Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

As the person responsible for IT I was audited in several companies by several of the large auditing firms. The people auditing IT had no clue what they were doing, no clue about IT and were just running a checklist. I could have told them whatever I liked.


My wife started her career as an internal auditor at a UK financial company - she was apparently repeatedly told to stop finding problems, her manager acknowledged that the things she was finding were real problems but nobody wanted to have formal reports describing them.

She left after a colleague who apparently spent most of his time asleep in a cupboard got promoted over her....


I hope she wasn't surprised. People who listen to their managers get promoted.


The other person was probably told to stop finding problems as well, and he was complying. I once told a manager the only way to not do what I was doing would be for me to be asleep. Hell, maybe it was so easy he could do it in his sleep?


Perhaps this is naïveté on my part, but I imagine that if I worked for an organisation whose explicit purpose is to look for things which need fixing or certify that no known issues are present, I would be surprised if “shoot the messenger” was — even metaphorically — a real policy.

I would also ask myself how far the rot went, because if (for example) this organisation was also supposed to audit the government and yet promoted those who “slept in a cupboard” over those who worked diligently, then I would expect the country to suffer a very large and very surprising economic disaster.


Hi, yes, this is largely how audit firms work. If they find a problem, they will not be hired next year.

That said - don’t despair! The purpose is NOT to catch purposefully-fraudulent CFOs. That’s the SEC’s job. It’s much more of a forcing mechanism for otherwise-honest CFOs: they know they have to justify what they’re doing somehow, and the auditor knows that if something will inevitably blow up anyway, they can’t sign off. So it just arrests the slippery slope when honest mistakes are made.


> arrests the slippery slope

What does that mean? Not a native speaker, dictionary not so helpful


“Slippery slope” is an (often misused) metaphor; the bottom of the slope is generic badness, the top is a good place to be, and the slope is slippery because if you start sliding down it can be very difficult to stop.

While “arrest” normally means a police officer putting someone in handcuffs, it is derived from derived from the French word “arrêt“ meaning 'to stop or stay', and can still be used in that sense.

Thus, “arrest the slippery slope” means “prevent bad behaviour”.


Thanks! Interesting to hear about the origins of the words


Note it was an internal audit role - not acting as an external auditor working for an accounting company.


While that is worth pointing out, I would still be concerned in such circumstances. As I say, perhaps naively so — I have no familiarity with the norms of that industry.


The problem is when internal auditors highlight major issues it is the internal auditor who is disgraced and fired


Whistleblowers are very rarely welcomed in any business or government context, which is most unfortunate.


Well, she did leave accounting completely and did something else entirely - so I think it is fair to say that she was concerned!


I think being told not to find so many problems she could perhaps have coped with - having someone who was apparently unconscious most of the time promoted ahead of her was what really did it.

NB It was financial auditing not IT.


Well, it is clear that he was promoted because he wasn't interested. It allowed the rest of the people there to get away with stuff that they shouldn't have been doing.

Leaving was the best option that your wife had, in such a case you really don't want to stick around until the house burns down.


Is the point, from the company's point of view, to just have some people on its payroll with certain job titles, so looks fine to people outside?

To make gov agencies happy? Or investors? -- who are those who care

(And good if they do mostly nothing)


what's the legal liability in omitting a problem you've found during an audit? not for the auditing company, for the auditor.


https://en.wikipedia.org/wiki/Arthur_Andersen

For the individual auditor: if you're a chartered/certified accountant you can get into a lot of hot water, including possible jail time.


Thankfully there are very strong incentives for audit companies not to f-up. They themselves are not audited and are not public. Their reputation means a lot to them.

With this situation, there is a reasonable expectation for EY to lose clients. Partners will also face some consequence. Most likely they will be let go and removed from accreditation by CPA (in the US). There are several high profile cases where partners get sacked[0].

[0]: https://www.ft.com/content/5179fb94-fd6c-11e8-ac00-57a2a8264...


Partly false. We were audited every year by one of our competitors. There is a strong likely hood that the reason she was told to stop finding problems is because the de minimus limit (the dollar figure at which we don't care) is truly, and I mean TRULY massive for the kind of companies that are audited by EY, PWC, KPMG, and Deloitte. I refuse to believe for one second that a serious issue was swept under the rug by a senior or manager.

As for the guy sleeping in cupboards...the staff at those firms reguarly work 80 hour weeks (not the "I work 80 hour weeks counting all kinds of stupid things" but the "I was at the client site or in the home office for 80 hours this week". It was a very common occurence for hard working staff members to take naps at the client (most likely because last night was a 2am night). Promotions at these firms are often very competitive as the organization is an "Up or out" organization designed to chew up fresh college grads.

The peer review is conducted by an independent evaluator, known as a peer reviewer. The AICPA oversees the program, and the review is administered by an entity approved by the AICPA to perform that role. 2. The peer review helps to monitor a CPA firm's accounting and auditing practice (practice monitoring).


>There is a strong likely hood that the reason she was told to stop finding problems is because the de minimus limit (the dollar figure at which we don't care) is truly, and I mean TRULY massive for the kind of companies that are audited by EY, PWC, KPMG, and Deloitte. I refuse to believe for one second that a serious issue was swept under the rug by a senior or manager.

That's a big claim for you to make given that you don't know the company, the size of their clients, or even whether or not anyone went to jail over the proceeding decades.


It was an internal audit role and she wasn't a professionally qualified accountant.


So no legal risk, but there is still professional risk. When external auditors come in or an issue is found that impacts customers, they could scapegoat their internal (deliberately made useless) team, fire them, and have a go at using that as part of their defense/response. The higher-ups would be ok if they can pull it off, but your wife would've been out a job and with an inability to get a reference from them (beyond the basic: She was employed here from X-Y).

Best plan for everyone is to get out of shady companies like that ASAP.


> shady companies like that

Ok so that's not how things usually work?

In most? companies internal auditors do real work, would you say? (I'm clueless)


In my experience, yes. They certainly don’t tell people to slow down or ignore findings.


I tried this once and it resulted in my lowest performance review on record. So, it depends on the manager.


I once had a technical discussion with my manager, he wanted me to use a technical solution that did not work, while making me fully responsible for the result.

In the end I implemented both my solution and his. Mine worked like a charm, his literally caught on fire (it was power electronics development). Got fired anyway...


> he wanted me to use a technical solution that did not work, while making me fully responsible for the result

Just say "yes", and work on your job-hunting instead.


Which solution did they end up using, if any? (Or was his damaged permanently because of catching fire)

Makes me slightly wonder if the manager had hidden motivations and didn't want the project to succeed


They hired a junior make sure he would do as he was told to, and developed my solution. In the end, “my solution” was what anyone would have developed after some research on the problem.

The manager was one of the company owners, so he was well motivated, but he was an academic with little world experience that though he knew better than the industry.


The largest pop/fire I saw in some past power electronics work was a poor implementation in trying to combine the output of multiple DC-DC converters. The original caught fire in front of a potential customer, in a demo. What I saw was a repeat of the experiment, in the lab. A manager that would always say "just add more capacitance" was involved. I guess firing and fires go with managers like that.


It is not always a manager's motivation to get you promoted. Sometimes their motivation is to keep you where you are.


This sounds like the sort of thing to forward to a journalist.


If the guy was auditing Enron or Madoff, that explains a lot ....


The Ministry of Magic has always had problems with retention, but I hope most of us would agree that Potter earned that Auror badge.


Yes, we hear this all the time. It's just kids with checklists who have absolutely no idea about the nature of the questions they are asking, why they are asking them and have absolutely no plan for off-script follow up questions based on the answers given.

A lot of these auditors come from a financial background and they treat IT in much the same way, as if there is some kind of checksum they can calculate which will tell them if the company is healthy from an IT perspective or not.

Companies that are certified tend to be very good at process but are sometimes surprisingly bad at the actual IT. But it's all documented perfectly.


On the other hand, one of the benefits of all that documentation and policy is that blame can be assigned when the inevitable problems arise


The CYA component is definitely present.


As a former IT auditor I can only confirm your statement. After I did my master in business administration with a touch of CS (it was called Master of Information, Media and Technology Management - and I really just learned basic Java, SAP, and one course about IT architecture) I got a job at a big four auditing company as an IT auditor. I was literally just going through some checklists and at that time I had no idea about the systems or technology I was auditing. After two years I got so frustrated with my job I decided to get a second degree in CS. The more I studied, the more obvious it became to me that someone with a CS degree never would do such boring work if there are other job opportunities in IT.


So, as someone who spent a lifetime in IT, I actually enjoy the work. It gives me a way to give other companies, many more than I could normally work for, a way to benefit from that experience. Our little crew is composed of veteran IT people, all with lots of real world experience, we get the privilege of looking at lots of different companies, both the good and the bad. Which in turn gives us more knowledge.

It is anything but boring to me.


Glad to hear you enjoy your work. For me, it was just going through some checklists under enormous time pressure at large financial institutions and mostly alone, without any of my team members on site. If I were to do the job today, I might be able to look more into the details of the systems/applications I am auditing, immerse myself in them and have some meaningful conversations with the people I am auditing. Thank you for your perspective


Similarly, I remember at my last job management would start talking about the "ISO corner" each year, where all the forms that we never, ever touched sat. This of course coincided with our ISO 9001 recertification. A few developers would be coached on what to say to the certifier, he'd be there for 2 days, and then we'd go back to business as usual.


By the way, ISO organization does not endorse, check or enforce compliance of any of the certification providers, and can't basically do anything against someone who just sells ISO certificates in shiny bevel, even if they wanted.

That said, all the ISO standards are corporate moonspeak and bullshit themselves and do not bear any practical sense. (All that, for example, looong document on infosec ISO 27001 says is "try to be secure, my friend")


Mixed bag. ISO27001 when taken seriously and implemented throughout a company that means well and has the resources to do so will at least guarantee some level of process to be present. This then needs to be backed up with actual IT and security knowledge to be effective, and that is more often than not where the problems are.

So as a rule we treat an ISO 27001 certificate not so much as a checkbox item meaning we can skip certain parts of our audit, but as a nice-to-have which may help speed up the interview process because we at least know what terminology to use.

In practice there is too little difference between companies with or without such certification to see it as anything other than a marketing tool.


"all the ISO standards are corporate moonspeak" Bit of a generalisation there. ISO/IEC 13818-3 was quite useful, for example.


Okok, I mean all that corporate/org standards.


I believe I can provide some color as my wife is an auditor and I work in IT. We’ve had this discussion before.

Audit is really freaking expensive; Domain experts too. While there is a checklist that given to the auditor, the person asking those questions are usually senior or early manager level. The person has little experience in IT but usually has a small BS detector because of previous audits. That checklist is then sent to an internal domain expert to verify. Follow up questions may occur.

Having said that, this is strictly for compliance and “covering your own butt”. This past year a firm was found negligent because they didn’t catch fraud because they simply “checked the box”. Since then, most firms have introduced rudimentary IT training for auditors responsible for said checklist. (All staff have to take the classes, when at level).

TL;DR an auditor cannot have same knowledge as IT person and audit time is expensive. They’re trained to earmark fraud and to verify, to the best of their abilities, they are not signing off on a lie. Shit is hard and no system is perfect.


This is spot on and one of the reasons why those reports are worth absolutely nothing other than that they might help close some deals.


This isn't for "closing a deal" but because the audit co is signing off on financials. This is why in a companies public reporting, they have a section about possible damage from losing customer info. That's legalize for:

1. The Public Company being audited isn't going to spend money on a real technical audit and may in the future lose customer info, etc.

2. The financial auditing company doesn't have enough experience to properly asses the situation. They did the best they could but they're no experts.


Ah, yes, I still had ISO27001 in mind.


> TL;DR an auditor cannot have same knowledge as IT person and audit time is expensive.

Code audits and pentesting are a thing you can buy. But yes, they're even more expensive. Turns out security isn't considered valuable enough for most.


Right, that's exactly why the audit company isn't signing off on code audit or pen testing. They can only sign off on a simple checklist, if a caveat is listed in the financial reporting.

They have no proficiency or enough people who know what they're doing. The approach is to meet the lowest common denominator set by the SEC or is expected from investors.


I am an IT person, and I put this first, and Auditor for 27001. Wouldn't say that you can't bullshit me, cause who knows all. I go in and look at the absolute basics. Like is there a person responsible for Security? What are his responsibilities? In the last 12 Months is there anything documented that proofs that he did his job? If so did the management followed through on his findings? If not why?

You can fake all of this. But at some point its easier to do the job than to fake it. Well at least this is what I hope...


That's exactly it. They're seen as an unneccesary cost because there are no real penalties for being compromised. Though this is fortunately changing, which has caused companies to begin to take this stuff more serious than in the past.


Pay boat loads for auditors vs. paying pittances for getting pwned a few times. It's no wonder, really.


As a former IT auditor, this checks out. Depending on the company, they may have just grabbed whoever was available.


Very much true. I've had the pleasure of doing this stuff on both sides.




Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: