0% found this document useful (0 votes)
8 views181 pages

CRMWork Programs

Uploaded by

Fares Salman
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOC, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
8 views181 pages

CRMWork Programs

Uploaded by

Fares Salman
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOC, PDF, TXT or read online on Scribd

Information Systems Audit and Control

Association
[Link]

Systems Audit and Control Association & Foundation


Risks of Customer Relationship
Management
A Security, Control and Audit Approach

Audit Work Programs

Information Systems Audit and Control Association


With more than 28,000 members in more than 100 countries, the Information Systems Audit and Control Association
(ISACA®) ([Link]) is a recognized worldwide leader in IT governance, control, security and assurance.
Founded in 1969, ISACA sponsors international conferences, publishes the Information Systems Control Journal™,
develops international information systems auditing and control standards, and administers the globally respected
Certified Information Systems Auditor™ (CISA®) designation earned by more than 34,000 professionals since
inception, and Certified Information Security Manager (CISM™) designation, a groundbreaking credential earned by
5,000 professionals in its first two years.

IT Governance Institute™
The IT Governance Institute ([Link]) was established in 1998 to advance international thinking and standards in
directing and controlling an enterprise’s information technology. Effective IT governance helps ensure that IT supports
business goals, optimizes business investment in IT, and appropriately manages IT-related risks and opportunities. The
IT Governance Institute offers symposia, original research and case studies to assist enterprise leaders and boards of
directors in their IT governance responsibilities.

Purpose of Audit Programs and Internal Control Questionnaires


One of ISACA’s goals is to ensure that educational products support member and industry information needs.
Responding to member requests for useful audit programs, ISACA’s Education Board has released audit programs and
internal control questionnaires for member use through K-NET. These check lists were developed for a recently
released publication Risks of Customer Relationship Management A Security, Control and Audit Approach available
in the ISACA bookstore.

Control Objectives for Information and related Technology


Control Objectives for Information and related Technology (COBIT®) has been developed as a generally applicable and
accepted standard for good information technology (IT) security and control practices that provides a reference
framework for management, users, and IS audit, control and security practitioners. These audit work programs
reference key COBIT control objectives.

Disclaimer
ITGI, ISACA and the author of this document have designed the publication primarily as an educational resource for
control professionals. ISACA makes no claim that use of this product will assure a successful outcome. The publication
should not be considered inclusive of any proper procedures and tests or exclusive of other procedures and tests that are
reasonably directed to obtaining the same results. In determining the propriety of any specific procedure or test, the
controls professional should apply his/her own professional judgment to the specific control circumstances presented
by the particular systems or information technology environment. Users are cautioned not to consider these audit
programs and internal control questionnaires to be all-inclusive or applicable to all organizations. They should be used
as a starting point to build upon based on an organization’s constraints, policies, practices and operational environment.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 1


Table of Contents

Audit Work Programs


1. Sales Risks
2. Marketing Risks
3. Customer Interaction Center and Field Service Risks
4. Data Management Risks
5. Integration Risks
6. Channel Management and Integration Risks
7. Telecommunication Infrastructure Risks
8. Security Risks
9. Project Management Risks
10. Benefit Realization
11. Organizational Change Management
12. Privacy Risks

© Copyright IT Governance Institute 2003 [Link]/auditprograms 2


1. Sales Risks Work Program
The following work program will help address the sales risks within the organization. Those
auditing, reviewing or advising on controls in a CRM project will need to select tasks from the
work program and consider the key issues raised in the IT Governance Institute publication Risks
of Customer Relationship Management as part of their preparation. The work program should not
be used as a checklist of best practice, but as a selection of examples of good practice that can be
applied. By using the work programs blindly, there is a risk of losing the confidence of the
auditee and even of missing the largest risks in the project, due to the peculiarities of each project.
Therefore, work programs should be used as guidance with the specific knowledge of the
organization and risks added to them.

Note: A business objective may be listed more than once because it has multiple risks and
corresponding control objectives. Note disclaimer.

Business Risk Control Comments/ COBIT


Objective Results/ Reference
W/P Ref.
Sales Strategy and Management
The sales strategy  The organization  Market intelligence on PO1
plans for current may not current and future PO3
and future market appropriately market conditions is
conditions. anticipate and plan gathered and factored
for changes in into the development of
market conditions. sales strategies.
An integrated sales  Individual  Communication exists PO6
strategy is adopted departments within between all key PO11
throughout the the organization departments to ensure M1
entire organization. may pursue that all relevant input is
conflicting and incorporated into setting
counter-productive the strategic direction.
sales strategies.  The sales strategy is
communicated to all
sales personnel.
 The sales personnel are
enticed to act in
accordance with the
overall sales strategy via
sales metrics and
incentives.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 3


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
The organization  The organization  Procedures and PO6
develops long-term may pursue near- incentives for sales M1
and profitable sighted personnel focus on
customer relationships and building long-term
relationships. unprofitable relationships with
customers. customers.
 Management commits
appropriate resources to
the development of long-
term customer
relationships.
 Customer profitability is
measured and factored
into customer strategies.
Sales personnel are  Sales goals and  Both financial and PO7
motivated to targets may not be nonfinancial M1
achieve sales goals met. motivational techniques
and targets. and incentives are used
to reward and encourage
positive behavior that
aligns with the
organization’s sales
strategy.
 Realistic sales goals and
targets are created at the
organizational level and
also at an individual
level for each sales
person.
 Progress against sales
goals and targets is
measured on a periodic
basis and feedback is
provided on an
organizational level and
individual level.
Sales personnel  Information may  Participation in team- PO10
work together as a not be shared based selling is
team. across the sales encouraged within the
team. organization and is part
 Conflicting of each sales person’s
behavior within performance assessment
the team may criteria.
exist.
 There may be loss
of revenue.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 4


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Reward criteria for  Sales personnel  Sales personnel rewards PO7
sales personnel are actions may be are set to motivate
in alignment with focused on performance that is
the organization’s short-term goals consistent with corporate
overall strategic (e.g., quick sales objectives.
direction. sales) rather than  Staff actions are
long-term monitored to detect
strategic goals incongruent sales
(e.g., building activities.
customer
relationships and
long-term
profitable
customers).
Roles and  Sales personnel  The organizational PO4
responsibilities are may spend too structure is designed to
segregated to much time on provide a clear division
increase selling noncustomer- between sales personnel
efficiency. facing and support personnel.
administration,  The support personnel
reducing the are effectively utilized to
time spent reduce the amount of
engaged in sales- administrative time for
related activities. sales personnel.
The organizational  Sales resources  The sales PO1
structure reflects may be organizational structure
the segmentation misdirected. is designed to reflect
of key customer the segmentation of
market segments. key customer markets
and is continually
reevaluated as markets
evolve.
Information about  Interdepartmental  Sales personnel work PO11
customers is communication in teams that cross
disseminated may be limited departmental
effectively and may impact boundaries to facilitate
throughout the the knowledge sharing and
organization. organization’s effective
ability to share communication about
knowledge all critical interactions
across all for a given customer
customer account.
touchpoints.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 5


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Sales channels are  Channel  Sales channels have PO1
complementary. conflicts may clearly defined M1
lead to wasted boundaries.
resources and  All channel conflicts are
missed sales identified and resolved
opportunities. to gain efficiencies,
allow effective multi-
channel integration, and
increase revenue and
customer satisfaction.
 Performance metrics are
based on a balanced
scorecard (e.g.,
recognizing sales made
for other channels) so
that channels are
working together rather
than competing.
Succession  Lack of  A succession plan is in PO7
strategies minimize succession place for all key roles
the impact of planning could or responsibilities
employee turnover. result in a failure within the sales
to retain organization.
intellectual
capital and
customer
contacts in the
event of sales
personnel
turnover, which
is typically very
high.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 6


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Profitability is  Potential  Sales managers regularly PO6
regularly profitability and assess profitability by DS6
monitored. value may not be major accounts, M1
understood for territories, and
major accounts, locations/divisions
territories, within the organization
locations and and the results are
divisions. communicated to all
relevant sales personnel
and management.
 Reports on margin per
customer are a regular
activity to improve
profitability on low
margin customers (or to
cease trading with those
customers).
Account plans are  Inappropriate  Account plans are DS11
developed to targeting and developed, and they
determine sales budgets may be include profitability and
effort and made for key forecast information to
investment. accounts. assist in compiling
budgets for key account
targeting activities.
 Cost of targeting and
managing the account
should be measured.
Revenue and  Inaccurate  Revenue and product DS6
product forecasts revenue and forecasting information PO9
are updated in a product forecasts is regularly updated and
timely manner. may be made. reflects the latest market
trends.
 Significant deviations
from the original
forecast are investigated
to understand the impact.
Compensation  There may be an  The sales compensation PO11
plans are in inability to plan is designed to
alignment with motivate sales reward sales
corporate sales personnel to performance in
objectives. achieve alignment with corporate
corporate sales sales objectives.
goals.  The sales personnel are
motivated to achieve
corporate sales goals and
objectives.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 7


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
The sales force  Ineffective sales  Appropriate training PO7
receives skills may not be resources are available to PO10
appropriate addressed. ensure sales personnel
training to develop  Lack of have the necessary skills
their sales skills. understanding of to sell and build
sales strategy, profitable customer
goals and relationships.
objectives may not  Sales personnel are
be addressed. provided regular
 Lack of training.
understanding of  Sales curriculum is
organization developed in conjunction
background, with sales management
product on current topics,
information and policies, strategies, etc.
organization
policies may not
be addressed.
Sales performance  Difficulty in  Sales performance is M1
is actively identifying regularly monitored to AI6
monitored. performance assess sales personnel
trends or problems performance, trends for
may occur. market segments, sales
 There may be an personnel and key
inability to customer accounts.
respond quickly to  Key Performance
changing market Indicators (KPIs)
conditions. including margin
analysis and customer
satisfaction ratings, are
monitored to actively
manage the sales
process.
Identify and Qualify Opportunities

© Copyright IT Governance Institute 2003 [Link]/auditprograms 8


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Sales management  Ineffective sales  The performance of sales DS1
supports sales teams or wasted management is linked to
goals and resources in sales goals and
objectives. opportunities that objectives.
are not in  Sales personnel are
alignment with evaluated and
sales goals and remunerated against the
objectives may sales objectives.
occur.  Sales opportunities are
 Lost opportunities linked to the sales goals
may occur. and objectives to ensure
that they are in
alignment with sales
goals and objectives
before time and
resources are spent
pursing the
opportunities.
Markets and  Inappropriate  Key market segments PO11
customer segments market segments are analyzed and the DS1
are appropriately may be targeted. most profitable accounts DS8
targeted.  The sales identified.
organization may  Sales efforts are focused
not focus enough where they will have the
effort on the most greatest results.
profitable
accounts.
Accurate and  Uninformed  Market segment data DS7
complete market decisions about are collated in a central DS8
segment data are where to focus repository that is
available to sales sales efforts may accessible to relevant
personnel. be made. sales personnel.
 Market segment data
are accurate, complete
and updated on a
timely basis.
Sales channels are  Changing sales  Sales channels are M1
regularly evaluated channels may regularly re-evaluated
for viability. not be identified, to reflect changes in
which may result market conditions and
in lost sales customer demand.
opportunities.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 9


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Sales opportunities  Lost sales  All sales opportunities DS9
are recorded opportunities may are identified and DS11
completely, occur. recorded in a timely PO2
promptly and  Incomplete or manner so that the sales AI2
accurately. invalid sales team and management
opportunity are aware of all potential
information may opportunities.
be obtained.  Key dates are recorded
to prioritize more
immediate opportunities
and also ensure stale
opportunities are
removed from the list.
 Experienced sales
personnel identify
opportunities and make
assumptions on the basis
of the information
identified.
 A centralized
information repository is
used to assist in the
accurate identification of
sales opportunities.
 The CRM application
requires key fields to be
entered before allowing
the opportunity to be
saved.
 Data entry is reviewed
for reasonableness.
Only viable  Leads may be  Leads/potential sales PO2
opportunities are incorrectly opportunities are
pursued. classified and, analyzed prior to being
therefore, sales pursued.
opportunities
result in wasted
sales efforts.
Sales opportunities  Duplicate sales  Sales personnel search DS9
are only recorded opportunities may for existing opportunities
once. be recorded. before entering a new
 Distortion of the opportunity.
sales pipeline/  System controls identify
forecast may potential duplicate
occur. records.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 10


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
All sales  Valid sales  Management reviews PO6
opportunities are opportunities may dismissed sales PO9
appropriately not be pursued. opportunities for AI4
evaluated.  Invalid sales appropriateness, lessons
opportunities may learned, etc.
be pursued.  Formal criteria are used
 Lessons learned to analyze each
may not be opportunity and perform
captured to better an objective assessment
identify and of whether to pursue the
quality opportunity. The criteria
opportunities. should include a cost-
benefit analysis of the
opportunity.
 Opportunities are
assessed against the
formalized criteria
before being rejected or
accepted.
 Reasons are captured for
rejected opportunities.
 High-level deadlines and
action plans are
developed for qualified
sales opportunities.
All required  Information  Comprehensive sales DS9
information is necessary to opportunity data are PO2
available to assist qualify a sales stored within the CRM
with qualifying an opportunity may system.
opportunity. not be available.  Information is available
to qualify sales.
Customer history is  Customer  The CRM tracks DS3
used to predict buying history customer transaction
future buying may not be history and makes this
patterns. available to information readily
assist in available during
analyzing sales opportunity analysis.
opportunities

© Copyright IT Governance Institute 2003 [Link]/auditprograms 11


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Sales opportunities Sales opportunities  Experienced sales DS3
are accurately may not be personnel are PO9
qualified. accurately responsible for PO10
qualified or qualifying and
quantified. quantifying
 The risks inherent opportunities according
to opportunities to established guidelines.
may not be  The risks associated with
correctly assessed, opportunities are
resulting in identified, documented
incorrect decisions and factored into the
to pursue assessment of
opportunities. opportunities.
 Clear rules on qualifying
sales opportunities are
set down and all
employees are made
aware of them.
The value of sales  Sales personnel  Opportunity estimates DS11
opportunities is may inflate are reviewed AI1
accurately opportunity periodically and
recorded. values to meet validated.
personal  Estimated revenues are
objectives compared against actual
revenues on a periodic
basis. The comparison is
used to provide more
realistic revenue
estimates for future
opportunities.
Pursuing Qualified Opportunities and Submitting Proposals

© Copyright IT Governance Institute 2003 [Link]/auditprograms 12


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
The appropriate  Sales opportunities  The CRM system PO3
sales personnel may not be workflow routines or PO11
pursue sales distributed and manual procedures route AI4
opportunities in a pursued in a timely sales opportunities to the
timely manner. manner. correct sales people in a
 Sales opportunities timely manner.
may not be  Procedures are in place
assigned to the to ensure the timely
correct sales follow-up of all
personnel. opportunities.
 Staff review sales
opportunities in a timely
manner and
communicate any issues
with the routing of sales
opportunities.
 Realistic action plans are
assigned to
opportunities, with the
responsibilities clearly
defined.
Customer  Customer  Procedures are in place AI4
requirements are requirements for identifying, PO11
confirmed. may be verifying, clarifying and
misunderstood. modifying customer
requirements.
 Requirements are
reviewed to determine if
they can be met by the
organization.
 Procedures exist for
communicating and
resolving unfulfilled
requirements with the
customers.
 Once finalized, customer
requirements are
documented in the CRM
system for all sales
personnel to reference.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 13


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Customer  Unrealistic  There are systems and PO11
requirements are customer procedures in place to AI4
realistic. requirements validate customer DS3
may lead to the requirements (e.g.,
organization’s delivery dates,
inability to product/service needs)
deliver, resulting prior to customer
in an unsatisfied confirmation.
customer and
potentially the
loss of the sales
opportunity.
The customer is  Customers may  Products/services data DS8
offered the not be offered are available and are
correct/complete the correct accurate and complete.
product/service. product/service  Guidance is distributed
or the complete for helping sales
solution to their personnel identify
needs. solutions to meet the
customers’ needs.
Up-selling and  Opportunities to  Sales personnel are DS8
cross-selling up-sell/cross-sell trained in how to up-
opportunities are products/service sell/cross-sell
identified. s to the customer products/services.
may not be  The CRM application
identified or automatically suggests
pursued. potential up-sell/cross-
sell opportunities.
The sales pipeline  The sales pipeline  The CRM application PO1
is actively may not be provides tools/reports to DS13
monitored in a monitored help management M1
timely manner. actively. actively monitor the
 Reporting and sales pipeline.
analysis of the  Management actively
sales pipeline may monitors the sales
be unsatisfactory, pipelines and tracks
resulting in lost opportunities and the
sales action items by date to
opportunities. ensure timely follow-up.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 14


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Resources are  Senior sales  The time allocated to PO6
allocated to each personnel may pursuing sales DS13
opportunity spend too much opportunities is
according to its time on minor proportionate to the
size and opportunities. importance of the
importance to the  Junior sales account/opportunity.
organization. personnel may  Junior sales personnel
pursue major are assigned to minor
accounts. accounts. When junior
sales personnel work on
major accounts, a senior
sales person oversees all
account activities.
 Senior sales personnel
are allocated to major
accounts with smaller
accounts handled by
junior sales personnel,
automated self-service
sales functionality or
administrative sales
support personnel.
The request for  Customer  The RFP is reviewed to AI1
proposal (RFP) is requirements determine whether AI4
reviewed prior to may be customer requirements DS3
allocating misunderstood. are clearly defined and
resources to the can be met by the
preparation of a organization.
response.  Procedures are in place
for identifying,
verifying, clarifying
and modifying
customer requirements.
 Procedures exist for
communicating and
resolving unfulfilled
requirements with the
customers.
 Once finalized,
customer requirements
are documented in the
CRM system for all
sales personnel to
reference while
working on the RFP.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 15


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Nonstandard  Nonstandard  Procedures are in place AI4
quotes are quotes may be to guide the DS13
accurately inaccurately preparation and
prepared. prepared and authorization of
may not be nonstandard quotes.
authorized.  Management must
review and authorize
all nonstandard quotes
over a specified
threshold.
Access to create  Quotes may be  Access to create or DS5
quotes is restricted created or maintain quotes in the
to authorized amended by CRM/sales system is
personnel. unauthorized restricted to authorized
personnel that personnel.
could result in
an inappropriate
commitment to
sell goods or
services to
customers.
Quotes are valid  Quotes may be  The CRM application DS5
for a specified created without a requires the entry of an
period of time specified time effective time period
only. period. for all quotes.
Therefore, the
organization
may be obligated
to provide the
product/service
at a locked price
indefinitely into
the future which
could result in
sales at lower
than the
effective market
price.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 16


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Proposals are  Proposals may  Proposal creation AI2
created accurately be prepared procedures are DS7
and completely. incompletely or enforced and stipulate
inaccurately. the required
Therefore, they information for each
may not address type of proposal.
the customers’  Sales personnel are
needs. trained in the
preparation of
proposals.
 A quality review is
conducted of proposal
in which the proposals
are reviewed against
the original
requirements to ensure
that all the customer
requirements are met.
Proposals are  Proposals may  Proposal timelines are PO1
created in a timely not be prepared identified and followed AI1
manner. in a timely during the creation of
manner, proposals.
resulting in
forfeited sales
opportunities.
The proposal  The proposal  All proposals are PO8
addresses the may not respond subject to quality
customer’s to the RFP or the review by management
requirements. customer’s before being forwarded
requirements. to the customer to
ensure the original
customer requirements
are met.
Products/services  The key reasons  The CRM application PO6
are easily why customers can create comparisons AI1
distinguished from should buy from with competitor
competitors. the organization products.
may not be  The key value
clearly proposition for buyers
articulated, is clearly articulated
resulting in a and communicated to
lost sales sales personnel and
opportunity. customers.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 17


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Current product  Sales personnel  Pricing and product AI3
pricing and may not have information is stored in DS3
information is access to the a centralized CRM DS5
available to sales latest pricing and database and is easily
personnel. product accessed by all
information, authorized sales
which could personnel for use
result in during the sales
misleading process.
information
being supplied to
customers.
The benefits of  The cost of  A cost-benefit analysis PO6
winning the preparing the is prepared prior to DS1
proposal exceed proposal may creating proposals to
the cost of proposal exceed the profit ensure that the sales
preparation. of the sale. are profitable.
 There are mechanisms
to capture the full cost
of a bid/proposal
Proposals are  Inappropriate  Only authorized DS5
changed only by changes may be personnel can create or DS9
authorized made to modify proposals.
personnel. proposals, which  The CRM application
may result in populates pricing and
inconsistent and other critical information
inaccurate into the proposal
information template.
being presented  Proposals are reviewed
to customers. and approved by
management.

Negotiating Terms and Closing Sales

© Copyright IT Governance Institute 2003 [Link]/auditprograms 18


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Customer  Customer  Procedures and DS4
questions and questions or methodologies exist for DS8
objections are objections may answering customer AI1
answered in a not be questions and objections.
timely manner. addressed,  Sales personnel solicit
resulting in a customer feedback as
lost sales part of the sales process
opportunity. to identify customer
questions and objectives
not communicated.
 For lost customers there
is a process for capturing
reasons why the
customer ceased trading
with the organization.
Market research or other
independent
organizations are
employed to
interview/discuss issues
with the lost customer
(control for loss of major
accounts only).
Sales personnel are  Sales personnel  Sales personnel are DS7
trained in may not be provided with AI4
negotiating and familiar with appropriate training for
closing sales. corporate negotiating and closing
guidelines for sales.
negotiating and  Corporate guidelines
closing sales exist and are
transactions. communicated to sales
personnel for negotiating
and closing sales
transactions.
Inactive sales  Inactive  Procedures enforce the AI4
opportunities are opportunities close of inactive leads on M1
closed. may remain a regular basis.
open in the  Aged reports of
pipeline, opportunities sorted by
distorting the customer, salesperson,
sales forecast or territory, channel, etc.,
diverting sales are available both to
personnel’s clean up old prospects
attention from and to identify areas of
more profitable poor sales performance
sales leads. (i.e., where leads are not
being followed up).

© Copyright IT Governance Institute 2003 [Link]/auditprograms 19


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Contract terms and  Contract terms  Standard contract terms PO4
conditions are and conditions and conditions are DS1
drafted that are may be prepared and used by
clear and satisfy misunderstood sales personnel.
both parties. or disputed by  Legal personnel are
the customer. involved in any unusual
 Important contract negotiations.
contractual  Only qualified legal
clauses may be personnel make
omitted, thereby amendments to contracts.
exposing the
organization to
significant risk.
Processing Sales Orders
Sales orders are  Duplicate sales  Procedures include a DS5
only processed orders may be search for existing sales DS11
once. received and/or orders before the entry
processed. of a new sales order.
 The CRM system detects
potential duplicate sales
orders.
Sales orders are  Sales orders may  Sales orders are entered PO6
processed in a not be entered promptly when received. PO8
timely manner. into the system  Monitoring controls are M1
in a timely in place to analyze the
manner, timeliness of order
resulting in processing.
delays for the
customer.
Orders are created  Sales orders may  The CRM system AI1
with reference to a not reference the automatically links the AI4
quote (if corresponding quotes to the sales order,
applicable). quotes, which or provides a list of
could result in possible quotes from
pricing errors or which to reference the
deviations. sales order.
 Lost revenue or  Procedures govern the
customer creation of sales orders
dissatisfaction based on quotes,
may occur. whenever possible.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 20


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Phone orders are  Phone orders  The system DS11
routed to the may not be automatically routes
appropriate routed to the the caller to the
personnel. appropriate appropriate sales
personnel. personnel or
 Lost revenue or appropriate manual
customer procedures exist.
dissatisfaction
may occur.
Customers’ calls  Customer calls  Call wait times are M1
are answered may not be actively monitored and DS8
promptly. answered and appropriate remedial
responded to action taken if wait
promptly. times exceed a
 Lost business or predetermined
customer maximum response
dissatisfaction time.
may occur.
Orders are  Incomplete or  The sales order DS9
processed inaccurate orders processing system is
accurately and may occur. configured to enforce
completely.  Lost revenue or the entry of all
customer required fields
dissatisfaction necessary to
may occur. completely process the
sales order.
Open orders and  Open orders and  Open orders and M1
orders in error are orders that have orders with errors are
corrected in a errors may not monitored actively by
timely manner. process in a sales personnel.
timely manner.
 Lost sales and
customer
dissatisfaction
may occur.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 21


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Order pricing,  Orders may be  The CRM application AI2
discounts and processed with controls customer DS5
payment terms are unauthorized credit limits. DS11
approved. pricing,  Changes to pricing, M1
discounts or discounts and payment
terms of terms require
payment. management approval.
 Prices may only be
changed within pre-
established limits.
Management must
approve all changes
outside these limits.
 Where ERP and CRM
systems interact there
is a single process for
determining the price
(i.e., either the ERP
system or the CRM
system is used for
determining the price).
 Regular monitoring of
prices is carried out by
review of pricing
master data and actual
margin achieved per
order, to identify
possible pricing errors
(or salesperson
override).
Customer orders  A customer’s  The CRM/sales order AI2
are controlled by credit limit may system validates that DS5
credit limits. not be checked the customer credit
prior to order limit has not been
processing exceeded prior to
which may processing the order.
expose the  Only authorized
organization to personnel can override
unnecessary risk credit limits.
of bad debts.
Processing Internet Sales Orders

© Copyright IT Governance Institute 2003 [Link]/auditprograms 22


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Customers’  The privacy of  A formal privacy PO6
personal customer policy governs the PO8
information is information treatment of customer DS11
protected. collected on the personal information.
web site may not  The privacy policy is
be safeguarded, communicated to all
resulting in a customers via the web
loss of customer site and has been
confidence. independently certified
(e.g., BetterWeb, CPA
WebTrust).
Internet customers  Internet  The system is AI2
are differentiated customers may customized to identify AI4
to enable unique not be identified Internet users and
needs to be met. uniquely. provide a tailored
environment for each
customer (e.g., access
to order history,
favorite links).
 Internet procedures are
linked into the core
business to allow
customers the ability
to choose their channel
preference for returns,
future sales, sales
support, customer
service, etc.
Internet customers  Web site  Password standards DS5
are authenticated. security may not and controls are
provide adequate enforced by the system
online security. (e.g., minimum
 Compromised password lengths,
customer disallowed common
confidentiality passwords).
and fraudulent  Each Internet session
transactions may timeouts after a
occur. minimum period of
inactivity.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 23


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
The web servers  Service delays  Server capacity is DS1
can accommodate and interruptions appropriate for M1
the anticipated may occur. maximum anticipated
volume of traffic. customer volumes.
 Server capacity is
constantly monitored
to identify potential
problems before they
occur.
Internet sales  The  Use of the web site is M1
initiatives are effectiveness of monitored to assess its AI4
effective at Internet sales effectiveness (e.g., AI6
generating sales initiatives may abandon rates, repeat DS8
with existing not be measured. customers).
customers and for  The Internet  Feedback is solicited
obtaining new sales channel from customers about
customers. may not be used the web site.
to its full  Web site improvement
potential. recommendations are
prioritized regarding
the impact on sales,
cost-benefit, etc.
 Improvement
recommendations are
incorporated into the
web site to make it a
more effective sales
channel.
The web site  Insufficient and  Content management DS9
contains inaccurate software is used to AI5
comprehensive and information ensure that web site
up-to-date about products product and service
information on and services may data are accurate,
products/services. be available on complete, current and
the web site. comprehensive.
 Page links may  All web site links and
fail, resulting in operations are tested
customer prior to
abandonment. implementation for
functionality and
stickiness.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 24


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Web site  Web site  Customer credit card DS5
transactions are transactions may details are verified DS11
valid. be not verified with banks; additional
or authorized. fraud prevention
 Fraudulent processes are in place.
transactions may
be processed.
Internet orders are  Internet order  The CRM application DS5
processed information may requires key fields to M1
accurately and not be complete be entered before the
completely. or accurate. order can be saved.
 Field validations are
performed on key
fields.
 Reports are monitored
to identify incomplete
transfer of data from
the web site front end
to the order processing
system.
 Order confirmations
are sent to customers.
Only valid sales  Unauthorized  User authentication DS5
orders are individuals may procedures exist to
processed via the process Internet validate the identity of
Internet. orders. customers.
 Customer payment and
address data are
validated.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 25


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Sales orders are  Sales orders may  Contact information is DS5
processed not be processed provided in the event DS10
completely and due to a lost the customer needs to
accurately. connection call about a processing
during an online error.
session.  Shopping cart
 Sales order data information is
may be maintained to ensure
incomplete, the sales order is
resulting in completely and
delays in accurately captured.
shipping and  The Internet order
customer entry system requires
dissatisfaction. that all key fields be
entered before the
order can be
submitted.
 Customers are notified
if any required data are
missing.
Customer credit  Customer credit  Customer credit card DS5
card data are card data may information is PO8
secured from not be protected during
unauthorized use. encrypted, which transmission from the
could result in web site by encryption
credit card technology (e.g., 128
information bit SSL encryption).
being  Credit card data are
compromised. stored in a secured
encrypted database
within the organization
and access is restricted
to authorized
personnel only.
Sales order data are  Delays may  The web site and CRM AI1
completely and occur in application are PO8
accurately shipping and integrated. DS3
interfaced to back- invoicing,  Front- and back-office
office systems. increasing the systems are integrated.
potential for  Interface monitoring
cancelled orders controls ensure the
and customer accuracy and
dissatisfaction. completeness of all
data transfers between
systems.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 26


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Sales orders are  Sales orders may  Sales orders via the DS3
confirmed with the not be Internet are confirmed M1
customer. confirmed, and a unique order
which might number is provided to
result in sales the customer, which
order errors can be used for
remaining tracking the order
undetected, status.
increasing the  Management monitors
potential cost of order confirmations
returns. and open orders.
Stock availability  The systems  The availability of DS8
is confirmed with may not provide stock to complete the DS11
the customer. customers with order is provided
real-time online to the customer
inventory prior to placing the
availability data, order.
which could lead  Customers are
to customer automatically notified
dissatisfaction via e-mail or phone
and loss of when unexpected
repeat business. stock shortages or
delays occur.
Customer sessions 
If customers do  The system terminates DS5
are terminated after not log out the the customer’s active
they have logged session, the session when they
out. session may select the log out
remain active option.
after they have  The browser back key
left their cannot be used to gain
terminal. access to a terminated
 Unauthorized or session.
fraudulent
transactions may
occur.
Processing Telephone Sales/Telesales

© Copyright IT Governance Institute 2003 [Link]/auditprograms 27


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Telesales strategies  Telesales  Telesales strategies are AI4
are properly strategies may formalized, clearly PO1
communicated to not be properly documented, and
sales personnel. communicated communicated to all
to sales sales personnel.
personnel.  Strategies include
identifying the
marketing activity
(e.g., qualifying
opportunities, setting
appointments,
gathering information,
closing the sale),
identifying how these
activities are presently
handled, and how
telesales can achieve
the company’s sales
goals.
Telesales activities  Telesales  Management monitors M1
are controlled and activities may telesales activities. DS11
monitored to not be monitored  Regularly,
ensure goals are properly and, management evaluates
met. therefore, sales and makes adjustments
goals are not to telesales activities to
met. ensure telesales goals
are met.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 28


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Telesales personnel  Telesales  The company trains and DS7
are properly personnel may routinely monitors the M1
trained and their not be activities of telesales
activities adequately personnel. Training may
monitored to trained. As a include:
ensure their result, potential - Use of sales
conduct and sales may be lost literature
performance best or optimum - Responses to
represent the customer common questions /
company in satisfaction may objections
meeting its not be achieved. - Use of call scripts
telesales - Increased emphasis
objectives. on listening
- Building rapport
- Understanding of
products and/or
services and how
they best fit the
customer’s buying
motives (e.g.,
financial benefits,
security,
convenience, sex
appeal, pleasure, and
acceptance).
 Monitoring activities
may include:
- Periodic review of
sales calls
- Comparing actual to
budgeted goals

© Copyright IT Governance Institute 2003 [Link]/auditprograms 29


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Sales personnel  Call goals are  Goals are identified for PO1
identify and not identified, each call. DS1
manage their which may result  Telesales personnel
objectives and in nonproductive identify the marketing
goals for each call. sales activity. context and approach
of the telephone call
and what they want to
accomplish (e.g.,
initial contact or
closing sale). This will
then determine what
they have to learn
about the prospect or
his/her company
before the call.
 Sales personnel may
identify:
- Entity (e.g.,
individual or
business)
- Decision maker(s)
- Questions to ask to
understand buyer’s
needs, desires,
concerns, problems
- Accuracy of
information that
may be presented
- Previous inquires
about products/
services
Customers are  Telesales  The CRM application PO9
contacted only personnel may is used to accurately DS5
once per sales inadvertently track and close
opportunity. contact a opportunities.
customer that  The CRM application
has already been prevents multiple
contacted or telesales personnel
closed. from contacting the
same prospects by a
lock-out feature on the
record.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 30


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Telesales personnel  Call worksheets  Sales personnel utilize PO9
utilize electronic may not be electronic “call M1
“call worksheets” utilized to track worksheets” to track and
to ensure proper telesales monitor telesales
information and activities. activities. Call
gathering of worksheets may include:
information is - Opening (e.g., greeting/
performed for each introduction)
prospect. - Decision-makers and
influencers
- Buyer’s needs
/response to needs
- Product position (e.g.,
position features and
benefits to match
buyer’s needs)
- Call notes
- Closing activity (e.g.,
ask for order, request
next step, action
step, commitment).
Telesales personnel  Untrained or  The smart scripting DS7
interact with inexperienced functionality within DS8
customers in a telesales the CRM application is
knowledgeable and personnel may used to enable the
consistent manner. be inconsistent telesales personnel to
or unknowledge- interact with
able. As a result, customers in a
customer knowledgeable and
interactions may consistent way. Smart
not be scripting generates
appropriate. questions to ask
callers, based upon
their answers to
previous questions and
customer attributes.
Environment is  Customers may  The company PO6
free from excessive not be able to maintains a productive
noise to ensure hear or working environment
communication understand for its telesales
between the telesales personnel and the
customers and personnel. environment is free
telesales personnel from excessive noise.
is clear.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 31


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Telesales personnel  Customer needs Telesales personnel DS7
are trained to may not be are periodically trained PO7
gather and analyze addressed to gather and analyze
customer /identified fully, customer information
information to resulting in loss to determine needs and
ensure customer’s sales. interests.
needs/wants are  Training activities may
met successfully. include:
- Developing
effective listening
skills (e.g.,
listening for buying
motives that may
not arise in the
course of formal
questioning)
- Probing more
detailed questions
(e.g., open-ended
questions for a full,
expository answer)
- Utilizing available
data (e.g.,
information
gathered on
application forms,
requests for
information)
Telesales personnel  Product/service  The company provides DS7
are trained to solution may not periodic training to its PO7
ensure product/ fit customer’s telesales personnel on its
service fits needs/wants. products/services,
customer’s needs. identifying potential
needs/wants they may
satisfy.
 Changes to an
enterprise’s products/
service are formally
communicated,
identifying the value that
can be obtained and
potential needs that can
be filled.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 32


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Telesales personnel  Telesales  Telesales personnel DS5
are given personnel may have access to critical
appropriate access not have access customer information
to customer to critical to allow them to
information. customer review and analyze
information. customer information.
Note: Please refer to the Processing Sales Order section for additional telesales order controls and the
Customer Service section for additional controls for managing telesales personnel within the interaction
center.
Delivering Goods to the Proper Location at the Right Time
Goods are  Deliveries may  Orders are validated AI2
delivered to the be created which for completeness DS1
proper location at do not refer to during order handling
the right time. approved sales before they are passed
orders, therefore to delivery.
fraudulent  Deliveries completed
deliveries could before the end of the
occur. period are posted to
update the inventory
balances.
Goods are  Backorders and  Management DS1
delivered to the incomplete periodically reviews DS10
proper location at orders may not the list of backorders
the right time. be processed and releases them for
when items processing.
become
available,
resulting in lost
sales and
customer
dissatisfaction.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 33


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Goods are  Deliveries may  Goods can be posted for AI2
delivered to the not be processed a delivery only if the DS9
proper location at in the correct following prerequisites DS11
the right time. accounting are fulfilled:
period if - The data in the
procedures are delivery must be
not established complete.
to verify cutoff - Picking must have
of shipments. been completed for
This would all items in the
result in delivery.
misstated  Once a delivery has been
inventory and processed, the following
cost of goods functions occur:
sold, and a - Stock quantities are
failure to invoice updated.
the customer for - Balance sheet
the sale. accounts are
evaluated and
updated.
- Requirements are
reduced.
- The invoice is
processed.
Goods are  Access to  Access to delivery DS5
delivered to the delivery functions is restricted
proper location at processing to delivery personnel.
the right time. functions may
not be restricted
to users in the
shipping
department, to
prevent
unauthorized
deliveries and
unauthorized
changes.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 34


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Goods are  Approved orders  All approved orders DS11
delivered to the may not be are processed for
proper location at delivered, delivery regularly.
the right time. resulting in
financial loss to
the company,
dissatisfied
customers and
understated
revenues and
receivables.
Goods are  Rejected  Rejected and DS10
delivered to the deliveries may incomplete deliveries
proper location at not be isolated, are reviewed regularly
the right time. analyzed and and corrected.
corrected in a
timely manner.
Goods are  Deliveries may  Customers who are DS10
delivered to the be processed for considered a risk for
proper location at customers who payment are blocked
the right time. represent a credit for deliveries and
risk to the informed promptly
company. that the sales order and
 Customer may delivery cannot be
not be advised processed. By clearly
promptly that communicating these
orders and policies, any confusion
deliveries will by the customer is
not be processed avoided.
for them due to
their credit risk.
Goods are  Ordered goods  A formal process exists PO6
delivered to the may not be for picking and M1
proper location at picked and preparing orders for DS7
the right time. packed for shipment. DS10
shipment  Procedures for picking DS13
properly, and preparing orders for
resulting in shipment are
shipping delays. documented.
 Shipping personnel are
properly trained on all
loading procedures.
 Specifications and
quantity of products
retrieved from storage is
reconciled back to the
authorized customer

© Copyright IT Governance Institute 2003 [Link]/auditprograms 35


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
order or delivery
documentation prior to
loading.
 Order picking is
undertaken to ensure that
stock is picked on a
FIFO basis.
 Goods dispatched
document is issued for
all deliveries.
 Goods dispatched
documents are pre-
numbered and
sequentially controlled.
 Order documents are
pre-numbered and
missing documents are
investigated promptly.
 Key performance
indicators are:
- Order accuracy
- Percentage pick
accuracy
- Number of expedited
or emergency orders
by cause
Goods are  Shipments may  A formal process exists PO6
delivered to the not be accurate. for verifying loads for
proper location at shipment (correct goods/
the right time. quantities and no
damage/mislabeling).
 Packing materials,
containers and
procedures give
consideration to the
nature of the product and
method of delivery to
safeguard products.
 Goods are checked for
accuracy, damage and
proper labeling/packing
prior to loading.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 36


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Goods are  Carriers may not  Formal processes exist PO6
delivered to the deliver goods to for coordinating carrier PO11
proper location at customers on transport for customer
the right time. time. shipments.
 All transport carriers are
evaluated for financial
stability, service quality
and proper insurance.
 The selection of
approved carriers also
involves personnel
independent of the
logistics function.
 Customer information
and specific
requirements are
communicated to
external carriers to
ensure timely and
accurate delivery.
 Key performance
indicators are:
- Transit cycle times
by mode, route and
carrier
- Percentage of
shipments by
individual carrier
- Percentage of
shipments by mode
- Transit time
- Dollar amount by
carrier
Goods are  Shipping  Formal processes exist AI2
delivered to the documentation for preparing/processing PO4
proper location at may not be shipping documentation. DS7
the right time. accurate.  Documented procedures DS13
for outbound logistics
are in place.
 Personnel are trained
properly on procedures.
 All delivery notes are
signed and time-stamped
by customers or third-
party carriers.
 Controls are in place to
ensure proper
preparation, approval

© Copyright IT Governance Institute 2003 [Link]/auditprograms 37


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
and accountability over
bills of lading, air bills,
manifests or the
equivalent.
 Final shipping
documents drive
customer billings as pick
tickets were updated
during loading.
 Shipping documents are
cross-referenced
properly to the document
authorizing the
shipment.
 Controls ensure goods
are shipped in
accordance with agreed
delivery term.
 Appropriate procedures
exist for obtaining and
filing signed documents
and recording of seals on
all loaded trucks.
 Key performance
indicators are:
- Undeliverable
shipments by cause
- Billing disputes by
customer/cause/
location
- Delivery document
accuracy percentage
- Credit memos by
cause
Goods are  Foreign or other  Formal processes exist DS13
delivered to the unique customer for preparing/processing AI1
proper location at shipments may documentation for PO6
the right time. not be delivered foreign/other unique
to the customer customer shipments.
on time to the  Export arrangements and
right location. requirements are
separately determined
and take into account
methods of
transportation, packing
requirements, etc.
 Export documentation
clearly defines when title

© Copyright IT Governance Institute 2003 [Link]/auditprograms 38


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
passes and when
responsibility for
insurance passes to the
importer.
 Procedures are adequate
to ensure that all
necessary documents are
forwarded to customers
so that they are received
before goods arrive.
 Customs classifications
for materials are
accurately defined for
customs purposes.
 Applicable export
permits are obtained for
all shipments as
necessary.
 Shipments classified as
containing hazardous
materials have required
transport/safety
documentation.
 Controls in place for
return of signed
manifests documenting
final disposition on
hazardous loads.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 39


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Goods are  Customer  Formal processes exist DS13
delivered to the shipments may for tracking products PO4
proper location at not be tracked shipped to customers.
the right time. properly.  A reliable system is in
place for monitoring
customer shipments and
taking corrective action
promptly.
 An emergency delivery
process is in place and
understood.
 Key performance
indicators include:
- Redeliveries
- Order receipts
- Order refusals
- Delivery promised
dates to actual
- Inquiry response
time by average
minutes/hours
- Perfect orders
received or delivered
on time
- Customer
complaints (total or
percentage)
Goods are  Customers may  Formal processes exist PO8
delivered to the not be for addressing goods M1
proper location at communicated damaged, lost or stolen DS13
the right time. with promptly in transit.
about goods  Procedures are in place
damaged, lost or to ensure freight claims
stolen in transit. are promptly filed,
followed up and
collected.
 Allowances or returns
for products damaged,
lost or stolen in transmit
handled within
company’s policy
parameters.
 Management reviews
and follows up on
reports of customer
returns due to incorrect
goods being delivered or
billing disputes relating

© Copyright IT Governance Institute 2003 [Link]/auditprograms 40


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
to products delivered
that were inferior quality
or damaged.
 Key performance
indicators:
- Damages/loss as a
percentage of sales
- Shipments with
claims percent/
carrier claim ratio
- Claims handling
cycle time days
- Damage-free
delivery
performance
- Total damage costs
Post Sales—Handling Customer Sales Questions
Sales inquiries are  Sales inquiries  Sales personnel DS1
routed to the may be maintain regular
correct personnel misrouted, contact with
for response. resulting in customers.
customer  Inquiries are routed
dissatisfaction to the correct inside
because of or outside sales
response delays. person for
resolution.
Customer requests  Customer  Customer requests DS1
are immediately requests may not are auto-answered,
acknowledged, be when feasible.
enhancing acknowledged in  Acknowledgments
customers’ a timely manner. or confirmations
experience and are sent to
satisfaction. customers to
indicate that their
request was
received and the
expected response
time is indicated.
 Customers are
provided self-
service
functionality to
handle the majority
of sales inquiries.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 41


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Customer sales  Customer sales  Sales personnel are DS7
information is information may trained
completely and be entered appropriately on
accurately input. inconsistently or data entry
incompletely. requirements and
the intended uses
for fields.
 Key fields are
required to be
entered.
 When possible,
pick lists and field
masks are used to
validate and secure
data entry (i.e., pick
lists for titles,
preferences, states,
field masks for
phone numbers,
social security
numbers, credit
card numbers).
Sales inquiries are  Requests may by  Sales personnel (or AI4
routed categorized customers via web
appropriately and inconsistently, forms/e-mail) are
reports on requests resulting in required to select a
are accurate. inaccurate request type from a
routing and/or pick list to indicate
reporting. the type of inquiry.
Inquiries are routed  Inquiries may be  Sales personnel are DS7
appropriately and categorized trained on the
reports on requests inconsistently, proper usage of the
are accurate. resulting in different request
untimely types.
resolution and  Formal procedures
inaccurate exist for processing
reporting. requests.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 42


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Adequate  Insufficient detail  Sales personnel are DS7
information is as to nature of the appropriately
captured about request may be trained on the
customer inquiries. captured in initial importance of
contact with understanding and
customer. documenting the
request with
sufficient detail.
 A description field
is required when
documenting a
request.
Inquiries are  Inquiries may be  Sales personnel are DS7
appropriately prioritized trained AI1
prioritized, so that inappropriately. appropriately on M1
they are addressed the meaning of
in an appropriate service request
manner. severity codes.
 The severity field is
required and given
an appropriate
default.
 Management
monitors the
number of
outstanding service
requests by severity
to help determine
the appropriate use
of severity codes.
Inquiry resolution  Sales personnel  The inquiry DS9
information is may not provide resolution field
captured. complete should be
descriptions of configured as
how issues are required to ensure
resolved. proper
Therefore, documentation.
request
resolution
information is
not available to
answer
subsequent
questions.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 43


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Inquiries and  Inquiries and  Procedures are DS13
requests are requests may not defined on how and M1
appropriately be closed when to
closed. properly; appropriately close
therefore, the a request or
requests remain inquiry.
open on the  Monitoring
system and controls exist to
continue to be monitor open
worked on by requests or
other employees. inquiries to ensure
that they are closed
in a timely manner.
Customers are  Request  Customers are DS1
satisfied with the resolutions may surveyed
request resolution. be closed periodically to
without the determine
customer being satisfaction. The
satisfied with the surveys include
response. feedback on system
accessibility, front-
line
professionalism
and overall
satisfaction with
the way their calls
are handled.
 When customers’
e-mail addresses
are available, they
are e-mailed a
confirmation that
their request has
been closed and the
customers have the
ability to provide
feedback. Mail
confirmation is sent
if e-mail is
unavailable.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 44


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Customer feedback  Sales personnel  Management AI5
is quantified and may not be notifies appropriate DS1
analyzed on a effective in individuals that a M1
proactive basis. handling complaint was filed
customer for their area of
inquiries. responsibility.
 Management and
the responsible
individual
determine and
implement an
action plan to avoid
the noted complaint
in the future.
 The action plans
are documented
and monitored.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 45


2. Marketing Risks Work Program
The following work program will help manage marketing risks within the organization. Those
auditing, reviewing or advising on controls in a CRM project need to select tasks from the work
program and consider the key issues raised in the IT Governance Institute publication Risks of
Customer Relationship Management as part of their preparation. The work program should not be
used as a checklist of best practice, but as a selection of examples of good practice that can be
applied. By using the work programs blindly, there is a risk of losing the confidence of the
auditee and even of missing the largest risks in the project, due to the peculiarities of each project.
Therefore, work programs should be used as guidance and specific knowledge of the organization
and risks should be added to them.

Note: A business objective may be listed more than once because it has multiple risks and
corresponding control objectives. Note disclaimer.

Business Risk Control Comments/ COBIT


Objective Results/ Reference
W/P Ref.
Marketing Strategy
New product and  New product and  Product offerings are PO1
services offerings service offerings clearly defined and AI4
are defined may be defined planned. The AI6
accurately and inaccurately or information includes,
clearly. unclearly, at a minimum:
resulting in - Target audience
diminished sales - Expected revenue
opportunities or stream
dissatisfied - Time period
customers. - Cost
 A process is in place
for gathering and
documenting the
technical specifications
and intended uses and
functional information
for products and
services, including, at a
minimum:
- Product shelf life
- Product wear-out
rates
- Problems that may
result from
improper usage or
consumption

© Copyright IT Governance Institute 2003 [Link]/auditprograms 46


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
New product and  Organization  A process is in place DS3
service offerings may not meet for the continual
are continually sales and generation and review
identified. marketing goals of new product and
because new service ideas.
product and
service offering
possibilities are
not identified.
Products are  Product or  As part of the product DS1
available to ensure retailer development DS3
a successful new marketing processes, procedures
launch. campaigns may ensure that products or
not consider services can be
production supplied following a
schedules or product or service
inventory levels launch.
resulting in
delays in product
delivery.
 Contractual
defaults or
customer
dissatisfaction
may result.
Product pricing is  Pricing may not  Market information PO10
commensurate with be appropriate and research aids in
market conditions for product or determining product
and product service pricing.
positioning. positioning,
resulting in a
loss of sales.
Access is properly  Pricing lists,  Only authorized users DS5
restricted. marketing have access to
templates and create/maintain pricing
literature may be lists, marketing
altered without templates, literature,
authorization. etc.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 47


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Product  New product or Project managers are M1
effectiveness is service offerings made accountable for
monitored. may not be delivering a
measured, commercially
resulting in the successful product.
inability to  Customer and
determine the competitive reaction to
success of the the new product is
new product or monitored.
service.  Planned vs. actual
financial results are
monitored and reported
to management.
 A product-costing
model is used to assess
product costs,
including all ancillary
costs related to product
introduction as well as
development.
Marketing Strategy Research and Execution (Market Understanding and Analysis)
Market data are  Invalid market  Market data are DS11
valid and from a data may lead to validated and research
reliable source. false sources are
assumptions investigated for
regarding market reputation and
conditions. reliability.
A complete  An incomplete  Market driving AI1
understanding of understanding conditions have been
market conditions and analysis of identified.
exists within the market  Analytical procedures
organization. conditions may are used to measure
lead to and monitor changing
ineffective or conditions.
inappropriate
market strategy
and sales
penetration.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 48


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Competitor product  The organization  Regular comparison of DS3
and service may lose a product and service PO3
offerings are competitive offerings is performed
identified and their advantage by not against identified
impact on the identifying a competitors, and
organization’s own competitor’s improvements are
product and service changes in its made to product and
range is fully product and service offerings, as
assessed. service appropriate.
offerings.
Customer feedback  Inaccurate 
Procedures exist to AI4
and survey customer ensure that marketing AI5
responses are feedback and surveys and customer PO10
accurate. responses to feedback are accurate
marketing and that questions are
surveys may not leading (i.e. forcing
lead to or encouraging the
inaccurate customer to answer a
understanding of certain way).
customer wants  Customer feedback is
and needs. incorporated into the
processes to improve
products and services.
Regulatory barriers  Regulatory  Regulatory barriers are PO8
relevant to entering barriers may identified and assessed
a market are delay or prevent by marketing personnel
clearly understood. entry into and are taken into
markets consideration when
significantly. working with research
and development for
new products and
services.
Marketing Strategy Research and Execution (Market Segmentation)
Customer needs  Information about  Marketing surveys are DS1
and wants are targeted used to understand
understood consumers may be customer needs and
completely. poor or wants. These surveys
unavailable. contain information such
 Customer as:
expectations may - Demographics
not be understood - Preference
properly. - Buying habits

© Copyright IT Governance Institute 2003 [Link]/auditprograms 49


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Market segments  Unclear or  Marketing personnel DS1
are clearly and outdated market periodically evaluate
properly defined. segment existing market segment
definitions may definitions.
lead to inefficient  Segment definitions are
campaigns and updated periodically as
target marketing. the market changes.
Marketing  Marketing dollars  Marketing prioritizes PO5
segments are may be spent on market segments based
prioritized and market segments on the organization’s
campaigns are that do not need strategic plan, highest
appropriately incentives return, growth potential,
targeted to provided or that competitive advantage,
maximize return on are not part of etc.
investment for management’s  Campaigns are
marketing strategic plan for prioritized and targeted
expenditures. targeting toward the most
customers. profitable market
 Fewer sales leads segments.
may be generated
as a result of
inappropriate
campaign
targeting.
Marketing Strategy Research and Execution (Marketing Campaign Planning and Execution)
Efficient  Inefficient and  Campaign management AI1
campaigns are ineffective software and processes
conducted campaigns, are used to effectively
leveraging which do not plan, execute, track and
technology to maximize the analyze marketing
effectively organization’s campaigns.
automate and marketing  Marketing personnel
inform the investment measure each
processes of dollars, may be campaign’s return-on-
planning, executed. investment, time-to-
executing, tracking market, campaign
and analyzing execution, etc.
marketing
campaigns.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 50


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Campaign  Ineffective  Clearly defined metrics AI4
effectiveness is campaigns may be and objectives are in use PO10
measured through repeated due to to track and review
the use of clearly poor or undefined campaign effectiveness
defined metrics metrics and and return on
and objectives. objectives. investment.
 Effective  Management uses the
campaigns may objectives and metrics to
not be detected assess campaign
and therefore they effectiveness.
are not repeated.  Metrics to consider
tracking are:
- Costs
- Return on
investment
- Customer response
- Customer action
 Lessons learned are
tracked for both
successful and
unsuccessful campaigns,
and the lessons are
incorporated into future
campaigns.
Marketing Strategy Research and Execution (Capturing and Analyzing Marketing Strategy
Effectiveness)
The organization  Marketing  Data mining techniques PO2
efficiently and information that and software are used to
effectively has been analyze customer data.
analyzes customer gathered may Data mining techniques
information. not provide may include:
value. - Product affinity
analysis
- Customer retention
and vulnerability
- Customer
acquisition life cycle
- Price optimization
- Risk management
 Data modeling
techniques are regularly
reviewed to optimize
interpretation of existing
data.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 51


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
The marketing  Marketing  Data mining results and AI1
strategy is strategies and campaign effectiveness PO1
continually refined campaigns may reports are incorporated
based on new not be effective formally into future
customer data. for current and marketing decisions.
future trends.  Formal procedures exist
to assess and report
campaign effectiveness
to all relevant personnel
on an ongoing basis.
 Meaningful and relevant
key performance
indicators are measured
and analyzed.
Vendor Management
Marketing service  Advertising  Management approval DS1
providers meet agencies, market procedures are in place DS2
quality, quantity, research to select and review
price, delivery or organizations and marketing service
other requirements. other marketing providers.
service providers  Formal vendor selection
may not provide and management
value for services methodology is used.
purchased.  Procedures to monitor
 Organization vendor viability and
policy may not creditworthiness are
require that service used.
providers be  Periodic competitive
selected through a rebidding is required.
formal process,
using objective
criteria.
 Contractual terms
may not be clear,
favorable to the
organization,
properly
enforceable or
competitive.
Vendor work  Vendor quality  Formal procedures are DS2
meets quality and standards may used to monitor vendor
delivery standards. differ in material quality and delivery
ways from those of standards (e.g., time,
the marketing documentation).
organization,  Escrow agreements and
leading to contingency plans are
substandard work. used in the event the

© Copyright IT Governance Institute 2003 [Link]/auditprograms 52


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
 Supervision of the vendor ceases
vendor by the operations.
marketing  Confidentiality
organization may agreements are signed by
be difficult (if the all vendor employees.
vendor is  Strong internal project
physically remote). managers are used to
 Vendor employees manage vendors.
may breach
organization
standards related
to information
security and
confidentiality.
 The vendor could
cease operations,
with resultant
losses or costs
related to
replacement of
services.
 Marketing projects
may not be
managed properly.
Technology Management
Organization  Organization  Policies and guidelines PO2
technology technology for investment in AI2
infrastructure and infrastructure and marketing technology
design should be design may not be are developed jointly by
fully supportive of capable of marketing and the IT
all beneficial supporting organization.
marketing competitive  The marketing channel
activities. marketing selection process
activities such as includes procedures to
Internet web pages address technology
or call centers. requirements, and other
competitive marketing
activities are
incorporated into the
analysis.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 53


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Marketing  Implementation of  Careful selection is made AI1
technology the technology of integrators, AI3
implementations may fail. This may consultants and software PO1
are successful. be attributable to a vendors with due PO5
number of reasons, attention to alignment of
including lack of vendor capabilities and
integration skill, project requirements
lack of user  A structured systems
involvement in the integration methodology
implementation is used to minimize risk
project, of project failure or
inappropriate underperformance
systems  Long-term technology
architecture and architecture is deployed
others. to manage the impact of
 Users may fail to technological change
accept the new  Cost-benefit analysis in
system, in most technology investment
cases, because user planning is
requirements were systematically deployed,
not captured and with post-
integrated into the implementation variance
design properly. analysis
 Technology may
become obsolete,
due to rapid
change.
 Benefits may not
be realized or may
be substantially
less than expected.
Legal and Regulatory
Marketing  Consumers  A consistent review by PO8
campaigns and purchasing legal counsel of
literature meet products based on marketing policies for
legal and false or misleading legal and regulatory
regulatory claims may be able compliance, false
restrictions. to sue for damages advertising, new
and regulatory trademarks (trademark
agencies may infringement), customer
intervene to stop communications, etc., is
practices regarded performed.
as misleading to  Time for legal review is
consumers. designed into an end-to-
 Trademark end marketing process.
development may  Proactive legal review is
infringe on the exercised in the
property rights of development of

© Copyright IT Governance Institute 2003 [Link]/auditprograms 54


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
other marketing materials, to
organizations. remove the task from the
 Materials similar project critical path.
to another
organization’s may
confuse
consumers, which
could lead to
litigation and
damages.
 Adverse court
decisions related to
an organization’s
trademarks and
materials may
require complete
rebranding and
repositioning, with
a total loss of the
organization’s
initial marketing
investment.
 Substantial cost
overruns related to
discarded print
runs, overtime,
vendor rush fees
and related costs
may be an issue.
 Competition and
antitrust concerns
may be an issue.
Consumer Privacy

© Copyright IT Governance Institute 2003 [Link]/auditprograms 55


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Compliance with  Marketers that  Privacy policies and PO8
privacy laws and do not comply procedures should be M3
regulations is with privacy implemented and include AI1
practiced. laws and areas such as unsolicited AI4
regulations may customer contact and
increase the risk disclosure of customer
of litigation, information.
damages and  Cultural differences
adverse impacts between countries are
to operations due considered.
to regulatory  Marketers must establish
injunctions. clear policy guidelines
for unsolicited messages,
which should include
classification of
messages by type and
channel, policy
regarding message
frequency, and
provisions for customer
opt-in and opt-out.
 A policy regarding
message type or class
enables organizations to
differentiate policy
according to the purpose
and intent of the
message.
For additional privacy risks and controls, refer to the privacy work program, 12. Privacy.
Fraud and Unlawful Conversion
Fraud and unlawful  Trade promotions,  Basic risk management PO4
conversion are cash rebates, controls, such as dual DS5
prevented. coupons, approval, separation of DS11
sweepstakes, duties and independent
loyalty programs audit, are a part of the
and other practices marketing process where
may not comply significant payments are
with fraud and made to other parties.
unlawful  Incentive promotions
conversion designed to reward
regulations customers for specific
 Misuse and abuse behavior, such as
of marketing funds making a purchase, are
may be an issue. designed with controls to
 Fraud may be an ensure that reward
issue payments are earned and
 Organizations that claimants are qualified to

© Copyright IT Governance Institute 2003 [Link]/auditprograms 56


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
do not ensure that earn the incentive.
benefit claims are  Proof of purchase is
supported by proof required for
of eligibility risk disbursement.
spending program  Aggregate claims are
funds in a manner matched to sales.
that does not Analysis of claims
effectively incidence by channel,
influence vendor, sales rep and
consumer other key dimensions
behavior. can reveal a
disproportionate
incidence of claims
meriting further
investigation
 Claims are checked
randomly, to validate
that claims are properly
earned and documented
 Machine procedures are
used for random printing
and insertion of winning
tickets or coupons. In the
absence of machine
procedures, control over
winning tickets should
be based on dual
approval, employee
rotation and separation
of duties.
 Security printing and
paper may be used to
reduce fraudulent
duplication of winning
tickets.
 Mailing lists are seeded
with names supplied by
an independent list-
monitoring agency, so
that the agency can track
the incidence of
communications to the
seed list by source, and
report findings to the list
owner.
Marketing Channel Management

© Copyright IT Governance Institute 2003 [Link]/auditprograms 57


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Marketing  Communications  Procedures are clearly DS11
channels are and offerings defined and followed to DS13
selected to align may not be ensure that a market
the right customers reaching the channel will link
with the right target customers customers to products
products. through the appropriately.
appropriate  Communications and
channels, offerings are sent to
resulting in customers based on their
inefficient preferences. For
marketing costs example, a customer
and reach. who prefers direct e-mail
promotions may only
want to receive e-mail
promotions and therefore
other channels may not
be effective (i.e.,
telesales, TV).
Marketing channel  Marketing  Procedures are put in AI1
analysis is channel data place to review
complete. may be marketing channel
incomplete, information to ensure
resulting in an that it is complete.
inaccurate
picture of
channel
effectiveness.
To further address channel management risks, refer to work program 6. Channel Management and
Integration Risk.
Marketing Literature Development and Fulfillment

© Copyright IT Governance Institute 2003 [Link]/auditprograms 58


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Marketing  Marketing  Marketing information is M1
information and content may be verified for accuracy PO8
content are inaccurate, or prior to releasing the
accurate. contain false or marketing literature and
misleading communication to the
claims (e.g., customer.
claims  Management reviews
inconsistent with marketing content to
product design ensure that the marketing
or performance). claims can be met (e.g.
product promises,
product availability, etc.)
 Marketing content
complies with laws,
regulations and
organization policies on
business ethics, codes of
conduct and conflict of
interest to prevent
damage to the
organization's reputation.
Literature  Literature  Formal procedures exist AI4
requirements and requirements for gathering and
needs are defined may not be assessing literature
and addressed defined requirements.
completely. completely,  Marketing personnel
resulting in ensure that all beneficial
ineffective types of literature and
literature. literature content are
developed and available
for products and
services.
Only authorized  Unauthorized  The ability to change DS5
changes to changes may be printed or web-based DS11
literature are made. made to printed literature is limited to
or web-based appropriate personnel
literature. and approved properly.
 Version control
procedures are in place
for controlling updates to
literature files.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 59


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Literature is  Requested  The organization DS11
distributed literature may utilizes collateral
effectively and not be management
properly tracked. distributed technology or
properly to sufficient manual
customers or processes to fill
prospects. literature requests
from customers and
prospects accurately
and in a timely
manner.
Customer feedback  Customer  Customer feedback is PO11
is considered feedback may reviewed formally and
during literature not be incorporated into new
design and update. incorporated into literature during
literature literature development
updates or and update processes.
development of
new literature,
resulting in lost
opportunities to
improve
literature quality.
Literature is up to  Documents that  Literature preparation M1
date. Old literature are outdated may personnel monitor
is destroyed on a not be identified documents on an
timely basis. and destroyed in ongoing basis to
a timely manner. ensure outdated
literature is identified
and removed from
circulation.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 60


3. Customer Interaction Center and Field Service Risks Work
Program
The following work program will help manage customer interaction centers and field service
risks. For detailed work programs on the telecommunication equipment within interaction
centers, see work program 7, Telecommunication Infrastructure. Any person auditing, reviewing
or advising on controls in a CRM project will need to select tasks from the work program and to
consider the key issues raised in the IT Governance Institute publication Risks of Customer
Relationship Management as part of their preparation. The work program should not be used as a
checklist of best practice, but as a selection of examples of good practice that can be applied. By
using the work programs blindly, there is a risk of losing the confidence of the auditee and even
of missing the largest risks in the project, due to the peculiarities of each project. Therefore, work
programs should be used as guidance, and specific knowledge of the organization and risks
should be added to it.

Note: A business objective may be listed more than once because it has multiple risks and
corresponding control objectives. Note disclaimer.

Business Risk Control Comments/ COBIT


Objective Results/ Reference
W/P Ref.
Customer Interaction Center—Inbound Request Processes
Customers’ calls  Inbound  Telephone trunks are DS3
are always telephone calls actively monitored to
received by the may not reach ensure they are not
interaction center. the interaction busy or out of order.
center as a result
of inactive
phone line
trunks.
Customer calls are  Telephone calls  Initial implementation AI5
routed to the may be and all changes made
correct extension inappropriately to the automatic call
or interactive voice routed resulting distributor (ACD) are
response (IVR) in dissatisfied reviewed and tested
system. and poorly thoroughly.
served
customers.
The IVR provides  Customers may  All changes to the IVR AI6
customers with an be unable to are thoroughly
easy-to-use means determine how reviewed and tested
of obtaining to route their call with end users to
information or via the IVR ensure the options and
routing their call to system or are menu path of the IVR
an appropriate dissatisfied due are clearly understood.
individual. to the
complexity of
options
available.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 61


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
The interaction  Customer calls  Network connections AI3
center provides may be dropped between the CTI or IVR DS4
customers a once the call systems and the back- DS13
positive and enters the end database system
reinforcing IVR/CTI systems. have sufficient
experience when bandwidth to
using telephone accommodate customer
self-service. information requests.
 Network connections
between the CTI or IVR
systems and the back-
end database are
monitored.
 An alternative IVR
system is made available
in the event the back-end
database is unavailable
to ensure the customer’s
time is not wasted.
Customers use IVR  Customers may  The IVR is easy to use DS3
self-service to “zero out” of the for requesting
answer common IVR rather than information, such as
questions and use automated account information, and
alleviate demand assistance because manual intervention is
for live interaction the IVR is minimized for simple
center personnel. confusing or self-service questions.
difficult to use.
Callers waiting in  Callers may  Callers are updated DS3
the queue are given become impatient periodically with the
information on and dissatisfied expected wait time while
expected wait time. with the on hold.
organization due  Callers are provided
to inability to alternative methods of
determine length communicating with the
of hold time or due organization, such as the
to excessive hold web site, nonpeak hours,
times. etc.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 62


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Web form/e-mail  Web form e-  Web form and e-mail DS13
requests are routed mail requests requests are routed to the
to the correct may be correct mailboxes using
personnel for misrouted e-mail management
response. resulting in software, also called
customer automatic e-mail
dissatisfaction distributors (AEDs).
because of  Periodic tests of web
response delays. service are conducted
and e-mails are sent to
customers to ensure
correct routing.
Web form/e-mails  Web form/e-  Users are encouraged to DS11
are easily mails requests use a web form on the DS13
integrated and read may not be organization’s web site
by e-mail routed when sending web
management efficiently or service/e-mail requests.
software. effectively, Therefore, the user
resulting in poor selects a category for
response times their e-mail from a
to customer predefined list of
requests. choices, allowing the
request to be more
efficiently routed,
understood and
answered by customer
service personnel.
Customer requests  Customer  Customer requests are DS1
are immediately requests may not auto answered, when DS13
acknowledged, be feasible. M1
enhancing acknowledged in  Acknowledgments or
customers’ a timely manner. confirmations are sent to
experience and customers to indicate
perception of using that their request was
chat for service. received and the
expected response time.
Customer requests  Customer  Customer requests are DS13
are routed within requests may be distributed evenly
the interaction routed to among customer service
center based on overloaded personnel.
nature of request CSRs.
and workload.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 63


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Customer  Customer master  CSRs perform a AI5
information is data may be thorough search for the DS11
input completely duplicated, customer in the database
and accurately. resulting in an prior to creating a new
incomplete customer. For example,
record of a they search by name,
customer’s phone number or e-mail.
history.  The system
automatically flags
potential duplicate
customer records during
entry.
Customer  Customer  CSRs are trained PO7
information is information may appropriately on data DS7
input completely be entered entry requirements and DS11
and accurately. inconsistently or the intended uses for
incompletely. fields.
 Key fields are required
to be entered.
 When possible, pick lists
and field masks are used
to validate and secure
data entry (i.e., pick lists
for titles, preferences,
states, field masks for
phone numbers, ID
numbers and credit card
numbers).
Only authorized  Unapproved  Access to maintain DS5
personnel create customer records customer information PO4
new customer maintenance is restricted to the
records. may be appropriate personnel.
performed.
Requests are  Requests may be  Contact center DS1
routed categorized personnel (or
appropriately and inconsistently, customers via web
reports on requests resulting in forms/e-mail) are
are accurate. inaccurate required to select a
routing and/or request type from a
reporting. pick list.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 64


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Requests are  Requests may be  CSRs are trained on the DS13
routed categorized proper usage of the
appropriately and inconsistently, different request types.
reports on requests resulting in  Formal procedures exist
are accurate. untimely for processing requests.
resolution and
inaccurate
reporting.
Adequate  Insufficient  CSRs are trained PO7
information is detail as to appropriately on the DS7
captured on the nature of the importance of
service request. request may be understanding and
captured in documenting the request
initial contact with sufficient detail.
with customer.  A description field is
required when
documenting a request.
Service requests  Service requests  CSRs are trained PO7
are prioritized may be appropriately on the DS7
appropriately, so prioritized meaning of service
that they are inappropriately. request severity codes.
addressed in an  The severity field is
appropriate required and given an
manner. appropriate default.
 Management monitors
the number of
outstanding service
requests by severity to
help determine the
appropriate use of
severity codes.
Web form and e-  Web form and e-  Web form and e-mail DS11
mail requests are mail requests requests are included as
seamlessly may be stored service requests in the
integrated into the separately from customer’s service
call center service telephone history.
request application, service requests,
allowing a giving an
complete picture of incomplete
the customer’s picture of the
service history. customer’s
service history.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 65


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Customer service  Customers’  Access to changing and DS5
levels are service levels assigning customer DS7
accurately reflected may not be service levels is AI5
in the system. recorded restricted appropriately.
appropriately in  Procedures exist to
the system. ensure customer service
levels are input into the
system accurately and
completely.
Customers are  Customer  CSRs are trained DS1
provided expectations for adequately on the service DS7
appropriate the level of levels. For example, DS13
service. service they will initial training is aligned
receive may not with key customer
be managed satisfiers and empowers
appropriately. the worker to satisfy the
customer.
 Customer service levels
are maintained in the
customer profile. For
example, service levels
may be as follows:
- Gold service—24/7
support, onsite support
if needed, requests
addressed in four
hours. (US $20,000
every 6 months)
- Silver service—24/7
support, no onsite
support, requests
addressed within 24
hours. (US $10,000
every 6 months)
- Bronze service—12/5
support, no onsite
support, requests
addressed within 48
hours. (US$5,000
every 6 months)
 All service levels expire
after a period of time if
not renewed.
 CSRs manage
customers’ expectations
for the level of service
they will receive by
communicating service

© Copyright IT Governance Institute 2003 [Link]/auditprograms 66


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
levels.
 A report is processed
periodically to identify
customers without a
service level or with
service levels that do not
match their current
service level.
Appropriate action is
taken to update service
levels.
Service request  The CSRs may  The request resolution PO11
resolution not provide field is configured as DS9
information is complete required to ensure proper
captured. descriptions of documentation.
how issues are  Contact center managers
resolved. perform quality
assurance on closed
service requests to
ensure the resolution is
documented adequately
and the customer’s
request was
appropriately satisfied.
For example, senior
managers regularly listen
in on live or recorded
calls for each front-line
worker to ensure that the
resolution is accurate
and documented
uniformly and
completely.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 67


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Comprehensive  Inadequate or  Documentation PO11
documentation inconsistent standards are defined AI4
standards exist. documentation to ensure
standards may comprehensive
lead to a documentation of the
difficulty in resolution. Standards
retrieving include guidelines for
solutions to referencing related case
problems. analysis, diagnostic
Q&A, decision trees,
search engines for
repositories of
technical documents,
FAQs and known
customer service
solutions, etc.
Requests are  Requests may  Procedures are defined AI4
closed not be closed on how and when to M1
appropriately. properly; appropriately close a
therefore, the request.
requests remain  Monitoring controls
open on the exist to monitor open
system and requests to ensure that
continue to be they are closed in a
worked on by timely manner.
other employees.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 68


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Customers are  Request  Customers are AI4
satisfied with the resolutions may surveyed periodically DS1
request resolution. be closed to determine DS8
without the satisfaction. The
customer being surveys include
satisfied with the
feedback on system
response. accessibility, front-line
professionalism and
overall satisfaction
with the way their calls
are handled.
 When customers’ e-
mail address is
available, they are e-
mailed a confirmation
that their request has
been closed and the
customers have the
ability to provide
feedback. Mail
confirmation is sent, if
e-mail is unavailable.
Customer feedback  Customer  Management notifies M1
is quantified and service may not appropriate individuals
analyzed on a be effective. that a complaint was
proactive basis. filed for their area of
responsibility.
 Management and the
responsible individual
determine and
implement an action
plan to avoid the noted
complaint in the future.
 The action plans are
documented and
monitored.
Services address  The needs of  Customer focus groups DS1
the needs of all specific are used to determine
groups within the customers may the needs of specific
customer base. not be met. customer groups and
how well those needs
are being met.
Customer Interaction Center—Out Bound Processes

© Copyright IT Governance Institute 2003 [Link]/auditprograms 69


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
All customers and  The out bound  The system AI1
all potential dialing system automatically AI2
customers are may not reschedules calls for
contacted. effectively busy signals and no-
switch between answers.
lists and
campaigns nor
reschedule
callbacks for
busy signals and
no-answers.
CSR time is used  CSR time may  The system keeps a AI1
effectively. be wasted due to record of call attempts to AI2
inefficient call be certain that each
scheduling of attempt is at a different
customers. time during the day and
on different days.
CSRs effectively  CSRs may not  Scripting is used to AI1
communicate the be aware of or automatically allow for AI2
organization’s do not data to be entered and
message. effectively calculations to be
communicate the performed in the script.
proper campaign  Future calls and action
messages. items are routed to the
correct agent based on
the answers received.
For example, effective
workstation
configurations identify
the probable incoming
caller by automatically
linking the caller’s
phone number and
account history, and
instantly placing this
information on the front-
line worker’s computer
screen.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 70


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Customer data are  Customer master  CSRs perform a DS9
accurate and data may be thorough search for the DS11
reliable. duplicated, customer in the database
resulting in an by name, phone or e-
incomplete mail prior to creating a
record of the new customer.
customer’s  The system
history. automatically flags
potential duplicate
customer records during
entry.
Customer data are  Customer  Pick lists and field DS11
accurate and information may masks are used to
reliable. be entered validate data entry (i.e.,
inconsistently or pick lists for titles,
incompletely. preferences, states, field
masks for phone
numbers, ID numbers
and credit card
numbers).
 Key fields are required
to be entered.
Customer data are  Unapproved  Access to add new DS5
accurate and customer records customer information is
reliable. may be created. restricted to appropriate
personnel.
Field Service Delivery
Requests are  Field service  Assignment rules are PO4
resolved in a cases may not be designed appropriately AI4
timely manner. correctly routed to consider geographical DS10
to the field, e.g., location, employee
an incorrect field expertise and availability
office. when proposing
potential field service
personnel.
 Procedures exist to
reroute incorrect
routings to another
office.
Requests are  Field service  Adequate escalation AI4
resolved in a requests may be procedures route cases to DS10
timely manner. assigned to a higher level of
unavailable or management if the cases
overworked are not addressed in a
personnel. specified period of time.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 71


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Requests are  Past solutions to  Field service personnel PO4
resolved in a similar problems have tools available to AI1
timely manner. may not be them in the field to help DS5
easily retrievable troubleshoot problems. DS!0
or available to  A solutions database is
field service maintained to assist field
personnel while service personnel in
they are in the troubleshooting
field. problems.
 Field service personnel
can access the solutions
database via field service
computers.
Requests are  Subject matter  Subject matter experts DS8
resolved in a expertise may are available to find
timely manner. not be available solutions to new and
for complex or complex problems as
new problems, they arise.
resulting in  Customer self-service
delayed can dramatically
resolution time. improve control. A
major European
electronic components
distributor, for example,
has achieved 10 percent
of its sales through its
B2B web site. At the
same time, technical
support documentation
for its products is on the
web site. More than 90
percent of all requests
for technical information
are now performed
electronically rather than
using the call center.
Reliable and  Performance  Field service personnel DS7
meaningful metrics may not understand the DS11
information is be calculated importance of and
available for field accurately due to procedures for closing a
service request inconsistent completed request.
resolution times. request closing  Field service personnel
procedures. are trained adequately on
case closing procedures.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 72


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Requests are  Spare or  Proactive steps are taken DS9
resolved in a replacement to monitor spare and
timely manner. parts may not be replacement parts
available in the inventory.
time frame the  Adequate safety stocks
customer are kept.
requires to  If the part is not
resolve the available, the customer
problem. is made aware and
approximate wait-time is
indicated.
Customers are  Customers may  Customer feedback DS8
satisfied with field not be satisfied surveys are sent to all DS10
service request completely with customers, including
resolutions. field service requests resolved by
work. field sales personnel.
 Customers are surveyed
to determine their
satisfaction with the field
service technical
assistance.
Feedback is  Ineffective  Customer feedback DS8
utilized to provide solutions may be regarding specific field
enhanced repeated for the service solutions is fed
solutions. same problem. into the solutions
knowledge database.
 Field service personnel
can propose amendments
or changes to solutions.
 Subject matter experts
review these
amendments and
changes and incorporate
them as appropriate.
Time and expense  Time and  Time and expense PO5
associated with expenses may procedures are defined DS6
field service calls not be and enforced.
are tracked. documented in  Field service personnel
the system; must submit time and
therefore, expenses periodically to
services received receive a paycheck.
may not be  To be reimbursable,
billed (e.g., loss expenses must be
of revenue). submitted prior to the
final client billing.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 73


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Customers are  Lack of  The customer service, DS6
appropriately appropriate billing and warranty
charged or not warranty-related systems are integrated to
charged for field information help ensure appropriate
service calls. might result in customer billings.
customers being
charged
inappropriately
or not charged
for the cost of
the repairs.
Field service  Field service  Parts used must be DS9
inventories are inventories may recorded prior to closing DS11
protected and be overstated as the case ticket.
monitored a result of poor  Periodic physical
adequately. parts inventories of field
management. service vehicles/
locations are taken.
 Field service personnel
are held responsible and
accountable for all
service parts in their
possession.
Field service  Performance  Field service personnel AI4
performance is metrics may not understand the DS7
understood and be calculated importance of and PO11
measurable. due to procedures for closing a
inconsistent completed request.
request closing  Field service personnel
procedures. are trained adequately on
case closing procedures.
Quality levels are  Quality levels  Contact center managers PO10
monitored. may not be met, perform quality PO11
resulting in poor assurance on closed
customer service requests to
satisfaction. ensure the resolution is
documented adequately
and it appears that the
customer’s request was
satisfied appropriately.
Service Spares Logistics

© Copyright IT Governance Institute 2003 [Link]/auditprograms 74


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Spare parts are  The right parts  Formal inventory PO6
properly managed. may not be management procedures AI4
available for is implemented to
service personnel; control the inventory of
therefore, they will spare parts to ensure that
not be able to fix all parts are accounted
products or resolve for and are available to
customer the field service
problems. representatives when
 Spare parts may be needed to resolve
stolen, misplaced, customer problems or fix
lost, etc. products.
Proprietary and  Internal  All internal, DS5
confidential documentation noncustomer-facing, DS11
information is may be information is marked
properly restricted. distributed clearly and maintained in
inappropriately a separate folder from
to the public. information designed for
distribution to
customers.
 Access to all sensitive
internal documentation
is restricted
appropriately through an
approval process.
Solution  Past solutions to  Field service personnel DS5
information is up- similar problems have tools available to DS9
to-date and easily may not be them in the field to help
retrievable. easily retrievable troubleshoot problems.
or available to  A solutions database is
field service maintained to assist field
personnel while service personnel in
they are in the troubleshooting
field. problems.
 Field service personnel
can access the solutions
database via field service
computers.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 75


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Solution  Ineffective  Customer feedback DS11
information is up- solutions may be regarding specific field DS13
to-date and easily repeated for the service solutions is fed
retrievable. same problem. into the solutions
knowledge database.
 Field service personnel
also can propose
amendments or changes
to solutions.
 Subject matter experts
review these
amendments and
changes and incorporate
them as appropriate.
Solution  The CSR may not  The request resolution DS9
information is up– provide a field is configured as M1
to-date and easily description of how required to ensure proper
retrievable. the issue was documentation.
resolved.  Management monitors
 An inability to solution information and
capture important issue resolutions.
request resolution
information may
exist.
Solution  Inadequate or  Documentation AI1
information is up- inconsistent standards are defined to PO11
to-date and easily documentation ensure comprehensive
retrievable. standards may lead documentation of the
to a difficulty in resolution. Standards
retrieving include guidelines for
solutions to referencing related case
problems. analysis, diagnostic
Q&A, decision trees,
search engines for
repositories of technical
documents, FAQs and
known customer service
solutions, etc.
Solution  New solutions  CSRs are encouraged to DS11
information is up- may not be propose new solutions in
to-date and easily documented as the solutions database
retrievable. needed, resulting and are recognized for
in a lack of their effort.
knowledge
sharing between
CSR’s.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 76


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Solution  Ineffective  All solutions are DS13
information is up- solutions may be reviewed by technical
to-date and easily repeated for the experts prior to approval
retrievable. same problem. for general use at the
interaction center.
Solution  Problem  Templates or standards PO1
information is up- resolution data govern the form of the PO3
to-date and easily may be solutions documentation.
retrievable. maintained
inconsistently.
Solution  Employees may  Responsibility and DS3
information is up- not be able to accountability for DS13
to-date and easily extract knowledge
creating and maintaining
retrievable. solutions in an product and service
efficient manner.
information are defined.
 Product and service
information is stored in
an easily accessible and
searchable format.
Policies and  CSRs may provide  Return instructions are AI4
procedures for customers available online to the DS7
returns and inaccurate CSRs.
replacements are information.  CSRs are trained
followed.  Customers may appropriately on return
not follow return policies and procedures.
and replacement
procedures
therefore their
returns are
rejected.
People Management

© Copyright IT Governance Institute 2003 [Link]/auditprograms 77


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Customers are  Inexperienced  Initial and periodic PO7
satisfied with the CSRs may training is conducted to DS7
level of service. provide educate CSRs on
inappropriate standard and timely
and incomplete literature and grouping
literature to of literature materials.
customers. For example, training
hours are allotted for
every front-line worker
(ranging from 90-150
hours) and are factored
into the forecasting and
scheduling process, at
least one year in
advance.
 Customer request
scenarios are provided to
assist in ensuring all
applicable literature is
provided during the
initial request.
Customer data are  Customer  CSRs are trained DS7
accurate and information may appropriately on data DS11
reliable. be entered entry requirements and
inconsistently. the intended uses for
fields.
Customer requests  Requests may be  CSRs are trained DS7
are responded to categorized appropriately on the
efficiently. inconsistently, proper response to the
resulting in different request types.
untimely
resolution and
inaccurate
reporting.
Customer requests  CSRs may not  CSRs are trained on the DS1
are responded to categorize importance of using the DS7
efficiently. service requests appropriate category for
consistently, service requests and the
resulting in meaning of each
inaccurate category.
request analysis.  The category field is
required.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 78


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
CSRs are well  Training  A dedicated training PO7
trained. initiatives may group is an integral part PO10
be executed of a successful DS7
poorly. interaction center
operation.
 Technical training
programs are delivered
by experienced subject-
matter experts to ensure
the skill and knowledge
transfer of information is
current and relevant.
 Training programs are
subject to a beta test or
pilot test to solicit CSR
end-user feedback and
improve the training
program.
 Formal training agendas
are prepared and
approved by
management.
CSRs are well  Personnel may  Training curriculum PO7
trained. not be trained to includes systems, DS7
meet customer products, call types, DS13
needs customer handling and
effectively. telephone skills.
 CSRs are involved in
developing training
courses and management
approves course content.
 Multiple training
methods are used,
including written tests,
telephone interviews and
role-playing to provide
comprehensive
scenarios.
CSRs are well  Customer  Training hours are DS1
trained. service needs allotted for every front- DS7
and workloads line CSR (ranging
may not allow from 80-160 hours per
sufficient time employee) and are
for proper factored into the
training. forecasting and
scheduling process at
least one year in
advance.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 79


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
CSRs are well  Training may  Training effectiveness AI4
trained. not enhance is verified through self- AI5
productivity. assessments, service DS7
observations, one-on-
one coaching, team
interactions and
metrics.
Customers are  Customers may  Front-line CSRs are DS10
satisfied with the be treated with trained to recognize DS13
service. disrespect. and adapt to different
caller personality
types.
Customer requests  Insufficient  CSRs are trained DS7
are responded to detail as to the appropriately on the
efficiently. nature of the importance of
request may be describing the request
captured in in detail.
initial contact
with customer.
Customers are  Customer  CSRs are trained PO7
satisfied with the expectations for adequately on the DS1
service. the level of meaning of different
service they will service levels.
receive may not
be managed
appropriately.
Customer requests  Service requests  CSRs are trained DS13
are responded to may be routed to adequately and
efficiently. inappropriate provided information
individuals, regarding to whom to
delaying route calls depending
resolution. on the type of inquiry,
in the event they
receive a call they
cannot answer.
Customer service  Personnel may  Personnel are trained PO7
representatives are not be trained to appropriately in
well trained. manage managing assignment
assignment or and workflow rules.
workflow rules.
Physical conditions  Contact center  There is a natural source PO8
are sufficient to personnel may of lighting, artificial DS12
allow interaction be inefficient direct and indirect
center personnel to due to a poor lighting to reduce glare.
operate effectively. physical  Customer care personnel
environment. have facilities for rest
and recreation.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 80


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
 The layout supports ease
of operations and an
ability to deal with calls
effectively, e.g., hot
desk, printer locations,
etc.
 The noise level is
controlled and the
general noise level (e.g.,
background noise) is
adequate. Mitigating
methods are white noise,
sound absorbing
materials, baffling
materials, etc.
 Proper ventilation exists
to provide ambient
temperature and proper
circulation of air, e.g., no
hot spots and cold spots.
 Ceiling height provides a
sense of openness,
visibility, etc.
 The interaction center is
clean and well
maintained.
 Support for offices
includes office facilities,
e.g., printers, phone
headsets, photocopiers,
etc.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 81


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Workloads are  The interaction  Workload is forecast 12- DS1
managed center may be 18 months in the future DS3
effectively to inefficient and in and is adjusted quarterly, DS7
ensure high-quality constant monthly and weekly AI4
customer service. response mode. based upon current
information.
 Attrition and training are
factored in the forecast
equation.
 Forecasting accuracy is
tracked weekly and
monthly, in hopes of
achieving accuracy
within a +/- 2 percent
range.
 In addition, periods of
excellent service levels,
not poor service, are
leveraged for goal
setting.
 Workflow management
and work queue
management are used to
monitor agent’s
workload and to take
action to avoid backlogs
or bottlenecks from
developing.
Workloads are  All resources  Workload balance DS3
effectively may not be efficiency strategies
managed to ensure leveraged for include:
high-quality efficiency. - Site consolidations
customer service - Workload
while minimizing balancing between
costs. multiple interaction
centers
- Staggered shifts by
15-minute intervals
- Availability of
part-time workers.
Workloads are  CSRs may  Contact center DS1
managed become managers monitor DS3
effectively to overburdened workloads of CSRs and
ensure high-quality and unable to take action to reassign
customer service. answer customer requests to smooth the
requests in a workload.
timely manner.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 82


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Workloads are  Requests may be  Assignment managers DS3
managed assigned to over are used to smooth the
effectively to burdened workload among
ensure high-quality employees, employees and to help
customer service. resulting in ensure the most
delays in qualified person is
resolving service working on the
requests. problem.
Workloads are  Service requests  CSRs are aware of DS3
managed may not be overall workloads in the
effectively to resolved in a interaction center and
ensure high-quality timely manner can therefore manage
customer service. due to lack of customer expectations
appropriate on resolution time.
resources.  Contact center
management monitor
workloads over time and
anticipate periods of
increased demand for
service.
Workloads are  Service requests  Employees are marked DS3
managed may be routed to as unavailable in their
effectively to unavailable personnel profile while
ensure high-quality individuals, on vacation or
customer service. delaying otherwise away from
resolution. the office so requests
will not be routed to
them.
Workloads are  Requests may be  Customer requests are DS1
managed routed to distributed evenly
effectively to overloaded among customer
ensure high-quality CSRs. service personnel.
customer service.
The contact center  Contact center  Contact center DS1
is managed efficiency may interaction times are DS3
efficiently to decline due to tracked, monitored and
ensure high-quality inadequately reviewed to help
customer service trained ensure interaction
while minimizing personnel or new center efficiency.
costs. customer
problems.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 83


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
The contact center  Feedback may  Customer feedback is DS3
is managed not be compiled summarized and used
efficiently to to implement to make decisions
ensure high-quality continuous regarding employee
customer service improvement of incentives, policy and
while minimizing organization procedure, resource
costs. practices. allocation and skill
needs.
The contact center  Contact center  Common service DS1
is managed management requests are reported
efficiently to may not analyze in overall interaction
ensure high-quality commonality center statistical
customer service among service information.
while minimizing requests,  Common service
costs. forgoing any request resolution
potential information is
efficiency gains incorporated into the
from web site FAQ
incorporating information and also in
common service the IVR.
request  CSRs are made aware
information. periodically of the
most common service
requests, to ensure
they are able to
efficiently answer
customer inquiries.
The contact center  Personnel  Policies state that the DS1
is managed monitoring may primary purpose of
efficiently to be perceived monitoring is to
ensure high-quality negatively by identify individual
customer service personnel. training needs as part
while minimizing of an organizationwide
costs. continuous
improvement effort.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 84


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
The contact center  Key decision-  Senior managers DS1
is managed makers may not regularly listen in on live DS3
efficiently to be aligned with calls to stay in touch
ensure high-quality day-to-day with the customer and
customer service operations. with the effectiveness of
while minimizing their interaction center
costs. operations. For example,
team leaders typically
should monitor five to
ten calls per front-line
personnel per month.
Both silent/remote and
side-by-side monitoring
are used.
 Team leaders shadow
front-line personnel for a
day to better understand
call operations, job
procedures, working
conditions and customer
expectations.
The contact center  Front-line  Front-line personnel DS1
is managed personnel satisfaction is measured DS2
efficiently to satisfaction may as routinely as customer
ensure high-quality not be valued satisfaction.
customer service and  Comprehensive annual
while minimizing incorporated. surveys are compared to
costs. specifically targeted
weekly and monthly
surveys to ensure
continuous
improvement.
The contact center  Customer  Tracking of methods DS10
is managed problems may utilized for problem
efficiently to not be handled resolution is performed
ensure high-quality efficiently. to analyze effective vs.
customer service ineffective methods.
while minimizing
costs.
The contact center  Employee skills  Employee skills are PO7
is managed may not be reviewed periodically
efficiently to updated and adjusted as those
ensure high-quality regularly in the skills change.
customer service system.
while minimizing
costs.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 85


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
The contact center  Requests  Contact center DS1
is managed (including web management monitors M1
efficiently to form and e-mail outstanding requests
ensure high-quality requests) may (including web form and
customer service not be assigned e-mail requests) to
while minimizing to appropriate ensure service requests
costs. personnel in a are addressed in a timely
timely manner, manner.
resulting in  Management monitors
customer average resolution time
dissatisfaction. for service requests.
Outsourcing
Outsourcing  Outsourcing  Service level agreements DS2
arrangements are arrangements define the M1
managed properly. may not meet responsibilities and
expectations details of the expected
resulting in poor service levels to be
customer provided by the
service, outsourcing
unresolved organization, as well as
customer needs, metrics to be achieved
etc. by the outsourcer. The
service level agreement
includes required
processing levels,
security, monitoring,
contingency
requirements and other
stipulations, as required.
 Management monitors
performance of the
outsourced vendor to
ensure that key controls
are being performed. For
instance, a SAS 70
report, which describes
key processes and
controls in place at the
outsourcer, may be
available.
Management Analytics and Reporting
Calls analysis is  The interaction  The following areas are M1
performed to center may not monitored, and if an DS3
monitor service be performing at acceptable service DS13
levels and improve an acceptable level is not met,
performance. service level. performance
improvement steps are

© Copyright IT Governance Institute 2003 [Link]/auditprograms 86


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
taken:
- Proportion of
callers to receive a
busy tone due to no
telecommunication
- Proportion of
callers to receive a
busy tone due to
operational policies
during the busy and
other hours
- Proportion of calls
that are abandoned
by department and
service line
- Length of time
customers have to
wait for an agent
when they are the
targets of an
outbound call (best
practice is zero and
acceptable
performance with
power dialer is 1
percent)
- The proportion of
average call
handling time to
talk time (best
practice is 95
percent or better)
- Proportion of
handling time to
information
system wait time
between screens,
for searches, etc .
(Best practice is
less than 5 percent
of contact time)
- Proportion of talk
time that is wasted
where the
customer or agent
is waiting or
something to
happen (best

© Copyright IT Governance Institute 2003 [Link]/auditprograms 87


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
practice allows 10
percent). Wasted
time includes
waiting for:
information from
database,
information from
customer, to
transfer call, to
look up a
list/book, to
contact someone
else, etc.
- Proportion of
incoming calls that
are abandoned by
the caller (should
be less than 1
percent, very near
zero, or zero).
Note: Beware
misinterpreting
statistics as IVR
on overflow makes
this easy to
achieve on the
ACD stats. Best
practice is only
achieved if IVR is
fast/simple and not
compulsory.
- Average setup time
per outbound call
attempt (best
practice is less
than 10 seconds
per attempt)
- Number of
attempts the
average outbound
call takes before
success
- Differences
between CSRs for
individual call
handling time
-Average time to
respond to a

© Copyright IT Governance Institute 2003 [Link]/auditprograms 88


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
ringing phone and
the variances
between CSRs
- Average time to
respond to a
ringing phone and
the variances
between CSRs
- Average utilization
and the variances
between CSRs
- Number of calls per
hour worked and
the variances
between the CSRs
- Proportion of
customer
transactions
recorded by
reporting systems
- Customer
transaction history
length
- Number of
telephone numbers
customers can use
to gain access
- Proportion of calls
to arrive on the
three most
common numbers
- Proportion of calls
that use ordinary
geographic
numbers and the
proportion that use
branded NTS
numbers, e.g. 800,
888, 990, etc.
- Proportion of calls
that are satisfied
during one call
- Number and
percentage of calls
that are complaints

© Copyright IT Governance Institute 2003 [Link]/auditprograms 89


4. Data Management Risks Work Program
The following work program will help manage data risks for customer relationship management.
Any person auditing, reviewing or advising on controls in a CRM project will need to select tasks
from the work program and to consider the key issues raised in the IT Governance Institute
publication Risks of Customer Relationship Management as part of their preparation. The work
program should not be used as a checklist of best practice, but as a selection of examples of good
practice that can be applied. By using the work programs blindly, there is a risk of losing the
confidence of the auditee and even of missing the largest risks in the project, due to the
peculiarities of each project. Therefore, work programs should be used as guidance and specific
knowledge of the organization and risks added to it.

Note: A business objective may be listed more than once because it has multiple risks and
corresponding control objectives. Note disclaimer.

Business Risk Control Comments/ COBIT


Objective Results/ Reference
W/P Ref.
Data Management Strategy
The data strategy  The business  A strategy exists to PO1
supports the strategy may not exploit data in the DS2
business. address data organization’s
quality and data possession to support
management core business objectives.
issues.  Future CRM initiatives
are discussed by senior
management and
communicated to the
data team so that future
data needs can be
evaluated.
 The data strategy is
formally documented
and approved by senior
management.
 Senior management
views data management
as a strategic business
issue that is important to
the success of the
business.
 Data management and
data quality are
discussed at senior level
management meetings.
 The use of external data
from a third-party
vendor is reviewed.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 90


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Future data needs  Excessive costs  The major drivers of AI1
are understood and may occur in change in the collection PO4
processes meet changing data and use of data within DS8
these needs. definitions and the organization and AI4
structures. growth in automated
 Data needs may decisions and processes
not be met. are identified over the
next two years.
 All projects validate data
structure/item needs
against corporate data
structures and comply
when feasible.
 The value of data held
by the organization is
periodically assessed and
measured (e.g., users
surveyed to determine
how well data meets
their needs).
Data Ownership and Executive Sponsorship
Business owners  The business  An executive director DS11
and sponsors owners and (e.g., CEO, CIO, CFO)
provide support. sponsors may is responsible for data
not support the quality.
data warehouse  A cross business unit
and data (e.g., steering
initiatives. committee) addresses
issues dealing with data
management and quality.
 A data stewardship
program for all data
sources is implemented.
Steward drives data
quality approach from
the business owner’s
point of view.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 91


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Data roles are  A lack of focus  Roles and PO11
defined clearly. may exist responsibilities for data PO10
regarding data quality are identified
quality, resulting clearly. For example, the
in poor data roles and responsibilities
quality. are documented and
communicated to the
user on an annual basis.
 A formal group is
responsible for data
quality within the
organization.
 There is one person or a
group of people
responsible for the
quality of data within
each business unit or key
category of information.
 There is one person or
group of people
responsible for
responding when
problems are
encountered with data
within each business unit
or key category of
information.
Key data are  Data may not be  Management has PO2
properly identified organized and established categories of
and utilized. understood. data by level of
importance to the
business.
Data

© Copyright IT Governance Institute 2003 [Link]/auditprograms 92


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Sufficient audit  Research and  An audit trail is DS10
trails exist. forensics may maintained in enough DS11
not be able to be detail to allow M4
performed due to management to monitor PO8
a lack of audit the data warehouse
trails. activities, transactions,
etc., and to meet the
needs of various internal
and external regulations.
 Periodic, scheduled
audits are performed and
documented to verify
that established
procedures are being
followed.
 An audit trail is
maintained in enough
detail and for an
adequate period of time
to allow management to
monitor the data
warehouse activities,
transactions, etc., and to
meet the needs of
various internal and
external regulations.
Preservation for a long
period is one of the most
important aspects of
audit trails (in many
cases also required by
regulation).

© Copyright IT Governance Institute 2003 [Link]/auditprograms 93


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Data quality is  Poor data quality  A center of data PO11
monitored. may lead to loss excellence is established DS8
in user within the organization DS11
confidence. to monitor the
consistency of data over
a period in time.
 A feedback mechanism
exists to determine the
customer’s, vendor’s and
user’s level of
confidence in the
organization’s data.
 The quality of data held
in the business,
processes or systems has
a means of being
measured.
 Vendors and the
organization work
together in failure
analysis and trouble-
shooting quality issues to
resolve conflicts.
 Customer complaints are
reviewed for linkage
back to poor data.
 Reconciliation efforts
are investigated to
determine if they relate
to data quality issues.
Data are accurate,  Data quality may  Data policies and PO2
consistent, become procedures surrounding DS11
complete, etc. compromised. data quality, such as PO4
accuracy, consistency, DS5
integrity and
completeness, are
established and
communicated to the
users.
 Data is scrubbed and
integrity checks are in
place so that only quality
data are moved from
operational systems to
the data warehouse.
 Data adheres to a
common definition for
meaning and use, for

© Copyright IT Governance Institute 2003 [Link]/auditprograms 94


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
example, address fields
incorrectly used to
record specific notes
about a customer.
 Data adhere to defined
business rules, accepted
values and accepted
formats (e.g., valid
industry codes).
 Data contain correct
values.
 Data adhere to integrity
constraints such as
reasonableness checks,
validity checks, etc.
 Processes exist to
validate that downloaded
or incoming data are
successful, by tracing it
back to the system of
record.
 Data are checked
routinely against
external sources for
accuracy.
 Statistical sampling (e.g.,
fixed percent of data are
checked each month) is
used to assess data
quality.
Access to data is  Inappropriate  Data owners identify DS5
restricted. access to data users who need access to
may exist. pertinent data and
provide them with only
the level of access
needed for their job
duties.
 Procedures are in place
to set up users for the
information access they
need and are authorized
to receive.
 Filters block
unauthorized access to
sensitive or
inappropriate
information.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 95


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Data privacy and 
Loss of customer  Policies and standards PO6
confidentiality are confidence may exist for data that are DS5
observed. occur. shared with the public
web site.
 Data privacy and
security compliance are
established.
 Policies exist regarding
the sale or publication of
data.
Data needs are  Nonexistent data  Data owners identify all DS11
complete. may lead to loss required information and
of opportunity acquire nonexisting
and business information from outside
growth. the organization to fuel
CRM initiatives.
Data are available.  An inability to  Data can be accessed DS11
make business when required and by
decisions due to the appropriate people.
lack of data may  Knowledge of data and
exist. their availability (e.g.,
meta data) is made
known generally to user
departments existing
outside of IT and project
teams.
 The organization has a
shared information
system, drawing together
data from a range of
divisions and
departments.
Data Warehouse Implementation and Data Conversion Risks

© Copyright IT Governance Institute 2003 [Link]/auditprograms 96


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
A thorough review  Errors or  The system has been DS5
has been anomalies in the balanced and DS11
completed of the old system may reconciled regularly.
existing data to be not be identified  The system has its own
converted. fully, and internal integrity (e.g.,
corrections may opening balance +
not be managed receipts – issues +/-
properly. adjustments = closing
balance).
 The security and access
controls are sufficient
to prevent unauthorized
access or usage.
 The system has
sufficient input
validation and error
checking to prevent
invalid master and
transaction data from
entering the system.
 If tables are used, they
have been maintained
correctly and are
current.
 There are no
noncurrent data in the
system.
 There are no missing or
incomplete data in the
new systems.
The data  Balances from  The reconciliation AI1
conversion system the old system procedures ensure that AI4
design has may not be the existing system AI5
specified the transferred balances internally at M4
means to reconcile properly to the the time of conversion.
both the old system new system.  The procedures for
(internally) and the reconciling the old
old system to new system to the system
system on master file data and
commencement of opening balance data
live production. are established.
 Where the system
implementation
strategy involves
parallel running, staged
or phased
implementation,

© Copyright IT Governance Institute 2003 [Link]/auditprograms 97


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
procedures for the
different types of
reconciliations required
are identified.
 Acceptance criteria, to
determine whether the
data conversion process
has been completed
successfully, are
defined and agreed
upon.
 The responsibility for
sign-off and audit of
completion of the
conversion process is
defined and agreed
upon.
 The documentation and
supporting materials to
be retained, as proof of
conversion, are defined.
The data to be  Balances from  A match exists between AI5
converted from the the old system all of the old system data DS4
old system to the may not be elements and the new DS9
new system have transferred system data elements to
been defined properly to the determine what will be
properly. new system. converted, what will not
be converted and what
will need to be created.
 Requiring selection
criteria, purge criteria
and translation rules are
clearly identified,
documented and agreed
upon with users.
 The validation of the old
data to the new system is
specified and agreed
upon.
 Timing for the data
conversion is defined
and agreed upon with
users.
 Issues of one-to-many
and many-to-one
conversions are resolved.
 Field length and value
are analyzed.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 98


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
 The old system history,
the means of retention
(e.g., tape) and the
duration for which it is
to be held are defined.
 Decisions are made in
relation to any redundant
data.
 The means of formally
closing the old system
are defined.
The data cleanup  The protection,  The approach to data AI5
process must be adherence to and cleanup is thoroughly AI6
adequately maintenance of planned to ensure that DS11
controlled to data standards dependencies between
ensure that may be data items are
amended data are insufficient to maintained.
consistent and ensure the  Data items to be
integrity integrity and amended and enhanced
maintained. successful are identified.
operation of  Criteria are agreed upon
systems. for determining the data
conversion rules.
 The tools/programs used
to effect changes to data
are tested and are
reliable.
 An auditable trail of the
changes applied is
produced for
management review and
sign-off by the data
owner or nominated
deputies.
 All changes applied are
reversible or can be
backed out by using
back-up copies of the
data.
 Changes are never
applied directly to
production data.
Procedures for the  The protection,  Different means may be AI4
creation or adherence to and used to create/convert AI5
conversion of data maintenance of data for the new system, DS2
for the new system data standards such as developing DS11
have been defined may be custom programs or the
properly. insufficient to use of master file bulk or

© Copyright IT Governance Institute 2003 [Link]/auditprograms 99


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
ensure the mass conversion tools
integrity and (e.g., provided in the
successful data warehouse or CRM
operation of application). It is
systems. necessary to ensure:
- If custom programs
are written, the
development and
testing process
follows the normal
system development
life cycle.
- If a scanning device
is to be used to
create data, it is fully
tested to determine
capacity, accuracy
and the contents of
file outputs.
- If a mass or bulk
conversion tool is
used, it is fully
specified and
documented, and
capacity needs
determined and
tested.
- If the data are keyed,
the input programs
are tested
appropriately and
data are verified on
input.
- If the data are keyed
by a third party (e.g.,
service bureau),
proper instructions
and input validation
must be specified.
- If data are acquired,
they are loaded onto
the new system
through standard
input routines to
validate its accuracy.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 100


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Adequate project  Errors or  The entire data PO9
management of the anomalies in the conversion process is PO10
data conversion old system may treated as if it were a DS5
process is in place. not be identified separate systems
fully, and development project.
corrections may Thus, the normal
not be managed project management
properly. sections should be in
place including:
- Adherence to a
structured systems
development
methodology
- Use of project
management tools
and techniques to
define and manage
resources, outputs,
costs and time
- Project risk
assessment
- Definition of
security and access
- Definition of the
responsibility for
approval and the
means for any
adjustments
discovered as part of
the data conversion
process.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 101


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Adequate testing  The protection,  Unit, component, string AI5
procedures for the adherence to and and system testing of all
data conversion maintenance of parts of the data
system are in data standards conversion systems are
place. and testing may completed in the same
be insufficient to comprehensive manner
ensure the as in a normal systems
integrity and implementation.
successful  The testing to be
operation of completed includes all of
systems. the different means that
will be used in the
conversion process.
 Depending on the
implementation strategy
used, this testing process
is completed on more
than one occasion.
Sufficient training  Insufficient  Sufficient resources are DS1
and support exists maintenance and available to provide DS7
for data support may occur support and training of
warehouses. for the data data warehouse
warehouse. personnel, end users, etc.
 End users may not  Staff members with
understand how to responsibility for data
use the data are trained in areas such
warehouse and, as company knowledge
therefore, reject it. systems, data quality,
and data ownership
responsibilities.
 A structure exists by
which users can report
data problems to the data
and IT support
personnel.
 There are documented
service level agreements
(SLAs) between
providers and users for
data deliverables.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 102


5. Integration Risks Work Program
The following work program will help manage the integration risks for customer relationship
management. Any person auditing, reviewing or advising on controls in a CRM project will need
to select tasks from the work program and to consider the key issues raised in the IT Governance
Institute publication Risks of Customer Relationship Management as part of their preparation. The
work program should not be used as a checklist of best practice, but as a selection of examples of
good practice that can be applied. By using the work program blindly, there is a risk of losing the
confidence of the auditee and even of missing the largest risks in the project, due to the
peculiarities of each project. Therefore, the work program should be used as guidance and
specific knowledge of the organization and risks added to it.

Note: A business objective may be listed more than once because it has multiple risks and
corresponding control objectives. Note disclaimer.

Business Risk Control Comments/ COBIT


Objective Results/ Reference
W/P Ref.
Data Consistency
Data are consistent  Lack of  Data validation rules, AI2
between systems. uniformity business rules and AI5
across connected system controls ensure DS10
systems may the integration of data
cause conflicts among multiple
among the systems.
applications.  The data definition is
clear for key data
fields: customer,
product, sales order,
price, etc.
Data Quality
Quality data are  When  A comprehensive data AI5
maintained combining quality administration AI6
between the information or steering committee DS10
systems. from multiple can lead to the
systems into one institution of company-
CRM wide data standards.
application, the  Data validation tools
risk of are used to validate
inaccurate data data quality. Using
may arise. tools to periodically
Inaccurate data identify and resolve
leads to lack of data quality issues
user buy-in, loss immediately can
of customers, mitigate the risk for
and failure of larger data quality
CRM adoption. issues in the future.
 Data quality linkage
among systems is
defined, maintained

© Copyright IT Governance Institute 2003 [Link]/auditprograms 103


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
and measured.
 Once a data quality
administration program
is implemented, the
following controls are
implemented as part of
the program:
- Concurrent access
that allows logic to
be updated with
many applications
linked to one
database/source
- Validation checks
- Data entry controls
- Change procedures
Data Structure
Data structures are  Without a standard  A complete and PO2
uniform between customer profile, thorough analysis of the DS11
systems. customer data structures and data
information may definitions is performed
not be consistent for each system to
between systems. ensure that each
 Data loss and application has the same
inaccuracies may definition of customer
occur. profiles and methods of
storing customer data,
e.g., flat files,
hierarchical databases, or
relational databases.
 Data relationships are
assessed for each system
before attempting CRM
integration.
 XML can be used to
mitigate data structure
risks by presenting
flexible ways to create
common information
formats and share the
format and data.
Connectivity
Connectivity is  When  EAI is used when PO9
maintained to combining feasible and cost- PO11
allow data access information justifiable. AI5
and transfer from multiple  Custom code used as
between systems. systems into one adapters are inserted,

© Copyright IT Governance Institute 2003 [Link]/auditprograms 104


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
CRM tested, documented and
application, the maintained properly.
risk of
inaccurate data
may arise.
Inaccurate data
leads to lack of
user buy-in, loss
of customers and
failure of CRM
adoption
Vendor Management
The CRM product  The solution may  The trade-off between AI1
meets functionality not meet functionality and ease AI2
requirements and functionality of integration is
the integration expectations. analyzed before
effort is  The cost and effort selecting a vendor. For
reasonable. to integrate instance, an ERP
applications may vendor with a CRM
be excessive. extension may be
much more attractive
to the consumer from
an integration
standpoint, but the
product may not meet
functionality
expectations.
Vendors are  Integration may  Vendors and the AI1
researched be too costly or proposed CRM solution AI2
thoroughly to difficult. are researched to
understand the determine the integration
integration effort. effort and any issues that
may exist.
 Vendors that have fully
integrated products, such
as Siebel, PeopleSoft,
Oracle, SAP and Clarify,
can be utilized.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 105


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Vendor  Due diligence  Proper research is AI1
performance meets performed by the performed on CRM AI2
the needs. company to ensure vendors to identify DS9
that the product integration and
meets functionality issues that
requirements, the may exist within the
vendor and product itself.
product are stable,  Prior to purchasing a
etc., may be vendor product,
inadequate. management performs a
 There may be a thorough check of the
lack of quality of vendor including
support from the reference checks,
vendor, therefore, financial position check,
when issues arise; escrow agreements, etc.
the vendor may
not be responsive.
System Maintenance/Manageability
System  A change in one  A system maintenance PO6
documentation is area may affect and modifications PO11
maintained. numerous strategy is developed, AI1
connected systems, including periodic AI6
cascading into releases of changes to
voluminous re- customers, change
working and re- approval, modification
testing of rules (“vanilla” vs.
previously modifications allowed),
established etc.
connectivity.  Systems documentation
 Potential system is maintained for
downtime, data integration issues
and productivity encountered on the
loss, and project, e.g.,
reconfiguration connectivity difficulties.
struggles may  Changes to systems,
occur. applications and
connectivity adapters are
recorded to help transfer
knowledge to future
systems administrators.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 106


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
System  Technical  The organization has AI3
obsolescence is obsolescence may confidence in system AI4
avoided. occur. upgrade procedures due DS9
 There may be a to proper system
lack of vendor documentation and
support for older knowledge; therefore,
systems. the system can be
upgraded to keep current
with the latest release.
 Sufficient planning is
performed to understand
the effort required to
upgrade the system.
Post-upgrade  When systems  Proper testing and AI3
testing is are processing debugging after system AI5
performed. smoothly changes, maintenance or PO11
without incident, upgrades are performed
administrators to verify previously
may feel that established connectivity,
post-upgrade synchronicity and data
testing is an quality.
unnecessary  Results are documented
step. Therefore, and any inconsistencies
testing may not or errors are investigated
be performed thoroughly.
thoroughly.
Interfaces are  Interfaces may  Manageability of point- DS11
manageable. grow to-point connections is
exponentially achieved through use of
because of the EAI solutions. EAI
number of usually is used for CRM
applications that projects that are large in
need to be both scope and budget
integrated for the due to its facilitation of
CRM solution. data flow in real time,
 Changes in one and its effectiveness in
application may managing connectivity.
ripple through
other systems,
potentially
delaying data
movement.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 107


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
System Performance
The system is  The amount of  Before integrating new PO9
scalable. data being systems, a thorough AI5
transferred, systems analysis is DS11
acceptable speed executed to expose
of data transfer or system weaknesses and
the number of mitigate scalability and
concurrent users performance risks.
may increase, thus
increasing
uncertainty about
stability and
response time.
 The system may
be unstable,
resulting in loss of
data, loss of
productivity and
user
dissatisfaction.
Data are updated in  CRM users may  A proper assessment DS3
a timely manner. not be able to based on industry, DS7
access customer volume and number of
data in a timely users is performed to
manner. determine if data needs
to be processed in real
time or with batch
processing.
 By taking this hybrid
approach to data flow
and minimizing the real-
time processing needed,
an organization may
avoid system
performance risks and
still meet user needs.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 108


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Backup, Restoration and Continuity
Data can be  Without proper  Formal, written and DS4
recovered. backup and proven backup and
restore restoration procedures
procedures in are documented and
place, include the
organizations responsibilities and time
may expose expectations for
themselves to recovering the system.
extensive  The restoration
damage or loss procedures are tested
of data as well periodically and proven
as productivity successful.
losses.  The organization has
formally documented,
tested and updated
business continuity and
disaster recovery plans.
 The organization has a
way to operate the
business in the event of a
disaster, system outage
or interruption, i.e.,
manual procedures to
enter sales orders, take
customer service calls,
etc.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 109


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Interface Monitoring and Workflow
Data is interfaced  There may be  Formal roles and PO7
properly. interface errors responsibilities are AI4
due to data defined for monitoring DS1
mapping or interfaces and resolving
translation tables errors.
that have changed  Manual or automated
so that the monitoring controls are
interfaces do not used to ensure that
match, or due to interface errors are
data that have been identified, investigated
received in an and resolved in a timely
incorrect format. manner.
 Interface errors  Criticality and frequency
may not be of the interface will help
identified, to determine the type of
investigated and error identification and
resolved in a resolution procedures
timely manner. needed to ensure data
 Customer completeness and
transactions may accuracy. Noncritical or
not be processed batch interfaces, may
correctly and CRM indicate that manual
information may procedures are sufficient.
not be complete.  Reporting is defined and
reviewed regularly to
identify interface
processing information,
such as outstanding
errors, days outstanding,
etc.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 110


6. Channel Management and Integration Risks Work Program
The following work program will help in channel management and in managing the integration
risks for customer relationship management. Any person auditing, reviewing or advising on
controls in a CRM project will need to select tasks from the work program and to consider the
key issues raised in the IT Governance Institute publication Risks of Customer Relationship
Management as part of their preparation. The work program should not be used as a checklist of
best practice, but as a selection of examples of good practice that can be applied. By using the
work programs blindly, there is a risk of losing the confidence of the auditee and even of missing
the largest risks in the project, due to the peculiarities of each project. Therefore, work programs
should be used as guidance, and specific knowledge of the organization and risks should be added
to it.

Note: A business objective may be listed more than once because it has multiple risks and
corresponding control objectives. Note disclaimer.

Business Risk Control Comments/ COBIT


Objective Results/ Reference
W/P Ref.
Channel Strategy
Channel strategy  Messages across  Cross-function teams are PO1
provides profitable channels may not established to create a
customer be consistent. formal channel strategy
relationships.  Each channel or that meets customer
department may needs and provides a
operate profitable relationship
independently, i.e., for the organization.
silo behavior.  Channels are matched to
 Channels may not the demands from the
match the demands primary customer
from primary segments of the
customer segments organization.
of the  Channel performance is
organization. optimized from the
perspective of both the
customer and the
organization.
Data Integrity and Consistency

© Copyright IT Governance Institute 2003 [Link]/auditprograms 111


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Consistent  Information  Cross-functional teams AI2
information is regarding product compare information
provided across availability, across channels.
channels. features and price  Changes to information
may not be are considered and
consistent across agreed upon across all
channels. channels.
 Customers may
not know what
price, promotion
and general
experience to
expect each time
they contact what
they perceive to be
the same
organization.
Sales channels are  Each sales  Sales channels are DS11
integrated to channel is integrated so that brands
provide consistent treated as a and information are
brands and separate consistent.
information. operating unit  Separate operations are
and configured not created for each sales
as a separate channel, but instead
organization, operations are integrated
which may across sales channels.
generate
conflicting
information and
sometimes may
create competing
brands.
CSRs understand  Inexperienced  Initial and periodic DS7
functionality, CSRs may not training is conducted to
policies and understand the educate CSRs about all
procedures across functionality, channels including
channels. policies and policies, procedures,
procedures of all functionality, etc.
channels (e.g.,
Internet, kiosks,
telemarketing,
face-to-face
sales, etc).

© Copyright IT Governance Institute 2003 [Link]/auditprograms 112


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Data are  Data may not be  Controls are in place to DS11
normalized across collected from ensure data analyzed
all channels. all channels. include complete and
final data from all
relevant channels.
Data are complete  Data and  Data and customer DS11
and useful. customer feedback are obtained
feedback may from all customer
not be obtained touchpoints to ensure
from all relevant that data obtained are
channels. valuable and present a
complete view of the
customer.
The CRM system  Silo CRM  The CRM solution AI6
encompasses all solutions may have spreads across the
customer-facing been built to organization, division,
channels. service new etc., and therefore
customer-facing encompasses all
channels. customer-facing
 Inconsistent channels to ensure
service, consistency.
information and  The CRM system is
procedures across integrated across all
channels may channels and back into
exist. the legacy systems.
Up-to-date  Customers may  Up-to-date information DS11
information is make repeated is dispersed across all
available. attempts to get touchpoints.
tasks completed.
Customer Experience
Customers are  Customers may  Feedback is solicited and M1
provided with a not be provided analyzed from customers
variety of channels. with the right to understand the variety
variety of of channels that
channels; customers want.
therefore, they  The channels used by the
cannot interact company match the
with the preferences of the
organization customers.
using their
preferred
channel.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 113


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Customers’  Customers’  Customer channel DS8
interaction occurs interaction may preferences are DS13
through their not be understood and future
preferred channels. communicated contact with customers is
via their via their preferred
preferred channel.
channel.  Customers have the
freedom to interact with
the organization via
multiple channels, and
they are not restricted to
only one or two
channels.
The organization’s  Organizations may  Organizations fully DS7
channels enhance rush to the next explore new DS8
the customer communication or communication or
experience. distribution distribution media to
medium out of understand how they fit
competitive into their overall CRM
necessity before picture before offering
studying how it the media to their
will fit into their customers.
overall CRM
picture.
 Customer
experience may
not be satisfied
despite the
addition of new
channels.
 Channel
development may
be unbridled,
therefore wasting
resources.
Leverage of Customer Information
Cross-selling  Cross-selling  Channel information is PO7
opportunities are opportunities consolidated and DS6
identified. may not be reviewed for possible
identified due to cross-selling
inadequate opportunities.
information
across channels.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 114


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Customer  Profitability  Customer analysis is DS6
profitability is information may performed to identify the
measured across not be shared least and most profitable
channels. across channels; customers across sales
therefore, channels.
management  Priority queuing is used
will not have a to move less-profitable
full view of the customers to channels
customer. that cost less to service.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 115


7. Telecommunication Infrastructure Risks Work Program
The following work program will help manage the telecommunication infrastructure risks for
customer relationship management. Any person auditing, reviewing or advising on controls in a
CRM project will need to select tasks from the work program and to consider the key issues
raised in the IT Governance Institute publication Risks of Customer Relationship Management as
part of their preparation. The work program should not be used as a checklist of best practice, but
as a selection of examples of good practice that can be applied. By using the work programs
blindly, there is a risk of losing the confidence of the auditee and even of missing the largest risks
in the project, due to the peculiarities of each project. Therefore, work programs should be used
as guidance, and specific knowledge of the organization and risks should be added to it.

Note: A business objective may be listed more than once because it has multiple risks and
corresponding control objectives. Note disclaimer.

Business Risk Control Comments/ COBIT


Objective Results/ Reference
W/P Ref.
Call Handling
Calls are received,  Calls may be  ACD implementations AI3
routed and handled blocked. are tested properly to AI5
properly resulting  Calls may be ensure they are coded AI6
in prompt dropped. correctly to route calls DS7
resolution.  Calls may be to the proper agent, to DS9
misdirected. provide correct
 Unauthorized announcements to a
database access caller and to place calls
may occur. into voice mail.
 Only trained personnel
can make changes to
ACDs and those
changes are tested in a
controlled environment
at offpeak times.
 Other controls include
properly configuring
the tables that
indicating to the long-
distance telephone
organization where toll
free 800 numbers
should terminate.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 116


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Implementation
Telecommunica-  Applications and  Software is tested to AI3
tions infrastructure systems may fail detect programming AI5
is implemented from incorrect errors. AI6
properly. configurations or  Software is tested to
inadequate ensure it operates as
engineering. intended in a live
 Changes may environment.
falsely appear to  Modifications made
be successful, subsequent to initial
and are later, testing are retested.
during call center  Systems and
peak operations, applications are backed
found out to be up prior to installation.
defective.  Implementations are
 Data authorized and signed-
communications off by management.
and voice  Application features are
communications documented.
may not be  Users are trained on the
coordinated software.
properly.  Acceptance testing and
 Redundancy may operations (e.g., backup
not be built into and recovery) testing
the systems. are performed.
 Agents may not  Formal change
be comfortable management
with procedures exist.
modifications to
call flows or
their work
menus.
 Response time
degradations
may exist.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 117


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Efficiency
Customer  Serious service  Statistical analysis and DS1
interaction center level impairment real-time monitoring is M1
operations and and excess costs used to measure and
systems are may exist. improve efficiency.
efficient.  The contact Reader boards, also
center may not called marquees, are
be organized and sometimes used to
tooled monitor metrics and
effectively so statistics.
workers have to
get up for
faxing, obtaining
reference
material, and
performing other
business
functions away
from their
workstation.
Business Continuity
Business continuity  Customer  Budgets for disaster DS2
and disaster interaction recovery options are DS4
recovery plans can center operations drafted, not only to
recover systems may be provide electronic
and operations interrupted. backup systems for
quickly.  Customers may servers and local area
be dissatisfied. networks but also
 Costs may be enable customers to
excessive. receive uninterrupted
service.
 Disaster recovery
options that go beyond
the retrieval of data, to
include voice and data
communication and
the relocation of
business personnel to
alternative facilities,
have been researched.
Technical and business
personnel have
established a process
so everyone knows
that course of action to
take when an
emergency occurs.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 118


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
 Key call center
systems that have
plans for recovery
include:
- Voice mail
- Automatic call
distribution (ACD)
- E-mail servers
- Customer contact
database
- Standard response
database
 The call center BCP
plan consists of the
following:
- Plan purpose,
assumptions,
strategy,
responsibilities,
organization
- Plan activation, call
list, recovery
procedures,
restoration
procedures
- External contacts
- Plan testing and
maintenance
procedures
- A monitoring policy
- Social engineering

© Copyright IT Governance Institute 2003 [Link]/auditprograms 119


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Security
Physical security  Service may be  All areas related to PO4
exists over the disrupted telecommunications, DS12
PBX room, adjunct intentionally. including the PBX
equipment and  Equipment and room, communications
wiring closets. wiring may be server areas (e.g., for
damaged voice mail servers) and
accidentally. wiring closets are
 Unauthorized protected with
access to electronic locks and
confidential appropriate alarming.
information  Access to
(e.g., voice mail telecommunications
data) may be areas is limited to
granted. those who have a need
to work in the area.
 Vendors and repair
personnel from other
organizations are
preapproved for access
or subject to specific
control points, such as
signing visitor logs
and being escorted
when working in the
facilities.
Users and  Users whose  Each extension is DS5
telephones are duties do not assigned an DS12
assigned only the require long- appropriate “class of
level of telephony distance dialing service” that permits
access needed for may make only the level of
employees to unauthorized telephony access
perform their work. domestic and appropriate to either
international the person using it or
long distance its physical location.
personal calls at For example:
the 1) Only senior
organization’s executives with
expense. business need have
 Telephones in external call
lobby areas, forwarding
conference enabled.
rooms and other 2) Only the telecom
public areas may department has the
not be restricted, direct trunk select
so they may be feature, which
used to make typically is used
unauthorized for testing

© Copyright IT Governance Institute 2003 [Link]/auditprograms 120


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
long distance purposes. It can
calls. also be used to
perpetrate toll
fraud.
3) If it is required for
business purposes,
only trained
operators should
have the trunk-to-
trunk feature that
allows them to
connect an
incoming caller to
an outbound trunk.
This feature is
commonly used to
perpetrate toll
fraud.
4) Conference room
phones should not
have international
dialing privileges.
 Profiles are developed
for broad classes of
positions, including
contractors,
administrative
assistants, executives,
switchboard operators
and the standard
profile for most
employees. These
profiles relate to
classes of service and
other determinants of
functionality.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 121


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Password controls  Unauthorized  Standard good DS5
exist for the PBX, personnel may practices for passwords
voice mail and dial into the are used for all users,
other adjunct PBX administrative users
equipment. “maintenance and super users,
port” and obtain including:
the superuser - Adequate password
ID(s) via a length
password - Hard-to-guess
cracking utility. sequences
With this level - Elimination of
of access, installation default
telephone passwords
records may be - Published policies
destroyed, and and procedures for
critical system all users
parameters could - Mandatory
be changed. password changes
Changing every 60-90 days
parameters, such
as class of
service, may
shutdown the
PBX.
 Confidential
information left
in employee’s
voice mail boxes
may be obtained
and greetings
may be altered
maliciously.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 122


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Inactive or unused  Unauthorized  Using telephony DS5
resources are individuals may management tools, DS13
deleted. utilize assets are reviewed for
abandoned or currency and last date
unused voice of use. Unused
mail boxes for facilities are made
illegal and inactive or reused. For
untraceable example, voice mail
activities. boxes and IDs of
 Analog lines terminated employees,
connected to unused or unneeded
modems may be analog lines, modem
used to break facsimile lines, and
into computer telephone extensions
systems by are removed.
bypassing the IP  IDs are examined for
firewall via the good practices, such as
voice network, avoidance of common
and then names, etc.
compromising
ID passwords to
enter the PBX or
voice mail and
shutdown
services.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 123


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
PBX and voice  Security  All security parameters AI3
mail security parameters may in the PBX and voice DS5
parameters are set be set to default mail systems are
appropriately. or uncontrolled reviewed for
values. appropriate values.
 Intruders may Examples include:
easily penetrate - Voice mail, PBX
the PBX and superuser IDs and
commit toll administrative IDs
fraud by illegally are set to force
selling the password change
organization’s every 60 days.
long-distance - Tables used to
services to block calls to
others without premium numbers
the (e.g., 900 numbers)
organization’s are updated
knowledge or regularly.
authorization. - Trunk-to-trunk
 Unauthorized transfer is set to
personnel may “No.”
place long- - Maximum number
distance and of attempts to sign
international on as
calls, causing the “administrator” is
organization, set at three,
instead of the preventing the
individual who continued guessing
placed the calls, of passwords by
to incur unauthorized
fraudulent personnel.
charges for the - DISA (direct
calls. inward system
access) is disabled,
preventing
unauthorized
individuals from
perpetrating toll
fraud. For instance,
with DISA enabled,
users can dial into
the PBX, receive a
dial tone, and then
dial out and make
an unauthorized
call.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 124


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Telecommunica-  Trunk access  Manual documentation AI4
tions codes, the containing critical, DS5
documentation is maintenance security-related
secured. port dial-in information is stored
number, and in locked cabinets.
other sensitive  Sensitive electronic
information may documentation on CD-
be obtained ROMs is protected
internally and adequately with
used for passwords and other
unauthorized standard security
penetration of measures.
the PBX.
Specific functions  Hackers may use  Management PO2
that are known to the “call forward periodically review the PO4
create external” feature security structure of the AI6
vulnerabilities are to perpetrate toll PBX, voice mail and DS5
reviewed to ensure fraud. They may adjuncts to ensure that
that if they are not accomplish this excessive permissions
disabled, by having an are not granted.
management has accomplice call Examples include:
made a conscious forward phones - Blocking area
decision to keep to an codes where no
them active based unauthorized business is
on business needs. domestic or conducted
international - Eliminating the
location, then ability to get dial
call that tone from voice
extension so mail
they are - Eliminating the
forwarded to the “call forward
intended external” feature on
number. most telephones
 Hackers may - Limiting call-out
penetrate users’ features within the
voice mail, enter data center
a two digit code, - Limiting lobby
get dial tone and telephones to local
make calls calls only
anywhere in the
world.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 125


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
The PBX and  Unauthorized  The maintenance port PO4
related equipment individuals may on the PBX is AI2
are protected from obtain the range protected by a two-
unauthorized of telephone factor authentication
access via a dial-up numbers used in code, greatly reducing
modem. an organization the likelihood of
and war dial to unauthorized access.
identify the PBX  The analog line
maintenance connecting the
port. maintenance port to
 Using password the outside world uses
crackers and a telephone number
other techniques, that is completely out
hackers may of the normal range of
penetrate the business numbers.
PBX and voice  The maintenance line
mail systems. does not go through
the PBX, but comes
directly from the local
telephone organization
(e.g., central office).
Telecommunica-  A break-in may  Exception reporting is AI4
tions activities are occur and not be well designed to DS13
monitored detected until the identify unusual PO2
appropriately. volume of toll activity. For example, M1
fraud activity reports are generated
becomes that summarize calls to
significant international locations,
enough to cause list all calls over four
obvious hours and show any
problems, such major repetition of
as excessive very short calls,
busy signals, indicating hacker
indicating all activity.
trunks are being  Exception reports are
used for summarized at a
unauthorized practical level to
traffic. identify suspicious
activity.
 Exception reports are
provided online, via a
web browser.
 Exception reports are
monitored on a timely
basis.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 126


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Alarm systems  Unauthorized  PBX management AI4
provide real-time access may be software monitors both DS5
alerts that gained to the potential fraudulent DS10
operational PBX activities as well as
problems or maintenance operational
unusual events, port by repeated malfunctions, such as
possibly attempts to crack failed trunk lines or
fraudulent, are in the ID/password PBX call flow
progress. combinations. interruption.
 Unauthorized  Procedures exist for
attacks may not promptly investigating
be detected. and resolving
 Operational fraudulent activities
malfunctions and operational
may not be malfunctions.
detected, so
telephone
service may be
interrupted.
Telecom  Employees may  Charge-back reports DS1
expenditures are incur large are produced every DS6
monitored. internal month showing M1
telephone telecom expenditures
charges for the at the departmental
organization by level to identify
frequently charges that indicate
placing personal either internal abuse or
calls to long- external toll fraud.
distance or  Managers review
international charges via a browser
locations. and are able to quickly
 Telecom charges identify suspicious
may be activity or charges.
summarized at a  Telecom charge-back
high level so that reports are produced
their with sufficient detail to
inappropriate or enable detection of
fraudulent inappropriate or
activity is not fraudulent activity.
detected. Examples of reports
include calls to toll-
fraud hot spots, the top
20 long duration calls
and the top 20 most
expensive calls.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 127


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
External  Unauthorized  Using the long- M1
monitoring individuals, distance carrier, PBX
provides a second having thwarted vendor or other parties,
line of defense the all calls are monitored
against toll fraud. organization’s for unusual traffic
internal barriers patterns, such as a 500
to toll fraud, percent increase in
may have free calls to a particular
reign to the PBX international and long
and pass distance location. The
thousands of monitoring
calls through the organization uses
victim PBX, sophisticated
resulting in very algorithms to detect
large long- fraud.
distance or  Once unusual activity
international is detected,
charges. management is
notified and presented
with options to
terminate the activity.
Security restricts  Unauthorized  Access to powerful DS5
access to sensitive individuals may PBX and CRM
powerful functions. commit toll functions should be
fraud. restricted properly.
As a last line of  The PBX may  Arrangements are PO8
defense, the be compromised made with the PBX
organization resulting in a vendor or long-
maintains toll fraud large financial distance carrier to
insurance. loss. purchase toll fraud
insurance. Any actual
losses beyond the
deductible are covered.
 The telecom manager
reviews security
measures to ensure
compliance with the
caveats of the toll-
fraud insurance.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 128


8. Security Risks Work Program
The following work program will help perform a high-level security audit and manage the
security risks for customer relationship management. Any person auditing, reviewing or advising
on controls in a CRM project will need to select tasks from the work program and to consider the
key issues raised in the IT Governance Institute publication Risks of Customer Relationship
Management as part of their preparation. The work program should not be used as a checklist of
best practice, but as a selection of examples of good practice that can be applied. By using the
work programs blindly, there is a risk of losing the confidence of the auditee and even of missing
the largest risks in the project, due to the peculiarities of each project. Therefore, work programs
should be used as guidance and specific knowledge of the organization and risks added to it.

Note: A business objective may be listed more than once because it has multiple risks and
corresponding control objectives. Note disclaimer.

Business Risk Control Comments/ COBIT


Objective Results/ Reference
W/P Ref.
User Management
Default accounts  Default accounts  The default accounts PO4
are safeguarded. may be (e.g., administrator and AI3
compromised. guest accounts) are DS5
Since default renamed immediately
accounts are after installation to an
widely known, unidentifiable name.
these are usually  Passwords for default
the first accounts accounts are changed to
that an intruder a not easily guessed
will attempt to use. password, e.g., a long
Many of these password containing
accounts have both alpha and numeric
powerful system characters.
access; therefore,  Accounts are disabled if
intruders can gain they are not being used.
extensive system
access.
 If default accounts
are not renamed,
an attacker may
launch a brute
force attack to
guess passwords
for these default
accounts.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 129


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Groups contain  When  Individuals are assigned PO4
only appropriate unnecessary as members of the DS5
users. users are administrator’s group, M1
assigned as only if absolutely
members of necessary.
groups that have  Users are assigned to
extended groups properly.
privileges, they  The groups report is
may use this monitored on a regular
enhanced ability basis to ensure that only
to compromise authorized users are
the security of members of these
the system and groups.
gain
unauthorized
access to
sensitive system
data.
Naming  Users may not  Standard naming DS5
conventions are be easily conventions are DS10
established and identified, so established and AI3
followed for all unusual activity consistently followed for
user accounts (e.g., may not be naming each type of
end users, identified. user, so that users within
contractors, each group can be
consultants and identified easily.
vendors).  Temporary accounts
used for contractors,
consultants and vendors
follow an identifiable
naming convention that
allows these accounts to
be easily identified and
purged if warranted.
All users and  Domain security  All existing groups DS5
groups in the may be within a specific
domain are known compromised, as domain are
and documented. security documented according
personnel are not to corporate policy.
familiar with
authorized vs.
unauthorized
users.
Accounts for  Existence of  Procedures exist to PO7
individuals who are accounts that are promptly remove AI2
no longer employed no longer needed unneeded user AI4
or have a increases the risk accounts from the DS5

© Copyright IT Governance Institute 2003 [Link]/auditprograms 130


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
requirement for that system. They include:
system access are unauthorized - Obtaining a listing
deleted. personnel may of recently
gain separated
inappropriate employees from the
access via these HR department and
accounts and it ensuring that the
would not be former employee’s
identified as account(s) have
unusual activity. been removed or
disabled from the
system.
- Automated
integration exists
between the HR
system and the
security system so
user accounts are
automatically
locked, inactivated,
changed or deleted
when an employee
is terminated or
transferred.
- Inactive accounts
are monitored
periodically (e.g.,
after a specified
period of
inactivity).
User accounts are  Extraneous,  All user accounts have an DS5
descriptive. unneeded user applicable, informative
accounts may be full name and
created. description, such as
 Security department, division, etc.
administrators may
not know the
background of
users assigned to
user IDs;
therefore, it may
be difficult to
understand if user
activities are
appropriate.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 131


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Passwords are  The automatic  The automatic logon AI#
secured within the logon option may options for servers are DS5
registry. embed the not enabled. All users
password of must enter a user name
accounts in the and password each time
registry in clear they log on to the
text; therefore, system.
passwords may be  The registry is reviewed
compromised. periodically to ensure
 The default that it does not contain
password may default passwords.
exist within the
registry and,
therefore, be
compromised.
Any account that  A malicious user  All inactive user DS5
has not logged on may gain access accounts are disabled. DS7
for an extended to system  User account listings are DS10
period of time is resources used reviewed to identify the PO6
disabled. by these last logon times of users
accounts. to ensure that no one
exceeds corporate
standards indicating the
number of days of
inactivity allowed before
user IDs are locked or
deleted.
 If corporate standards do
not exist, industry
standards are used, such
as 60 days of inactivity.
Privileged user  The  Privileged account DS5
passwords are not effectiveness of passwords are
widely distributed. passwords for distributed only to those
sensitive or individuals with a
critical accounts legitimate business need
may be for such access.
weakened due to
excessive
distribution.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 132


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Password Management
Default passwords  Application  The administrator is AI3
supplied with default passwords interviewed to ensure DS5
software packages may be widely that all default passwords
are changed upon known and have been renamed
installation. therefore the and/or disabled if the
default user IDs account is not being
are easy targets for used.
attacks.
 Unauthorized
access may be
obtained if these
passwords are not
changed.
Passwords are  Passwords may  Temporary passwords do DS5
unique. be easily not remain in use. All
guessable, new users are required to
resulting in change their password
unauthorized upon their initial login.
access to the  Generic or predictable
system. passwords are not used
as an initial password.
Each new account is
created with a unique
and difficult-to-
determine password.
The administrator  The system or  The administrator DS4
password is user accounts password can be DS5
available for may be locked obtained in the event of DS10
emergencies. and an an emergency.
administrator  The administrator
account may not passwords are stored in a
be available, physically secure
resulting in location on and offsite.
significant
downtime.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 133


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Accounts are  User accounts  The account lockout PO6
locked to prevent may be feature is enabled and AI3
invalid logon compromised the related parameters DS5
attempts. through brute are set in accordance DS7
force attacks. with corporate security
standards and guidelines.
 If no corporate policy
exists, industry
guidelines are used,
which state that accounts
are locked after three
invalid logon attempts
and that the invalid
logon counter is reset
after 1,440 minutes.
 Locked accounts remain
locked indefinitely until
an administrator
manually unlocks them.
The password for  The useful life of  All passwords, including PO6
the administrator any compromised the administrative DS5
account is unique passwords may not password, are changed
across all servers. be limited. periodically in
 A common accordance with
administrator corporate standards.
password on
multiple systems
may increase
exposure to all
systems, because
unauthorized
personnel have
access to all
systems if they
compromise the
password.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 134


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Data are classified  Unauthorized  Data classification is a PO2
and mapped to access to data primary driver for PO4
security needs. may occur. determining the proper DS5
security measures
needed.
 By mapping the data to
data owners and
understanding the data
classifications,
management are able to
determine what groups
of users need access to
data.
 This data classification
feeds into the design of
security roles that are
eventually configured
into the system.
Strong password  Users may reduce  User-level overrides of DS5
controls restrict the effectiveness password policies are not
access to the of their specific allowed for any user
system. password controls. accounts, except for
 Unauthorized service accounts.
access may occur
if passwords are
compromised.
Group Management
Local and global  Network and  User accounts are PO4
groups simplify security logically grouped DS5
network and administration through the use of global DS11
security may be ineffective. groups in the
administration. authentication domain.
 Users are grouped
according to similar job
functions, departments
or access requirements.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 135


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Naming  Nonstandard,  Standard naming DS5
conventions are unauthorized conventions are set for DS9
established and groups may not be each type of user group. DS11
followed for all identified easily. Each user group can be
global and local  Unauthorized identified easily.
groups. access may occur.  Global groups have
different naming
standards than local
groups.
 Groups are named,
identifying the type of
group, group purpose,
and department.
 No unnecessary
additional groups exist
on the system.
 Other than the built-in
global groups, no global
groups exist outside of
the authentication
domains.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 136


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
File System Access and Management
Access to  Granting  The most restrictive AI2
application and excessive level of permissions is DS5
system directories permissions to used for application and DS11
and files is applications may system files and
restricted. lead to directories. No users,
inappropriate including IT and end
access and users, are allowed
unauthorized excessive permission to
transactions. application files and
directories.
 If under certain
circumstances relaxed
permissions are
necessary, new groups
are created to manage
relaxed permissions.
Then, the specific users
are assigned to the new
group, instead of the
regular group.
 Application and system
directories do not allow
“write,” “delete,” and
“change” permissions to
users.
 Application and system
directories do not allow
“take ownership” to
users.
 The built-in “special”
group has no
permissions.
Data files are  The appropriate  Data files are stored in AI2
segregated from level of security segregated directories DS5
application and may not be granted external to the
system directories. for each type of application and system
file, and therefore, directories, possibly in
it may be too the data owners’ home
excessive. directories, or the
 Directory application-specified data
permission levels directory.
may be assigned
accidentally to
executable
program files.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 137


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Maintenance and Operations
Unattended  Unattended  When workstations are PO4
workstations are servers and not being used, the DS5
secured. workstations accounts are logged off
may be from the system console.
compromised.  Users are forced to
enable password-
protected screensavers.
 In Windows 2000
environments, users lock
their workstations.
Auditing, Logging and Monitoring
Auditing is enabled  Unauthorized  Auditing of sensitive DS5
for critical files and access to the system and application M3
directories. system may not files and directories is
be detected and enabled. For instance,
terminated in a changes to system
timely manner registry keys are
due to a lack of audited.
audit trail.
All audit logs are  Inadequate  Policies are followed PO8
archived in retention of audit properly for archiving DS5
accordance with logs may result and purging audit logs. DS13
corporate standards in the inability  Organization and M3
and regulatory of an regulatory requirements
requirements. organization to (e.g., US Internal
defend itself Revenue Service, US
against Federal Trade
unauthorized Commission) are met.
access.  Access to “read,”
“change,” “delete” audit
files is restricted
properly.
Audit logs are  Unauthorized  Audit logs containing DS5
secured. personnel may sensitive system DS13
delete audit logs information are
to eliminate the secured properly (e.g.,
audit trails. password protected).

© Copyright IT Governance Institute 2003 [Link]/auditprograms 138


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
System Development and Change Control
Production  Unauthorized  Programmers and PO4
application and access to developers do not have PO11
data files are production and access to production or AI5
secured. data files may intermediate program AI6
exist. and data files. DS9
 Separate servers are
utilized for production,
development and testing
environments. If separate
servers are not utilized,
developers have access
only to development
files and directories.
They do not have any
access to test and
production directories.
 The migration of
programs from
development and testing
environments to the
production environment
is controlled through an
appropriate segregation
of roles.
Security Administration Activities
Prior user names  Unauthorized  When logging on to the PO6
are not displayed at users may gain system, the last user DS5
login. knowledge of name and default user
the client name are not displayed
domain naming at login.
standards and
the user name of
the last user to
log on to the
system. This
information may
be used to gain
unauthorized
access to the
domain.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 139


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
The system does  A full audit log  Full audit logs do not DS10
not shut down if the may cause the shut down the server.
audit log becomes server to be In some cases, it may
full. shutdown. be necessary to shut
down the server when
the audit log becomes
full, to ensure that an
audit trail is always in
existence.
Only legitimate  The scheduled  The administrator is the DS11
jobs are scheduled. service may only one to schedule DS13
allow an jobs in the system.
unauthorized  If a separate individual
user to execute performs this function,
malicious code the administrator still
as an retains rights to schedule
administrator jobs, but only as a
backup.
Operational Resilience
Disaster recovery  Critical  Disaster recovery polices DS4
and business operations and exist for recovering
continuity plans systems may not critical operations and
exist. be recoverable in systems in the event of
the event of a a disaster.
disaster.  An organizationwide
disaster recovery plan
exists. The plan is
updated frequently and
tested periodically.
System redundancy  Hardware  System redundancy (e.g., DS4
and contingency failures may lead mirroring, load
plans are used. to the loss or balancing) and
corruption of contingency plans are
critical data. established for critical
servers (e.g., web server
for an e-business).
An uninterrupted  Data and  An uninterrupted power DS4
power supply is systems may be supply is used for all DS12
used for critical lost or corrupted critical systems. This
systems. in the event of a provides power for the
power loss. system to be shut down
in the event of power
loss or degradation.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 140


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
System backups are  The systems may  Incremental daily DS4
performed on a not be backups and DS11
regular basis. recoverable. weekly/monthly full-
system backups are
performed for all critical
systems.
 The administrator and
business lead determine
the frequency and
completeness of backups
(e.g., incremental, partial
or full).
 Daily and weekly/
monthly backups are
stored in a secured
offsite location.
Networking
Workstation and  Unauthorized  Users are restricted on DS5
time restrictions are personnel may the system by enforcing
enforced. gain access to workstation and time
systems during restrictions. Note: these
nonpeak hours controls usually are
when user IDs are feasible only for users
dormant. that utilize one
workstation during set
hours of the day.
Users are forcibly  Unauthorized  Network resources can DS5
disconnected from personnel may be accessed only if the
servers when their gain access to user is specifically
login hours expire. systems through authorized for access
unattended user during those hours.
logon sessions.  The appropriate block-
out times are set for the
user community.
 Users are disconnected
automatically from the
system when their login
hour expires

© Copyright IT Governance Institute 2003 [Link]/auditprograms 141


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Physical Access
Physical access to  Unauthorized  Access to the data center DS9
the data center is personnel may is restricted properly DS11
strictly controlled. have physical based on responsibility/ DS12
access to the data roles. DS13
center, and  All data center access is
therefore, access to logged and reviewed on
the system a regular basis.
consoles and
operations
information.
Security Policies and Procedures
A general security  Without a full risk  A full risk assessment is PO9
risk assessment is assessment, critical performed to identify
performed. systems and critical systems and
applications may applications and the
not be identified appropriateness of
and secured security settings.
properly.
A security  Users who are not  A formal security PO6
awareness program reminded of good awareness program PO7
exists. security practices exists and is updated DS5
may create regularly.
security violations  All new employees must
inadvertently or sign an employee
intentionally. information security
policy when hired.
A data  Without a data  A data classification PO2
classification classification system exists and all DS5
structure is system, it may be departments and
identified clearly. difficult to employees understand
dedicate how to apply the
appropriate classification system
resources to (e.g., stamping
protect high-value documents, watermarks).
data.
The policies and  Employees may  Security policies and PO6
procedures are not understand procedures are widely PO7
readily accessible security policies distributed throughout DS5
to all employees. and procedures, the organization.
and therefore,
they may cause
security
violations
inadvertently or
intentionally.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 142


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Security training is  Users who do not  New hire orientation PO7
a part of new understand good includes security DS7
employee security practices awareness training.
orientation. may cause security
violations
inadvertently or
intentionally.
Security Administration and Management
Terminated  Users may  Separations from the PO7
employees are continue to access organization are DS5
promptly removed the system after communicated
from the system. they have been immediately to the
terminated and administrator and ex-
have no legal employees are removed
relationship with promptly from the
the organization. system.
A formal security  End users may not  A security team or PO6
administration understand whom system administrator DS5
function exists and to call when exists and is completely
is communicated violations are dedicated to the security
throughout the identified. of the corporate network
organization.  If security is not and infrastructure.
someone’s focused
effort, it may be
forgotten when
other crises occur.
System, application  Inappropriate  A formal periodic review DS13
and user access is access may not be process of system, M4
periodically detected. application and user
reviewed. access is performed on a
regular basis.
A standard profile  Unauthorized  A standard “load” or DS9
exists for PC software and “image” exists for all DS13
configurations to hardware additions laptops and desktops
ensure consistency. may be recognized deployed by the
quickly. organization.
 Software and hardware
licenses are reviewed
periodically for
appropriateness.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 143


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
System Level Controls
Administrator  System  No one person can create DS5
activities are administrators may potentially business- DS13
limited, controlled perform crippling changes to the M1
and monitored. unauthorized network.
activities, which  Administrator activities
may not be are limited, controlled
detected. and monitored.
For high-volume  Volumes of  System logging (e.g., DS8
systems, automated logging data may inherent to the system or DS10
monitoring tools be produced daily. third-party tools) is DS13
are utilized. Without automated performed.
tools to flag
possibly
inappropriate
access, it may go
unnoticed.
Internet Information Server
The latest Internet  If the version of  The most current version PO3
information server the operating of the operating system AI3
program directory system or and application contain DS5
structure is applications is processing and security
installed. not current, enhancements.
unauthorized  The most recent security
users may be able patches have been
to exploit applied to the servers.
weaknesses.
Only required  Unnecessary  The Internet information DS5
server extensions server extensions server’s application is DS11
are used. may expose the configured to check for
IIS server to the existence of URLs
unnecessary before passing them on
attacks. to the system’s DLLs.
 Only required DLLs are
mapped for the server.
Firewall Configuration
Only authorized  Unauthorized  Only authorized ports are DS5
ports are allowed personnel may open on the firewall
on the firewalls. attempt to based on the
compromise the requirements of the
firewall or other applications within the
network devices environment.
by targeting
specific ports or
services.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 144


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Online business  Unauthorized  Online business DS5
transactions are personnel may transactions are
encrypted (e.g., sniff unencrypted encrypted.
SSL). transactions.
Critical firewalls  In the event of a  Critical firewalls are DS5
are configured with hardware failure, designed to provide 100
fail-over or fault users may not be percent uptime through
tolerance able to access fail-over or fault
capabilities. resources (e.g., tolerance.
Internet).
Segregation of Duties/Application-based Security
Access to sensitive  Unauthorized  Incompatible duties PO4
and powerful access to CRM are separated properly DS5
transactions is functions may within the CRM
restricted properly. exist. system and other
applications, for
example:
- The ability to
create a customer
and process a
credit
- The ability to
create a vendor
and approve
marketing
expenditures
- The ability to
physically
access/take spare
parts and process
spare parts
inventory
adjustments
 Access to
sensitive/powerful
master data and
transactions, for
example, prices and
credit limits which could
be used to support fraud
and collusion with a
customer, is restricted
properly within the CRM
system.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 145


9. Project Management Risks Work Program
The following work program will help control the project management risks of a customer
relationship implementation project. Any person auditing, reviewing or advising on controls in a
CRM project will need to select tasks from the work program and to consider the key issues
raised in the IT Governance Institute publication Risks of Customer Relationship Management as
part of their preparation. The work program should not be used as a checklist of best practice, but
as a selection of examples of good practice that can be applied. By using the work programs
blindly, there is a risk of losing the confidence of the auditee and even of missing the largest risks
in the project, due to the peculiarities of each project. Therefore, work programs should be used
as guidance, and specific knowledge of the organization and risks should be added to it.

Note: A business objective may be listed more than once because it has multiple risks and
corresponding control objectives. Note disclaimer.

Business Risk Control Comments/ COBIT


Objective Results Reference
W/P Ref.
Project Initiation
Senior  Senior  The project steering PO1
management management may committee reviews and PO10
reviews the project not support the approves project
charter and plan project. initiation documents to
and approves the  The project may ensure that the project is
project prior to the not be in in alignment with
project alignment with business objectives and
commencing. business goals.
objectives and  The project is approved,
goals. with the commitment
of continued senior
management support.
 Control is exercised
over the existence of
formal and written
project management
procedures in the
organization (on SDLC
bases), which provide a
good starting point for
effective project
management.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 146


Business Risk Control Comments/ COBIT
Objective Results Reference
W/P Ref.
Project Scope Management
Project scope is  The project may  The project PO10
managed not be management team AI6
effectively. implemented on should adhere to the DS9
time or on budget business case, taking
due to excessive into consideration
scope changes. priority objectives set
and approved by senior
management.
 The project team
always refers back to
the CRM values to
guide the decision-
making process.
 A strong configuration
and change
management process
used when changing
scope.
 The scope is altered
only with executive
approval and a thorough
analysis of the impact
of scope changes.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 147


Business Risk Control Comments/ COBIT
Objective Results Reference
W/P Ref.
Project Integration and Management
For complex  The project may  A project support office PO4
projects, a project not be well is established to manage PO10
support office is coordinated, the following aspects of
established. managed and the project: issue and
controlled. risk management,
dependency
management, scope
management, cost and
resource management,
project standards and
procedures
establishment, project
planning and
integration, vendor and
contractor management
and organizational
change management.
 Roles and
responsibilities are
defined clearly, and a
project support office is
established, with
resources at a sufficient
experience level.
The project  The project may  During project start-up PO5
contains well- not be well the following areas are PO6
defined business defined; determined and PO10
justification, therefore, the documented:
budget, scope, business - Business
dates and key justification, justification
resources. budget, scope, - Budget statement
dates and key and justification
resources are - Scope definition
misunderstood. - High-level plan
including dates and
phases
- Key personnel
identification and
resource levels
- Key internal and
external
dependencies
- Critical success
factors
- Key risks

© Copyright IT Governance Institute 2003 [Link]/auditprograms 148


Business Risk Control Comments/ COBIT
Objective Results Reference
W/P Ref.
A steering  The project may  The role of the steering PO4
committee not meet committee is defined PO10
oversees the objectives, clearly. A determination
project. milestones or is made as to whether
budget. the committee has
approval authority or is
in a guidance mode
with approval authority
vested in the managers,
especially for the
following items:
 Project schedule
 Project standards
 Project personnel
assignments
 Project deliverables
 If the project is to be
managed through a
senior management
position, this reporting
line and accountability
should be established
and agreed.

A steering  The project may  A steering committee PO4


committee not meet is established that has PO10
oversees the objectives, representation from all
project. milestones or the business functions
budget. involved in using,
operating and setting
policy for the
proposed system. The
following types of
personnel are
considered for
membership in the
committee:
- Senior
management—
depends on
whether
management
wishes to delegate
steering committee
roles or perform a
hands-on function
- Information
systems personnel

© Copyright IT Governance Institute 2003 [Link]/auditprograms 149


Business Risk Control Comments/ COBIT
Objective Results Reference
W/P Ref.
—representing
database
administration, data
administration, e-
commerce,
application
development,
security, etc.
- Key end-users—
representing major
functional areas
and consisting of
strong individuals
with key
understanding of
business
- Technology
personnel—with
key understanding
of the new
technology and its
impact on the
organization
Internal and  All project  Project team managers PO1
external project dependencies may keep a central record of AI3
dependencies are not be identified or all dependencies during AI6
identified and monitored. the lifetime of the AI8
monitored. Therefore, project.
misunderstood or  Each dependency is
undetected project associated with an owner
dependencies may responsible for regularly
negatively impact tracking and updating
the project. the dependencies.
 Regular meetings are
scheduled to facilitate
communication of
dependencies between
project teams.
 External and internal
dependencies are
reported to senior
management regularly,
thus making
management aware of
possible impacts on
project deliverables or
milestones.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 150


Business Risk Control Comments/ COBIT
Objective Results Reference
W/P Ref.
Dependencies are  Issues raised by  Project dependencies PO1
managed dependencies are prioritized, and an PO10
effectively. may not be action plan to resolve
resolved, them is agreed upon
increasing the and implemented.
risk of project
failure.
A common  Separate and  Procedures and PO6
approach for inconsistent standards are in place PO10
project approaches may for:
administration is be used for the - New project
utilized. administration of definition and
different scope
projects. - Common project
tools (i.e., MS
Project)
- Project-related
travel and
accommodation
- Diary management
for key project
personnel
Changes and the  The impact of  Any change or deviation PO10
possible impact changes to the to the project baseline AI6
they have on project scope and requires a change request
project deliverables timeline may not to be completed and
and timelines are be identified before authorized by senior
communicated, implementation. management before
monitored and  Changes may be work is scheduled or
controlled. made without undertaken.
proper  All change requests
authorization. include an impact
 Excessive changes assessment and are
may negatively prioritized.
impact project  All change requests are
timing and scope. documented in a central
control log that contains
the current status.
 The central control log is
updated on an ongoing
basis.
 At agreed intervals,
status reports on changes
are prepared and
communicated to the
project team and senior
management.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 151


Business Risk Control Comments/ COBIT
Objective Results Reference
W/P Ref.
Time and Activity Management
Project meets  Project may be A project plan exists to PO10
planned milestones delivered late. provide a single and AI2
and deadlines. consolidated repository
of task, resource and
cost information.
A clear owner is
responsible for
maintaining the plan,
i.e., rescheduling,
capturing actual
hours/milestones, and
producing progress
reports against the
plan.
The project plan is
baselined when work
is approved initially.
When additional work
beyond the original
scope is sanctioned
through a formal
change request
procedure, the plan is
revised and the new
tasks are baselined.
The baseline process
saves the original
estimates and schedule
for comparison against
the working schedule,
which allows slippage
and/or gain to be
monitored easily.
Project performance and
progress is monitored
against the plan to
provide an early
warning of potential
issues when milestones
are not met within the
specified timeframe.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 152


Business Risk Control Comments/ COBIT
Objective Results Reference
W/P Ref.
Cost Management
Costs are controlled  The project may  Initial assessments of PO5
to stay within the exceed its interfaces, data PO10
project budget. budgeted costs. conversion efforts, AI6
customization and
expertise are
determined to ensure
that project costs are
managed and the
budget is realistic.
 Formal proven
methodologies are used
for planning resources,
planning and estimating
costs, and budgeting
and monitoring costs.
Project Communications Management
Senior management  Senior A communication plan and PO6
is kept regularly management may reporting schedule are PO10
informed of the not be made defined at the onset of
progress of projects aware of all risks the project.
and work streams. and issues on a Reporting procedures are
timely basis. developed to describe
the frequency and type
of reporting, report
distribution and
personnel responsible for
each critical project
activity and action item.
Reporting levels, report
contents and an
overview of items to be
tracked regularly are
clearly documented.
Regular meetings are
conducted to
communicate project
progress, raise key
issues, solicit critical
management input and
make key decisions.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 153


Business Risk Control Comments/ COBIT
Objective Results Reference
W/P Ref.
The project library  Pertinent project  A target list of PO10
provides logistical information may documents to be
and informative not be available collected in both hard
support to both the and readily and soft (electronic)
project support accessible to all formats is compiled.
office and the team members.  The library is set up and
project groups. operates so that:
 Reference material is
easily accessible to
all project personnel.
 Distribution of
sensitive documents
is controlled.
 Standard version
control of documents
is maintained.
Documents are  Project team  Standard software tools AI4
produced and members may are utilized throughout PO11
changed according create documents the project.
to project without  Standard templates are
standards. following utilized.
consistent  Deliverable documents
standards. are subject to version
control.
 Documentation
standards are established
and followed
consistently for all key
project deliverables.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 154


Business Risk Control Comments/ COBIT
Objective Results Reference
W/P Ref.
Project Personnel Management
Project personnel  Personnel may not  The organization should PO7
should be managed understand their perform project PO10
appropriately. project roles. personnel planning to DS2
 Key personnel ensure that:
may be lost from - Project roles and
the project and the responsibilities are
organization, defined clearly.
causing the - The best resources
solution to fail. are acquired to work
on the CRM project.
- Resources are
trained properly to
perform their project
roles.
- Teams work well
together.
 If heavy reliance is
placed on outside
resources or contract
staff, sufficient
knowledge transfer is
ensured by pairing
company personnel with
technology/application
experts.
 Contingency plans and
incentives are provided
to ensure that project
personnel remain in key
knowledge champion
positions once the
system is implemented.
 Dependence placed on
contract staff is
moderated.
Organizational Change Management
(Refer to work program 11. Organizational Change Management, for a detailed work program
surrounding this area.)

© Copyright IT Governance Institute 2003 [Link]/auditprograms 155


Business Risk Control Comments/ COBIT
Objective Results Reference
W/P Ref.
Project Risk Management
All risks that may  All potential  A formal risk assessment PO1
impact the project risks may not be is undertaken at the start of PO9
are identified, identified. the project. PO10
documented and  Unmitigated  Each member of the
managed. risks may cause project team is given the
the project to fail opportunity to voice risk
to achieve concerns throughout the
deadlines, costs duration of the project.
or operational  All risks are captured and
objectives. documented in a risk log
on an ongoing basis.
 The project support office
is responsible for
maintaining a risk log and
for up-channeling risk
issues to senior
management.
 Each risk is associated
with an owner. The owner
is responsible for
developing a strategy to
mitigate the risk.
 The strategy includes a
brief plan of action to be
taken and the impacts that
the risks have on the
current project deadlines,
costs, or operational
objectives.
All issues arising  Issues may not  All issues are captured and PO6
throughout the be documented in an issue log PO10
project are communicated to on an ongoing basis. PO11
communicated and the appropriate  Each issue is associated
resolved in a timely levels within the with an owner responsible
manner. project or for its resolution.
organization.  At agreed intervals, status
 Issues may not reports on issues are
be resolved in a prepared and
timely manner. communicated to project
managers.
 An escalation procedure is
established to handle
issues that cannot be
solved at the project level.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 156


Business Risk Control Comments/ COBIT
Objective Results Reference
W/P Ref.
Quality Management
Project outcome  The final project  The organization’s existing PO10
meets or exceeds may not meet quality processes are used PO11
customer customer to establish a project M1
requirements. expectations. quality framework.
 The desired  Project quality controls
benefits of the and standards are
project may not established and applied
be realized. consistently throughout the
project.
 Acceptance and
completion criteria are
established and used to
facilitate quality control of
deliverables.
 Quality checkpoints are
established and used to
measure project processes
and deliverables against
quality standards and
criteria.
 Overall escalation
procedure and levels of
responsibility are
established and used to
escalate issues and resolve
disputes over rejection and
rework.
 Project quality is audited
on an ongoing basis.
The project is  Implementation  All project documentation PO10
closed formally activities may is completed and filed.
without significant not be  A project exit review is
open items. completed conducted to ensure that all
satisfactorily. project tasks are completed
 Contractual satisfactorily.
issues associated  Project contractual issues
with project are resolved.
closure may not  Project completion
be completed. documentation is produced
 Lessons learned and formally signed-off.
from project  Lessons learned are
issues may not discussed and documented.
be identified.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 157


Business Risk Control Comments/ COBIT
Objective Results Reference
W/P Ref.
Technology Management
Vendor  Vendors may  A vendor management PO10
performance is not adhere to process is defined and DS1
monitored against contract consistently applied DS2
contract specifications. throughout the project to
specifications. include:
- High-level and
detailed definition of
requirements
- Quality standards
- Quantification of
risk associated with
hiring the vendor
- Competitive
tendering
- Contract
requirements
- Vendor performance
monitoring
- Deliverable(s)
acceptance only if
the final product
meets or exceeds
expectations

© Copyright IT Governance Institute 2003 [Link]/auditprograms 158


Business Risk Control Comments/ COBIT
Objective Results Reference
W/P Ref.
Regulatory Compliance
The CRM project  The CRM  Project managers must PO8
and solution meets project and/or understand the PO10
regulatory, security CRM solution regulations and security
and privacy may not be and privacy
requirements. implemented in requirements facing their
compliance with CRM projects. They
regulations and incorporate project tasks
security and into the project plan to
privacy ensure that they are in
requirements. compliance with
regulations that impact
their project or the CRM
solution, for example:
 US Gramm-Leach-
Bliley Act (GLBA)
 US Computer
Systems Validation
 US FDA Electronic
Signatures and
Records
Requirements
 US 21 CFR Part 820
 US Health Insurance
Portability and
Accountability Act
(HIPAA)
 EU Data Protection
Directive
Cultural differences  When CRM  Careful attention PO6
are considered solutions are should be paid to PO7
when developing implemented cultural differences PO10
and implementing across borders, and a representative DS1
the CRM solution. or globally, from each country is
additional included in defining
complexities the CRM strategy/
may be vision, business case,
introduced. For analysis, design, etc.
instance, cultural
and economic
differences may
make strategies
and solutions
that work in one
country not
practical for
other countries.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 159


10. Benefits Realization Work Program
The following work program will help to ensure that the organization is realizing the benefits
from the customer relationship management implementation project. Any person auditing,
reviewing or advising on controls in a CRM project will need to select tasks from the work
program and to consider the key issues raised in the IT Governance Institute publication Risks of
Customer Relationship Management as part of their preparation. The work program should not be
used as a checklist of best practice, but as a selection of examples of good practice that can be
applied. By using the work programs blindly, there is a risk of losing the confidence of the
auditee and even of missing the largest risks in the project, due to the peculiarities of each project.
Therefore, work programs should be used as guidance and specific knowledge of the organization
and risks added to it.

Note: A business objective may be listed more than once because it has multiple risks and
corresponding control objectives. Note disclaimer.

Business Risk Control Comments/ COBIT


Objective Results Reference
W/P Ref.
Defining Business Benefits
The CRM  The organization’s  A business case is PO1
initiative is clearly objectives for developed for the CRM PO5
defined from the initiating a CRM project. PO10
beginning, with project may not be  The business case clearly
clearly articulated clear. identifies desired
anticipated  Management’s business benefits.
benefits. expectations may  The business case
not be articulated. prioritizes the
 The desired organization’s
benefits may not objectives.
be defined  The business case
realistically. presents the expected
return on investment
(ROI) and expected
payback period.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 160


Business Risk Control Comments/ COBIT
Objective Results Reference
W/P Ref.
The project plans  The project may  Anticipated benefits are PO10
and deliverables progress without a mapped to specific
are linked to the relationship to the project deliverables
business case and business case. during the project
desired benefits.  Project decisions planning phase.
may be made  All enabling benefits are
without regard to linked to direct benefits
original project to determine the
objectives and complete benefit path for
values. achieving the desired
 The organization business results.
may end up with a  All dependencies to
final project output project deliverables are
that does not meet identified and included
expectations. in the benefit path.
 Every project deliverable
is linked to a desired
objective or business
benefit.
Accountability is  Sponsors for  An appropriate business PO5
assigned for benefits may not or process owner is PO9
achieving each be identified. identified and assigned
benefit.  All activities accountability for each
necessary to benefit.
achieve the  Accountability rests with
benefits may not individuals who can
be completed. impact or influence the
delivery of project
outputs (e.g., process,
technology or people
changes).
Monitoring Benefits
Benefits  Project decisions  Accountable individuals PO10
monitoring is a may be made are part of the extended
continuous process without regard to project team and are
throughout the the original project involved actively.
project lifecycle. objectives and  Project decisions are
values. reviewed against
 The final project potential impact to
output may not anticipated benefits.
meet expectations.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 161


Business Risk Control Comments/ COBIT
Objective Results Reference
W/P Ref.
The indicators are  The organization  Success indicators are M1
identified for may not be able defined and PO10
measuring success. to measure communicated clearly to
performance and the project team.
success of the  Baseline performance
project. data are collected to
provide the basis for
comparison.
 Appropriate sets of
metrics are developed
for direct and enabling
benefits.
 Tools are used to
facilitate collection of
data and calculation of
results.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 162


11. Organizational Change Management Work Program
The following work program will help to ensure that the organization is managing the
organizational changes from the customer relationship management implementation project. Any
person auditing, reviewing or advising on controls in a CRM project will need to select tasks
from the work program and to consider the key issues raised in the IT Governance Institute
publication Risks of Customer Relationship Management as part of their preparation. The work
program should not be used as a checklist of best practice, but as a selection of examples of good
practice that can be applied. By using the work programs blindly, there is a risk of losing the
confidence of the auditee and even of missing the largest risks in the project, due to the
peculiarities of each project. Therefore, work programs should be used as guidance and specific
knowledge of the organization and risks added to it.

Note: A business objective may be listed more than once because it has multiple risks and
corresponding control objectives. Note disclaimer.

Business Risk Control Comments/ COBIT


Objective Results/ Reference
W/P Ref.
Organizational Change Management Process
There is a defined  There may be a  Change management AI6
project lack of focus and activities are included in PO6
workstream to activities to the overall project
address address planning activities for
organizational organizational the CRM
change. change implementation.
 No one may be  Change management
assigned timelines and milestones
responsibility or are incorporated in the
accountability for project plan.
organizational  The change management
alignment. team is included in all
 All activities project team meetings.
necessary to  The same level of
achieve reporting and monitoring
organizational of change management
change may not be activities is required as
completed. with all other project
workstreams.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 163


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Change  If the extent of  The objectives of the PO1
management changes that will CRM implementation PO4
requirements for result from the and its intended business AI6
the CRM CRM results are articulated.
implementation implementation  The changes (process,
are defined. are not clearly systems, organizational
understood, the structure, staffing, etc.)
appropriate steps that may be required are
to prepare the identified.
organization may  An owner for each of
not be undertaken defined change is
during the course identified.
of the  The change owner is
implementation. engaged as early as
possible in the
implementation.
Project Strategy
The project  Sustained  The organization is PO10
strategy delivers organizational focusing on delivering
quick wins, if commitment and quick wins when
needed, to support to the planning for the project
encourage morale initiative may to help ease user
and adoption. wane over time, adoption and build
without excitement for the new
demonstration of solution.
quick wins that  Demonstrable
clearly show the improvement to the
benefits of CRM process, or people’s
to the ability to contribute to
organization. the project’s end goal,
are shown.
 Quick wins are
communicated and
celebrated to maintain
momentum and
encourage continued
change support.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 164


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
The timing of  Organizational  Plan activities in AI6
organizational change activities alignment with overall PO10
change activities is may not be done in project milestones.
closely aligned coordination with  Change management
with project implementation timelines and milestones
activities and activities and are incorporated in the
timelines. communication. project plan.
 An attempt at  Include change
addressing management team in all
organizational project team meetings.
change may be
made only at the
time of, or after,
system rollout.
Project Sponsorship
Leadership is  Management  Senior management buy- PO1
engaged in change support may not in of the required
management be obtained; changes is obtained.
initiative.  Senior management
therefore, it is not
sustained during commitment to and
the support of change
implementation. management activities
that will be carried out to
prepare the organization
are obtained.
 A sponsor who will be
personally vested to
ensure project success is
identified.
Department Involvement and Employee Representation
Commitment is  If no commitment  The teams are built that PO3
obtained and is obtained from are responsible for PO4
maintained from specific carrying out change
key departments individuals to management activities.
and employee drive change  Involvement and
representatives. management, participation come from
activities will not all affected departments
be carried out as and the top performers
planned, and will are part of the project
end up falling team.
back to members  A communication
of the project framework is established
team. that will address
communication needs
for all levels—project
teams, stakeholders, end-
users, etc.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 165


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Plan for Change/Resistance to Change
Change strategy is  The organization’s  The organization’s AI6
defined. change readiness readiness to adopt the
is not assessed, required changes has
and therefore been assessed.
activities may not  The change management
be in line with activities are planned
organizational and defined in line with
requirements. the organization’s
change readiness.
 A change management
governance structure is
established that is
responsible for ensuring
that change management
activities are being
carried out as planned.
A change  The project team  A change management PO6
management and end users may culture exists to impact
culture is not embrace the the values, behaviors and
developed. changes. mindset of the project
team and end users.
The organization’s  The organization  Change readiness exists AI3
change readiness may not be ready along the lines of the AI5
is assessed and for the changes following categories. AI6
considered. being introduced - Project management DS4
through the new risks DS7
CRM  Project DS8
implementation. management DS10
expertise PO9
 Project PO10
management
methodology
 Program
management
 Project tools
 Project planning,
monitoring,
milestones
 Project controls
 Project scope and
approach
 Vendor and
contractor
management and
deliverables
 Project staffing

© Copyright IT Governance Institute 2003 [Link]/auditprograms 166


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
 Project training
 Project
communication
- Technical risks
 Hardware and
software design
methods
 System
architecture
design methods
 Networking
acceptance
procedures
 Performance,
sizing and
availability
acceptance
procedures
 Disaster
recovery and
business
continuity plans
- Functional risks
 Requirements
definition
methods
 Business process
design methods
 Data management
methods
 Reliability and
usability
 Legacy system
integration
methods
 Program change
management
- Executive
sponsorship
 Alignment with
other initiatives
 Commitment
 Executive Support
 Sponsorship
- User acceptance
testing approach and
results
 Conference room

© Copyright IT Governance Institute 2003 [Link]/auditprograms 167


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
pilot
 Testenvironment
 Test data
 Test approach
 Validation and
sign-offs
- Organizational risks
 Organizational
alignment
 Release integration
 Business process
redesign
methods
 Organizational
change
management
 Business process
change
integration
approach
 Skill gap analysis
and retraining
 Documentation
- Operational and
production support
 Problem resolution
and escalation
 User support (help
desks, etc.)
 IT production
support plans
 Documentation
- End-user training
and pilot
 Training program
 Training schedules
and participants
 Trainees’ feedback

© Copyright IT Governance Institute 2003 [Link]/auditprograms 168


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Organizational  There may be lack  The organization’s PO7
change addresses of readiness from training needs have been
the appropriate the organization to assessed.
areas such as accept and  Adequate training in line
training, implement CRM. with the organization’s
organizational  Organizational requirements is planned.
restructure and alignment and  CRM champions are
employee reorganization identified who will help
readiness. may not be communicate the
considered. benefits of CRM
 Appropriate throughout their
training and timing respective section of the
of training for organization.
users may be  Changes in functional
inappropriate. responsibilities are
identified and plans exist
for any necessary
organization restructure.
Communication
Organizational  There may be a  A communication PO6
change includes lack of framework exists, PO11
constant education communication addressing information
and with employees, needs at all levels.
communication users and  Existing communication
with employees customers. channels are utilized to
and sustained  Communication leverage the
stakeholder may be provided organization’s
management. without context to infrastructure.
implementation  Steps are identified to
activities and encourage regular
implications. dialogue with the user
 The business case community. Questions
and benefits may are encouraged and
not be feedback solicited as
communicated early as possible, and
clearly with the throughout the
message of implementation.
upcoming change.  User concerns are
 Rumors of project addressed, to minimize
activities and speculation.
implications may
be apparent prior
to any formal
communication.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 169


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
A change vision is  Users may be  A strategic vision is PO1
understood. apprehensive of developed and
the changes that communicated within
will occur and do the project team and the
not understand the organization. The vision
overall impact. is comprehensive and
 Users may reject operational so
the changes. employees understand
the overall impact and
also how it will impact
their job function.
 A compelling change
story exists for the
organization, functions
impacted and specific
employee roles.
Training
Employees and  Training may not  Training is planned PO7
customers receive teach workflow, sufficiently with
the proper processes, internal adequate time allotted
training. controls (e.g., and training materials to
approvals and support the users.
monitoring  Various teaching
controls), and new methods are used to
roles and promote retention of
responsibilities. information.
 Problems with  The training includes the
integrity of user’s role in the new
transactions, organization, the new
quality of data, processes and their
timeliness of responsibilities, in
input, lack of addition to how to use
consistency in the system.
monitoring
controls, etc., may
exist.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 170


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Functional Roles, Skills and Security
The organizational  Employees may  An organizational PO4
structure changes reject the changes reporting structure PO7
are understood. due to lack of exists.
understanding.  Employees’ roles and
their corresponding
performance measures
are clearly
communicated.
 Integrated workgroups
are used to develop the
new solution to ensure
a clear cross-
departmental
understanding.
Roles and  Incorrect security  Roles and PO7
responsibilities are may exist. responsibilities are PO10
defined clearly.  Incompatible developed early in the DS5
duties may not be implementation project DS7
segregated to ensure ample time
properly. for security, training
 Training may not and documentation of
be built properly. new responsibilities.
 Employees may  Role-based application
not have the right security is built and
skills for their users have access only
new roles. to transactions and
information they need
for business purposes.
 A segregation of duties
matrix ensures that
incompatible duties are
properly segregated.
 Training is in place for
all functional roles and
include interaction with
other roles/departments
and the overall business
processes, workflows,
and corresponding
impacts.
 Skill and training gaps
are identified early in
the implementation to
ensure that employees
can be properly trained.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 171


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Management Information and Data Sharing
Management are  Employees may  Employees can earn DS10
able to obtain reject new data incentives for
useful sharing models. maintaining accurate and
management  Management timely information in the
information and information and new systems.
data from the data may not be  An understanding of the
CRM system. useful. benefits to the
organization and to
specific groups of
employees from
maintaining accurately
and timely information is
communicated.
Business Process Change
Business processes  Departments and  Business practices and PO4
are changed to processes may not daily operational M1
accommodate the be realigned processes are reviewed,
new CRM properly. in light of the CRM
solution.  Employees may capabilities, to align
not understand them with CRM
cross-departmental objectives, streamline
workflows and the processes to become
business more efficient and take
processes; advantage of best
therefore, they practices.
need to be
understood by the
project team when
they are building
the new CRM
solution and also
by the end-user
departments who
will be using the
new system.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 172


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Reward Mechanisms
Performance  Poor behavior may  Performance metrics and PO11
management be encouraged, management techniques
techniques are while good to drive the right
used to drive the behavior may be behavior are used. These
right behavior. discouraged. include rewards for the
project team and end
users to encourage that
the system be
implemented on time, on
budget and according to
expectations, and then
adopted by end-user
departments.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 173


12. Privacy Work Program
The following work program will help to manage the privacy risks surrounding customer
relationship management. Any person auditing, reviewing or advising on controls in a CRM
project will need to select tasks from the work program and to consider the key issues raised in
the IT Governance Institute publication Risks of Customer Relationship Management as part of
their preparation. The work program should not be used as a checklist of best practice, but as a
selection of examples of good practice that can be applied. By using the work programs blindly,
there is a risk of losing the confidence of the auditee and even of missing the largest risks in the
project, due to the peculiarities of each project. Therefore, work programs should be used as
guidance and specific knowledge of the organization and risks added to it.

Note: A business objective may be listed more than once because it has multiple risks and
corresponding control objectives. Note disclaimer.

Business Risk Control Comments/ COBIT


Objective Results/ Reference
W/P Ref.
Access
Employees’ access  Inappropriate  Employees’ access to PO2
to personal and access to personal personal information is DS5
sensitive information may limited to the DS11
information within result in misuse of information they need to
the CRM system is the information perform their job
controlled and functions.
appropriately. noncompliance  A business case is
with the required before
organization’s employees receive
privacy notice and access to sensitive
policies and information. For
procedures. example, all access
requests are reviewed
and formerly approved
(signature) before a user
is granted access to the
system.
Employee access  Employees may  Regular reviews of PO7
to personal have inappropriate employee access to DS5
information is access to personal personal information DS11
reviewed on a information due to within the CRM system
regular basis. changes in job are performed. The
status or reviews are designed to
responsibilities. determine whether
access levels should be
adjusted based on
employees’ current job
responsibilities.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 174


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Sensitive personal  Personal  Strong authentication DS5
information information may and authorization DS11
collected and be unsecured and controls, firewalls,
maintained in the accessed by operating system
CRM system is inappropriate controls, and encryption
secured. parties, which standards secure
could result in sensitive personal
noncompliance information.
with the
organization’s
privacy notice.
Physical controls  Unauthorized use  Printed outputs from the DS9
protect against of customer CRM system (e.g., DS12
identity theft. accounts may statements, forms,
result in applications) and
financially handwritten notes taken
unrecoverable by employees are
losses for the disposed of properly.
organization. Alternatives include
Note: although locked garbage/recycling
electronic access is can and outsourcing to
growing in professional disposal
importance, access organizations.
to paper  Documents sent to
documents by customers are reviewed
improper regularly to ensure that
individuals still they contain the
poses a great risk minimum information
of identity theft. necessary.
The use of  Overuse of  A risk assessment of PO8
government issued identifiers issued current practices is PO9
identifiers, such as by national performed and high-risk
social security authorities areas addressed.
numbers, is increases the risk  Policies around the use
assessed and of identity theft of government issued
limited. and may make identifiers are created
customers and monitored.
uncomfortable
with their privacy.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 175


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Best practice user  Without  On a regular basis, DS5
and caller appropriate review changes to caller DS11
identification authentication authentication questions.
methods are in procedures, Caller authentication
place. organizations may questions are those
provide personal questions that the
customer customer can provide the
information to answer to, but would be
inappropriate difficult for a stranger to
parties. answer.
Regulatory Compliance
The organization  Organizations may  New privacy legislation PO8
identifies the be unaware of the is monitored in the
privacy legislation privacy legislation countries in which the
that it is subject to they are subject to organization operates on
for all the and may not be a regular basis. Any new
countries and able to meet legislation or updates to
territories in which regulatory existing legislation are
it operates. requirements. reviewed and forwarded
to the appropriate
individuals.
The organization  Organizations that  Compliance occurs in a PO3
implements do not implement timely manner within the PO4
compliance appropriate appropriate divisions in PO8
programs for compliance the organization.
applicable privacy programs may
legislation. misuse customer
information and be
subject to
regulatory action.
The organization  Lack of  Internal or external PO6
monitors monitoring may parties conduct privacy PO8
compliance with lead to audits on a regular basis. M1
privacy legislation noncompliance
on an on-going with privacy
basis. legislation.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 176


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
All system  The business units  The privacy PO6
changes with a requesting system management team is a AI6
material impact on changes and the part of the system
customer development team change methodology.
information must responsible for Working with the
pass a privacy test. implementing development team, it
them may not be develops a test or set of
aware of privacy standards that must be
issues. met before system
 Without a formal changes that may impact
review of changes customer privacy are
that impact the use implemented.
of and access to  The individual(s)
customer responsible for
information, reviewing changes are
organizations may independent of
use the marketing, IT, and
information functional areas that
inappropriately. made the change request.
Emerging privacy  Unexpected  A formal method for PO4
laws are monitored privacy law tracking relevant PO8
for their relevance changes may emerging legislation is AI6
to systems. require costly and in place.
unplanned changes  Possible functional
to systems and changes are discussed
procedures. with IT to ensure that the
 Organizations may system changes are
not implement the made at the most
changes at a time opportune time in the
that is most cost- development cycle.
efficient.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 177


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Privacy Organization and Management
The organization  Privacy issues may  A privacy organizational PO7
has personnel be present within structure is developed
responsible for the organization, and implemented at the
addressing privacy and they may not organization.
concerns. be detected and  The structure is staffed
addressed due to with individuals who are
the absence of a knowledgeable about
privacy group or a privacy issues, provided
chief privacy with authority to
officer who implement the necessary
focuses on privacy privacy procedures and
regulations and given appropriate
issues. funding.
 Noncompliance
with privacy
regulations may
exist.
The privacy group  Personal  The privacy group is PO4
is involved with information may consulted when PO8
decisions that not reflect decisions are made that
affect personal implications of involve personal
information. privacy policies information.
and applicable  Privacy policies and
privacy applicable privacy
legislation. legislation are
 Noncompliance considered when making
with privacy decisions affecting
regulations may personal information.
exist.
Employees are  Employees may  Privacy policies and PO7
made aware of the use personal procedures are
organization’s information developed and
privacy policies inappropriately. distributed to all
and procedures for  Noncompliance employees.
handing personal with privacy  Employees are trained
information. regulations may on privacy policies and
exist. procedures.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 178


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Disclosure
The organization’s  Personal  The method of collecting PO6
privacy notice information that is personal information is PO8
accurately collected from described fully and DS5
describes its consumers and accurately in the
practices regarding entered in the organization’s privacy
the collection of CRM system may notice and its privacy
personal not follow the policies and procedures.
information. collection  The privacy notice
practices outlined addresses all personal
in the information whether
organization’s posted online, mailed to
privacy notice. customers or developed
for internal use only.
 Any new practices or
uses of customer
information are reflected
in the privacy notice.
Full and accurate  Customers may  Industry best practices PO8
disclosure of the not want to and applicable privacy AI4
organization’s transact with an regulations are reviewed, DS5
privacy practices organization if and an inventory of
is provided to they do not know organization practices
customers in a how their conducted, to develop a
privacy notice. information will formal privacy notice.
be used and  The privacy notice is
secured. communicated to
employees and
customers. The privacy
notice is updated each
year to ensure it aligns
with current business
practices. The updated
privacy notice is
communicated to all
employees and
customers annually.
The organization  Activities may not  Internal audit or M1
monitors be performed in members of the privacy M4
compliance with accordance with group review
its privacy notice. statements in the compliance with the
privacy notice. organization’s privacy
notice on a regular basis.
 Any new practices or
uses of customer
information are reflected
in the privacy notice.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 179


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
Training and Procedural Controls
CSRs are trained  CSRs may be  CSRs are recognized as PO4
on the improperly a critical point of contact PO6
organization’s trained; therefore, for customers around PO7
privacy policies they may provide many issues, including DS5
and procedures. inaccurate or privacy. Therefore, they DS7
misleading are provided with
information about comprehensive training
organization on:
privacy practices. - General privacy
 CSRs may provide topics
customer - Privacy risks
information - The organization’s
inadvertently to privacy guidelines
individuals - Safeguards against
attempting to pretext calling
compromise the - Regulatory
customers’ requirements
identities. - Opt-out procedures
- The right of
customers to access
their information;
methods to access
customer
information
- Scripts to be used
to provide a clear
and consistent
privacy message to
consumers
CSRs process  Customer  Opt-in/opt-out requests PO6
customer information may are processed within a PO8
opt-in/opt-out be used period of time defined AI4
requests in a inappropriately. by the organization’s
timely and  Customer privacy management.
accurate manner. dissatisfaction and  Opt-in/opt-out requests
regulatory are reviewed
oversight may periodically to ensure
occur. they are entered and
processed properly.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 180


Business Risk Control Comments/ COBIT
Objective Results/ Reference
W/P Ref.
CSR behavior and  Improper privacy  CSRs are informed that PO6
privacy messaging messaging may their conversations may PO7
are monitored. occur, which may be recorded and
contribute to monitored.
identity theft and  Conversations are
improper opt-out reviewed periodically to
procedures. ensure that appropriate
privacy messages are
given to customers and
that privacy procedures
are followed.

© Copyright IT Governance Institute 2003 [Link]/auditprograms 181

You might also like