Skip to main content
Category: Fraud Risk Management

Data Analytics

Simply put

Data analytics is the process of collecting, organizing, and examining data to find patterns and trends and to draw conclusions that support decision-making. It turns raw data into meaningful insights, often using specialized tools and techniques to make information easier to understand. In a governance, risk, and compliance setting, it is generally used as a tool to support activities such as monitoring, testing, and reporting rather than as a discipline in itself.

Formal definition

Data analytics generally refers to the set of processes, tools, and technologies used to collect, transform, analyze, interpret, and visualize datasets in order to identify patterns and trends, draw conclusions, and inform decisions. Depending on the source, its scope may range from descriptive analysis of raw data to techniques supporting prediction. Within governance, risk, and compliance functions it is typically applied as a technique to enhance activities such as risk assessment, control testing, transaction monitoring, and management reporting; its specific application, ownership, and reliability depend on the facts, the function deploying it, and the professional's own judgment. This entry is educational and not legal, audit, or compliance advice.

Why it matters

Governance, risk, and compliance functions depend on the ability to draw reliable conclusions from large and often complex datasets. Data analytics converts raw data into meaningful insights that can support monitoring, testing, and reporting, allowing functions to identify patterns and trends that might not be visible through manual review of individual records. As the volume and complexity of organizational data grow, analytics has become an increasingly important technique for helping assurance and compliance professionals focus their attention where it is most needed.

The value of data analytics in a GRC setting comes from its role as a supporting tool rather than a standalone discipline. It can enhance activities such as risk assessment, control testing, transaction monitoring, and management reporting, but it does not replace the professional judgment, oversight, and accountability that these activities require. The reliability of any insight depends on the quality of the underlying data, the appropriateness of the technique applied, and the competence of the person interpreting the results.

Because outputs from analytics can inform significant decisions, it matters greatly who owns a given analytics activity, how the results are validated, and how they are reported. Overreliance on analytics without an understanding of its limitations, data quality issues, or the assumptions built into a technique can lead to misplaced confidence. The specific application, ownership, and reliability of any analytics work depend on the facts, the function deploying it, and the professional's own judgment.

Who it's relevant to

Internal Auditors
Internal audit may use data analytics to test controls, examine full transaction populations rather than samples, and identify anomalies that warrant follow-up. Analytics can enhance the efficiency and coverage of audit procedures, but auditors remain responsible for exercising professional judgment, validating the underlying data, and understanding the limitations of the techniques applied.
Chief Compliance and Risk Officers
Compliance and risk functions may apply analytics to support transaction monitoring, risk assessment, and reporting. Analytics can help these functions focus attention on higher-risk areas, but it supplements rather than replaces the design and operation of the underlying monitoring and risk management processes, which remain owned by the relevant function.
The Board and Its Committees
Boards and committees such as audit and risk committees are typically consumers of insights produced through data analytics, particularly in management and assurance reporting. Their oversight role includes understanding the basis and limitations of analytics-driven conclusions and challenging the reliability of the information on which decisions rest, without assuming operational responsibility for the analytics itself.
Management
Management generally owns the operational deployment of analytics within business processes, including data quality, tool selection, and the interpretation of results in day-to-day decision-making. Management is responsible for ensuring that analytics used in monitoring and reporting is fit for purpose and that its outputs are appropriately validated.

Inside Data Analytics

Descriptive Analytics
Techniques that summarize historical data to describe what has occurred, such as aggregating transactions, reconciling balances, or profiling populations. In governance, risk, and compliance work, this is typically the entry point for understanding a data set before more advanced analysis.
Diagnostic Analytics
Analysis aimed at explaining why something happened, often through drill-down, root-cause exploration, or correlation. It generally supports investigations and control failure analysis but does not by itself establish causation.
Predictive and Prescriptive Analytics
More advanced techniques that estimate the likelihood of future outcomes or suggest actions. These typically depend on model quality, data completeness, and assumptions, and their outputs are estimates rather than certainties.
Continuous Monitoring and Full-Population Testing
The use of analytics to test entire data populations rather than samples, on an ongoing or periodic basis. This capability is generally leveraged differently by management (as a first-line control), by compliance monitoring functions, and by internal audit (as assurance), and accountability for each use differs by line of defense.
Data Quality and Governance
The controls, definitions, lineage, and ownership that determine whether underlying data is complete, accurate, and reliable. Analytics conclusions are generally only as sound as the data and the documented assumptions behind them.
Visualization and Reporting
Dashboards and reports that present analytical results to management, committees, and the board. The intended audience and its decision rights should shape what is presented, since oversight bodies and operational management use the same outputs for different purposes.

Common questions

Answers to the questions practitioners most commonly ask about Data Analytics.

Does deploying data analytics mean an organization has achieved continuous monitoring or continuous auditing?
Not necessarily. Data analytics is a technique for examining data to identify patterns, anomalies, or relationships; it is a tool rather than an operating model. Continuous monitoring is typically a management activity embedded in first-line processes, while continuous auditing is generally an assurance activity performed by internal audit. Analytics can support either, but simply running analytical queries, especially on an ad hoc or periodic basis, does not by itself constitute a continuous approach. Whether monitoring is truly continuous depends on the frequency, automation, and governance around how the analytics are applied, and on which function owns the activity.
Do analytics results provide assurance or prove that a control is operating effectively?
Analytics generally produce indicators, exceptions, or risk signals rather than conclusions about control effectiveness on their own. Distinguishing control design from operating effectiveness still requires professional judgment and, often, corroborating evidence. An analytic that flags outliers highlights items warranting investigation; it does not establish that a control was designed appropriately or operated as intended throughout a period. Assurance conclusions typically depend on how the results are scoped, validated, and interpreted by the responsible function, and analytics do not replace that judgment.
Which function should own a data analytics capability, management, internal audit, or compliance?
This depends on the purpose of the analytics and where accountability sits, and the same tool may be used by different functions for different ends. First-line management may use analytics to run and monitor processes; a compliance function may use them for compliance monitoring; internal audit may use them for assurance. To preserve independence, analytics used by internal audit for assurance are generally kept distinct from analytics management relies on for its own control activities. Organizations often clarify ownership, data access, and reporting lines up front so the roles of each line are not blurred. The right structure depends on facts, mandate, and applicable independence expectations.
How should data quality be addressed before relying on analytics output?
Because analytics conclusions are only as reliable as the underlying data, practitioners typically assess completeness, accuracy, and the relevance of the source data before drawing inferences. This can include reconciling extracted data to authoritative sources, understanding how fields are defined and populated, and documenting data lineage and any transformations. Where data quality is uncertain, results are generally treated as directional rather than conclusive. The appropriate level of validation depends on how the output will be used and the significance of the decisions it informs, and remains a matter of professional judgment.
How can false positives from analytics be managed so investigation effort stays proportionate?
Analytics that flag anomalies commonly generate exceptions that turn out to be benign, so a practical approach is to refine thresholds, rules, and logic over time based on the outcomes of prior investigations. Some teams prioritize exceptions by likelihood and potential impact so effort is focused where risk is greatest, and document rationale for tuning decisions. Distinguishing a high volume of low-significance flags from a smaller set of higher-risk items helps keep follow-up manageable. What counts as an acceptable rate of false positives depends on the objective, risk appetite, and available resources.
What documentation and governance typically support analytics used in a GRC context?
Practitioners generally document the objective of an analytic, the data sources and period covered, the logic or rules applied, any assumptions and limitations, and how results were reviewed and dispositioned. This supports repeatability, review, and, where relevant, the ability of others to rely on or challenge the work. Governance considerations often include access controls over sensitive data, version control of scripts or models, and clarity about who is accountable for the analytic's outputs. The extent of documentation expected varies by the analytic's purpose, the function performing it, and applicable internal standards; these entries are educational and not audit, legal, or compliance advice.

Common misconceptions

Data analytics is an internal audit tool, so its results belong to the assurance function.
Analytics can be deployed across all three lines. Management (first line) may use it to operate and monitor controls, compliance or risk functions (second line) may use it for monitoring and oversight, and internal audit (third line) may use it to provide independent assurance. Which function owns a given analytics activity, and the accountability that attaches to it, depends on how and by whom it is used; the same technique does not carry the same role in each context.
Analyzing the full population instead of a sample proves that controls are operating effectively.
Full-population testing can improve coverage over the design and outputs of controls, but analytics generally evidences what the data shows, not necessarily whether a control was designed appropriately and operated effectively throughout a period. Control design and operating effectiveness remain distinct questions that typically require professional judgment beyond the analytical result.
Predictive analytics quantifies risk with precision and can replace risk assessment judgment.
Predictive outputs are estimates dependent on data quality, model assumptions, and context. They can inform assessments of likelihood and impact but do not substitute for the qualitative judgment, risk appetite, and oversight responsibilities that sit with management and the board. Outputs should be treated as inputs, not conclusions.

Best practices

Define the intended use and owning function before building an analytic, and confirm whether it is a first-line operational control, a second-line monitoring activity, or a third-line assurance procedure, since accountability and independence expectations differ.
Establish and document data quality, lineage, and ownership for source data, and disclose the completeness and reliability limitations of the data alongside any analytical conclusions.
Document the assumptions, logic, and thresholds behind each analytic so results are reproducible and can be reviewed, and treat predictive or prescriptive outputs as estimates that inform, rather than replace, professional judgment.
Keep the distinction between what the data shows and whether a control is well designed and operating effectively; use analytics as evidence to inform those conclusions rather than as the conclusion itself.
Tailor visualization and reporting to the audience's role and decision rights, distinguishing information provided to management for operational action from information provided to the board and its committees for oversight.
Periodically validate and recalibrate analytics for changes in data structures, business processes, and applicable requirements, recognizing that obligations and thresholds vary by jurisdiction, sector, and entity type.