Top Banner
How to Conduct an Effec/ve Social Media Audit Pete Sco7, APR @prsco7 flickr.com/photos/lendingmemo/
67
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: PRSA presentation auditing social media presented by PeteScott, APR @prscott

How  to  Conduct  an  Effec/ve  Social  Media  Audit

Pete  Sco7,  APR  @prsco7

flickr.com/photos/lendingmemo/

Page 2: PRSA presentation auditing social media presented by PeteScott, APR @prscott

Overview• The  Disconnect    

• How  I  Got  Here  

• The  Major  Risks    

• A  Governance  Structure    

• The  Social  Media  Audit    

• Three  Cases  

• Ques/ons  

Page 3: PRSA presentation auditing social media presented by PeteScott, APR @prscott

disconnect

flickr.com/photos/nikonvscanon/

Page 4: PRSA presentation auditing social media presented by PeteScott, APR @prscott

Our  Influencers

Page 5: PRSA presentation auditing social media presented by PeteScott, APR @prscott

What  They  Say• How  good  the  company  is  in  leveraging  the  various  social  media  tools?  !

• How  good  the  company  is  in  engaging  with  the  target  audience?  !

• How  good  the  company  is  in  amplifying  its  messages?  !

• How  good  the  company  is  in  targe/ng  customers?  !

• How  good  the  company  is  in  building  posi/ve  influence  among  customers?

Page 6: PRSA presentation auditing social media presented by PeteScott, APR @prscott

This  is  all  necessary,  but..

Page 7: PRSA presentation auditing social media presented by PeteScott, APR @prscott

C-­‐Suite  and  Board  Influencers

Page 8: PRSA presentation auditing social media presented by PeteScott, APR @prscott

What  they  saySocial  media  oversight  is  lagging  in  firms  !The  evalua;on  and  monitoring  of  risk  needs  to  be  a  key  component  of  any  organiza;on’s  social  media  strategy    !Organiza;ons  do  not  have  an  adequate  social  media  governance  program  in  place  !For  all  its  advantages,  social  media  also  brings  inherent  risks,  including  threats  to  confiden;al  informa;on,  intellectual  property,  and  reputa;on  as  well  as  the  poten/al  for  regulatory  infrac/ons  !Governance  for  social  media  compliance  remains  fragmented      

Page 9: PRSA presentation auditing social media presented by PeteScott, APR @prscott

They  are  taking  it    much  further  

Page 10: PRSA presentation auditing social media presented by PeteScott, APR @prscott

How  I  Got  Here

Page 11: PRSA presentation auditing social media presented by PeteScott, APR @prscott

Trained  over  5,000  internal  auditors  globally  Most  of  the  Fortune  500    All  of  the  Big  Four  and  major  professional  services  firms  

Page 12: PRSA presentation auditing social media presented by PeteScott, APR @prscott

What  Went  Wrong?  • United  Airlines  -­‐  baggage  handling  -­‐  YouTube      

• Nestle  -­‐  product  sourcing  -­‐  Facebook  

• Francesca  Holdings  -­‐  financial  communica/ons  -­‐  Twi7er    

• Dell  -­‐  customer  service  -­‐  Blog  

• Chrysler  -­‐  third  party  agency  -­‐  Twi7er    

• Taco  Bell  and  Domino’s  Pizza  -­‐  employee  training  -­‐  Facebook  &  YouTube  

Page 13: PRSA presentation auditing social media presented by PeteScott, APR @prscott

What  Went  Wrong?  • Kenneth  Cole  -­‐  employee  training  -­‐  Twi7er    

• Hooters  -­‐  employee  policies    

• ADT  -­‐  disclosure  -­‐  Twi7er  and  Facebook  

• Delta  Airlines  -­‐  Twi7er    

Proac/vely  Solved  Issue:  

• Best  Buy  -­‐  employee  compensa/on  -­‐  Twi7er  

Page 14: PRSA presentation auditing social media presented by PeteScott, APR @prscott

Major  Risk  Areas• Brand  &  Reputa/on  Risk    

• Strategic  Risks    

• Technology  and  Data  Leakage  Risks  

• Third  Party  Risks    

• Legal  Risks    

• Governance  Risks  

Page 15: PRSA presentation auditing social media presented by PeteScott, APR @prscott

Examples  from  an  Actual  Social  Media  Audit

Page 16: PRSA presentation auditing social media presented by PeteScott, APR @prscott

Brand  &  Reputa/on  Risk

flickr.com/photos/89275439@N07/

Page 17: PRSA presentation auditing social media presented by PeteScott, APR @prscott

Brand  &  Reputa/on  Risk  Iden%fying  Risk    • Accelerated  Corporate  Reputa/on  Loss  

• CASE:    TripAdvisor  Ra;ngs    • Financial  Loss  from  Inaccurate  Social  Media  Posts    • Ineffec/ve  Crisis  Management  

• CASE:  Discovery  Communica;ons  • Accelerated  Consumer  /Employee  Dissa/sfac/on  

• CASE:  Dell  Hell  

Page 18: PRSA presentation auditing social media presented by PeteScott, APR @prscott

Brand  &  Reputa/on  Risk  Mi%ga%ng  Risk    • Social  Media  Strategy,  Plans  and  Metrics  aligned  with  Business  

Objec/ves    • Social  Media  Policies    • Employee  Training    • Social  Media  Monitoring    • Social  Media  Triage  • Incident  Escala/on  Policies  and  Procedures

Page 19: PRSA presentation auditing social media presented by PeteScott, APR @prscott

Brand  &  Reputa/on  Risk  Mi%ga%ng  Risk    • Account  Inventory    

• Person(s)  Accountable  • Ac2vity  Level    • Content  Ownership  • Account  Ownership  &  Iden2fica2on    

• CASE:    Dell,  Delta  and  TD  Bank    • Content  Taxonomy    

• Oversight    • On  Message?    • Achieving  Objec2ves?      

Page 20: PRSA presentation auditing social media presented by PeteScott, APR @prscott

Strategic  Risk

http://blog.90octane.com/

Page 21: PRSA presentation auditing social media presented by PeteScott, APR @prscott

Strategic  Risk  Iden%fying  Risk    • Lack  of  Enterprise  Strategy    • Failure  to  fully  leverage  Social  Media  Opportuni/es  to  full  poten/al    

• Inability  to  determine  return  on  investment  of  social  media  • CASE:  NAVC  

• Speed  of  Service  Inadequate  for  consumers    and  employees  • CASE:  Delta  Airlines    

• Lack  of  resource  commitment  to  social  media  impac/ng  consumers

Page 22: PRSA presentation auditing social media presented by PeteScott, APR @prscott

Strategic  Risk  Mi%ga%ng  Risk    • Social  Media  Strategy  • Tracking  and  KPI’s  • Professional  Development  • Business  Case  for  Social  Media

Page 23: PRSA presentation auditing social media presented by PeteScott, APR @prscott

Technology  Risks

Page 24: PRSA presentation auditing social media presented by PeteScott, APR @prscott

Technology  &  Data  Leakage  Iden%fying  Risk    • Data  Leakage    

• CASE:  DM  from  CEO  • CASE:  TheOldCFO  

• Increase  in  Cyber  Threats    • Lack  of  Auditability

Page 25: PRSA presentation auditing social media presented by PeteScott, APR @prscott

Technology  &  Data  Leakage  Mi%ga%ng  Risk    • Social  Media  Policies  • Employee  Training  • Social  Media  Monitoring  • Data  Archiving  • IT  Security  

Page 26: PRSA presentation auditing social media presented by PeteScott, APR @prscott

Third  Party  Risk

Page 27: PRSA presentation auditing social media presented by PeteScott, APR @prscott
Page 28: PRSA presentation auditing social media presented by PeteScott, APR @prscott

Third  Party  RisksIden%fying  Risk  • Lack  of  Control  over  Agency  Rela/onships  • Lack  of  Func/onality  Control  on  Third  Party  Sites    

• POTENTIAL  CASE:    Facebook  • Lack  of  Business  Con/nuity  onThird  Party  Sites    

• POTENTIAL  CASE:    TwiUer  • Lack  of  Content  Control  on  Third  Party  Sites  

• CASE:  Novar;s  • Lack  of  Control  over  Hijacked  Accounts  for  Fake  Sites  

• CASE:  Farmer’s  Insurance  • Lack  of  Control  over  Depar/ng  Employees

Page 29: PRSA presentation auditing social media presented by PeteScott, APR @prscott

Third  Party  RisksMi%ga%ng  Risk  • Set  expecta/ons  on  employee  training  and  oversight  in  agency  agreements    

• Conduct  periodic  audits  of  the  agency  • Set  goals,  expecta/ons,  metrics,  policies  and  accountabili/es        • Establish  social  media  monitoring  program,  even  if  using  an  agency  for  monitoring      • CASE:  Major  SoVware  Company  

• Establish  escala/on  and  triage  policies      • Establish  policies  and  tes/ng  plan  for  removing  access  to  social  media  accounts  

Page 30: PRSA presentation auditing social media presented by PeteScott, APR @prscott

Legal  Risk

Page 31: PRSA presentation auditing social media presented by PeteScott, APR @prscott

Legal  RisksIden%fying  Risk  • Expansive  Federal  and  State  Legal  and  Regulatory  Concerns  

• Inadequate  Contracts    

• Online  Bullying/  Harassment  /  Personal  Reputa/on  

• Negligent  Hiring  &  Reten/on  Liability

Page 32: PRSA presentation auditing social media presented by PeteScott, APR @prscott

Governance  Risks

Page 33: PRSA presentation auditing social media presented by PeteScott, APR @prscott

Governance  Risks

Page 34: PRSA presentation auditing social media presented by PeteScott, APR @prscott

Doing  What  You  Are  Supposed  to  Do

Page 35: PRSA presentation auditing social media presented by PeteScott, APR @prscott

Governance  RisksIden%fying  Risk  • Lack  of  Enterprise  Governance    • Lack  of  Compliance  • Inadequate  Policies    • Inadequate  Training

Page 36: PRSA presentation auditing social media presented by PeteScott, APR @prscott

U.S.  Guidelines• FTC  -­‐  Social  Media  Disclosures    

• NLRB  -­‐  Social  Media  Policies    

• HIPPA  -­‐  Healthcare  Disclosure    

• FFIEC  -­‐  Banks  and  Financial  Ins%tu%ons    

• SEC/FINRA  -­‐  Financial  Advisors    

• FDA  -­‐  Pharmaceu%cal

Page 37: PRSA presentation auditing social media presented by PeteScott, APR @prscott

U.S.  Guidelines• TTB  -­‐  Alcohol    

• State  Guidelines  -­‐  Insurance  Companies  

• CASE:  Farmer’s  Insurance      

• ASRC  -­‐  (NAD)  Self  Regula%on  in  Adver%sing  

• Others  -­‐  Compensa%on,  Harassment,  Employment  

Page 38: PRSA presentation auditing social media presented by PeteScott, APR @prscott

FTC  Guidelines

State of Sponsored Social Report Izea.com (December 2013)

h7p://www.olshanlaw.com/resources-­‐events-­‐Webinar-­‐Digital-­‐Social-­‐Media-­‐Promo/ons.html

Page 39: PRSA presentation auditing social media presented by PeteScott, APR @prscott

Establishing  a  Governance  Structure

Page 40: PRSA presentation auditing social media presented by PeteScott, APR @prscott

Relying  on  one  department  or  person  is  inadequate,    but  it  does  need  a  leader  

Page 41: PRSA presentation auditing social media presented by PeteScott, APR @prscott

Team  Effort  • Managing  social  risk  is  oaen  found  in  numerous  business  units    

• Communica/ons    

• Marke/ng    

• Customer  Service    

• Product  Development  

• IT  

• Human  Resources  

• Legal  

• Internal  Audit  

Page 42: PRSA presentation auditing social media presented by PeteScott, APR @prscott

Governance  Architecture• The  governance  architecture  should  detail:  

• Social  Media  Objec;ves  -­‐  strategy,  objec;ves  and  goals    

• Departmental  responsibili;es    

• Individual  accountabili;es    

• Brand  guidelines  

• Approval  processes  and  procedures    

• Training  

Page 43: PRSA presentation auditing social media presented by PeteScott, APR @prscott

Why  You?  

Page 44: PRSA presentation auditing social media presented by PeteScott, APR @prscott

Why  You?  • Though  the  risk  might  not  happen  in  your  area,  it  will  probably  become  your  issue    

• Why  are  we  doing  this?      

• How  did  this  happen?      What  did  you  do?    

• Chances  are,  you  manage  or  have  influence  over:    

• The  voice,  brand,  reputa/on,  ac/vi/es,  strategies,  plans  and  monitoring    

• An  opportunity  to  demonstrate  value  at  the  highest  levels  

Page 45: PRSA presentation auditing social media presented by PeteScott, APR @prscott

How  to  Audit    Social  Media

Page 46: PRSA presentation auditing social media presented by PeteScott, APR @prscott

The  Audit  Process

Identify Risk

Assess Risk

Identify Controls

Assess Controls

Develop Plan

Page 47: PRSA presentation auditing social media presented by PeteScott, APR @prscott

Objec/ves  of  an  AuditIden/fica/on  of  Risks  • Iden;fy  all  poten;al  risks    • Assess  likelihood  and  significance      • Set  priori;es    !Controls  to  Mi/gate  Risks      • Verifying  documents,  policies,  procedures  and  ac;vi;es    !Tes/ng    • Is  the  procedure  followed?  • Could  the  procedure  be  improved?  • Could  work  prac;ces  be  improved?  • Is  risk  mi;gated?    • Are  opportuni;es  leveraged?    

Page 48: PRSA presentation auditing social media presented by PeteScott, APR @prscott

Risk  Assessment

Significance  

Risk  Ra/ng Descrip/on  

Managable Small  impact,  able  to  recover  with  minor  effort

Major   Medium  to  serious  impact,  able  to  recover  with  serious  effort  

Cri;cal Very  serious  impact,  very  difficult  recovery  

Likelihood

Risk  Ra/ng   Descrip/on  

Remote Small  impact,  able  to  recover  with  minor  effort

Possible Possible  and  could  occur  during  the  period  

Likely Expected  to  occur  

Page 49: PRSA presentation auditing social media presented by PeteScott, APR @prscott

Risk  Assessment

Medium High Critical

Low Medium High

Low Low Medium

Significance

Manageable

Major

Critical

Remote Possible Likely Likelihood

Page 50: PRSA presentation auditing social media presented by PeteScott, APR @prscott

Controls• Exis/ng  Controls  

• Plans    

• Policies  

• Processes  

• Ac/vi/es    

• Control  Objec/ves    

• Gaps  in  Controls  

Page 51: PRSA presentation auditing social media presented by PeteScott, APR @prscott

Tes/ng• Iden/fy  Gaps  and  Inadequate  Controls      

• Develop  Work  Plan  to  Close  Gaps  

Page 52: PRSA presentation auditing social media presented by PeteScott, APR @prscott

Three  Cases• Francesca  Holdings  -­‐  Inappropriate  Tweets  by  CFO    

• Hooters  -­‐  Social  Media  Policy    

• Best  Buy

Page 53: PRSA presentation auditing social media presented by PeteScott, APR @prscott

Risks:  • Employee  Use  of  Social  Media  • Lack  of  Iden/fica/on  of    Inappropriate  Posts

Page 54: PRSA presentation auditing social media presented by PeteScott, APR @prscott

Francesca  HoldingsThe  Issue:    Inappropriate  Tweets    by  Gene  Morphis,  CFO  -­‐  Francesca  Holdings  !March  6  2012  he  tweeted:    !"Dinner  w/Board  tonite.  Used  to  be  fun.  Now  one  must  be  on  guard  every  second."    !March  7,  2012  he  tweeted    !"Board  mee/ng.  Good  numbers=Happy  Board.”  !Stock  increased  15%  

Page 55: PRSA presentation auditing social media presented by PeteScott, APR @prscott

Francesca  Holdings

The  Result  -­‐  On  May  14,  2012  !

CFO  Fired  Stock  temporarily  dropped  by  more  than  20%  

Page 56: PRSA presentation auditing social media presented by PeteScott, APR @prscott

Audit• Risk  was  Iden/fied:    Employees  Use  of  Social  Media,  especially  as  a  public  company    

• Risk  was  Assessed:    Likelihood  and  Severity  Assessed    

• Controls  Established:    Employee  Policies  Were  in  Place  

• Controls  Tested:    There  was  inadequate  training  on  use  of  policy  and  there  was  a  lack  of  monitoring  of  key  employees  

• Work  Plan:    Reassess  Policy  and  Training  Plan,  Update  Monitoring  Plan    

Page 57: PRSA presentation auditing social media presented by PeteScott, APR @prscott

Risk:  Out  of  Date  Policies

Page 58: PRSA presentation auditing social media presented by PeteScott, APR @prscott

Alexis  Hanson

Result  A  New  York  Na;onal  Labor  Rela;ons  Board  judge  ruled  that  a  Hooters  franchise  cannot  force  its  employees  to  act  in  a  respecaul  manner  toward  customers,  nor  could  managers  punish  employees  for  

insubordina;on.

The  Issue:    A  Tirade  Over  A  Rigged  Bikini  Contest

Page 59: PRSA presentation auditing social media presented by PeteScott, APR @prscott

Courtesy

 Courtesy:  Courtesy  is  the  responsibility  of  every  employee.  Everyone  is  expected  to  be  courteous,  polite  and  friendly  to  our  customers,  vendors  and  suppliers,  as  well  as  to  their  fellow  employees.  No  one  should  be  disrespecaul  or  use  profanity  or  any  other  language  which  injures  the  image  or  reputa;on  of  the  Dealership.

Page 60: PRSA presentation auditing social media presented by PeteScott, APR @prscott

Audit• Risk  was  Iden/fied:    Employees  Disrespect  and  Use  via  Social  Media  

• Risk  was  Assessed:    Likelihood  and  Severity  Assessed    

• Controls  Established:    Employee  Policies  Were  in  Place  

• Controls  Tested:    The  Policy  Was  Not  Updated  in  Light  of  Updated  NLRB  Guidelines    

• Work  Plan:    Update  the  Policy  and  Communicate  and  Train  All  Staff

Page 61: PRSA presentation auditing social media presented by PeteScott, APR @prscott

Risk:  Employee  Compensa/on

Page 62: PRSA presentation auditing social media presented by PeteScott, APR @prscott

Best  Buy  

Result  As  Best  Buy  developed  a  plan  to  compensate  associates  for  Twelpforce,  

so  they  can  answer  ques;ons  on  TwiUer  from  customers

The  Issue:    Compensa/ng  Employees  for  Social  Media  Engagement

Page 63: PRSA presentation auditing social media presented by PeteScott, APR @prscott

Audit• Risk  was  Iden/fied:    Employees  Needed  to  be  Compensated  for  Work  

• Risk  was  Assessed:    Likelihood  and  Severity  Assessed    

• Controls  Established:    A  Compensa/on  Program  was  Developed  

• Controls  Tested:    Were  Employees  Compensated?    Review  of  Payroll  Records  was  Conducted    

• Work  Plan:    Periodic  Review  of  Compensa/on  Records  as  well  as  Tweets  to  Mi/gate  Employee  Fraud

Page 64: PRSA presentation auditing social media presented by PeteScott, APR @prscott

It  Can  Take  Time  !

But  the  Benefits    Can  Be  Huge

Page 65: PRSA presentation auditing social media presented by PeteScott, APR @prscott

!

If  Internal  Audit  Comes,  It’s  Much  Be7er  To

Page 66: PRSA presentation auditing social media presented by PeteScott, APR @prscott

Ques/ons?  

Page 67: PRSA presentation auditing social media presented by PeteScott, APR @prscott

Thank  You.    

Peter  Sco7,  APR    !

[email protected]  !

@prsco7