Click HERE to download this section
Cloud Computing
Trends
- Given exponential data growth,92 cloud computing is becoming a necessity. There is an increasing use of third-party cloud services such as governance, risk management, and compliance (GRC) and audit management tools for organizations to manage and document their controls. In particular, the COVID-19 pandemic ushered in a new era of cloud-based Software as a Service (SaaS – software distribution models in which a cloud provider hosts applications and makes them available to end users over the internet). In this model, an independent software vendor may contract a third-party cloud provider to host the application or alternatively, with larger organizations, the cloud provider might also be the software vendor.93
Opportunities
- Cloud computing marks a significant shift from the traditional way businesses think about IT resources.94 One of the biggest impacts is in relation to cost and scalability. Use of cloud eliminates the capital expense of buying, operating, and maintaining local hardware and software and setting up and running on-site data centers. At the same time, it enables more rapid scaling by changing the service agreement for IT resources with the vendor as needed (i.e., more or less computing power, storage, bandwidth). In addition, cloud computing makes data backup, disaster recovery, and business continuity easier and less expensive because data can be mirrored at multiple redundant sites on the cloud provider’s network.
Impact/Risks
- Stakeholders observed that whether a firm or company decides to use a cloud provider typically involves the following considerations:
- Security concerns, given the sensitivity of data being processed and stored outside the organization’s direct control (potential market sensitive data, private employee and client data, industry-specific considerations, etc.).
- Legal, regulatory, and/or professional compliance requirements, such as data sovereignty laws that require data to remain within a particular jurisdiction.
- Many organizations or firms already use the cloud for their data and accounting systems. When a cloud provider is used, the provider stores data and information related to the particular organization or firm and/or its clients or customers. Hence, the organization or firm must ensure that the provider implements necessary security measures. Designing and implementing an appropriate data governance and management framework that might not have traditionally existed has become a priority, especially in the face of increasing, and ever more sophisticated, cyberattacks. It was noted that this might be particularly challenging for small- and medium-sized entities and practitioners who potentially lack the budget, resources, and negotiating influence needed to engage cloud service providers.
- Stakeholders indicated that it is challenging to keep up with the direction of evolving data privacy and cybersecurity regulations and best practices. Other important pain points to watch in data governance are: (a) data collection, including the quality of metadata management, (b) data access and controls, and (c) objectivity in data analytics. See discussion on Focus on Data Governance.
- For firms in particular, providing cloud-based services has raised questions over when holding client information and data constitutes “hosting” by a firm, and whether this is permissible or is seen to be assuming a management responsibility. See discussion on Independence.
Endnotes
92 “Data: a small four-letter word which has grown exponentially to such a big value.” Deloitte, https://www2.deloitte.com/cy/en/pages/technology/articles/data-grown-big-value.html.
93 Chai, Wesley. “Software as a Service (SaaS).” TechTarget, October 2022, https://www.techtarget.com/searchcloudcomputing/definition/Software-asa-Service.
94 Microsoft has produced a concise and easy to understand guide to the key benefits, types, and service types of cloud computing, including SaaS. See “What is cloud computing? A beginner’s guide.” Azure, https://azure.microsoft.com/en-ca/resources/cloud-computing-dictionary/what-is-cloudcomputing/.