The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Finance/The FinTech Flo
The FinTech Flo artwork

Straight Outta Compliance! Plus, New Music - Ep. 38

The FinTech Flo · 2024-10-31 · 1h 18m

0:00--:--

Key moments - from our scoring

Substance score

52 / 100

Five dimensions, 20 points each

Insight Density11 / 20
Originality9 / 20
Guest Caliber12 / 20
Specificity & Evidence10 / 20
Conversational Craft10 / 20

FLO Cast's shift from a single-product company focused on close management to a multi-product platform includes the launch of their compliance management tool. Jason, who joined as product marketing manager in January 2022, discusses how the company conducted a survey with the University of Georgia Consumer Analytics Program - intentionally designed as non-biased, exploratory research rather than pay-to-play analysis. The study probed how compliance professionals view their roles, responsibilities, technology needs, and job satisfaction across organizations. Key findings revealed three dominant compliance personas: 47% view compliance as checkbox work driven purely by legal requirements (often accounting staff handed compliance as an additional hat), 37% focus on risk mitigation, and a smaller segment pursues strategic risk orchestration. The research shows clear correlation between job satisfaction and whether professionals perform tactical box-checking versus strategic advisory work. Jason draws on his background in both external audit and internal audit experience to contextualize these findings. The episode also features 'Ghost Tick Killa,' a rap track from CPE music about ghost ticking - the dangerous audit practice of falsely attesting to work not actually performed - complete with accounting terminology woven throughout the lyrics.

Key takeaways

  • →Almost half of compliance professionals (47%) view their role as checkbox compliance driven solely by legal requirements, typically because accounting teams inherit compliance responsibilities when regulations emerge.
  • →Job satisfaction among compliance professionals correlates strongly with whether they perform tactical reporting work versus strategic advisory functions that improve organizational processes and efficiency.
  • →Internal auditors and compliance teams can deliver greatest value by transitioning from low-value control-checking to strategic advisory roles that analyze cross-functional processes and recommend risk mitigation approaches.
  • →The survey was deliberately designed as exploratory research without predetermined outcomes, conducted in partnership with University of Georgia to avoid bias that pay-to-play market studies often introduce.
  • →FLO Cast's compliance product aligns with the market need to move compliance professionals from pure regulatory box-checking toward risk orchestration and strategic business value.

In this episode

  1. 1Halloween Costumes and CPE Music Album Launch
  2. 2Ghost Ticking and Audit Compliance Issues
  3. 3Jason's Journey from Audit to FLO Cast Product Marketing
  4. 4Internal Audit Strategic Value and the Three Lines of Defense Model
  5. 5Strategic Compliance Study Overview and Methodology
  6. 6Survey Findings: Three Views of Compliance Roles
  7. 7Accounting Department as Central Hub for Regulatory and Compliance Work

Mentioned

FLO CastDrew CarrickJasonJosh SimsPetty CashUniversity of Georgia Consumer Analytics ProgramSpotifyApple MusicFlow Academy

Topics in this episode

Three lines of defense modelInternal auditfloqast studiosconnected compliancebest accounting podcastcpe talk showFLO Cast compliance management productGhost ticking (audit fraud)Risk orchestration frameworkCheckout compliance versus strategic complianceInternal audit versus external auditUniversity of Georgia Consumer Analytics ProgramReasonably Possible Risks (RPRs) frameworkCPE music and Ghost Tick Killa trackCorporate Transparency Act business ownership reporting

Questions this episode answers

What is ghost ticking in audit and why is it dangerous?

Ghost ticking is falsely attesting to audit work you did not actually perform - checking off that you vouched an invoice or reviewed board minutes when you didn't - and it's a fireable offense that auditors take extremely seriously.

Why do accounting teams typically inherit compliance responsibilities?

As the central hub managing financial records and regulatory relationships with the entire organization, accounting naturally becomes the first team assigned new compliance requirements, especially in scaling companies where compliance duties emerge suddenly.

What are the three main ways compliance professionals view their roles according to the survey?

The survey found 47% view compliance as checkbox legal requirements, 37% focus on risk mitigation, and a smaller segment pursues strategic risk orchestration that includes process improvement and advisory services.

What's the difference between a pay-to-play study and exploratory market research?

Pay-to-play studies hire vendors with predetermined outcome expectations, introducing bias, while exploratory research like FLO Cast's uses probing questions without expected results to discover genuine market insights.

How can internal auditors transition from low-value work to strategic advisory roles?

By moving beyond checking whether controls exist to analyzing processes across the organization, identifying potential risks, recommending effective controls at appropriate thresholds, and providing management with strategic recommendations rather than just compliance dings.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

11 / 20

The episode delivers moderate substantive content on compliance frameworks and the three-tier model (check-box, risk mitigation, risk navigation), with practical observations about internal audit roles and technology's role in reducing administrative burden. However, significant portions consist of tangential discussions (Halloween costumes, music production, sports betting implications, FTX anecdotes without new analysis), filler banter, and repetitive affirmations that dilute insight density. The core compliance survey findings and automation philosophy are solid but not densely packed throughout 78 minutes.

47% view compliance as a check the box activity
the path to get to this view of compliance...is through administrative burden

Originality

9 / 20

The episode repackages established compliance frameworks (three lines of defense, tone at the top, controls-based auditing) rather than introducing genuinely novel thinking. The 'risk orchestration' term is presented as novel but amounts to standard risk management practice rebranded. The FTX discussion is retrospective commentary on well-documented failures. The automation take - that technology should handle administrative tasks, not strategic ones - is sensible but represents conventional wisdom in compliance and tech circles, not contrarian insight.

risk management to risk orchestration
we coined the term risk orchestra

Guest Caliber

12 / 20

Jason is a product marketing manager at FloCAst with audit background and involvement in a market study on compliance practices. He brings practitioner experience and has conducted research, making him reasonably credible. However, he is not a C-suite executive or recognized thought leader in compliance; he is a vendor representative marketing his company's solution. His insights, while competent, carry inherent bias and lack the independent authority of a compliance officer at a major firm or a regulatory figure.

Jason, the product marketing manager here at FLO Cast. Um, started my career in audit
we did a study...with the University of Georgia Consumer Analytics Program

Specificity & Evidence

10 / 20

The episode provides some concrete data points (47% check-box, 37% risk mitigation, 16% risk navigation; 1.235 billion revenue threshold for 404B; 75 million public float threshold) and names FTX and specific audit standards (SOX, 404A/B). However, much of the discussion lacks named examples, metrics, and timelines. The compliance survey is referenced but details are sparse. FTX discussion recycles public information without new specifics. Large stretches involve abstract philosophy on auditor independence and automation without supporting numbers or case studies.

almost half, 47% view compliance as a check the box activity
if your revenue is over 1.235 billion you trigger 404B

Conversational Craft

10 / 20

The host (Drew) asks reasonable opening questions and attempts follow-ups, but the conversation often meanders into tangential territory (costumes, music, baseball, LinkedIn jokes) rather than pursuing substantive depth. When compliance topics arise, follow-ups are sometimes surface-level (e.g., 'how did people view their jobs?') rather than pressing for specifics or challenging Jason's vendor-friendly framing. There is little productive disagreement or skepticism; Jason's points are largely affirmed. The host occasionally pivots to personal anecdotes (his own audit experience) rather than extracting more from the guest.

So diving into that study, how did people view their jobs?
it's always great having you back here on the show

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker B52%
  • Speaker A47%
  • Speaker C1%

Most-used words

compliance66risk51audit49controls38internal37accounting28part25sure25role23back22product22auditors21auditor21control21strategic21automation20

Episode notes

Strategic compliance is the next frontier for companies with massive compliance obligations and regulations requiring them to follow strict standards. With all of the fraud and bad financial practices that have taken place over the last decade, there are constantly new regulations coming out for businesses to stay on top of, and allowing these tasks to become mundane, tedious, and monotonous will result in increased burnout and chances of non-compliance. Jaysen Dyal joins the podcast to chat with Drew about results of a recent compliance survey, the role of internal auditors, and the recent scandals that brought the industry here, plus they get a sneak peak listen do the new music album Audit Jamz! This episode and all FinTech Flo episodes are available for CPE credit over at FloQademy and on the Earmark app (links below!) Earn CPE credit while you watch, along with a bunch of other high quality, engaging, and entertaining CPE eligible video content for free as a member of FloQademy! or via the Earmark app! Listen to Audit Jamz on all music streaming platforms! There’s lots you can do in your career with an accounting background - we’re hiring! Learn more at Want to watch?

Full transcript

1h 18m

Transcribed and scored by The B2B Podcast Index.

Speaker A: I am here, ready to be rolling like Speed Racer. This is my costume.

Speaker B: Let's roll. You're rolling.

Speaker A: No, this is a. This is a flow. This is a. I think if you're a speed racer, you should be flowing, because rolling seems like you might hit some bumps along the way.

Speaker B: Right.

Speaker A: But I think flowing means you're just. You're moving with ease, gliding through the air. I'm like a speed racer out there. But I do have the festive, uh, socks as well.

Speaker B: I mean, we were supposed to have, um, some costumes here today, but I just kind of threw this on. I didn't even expect to be wearing this. But here we are.

Speaker A: You're dressed as the Flo Cast mascot.

Speaker B: Yeah. Yeah.

Speaker A: If you were to pick them m. Uh, if you were to pick a mascot for Flo Cast, what would you. What would it be?

Speaker B: Oh, man, you're putting me on the spot here now.

Speaker A: Um, I mean, it can't just be the unicorn.

Speaker B: I mean, this is gonna be bad. But he can be the guardian.

Speaker A: The Guardian. Guardians of the Galaxy. The Guardians of the Guardians of Business.

Speaker B: The protectors.

Speaker A: The protectors. All right, I dig that. What are you going to be for Halloween this year? Do you have a costume set?

Speaker B: Uh, I watched Scary Movie for the first time, and so that. That little. Like, you had the. The mask. Yes, I wanted to wear that.

Speaker A: Well, so the mask actually has to do with, uh, Ghost. Ghost Tick Killa, which is part of the announcement that I wanted to share with everybody, which is the CPE music album just came out. I don't know if you've listened or have a favorite song. One of my favorites, personally. Is Fitting in time for this episode, which is our Halloween episode, which is Ghost to Killa, Ghost to Killer. And it's actually very. Makes a lot of sense thematically for what we're talking about today.

Speaker B: Uh, it's all fitting. Stars have aligned.

Speaker A: And also shout out to Ghost. Uh, Ghost was also the dog that we, uh, Cap and I were, uh, babysitting essentially for a few months, and Ghost just went back to her owners. So, um, we'll throw up Ghost on the screen in post so everybody can see.

Speaker B: Well, that'll be solid. A dog named Ghost is weird. Um, I always thought giving pets, like, normal names was weird, too. Like Brian.

Speaker A: Yeah.

Speaker B: If you're Brian, it would make it a little strange. That's strange. Yeah.

Speaker A: So I want to show you Ghost Tick Killa. Just a quick little sample. Not the whole thing, but we'll throw it on. Initial reactions. Have you heard Ghost Dick Killa before.

Speaker B: Uh, no. If it wasn't on the commercial, I saw the commercial. That was pretty good.

Speaker A: Okay, so, yeah, this was not featured directly on the commercial. So you know what ghost ticking is? Um, from the days of audit for the.

Speaker B: For the sake of the audience?

Speaker A: Sure, yeah.

Speaker B: Let's say. I don't.

Speaker A: So a lot of people listening who come from the audit background probably would be familiar with this. But ghost ticking is the act of saying that you did something that you didn't actually do. So it's putting your check mark, your tick mark on. On the work. Yes, I did vouch the invoice. Yes, I did actually read through the board of director minutes. I read through the notes. And you're checking off in the audit file that you did it, but you didn't actually do it.

Speaker B: That is really dangerous.

Speaker C: Big.

Speaker A: No, no, no.

Speaker B: I've heard of that.

Speaker A: No, no. As you say, people get people fired for that.

Speaker B: Oh, absolutely. Um, we. We'll get to it today. But there's all kinds of crazy stories you hear in audit. I think. I still think that's why it's a good career to start in.

Speaker A: Yeah.

Speaker B: Good place to start your career. You're, you know, just out of college. I think you see a lot of things. I think you learn a lot of things. Um, yeah. Ah, audit days. There's. Everyone's got a story.

Speaker A: Yeah. And you got to be disciplined. So this song is available on Flow Academy for CPE credit, and it's also available just on Spotify and Apple Music and everywhere else. So I'll give you a little. A little preview here of the. You know what I think is the favorite track also, because it's by Petty Cash, which is, as those who have followed me throughout my career know, the rapping CPA's rap stage name, Pet. So this is Ghost to Killa. Just listen to, uh, the first port. You'll hear the accounting stuff mixed in there, too.

Speaker C: Started at the top, checking out the instructions Vouching my way down to the bottom of the bucket smooth like Keystone man from Nantucket See something fishy, sound

Speaker A: off the trumpet dance around the hoarding room Marketing up financials, looking at the

Speaker C: rprs planning the substantials no time to rest When I test, I invest but if I see a check hope you hashtag blessed. Cause I'm the innovative so creative in the valley and you're the same as last you're like your parents name you Sally got the big four showing love that's a rally my busy season always gets renewed no finale. Cuz the EVPs won't let me be but incs get next to me. So if you say that you did it then that better be true Cause if you didn't then I'm coming for you. They calling me the ghost chick killer. I got ghost stickers in the name. Yeah.

Speaker B: Who produced that song? Who, who made the beat for that?

Speaker A: So that uh, is by our producer, Josh Sims. He no way composed the music and everything behind it. I wrote the lyrics and I think it's like a hit thriller song. I mean this is what to jam out to today for Halloween.

Speaker B: Absolutely. No, the words were fitting. The beat was great. Uh, I mean I'm impressed.

Speaker A: It makes so much sense. I, I love the uh, references. You know you're the same as last year. Like your parents named you Sally which is just that one hits. That applies looking at the rprs, planning the substantials, reasonably possible risks. Right. I mean I'm fitting in the stuff. There I am. Independence checks, you know, all of the things started at the top, checking out in the instructions, vouching my way down to the bottom because you're vouching your way through all the evidence.

Speaker B: Vouching is down if you don't do it.

Speaker A: Taking you out to the woods and getting you handed in your manila.

Speaker B: Making accounting cool.

Speaker A: Yeah. So I think, I think that's what it is. Uh, but with that being said, let's dive into the episode. This is the fintech flow. Let's get flow. So welcome on everybody to the fintech flow. I am your host, Drew Carrick, the rapping cpa. I've got another special guest here with me.

Speaker B: Oh, I'm Jason. Jason, the all product marketing manager here at FLO Cast. Um, started my career in audit and now ended up back in the studio.

Speaker A: Yeah. So it's cool.

Speaker B: Oh, it's always fun working with you guys. Um, not a lot of companies that have a full on studio. So we were in the, we were in, we were in big Frosty I think last time and just kind of made shift the podcast from there and this time you walk in here and it's pretty sick.

Speaker A: Yeah, they uh, did a phenomenal job. Phenomenal job building it. We've got our cool little art pieces which we can highlight and whatnot. Cool little bunch of nuggets throughout the walls. But uh, so you're Mr. Compliance here at Flo Cast.

Speaker B: That's right. Yeah. Uh, cover the compliance Management product. Um, there's a lot of compliance experts in the building. I um, think uh, we're kind of going through a cool transition in the company where we were one product company closed. That was our bread and butter. And now we're transitioning to a true platform play. Um, so uh, we did a huge launch, uh, to kind of pitch the accounting transformation platform. Um, and part of that is um, bringing in the compliance product as a true, you know, second, second product. Um, but the way that we approached the close and you know, we said buy accounts for accounts and really focused on building the product that meets the market and their specific needs. Um, we're really focused on doing the same thing with compliance. And so it's cool to see how that same philosophy is uh, flowing over to a different product.

Speaker A: Now did you start before or after the compliance product was created? Or was it like, hey, we want to do this, let's start to assemble some folks that are in the compliance space. Or did you lean more into compliance once it was like, okay, this is an area that seems to be growing and there's going to be a need in, in this product area.

Speaker B: Right. So I, I joined January of 2022. So it was the customer launch happened later that year, right when we first initially Bare Bones started the launching the product. So there was involvement in um, you know, preparing for that customer launch. And those were exciting months. I mean it was because it was completely new buyer, completely new use case. I will say I've learned more about, you know, compliance space and you know, three lines of defense model, risk managers, compliance managers, internal auditors has been really engaging um, because a lot of my experience comes from the compliance in terms of the, call it external auditor or the third party auditor that comes in and performs a, uh, an attestation. But then there's also everything that all the compliance that happens within an organization, um, it's been a great learning experience. And so the product is, is so sick. Uh, it's, it's amazing. So that makes work very easy for, for m. Me because it's a product that if, uh, you know, I know is useful back to the professionals that I came from, uh, ex colleagues and such. So we'll get into you know, a study that we did. You know, these are the kind of things I get to learn about is doing market studies and really taking a, a real interested look into what the, what the market is and how they view themselves. And so we'll get into it.

Speaker A: But yeah, yeah. I worked as an internal auditor after doing external audit and that was just briefly. Again I was an external internal auditor.

Speaker B: Okay.

Speaker A: It was like a hired External auditor, not somebody who actually was on payroll at the company. But you were the hired firm to work with the internal auditor, which is such an interesting role because that's considered advisory technically, even though you are doing some sort of assurance. But you're, you're, you're classified as an internal auditor but you're not actually internal to the entity. Which is just an interesting realm between the actual hired internal auditor and the external auditors. And you're in this sort of middle space.

Speaker B: Yeah, that's, that's a big part of like um, you know, the organization taking responsibility for their own financial records. Right. The relationship between a company and say management and the board versus uh, an auditor that comes in and audits. Like it's not the responsibility of the auditor to prepare. Like there's a, there's a big independence thing. They're there to just check the work, but all the work should exist there. All the financial records, control documentation, um, substantiating evidence, all of that should already exist. How you're assessing risks, what controls are in place, management takes responsibility for that. So I mean it takes a uh, personality, ah, to be an internal auditor. But I think the big miss is oftentimes they get stuck in a world of very low value work. Checking boxes. Did you do this? Right. Second signer did. Was there a second signer? And then you always deliver the news of hey, like there was a check over threshold and there wasn't a second signer. Ding on you guys. Where that sort of, that's, that's where a lot of teams get stuck.

Speaker A: Right.

Speaker B: Versus where internal owners could really deliver value is being like a strategic advisor. Um, right. Providing recommendations but they can't be responsible for implementing. Right. Because there is some level of independence required even within the organization. But being that strategic advisor. Right. They say, uh, internal auditors can make great coos because if, if they're doing their job effectively and delivering most value, they are able to perform like process audits across different parts of an organization. And then they look at a process and they think, well, okay, what are potential risks for this area? What are good controls to have to mitigate those risks? Is that an effective nut control or is there a better way we can do it? What's an appropriate threshold? And they provide that to management and the management sort of makes the final decisions. But if they're effective and they get past the regulation aspect of it and they're able to look at different parts of the organization and say, okay, how can we do this more effectively, more efficiently make great coos.

Speaker A: So you talked about the movement of these internal auditors into this more strategic thinking and the value that can be added there. I think one of the benefits of being one of the external internal auditors is that you, since you're not the external auditor, you don't have an actual independence issue. And since you're not inside, you're, you kind of can be that implementation sort of folk, or perhaps there's an opportunity to push that implementation internally where folks at the organization can be thinking strategically and implementing these sorts of initiatives or whatever the big project was. I remember we had basically four per year where we'd come in for a month at a time, four times throughout the year. So it wasn't like a full time internal auditor. But okay, now we're going to look at the payroll process and that was all we did for the course of those few months. So it was a very isolated audit. And of course the goal of that is to do process performance improvement, hopefully in the advisory services that you're able to add. But so we did a survey that you helped sort of conduct the creation of the questions and just design it. Uh, it's part of this publication here called Exploring Strategic Compliance the Next Frontier. A move from risk management to risk orchestration. So risk management to risk orchestration. These are some of that, some of those buzzwords, but do have, I think deeper context. So, uh, this survey was conducted in partnership with the University of Georgia Consumer Analytics Program. And it is noted that it was not a pay to play. So just what's the context of before we dive into the survey? What does that mean? Not pay to play?

Speaker B: Yeah, sure. So there are certain studies you can perform where you hire, say an analyst, you can hire, um, you know, a market study individual, you can hire a firm, um, to perform a certain study. And um, you know, you obviously, you pay them. Um, there's all kinds of implications that can happen with that. Since you're paying a vendor to do a study, you know, the results may not be as, uh, we really didn't know what we were going to get with this study. Right. We did this study very like, um, shoot a dart out, ask probing questions and let's see what happens sort of thing so that we can then perform some analysis over it. And so, you know, we put together some probing questions, but there was no goal in mind in terms of um, what results we expected. There were goals in terms of what we hoped to understand about the profession. Right. So things like how does, how do compliance professionals view their Role, Um, what, what sort of, um, job responsibilities do they feel they have or they should have? What, um, sort of technology did they have? And what does that technology look like? Um, a big part of it. In the compliance world, everything starts at risk. Um, everything is risk driven, more or less, because in order to justify why you are, you know, focusing on a certain area or performing testing, it has to be backed by risk. Um, and so, you know, with all that in mind, how do people view their job satisfaction as well? So those are sort of the probing questions that we wanted to find out. Um, but, yeah, shout out to Dee. We've worked with her a couple times now on, on these market studies and, um, it's been, it's been a cool experience to, to just find out from the market.

Speaker A: So diving into that study, how did people view their jobs? You know, what, what did the good teams and bad teams look like? And how is that criteria, how do you even evaluate that criteria of what, what's good and what's bad?

Speaker B: Right. So really, I mean, what's good and bad really came down to, like, job satisfaction. Right. Who was, like, pleased with the role? Um, who was viewed more respectably, you can say, or who is viewed more strategic within the role?

Speaker A: Um, so there's a correlation between job satisfaction and what you actually are doing in your role. How much of it is automated or how much of it is. You feel like your compliance is set and you're able to.

Speaker B: Absolutely, yeah. I think, um, the interesting thing about, um, you know, when we talked about the great resignation, some of that was around, you know, is there enough purpose within work? Am I satisfied with the value I'm bringing? Right. You spend about a third of your day at work. You know, is that an effective use of time or are you just kind of going through the motions and, you know, it's a paycheck and you're just kind of strolling along. Um, we found that there were three overarching views of compliance. One was 47%. Almost half view compliance as a check the box activity. Right. I, um, am doing this because there's a legal requirement that requires me to do so. And so it's very kind, um, of not so optimistic way to look at compliance, I don't think. Um, well, we'll get into it later. But basically compliance was probably thrown on these people's plates. They cared. They had another hat and, you know, all of a sudden it's, hey, you're, you're going to take over compliance as well now. Um, so it's not really a set role for this group. Um, they again, just like new regulation

Speaker A: comes out, says this is now a requirement legally we have to do this. Who, hey, who do we have at the company that can go do this here? You, you guys go do it.

Speaker B: Exactly.

Speaker A: And what, what roles this typically falling as? This is internal auditors. Typically.

Speaker B: No, I would say the accounting group is like the first group that this falls on. Um, if you're, if you're a scaling company or if you're say there's a new regulation. If there's a new regulation, the company is much bigger. Um, then yes, they have a separate compliance team. Like we internally, we have our own compliance team. Um, they would probably take that on. But we're talking like, you know, rapidly growing companies where new hats are having to be taken on all the time. Um, accounting is usually the first team to, to kind of take on that compliance role because again, they're the, you know, they're not back office. They're very middle office.

Speaker A: Yeah.

Speaker B: And they're the keepers of the financials and they kind of have that understanding relationship with the entire org. Right. That's a very central role. So they end up normally taking on the compliance burden. Responsibility. Um, which is also why it's a great way to segue for focus from close to compliance.

Speaker A: It is fascinating how much falls into the realm of accounting yet people. Well, I think this is actually really funny to think about. People think accountants only do a very few limited number of things like, oh, aren't you the people that do taxes? Right. When you say an accountant. But when you talk about even in corporate, oh, you guys are doing the bookkeeping. But every single thing that's filing or regulatory, it all seems to fall back to the accounting department. Like business ownership. Right. You have to. We have companies, LLCs, uh, and above have to submit business ownership percentages and, and tracking of who the actual owners are if it's part of the corporate transparency Act. And that falls now on accounting department to do. And it's like, well, why not finance department, why not legal department, why not any other department? And it always ends up coming back to, oh, well, the accountants are probably the most qualified because they understand the ins and outs of the business.

Speaker B: Yeah.

Speaker A: So it's like you want it when you want it when you want it and you don't want it when you don't want it.

Speaker B: Yeah. It goes both ways. Um, accounting and legal end up like I remember when I was doing technical, uh, accounting reporting for a brief bit. It was contract review. Every contract that came through. What's the accounting implication of this? So we used to keep a spreadsheet where it was like every single contract that we signed. Uh, it was, what's the accounting implication of this? And so, you know, then you're getting into memo writing, you're getting into, you know, what's the position? Restructuring, debt, doing a debt swap, buyback, all that. All that has like accounting implications.

Speaker A: I mean, people forget how integrated accounting is into every other function at the entire company. So like you said, it is middle. It's not, it's not back. It's, it's a center hub. It's a, every other department kind of has a spoke that, that it kind of runs through. I mean, I'm even thinking about things that you might consider to be budgets or budget or completely elsewhere. You have a marketing expense where you sign a contract with an influencer that you're paying them to make videos over the course of, uh, of year end and whether the, when the cash goes out is going to make a difference and how much is guaranteed that they're going to get for posting those video. I mean, that is, in theory the context of the contract has nothing to do with accounting, but the implications have everything to do with accounting.

Speaker B: 100%. If it's milestone accounting. Right. What percentage do you think it's going to? And with the rules changing too, it's like, how do you account for that? That's changing all the time as well. Yeah, right. There's accounting guidances that come out every year. Not all of them affect every company. Sure. But the rules, uh, change all the time. But. So you have this first group, right. Almost half, 47% that view compliance as a legal reporting requirement.

Speaker A: Requirement.

Speaker B: Tell me what the rules are and I'll just do what you ask of me. Second group, there's about 37%, about a third view their compliance role as mitigating risk for the organization. How do I minimize risk? That's like the lens through which they're viewing. And I think this is good for teams that are, um, getting into a new area or maybe you're in a highly regulated industry. Um, that's also a good kind of mentality to have, but really protecting the company at all costs. And now you're getting into a space where there's a separate compliance team and that's their focus is just how do I mitigate risk?

Speaker A: And this is once the legal requirement, uh, you've got that on lock. It's just. Yeah, we've got a process in place. We're good on that front. Now we can turn a little bit and be like, okay, now that everything we have to do is getting done, what can we do to lower the risk?

Speaker B: Exactly. That's a great point. Is like this builds on itself. Right. So it's not like the risk mitigation group never even thinks about the legal reporting requirements. They're probably just taking a step further. Right. They're being more strategic about their role, which is, look, we're not going to just do what the reporting requirements require, what SOX or MAR or ISO, whatever the requirements are. That's not, that's a great starting point and we satisfy that just fine. It's taking it one step further. What's specific to our organization? What's toward, you know, geography or you know, timing current events? Um, what are, how do we mitigate risk? Right. And so there's a, the final group that again, this builds on each other. The final group is those that sort of navigate risk. Right. They strategically navigate risk is what we call them. Um, and this, the, the path to get to this view of compliance, say not just a few, like that's your day to day, that's how you're executing your role is through administrative burden. Like it's, and if you talk to anyone in the profession, it's like it's chasing down PVCs, it's selecting samples, um, it's documenting your, your, you know, supporting files, annotating the PDF files, whatever doc you're looking at as part of your testing, doing the annotation. It's all of the administrative tasks that just take so much time. So 16% are able to, you know, kind of get past all of that. Yes, they understand how to mitigate risk, but they're also looking strategically, you know, they're also able to calculate what risks to take. Um, just being much more strategic about their role. Right. And we talk about strategy a lot, we'll get into a little bit, but 16. So there's two things. One, they, they meet regularly with company executives and they understand what, what are the company initiatives. Right. What are the goals for this year and then how do we navigate risk, uh, accordingly. And the second is they, they invest in effective technology, which it's just, you have to, you have to invest in technology to get to this place where, you know, some of that administrative burden is automated. Not only automated, but it's like you said, ghost ticking like that is a risk. Right, Right. I'm not, uh, fine. I'm really want to go into every file and I'm just going to, you know, there's a risk of ghost ticking, believe it or not. And so if you have effective technology that can mitigate that by actually going in each file and annotating and automating that piece of the compliance role. So that again, going back to internal auditors where they're seen as like kind of naggy and hey, can you send me this file or that all is automated for this group.

Speaker A: Sure.

Speaker B: They're not sending. The communication touch points aren't can you provide this? Or you know, hey, you missed this or something along those lines. The communication points is much more elevated. You know, you're doing these process audits, you have time to, to, to look into operational efficiencies and effectiveness, all grounded in risk navigation. And so it's the ability to mitigate risk and strategically navigate risk that we coined the term risk orchestra. Right. That's where that came, that's where that came from.

Speaker A: And so, so the administrative burden is the biggest inhibitor of being able to obviously think more strategic minded. Right. And to be going forward with being able to attend those meetings. M. Where I mean, if you think about it, if I'm leadership at a company, sure, we'd love to have you coming and attending these meetings and hearing the initiatives. That way you can get ahead of any risk we might foresee. But we've got a filing that's got to be in and you just got to get that done. So unfortunately you spending two hours to come to our executive leadership meeting is just not in the cards and it's not available.

Speaker B: There's technology that exists to where that filing, the data, you know, data moving from one tool to another, um, work being executed once and communicate and that data being shared across. I mean that just saves you so much time. And that's the cool thing because a lot of times it's, it's status meetings, it's, you know, these, these spreadsheets that then you're cutting out and sending emails. I mean it's, it's in all different kinds of areas of the accounting role where you're asking for information, um, or even in the internal audit role as well, where you're, you're performing an assessment over how processes are being executed. But if there's ways to automate that and that's how you can get to a much more strategic.

Speaker A: So is there a requirement at any point for internal auditors to have to be at a company or is that totally up to the company to decide whether they're going to have internal audit?

Speaker B: It's up to the company. Um, interesting. One thing the, the, the IIA group is focused on, which I agree with them, is like, you know, being taken more seriously being in the, the regulation. Right. Uh, getting into the, you know, regulations that exist, getting their names into there as to defining their role. Companies I think typically bring an IA like on their own. Um, or when, when necessary an absolute, like I would say touching point where it's like you should have IA or an IA group is you know, if you're publicly traded and you have you know, a 404B filing status. Right. So when you go public there's certain statuses that you can take. Filing statuses, socks. The whole thing around socks is around controls over financial reporting.

Speaker C: Right.

Speaker B: That's the whole gamut of socks, among other things. But it's really over financial reporting. And so when you go public you can, you get an exemption the first five years and you to where you don't have to abide by every regulation to say a 4.4B company has to maybe, maybe it helps to, to go backwards. Right? Sure. If you're 4, 4B sure. That's like the, you're a large accelerator or accelerated filer. You meet a threat, a uh, size threshold, um, you have a public float, which means outstanding shares of 75 million or more. That company is required to have the auditors not only attest to the financials but also to the effectiveness of internal controls. And there is a opinion over the internal controls. So I think it's one of the few say like for publicly traded companies, other compliance frameworks have the same sort of thing. Right. Like MAR for insurance companies. But um, yeah, you have a third, the external auditors coming in and pining on an opinion on your controls. So internal audits, it makes sense to have there because you should be performing your own assessment internally and providing that documentation because again, management should take over responsibility for that. 404A is one step below and that is where management is still required to assess the effectiveness. Right. So it still makes sense to have an IA group because there's some sort of assessment there that management has. But that external auditor that's coming in, that third party auditor doesn't have to opine on the internal controls and there is no public opinion on the internal controls. Now that's obviously a very different audit right between the two because you involve controls testing in 404A or 404B and there's no controls testing in 404A. So in order to help with that burden of Going from private to all of a sudden January 1st. Controls can be tested. Right. You go from private to all of a sudden if you, if you know, if you're a massive company overnight, you've got to be able to have your controls testable. Um, so there's a status called emerging growth companies, EGCs, where for the first five years you're allowed like a 404A status. M. Right. Now if your revenue exceeds a threshold, which I think they normally adjust them every three years.

Speaker A: Yeah, I think right now it's 100 million.

Speaker B: No, so, so that's for. We'll get to that. But if Your revenue is below 1.2 billion, 1.235 I think then you trigger 4.4B.

Speaker A: Okay. No matter what.

Speaker B: No matter what.

Speaker A: You're just too big.

Speaker B: You're too big.

Speaker A: And so I would, I would argue that makes sense.

Speaker B: Your revenue's over 1.235, I think. Billion. Um, you trigger 4.4B. Now the calculation between 404 A and 4.4 B is public float. It's 75 million. Right. So if your value of outstanding shares is over 75 million, you trigger 4.4B. If it's below 75 million 404A in order to provide smaller revenue companies some relief. Right. Say for whatever reason you have a market cap over 75mil in order to provide, but your revenue isn't that high.

Speaker A: Sure.

Speaker B: Uh, 100 million or less in annual revenue. Those companies qualify for 404 a.

Speaker A: So now, uh, because I feel like if I'm sitting in the audience, I'm thinking, wait a second, don't I do some sort of internal controls testing as part of my regular audit of just regular private, all sorts of companies, like regardless, because most people aren't working on these massive, massive public company audits, there's a gabillion, you know, gajillion, uh, you know, of, of your not for profits and your healthcare institutions, you know, private colleges, just, uh, private companies in general.

Speaker B: There controls always exist. Right. And this was actually the, the, the one thing I learned in audit, which was very helpful is our audit partners used to push us and say, nope, find the control. It exists somehow. Management is getting comfort over the financial statements. Right? So whatever risky revenue, there is some way that management is getting comfort over revenue. Right? And this, this is part of like, you know, having a compliance solution. Is that all that doc, the process narrative, the flowchart, the rcn that should all be up to date. Um, but oftentimes you get a process narrative that's just a, ah, copy of last year. And you have to ask probing questions to identify the control controls exist. Now, whether or not they are occurring all the time. Right. That's a different discussion, especially for private companies, very large private companies. Right. Should some level of controls exist, but they're not publicly held? Um, and so controls, yeah, they absolutely exist. And they, and they should be testable. There's controls based audits that you can perform in your audit, which I highly recommend, like even privately held companies, they should be performing controls based audits because you should be doing that even if you're not publicly held.

Speaker A: And I think that's why as an external auditor we come in and we would look at the risk based on the type of controls that are in place. So maybe we're not giving a full opinion per SE at a 404B level, that level of certainty of opining on it. But, but you are using your evaluation of internal controls to decide where there's a, uh, risk of material misstatement or perhaps a significant deficiency area. Because you have to start with looking at the controls and being like, okay, this is really risky. You can't just look at the numbers. And I think it's really interesting when SOX even came out where there was this like, aha moment to the profession and to auditing in general, SEC everything where it was like, oh, yeah, maybe it's not just like looking at the numbers that we have to do. Maybe we actually, and looking at the documentation, maybe we actually have to look at the controls to make sure that that documentation isn't being made up or isn't being fabricated or approvals are actually happening the way they're supposed to be happening.

Speaker B: Yeah, there was, sorry, there was a, uh, there was an audit partner at Armenino where I came from, and he actually challenged us on that point very hard where he said, okay, you should be able to perform a risk assessment, say as an auditor coming in, you perform a risk assessment form. That's kind of the planning stages of an audit where you identify, you get the whole trial balance, you identify the risky areas and how are you going to test, right? What are the risks, what are the assertions that are most risky for this balance to be misstated and then that's, that drives your audit procedures. And so he challenged some of us at times to say, you shouldn't even need the trial balance. You should look at the nature of the account, the nature of the industry, the company. You know, you should ask questions about quarterly, um, events, what happened during the year. And you should be able to perform a risk assessment without the trial balance, say the account balances. You know what accounts exist, but you don't know the balances. I uh, thought it was a bit extreme, but it just goes to speak of what you're talking about where it's like there's two parts of risk, right?

Speaker C: Right.

Speaker B: There's inherent risk, which is regardless of the organization itself. How risky is this certain account balance, cash, AP revenue intangibles, what's the risk of that account, regardless of anything the organization is doing and that we end up taking like a quantitative approach, which is like the account balance and then certain non quantitative, qualitative, you know, is there a big change in the balance? Did significant events take place internally or in the market that drives your inherent risk? Then you have the control risk that goes to what you're talking about where, what's the risk of the control not operating as designed? Right. So let's say you have a highly risky area, but a great control that is operating as designed. It's effective and it gives complete comfort. And the substantiating evidence is very well documented as well and retrievable. That drives your risk of material statement. Yeah. What's the residual risk after that?

Speaker A: My favorite part is looking at the rprs, planning the substantials. My lyrics. Um, but when you get to drop something where it's no longer a reasonably possible risk, it's, it's a less possible risk. I remember that sections being moved and the amount of testing you have to do then on it is drastically decreased. If it's, if it's not a reasonably

Speaker B: possible risk, people don't. There should be more talk about how much less, how much more effective a controls based audit is for both the company and the accounting team and whoever has to provide that evidence and the auditors. Right. It is. I mean you're talking hundreds of samples reduced. Right. To be able to just fully test an effective control. And you're helping the organization develop better controls. Right. The biggest risk though that drives a lot of auditors and companies away from a controls based audit is if, if you fail a control, sure. You're back to substantive testing.

Speaker A: Well, you know what this kind of makes me think of is like the plumbing on a house. Right. Where's the point of failure? And if you can ensure that the only place that there's a point of failure is up at where, you know, the plumbing meets the street. Right. That's the one valve and every other valve that goes to every other faucet in the entire home. You know, as long as the water is good, going into the initial drain essentially, or the initial pump right from the street, like, you're all good. But if you shut that off, then all the rest are, are impacted, all the rest are affected. It is interesting if you were to have the entire, if every aspect, all those little faucets of accounting, all those things that need to happen, the actual numbers that are coming out, if all of that's being done on autopilot, essentially, right, where you don't have to worry about people maybe making the mistake, you just have to make sure that the control that's getting the numbers to that system is working properly, how much it could reduce the cost of audits and the burden on people at the companies. I mean, that kind of gets into automation, which I think we'll touch on. Um, but we did also speak roughly about, you know, the fact that you have these, these companies that hit a certain threshold. Ah, right. You talked about the $75 million float of outstanding, um, um, you know, shares. And you have a lot of AI companies now, interestingly enough, talking about automation, talking about AI that are quickly growing to these revenue marks per year, to these market caps, these valuations, and they're doing it in such a quick time frame. I mean we had, there's cribble gradient flow and Wiz. Wiz did it in 18 months, crossing 100 million revenue threshold. And that's quicker than what most companies can get their compliance in order for. Because I mean, you think about, if you're looking to go public, talking about getting your SEC reporting manager in place, start building the S1, there's a process of, you know, getting SOC1 compliant, SOC2 compliant. All of these, all your socks controls, all of this stuff needs to happen and come together. And when you have this company that's just growing that quickly, I don't see how there's any ability to like freeze frame and focus on making these things happen.

Speaker B: Makes the case to invest in, again, invest in technology as early as possible. Right? If you're on that, that sort of a trajectory, like, it's, it's, it's like when you return home, you, you'll get this. When you come home from a trip and it's like you don't unpack right away, you're like, I'll get to it. And then you go on the next trip and you're like, oh, I'll unpack. And it's just like it, just it very quickly, like 18 months 0,100 mil, 18 months. Like compliance at that size of a company is way m more difficult to implement then at like you know, when you're early on. Um, and that goes for a lot of things. Sure. But compliance is, is the hardest thing about it is you have to be able to substantiate what you did at a later date. So it's almost like the work that you are performing, um, you better have a system to be able to retrieve that work or, or complete evidence. Right. And this is what drives me nuts about screenshots. It's like that's not the control. Right. Because it's not where it happened. It's just. It's an imitation of what happened. Right. We talked about this before.

Speaker A: Yeah.

Speaker B: The, the email that says approved.

Speaker C: Yeah.

Speaker A: The thumb, the thumbs up on a slack.

Speaker B: Right. That isn't the control. Right. It's like what did they look at? What were the questions that, that that were exchanged? What was the actual review process?

Speaker A: Well then you talk about the, the layers of it which is why you have systems uh, like okta that you have to sign in which is why laptops you turn off within two minutes because they, they want to lock it. That way you don't leave it and accidentally somebody else goes onto your slack and then goes and thumbs up an approval that they sent from another. I mean like, you know what I mean? Like that's an actual thing that could happen. Like people don't think about risks from that standpoint. But every, any where there's a will, there's a way. And where there's a desire to perform an egregious behavior, there's going to be a way get it done. If you're willing to take certain steps. So how do you make it damn near impossible? Like a penitentiary that you can't break out of?

Speaker B: Yeah, no, that. I mean as uh, in talking with internal auditors and discussions there's, there's like really creative and effective controls. Right. The two minute shutdown. Great, great sort of IT control. Um, some. In some things you wouldn't even think about. Like I talked to, to one internal auditor. He was saying he actually recommended to the company for employee reimbursements. You don't pay them out until you receive all of the documents. Right. Until we put everything into. Here's a receipt and everything. Right. You have the corporate card or whatnot or you're seeking a reimbursement. There was a company that was issuing reimbursements but didn't have all the documents. So then when it Came time to test the control, it's like, wait, you paid out but you didn't get all the documents. And he just, by switching that to where? No, the reimbursement doesn't occur until documents are received. It's a great control. Yeah, because it's everything that got paid out. You know that documents were received, hopefully they were reviewed and then there was some sort of issue.

Speaker A: It seems so common sense, you know, when you, when you look at it. But it's amazing how when you're moving fast and trying to scale and trying to grow and the focus is on revenue, these things get, I think often forgotten about. Um, so I want to talk about it in one example, a little plug to my buddy Dr. Sean Stein Smith, um, friend of the podcast, friend of the show, longtime uh, colleague of mine in the accounting industry, Mr. Dr. Blockchain is what I call him. And uh, he had an article recently, FTX auditors $2 million fine reveals wider compliance issues. And obviously this is him talking about it now. But we're looking back in time at the whole FTX thing which unfolded the beginning of last year where um, Sam Bankman Fried, uh, got jailed. Uh, and again this is what happens when you have a company that scales quicker than it can do compliance. Now obviously in this situation, whether leadership wanted to actually make sure compliance was going to happen is the thing in question of. No. Was it being designed to be fraudulent? Again, you don't know. Usually things start off with good intentions and then greed gets a hold of you. But it's just one example of how a quickly scaling company, it's very difficult and especially in a new and emerging industry which is AI technology, uh, and crypto. In those areas where things are happening so quickly, it's one thing to even track compliance, it's another thing to even have the laws and regulations in place to track in the first place. And when they're focused on growth and taking market share and growing the market cap, they're going to be focused on those initiatives and they're not going to be looking at the compliance aspects. And this puts a unique pressure on the auditors, which makes me kind of probe. And again, as somebody who came from audit, I, I, I have an affection in my heart for, for audit. But are auditors getting lazy? Is it an encouragement of being lazy? Because it's just, it's too confusing and you're not really rewarded for bringing up a problem that you see. You're almost discipline for being, bringing up a problem which going a layer further says, well, do we sort of have an independence issue? Is there, has audit become just inherently an independence issue because of the way at which you hire auditors? I'm paying you, I'm not paying you to tell me what's wrong. I'm paying you to give me a good audit opinion. And, and obviously you can argue no. A good company would want to have the honest truth. They'd want to know if their company's not doing things by the books. Sure. But they also have an obligation to the shareholders to keep that value high. And a lot of the times it's a, do it at all costs. And you have these situations where it's, it's, you're very rarely seeing any negative outcomes from audit opinions when perhaps that should be more frequent just given how prevalent goes greed and, and fraud is in the modern day.

Speaker B: Yeah, there's, there's, there's a couple things that that was, there's a lot to unpack there. Yeah. So first, you know, as it relates to FTX and you know, when we go back to the study that we did with that Strategic Navigation group, the sixteen, one thing that we learned was a lot of being able to view your own job that way was getting buy in from the top from management and the board. Right. Compliance is driven by the head. It's the tone uh, at the top will define what compliance is like for the rest of the org. And it's, it's, you know, one of those things. Right. Where do you prioritize and um, you know, what matters most to your organization is it revenue growth at all means, um, again and viewing how you view compliance, is it a legal requirement, is it a, hey, let's not grow as fast as we can because we're just focused on mitigating risk or is it, you know, hey, all right, we understand you guys want to grow. That's an initiative. But that shouldn't be the end all, be all. There should be a responsible person in the room to say all right, let's grow and sort of just build the architecture right around financial reporting. Financials numbers or accounting is the, the language of business. Right. There's all kinds of quotes that you can say. But that's part of what drew me to accounting as a whole was it's everywhere and either you're putting out good numbers or you're not putting out good numbers. And I can't think of a story where, call it Enron or, or you know, ftx, whatever other big scandal where tone at the top wasn't there and it Wasn't driven by, you know, out of the executives, the board or someone. Um, and so growing responsibility that starts at the top. Um, in terms of auditors, I think it's like uh, uh, a lot of other things that make the news is you hear about the bad parts or you hear about where it went wrong. Um, one of the things that I encourage people to, I wish they would just pay people more honestly. Like that's it's a highly leveraged business and people should get paid more like you see in finance or other um, um, industries. I think audit is still a great profession to get to start your career. You get a couple things. One, you build great relationships. You're in a conference room, but getting back to being in conference rooms in person, there's a great camaraderie that you build so great relationships. Um, two, you see a lot of different things, right? Typical staff right out of college, you're going to deal with say from if you're at a, ah, big four, maybe it's one or two clients or if you're at a mid tier, you might see 10 to 12 clients. If you're a manager you're seeing maybe 20 clients, 50 clients a year. That's 20, 50 ways different ways that accounting is done or processes are built or how teams assess risk. Where else can you do that? And so then you take it a level further and it's reading financial statements, reading footnotes, right? You learn how to do all of that. I think it's still a very rewarding career to get into. And the one thing that um, my advisor when I was in audit told me was get to manager because the audit experience changes from senior to manager and it really did became much more about project planning, leading, managing the finances of the business. You know, it's like opening the curtain and you see like it's all peaceful and everything on the back and then you know, staff and auditors are just going away auditing. Then you open the curtain, you just see all of the, you know, realities of running a uh, CPA firm and the business behind it. And then you know how to conversations that partners have still a very rewarding and and again the news breaks where it goes bad. But there are so many examples of when I was in audit where you go through a moral exercise as well, a real more exercise I found something and what do I do about it and what's the right thing to do? Um, and you've seen where it goes wrong. I've seen in my career but also a bunch of times where people get it right.

Speaker A: Well, I think this is where there's nothing wrong, I think with the audit profession whatsoever. And I completely agree with you too, also from the manager level. You're learning about budgeting and talking about utilization rates. You're thinking about all these other things that you didn't have to think about. You're the one technically you're billing the client at that point. It's your project, it's your engagement to uh, own and run. But when I think about the audit profession, I think it really matters is the relationship between the company and the audit firm. But that's an industry wide thing which, uh, Mike Whitmire and I have speculated on this a couple times. What we think would be the potential solution, and I happen to be really a big fan of this, is it's almost like there's a collective, right? Depending on the size of your company, you have a contribution the same way that you have the fdic, right, where there's a contribute. All the banks contribute to this, to this fund. You have this fund which is an audit fund which is then parsed out. And every seven years you get a new audit firm. And there's obviously the firms of the different sizes which are uh, essentially established at this point. Obviously how this actually would roll out. I'm sure there's a million implications and people are going to go crazy about, well, that wouldn't be possible because of this. But you, uh, know as a whole, if you simplify it, take the relationship away from it being you're paying us, and if you're being, if your firm is being paid out of this collective, it's your job to do the audit as efficiently as possible. But now there's no pressure to have to make that audit run smoothly because you know, you're on that engagement for seven years, unless you royally mess it up, you're on that engagement for seven years and then you're going to roll off and then you're going to get another client of equal size or if you did a good job or whatever. I'm sure there's still custody client relationship involved with that. But it takes the independence issue out of it because I don't understand how a firm can say we are independent when you're being paid by that, by that company. Like that's inherently not independent. No, you're, you're a client of ours. And, and I, I would just say that the only way that's, that's the only way is you'd have to have it be where now I'm going to pay you to go into that company and let the public, we, the public essentially are asking you to go into that company and let us know if there's anything wrong with them. And whether you say it's good or bad doesn't impact you at all. You used to get paid. You're still going to have another job after this, but at least now we know and it puts a little more pressure on them to make sure, okay, we got to have our stuff clean. We can't just schmooze you into giving us the audit opinion that we want.

Speaker B: Uh, yeah, I mean just any, anybody that gets audited and it's like the relationship between that. But um, again, I think for me it just comes back to tone at the top. It's like there is an audit, you know, good governance. There's an audit committee, um, that the internal auditors also report to. Right. They present their audit plan of where they are going to be focusing their time and effort for the year. Right. What, what processes they're going to look at. When you're a third party auditor that comes in and performs your audit, you report to the audit committee. Audit committee should have an interest in, you know, making sure the numbers are final and identifying any, um, you know, um, um, not misstatements, but exceptions. Yep. Right. Management's letter to. Or the auditor's letter to management around internal controls. Even if you're privately held, like, even if you're private, there's still a requirement to understand the control environment. And so that, that, you know, you still perform a walkthrough, you're 448, you still do all of that. But yes, I mean so much of it hinges on um, you know, management's opinion of. Or not management. But even, uh, the border, the tone

Speaker A: of the top, everything, uh, that, that's the captain of the ship.

Speaker C: Right.

Speaker A: They, they, they set the tone, they steered the direction. So regardless of, I mean you even think about, you know, we got the election coming up, right. Regardless of who the leader is, it doesn't really, we know that it's, it's. The role of the executive role is more or less in. It's kind of doesn't really matter. It's a. Congress has everything to do. There's checks and balances. Hardly anything ever gets done really. Rarely ever will. So it doesn't really matter who's in charge. But there is still that like tone at the top message that, that transcends through, which does impact the overall culture. Even if it doesn't actually make that big of a difference in actuality of rolling out. It does set that, that tone and that culture. So I do want to jump into this bullish or bearish section. Um, you sort of have a hot take here. So less bullish or bearish. We're talking more hot takes here.

Speaker B: Yep.

Speaker A: Automation technology. Now this has been a hot topic which we've spoken about on the show before. Last time we, uh, talked about automating pitches and uh, balls. Pitches, balls and strikes from pitches in baseball right now and the shortcomings of it or the value of doing it. But it seems that you think a lot of companies aren't utilizing automation in the right way. Uh, obviously there's a compliance tie in to that. But what should automation actually look like? And how, how are, how are companies or teams not using automation properly, perhaps? And what would you advise them to be doing?

Speaker B: Yeah, so, um, one of the frustrating things about being in marketing is that when you try to market a functionality that your product does, um, everyone often ends up speaking the same way. And so it's hard to decipher, like, wait, what, what do you actually do? Or where, where are you different from, you know, vendor B. Um, if you look at automation and particularly AI, um, that's just such a hot topic this year, even like last year, is implementing AI in a technology. Um, there's sort of two things that I've come across. One is a lot of the AI that gets pushed and the automation that gets pushed is around the strategic aspect of your job saying compliance. For this example, it's what, you know, it's, it's AI telling you what are, what are new risks that you should be, you know, identifying, um, what's an effective control over this. Now that's useful, um, but it should supplement the exercise that you're performing. If we take it. If you go back to the study that we performed, one thing that we learned was again, the path to becoming an advisor or becoming strategic, where there's higher job satisfaction, you view, you're viewed as an advisor. The, the road to that is through administrative burden and manual process and, and tackling manual processes. Right. And so there's technology out there that they'll, they'll continue saying get strategic, become strategic. And then, hey, we, we have automation around that as well. So that, you know, when you're strategic, uh, when you're doing that aspect of your job, um, we have automation to help you do that. You know, whether it's writing a tactical memo or it's again like, where are their duplicate controls? It's an awesome thing to have. Or what controls should I implement? But that's like, that's the strategic aspect of your job, right? So when you look at, well, what should technology automate? It's. It is that administrative part of your role. It's think of any manual process that you have. Think of anything that you ask yourself. You say, I didn't go to school for this. I didn't go to school to send an email. I didn't go to school to check if there's a second signer on a invoice. Right? That's all the, like the legal aspect, the check in the box part of my role. Right? That's not where you should be spending. That's where the technology should exist. M. Right. And some people say, well, oh, uh, you're. You just, you're just an administrative product. It's like, not necessarily. That's the part of your role that's preventing you from being everything you can be. Right. As strategic as you can be. So when you think about where should automation exist, it should exist at those administrative aspects of your job. It should exist. Again, if you ever find yourself saying, I didn't go to school for this, or I didn't go and get my CPA or CIA and do hours of study to chase down the right payroll report that charts, that part should be automated. And so that's sort of the hot take, I guess, is that technology, you know, companies market and they say, you know, become strategic and do. But like, if you're doing your job effectively, the check the box and legal aspect of it is all figured out. It's. It's. You're able to come in and review it, make sure it's all good, but you're able to actually spend your time and say, you know, we want to do this large transaction. What are the risks? Here they are. Um, hey, you know, you're keeping in touch with global events, current events. This is something that we should keep an eye on. Um, you know what certain indicators are, right. And you become that advisor. Business wants to make, make a, make a huge initiative for next year. Okay. From a compliance standpoint, how should we be organization. How should the organization respond to that? That's the job. That's the part of your job that you should be spending your time on.

Speaker A: It's kind of like if I kind of pull this into entertainment realm, right? Like, the fun part, I think, is the developing of the script. It's coming up with the idea. It's Coming up with the joke. It's figuring out what's going to resonate with the audience, what's going to be a compelling story to tell. And you can of course ask the technology to write you something is Kyla B. It's probably gonna be weaker. It's probably gonna be something that you're gonna have to review. But what you really need the help in is the actual like editing of it, getting it chopped up, right? The more monotonous things, you're taking that script that you've written and blocking out what every shot's gonna look like and understanding all those tedious components that go into it that aren't as fun. It's almost, uh, it's almost like these companies are providing automation for the part part that you should be actually doing and then not providing automation for the part that you don't want to do. And it's like, no, well, you'll have time to do the stuff you don't want to do because we're going to automate the stuff that you do want to do. It's almost like the, the, the fun stuff, right? Because I think, uh, I mean, you talk about it from the survey, right? I think it was 27. Higher satisfaction in job for those who were doing strategic stuff. And it's. Because strategic stuff is more fun to do. It can be more impactful, but it can also be more fun. Like you can get your, you can have your cake and you can eat it too. But that's only if all those baseline things are all being taken care of.

Speaker B: And I do think that breeds the, oh, is AI going to replace my role? Well, because that, again, that, that high value part of it, that's what, you know, people pitch. Oh, that's what automation can be. Automation should be. You know, like my favorite part of doing an audit. Part M that I'd say I miss the most is doing the risk assessment. It's, it's getting some preliminary docs, doing the interviews, understanding, okay, what does company go through with any large transactions? Getting the trial balance, determining what's high and low inherent risk, um, doing walkthroughs, taking the results of that and saying, okay, what's the design of this control? What's the control? What's the risk of this balance? What are the assertions that I think we should be testing for? And then what are the associated procedures we're going to do to address those risks to bring the risk down. That to me was like the most fun part of audit.

Speaker A: You, you want to know what the least fun part was, was actually looking at the sheet with the invoice numbers and then the checks that are tied attached to the invoice and going one by one and looking at it on the document and then looking at it on the list and then checking off. Yes, that number is the same.

Speaker B: Yep. It's. It's a, uh, drawing the text box over, putting a tick mark, and then, you know, all the annotating, like, yes, that has to exist. You can't get around that. But, man, if that could be automated, how great would that be?

Speaker A: Right.

Speaker B: If, you know, you're able to go from having a population file to select samples from. To the testing results in the dashboard that delivers, that is done. Right. How cool would that be if that entire process. And it sounds so like fantasy, but that's what technology should be doing.

Speaker A: Yeah.

Speaker B: And then now you have that, uh, you're performing operational audits, you're reassessing risk, not just doing an annual Sally exercise. You're actually cementing time there. And then it's. You have more time to develop your audit plan, and your audit plan is much more operational effectiveness.

Speaker A: I love to just spend, uh, spend a couple minutes just picking some selections and then shipping it on, off and being like, okay, here's all the selections. Go pull the evidence and check it. Go vouch it, go trace it.

Speaker B: It's not even. Even the sample selection should be automated. Right. And it's like, no, Once you get a entire file, you assess the reliability of that file, completeness and accuracy, you ship it off, and then it's like the testing's all done. You know, that's, uh. Now that's a lot of automation, but that's where it should exist. Right. That's the point I'm trying to make is like, it's in the process. It's in the administrative aspect of your job. You know, that that aspect should be. It should be automated at this point.

Speaker C: Sure.

Speaker A: Uh, so I think one of the things that I want to segue this into our business philosophy section, because I think one of the issues is you talk about tone at the top, and it depends on, are you a product person, are you a CEO, co founder, who's a product person, or are you a business person? Obviously, the ideal is a hybrid of both, which is one of the benefits, I think, at Flowcast, of Mike Whitmire, who is an accountant at Core, also a business owner and founder, doing an accounting product. Right. So it all works together. Plus, I would make the argument accountants are very qualified for having the full knowledge of a business, of what it takes. But you have these, you have different types of uh, founders, especially now with all these AI and tech companies that are either very product focused and they don't really understand the implications on the business side, or you have the hated person who's just the business person who doesn't care about the product and they're doing whatever it takes to just drive the bottom line. Is it better for one or the other? Because I think the product person might neglect a lot of the automation of like they may be very forward thinking on automation of how they can use it if they're a tech company, for example. But oftentimes I think like the accounting functions and compliance functions are like an afterthought of automation. Whereas it's like, well, let's automate our workflow and let's automate how we get social media posts out and let's automate the process of, I don't know, ordering food for the pantry. You know what I mean? Everything else will come first on the things we need to automate list, except for compliance, where that is I think one of the benefits of somebody who is an experienced business side side of house vet, who understands no, this is an important thing that we do need to invest in.

Speaker B: Yeah, absolutely. I think, um, the way I view it is there's like three types of CEOs. There's the, the founder, product evangelist and you know, they understand the culture very well, they understand the product vision very well. Right. I'd say that's, that's, that's Mike for us.

Speaker A: Yep.

Speaker B: Um, but then you have the um, the like the disruptive CEO.

Speaker C: Right.

Speaker B: The one that's kind of. Well, let me take a step back. So first you have the founder, right. They sort of understand the vision, they understand the market and very motivated and bring a lot of, to the culture of the, the um, organization also could also, you know, that's Tony at the top as well. Right. How serious do they take compliance at the onset? Then? Um, you have your, your organizational. Keep things the same. Right. Everything's already operating as it needs to. Right. For whatever reason, you know, the founder, uh, you know, is no longer here. But just keep things the same. And that's a very like compliance focused CEO. Uh, right. Let's focus on operational efficiencies. Let's make sure that we're driving, you know, the revenues, where it needs to be growth is, is on a good trajectory. But like, you know, if market conditions change or you know, there's Some sort of pivot needed that. That's a tough place for that CEO. Right. They're not the seasoned. They're just, they're going to, just keeping things the same focus on compliance.

Speaker A: It's your blue chip. I everything. It's your blue chip. You know, it's a blue chip.

Speaker B: Yeah. CEOs. Right? Just seasoned CEOs that can lead a large organization. Just very good at that. Then you have your like disruptive CEOs. Things need to pivot. We need to change. We need to uh, we need to be disruptive in the market. And I'd argue this is where like we see Mike now, where it's like we, he is leading Flowcast and being disruptive into an industry and trying to convince people that this type of technology can exist. And I think it's often funny sometimes you see people are just like, I don't believe it. Nope. It's too, too in tune to what I expect it to do. It can't be this easy.

Speaker A: I do think that CEOs now there's a demand for more disruption than there was ever in the past. Because you see this in every market. The fluctuation is crazy. I mean from, from things that the inflation has gone up through the roof to other industries where it's, you know, uh, the price of cable went up, up, up and then eventually cable disappeared and then now it might be coming back, you know, because you have this, the streaming wars resulting in all these consolidations. So that's the thing. TVs used to be so expensive, now TVs, nobody even wants them for Black Friday anymore. And they're like, uh, it's not any different than the one last year. It's all the same. You can get a thousand inch TV for a thousand bucks. So who really cares anymore, right? And it just, it's. The industries are changing so quickly that you can't really afford to be your blue chip CEO anymore. Who's just there to maintain. I mean obviously the mega massive companies, sure. But it almost means like we think we can ride this out through our lifetime on a slow plateau, maybe even a slow slight decline. But you really with how quickly industries change. Like if you want to stay relevant, you have to be ready to every couple years be shifting and growing. And that's definitely exhausting I would say for companies. But to kind of circle it back to the whole point of this whole thing. If you have processes and systems in place that enable the things that have to be getting done to keep getting done that will free up People across the board. You need workflows to free up your creative thinkers. You need workflows automation and, and tasks administrative burden to be handled so that your finance and accounting professionals can be thinking more strategic and you want all of that in place so that your leadership can feel confident that everything that needs to get done is getting done at the company. And you're not worried about becoming non compliant or something falling through the cracks or a project flopping because all the baseline stuff's being covered and your people are thinking innovative and that can help push the whole entire organization to always be at the front end of that curve as opposed to getting pummeled by the wave that's already crashing and you're just getting sucked in and thrown back out and you'll lose so much energy trying to swim out of that riptide.

Speaker B: Yeah. I mean if, yeah again things are always changing. Just makes the compliance roll that much more important and it's very over overthought and I think again. But it just comes from the tone at the top where what, how do we treat compliance? Because again compliance shouldn't be like I think the, the reporting requirements and the compliance requirements just do a great job of getting you to try to think the right way. But from there you've got to take it into what's specific to your own organization.

Speaker A: Yeah.

Speaker B: And that involves some thinking that people shouldn't overlook.

Speaker A: Absolutely. Taking it to our final section here. Make meme. Lol. Uh, I found this one which I couldn't believe it was even real. And this is again a little throwback to our favorite folks over at ftx. The former co CEO of FTX Digital Markets, Ryan Salome is headed to federal prison today to serve a 7.5 year sentence. He made sure to update his LinkedIn profile today to reflect his new role. I think this came from liquidity actually it makes some like sense that he would post that. Uh, I'm happy to share. I'm starting a new position as an inmate at FCI Cumberland. I mean making a joke of this is, is absolutely absurd. Especially after you caused so many people total heartache and financial devastation. And it just highlights again the tone of the top was that we don't really care about compliance and we never have and we never will.

Speaker B: I agree. I think there's some rehabilitation to take place there.

Speaker A: Mhm. Uh, I mean just for context for those who are not familiar with all the compliance issues with ftx, we obviously know about the outlandish lifestyle at the top and the spending of all the investors money. And then when, when goes crypto, so does the, the broker that's got all their money held up in it. Uh, internal controls. FTX had almost no internal controls, lacked oversight and risk management practices. That's at the very base, the very initial thing is like, okay, well we tried to implement controls. Now they didn't try to have any internal controls. And that's where you, when you're starting the company it starts with that. Obviously there's the advanced levels of compliance, but it starts with just having some basic internal controls. Not even a shot. Bookkeeping. They didn't even have, they had poor record keeping, uh, due to the use of auto deleting applications like Snapchat, like they were using Snapchat for the business. Could you imagine, I mean could you just imagine you talk about your approvals, an email at least you can print that out. A Snapchat, you imagine a thumbs up on a Snapchat from your CEO. Like yeah, you can wire that $3 million. Like that's, that's crazy. Um, obviously because of this, the financial statements were unreliable. Which goes back to the, the auditors. Where's the independence? You know, how are you not doing your job in that. Which is why they got hit with the two million dollar fine which perhaps isn't even enough. I don't know how they, I don't know how with all of these things, these factors, they got any sense of any sort of assurance whatsoever. Um, confidential data was being mishandled, Corporate funds were being diverted to purchase homes for employees. Um, they had no centralized control of company cash. The uh, so Prager Metis, which is the auditor, issued audit reports that falsely claim to comply with gas, which is obviously a blatant lie. So I don't know how they even get that in there unless they were getting paid off to be like, yeah, just say this is fine. Um, and then the, the obviously they had the whistleblower lawsuit alleged that the FTX's chief compliance officer tried to bribe an internal whistleblower. When your compliance officer is bribing

Speaker B: your

Speaker A: internal, your, you know, an internal whistleblower, I mean, I mean it's just, that's absolutely insanity. Um, and then of course in the financials itself, the leak balance sheet showed that there was a lack of diversification and a negative $8 billion balance.

Speaker B: Yeah, you think of worst case scenarios. This is it. They're, they're, they're. Every time you take on a new client in audit like you, you're required to do some kind of assessment on the company, like is this a reasonable or is this, is this a reliable company that we want to take on? Is there any risk here? And gosh, the number of red flags that go off on here, it's just, it's amazing. Um, and, and there are audits. Like I, I was very grateful to work with people that were morally, uh, you know, aligned, you could say. Um, there are clients that we turned down. It was like, no, this is just too risky, can't take this on. But something the size of ftx, someone's going to take that on.

Speaker A: Yeah, and that's, I mean just, it's, that's like your cookie cutter example of like, here's every single type of compliance issue that you can make and we have it all.

Speaker B: We have it all.

Speaker A: I mean, I mean that's, that, that's uh, that almost gives me an idea for like a short film of like the, the, the un, the non compliant company. It's in like opposite land. You know, Tuesday's opposite day, right? And it's just like we're going to do everything the opposite of, you know, internal controls. No, we have none. Centralized, um, you know, control, uh, of cash. No, anybody who wants cash. I mean like no controls. All right, that's enough of FTX and that's enough of the fintech flow. So I'm going to take it to our concluding cycle. I thought we, we had obviously this awesome conversation on all, all things compliance. Jason, it's always great having you back here on the show and uh, I do want to talk about one monumental moment which this episode is airing during the World Series. And obviously as a New Yorker natively, uh, I'm in this precarious situation because I'm a Mets fan. Um, and Mets and Yankees are not typically ones who get along, but also, you know, the Dodgers beat the Mets and knocked them out. So. But I also, my grandfather was a Brooklyn Dodgers fan. All this, um, to say the Mets did leave us with, with, with one treat. And I don't know if you knew this and I don't know if anybody at home knew this, but over the past hundred years a fin. A major financial crisis has coincided with a team from Philadelphia winning the World Series. 1929, 30, 1980, 2008 almost happened again a few years ago and they lost. The Mets were able to knock out the Philadelphia Phillies. So I believe we have averted another major financial crisis.

Speaker B: You're already winners.

Speaker A: We're winners.

Speaker B: You're already winners.

Speaker A: And I think, you know, given that I reside in both New York and la, I don't think I can lose. Right. You know, I think uh, all I, all I can do is win. Now that doesn't mean I'm not going to have compliance in place to make sure that uh, I'm still you know, making sure that the back door is covered. But I'm, I'm trucking forward like a winner.

Speaker B: There you go. No, it's gonna be a good series. I'm excited. I mean it's two storied franchises ironically. Uh, don't they have the two highest payrolls?

Speaker A: The Mets, the Yankees and the Dodgers are the highest payroll teams. Um, the Dodgers are currently the last, the lowest, the lowest payroll team in the MLB playoffs. Um, spoiler. There's only two teams left and they are the underdog. Then there you go. Because they're not getting. But the interesting thing is, and I think we talked about this before the show is the teams actually regardless of where your payroll is. Right? Because you have down to the Oakland A's or in the I think upper 30 millions like $40 million below 40 million in, in payroll. Whereas you have the Dodgers yet Mets, Yankees who are in the 300 million dollar range. Huge discrepancy. The difference in, in how many games are win is like you know, the best teams win 60% of games and the worst teams win 40% of games. So it's one of those things where I do want to talk about this at some point on, on a show with somebody who's can really give a cost benefit analysis of. Is there really the ROI on some of these star star players when it's, are they really helping you win that much more where it's really worth the hundreds of millions of dollars in difference of payroll that it costs.

Speaker B: Yeah, that's, that's for another podcast. You could probably do a whole episode on that.

Speaker A: I uh, also want to know what the compliance is like at these sports organizations. They got so much money, right. They got to be able to invest in it. Right? They can, they can invest in, can invest in compliance.

Speaker B: There's a couple sports teams on full cast so they. Yeah, that's cool. They care about it.

Speaker A: It's good. It's good to see they care. It's good to see everybody who's care. It's good to see you again. Jason. Thanks for being here for this episode. Hope everybody enjoyed and we'll see you next time. This has been the fintech flow.

Speaker B: Thanks for having me.

Speaker A: Thanks for checking out the fintech flow. As a reminder, this episode is available for CPE credit, and you can get that at Flow Academy or on the Earmark app. Details are in the description below.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • When GRC Stops Watching and Starts Working ft Ryan Schoeller, Director of Security & GRC @ Treasure DataSecurity & GRC Decoded · on Three lines of defense model85 / 100
  • Why corporate culture mattersSpeaking of Risk and Audit · on Three lines of defense model83 / 100
  • Lessons from a finance revolution at Mars, with Colin MossFP&A Today · on Internal audit81 / 100
  • Chief Compliance Officer role explained. Jennifer Geary and Natalie McManus explore compliance leadership, strategy, and decision-making.RiskMasters · on Three lines of defense model70 / 100
  • Culture, Compliance and Humanizing Fraud Risk - Dr. Ursula Schmidt - Episode 168Fraud Talk · on Internal audit69 / 100
  • The AI Risk Posture Playbook for BoardsThe Digital Transformation Playbook · on Three lines of defense model49 / 100

More from The FinTech Flo

All episodes →
  • Why the Feds Just Called Accountants 'Non-Professionals'+ Is NVIDIA the Next Enron?70 / 100
  • The $3.8M NBA Fraud, AI's Dirty Secret & The Dodgers as a Tech Startup62 / 100
  • CPAcon, A Gaming Convention for Accountants! Is This The Future?! - Ep. 4057 / 100
  • Let’s Get Fiscal and Make Some Bets on the Future - Ep. 3967 / 100
  • Welcome to the FinTech Flo!
Explore the best B2B Finance podcasts →
All The FinTech Flo episodes →