0% found this document useful (0 votes)
10 views20 pages

Auditing BCP for FMCG Manufacturing

The project report certifies the completion of the DISA 3.0 course and presents an audit of the Business Continuity Plan (BCP) for a manufacturing company in the FMCG sector. The audit identifies deficiencies in the BCP, including poorly documented procedures and inadequate safety measures, and provides recommendations for improvement. Key findings highlight issues with employee attendance tracking, inventory management, and the need for regular testing of the BCP to ensure effective disaster recovery.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
10 views20 pages

Auditing BCP for FMCG Manufacturing

The project report certifies the completion of the DISA 3.0 course and presents an audit of the Business Continuity Plan (BCP) for a manufacturing company in the FMCG sector. The audit identifies deficiencies in the BCP, including poorly documented procedures and inadequate safety measures, and provides recommendations for improvement. Key findings highlight issues with employee attendance tracking, inventory management, and the need for regular testing of the BCP to ensure effective disaster recovery.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd

Project Report

of
DISA 3.0 Course

1|BCP AUDIT
CERTIFICATE

Project report of DISA 3.0 Course

This is to certify that we have successfully completed the DISA 3.0 course training conducted at:

Coimbatore from 13-01-2024 to 24-02-2024.

and we have the required attendance. We are submitting the Project titled: Auditing Business
Continuity Plan for Manufacturing system. We hereby confirm that we have adhered to the
guidelines issued by DAAB, ICAI for the project. We also certify that this project report is the
original work of our group and each one of us has actively participated and contributed in
preparing this project. We have not shared the project details or taken help in preparing project
reports from anyone except members of our group.

1. Name: Prabhu R Membership No 232825 Sign Sd/-


2. Name: Nivedha Membership No 259928 Sign Sd/-
3. Name: Durgaa Manjari R M Membership No 263141 Sign Sd/-

Place: Coimbatore

Date: 10-02-2024

2|BCP AUDIT
Table of Contents

Auditing Business continuity plan for Manufacturing system

Project Report

1. Introduction 4

2. Auditee Environment 4-5

3. Background and situation 5-6

4. Terms and Scope of assignment ------------------------------------------------- 6

5. Logistic arrangements required ------------------------------------------------ 7

6. Methodology and Strategy adapted for execution of assignment ----------- 7-8

7. Documents reviewed 8-9

8. References 9

9. Report 9-19

10. Conclusion 20

3|BCP AUDIT
PROJECT REPORT

Title: Auditing Business Continuity Plan for Manufacturing system

Details of Case Study/Project (Problem)

The Auditee is a manufacturing company of Fast-Moving Consumer Goods (FMCG) and deals with the
production of goods of multiple products. The main objective of this project is to ensure the
effectiveness and efficiency of the Business continuity plan and evaluate the control
effectiveness in the organization on how fast the business would resume its operations in the
event of an unforeseen disaster.

Assumption of Auditing the Manufacturing system of an FMCG and the report is prepared based on the
assumption of auditing the same based on previous experience or research. Assuming that this
has happened over some time from Audit recommendations to test checks and our
recommendations have been implemented by them.

Project Report

1. Introduction
The auditee is a Private Limited Company (Hereinafter referred to as “PLC”) manufacturing Fast-
Moving Consumer Goods (FMCG). PLC Manufactures a wide variety of products meeting
various needs of the end consumer. There are separate factory buildings for each type of products
manufactured therefore more often the products manufactured in each factory building are not
related to each other. The technology infrastructure (ERP software) of PLC in each of its factory
buildings is different from each other therefore the auditing of the manufacturing system has
been done unit-wise and consolidated auditing is made as and when required.

4|BCP AUDIT
2. Auditee Environment

Nature of Business: The Auditee is a Fast Moving Consumer Goods (FMCG) manufacturer
primarily focused on food products.

Organization structure: As PLC consists of many business units it follows a divisional


structure wherein the leadership is based on products or projects they operate. Division may also
be designated geographically in addition to specialization.

Technology deployed: Inhouse-developed software (ERP) is used for various accounting


operations of the PLC. It also has its inventory management software to manage the inventory of
raw materials, production of goods, already in store, and goods for which orders by the
distributors are made. These are managed separately for each unit.

Legal requirements: As most of the products manufactured by PLC are related to food it has
obtained a food license from the Food Safety and Standards Authority of India (FSSAI license)
which complies with the regulatory framework of Food safety and standard regulations.

Internal policies and procedures: The attendance of the employees is marked by biometric
system and the factory operates in two shifts. The internal procedures related to health standard
rules are followed adequately to maintain a hygienic environment. The safety measures taken in
case of any natural or man-made disasters are taken care and to mitigate the same adequate care
is taken subject to some suggestions.

Physical and Software Security: Only specific persons who are authorized to do the day-to-day
data entry and management of the products manufactured are let in. Everything which requires
high level security is given that high level of security subject to some suggestion.

5|BCP AUDIT
3. Background and Situation

PLC already had a Business Continuity Plan (BCP) and made prior arrangements and procedures
that enable them to respond to an event if anything happens disrupting the normal operations of
the company. They also have a Disaster Recovery Plan (DRP) in parallel to BCP. The risk has
already happened BCP enabled the time taken to recover when an incident occurs minimized the
risk involved in the recovery process and also reduced the cost involved in reviving the business.
However, the problem is that the BCP manual was not well documented and the test check of the
BCP was not carried out before the implementation. The effectiveness of the BCP can be only
through regular testing so that when a real situation comes the people will be able to handle it.
This came to be known only when there was a fire accident in one of the units in the
manufacturing factory. When they were required to continue the business as before the
management came to know about the poorly drafted BCP Manual. Also came to know that once
the BCP manual is well drafted a test must be made in the live location or live-like location to
see the impact, calculate damages and the revival time taken can be known.

Hence the management of the company wants us to verify the plans already drafted manual
correct it wherever required and do a test check on the same.

4. Terms and Scope of assignment


Our work is to review all the process in each of the unit as the process differs from each and
every unit majorly our focus is on the following areas where we will consult them to improve in:

 Obtaining Business order


 Raw material procurement
 Time management (from order to cash process)
 Inventory safety and clearance of the same
 Distributors procurement verification
 Production indicators to halt the manufacturing or to increase specific manufacturing of
goods

6|BCP AUDIT
The main objective of the assignment is to ensure the following:

 Safety and security of the personnels


 Reducing confusion during the emergency
 Identifying critical application systems
 Identifying the resources required to recover from emergency
 Identifying alternative means to recover critical business functions

5. Logistic arrangements required


The test that we are going to make is a Parallel test which is a full test of recovery plan
utilizing all personnel. The test check runs in parallel to primary production process and
business does not stop. So as to ensure that critical systems will actually run at the
processing backup site.

Based on responsibilities given to Disaster Recovery Team (DRT) the requirements will be
arranged based on our suggestion.

Therefore, relocation of systems except that of primary operations to the alternate site is
required.

6. Methodology and Strategy adapted for execution of assignment


Brief about the main Recovery strategies that are planned to recover from a disaster are listed
below:

 Backing up of data

It is very important to protect the data available with the auditee so that entire data can be
recovered back once the disaster is over.

7|BCP AUDIT
 Networking systems

Every process is connected as chain therefore it is very important to protection and


recovery has to be done as quickly as possible. Data encryption is also very important
when data is shared via a radio signal as there is a chance of interception of data shared.
Specifically, when sensitive information is shared.

 Data communications

Carrier through which the data is shared is crucial. Therefore, switching of data
communication from one channel to another channel is need of the hour.

 Voice communications

Coordination among the employees and the management is very important. The
information should pass on from the Higher authority to a lower-level employees should
happen uniformly without any urgency. As the urgency may lead the already occurred
disaster to a severe condition.

 Preparation of site for a parallel running operation during disaster test

As we have planned to make parallel testing, we have asked them to prepare a site which
is nearer to the primary processing location.

 Checking the Responsibility Chart:

Once the disaster occurs the people in the PLC should know about the responsibility they
have after the occurrence of any disaster. Disaster recovery team should get involved and
recover the entity from the disaster.

8|BCP AUDIT
7. Documents reviewed
 Business Continuity Planning (BCP) Manual
 Previously given reports based on BCP manual
 Review of list of documents or hardware or software that got corrupted during the
disaster that has happened earlier in one of the unit.
 Access control documents
 Blue print of the location of the units and backup site
 The Hierarchy of the people in the organization
 Review of Financial statements of last 5 years to see the lossess (expenses) made to recover
 Flow chart on process of manufacturing various products
 Segregation of duties chart
 Disaster recovery team – responsibilities and persons responsible

8. References
 Background Material on Information systems audit 3.0 course.
 Insights from Articles obtained from search engine

9. Report

Executive summary:

Management of PLC has asked us to audit whole system and asked us to give recommendations
on what to do or steps to be taken once the disaster has happened.

Findings:

During our audit we found out the following defects in the system in itself which includes all the
defects which may also lead to a reason for disasters:

9|BCP AUDIT
 Employees attendance
The capturing of biometrics of the persons who are coming in and once the shift gets
completed the biometrics of the employees going out are captured. The thing we found to
be problematic is that sometimes the biometrics given are not captured properly by the
device and it marks absence for the employees for the whole day itself and this problem
seems too persistent and employees used to complain about this to the management but
everything seemed to be in vain thus leading to non-interest of the employees to work
during those specific days. Sometimes this has caused a big problem and resulted in riots.
Sometimes the attendance is also marked wrongly when biometrics are handled manually
because of name confusion.

 Employees Shift changing process

During the change of shift process the pathway for the incoming employees for the next
shift and outgoing people are the same. Therefore, during the shift changing process it
takes more time to start the process where the previous employees left. This might
sometimes lead to chaos.

 Goods inward, outward control and Management of inventory

Though the goods inward and outward are maintained in SAP inventory management
system. But the problem lies when the entry in the inventory management software is
made. There is a huge gap between the following:
 Goods inwards and entry in the software
 Goods outward for production team
 Goods inward for storage of team
 Goods outward to wholesale distribution team
 Goods outward from wholesale distribution team to retail distribution team
 Return management

10 | B C P A U D I T
Due to the delay in entry, there is a possibility of not accounting some of the goods both
during the inward and outward. Which leads to wrong calculation of emergency
availability.

Due to lag between the updation in software and actual goods inward and outwards process
there has been theft of the products (Majorly in huge number) both raw materials and
finished products.

 Backing up of data

Currently full backup is taken at a regular intervals and old backups are stored in large hard
disks which requires more space and also required huge cost.

 Safety of people

Primary reason of the IS audit is to successfully test the safety and back to safety after the
disaster happens. PLC has not enabled the fire alarm and water sprinkler when the fire
breaks in. As there are two shifts of people workings in there is no break to the units
running. Sometimes due to non-maintenance of the machineries leads to stoppage of
manufacturing process and even sometimes lead to man-made disaster.

 Networking and communication channels

Currently they are using manual cables for networking which is costly and not so easy to recover
whatever process is obtained.

11 | B C P A U D I T
 Availability of alternate site

At present there is only one place where the whole unit is working and there is no
alternate site wherein the production process continues to run after the disaster has
happened.

 Changes in technology adoption and updation

The people involved in IT department majorly seems to be non-updated people who are
unaware of the latest technology. Therefore, they are not able to make recommendations
to the people in the management.

 Destruction of date-barred products

Since the goods manufactured are food products the process should be looked into very
carefully. Though till this time as per management’s report, there is no mix-up of the
products expired and not expired. If in any case the time-barred products get released in
the market then that problem will be a huge man-made disaster.

 Taking responsibility once the disaster occurs

There were no responsibilities given to the people when the disaster occurred. Therefore
this will lead to confusion about which people have to do to continue the business as it is.

Recommendations:

 Biometrics regularity:

The problem discussed above is due to the non-updation of the software used as and
when the updation comes. When the problem occurs the IT in charge people manually

12 | B C P A U D I T
corrects the error and sometimes they forget to do the same which results in riots among
the employees often.

 Pathway regulation:

Separate pathway creation for employees coming in and going out. There should not be
any clash during the exchange. If we calculate the time taken for shift change then it
comes to a huge number resulting in loss of labour force working time.

 Enabling censor calculation:

Once the raw materials enter the area, during the time of inward itself there should be an
automated censor to scan the products coming in and automatically enter the quantity of
the products coming inward and value will be already entered in the software as the cost
of the raw materials are predetermined as per the contract.

Once the raw materials enter the next process the inward raw materials to the production
place is censored automatically and will be entered and then the product is fully
manufactured.
Then the finished goods are sent to the distributors which will also be recorded in the
software automatically using a censor.

 Backing up of data
It is very important to protect the data available with the auditee so that entire data can be
recovered back once the disaster is over. Here we have recommended they do full
backup. We have recommended this type of backup and adding the already backup data
to a cloud space created in-house. The data stored in cloud space remains in the cloud for
Six months and after that, the data stored will automatically be deleted i.e., the backed-up
data shall remain in the cloud only for a period of Six months.

13 | B C P A U D I T
Appropriate instructions and procedures must be provided on how to restore from backup
copies of program and data files

 Enabling safety measures:

For both human beings and machineries used for production. Ensuring the emergency
exit for the people working there are readily available. A drill for the same should be
given beforehand to the people out there.

Concerning the safety measures for the machinery, there should be a maintenance check
once in every Fifteen days to ensure that even if there is a small problem it can be a
starting point for a big disaster. Therefore, it is suggested to do a maintenance check once
in every Fifteen (15) days.

 Networking systems

We have recommended them to adopt wireless Local area networks so that the restoration
of network services can be done quickly as they don’t require cabling infrastructure of
conventional LAN’s. But we have also recommended them to do data encryption because
the data are shared over a radio signal there is a chance of interception of data shared.
Specifically, when sensitive information is shared.

 Preparation of site for a parallel running operation during disaster test

As we have planned to make parallel testing, we have asked them to prepare a site which
is nearer to the primary processing location. Another recommendation to PLC is that the
alternate site need not kept idle for waiting for the disaster to happen. Minor operation of
production, accounting and research works can be take care of from there. Once the test
or actual disaster happen the business has to be able to recover and run faster to achieve
its goals.

14 | B C P A U D I T
 Upgradation required:

The people involved in IT team should get updated to the latest technology. This will be
possible only when meetings are conducted in a regular interval. Where the team will
read about the various notifications, and guidelines issued by various authorities and also
about the upgrade that has been flowing in the market. And how can they implement the
same in the auditee environment?
This a very important step in a technology-savvy environment because the virus or any
type of disruption can make to the sensitive data available with the auditee. Once if this
happens then the people in the IT team must be able to tackle it and find a solution which
will be a biggest disaster to the auditee. Therefore, if the people in the IT team are
technology savy who knows about the updates they can implement the same even before
the disaster occurs.

 Bifurcation of date barred products:

The software should be enabled such that the goods that come in and goods that go out
should be recorded in lots. And once the expired goods are identified they should be
isolated and destroyed in a manner not affecting the environment.

 Data communications

We have recommended recovering the data communication on a demand basis because


they can be easily switched to the recovery site from the primary site on auditee order to
the carrier service provider.

 Voice communications

15 | B C P A U D I T
The communication between the departments is happening via voice carriers. The alternative
to that has been suggested as communication via encrypted voice software created
inhouse using the mobile phones given by PLC where the communication made will be
stored for a day and then automatically gets deleted. This will be useful if any
communication which needs to heard more than once.
All other formal communication is operated via Mails and online. The most important
suppliers and distributors data are stored in the cloud data which can be used.

 Formation of Disaster Recovery Team (DRT) and Business continuity Team (BCT):

As of now, PLC does not have any document that contains the personnel who have to
perform the recovery tasks.
Formulation of the DR team is essential for the organization to manage the DR plan by
detecting, evaluating, and responding to disasters and re-establishes primary site
operations.
If the impact of the crisis is very high, then BCT steps into the DR Team.

 Drafting proper BCP Manual:

Currently, the company does not possess any BCP manual on how to handle any disaster
event.
A proper BCP manual must be comprised of the following elements to respond to an event in
such a manner that critical business functions can continue within the planned level of
disruption :

a. Purpose of the plan


b. Organization of the manual
c. Definitions of the disaster
d. Objective of the plan
e. Scope of the plan
f. Recovery strategy

16 | B C P A U D I T
g. Plan administration
h. Plan management
i. Disaster notification and plan activation procedures.

The responsibilities can be as follows:

 General responsibilities – Overall coordination of disaster recovery process


headed by member of IT Disaster recovery management team.
 Administrative responsibilities – Support to any team in the DRT
 Supply responsibilities – Purchases stuffs which are required during the disaster
recovery period
 Public relation responsibilities – Communicate about the process taken to the
stakeholders who have interest in the organisation
 Hardware responsibilities – They acquire, configure and install servers and
workstations
 Software responsibilities – Offer technical support to other teams
 Network responsibilities – Responsible for preparing voice and communications
 Operations responsibilities – They arrange the computer service and managing the
backups. They are responsible for arranging the requirements of other teams

10. Test check


We have conducted the test check of the Business Continuity Plan (BCP) in the alternate
available site.

After the recommendations given PLC has made the changes and upgradation required

 Biometrics software has been updated up to date and as per the checks made the error
percentage is 0.5%

17 | B C P A U D I T
 A new pathway for the inward and outward employees has been created and now the
process of shifting is going on smoothly
 Censor has been enabled for goods inward and outward process
 The of incremental backup is currently followed by PLC as express before and stored in
inhouse created cloud space.
 Conduction of drill for personnel and maintenance work done for machinery were been
documented and reviewed.
 The usage of radio signals has not been done as of now as involves higher cost and
stoppage of whole units. Therefore, this transformation are expected to be done in near
future.
 The site has already been created and test has also happened there only
 Minutes of the meeting held among the IT team has been reviewed.
 Since the censor system has been enabled everything is saved and track of the goods
coming in and going out are being traced along with the expiry dates.
 The idea of storing voice software in cellphones are given to the department manager.
 The Disaster recovery team has been formed and they were given responsibilities also as
recommended. The performance of the team was as expected and they are expected to
work like this during the actual disaster happens.

The point that has to be noted here is that every disaster happening does not require a
alternate site.

Some of the examples which may take more time to restart the work from primary
process location for which requires usage of alternate site are:
 Fire
 Lightning
 Terrorist attack
 Bomb threat
 Chemical spills
 Civil disturbance
 Electrical failure
 Water leaks
18 | B C P A U D I T
 Water stoppage
 Power failure permanent
 Prolonged equipment outage

Some of the examples of disasters which does not require usage of alternate site or the
primary process location can be revived are:
 Hacker attacks
 Human error
 Loss of telecommunication
 Date center outrage
 Lost data
 Corrupted data
 Loss of network services
 Power failure temporary
 UPS loss

There are some disasters which results in non-conduct of business in itself unless the
products manufactured is basic need. They are as follows:

 Earthquake (Assuming that the primary place of production and alternate site are
nearer to each other)
 Tsunami
 Typhoon
 Floods
 Tornado
 Freezing temperature
 Heavy snowfall
 Pandemic

19 | B C P A U D I T
11. Conclusion

The problems in PLC were seemed to be scattered in nature and every department requires its own
upgradation. Therefore, the test check was made on most important recoveries data,
communication, networks, backup, and documents. They were satisfying as far as concerned
from our view. Still, some of our suggestions were not implemented during our test check which
will be implemented as soon as possible as said by the PLC management.

The impact disaster can cause loss to Human life, Productivity, Revenue, Market share ,Goodwill
and Customer Service. From the above Productivity, Revenue, Market share, and Goodwill can
be recovered even it may take a few years to recover back. But the human life cannot be
recovered back once the life is lost due to disaster. Therefore, disasters which arise due to human
error should ever not happen at any circumstance but unfortunately the Man-made disaster is
happening in and around the world and no other way that business should run whoever comes
and goes. Recovery from that disaster should happen as quickly as possible and the business
should run and get back to the form as before.

Ultimately, BCP of an organization is to ensure that critical functions and operations are recovered
and made operational in an acceptable time frame.

20 | B C P A U D I T

You might also like