EY gets banned from new audit business in Germany
economist.com
economist.com
Since going out on my own as a consultant – focused on the same sort of growth programs, as opposed to audit – I generally find that I can achieve the same outcomes for a client with a handful of people on a a reasonable budget.
I left primarily because it's just bonkers how much pork these big consultancies manage to get away with packing on, to the point where it was a major reputation risk to me.
I'd encourage any CXOs out there seeking to outsource major strategic initiatives to consider hiring individuals or smaller entrepreneurs with experience inside the bigs, but without the downward pressure to get as many butts in seats as possible.
actually, brb
My only (personal) hope is that it’ll free guys like me up to soar through ‘creative configuration space’ and come up with those truly unique and unexpected tactics that are new to an entire segment or industry.
Sure I don’t get to be a millionaire MD with two hundred reports billing hourly, but maybe I can do value-based or outcome-based pricing and get my clientele to take ‘healthy’ risk - instead of sitting around fretting about shaving half a point off labor costs through a mindless re-org :/
Related anecdote: if you see someone on the airplane rejiggering a public company’s org chart - short the stock!
I'm pure strategy, most of my clients are 'intraprenurial' CIOs, CSOs, CFOs.
With software engineers some of the remaining 90% really are talented but spend most of the project learning on the job, fixing an issue in a few hours that a senior engineer in their stack could fix in 30 minutes with their arcane knowledge. Meanwhile the senior engineer goes to the scrums (they love to hide behind agile). It's a solid grift.
What's interesting about this article (and the general state of management consulting) is that the cracks are beginning to show in these big firms that used to have a "nobody got fired for hiring EY" reputation.
My client (typically an executive) can then take the presentation to his or her leadership team or board to unlock the funding required to stand up the 'execution' phase of that initiative internally through hiring.
So I guess you could say I build MVPs or proofs-of-concept that, if they work and are desirable to the company, get spun out into new lines of business.
Do you stick to a particular business domain? Eg finance, transportation, e-commerce? I’d think it would help you to build MVPs if you stayed in a specific domain, but it could be fun to move around a bit too :)
Also: how do you find clients? I feel like again this would come from having connections in a specific business domain? It feels like it should be hard to sell yourself as the “prototype person”, but how do you convince someone to let you prototype for them for a while?
2. Word of mouth primarily. When they look at what I cost them vs. what the big consultancies – or even the midsize 'innovation consultancies' like Frog or IDEO cost, it's a no-brainer. I just blend basic financial rigor with a bit of visionary thinking and competitive research, and set my clients up for the win when they go ask for permission to go from idea to prototype to MVP to pilot.
See: IBM's software engineering, vs Delta's offering of their maintenance ops to other airlines. One has really, really worked out, the other hasn't.
It is not for performance.
It's for minimizing risk.
And not "risk that the project will fail to hit its schedule." Rather "risk that the company is unable to deliver the thing we're asking for at all."
When I've seen big consultancies fail, it almost always goes like this: (1) big idea sold with A-team, (2) contract won and lowest-cost B-team substituted in, (3) B-team screws up execution, and customer usually figures out on or right before target delivery date, (4) if smart, customer tears consultancy a new asshole, from people with VP et al. titles, (5) if interested in further business then consultancy profusely apologies and puts an A-team back on the project, (6) A-team delivers, albeit after schedule.
The difference between ey et al. vs smaller shops is (4). Smaller shops don't have extra senior bodies laying around to retask.
So a more accurate description of a VP hiring ey is probably "I know they're going to screw it up, but I know if I bitch enough they'll eventually get it done right."
And when I say innovation I don’t mean gravity boots, I just mean a progressive use of robust tech, easily understood processes, and a general aversion to complexity - so you don’t have to do it all over again in five years.
OTOH executive retention is tanking, so maybe it’s fine you one-and-done it, and move on to your next job before the truth is out - YOLO! (Barf).
This brings back my PTSD. "I have never seen so many fine men wasted so badly"
There's no good outcome from a knock-down, drag-out fight for either party when it goes that badly.
And yeah... I've observed my fair share of "So, we all agree we're going to call this a success? Great!" + director / VP takes a new job before it explodes.
In my company, to hire a company like IBM or Accenture we have to propose a plan, which has to be approved by many layers of bureaucracy. This plan includes a budget. A real risk is that the consultant underdelivers, or we need more budget. Then we have the sunk cost problem, and we have a bureaucratic one as well to increase the budget. And the consultant already costs more than hiring on our own and doing it in house.
The other big risk is: 'Will _I_ get in trouble, if the project fails?'
This is the crux of it. GP described the process but not the reasoning. Consultancy come in to help management push a vision. One or two VPs may not be able to get their vision but if one of the big 4 supports them it will likely be easier to get buy in.
I work as a Client Partner for a $1B+ consulting firm that comes in and cleans up after these situations. We bring in seasoned, experienced consultants with the functional knowledge that these big consulting firms don’t have. And even though our consultants are more costly on a per head basis, we’re more cost effective overall, because we do more with less.
I always admired the big consulting firms until I realized how consistently they fail to deliver. It’s hard for the clients to fix it because they genuinely think they are getting the best. It’s sad and laughable. Eventually they figure it out. Usually when a firm like us comes in and exposes the dysfunction by getting a few consultants in there that know what they are doing and running things like it should. And it generally comes down to a lack of leadership— by both the client and the big consulting firm. They point the finger at each other. But also it’s just a lack of experience by those running/implementing the program. Staffed by consultants who read all the books and go to the trainings and classes but have never been in industry and been in the clients shoes.
That's not an easy job, because you've got a shitton of unstructured data, new data sources coming online all the time, and a patchwork of analysis tools. This work would be a hell of a lot easier and more accurate and maybe even cheaper in the long run if you had an analytics layer that was more modern - but you don't have time to make the case to the CIO, because you're too busy just running the reports and doing the job that you're paid to do.
However, maybe a guy like me is having a convo with his client the CIO and she says "Y'know, Eisenstein thinks we need a new analytics plat, but he's busy on five other projects – can I pay you $5k to take a look at it and make me some recommendations?"
So I can sit with you, get your hot take, maybe bring in one of my guys who is shit-hot on dozens of analytics platforms, show you and your boss the trade-offs, costs, etc. If I'm lucky maybe you'll even hire one of my guys for a couple of months to install it and train you and your team up on it.
Way cheaper than interviewing and trying to do an apples-to-apples comparison between a dozen different analytics companies who're all gonna lie to your face about how their product is the best, probably politically better that you don't miss a full quarter of you doing your job, and your boss also gets to look good when I ship a sexy deck that shows how we're going to integrate all her peers' pet systems and provide much more timely, accurate, and readable results.
(I made this all up out of whole cloth, but the bottom line is sometimes incentives are aligned as such that a middle man can help you get there faster, cheaper, and better than DIY. On the other hand, consultants can also make things WAY worse as this thread illustrates)
Companies don’t have the skills or experience or expertise or resources or time in-house to do it themselves, so they essentially outsource the initiative or objective to a consulting firm.
It’s seen as less risky to go with name brand big consulting firm. But companies think they can pay little and get a quality delivery team, and the big consulting firms usually find a way to make a profit at the expense of quality by leveraging inexperienced consultants or consultants overseas with no real world experience.
Engagements are often around $100k a month and when I go looking for one of the consultants to help in an emergency, I often hear they are busy with something else (another client) and need a day to get the request started. When we’re paying 100k a month you better damn well have one person on deck or able to pivot immediately to us as if they are one of our employees.
My current client is spending $300M+ a year on an implementation program, and they are going on their third year with 2-3 more to go.
When I say pay little, they need more people and/or more experienced people to actually get the job done right. But they end up off shoring to teams in India or green consultants with zero industry background and limited experience.
They choose the firm with the most compelling economics, but severely overlook quality. They forget that these are organizational changes that impact humans. That outsourcing to lower skilled or different cultural regions will impact communication and team dynamics and overall ability to get things done properly.
The rate cards we use are tied to market rates. Consulting (and services businesses in general) aren't super-profitable.
I think probably you're just pulling numbers out of thin air.
Now if you think that the value of consultants is overrated, I tend to agree with you in some - but not all - cases. As an example, it makes little sense to hire FTEs for a short term project that has to happen on a discrete timeline.
In Canada, the 'Gun Registry' cost $700M and it could be literally an access database not even mySQL. Literally probably could fit in Excel.
The governments custom payroll is going to cost another $1B and it still does not work, they are looking for alternatives.
It's fraud. The bill $1B for a piece of shit that a handfull of decent Engineers could have built for 10% the cost.
It's blind leading the blind leading the blind who don't care. Everyone's repuation is a stake so they will lie lie lie.
Bureaucrats believe the smooth sales pitch and have no clue what a good project should look like.
We need much better standards for IT projects because this is going to kill us.
Also, from a dynamics perspective, this is a lot like the insurance industry. In the insurance industry you can underestimate risk during the good times, take profits, and then go bankrupt in the bad times. In auditing you can spend a lot of money being extremely thorough - you'll lose all your customers because you're expensive and painful. So instead you lower your standards, you're cheap, you're easy to work with, and it's easy for a fraudster to slip through, in the 1 in a 1000 chance that happens the regulator comes down on you like a tonne of bricks. Well ok, but was EY less competent than McKinsey or did they just get unlucky that they're the poor bastards who stepped on the landmine?
Well, maybe in this case we should learn from the insurance industry and institute some sort of fund that all auditors pay into that pays out in the case that fraud is discovered.
I have asked myself the same question, before I noticed that EY is basically the Credit Suisse and the SoftBank of the audit world[1]:
> EY has been involved in many accounting scandals: Bank of Credit and Commerce International (1991), Informix Corporation (1996), Sybase (1997), Cendant (1998), One.Tel (2001), AOL (2002), HealthSouth Corporation (2003), Chiquita Brands International (2004), Lehman Brothers (2010), Sino-Forest Corporation (2011), Olympus Corporation (2011), Stagecoach Group (2017), Wirecard (2020), Luckin Coffee (2020) and NMC Health (2020).
In fact, Wirecard managed to partner with EY, Credit Suisse, and SoftBank simultaneously just before going bankrupt.
Maybe because no reputable companies wanted to touch it?
[1] https://en.wikipedia.org/wiki/Ernst_%26_Young#Accounting_sca...
Andressen is one half of Andreessen Horowitz (a16z) which (I think?) doesn't have any connection to Enron.
E&T are accountants who double check that your financials are what they say they are.
McKinsey are management consultants who generally do strategic projects, and/or facilitate other consultants to actually do work.
https://www.ey.com/en_gl/strategy-transactions/strategy-serv...
That EY's auditing track record is, well, checkered is a different problem. By throwing those two into the same bucket, so, shows some lack of understanding of auditing, accounting and consulting. EY also does, sometimes legally required "consulting" work for in the accounting space. That work is completely different from stragoc management consulting ala McK and BCG. And it also a different beast than the lower level outsourcing consulting ala Accenture.
https://pcaobus.org/oversight/standards/auditing-standards/d...
Contrast that with say an HMRC tax audit. They're not there to be your friend and it actually makes sense for them to investigate certain firms.
It would be interesting to read a history of the industry to see how we ended up here.
While I agree audit is a hard job auditors should not just rubber stamp what the company gives them. They should ask probing questions like "where did this sale come from?", "how did you calculate this figure?" and "why are you doing this? It is unusual." A consequence of this is that they may pick up on suspicious signs within a set of accounts and choose not to sign them off, but I wouldn't say theeir job is to identify fraud per se.
What is clear from cases such as wirecard is that EY have failed to ask these probing questions on several occasions, and subsequent audits (by other firms) have shown it is entirely possible to ask appropriate questions and uncover dodgy practices.
Also audit is highly regulated. If the standards are too loose the PCAOB can come in and punish you severely.
Its the pervasive cases, the wirecards, that are hard. Those are the frauds that are pervasive and go to the top, and include auditors that are not pushing back. These are the true landmines.
How are they addressed? Many ways: A) There is a layer of prevention, where audit firms will force rotation of their lead audit partners on an audit every 2-3 years to prevent cozy relationships.
B) And theres Also the "audit the auditor" where another partner has the sole job of reviewing the work done. He's the landmine hound looking for explosives.
2) the insurance business actually rakes in profits typically after a large disaster, when premiums are sky high and customers are are hyper aware of the risks (and Boards unforgiving with CEOs that fail to mitigate the risks.
expertise is a virtue in modern society. signaling it well is often easier and more successful than developing and maintaining it.
damn lucrative, too.
this is why we can’t have nice things.
I’m not sure many reputable public companies will be queuing up to use their services in 2 years time
It is the company being audited that gives the auditers the business. Its not in the interests of a dodgy company to appoint a good auditor, and its not actually in the auditors (short term) interest to uncover wrongdoing as it just means they'd lose a client.
My proposal is that you require every company to have insurance to cover the risks, making the insurers fully liable for fraud (and any other business risk that audits protect against).
Companies then don't appoint their own auditors, but the insurers do. Its in the insurers interest to make sure that any audit is effective as they're on the hook for any liability the audit misses.
This way the insentives for the auditors are aligned with the interests of the people relying on the audit (shareholders, customers, suppliers).
Rating agencies were, and are, paid by bond issuers are rated a bunch of synthetic real estate backed bonds as very safe. But then on top of that, certain of these bonds were insured—-notably by AIG. However, AIG just rubber stamped the ratings and ended up going bankrupt when the crisis hit.
The real mismatch of incentives is one layer deeper than your comment suggests. An insurance company CEO can do very well for himself underpricing insurance. The business grows as premiums roll in and he collects a bunch of bonuses. When the SHTF he could just resign and collect his golden parachute.
The regulator pre-negotiated approved rates and vetted a bunch of companies, all of which had to had presence in Malta. The audit reports have to be turned by mid-June, IIRC, and they can't really start until the accounts for the previous year have been finalised. So in practice the audits must take place between late February and mid-May. At the time the entire nation of Malta had about 450k people in total, and each audit blocks two accredited people for approximately three weeks.
Turns out there are a lot of gambling companies registered in Malta, and each pair of auditors could only process 5-6 companies within the allotted time. The country would have run out of auditors ... so they licensed a whole lot of local smaller shops as accredited gambling auditors to make up the numbers. Many of whom did not have the technical knowledge to actually even assess, let alone understand the businesses they were assigned to.
And I can say this from painful experience: there is real value having the same team of auditors for 2-3 years running. They will get to know how your company operates, and any good ones will figure out entirely new questions to ask you from year to year. By all means, be an adversarial assessor, but at least please be clued in.
Disclosure: on the receiving end as a key person in technical audits since 2015.
If you want to sell in the Germany, get a business license from Estonia or Romania or some other low-cost low-bureocracy EU country, and pay your taxes there. Germany is still living in the business climate of the '60s.
In Germany income is taxed where it is generated, which includes the head of the person running the business. So if you run your foreign company from Germany - which is expect to be the case if you have no physical permanent office in Estonia, where you also have to be regularly present - you home is considered to be an business location and thus you are taxed accordingly.
Note that this only applies to limited liability companies.
If you are a single person with no need for limited liability, just register an individual business (Einzelunternehmen) with your local authority (Gewerbeamt). It’s really easy, cheap and if you need support, tax consulting for individual business is rather cheap as well and worth it if your business generates regular income. Otherwise you can just talk to the authorities, because income from passion projects (i.e. non-regular, without the goal of generating a substantial income amount) is not taxed at all.
Only if you're a resident in Germany, But if I live somewhere in the EU and sell something to someone living in Germany I don't owe income tax to the German government.
I pay my income tax where I'm a fiscal resident (Estonia, Romania, etc.)
If you are a freelancer trading without a corporate entity you can get screwed so hard. There are nasty people out there that will take advantage of this and can demand loads of free work or refunds, knowing that your entire personal wealth is on the line.
The UAE has no bankruptcy laws, so there is no protection for those who fail to meet their car repayments, pay off their credit cards or default on their mortgage, even accidentally.
Anyone who fails to make their payments faces imprisonment in the notoriously tough prisons of the United Arab Emirates, and the Sharia-influenced debt offences have even led Interpol to circulate red alerts to capture indebted Europeans attempting to flee the UAE.
There have been previously recorded cases of foreign workers being prevented from leaving the Emirates after being blacklisted for simply missing one credit card payment or bouncing a cheque. As a result, many expats are forced to abandon their lives to avoid jail time, often with their car keys still in the ignition.
I would bet they fixed their information systems, and you couldn’t now leave if you happen to screw up.https://www.carkeys.co.uk/news/the-story-behind-dubais-aband...
Actually, I had a friend working there as a nurse who bought property to live in, and they were underwater for a while. They were not stupid: it was an easy and normal mistake to make given their background (mortgages are not thought of as jail material at home, I’m not sure if they were warned of dangers).
I expect there are other unknown serious “gotchas”, because you are not a citizen in Dubai. You could easily be treated the same as the third-world working imported labour, and the legal system there can heavily penalise non-citizens.
Yeah: 0% tax is nice, but personally I think it is not worth it to live in a crappy place and there are hidden costs. Been there for a week just to have a good look around: fucking hated how people were treated there - weird economy.
The problem isn't the concept of regulation, but the follow-through on loopholes. By doing away with regulations you'll decrease quality of life for most people. Instead we have to find ways to react to loopholes in a fair way. It's not impossible, we've done it before, see the previously-mentioned examples!
See, for example, UL/CE and FCC regulations - unless they burn something down or interfere with emergency services, businesses can usually defer the regulatory cost till they can afford it. Or the FAA, which gives out slaps on the wrist like its going out of style, as long as the offender is not an airline.
Case in point: many countries allows underage family members to work for family businesses and even the ones that don’t, barely enforce it. A factory hiring dozens of kids? That’s a lot less likely to go unnoticed.
This is a remarkable claim. Why would you think that?
If you sell as an individual, it’s just you selling random stuff that you don’t need to pay taxes for. Once you do this as a business, you declare it as such and notify the state about it.
Britain is great. I can file my taxes online relatively painlessly for any non-employment income. Employment income is done automatically. To set up a small business, I buy public liability insurance and a domain. Many tasks that require multiple notary appointments in Spain can be done online or, for some obscure processes, at the post office.
I suspect that business climate divides sharply between the north and south, with Germany and France being honorary southerners. I'd love to unpack the link between Catholicism and stultifying bureaucracy, since both involve archaic institutions imposing themselves between oneself and one's goal.
The Economist Intelligence Unit ranks Germany 13th in its global business environment index, the UK 15th. In the local index, it's 7th vs. 9th.
https://country.eiu.com/article.aspx?articleid=222209005&Cou...
https://country.eiu.com/article.aspx?articleid=402870423&Cou...
There’s a big difference between bankruptcy and business failure. Plenty of businesses fail without entering bankruptcy, they’re wound down responsibly and their creditors are repaid in full.
If a company fails due to bankruptcy, then it means that people who lent money to that business are out of pocket, and end up paying for the failure.
The whole point of “limited liability” companies is that the owners and management are shielded from creditors in the event of bankruptcy (hence the “limited liability”). So a five year ban (which is true in most countries) from directing another limited liability company is reasonable, it don’t prevent your from running a business, only from running a limited liability business, because there’s now evidence that in the event of failure you’ll leave your creditors high and dry.
Ultimately the privilege of running a limited liability company, where the state promises to protect you from your creditors if things go wrong, is just that, a privilege. If you prove yourself unable use that privilege responsibly, then that privilege is temporary taken away. To be clear, the privilege removed is protection from creditors by the state, if your business fails. You can absolutely start another business, it’s just that the state won’t protect you if you fail.
> Shareholders are often last in line to receive proceeds with preferred stock shareholders getting better treatment than common stock shareholders.
Loans aren't shares; not even early loans. Else they'd get much better returns from the successful businesses.
Though, I don't think the distinction really matters within the context of my point. Both investors and creditors are exchanging money for a bet on future profit derived from the company being solvent in the future and having extra money to either pay back debts or pay out dividends.
My point is that America tends to get a lot of flak for rigging the system in favor of those with excess money (some of it is even fair). My point is that if you want to structure your system past what we're willing to do, you may want to stop and think for a second about if that's what you really want.
Now, if you want to protect the money of people with extra money to lend out, that's absolutely fine. It's a completely internally consistent position. But my understanding is that it's not that popular of a position, so I'm surprised the system is set up this way.
Nope, that's still just investors.
Creditors are not people who made bets on the company's future profits. Creditors are people who the company made legally binding contracts with to pay them. For example people who provided products and services who are getting stiffed. Also: taxes due.
Even a bank loan is not a bet on the company's future profits. A bank loan is a contract that says you will repay the money lent, with interest. Irrespective of profitability.
Which is why a limited liability company usually can't get credit unless it is also guaranteed by someone else. Because with no outside guarantees, it would be a bet. (Yes, convertible bonds exist, but different topic).
That being said, I completely disagree with this part:
> Creditors are not people who made bets on the company's future profits.
Nope, that's not how reality works. If the company doesn't have the money (including their assets), you aren't getting paid.
Extending credit is fundamentally a risk. That's one of the reasons credit card companies charge interest.
And of course for startups in the early years it's not that relevant anyways, since nobody will lend you anything until you have revenue. VCs invest instead of lending and aren't owed anything if you shut the company down.
Banks can take into account the borrowing history of the executive teams already.
> And of course for startups in the early years it's not that relevant anyways, since nobody will lend you anything until you have revenue.
Being unable to make payments on leases, etc, is pretty likely for startups that fail.
And that's without even factoring in the effect of bankruptcy on consumers employed by the bankrupt company. Employees of a bankrupt company are considered the highest level of unsecured creditors, but they still come behind secured creditors. So bankruptcy can not only result in an employee (who is also a consumer in the more general economy) losing their job, but losing their last paycheck and benefits coverage. Which has a consequent effect not only on consumption, but on utilization of public, tax- or fee-supported services.
---
If a person bankrupts a company, they could probably use 5 years to let all of the lessons that they should have learned sink in. If you fail out of school you have to retake your classes in order to graduate.
Ultimately most of the real creditors to small and medium businesses are other small and medium businesses. So if you offer no protection to them at all, you either get extremely risk adverse companies that refuse to offer any sort of credit (such as 30 day invoices), or a single business failure ends up causing a cascade of failures all of their suppliers take the hit, and also go out of business.
Ultimately increasing the trust between businesses, so they’re able to extend thing like 30 day invoices as standard, substantially improves the business climate. It reduces the barrier and risk of everyday business transactions, makes it easier for businesses to manage their cashflow, and ultimately allows businesses to grow faster and in more robust manner.
None of this is about protecting lenders like banks, or investors. Most of the time they screwed anyway, it’s about protecting other businesses who’s primary function isn’t financial risk management.
If you have no debts, and thus, no creditors, you can't go bankrupt by definition. Of course, if there are government fees or taxes to pay, the collector of those becomes a creditor. You would want to formally close the business so that it doesn't accrue annual fees and force you to do more paperwork.
If you spend all your money down to zero, then the normal thing is to just have your company dissolved and struck of the companies register. For which there is no consequences, you just tell the state your business is no longer operating, they make a note of that, and that’s it. Business dissolved, you get on with your day.
> If you prove yourself unable use that privilege responsibly
Good luck determining whose actually to blame and who is innocent... at the end of the days only unlucky small to medium business owners who can't afford expensive lawyers or consultants will suffer from such a policy.
I really dislike this attitude, lawyers, engineers and auditors are liable in case of negligence. Why should CEO's be excluded from liability?
Also CEO are liable when they engage in criminal behavior just like everyone else.
And where are talking about auditors there are very specific and procedures which define they duties and responsibilities. How could you replicate that for CEOs?
> I really dislike this attitude
I'm just trying to be rational...
Bankruptcy is not a mild consequence. People can and often are ruined by a bankruptcy, not to mention the harsh impact that it has on employees who are suddenly forced out of a job. Declaring bankruptcy should not be considered as something mundane or yet another run-of-the-mill managerial decision.
Also, not being able to found a company is not what I would call "harsh". Even in a purely capitalist view of society, a entrepreneur needs to focus on ventures to ensure they are successful, and "failing fast" does not mean it's ok to file for bankruptcies.
At the end of the day, creditors must (and generally do) realise when supplying a limited liability company there is a risk that the company goes under you won't get paid. That's why credit insurance and credit control departments exist.
If the directors were committing fraud by misrepresenting the state of the business and it fails, that is a completely different thing and directors should be barred from trading. But businesses fail all the time and we must accept that. Barring people from trying again for 5 years isn't a great solution imo.
All the more reason why entrepreneurs should not take lightly the prospect of filing for bankruptcy, and should focus their energy on ventures where they can minimize the chance of burning through cash right into bankruptcy. Otherwise it starts to sound like these serial entrepreneurs are just flinging crap at a wall to see which one will stick with little to no effort. This is a massive disservice to investors and employees alike, if not outright fraud.
As someone who knows nothing about this area, I don't understand why audits won't always detect fraud.
I would naively assume that auditors have access to all financial accounts and records of cash flows and they make sure they all add up and are categorized correctly. And that if fraud is happening, there will necessarily be numbers that don't add up.
So what am I missing? Do they not have access to all accounts and statements? Is it just a top-level glance at the numbers because there isn't enough time/money to scrutinize everything? Or can the numbers all add up but there's still fraud?
Is there anyone here who can give an example of something fraudulent that is hard to catch?
Someone in control of the checkbook at a medical facility who starts a shell company with some innocuous sounding name (i.e. Smith's Medical Supply) and and regularly submits bills in low enough amounts that they don't raise concerns - which of course is relative to the size of the company - but say you run a practice that has $50M in annual revenues, it would be quite easy to send in bills for supplies that only amount to 1-2K per invoice over a long period of time.
This kind of thing happens a lot, and without actually contacting every single vendor, verifying they are real, and verifying every thing that was purchased, can be very difficult to root out - especially with supplies that get used up, as opposed to hard assets they are supposed to be around for a while.
When the numbers are small enough, nobody even bothers to verify them - even though over years they can add up to a significant amount of losses.
I hear about stories like this all the time - it is pretty common.
Fraud can be easily detected if one employee is committing it. Fraud is substantially harder to find if two employees are involved, specifically 2 employees involved in internal controls.
For instance, if you have a policy that all checks paid over $10k require 2 signatures from corporate officers, it’s easy to catch a check with one officer forging the name of a second in order to siphon money to his 3rd party shell company.
But if both officers make a shell company, they can post the check as usual, and the check would pass auditor checks unless they looked into the specific corporation being paid, which may be out of scope if it’s a relatively small transaction.
Ultimately, you don’t need assurance that the financials don’t have fraud, you want assurance that they’re materially correct. Whether the company lost 10k to fraud or waste or incompetence is almost irrelevant for the investor, because the company has 10k less money. Obviously they’d prefer it not be due to fraud, but the impact on the financials is more or less the same.
Source: am a CPA
If an AI can augment the auditors to find more suspicious transactions such as to companies with no employees, or conflicts of interest - I could probably find more fraud.
Honestly, this seems like a lose-lose for decision makers: - automation reduces billable hours, a net loss to the auditor - automation finds more fraud, a net loss to the person who hired the good auditor
Of course, shareholders would appreciate less fraud, but have no seat at this particular table.
But why does cost not matter on the contract? A few reasons, one being is these are hourly contracts and the consultants know the customer has to finish the project. there will be more money. Second the customers are picking one of these companies on rep. If they fire the consultants they just rotate through the rest of the big five. There's no real incentive for the big five to change their model with customers who are making decisions based on who sponsors the golfer they like. Just like how every VC used svb, go with who you know.
This is why I left consulting. Every good shop gets wooed by the siren song of butts in seats economics. After consulting I've moved to where I sonetimes have to damage control projects from the big 5 and other high end large tech consultants on code. They're all doing the same thing if they get that big.
We had 2 recently with nationally renowned consultants where the provided heads couldn't use basic shell scripts or basic cloud cli, all at a senior DevOps bill rate. I ended up interviewing several of them and the only one of them id trust was their senior principal architect (5% time) who I'd put as a Jr/sr sysde/sde at our co. We fired the consultants. Luckily we only wasted money, our pm, and a few hours of my time.
Beware any company that competes with beer and insurance companies for commercial slots.
Your comment was the first in this comment section where everything was coherent and on point. While everyone else is spitballing, you hit the nail on the head. I was not surprised at all that you revealed you’re a CPA because the accuracy of your comment perfectly conveys your credentials. Funny how things like that can come through.
Source: am also a CPA
There aren't many of us, so I’d love to connect. If you want, shoot me note at: Anthonyj at gwu.edu
Same with picking a supplier - there are processes in place that try to assess quality, speed, price, effort, etc, but in the end it's humans making decisions, humans with bias and the ability to lie and make untrue statements as to how they made their decision.
Then there are the usual money laundering techniques, eg art dealing. You could easily spend a few million $$ on art for, say, a big office. And the VP's niece might be an artist that can demand that on the open market.
Someone was CFO at two companies and the auditors only checked the year end balance against his falsified statements. So he transferred money from the other company temporarily to make them match.
"""To avoid detection, Morgenthau doctored African Gold’s monthly bank statements by, for example, deleting his unauthorized transactions and overstating the available account balance in any given month by as much as $1.19 million. [...]
Morgenthau knew that African Gold’s auditor would confirm directly with the bank the actual account balance as of December 31, 2021, as a part of its year-end audit. [...]
Morgenthau deposited more than half a million dollars of Strategic Metals’ funds into African Gold’s bank account on December 31, 2021, because he knew that African Gold’s auditor would confirm the account balance as of that date, in connection with African Gold’s year-end audit. """
https://www.sec.gov/litigation/complaints/2023/comp-pr2023-1...
Yes, of course. Consider that you've set up a separate company and you intend to steal money from your employer. You've got a buddy in accounts payable that you're in cahoots with. You get set up as a vendor, you send invoices to the company, they pay them, and you never deliver anything. The company's numbers add up. They pay vendors for services all the time. Whether the vendors are real, the contracts are legitimate, and the expected services were provided isn't on the account statements.
A thorough audit would reveal this as well though, as it would actually evaluate the entire supply chain is actually working as intended.
It's more akin to you being denied Linux maintainer privilege if you keep finding bugs and annoy Linus in the forum. Which is hardly the case (heh).
I expect that EY does not have access to numbers and any account information. You give away as least information as you can because you cannot just trust auditing team from some 3rd party not to use that data in collusion with your competitors.
What I expect they do have access to is documentation for procedures and processes. They audit for example if all procedures are written down and check proofs for procedures that were done by employees.
So it is like you have to clean the toilet and you have procedure that whoever cleans the toilet signs list. Every end of the shift manager checks the list and checks toilet if it is clean.
Fun part is having signed list for a day does not tell you that for half of the shift employee was only signing the list but did not do any cleaning and you might have dozens of customers seeing how terrible dirty toilet was.
I think it's even worse: the shift manager checks list to see if the toilet is clean, but they don't actually look at the toilet.
This seems to be the case for our EY IT audits anyway. Just send them the right screenshots and all the boxes will be ticked.
> As someone who knows nothing about this area, I don't understand why audits won't always detect fraud.
as some one who studied accounting and auditing, here is a page from my text:https://kfknowledgebank.kaplan.co.uk/audit-and-assurance/aud...
but the tl;dr is that auditors don't provide "insurance", they provide "assurance", specifically reasonable assurance.... that the accounts are "true and fair"
or to be put it in even simpler terms, they can't guarantee something fishy did or didn't happen, the transaction scope is just too much, they will "try their best" and do enough of a check to say if anything fishy pops put.
> Is it just a top-level glance at the numbers because there isn't enough time/money to scrutinize everything?
yes you hit the nail right on the head. Of course things have changed, govt have put their own requirements in addition to auditing standards, but still that's an adequate summary.the more through of a check, the more difficult, time consuming and expensive it becomes, and at some point the fraud becomes cheaper than the audit.
but even more importantly is the mentality. There is a phrase we were taught "Auditor is a watchdog and not a bloodhound" that kind of explains what auditors are supposed to do.
----
i left the field but i'll try to answer to the best of my ability
i am NOT haying pattern recognition won't help, search for audit software and you will see each of the big four has specialized software. (here is EY's: https://www.ey.com/en_gl/audit/technology)
the problem is the issue of perverse incentives, IMHO. Audit takes a butt load of time and money, and disrupt business while they do their thing, and pays peanuts frankly... and audit firms earn more from associated services, contracts which they can earn if they don't bother the management too much.
yes, there are a dozen caveats and stuff, but frankly, the issue comes down not to technology but to people. The same network of people are in the few audit firms, and the spin out to join companies sometime later, who hire the same few audit firms, and so on.
In reality of course all this work could have been replaced by def is_fraud():return True
And the accuracy would probably increase. Crypto fraud has the beautiful property that the people being defrauded actively defend the fraudsters. Moreover, in a lot of cases it isn't technically fraud since the contract is upfront about what it does but at the same time it is very exploitative but that doesn't matter to crypto people
The vast majority of auditors are only 3 year or less years out of school. They don't even know how a corporation is run at that point, so how are they supposed to catch anything suspicious.
From business perspective the auditors are clueless.
I dont claim that audits are bad, they are very needed. But the execution in many ways is so poor.
The conflict of interest in external audit is absurd. It’s similar to securities rated rating agencies paid to rate the instruments by the issuing company.
Also have you ever tried to stop something that makes a ton of money? It is damn near impossible. If governments had that much power the people who would lose their money have a very strong incentive to invest a large portion of that money into regulatory capture. So any solution that uses government must be predicated on a non-corruptable government which do not exist, at least not for very long. A variation of auditor’s prudence. A lot of our traditions and institutions that are resistant to corruption were designed and maintained that way to support wealth extraction via expansive empires, as you can’t export wealth if it all disappears into corruption. And empires must export wealth from colonies in order to compete with other burgeoning empires. Without such an empire to support the resistance to corruption erodes as the mechanism to reward those who eschew corruption disappears. It becomes increasingly difficult to acquire power without first being corrupt.
Sure there were some "bare minimum" things that was expected to be upheld like passwords not being in plain text, but come time for a security audit it was exactly as you say. Not done out of genuine interest in security but as a rubber stamp of items to be able to show the client "look we did this"
Not even joking when I say that the development plan for most of these projects basically just tacked on a few days in the last week for "security improvements" alongside things like "tech debt" rather than it being a top of mind thing for the entire development process.
Hey! I used to be a young IT grad helping with financial audits.
If it helps, I was young and clueless and frequently I still figured out more about the business processes I was auditing than the client employees taking care of them every day :-p
Many audits and compliance frameworks have so many loopholes and DIY rulings that basically anything is possible and acceptable as long as whatever you're doing is written beforehand.
But I was checking what were called "IT controls" for their systems and a lot of that stuff was straight forward and yes, it did involve some rubber stamping, but a lot of it made sense: "Do you have a written approval process for adding users to this sensitive system?". "Can you show us how you mitigate not having a written process?".
And it wasn't super rare that besides the fact they didn't have the thing I asked for, but sometimes I couldn't even get them to understand why it would be a good idea.
A lot of companies are the Wild West :-)
In terms of actual liability - no, at least not yet. A number of lawsuits by individual investors were thrown out[3] but it's possible there will be public prosecution:
> Criminal prosecutors in Frankfurt are assessing whether BaFin employees obstructed justice by not properly investigating fraud warnings.
In the end, it's a regulator, they have to rely on auditors to some point. If Wirecard lies and EY doesn't catch it, that's on the criminal and the auditor. Still, it's hard to understate just how badly the agency fucked this one up... Hopefully, it'll serve as a true wake-up call.
Certainly seems like it - they have been more aggressive recently with other problem companies like N26, Solaris Bank, Coinbase, Deutsche and others.
[1]: https://www.ft.com/content/4f948457-678e-485c-92f7-2837064a5...
[2]: https://www.ft.com/content/587b6c52-c93e-4b2c-949a-53f6a1667...
[3]: https://www.ft.com/content/9fab6842-4ee6-4114-a35c-09bf9c62a...
They tried to get innocent people put in prison. They belong in prison themselves. If all that happened to them was losing their careers, then they haven't been brought to justice.
Actually figuring out who, if anyone, committed a crime (through gross negligience, willful obstruction, or similar) will take years.
I’ve worked for a regulator in a sector with more lenient oversight (health) and there the accountant was one of the pillars of our understanding. We just didn’t have the mandate or capabilities to understand the finance of the thousands of providers. In that way regulating finance is easy. Banks and insurers are relatively low-N activities. In case of BaFin I find it hard to imagine that they couldn’t, so they probably wouldn’t.
Food for another thread is how to match the European perspective above to, say, the SVB case in the US. How on earth the regulator didn’t track the interest rate risk is beyond me. (I believe the legal explanation is that they fell in a D-F regime with less regulatory burden.)
"The German financial watchdog has filed a criminal complaint against two Financial Times journalists and several short sellers, accusing them of potential market manipulation over reports about suspected accounting irregularities at payments processor Wirecard."
https://www.ft.com/content/8e1948be-6060-11e9-b285-3acd5d435...
There's a pretty good book on the whole sad story: Money Men: A Hot Startup, A Billion Dollar Fraud, A Fight for the Truth by the FT journalist that did most of the digging.
If journalists and short sellers hadn't kept pushing (against Wirecard, auditors, and BaFin), Wirecard might have survived a bit longer, managed to acquire Deutsche Bank, and then (with the merged balance sheet) gotten away with it. Mind boggling.
However, I must say, after reading that book and several articles about the whole thing, I am still not quite sure how they could keep up the fraud for so long, what exactly happened there, and who benefited.
(I suspect that crypto firms have taken over a lot of Wirecard's "business"...)
Publicly traded company should pay a small fee to SEC each year and they be responsible to hire auditors, for everyone. Or even better, market bid for auditors with incentives for finding irregularities.
With the current line up of incentives, auditors merely ensures any fraud are slightly better hidden.
Read up on regulations, it helps!
Is it? The incentives are not going to be aligned so far as the auditing companies are hired by the company being audited. It doesn't matter how many auditing company there is and the division of labor within.
Think of lobbyists, there are many different flavor of lobbyists, some might even be against the others. They distribute events, campaign finances and other things to legislators and as we know recently even certain members of judiciary. A bad idea in general in terms of the incentives at play.
I do think the incentives are entirely wrong for auditing. Auditors should be paid for by shareholders. Even if it decreases your dividends, you _want_ to pay for an auditor to provide reasonable assurance that there is no funny business going on with your money. In fact, that's how auditing began. The current system provides for conflicts of interest where partners are incentivized to please the board of directors that hire them and pay them large sums of money.
However, this doesn't lead straight to all auditors covering up fraud, and I feel that many people in these comments are overly critical. Having skepticism of the process is great (and auditors emphasize professional skepticism themselves), but I don't think we should throw the baby out with the bathwater as the current system does still provide a lot value. I also think many people here believe auditors at Big 4 firms are forensic accountants, which they are not. In the US, the FBI employs the forensic auditors many here may be thinking of. The auditors that EY employs are there to provide an audit opinion that expresses reasonable assurance that the financial statements are fairly presented. It's a very tough job that cannot be performed perfectly in its current form yet works remarkably well, all things considered. Finally, EY is a very large company that's really made up of many individual pieces that share a larger name but are structurally different, particularly between regions such as the US and Europe. EY in Germany certainly deserves the negativity they're receiving here, but that shouldn't necessarily be applied to all employees of EY all over the world. It's an accounting firm made up of thousands partners who are CPAs (in the US at least).
The exciting thing is that given the nature of accountancy, the industry is extremely conservative and open to disruption. However, that disruption has to adhere to numerous rules and regulations that would probably frustrate many entrepreneurs here. Most auditors are working with Excel and PDFs and do mindless work at the lower levels. A lot of this is getting off-shored, which is lessening the quality of the work. If a new technology was able to be designed that could overcome the shortcomings of humans manually using Excel and PDF markup tools while providing a higher quality of work than the off-shore work many in the industry are using, there would be a great opportunity to replace jobs at the lower level - boy I don't like saying that out loud. Hopefully it would allow for new employees to focus more on judgement based decisions using their expertise gained from obtaining the difficult to attain CPA license. They say that every year at a Big 4 accounting firm is equal to two years in industry, and I certainly believe that. Based on my experience, I strongly believe that licensed CPAs that come from auditing firms know far more about the ins and outs of businesses than the MBAs at consulting firms like McKinsey that many here seem to be conflating them with.
Perhaps I should join an accounting software company. It can be easy to forgot how much expertise I have as a CPA when I was surrounded by them in my previous career. Yet I have found that the software companies I have reached out to undervalue my CPA and overemphasize leetcode skills, which is truly a shame. If anyone is interested in a decent software engineer with a CPA to add, I'm open to talking!
Instead it is lawyers and accountants working for these big auditing companies.
GDPR is good but the absolute insanity of how GDPR is being applied cannot be understated.
They were the big proponent of the the just in time management principles in the hospitals in the Netherlands.
Then when covid came they were the first the market on twitter & linkedin for advice how to improve your health inventory & deal with covid challenges.
Serious impact with zero skin in the game. These consultants are parasites.
They are mainly used as proxies to make decisions managers dont want to be responsible for.
Otherwise, I mostly agree, though I don't support a ban. It's a complex topic - companies are free to waste money how they want, and even governments do need real advice. It's just too bad they pick such shitty advisors to support decisions they've already made instead of actually seeking good advice.
OTOH, the monetary penalties where a bit on the light side so maybe that also balances out the rather harsh ban.
If you are a team lead doing programming for one of these sorts of companies and the auditors come round with some findings, I promise you that you need to take it deadly seriously. I've seen engineers fired for cause by the board of directors of a fortune 500 for failing to do so. Word gets around and nobody will touch them after that. Its literally career ending to poo poo audits.
Tech companies are the odd man out when it comes to audits, which is why its possible for so many in a thread like this to have opinions that are so wildly inconsistent with reality. Who knows how much longer that will last, particularly with advances in AI.
It means delaying or coming up with excuses for why you can't have security concerns remediated within the agreed upon time frame. Regardless of the technical challenges involved.
Audit remediations are not the kind of projects where delays are acceptable. You absolutely must drop everything else you've got going on in those situations if you even remotely get a hint that the project might be behind.
The reason here is that your boss and your bosses' boss can't save you. If bad audit results come back you can bet the C suite had an emergency meeting discussing how to explain them to the board and the timeframe for getting them fixed. And you can bet they made some sort of commitment.
There are hundreds of millions to billions of dollars on the line in insurance premiums and future legal process in some cases. Oftentimes cyber insurance will mandate some kind of timeframe for remediation upon notification of a security issue. So you'll get hit with penalties well before the next audit if you delay. You don't want to be the programmer(s) that missed a deadline there.
You audit accounts that are falsified and give thumbs up: you close shop, are held liable for damages and could go to prison.
Auditing companies are crucially important for a working economy. Bank loans, bonds, equity markets would all be chaos and fraud mayhem without them.
We might as well turn "audits" over to the short sellers like Hindenburg Research, at least they make money by exposing rotten accounts rather than hiding them.
The fact that being an activist short seller has become a business model in the last ~8 years tell you how bad the likes of EY are.
RATING agencies are different from AUDITING companies different from CONSULTANCIES.
Rating agencies were somewhat restructured after 2008 (but are still kind of edgy) - because they did literally write AAA on a piece of paper for money. But there ratings were opinions and had no real legal meaning.
Enron’s problem was the “consulting AND auditing” mess with conflict of interest if I am not mistaken.
By the way, it was KPMG that caught the Wirecard fraud. And KPMG is in the same league and business as EY.
One of the reasons, IMHO, that Wirecard managed to get away with it for so long is, that as a German company, they didn't have to switch Accountants and have another accounting firm helping them in preparing the books. That would be a SOX set-up, and it makes perfect sense. It helps to prevent fraud and it protects retail investors, both of which are good things in my book.
Strategy consulting, the stuff BCG and McK does, is different. As is the outsourcing and consulting Accebture does, which is also different from what McK does. The topic so, is EY and accounting.
Consultancies are not doing that.
I’m not sure why certain businesses should be “banned” because YOU believe they do not add value. Do you pay them? No.
It’s not correct that they are proxies for decision making that mangers don’t want to be responsible for. Neither McK nor BCG could run at the scale they do for five decades if that was the case.
But I suppose that was just your happy Sunday rant of the day to let off some steam.
Yes, whenever they are hired by the public sector. http://recreation.gov is one example in the US I know about.
How is a mismanagement of consultants by public sector entities a justification to “ban” an entire sector?
BCG and McK don’t offer auditing.
At a sufficient level of negligence and authority -- yes.
Say your a large company listed on the stock market, so pick from the four big companies because serious companies use them, who's the CFO an ex-account from the big four who knows their orderand process.
Now if no other companies can enter that bubble, are we really surprised at the outcome!?
We should really consider the present western world as some sort of marriage of corporatism and government - they are really hand in hand as two sides of the same coin.
I was a Deloitte manager.
I know much more people on the IT Consulting side who are in it for the long haul to partner or whatever. The job was also much better than the Audit scene, 80+ hour days in a sweaty conference room and next to no days off.
They both had he same MO, send in the 30s\40s flashy employees who then delegate all the work to 23 year olds. Once the project is in full force they tend to leave and another crew comes in who interfaces with the low cost offshore teams or 23 year olds.
Shure a lot of the leg work is being delegated off to juniors but that is not of substance here.
What you talk about might be happening in smaller shops but not on tier 1 audits inside the big four, there just is too much at stake.
worth mentioning that the complex tax situations are the effect of lobbying of the big four firms in the first place.
“Corporatism” is a model of society in which government, private industry, union, and other power centers are integrated, mutually cooperating, and centrally coordinated. A “marriage of corporatism and government” is just “corporatism”.
(Corporatism is an element of, but not coextensive with, fascism.)
Interesting I just watched a video [1] on consulting yday. It is on something similar happening in the UK. And another video ( couldn't find it ) that suggest unless there are some other interest for these consultant, ( like outsourcing certain function to certain clients ) all they do is to make a case for what the management wanted to do anyway, and rubber stamp on it. And mostly because management wanted something on their CV / resume, so they could move on to another job and repeat the same process again.
>listed
>new
>in Germany
>two years
...that's gonna be like one or two clients max. Very bad PR but complete non-issue from a biz pov