Video summary

Special Topics in Accounting: IT Governance

Main summary

Key takeaways

Educational

Main ideas / lessons

  • IT governance is essential for reliable financial reporting

    • In digital organizations, it’s not enough to ask whether financial statement numbers are correct—organizations must also ensure the systems producing the numbers are reliable.
    • A weak system can lead to weak reports; therefore, IT governance connects technology execution to business/accounting needs.
  • IT governance acts like a “bridge” between strategy and technology

    • One side: business goals (strategy).
    • Other side: technology decisions and execution.
    • Without governance, technology investments become expensive but directionless (e.g., buying ERP/cloud/AI without clear priorities, access control, risk checks, or measuring whether the investment works).
  • IT is a strategic asset, not just a support function

    • Historically, IT focused on fixing computers and maintaining servers.
    • Today, IT enables competitive advantage (e.g., mobile banking, digital learning platforms, online transactions).
    • Strategic assets must be governed, and decisions should not be left only to IT—finance/accounting/audit/operations and top management must be involved.
  • Governance improvements determine outcomes even with the same tools

    • If two companies implement the “same” ERP:
      • The one that only installs it benefits less.
      • The one that also defines access control, reporting needs, approval workflows, data ownership, and audit trails benefits more.
    • The difference is governance, not software.
  • Why IT governance became prominent

    • Major scandals and stricter regulations increased focus because:
      • Financial reporting depends on information systems.
      • Weak access rights can enable manipulation.
      • Poor change control can cause errors.
      • Inadequate data protection can cause leaks.
    • Regulators and boards treat IT as part of corporate governance.
  • IT governance definition and accountability

    • IT governance answers:
      1. Who decides? (e.g., who approves new accounting systems)
      2. Who is accountable? (e.g., who is responsible if the system fails)
      3. How do we measure success? (speed, security, accuracy, usefulness)
    • It’s framed as an accountability topic, not only technical.
  • Five focus areas of IT governance (explained)

    1. Strategic alignment: IT supports organizational goals.
    2. Value delivery: IT delivers benefits, not only costs.
    3. Risk management: identify/control IT risks.
    4. Resource management: use people, systems, data, budgets effectively.
    5. Performance measurement: monitor whether IT is working well.
  • Key examples illustrating the focus areas

    • Hospital billing system
      • Alignment: better patient service
      • Value: faster/more accurate billing
      • Risk: protect patient and payment data
      • Resources: staff training
      • Performance: track errors, delays, downtime
  • Standards/frameworks used for IT governance

    • ISO/IEC 38500 (board-level model)

      • Uses EDM: Evaluate, Direct, Monitor
        • Evaluate: Is technology needed? Worth investment? Risks?
        • Direct: priorities, policies, responsibilities, boundaries
        • Monitor: performance, compliance, incidents, outcomes
      • Example given for AI in accounting:
        • Beyond “is it sophisticated?”—ask about data security, verifiability, responsibility for wrong outputs, policy compliance.
    • COBIT 2019 (management/control level)

      • Translates governance into control objectives.
      • Separates governance from management:
        • Governance: evaluate, direct, monitor
        • Management: plan/build/run/monitor IT activities
      • Examples tied to ERP:
        • Are access rights properly approved?
        • Are system changes documented?
        • Are backups tested?
        • Are incidents followed up?
        • Are IT risks reported to management?
    • ITIL (operations/service management level)

      • Focuses on reliable day-to-day service management:
        • Incident management (handle failures quickly)
        • Problem management (fix root cause)
        • Change management (prevent new issues after updates)
      • Example: accounting system downtime two days before reporting deadline impacts closing/reporting/audit/decisions.
  • Digital transformation requires governance

    • Cloud, AI dashboards, mobile apps, automation, big data can improve capability.
    • Without governance, transformations become risky, e.g.:
      • Cloud: access control, data location, backups, vendor failure handling
      • AI: explainability, reliance, bias/wrong recommendations
    • The message: technology can move fast, but accountability must not disappear.
  • Consequences when IT governance fails

    • Data breaches → major financial and reputational loss.
    • System errors → can harm people if flawed systems are trusted.
    • Core warning: don’t assume “digital” means correct:
      • fast but wrong
      • automated but biased
      • integrated but improperly controlled
      • efficient but insecure
  • IT governance enables safe innovation

    • Example: a bank launching digital banking needs not just an app but governance across:
      • cyber security controls, customer data protection, transaction monitoring, backups, internal audit, regulatory compliance.
    • Result: innovation + controls + reliability.
  • Relevance to Indonesia

    • Banks, public institutions, state-owned enterprises, universities, and digital businesses all depend on technology.
    • Governance frameworks (e.g., COBIT) must be adapted to local regulations, culture, and organizational structure.
    • Don’t just copy frameworks—apply them wisely.
  • How governance, risk, and compliance connect (3-part relationship)

    • Governance answers: “Who is responsible?”
    • Risk management answers: “What could go wrong?”
    • Compliance answers: “What rules must be followed?”
    • These must work together; missing one creates vulnerability.
    • Example (online payments): governance defines system ownership, risk management identifies fraud/downtime/breach risks, compliance ensures regulatory/policy adherence.
  • Why IT weaknesses become accounting/audit weaknesses

    • Examples explicitly linked to accounting controls:
      • Weak access control → unauthorized transaction entry
      • Weak segregation of duties → one person can create vendors and approve payments
      • Weak change control → updates affect revenue recognition or inventory valuation
      • Weak backups → possible accounting data loss
    • These are audit/accounting problems, not only IT problems.
  • Role of auditors

    • Auditors focus on IT General Controls (ITGC) to provide independent assurance.
    • Internal/external auditors test whether:
      • access is reviewed regularly
      • system changes are approved
      • backups were tested
      • audit trails are complete
    • Without audit, governance may exist only “on paper”; audit makes it accountable.
  • Implications for modern accountants

    • Accountants aren’t just record keepers—they must understand IT reliability because accounting information flows from ERP, databases, cloud, dashboards, and automated workflows.
    • They should understand:
      • controls, risks, access rights, audit trails, system reports, data quality
    • They can act as a bridge between business and IT:
      • translate technical proposals into control/risk/value/accountability questions (e.g., cloud migration cost/risk/data protection/audit evidence impact on reporting).
  • Career opportunities linked to IT governance

    • ERP/systems implementation roles
    • IT auditor evaluating IT controls and system risk
    • Finance/controller overseeing digital transformation
    • GRC advisor supporting governance-risk-compliance management

Methodology / structured instructions (detailed bullet points)

A) IT governance definition: the “3 questions”

  • Who decides?
    • Example: who approves a new accounting system
  • Who is accountable?
    • Example: who is responsible if the system fails
  • How do we measure success?
    • Examples: faster, more secure, more accurate, more useful for decision-making

B) Five focus areas of IT governance (framework applied)

  • Strategic alignment
    • Ensure IT supports organizational goals
  • Value delivery
    • Ensure IT produces benefits, not only costs
  • Risk management
    • Identify and control IT risks
  • Resource management
    • Use people, systems, data, and budgets effectively
  • Performance measurement
    • Monitor whether IT is working well (e.g., errors, delays, uptime)

C) ISO/IEC 38500 “EDM” model (board-level governance)

  • Evaluate
    • Assess whether technology is needed
    • Assess investment value
    • Assess risks
  • Direct
    • Set priorities
    • Set policies
    • Assign responsibilities
    • Define boundaries
  • Monitor
    • Check performance
    • Check compliance
    • Review incidents
    • Review outcomes

D) COBIT 2019 (governance vs management + control-oriented questions)

  • Governance
    • Evaluate, direct, monitor
  • Management
    • Plan, build, run, monitor IT activities
  • Control objectives examples for ERP
    • Access rights properly approved?
    • System changes documented?
    • Backups tested?
    • Incidents followed up?
    • IT risks reported to management?

E) ITIL (operational service management when systems fail)

  • Incident management
    • Handle breakdown quickly
  • Problem management
    • Fix root cause
  • Change management
    • Prevent updates from creating new problems

F) Governance vs Risk vs Compliance (how they must work together)

  • Governance
    • Define “who is responsible” (ownership/accountability)
  • Risk management
    • Identify “what could go wrong” (fraud, downtime, data breach)
  • Compliance
    • Ensure “what rules must be followed” (regulations and internal policies)

Speakers / sources featured

  • Gunawan Biswono (speaker; also referred to as “Gungu”)

Frameworks/standards used as sources

  • ISO/IEC 38500
  • COBIT 2019
  • ITIL

Mentioned stakeholder groups (as featured roles)

  • Board/top management
  • IT department
  • Finance, accounting, audit, operations
  • Internal auditors and external auditors
  • Auditors / audit committee (roles referenced)

Original video