Automating Information Controls and Integrity: A Critical Risk Management Strategy
Information risk often underlies all the other types of risk. Faulty information can cause substantial financial loss or result in a significant breach of compliance. Management of information risk is therefore a cornerstone of any enterprise risk management strategy.
Information risk, however, comes in many forms. One is information security risk. This risk category has received tremendous attention in recent years, and has led to the implementation of technologies and processes to ensure the confidentiality and privacy of corporate data. Another is information technology risk. This risk category is also well understood, and has led to the implementation of technologies and processes to ensure business continuity and minimize downtime for IT services.
A third form of information risk is information integrity risk. This is the risk posed by information that is inaccurate, incomplete and/or out-of-date. Information integrity risk may be the most poorly understood form of information risk – and thus the one that is least effectively managed today. This combination of inadequate understanding and inadequate management makes information integrity risk a major issue for senior finance and treasury professionals. Fortunately, with appropriate best practices and supporting automation technologies in place, financial managers can effectively mitigate information integrity risk and protect their organizations from a wide range of potential dangers.

Several factors determine the magnitude of a company’s overall information integrity risk. The first factor is obviously the quantified consequences of individual risk events. For example, a bank that fails to properly balance accounts – and therefore winds up with millions of euros in unutilized capital – can assign an opportunity cost to such an event by calculating the current rate of return on those funds.
Other types of events may be more difficult to precisely quantify, although their potential cost may be much greater. A company that provides inaccurate financial statements to government regulators, for example, may have to pay substantial fines and bear the costs of an audit and re-statement. The size of those fines and costs may not be wholly predictable, even though they are likely to be substantial.
A second factor to consider is the number of times such an individual risk event may take place before it is detected. A financial services firm must therefore multiply the opportunity cost of a misallocation of funds by the total number of times that such a misallocation can potentially occur before the error is discovered.
A third factor is the total number of different potential risk events the company has. A bank providing a focused set of services for a select set of customers in a limited number of geographies clearly has less exposure than a bank offering more services to more customers on a global basis.
A fourth factor is the complexity and sophistication of a company’s information supply chains. A simple transaction between two parties has much less exposure then a complex transaction that passes through many parties. The more steps there are in the information supply chains that drive a company’s risk events, the greater its potential exposure.
Magnitude of risk is further affected by intangibles. What happens to a company’s reputation if it has to re-state earnings or doesn’t project its performance accurately? What is the potential impact on its stock price and market cap? What are the potential consequences if a company has to pull resources away from strategic tasks in order to address information supply chain problems in crisis mode?
One factor, however, supersedes all others in determining a company’s exposure to information integrity risk. That factor is the effectiveness with which it protects its information supply chains. Without such protections, even a company with a relatively limited risk profile will remain vulnerable to potentially costly information miscues. With such protections, on the other hand, companies with otherwise significant exposures can substantially reduce the probability of such a problem occurring – and can ensure that if it does occur, its impact on the business will bestrictly limited.
Many types of companies create value through a set of processes by which goods and materials come into the company in one form and leave in another. These processes make up what we call supply chains. Companies manage these supply chains to make sure that they deliver quality products in a timely, cost-efficient manner.
Companies also have information supply chains. Information may or may not be an explicit component of what the company sells to its customers. But the information a company receives, processes, and delivers is critical. This information is delivered to internal users, customers, partners, and/or external regulators. It provides insight into the company’s operations (inventory, sales performance, P&L). It describes the world in which the company does business (commodity prices, interest rates, market projections). It relates to everything from products (lot numbers, specifications, unit costs) to customers (purchase orders, buying patterns, account balances). In fact, just about everything a company does involves some sort of information supply chain.
Information supply chains are often quite complex. Information from multiple sources goes through a variety of transformations as it passes through people, spreadsheets, enterprise applications, databases, data warehouses, and reports. And, just as glitches can occur in conventional supply chains, so too can they occur in information supply chains. Sometimes these glitches are a result of human error, such as someone keying the wrong data into a system. Other times, systems are the culprit – such as when a “hiccup” occurs during a batch data transfer.
One major difference between conventional supply chains and information supply chains is that problems in the latter are often much more difficult to detect. If a factory worker opens a crate of recently delivered parts and sees that some of them are chipped, it’s a fairly simple matter to bring the issue to the attention of a foreman. But flaws in digital data are not always so self-evident. In fact, information supply chains can generate bad data for an extended period of time without anyone noticing – until it’s too late.
When a company’s information supply chains are operating properly, it possesses a high degree of information integrity. When they’re not, the company is exposed to information integrity risk – and can therefore easily be blindsided by the potentially disastrous consequences of delivering bad information to internal users, customers, partners, and/or regulators.
With so much at stake, it’s clear that companies must take proactive steps to ensure the integrity of their information supply chains and protect themselves from information integrity risk. But how exactly can companies accomplish this? And what differentiates an effective information integrity risk mitigation strategy from an ineffective one?
Based on the real-world experiences of companies that have successfully met this emerging challenge, it is clear that both best practices and robust technology are required to safeguard the end-to-end integrity of information supply chains across the enterprise. Specific attributes of effective risk mitigation strategies include:
Of course, companies can only implement these risk mitigation measures if they have fully mapped out their critical information supply chains and gone through the exercise of defining business rules that allow them to determine when information is faulty and/or presents a meaningful exception to established information parameters. And, once these measures are in place, a company will ideally track trends in errors and error sources in order to continuously improve information integrity across the enterprise.
However, regardless of how far it may or may not ultimately decide to take its information integrity risk management strategy, no company can continue to operate without automated information supply chain controls in place. Information is too critical to financial performance, operations, customer relationships, corporate reputation, and regulatory compliance to allow error and unreliability to creep in. If a company’s data isn’t trustworthy, nothing else it does will be either. That’s why corporate treasurers and the financial institutions that serve them need to fully assess their current information integrity risk profiles and take immediate, proactive steps to mitigate their vulnerabilities.