Вы находитесь на странице: 1из 11

pwc.com.

au

Who minds
the bots?
Why organisations need
to consider risks related to
Robotic Process Automation

As Robotic Process
Automation gains
momentum, organisations
need to implement a
strong control framework
to address potential risks
Contents
The heart of the matter 4
An in-depth discussion 5
Our recommendations 8
What this means for your business 11
The heart of the matter
With Robotic Process From financial markets to
Automation (RPA) becoming a driverless cars, we rely more and
more on automated systems.
prominent topic of discussion, Theyre game changersbut
organisations are thinking without effective controls, they
of ways to integrate digital can cause trouble in a hurry.
labour into operations. While Across many industry sectors,
swift results can be enticing, companies are looking to digital labour
companies should identify to supplement human work. From front
relevant risks and ask the right office to Finance, HR and operations,
questions before diving into RPA is helping organisations become
more efficient and reduce costs. Used
implementation. By doing the properly, the tools even address many
initial legwork, companies problems that end-user computing
can position themselves for applications have faced. But there
success. Streamlined processes are less obvious ramifications
and effective controls can help both good and badtoo. RPA calls
for a new mindset when it comes
pinpoint issues early and ensure to risks and controls, but this isnt
a positive return on investment. always clear to companies as they
eagerly embrace these new tools.

In this paper, we explore the potential


Bots for the sake of regulatory, financial, and reputational
hazards posed by digital labour;
bots is a very blunt highlight specific areas of concern,
instrument... without and suggest some controls to consider
before you implement RPA broadly.
investing the time Of course, theres no one- size-fits-
in risk and controls all option when it comes to a risk
assessments up front, and control program. Still, without
proper governance, the benefits of
you simply run the digital labour can quickly vanish.
risk of making a big Getting it right from the start is far
more effective and cost efficient than
problem happen cobbling together a patchwork of
much faster. policies and controls later on. Good
controls dont just avoid problems.
They make things better by enhancing
transparency, reducing costs, driving
consistency, and producing metrics
that lead to continuous improvement.

PwC | Who minds the bots? | 3


An in-depth discussion

Risks and robots


Lets start by looking at what we Executive: Have the right people Operational: What controls exist
mean by risks and controls. When you bought in? Does everyone agree to monitor performance? How will
implement any new technology, its on what needs to be done? you stay compliant with relevant
easy to be enchanted by what it can regulatory requirements?
Technical: Have you got a strong
do when working well. With effective
controls, you can mitigate the risks of enough technical foundation for Functional: Do you understand
the new technology while protecting the robots to operate on? How your processes well enough and
your investment and, quite often, your will you control the robots access are they standardised to the point
customers experience. to your systems and data? How of being able to be automated?
will you test the robots to make Who designs controls? Can
The best way to do this is to think sure they function as intended? what I have implemented be
broadly about risk and oversight, Are there scalability limitations tracked and is it auditable?
starting by understanding the in RPA and core systems?
stakeholders involved. As shown Obviously, these are high-level
Change management: How will examples, and theyre not intended
in Figure 1 below, we see five risk
you manage change that will to act as a checklist. Weve identified
categories that apply to RPA programs:
cause the robots to malfunction? many potential problem spots from
Who manages communication? minor to complex, and weve found
How can you address potential plenty of ways to get more value out
resistance from workers? of RPA investments. When handled
properly, they can often be addressed
easily. But when they pop up in a crisis,
they can sink a promising program.

Figure 1: Five categories of risk to consider when implementing an RPA program.

RPA robots&risk
To design effective controls,
think broadly about exposure

l Exe
na cu
tio tiv
nc e
Fu

PwCs RPA
risk framework
O p e ra

al
nic
t io n

ch
Te
al

Ch a
n g e m a n a ge m e n t

PwC | Who minds the bots? | 4


Digital labour: Whose job is it,
not just digital, anyway?
not just labour
In our view, too many companies treat A tech company is a whiz at installing
risk and control as an afterthought. software, not controlsand it may not
They do so because they assume have the skills or incentive to even think
that RPA is just more software, and about risk management. Likewise, an
they know how to manage software. auditor may be well schooled in the
Typically, they leave it to RPA vendors, complexities of traditional governance,
software integrators or Internal Audit, but robotic technology introduces
Risk Management, and Compliance. new layers of digital risk that call for a
Unfortunately, there are issues either different level of understanding and a
way. Someone with the right skills new tool set.
needs to be focused on the design and
Dont assume that someone else is
implementation of controls across the
focusing on risk and control.
entire program. And, to be successful,
We typically dont see this as a priority
its important to build in controls right
in many RPA enterprise mobilisation
from the beginning. Controls can be a
efforts, and that can lead to problems
separate formal work stream, or even
down the road. In RPA projects with
better as an embedded capability in
our clients, we embed governance, risk
design and deployment teams.
management, and controls into our
approach to enterprise mobilisation and
deployment. As noted in Figure 2, when
you bring this lens to a project plan,
you often catch issues before they arise,
and you can identify opportunities for
improvement, too.

Figure 2: Benefits of a robust RPA control framework.

Digital
labour Fix it before its broken. A robust control
framework to address risks can help you
spot issues early and get the most value
from your RPA investment.

PwC | Who minds the bots? | 5


A little now, Controls and end
a lot later user computing
Theres another problem with This isnt the first time that companies
handling risk and control later: it can have experienced these issues. Many
be expensive to do so. Sometimes organisations have come to rely on end-
companies will have humans check the user computing applications (EUCs) as
work of the robots as a control point. a fundamental part of their business
operations. While EUCs provide
This is fine, up to a point. But the
valuable tools, they dont offer many
human infrastructure you need to
provisions for management control.
check the work of three robots becomes
RPA often circumvents these problems
overwhelming with 30 robots, and
because the newer technology includes
untenable at 300. If you treat controls
tools like audit logging and control
as something to get around to later, you
rooms that allow central support staff
run some expensive risks, from retrofits
to monitor robot activity. If youve
to the loss of executive credibility.
designed your RPA controls properly,
youll know exactly where each robot is,
what its allowed to do, and what
it has done. This can be a challenge
for EUCs even within a strong
governance culture.

PwC | Who minds the bots? | 6


Our recommendations
Designing controls
that work
When control functions arent environment for your organisation, and
considered early in the RPA design controls for each. When digital
development cycle, small issues labour is involved, there are multiple
can grow big, as can remediation stakeholders, internal and external,
costs. So, developing effective each with their own concerns. They
policies and procedures before any all should be educated on what digital
enterprise-wide roll out increases labour can do, and why. Someone who
your chances of success. But starting oversees cybersecurity will focus on
early is only one component in one set of challenges, while the people
designing effective controls. who conduct quality assurance testing
may have very different priorities.
Remember, one of the principal goals Regulators and the Internal Audit, Risk
of a risk and control strategy is to Management, and Compliance teams
establish trust and transparency. So, may be particularly interested in how
you need to understand which RPA you use RPA, especially when customer
risks really matter most in the broader data or financial reporting is involved.

Figure 3: Questions to ask as companies design and implement RPA control structures.

RPA robots, and risk:


Crucial questions to stay in control

How will you choose How will How do you Whos in charge?
your projects? robots share? configure robots?

Are you in What about Whats the How will you


compliance? cybersecurity and backup plan? manage changes?
data privacy?

PwC | Who minds the bots? | 7


As noted in Figure 3, here are some How do you configure robots? Whos in charge? Once the
questions to consider as you prepare Will you follow legacy change robots are at work, someone has
to design and implement your RPA management protocols? This may to oversee operations: essentially,
control structures. The list isnt seem like a sound approach, but a digital workforce manager.
exhaustive, but it should illustrate consider how you will reduce the People in this role will need tools to
the kinds of issues you may face: cycle time and policies associated monitor the capacity, availability,
How will you choose your with the delivery approach for and performance of robots in
projects? Does management digital labour without increasing production. Theyll need to oversee
have a formal methodology to the risk. Testing is part of the logical security rights and take
inventory, analyse, prioritise, and configuration process, too so who ownership for the robots user IDs
select projects where digital labour will develop the robots test plans? and passwords. Theyll need to know
makes sense? If this doesnt seem Testing is a well-defined discipline; how to respond if something breaks
significant, think again. As weve will the user who creates tests know down in a production setting (Is it
noted elsewhere, automating how to design user acceptance the same kind of escalation process
a bad process can destroy the tests and regression test cases to as when other technology fails?
return on your RPA investment. sufficiently assess the changes? You Will you have additional resources
First and foremost you should should be sure that youve designed on call to help?). Finally, theyll
consider how you optimise the and conducted a comprehensive need to troubleshoot for the long
processes and have a lens on how to examination, documented the term. Just as in any complex system,
optimise the controls framework. results, and made this information there will be opportunities for
accessible to new team members. improvement, and someone needs
How will robots share? RPA is It seems like it works isnt good to own the role of analysing failures
lightweight in that it doesnt require enough. It is highly recommended and applying a fix to the root causes.
much centralised IT support. But to have a dedicated testing lab
youre likely to see better results if Are you in compliance? Oversight
and development and testing structures arent static because
you set a formal protocol that spells environments to prevent delays. You
out a shared approach to RPA across stakeholder concerns arent
also need to ensure that you test static. Among other things,
business units, supported by a clear the ability of the RPA tool to work
communication process. When you should determine if these
in your environment. Good testing controls are in compliance
starting an RPA program, its also programs can save money and reduce
important that you build a library of with statutory, regulatory, and
frustration by identifying and fixing contractual requirements. This is
bots to enable re-use down the line potential problems before they occur.
and reduce overall time and cost to especially true when the digital
implement. Consistency simplifies labour is processing cross-border
and speeds up RPA production, transactions that can involve an
especially when introducing new entirely different set of rules and
robots. Its also easier to design procedures, or transactions that are
tools to monitor standardised governed by regulatory bodies.
operations. You dont have to be
heavy-handed; business units should
be able to find their own innovative
uses. But with some simple control
processes, youll deploy processes
more quickly and consistently.

PwC | Who minds the bots? | 8


What about cybersecurity and Are you ready for change?
data privacy? Almost by default, Does this automation affect
robots access multiple systems, and financial reporting processes
each can be a potential vulnerability. and Sarbanes-Oxley controls?
Will the robots touch personally If youre a service provider, how
identifiable information? How might are you going to describe your
they be compromised? Given that RPA processes to clients? Do you
many robots will be used to handle issue a controls report (i.e. SOC 1
sensitive information, what vendor and SOC 2)? How are you going
management provisions will you to demonstrate the operating
establish and maintain to verify effectiveness of the robots?
how data might be accessed? These
Finally, controls that work rely on
risks should be identified, built into
documenting compliance at every
any risk assessment, and plugged
stage of planning and operation. Even
into enterprise-wide controls.
if youve done all the work to establish
Whats the backup plan? How an effective control system, you wont
are you addressing the business have established trust and transparency
continuity risk? Can you cope if you cant prove your work.
with the sudden departure of
key personnel and the possible This doesnt have to be an onerous,
loss of institutional knowledge? administrative process, but it can spell
If you have designed manual the difference between success and
workarounds in the event of a failure for new technology like RPA.
robotic failure, are you prepared if
the responsible humans leave? How
do robots fit into the organisations
broader resiliency plan?

PwC | Who minds the bots? | 9


What this means
for your business
One step back,
two steps forward
Its the paradox of control: slowing programs offer many benefits. They
down to add checks and balances can can give the flexibility and appeal of
speed up a project in the long run. EUCs without unwanted surprises.
Behind every RPA program delay is They offer transparency that helps
a set of stakeholders asking: What you communicate effectively with
would happen if...? What if the robots regulators and stakeholders. They
make private data public? What if they lead to consistency instead of
make financial commitments we cant workarounds. They make RPA stronger.
honour? What if they affect mandatory
With good governance from the
reporting? What could go wrong here?
beginning, you are more likely to
At the same time, you can also bypass problems. This lets you focus
ask What could go right? When on efficiency, speed, transparency, and
handled properly, effective controls digital labours many other benefits.

PwC | Who minds the bots? | 10


www.pwc.com.au

Contacts

Sascha Chandler Clare Power


Partner Partner
P: +61 (2) 8266 3009 P: +61 (3) 8603 2360
E: sascha.chandler@pwc.com E: clare.power@pwc.com

Morven Fulton Nathalie Van Nueten


Partner Director
P: +61 (3) 8603 3641 P: +61 (2) 8266 3309
E: morven.fulton@pwc.com E: nathalie.a.van.nueten@pwc.com

2017 PricewaterhouseCoopers. All rights reserved.


PwC refers to the Australia member firm, and may sometimes refer to the PwC network. Each member firm is a separate legal entity. Please see
www.pwc.com/structure for further details.
This content is for general information purposes only, and should not be used as a substitute for consultation with professional advisors.
Liability limited by a scheme approved under Professional Standards Legislation.
At PwC Australia our purpose is to build trust in society and solve important problems. Were a network of firms in 157 countries with more
than 223,000 people who are committed to delivering quality in assurance, advisory and tax services. Find out more and tell us what matters to
you by visiting us at www.pwc.com.au.
127052504

Вам также может понравиться