Robotic process automation (“RPA”) refers to a set of modular software programs (or “bots”) to complete structured, repeatable, and logic-based tasks by mimicking the actions taken by human personnel.
Usage of Robotic Process Automation tools has turned out to be one of the key productivity indicators for all the organizations. Finance, Sales, Marketing, Procurement, Human resource irrespective of the functional domains, Bots and other tools are major enablers in the current set up globally. Focus over RPAs governance has increased significantly over the years due to large scale usage. This is reaffirmed by Gartner projection of Worldwide spending on RPA software to reach $2.9 Billion in 2022 which is an increase of 19.5% from 2021.
Benefits of Using RPA Tools
These are some of the key benefits which has led organizations to adopt Robotic Process Automation in their critical business processes:
- Increased efficiency and Productivity: RPA can work continuously 24X7 without fatigue, with consistency resulting in faster turnaround times and increased productivity.
- Cost Effectiveness: RPA can reduce labor spends resulting in cost savings for organizations.
- Improved accuracy: RPA can reduce the risk of errors and improve the accuracy of tasks, as it follows predetermined/predefined rules.
- Enhanced customer service: RPA can help organizations to respond to customer inquiries and requests speedily leading to improved customer satisfaction.
- Improved compliance: RPA can help organizations to adhere to regulations and comply with industry standards, as it follows predetermined/pre-defined rules and processes.
- Greater scalability: RPA can be easily scaled up or down to meet the changing needs of the organization.
- Enhanced data security: RPA can help organizations to protect sensitive data through defined rules, standard processes and automating tasks.
- Increased employee satisfaction: RPA can help to alleviate the burden of strain, fatigue and inconsistency to employees, allowing them to focus on more objective and qualitative work.
“RPA can help organizations to adhere to regulations and comply with industry standards, as it follows predetermined/pre-defined rules and processes.”
Practical Applications across Functions
| Functional Domain | Automated Processes & Workflows |
|---|---|
| Accounting and Finance | Order to Cash / AR: Credit analysis, Sales order processing, Customer MDM, Order entry, Reports by segments. Procure to Pay / AP: 3-way match, PO issuance, Invoice receipt, Vendor master, Payment process, Duplicate payment Tracking. Record to Report / R2R: Monthly close, Treasury and tax, Financial statements, General ledger, Journal entry processing, Inter-company accounting, Account reconciliations. |
| Human Resources (HR) | Master data management, Payroll Processing, Journal Entries, Updating Personnel Information. |
| Information Technology (IT) | Active Directory, File systems, FTP management, Automated installations, Server/application monitoring and alert management, Service desk management, Notification & escalation, VMware integration, Data movement, Provisioning, Configuration management, Routine maintenance. |
| Audit and Compliance | Testing scripts / Automation Audit Tools, Continuous Monitoring Tools, Automated Reporting and Scheduling, User Provisioning and De-provisioning Controls, Data Consolidation and Upload. |
RPA as an Audit Tool
As organizations are embracing digitization, Auditors would have multiple opportunities to save a lot of man-hours by employing RPA and related Machine Learning and Artificial Intelligence tools and gain advantage of technologies. These would help the auditor to have deep focus and conduct more cutting-edge analysis of risks during the audit process.
- Risk Assessment: RPA can be used as a tool to conduct risk assessments (for both Statutory Audits/Internal Audits) to identify different types of risk (strategic, operational, financial and compliance risk). RPA can be used to design and develop Risk Assessment models which help in assessing risks objectively and help in framing risk mitigation actions.
- Field Work: RPA can be used to:
- Automate audit tests
- Consolidate operational data
- Review supporting documentation
- Perform complex analytical reviews
- Identify process exceptions
- Perform Continuous Monitoring
- Run pre-defined automated scripts to identify potential fraud transactions
- Build checks for ensuring quality of audit documentation
- Derive samples based on sets of rules from large population datasets
- Save effort, time, and cost without compromising on quality and audit objectives
- Audit Closure and Follow up: RPA can be used to automate communication and follow up of audit findings with auditees.
Risks in Adopting RPA
Alongside the benefits, embedded risks must be carefully evaluated and addressed while adopting Robotic Process Automation (RPA) in an organization as well as when RPA is used as an Audit tool by Auditors. Some of the key risks include:
- Dependency on technology: RPA relies on technology to automate tasks, which means that there is a risk of disruption if the technology fails or is not available. This can have a significant impact on the organization’s operations and may require contingency plans to be in place.
- Data security: RPA relies on the use of data, which means that there could be risks of data breaches or unauthorized access to sensitive data. It’s important to implement robust security measures (driven through policies) to protect against these risks.
- Compliance risks: RPA has to be designed to comply with regulations during implementation. It’s important to carefully assess the impact of RPA on compliance and ensure that the implementation is compliant in line with statutory requirements from time to time.
- Change management: RPA can significantly change the way work is done, which can be disruptive for employees, their way of working, processes to be adhered to and may involve significant change management efforts. It’s important to carefully plan and communicate the changes to stakeholders regularly to ensure that they are successful.
- Cost: Implementing RPA can be expensive, as it requires the purchase of software licenses, hardware infrastructure and continuous training to staff. It’s important to carefully assess the costs and benefits of RPA to ensure that it is a cost-effective solution.
Overall, it’s important to carefully assess the risks and benefits of RPA and to implement robust measures to manage these risks before being adopted in any organization.
“RPA can significantly change the way work is done, which can be disruptive for employees, their way of working, processes to be adhered to and may involve significant change management efforts.”
Business Readiness to Adopt RPA
Advantages of using RPA tools are no doubt attractive. However, before RPA implementation, business needs to conduct proper due diligence on readiness to adopt RPA:
- Business Requirements: The organization should have a clear understanding of its business expectations and how RPA can help to address those expectations. This may include identifying specific processes that can be automated, as well as the potential benefits of automation. Business Environment may vary between divisions and this needs to be clearly captured as part of business requirements.
- Process Complexity: RPA is most effective for automating repetitive, rules-based processes. If the process is complex or involves a high degree of decision-making, it may not be suitable for automation.
- IT Infrastructure: The organization should have the necessary IT infrastructure in place to support RPA, including hardware and software requirements.
- Data Veracity: RPA requires accurate and reliable data to function effectively. The organization should ensure that the data needed for automation is available, of good quality and validated by data owners.
- Culture and Change Management: The organization should have a culture that is open to and supportive of change, as well as a plan in place for managing the transition to RPA.
- Skills and Resources: The organization should have the necessary skills and resources in place to implement and maintain an RPA solution. This may include hiring or training employees with relevant expertise.
- Statutory / Compliance Requirements: Specific Compliance requirements like Data Privacy which may be applicable to the organization as well as specific business process must be studied and put in place on time.
- Scalability: Scalability of the RPA within different internal divisions within the organization.
Once decided, Organizations ready to adopt RPA typically have a clear understanding of their business needs, processes that can be automated, and the necessary IT infrastructure and resources in place to support automation and above all an effective governance process for managing of RPA.
“Advantages of using RPA tools are no doubt attractive. However, before RPA implementation, business needs to conduct proper due diligence on readiness to adopt RPA.”
Scoping of RPA Applications for Audit
Organizations have a plethora of RPA Bots running across different divisions of business spread across. It is not necessary that all the BOTs are relevant for audit. Nature of engagement decides on the scoping of RPA applications as well as ensuring the audit deliverables are in line with the expectation of the stakeholders.
Management may engage Auditors to do specific process audit engagements which may be to evaluate existing RPA bots or RPA bots which are in various phases (Design, Implementation, Operational) or RPAs which are specific to certain processes (say HR, Accounts Reconciliations):
- Design Phase: Management/Stakeholder may engage Internal Audit team or Internal Controls team separately to vet controls and proper governance are included in the design of the RPA tool and environment.
- Implementation Phase: Management may engage Internal audit or Internal Controls team to perform an Information Technology General Controls (ITGC) readiness assessment before bots are deployed in production to specifically cover areas like security, processing integrity and change management.
- Operational / Active Phase: Internal Audit is well positioned to perform audit to validate that RPA BOTS are performing reliably and effectively as per the design and development in accordance with the System Development Life Cycle (SDLC) methodology.
Audit Engagement Architecture: Business Expectation vs. Scope
| Process Audit Pathway | Assurance Pathway |
|---|---|
|
|
Key Risk Drivers and How Auditors Need to Approach Them in RPA Audit
Auditors must review RPA deployments across six critical risk driver pillars:
- RPA Governance
- RPA Security
- System in RPA Implementation
- SDLC in RPA Implementation
- Data Management and Security
- Compliances
“Good Governance is a system or process that provides systematic approach that incorporates strategic planning, risk management and performance management.”
1. Establishing RPA Governance Process
Good Governance is a system or process that provides systematic approach that incorporates strategic planning, risk management and performance management. Some of the critical aspects which require consideration in this regard are:
- There exists formally defined policies and procedures over the RPA strategy and implementation.
- Policies are reviewed and approved periodically to incorporate any changes.
- Updated Policies are communicated and available to all stakeholders.
- Individuals tasked with RPA Environment have the necessary skills, competency to sustain the RPA Program strategy. Specific Organizational training is provided to employees deployed in RPA roles.
- Roles and responsibilities for employees in RPA roles are defined in job descriptions.
- Vendor Management Program is established which covers the risks to contract and monitor RPA third party vendors.
- Documented policies and procedures should cover business continuity and disaster recovery plans considering RPA strategy. In this regard, Business Impact Assessment exercise should define critical RPA Processes.
- BCP and DRP periodic testing along with results documentation should cover critical RPA processes along with their response times. This would provide an outlook on how RPA environment is operating in case of an unplanned disruptive event taking place.
- In case failures are identified during the testing phase, fallback plans must be in place which provide clearly defined steps and guidelines to be followed.
- Incident response guidelines should be clear and precise to cover issues arising in RPA environment, ensuring they are identified, assessed and addressed in a timely manner. Escalation matrix should be clearly defined and identified which plays a key role in effective monitoring and timely resolution of issues.
- Change in Governance, escalation structure needs to be communicated to relevant stakeholders in a timely manner. This needs to be incorporated in standard operating procedures.
“Vendor Management Program plays a key role in third party vendor related risks in this era of outsourcing.”
2. RPA Security
Corporations need to address the security needs to guard the RPA environment from external/internal threats, malware in the ever-changing scenarios. Critical Security features are listed below:
- Firewalls are implemented, tested, and monitored regularly.
- Advanced encryption standards are used for data in transit as well as data at rest.
- Organizations are storing their data in the cloud, which means cloud security is essential. Encrypted storage helps to maintain the privacy of that data. Users should ensure that data is encrypted in-flight, while in use, and at rest in storage.
- Intrusion Detection systems / Intrusion prevention systems (IDS/IPS) are implemented and monitored regularly for any breach attempts.
- Strong Authentication Methods (Multi-Factor Authentication - MFA) are applied for managing RPA bot access.
- Privilege Accounts (Super user Access) usage is minimal and restricted to few users based on specific needs. Their usage is regularly monitored.
- Bot password is encrypted and cannot be accessed by company personnel. Any communication performed by the robot across different networks is encrypted.
- Vulnerability Assessment should be done by independent third-party professionals.
- Access removal ensures timely and immediate removal of users who are out of system or organization.
- Access reviews should be conducted on a regular basis and should extensively cover access provisioning rules and permissions.
- Physical access to the location hosting the RPA should have restricted access.
- Periodic review and monitoring should be conducted on physical access logs to ensure restricted access is enforced.
- Physical Facility also needs to follow regulatory and other certifications (e.g., ISO, EHS). This in a way ensures that minimum/standard requirements for application of BCP and DRP will be met.
- Incremental backups of RPA environment need to be done regularly in line with business criticality. Backup procedures are defined and listed out in standard documentation.
- Monitoring tools are implemented to capture and notify critical system health issues, errors in scheduled bot runs, and performance issues affecting the RPA environment. These incidents and failures are appropriately identified, documented, escalated, and remediated in a timely manner.
3. Review of System Change Management
A review of the system change management control is a process of evaluating and analyzing the controls in place to ensure the effectiveness, efficiency, and compliance of the system change management process in an organization. This can be done to identify any areas for improvement and to ensure that the controls are aligned with the needs and goals of the organization. There are several steps that can be followed when conducting a review of the system change management control:
- Define the scope of the review: It’s important to clearly define the scope of the review, including the specific systems and controls that will be evaluated.
- Gather data: To conduct the review, it will be necessary to gather data about current system change management controls, including information about the controls themselves, tools and technologies used, and control outcomes. This can be done through interviews, surveys, and other data-gathering methods. Care must be taken to ensure authenticity of data source.
- Analyze data: Once data has been gathered, it’s important to analyze for its purpose, integrity, representation, and veracity. These would get reflected through identifying trends, patterns, or areas where controls are not meeting organizational needs.
- Develop recommendations: Based on analysis of the data, it will be necessary to develop recommendations for improving system change management controls. These recommendations should be specific, actionable, and aligned with organizational goals.
- Implement recommendations: Once recommendations have been developed, it will be necessary to implement them to improve system change management controls. This may involve updating policies, procedures, and tools as well as providing training to ensure that changes are successful.
4. SDLC in RPA Implementation and Maintenance
Management should have a structured way of assessing which processes are suitable for automation. The company has systems development life cycle (SDLC) policies and procedures in place that are updated on a periodic basis. The benefits of RPA may not outweigh the cost of investment, and the creation of multiple robots may lead to duplication of efforts and disjointed RPA environment.
Factors to consider before RPA implementation for a process:
- Nature of process (Complex/simple, Priority, Structured/Unstructured)
- Degree of decision making involved / Subjectivity
- Cost-benefit Analysis
- Human intervention requirements
- Security and Confidentiality considerations
- Stability of the underlying process
- Data Source Quality
SDLC Implementation Controls:
- RPA Requirements need to be vetted and approved at appropriate levels before development of bot commences.
- Standard Documentation should be prepared and available for requirements, design, and implementation plans.
- Configurations should be as per agreed design and any changes are vetted and approved. Appropriate communication regarding changes should be made to relevant stakeholders who could be impacted.
- Segregation is in place with respect to Production and development environment.
- Segregation of duties with respect to access rights is maintained so that code changes and configuration changes are not done by the same person (i.e., person developing the code should not place the change in Production environment).
- Changes to the RPA after launch in production are authorized, tested, and approved by appropriate Management. Changes covered include changes to automation software and changes to key automation scripts (robots) performed by the software.
- Version control is maintained before and after implementation of RPA so that changes are labeled, controlled, and prevented from being erroneously used.
- Rollback procedures have to be considered and integrated into design to ensure minimal damages in the event of change implementation failure.
- Maintenance activities for RPA environment need to be planned. Checks should be in place to ensure monitoring and review activities are done pre and post completion of maintenance activities.
5. Data Management and Security
Data breaches have become a regular occurrence worldwide and have serious repercussions on the running of the business. Data breach average cost increased from USD 4.24 million in 2021 to USD 4.35 million in 2022.
RPA accesses, processes, stores, and disposes data to accomplish the task for which it is built and operated. It is imperative that data security is considered at the governance layer. Following aspects are critical while data is considered in RPA Environment:
- Confidentiality
- Integrity
- Availability
- Privacy
Safeguards for Sensitive Data:
- In case confidential/Sensitive data is used, care should be taken to ensure access is restricted and regulated, secure storage is planned (wherever possible confidential data is not stored), and after processing, data is not retained and disposed of in an apt manner.
- RPA environment should ensure that data integrity is maintained throughout the process. Checks and validations need to be part of design to prevent any errors or data intrusion which may impact integrity, besides ensuring data is processed completely and accurately.
- Availability of accurate and complete data in a timely manner is a critical factor in the success of the RPA. Data Sources need to be clearly defined.
- Data retention should be as per policy and compliance requirements.
6. Compliance in RPA Environment
Compliance in relation to RPA environment can cover different facets and as more automation is happening across functions with fulcrum being data, this area has been evolving:
- Data Privacy: Vast sensitive information is collected from customers/vendors by businesses at different touchpoints in business operations. This collected sensitive information poses risks to both customers and companies responsible for storing and using it. Data privacy requirements prompt businesses to treat sensitive data with more caution and take proactive steps to strengthen their data management strategies/practices for any information that could be harmful to individuals if breached. The General Data Protection Regulation (GDPR), CCPA: The California Consumer Privacy Act, PCI-DSS, HIPAA, and other regional privacy legislations specifically deal with Data Privacy.
- Licensing of RPA Bots: In RPA environment, User access and appropriate licensing requirements should be addressed pre and post implementation. Care must be taken to ensure access is provided as per agreed licensing norms.
- Risk Assessment: Periodically risk assessment needs to be done for identification of potential risks. The identified risks should be evaluated for any significant deficiency in the process/functionality of the Application. Risks identified must be mitigated by way of change in process/system or through preventive/corrective measures.
Conclusion
With the evolution of Machine learning and Artificial Intelligence products, opportunities are wide open (albeit risks associated with), Organisations need to gear up to the task of providing adequate risk assurance on these applications. Rise of cyber-attacks has challenged Organisations’ responsibility towards business and has increased liabilities manifold. Systems which are biased, error-prone or used for unethical purposes pose significant reputational risks to the organization that owns it.
As we embark on this transformational journey, it is imperative to focus on the basic tenets of: Transparency, Integrity, Accuracy, Completeness and Reliability while evaluating the risks associated with the governance of these applications.
References
- https://www.gartner.com/en/newsroom/press-releases/2022-08-1-rpa-forecast-2022-2q22-press-release
- https://www2.deloitte.com/content/dam/Deloitte/in/Documents/risk/in-ra-auditing-the-rpa-environment-noexp.pdf
- https://www.ibm.com/in-en/security/data-breach
- http://isaca-denver.org/Chapter-Resources/EYRPAAIRiskSlideDeck.pdf
Author may be reached at: bprashant49@gmail.com and eboard@icai.in