Follow-up and Issue Tracking — Confirming Management Action - ZServiceDesk Blog

Follow-up and Issue Tracking — Confirming Management Action

Audits Are Only as Good as Their Follow-up — A Guide to Effective Issue Tracking The Follow-up Standard Standard 15.2 requires internal audit functions to confirm whether management has implemented action plans and, when they have not, to follow the CAE's established guidelines for management acceptance of risk . The Follow-up Challenge Follow-up processes are often less structured than planning or testing phases. Many offices rely heavily on email and phone communication and lack standardized tools for tracking status updates . Common problems: Auditors feel the follow-up process is treated like an afterthought Delays in management action plan completion Clients do not provide explanations or updated timelines Balancing accountability with maintaining positive client relationships Determining what constitutes sufficient verification Strategies for Effective Follow-up 1. Evidence-Based Approach Transition from "trust but don't verify" cultures to more evidence-based follow-up procedures . 2. Include Follow-up in the Audit Plan Include follow-up activities directly in the audit plan to signal their importance to leadership and audit committees . 3. Use Standard Templates Develop standard templates for documenting action plan status updates . 4. Establish Regular Cadences Establish regular follow-up cadences, such as every 90-120 days . 5. Conduct Interim Check-Ins Conduct interim check-ins rather than waiting for due dates, which has improved implementation rates . 6. Prioritize High-Risk Findings Use prioritization methodologies to identify high-risk findings that require closer monitoring or escalation . 7. Require Written Justifications Require written justifications for non-implementation or use standard forms for documenting risk acceptance . 8. Use Dashboards Report overdue action plans to leadership using dashboards and visualizations . 9. Escalate to Leadership Require clients to present their rationale for non-implementation directly to the audit committee . Determining Verification Sufficiency Determining what constitutes sufficient verification—especially when deciding between retesting and reviewing client-provided evidence—remains a challenge . Guidelines: Low-risk findings: Client-provided evidence may suffice High-risk findings: Independent verification (retesting) may be warranted Document the rationale for verification approach Action Plan Development During reporting, auditors should : Have the client determine the specific action plan (with internal audit approval) to mitigate each finding rather than prescribing action plans they may not fully understand Define what "implemented" will look like for each action plan Explain how non-responsiveness may be escalated Conclusion Follow-up is essential for audit effectiveness. Organizations that implement structured follow-up processes will achieve better action plan implementation and stronger control environments. Action Items for Your Organization Document your follow-up methodology Create standard templates for status updates Establish regular follow-up cadences Develop escalation procedures Report follow-up status to leadership Verify action plan implementation
Read More 19 Apr 2023
Proactive vs. Reactive Problem Management — Why Prevention Is Now Cheaper Than Cure - ZServiceDesk Blog

Proactive vs. Reactive Problem Management — Why Prevention Is Now Cheaper Than Cure

The 80/20 Rule of Problem Management — Fixing Root Causes Eliminates 80% of Recurring Incidents The Two Faces of Problem Management Problem Management has two distinct sub-processes: Reactive Problem Management: The goal is to identify the root cause, or provide suitable workarounds, of known incidents  Proactive Problem Management: The goal is to identify and eliminate the root cause of incidents, or provide suitable workarounds, in order to prevent their recurrence  Reactive Problem Management Reactive Problem Management is triggered by incidents and aims to: Identify the root cause of incidents that have already occurred Provide suitable workarounds to reduce service interruptions Document known errors for future reference When to use reactive problem management: When a major incident has occurred  When a pattern of recurring incidents emerges  When monitoring events indicate an underlying issue that should be addressed  Proactive Problem Management Proactive Problem Management aims to: Identify and eliminate root causes before incidents occur Use trend analysis to detect emerging issues Continuously improve service stability When to use proactive problem management: During routine monitoring and trend analysis When reviewing incident patterns As part of continuous improvement initiatives The Business Case for Proactive Problem Management The economic case for proactive problem management is compelling. Research shows that problem management delivers measurable ROI: Benefit Area Impact Incident volume reduction 4-6% decrease in total incidents  Time for incident solution 95% reduction in incidents exceeding 5 days  Solver team capacity savings 5% increase in available capacity  Reduced severity of incident impact 3% reduction in impact severity  Increase in end-user satisfaction 2-3% improvement  The ROI of Problem Management A documented business case demonstrates the financial value: Direct savings include: Reduced incident solving costs Savings on SLA breach penalties First-line support efficiency gains Higher-level professional capacity savings  Indirect savings include: Improved service quality leading to higher employee satisfaction Reduced risk of incidents impacting the business  Quick Wins for Problem Management Organizations can achieve quick wins by: Internal education: Making common terminological language unified Separating Incident and Problem management: Clear distinction between the two Defining activities in each process: Clear, documented procedures Defining and measuring metrics: For both Incident and Problem management processes Automating the process: Leveraging software tools Quick start: Logging the first problem Regular reporting: Tracking progress Proactive Problem Management start: Moving beyond reactive  Conclusion The shift from reactive to proactive problem management is not just a best practice—it's a financial imperative. Organizations that invest in proactive problem management will see fewer incidents, lower costs, and higher satisfaction. Action Items for Your Organization Assess your current problem management approach—is it reactive or proactive? Separate Incident and Problem management processes Start logging problem records for recurring issues Begin trend analysis on incident patterns Measure the ROI of proactive problem management in your organization  
Read More 05 Apr 2023
Vendor Risk Assessment — A Practical Guide - ZServiceDesk Blog

Vendor Risk Assessment — A Practical Guide

The Vendor Risk Assessment — A Step-by-Step Guide to Evaluating Third-Party Risk What Is a Vendor Risk Assessment? A vendor risk assessment reviews the vendor to determine how well equipped it is to provide the needed assurance of maintaining information security throughout the data life cycle and/or contractual period . It should identify any potential threats and vulnerabilities that the vendor might encounter and evaluate how well equipped the vendor is to proactively identify and mitigate risk if it materializes . The Assessment Process Step 1: Assemble Internal Stakeholders Gather a cross-functional team representing multiple roles with different priorities : IT Security Compliance Procurement Legal Business owners Step 2: Define Acceptable Risk Levels Before assessing potential vendors, define the organization's risk appetite . This makes the vendor selection process more efficient, identifying vendors that won't meet the required risk tolerance . Step 3: Categorize Vendors by Risk Classify partners into risk levels—critical, moderate, and low—based on service dependency : Critical: Access to sensitive data, business-critical services Moderate: Limited access, moderate impact Low: Minimal access, low impact Step 4: Send Risk Assessment Questionnaires Different types of questionnaires can be sent: Industry-standard questionnaires (SIG, CAIQ, VSAQ)  Customized questionnaires based on organizational needs  Use frameworks such as NIST Cybersecurity Framework when designing questionnaires  Questionnaire focus areas: What security controls do you have in place?  How do you store or process sensitive data?  What is your authentication policy? Is MFA mandatory?  How often do you conduct backups?  Do you have an incident response plan?  What is your privacy policy?  Step 5: Evaluate Assessment Results Review vendor responses Validate claims with evidence Identify gaps and risks Document findings Step 6: Categorize and Remediate Risks Risks identified must be categorized as either acceptable or unacceptable . For unacceptable risks, organizations work with vendors on remediation or terminate the relationship . The FAIR Evaluation Criteria Organizations should consider 4 objectives to be non-negotiable when outsourcing deliverables to a vendor : Restricting Sensitive Data Access: Assessing the effectiveness of the vendor's security measures against unauthorized access, loss, or theft  Ensuring Regulatory Compliance: Vendor risk assessments help ensure that third-party vendors comply with regulations, reducing the risk of legal penalties  Mitigating Supply Chain Risk: A security breach of a vendor can create a domino effect, compromising the entire supply chain  Maintaining Effective Communication: Establishing and maintaining effective communication with vendors on an ongoing basis is critical  Due Diligence Questions Before engaging a vendor, organizations should consider : Have the vendor's security policies, procedures, and practices been vetted and approved by organizational security leaders? Does the vendor follow any industry-recognized best practices or have security certifications? Have audit and assessment reports been reviewed and on-site assessments conducted, if required? Has guidance been sought where required to assess the vendor's security practices? Conclusion Vendor risk assessments are essential for evaluating how well vendors handle secure information throughout the data life cycle . Effective assessments enhance transparency, accountability, and security controls in an evolving cyberrisk environment . Action Items for Your Organization Define vendor risk assessment process Create assessment questionnaires Establish vendor tiering Conduct initial assessments for critical vendors Document findings and remediation plans  
Read More 07 Mar 2023
Compliance Risk in Vendor Relationships - ZServiceDesk Blog

Compliance Risk in Vendor Relationships

Your Vendor's Compliance Failure Is Your Compliance Failure — Managing Regulatory Risk The Compliance Risk Reality Compliance risk is the risk that arises from violations of the laws, regulations, and internal processes that an organization must follow in order to conduct business. From a vendor standpoint, this risk exists when the actions or services of a third party do not align with governing regulations . The critical point: If a vendor is breached and loses personally identifiable information, such as a customer's social security numbers or healthcare records, the law clearly states the organization is responsible, not its vendor . Regulatory Frameworks Regulation Scope Impact of Non-Compliance GDPR EU data protection Fines up to €20M or 4% of global turnover HIPAA US healthcare data Fines up to $1.5M per violation PCI DSS Payment card data Fines, loss of payment processing SOX Corporate governance Fines, criminal penalties DPDPA (India) Data protection Significant penalties Assessing Compliance Risk Questions to ask : Does the vendor comply with relevant regulatory requirements? Does the vendor have compliance certifications? Has the vendor been subject to regulatory actions? Does the vendor have a compliance program? Industry-specific requirements: Healthcare: HIPAA compliance for vendors handling patient information  Financial services: Anti-money laundering (AML) and KYC compliance  Retail: PCI DSS compliance for payment processing  Compliance Risk Management Pre-Onboarding : Assess vendor compliance with relevant regulations Review compliance certifications Evaluate regulatory history Contractual Protection : Include compliance clauses in contracts Require immediate notification of compliance changes  Define consequences of non-compliance Ongoing Monitoring : Verify compliance regularly Monitor for regulatory changes  Conduct periodic audits The Fourth-Party Compliance Risk Vendors' subcontractors may introduce compliance risk. Banks evaluate not only direct vendors but also their suppliers to ensure supply-chain transparency . Conclusion If a vendor is breached and loses personally identifiable information, the law clearly states the organization is responsible, not its vendor . Organizations that assess and monitor vendor compliance risk will avoid regulatory penalties and legal action. Action Items for Your Organization Assess vendor compliance with relevant regulations Include compliance clauses in contracts Monitor vendor compliance continuously Address fourth-party compliance risk Document compliance verification  
Read More 07 Feb 2023
The Governance Gap — Why 77% of Organizations Lack Cyber Resilience - ZServiceDesk Blog

The Governance Gap — Why 77% of Organizations Lack Cyber Resilience

Only 2% Report Firm-Wide Cyber Resilience — The Governance Gap That Keeps CISOs Up at Night The Resilience Gap PwC's Global Digital Trust Insights 2025 highlights a stark reality: while 77% of organizations plan to increase cyber budgets, only 2% report firm-wide cyber resilience . This gap points to missing governance structures, unclear decision rights, and insufficient board-level accountability . What Is the Governance Gap? The governance gap is the distance between what compliance documentation says and what the organization actually is . It manifests as: Fragmented ownership models Siloed data Legacy GRC tools Delayed risk insights Incomplete risk visibility Disconnected operational reality Why the Governance Gap Exists Assumptions That No Longer Hold The systems, processes, and assumptions that got you here were built for a world that moves more slowly than the one you operate in now . Your GRC stack was built for a world that no longer exists: The pace of change is faster: Engineering deploys changes hourly; your quarterly access review captures a snapshot that has already changed by the time it's complete . New vendors appear daily: A new vendor gets embedded in production before procurement is notified . AI changes everything: A vendor you approved for one purpose now uses AI in ways you never signed off on . The Assurance Gap The result is an assurance gap: the distance between what your compliance documentation says and what your organization actually is . Your team fills that gap with judgment and extra hours, but that is not sustainable when the rate of change keeps accelerating. The GRC Operating Model Problem One head of GRC described: running audits, answering security questionnaires, managing third-party risk, maintaining the trust center, and setting the certification strategy—all on their own. Their tools automate the repeatable parts, but the judgment calls, the context shifts, the things that happen between scheduled reviews—those fall entirely on one person . What Mature Organizations Are Doing Connected GRC Platforms CISOs are adopting connected GRC platforms that provide holistic visibility across risk domains. This connected approach is essential for understanding how risks cascade across the organization and for coordinating response efforts across security, risk, compliance, and the business . Integrated Risk Management Cyber risk no longer exists in isolation. It is deeply interconnected with third-party risk, operational risk, regulatory risk, and enterprise resilience. Connected GRC enables better prioritization, faster response, and stronger alignment between cyber risk management and business objectives . The Trust Management Lesson The trust landscape in 2026 is demanding more from GRC teams than the current operating model was designed to deliver . Recognizing that the model needs to evolve is the most important lesson of the year, and it is the first step toward building something that can actually keep pace. Action Items for Your Organization Assess your current GRC operating model Identify gaps between documentation and reality Build governance structures with clear accountability Adopt connected GRC platforms Define clear decision rights Measure and close the assurance gap  
Read More 03 Feb 2023
The 2026 Regulatory Tsunami — Key Regulations and Deadlines - ZServiceDesk Blog

The 2026 Regulatory Tsunami — Key Regulations and Deadlines

DORA, NIS2, EU AI Act, SEC Rules — What Every GRC Professional Must Know for 2026 The Regulatory Landscape If 2025 felt like a regulatory crescendo, 2026 is the year the orchestra starts playing in full force. Regulators are accelerating enforcement, from EU frameworks such as NIS2, DORA, and the AI Act, to new privacy mandates in Australia, India, and Brazil, to US SEC rules . Key 2026 Regulatory Developments EU Digital Operational Resilience Act (DORA) Status: Fully applicable from January 17, 2025 Scope: Financial entities must maintain structured ICT incident records and reporting discipline  Key Requirements: ICT risk management framework Incident reporting within deadlines Digital operational resilience testing Third-party risk management Information sharing Why It Matters: DORA ties governance to supplier dependency and strengthens testing and evidence trails, turning paper programs into auditable resilience programs . NIS2 Directive Status: Member states completing transposition; enforcement beginning Scope: Essential and important entities across critical sectors Key Requirements: Risk management measures Incident reporting Management accountability Supply chain security Expectation: Intensified scrutiny in early 2026 as national laws come online . EU AI Act Status: Phased obligations in effect; major checkpoint August 2026 Key Requirements: August 2025: Transparency for general-purpose AI and foundation models August 2026: High-risk AI systems compliance (HR, credit, medical diagnostics, critical infrastructure) What's Required for High-Risk AI: Risk management system Human oversight Documentation Transparency Accuracy, robustness, cybersecurity Why It Matters: Organizations running HR, credit, medical diagnostics, or critical infrastructure AI must prepare risk management, human oversight, and documentation that withstand regulator review . US SEC Cyber Disclosure Rules Status: Normalized requirement Key Requirements: Incident reporting within 4 business days Annual governance disclosures Materiality determination Why It Matters: Drives cross-functional alignment between security, finance, and legal. Boards and CISOs must have decision frameworks ready . Australia Privacy Reforms Status: Staged applicability, with requirements active now Key Requirements: New statutory torts Anti-doxxing offenses Enhanced OAIC powers Technical and organizational security measures Transparency for automated decisions Children's Online Privacy Code (24-month runway) Why It Matters: Governance teams must actively manage staged applicability . The 90-Day Readiness Roadmap IBM recommends a 90-day roadmap for regulatory readiness : Timeframe Actions Board and Policy Approve unified SGR charter; assign named executive accountability Controls and Evidence Maintain control libraries with test artifacts AI Readiness Complete AI inventories; classify high-risk use cases; draft conformity files Incident Convergence Integrate legal, finance, and security tooling Cross-Border Maintain live register of transfers and mechanisms The Global Enforcement Map Europe: NIS2 enforcement accelerating, DORA in full effect, EU AI Act deadlines approaching US: SEC rules normalized, state-level AI laws emerging Canada: Provincial frameworks (Québec Law 25) raising national expectations Asia: China clarifying outbound data pathways; Singapore maintaining fast-response breach notification (3 days); Australia privacy reforms in effect Latin America: Brazil ANPD 2026–2027 enforcement map prioritizing data-subject rights, AI, and emerging tech  Conclusion 2026 is the year SGR determines your license to operate across product design, AI deployment, capital markets disclosure, and cross-border data . Organizations that prepare early—building governance that scales, security that proves resilience, and risk models that inform real decisions—will stand apart. Action Items for Your Organization Map applicable regulations to your organization Identify compliance gaps Establish accountability for regulatory compliance Build audit-ready controls Prepare for AI Act compliance (August 2026 deadline) Align incident reporting across regulations    
Read More 31 Jan 2023