Controls Maturity — Assessing and Improving Your Controls Program - ZServiceDesk Blog

Controls Maturity — Assessing and Improving Your Controls Program

Are You Doing Controls or Just Going Through the Motions? — The Controls Maturity Model The Maturity Model Controls maturity describes how advanced your controls management practice is. Maturity Levels Level 1: Initial/Ad-Hoc Characteristics: Controls exist but are not documented Ad-hoc implementation Inconsistent execution No ownership Reactive Signs you're at Level 1: Controls are not documented No formal control testing No evidence of operation Level 2: Repeatable Characteristics: Basic documentation Inconsistent execution Emerging ownership Some testing Signs you're at Level 2: Controls are documented Some control testing Some evidence collection Level 3: Defined Characteristics: Standardized controls Documented processes Clear ownership Regular testing Signs you're at Level 3: Controls are consistently documented Formal testing schedule Clear ownership Level 4: Managed Characteristics: Performance measured Proactive improvement Continuous monitoring Integration with other processes Signs you're at Level 4: Control metrics tracked Continuous monitoring Evidence is automated Level 5: Optimizing Characteristics: Continuous improvement AI-driven controls Predictive analytics Fully integrated controls Self-healing controls Signs you're at Level 5: AI for controls monitoring Automated remediation Always audit-ready Maturity Assessment Questions Area Question Documentation Are controls documented? Ownership Is ownership assigned? Testing Are controls tested regularly? Monitoring Are controls monitored continuously? Evidence Is evidence collected automatically? Automation Are controls automated? Building a Roadmap Level 1 → Level 2: Document controls Assign ownership Implement basic testing Level 2 → Level 3: Standardize processes Formalize testing schedule Establish evidence collection Level 3 → Level 4: Implement continuous monitoring Track metrics Integrate with other processes Level 4 → Level 5: Implement AI-driven controls Enable automated remediation Achieve continuous improvement Conclusion Controls maturity is a journey. Organizations that assess their maturity and build a roadmap for improvement will achieve more effective controls, better risk management, and audit readiness. Action Items for Your Organization Assess your current controls maturity Identify gaps Build a roadmap to the next level Measure progress Celebrate improvements
Read More 14 Oct 2023
Measuring Change Success — From Activity Metrics to Impact Metrics - ZServiceDesk Blog

Measuring Change Success — From Activity Metrics to Impact Metrics

Measuring Change Adoption Without Measuring Impact Is a Trap The Measurement Problem Traditional change management metrics focus on activity: training completion, licenses issued, adoption rates. But these don't show whether change is delivering value. Activity vs. Impact Activity Metrics Impact Metrics Training completion Behaviour change Licenses issued Active usage Communications sent Message retention Survey participation Sentiment change Adoption rates Business outcomes What to Measure 1. Awareness Are employees aware of the change? Communication engagement Survey awareness scores Message retention  2. Preparedness Are employees prepared to adopt the change? Training participation Training effectiveness Help desk metrics (tickets, escalations)  3. Adoption Are employees using the new tools or processes? Usage and utilization reports Compliance and adherence reports Behavioral observations  4. Impact Is the change delivering business value? Benefit realization ROI Quality metrics Customer satisfaction The Outside-In Mindset Otto recommends a change manager focuses on two outside-in outputs : Awareness: Measuring if employees understand the change Preparedness: Measuring if employees have the knowledge and ability to make the change and sustain it Measuring Performance Zendesk's Dana Otto recommends the following approach: 1. Focus on Two Main Outputs: Awareness and Preparedness Make sure employees understand the change and have the tools to adopt it. 2. Quantify Qualitative Data Frame qualitative questions in employee surveys on a scale to quantify responses. "Measuring change management is one of the most difficult parts of the process because you're measuring people and their emotions, which is hard to quantify" . 3. Ask Managers to Hold Teams Accountable A major component of measuring change is assessing if people are doing their part to meet project goals . 4. Measure if the Business Is Prepared Evaluate if the business is ready to move from its current state to the desired future state . 5. Leverage Technology to Track Communications Use tools to track if communications are impactful . 6. Incorporate Feedback Early On Foster a feedback loop between impacted groups and business leaders early on . 7. Measure if the Change Stuck Continue measuring to see if people continue to incorporate the change over time . Conclusion Measuring change success requires moving beyond activity metrics to impact metrics. By focusing on awareness, preparedness, adoption, and impact, organizations can understand whether change is actually working. Action Items for Your Organization Define success metrics for your change initiative Measure awareness and preparedness Track adoption over time Measure business impact Use outside-in metrics (employee perspective) Continue measuring after rollout
Read More 05 Sep 2023
Fourth-Party Risk Management — Beyond the Direct Vendor - ZServiceDesk Blog

Fourth-Party Risk Management — Beyond the Direct Vendor

Your Vendor's Vendors Are Your Risk — Managing Fourth-Party Exposure The Fourth-Party Risk Reality Sub-tier vendor activities, known as fourth-party or nth-party risks, are harder to monitor without adequate technological interventions . A vendor's security practices may be sound, but their subcontractors may introduce significant vulnerabilities. The critical point: Understanding inter- and intra-dependent activities (including those of the subcontractors or sub-processors) is a significant facet of the vendor supply chain . Why Fourth-Party Risk Matters Hidden vulnerabilities: A vendor's subcontractor may have poor security practices that expose your data. Supply chain disruption: If a subcontractor fails, the vendor may fail, cascading to your organization. Regulatory expectations: Banks evaluate not only direct vendors but also their suppliers to ensure supply-chain transparency . Lack of visibility: Fourth-party risks are invisible without active investigation. Examples of Fourth-Party Risk Cloud service provider: Your vendor uses a cloud provider that suffers a breach affecting your data. Subcontractor: Your vendor outsources development to a subcontractor with poor security practices. Supplier: Your vendor's supplier faces financial instability, disrupting your vendor's operations. Managing Fourth-Party Risk 1. Require Vendor Visibility Contractually require vendors to disclose: Subcontractors and sub-processors Key suppliers Dependencies Security practices 2. Assess Fourth Parties Extend risk assessment to critical subcontractors: Security practices Compliance history Financial health Reputational risk 3. Monitor Continuously Use technology to monitor fourth-party risk: Security rating services Threat intelligence Automated scanning 4. Incorporate into Contractual Requirements Define requirements for:
Read More 26 Jul 2023
Building Trust During Change — The Catalyst for Sustainable Adoption - ZServiceDesk Blog

Building Trust During Change — The Catalyst for Sustainable Adoption

Headline: Trust Creates "Change Stickiness" — Without It, Even the Best Change Programs Stall The Trust Imperative Trust creates "change stickiness." Without trust, even the best-designed programs stall because people hesitate to adopt what they don't believe in . In low-trust environments: Teams second-guess decisions Execution slows down Employees turn to workarounds Change efforts fail In high-trust change cultures: Teams move faster They take smart risks They collaborate more freely They become more resilient, productive, and engaged  The Four Factors of Trust When leaders "open the curtain" and make trust intentional, it becomes a true differentiator. That intention comes to life through four essential factors : 1. Humanity Meaning: Showing people they're seen and valued by clearly articulating how change benefits them individually. Application: Personalized communications, empathy in leadership, genuine care for employee wellbeing. 2. Transparency Meaning: Being open about the "why," the trade-offs, and the progress of change—explaining not just what's happening but how decisions are made. Application: Clear communication about timelines, challenges, and progress. Regular updates and honest conversations. 3. Capability Meaning: Demonstrating competence—launching tools and systems only when they've been tested and employees are equipped to use them. Application: Thorough testing before launch, adequate training and support, evidence of competence. 4. Reliability Meaning: Following through—doing what you said you would so employees learn the organization delivers on its promises. Application: Meeting commitments, delivering on promises, consistent follow-through. The Business Case for Trust When Deloitte launched its internal GenAI assistant in 2023, adoption surged—then dropped. Using a trust-based analytics methodology, Deloitte identified transparency and reliability gaps that were eroding confidence. By running controlled experiments and improving trust-building efforts, they achieved : Metric Improvement Trust scores +16% Perceived reliability +49% Perceived transparency +52% New users +14% Repeat users +13% Sessions per user +65% Trust and AI Trust is especially critical with AI, where the technology itself is often misunderstood or mistrusted. Nearly half (43%) of employees turn to "shadow AI"—unapproved tools outside the organization's guardrails—creating new risks even as official adoption stalls . By contrast, employees who trust their organization's AI solutions are 2.8 times more likely to use GenAI daily and gain back more than two hours each week . Conclusion Trust is not merely a facilitator of change; it is the catalyst that drives sustainable growth and innovation across the enterprise . Organizations should invest time in thoughtfully identifying what matters most in each context—for some workers, it may be clear communication of benefits; for others, visible leadership follow-through. Action Items for Your Organization Assess trust levels in your organization Identify trust gaps in current change initiatives Build trust through humanity, transparency, capability, and reliability Address trust as a measurable factor in change Invest in trust-building specifically for AI change
Read More 22 May 2023
Follow-up and Issue Tracking — Confirming Management Action - ZServiceDesk Blog

Follow-up and Issue Tracking — Confirming Management Action

Audits Are Only as Good as Their Follow-up — A Guide to Effective Issue Tracking The Follow-up Standard Standard 15.2 requires internal audit functions to confirm whether management has implemented action plans and, when they have not, to follow the CAE's established guidelines for management acceptance of risk . The Follow-up Challenge Follow-up processes are often less structured than planning or testing phases. Many offices rely heavily on email and phone communication and lack standardized tools for tracking status updates . Common problems: Auditors feel the follow-up process is treated like an afterthought Delays in management action plan completion Clients do not provide explanations or updated timelines Balancing accountability with maintaining positive client relationships Determining what constitutes sufficient verification Strategies for Effective Follow-up 1. Evidence-Based Approach Transition from "trust but don't verify" cultures to more evidence-based follow-up procedures . 2. Include Follow-up in the Audit Plan Include follow-up activities directly in the audit plan to signal their importance to leadership and audit committees . 3. Use Standard Templates Develop standard templates for documenting action plan status updates . 4. Establish Regular Cadences Establish regular follow-up cadences, such as every 90-120 days . 5. Conduct Interim Check-Ins Conduct interim check-ins rather than waiting for due dates, which has improved implementation rates . 6. Prioritize High-Risk Findings Use prioritization methodologies to identify high-risk findings that require closer monitoring or escalation . 7. Require Written Justifications Require written justifications for non-implementation or use standard forms for documenting risk acceptance . 8. Use Dashboards Report overdue action plans to leadership using dashboards and visualizations . 9. Escalate to Leadership Require clients to present their rationale for non-implementation directly to the audit committee . Determining Verification Sufficiency Determining what constitutes sufficient verification—especially when deciding between retesting and reviewing client-provided evidence—remains a challenge . Guidelines: Low-risk findings: Client-provided evidence may suffice High-risk findings: Independent verification (retesting) may be warranted Document the rationale for verification approach Action Plan Development During reporting, auditors should : Have the client determine the specific action plan (with internal audit approval) to mitigate each finding rather than prescribing action plans they may not fully understand Define what "implemented" will look like for each action plan Explain how non-responsiveness may be escalated Conclusion Follow-up is essential for audit effectiveness. Organizations that implement structured follow-up processes will achieve better action plan implementation and stronger control environments. Action Items for Your Organization Document your follow-up methodology Create standard templates for status updates Establish regular follow-up cadences Develop escalation procedures Report follow-up status to leadership Verify action plan implementation
Read More 19 Apr 2023
Problem Management Metrics — What to Measure and Why - ZServiceDesk Blog

Problem Management Metrics — What to Measure and Why

You Can't Improve What You Don't Measure — The Key Metrics for Problem Management Success Why Measurement Matters Measuring problem management effectiveness helps organizations: Identify areas for improvement Demonstrate the value of problem management Make data-driven decisions Track progress over time Key Metrics Process Effectiveness Metrics Metric Purpose Total number of problems, by priority Control measure for level of problems. The change in level over time can be considered both positive and negative  % of problems with workaround defined Measure the effectiveness of problem management in defining and communicating workarounds  % of problems with a root cause identified Measure the effectiveness of problem management in defining root cause  Mean time to first respond to problems Measure of how well response SLAs are achieved  Average time to determine root cause This is about identifying and not resolving root cause as this could take a considerable time  Outcome Metrics Metric Purpose % of problems that recur Measure of recurring problems that have a business impact  Number of incidents related to closed (or open) problems Indication of how much problem management reduces disruption. Indicator of avoided outages  % of incidents resolved by fixing known errors Measures the effectiveness of problem management in supporting the timely resolution of incidents  Why Speed of Resolution Shouldn't Be a Metric With problem management, the purpose is to understand the underlying cause of issues and permanently fix them no matter how long that takes or if it is even possible. Therefore, in problem management speed of resolution is not something that should be measured. This would drive the wrong behavior for the process and focus on closing records rather than finding the permanent fix. Process Owners need to feel comfortable with problem records potentially remaining open for months or even years . Direct and Indirect ROI Direct ROI: Reduction in incident solving costs Savings on SLA breach penalties Reduced higher-level support involvement Indirect ROI: Improved service quality leading to higher employee satisfaction Reduced risk of incidents impacting the business  Measuring Success Track metrics as trend lines over time, not snapshots  Monitored by the Process Owner  Use data for improvement - identify areas for investment Demonstrate value - show the ROI of problem management Conclusion Effective measurement is essential for problem management success. By tracking the right metrics and using them to drive improvement, organizations can reduce incident volume, improve service quality, and demonstrate the value of problem management. Action Items for Your Organization Define your problem management metrics Set up measurement and reporting Establish baseline measurements Review metrics regularly Use data to drive improvement
Read More 27 Oct 2022