS5

25

Business
Objective

Risk

Sales orders are


processed
completely and
accurately.

Control

Sales orders may


not be processed
due to a lost
connection
during an online
session.
Sales order data
may be
incomplete,
resulting in
delays in
shipping and
customer
dissatisfaction.

Customer credit
card data are
secured from
unauthorized use.

Sales order data are


completely and
accurately
interfaced to backoffice systems.

Customer credit
card data may
not be
encrypted, which
could result in
credit card
information
being
compromised.

Delays may
occur in
shipping and
invoicing,
increasing the
potential for
cancelled orders
and customer
dissatisfaction.

Copyright IT Governance Institute 2003

Comments/
Results/
W/P Ref.

Contact information is
provided in the event
the customer needs to
call about a processing
error.
Shopping cart
information is
maintained to ensure
the sales order is
completely and
accurately captured.
The Internet order
entry system requires
that all key fields be
entered before the
order can be
submitted.
Customers are notified
if any required data are
missing.
Customer credit card
information is
protected during
transmission from the
web site by encryption
technology (e.g., 128
bit SSL encryption).
Credit card data are
stored in a secured
encrypted database
within the organization
and access is restricted
to authorized
personnel only.
The web site and CRM
application are
integrated.
Front- and back-office
systems are integrated.
Interface monitoring
controls ensure the
accuracy and
completeness of all
data transfers between
systems.

[Link]/auditprograms

COBIT
Reference
DS5

DS10

DS5

PO8

AI1
PO8
DS3

26

Business
Objective

Risk

Sales orders are


confirmed with the
customer.

Control

Sales orders may


not be
confirmed,
which might
result in sales
order errors
remaining
undetected,
increasing the
potential cost of
returns.
The systems
may not provide
customers with
real-time
inventory
availability data,
which could lead
to customer
dissatisfaction
and loss of
repeat business.

If customers do
not log out the
session, the
session may
remain active
after they have
left their
terminal.
Unauthorized or
fraudulent
transactions may
occur.
Processing Telephone Sales/Telesales

Stock availability
is confirmed with
the customer.

Customer sessions
are terminated after
they have logged
out.

Copyright IT Governance Institute 2003

Comments/
Results/
W/P Ref.

Sales orders via the


Internet are confirmed
and a unique order
number is provided to
the customer, which
can be used for
tracking the order
status.
Management monitors
order confirmations
and open orders.
The availability of
stock to complete the
order is provided
online to the customer
prior to placing the
order.
Customers are
automatically notified
via e-mail or phone
when unexpected
stock shortages or
delays occur.
The system terminates
the customers active
session when they
select the log out
option.
The browser back key
cannot be used to gain
access to a terminated
session.

[Link]/auditprograms

COBIT
Reference
DS3
M1

DS8

DS11

DS5

27

Business
Objective

Risk

Telesales strategies
are properly
communicated to
sales personnel.

Telesales activities
are controlled and
monitored to
ensure goals are
met.

Control

Telesales
strategies may
not be properly
communicated
to sales
personnel.

Telesales

activities may
not be monitored
properly and,
therefore, sales
goals are not
met.

Copyright IT Governance Institute 2003

Comments/
Results/
W/P Ref.

Telesales strategies are


formalized, clearly
documented, and
communicated to all
sales personnel.
Strategies include
identifying the
marketing activity
(e.g., qualifying
opportunities, setting
appointments,
gathering information,
closing the sale),
identifying how these
activities are presently
handled, and how
telesales can achieve
the companys sales
goals.
Management monitors
telesales activities.
Regularly,
management evaluates
and makes adjustments
to telesales activities to
ensure telesales goals
are met.

[Link]/auditprograms

COBIT
Reference
AI4
PO1

M1
DS11

28

Business
Objective

Risk

Telesales personnel
are properly
trained and their
activities
monitored to
ensure their
conduct and
performance best
represent the
company in
meeting its
telesales
objectives.

Control

Comments/
Results/
W/P Ref.

Telesales
The company trains and
personnel may
routinely monitors the
not be
activities of telesales
adequately
personnel. Training may
trained. As a
include:
result, potential
- Use of sales
sales may be lost
literature
or optimum
- Responses to
customer
common questions /
satisfaction may
objections
not be achieved.
- Use of call scripts
- Increased emphasis
on listening
- Building rapport
- Understanding of
products and/or
services and how
they best fit the
customers buying
motives (e.g.,
financial benefits,
security,
convenience, sex
appeal, pleasure, and
acceptance).
Monitoring activities
may include:
- Periodic review of
sales calls
- Comparing actual to
budgeted goals

Copyright IT Governance Institute 2003

[Link]/auditprograms

COBIT
Reference
DS7
M1

29

Business
Objective

Risk

Sales personnel
identify and
manage their
objectives and
goals for each call.

Control

Call goals are


not identified,
which may result
in nonproductive
sales activity.

Customers are
contacted only
once per sales
opportunity.

Telesales
personnel may
inadvertently
contact a
customer that
has already been
contacted or
closed.

Copyright IT Governance Institute 2003

Comments/
Results/
W/P Ref.

Goals are identified for


each call.
Telesales personnel
identify the marketing
context and approach
of the telephone call
and what they want to
accomplish (e.g.,
initial contact or
closing sale). This will
then determine what
they have to learn
about the prospect or
his/her company
before the call.
Sales personnel may
identify:
- Entity (e.g.,
individual or
business)
- Decision maker(s)
- Questions to ask to
understand buyers
needs, desires,
concerns, problems
- Accuracy of
information that
may be presented
- Previous inquires
about products/
services
The CRM application
is used to accurately
track and close
opportunities.
The CRM application
prevents multiple
telesales personnel
from contacting the
same prospects by a
lock-out feature on the
record.

[Link]/auditprograms

COBIT
Reference
PO1
DS1

PO9
DS5

30

Business
Objective

Risk

Control

Telesales personnel
utilize electronic
call worksheets
to ensure proper
information and
gathering of
information is
performed for each
prospect.

Call worksheets
may not be
utilized to track
telesales
activities.

Telesales personnel
interact with
customers in a
knowledgeable and
consistent manner.

Untrained or
inexperienced
telesales
personnel may
be inconsistent
or unknowledgeable. As a result,
customer
interactions may
not be
appropriate.

Environment is
free from excessive
noise to ensure
communication
between the
customers and
telesales personnel
is clear.

Customers may
not be able to
hear or
understand
telesales
personnel.

Sales personnel utilize


electronic call
worksheets to track and
monitor telesales
activities. Call
worksheets may include:
- Opening (e.g., greeting/
introduction)
- Decision-makers and
influencers
- Buyers needs
/response to needs
- Product position (e.g.,
position features and
benefits to match
buyers needs)
- Call notes
- Closing activity (e.g.,
ask for order, request
next step, action
step, commitment).
The smart scripting
functionality within
the CRM application is
used to enable the
telesales personnel to
interact with
customers in a
knowledgeable and
consistent way. Smart
scripting generates
questions to ask
callers, based upon
their answers to
previous questions and
customer attributes.
The company
maintains a productive
working environment
for its telesales
personnel and the
environment is free
from excessive noise.

Copyright IT Governance Institute 2003

Comments/
Results/
W/P Ref.

[Link]/auditprograms

COBIT
Reference
PO9
M1

DS7
DS8

PO6

31

Business
Objective

Risk

Telesales personnel
are trained to
gather and analyze
customer
information to
ensure customers
needs/wants are
met successfully.

Telesales personnel
are trained to
ensure product/
service fits
customers needs.

Control

Customer needs
may not be
addressed
/identified fully,
resulting in loss
sales.

Comments/
Results/
W/P Ref.

Telesales personnel are


periodically trained to
gather and analyze
customer information
to determine needs and
interests.
Training activities may
include:
- Developing
effective listening
skills (e.g.,
listening for buying
motives that may
not arise in the
course of formal
questioning)
- Probing more
detailed questions
(e.g., open-ended
questions for a full,
expository answer)
- Utilizing available
data (e.g.,
information
gathered on
application forms,
requests for
information)
Product/service The company provides
solution may not
periodic training to its
fit customers
telesales personnel on its
needs/wants.
products/services,
identifying potential
needs/wants they may
satisfy.
Changes to an
enterprises products/
service are formally
communicated,
identifying the value that
can be obtained and
potential needs that can
be filled.

Copyright IT Governance Institute 2003

[Link]/auditprograms

COBIT
Reference
DS7
PO7

DS7
PO7

32

Business
Objective

Risk

Control

Comments/
Results/
W/P Ref.

COBIT
Reference

DS5
Telesales
Telesales personnel
personnel may
have access to critical
not have access
customer information
to critical
to allow them to
customer
review and analyze
information.
customer information.
Note: Please refer to the Processing Sales Order section for additional telesales order controls and the
Customer Service section for additional controls for managing telesales personnel within the interaction
center.
Delivering Goods to the Proper Location at the Right Time
Goods are
AI2
Deliveries may

Orders are validated


delivered to the
DS1
be created which
for completeness
proper location at
do not refer to
during order handling
the right time.
approved sales
before they are passed
orders, therefore
to delivery.
fraudulent

Deliveries completed
deliveries could
before the end of the
occur.
period are posted to
update the inventory
balances.
Goods are
DS1
Backorders and
Management
delivered to the
DS10
incomplete
periodically reviews
proper location at
orders may not
the list of backorders
the right time.
be processed
and releases them for
when items
processing.
become
available,
resulting in lost
sales and
customer
dissatisfaction.
Telesales personnel
are given
appropriate access
to customer
information.

Copyright IT Governance Institute 2003

[Link]/auditprograms

33

Business
Objective

Risk

Goods are
delivered to the
proper location at
the right time.

Goods are
delivered to the
proper location at
the right time.

Control

Comments/
Results/
W/P Ref.

Deliveries may
Goods can be posted for
not be processed
a delivery only if the
in the correct
following prerequisites
accounting
are fulfilled:
period if
- The data in the
procedures are
delivery must be
not established
complete.
to verify cutoff
- Picking must have
of shipments.
been completed for
This would
all items in the
result in
delivery.
misstated
Once a delivery has been
inventory and
processed, the following
cost of goods
functions occur:
sold, and a
- Stock quantities are
failure to invoice
updated.
the customer for
- Balance sheet
the sale.
accounts are
evaluated and
updated.
- Requirements are
reduced.
- The invoice is
processed.
Access to
Access to delivery
delivery
functions is restricted
processing
to delivery personnel.
functions may
not be restricted
to users in the
shipping
department, to
prevent
unauthorized
deliveries and
unauthorized
changes.

Copyright IT Governance Institute 2003

[Link]/auditprograms

COBIT
Reference
AI2

DS9
DS11

DS5

34

Business
Objective

Risk

Goods are
delivered to the
proper location at
the right time.

Goods are
delivered to the
proper location at
the right time.

Goods are
delivered to the
proper location at
the right time.

Goods are
delivered to the
proper location at
the right time.

Control

Comments/
Results/
W/P Ref.

Approved orders All approved orders


may not be
are processed for
delivered,
delivery regularly.
resulting in
financial loss to
the company,
dissatisfied
customers and
understated
revenues and
receivables.
Rejected
Rejected and
deliveries may
incomplete deliveries
not be isolated,
are reviewed regularly
analyzed and
and corrected.
corrected in a
timely manner.
Deliveries may
Customers who are
be processed for
considered a risk for
customers who
payment are blocked
represent a credit
for deliveries and
risk to the
informed promptly
company.
that the sales order and
delivery cannot be
Customer may
processed. By clearly
not be advised
communicating these
promptly that
policies, any confusion
orders and
by the customer is
deliveries will
avoided.
not be processed
for them due to
their credit risk.
Ordered goods
A formal process exists
may not be
for picking and
picked and
preparing orders for
packed for
shipment.
shipment
Procedures for picking
properly,
and preparing orders for
resulting in
shipment are
shipping delays.
documented.
Shipping personnel are
properly trained on all
loading procedures.
Specifications and
quantity of products
retrieved from storage is
reconciled back to the

Copyright IT Governance Institute 2003

[Link]/auditprograms

COBIT
Reference
DS11

DS10

DS10

PO6

M1
DS7
DS10
DS13

35

Business
Objective

Risk

Control

Goods are
delivered to the
proper location at
the right time.

Shipments may
not be accurate.

Copyright IT Governance Institute 2003

Comments/
Results/
W/P Ref.

authorized customer
order or delivery
documentation prior to
loading.
Order picking is
undertaken to ensure that
stock is picked on a
FIFO basis.
Goods dispatched
document is issued for
all deliveries.
Goods dispatched
documents are prenumbered and
sequentially controlled.
Order documents are
pre-numbered and
missing documents are
investigated promptly.
Key performance
indicators are:
- Order accuracy
- Percentage pick
accuracy
- Number of expedited
or emergency orders
by cause
A formal process exists
for verifying loads for
shipment (correct goods/
quantities and no
damage/mislabeling).
Packing materials,
containers and
procedures give
consideration to the
nature of the product and
method of delivery to
safeguard products.
Goods are checked for
accuracy, damage and
proper labeling/packing
prior to loading.

[Link]/auditprograms

COBIT
Reference

PO6

36

Business
Objective

Risk

Control

Goods are
delivered to the
proper location at
the right time.

Carriers may not


deliver goods to
customers on
time.

Goods are
delivered to the
proper location at
the right time.

Shipping
documentation
may not be
accurate.

Formal processes exist


for coordinating carrier
transport for customer
shipments.
All transport carriers are
evaluated for financial
stability, service quality
and proper insurance.
The selection of
approved carriers also
involves personnel
independent of the
logistics function.
Customer information
and specific
requirements are
communicated to
external carriers to
ensure timely and
accurate delivery.
Key performance
indicators are:
- Transit cycle times
by mode, route and
carrier
- Percentage of
shipments by
individual carrier
- Percentage of
shipments by mode
- Transit time
- Dollar amount by
carrier
Formal processes exist
for preparing/processing
shipping documentation.
Documented procedures
for outbound logistics
are in place.
Personnel are trained
properly on procedures.
All delivery notes are
signed and time-stamped
by customers or thirdparty carriers.
Controls are in place to

Copyright IT Governance Institute 2003

Comments/
Results/
W/P Ref.

[Link]/auditprograms

COBIT
Reference
PO6

PO11

AI2

PO4
DS7
DS13

37

Business
Objective

Risk

Control

Goods are
delivered to the
proper location at
the right time.

Foreign or other
unique customer
shipments may
not be delivered
to the customer
on time to the
right location.

Copyright IT Governance Institute 2003

Comments/
Results/
W/P Ref.

ensure proper
preparation, approval
and accountability over
bills of lading, air bills,
manifests or the
equivalent.
Final shipping
documents drive
customer billings as pick
tickets were updated
during loading.
Shipping documents are
cross-referenced
properly to the document
authorizing the
shipment.
Controls ensure goods
are shipped in
accordance with agreed
delivery term.
Appropriate procedures
exist for obtaining and
filing signed documents
and recording of seals on
all loaded trucks.
Key performance
indicators are:
- Undeliverable
shipments by cause
- Billing disputes by
customer/cause/
location
- Delivery document
accuracy percentage
- Credit memos by
cause
Formal processes exist
for preparing/processing
documentation for
foreign/other unique
customer shipments.
Export arrangements and
requirements are
separately determined
and take into account
methods of
transportation, packing

[Link]/auditprograms

COBIT
Reference

DS13

AI1
PO6

38

Business
Objective

Risk

Control

Comments/
Results/
W/P Ref.

COBIT
Reference

requirements, etc.
Export documentation
clearly defines when title
passes and when
responsibility for
insurance passes to the
importer.
Procedures are adequate
to ensure that all
necessary documents are
forwarded to customers
so that they are received
before goods arrive.
Customs classifications
for materials are
accurately defined for
customs purposes.
Applicable export
permits are obtained for
all shipments as
necessary.
Shipments classified as
containing hazardous
materials have required
transport/safety
documentation.
Controls in place for
return of signed
manifests documenting
final disposition on
hazardous loads.

Copyright IT Governance Institute 2003

[Link]/auditprograms

39

Business
Objective

Risk

Control

Goods are
delivered to the
proper location at
the right time.

Customer
shipments may
not be tracked
properly.

Goods are
delivered to the
proper location at
the right time.

Customers may
not be
communicated
with promptly
about goods
damaged, lost or
stolen in transit.

Formal processes exist


for tracking products
shipped to customers.
A reliable system is in
place for monitoring
customer shipments and
taking corrective action
promptly.
An emergency delivery
process is in place and
understood.
Key performance
indicators include:
- Redeliveries
- Order receipts
- Order refusals
- Delivery promised
dates to actual
- Inquiry response
time by average
minutes/hours
- Perfect orders
received or delivered
on time
- Customer
complaints (total or
percentage)
Formal processes exist
for addressing goods
damaged, lost or stolen
in transit.
Procedures are in place
to ensure freight claims
are promptly filed,
followed up and
collected.
Allowances or returns
for products damaged,
lost or stolen in transmit
handled within
companys policy
parameters.
Management reviews
and follows up on
reports of customer
returns due to incorrect

Copyright IT Governance Institute 2003

Comments/
Results/
W/P Ref.

[Link]/auditprograms

COBIT
Reference
DS13

PO4

PO8

M1
DS13

40

Business
Objective

Risk

Control

Comments/
Results/
W/P Ref.

goods being delivered or


billing disputes relating
to products delivered
that were inferior quality
or damaged.
Key performance
indicators:
- Damages/loss as a
percentage of sales
- Shipments with
claims percent/
carrier claim ratio
- Claims handling
cycle time days
- Damage-free
delivery
performance
- Total damage costs
Post SalesHandling Customer Sales Questions
Sales inquiries are
Sales inquiries
Sales personnel
routed to the
may be
maintain regular
correct personnel
misrouted,
contact with
for response.
resulting in
customers.
customer
Inquiries are routed
dissatisfaction
to the correct inside
because of
or outside sales
response delays.
person for
resolution.
Customer requests
Customer
Customer requests
are immediately
requests may not
are auto-answered,
acknowledged,
be
when feasible.
enhancing
acknowledged in
Acknowledgments
customers
a timely manner.
or confirmations
experience and
are sent to
satisfaction.
customers to
indicate that their
request was
received and the
expected response
time is indicated.
Customers are
provided selfservice
functionality to
handle the majority
of sales inquiries.

Copyright IT Governance Institute 2003

[Link]/auditprograms

COBIT
Reference

DS1

DS1

41

Business
Objective

Risk

Customer sales
information is
completely and
accurately input.

Control

Customer sales
information may
be entered
inconsistently or
incompletely.

Sales inquiries are


routed
appropriately and
reports on requests
are accurate.

Inquiries are routed


appropriately and
reports on requests
are accurate.

Requests may by
categorized
inconsistently,
resulting in
inaccurate
routing and/or
reporting.
Inquiries may be
categorized
inconsistently,
resulting in
untimely
resolution and
inaccurate
reporting.

Copyright IT Governance Institute 2003

Comments/
Results/
W/P Ref.

Sales personnel are


trained
appropriately on
data entry
requirements and
the intended uses
for fields.
Key fields are
required to be
entered.
When possible,
pick lists and field
masks are used to
validate and secure
data entry (i.e., pick
lists for titles,
preferences, states,
field masks for
phone numbers,
social security
numbers, credit
card numbers).
Sales personnel (or
customers via web
forms/e-mail) are
required to select a
request type from a
pick list to indicate
the type of inquiry.
Sales personnel are
trained on the
proper usage of the
different request
types.
Formal procedures
exist for processing
requests.

[Link]/auditprograms

COBIT
Reference
DS7

AI4

DS7

42

Business
Objective

Risk

Adequate
information is
captured about
customer inquiries.

Insufficient detail
as to nature of the
request may be
captured in initial
contact with
customer.

Control

Inquiries are
appropriately
prioritized, so that
they are addressed
in an appropriate
manner.

Inquiries may be
prioritized
inappropriately.

Inquiry resolution
information is
captured.

Sales personnel
may not provide
complete
descriptions of
how issues are
resolved.
Therefore,
request
resolution
information is
not available to
answer
subsequent
questions.

Copyright IT Governance Institute 2003

Comments/
Results/
W/P Ref.

Sales personnel are


appropriately
trained on the
importance of
understanding and
documenting the
request with
sufficient detail.
A description field
is required when
documenting a
request.
Sales personnel are
trained
appropriately on
the meaning of
service request
severity codes.
The severity field is
required and given
an appropriate
default.
Management
monitors the
number of
outstanding service
requests by severity
to help determine
the appropriate use
of severity codes.
The inquiry
resolution field
should be
configured as
required to ensure
proper
documentation.

[Link]/auditprograms

COBIT
Reference
DS7

DS7
AI1
M1

DS9

43

Business
Objective

Risk

Inquiries and
requests are
appropriately
closed.

Customers are
satisfied with the
request resolution.

Control

Inquiries and
requests may not
be closed
properly;
therefore, the
requests remain
open on the
system and
continue to be
worked on by
other employees.

Request
resolutions may
be closed
without the
customer being
satisfied with the
response.

Copyright IT Governance Institute 2003

Comments/
Results/
W/P Ref.

Procedures are
defined on how and
when to
appropriately close
a request or inquiry.
Monitoring
controls exist to
monitor open
requests or
inquiries to ensure
that they are closed
in a timely manner.
Customers are
surveyed
periodically to
determine
satisfaction. The
surveys include
feedback on system
accessibility, frontline
professionalism
and overall
satisfaction with
the way their calls
are handled.
When customers email addresses are
available, they are
e-mailed a
confirmation that
their request has
been closed and the
customers have the
ability to provide
feedback. Mail
confirmation is sent
if e-mail is
unavailable.

[Link]/auditprograms

COBIT
Reference
DS13
M1

DS1

44

Business
Objective

Risk

Customer feedback
is quantified and
analyzed on a
proactive basis.

Control

Sales personnel
may not be
effective in
handling
customer
inquiries.

Copyright IT Governance Institute 2003

Comments/
Results/
W/P Ref.

Management
notifies appropriate
individuals that a
complaint was filed
for their area of
responsibility.
Management and
the responsible
individual
determine and
implement an
action plan to avoid
the noted complaint
in the future.
The action plans
are documented
and monitored.

[Link]/auditprograms

COBIT
Reference
AI5
DS1
M1

45

2.

Marketing Risks Work Program

The following work program will help manage marketing risks within the organization. Those
auditing, reviewing or advising on controls in a CRM project need to select tasks from the work
program and consider the key issues raised in the IT Governance Institute publication Risks of
Customer Relationship Management as part of their preparation. The work program should not be
used as a checklist of best practice, but as a selection of examples of good practice that can be
applied. By using the work programs blindly, there is a risk of losing the confidence of the auditee
and even of missing the largest risks in the project, due to the peculiarities of each project.
Therefore, work programs should be used as guidance and specific knowledge of the organization
and risks should be added to them.
Note: A business objective may be listed more than once because it has multiple risks and
corresponding control objectives. Note disclaimer.
Business
Objective

Risk

Marketing Strategy
New product and

services offerings
are defined
accurately and
clearly.

New product and


service offerings
may be defined
inaccurately or
unclearly,
resulting in
diminished sales
opportunities or
dissatisfied
customers.

Control

Copyright IT Governance Institute 2003

Comments/
Results/
W/P Ref.

Product offerings are


clearly defined and
planned. The
information includes,
at a minimum:

Target audience

Expected revenue
stream

Time period

Cost
A process is in place
for gathering and
documenting the
technical specifications
and intended uses and
functional information
for products and
services, including, at a
minimum:

Product shelf life

Product wear-out
rates

Problems that may


result from
improper usage or
consumption

[Link]/auditprograms

COBIT
Reference
PO1
AI4
AI6

46

Business
Objective

Risk

Control

New product and


service offerings
are continually
identified.

A process is in place
for the continual
generation and review
of new product and
service ideas.

DS3

Products are
available to ensure
a successful new
launch.

As part of the product


development
processes, procedures
ensure that products or
services can be
supplied following a
product or service
launch.

DS1
DS3

Market information
and research aids in
determining product
pricing.

PO10

Only authorized users


have access to
create/maintain pricing
lists, marketing
templates, literature,
etc.

DS5

Product pricing is
commensurate with
market conditions
and product
positioning.

Access is properly
restricted.

Organization
may not meet
sales and
marketing goals
because new
product and
service offering
possibilities are
not identified.
Product or
retailer
marketing
campaigns may
not consider
production
schedules or
inventory levels
resulting in
delays in product
delivery.
Contractual
defaults or
customer
dissatisfaction
may result.
Pricing may not
be appropriate
for product or
service
positioning,
resulting in a
loss of sales.
Pricing lists,
marketing
templates and
literature may be
altered without
authorization.

Copyright IT Governance Institute 2003

Comments/
Results/
W/P Ref.

[Link]/auditprograms

COBIT
Reference

47

Business
Objective

Risk

Control

Product
effectiveness is
monitored.

New product or
service offerings
may not be
measured,
resulting in the
inability to
determine the
success of the
new product or
service.

Comments/
Results/
W/P Ref.

Project managers are


made accountable for
delivering a
commercially
successful product.
Customer and
competitive reaction to
the new product is
monitored.
Planned vs. actual
financial results are
monitored and reported
to management.
A product-costing
model is used to assess
product costs,
including all ancillary
costs related to product
introduction as well as
development.
Marketing Strategy Research and Execution (Market Understanding and Analysis)
Market data are
Invalid market
Market data are
valid and from a
data may lead to
validated and research
reliable source.
false
sources are
assumptions
investigated for
regarding market
reputation and
conditions.
reliability.
A complete
An incomplete
Market driving
understanding of
understanding
conditions have been
market conditions
and analysis of
identified.
exists within the
market
Analytical procedures
organization.
conditions may
are used to measure
lead to
and monitor changing
ineffective or
conditions.
inappropriate
market strategy
and sales
penetration.

Copyright IT Governance Institute 2003

[Link]/auditprograms

COBIT
Reference
M1

DS11

AI1

48

Business
Objective

Risk

Control

Competitor product
and service
offerings are
identified and their
impact on the
organizations own
product and service
range is fully
assessed.

Customer feedback
and survey
responses are
accurate.

The organization
may lose a
competitive
advantage by not
identifying a
competitors
changes in its
product and
service
offerings.
Inaccurate
customer
feedback and
responses to
marketing
surveys may
lead to
inaccurate
understanding of
customer wants
and needs.

Comments/
Results/
W/P Ref.

Regular comparison of
product and service
offerings is performed
against identified
competitors, and
improvements are
made to product and
service offerings, as
appropriate.

Procedures exist to
ensure that marketing
surveys and customer
feedback are accurate
and that questions are
not leading (i.e. forcing
or encouraging the
customer to answer a
certain way).
Customer feedback is
incorporated into the
processes to improve
products and services.
Regulatory barriers Regulatory
Regulatory barriers are
relevant to entering
barriers may
identified and assessed
a market are
delay or prevent
by marketing personnel
clearly understood.
entry into
and are taken into
markets
consideration when
significantly.
working with research
and development for
new products and
services.
Marketing Strategy Research and Execution (Market Segmentation)
Customer needs
Information about Marketing surveys are
and wants are
targeted consumers
used to understand
understood
may be poor or
customer needs and
completely.
unavailable.
wants. These surveys
contain information such
Customer
as:
expectations may
- Demographics
not be understood
- Preference
properly.
- Buying habits

Copyright IT Governance Institute 2003

[Link]/auditprograms

COBIT
Reference
DS3
PO3

AI4
AI5
PO10

PO8

DS1

49

Business
Objective

Risk

Control

Comments/
Results/
W/P Ref.

COBIT
Reference

DS1
Unclear or
Marketing personnel
outdated market
periodically evaluate
segment
existing market segment
definitions may
definitions.
lead to inefficient
Segment definitions are
campaigns and
updated periodically as
target marketing.
the market changes.
Marketing
PO5
Marketing dollars Marketing prioritizes
segments are
may be spent on
market segments based
prioritized and
market segments
on the organizations
campaigns are
that do not need
strategic plan, highest
appropriately
incentives
return, growth potential,
targeted to
provided or that
competitive advantage,
maximize return on
are not part of
etc.
investment for
managements
Campaigns are
marketing
strategic plan for
prioritized and targeted
expenditures.
targeting
toward the most
customers.
profitable market
Fewer sales leads
segments.
may be generated
as a result of
inappropriate
campaign
targeting.
Marketing Strategy Research and Execution (Marketing Campaign Planning and Execution)
Efficient
AI1
Inefficient and
Campaign management
campaigns are
ineffective
software and processes
conducted
campaigns,
are used to effectively
leveraging
which do not
plan, execute, track and
technology to
maximize the
analyze marketing
effectively
organizations
campaigns.
automate and
marketing
Marketing personnel
inform the
investment
measure each
processes of
dollars, may be
campaigns return-onplanning,
executed.
investment, time-toexecuting, tracking
market, campaign
and analyzing
execution, etc.
marketing
campaigns.
Market segments
are clearly and
properly defined.

Copyright IT Governance Institute 2003

[Link]/auditprograms

50

Business
Objective

Risk

Control

Comments/
Results/
W/P Ref.

COBIT
Reference

AI4
Clearly defined metrics
PO10
and objectives are in use
to track and review
campaign effectiveness
and return on
investment.
Management uses the
objectives and metrics to
assess campaign
effectiveness.
Metrics to consider
tracking are:
- Costs
- Return on
investment
- Customer response
- Customer action
Lessons learned are
tracked for both
successful and
unsuccessful campaigns,
and the lessons are
incorporated into future
campaigns.
Marketing Strategy Research and Execution (Capturing and Analyzing Marketing Strategy
Effectiveness)
The organization
PO2
Data mining techniques
Marketing
efficiently and
and software are used to
information that
effectively
analyze customer data.
has been
analyzes customer
Data mining techniques
gathered may
information.
may include:
not provide
- Product affinity
value.
analysis
- Customer retention
and vulnerability
- Customer
acquisition life cycle
- Price optimization
- Risk management
Data modeling
techniques are regularly
reviewed to optimize
interpretation of existing
data.
Campaign
effectiveness is
measured through
the use of clearly
defined metrics
and objectives.

Ineffective
campaigns may be
repeated due to
poor or undefined
metrics and
objectives.
Effective
campaigns may
not be detected
and therefore they
are not repeated.

Copyright IT Governance Institute 2003

[Link]/auditprograms

51

Business
Objective

Risk

Control

The marketing
strategy is
continually refined
based on new
customer data.

Data mining results and


campaign effectiveness
reports are incorporated
formally into future
marketing decisions.
Formal procedures exist
to assess and report
campaign effectiveness
to all relevant personnel
on an ongoing basis.
Meaningful and relevant
key performance
indicators are measured
and analyzed.

AI1
PO1

Management approval
procedures are in place
to select and review
marketing service
providers.
Formal vendor selection
and management
methodology is used.
Procedures to monitor
vendor viability and
creditworthiness are
used.
Periodic competitive
rebidding is required.

DS1
DS2

Formal procedures are


used to monitor vendor
quality and delivery
standards (e.g., time,
documentation).
Escrow agreements and
contingency plans are

DS2

Vendor Management
Marketing service
providers meet
quality, quantity,
price, delivery or
other requirements.

Marketing
strategies and
campaigns may
not be effective
for current and
future trends.

Advertising
agencies, market
research
organizations and
other marketing
service providers
may not provide
value for services
purchased.
Organization
policy may not
require that service
providers be
selected through a
formal process,
using objective
criteria.
Contractual terms
may not be clear,
favorable to the
organization,
properly
enforceable or
competitive.
Vendor work meets Vendor quality
quality and
standards may
delivery standards.
differ in material
ways from those of
the marketing
organization,
leading to
substandard work.

Copyright IT Governance Institute 2003

Comments/
Results/
W/P Ref.

[Link]/auditprograms

COBIT
Reference

52

Business
Objective

Risk

Supervision of the
vendor by the
marketing
organization may
be difficult (if the
vendor is
physically remote).
Vendor employees
may breach
organization
standards related
to information
security and
confidentiality.
The vendor could
cease operations,
with resultant
losses or costs
related to
replacement of
services.
Marketing projects
may not be
managed properly.
Technology Management
Organization
Organization
technology
technology
infrastructure and
infrastructure and
design should be
design may not be
fully supportive of
capable of
all beneficial
supporting
marketing
competitive
activities.
marketing
activities such as
Internet web pages
or call centers.

Control

Comments/
Results/
W/P Ref.

COBIT
Reference

used in the event the


vendor ceases
operations.
Confidentiality
agreements are signed by
all vendor employees.
Strong internal project
managers are used to
manage vendors.

Policies and guidelines


for investment in
marketing technology
are developed jointly by
marketing and the IT
organization.
The marketing channel
selection process
includes procedures to
address technology
requirements, and other
competitive marketing
activities are
incorporated into the
analysis.

Copyright IT Governance Institute 2003

[Link]/auditprograms

PO2
AI2

53

Business
Objective

Risk

Implementation of
the technology
may fail. This may
be attributable to a
number of reasons,
including lack of
integration skill,
lack of user
involvement in the
implementation
project,
inappropriate
systems
architecture and
others.
Users may fail to
accept the new
system, in most
cases, because user
requirements were
not captured and
integrated into the
design properly.
Technology may
become obsolete,
due to rapid
change.
Benefits may not
be realized or may
be substantially
less than expected.
Legal and Regulatory
Marketing
Consumers
campaigns and
purchasing
literature meet
products based on
legal and
false or misleading
regulatory
claims may be able
restrictions.
to sue for damages
and regulatory
agencies may
intervene to stop
practices regarded
as misleading to
consumers.
Trademark
development may
infringe on the
Marketing
technology
implementations
are successful.

Control

Comments/
Results/
W/P Ref.

COBIT
Reference

Careful selection is made


of integrators,
consultants and software
vendors with due
attention to alignment of
vendor capabilities and
project requirements
A structured systems
integration methodology
is used to minimize risk
of project failure or
underperformance
Long-term technology
architecture is deployed
to manage the impact of
technological change
Cost-benefit analysis in
technology investment
planning is
systematically deployed,
with postimplementation variance
analysis

AI1
AI3
PO1
PO5

A consistent review by
legal counsel of
marketing policies for
legal and regulatory
compliance, false
advertising, new
trademarks (trademark
infringement), customer
communications, etc., is
performed.
Time for legal review is
designed into an end-toend marketing process.
Proactive legal review is
exercised in the

PO8

Copyright IT Governance Institute 2003

[Link]/auditprograms

54

Business
Objective

Risk

Control

property rights of
other
organizations.
Materials similar
to another
organizations may
confuse
consumers, which
could lead to
litigation and
damages.
Adverse court
decisions related to
an organizations
trademarks and
materials may
require complete
rebranding and
repositioning, with
a total loss of the
organizations
initial marketing
investment.
Substantial cost
overruns related to
discarded print
runs, overtime,
vendor rush fees
and related costs
may be an issue.
Competition and
antitrust concerns
may be an issue.

Comments/
Results/
W/P Ref.

COBIT
Reference

development of
marketing materials, to
remove the task from the
project critical path.

Consumer Privacy

Copyright IT Governance Institute 2003

[Link]/auditprograms

55

Business
Objective

Risk

Control

Comments/
Results/
W/P Ref.

Marketers that
Privacy policies and
do not comply
procedures should be
with privacy
implemented and include
laws and
areas such as unsolicited
regulations may
customer contact and
increase the risk
disclosure of customer
of litigation,
information.
damages and
Cultural differences
adverse impacts
between countries are
to operations due
considered.
to regulatory
Marketers must establish
injunctions.
clear policy guidelines
for unsolicited messages,
which should include
classification of
messages by type and
channel, policy
regarding message
frequency, and
provisions for customer
opt-in and opt-out.
A policy regarding
message type or class
enables organizations to
differentiate policy
according to the purpose
and intent of the
message.
For additional privacy risks and controls, refer to the privacy work program, 12. Privacy.
Fraud and Unlawful Conversion
Fraud and unlawful Trade promotions, Basic risk management
conversion are
cash rebates,
controls, such as dual
prevented.
coupons,
approval, separation of
sweepstakes,
duties and independent
loyalty programs
audit, are a part of the
and other practices
marketing process where
may not comply
significant payments are
with fraud and
made to other parties.
unlawful
Incentive promotions
conversion
designed to reward
regulations
customers for specific
Misuse and abuse
behavior, such as making
of marketing funds
a purchase, are designed
may be an issue.
with controls to ensure
that reward payments are
Fraud may be an
earned and claimants are
issue
qualified to earn the
Compliance with
privacy laws and
regulations is
practiced.

Copyright IT Governance Institute 2003

[Link]/auditprograms

COBIT
Reference
PO8
M3
AI1
AI4

PO4
DS5
DS11

56

Business
Objective

Risk

Control

Organizations that
do not ensure that
benefit claims are
supported by proof
of eligibility risk
spending program
funds in a manner
that does not
effectively
influence
consumer
behavior.

incentive.
Proof of purchase is
required for
disbursement.
Aggregate claims are
matched to sales.
Analysis of claims
incidence by channel,
vendor, sales rep and
other key dimensions
can reveal a
disproportionate
incidence of claims
meriting further
investigation
Claims are checked
randomly, to validate
that claims are properly
earned and documented
Machine procedures are
used for random printing
and insertion of winning
tickets or coupons. In the
absence of machine
procedures, control over
winning tickets should
be based on dual
approval, employee
rotation and separation
of duties.
Security printing and
paper may be used to
reduce fraudulent
duplication of winning
tickets.
Mailing lists are seeded
with names supplied by
an independent listmonitoring agency, so
that the agency can track
the incidence of
communications to the
seed list by source, and
report findings to the list
owner.

Comments/
Results/
W/P Ref.

COBIT
Reference

Marketing Channel Management

Copyright IT Governance Institute 2003

[Link]/auditprograms

57

Business
Objective

Risk

Control

Comments/
Results/
W/P Ref.

COBIT
Reference

DS11
Communications Procedures are clearly
DS13
and offerings
defined and followed to
may not be
ensure that a market
reaching the
channel will link
target customers
customers to products
through the
appropriately.
appropriate
Communications and
channels,
offerings are sent to
resulting in
customers based on their
inefficient
preferences. For
marketing costs
example, a customer
and reach.
who prefers direct e-mail
promotions may only
want to receive e-mail
promotions and therefore
other channels may not
be effective (i.e.,
telesales, TV).
Marketing channel Marketing
AI1
Procedures are put in
analysis is
channel data
place to review
complete.
may be
marketing channel
incomplete,
information to ensure
resulting in an
that it is complete.
inaccurate
picture of
channel
effectiveness.
To further address channel management risks, refer to work program 6. Channel Management and
Integration Risk.
Marketing Literature Development and Fulfillment
Marketing
channels are
selected to align
the right customers
with the right
products.

Copyright IT Governance Institute 2003

[Link]/auditprograms

58

Business
Objective

Risk

Marketing
information and
content are
accurate.

Literature
requirements and
needs are defined
and addressed
completely.

Only authorized
changes to
literature are made.

Control

Comments/
Results/
W/P Ref.

Marketing
Marketing information is
content may be
verified for accuracy
inaccurate, or
prior to releasing the
contain false or
marketing literature and
misleading
communication to the
claims (e.g.,
customer.
claims
Management reviews
inconsistent with
marketing content to
product design
ensure that the marketing
or performance).
claims can be met (e.g.
product promises,
product availability, etc.)
Marketing content
complies with laws,
regulations and
organization policies on
business ethics, codes of
conduct and conflict of
interest to prevent
damage to the
organization's reputation.
Literature
Formal procedures exist
requirements
for gathering and
may not be
assessing literature
defined
requirements.
completely,
Marketing personnel
resulting in
ensure that all beneficial
ineffective
types of literature and
literature.
literature content are
developed and available
for products and
services.
Unauthorized
The ability to change
changes may be
printed or web-based
made to printed
literature is limited to
or web-based
appropriate personnel
literature.
and approved properly.
Version control
procedures are in place
for controlling updates to
literature files.

Copyright IT Governance Institute 2003

[Link]/auditprograms

COBIT
Reference
M1
PO8

AI4

DS5
DS11

59

Business
Objective

Risk

Control

Literature is
distributed
effectively and
properly tracked.

Requested
literature may
not be
distributed
properly to
customers or
prospects.

Customer feedback
is considered
during literature
design and update.

Literature is up to
date. Old literature
is destroyed on a
timely basis.

Customer
feedback may
not be
incorporated into
literature
updates or
development of
new literature,
resulting in lost
opportunities to
improve
literature quality.
Documents that
are outdated may
not be identified
and destroyed in
a timely manner.

Copyright IT Governance Institute 2003

Comments/
Results/
W/P Ref.

COBIT
Reference

The organization
utilizes collateral
management
technology or
sufficient manual
processes to fill
literature requests
from customers and
prospects accurately
and in a timely
manner.
Customer feedback is
reviewed formally and
incorporated into new
literature during
literature development
and update processes.

DS11

Literature preparation
personnel monitor
documents on an
ongoing basis to
ensure outdated
literature is identified
and removed from
circulation.

M1

[Link]/auditprograms

PO11

60

3.

Customer Interaction Center and Field Service Risks Work


Program

The following work program will help manage customer interaction centers and field service
risks. For detailed work programs on the telecommunication equipment within interaction
centers, see work program 7, Telecommunication Infrastructure. Any person auditing,
reviewing or advising on controls in a CRM project will need to select tasks from the
work program and to consider the key issues raised in the IT Governance Institute
publication Risks of Customer Relationship Management as part of their preparation. The
work program should not be used as a checklist of best practice, but as a selection of
examples of good practice that can be applied. By using the work programs blindly, there
is a risk of losing the confidence of the auditee and even of missing the largest risks in the
project, due to the peculiarities of each project. Therefore, work programs should be used
as guidance, and specific knowledge of the organization and risks should be added to it.
Note: A business objective may be listed more than once because it has multiple risks and
corresponding control objectives. Note disclaimer.
Business
Objective

Risk

Control

Comments/
Results/
W/P Ref.

Customer Interaction CenterInbound Request Processes


Customers calls
Inbound
Telephone trunks are
are always
telephone calls
actively monitored to
received by the
may not reach
ensure they are not
interaction center.
the interaction
busy or out of order.
center as a result
of inactive
phone line
trunks.
Customer calls are
Telephone calls
Initial implementation
routed to the
may be
and all changes made
correct extension
inappropriately
to the automatic call
or interactive voice
routed resulting
distributor (ACD) are
response (IVR)
in dissatisfied
reviewed and tested
system.
and poorly
thoroughly.
served
customers.
The IVR provides
Customers may
All changes to the IVR
customers with an
be unable to
are thoroughly
easy-to-use means
determine how
reviewed and tested
of obtaining
to route their call
with end users to
information or
via the IVR
ensure the options and
routing their call to
system or are
menu path of the IVR
an appropriate
dissatisfied due
are clearly understood.
individual.
to the
complexity of
options
available.

Copyright IT Governance Institute 2003

[Link]/auditprograms

COBIT
Reference
DS3

AI5

AI6

61

Business
Objective

Risk

Control

The interaction
center provides
customers a
positive and
reinforcing
experience when
using telephone
self-service.

Customer calls
may be dropped
once the call
enters the
IVR/CTI systems.

Customers use IVR


self-service to
answer common
questions and
alleviate demand
for live interaction
center personnel.

Network connections
between the CTI or IVR
systems and the backend database system
have sufficient
bandwidth to
accommodate customer
information requests.
Network connections
between the CTI or IVR
systems and the backend database are
monitored.
An alternative IVR
system is made available
in the event the back-end
database is unavailable
to ensure the customers
time is not wasted.
The IVR is easy to use
for requesting
information, such as
account information, and
manual intervention is
minimized for simple
self-service questions.

Customers may
zero out of the
IVR rather than
use automated
assistance because
the IVR is
confusing or
difficult to use.
Callers may
Callers are updated
become impatient
periodically with the
and dissatisfied
expected wait time while
with the
on hold.
organization due
Callers are provided
to inability to
alternative methods of
determine length
communicating with the
of hold time or due
organization, such as the
to excessive hold
web site, nonpeak hours,
times.
etc.

Callers waiting in
the queue are given
information on
expected wait time.

Copyright IT Governance Institute 2003

Comments/
Results/
W/P Ref.

[Link]/auditprograms

COBIT
Reference
AI3
DS4
DS13

DS3

DS3

62

Business
Objective

Risk

Web form/e-mail
requests are routed
to the correct
personnel for
response.

Web form/e-mails
are easily
integrated and read
by e-mail
management
software.

Customer requests
are immediately
acknowledged,
enhancing
customers
experience and
perception of using
chat for service.

Customer requests
are routed within
the interaction
center based on
nature of request
and workload.

Control

Comments/
Results/
W/P Ref.

Web form e-mail Web form and e-mail


requests may be
requests are routed to the
misrouted
correct mailboxes using
resulting in
e-mail management
customer
software, also called
dissatisfaction
automatic e-mail
because of
distributors (AEDs).
response delays. Periodic tests of web
service are conducted
and e-mails are sent to
customers to ensure
correct routing.
Web form/e Users are encouraged to
mails requests
use a web form on the
may not be
organizations web site
routed
when sending web
efficiently or
service/e-mail requests.
effectively,
Therefore, the user
resulting in poor
selects a category for
response times
their e-mail from a
to customer
predefined list of
requests.
choices, allowing the
request to be more
efficiently routed,
understood and
answered by customer
service personnel.
Customer
Customer requests are
requests may not
auto answered, when
be
feasible.
acknowledged in Acknowledgments or
a timely manner.
confirmations are sent to
customers to indicate
that their request was
received and the
expected response time.
Customer
Customer requests are
requests may be
distributed evenly
routed to
among customer service
overloaded
personnel.
CSRs.

Copyright IT Governance Institute 2003

[Link]/auditprograms

COBIT
Reference
DS13

DS11
DS13

DS1
DS13
M1

DS13

63

Business
Objective

Risk

Customer
information is
input completely
and accurately.

Customer
information is
input completely
and accurately.

Only authorized
personnel create
new customer
records.

Requests are
routed
appropriately and
reports on requests
are accurate.

Control

Comments/
Results/
W/P Ref.

Customer master CSRs perform a


data may be
thorough search for the
duplicated,
customer in the database
resulting in an
prior to creating a new
incomplete
customer. For example,
record of a
they search by name,
customers
phone number or e-mail.
history.
The system
automatically flags
potential duplicate
customer records during
entry.
Customer
CSRs are trained
information may
appropriately on data
be entered
entry requirements and
inconsistently or
the intended uses for
incompletely.
fields.
Key fields are required
to be entered.
When possible, pick lists
and field masks are used
to validate and secure
data entry (i.e., pick lists
for titles, preferences,
states, field masks for
phone numbers, ID
numbers and credit card
numbers).
Unapproved
Access to maintain
customer records
customer information
maintenance
is restricted to the
may be
appropriate personnel.
performed.
Requests may be Contact center
categorized
personnel (or
inconsistently,
customers via web
resulting in
forms/e-mail) are
inaccurate
required to select a
routing and/or
request type from a
reporting.
pick list.

Copyright IT Governance Institute 2003

[Link]/auditprograms

COBIT
Reference
AI5
DS11

PO7
DS7
DS11

DS5
PO4

DS1

64

Business
Objective

Risk

Control

Requests are
routed
appropriately and
reports on requests
are accurate.

CSRs are trained on the


proper usage of the
different request types.
Formal procedures exist
for processing requests.

Adequate
information is
captured on the
service request.

Service requests
are prioritized
appropriately, so
that they are
addressed in an
appropriate
manner.

Web form and email requests are


seamlessly
integrated into the
call center service
request application,
allowing a
complete picture of
the customers
service history.

Requests may be
categorized
inconsistently,
resulting in
untimely
resolution and
inaccurate
reporting.
Insufficient
detail as to
nature of the
request may be
captured in
initial contact
with customer.

Comments/
Results/
W/P Ref.

CSRs are trained


appropriately on the
importance of
understanding and
documenting the request
with sufficient detail.
A description field is
required when
documenting a request.
Service requests CSRs are trained
may be
appropriately on the
prioritized
meaning of service
inappropriately.
request severity codes.
The severity field is
required and given an
appropriate default.
Management monitors
the number of
outstanding service
requests by severity to
help determine the
appropriate use of
severity codes.
Web form and e- Web form and e-mail
mail requests
requests are included as
may be stored
service requests in the
separately from
customers service
telephone
history.
service requests,
giving an
incomplete
picture of the
customers
service history.

Copyright IT Governance Institute 2003

[Link]/auditprograms

COBIT
Reference
DS13

PO7
DS7

PO7
DS7

DS11

65

Business
Objective

Risk

Control

Customer service
levels are
accurately reflected
in the system.

Customers
service levels
may not be
recorded
appropriately in
the system.

Customers are
provided
appropriate
service.

Customer
expectations for
the level of
service they will
receive may not
be managed
appropriately.

Access to changing and


assigning customer
service levels is
restricted appropriately.
Procedures exist to
ensure customer service
levels are input into the
system accurately and
completely.
CSRs are trained
adequately on the service
levels. For example,
initial training is aligned
with key customer
satisfiers and empowers
the worker to satisfy the
customer.
Customer service levels
are maintained in the
customer profile. For
example, service levels
may be as follows:
- Gold service24/7
support, onsite support
if needed, requests
addressed in four
hours. (US $20,000
every 6 months)
- Silver service24/7
support, no onsite
support, requests
addressed within 24
hours. (US $10,000
every 6 months)
- Bronze service12/5
support, no onsite
support, requests
addressed within 48
hours. (US$5,000
every 6 months)
All service levels expire
after a period of time if
not renewed.
CSRs manage
customers expectations
for the level of service
they will receive by

Copyright IT Governance Institute 2003

Comments/
Results/
W/P Ref.

[Link]/auditprograms

COBIT
Reference
DS5
DS7
AI5

DS1
DS7
DS13

66

Business
Objective

Service request
resolution
information is
captured.

Risk

The CSRs may


not provide
complete
descriptions of
how issues are
resolved.

Control

Comments/
Results/
W/P Ref.

communicating service
levels.
A report is processed
periodically to identify
customers without a
service level or with
service levels that do not
match their current
service level.
Appropriate action is
taken to update service
levels.
The request resolution
field is configured as
required to ensure proper
documentation.
Contact center managers
perform quality
assurance on closed
service requests to
ensure the resolution is
documented adequately
and the customers
request was
appropriately satisfied.
For example, senior
managers regularly listen
in on live or recorded
calls for each front-line
worker to ensure that the
resolution is accurate
and documented
uniformly and
completely.

Copyright IT Governance Institute 2003

[Link]/auditprograms

COBIT
Reference

PO11
DS9

67

Business
Objective

Risk

Control

Comprehensive
documentation
standards exist.

Inadequate or
inconsistent
documentation
standards may
lead to a
difficulty in
retrieving
solutions to
problems.

Requests are
closed
appropriately.

Requests may
not be closed
properly;
therefore, the
requests remain
open on the
system and
continue to be
worked on by
other employees.

Copyright IT Governance Institute 2003

Comments/
Results/
W/P Ref.

Documentation
standards are defined
to ensure
comprehensive
documentation of the
resolution. Standards
include guidelines for
referencing related case
analysis, diagnostic
Q&A, decision trees,
search engines for
repositories of
technical documents,
FAQs and known
customer service
solutions, etc.
Procedures are defined
on how and when to
appropriately close a
request.
Monitoring controls
exist to monitor open
requests to ensure that
they are closed in a
timely manner.

[Link]/auditprograms

COBIT
Reference
PO11
AI4

AI4
M1

68

Business
Objective

Risk

Comments/
Results/
W/P Ref.

Customers are
surveyed periodically
to determine
satisfaction. The
surveys include
feedback on system
accessibility, front-line
professionalism and
overall satisfaction
with the way their calls
are handled.
When customers email address is
available, they are emailed a confirmation
that their request has
been closed and the
customers have the
ability to provide
feedback. Mail
confirmation is sent, if
e-mail is unavailable.
Customer feedback Customer
Management notifies
is quantified and
service may not
appropriate individuals
analyzed on a
be effective.
that a complaint was
proactive basis.
filed for their area of
responsibility.
Management and the
responsible individual
determine and
implement an action
plan to avoid the noted
complaint in the future.
The action plans are
documented and
monitored.
Services address
The needs of
Customer focus groups
the needs of all
specific
are used to determine
groups within the
customers may
the needs of specific
customer base.
not be met.
customer groups and
how well those needs
are being met.
Customer Interaction CenterOut Bound Processes
Customers are
satisfied with the
request resolution.

Control

Request
resolutions may
be closed
without the
customer being
satisfied with the
response.

Copyright IT Governance Institute 2003

[Link]/auditprograms

COBIT
Reference
AI4
DS1
DS8

M1

DS1

69

Business
Objective

Risk

Control

All customers and


all potential
customers are
contacted.

The system
automatically
reschedules calls for
busy signals and noanswers.

CSR time is used


effectively.

CSRs effectively
communicate the
organizations
message.

The out bound


dialing system
may not
effectively
switch between
lists and
campaigns nor
reschedule
callbacks for
busy signals and
no-answers.
CSR time may
be wasted due to
inefficient call
scheduling of
customers.

Comments/
Results/
W/P Ref.

The system keeps a


record of call attempts to
be certain that each
attempt is at a different
time during the day and
on different days.
CSRs may not
Scripting is used to
be aware of or
automatically allow for
do not
data to be entered and
effectively
calculations to be
communicate the
performed in the script.
proper campaign Future calls and action
messages.
items are routed to the
correct agent based on
the answers received.
For example, effective
workstation
configurations identify
the probable incoming
caller by automatically
linking the callers
phone number and
account history, and
instantly placing this
information on the frontline workers computer
screen.

Copyright IT Governance Institute 2003

[Link]/auditprograms

COBIT
Reference
AI1
AI2

AI1
AI2

AI1
AI2

70

Business
Objective

Risk

Customer data are


accurate and
reliable.

Customer data are


accurate and
reliable.

Customer data are


accurate and
reliable.

Field Service Delivery


Requests are

resolved in a
timely manner.

Requests are
resolved in a
timely manner.

Control

Comments/
Results/
W/P Ref.

COBIT
Reference

Customer master CSRs perform a


thorough search for the
data may be
customer in the database
duplicated,
by name, phone or eresulting in an
mail prior to creating a
incomplete
new customer.
record of the

The system
customers
history.
automatically flags
potential duplicate
customer records during
entry.
Customer
Pick lists and field
information may
masks are used to
be entered
validate data entry (i.e.,
inconsistently or
pick lists for titles,
incompletely.
preferences, states, field
masks for phone
numbers, ID numbers
and credit card
numbers).
Key fields are required
to be entered.
Unapproved
Access to add new
customer records
customer information is
may be created.
restricted to appropriate
personnel.

DS9

Field service
Assignment rules are
cases may not be
designed appropriately
correctly routed
to consider geographical
to the field, e.g.,
location, employee
an incorrect field
expertise and availability
office.
when proposing
potential field service
personnel.
Procedures exist to
reroute incorrect
routings to another
office.
Field service
Adequate escalation
requests may be
procedures route cases to
assigned to
a higher level of
unavailable or
management if the cases
overworked
are not addressed in a
personnel.
specified period of time.

PO4
AI4
DS10

Copyright IT Governance Institute 2003

[Link]/auditprograms

DS11

DS11

DS5

AI4
DS10

71

Business
Objective

Risk

Requests are
resolved in a
timely manner.

Requests are
resolved in a
timely manner.

Reliable and
meaningful
information is
available for field
service request
resolution times.

Control

Comments/
Results/
W/P Ref.

Past solutions to Field service personnel


similar problems
have tools available to
may not be
them in the field to help
easily retrievable
troubleshoot problems.
or available to
A solutions database is
field service
maintained to assist field
personnel while
service personnel in
they are in the
troubleshooting
field.
problems.
Field service personnel
can access the solutions
database via field service
computers.
Subject matter
Subject matter experts
expertise may
are available to find
not be available
solutions to new and
for complex or
complex problems as
new problems,
they arise.
resulting in
Customer self-service
delayed
can dramatically
resolution time.
improve control. A major
European electronic
components distributor,
for example, has
achieved 10 percent of
its sales through its B2B
web site. At the same
time, technical support
documentation for its
products is on the web
site. More than 90
percent of all requests
for technical information
are now performed
electronically rather than
using the call center.
Performance
Field service personnel
metrics may not
understand the
be calculated
importance of and
accurately due to
procedures for closing a
inconsistent
completed request.
request closing
Field service personnel
procedures.
are trained adequately on
case closing procedures.

Copyright IT Governance Institute 2003

[Link]/auditprograms

COBIT
Reference
PO4
AI1
DS5
DS!0

DS8

DS7
DS11

72

Business
Objective

Risk

Requests are
resolved in a
timely manner.

Customers are
satisfied with field
service request
resolutions.

Feedback is
utilized to provide
enhanced
solutions.

Time and expense


associated with
field service calls
are tracked.

Control

Comments/
Results/
W/P Ref.

Proactive steps are taken


to monitor spare and
replacement parts
inventory.
Adequate safety stocks
are kept.
If the part is not
available, the customer
is made aware and
approximate wait-time is
indicated.
Customers may Customer feedback
not be satisfied
surveys are sent to all
completely with
customers, including
field service
requests resolved by
work.
field sales personnel.
Customers are surveyed
to determine their
satisfaction with the field
service technical
assistance.
Ineffective
Customer feedback
solutions may be
regarding specific field
repeated for the
service solutions is fed
same problem.
into the solutions
knowledge database.
Field service personnel
can propose amendments
or changes to solutions.
Subject matter experts
review these
amendments and
changes and incorporate
them as appropriate.
Time and
Time and expense
expenses may
procedures are defined
not be
and enforced.
documented in
Field service personnel
the system;
must submit time and
therefore,
expenses periodically to
services received
receive a paycheck.
may not be
To be reimbursable,
billed (e.g., loss
expenses must be
of revenue).
submitted prior to the
final client billing.
Spare or
replacement
parts may not be
available in the
time frame the
customer
requires to
resolve the
problem.

Copyright IT Governance Institute 2003

[Link]/auditprograms

COBIT
Reference
DS9

DS8
DS10

DS8

PO5
DS6

73

Business
Objective

Risk

Control

Customers are
appropriately
charged or not
charged for field
service calls.

The customer service,


billing and warranty
systems are integrated to
help ensure appropriate
customer billings.

DS6

Field service
inventories are
protected and
monitored
adequately.

DS9
DS11

Field service
performance is
understood and
measurable.

Performance
metrics may not
be calculated
due to
inconsistent
request closing
procedures.

Quality levels are


monitored.

Quality levels
may not be met,
resulting in poor
customer
satisfaction.

Parts used must be


recorded prior to closing
the case ticket.
Periodic physical
inventories of field
service vehicles/
locations are taken.
Field service personnel
are held responsible and
accountable for all
service parts in their
possession.
Field service personnel
understand the
importance of and
procedures for closing a
completed request.
Field service personnel
are trained adequately on
case closing procedures.
Contact center managers
perform quality
assurance on closed
service requests to
ensure the resolution is
documented adequately
and it appears that the
customers request was
satisfied appropriately.

Lack of
appropriate
warranty-related
information
might result in
customers being
charged
inappropriately
or not charged
for the cost of
the repairs.
Field service
inventories may
be overstated as
a result of poor
parts
management.

Comments/
Results/
W/P Ref.

COBIT
Reference

AI4
DS7
PO11

PO10
PO11

Service Spares Logistics

Copyright IT Governance Institute 2003

[Link]/auditprograms

74

Business
Objective

Risk

Spare parts are


properly managed.

The right parts


Formal inventory
may not be
management procedures
available for
is implemented to
service personnel;
control the inventory of
therefore, they will
spare parts to ensure that
not be able to fix
all parts are accounted
products or resolve
for and are available to
customer
the field service
problems.
representatives when
needed to resolve
Spare parts may be
customer problems or fix
stolen, misplaced,
products.
lost, etc.
Internal
All internal,
documentation
noncustomer-facing,
may be
information is marked
distributed
clearly and maintained in
inappropriately
a separate folder from
to the public.
information designed for
distribution to
customers.
Access to all sensitive
internal documentation
is restricted
appropriately through an
approval process.
Past solutions to Field service personnel
similar problems
have tools available to
may not be
them in the field to help
easily retrievable
troubleshoot problems.
or available to
A solutions database is
field service
maintained to assist field
personnel while
service personnel in
they are in the
troubleshooting
field.
problems.
Field service personnel
can access the solutions
database via field service
computers.

Proprietary and
confidential
information is
properly restricted.

Solution
information is upto-date and easily
retrievable.

Control

Copyright IT Governance Institute 2003

Comments/
Results/
W/P Ref.

[Link]/auditprograms

COBIT
Reference
PO6
AI4

DS5
DS11

DS5
DS9

75

Business
Objective

Risk

Solution
information is upto-date and easily
retrievable.

Solution
information is up
to-date and easily
retrievable.

Solution
information is upto-date and easily
retrievable.

Solution
information is upto-date and easily
retrievable.

Control

Comments/
Results/
W/P Ref.

Ineffective
Customer feedback
solutions may be
regarding specific field
repeated for the
service solutions is fed
same problem.
into the solutions
knowledge database.
Field service personnel
also can propose
amendments or changes
to solutions.
Subject matter experts
review these
amendments and
changes and incorporate
them as appropriate.
The CSR may not The request resolution
provide a
field is configured as
description of how
required to ensure proper
the issue was
documentation.
resolved.
Management monitors
An inability to
solution information and
capture important
issue resolutions.
request resolution
information may
exist.
Inadequate or
Documentation
inconsistent
standards are defined to
documentation
ensure comprehensive
standards may lead
documentation of the
to a difficulty in
resolution. Standards
retrieving
include guidelines for
solutions to
referencing related case
problems.
analysis, diagnostic
Q&A, decision trees,
search engines for
repositories of technical
documents, FAQs and
known customer service
solutions, etc.
New solutions
CSRs are encouraged to
may not be
propose new solutions in
documented as
the solutions database
needed, resulting
and are recognized for
in a lack of
their effort.
knowledge
sharing between
CSRs.

Copyright IT Governance Institute 2003

[Link]/auditprograms

COBIT
Reference
DS11
DS13

DS9
M1

AI1
PO11

DS11

76

Business
Objective

Risk

Control

Solution
information is upto-date and easily
retrievable.

DS13

Solution
information is upto-date and easily
retrievable.

All solutions are


reviewed by technical
experts prior to approval
for general use at the
interaction center.
Templates or standards
govern the form of the
solutions documentation.

Responsibility and
accountability for
creating and maintaining
product and service
information are defined.
Product and service
information is stored in
an easily accessible and
searchable format.
CSRs may provide Return instructions are
customers
available online to the
inaccurate
CSRs.
information.
CSRs are trained
Customers may
appropriately on return
not follow return
policies and procedures.
and replacement
procedures
therefore their
returns are
rejected.

DS3
DS13

Solution
information is upto-date and easily
retrievable.

Policies and
procedures for
returns and
replacements are
followed.

Ineffective
solutions may be
repeated for the
same problem.

Problem
resolution data
may be
maintained
inconsistently.
Employees may
not be able to
extract knowledge
solutions in an
efficient manner.

Comments/
Results/
W/P Ref.

COBIT
Reference

PO1
PO3

AI4
DS7

People Management

Copyright IT Governance Institute 2003

[Link]/auditprograms

77

Business
Objective

Risk

Customers are
satisfied with the
level of service.

Customer data are


accurate and
reliable.

Customer requests
are responded to
efficiently.

Customer requests
are responded to
efficiently.

Control

Comments/
Results/
W/P Ref.

Initial and periodic


training is conducted to
educate CSRs on
standard and timely
literature and grouping
of literature materials.
For example, training
hours are allotted for
every front-line worker
(ranging from 90-150
hours) and are factored
into the forecasting and
scheduling process, at
least one year in
advance.
Customer request
scenarios are provided to
assist in ensuring all
applicable literature is
provided during the
initial request.
Customer
CSRs are trained
information may
appropriately on data
be entered
entry requirements and
inconsistently.
the intended uses for
fields.
Requests may be CSRs are trained
categorized
appropriately on the
inconsistently,
proper response to the
resulting in
different request types.
untimely
resolution and
inaccurate
reporting.
CSRs may not
CSRs are trained on the
categorize
importance of using the
service requests
appropriate category for
consistently,
service requests and the
resulting in
meaning of each
inaccurate
category.
request analysis. The category field is
required.
Inexperienced
CSRs may
provide
inappropriate
and incomplete
literature to
customers.

Copyright IT Governance Institute 2003

[Link]/auditprograms

COBIT
Reference
PO7
DS7

DS7
DS11

DS7

DS1
DS7

78

Business
Objective

Risk

Control

CSRs are well


trained.

Training
initiatives may
be executed
poorly.

CSRs are well


trained.

Personnel may
not be trained to
meet customer
needs
effectively.

A dedicated training
group is an integral part
of a successful
interaction center
operation.
Technical training
programs are delivered
by experienced subjectmatter experts to ensure
the skill and knowledge
transfer of information is
current and relevant.
Training programs are
subject to a beta test or
pilot test to solicit CSR
end-user feedback and
improve the training
program.
Formal training agendas
are prepared and
approved by
management.
Training curriculum
includes systems,
products, call types,
customer handling and
telephone skills.
CSRs are involved in
developing training
courses and management
approves course content.
Multiple training
methods are used,
including written tests,
telephone interviews and
role-playing to provide
comprehensive
scenarios.

Copyright IT Governance Institute 2003

Comments/
Results/
W/P Ref.

[Link]/auditprograms

COBIT
Reference
PO7
PO10
DS7

PO7
DS7
DS13

79

Business
Objective

Risk

Control

CSRs are well


trained.

Customer
service needs
and workloads
may not allow
sufficient time
for proper
training.

CSRs are well


trained.

Training may
not enhance
productivity.

Customers are
satisfied with the
service.

Customers may
be treated with
disrespect.

Customer requests
are responded to
efficiently.

Customers are
satisfied with the
service.

Customer requests
are responded to
efficiently.

Insufficient
detail as to the
nature of the
request may be
captured in
initial contact
with customer.
Customer
expectations for
the level of
service they will
receive may not
be managed
appropriately.
Service requests
may be routed to
inappropriate
individuals,
delaying
resolution.

Comments/
Results/
W/P Ref.

COBIT
Reference

Training hours are


allotted for every frontline CSR (ranging
from 80-160 hours per
employee) and are
factored into the
forecasting and
scheduling process at
least one year in
advance.
Training effectiveness
is verified through selfassessments, service
observations, one-onone coaching, team
interactions and
metrics.
Front-line CSRs are
trained to recognize
and adapt to different
caller personality
types.
CSRs are trained
appropriately on the
importance of
describing the request
in detail.

DS1
DS7

CSRs are trained


adequately on the
meaning of different
service levels.

PO7
DS1

CSRs are trained


adequately and
provided information
regarding to whom to
route calls depending
on the type of inquiry,
in the event they
receive a call they
cannot answer.

DS13

Copyright IT Governance Institute 2003

[Link]/auditprograms

AI4
AI5
DS7

DS10
DS13

DS7

80

Business
Objective

Risk

Control

Customer service
representatives are
well trained.

Personnel may
not be trained to
manage
assignment or
workflow rules.
Contact center
personnel may
be inefficient
due to a poor
physical
environment.

Personnel are trained


appropriately in
managing assignment
and workflow rules.

PO7

There is a natural source


of lighting, artificial
direct and indirect
lighting to reduce glare.
Customer care personnel
have facilities for rest
and recreation.
The layout supports ease
of operations and an
ability to deal with calls
effectively, e.g., hot
desk, printer locations,
etc.
The noise level is
controlled and the
general noise level (e.g.,
background noise) is
adequate. Mitigating
methods are white noise,
sound absorbing
materials, baffling
materials, etc.
Proper ventilation exists
to provide ambient
temperature and proper
circulation of air, e.g., no
hot spots and cold spots.
Ceiling height provides a
sense of openness,
visibility, etc.
The interaction center is
clean and well
maintained.
Support for offices
includes office facilities,
e.g., printers, phone
headsets, photocopiers,
etc.

PO8
DS12

Physical conditions
are sufficient to
allow interaction
center personnel to
operate effectively.

Copyright IT Governance Institute 2003

Comments/
Results/
W/P Ref.

[Link]/auditprograms

COBIT
Reference

81

Business
Objective

Risk

Workloads are
managed
effectively to
ensure high-quality
customer service.

Workloads are
effectively
managed to ensure
high-quality
customer service
while minimizing
costs.

Workloads are
managed
effectively to
ensure high-quality
customer service.

Control

Comments/
Results/
W/P Ref.

The interaction
Workload is forecast 12center may be
18 months in the future
inefficient and in
and is adjusted quarterly,
constant
monthly and weekly
response mode.
based upon current
information.
Attrition and training are
factored in the forecast
equation.
Forecasting accuracy is
tracked weekly and
monthly, in hopes of
achieving accuracy
within a +/- 2 percent
range.
In addition, periods of
excellent service levels,
not poor service, are
leveraged for goal
setting.
Workflow management
and work queue
management are used to
monitor agents
workload and to take
action to avoid backlogs
or bottlenecks from
developing.
All resources
Workload balance
may not be
efficiency strategies
leveraged for
include:
efficiency.
- Site consolidations
- Workload
balancing between
multiple interaction
centers
- Staggered shifts by
15-minute intervals
- Availability of parttime workers.
CSRs may
Contact center
become
managers monitor
overburdened
workloads of CSRs
and unable to
and take action to
answer customer
reassign requests to
requests in a
smooth the workload.
timely manner.

Copyright IT Governance Institute 2003

[Link]/auditprograms

COBIT
Reference
DS1
DS3
DS7
AI4

DS3

DS1
DS3

82

Business
Objective

Risk

Workloads are
managed
effectively to
ensure high-quality
customer service.

Workloads are
managed
effectively to
ensure high-quality
customer service.

Workloads are
managed
effectively to
ensure high-quality
customer service.

Workloads are
managed
effectively to
ensure high-quality
customer service.
The contact center
is managed
efficiently to
ensure high-quality
customer service
while minimizing
costs.

Control

Comments/
Results/
W/P Ref.

Requests may be Assignment managers


assigned to over
are used to smooth the
burdened
workload among
employees,
employees and to help
resulting in
ensure the most
delays in
qualified person is
resolving service
working on the
requests.
problem.
Service requests CSRs are aware of
may not be
overall workloads in the
resolved in a
interaction center and
timely manner
can therefore manage
due to lack of
customer expectations
appropriate
on resolution time.
resources.
Contact center
management monitor
workloads over time and
anticipate periods of
increased demand for
service.
Service requests
Employees are marked
may be routed to
as unavailable in their
unavailable
personnel profile while
individuals,
on vacation or
delaying
otherwise away from
resolution.
the office so requests
will not be routed to
them.
Requests may be Customer requests are
routed to
distributed evenly
overloaded
among customer
CSRs.
service personnel.
Contact center
efficiency may
decline due to
inadequately
trained
personnel or new
customer
problems.

Copyright IT Governance Institute 2003

Contact center
interaction times are
tracked, monitored and
reviewed to help
ensure interaction
center efficiency.

[Link]/auditprograms

COBIT
Reference
DS3

DS3

DS3

DS1

DS1
DS3

83

Business
Objective

Risk

Control

The contact center


is managed
efficiently to
ensure high-quality
customer service
while minimizing
costs.

Feedback may
not be compiled
to implement
continuous
improvement of
organization
practices.

The contact center


is managed
efficiently to
ensure high-quality
customer service
while minimizing
costs.

Contact center
management
may not analyze
commonality
among service
requests,
forgoing any
potential
efficiency gains
from
incorporating
common service
request
information.

Personnel
monitoring may
be perceived
negatively by
personnel.

The contact center


is managed
efficiently to
ensure high-quality
customer service
while minimizing
costs.

Copyright IT Governance Institute 2003

Comments/
Results/
W/P Ref.

Customer feedback is
summarized and used
to make decisions
regarding employee
incentives, policy and
procedure, resource
allocation and skill
needs.
Common service
requests are reported
in overall interaction
center statistical
information.
Common service
request resolution
information is
incorporated into the
web site FAQ
information and also in
the IVR.
CSRs are made aware
periodically of the
most common service
requests, to ensure
they are able to
efficiently answer
customer inquiries.
Policies state that the
primary purpose of
monitoring is to
identify individual
training needs as part
of an organizationwide
continuous
improvement effort.

[Link]/auditprograms

COBIT
Reference
DS3

DS1

DS1

84

Business
Objective

Risk

Control

The contact center


is managed
efficiently to
ensure high-quality
customer service
while minimizing
costs.

Key decisionmakers may not


be aligned with
day-to-day
operations.

DS1
DS3

The contact center


is managed
efficiently to
ensure high-quality
customer service
while minimizing
costs.

Front-line
personnel
satisfaction may
not be valued
and
incorporated.

The contact center


is managed
efficiently to
ensure high-quality
customer service
while minimizing
costs.
The contact center
is managed
efficiently to
ensure high-quality
customer service
while minimizing
costs.

Customer
problems may
not be handled
efficiently.

Senior managers
regularly listen in on live
calls to stay in touch
with the customer and
with the effectiveness of
their interaction center
operations. For example,
team leaders typically
should monitor five to
ten calls per front-line
personnel per month.
Both silent/remote and
side-by-side monitoring
are used.
Team leaders shadow
front-line personnel for a
day to better understand
call operations, job
procedures, working
conditions and customer
expectations.
Front-line personnel
satisfaction is measured
as routinely as customer
satisfaction.
Comprehensive annual
surveys are compared to
specifically targeted
weekly and monthly
surveys to ensure
continuous
improvement.
Tracking of methods
utilized for problem
resolution is performed
to analyze effective vs.
ineffective methods.

Employee skills
may not be
updated
regularly in the
system.

Employee skills are


reviewed periodically
and adjusted as those
skills change.

PO7

Copyright IT Governance Institute 2003

Comments/
Results/
W/P Ref.

[Link]/auditprograms

COBIT
Reference

DS1
DS2

DS10

85

Business
Objective

Risk

Control

The contact center


is managed
efficiently to
ensure high-quality
customer service
while minimizing
costs.

Requests
(including web
form and e-mail
requests) may
not be assigned
to appropriate
personnel in a
timely manner,
resulting in
customer
dissatisfaction.

Contact center
management monitors
outstanding requests
(including web form and
e-mail requests) to
ensure service requests
are addressed in a timely
manner.
Management monitors
average resolution time
for service requests.

DS1
M1

Outsourcing
arrangements
may not meet
expectations
resulting in poor
customer
service,
unresolved
customer needs,
etc.

Service level agreements


define the
responsibilities and
details of the expected
service levels to be
provided by the
outsourcing
organization, as well as
metrics to be achieved
by the outsourcer. The
service level agreement
includes required
processing levels,
security, monitoring,
contingency
requirements and other
stipulations, as required.
Management monitors
performance of the
outsourced vendor to
ensure that key controls
are being performed. For
instance, a SAS 70
report, which describes
key processes and
controls in place at the
outsourcer, may be
available.

DS2
M1

M1
DS3
DS13

Outsourcing
Outsourcing
arrangements are
managed properly.

Management Analytics and Reporting


Calls analysis is
The interaction
performed to
center may not
monitor service
be performing at
levels and improve
an acceptable
performance.
service level.

Copyright IT Governance Institute 2003

Comments/
Results/
W/P Ref.

The following areas are


monitored, and if an
acceptable service
level is not met,
performance
improvement steps are

[Link]/auditprograms

COBIT
Reference

86

Business
Objective

Risk

Control

Comments/
Results/
W/P Ref.

COBIT
Reference

taken:
- Proportion of
callers to receive a
busy tone due to no
telecommunication
- Proportion of
callers to receive a
busy tone due to
operational policies
during the busy and
other hours
- Proportion of calls
that are abandoned
by department and
service line
- Length of time
customers have to
wait for an agent
when they are the
targets of an
outbound call (best
practice is zero and
acceptable
performance with
power dialer is 1
percent)
- The proportion of
average call
handling time to
talk time (best
practice is 95
percent or better)
- Proportion of
handling time to
information
system wait time
between screens,
for searches, etc .
(Best practice is
less than 5 percent
of contact time)
- Proportion of talk
time that is wasted
where the
customer or agent
is waiting or
something to
happen (best
practice allows 10

Copyright IT Governance Institute 2003

[Link]/auditprograms

87

Copyright IT Governance Institute 2003

[Link]/auditprograms

88

4.

Data Management Risks Work Program

The following work program will help manage data risks for customer relationship management.
Any person auditing, reviewing or advising on controls in a CRM project will need to select tasks
from the work program and to consider the key issues raised in the IT Governance Institute
publication Risks of Customer Relationship Management as part of their preparation. The work
program should not be used as a checklist of best practice, but as a selection of examples of good
practice that can be applied. By using the work programs blindly, there is a risk of losing the
confidence of the auditee and even of missing the largest risks in the project, due to the
peculiarities of each project. Therefore, work programs should be used as guidance and specific
knowledge of the organization and risks added to it.
Note: A business objective may be listed more than once because it has multiple risks and
corresponding control objectives. Note disclaimer.
Business
Objective

Risk

Data Management Strategy


The data strategy
The business
supports the
strategy may not
business.
address data
quality and data
management
issues.

Control

Comments/
Results/
W/P Ref.

A strategy exists to
exploit data in the
organizations
possession to support
core business objectives.
Future CRM initiatives
are discussed by senior
management and
communicated to the
data team so that future
data needs can be
evaluated.
The data strategy is
formally documented
and approved by senior
management.
Senior management
views data management
as a strategic business
issue that is important to
the success of the
business.
Data management and
data quality are
discussed at senior level
management meetings.
The use of external data
from a third-party
vendor is reviewed.

Copyright IT Governance Institute 2003

[Link]/auditprograms

COBIT
Reference
PO1
DS2

89

Business
Objective

Risk

Control

Comments/
Results/
W/P Ref.

The major drivers of


change in the collection
and use of data within
the organization and
growth in automated
decisions and processes
are identified over the
next two years.
All projects validate data
structure/item needs
against corporate data
structures and comply
when feasible.
The value of data held
by the organization is
periodically assessed and
measured (e.g., users
surveyed to determine
how well data meets
their needs).
Data Ownership and Executive Sponsorship
Business owners
The business
An executive director
and sponsors
owners and
(e.g., CEO, CIO, CFO)
provide support.
sponsors may
is responsible for data
not support the
quality.
data warehouse
A cross business unit
and data
(e.g., steering
initiatives.
committee) addresses
issues dealing with data
management and quality.
A data stewardship
program for all data
sources is implemented.
Steward drives data
quality approach from
the business owners
point of view.

AI1
PO4
DS8
AI4

Copyright IT Governance Institute 2003

90

Future data needs


are understood and
processes meet
these needs.

Excessive costs
may occur in
changing data
definitions and
structures.
Data needs may
not be met.

COBIT
Reference

[Link]/auditprograms

DS11

Business
Objective

Risk

Data roles are


defined clearly.

Key data are


properly identified
and utilized.

Control

Comments/
Results/
W/P Ref.

A lack of focus
Roles and
may exist
responsibilities for data
regarding data
quality are identified
quality, resulting
clearly. For example, the
in poor data
roles and responsibilities
quality.
are documented and
communicated to the
user on an annual basis.
A formal group is
responsible for data
quality within the
organization.
There is one person or a
group of people
responsible for the
quality of data within
each business unit or key
category of information.
There is one person or
group of people
responsible for
responding when
problems are
encountered with data
within each business unit
or key category of
information.
Data may not be Management has
organized and
established categories of
understood.
data by level of
importance to the
business.

COBIT
Reference
PO11
PO10

PO2

Data

Copyright IT Governance Institute 2003

[Link]/auditprograms

91

Business
Objective

Risk

Sufficient audit
trails exist.

Control

Comments/
Results/
W/P Ref.

Research and
An audit trail is
forensics may
maintained in enough
not be able to be
detail to allow
performed due to
management to monitor
a lack of audit
the data warehouse
trails.
activities, transactions,
etc., and to meet the
needs of various internal
and external regulations.
Periodic, scheduled
audits are performed and
documented to verify
that established
procedures are being
followed.
An audit trail is
maintained in enough
detail and for an
adequate period of time
to allow management to
monitor the data
warehouse activities,
transactions, etc., and to
meet the needs of
various internal and
external regulations.
Preservation for a long
period is one of the most
important aspects of
audit trails (in many
cases also required by
regulation).

Copyright IT Governance Institute 2003

[Link]/auditprograms

COBIT
Reference
DS10
DS11
M4
PO8

92

Business
Objective

Risk

Data quality is
monitored.

Data are accurate,


consistent,
complete, etc.

Control

Comments/
Results/
W/P Ref.

Poor data quality A center of data


may lead to loss
excellence is established
in user
within the organization
confidence.
to monitor the
consistency of data over
a period in time.
A feedback mechanism
exists to determine the
customers, vendors and
users level of
confidence in the
organizations data.
The quality of data held
in the business,
processes or systems has
a means of being
measured.
Vendors and the
organization work
together in failure
analysis and troubleshooting quality issues to
resolve conflicts.
Customer complaints are
reviewed for linkage
back to poor data.
Reconciliation efforts
are investigated to
determine if they relate
to data quality issues.
Data quality may Data policies and
become
procedures surrounding
compromised.
data quality, such as
accuracy, consistency,
integrity and
completeness, are
established and
communicated to the
users.
Data is scrubbed and
integrity checks are in
place so that only quality
data are moved from
operational systems to
the data warehouse.
Data adheres to a

Copyright IT Governance Institute 2003

[Link]/auditprograms

COBIT
Reference
PO11
DS8
DS11

PO2
DS11
PO4
DS5

93

Business
Objective

Risk

Control

Copyright IT Governance Institute 2003

Comments/
Results/
W/P Ref.

COBIT
Reference

common definition for


meaning and use, for
example, address fields
incorrectly used to
record specific notes
about a customer.
Data adhere to defined
business rules, accepted
values and accepted
formats (e.g., valid
industry codes).
Data contain correct
values.
Data adhere to integrity
constraints such as
reasonableness checks,
validity checks, etc.
Processes exist to
validate that downloaded
or incoming data are
successful, by tracing it
back to the system of
record.
Data are checked
routinely against
external sources for
accuracy.
Statistical sampling (e.g.,
fixed percent of data are
checked each month) is
used to assess data
quality.

[Link]/auditprograms

94

Business
Objective

Risk

Access to data is
restricted.

Data privacy and


confidentiality are
observed.

Data needs are


complete.

Control

Comments/
Results/
W/P Ref.

Data owners identify


users who need access to
pertinent data and
provide them with only
the level of access
needed for their job
duties.
Procedures are in place
to set up users for the
information access they
need and are authorized
to receive.
Filters block
unauthorized access to
sensitive or
inappropriate
information.
Loss of customer Policies and standards
confidence may
exist for data that are
occur.
shared with the public
web site.
Data privacy and
security compliance are
established.
Policies exist regarding
the sale or publication of
data.
Nonexistent data Data owners identify all
may lead to loss
required information and
of opportunity
acquire nonexisting
and business
information from outside
growth.
the organization to fuel
CRM initiatives.
Inappropriate
access to data
may exist.

Copyright IT Governance Institute 2003

[Link]/auditprograms

COBIT
Reference
DS5

PO6
DS5

DS11

95

Business
Objective

Risk

Comments/
Results/
W/P Ref.

COBIT
Reference

Data can be accessed


when required and by
the appropriate people.
Knowledge of data and
their availability (e.g.,
meta data) is made
known generally to user
departments existing
outside of IT and project
teams.
The organization has a
shared information
system, drawing together
data from a range of
divisions and
departments.
Data Warehouse Implementation and Data Conversion Risks

DS11

Copyright IT Governance Institute 2003

96

Data are available.

Control

An inability to
make business
decisions due to
lack of data may
exist.

[Link]/auditprograms

Business
Objective

Risk

Control

A thorough review
has been
completed of the
existing data to be
converted.

Errors or
anomalies in the
old system may
not be identified
fully, and
corrections may
not be managed
properly.

The data
conversion system
design has
specified the
means to reconcile
both the old system
(internally) and the
old system to new
system on
commencement of
live production.

Balances from
the old system
may not be
transferred
properly to the
new system.

Copyright IT Governance Institute 2003

Comments/
Results/
W/P Ref.

The system has been


balanced and
reconciled regularly.
The system has its own
internal integrity (e.g.,
opening balance +
receipts issues +/adjustments = closing
balance).
The security and access
controls are sufficient
to prevent unauthorized
access or usage.
The system has
sufficient input
validation and error
checking to prevent
invalid master and
transaction data from
entering the system.
If tables are used, they
have been maintained
correctly and are
current.
There are no
noncurrent data in the
system.
There are no missing or
incomplete data in the
new systems.
The reconciliation
procedures ensure that
the existing system
balances internally at
the time of conversion.
The procedures for
reconciling the old
system to the system
master file data and
opening balance data
are established.
Where the system
implementation
strategy involves
parallel running, staged

[Link]/auditprograms

COBIT
Reference
DS5
DS11

AI1
AI4
AI5
M4

97

Business
Objective

Risk

Control

The data to be
converted from the
old system to the
new system have
been defined
properly.

Balances from
the old system
may not be
transferred
properly to the
new system.

Copyright IT Governance Institute 2003

Comments/
Results/
W/P Ref.

or phased
implementation,
procedures for the
different types of
reconciliations required
are identified.
Acceptance criteria, to
determine whether the
data conversion process
has been completed
successfully, are
defined and agreed
upon.
The responsibility for
sign-off and audit of
completion of the
conversion process is
defined and agreed
upon.
The documentation and
supporting materials to
be retained, as proof of
conversion, are defined.
A match exists between
all of the old system data
elements and the new
system data elements to
determine what will be
converted, what will not
be converted and what
will need to be created.
Requiring selection
criteria, purge criteria
and translation rules are
clearly identified,
documented and agreed
upon with users.
The validation of the old
data to the new system is
specified and agreed
upon.
Timing for the data
conversion is defined
and agreed upon with
users.
Issues of one-to-many

[Link]/auditprograms

COBIT
Reference

AI5
DS4
DS9

98

Business
Objective

Risk

Control

The data cleanup


process must be
adequately
controlled to
ensure that
amended data are
consistent and
integrity
maintained.

The protection,

adherence to and
maintenance of
data standards
may be
insufficient to
ensure the

integrity and
successful
operation of

systems.

Copyright IT Governance Institute 2003

Comments/
Results/
W/P Ref.

and many-to-one
conversions are resolved.
Field length and value
are analyzed.
The old system history,
the means of retention
(e.g., tape) and the
duration for which it is
to be held are defined.
Decisions are made in
relation to any redundant
data.
The means of formally
closing the old system
are defined.
The approach to data
cleanup is thoroughly
planned to ensure that
dependencies between
data items are
maintained.
Data items to be
amended and enhanced
are identified.
Criteria are agreed upon
for determining the data
conversion rules.
The tools/programs used
to effect changes to data
are tested and are
reliable.
An auditable trail of the
changes applied is
produced for
management review and
sign-off by the data
owner or nominated
deputies.
All changes applied are
reversible or can be
backed out by using
back-up copies of the
data.
Changes are never
applied directly to
production data.

[Link]/auditprograms

COBIT
Reference

AI5
AI6
DS11

99

Business
Objective

Risk

Procedures for the


creation or
conversion of data
for the new system
have been defined
properly.

Control

Comments/
Results/
W/P Ref.

The protection,
Different means may be
adherence to and
used to create/convert
maintenance of
data for the new system,
data standards
such as developing
may be
custom programs or the
insufficient to
use of master file bulk or
ensure the
mass conversion tools
integrity and
(e.g., provided in the
successful
data warehouse or CRM
operation of
application). It is
systems.
necessary to ensure:
- If custom programs
are written, the
development and
testing process
follows the normal
system development
life cycle.
- If a scanning device
is to be used to
create data, it is fully
tested to determine
capacity, accuracy
and the contents of
file outputs.
- If a mass or bulk
conversion tool is
used, it is fully
specified and
documented, and
capacity needs
determined and
tested.
- If the data are keyed,
the input programs
are tested
appropriately and
data are verified on
input.
- If the data are keyed
by a third party (e.g.,
service bureau),
proper instructions
and input validation
must be specified.
- If data are acquired,
they are loaded onto

Copyright IT Governance Institute 2003

[Link]/auditprograms

COBIT
Reference
AI4
AI5
DS2
DS11

100

Business
Objective

Adequate project
management of the
data conversion
process is in place.

Risk

Errors or

Control

anomalies in the
old system may
not be identified
fully, and
corrections may
not be managed
properly.

Copyright IT Governance Institute 2003

Comments/
Results/
W/P Ref.

the new system


through standard
input routines to
validate its accuracy.
The entire data
conversion process is
treated as if it were a
separate systems
development project.
Thus, the normal
project management
sections should be in
place including:
- Adherence to a
structured systems
development
methodology
- Use of project
management tools
and techniques to
define and manage
resources, outputs,
costs and time
- Project risk
assessment
- Definition of
security and access
- Definition of the
responsibility for
approval and the
means for any
adjustments
discovered as part of
the data conversion
process.

[Link]/auditprograms

COBIT
Reference

PO9
PO10
DS5

101

Business
Objective

Risk

Adequate testing
procedures for the
data conversion
system are in
place.

Sufficient training
and support exists
for data
warehouses.

Control

Comments/
Results/
W/P Ref.

The protection,
Unit, component, string
adherence to and
and system testing of all
maintenance of
parts of the data
data standards
conversion systems are
and testing may
completed in the same
be insufficient to
comprehensive manner
ensure the
as in a normal systems
integrity and
implementation.
successful
The testing to be
operation of
completed includes all of
systems.
the different means that
will be used in the
conversion process.
Depending on the
implementation strategy
used, this testing process
is completed on more
than one occasion.
Insufficient
Sufficient resources are
maintenance and
available to provide
support may occur
support and training of
for the data
data warehouse
warehouse.
personnel, end users, etc.
End users may not Staff members with
understand how to
responsibility for data
use the data
are trained in areas such
warehouse and,
as company knowledge
therefore, reject it.
systems, data quality,
and data ownership
responsibilities.
A structure exists by
which users can report
data problems to the data
and IT support
personnel.
There are documented
service level agreements
(SLAs) between
providers and users for
data deliverables.

Copyright IT Governance Institute 2003

[Link]/auditprograms

COBIT
Reference
AI5

DS1
DS7

102

5.

Integration Risks Work Program

The following work program will help manage the integration risks for customer relationship
management. Any person auditing, reviewing or advising on controls in a CRM project will need
to select tasks from the work program and to consider the key issues raised in the IT Governance
Institute publication Risks of Customer Relationship Management as part of their preparation. The
work program should not be used as a checklist of best practice, but as a selection of examples of
good practice that can be applied. By using the work program blindly, there is a risk of losing the
confidence of the auditee and even of missing the largest risks in the project, due to the
peculiarities of each project. Therefore, the work program should be used as guidance and
specific knowledge of the organization and risks added to it.
Note: A business objective may be listed more than once because it has multiple risks and
corresponding control objectives. Note disclaimer.
Business
Objective
Data Consistency
Data are consistent
between systems.

Data Quality
Quality data are
maintained
between the
systems.

Risk

Control

Lack of
uniformity
across connected
systems may
cause conflicts
among the
applications.

When
combining
information
from multiple
systems into one
CRM
application, the
risk of
inaccurate data
may arise.
Inaccurate data
leads to lack of
user buy-in, loss
of customers,
and failure of
CRM adoption.

Copyright IT Governance Institute 2003

Comments/
Results/
W/P Ref.

COBIT
Reference

Data validation rules,


business rules and
system controls ensure
the integration of data
among multiple
systems.
The data definition is
clear for key data
fields: customer,
product, sales order,
price, etc.

AI2
AI5
DS10

A comprehensive data
quality administration
or steering committee
can lead to the
institution of companywide data standards.
Data validation tools
are used to validate
data quality. Using
tools to periodically
identify and resolve
data quality issues
immediately can
mitigate the risk for
larger data quality
issues in the future.
Data quality linkage
among systems is
defined, maintained

AI5
AI6
DS10

[Link]/auditprograms

103

Business
Objective

Risk

Control

Data Structure
Data structures are
uniform between
systems.

Connectivity
Connectivity is
maintained to
allow data access
and transfer
between systems.

Comments/
Results/
W/P Ref.

COBIT
Reference

and measured.
Once a data quality
administration program
is implemented, the
following controls are
implemented as part of
the program:
- Concurrent access
that allows logic to
be updated with
many applications
linked to one
database/source
- Validation checks
- Data entry controls
- Change procedures

Without a standard
customer profile,
customer
information may
not be consistent
between systems.
Data loss and
inaccuracies may
occur.

A complete and thorough


analysis of the data
structures and data
definitions is performed
for each system to
ensure that each
application has the same
definition of customer
profiles and methods of
storing customer data,
e.g., flat files,
hierarchical databases, or
relational databases.
Data relationships are
assessed for each system
before attempting CRM
integration.
XML can be used to
mitigate data structure
risks by presenting
flexible ways to create
common information
formats and share the
format and data.

PO2
DS11

PO9
PO11
AI5

When
combining
information
from multiple
systems into one

Copyright IT Governance Institute 2003

EAI is used when


feasible and costjustifiable.
Custom code used as
adapters are inserted,

[Link]/auditprograms

104

Business
Objective

Risk

Control

CRM
application, the
risk of
inaccurate data
may arise.
Inaccurate data
leads to lack of
user buy-in, loss
of customers and
failure of CRM
adoption
Vendor Management
The CRM product

meets functionality
requirements and
the integration
effort is

reasonable.

Vendors are
researched
thoroughly to
understand the
integration effort.

The solution may


not meet
functionality
expectations.
The cost and effort
to integrate
applications may
be excessive.

Integration may
be too costly or
difficult.

Comments/
Results/
W/P Ref.

COBIT
Reference

tested, documented and


maintained properly.

The trade-off between


functionality and ease
of integration is
analyzed before
selecting a vendor. For
instance, an ERP
vendor with a CRM
extension may be
much more attractive
to the consumer from
an integration
standpoint, but the
product may not meet
functionality
expectations.
Vendors and the
proposed CRM solution
are researched to
determine the integration
effort and any issues that
may exist.
Vendors that have fully
integrated products, such
as Siebel, PeopleSoft,
Oracle, SAP and Clarify,
can be utilized.

Copyright IT Governance Institute 2003

[Link]/auditprograms

AI1
AI2

AI1
AI2

105

Business
Objective

Risk

Due diligence
performed by the
company to ensure
that the product
meets
requirements, the
vendor and
product are stable,
etc., may be
inadequate.
There may be a
lack of quality of
support from the
vendor, therefore,
when issues arise;
the vendor may
not be responsive.
System Maintenance/Manageability
System
A change in one
documentation is
area may affect
maintained.
numerous
connected systems,
cascading into
voluminous reworking and retesting of
previously
established
connectivity.
Potential system
downtime, data
and productivity
loss, and
reconfiguration
struggles may
occur.
Vendor
performance meets
the needs.

Control

Comments/
Results/
W/P Ref.

COBIT
Reference

Proper research is
performed on CRM
vendors to identify
integration and
functionality issues that
may exist within the
product itself.
Prior to purchasing a
vendor product,
management performs a
thorough check of the
vendor including
reference checks,
financial position check,
escrow agreements, etc.

AI1
AI2
DS9

A system maintenance
and modifications
strategy is developed,
including periodic
releases of changes to
customers, change
approval, modification
rules (vanilla vs.
modifications allowed),
etc.
Systems documentation
is maintained for
integration issues
encountered on the
project, e.g.,
connectivity difficulties.
Changes to systems,
applications and
connectivity adapters are
recorded to help transfer
knowledge to future
systems administrators.

PO6
PO11
AI1
AI6

Copyright IT Governance Institute 2003

[Link]/auditprograms

106

Business
Objective

Risk

Control

System
obsolescence is
avoided.

Technical
obsolescence may
occur.
There may be a
lack of vendor
support for older
systems.

AI3
AI4
DS9

Post-upgrade
testing is
performed.

The organization has


confidence in system
upgrade procedures due
to proper system
documentation and
knowledge; therefore,
the system can be
upgraded to keep current
with the latest release.
Sufficient planning is
performed to understand
the effort required to
upgrade the system.
Proper testing and
debugging after system
changes, maintenance or
upgrades are performed
to verify previously
established connectivity,
synchronicity and data
quality.
Results are documented
and any inconsistencies
or errors are investigated
thoroughly.
Manageability of pointto-point connections is
achieved through use of
EAI solutions. EAI
usually is used for CRM
projects that are large in
both scope and budget
due to its facilitation of
data flow in real time,
and its effectiveness in
managing connectivity.

DS11

Interfaces are
manageable.

When systems
are processing
smoothly
without incident,
administrators
may feel that
post-upgrade
testing is an
unnecessary
step. Therefore,
testing may not
be performed
thoroughly.
Interfaces may
grow
exponentially
because of the
number of
applications that
need to be
integrated for the
CRM solution.
Changes in one
application may
ripple through
other systems,
potentially
delaying data
movement.

Copyright IT Governance Institute 2003

Comments/
Results/
W/P Ref.

[Link]/auditprograms

COBIT
Reference

AI3
AI5
PO11

107

Business
Objective

Risk

System Performance
The system is
The amount of
scalable.
data being
transferred,
acceptable speed
of data transfer or
the number of
concurrent users
may increase, thus
increasing
uncertainty about
stability and
response time.
The system may
be unstable,
resulting in loss of
data, loss of
productivity and
user
dissatisfaction.
Data are updated in CRM users may
a timely manner.
not be able to
access customer
data in a timely
manner.

Control

Comments/
Results/
W/P Ref.

COBIT
Reference

Before integrating new


systems, a thorough
systems analysis is
executed to expose
system weaknesses and
mitigate scalability and
performance risks.

PO9
AI5
DS11

A proper assessment
based on industry,
volume and number of
users is performed to
determine if data needs
to be processed in real
time or with batch
processing.
By taking this hybrid
approach to data flow
and minimizing the realtime processing needed,
an organization may
avoid system
performance risks and
still meet user needs.

DS3
DS7

Copyright IT Governance Institute 2003

[Link]/auditprograms

108

Business
Objective

Risk

Backup, Restoration and Continuity


Data can be
Without proper
recovered.
backup and
restore
procedures in
place,
organizations
may expose
themselves to
extensive
damage or loss
of data as well
as productivity
losses.

Control

Comments/
Results/
W/P Ref.

Formal, written and


proven backup and
restoration procedures
are documented and
include the
responsibilities and time
expectations for
recovering the system.
The restoration
procedures are tested
periodically and proven
successful.
The organization has
formally documented,
tested and updated
business continuity and
disaster recovery plans.
The organization has a
way to operate the
business in the event of a
disaster, system outage
or interruption, i.e.,
manual procedures to
enter sales orders, take
customer service calls,
etc.

Copyright IT Governance Institute 2003

[Link]/auditprograms

COBIT
Reference
DS4

109

Business
Objective

Risk

Interface Monitoring and Workflow


Data is interfaced
There may be
properly.
interface errors
due to data
mapping or
translation tables
that have changed
so that the
interfaces do not
match, or due to
data that have been
received in an
incorrect format.
Interface errors
may not be
identified,
investigated and
resolved in a
timely manner.
Customer
transactions may
not be processed
correctly and CRM
information may
not be complete.

Control

Comments/
Results/
W/P Ref.

Formal roles and


responsibilities are
defined for monitoring
interfaces and resolving
errors.
Manual or automated
monitoring controls are
used to ensure that
interface errors are
identified, investigated
and resolved in a timely
manner.
Criticality and frequency
of the interface will help
to determine the type of
error identification and
resolution procedures
needed to ensure data
completeness and
accuracy. Noncritical or
batch interfaces, may
indicate that manual
procedures are sufficient.
Reporting is defined and
reviewed regularly to
identify interface
processing information,
such as outstanding
errors, days outstanding,
etc.

Copyright IT Governance Institute 2003

[Link]/auditprograms

COBIT
Reference
PO7
AI4
DS1

110

6.

Channel Management and Integration Risks Work Program

The following work program will help in channel management and in managing the integration
risks for customer relationship management. Any person auditing, reviewing or advising on
controls in a CRM project will need to select tasks from the work program and to consider the
key issues raised in the IT Governance Institute publication Risks of Customer Relationship
Management as part of their preparation. The work program should not be used as a checklist of
best practice, but as a selection of examples of good practice that can be applied. By using the
work programs blindly, there is a risk of losing the confidence of the auditee and even of missing
the largest risks in the project, due to the peculiarities of each project. Therefore, work programs
should be used as guidance, and specific knowledge of the organization and risks should be added
to it.
Note: A business objective may be listed more than once because it has multiple risks and
corresponding control objectives. Note disclaimer.
Business
Objective
Channel Strategy
Channel strategy
provides profitable
customer
relationships.

Risk

Control

Messages across
channels may not
be consistent.
Each channel or
department may
operate
independently, i.e.,
silo behavior.
Channels may not
match the demands
from primary
customer segments
of the
organization.

Cross-function teams are


established to create a
formal channel strategy
that meets customer
needs and provides a
profitable relationship
for the organization.
Channels are matched to
the demands from the
primary customer
segments of the
organization.
Channel performance is
optimized from the
perspective of both the
customer and the
organization.

Comments/
Results/
W/P Ref.

COBIT
Reference
PO1

Data Integrity and Consistency

Copyright IT Governance Institute 2003

[Link]/auditprograms

111

Business
Objective

Risk

Control

Consistent
information is
provided across
channels.

Information
regarding product
availability,
features and price
may not be
consistent across
channels.
Customers may
not know what
price, promotion
and general
experience to
expect each time
they contact what
they perceive to be
the same
organization.
Each sales
channel is
treated as a
separate
operating unit
and configured
as a separate
organization,
which may
generate
conflicting
information and
sometimes may
create competing
brands.
Inexperienced
CSRs may not
understand the
functionality,
policies and
procedures of all
channels (e.g.,
Internet, kiosks,
telemarketing,
face-to-face
sales, etc).

Cross-functional teams
compare information
across channels.
Changes to information
are considered and
agreed upon across all
channels.

AI2

Sales channels are


integrated so that brands
and information are
consistent.
Separate operations are
not created for each sales
channel, but instead
operations are integrated
across sales channels.

DS11

DS7

Sales channels are


integrated to
provide consistent
brands and
information.

CSRs understand
functionality,
policies and
procedures across
channels.

Copyright IT Governance Institute 2003

Comments/
Results/
W/P Ref.

Initial and periodic


training is conducted to
educate CSRs about all
channels including
policies, procedures,
functionality, etc.

[Link]/auditprograms

COBIT
Reference

112

Business
Objective

Risk

Control

Data are
normalized across
all channels.

Data may not be


collected from
all channels.

Data are complete


and useful.

Data and
customer
feedback may
not be obtained
from all relevant
channels.

Silo CRM
solutions may have
been built to
service new
customer-facing
channels.
Inconsistent
service,
information and
procedures across
channels may
exist.
Up-to-date
Customers may
information is
make repeated
available.
attempts to get
tasks completed.
Customer Experience
Customers are
Customers may
provided with a
not be provided
variety of channels.
with the right
variety of
channels;
therefore, they
cannot interact
with the
organization
using their
preferred
channel.

The CRM system


encompasses all
customer-facing
channels.

Comments/
Results/
W/P Ref.

Controls are in place to


ensure data analyzed
include complete and
final data from all
relevant channels.
Data and customer
feedback are obtained
from all customer
touchpoints to ensure
that data obtained are
valuable and present a
complete view of the
customer.
The CRM solution
spreads across the
organization, division,
etc., and therefore
encompasses all
customer-facing
channels to ensure
consistency.
The CRM system is
integrated across all
channels and back into
the legacy systems.
Up-to-date information
is dispersed across all
touchpoints.

Feedback is solicited and


analyzed from customers
to understand the variety
of channels that
customers want.
The channels used by the
company match the
preferences of the
customers.

Copyright IT Governance Institute 2003

[Link]/auditprograms

COBIT
Reference
DS11

DS11

AI6

DS11

M1

113

Business
Objective

Risk

Control

Customers
interaction occurs
through their
preferred channels.

Customer channel
preferences are
understood and future
contact with customers is
via their preferred
channel.
Customers have the
freedom to interact with
the organization via
multiple channels, and
they are not restricted to
only one or two
channels.
Organizations fully
explore new
communication or
distribution media to
understand how they fit
into their overall CRM
picture before offering
the media to their
customers.

DS8
DS13

PO7
DS6

Customers
interaction may
not be
communicated
via their
preferred
channel.

Organizations may
rush to the next
communication or
distribution
medium out of
competitive
necessity before
studying how it
will fit into their
overall CRM
picture.
Customer
experience may
not be satisfied
despite the
addition of new
channels.
Channel
development may
be unbridled,
therefore wasting
resources.
Leverage of Customer Information
Cross-selling
Cross-selling
opportunities are
opportunities
identified.
may not be
identified due to
inadequate
information
across channels.
The organizations
channels enhance
the customer
experience.

Copyright IT Governance Institute 2003

Comments/
Results/
W/P Ref.

Channel information is
consolidated and
reviewed for possible
cross-selling
opportunities.

[Link]/auditprograms

COBIT
Reference

DS7
DS8

114

Business
Objective

Risk

Control

Customer
profitability is
measured across
channels.

Customer analysis is
performed to identify the
least and most profitable
customers across sales
channels.
Priority queuing is used
to move less-profitable
customers to channels
that cost less to service.

Profitability
information may
not be shared
across channels;
therefore,
management
will not have a
full view of the
customer.

Copyright IT Governance Institute 2003

Comments/
Results/
W/P Ref.

[Link]/auditprograms

COBIT
Reference
DS6

115

7.

Telecommunication Infrastructure Risks Work Program

The following work program will help manage the telecommunication infrastructure risks for
customer relationship management. Any person auditing, reviewing or advising on controls in a
CRM project will need to select tasks from the work program and to consider the key issues
raised in the IT Governance Institute publication Risks of Customer Relationship Management as
part of their preparation. The work program should not be used as a checklist of best practice, but
as a selection of examples of good practice that can be applied. By using the work programs
blindly, there is a risk of losing the confidence of the auditee and even of missing the largest risks
in the project, due to the peculiarities of each project. Therefore, work programs should be used
as guidance, and specific knowledge of the organization and risks should be added to it.
Note: A business objective may be listed more than once because it has multiple risks and
corresponding control objectives. Note disclaimer.
Business
Objective
Call Handling
Calls are received,
routed and handled
properly resulting
in prompt
resolution.

Risk

Control

Calls may be
blocked.
Calls may be
dropped.
Calls may be
misdirected.
Unauthorized
database access
may occur.

Copyright IT Governance Institute 2003

Comments/
Results/
W/P Ref.

ACD implementations
are tested properly to
ensure they are coded
correctly to route calls
to the proper agent, to
provide correct
announcements to a
caller and to place calls
into voice mail.
Only trained personnel
can make changes to
ACDs and those
changes are tested in a
controlled environment
at offpeak times.
Other controls include
properly configuring
the tables that
indicating to the longdistance telephone
organization where toll
free 800 numbers
should terminate.

[Link]/auditprograms

COBIT
Reference
AI3

AI5
AI6
DS7
DS9

116

Business
Objective
Implementation
Telecommunications infrastructure
is implemented
properly.

Risk

Control

Applications and
systems may fail
from incorrect
configurations or
inadequate
engineering.
Changes may
falsely appear to
be successful,
and are later,
during call center
peak operations,
found out to be
defective.
Data
communications
and voice
communications
may not be
coordinated
properly.
Redundancy may
not be built into
the systems.
Agents may not
be comfortable
with
modifications to
call flows or
their work
menus.
Response time
degradations
may exist.

Copyright IT Governance Institute 2003

Comments/
Results/
W/P Ref.

Software is tested to
detect programming
errors.
Software is tested to
ensure it operates as
intended in a live
environment.
Modifications made
subsequent to initial
testing are retested.
Systems and
applications are backed
up prior to installation.
Implementations are
authorized and signedoff by management.
Application features are
documented.
Users are trained on the
software.
Acceptance testing and
operations (e.g., backup
and recovery) testing
are performed.
Formal change
management
procedures exist.

[Link]/auditprograms

COBIT
Reference
AI3

AI5
AI6

117

Business
Objective
Efficiency
Customer
interaction center
operations and
systems are
efficient.

Risk

Control

Serious service
level impairment
and excess costs
may exist.
The contact
center may not
be organized and
tooled
effectively so
workers have to
get up for
faxing, obtaining
reference
material, and
performing other
business
functions away
from their
workstation.

Statistical analysis and


real-time monitoring is
used to measure and
improve efficiency.
Reader boards, also
called marquees, are
sometimes used to
monitor metrics and
statistics.

DS1

Customer
interaction
center operations
may be
interrupted.
Customers may
be dissatisfied.
Costs may be
excessive.

Budgets for disaster


recovery options are
drafted, not only to
provide electronic
backup systems for
servers and local area
networks but also
enable customers to
receive uninterrupted
service.
Disaster recovery
options that go beyond
the retrieval of data, to
include voice and data
communication and
the relocation of
business personnel to
alternative facilities,
have been researched.
Technical and business
personnel have
established a process
so everyone knows
that course of action to
take when an
emergency occurs.

DS2

Business Continuity
Business continuity
and disaster
recovery plans can
recover systems
and operations
quickly.

Copyright IT Governance Institute 2003

Comments/
Results/
W/P Ref.

[Link]/auditprograms

COBIT
Reference

M1

DS4

118

Business
Objective

Risk

Control

Copyright IT Governance Institute 2003

Comments/
Results/
W/P Ref.

COBIT
Reference

Key call center


systems that have
plans for recovery
include:
- Voice mail
- Automatic call
distribution (ACD)
- E-mail servers
- Customer contact
database
- Standard response
database
The call center BCP
plan consists of the
following:
- Plan purpose,
assumptions,
strategy,
responsibilities,
organization
- Plan activation, call
list, recovery
procedures,
restoration
procedures
- External contacts
- Plan testing and
maintenance
procedures
- A monitoring policy
- Social engineering

[Link]/auditprograms

119

Business
Objective
Security
Physical security
exists over the
PBX room, adjunct
equipment and
wiring closets.

Risk

Control

Service may be
disrupted
intentionally.
Equipment and
wiring may be
damaged
accidentally.
Unauthorized
access to
confidential
information
(e.g., voice mail
data) may be
granted.

Users and
telephones are
assigned only the
level of telephony
access needed for
employees to
perform their work.

Users whose
duties do not
require longdistance dialing
may make
unauthorized
domestic and
international
long distance
personal calls at
the
organizations
expense.
Telephones in
lobby areas,
conference
rooms and other
public areas may
not be restricted,
so they may be
used to make

Copyright IT Governance Institute 2003

Comments/
Results/
W/P Ref.

All areas related to


telecommunications,
including the PBX
room, communications
server areas (e.g., for
voice mail servers) and
wiring closets are
protected with
electronic locks and
appropriate alarming.
Access to
telecommunications
areas is limited to
those who have a need
to work in the area.
Vendors and repair
personnel from other
organizations are
preapproved for access
or subject to specific
control points, such as
signing visitor logs
and being escorted
when working in the
facilities.
Each extension is
assigned an
appropriate class of
service that permits
only the level of
telephony access
appropriate to either
the person using it or
its physical location.
For example:
1) Only senior
executives with
business need have
external call
forwarding
enabled.
2) Only the telecom
department has the
direct trunk select
feature, which
typically is used

[Link]/auditprograms

COBIT
Reference
PO4

DS12

DS5
DS12

120

Business
Objective

Risk

Control

unauthorized
long distance
calls.

Copyright IT Governance Institute 2003

Comments/
Results/
W/P Ref.

COBIT
Reference

for testing
purposes. It can
also be used to
perpetrate toll
fraud.
3) If it is required for
business purposes,
only trained
operators should
have the trunk-totrunk feature that
allows them to
connect an
incoming caller to
an outbound trunk.
This feature is
commonly used to
perpetrate toll
fraud.
4) Conference room
phones should not
have international
dialing privileges.
Profiles are developed
for broad classes of
positions, including
contractors,
administrative
assistants, executives,
switchboard operators
and the standard
profile for most
employees. These
profiles relate to
classes of service and
other determinants of
functionality.

[Link]/auditprograms

121

Business
Objective

Risk

Control

Password controls
exist for the PBX,
voice mail and
other adjunct
equipment.

Unauthorized
personnel may
dial into the
PBX
maintenance
port and obtain
the superuser
ID(s) via a
password
cracking utility.
With this level
of access,
telephone
records may be
destroyed, and
critical system
parameters could
be changed.
Changing
parameters, such
as class of
service, may
shutdown the
PBX.
Confidential
information left
in employees
voice mail boxes
may be obtained
and greetings
may be altered
maliciously.

Copyright IT Governance Institute 2003

Comments/
Results/
W/P Ref.

Standard good
practices for passwords
are used for all users,
administrative users
and super users,
including:
- Adequate password
length
- Hard-to-guess
sequences
- Elimination of
installation default
passwords
- Published policies
and procedures for
all users
- Mandatory
password changes
every 60-90 days

[Link]/auditprograms

COBIT
Reference
DS5

122

Business
Objective

Risk

Control

Inactive or unused
resources are
deleted.

Unauthorized
individuals may
utilize
abandoned or
unused voice
mail boxes for
illegal and
untraceable
activities.
Analog lines
connected to
modems may be
used to break
into computer
systems by
bypassing the IP
firewall via the
voice network,
and then
compromising
ID passwords to
enter the PBX or
voice mail and
shutdown
services.

Copyright IT Governance Institute 2003

Comments/
Results/
W/P Ref.

Using telephony
management tools,
assets are reviewed for
currency and last date
of use. Unused
facilities are made
inactive or reused. For
example, voice mail
boxes and IDs of
terminated employees,
unused or unneeded
analog lines, modem
facsimile lines, and
telephone extensions
are removed.
IDs are examined for
good practices, such as
avoidance of common
names, etc.

[Link]/auditprograms

COBIT
Reference
DS5
DS13

123

Business
Objective

Risk

Control

PBX and voice


mail security
parameters are set
appropriately.

Security
parameters may
be set to default
or uncontrolled
values.
Intruders may
easily penetrate
the PBX and
commit toll
fraud by illegally
selling the
organizations
long-distance
services to
others without
the
organizations
knowledge or
authorization.
Unauthorized
personnel may
place longdistance and
international
calls, causing the
organization,
instead of the
individual who
placed the calls,
to incur
fraudulent
charges for the
calls.

Copyright IT Governance Institute 2003

Comments/
Results/
W/P Ref.

All security parameters


in the PBX and voice
mail systems are
reviewed for
appropriate values.
Examples include:
- Voice mail, PBX
superuser IDs and
administrative IDs
are set to force
password change
every 60 days.
- Tables used to
block calls to
premium numbers
(e.g., 900 numbers)
are updated
regularly.
- Trunk-to-trunk
transfer is set to
No.
- Maximum number
of attempts to sign
on as
administrator is
set at three,
preventing the
continued guessing
of passwords by
unauthorized
personnel.
- DISA (direct
inward system
access) is disabled,
preventing
unauthorized
individuals from
perpetrating toll
fraud. For instance,
with DISA enabled,
users can dial into
the PBX, receive a
dial tone, and then
dial out and make
an unauthorized
call.

[Link]/auditprograms

COBIT
Reference
AI3
DS5

124

Business
Objective

Risk

Control

Telecommunications
documentation is
secured.

Specific functions
that are known to
create
vulnerabilities are
reviewed to ensure
that if they are not
disabled,
management has
made a conscious
decision to keep
them active based
on business needs.

Trunk access
codes, the
maintenance
port dial-in
number, and
other sensitive
information may
be obtained
internally and
used for
unauthorized
penetration of
the PBX.
Hackers may use
the call forward
external feature
to perpetrate toll
fraud. They may
accomplish this
by having an
accomplice call
forward phones
to an
unauthorized
domestic or
international
location, then
call that
extension so
they are
forwarded to the
intended
number.
Hackers may
penetrate users
voice mail, enter
a two digit code,
get dial tone and
make calls
anywhere in the
world.

Copyright IT Governance Institute 2003

Comments/
Results/
W/P Ref.

COBIT
Reference

Manual documentation
containing critical,
security-related
information is stored
in locked cabinets.
Sensitive electronic
documentation on CDROMs is protected
adequately with
passwords and other
standard security
measures.

AI4
DS5

Management
periodically review the
security structure of the
PBX, voice mail and
adjuncts to ensure that
excessive permissions
are not granted.
Examples include:
- Blocking area
codes where no
business is
conducted
- Eliminating the
ability to get dial
tone from voice
mail
- Eliminating the
call forward
external feature on
most telephones
- Limiting call-out
features within the
data center
- Limiting lobby
telephones to local
calls only

PO2
PO4
AI6
DS5

[Link]/auditprograms

125

Business
Objective

Risk

Control

The PBX and


related equipment
are protected from
unauthorized
access via a dial-up
modem.

Unauthorized
individuals may
obtain the range
of telephone
numbers used in
an organization
and war dial to
identify the PBX
maintenance
port.
Using password
crackers and
other techniques,
hackers may
penetrate the
PBX and voice
mail systems.

A break-in may
occur and not be
detected until the
volume of toll
fraud activity
becomes
significant
enough to cause
obvious
problems, such
as excessive
busy signals,
indicating all
trunks are being
used for
unauthorized
traffic.

Telecommunications activities are


monitored
appropriately.

Copyright IT Governance Institute 2003

Comments/
Results/
W/P Ref.

The maintenance port


on the PBX is
protected by a twofactor authentication
code, greatly reducing
the likelihood of
unauthorized access.
The analog line
connecting the
maintenance port to
the outside world uses
a telephone number
that is completely out
of the normal range of
business numbers.
The maintenance line
does not go through
the PBX, but comes
directly from the local
telephone organization
(e.g., central office).
Exception reporting is
well designed to
identify unusual
activity. For example,
reports are generated
that summarize calls to
international locations,
list all calls over four
hours and show any
major repetition of
very short calls,
indicating hacker
activity.
Exception reports are
summarized at a
practical level to
identify suspicious
activity.
Exception reports are
provided online, via a
web browser.
Exception reports are
monitored on a timely
basis.

[Link]/auditprograms

COBIT
Reference
PO4
AI2

AI4
DS13
PO2
M1

126

Business
Objective

Risk

Control

Alarm systems
provide real-time
alerts that
operational
problems or
unusual events,
possibly
fraudulent, are in
progress.

Telecom
expenditures are
monitored.

Unauthorized
access may be
gained to the
PBX
maintenance
port by repeated
attempts to crack
the ID/password
combinations.
Unauthorized
attacks may not
be detected.
Operational
malfunctions
may not be
detected, so
telephone
service may be
interrupted.
Employees may
incur large
internal
telephone
charges for the
organization by
frequently
placing personal
calls to longdistance or
international
locations.
Telecom charges
may be
summarized at a
high level so that
their
inappropriate or
fraudulent
activity is not
detected.

Copyright IT Governance Institute 2003

Comments/
Results/
W/P Ref.

COBIT
Reference

PBX management
software monitors both
potential fraudulent
activities as well as
operational
malfunctions, such as
failed trunk lines or
PBX call flow
interruption.
Procedures exist for
promptly investigating
and resolving
fraudulent activities
and operational
malfunctions.

AI4
DS5
DS10

Charge-back reports
are produced every
month showing
telecom expenditures
at the departmental
level to identify
charges that indicate
either internal abuse or
external toll fraud.
Managers review
charges via a browser
and are able to quickly
identify suspicious
activity or charges.
Telecom charge-back
reports are produced
with sufficient detail to
enable detection of
inappropriate or
fraudulent activity.
Examples of reports
include calls to tollfraud hot spots, the top
20 long duration calls
and the top 20 most
expensive calls.

DS1
DS6
M1

[Link]/auditprograms

127

Business
Objective

Risk

Control

External
monitoring
provides a second
line of defense
against toll fraud.

Unauthorized
individuals,
having thwarted
the
organizations
internal barriers
to toll fraud,
may have free
reign to the PBX
and pass
thousands of
calls through the
victim PBX,
resulting in very
large longdistance or
international
charges.

Unauthorized
individuals may
commit toll
fraud.
The PBX may
be compromised
resulting in a
large financial
loss.

Security restricts
access to sensitive
powerful functions.

As a last line of
defense, the
organization
maintains toll fraud
insurance.

Copyright IT Governance Institute 2003

Comments/
Results/
W/P Ref.

Using the longdistance carrier, PBX


vendor or other parties,
all calls are monitored
for unusual traffic
patterns, such as a 500
percent increase in
calls to a particular
international and long
distance location. The
monitoring
organization uses
sophisticated
algorithms to detect
fraud.
Once unusual activity
is detected,
management is
notified and presented
with options to
terminate the activity.
Access to powerful
PBX and CRM
functions should be
restricted properly.
Arrangements are
made with the PBX
vendor or longdistance carrier to
purchase toll fraud
insurance. Any actual
losses beyond the
deductible are covered.
The telecom manager
reviews security
measures to ensure
compliance with the
caveats of the tollfraud insurance.

[Link]/auditprograms

COBIT
Reference
M1

DS5

PO8

128

8.

Security Risks Work Program

The following work program will help perform a high-level security audit and manage the
security risks for customer relationship management. Any person auditing, reviewing or advising
on controls in a CRM project will need to select tasks from the work program and to consider the
key issues raised in the IT Governance Institute publication Risks of Customer Relationship
Management as part of their preparation. The work program should not be used as a checklist of
best practice, but as a selection of examples of good practice that can be applied. By using the
work programs blindly, there is a risk of losing the confidence of the auditee and even of missing
the largest risks in the project, due to the peculiarities of each project. Therefore, work programs
should be used as guidance and specific knowledge of the organization and risks added to it.
Note: A business objective may be listed more than once because it has multiple risks and
corresponding control objectives. Note disclaimer.
Business
Objective
User Management
Default accounts
are safeguarded.

Risk

Control

Comments/
Results/
W/P Ref.

Default accounts
The default accounts
may be
(e.g., administrator and
compromised.
guest accounts) are
Since default
renamed immediately
accounts are
after installation to an
widely known,
unidentifiable name.
these are usually
Passwords for default
the first accounts
accounts are changed to
that an intruder
a not easily guessed
will attempt to use.
password, e.g., a long
Many of these
password containing
accounts have
both alpha and numeric
powerful system
characters.
access; therefore,
Accounts are disabled if
intruders can gain
they are not being used.
extensive system
access.
If default accounts
are not renamed,
an attacker may
launch a brute
force attack to
guess passwords
for these default
accounts.

Copyright IT Governance Institute 2003

[Link]/auditprograms

COBIT
Reference
PO4
AI3
DS5

129

Business
Objective

Risk

Control

Groups contain
only appropriate
users.

Individuals are assigned


as members of the
administrators group,
only if absolutely
necessary.
Users are assigned to
groups properly.
The groups report is
monitored on a regular
basis to ensure that only
authorized users are
members of these
groups.

Naming
conventions are
established and
followed for all
user accounts (e.g.,
end users,
contractors,
consultants and
vendors).

All users and


groups in the
domain are known
and documented.

Accounts for
individuals who are
no longer employed
or have a

When
unnecessary
users are
assigned as
members of
groups that have
extended
privileges, they
may use this
enhanced ability
to compromise
the security of
the system and
gain
unauthorized
access to
sensitive system
data.
Users may not
be easily
identified, so
unusual activity
may not be
identified.

Comments/
Results/
W/P Ref.

Standard naming
conventions are
established and
consistently followed for
naming each type of
user, so that users within
each group can be
identified easily.
Temporary accounts
used for contractors,
consultants and vendors
follow an identifiable
naming convention that
allows these accounts to
be easily identified and
purged if warranted.
Domain security
All existing groups
may be
within a specific
compromised, as
domain are
security
documented according
personnel are not
to corporate policy.
familiar with
authorized vs.
unauthorized
users.
Existence of
Procedures exist to
accounts that are
promptly remove
no longer needed
unneeded user
increases the risk
accounts from the

Copyright IT Governance Institute 2003

[Link]/auditprograms

COBIT
Reference
PO4
DS5
M1

DS5
DS10
AI3

DS5

PO7
AI2
AI4
DS5

130

Business
Objective
requirement for
system access are
deleted.

User accounts are


descriptive.

Risk
that
unauthorized
personnel may
gain
inappropriate
access via these
accounts and it
would not be
identified as
unusual activity.

Extraneous,
unneeded user
accounts may be
created.
Security
administrators may
not know the
background of
users assigned to
user IDs;
therefore, it may
be difficult to
understand if user
activities are
appropriate.

Control

Comments/
Results/
W/P Ref.

system. They include:


- Obtaining a listing
of recently
separated
employees from the
HR department and
ensuring that the
former employees
account(s) have
been removed or
disabled from the
system.
- Automated
integration exists
between the HR
system and the
security system so
user accounts are
automatically
locked, inactivated,
changed or deleted
when an employee
is terminated or
transferred.
- Inactive accounts
are monitored
periodically (e.g.,
after a specified
period of
inactivity).
All user accounts have an
applicable, informative
full name and
description, such as
department, division, etc.

Copyright IT Governance Institute 2003

[Link]/auditprograms

COBIT
Reference

DS5

131

Business
Objective

Risk

Control

Passwords are
secured within the
registry.

The automatic
logon option may
embed the
password of
accounts in the
registry in clear
text; therefore,
passwords may be
compromised.
The default
password may
exist within the
registry and,
therefore, be
compromised.
A malicious user
may gain access
to system
resources used
by these
accounts.

The automatic logon


options for servers are
not enabled. All users
must enter a user name
and password each time
they log on to the
system.
The registry is reviewed
periodically to ensure
that it does not contain
default passwords.

AI#
DS5

All inactive user


accounts are disabled.
User account listings are
reviewed to identify the
last logon times of users
to ensure that no one
exceeds corporate
standards indicating the
number of days of
inactivity allowed before
user IDs are locked or
deleted.
If corporate standards do
not exist, industry
standards are used, such
as 60 days of inactivity.
Privileged account
passwords are
distributed only to those
individuals with a
legitimate business need
for such access.

DS5
DS7
DS10
PO6

Any account that


has not logged on
for an extended
period of time is
disabled.

Privileged user
passwords are not
widely distributed.

The
effectiveness of
passwords for
sensitive or
critical accounts
may be
weakened due to
excessive
distribution.

Copyright IT Governance Institute 2003

Comments/
Results/
W/P Ref.

[Link]/auditprograms

COBIT
Reference

DS5

132

Business
Objective

Risk

Control

Comments/
Results/
W/P Ref.

Password Management
Default passwords Application
The administrator is
supplied with
default passwords
interviewed to ensure
software packages
may be widely
that all default passwords
are changed upon
known and
have been renamed
installation.
therefore the
and/or disabled if the
default user IDs
account is not being
are easy targets for
used.
attacks.
Unauthorized
access may be
obtained if these
passwords are not
changed.
Passwords are
Passwords may
Temporary passwords do
unique.
be easily
not remain in use. All
guessable,
new users are required to
resulting in
change their password
unauthorized
upon their initial login.
access to the
Generic or predictable
system.
passwords are not used
as an initial password.
Each new account is
created with a unique
and difficult-todetermine password.
The administrator
The system or
The administrator
password is
user accounts
password can be
available for
may be locked
obtained in the event of
emergencies.
and an
an emergency.
administrator
The administrator
account may not
passwords are stored in a
be available,
physically secure
resulting in
location on and offsite.
significant
downtime.

Copyright IT Governance Institute 2003

[Link]/auditprograms

COBIT
Reference
AI3
DS5

DS5

DS4
DS5
DS10

133

Business
Objective

Risk

Accounts are
locked to prevent
invalid logon
attempts.

The password for


the administrator
account is unique
across all servers.

Control

Comments/
Results/
W/P Ref.

The account lockout


feature is enabled and
the related parameters
are set in accordance
with corporate security
standards and guidelines.
If no corporate policy
exists, industry
guidelines are used,
which state that accounts
are locked after three
invalid logon attempts
and that the invalid
logon counter is reset
after 1,440 minutes.
Locked accounts remain
locked indefinitely until
an administrator
manually unlocks them.
The useful life of
All passwords, including
any compromised
the administrative
passwords may not
password, are changed
be limited.
periodically in
accordance with
A common
corporate standards.
administrator
password on
multiple systems
may increase
exposure to all
systems, because
unauthorized
personnel have
access to all
systems if they
compromise the
password.
User accounts
may be
compromised
through brute
force attacks.

Copyright IT Governance Institute 2003

[Link]/auditprograms

COBIT
Reference
PO6
AI3
DS5
DS7

PO6
DS5

134

Business
Objective

Risk

Control

Data are classified


and mapped to
security needs.

Data classification is a
primary driver for
determining the proper
security measures
needed.
By mapping the data to
data owners and
understanding the data
classifications,
management are able to
determine what groups
of users need access to
data.
This data classification
feeds into the design of
security roles that are
eventually configured
into the system.
User-level overrides of
password policies are not
allowed for any user
accounts, except for
service accounts.

Strong password
controls restrict
access to the
system.

Unauthorized
access to data
may occur.

Users may reduce


the effectiveness
of their specific
password controls.
Unauthorized
access may occur
if passwords are
compromised.

Comments/
Results/
W/P Ref.

Group Management
Local and global
Network and
User accounts are
groups simplify
security
logically grouped
network and
administration
through the use of global
security
may be ineffective.
groups in the
administration.
authentication domain.
Users are grouped
according to similar job
functions, departments
or access requirements.

Copyright IT Governance Institute 2003

[Link]/auditprograms

COBIT
Reference
PO2
PO4
DS5

DS5

PO4
DS5
DS11

135

Business
Objective

Risk

Control

Naming
conventions are
established and
followed for all
global and local
groups.

Nonstandard,
unauthorized
groups may not be
identified easily.
Unauthorized
access may occur.

Standard naming
conventions are set for
each type of user group.
Each user group can be
identified easily.
Global groups have
different naming
standards than local
groups.
Groups are named,
identifying the type of
group, group purpose,
and department.
No unnecessary
additional groups exist
on the system.
Other than the built-in
global groups, no global
groups exist outside of
the authentication
domains.

Copyright IT Governance Institute 2003

Comments/
Results/
W/P Ref.

[Link]/auditprograms

COBIT
Reference
DS5
DS9
DS11

136

Business
Objective

Risk

Control

Comments/
Results/
W/P Ref.

File System Access and Management


Access to
Granting
The most restrictive
application and
excessive
level of permissions is
system directories
permissions to
used for application and
and files is
applications may
system files and
restricted.
lead to
directories. No users,
inappropriate
including IT and end
access and
users, are allowed
unauthorized
excessive permission to
transactions.
application files and
directories.
If under certain
circumstances relaxed
permissions are
necessary, new groups
are created to manage
relaxed permissions.
Then, the specific users
are assigned to the new
group, instead of the
regular group.
Application and system
directories do not allow
write, delete, and
change permissions to
users.
Application and system
directories do not allow
take ownership to
users.
The built-in special
group has no
permissions.
Data files are
The appropriate
Data files are stored in
segregated from
level of security
segregated directories
application and
may not be granted
external to the
system directories.
for each type of
application and system
file, and therefore,
directories, possibly in
it may be too
the data owners home
excessive.
directories, or the
application-specified data
Directory
directory.
permission levels
may be assigned
accidentally to
executable
program files.

Copyright IT Governance Institute 2003

[Link]/auditprograms

COBIT
Reference
AI2
DS5
DS11

AI2
DS5

137

Business
Objective

Risk

Maintenance and Operations


Unattended
Unattended
workstations are
servers and
secured.
workstations
may be
compromised.

Control

Comments/
Results/
W/P Ref.

When workstations are


not being used, the
accounts are logged off
from the system console.
Users are forced to
enable passwordprotected screensavers.
In Windows 2000
environments, users lock
their workstations.

Auditing, Logging and Monitoring


Auditing is enabled Unauthorized
Auditing of sensitive
for critical files and
access to the
system and application
directories.
system may not
files and directories is
be detected and
enabled. For instance,
terminated in a
changes to system
timely manner
registry keys are
due to a lack of
audited.
audit trail.
All audit logs are
Inadequate
Policies are followed
archived in
retention of audit
properly for archiving
accordance with
logs may result
and purging audit logs.
corporate standards
in the inability
Organization and
and regulatory
of an
regulatory requirements
requirements.
organization to
(e.g., US Internal
defend itself
Revenue Service, US
against
Federal Trade
unauthorized
Commission) are met.
access.
Access to read,
change, delete audit
files is restricted
properly.
Audit logs are
Unauthorized
Audit logs containing
secured.
personnel may
sensitive system
delete audit logs
information are
to eliminate the
secured properly (e.g.,
audit trails.
password protected).

Copyright IT Governance Institute 2003

[Link]/auditprograms

COBIT
Reference
PO4
DS5

DS5
M3

PO8
DS5
DS13
M3

DS5
DS13

138

Business
Objective

Risk

Control

Comments/
Results/
W/P Ref.

System Development and Change Control


Production
Unauthorized
Programmers and
application and
access to
developers do not have
data files are
production and
access to production or
secured.
data files may
intermediate program
exist.
and data files.
Separate servers are
utilized for production,
development and testing
environments. If separate
servers are not utilized,
developers have access
only to development
files and directories.
They do not have any
access to test and
production directories.
The migration of
programs from
development and testing
environments to the
production environment
is controlled through an
appropriate segregation
of roles.
Security Administration Activities
Prior user names
Unauthorized
When logging on to the
are not displayed at
users may gain
system, the last user
login.
knowledge of
name and default user
the client
name are not displayed
domain naming
at login.
standards and
the user name of
the last user to
log on to the
system. This
information may
be used to gain
unauthorized
access to the
domain.

Copyright IT Governance Institute 2003

[Link]/auditprograms

COBIT
Reference
PO4
PO11
AI5
AI6
DS9

PO6
DS5

139

Business
Objective

Risk

Control

The system does


not shut down if the
audit log becomes
full.

A full audit log


may cause the
server to be
shutdown.

Only legitimate
jobs are scheduled.

The scheduled
service may
allow an
unauthorized
user to execute
malicious code
as an
administrator

Operational Resilience
Disaster recovery

and business
continuity plans
exist.

System redundancy
and contingency
plans are used.

An uninterrupted
power supply is
used for critical
systems.

Comments/
Results/
W/P Ref.

Full audit logs do not


shut down the server.
In some cases, it may
be necessary to shut
down the server when
the audit log becomes
full, to ensure that an
audit trail is always in
existence.
The administrator is the
only one to schedule
jobs in the system.
If a separate individual
performs this function,
the administrator still
retains rights to schedule
jobs, but only as a
backup.

Critical
Disaster recovery polices
operations and
exist for recovering
systems may not
critical operations and
be recoverable in
systems in the event of
the event of a
a disaster.
disaster.
An organizationwide
disaster recovery plan
exists. The plan is
updated frequently and
tested periodically.
Hardware
System redundancy (e.g.,
failures may lead
mirroring, load
to the loss or
balancing) and
corruption of
contingency plans are
critical data.
established for critical
servers (e.g., web server
for an e-business).
Data and
An uninterrupted power
systems may be
supply is used for all
lost or corrupted
critical systems. This
in the event of a
provides power for the
power loss.
system to be shut down
in the event of power
loss or degradation.

Copyright IT Governance Institute 2003

[Link]/auditprograms

COBIT
Reference
DS10

DS11
DS13

DS4

DS4

DS4
DS12

140

Business
Objective

Risk

System backups are The systems may


performed on a
not be
regular basis.
recoverable.

Networking
Workstation and
time restrictions are
enforced.

Users are forcibly


disconnected from
servers when their
login hours expire.

Unauthorized
personnel may
gain access to
systems during
nonpeak hours
when user IDs are
dormant.
Unauthorized
personnel may
gain access to
systems through
unattended user
logon sessions.

Control

Comments/
Results/
W/P Ref.

COBIT
Reference

Incremental daily
backups and
weekly/monthly fullsystem backups are
performed for all critical
systems.
The administrator and
business lead determine
the frequency and
completeness of backups
(e.g., incremental, partial
or full).
Daily and weekly/
monthly backups are
stored in a secured
offsite location.

DS4
DS11

Users are restricted on


the system by enforcing
workstation and time
restrictions. Note: these
controls usually are
feasible only for users
that utilize one
workstation during set
hours of the day.
Network resources can
be accessed only if the
user is specifically
authorized for access
during those hours.
The appropriate blockout times are set for the
user community.
Users are disconnected
automatically from the
system when their login
hour expires

DS5

Copyright IT Governance Institute 2003

[Link]/auditprograms

DS5

141

Business
Objective

Risk

Physical Access
Physical access to
the data center is
strictly controlled.

Unauthorized
personnel may
have physical
access to the data
center, and
therefore, access to
the system
consoles and
operations
information.
Security Policies and Procedures
A general security
Without a full risk
risk assessment is
assessment, critical
performed.
systems and
applications may
not be identified
and secured
properly.
A security
Users who are not
awareness program
reminded of good
exists.
security practices
may create
security violations
inadvertently or
intentionally.
A data
classification
structure is
identified clearly.

The policies and


procedures are
readily accessible
to all employees.

Without a data
classification
system, it may be
difficult to
dedicate
appropriate
resources to
protect high-value
data.
Employees may
not understand
security policies
and procedures,
and therefore,
they may cause
security
violations
inadvertently or
intentionally.

Control

Comments/
Results/
W/P Ref.

COBIT
Reference

Access to the data center


is restricted properly
based on responsibility/
roles.
All data center access is
logged and reviewed on
a regular basis.

DS9
DS11
DS12
DS13

A full risk assessment is


performed to identify
critical systems and
applications and the
appropriateness of
security settings.

PO9

A formal security
awareness program
exists and is updated
regularly.
All new employees must
sign an employee
information security
policy when hired.
A data classification
system exists and all
departments and
employees understand
how to apply the
classification system
(e.g., stamping
documents, watermarks).

PO6
PO7
DS5

Security policies and


procedures are widely
distributed throughout
the organization.

Copyright IT Governance Institute 2003

[Link]/auditprograms

PO2
DS5

PO6
PO7
DS5

142

Business
Objective

Risk

Users who do not


understand good
security practices
may cause security
violations
inadvertently or
intentionally.
Security Administration and Management
Terminated
Users may
employees are
continue to access
promptly removed
the system after
from the system.
they have been
terminated and
have no legal
relationship with
the organization.
A formal security
End users may not
administration
understand whom
function exists and
to call when
is communicated
violations are
throughout the
identified.
organization.
If security is not
someones focused
effort, it may be
forgotten when
other crises occur.
System, application Inappropriate
and user access is
access may not be
periodically
detected.
reviewed.
Security training is
a part of new
employee
orientation.

A standard profile
exists for PC
configurations to
ensure consistency.

Control

Comments/
Results/
W/P Ref.

COBIT
Reference

New hire orientation


includes security
awareness training.

PO7
DS7

Separations from the

PO7
DS5

organization are
communicated
immediately to the
administrator and exemployees are removed
promptly from the
system.
A security team or
system administrator
exists and is completely
dedicated to the security
of the corporate network
and infrastructure.

A formal periodic review


process of system,
application and user
access is performed on a
regular basis.
Unauthorized
A standard load or
software and
image exists for all
hardware additions
laptops and desktops
may be recognized
deployed by the
quickly.
organization.
Software and hardware
licenses are reviewed
periodically for
appropriateness.

Copyright IT Governance Institute 2003

[Link]/auditprograms

PO6
DS5

DS13
M4

DS9
DS13

143

Business
Objective

Risk

Control

Comments/
Results/
W/P Ref.

System Level Controls


Administrator

activities are
limited, controlled
and monitored.

No one person can create


System
potentially businessadministrators may
crippling changes to the
perform
network.
unauthorized

Administrator activities
activities, which
may not be
are limited, controlled
detected.
and monitored.
For high-volume
Volumes of
System logging (e.g.,
systems, automated
logging data may
inherent to the system or
monitoring tools
be produced daily.
third-party tools) is
are utilized.
Without automated
performed.
tools to flag
possibly
inappropriate
access, it may go
unnoticed.
Internet Information Server
The latest Internet
If the version of
The most current version
information server
the operating
of the operating system
program directory
system or
and application contain
structure is
applications is
processing and security
installed.
not current,
enhancements.
unauthorized
The most recent security
users may be able
patches have been
to exploit
applied to the servers.
weaknesses.
Only required
Unnecessary
The Internet information
server extensions
server extensions
servers application is
are used.
may expose the
configured to check for
IIS server to
the existence of URLs
unnecessary
before passing them on
attacks.
to the systems DLLs.
Only required DLLs are
mapped for the server.
Firewall Configuration
Only authorized
Unauthorized
Only authorized ports are
ports are allowed
personnel may
open on the firewall
on the firewalls.
attempt to
based on the
compromise the
requirements of the
firewall or other
applications within the
network devices
environment.
by targeting
specific ports or
services.

Copyright IT Governance Institute 2003

[Link]/auditprograms

COBIT
Reference
DS5
DS13
M1

DS8
DS10
DS13

PO3
AI3
DS5

DS5
DS11

DS5

144

Business
Objective

Risk

Control

Comments/
Results/
W/P Ref.

Unauthorized
Online business
personnel may
transactions are
sniff unencrypted
encrypted.
transactions.
In the event of a
Critical firewalls are
hardware failure,
designed to provide 100
users may not be
percent uptime through
able to access
fail-over or fault
resources (e.g.,
tolerance.
Internet).
Segregation of Duties/Application-based Security
Access to sensitive
Unauthorized
Incompatible duties
and powerful
access to CRM
are separated properly
transactions is
functions may
within the CRM
restricted properly.
exist.
system and other
applications, for
example:
- The ability to
create a customer
and process a
credit
- The ability to
create a vendor
and approve
marketing
expenditures
- The ability to
physically
access/take spare
parts and process
spare parts
inventory
adjustments
Access to
sensitive/powerful
master data and
transactions, for
example, prices and
credit limits which could
be used to support fraud
and collusion with a
customer, is restricted
properly within the CRM
system.
Online business
transactions are
encrypted (e.g.,
SSL).
Critical firewalls
are configured with
fail-over or fault
tolerance
capabilities.

Copyright IT Governance Institute 2003

[Link]/auditprograms

COBIT
Reference
DS5

DS5

PO4
DS5

145

9.

Project Management Risks Work Program

The following work program will help control the project management risks of a customer
relationship implementation project. Any person auditing, reviewing or advising on controls in a
CRM project will need to select tasks from the work program and to consider the key issues
raised in the IT Governance Institute publication Risks of Customer Relationship Management as
part of their preparation. The work program should not be used as a checklist of best practice, but
as a selection of examples of good practice that can be applied. By using the work programs
blindly, there is a risk of losing the confidence of the auditee and even of missing the largest risks
in the project, due to the peculiarities of each project. Therefore, work programs should be used
as guidance, and specific knowledge of the organization and risks should be added to it.
Note: A business objective may be listed more than once because it has multiple risks and
corresponding control objectives. Note disclaimer.
Business
Objective

Risk

Project Initiation
Senior

management
reviews the project
charter and plan
and approves the

project prior to the


project
commencing.

Senior
management may
not support the
project.
The project may
not be in
alignment with
business
objectives and
goals.

Control

Comments/
Results
W/P Ref.

The project steering


committee reviews and
approves project
initiation documents to
ensure that the project is
in alignment with
business objectives and
goals.
The project is approved,
with the commitment
of continued senior
management support.
Control is exercised
over the existence of
formal and written
project management
procedures in the
organization (on SDLC
bases), which provide a
good starting point for
effective project
management.

Copyright IT Governance Institute 2003

[Link]/auditprograms

COBIT
Reference
PO1
PO10

146

Business
Objective

Risk

Project Scope Management


Project scope is
The project may
managed
not be
effectively.
implemented on
time or on budget
due to excessive
scope changes.

Control

Comments/
Results
W/P Ref.

The project
management team
should adhere to the
business case, taking
into consideration
priority objectives set
and approved by senior
management.
The project team
always refers back to
the CRM values to
guide the decisionmaking process.
A strong configuration
and change
management process
used when changing
scope.
The scope is altered
only with executive
approval and a thorough
analysis of the impact
of scope changes.

Copyright IT Governance Institute 2003

[Link]/auditprograms

COBIT
Reference
PO10
AI6
DS9

147

Business
Objective

Risk

Project Integration and Management


For complex
The project may
projects, a project
not be well
support office is
coordinated,
established.
managed and
controlled.

The project
contains welldefined business
justification,
budget, scope,
dates and key
resources.

The project may


not be well
defined;
therefore, the
business
justification,
budget, scope,
dates and key
resources are
misunderstood.

Control

Comments/
Results
W/P Ref.

A project support office


is established to manage
the following aspects of
the project: issue and
risk management,
dependency
management, scope
management, cost and
resource management,
project standards and
procedures
establishment, project
planning and
integration, vendor and
contractor management
and organizational
change management.
Roles and
responsibilities are
defined clearly, and a
project support office is
established, with
resources at a sufficient
experience level.
During project start-up
the following areas are
determined and
documented:
- Business
justification
- Budget statement
and justification
- Scope definition
- High-level plan
including dates and
phases
- Key personnel
identification and
resource levels
- Key internal and
external
dependencies
- Critical success
factors
- Key risks

Copyright IT Governance Institute 2003

[Link]/auditprograms

COBIT
Reference
PO4
PO10

PO5
PO6
PO10

148

Business
Objective

Risk

Control

A steering
committee
oversees the
project.

The project may

The role of the steering

A steering
committee
oversees the
project.

Comments/
Results
W/P Ref.

not meet
objectives,
milestones or
budget.

committee is defined
clearly. A determination
is made as to whether
the committee has
approval authority or is
in a guidance mode
with approval authority
vested in the managers,
especially for the
following items:
Project schedule
Project standards
Project personnel
assignments
Project deliverables
If the project is to be
managed through a
senior management
position, this reporting
line and accountability
should be established
and agreed.
The project may A steering committee
not meet
is established that has
objectives,
representation from all
milestones or
the business functions
budget.
involved in using,
operating and setting
policy for the
proposed system. The
following types of
personnel are
considered for
membership in the
committee:
- Senior
management
depends on
whether
management
wishes to delegate
steering committee
roles or perform a
hands-on function
- Information

Copyright IT Governance Institute 2003

[Link]/auditprograms

COBIT
Reference
PO4
PO10

PO4
PO10

149

Business
Objective

Risk

Control

Copyright IT Governance Institute 2003

Comments/
Results
W/P Ref.

COBIT
Reference

systems personnel
representing
database
administration, data
administration, ecommerce,
application
development,
security, etc.
Key end-users
representing major
functional areas
and consisting of
strong individuals
with key
understanding of
business
Technology
personnelwith
key understanding
of the new
technology and its
impact on the
organization

[Link]/auditprograms

150

Business
Objective

Risk

Internal and
external project
dependencies are
identified and
monitored.

All project
dependencies may
not be identified or
monitored.
Therefore,
misunderstood or
undetected project
dependencies may
negatively impact
the project.

Dependencies are
managed
effectively.

A common
approach for
project
administration is
utilized.

Issues raised by
dependencies
may not be
resolved,
increasing the
risk of project
failure.
Separate and
inconsistent
approaches may
be used for the
administration of
different
projects.

Control

Comments/
Results
W/P Ref.

COBIT
Reference

Project team managers


keep a central record of
all dependencies during
the lifetime of the
project.
Each dependency is
associated with an owner
responsible for regularly
tracking and updating
the dependencies.
Regular meetings are
scheduled to facilitate
communication of
dependencies between
project teams.
External and internal
dependencies are
reported to senior
management regularly,
thus making
management aware of
possible impacts on
project deliverables or
milestones.
Project dependencies
are prioritized, and an
action plan to resolve
them is agreed upon
and implemented.

PO1
AI3
AI6
AI8

PO6
PO10

Copyright IT Governance Institute 2003

Procedures and
standards are in place
for:
- New project
definition and
scope
- Common project
tools (i.e., MS
Project)
- Project-related
travel and
accommodation
- Diary management
for key project
personnel

[Link]/auditprograms

PO1
PO10

151

Business
Objective

Risk

Changes and the


possible impact
they have on
project deliverables
and timelines are
communicated,
monitored and
controlled.

The impact of
changes to the
project scope and
timeline may not
be identified before
implementation.
Changes may be
made without
proper
authorization.
Excessive changes
may negatively
impact project
timing and scope.

Time and Activity Management


Project meets
Project may be
planned milestones
delivered late.
and deadlines.

Control

Comments/
Results
W/P Ref.

COBIT
Reference

Any change or deviation


to the project baseline
requires a change request
to be completed and
authorized by senior
management before
work is scheduled or
undertaken.
All change requests
include an impact
assessment and are
prioritized.
All change requests are
documented in a central
control log that contains
the current status.
The central control log is
updated on an ongoing
basis.
At agreed intervals,
status reports on changes
are prepared and
communicated to the
project team and senior
management.

PO10
AI6

A project plan exists to


provide a single and
consolidated repository
of task, resource and
cost information.
A clear owner is
responsible for
maintaining the plan,
i.e., rescheduling,
capturing actual
hours/milestones, and
producing progress
reports against the
plan.
The project plan is
baselined when work
is approved initially.
When additional work
beyond the original
scope is sanctioned

PO10
AI2

Copyright IT Governance Institute 2003

[Link]/auditprograms

152

Business
Objective

Risk

Control

Comments/
Results
W/P Ref.

COBIT
Reference

through a formal
change request
procedure, the plan is
revised and the new
tasks are baselined.
The baseline process
saves the original
estimates and schedule
for comparison against
the working schedule,
which allows slippage
and/or gain to be
monitored easily.
Project performance and
progress is monitored
against the plan to
provide an early
warning of potential
issues when milestones
are not met within the
specified timeframe.
Cost Management
Costs are controlled
to stay within the
project budget.

The project may


exceed its
budgeted costs.

Copyright IT Governance Institute 2003

Initial assessments of
interfaces, data
conversion efforts,
customization and
expertise are
determined to ensure
that project costs are
managed and the
budget is realistic.
Formal proven
methodologies are used
for planning resources,
planning and estimating
costs, and budgeting
and monitoring costs.

[Link]/auditprograms

PO5
PO10
AI6

153

Business
Objective

Risk

Control

Comments/
Results
W/P Ref.

Project Communications Management


Senior management Senior
A communication plan and
is kept regularly
management may
reporting schedule are
informed of the
not be made
defined at the onset of
progress of projects
aware of all risks
the project.
and work streams.
and issues on a
Reporting procedures are
timely basis.
developed to describe
the frequency and type
of reporting, report
distribution and
personnel responsible for
each critical project
activity and action item.
Reporting levels, report
contents and an
overview of items to be
tracked regularly are
clearly documented.
Regular meetings are
conducted to
communicate project
progress, raise key
issues, solicit critical
management input and
make key decisions.
The project library
Pertinent project
A target list of
provides logistical
information may
documents to be
and informative
not be available
collected in both hard
support to both the
and readily
and soft (electronic)
project support
accessible to all
formats is compiled.
office and the
team members.
The library is set up and
project groups.
operates so that:
Reference material is
easily accessible to
all project personnel.
Distribution of
sensitive documents
is controlled.
Standard version
control of documents
is maintained.

Copyright IT Governance Institute 2003

[Link]/auditprograms

COBIT
Reference
PO6
PO10

PO10

154

Business
Objective

Risk

Documents are
produced and
changed according
to project
standards.

Control

Project team
members may
create documents
without
following
consistent
standards.

Copyright IT Governance Institute 2003

Comments/
Results
W/P Ref.

Standard software tools


are utilized throughout
the project.
Standard templates are
utilized.
Deliverable documents
are subject to version
control.
Documentation
standards are established
and followed
consistently for all key
project deliverables.

[Link]/auditprograms

COBIT
Reference
AI4
PO11

155

Business
Objective

Risk

Project Personnel Management


Project personnel
Personnel may not
should be managed
understand their
appropriately.
project roles.
Key personnel
may be lost from
the project and the
organization,
causing the
solution to fail.

Control

Comments/
Results
W/P Ref.

The organization should


perform project
personnel planning to
ensure that:
- Project roles and
responsibilities are
defined clearly.
- The best resources
are acquired to work
on the CRM project.
- Resources are
trained properly to
perform their project
roles.
- Teams work well
together.
If heavy reliance is
placed on outside
resources or contract
staff, sufficient
knowledge transfer is
ensured by pairing
company personnel with
technology/application
experts.
Contingency plans and
incentives are provided
to ensure that project
personnel remain in key
knowledge champion
positions once the
system is implemented.
Dependence placed on
contract staff is
moderated.

COBIT
Reference
PO7
PO10
DS2

Organizational Change Management


(Refer to work program 11. Organizational Change Management, for a detailed work program
surrounding this area.)

Copyright IT Governance Institute 2003

[Link]/auditprograms

156

Business
Objective

Risk

Project Risk Management


All risks that may
All potential
impact the project
risks may not be
are identified,
identified.
documented and
Unmitigated
managed.
risks may cause
the project to fail
to achieve
deadlines, costs
or operational
objectives.

All issues arising


Issues may not
throughout the
be
project are
communicated to
communicated and
the appropriate
resolved in a timely
levels within the
manner.
project or
organization.
Issues may not
be resolved in a
timely manner.

Control

Comments/
Results
W/P Ref.

A formal risk assessment is


undertaken at the start of
the project.
Each member of the
project team is given the
opportunity to voice risk
concerns throughout the
duration of the project.
All risks are captured and
documented in a risk log
on an ongoing basis.
The project support office
is responsible for
maintaining a risk log and
for up-channeling risk
issues to senior
management.
Each risk is associated
with an owner. The owner
is responsible for
developing a strategy to
mitigate the risk.
The strategy includes a
brief plan of action to be
taken and the impacts that
the risks have on the
current project deadlines,
costs, or operational
objectives.
All issues are captured and
documented in an issue log
on an ongoing basis.
Each issue is associated
with an owner responsible
for its resolution.
At agreed intervals, status
reports on issues are
prepared and
communicated to project
managers.
An escalation procedure is
established to handle
issues that cannot be
solved at the project level.

Copyright IT Governance Institute 2003

[Link]/auditprograms

COBIT
Reference
PO1
PO9
PO10

PO6

PO10
PO11

157

Business
Objective

Risk

Quality Management
Project outcome

meets or exceeds
customer
requirements.

The project is
closed formally
without significant
open items.

Control

Comments/
Results
W/P Ref.

The organizations existing


quality processes are used
to establish a project
quality framework.
Project quality controls
and standards are
established and applied
consistently throughout the
project.
Acceptance and
completion criteria are
established and used to
facilitate quality control of
deliverables.
Quality checkpoints are
established and used to
measure project processes
and deliverables against
quality standards and
criteria.
Overall escalation
procedure and levels of
responsibility are
established and used to
escalate issues and resolve
disputes over rejection and
rework.
Project quality is audited
on an ongoing basis.
Implementation All project documentation
activities may
is completed and filed.
not be
A project exit review is
completed
conducted to ensure that all
satisfactorily.
project tasks are completed
Contractual
satisfactorily.
issues associated Project contractual issues
with project
are resolved.
closure may not Project completion
be completed.
documentation is produced
Lessons learned
and formally signed-off.
from project
Lessons learned are
issues may not
discussed and documented.
be identified.
The final project
may not meet
customer
expectations.
The desired
benefits of the
project may not
be realized.

Copyright IT Governance Institute 2003

[Link]/auditprograms

COBIT
Reference
PO10

PO11
M1

PO10

158

Business
Objective

Risk

Control

Comments/
Results
W/P Ref.

Technology Management
Vendor
Vendors may not A vendor management
performance is
adhere to
process is defined and
monitored against
contract
consistently applied
contract
specifications.
throughout the project to
specifications.
include:
- High-level and
detailed definition of
requirements
- Quality standards
- Quantification of
risk associated with
hiring the vendor
- Competitive
tendering
- Contract
requirements
- Vendor performance
monitoring
- Deliverable(s)
acceptance only if
the final product
meets or exceeds
expectations

Copyright IT Governance Institute 2003

[Link]/auditprograms

COBIT
Reference
PO10
DS1
DS2

159

Business
Objective

Risk

Regulatory Compliance
The CRM project

and solution meets


regulatory, security
and privacy
requirements.

Control

The CRM
project and/or
CRM solution
may not be
implemented in
compliance with
regulations and
security and
privacy
requirements.

Comments/
Results
W/P Ref.

Project managers must


understand the
regulations and security
and privacy
requirements facing their
CRM projects. They
incorporate project tasks
into the project plan to
ensure that they are in
compliance with
regulations that impact
their project or the CRM
solution, for example:
US Gramm-LeachBliley Act (GLBA)
US Computer
Systems Validation
US FDA Electronic
Signatures and
Records
Requirements
US 21 CFR Part 820
US Health Insurance
Portability and
Accountability Act
(HIPAA)
EU Data Protection
Directive

Copyright IT Governance Institute 2003

[Link]/auditprograms

COBIT
Reference
PO8
PO10

160

Business
Objective
Cultural differences
are considered
when developing
and implementing
the CRM solution.

Risk

Control
When CRM
solutions are
implemented
across borders,
or globally,
additional
complexities
may be
introduced. For
instance, cultural
and economic
differences may
make strategies
and solutions
that work in one
country not
practical for
other countries.

Copyright IT Governance Institute 2003

Comments/
Results
W/P Ref.

Careful attention
should be paid to
cultural differences
and a representative
from each country is
included in defining
the CRM strategy/
vision, business case,
analysis, design, etc.

[Link]/auditprograms

COBIT
Reference
PO6
PO7
PO10
DS1

161

10.

Benefits Realization Work Program

The following work program will help to ensure that the organization is realizing the benefits
from the customer relationship management implementation project. Any person auditing,
reviewing or advising on controls in a CRM project will need to select tasks from the work
program and to consider the key issues raised in the IT Governance Institute publication Risks of
Customer Relationship Management as part of their preparation. The work program should not be
used as a checklist of best practice, but as a selection of examples of good practice that can be
applied. By using the work programs blindly, there is a risk of losing the confidence of the auditee
and even of missing the largest risks in the project, due to the peculiarities of each project.
Therefore, work programs should be used as guidance and specific knowledge of the organization
and risks added to it.
Note: A business objective may be listed more than once because it has multiple risks and
corresponding control objectives. Note disclaimer.
Business
Objective

Risk

Defining Business Benefits


The CRM
The organizations
initiative is clearly
objectives for
defined from the
initiating a CRM
beginning, with
project may not be
clearly articulated
clear.
anticipated
Managements
benefits.
expectations may
not be articulated.
The desired
benefits may not
be defined
realistically.

Control

Comments/
Results
W/P Ref.

A business case is
developed for the CRM
project.
The business case clearly
identifies desired
business benefits.
The business case
prioritizes the
organizations
objectives.
The business case
presents the expected
return on investment
(ROI) and expected
payback period.

Copyright IT Governance Institute 2003

[Link]/auditprograms

COBIT
Reference
PO1
PO5
PO10

162

Business
Objective

Risk

The project plans


and deliverables
are linked to the
business case and
desired benefits.

The project may


Anticipated benefits are
progress without a
mapped to specific
relationship to the
project deliverables
business case.
during the project
planning phase.
Project decisions
All enabling benefits are
may be made
without regard to
linked to direct benefits
original project
to determine the
objectives and
complete benefit path for
values.
achieving the desired
business results.
The organization
may end up with a All dependencies to
final project output
project deliverables are
that does not meet
identified and included
expectations.
in the benefit path.
Every project deliverable
is linked to a desired
objective or business
benefit.
Sponsors for
An appropriate business
benefits may not
or process owner is
be identified.
identified and assigned
accountability for each
All activities
benefit.
necessary to
Accountability rests with
achieve the
benefits may not
individuals who can
be completed.
impact or influence the
delivery of project
outputs (e.g., process,
technology or people
changes).

Accountability is
assigned for
achieving each
benefit.

Control

Comments/
Results
W/P Ref.

Monitoring Benefits
Benefits

monitoring is a
continuous process
throughout the
project lifecycle.

Project decisions
Accountable individuals
may be made
are part of the extended
without regard to
project team and are
the original project
involved actively.
objectives and
Project decisions are
values.
reviewed against
The final project
potential impact to
output may not
anticipated benefits.
meet expectations.

Copyright IT Governance Institute 2003

[Link]/auditprograms

COBIT
Reference
PO10

PO5
PO9

PO10

163

Business
Objective
The indicators are
identified for
measuring success.

Risk

Control

Comments/
Results
W/P Ref.

The organization Success indicators are


may not be able
defined and
to measure
communicated clearly to
performance and
the project team.
success of the
Baseline performance
project.
data are collected to
provide the basis for
comparison.
Appropriate sets of
metrics are developed
for direct and enabling
benefits.
Tools are used to
facilitate collection of
data and calculation of
results.

Copyright IT Governance Institute 2003

[Link]/auditprograms

COBIT
Reference
M1
PO10

164

11.

Organizational Change Management Work Program

The following work program will help to ensure that the organization is managing the
organizational changes from the customer relationship management implementation project. Any
person auditing, reviewing or advising on controls in a CRM project will need to select tasks
from the work program and to consider the key issues raised in the IT Governance Institute
publication Risks of Customer Relationship Management as part of their preparation. The work
program should not be used as a checklist of best practice, but as a selection of examples of good
practice that can be applied. By using the work programs blindly, there is a risk of losing the
confidence of the auditee and even of missing the largest risks in the project, due to the
peculiarities of each project. Therefore, work programs should be used as guidance and specific
knowledge of the organization and risks added to it.
Note: A business objective may be listed more than once because it has multiple risks and
corresponding control objectives. Note disclaimer.
Business
Objective

Risk

Control

Organizational Change Management Process


There is a defined There may be a

project
lack of focus and
workstream to
activities to
address
address
organizational
organizational
change.
change
No one may be

assigned
responsibility or
accountability for
organizational

alignment.
All activities
necessary to

achieve
organizational
change may not be
completed.

Copyright IT Governance Institute 2003

Comments/
Results/
W/P Ref.

Change management
activities are included in
the overall project
planning activities for
the CRM
implementation.
Change management
timelines and milestones
are incorporated in the
project plan.
The change management
team is included in all
project team meetings.
The same level of
reporting and monitoring
of change management
activities is required as
with all other project
workstreams.

[Link]/auditprograms

COBIT
Reference
AI6
PO6

165

Business
Objective

Risk

Control

Change
management
requirements for
the CRM
implementation
are defined.

If the extent of

The objectives of the

Project Strategy
The project
strategy delivers
quick wins, if
needed, to
encourage morale
and adoption.

changes that will


result from the
CRM
implementation
are not clearly
understood, the
appropriate steps
to prepare the
organization may
not be undertaken
during the course
of the
implementation.

Sustained
organizational
commitment and
support to the
initiative may
wane over time,
without
demonstration of
quick wins that
clearly show the
benefits of CRM
to the
organization.

Comments/
Results/
W/P Ref.

CRM implementation
and its intended business
results are articulated.
The changes (process,
systems, organizational
structure, staffing, etc.)
that may be required are
identified.
An owner for each of
defined change is
identified.
The change owner is
engaged as early as
possible in the
implementation.

The organization is

COBIT
Reference
PO1
PO4
AI6

PO10

focusing on delivering
quick wins when
planning for the project
to help ease user
adoption and build
excitement for the new
solution.
Demonstrable
improvement to the
process, or peoples
ability to contribute to
the projects end goal,
are shown.
Quick wins are
communicated and
celebrated to maintain
momentum and
encourage continued
change support.

Copyright IT Governance Institute 2003

[Link]/auditprograms

166

Business
Objective

Risk

Control

The timing of
organizational
change activities is
closely aligned
with project
activities and
timelines.

Organizational

Plan activities in

change activities
may not be done in
coordination with
implementation
activities and
communication.
An attempt at
addressing
organizational
change may be
made only at the
time of, or after,
system rollout.

alignment with overall


project milestones.
Change management
timelines and milestones
are incorporated in the
project plan.
Include change
management team in all
project team meetings.

Project Sponsorship
Leadership is

engaged in change
management
initiative.

Management
support may not
be obtained;
therefore, it is not
sustained during
the
implementation.

Copyright IT Governance Institute 2003

Comments/
Results/
W/P Ref.

Senior management buy-

COBIT
Reference
AI6
PO10

PO1

in of the required
changes is obtained.
Senior management
commitment to and
support of change
management activities
that will be carried out to
prepare the organization
are obtained.
A sponsor who will be
personally vested to
ensure project success is
identified.

[Link]/auditprograms

167

Business
Objective

Risk

Control

Comments/
Results/
W/P Ref.

Department Involvement and Employee Representation


Commitment is
If no commitment
The teams are built that
obtained and
is obtained from
are responsible for
maintained from
specific
carrying out change
key departments
individuals to
management activities.
and employee
drive change
Involvement and
representatives.
management,
participation come from
activities will not
all affected departments
be carried out as
and the top performers
planned, and will
are part of the project
end up falling
team.
back to members
A communication
of the project
framework is established
team.
that will address
communication needs
for all levelsproject
teams, stakeholders, endusers, etc.
Plan for Change/Resistance to Change
Change strategy is
The organizations The organizations
defined.
change readiness
readiness to adopt the
is not assessed,
required changes has
and therefore
been assessed.
activities may not
The change management
be in line with
activities are planned
organizational
and defined in line with
requirements.
the organizations
change readiness.
A change management
governance structure is
established that is
responsible for ensuring
that change management
activities are being
carried out as planned.
A change
The project team
A change management
management
and end users may
culture exists to impact
culture is
not embrace the
the values, behaviors and
developed.
changes.
mindset of the project
team and end users.
The organizations The organization
Change readiness exists
change readiness
may not be ready
along the lines of the
is assessed and
for the changes
following categories.
considered.
being introduced
- Project management
through the new
risks
CRM
Project

Copyright IT Governance Institute 2003

[Link]/auditprograms

COBIT
Reference
PO3
PO4

AI6

PO6

AI3
AI5
AI6
DS4
DS7
DS8

168

Business
Objective

Risk

Control

implementation.

Copyright IT Governance Institute 2003

Comments/
Results/
W/P Ref.

management
expertise
Project
management
methodology
Program
management
Project tools
Project planning,
monitoring,
milestones
Project controls
Project scope and
approach

Vendor and
contractor
management and
deliverables

Project staffing

Project training

Project
communication
Technical risks

Hardware and
software design
methods

System
architecture
design methods

Networking
acceptance
procedures

Performance,
sizing and
availability
acceptance
procedures

Disaster
recovery and
business
continuity plans
Functional risks
Requirements
definition
methods
Business process
design methods
Data management

[Link]/auditprograms

COBIT
Reference
DS10
PO9
PO10

169

Business
Objective

Risk

Control

Comments/
Results/
W/P Ref.

COBIT
Reference

methods
and
usability
Legacy system
integration
methods
Program change
management
- Executive
sponsorship
Alignment with
other initiatives
Commitment
Executive Support
Sponsorship
- User acceptance
testing approach and
results
Conference room
pilot
Test environment
Test data
Test approach
Validation and
sign-offs
- Organizational risks
Organizational
alignment
Release integration
Business process
redesign
methods
Organizational
change
management
Business process
change
integration
approach
Skill gap analysis
and retraining
Documentation
- Operational and
production support
Problem resolution
and escalation
User support (help
desks, etc.)
Reliability

Copyright IT Governance Institute 2003

[Link]/auditprograms

170

Business
Objective

Risk

Control

Comments/
Results/
W/P Ref.

IT

Organizational
change addresses
the appropriate
areas such as
training,
organizational
restructure and
employee
readiness.

There may be lack


of readiness from
the organization to
accept and
implement CRM.
Organizational
alignment and
reorganization
may not be
considered.
Appropriate
training and timing
of training for
users may be
inappropriate.

Copyright IT Governance Institute 2003

production
support plans
Documentation
- End-user training
and pilot
Training program
Training schedules
and participants
Trainees feedback
The organizations
training needs have been
assessed.
Adequate training in line
with the organizations
requirements is planned.
CRM champions are
identified who will help
communicate the
benefits of CRM
throughout their
respective section of the
organization.
Changes in functional
responsibilities are
identified and plans exist
for any necessary
organization restructure.

COBIT
Reference

[Link]/auditprograms

PO7

171

Business
Objective
Communication
Organizational
change includes
constant education
and
communication
with employees
and sustained
stakeholder
management.

Risk

There may be a

A change vision is
understood.

Control

lack of
communication
with employees,
users and
customers.
Communication
may be provided
without context to
implementation
activities and
implications.
The business case
and benefits may
not be
communicated
clearly with the
message of
upcoming change.
Rumors of project
activities and
implications may
be apparent prior
to any formal
communication.
Users may be
apprehensive of
the changes that
will occur and do
not understand the
overall impact.
Users may reject
the changes.

Comments/
Results/
W/P Ref.

A communication
framework exists,
addressing information
needs at all levels.
Existing communication
channels are utilized to
leverage the
organizations
infrastructure.
Steps are identified to
encourage regular
dialogue with the user
community. Questions
are encouraged and
feedback solicited as
early as possible, and
throughout the
implementation.
User concerns are
addressed, to minimize
speculation.

A strategic vision is

COBIT
Reference
PO6
PO11

PO1

developed and
communicated within
the project team and the
organization. The vision
is comprehensive and
operational so
employees understand
the overall impact and
also how it will impact
their job function.
A compelling change
story exists for the
organization, functions
impacted and specific
employee roles.

Copyright IT Governance Institute 2003

[Link]/auditprograms

172

Business
Objective
Training
Employees and
customers receive
the proper
training.

Risk

Control

Training may not

Training is planned

teach workflow,
processes, internal
controls (e.g.,
approvals and
monitoring
controls), and new
roles and
responsibilities.
Problems with
integrity of
transactions,
quality of data,
timeliness of
input, lack of
consistency in
monitoring
controls, etc., may
exist.
Functional Roles, Skills and Security
The organizational Employees may
structure changes
reject the changes
are understood.
due to lack of
understanding.

Incorrect security
may exist.
Incompatible
duties may not be
segregated
properly.
Training may not
be built properly.
Employees may
not have the right

COBIT
Reference
PO7

sufficiently with
adequate time allotted
and training materials to
support the users.
Various teaching
methods are used to
promote retention of
information.
The training includes the
users role in the new
organization, the new
processes and their
responsibilities, in
addition to how to use
the system.

Roles and
responsibilities are
defined clearly.

Comments/
Results/
W/P Ref.

Copyright IT Governance Institute 2003

An organizational
reporting structure
exists.
Employees roles and
their corresponding
performance measures
are clearly
communicated.
Integrated workgroups
are used to develop the
new solution to ensure
a clear crossdepartmental
understanding.
Roles and
responsibilities are
developed early in the
implementation project
to ensure ample time
for security, training
and documentation of
new responsibilities.
Role-based application
security is built and
users have access only

[Link]/auditprograms

PO4
PO7

PO7
PO10
DS5
DS7

173

Business
Objective

Risk

Control

skills for their


new roles.

Management Information and Data Sharing


Management are
Employees may

able to obtain
reject new data
useful
sharing models.
management
Management
information and
information and
data from the

data may not be


CRM system.
useful.

Copyright IT Governance Institute 2003

Comments/
Results/
W/P Ref.

COBIT
Reference

to transactions and
information they need
for business purposes.
A segregation of duties
matrix ensures that
incompatible duties are
properly segregated.
Training is in place for
all functional roles and
include interaction with
other roles/departments
and the overall business
processes, workflows,
and corresponding
impacts.
Skill and training gaps
are identified early in
the implementation to
ensure that employees
can be properly trained.
Employees can earn
incentives for
maintaining accurate and
timely information in the
new systems.
An understanding of the
benefits to the
organization and to
specific groups of
employees from
maintaining accurately
and timely information is
communicated.

[Link]/auditprograms

DS10

174

Business
Objective

Risk

Business Process Change


Business processes Departments and
are changed to
processes may not
accommodate the
be realigned
new CRM
properly.
solution.
Employees may
not understand
cross-departmental
workflows and
business
processes;
therefore, they
need to be
understood by the
project team when
they are building
the new CRM
solution and also
by the end-user
departments who
will be using the
new system.
Reward Mechanisms
Performance
Poor behavior may
management
be encouraged,
techniques are
while good
used to drive the
behavior may be
right behavior.
discouraged.

Control

Comments/
Results/
W/P Ref.

Business practices and


daily operational
processes are reviewed,
in light of the CRM
capabilities, to align
them with CRM
objectives, streamline
the processes to become
more efficient and take
advantage of best
practices.

Performance metrics and

Copyright IT Governance Institute 2003

COBIT
Reference
PO4
M1

PO11

management techniques
to drive the right
behavior are used. These
include rewards for the
project team and end
users to encourage that
the system be
implemented on time, on
budget and according to
expectations, and then
adopted by end-user
departments.

[Link]/auditprograms

175

12.

Privacy Work Program

The following work program will help to manage the privacy risks surrounding customer
relationship management. Any person auditing, reviewing or advising on controls in a CRM
project will need to select tasks from the work program and to consider the key issues raised in
the IT Governance Institute publication Risks of Customer Relationship Management as part of
their preparation. The work program should not be used as a checklist of best practice, but as a
selection of examples of good practice that can be applied. By using the work programs blindly,
there is a risk of losing the confidence of the auditee and even of missing the largest risks in the
project, due to the peculiarities of each project. Therefore, work programs should be used as
guidance and specific knowledge of the organization and risks added to it.
Note: A business objective may be listed more than once because it has multiple risks and
corresponding control objectives. Note disclaimer.
Business
Objective
Access
Employees access
to personal and
sensitive
information within
the CRM system is
controlled
appropriately.

Employee access
to personal
information is
reviewed on a
regular basis.

Risk

Inappropriate
access to personal
information may
result in misuse of
the information
and
noncompliance
with the
organizations
privacy notice and
policies and
procedures.

Employees may
have inappropriate
access to personal
information due to
changes in job
status or
responsibilities.

Control

Comments/
Results/
W/P Ref.

Employees access to
personal information is
limited to the
information they need to
perform their job
functions.
A business case is
required before
employees receive
access to sensitive
information. For
example, all access
requests are reviewed
and formerly approved
(signature) before a user
is granted access to the
system.
Regular reviews of
employee access to
personal information
within the CRM system
are performed. The
reviews are designed to
determine whether
access levels should be
adjusted based on
employees current job
responsibilities.

Copyright IT Governance Institute 2003

[Link]/auditprograms

COBIT
Reference
PO2
DS5
DS11

PO7
DS5
DS11

176

Business
Objective

Risk

Sensitive personal
information
collected and
maintained in the
CRM system is
secured.

Personal

information may
be unsecured and
accessed by
inappropriate
parties, which
could result in
noncompliance
with the
organizations
privacy notice.
Physical controls
Unauthorized use
protect against
of customer
identity theft.
accounts may
result in
financially
unrecoverable
losses for the
organization.
Note: although
electronic access is
growing in
importance, access
to paper
documents by
improper
individuals still
poses a great risk
of identity theft.
The use of
Overuse of
government issued
identifiers issued
identifiers, such as
by national
social security
authorities
numbers, is
increases the risk
assessed and
of identity theft
limited.
and may make
customers
uncomfortable
with their privacy.

Control

Comments/
Results/
W/P Ref.

Strong authentication
and authorization
controls, firewalls,
operating system
controls, and encryption
standards secure
sensitive personal
information.

Printed outputs from the


CRM system (e.g.,
statements, forms,
applications) and
handwritten notes taken
by employees are
disposed of properly.
Alternatives include
locked garbage/recycling
can and outsourcing to
professional disposal
organizations.
Documents sent to
customers are reviewed
regularly to ensure that
they contain the
minimum information
necessary.
A risk assessment of
current practices is
performed and high-risk
areas addressed.
Policies around the use
of government issued
identifiers are created
and monitored.

Copyright IT Governance Institute 2003

[Link]/auditprograms

COBIT
Reference
DS5
DS11

DS9
DS12

PO8
PO9

177

Business
Objective
Best practice user
and caller
identification
methods are in
place.

Risk

Without

appropriate
authentication
procedures,
organizations may
provide personal
customer
information to
inappropriate
parties.
Regulatory Compliance
The organization
Organizations may
identifies the
be unaware of the
privacy legislation
privacy legislation
that it is subject to
they are subject to
for all the
and may not be
countries and
able to meet
territories in which
regulatory
it operates.
requirements.
The organization
implements
compliance
programs for
applicable privacy
legislation.

The organization
monitors
compliance with
privacy legislation
on an on-going
basis.

Control

Organizations that
do not implement
appropriate
compliance
programs may
misuse customer
information and be
subject to
regulatory action.
Lack of
monitoring may
lead to
noncompliance
with privacy
legislation.

Comments/
Results/
W/P Ref.

On a regular basis,
review changes to caller
authentication questions.
Caller authentication
questions are those
questions that the
customer can provide the
answer to, but would be
difficult for a stranger to
answer.

New privacy legislation


is monitored in the
countries in which the
organization operates on
a regular basis. Any new
legislation or updates to
existing legislation are
reviewed and forwarded
to the appropriate
individuals.
Compliance occurs in a
timely manner within the
appropriate divisions in
the organization.

Internal or external

Copyright IT Governance Institute 2003

parties conduct privacy


audits on a regular basis.

[Link]/auditprograms

COBIT
Reference
DS5
DS11

PO8

PO3
PO4
PO8

PO6
PO8
M1

178

Business
Objective

Risk

The business units


requesting system
changes and the
development team
responsible for
implementing
them may not be
aware of privacy
issues.
Without a formal
review of changes
that impact the use
of and access to
customer
information,
organizations may
use the
information
inappropriately.
Emerging privacy Unexpected
laws are monitored
privacy law
for their relevance
changes may
to systems.
require costly and
unplanned changes
to systems and
procedures.
Organizations may
not implement the
changes at a time
that is most costefficient.
All system
changes with a
material impact on
customer
information must
pass a privacy test.

Control

Comments/
Results/
W/P Ref.

The privacy
management team is a
part of the system
change methodology.
Working with the
development team, it
develops a test or set of
standards that must be
met before system
changes that may impact
customer privacy are
implemented.
The individual(s)
responsible for
reviewing changes are
independent of
marketing, IT, and
functional areas that
made the change request.
A formal method for
tracking relevant
emerging legislation is in
place.
Possible functional
changes are discussed
with IT to ensure that the
system changes are
made at the most
opportune time in the
development cycle.

Copyright IT Governance Institute 2003

[Link]/auditprograms

COBIT
Reference
PO6
AI6

PO4
PO8
AI6

179

Business
Objective

Risk

Privacy Organization and Management


The organization
Privacy issues may
has personnel
be present within
responsible for
the organization,
addressing privacy
and they may not
concerns.
be detected and
addressed due to
the absence of a
privacy group or a
chief privacy
officer who
focuses on privacy
regulations and
issues.
Noncompliance
with privacy
regulations may
exist.
The privacy group Personal
is involved with
information may
decisions that
not reflect
affect personal
implications of
information.
privacy policies
and applicable
privacy
legislation.
Noncompliance
with privacy
regulations may
exist.
Employees are
Employees may
made aware of the
use personal
organizations
information
privacy policies
inappropriately.
and procedures for Noncompliance
handing personal
with privacy
information.
regulations may
exist.

Control

Comments/
Results/
W/P Ref.

COBIT
Reference

A privacy organizational
structure is developed
and implemented at the
organization.
The structure is staffed
with individuals who are
knowledgeable about
privacy issues, provided
with authority to
implement the necessary
privacy procedures and
given appropriate
funding.

PO7

The privacy group is


consulted when
decisions are made that
involve personal
information.
Privacy policies and
applicable privacy
legislation are
considered when making
decisions affecting
personal information.

PO4
PO8

Privacy policies and


procedures are
developed and
distributed to all
employees.
Employees are trained
on privacy policies and
procedures.

PO7

Copyright IT Governance Institute 2003

[Link]/auditprograms

180

Business
Objective
Disclosure
The organizations
privacy notice
accurately
describes its
practices regarding
the collection of
personal
information.

Full and accurate


disclosure of the
organizations
privacy practices
is provided to
customers in a
privacy notice.

The organization
monitors
compliance with
its privacy notice.

Risk

Personal
information that is
collected from
consumers and
entered in the
CRM system may
not follow the
collection
practices outlined
in the
organizations
privacy notice.

Customers may
not want to
transact with an
organization if
they do not know
how their
information will
be used and
secured.

Activities may not


be performed in
accordance with
statements in the
privacy notice.

Control

Comments/
Results/
W/P Ref.

The method of collecting


personal information is
described fully and
accurately in the
organizations privacy
notice and its privacy
policies and procedures.
The privacy notice
addresses all personal
information whether
posted online, mailed to
customers or developed
for internal use only.
Any new practices or
uses of customer
information are reflected
in the privacy notice.
Industry best practices
and applicable privacy
regulations are reviewed,
and an inventory of
organization practices
conducted, to develop a
formal privacy notice.
The privacy notice is
communicated to
employees and
customers. The privacy
notice is updated each
year to ensure it aligns
with current business
practices. The updated
privacy notice is
communicated to all
employees and
customers annually.
Internal audit or
members of the privacy
group review
compliance with the
organizations privacy
notice on a regular basis.
Any new practices or
uses of customer
information are reflected
in the privacy notice.

Copyright IT Governance Institute 2003

[Link]/auditprograms

COBIT
Reference
PO6
PO8
DS5

PO8
AI4
DS5

M1
M4

181

Business
Objective

Risk

Training and Procedural Controls


CSRs are trained
CSRs may be
on the
improperly
organizations
trained; therefore,
privacy policies
they may provide
and procedures.
inaccurate or
misleading
information about
organization
privacy practices.
CSRs may provide
customer
information
inadvertently to
individuals
attempting to
compromise the
customers
identities.

CSRs process
customer optin/opt-out requests
in a timely and
accurate manner.

Customer
information may
be used
inappropriately.
Customer
dissatisfaction and
regulatory
oversight may
occur.

Control

Comments/
Results/
W/P Ref.

CSRs are recognized as


a critical point of contact
for customers around
many issues, including
privacy. Therefore, they
are provided with
comprehensive training
on:
- General privacy
topics
- Privacy risks
- The organizations
privacy guidelines
- Safeguards against
pretext calling
- Regulatory
requirements
- Opt-out procedures
- The right of
customers to access
their information;
methods to access
customer
information
- Scripts to be used
to provide a clear
and consistent
privacy message to
consumers
Opt-in/opt-out requests
are processed within a
period of time defined
by the organizations
privacy management.
Opt-in/opt-out requests
are reviewed
periodically to ensure
they are entered and
processed properly.

Copyright IT Governance Institute 2003

[Link]/auditprograms

COBIT
Reference
PO4
PO6
PO7
DS5
DS7

PO6
PO8
AI4

182

Business
Objective

Risk

Control

CSR behavior and


privacy messaging
are monitored.

Improper privacy
messaging may
occur, which may
contribute to
identity theft and
improper opt-out
procedures.

CSRs are informed that


their conversations may
be recorded and
monitored.
Conversations are
reviewed periodically to
ensure that appropriate
privacy messages are
given to customers and
that privacy procedures
are followed.

Copyright IT Governance Institute 2003

Comments/
Results/
W/P Ref.

[Link]/auditprograms

COBIT
Reference
PO6
PO7

183

You might also like