Video summary
Special Topics in Accounting: IT Governance
Main summary
Key takeaways
Main ideas / lessons
-
IT governance is essential for reliable financial reporting
- In digital organizations, it’s not enough to ask whether financial statement numbers are correct—organizations must also ensure the systems producing the numbers are reliable.
- A weak system can lead to weak reports; therefore, IT governance connects technology execution to business/accounting needs.
-
IT governance acts like a “bridge” between strategy and technology
- One side: business goals (strategy).
- Other side: technology decisions and execution.
- Without governance, technology investments become expensive but directionless (e.g., buying ERP/cloud/AI without clear priorities, access control, risk checks, or measuring whether the investment works).
-
IT is a strategic asset, not just a support function
- Historically, IT focused on fixing computers and maintaining servers.
- Today, IT enables competitive advantage (e.g., mobile banking, digital learning platforms, online transactions).
- Strategic assets must be governed, and decisions should not be left only to IT—finance/accounting/audit/operations and top management must be involved.
-
Governance improvements determine outcomes even with the same tools
- If two companies implement the “same” ERP:
- The one that only installs it benefits less.
- The one that also defines access control, reporting needs, approval workflows, data ownership, and audit trails benefits more.
- The difference is governance, not software.
- If two companies implement the “same” ERP:
-
Why IT governance became prominent
- Major scandals and stricter regulations increased focus because:
- Financial reporting depends on information systems.
- Weak access rights can enable manipulation.
- Poor change control can cause errors.
- Inadequate data protection can cause leaks.
- Regulators and boards treat IT as part of corporate governance.
- Major scandals and stricter regulations increased focus because:
-
IT governance definition and accountability
- IT governance answers:
- Who decides? (e.g., who approves new accounting systems)
- Who is accountable? (e.g., who is responsible if the system fails)
- How do we measure success? (speed, security, accuracy, usefulness)
- It’s framed as an accountability topic, not only technical.
- IT governance answers:
-
Five focus areas of IT governance (explained)
- Strategic alignment: IT supports organizational goals.
- Value delivery: IT delivers benefits, not only costs.
- Risk management: identify/control IT risks.
- Resource management: use people, systems, data, budgets effectively.
- Performance measurement: monitor whether IT is working well.
-
Key examples illustrating the focus areas
- Hospital billing system
- Alignment: better patient service
- Value: faster/more accurate billing
- Risk: protect patient and payment data
- Resources: staff training
- Performance: track errors, delays, downtime
- Hospital billing system
-
Standards/frameworks used for IT governance
-
ISO/IEC 38500 (board-level model)
- Uses EDM: Evaluate, Direct, Monitor
- Evaluate: Is technology needed? Worth investment? Risks?
- Direct: priorities, policies, responsibilities, boundaries
- Monitor: performance, compliance, incidents, outcomes
- Example given for AI in accounting:
- Beyond “is it sophisticated?”—ask about data security, verifiability, responsibility for wrong outputs, policy compliance.
- Uses EDM: Evaluate, Direct, Monitor
-
COBIT 2019 (management/control level)
- Translates governance into control objectives.
- Separates governance from management:
- Governance: evaluate, direct, monitor
- Management: plan/build/run/monitor IT activities
- Examples tied to ERP:
- Are access rights properly approved?
- Are system changes documented?
- Are backups tested?
- Are incidents followed up?
- Are IT risks reported to management?
-
ITIL (operations/service management level)
- Focuses on reliable day-to-day service management:
- Incident management (handle failures quickly)
- Problem management (fix root cause)
- Change management (prevent new issues after updates)
- Example: accounting system downtime two days before reporting deadline impacts closing/reporting/audit/decisions.
- Focuses on reliable day-to-day service management:
-
-
Digital transformation requires governance
- Cloud, AI dashboards, mobile apps, automation, big data can improve capability.
- Without governance, transformations become risky, e.g.:
- Cloud: access control, data location, backups, vendor failure handling
- AI: explainability, reliance, bias/wrong recommendations
- The message: technology can move fast, but accountability must not disappear.
-
Consequences when IT governance fails
- Data breaches → major financial and reputational loss.
- System errors → can harm people if flawed systems are trusted.
- Core warning: don’t assume “digital” means correct:
- fast but wrong
- automated but biased
- integrated but improperly controlled
- efficient but insecure
-
IT governance enables safe innovation
- Example: a bank launching digital banking needs not just an app but governance across:
- cyber security controls, customer data protection, transaction monitoring, backups, internal audit, regulatory compliance.
- Result: innovation + controls + reliability.
- Example: a bank launching digital banking needs not just an app but governance across:
-
Relevance to Indonesia
- Banks, public institutions, state-owned enterprises, universities, and digital businesses all depend on technology.
- Governance frameworks (e.g., COBIT) must be adapted to local regulations, culture, and organizational structure.
- Don’t just copy frameworks—apply them wisely.
-
How governance, risk, and compliance connect (3-part relationship)
- Governance answers: “Who is responsible?”
- Risk management answers: “What could go wrong?”
- Compliance answers: “What rules must be followed?”
- These must work together; missing one creates vulnerability.
- Example (online payments): governance defines system ownership, risk management identifies fraud/downtime/breach risks, compliance ensures regulatory/policy adherence.
-
Why IT weaknesses become accounting/audit weaknesses
- Examples explicitly linked to accounting controls:
- Weak access control → unauthorized transaction entry
- Weak segregation of duties → one person can create vendors and approve payments
- Weak change control → updates affect revenue recognition or inventory valuation
- Weak backups → possible accounting data loss
- These are audit/accounting problems, not only IT problems.
- Examples explicitly linked to accounting controls:
-
Role of auditors
- Auditors focus on IT General Controls (ITGC) to provide independent assurance.
- Internal/external auditors test whether:
- access is reviewed regularly
- system changes are approved
- backups were tested
- audit trails are complete
- Without audit, governance may exist only “on paper”; audit makes it accountable.
-
Implications for modern accountants
- Accountants aren’t just record keepers—they must understand IT reliability because accounting information flows from ERP, databases, cloud, dashboards, and automated workflows.
- They should understand:
- controls, risks, access rights, audit trails, system reports, data quality
- They can act as a bridge between business and IT:
- translate technical proposals into control/risk/value/accountability questions (e.g., cloud migration cost/risk/data protection/audit evidence impact on reporting).
-
Career opportunities linked to IT governance
- ERP/systems implementation roles
- IT auditor evaluating IT controls and system risk
- Finance/controller overseeing digital transformation
- GRC advisor supporting governance-risk-compliance management
Methodology / structured instructions (detailed bullet points)
A) IT governance definition: the “3 questions”
- Who decides?
- Example: who approves a new accounting system
- Who is accountable?
- Example: who is responsible if the system fails
- How do we measure success?
- Examples: faster, more secure, more accurate, more useful for decision-making
B) Five focus areas of IT governance (framework applied)
- Strategic alignment
- Ensure IT supports organizational goals
- Value delivery
- Ensure IT produces benefits, not only costs
- Risk management
- Identify and control IT risks
- Resource management
- Use people, systems, data, and budgets effectively
- Performance measurement
- Monitor whether IT is working well (e.g., errors, delays, uptime)
C) ISO/IEC 38500 “EDM” model (board-level governance)
- Evaluate
- Assess whether technology is needed
- Assess investment value
- Assess risks
- Direct
- Set priorities
- Set policies
- Assign responsibilities
- Define boundaries
- Monitor
- Check performance
- Check compliance
- Review incidents
- Review outcomes
D) COBIT 2019 (governance vs management + control-oriented questions)
- Governance
- Evaluate, direct, monitor
- Management
- Plan, build, run, monitor IT activities
- Control objectives examples for ERP
- Access rights properly approved?
- System changes documented?
- Backups tested?
- Incidents followed up?
- IT risks reported to management?
E) ITIL (operational service management when systems fail)
- Incident management
- Handle breakdown quickly
- Problem management
- Fix root cause
- Change management
- Prevent updates from creating new problems
F) Governance vs Risk vs Compliance (how they must work together)
- Governance
- Define “who is responsible” (ownership/accountability)
- Risk management
- Identify “what could go wrong” (fraud, downtime, data breach)
- Compliance
- Ensure “what rules must be followed” (regulations and internal policies)
Speakers / sources featured
- Gunawan Biswono (speaker; also referred to as “Gungu”)
Frameworks/standards used as sources
- ISO/IEC 38500
- COBIT 2019
- ITIL
Mentioned stakeholder groups (as featured roles)
- Board/top management
- IT department
- Finance, accounting, audit, operations
- Internal auditors and external auditors
- Auditors / audit committee (roles referenced)