Paul Bulpitt, head of accounting at Xero, chair a panel of digital experts on the current trends in technology and what professional should look for in terms of opportunities and risks. The panel discussion took place in the course of The Accountant & International Accounting Bulletin 2016 conference held in London in October.


Chair: Paul Bulpitt, head of accounting, Xero

Access deeper industry intelligence

Experience unmatched clarity with a single platform that combines unique data, AI, and human expertise.

Find out more

Participants:

Hermann Sidhu, EY Global assurance digital leader
Omar El Sabh, digital marketing manager, RSM Egypt
Dave Clemente, manager – cyber risk research, Deloitte UK
Faye Chua, head of business insights, ACCA


Paul Bulpitt: Let me start the Q&A turning to Hermann, our first speaker. It’s really interesting to see to what degree EY has embraced digital, and that digital isn’t just a department on the side, but infuses everything. In terms of the audience we’ve got here today, what are the three things that you think they should be doing to maximise their digital opportunity?

Hermann Sidhu: From my perspective, it has to be pervasive, it has to be everything you do. And I go back to to my definition of how you drive innovation. I started with the incremental bit, which actually I think is the most important piece of it. We can all make bets on destructive stuff that’s coming down the pipeline, but actually it’s what is happening day to day, identifying those bubbles of opportunity where you can automate, where you can streamline, where you can do it better.

I think the days of big-scale top-down driven, big investment projects are probably winding down. Looking at collaboration, how do we collaborate with our alliance  partners? How do we collaborate within our firm? So I think it goes for everybody in the room. Identify those bubbles of opportunities and then raise your hand to blow them up in the enterprise.

Bulpitt:  How much of the audit process can we realistically automate?

Sidhu: When I think of an audit, what are our clients paying us for? They’re paying us for using our judgement and interpreting the grey, dealing with really complex issues. Is that going to be automated? In today’s technology, it’s not. So I try to break the audit down, if you think of the audit of our client’s routine practices. It’s highly important and it’s a liable part of the audit. Can you streamline that out? Can you automate more? I think you have real opportunities even with today’s technology. Then you contrast that with the really complex, really judgmental bits of the audit where the high level of judgement and skills are required. I don’t see it quite yet today but, obviously, with future technology, with AI etc, you can see a movement in those areas.

So I try to bifurcate between the routine and the complex parts of the audit. If it’s compliance, check the box. Routine, yes, there are opportunities to streamline it, but that’s what we want to do, right? We want to automate those so we can focus people’s time, energy and effort on the high-risk, high-judgement areas. And that’s what our people want to do. So we’d be hugely sort of promoting that.

Bulpitt: So the bit that only humans can do.

Hermann Sidhu: Absolutely.

Bulpitt: That’s interesting. Were there any questions from any of our audience for Hermann?

Unidentified Speaker: The question I have is quite a compelling one, because you mentioned that, essentially, there are certain parts where humans are needed – judgmental areas, complex areas, seeing through the grey. but in terms of getting that level of competence, that experience, that judgement, that all come with time, comes with training, comes with experience. If you’ve got a computer doing that, how is that going to flow through to the next generation and how does that really work?

Sidhu: I think that’s a fantastic question. And I think it’s a compelling question. We’re talking about automation, robotics, today, but it was the same question when the firms started to decentralise. And every one of the Big Four, if you look at them today, you’ll see a lot of routine processing happening in an offshore lower-cost jurisdiction. Then the question comes in: if I’m not going to train my staff to do cash confirmations then how am are they going to know how to do revenue? That’s how we all learn.

I think that is a very compelling question and I think we have to address that. And the way I envision it is our staff are going to have better utilities that makes it a lot easier. If you look at what they’re doing today to all those processes, a lot of those are what I’d call data manipulation, data gathering, moving stuff from one part of a file to another, etc. We want to automate those aspects of it while, at the same time, still want the staff to understand there is an inherent risk in those lower area processes. We want them to understand those inherent risks and how you mitigate and how you design audit programmes against any of these risks. It’s no different than 25 years ago: imagine a world with no Excel. Excel didn’t all of a sudden eliminate jobs for us. It just made it more seamless.

Bulpitt: Let’s turn to Omar who spoke about social media. You talked about a lot of platformes: Instagram, Twitter, Snapchat. But what practical advice can you give people? Where can they begin?

El Sabh: On social media for accountants?

Bulpitt: Yes.

El Sabh: Well, if you’re an individual accountant who’s working from home, you have to be on social media to monitor a conversation. If you’re not on LinkedIn, you need to get on LinkedIn to follow groups and monitor discussions. This conference here is bringing together all of these brains in one place but this is also happening online. So it’s important to be there as an individual.

But as an organisation I think back home in Egypt, LinkedIn is not the best platform to be on. With LinkedIn you can reach a lot of professionals, in terms of recruitment, or lead generation, or awareness, but also back home we don’t really use LinkedIn because the pool of people on LinkedIn is not really huge. But if I was working here, I would definitely recommend LinkedIn. Facebook is also a great way to target people. Advertising-wise the Facebook platform is really strong. You can target the professionals. You can also target industries. You can target interests.

So you can target and you can go onward into different fields. That depends on how good your targeting is and how good your digital marketer is. People start their journey on Facebook and they end up on your website. I recommend mostly these two.

Bulpitt: So one of the interesting points that you made was about how social media can be applied in the business. There’s a learning opportunity. There’s a massive recruitment opportunity. I know loads of accounting firms recruit through LinkedIn. In terms of accounting firms or accountants, how can you quantify the amount of time that should be spent each day, week or  month? How much budget should you allocate to social media?

El Sabh: Budget-wise, not really – CISCO won, I think 2012, an award for best performing company for the rollout of a product and they saved about $100,000 in the rollout. So I don’t know what that translates into budget, actually, but that is the cost – the cost of social media is definitely less than traditional advertising. But the other thing is, there was also a really interesting survey by a social media examiner, one of the best social media polling websites out there. And they polled about 30,000 professionals in different industries asking them how much time they spent on social media? Do you see any increase in marketing? And almost 70% responded with a yes, and that if you have a team that spends about six hours a week monitoring, optimising, and creating advertising on different platforms, you can see the concrete ROI. But again, these numbers are tentative and it depends on the organisation, how well they’re creating and putting their team in place.

Bulpitt: Were there any questions?

Unidentified Speaker: You mentioned in your presentation a little bit about keeping control of staff when they’re out there in the wild west of social media. Can you talk a little bit about how you could actually do that? It’s a very delicate matter, right, reaching into the personal side of employees.

El Sabh: First of all, I’m not a fan of having anyone access pages or accounts. To engage in social media, organisations need to have a team. That team is in charge and that’s it. But if you do leave it up to your accountants or employees, to sort of go in and respond or monitor or whatnot, I think it’s important to say there are guidelines of what not to say or what to say. And that obviously differ from one organisations to the next.

Bulpitt: Moving onto Dave. Some of us here would have been involved in, or affected by, the recent Yahoo! debacle. Approximately 500m accounts were hacked and if I remember right they kind of hid it for a couple of years.

Dave Clemente: Well, they weren’t even aware of it for a couple of years. I’m not sure which is worse. And this is perhaps more common than you would think. There was research done late last year by a reputable organisation. They looked at the number of data breaches that had happened over the last couple of years and, on average, it’s about 185 to 190 days that pass between the time when the initial incident takes place, when the hackers get into a company’s network, and the time when the team discovers it, by which time your data has all been sold so many times it’s no longer valuable and creates knock-on problems in a variety of ways.

I’m not going to ask for a show of hands about how many people reuse passwords but if I were to compromise your LinkedIn account, how many other accounts could I also get into using the password or very small variations thereof? And the answer is too many. So this is a real challenge, especially when perhaps we use the same password for our work laptop as we do for personal things as well.

The main challenge I see for organisations is putting this into its proper contex.And the tendency is to oscillate between two extremes. On one extreme you have big headlines about data breaches taking place and the senior manager and exec will read that and think, ‘Oh my God, what if that happens to us?’ And then the other extreme is waiting until something bad like that happens to actually do anything. So you have long, perhaps prolonged, inaction on one hand, and then when something bad happens to your competitor then there’s a flurry of activity and perhaps an overreaction. Here’s X amount of resources to go fix a problem, make it go away.

So somewhere in the middle there’s a sensible risk management, or risk assessment process, that needs to happen that in many cases doesn’t happen because the problem appears too technical. And that’s only a small component. There’s a whole risk and governance process that would be familiar to many in the room that has nothing to do with ones and zeroes and malicious code. In many organisations, there’s a gap between the technical team and the senior management. The technical team might be saying:  here’s what this bad thing means in terms of this impact. But for the senior management it means nothing or very little.

Bulpitt: Yes. How do we fix this? Because it’s a scary subject. The risk of reputational damage as much as anything is absolutely huge. How do we fix it? For the organisations in this room and our clients, where do we go?

Clemente: We probably start by having a plan for when things go wrong because, in any medium to large organisation, you will suffer an incident at some point eventually. Whether it’s headquarters or some subsidiary, some affiliate halfway around the globe, something will happen and there needs to be some sort of crisis management process in place to deal with that. And more and more often we’re seeing legal teams start to get involved in this process to advise when legal and regulatory considerations will kick in on things they may have to think about.

Some of the internet response process can be done under legal privilege, meaning that they may be able to notify the regulator slightly later than would otherwise have been possible. And then there’s some technical considerations as well. The regulators are starting to look – and they’re making a distinction between the data breach that happens to information that’s not encrypted and information that is encrypted. They’re saying, if the information was encrypted to these particular conditions, then you actually don’t need to notify the individuals whose data was lost because it’s encrypted strongly enough that there’s no expectation that it’s going to be accessed any time this century. On the other hand, if it’s not encrypted, then things really start to hit the fan and it gets messy. So there are some technical considerations, but a lot more of this is starting to sit in the classical assessment framework than companies may otherwise imagine.

Bulpitt: Fascinating. Were there any questions?

Unidentified Speaker: I have a question in respect to the third party security that you mentioned earlier. I’m just wondering if it’s actually recommended. We, for example, in my company have an IT team – we are actually protected. However, going to the bank, they actually recommended I download another software in order to protect me even further. Would you actually recommend that?

Clemente: On an individual level, it would be advisable to have some sort of security software on your computer just at least to have the ability to scan for the kind of things, the webpages that you’re searching, and documents you’re downloading. Some of this would come as part of this package that your bank would encourage you to download and often offer it for free. So it’s better than nothing, yes.

Bulpitt: Faye spoke of the seven key quotients in your presentation. In your opinion, which is the most important?

Faye Chua: Oh, gosh. That’s a very difficult question. Like I said, there isn’t one that we have priorities over. We as individuals need to think, what role are we in? What role are we playing? Where do priorities need to lie? But I think, at the core of it, it’s still our technical and in the future it will be much more  our ethics. Because I think society expects  an ethical way of doing business. And who has probably the most ethical background in a company? Probably us as professional accountants.

So in terms of which has a priority, I can’t really tell. It really will depend on what role the person is in and with which industry that person is working with. But then there needs to be a balance of all those seven qualities that we’re looking for.

Bulpitt: And obviously some of them like the technical quotients is well established and organisations like yours have been dealing with it for a while. But others like the digital quotient, this is relatively new. Are the younger generation at a massive advantage here?

Chua: Well, they do and they don’t. I think we also have experience – as for the youth, the youth will probably be more agile in terms of the way they play with apps. It’s easier for them. For us, it’s experience, right? When we sign up for Facebook, you may realise that you’re actually sending those right to Facebook and you can now never take them back. Have we actually read the fine print? And I think through our experience and our scepticism, which we built through experience, we can actually share. So there could be a reverse mentoring and sharing of knowledge and experiences.