Showing posts with label Big Data. Show all posts
Showing posts with label Big Data. Show all posts

Tuesday, January 3, 2023

Welcome to 2023! What are five key tech trends that CPAs should be aware of?

With the crypto-ice age in effect, there is some rethinking on crypto and NFTs path in 2023. Here is CNBC's take: 


However, there are still a number of key tech trends that Chartered Professional Accountants (CPAs) should be aware of in order to stay up-to-date and competitive in the industry. These trends include cloud computing, artificial intelligence and machine learning, big data, cybersecurity, and digital transformation. By understanding and leveraging these technologies, CPA firms can improve their operations and better serve their clients.

1. Cloud Computing: Cloud computing involves delivering computing services, including servers, storage, and databases, over the internet rather than using local servers or personal devices. CPA firms can benefit from cloud computing by being able to access data and applications from any location, as well as scaling up or down as needed. For more on cloud and the world of CPAs, check out this post

2. Artificial Intelligence and Machine Learning: AI and machine learning technologies can help CPA firms automate routine tasks, improve decision-making, and gain insights from data. For example, chatbots are now able to generate fully coherent posts using natural-language processing. We covered this in our last post, with the rise of ChatGPT. If you haven't checked it out, it is must read. 

3. Big Data: Businesses are generating and collecting a large amount of data from a variety of sources, including financial transactions, social media, and internet of things (IoT) devices. Tools such as data visualization and advanced analytics can help CPA firms make sense of this data and extract valuable insights. In the early days of big data, I put this post together. It captures the hope and potential - much of which still needs to be realized.

4. Cybersecurity: Cybersecurity is a critical concern for CPA firms, as they often handle sensitive financial and personal data. It is important for CPA firms to have robust cybersecurity measures in place to protect against cyber threats such as hacking, ransomware, and phishing attacks. I've always felt that Cyber is a natural extension for CPAs. We're not just versed in the concept of controls, but also the realities of auditing those controls - an increasingly important way of conveying of compliance to a variety of stakeholders. See here for CPA Canada's list of resources.

5. Digital Transformation: Digital transformation refers to the use of digital technologies to fundamentally change how an organization operates and delivers value to its customers. CPA firms can benefit from digital transformation by streamlining processes, improving efficiency, and increasing agility. This may involve adopting new technologies such as cloud computing, AI, and big data, as well as rethinking business models and organizational structures. See here for more on the topic. 

In closing, it is important for CPA firms to stay informed about the latest tech trends in order to take advantage of new opportunities and meet the changing needs of their clients. By embracing technologies such as cloud computing, artificial intelligence and machine learning, big data, cybersecurity, and digital transformation, CPA firms can improve their efficiency, effectiveness, and competitive edge. By staying up-to-date with these trends, CPA firms can continue to deliver value to their clients and succeed in an increasingly digital business environment.

Author: Malik Datardina, CPA, CA, CISA. Malik works at Auvenir as a GRC Strategist that is working to transform the engagement experience for accounting firms and their clients. The opinions expressed here do not necessarily represent UWCISA, UW, Auvenir (or its affiliates), CPA Canada or anyone else

Sunday, January 10, 2021

Data Tsunami: How big is the Data Deluge? (Part 1)

Was invited last year to speak about the Data Tsunami at the AICPA Engage conference, but I didn't quite make it there! Instead, I presented virtually

So, will be breaking out some of the topics that I will be discussing over a few blog posts. 

How big is the data tsunami?

Probably, the first thing that comes to mind is social data. The Internet truly unleashed the first torrent of the data tsunami. Google's search index alone is 100,000,000 GB. In terms, of social data we are looking at the following:

  • Twitter: 200 billion tweets per year (Twitter)
  • Facebook: 4 petabytes of data per day (WEF)
  • WhatsApp: 65 Billion Messages per day (WEF)
  • YouTube: 250 million hours per day (Variety)
  • Apple: 50 billion podcasts downloads (Fast Company
It's interesting how the data tsunami encompasses print, sight and sound. This is of course lends itself to analytics, but we will discuss that in a future post.

In terms of organizational data, Walmart generate 2.5 petabytes of data per hour. According to American Banker, 12 million petabytes (per year) of data flows through the financial industry. In terms of manufacturing, 6,000 fan blades manufactured by Rolls Royce generates 3 petabytes. It gives an idea of how much data is generated by the millions of parts that go into airplanes, trains and automobiles.

In terms of medical data, Stanford published the following

“The sheer volume of health care data is growing at an astronomical rate: 153 Exabyte…were produced in 2013 and an estimated 2,314 Exabyte will be produced in 2020, translating to an overall rate of increase at least 48 percent annually.”

This obviously has tremendous privacy concerns

How big will the data tsunami get? 

A couple of key contributors to this 'tsunami of data', will likely be the Internet of Things (IoT). 


IDC predicts that 40+ billion IoT devices will generate 79.4 ZB of data by 2025. The other generation of 'digital exhaust' will likely be autonomous vehicles, which according to Intel produce about 4 terabytes of data per hour

But the big question is so what?  

We'll take a look at this question in the next post. 

Author: Malik Datardina, CPA, CA, CISA. Malik works at Auvenir as a GRC Strategist that is working to transform the engagement experience for accounting firms and their clients. The opinions expressed here do not necessarily represent UWCISA, UW, Auvenir (or its affiliates), CPA Canada or anyone else.




 

Thursday, July 16, 2020

'The Algorithm Made Me Do It': How Racist-Tech led an African-American man sleeping in a filthy cell

We've heard of Fintech, maybe even Regtech, but have we heard of Racist-Tech?

In the past few weeks, the US sees the largest protests in its history. I am not referring to the protests where armed protestors show up to state-capitals without much reaction. Rather, these are the protests that were in response to the death of George Floyd. George Floyd who died after a police officer kneeled on his neck (with his hands in his pocket) for eight minutes and forty-six seconds. These protests, in contrast, have been met with a strong reaction.

A related incident occurred a few months before Mr. Floyd lost his life.

As reported in NPR, Robert Julian-Borchak Williams was picked up by police by January 2020 and when he got to the station, he was surprised to the lack of resemblance between him and the pictures of the suspect.

The officer's response? "So I guess the computer got it wrong, too." 

Regardless, "Williams was detained for 30 hours and then released on bail until a court hearing on the case, his lawyers say."

(For more on the story, check out this video)

The story is chilling, to say the least.  The knee jerk reaction is to think of Skynet and dark AI. But is that really what's happening here?

The social unrest speaks to how the desegregation struggles of the 1960s have not totally succeeded. The challenge is that racism is systemic. Within the institutions that hold society together, the gothic systems that existed in the 1950s somehow still exist until today. Sure, it's illegal for prosecutors, judges and cops to be racist. But then how do we explain the treatment of George Floyd and Robert Williams? Is there is no overall monitoring provisioning to ensure that the desired equality is achieved? For example, good monitoring controls over a system would assess the outcomes to see if the desired outcomes are achieved. There was a case that tested this idea. In McClesky v Kemp, where the defence team provided Dr. Baldus's study that statistically proved that the African American is 4.3 times more likely to get the death penalty, the "big data" analysis was rejected and Warren McClesky was put to death by the state. (And yes it controlled for 35 non-race variables).

In other words, data analysis shows there actually is a problem. However, the courts essentially denied this reality and pretended everything is okay.

What does this have to do with Racist Tech?

It means that the systems and the data are biased. Racist Tech will naturally grow out of such systems. AI and predictive policing models that use data from the court system - also pretending everything is okay - will inevitably lead to people like Mr. Williams getting caught up in the criminal justice system. Compared to George Floyd he only had to spend 30 hours in a filthy cell. But during that time he would have no idea whether it was going to be 30 hours or 30 months, given how long it takes to exonerate the innocent.

I was once asked at a conference whether we can look forward to a future where AI takes over. My response was to point out the real issues is with the human that run the technology.  If I had to answer that question today, I would simply ask them to call Mr. William who knows that the nightmare scenario is here already.

Author: Malik Datardina, CPA, CA, CISA. Malik works at Auvenir as a GRC Strategist that is working to transform the engagement experience for accounting firms and their clients. The opinions expressed here do not necessarily represent UWCISA, UW, Auvenir (or its affiliates), CPA Canada or anyone else.



Sunday, February 9, 2020

What do the Sony Car and the Visa acquisition of Plaid have in common?

Visa announced in early that they were going to buy Plaid for $5.3 billion. Who is Plaid, and why are they worth so much? 

According to the CNBC article that published the announcement: 

“Plaid’s API software, often referred to as the “plumbing” behind fintech companies, lets start-ups connect to users’ bank accounts. It’s well-known among financial technology developers, but the average person interacting with it most likely wouldn’t recognize the name. High-profile Plaid customers include popular peer-to-peer payment app Venmo, mobile investing app Robinhood and cryptocurrency exchanges Coinbase and Gemini.”

The article went on to note that about 25% of American bank account holders have “connected” the company’s app. 

Meanwhile, at the Consumer Electronics Show (CES), Sony unveiled its electric concept car, the Vision-S, in Las Vegas earlier this month. 

The car is a novel way for Sony to market its various technologies within the automotive space. The approach is not dissimilar from what Microsoft did with the Surface Book: allowing each company to put their stake in the ground as to what they see as the ‘art of the possible.’ 

This TheVerge video does an excellent job of highlighting its features and showing what the car:



Although these two innovations occur in vastly different fields, they speak to a common reality: data. The concept of big data has been with us for a while, but what separates it from innovations like AI and blockchain is that its underlying elements can give us insights into how a particular innovation lies on the value spectrum:
  • Cars are increasingly being “datafied.” According to Intel, autonomous vehicles will produce about 4 terabytes of data per day. So it should be no surprise that Sony’s concept car looks to harness the power of data. According to Time, the car has “33 sensors inside and outside the car” that help with ensuring the safety of passengers by detecting external threats and internal threats (e.g. falling asleep at the wheel). Coindesk takes this one step further, speculating that this type of move will help auto-makers more broadly make machine-to-machine cryptocurrency payments a reality. 
  • Plaid and the value of verified data: The Plaid acquisition highlights the “4th V” that some use – veracity. Visa's purchase of Plaid illustrates how “boring data” that is of how quality can be worth billions of dollars. But such value proposition is not limited to the financial realm. Blockchain databases can offer a similar value proposition, as they force standardization and data quality standards. 

In future posts, we will test this model further to see how the four Vs: volume, variety, velocity and veracity help us understand the value of up-and-coming technologies and trends. 

Author: Malik Datardina, CPA, CA, CISA. Malik works at Auvenir as a GRC Strategist that is working to transform the engagement experience for accounting firms and their clients. The opinions expressed here do not necessarily represent UWCISA, UW, Auvenir (or its affiliates), CPA Canada or anyone else

Sunday, September 30, 2018

Google Traffic, Time zones and Train Travel: What's the connection?

Had an interesting conversation about Google Traffic with my step-daughter the other day. Originally, my wife was supposed to pick her up, but the way things worked out was it made more sense for me to intercept her at the bus station and then bring her back from home. We were able to calculate timings and distance using Google Traffic.


I was explaining to her "life before Google": those days that I would work late at the client only to be stuck in traffic because a game just got out. We don't know how to avoid these jams because we didn't have Google traffic in those days and so we just had to wait it out.

She was a bit bewildered at the prospects of having to plan one's journey without having the benefit of being able to use Google Traffic. She compared to an era when trains didn't have the benefit of centrally coordinated time zones. As explained in this PBS clip, both trains and cities independently maintained their time based on the sun. Consequently, a train passenger had no way of knowing when they would arrive at their destination because the cities didn't coordinate on time. Hence, the invention of time zones.



And that's the connection.

We can no longer can we blame traffic for being late for an engagement, as we should have checked Google Traffic before we left to make sure we are on time. Google Traffic has now become essential to coordinating with others. Even for getting things done more efficiently requires us to leverage such information.  For me, it helped me pick up my step-daughter and made me realize that I hailed from a pre-historic era ;)

Author: Malik Datardina, CPA, CA, CISA. Malik works at Auvenir as a GRC Strategist that is working to transform the engagement experience for accounting firms and their clients. The opinions expressed here do not necessarily represent UWCISA, UW, Auvenir (or its affiliates), CPA Canada or anyone else.

Wednesday, March 28, 2018

Audit, Audit, Audit harked Mark: Can CPAs come to Facebook's rescue?

In an investigation by the Guardian and the New York Times, the alleged misdeeds of Cambridge Analytica were revealed.

As noted in the Guardian article:

"Christopher Wylie, who worked with a Cambridge University academic to obtain the data, told the Observer: “We exploited Facebook to harvest millions of people’s profiles. And built models to exploit what we knew about them and target their inner demons. That was the basis the entire company was built on.”... Documents seen by the Observer, and confirmed by a Facebook statement, show that by late 2015 the company had found out that information had been harvested on an unprecedented scale. However, at the time it failed to alert users and took only limited steps to recover and secure the private information of more than 50 million individuals."

The following video from TheVerge sums up the issue:



Although such allegations have received attention (in my opinion due to the association with Trump's campaign), the reality is that these allegations against Facebook are actually not new and reported in both the Intercept in early 2017 and the Guardian way back in 2015. 

There was an ensuing backlash (as noted in the video above and here) that forced Facebook CEO, Mark Zuckerberg to respond. He both had a written response and gave the following interview on CNN:



During the CNN interview, he mentioned the word "audit" 3 times[emphasis added]:
  • "So we're going to go now and investigate every app that has access to a large amount of information from before we locked down our platform. And if we detect any suspicious activity, we're going to do a full forensic audit"
  • "And we're now not just going to take people's word for it when they give us a legal certification, but if we see anything suspicious, which I think there probably were signs in this case that we could have looked into, we're going to do a full forensic audit."
  • "We know how much -- how many people were using those services, and we can look at the patterns of their data requests. And based on that, we think we'll have a pretty clear sense of whether anyone was doing anything abnormal, and we'll be able to do a full audit of anyone who is questionable."
Can CPAs come to Mark's rescue? 
Zuckerberg's repetitive use of the word audit should be read in conjunction with his "welcoming" of regulation:

"I actually am not sure we shouldn't be regulated. You know, I think in general, technology is an increasingly important trend in the world, and I actually think the question is more what is the right regulation rather than yes or no, should it be regulated?"

Zuckerberg would not be the first tech giant to opt for regulation as a business strategy.

In Tim Wu's Master Switch, Theodore Veil also advocated for the concept of a regulated monopoly in the arena of telephones:

"[Theodore] Vail died in 1920 at age 74, shortly after resigning as AT&T's president, but by that time, his life's work was done. The Bell system had uncontested domination of American telephony, and long-distance communication was unified according to his vision. The idea of an open, competitive system had lost out to AT&T's conception of an enlightened, licensed, and regulated monopoly. AT&T would remain in this form until the 1980s, and it would return in not so substantially different form in the 2000s. As historian Milton Mueller writes, Vail had completed the "political and ideological victory of the regulated monopoly paradigm, advanced under the banner of universal service."" [emphasis added]

As Tim points out in his book, the move enabled AT&T didn't always use their monopolistic powers for good. They charged high long distance rates and even stifled innovation suppressing the answering machine due to potential conflict with its main business.

Regardless, it shows that Facebook could be an early advocate for CPAs offering privacy related assurance services around its algorithms.

AlgoTrust: A new service offering for CPAs? 
The concept of AlgoTrust is something I have previously discussed in this post.

The idea actually has support from multiple angles not least of which of comes from information security expert, Bruce Schneier:

"...it is also worth noting that there are other experts who hold that algorithms - from a privacy perspective - need to be regulated. Bruce Schneier, a well-known information security expert who helped review the Snowden documents, in his latest book, Data and Goliath ... also calls for "auditing algorithms for fairness". He also notes that such audits don't need to make the algorithms public, which is it the same way financial statements of public companies are audited today. This keeps a balance between confidentiality and public confidence in the company's use of our data."

Big Data versus Privacy: The monetization paradox
Such an algo-audit could leverage the work done by AICPA and CPA Canada in the realm of privacy, specifically the Generally Accepted Privacy Principles. That being said, privacy audits have been a hard sell in the past. But what distinguishes the service here is that it would be auditing the algorithm for compliance with privacy "regulations".The reason regulations need to be put in quotes is that in substance privacy legislation is effectively eliminated if the consumer consents to use the service.  

The challenge, therefore, is balancing the drive to monetize big data with the privacy needs of the people who use the service. For example, people who identify with the "left" may not want Steve Bannon or Trump accessing their data. Similarly, people who identify with the "right" may not want Obama accessing their social media data. The end result is that no one can access meaningful data due to privacy restrictions - resulting in a standard so restrictive that it eliminates that ability of companies like Facebook to monetize the treasure trove of data that they have collected.

As noted in an earlier post, there is an inherent highlight the conflict between privacy and profiting from big data. The value of big data emerges from the secondary uses of big data. However, privacy policies require the user to consent to a specific use of data at the time they sign up for the service. This means future big data analytics are essentially limited by what uses the user agreed upon sign-up. However, corporations in their drive to maximize profits will ultimately make privacy policies so loose (i.e. to cover secondary uses) that the user essentially has to give up all their privacy in order to use the service.

There is a lot of potential in attempting to create an assurance service to address Facebook's predicament, but as they say, the devil is in the details. 

Author: Malik Datardina, CPA, CA, CISA. Malik works at Auvenir as a GRC Strategist that is working to transform the engagement experience for accounting firms and their clients. The opinions expressed here do not necessarily represent UWCISA, UW, Auvenir (or its affiliates), CPA Canada or anyone else

Friday, November 3, 2017

Big Data Auditing Revisited: Context is King

It has been a few years since I wrote up on Big Data and the Audit.  It was one of the more popular posts with over a 1,000 hits to date.

The post looks at Big Data: A Revolution That Will Transform How We Live, Work, and Think by Kenneth Cukier and Viktor Mayer-Schönberger. I enjoyed the book as it really broke down the business impact of big data without getting in technical details of the underlying technology.

Why take a second look at big data auditing?

Big data and the accompanying analytical models are key a precursor to artificial intelligence. Machine learning algorithms that power the AI bots requires the users to analyse the problem and teach the underlying algorithm.

Part 1: Context is King

To make things a bit more digestible, I thought it would be good to divide the post into two parts. The first post is more palatable as I want to explore the second use case in a bit more detail and its relevance to today.  The second post will be a bit more controversial as I will take a look at the difficulty of applying fraud or cancer-fighting algorithms in the realm of (external) financial audit.

But let's look at the first issue: how can big data analytics give us better context? 

In the original post, I spoke discussed the use case used in Cukier and Mayer-Schönberger's work around Inrix. The book gives the example of how an investment firm is using traffic analysis, from Inrix, to determine the sales that a retailer will make and then buy or sell the stock of the retailer on that information. In a sense, the investment is using vehicular traffic as a proxy for sales. In an audit context, auditors can develop expectations of what sales should be based on the number of vehicles going around stores. For example, if sales are going up, but the number of vehicles are going down then the auditor would need to take a closer look.

What I realized from this example is that what big data can give auditors better context around things and assess reasonability of things. That is as more sensor data and other data are available to auditors to integrate into statistical models, the more they will be able to spot anomalies. 

One of the issues with Barry Minkow's ZZZBest accounting fraud was the lack of context. For more on the fraud, check this video:

I actually studied this case in my auditing class at the University of Waterloo. One of the lessons we were take away from this case was that the auditors didn't know how much a site restoration would cost on average (see the first bullet in this text on page 129). But how would an auditor be able to access such data? Even with the advent of the internet, it is not simply a matter of Googling for the information.

More recently, an accounting professor was found to have generated data fraudulently. The way he got caught was that a statistic he used didn't correspond to reality. Specifically:

"misrepresented the number of U.S.-based offices it had: not 150, as the paper maintained (and as a reader had noticed might be on the high side, triggering an inquiry from the journal)" [Emphasis added]

Again, the reader had the context to understand what was presented was unreasonable causing the study to unravel and exposing the academic fraud perpetrated by Hunton. 

What will it take to make this a reality? 

What's missing is a data aggregation tool that can connect to the private, third party, and public data feeds that an auditor can leverage for statistical analysis. Furthermore, for this to be useful to clients and the business community large are visualized depictions that enable the auditor to tell the story in a better way rather than handing over complex spreadsheets.

Of course for auditors to present such materials requires them to have deeper training in data wrangling, statistics and visualization tools and techniques. 

In the next post, we will revisit the first use case that I presented in the original post that explored how the New York City was better able to audit illegal conversions through the use of big data analytical techniques. Originally, I had thought this would be a good model to apply in the world of audit. However, I am revisiting this idea. 

Author: Malik Datardina, CPA, CA, CISA. Malik works at Auvenir as a GRC Strategist that is working to transform the engagement experience for accounting firms and their clients. The opinions expressed here do not necessarily represent UWCISA, UW, Auvenir (or its affiliates), CPA Canada or anyone else

Monday, October 2, 2017

What can driving algorithms tell us about robo-auditors?

On a recent trip to the US, decided to opt for a vehicle with the sat-nav as I was going to need directions and wanted to save on the roaming charges. I normally rely on Google Maps for guiding me around traffic jams but thought that the sat-nav would be a good substitute.

Unfortunately, it took me on a wild goose chase more than once – to avoid the traffic. I had blindly followed the algorithm's suggestions assuming it would save me time. I ended up being stuck at traffic lights waiting to a left-turn for what seemed like forever.

Then I realized that I was missing was that feature in Google Maps that tells you how much time you will save by taking the path less traveled. If it only saves me a few minutes, I normally stick to the highway as there are no traffic lights and things may clear-up. Effectively, what Google does is that it gives a way to supervise it’s algorithmic decision-making process.


How does this help with understanding the future of robot auditors?

Algorithms, and AI robots more broadly, need to give sufficient data to judge whether the algorithm is driving in the right direction. Professional auditing standards currently require supervision of junior staff – but the analogy can be applied to AI-powered audit-bots. For example, let’s say there is an AI auditor assessing the effectiveness of access controls and it’s suggesting to not rely on the control. The supervisory data needs to give enough context to assess what the consequences of taking such a decision and the alternative. This could include:

  • Were controls relied on in previous years? This would give some context as to whether this recommendation is in-line with prior experience.
  • What are the results of other security controls? This would give an understanding whether this is actually an anomaly or part of the same pattern of an overall bad control environment.
  • How close is it between the reliance and non-reliance decision? Perhaps this is more relevant in the opposite situation where the system is saying to rely on controls when it has found weaknesses. However, either way the auditor should understand how close it is to make the opposite judgment.
  • What is the impact on substantive test procedures? If access controls are not relied on, the impact on substantive procedures needs to be understood.
  • What alternative procedures that can be relied on? Although in this scenario the algo is telling us the control is reliable, in a scenario where it would recommend not relying on such a control.

What UI does the auditor need to run algorithmic audit?

On a broader note, what is the user interface (UI) to capture this judgment and enable such supervision?

Visualization (e.g. the vehicle moving on the map), mobile technology, satellite navigation and other technologies are assembled to guide the driver. Similarly, auditors need a way to pull together the not just the data necessary to answer the questions above but also a way to understand what risks within the audit require greater attention. This will help the auditor understand where the audit resources need to be allocated from nature, extent and timing perspective.

We all feel a sense of panic when reading the latest study that predict the pending robot-apocalypse in the job market. The reality is that even driving algos need supervision and cannot wholly be trusted on their own. Consequently, when it comes to applying algorithms and AI to audits, it’s going to take some serious effort to define the map that enables such automation let alone building that automation itself.

Author: Malik Datardina, CPA, CA, CISA. Malik works at Auvenir as a GRC Strategist that is working to transform the engagement experience for accounting firms and their clients. The opinions expressed here do not necessarily represent UWCISA, UW, Auvenir (or its affiliates), CPA Canada or anyone else

Saturday, April 1, 2017

Cafe X and Amazon Go: Auditing a robot-operated store?

By now you've probably heard of the robot-barista - Cafe X.  If not check out this video from Wired, where David Pierce walks us not only through how the robot will make your latte, but why he thinks it better than the human alternative:



Amazing isn't it?

In a presentation I did last year on how these forces of automation could impact auditing & accounting, I noted it's easier to see how technology disrupts someone other than you.

And so it looks like baristas have met their match.

As Pierce notes in the video, the inconvenience of dealing with imperfect people is something that most people want to avoid in the rat-race we live in: who wants the barista to remake your coffee 11 times as he says? ;) 

The Wired article also notes that Cafe X is 'high-quality at a cheaper price': 

"Surprisingly delicious coffee, starting at $2.25—cheaper than you’d find at Sightglass or even Starbucks. Cafe X’s location in the corner of the Metreon may not entice you out of your daily routine."

Amazon Go: Walkthrough Technology 
Amazon has also wowed the "techthusiasts" out there with their cashier-less store concept:



In the FAQ section, Amazon summarizes how this cashier-less store works:

"Our checkout-free shopping experience is made possible by the same types of technologies used in self-driving cars: computer vision, sensor fusion, and deep learning. Our Just Walk Out Technology automatically detects when products are taken from or returned to the shelves and keeps track of them in a virtual cart. When you’re done shopping, you can just leave the store. Shortly after, we’ll charge your Amazon account and send you a receipt."

Although this has the potential to revolutionize retail, Amazon has experienced some setbacks of late. The store can allegedly only handle 20 people at a time. So there maybe some kinks to work out before this goes mainstream.

Obviously, this could have a massive impact on entry level jobs: most of us who were young a while ago relied on these McJobs for spending money and funding our college/university tuition. They also gave students some practical work experience to help land a career accounting profession ;)

But let's save this discussion for a future post.

How would you audit cashier-less stores, like Cafe X or Amazon Go?

The retail industry has been a manual intensive industry that requires cashiers, stock room personnel and the like. Such a process naturally requires policies and procedures (aka internal controls) that ensure that merchandise makes it from the shelf to the cash register and into the customers possession. And there are those anti-theft mechanisms to prevent shoplifting as well. In the industry, "shrinkage", the amount of merchandise that is stolen, robbed, damaged, etc, is estimated by the National Retail Federation to be 1.38% of sales or $45.2 billion for 2015.

Cafe X and Amazon Go offer a glimpse into how automating traditional businesses can alter these fundamental risks that impact the way we go about conducting our financial audits.

With Cafe X, shrinkage is almost eliminated as there is no humans involved in the production process. Once the kiosk is loaded up with cups, coffee, syrup, sugar, milk, etc. the system is essentially fully automated - no manual intervention by baristas or customers.

Amazon Go, on the other hand, uses a whole lot of automation that is watching and analyze every move of the customers (and employees) throughout the store. Consequently, this would not be the store to steal from! And let's not forget Amazon is experimenting with those drones and are we really sure that they are unarmed?


Given this level of automation of the actual business process and controls, could auditors stick to the tried, tested and true retail audit procedures? Or would this enable a more automated approach?

I was directly involved with the recent test-audit of the blockchain involving loyalty points. One of the realities of auditing such exponential technologies is that it makes controls testing a must. For example, for the financial auditor to rely on the digital signatures there needs to be some testing around the wallets to ensure that the signatures are reliable.

Consequently, testing such automated stores would require either a SOC2 or modified SOC report to meet the needs of such a store. For example, the SOC2 would need to have some way of having comfort of how the stock and inventory gets loaded into the store. Likely the auditor would rely on the automated process which the store uses to replenish stock, but it's that hand off between the delivery person (assuming it's still human) that would be the area there is a risk of shrinkage. For example, how does legitimately damaged inventory get accounted for at that point? Whatever process and controls Amazon/Cafe X put in place would need to be tested from a controls perspective.

For the substantive component, I think that's where things get interesting: enter the "embedded audit module". This concept has been around since at least 1989. The idea is that the auditor installs independent software onto the client's system and then transmits it back to the auditor, who uses it as a basis for conducting the necessary audit procedures and tests. The core idea is that the auditor has full control over such a system and the client cannot tamper with the code.

What would be relatively straightforward would be the data capture-component: sales data, stock data, spoilage, etc. would be uploaded from the automated store right into the auditor's system. But this then requires the additional step of verifying the data to independent source documents (e.g. invoices, purchase orders, etc.). In other words, the audit procedure would still require manual intervention as the auditee would need to send this information back to the auditor to complete their audit.

Where I think the audit innovation would be is exploring how video footage can act as a substitute for physical/direct observation by the auditor. That is, could the auditor install a video camera in the automated store as a part of the EAM that would then act as actual independent audit evidence of the actual sale or purchase? For example, in the Cafe X example the auditor could actually use the footage and the visual software to count the cups sold that day and reconcile that to the sales data transmitted back from the EAM for the day?

Although one can argue such transactions are not material and therefore such procedures are overkill.

However, I think now is the right time to conduct experiments and test audits to see whether we can reinvent the classic audit to meet the technology of today. In a future post, we will explore what this means broadly for jobs and more specifically how this could impact the profession.

Author: Malik Datardina, CPA, CA, CISA. Malik works at Auvenir as a GRC Strategist that is working to transform the engagement experience for accounting firms and their clients. The opinions expressed here do not necessarily represent UWCISA, UW, Auvenir (or its affiliates), CPA Canada or anyone else

Wednesday, July 27, 2016

Reflections on the demise of Yahoo!

By now we've all heard that Yahoo!'s web assets were bought by Verizon. According to the Wall Street Journal, Verizon paid $4.83 billion in cash for the assets. Yahoo itself will continue to hold the remaining assets but will eventually change its name and become an investment company. In total, the company was rumoured to be worth $6 billion.

For us Gen Xers this is an interesting day: we witnessed the end of a company we saw as innovative and fresh just a "few" (i.e. read ~20) years ago.

I was recently explaining to a young lad in his early 20s about life before the Internet: you had to find books at the library and it was almost impossible to connect socially with people beyond your classmates. So to use Yahoo or other search engines to access information or people was a completely new and mind-blowing concept.

As I noted in this post commemorating Google's 17th anniversary:

"It's especially memorable for those of us who were in university in the late 90s because we had access to high speed internet on campus unlike the painfully slow dial-up at home. 

I remember my first job as a coop student at the UW Federation of Students (I can't believe this quote is still hanging around from that time!) when a co-worker was explaining to me how OpenText was the best search engine (of course using my NetScape Browser). Of course back then there was a number of search engines including, Yahoo, Lyco, Alta Vista, etc. However, I stuck to OpenText for a while then eventually switched, along with everyone else, to Google...Well Lycos, OpenText (as a search engine) and AltaVista may be long gone, but it looks like plaid is back!"

So now we can add Yahoo! to the pile of "has beens" search engine.

Beyond nostalgia, I had the following reflections on the Verizon of Yahoo based on the WSJ article above:
  • Verizon is no longer just pipes: Verizon has a strategy to move beyond just serving mobile and broadband services. Verizon is adding Yahoo to its existing portfolio of content plays, such as AOL. For Verizon, it's an overall strategy to make billions through content and advertising. Net neutrality can potentially limit their ability to use this vertical integration to undermine competition, but regardless it shows how being a "pipes-only" company is not enough. Of course it is a bit ironic that former rivals, Yahoo and AOL, are now sitting in the same tent.  
  • Big Data is monetized at the expense of privacy: The ability of Verizon to combine the data plays between its various content plays is a great illustration of a point that I have noted before: for big data achieve value it must water down privacy. Since there are synergistic values (i.e. instead of just being additive) of combining the data, it could be argued that it's something that a user should explicitly consent because a user may simply not want Verizon to use their Yahoo data this way.  
  • Remember the Internet Bubble? Yahoo! had a market capitalization of "more than $125 billion at the height of the dot-com boom in early 2000", which is quite a steep decline to $6 billion. I wonder if it ever produced the cash flows to justify that valuation. 
  • Algorithms win over people: WSJ today published a good read comparing the algorithmic approach of Google, in contrast manual effort required to index the Internet. This is similar to Amazon's who found that the algorithms to better than humans in getting people to buy things: "Amabot replaced the personable, handcrafted sections of the site with automatically generated recommendations in a standardized layout," according to The Everything Store, a new book exploring the history of Amazon. "The system handily won a series of tests and demonstrated it could sell as many products as the human editors."
  • Innovation and exponential thinking: On a separate note, but related note Yahoo could have bought Google for $3B in 2002 but it didn't. It's a great example of how Google embraced leading-edge technology to deal with the exponential growth of the Internet and Yahoo's inability to recognize Google's approach as the winning approach led to its demise.

Yahoo! is now literally a shell of its former self - both in structure and the assets it holds. However, it's a good case study of how failing to identify exponential trends - and acting on them - can ultimately lead to disaster.

Monday, July 18, 2016

Big Data and Predictive Policing: Can algorithms become racists?

Interesting article on Forbes by Thomas Davenport on Big Data. The articles discusses how various government, including Canadian Public Safety Operations Organization (CanOps), have used big data tools for "situational awareness". These systems draw on myriad sources of data to give users (e.g. law enforcement) the information they need to deal with a particular situation.

Here are a few points that I thought were worth noting:

Government is making strides in big data: We often think of Amazon, Google and other tech-giants as key users of this data. However, as the Davenport points out that the government is using this technology to assist with decision making. However, whether this is something that should be celebrated remains to be seen (see predictive policing below)

Privacy versus Value trade-off: He talks about how CanOps use of MASAS, the Multi-Agency Situational Awareness System, is limited by the filtering of sensitive information: "breadth of MASAS is noble, but it seems to limit its value. For example, as the CanOps website notes, because agencies are reticent to share sensitive information with other agencies, all the information shared was non-sensitive (i.e. not terribly useful)." It seems that this continues to be a theme that we had noted in back a couple years when discussing a similar trade-off the companies face when dealing with big data. As I noted in this post:

"privacy policies require the user to consent to a specific uses of data at the time they sign up for the service. This means future big data analytics are essentially limited by what uses the user agreed upon sign-up. However, corporations in their drive to maximize profits will ultimately make privacy policies so loose (i.e. to cover secondary uses) that the user essentially has to give up all their privacy in order to use the service."

Consequently, there still needs to be a solution as to how privacy can be respected but organizations can use the data they have collected to make better decisions.

Predictive Policing is an emerging reality: The sci-fi movie, Minority Report, paints a future where law enforcement arrests people before they commit crimes.


That future seems to be well on its.  Davenport mentions how "predictive policing" was introduced in 2014 to the NYPD.  He also mentions how much data is being collected by the police:

"It collects and analyzes data from sensors—including 9,000 closed circuit TV cameras, 500 license plate readers with over 2 billion plate reads, 600 fixed and mobile radiation and chemical sensors, and a network of ShotSpotter audio gunshot detectors covering 24 square miles—as well as 54 million 911 calls from citizens. The system also can draw from NYPD crime records, including 100 million summonses."

The idea of predictive policing was also raised in the book,  Big Data: A Revolution That Will Transform How We Live, Work, and Think, which I had explored in a multi-blog post series (click here for the first installment).

Andrew Guthrie Ferguson, Law professor UDC David A. Clarke School of Law, wrote an article on how that predictive policing is something that has not be really sorted in out in terms of legality. He notes:

"The open question is whether this big-data information combined with predictive technologies will create “predictive reasonable suspicion“ undermining Fourth Amendment protections in ways quite similar to the stop-and-frisk practices challenged in federal court.

In two law review articles I have detailed the distorting effects of predictive policing and big data on the Fourth Amendment and have come to the conclusion that insufficient attention has been given at the front end to these constitutional questions. New York has the chance now to address these issues before the adoption of the technology and should be encouraged by the same civil libertarians and ordinary citizens who challenged the stop and frisk policies."

His commentary highlights another limitation: big data predictions are biased based on how the data is collected. The stop and frisk policies he refers to disproportionately targeted minorities. Furthermore, policing is more focused on poor, black/hispanic neighbourhoods. Michelle Alexander documents in her book, The New Jim Crow, how this happens:

"Alexander explains how the criminal justice system functions as a new system of racial control by targeting black men through the “War on Drugs.” The Anti-Drug Abuse Act of 1986, for example, included far more severe punishment for distribution of crack (associated with blacks) than powder cocaine (associated with whites). Civil penalties, such as not being able to live in public housing and not being able to get student loans, have been added to the already harsh prison sentences."

Consequently, if the data by law enforcement is used to predict crime that essentially the targeting of minorities will continue to target such groups given that it is based on biased data. 

Technology often is seen to be a silver bullet for problems. However, we need to keep in mind that it is vulnerable to the human element that makes it. Given Microsoft's recent faux pas of accidentally allowing an AI avatar to become a Nazi, it is something that should actively be considered in the systems that are built to police and govern. 


Friday, November 27, 2015

Will Accountants be Uberized? Part 2: Crowdsourcing and the rise of Pro-Ams

This is part 2 of a series of blogposts that I will write (aiming for 3 parts, but let's see) on how CPAs can be uberized. In this exciting installment, we explore how crowdsourcing and the rise of ProAms (professional amateurs) has altered other professionals, such as photography.

In the last installment, we explored how Uber was actually not a 1:1 replacement of the taxicab profession. Cab drivers fill a social function that ensures that people can from point A to point B safely, accommodates their disabilities and at a regulated rate. However, taxi cab still actively cash out now as we can expect Google to fill in the societal gaps that Uber appears to be unable to. Google could actually revolutionize car ownership by make their driverless cars they sell "ready-to-share" thereby enabling people to benefit from the share economy (imagine your car running around town earning money while work, sleep, play, engage in activism, etc!). Alternatively, they could go own a fleet of cars that people effectively rent in a way that's cheaper than owning a car altogether.

Crowdsourcing as Jeff Howewho authored the original 2006 Wired article that brought notoriety to the concept, where he was trying to describe the phenomenon of using the Internet to outsource work to individuals, defines it as: “is the act of taking a job traditionally performed by a designated agent (usually an employee) and outsourcing it to an undefined, generally large group of people in the form of an open call.”
 In his book he highlights the following uses to illustrate the impact of crowdsourcing on how companies do business:
  • Threadless: Is a great example of how the crowdsourcing brought life into the commodity business of selling t-shirts. In a nutshell, the crowd submits t-shirts designs, then the crowd votes on what designs are best and the designs that win are sold to the same crowd who already voted on them being the best! (For more details see the wiki article on Threadless)   
  • P&G hires scientists via Innocentive to solve problems that they can’t. As noted in the Wired article, Colgate-Palmolive "needed a way to inject fluoride powder into a toothpaste tube without it dispersing into the surrounding air". So the posted the challenge on Innocentive and Ed Melcarek, who has Master degree that is related to particle physics, "knew he had a solution by the time he’d finished reading the challenge: Impart an electric charge to the powder while grounding the tube. The positively charged fluoride particles would be attracted to the tube without any significant dispersion".  
  • iStock Photo: Instead of hiring professional photographers to make stock photos, iStock solicits photos from the crowd. The Wired article explains how the Claudia Menashe, director at the National Health Museum, was about to buy $600 worth of stock photos from a professional photographer Mark Harmel. However, she bought the photos from iStockPhoto for a fraction of the price at $1 a piece. iStockPhoto was snatched up by GettyImages “the largest agency by far with more than 30 percent of the global market, purchased iStockphoto for $50 million”. 
  • Howe's book (see pages 61-63) also discusses how NASA relied on the crowd to classify the age of craters. A professional had taken 2 years to complete a similar study that was done by these “clickworkers” over a month with results yielding a “comparable degree of accuracy”.
Can accountants/auditors be crowdsourced like the way professional photographers were? 

It seems were crowdsourcing works best is an arena where you find hobbyists who do such things out of passion instead of obligation. My dad was a hobby photographer and although I am no way near talented as he was, I love trying to capture those unique moments. For example, I was able to capture this unique division sunset with my Samsung Note 4


In other words, if I decided to put my mind to it, I could be potentially competing with Mark Harmel. 

However, are there hobby auditors or accountants out there that would compete with CPAs? 

I have yet to find one!

There's a case that can be made for the impact of David Weinberger's "networked knowledge" (book, YouTube video below) on the dilution of expert knowledge in general (law, medicine, accounting). What he proposes is that the ability to share, link and debate information on the Internet transforms knowledge into a more fluid state in contrast to the static nature of books. 


With respect to accounting, non-professional accountants can network with each other to get an understanding on how to account for stock provisions, but would management or the SEC find it acceptable that a company determining its accounting position by looking it up on Google Groups?

And that takes us back to the issue we discussed in the last blogpost: when disrupting a profession it's not just about the production of a good or service but also the social function that the profession was fulfilling. Public accountants have a fiduciary responsibility to the users of financial statements to ensure that they are free of material misstatements. Failure to fulfill this responsibility can result in fines, disciplinary measures or even loss of one's designation.

However, as Google's driverless cars could step in where Uber can't, could IBM's Watson step in and fulfill that societal function that accountants currently do?

To be concluded next time...





Tuesday, November 17, 2015

Will Accountants be Uberized? Part 1: Examining the Google-Uberization of the Taxi Profession

This is part 1 of a series of blogposts that I will write (aiming for 2 parts, but let's see) on how CPAs need to take lessons from the Uberization of taxi cab drivers and see whether CPAs can themselves be uberized.

A recent article in the Toronto Star highlighted the latest turn of events in the battle between taxi industry and those that want to bring Uber to Toronto

What is Uber? 
Uber enables the "sharing economy" by bringing together people who need a ride with those who have spare time and a spare ride via a mobile application. In other words, Uber does for car owners what Airbnb did for homeowners.

Who's resisting? 
Taxi cab owners have fiercely resisted the arrival of Uber into their cities as it can dramatically impact their ability to make a livelihood. The article attacks the position of the cab drivers as follows; "For decades, Toronto idled as taxi permits were traded among owners for obscene prices, pushing up meter rates while service declined". Taking the argument to the logical conclusion: Uber breaks the monopoly by enabling non-traditional competitors to enter into the marker.

The argument from the cab drivers side of things is that they are a profession: they have to pass examination standards that enables them to be qualified by the public to fulfill their duties. Furthermore, as noted in this article on the Walrus, taxis have a public duty in terms of assisting the handicap whereas Uber appears to be shirking this responsibility:

"Then there are disabled passengers, who don’t fare well at all with the Uber model of transportation. Indeed, nothing demonstrates the fundamental gulf between market-driven and civic-minded car services as much as the issue of accessibility. From a purely commercial point of view, passengers in wheelchairs represent a niche market. And unless compelled to by regulation or personal circumstance, most drivers are not going to invest the $60,000 needed to buy an accessible van.
For the most part, Uber pretends that the issue doesn’t even exist: In California, where a 2013 law requires ride-sharing services to report data about disabled passengers, the company has stonewalled the government. In July, a state judge recommended that Uber operations be suspended statewide and the company fined $7.3 million (US) for violating reporting requirements."

These protests are not limited to Toronto but are worldwide. Take for example the following video posted by Russell Brand actor-turned-activist who brings the issue of cab drivers in UK to light:



Other issues to note:
  • Is Uber cheaper? Not always. As noted in this Forbes article and this article on Business Insider, Uber is not always cheaper. Business Insider notes how that Uber you pay for both the distance and the length of ride. Although there are certain times that it's cheaper to use a cab than Uber, the reality is that it's significantly different in price between the two options and you need an app . 
  • Taxis have to charge standard pricing, Uber does not. The company engages in what it calls "surge pricing", which means "[a]t times of high demand, the number of drivers we can connect you with becomes limited. As a result, prices increase to encourage more drivers to become available." This is in contrast to taxis which are regulated in terms of how much they can charge.
  • Tax implications of Uber: Beyond the licensing fees a cab driver would pay to the municipal and other governments, Uber uses transfer pricing techniques - like any multi-national corporation - to minimize the taxes it pays. As noted in this Fortune article, Uber takes a 20% cut - meaning governments stand to lose the income taxes associated with this revenue that could have been taxed as income as from the local cab driver or the company that owns the plate. 
  • "Creative destruction" meets nest eggs, loans and food-beverage cart vendors. The disruption of Uber doesn't just impact taxi industry but also the retirement plans of drivers, financial institutions as well as tertiary industries that are ancillary to cabbies. In Toronto, plates were pricey costing as much as $360,000 (but are now selling for 120K). The logic of paying such an exorbitant amount was that it would provide a nest-egg for the purchaser and his or her family. But they weren't only ones betting on these assets. As noted in the Wall Street Journal, BankUnited Inc. lent $214 million against 577 cab licenses (also known as medallions). Finally, as noted by the cab driver in the video above, there are the food and beverage carts, restaurants, etc. that serve cab drivers who will also face a decline as cab drivers exit the business. 
Uber vs Taxis: What does the taxi-cab profession add to society?

Isn't it essentially trust? 

Prior to Uber, we had relied on municipal governments to license and vet cab drivers to ensure that they would get from us point A to point B in a safe, efficient (e.g. the fastest route possible) and cost-effective manner (e.g. fair pricing). 

Not to feed into the classical techno-phobic mantra of fear-uncertainty-doubt (FUD) but Uber drivers have violated that trust.

What Uber essentially proposes, is that municipal governments can be dis-intermediated in terms of oversight of the taxi profession. 

In terms of trust, what Uber purports is that the rating that drivers assign to passengers and passengers assign to drivers can serve as an effective substitute for the licensing and vetting function. Although this may work for the vast majority of time, it does not help those that have been victimized by Uber drivers. To use auditing-speak, the rules & regulations around cab drivers serve as a more effective control around cab drivers than Ubers rating system. 

The other issue is that Uber does not seem to be able to replace the public service function of the taxi profession: they openly "surge price" customers and are stone-walling the government around how they can serve the disabled community. 

Google's Driver-less Cars: Taking Uber to its logical conclusion 
Although the cab drivers can have a solid argument against Uber in terms of trust and public service, they may not fare so well at the next incarnation Uber: "Google's Uber". This is where we take Google's driverless cars to the concept of and apply it to Uber. I had mentioned the implication of Google's driverless car in a previous post - examining the impact on car insurance and the industry that has grown up around it. But I didn't explore how such a future will evolve. Google can effectively fill the role of cab services as follows:
  • Getting us there the fastest: With its Maps offering, we all have come to trust Google to get us to our destination the fastest which incorporates live traffic data. 
  • Safety:  Google's driverless cars have proven to be safer than human driven cars. Assuming it is not taken over by homicidal program like Skynet, the issue of assault basically is eliminated from the equation. 
  • Cost effective: This perhaps the most important part of the value proposition: Google's advanced algorithms could bring a level of optimization that would take the sharing economy to unparalleled heights. Imagine if Google sold driverless cars that would be earning money while the people are working. In such a scenario, the cost of the service would not only reduced by the amount of by the amount of wages and benefits paid out (regardless if it's a cab driver or an Uber driver), but it would also effectively share the cost of capital with the owner of the car. Alternatively, Google could offer, or supplement such an offering, with its own fleet of cars. Ultimately, would such an offering cannibalize car ownership altogether? If it's cheaper and faster to Google-Uber it, why bother owning a car and being held ransom by some insurance-feudal-corporate overlord? 
  • Public service: Given Google's experience with working with municipal government via its high speed internet offering, it is uniquely positioned to see such a service fulfill its public service role. As noted in the previous bullet, Google's own fleet of cars could be special purposed to serve the disabled.  In fact, Google openly advertises its driverless cars as something that will give the blind their independence (see video below as proof)

In the next installment (or set of installments), I will explore the prospects of how the CPA profession can be Uberized and what we can learn from the Uberization, and ultimately Google-Uberization, of the taxi cab profession. 

Wednesday, November 4, 2015

Did WSJ go too far in exposing Apple employee home purchasing habits?

The WSJ published an article discussing the cost of houses in the Bay Area. As per the title of the article, "Apple Paychecks—One Reason for High Home Prices", the key culprit they highlight are the significant salaries that the Apple employees are allegedly paid.

The the data for the findings were based on the work done by Zillow completed "at the request of The Wall Street Journal" who "used census data to track down where workers in the census tract that is dominated by Apple’s Cupertino, Calif., headquarters live—primarily neighborhoods in the San Jose and San Francisco metropolitan areas". It's not clear if they relied on their own data to complete this analysis. As per the graph below, Zillow tied the rising house prices to iPhone sales.



To be fair, and abide by full disclosure principles, the article does also blame "[z]oning laws and regulatory red tape are key factors as well". However, would it be the WSJ if it didn't lay such a charge?

Where to begin? The article raises a lot of issues in terms of the role of publicly available data - regardless if it is only the census data, data gathered by aggregators such as Zillow or social media sites.

As I had written a couple of years ago, the article actually is the promise of social media to "return us to the village". In the village privacy was limited because people knew each other and any deeds or misdeeds made by the individual were quickly found out by the community. A good example of how social media accomplishes this was role of public in identifying the rioters involved in the post-Stanley cup "celebrations". If such a riot had happened in the village, the rioters would be have been held accountable in a similar manner.

The Zillow-WSJ effort is really along similar lines: if employees of a company or members of a particular guild were buying up houses and driving up prices in particular area; wouldn't people in the village know?

Furthermore, it actually is village business. We need to understand how we will live with one another how we are going to make the most of living together in this shared space called community, which requires an understanding of how the actions of one group within the community will impact others especially when it relates to a basic need like housing.

That being said, it opens up the issue of big data and its ramifications on privacy.  Although the above rationale translates well into issues relating to communal benefit it doesn't translate well into issues relating to how private entities can handle the information they were given for a specific purposes. This of course refers to the concept of "consent" well-established within privacy parlance.

The authors of  Big Data: A Revolution That Will Transform How We Live, Work, and Think raised this issue in there book. As I had noted in a previous post:

"The authors, however, raise a much more interesting point when discussing privacy in the era of big data. They highlight the conflict between privacy and profiting from big data. They note how the value of big data emerges from the secondary uses of big data. However, privacy policies require the user to consent to a specific use of data at the time they sign up ahead. This would prohibit companies from big data. However, corporations in their drive to maximize profits will ultimately make privacy policies so loose (i.e. to cover secondary uses) that the user essentially has to give up all their privacy in order to use the service. What the authors propose is an accountability framework. Similar to how stock issuing companies are accountable to the security regulators, the idea is that organizations would be accountable to a privacy body of sorts that reviews the use of the big data and ensures that companies are accountable for the negative consequences of the data.

For those of use that have been involved in privacy compliance, such an approach would make it real for companies to deal with the privacy issues in proactive manner. We saw how companies attitudes towards controls over financial reporting shifted from mild interest (or indifference) to active concern with the passage of Sarbanes-Oxley. In contrast, no similar fervour could be found the business landscape when addressing privacy issues. Although the solution is not obvious, the reality is that companies will make their privacy notices meaningless in order to reap the ROI from investments made in big data."