Tuesday, September 6, 2011

Internal Controls in Football


It’s that time of year when college and professional football are beginning their seasons.  Looking at how teams set up their defensive players, one sees an exercise in internal controls. By examining the functions of different defensive players, one can see how they act to neutralize offensive threats and learn from their best practices and incorporate them into the defensive game plan (internal controls).

Teams set up three layers of protection against the threat of the offensive team moving the ball down the field. The first layer of defensive internal control is the defensive line. If the offensive side tries to run the ball, the defensive linemen will act to tackle the player who carries the ball to stop his progress as soon as possible. If the offensive team calls a pass play, the defensive linemen act to sack the quarterback or knock down the ball. If either action is successful, the defense will have neutralized the threat of the quarterback passing the ball down the field.

The second layer of protection is the linebackers. In the event of running play, they assist the linemen in tackling the ball carrier. In the event of a passing play, they will either assist the linemen in trying to sack the quarterback, or disrupt passes that the quarterback throws. The players who make up the last line of defense (set of controls) are the cornerbacks and safeties. These players primarily guard against passes that the quarterback throws. In the event of a running play where the ball carrier gets through the linemen and the linebackers, the responsibility falls to the cornerbacks and safeties to neutralize the threat.

If we replace the setting of a football field with, say, a computer and the threat of the opposition advancing the ball into our territory with someone trying to access the computer, we can learn from those football analogies (internal controls). The computer is housed in a building. Our defensive line are the security guards who block access to the building, except for those individuals who have legitimate reason and are authorized to be in the building. Next, the computer should be set up in a locked room. Instead of linebackers, we have a locked door to the room that will block unauthorized access to that room. If a person is then able to get past the guards and get into the building, we have a password to the computer instead of cornerbacks and safeties.” Hopefully, the result of both set of controls will be the same.  The offensive attack will be stopped before any significant damage is done.

Thursday, June 16, 2011

Internal Controls Provide Added Protection

Managers and employees alike often ask why do we always have to:

  1. Lock the supply room door?
  2. Display our identification card?
  3. Sign documents prepared by our subordinates?
  4. Ensure that all vendors are registered?
  5. Maintain copies of documents supporting transactions?
Some of these requirements are in fact a matter of law or regulation. But even in those cases compliance is not the real reason. This is generally because the provision of the law or regulation was writtin the support the real reason.

In each case such rules, which are examples of frequently applied interanl controls, are imposed to make it less likely that some serious adverse consequence (known as a risk) would 0ccur. The underlying risks behind doing the five internal controls listed above are:

  1. An unauthorized person could take some or a lots of supplied for personal use.
  2. A non-employee could be gain access to the office, remove personnal or organizational property or information, and not be suspected of having an inappropriate reason for being there.
  3. You assistant may make a serious error in preparing a document that could have costly consequences.
  4. An unregistered vendor may turn out not be be a legitamit business.
  5. It may be necessary to substantiate the validity or accuracy of a transaction at a later date.
An internal control is rarely an absolute quarantee that a problem will be avoided; neither is not doing the internal control a guarantee that there will be a problem. For example, it is possible that a supply room door could be unlocked all day and no items get taken for inappropriate purposes. However, leaving the door unlocked provides too high a likelhood of a theft to be allowed. Similarly, if the door is always kept locked there could still be a theft by an individual determined to commit a criminal act. However, the odds of this happening in an otherwise well managed work environment is appropriately low.
If you are wondering why a certain rule is in place in your workplace, contact Stu on Patrol at this website and he may provide you a likely underlying reason in the form the risk that the rule in designed to mitigate. On the other hand if you are worried that a certain bad thing may happen need an idea of what rule or device may make that problem less likely to happen, contact Stu on Patrol and he may be able to provide you some suggested actions.

Wednesday, June 16, 2010

BP Deepwater Horizon Risk Management

The news over the past 58 days regarding the consequences of the British Petroleum oil spill in the Gulf of Mexico is really about Risk Management. This process includes identifying serious risks and determining how best to manage them by developing and implementing appropriate internal controls. The Deepwater Horizon catastrophy illustrates the most fundamental risk management errors that can be made.

Traditionally, the most serious risk in the exploration portion of the petroleum industry related to spending huge resources to discover oil by digging a well and ending up with a dry hole. This risk has been addressed by minimizing drilling costs and increasing the speed of creating wells so as to provide the maximum number of chances that a producing well would be created.

Consequences of a blowout (a well that uncontrollably gushes oil) were considered secondary and of little concern. When there was a blowout, a specialized oil services firm was called in to extinguish any fire, install a cap and shut off the value so the owning company could easily take over the production process.

Some major changes that have occured over the past 20 years are:
  • Exploration relies more on geological theory and reliable instrumentation and less on random search
  • Drilling operations have become more automated and efficient
  • More drilling has to be deeper as available local reserves diminish
  • More drilling has to be off-shore as available on-land oil fields are becoming fully explored

These changes suggest oil companies should be refocusing their risk concerns from those associated with dry holes to those associated with blowouts.

It is now being painfully documented that there are numerous precautions that were diminised or skipped entirely in the Deepwater Horizon drilling operation. These include not ensuring that only top quality blowout protection equipment was submersed a mile beneath the surface and not thorouhly tesing that equipment before the drilling reached the depth where oil was expected. The most recent revelation was that BP used only about a third of the recommended number of mechanical devices designed to ensure that the drill pipe is centered in the well before attemping to seal the installation of that pipe with cement. The stated rationale for taking such short cuts was that the drilling operation was behind schedule.

There is no question now that the cost of not taking known precautions has greatly exceeded any projected savings from speeding up the completion of the well. Eleven men have died, many others were injured, many millions of barrels or crude have entered the Gulf and adjoining shoreline, wetlands and beaches, killing fish, birds and other wildlife and threatened the fishing and tourist industries throughout the entire Gulf Region.

Stu on Patrol is concerned about wasting resources to protect against risks that have greatly and decreased in relevance and ignoring new risks that are more severe than the old ones. If you know of other instances where industries and organizations seem to be guarding against risks that are no longer as serious as they used to be and have failed to address newer more serious risks, please comment back to Stu on Patrol with what you see and what you think needs to be done about it.

Stu on Patrol will take all comments seriously. If they relate to any aspect of Corporation for National and Community Service operations, they will be greatfully acknowledged and thoroughly researched, but will not be published. If your comment does not relate to the Corporation, it will be published here in its entirety.

Tuesday, January 19, 2010

Internal Controls for Painting a Room at Home?

When you decide to paint a room at home you will be concerned with the quality and cost of the job. Therefore, many of the things you do will be similar to the use of internal controls at work.

In planning the job, you will need to:

  • Choose the color
  • Gather equipment and materials
  • Decide when you will do the work

You will do a risk assessment - by thinking of what can go wrong:

  • Paint on the carpet, furniture, draperies, windows and/or moldings
  • The previous color may not get completely covered
  • Spots could be missed
  • The color on the wall may not look like the sample picked at the store

You will install controls - to prevent things from going wrong:

  • Mask windows, doors and moldings
  • Use plenty of drop clothes
  • Keep a damp rag handy to wipe up any drips before they dry
  • Paint a small section behind where funiture usually sits and let it dry to check color
  • Buy some extra paint in case another coat is needed

You will do quality control - so problems can be fixed as soon as possible:

  • Stop and check job after completing one wall
    - Is coverage okay?
    - Is there any paint under the drop clothes?
    - Are edges sharp between painted and unpainted surfaces?
    - Does the color look right?
  • What changes in procedure are needed before painting other walls?
  • What changes in proceudre are needed before painting other rooms?

If you apply these precautions and considerations, you will be glad you did and will also have a nicer paint job to show off to your friends.

Tuesday, September 8, 2009

Have You Ever Hired a Clushmaker?

When I was a youngster, many years ago, there was a popular campfire story known as The Clushmaker. The story is about an aspect of a strong internal control environment that is often lacking in a well established bureaucracy.

A young man entered a U.S. Army recruiting station. When asked his line of work, he answered that he was a Clushmaker. Not wanting to admit not knowing what a Clushmaker was, the Seargent who first greeted the applicant referred him to the Captain that supervised the station. As the story progressed, the young man was introduced to a long chain of ever more senior officers, none of whom was willing to admit not knowing what a Clushmaker was. Finally, the young man was introduced to a Five Star General who was not not in a position to refer this potential recruit to a more senior officer.

Naturally, the Five Star General was also unwilling to admit that he had never heard of a Clushmaker. But, he also didn't want to miss out on any benefit that a Clushmaker may provide his organization. So, he signed him up and ordered him to begin his clushmaking operation at once. The newly enlisted Clushmaker started by requisioning a long list of needed supplies and equipment as well as a detail of 50 men to make all needed preparations. Finally, when all was ready there was a tower erected that stood 500 feet above a pond that was 10 feet deep and 40 feet in diameter. At the top of the tower was a two ton ball that measured 10 feet in diameter. Connected to the giant ball was a cable that exended all the way down the tower to a large lever on a control panel at which the Clushmaker stood.

The General asked the Clushmaker if all was ready and the Clushmaker answered "yes."
Then the General directed that all available troups on the base where the preparations had been made be assembled around the 40 foot pond so that all of them would know the value of the Clushmaker who was recrutied into this unit.

Then, the General gave the order to "make clush." At which point the Clushmaker pulled on the lever, causing the ball to be dislodged from its resting place at top of the 500 foot tower and plumit down the 500 feet into the pond. The result was an overwelming clushing sound followed by water being splashed out of the pond in all directions thoroughly soaking all those who observed the event.

So, what does Stu on Patrol think of all this? That is an easy question. It was an absolute waste of whatever was paid to the Clushmaker, for the supplies, materials and work detail he requisitioned, and the time taken up by the numerous observers, including the ficticious Five Star General who authorized the project. The only lesson learned is that a great deal of time and expense could have been saved if the Seargent who initially greeted this young man of dubious talents had asked him what a Clushmaker did and what value it would have to the U.S. Army.

The more important question, directed to all those who read this story is, "Have you ever done or observed someone in your organization do anything that resembles hiring a Clushmaker?

Please write in to Are We in Control because Stu on Patrol wants to know.

Wednesday, March 25, 2009

How Does Risk Differ From Vulnerability?



Risk is a measure of the impact on your mission (or on your lifestyle) of a particular bad thing that could happen. There are two components that determine the severity of a risk:
  1. Likelihood or frequency of this bad thing occurring.
  2. Cost or other measure of stress caused when it does occur.
Based on the relative intensity of these two factors, risks are classified as High, Medium or Low.

Controls are things and actions that we add to our processes that reduce the likelihood that the potential bad thing will actually occur and/or reduce the resulting cost or other stress resulting when it does occur.

Some commonly used controls are:
  1. Having someone else check your work (like a proof reader);
  2. Getting a supervisor to watch what you do (like a beach or pool life guard);
  3. Wearing protective clothing (like safety shoes or a helmet);
  4. Attaching a safety rope or harness (when rock climbing or washing windows on a building).
Vulnerability is the residual level of risk that remains after a control is put in place.

To see how Risk, Controls, and Vulnerability interplay, take a levee on a river that floods 15’ every year. The Risk is your house being flooded. Since the river floods frequently, it is a High Risk. The Control is the levee. High vulnerability would be a 10’ levee and yearly floods of 15’. Low vulnerability would be a 20’ levee and yearly floods of 15’. You can’t change the risk – the river is going to flood - but you can heighten the levee. Thus, by strengthening the control you can lower the vulnerability.

Monday, December 22, 2008

Closing Barn Door After Horses Got Out

One very common apparent dilemma in the world of internal control is whether or not to fix the barn door after loosing one or more of your horses. Some say this is a waste of time and effort. However, more thought is needed. For example, there are some questions to ask before just leaving the current situation alone:


  • Are there still more horses in the barn (valuable assets that must not be lost)?

  • Is it possible that some of the lost horses could be recovered?

  • Will there be new horses added to your stable that need to be protected?

Just recently I had the opportunity to be faced with this question in a very personal way. I had been crossing Rockville Pike at Halpine Road on the way home from the Twinbrook Metro station on December 11, 2008 -- an action I do nearly every day that I go to work. The conditions were bad (dark, raining, a little later in the evening than usual). I was struck by a car driven by someone who either did not see me at all or thought he or she could make a left turn in front of me. The result was that I learned the definition of a pedestrian colision with me, Stu on Patrol, being the pedestrian.


As a student of risk management, I have known that crossing Rockville Pike is always a risky proposition. Now, I knew what happens when that risk is translated into an adverse result. Fortunately, I am still alive and able to tell of this unfortunate event. Moreover, there were no adverse effects shown on the CT scan or X-rays I had taken later than night at the Suburban Hospital Shock Trauma Unit. However, my losses and injuries were still significant:



  • I was violently stuck by the car sending me to the ground and injuring the back of my head

  • The head injury required 11 surgical staples

  • Several places on two or more ribs are bruised or broken (X-rays don't always see breakes)

  • Many truck and extremity muscles became strained, requiring weeks to fully recover

  • My glasses and hat were knocked off my head on impact not to be found again.

Now that a loss has been sustained, it seems foolhardy to me to assume it would could never happen again. The traffic patterns and personality of the local drivers has not changed. So, what adjustment to my behavior could be made to reduce the likelihoon of a recurrence? I am not likely to change my commuting habbits, such as walking to the Metro, any time soon. Nor is there any way I think I could change the habbits of those who drive cars near where I have to walk.

I decided I had to make it easier to see me and therefore less likely to not see me as I was crossing the street. I will therefore be on the lookout for more reflective or more brightly colored clothing . I also considered wearing a light when it was dark. In the end I purchased a runner's headlight that I have been wearing on my arm in blink mode on my way from home to the station or vice versa if it is dark outside. I will also add more vissible clothing to my wardrobe from time to time as I notice it in stores.

I was extremely lucky to have been hit, was able to limp away from the scene, and most likely have a full recovery in the next week or two. Thus, there were some lost horses, but many more still in the barn worth saving. It is also possible that the collission may have been avoided if I had taken the risk of crossing the street under bad condition more seriously and made myself more conspicuous. But, all decisons have to be made in the present, rather than the past or the future. So, yes, in this case as in most other cases, it does pay to fix the barn door after the horses get out.

If you have an account of how you fixed the barn door after loosing some horses, or it you decided not to fix it, please comment back to Stu on Patrol.


Monday, December 15, 2008

Why Sign Off? - - Why Sign On?

The requirement that official documents be signed is about as old as writing itself and continues to show up in nearly every new form that needs to be completed. Why are we asked to sign off on documents that we have completed. There appears to be three separate reasons:

  1. Tells the reader that the writer did in fact intend the meaning of every word (and number written in the document.
  2. Prevents the writer from claiming at a later time that someone else must have written the document. (Either the writer recognizes the signature or a handwriting expert can provide evidence of its authenticity.)
  3. Reminds the writer that anyone can determine his or her identity and therefore care should be taken to avoid any incorrect or inappropriate material.

If the above is why we sign off, then why do we sign on. In effect the sign on required to enter an information technology network or an specific application is a modern day version of a pen and ink signature. The three basic reasons still apply. A computer system sign-on also has an additional purpose:

  • Only those individuals with a recognized user name and password can gain access to network, application or special function protected by the password.

And the computer sign-on also has some very important features (provided passwords are kept secret):

  • The exact identity of the person signing on can be easily determined.
  • The precise day and time of a sign-on can also be determined and recorded.
  • Extra sign-ons can be required to specifically record the entry of a user into a specific function or sector of an application.

Did you ever wonder why you were asked sign-off so many places on a legal document or sign-on so many times during a single computer session? To discuss any puzzling examples, simply conact Stu on Patrol.

Friday, November 28, 2008

Internal Control Used in Every Day Life

  • Alarm Clock to wake up on time. Sometimes for extra important early morning events a second or even a third alarm is set.

  • Warning lights, visual messages, and/or audible messages on some cars when doors are left open, lights are left on or seat belts are not fastened.

  • Some cars will not start unless all doors are closed.

  • Some models automatically turn headlights and windshield wipers on and off as needed, so there is little chance that the driver fail to use these devises or turn them off when they are no longer needed.

You probably know of many more commonly used internal controls. Please take a moment and sent a comment to Stu on Patrol to let me know what some of them are.

Wednesday, November 5, 2008

Hospital Internal Controls

A common misconception about internal controls is that they only relate to financial matters. One example of non-financial internal controls are those used at hospitals to reduce to very low levels the risks that one patient would be mistaken for another or that a patient would receive the wrong medication.

  • When a new patient is admitted into a hospital even before leaving the registration desk the registrar checks a photo ID card and then affixes a bracelet to display vital information such as the patient's name, nature of hospitalization, account numbers, date of admission and the patient's doctor's name.

  • If a patient needs Introvenous medication, the supply bag cannot be hung over that patient's bed or stretcher unless the chart is signed by two Registered Nurses attesting to having compared the doctor's order to the lable on the bag before it was hung.
  • At one time when patients was prescribed a regular medication before being admitted to the hospital they were directed to leave those home so that the hospital pharmacy could benefit from the business of supplying those medicines. However, to reduce the likelihood of errors by the hospital pharmacy, patients are not encouraged to bring thier prescribed medicines with them unless directed otherwise by their doctors.

The reason for presenting these examples of non-financial internal controls is to show that good controls are needed to safeguard any valuable asset that may otherwise be vulnerable. There can not be any asset that is more valuable or worthy of our best care than a human life.

If you can think of other examples of internal controls, please comment back to Stu on Patrol.

Tuesday, August 5, 2008

Four Approval Signatures

An outside consultant was asked to find out why there were so many errors in a process that required four individuals to review and sign off on the work that was done. What she found was very disturbing. It turns out that while all four approvers knew they were supposed to review the document carefully before signing off, none of them reviewed it all all.

The first reviewer was the most junior level manager. He decided the other three knew much more that he did and would catch any errors. The second reviewer was more senior than the first and she decided that the first reviewer would catch anything obvious and the third and fourth reviewers would catch all of the more difficult problems. The third reviewer was sure that the first two would catch any errors and the fourth reviewer would make any important decisions. The fourth reviewer decided that if there were any problems, one of the other three reviewers would have found and corrected them before the document came to her for review.

Thus, each of the four reviewers signed the document and none of them reviewed it at all. So, what is the answer to this apparent puzzle. There are two answers that should be applied in all cases of multiple document review:

  • When developing a process procedure there should always be a specific expectation as to what each reviewer is to be responsible for checking and correcting.

  • Regardless of what the procedures say, each person assigned to review a document is to consider that she or he is the only one who is checking the document. Therefore, if there is an error to be corrected or a decision that needs to be made, there is no expectation that anyone else will do it. This attitude ensures that a document receiving multiple reviews get more attentions, not less, than one receiving a single reivew.

If you come across some internal control puzzle, such as four signers none of whom actually review anything, or you have more ideas on when to specify multiple reviews or how to make sure all reviewers do what is expected of them, send a message to Stu on Patrol or use the comment feature of this blog to get back to me.

Friday, August 1, 2008

Control Through Automation


One of the best ways to strengthen internal controls is to automate a process. For example, for many years travel orders were prepared as paper documents and later data-entered into the financial system. However, the paper document does not know for sure if there is money available to pay for the trip, or if the travel has started before all needed approvals are received, or even if all required approvals were ever received.

Now we have E2 Travel, which has increased our level of control over travel a great deal. Under this system all employee travel must be approved and booked through the E2 Travel system. Therefore, our Travel Management Center will not book transportation unless they receive the approval from the E2 Travel system. Also, the obligating travel order is entered into the Momentum financial system on the basis of the aproved amount and accounting codes recorded in the E2 Travel system. This means in most cases that it is virtually impossible for an E2 Travel trip to begin before it has been fully approved. Future integration of E2 Travel with the Momentum financial system will eliminate some of the current data entry and processing steps for travel orders and travel vouchers.

If you have other ideas about how to improve internal control over travel, or if you have noticed a weakness in how it is currently being controled here at the Corporation, please comment back to Stu on Patrol.

Thursday, July 31, 2008

How do you know?

Much of internal control is answering a question that starts with, "How do I know .....?" For example, How do I know that I take my multiple vitamin every day? There are many possible answers to this question, including "I don't really know." For me the answer is that I don't start eating my breakfast until I see my vitamin next to my cereal bowl and when I have finished eating, I make sure that it is no longer there.

If you have a different way to remember your vitamins, or if you have something that you seem to always forget, please comment back to Stu on Patrol so that more good internal controls can be used by more people.

Wednesday, July 30, 2008

Introduction to Stu on Patrol


Stu Graff is an employee of the Corporation for National and Community Service. He has entered upon a great discovery adventure on July 18, 1998, just over 10 years ago. That adventure is intended to search out new ways to create, enhance, simplify and automate internal controls within the Corporation so that everything works better, easier and with less risk that anything serious will go wrong.

In order to be more vigilante in the never ending search for better ways to organize program and administrative processes Stu is committed to be forever on patrol. That's right! I am Stu on Patrol.

If you have discovered a new internal control technique that we should try here at the Corporation or have come upon a problem that indicates the need to implement a new internal control , please take a few moments to share your thoughts with Stu on Patrol.