Krishna Priyan

Case Studies

The CEO’s Dashboard Lied Every Morning

A Case Study on Data Integrity and Why Accurate Reports Can Still Lead to Bad Decisions Every morning at 8:00 AM, the CEO of a rapidly growing manufacturing company reviewed the executive dashboard. Revenue was on target, production efficiency exceeded expectations, inventory levels appeared healthy, and customer orders were steadily increasing. The reports were generated directly from the ERP system, eliminating manual intervention and ensuring complete accuracy. Yet, the business was struggling. Customer deliveries were consistently delayed, inventory shortages disrupted production, profit margins were shrinking, and working capital requirements continued to increase. Management couldn’t understand how a company with such positive performance indicators could be facing so many operational challenges. From an internal audit perspective, the dashboard wasn’t wrong—it was incomplete. Every figure displayed on the dashboard was technically accurate. The problem was that each department reported its own success without showing how its performance affected the business as a whole. Procurement measured purchase cost savings, production measured output volume, sales measured revenue, and finance measured collections. Individually, every KPI was being achieved. Collectively, they were driving conflicting decisions. Procurement purchased materials in bulk to reduce unit costs, increasing inventory carrying costs. Sales pushed aggressive month-end targets, resulting in unrealistic production schedules. Production maximized machine utilization by manufacturing products that weren’t immediately required, while finance delayed payments to preserve cash, affecting supplier relationships and material availability. The dashboard reflected departmental achievements, but it failed to reveal enterprise-wide consequences. My audit approach would focus on evaluating data integrity beyond numerical accuracy. I would assess how KPIs were designed, how information flowed between departments, and whether executive reports represented the complete business picture. The review would examine whether dashboards encouraged balanced decision-making or unintentionally rewarded siloed performance. The recommendation would be to redesign executive reporting around integrated business metrics rather than isolated departmental achievements. KPIs should demonstrate relationships between profitability, inventory turnover, customer service, cash flow, production efficiency, and operational risk. A dashboard should not simply report what happened—it should explain why it happened and what decisions it should influence. Key Takeaway The greatest risk is not inaccurate data—it is accurate data presented without context. Internal audit should evaluate not only whether reports are correct, but whether they enable leaders to make the right decisions. A dashboard becomes truly valuable when it connects business performance across functions, revealing insights instead of simply displaying numbers.

The CEO’s Dashboard Lied Every Morning Read More »

Auditing Trust

A Case Study on Measuring Organizational Culture Beyond Financial Controls Trust is one of the most valuable assets an organization possesses, yet it rarely appears on a balance sheet. Companies invest millions in technology, compliance programs, and internal controls to manage financial risks, but few evaluate whether employees trust leadership, whether departments trust one another, or whether communication enables informed decision-making. Ironically, many operational failures originate not from weak financial controls, but from environments where trust has quietly deteriorated. Consider an organization where employees hesitate to report mistakes because they fear blame. Managers avoid escalating issues to senior leadership to protect performance ratings. Departments operate in isolation, withholding information instead of collaborating. On paper, policies are followed, reports are submitted, and compliance appears satisfactory. Beneath the surface, however, decisions are delayed, risks remain hidden, innovation slows, and small problems evolve into major business disruptions. From an internal audit perspective, the question should not simply be, “Are controls operating effectively?” It should also be, “Do people trust the environment enough to make those controls effective?” My audit approach would focus on organizational behaviours rather than financial transactions. The review would assess communication channels, accountability mechanisms, leadership accessibility, issue escalation practices, cross-functional collaboration, and employee willingness to report concerns. Anonymous surveys, structured interviews, and process walkthroughs would help identify whether employees feel empowered to raise risks or whether critical information is being filtered before reaching decision-makers. The objective would not be to assign a numerical trust score, but to identify patterns that influence organizational performance. Frequent blame-shifting, repeated communication breakdowns, unresolved audit observations, or consistently low participation in feedback mechanisms may indicate deeper cultural weaknesses that no policy manual can resolve. The recommendations would focus on strengthening leadership transparency, promoting open communication, clarifying accountability, encouraging constructive reporting of mistakes, and ensuring that employees are recognized for identifying risks rather than criticized for exposing them. Trust should be viewed as a business control that enables every other control to function effectively. Key Takeaway Internal audit has traditionally focused on evaluating systems, policies, and financial controls. However, even the strongest control framework cannot succeed in an environment where trust is absent. When employees trust leadership, communicate openly, and take ownership of risks, compliance becomes a natural outcome rather than an enforced obligation. Auditing trust is not about measuring culture—it is about understanding whether the organization’s people and processes are working together to achieve sustainable success.

Auditing Trust Read More »

The Perfect SOP That Everyone Ignored

A Case Study on Human Behavior, Process Design, and Why Compliance Isn’t Enough A manufacturing company had invested significant time and resources in developing its Standard Operating Procedures (SOPs). Every critical process—from procurement and inventory management to quality inspections and finance approvals—was documented in detail. Employees received training, manuals were available on the company intranet, and every audit confirmed that the required documentation existed. Yet operational issues continued to occur. Purchase requests bypassed approval workflows, inventory movements were recorded late, quality checks were skipped during peak production, and manual workarounds became routine. Management questioned why employees weren’t following procedures despite having clear instructions. From an internal audit perspective, the problem wasn’t a lack of policies—it was a lack of practicality. The SOPs had been designed around the ideal process, not the reality of day-to-day operations. Employees were expected to complete lengthy approval chains under tight deadlines, navigate multiple systems for a single transaction, and perform repetitive documentation that added little operational value. Over time, informal shortcuts replaced formal processes—not out of negligence, but because they helped employees get their work done. Rather than asking, “Why didn’t employees follow the SOP?”, I would ask, “Why did the process encourage employees to bypass it?” The audit would focus on observing how work was actually performed on the shop floor, in warehouses, and across business functions. Interviews with employees would help identify where procedures created delays, duplicated effort, or failed to reflect operational realities. Each deviation would be evaluated to determine whether it represented a control weakness or an opportunity to redesign the process. The recommendation would not be stricter enforcement or additional documentation. Instead, the organization should simplify approval workflows, eliminate unnecessary process steps, automate repetitive controls through ERP systems where possible, and involve employees in updating SOPs based on practical experience. Effective controls should fit naturally into the way people work rather than forcing people to work around them. Key Takeaway An SOP is only valuable if people can realistically follow it. Internal audit should measure not only whether procedures exist, but whether they are practical, efficient, and aligned with human behavior. The strongest control environment is not built on the thickest policy manual—it is built on processes that employees can follow consistently without sacrificing productivity.

The Perfect SOP That Everyone Ignored Read More »

The Meeting That Cost ₹2 Crore a Year

A Case Study on Auditing Time, Meetings, and Decision-Making Every Monday morning, the leadership team of a growing manufacturing company gathered for a three-hour operations meeting. Directors presented reports, managers explained delays, department heads reviewed KPIs, and action items were assigned. Similar meetings took place throughout the week across procurement, finance, production, sales, and quality assurance. No one questioned the meetings. After all, meetings were considered part of running the business. However, despite hundreds of meeting hours each month, the same operational issues kept resurfacing—late approvals, production bottlenecks, delayed vendor payments, repeated customer complaints, and projects that consistently missed deadlines. From an internal audit perspective, I would ask an unconventional question: What if meetings were treated like financial transactions? Every hour spent in a meeting has a cost. When ten managers earning senior-level salaries spend three hours discussing decisions that could have been made in thirty minutes, the organization is investing valuable resources without measuring the return. Unlike capital expenditure or procurement, meeting time is rarely audited, even though it directly affects productivity, decision speed, and operational efficiency. My audit approach would begin by mapping the organization’s meeting ecosystem. I would evaluate the number of recurring meetings, attendees, duration, objectives, decision outcomes, and follow-up actions. Particular attention would be given to identifying duplicate meetings, unnecessary approval discussions, repetitive reporting, and decisions that required multiple meetings before implementation. The review would also examine whether meetings were creating value or simply replacing effective decision-making. If the same issue appeared in weekly meetings without resolution, it would indicate a process failure rather than a communication success. Rather than recommending fewer meetings, I would recommend better governance. Routine updates could be replaced with dashboards, approvals delegated within defined authority limits, and every recurring meeting assigned measurable outcomes, owners, and decision timelines. Meetings should exist to solve problems—not to postpone them. Key Takeaway Organizations carefully audit cash, inventory, and assets because they recognize their value. Yet one of the most expensive resources—management time—is often left unmeasured. Internal audit should extend beyond financial controls to evaluate how decisions are made, how time is invested, and whether every meeting contributes to business performance. Sometimes, the biggest operational loss isn’t hidden in the balance sheet—it’s sitting in the boardroom.

The Meeting That Cost ₹2 Crore a Year Read More »

Why Every Department Thought Someone Else Owned the Risk

A Case Study on Ownership Gaps and Organizational Accountability A rapidly growing manufacturing company was experiencing recurring operational issues. Purchase orders were delayed, vendor payments were frequently disputed, production schedules slipped without warning, and customer complaints were steadily increasing. Individually, none of these incidents appeared severe. Collectively, however, they were costing the business significant time, money, and customer trust. When senior management initiated an internal review, every department had a logical explanation. Procurement believed production should have forecasted demand more accurately. Production pointed to delayed material deliveries. Finance argued that approvals from department heads were incomplete. Quality maintained that defects originated during manufacturing, while Operations believed supplier performance was the root cause. Everyone had an answer. No one had ownership. From an internal audit perspective, the problem was not process failure—it was ownership failure. Every function had clearly documented responsibilities, yet the risks that existed between departments had no defined owner. The organization had invested heavily in policies and systems, but very little attention had been given to accountability for cross-functional risks. Rather than auditing departments independently, I would map the complete business process from customer order to product delivery. The objective would be to identify every point where work changed hands between functions. These transition points often expose the greatest risks because responsibilities become blurred, approvals are delayed, and assumptions replace accountability. The review would focus on questions such as: Instead of recommending additional controls, I would recommend establishing clear risk ownership across every critical business process. Each key operational risk should have a designated owner, measurable accountability, escalation procedures, and regular cross-functional reviews. Performance metrics should reward collaboration, not just departmental success. Key Takeaway Businesses rarely lose money because departments fail independently. They lose money because critical risks exist in the spaces between departments, where everyone is involved, but no one is accountable. Effective internal audit is not just about evaluating controls—it is about ensuring every significant business risk has a clear owner before it becomes everyone’s problem.

Why Every Department Thought Someone Else Owned the Risk Read More »

The Employee Who Never Broke a Rule—But Cost the Company Millions

A Case Study on Incentive Design vs. Compliance A leading consumer goods company had a star performer in its sales division. Every month, he exceeded his sales targets, earned performance bonuses, and was consistently recognized as one of the organization’s top employees. Quarterly reviews praised his discipline, productivity, and ability to deliver results. From an audit perspective, there was nothing unusual—every transaction was approved, every policy was followed, and every report matched the company’s records. Yet, despite record sales, the company’s profitability continued to decline. Management initially suspected pricing issues, rising procurement costs, or operational inefficiencies. However, a closer examination revealed a different story. The sales incentive program rewarded employees solely based on revenue generated, without considering profitability, customer payment behavior, or long-term business value. To maximize his incentives, the employee consistently offered steep discounts within his approved authority, prioritized high-volume but low-margin products, and aggressively pushed inventory to distributors near month-end to meet targets. None of these actions violated company policy, yet together they eroded margins, increased product returns, and tied up working capital in unsold inventory. From an internal audit perspective, the employee was never the problem—the incentive system was. Rather than investigating individual behaviour, the audit would focus on evaluating whether performance metrics encouraged decisions that aligned with the organization’s strategic objectives. The review would assess the relationship between sales incentives, gross margins, customer profitability, return rates, receivable aging, and inventory movement. Discussions with business leaders would also determine whether success was being measured by sustainable value creation or simply by short-term revenue. The recommendation would not be additional controls or stricter compliance checks. Instead, management should redesign the performance framework to balance revenue with profitability, cash collections, customer retention, and quality of sales. Incentives should encourage decisions that strengthen the business rather than merely improve individual performance metrics. Key Takeaway Internal audit should not stop at asking, “Did employees follow the rules?” The more important question is, “Did the rules encourage the right behaviour?” A well-designed control environment is not just about preventing misconduct—it is about ensuring that good employees are rewarded for making good business decisions.

The Employee Who Never Broke a Rule—But Cost the Company Millions Read More »