Tech’s Tightrope: Navigating AI, Automation and Security

Julemm Banag

Director, Risk Advisory Group

Tech’s Tightrope: Navigating AI, Automation and Security
In Episode 3 of The Beehive Podcast, “Tech’s Tightrope: Navigating AI, Automation, and Security,” host William is joined by Risk Advisory experts Matthew Gopez and CJ Pacalso for an engaging discussion on the intersection of emerging technologies, cybersecurity, and business risk management. As AI, automation, and data privacy concerns become increasingly important, our experts explore how organizations can stay ahead of the curve while mitigating the risks tied to these technological advancements.

The Power of Emerging Technology and Its Risks

The conversation kicks off with an exploration of how new technologies such as Artificial Intelligence (AI) and Robotic Process Automation (RPA) are transforming business operations. While these tools have the potential to drive significant efficiencies, the podcast emphasizes the importance of recognizing and managing the risks they introduce, particularly in the realms of data privacy and cybersecurity.

CJ explains that with automation, AI, and RPA, businesses can streamline processes, but it’s crucial to think about the bigger picture, including data breaches and compliance. As technology evolves, so too must the frameworks that safeguard it. For instance, organizations already leveraging an outsourced accounting team are finding parallels in how external expertise can help manage risk more effectively.

Discover how our Risk Advisory Team can help you manage AI and automation risks.

How AI and Automation Change the Game

AI and automation technologies are reshaping customer experiences, operational efficiencies, and risk management. For instance, the evolution from ticket-based customer support systems to AI-driven chatbots exemplifies the rapid advancements in tech. While automation improves response times and customer engagement, CJ stresses that it’s crucial to ensure that these systems are adequately trained to avoid errors and unexpected outcomes.

The conversation between William and CJ highlights the benefits of combining AI with RPA for a more seamless user experience. CJ adds that when we look at a self-service portal, adding AI to the mix not only speeds up customer queries but also introduces a higher level of accuracy.


The Fine Line Between Efficiency and Ethical Considerations

One of the core points discussed in this episode is the balancing act between embracing technological advancements and staying true to an organization’s values, particularly regarding customer interaction. Some businesses, especially those in sectors focused on customer relationships, may be hesitant to fully adopt AI because it could jeopardize the personal touch that sets them apart from competitors.

Matthew reflects that it’s a delicate balance. You can’t disregard the human element entirely, even if the technology offers a clear efficiency advantage. People still want that human connection, especially when dealing with sensitive issues.


Managing the Risks of New Technology

As organizations adopt new technologies, mitigating risks becomes a priority. CJ recommends starting with a comprehensive risk assessment. The key to any technology adoption is understanding the risks, whether it’s data privacy, compliance regulations, or operational security. Doing a proper risk assessment upfront will help you manage these risks from the start.

Matthew and CJ highlight that organizations should consult internal risk teams and, if necessary, external experts to evaluate these risks. It’s not just about picking the right technology; it’s about integrating it securely within your organization’s risk framework.


Best Practices for Safeguarding Data and Privacy

Another vital discussion point revolves around the importance of data privacy and how organizations can adopt technologies like AI and RPA without compromising customer data. From GDPR compliance to cybersecurity regulations, several layers of protection need to be in place.

CJ stresses the importance of maintaining a clear cybersecurity strategy: It’s vital to have protocols in place not just for when things go wrong, but to proactively prevent data breaches before they happen. This becomes even more critical as organizations expand into areas such as ESG reporting services, where transparency and data accuracy are paramount.

Strengthen your CPA firm’s Risk Advisory. Watch this video.

Why Listen to Episode 3?

This episode offers actionable insights, including:
  1. What’s hot in the world of emerging technology
  2. What are the risks of emerging technologies
  3. State of Compliance – Statistics of Data Breaches
  4. MRC as a Strategic Tool for Proactive Risk Management.
  5. Preventive Measures and Best Practices

Ready to embrace the future of technology with confidence?

Tune in to Episode 3 of The Beehive Podcast, “Tech’s Tightrope: Navigating AI, Automation and Security.” Discover how to harness innovation, from AI and automation to data privacy and compliance without compromising security. You can suggest topics like emerging technologies in finance, cybersecurity best practices, or how SaaS accounting expertise is evolving to meet the demands of fast-growing tech companies.


LISTEN TO PODCAST

Related Content

Blogs

Decoding the Digital Ledger: Navigating FASB’s New Standards for Crypto Assets and Intangibles (ASU 2023-08)

Decoding the Digital Ledger: Navigating FASB’s New Standards for Crypto Assets and Intangibles (ASU 2023-08)

In a groundbreaking move reflecting the swift evolution of the financial landscape, the Financial Accounting Standards Board (FASB) has taken a significant step with the release of the final Accounting Standards Update (ASU) 2023-08 titled “Accounting for and Disclosure of Crypto Assets.” This authoritative guidance specifically addresses Crypto Assets within the Intangibles—Goodwill and Other category, marking a crucial advance in establishing standardized accounting practices for these assets. Bridging the Gap: A Brief Background The rise of digital assets, from cryptocurrencies like Bitcoin and Ethereum to unique non-fungible tokens (NFTs), has challenged traditional accounting norms. Without specific Generally Accepted Accounting Principles (GAAP) guidance, accounting professionals relied on analogies and interpretations, resulting in a diverse patchwork of practices.  Our article “Rise of Digital Assets in Business” explored the evolving landscape, highlighting the AICPA Practice Aid titled “Accounting for and Auditing of Digital Assets” as a crucial guide within the constraints of the existing accounting framework. We are witnessing a groundbreaking shift with the finalized FASB’s ASU on Crypto Assets, effective December 15, 2024, which will change how the world sees crypto assets. Who Will Be Affected? The new ASU applies to a wider range of entities than you might think. Any entity holding crypto assets that meet specific criteria will be impacted. These criteria include: Meet the definition of an intangible asset. Do not grant enforceable rights or claims on underlying goods, services, or assets. Exist on a blockchain-based distributed ledger or similar technology. Are secured using cryptography. Are fungible. Are not created or issued by the reporting entity or its related parties. Crypto assets falling within these criteria must be measured at fair value, with changes in value recognized in their income statement each reporting period. Moreover, transaction costs incurred in acquiring these assets, such as commissions and related fees, will be expensed unless other industry-specific guidance dictates otherwise. A Closer Look at the New ASU  Mandating Relevance: Fair Value Measurement  The update mandates the fair value measurement of crypto assets at each reporting period. This focus on fair value measurement stems from the belief that fair value offers investors more relevant information about the assets’ sale value and changes in that value. The Board rejected historical cost and net realizable value as alternatives due to limitations in reflecting downward and upward price movements. The existing guidance in Topic 820 was deemed sufficient for fair value measurement, given its applicability to other assets and current use by reporting entities. As financial reporting evolves, organizations offering ESG reporting services may also need to consider how such valuation updates intersect with broader transparency and sustainability disclosure requirements. Beyond Annual Assessment: Recognizing Both Gains and Losses Unlike the existing ASC 350 model, which mandates an annual assessment of crypto asset value that only recognizes gains upon sale, the update embraces a more dynamic approach. The new method captures both negative and positive market movements, addressing longstanding concerns about the traditional model’s failure to reflect the true and current economic nature of crypto assets at each reporting period. As well as providing a more comprehensive understanding of the underlying economics and an entity’s financial position, the shift signifies a progressive step toward a more responsive and accurate representation of the financial impact of market fluctuations on digital holdings. Enhancing Transparency: Disclosure Requirements The ASU prioritizes transparency, incorporating detailed disclosure requirements for asset categorization, impairment considerations, and, notably, the separate presentation of crypto assets from other intangible assets in the statement of financial position. Entities must disclose the following for annual and interim reporting periods: 1. Details of significant and less significant crypto asset holdings, including name, cost basis, fair value, and quantity. 2. Information on restricted crypto assets, covering fair value, nature, the remaining duration of restrictions, and circumstances for the potential lapse. For annual reporting periods, additional disclosures are required: 1. A roll forward of crypto asset activity, including additions, dispositions, gains, and losses. Specify the income statement line item for unrecognized gains and losses if not presented separately. 2. Detail dispositions of crypto assets, including sale price, cost basis difference, and relevant activities. 3. The method used to determine the cost basis of crypto assets. These changes enhance transparency and understanding of crypto asset holdings, ensuring comprehensive disclosure for annual and interim reporting periods. Nevertheless, entities immediately converting crypto assets received as noncash consideration or contributions into cash are exempt from the above annual additional disclosures. The Countdown Begins: Timeline and Adoption The final standard takes effect for all entities in reporting periods beginning after December 15, 2024, including interim periods within those fiscal years. Early adoption is permitted, allowing entities to embrace the changes ahead of the mandated timeline. However, early adopters must use a modified retrospective approach, requiring recording a cumulative effect adjustment to equity (or net assets) from the commencement of the adoption year. What Lies Ahead: Implications for the Future The issuance of the finalized ASU 2023-08 represents a proactive response to the growing significance of crypto assets in today’s financial landscape. The finalized ASU is a significant milestone in our journey toward a standardized and transparent future for crypto asset accounting, offering consistency in financial reporting across diverse industries engaged with crypto assets. The FASB’s move acknowledges the need for accounting standards that keep pace with technological advancements and reflect the realities of the modern economy. Stay tuned for further developments. How Scrubbed Can Help You? Navigating the opportunities and challenges of crypto assets demands expertise, whether you’re an individual investor or a business. At Scrubbed, our comprehensive range of services empowers you to stay ahead: • Compliance Experts: Navigate crypto regulations effortlessly with our seasoned professionals. From taxes to reporting, we’ve got your compliance needs covered. • Rock-Solid Controls: Establish secure systems and ensure compliance with the latest financial reporting standards like GAAP and IFRS. • Innovative Strategies: Beyond the numbers, we offer strategic insights about market tren ds and help you make wise decisions. As we collectively pioneer a new era of financial reporting, Scrubbed is committed to bridging the gap between traditional accounting norms and the groundbreaking shifts introduced by the FASB on Crypto Assets. Our Technical Accounting Group is ready to assist your business in decoding the digital ledger, ensuring effective operations, and maintaining compliance with evolving regulations. We also provide specialized biotech accounting services, supporting organizations in highly regulated industries with tailored financial reporting solutions. For a comprehensive consultancy assessment tailored to your specific needs, reach out to [email protected].

Read More >
Blogs

The CPA Firm’s Roadmap to Meeting Tight Audit Deadlines

The CPA Firm’s Roadmap to Meeting Tight Audit Deadlines

Every CPA firm knows the rhythm of the busy audit season: the long hours, the constant pressure, and the impossible balance between speed and accuracy. But what used to be a seasonal challenge has become a deeper structural issue for the profession. With fewer accounting graduates entering the field, growing client demands, and increasing audit complexity, firms can no longer rely on sheer effort to meet deadlines. CPA firm turnover is averaging around 15% nationally and nearly 71% of Big 4 auditors reporting mental health worries due to work pressures . The old model, hire more people, work more hours, simply doesn’t scale. The firms finding success today are the ones rethinking their audit approach. They’re replacing reactive, deadline-driven habits with proactive systems built on planning, visibility, and smart capacity management. This roadmap provides five core, actionable strategies that move beyond wishful thinking and establish a disciplined, collaborative framework to ensure timely completion without sacrificing the integrity of the audit. Step 1: Strategic Planning The planning phase is where you negotiate reality, manage expectations, and build essential time buffers to protect your team. Here’s how this step usually goes: Setting Realistic Timelines The single most destructive action in deadline management is setting a one-sided, unrealistic deadline without client input. This only creates resentment and guarantees delays. Suggested Action: Schedule a dedicated meeting with key client stakeholders early in the process. Use this time to negotiate and agree on an achievable timeline for deliverables, fieldwork, and final sign-off. This collaborative approach manages expectations on both sides and sets a realistic, mutually accepted path forward. When the client agrees to the timeline, they inherently take ownership of meeting their own deliverables, dramatically improving their response time. Buffering for Client Delays Even the most collaborative client will face unexpected internal hiccups. If your internal deadline is the same as the final delivery date, you have no recourse when issues arise. You need built-in protection. Suggested Action: The usual buffer to set is an internal deadline of two days before the official one. This two-day margin serves as your firm’s safety net. Furthermore, when communicating with the client, give them a one or two-day window to provide the necessary information before your internal deadline. This proactive strategy ensures that if the client misses their internal date by a day or two, your firm’s final schedule remains protected, insulating your team from external chaos. Step 2: Focused Execution Once the timeline is set, execution must be focused on ensuring maximum audit efficiency and professional skepticism is applied where it matters most. Prioritizing High-Risk Audits The most efficient audit is not the one that finishes every section fastest but the one that allocates the most senior resources to the areas carrying the highest risk. Suggested Action: Accounts that carry the highest risk of material misstatement must be prioritized and tackled first in peak season. These are the areas that will receive the most extensive and/or detailed audit procedures and require the judgment of senior staff. Common priority areas include: revenue and related accounts (such as Accounts Receivable and Cash), Inventories, Complex accounts (like derivatives or specialized equity), and accounts flagged during planning due to weak internal controls . By front-loading the heavy, high-risk lifting, you surface critical issues early when there is still time to resolve them. Avoiding Bottlenecks Bottlenecks are inevitable, but their impact is manageable. Delays typically stem from a few common issues: a client’s slow response to requests, unexpected material events or errors, and the discovery of mistakes from previous audits. It’s common to encounter one, or even all, of these hurdles during an audit. Suggested Action: When an audit encounters one or more of these hurdles, do not proceed in silence . The moment the delay is quantified, you must immediately renegotiate a new, achievable timeline with the client. Trying to push through an unexpected week-long delay on the original schedule will only lead to rushed, sub-par work. Anticipating and communicating delays early is the hallmark of professional project management. Using Project Trackers While sophisticated audit software exists, the core need remains visibility and accountability for both the firm and the client. Suggested Action: Maintain a simple, centralized project tracker. Often, keeping an Excel file is the most effective low-tech solution. This tracker should monitor the progress of each audit area and, crucially, track what is still needed from the client (the Pending Client List, or PBC). Clear, shared tracking ensures everyone knows the exact status of the engagement and holds the client accountable for their outstanding items. Step 3: Expand Capacity Through Strategic Partnership Even with great planning and process discipline, there’s one reality every CPA firm faces: capacity. This capacity constraint creates the unavoidable bottlenecks that these strategies are designed to mitigate, especially given that the unemployment rate for auditors sits at 2.0%. The talent shortage is the bottleneck. The most effective solution to this crisis is leveraging the dedicated, experienced offshore accounting professionals from Scrubbed. This will allow your firm to instantly scale capacity for high-volume tasks without the overhead or long lead time of permanent hiring, establishing the firm’s forward-looking strategy. Here’s how we make it possible: Audit Support . We handle all your testing, confirmations, and workpaper preparation so your team can focus on analysis and client relationships. Tax Preparation and Compliance. From 1040 and 1120 returns to nonprofit filings, we can help you ensure timely and compliant submissions even during the busy seasons. Accounting and Bookkeeping. We manage your daily bookkeeping, account reconciliations, and month-end close activities, so your team can dedicate more time to strategic initiatives. Transaction and Advisory Support. For firms providing M&A, valuation, or due diligence, we deliver the support you need to strengthen your advisory engagements. As a long-time partner to CPA firms of all sizes, Scrubbed provides access to highly trained accounting and audit professionals who work seamlessly as part of your extended team. We follow your firm’s methodology, align with your tools and standards, and deliver consistent, high-quality work. Beyond Just Meeting the Deadline Meeting tight deadlines shouldn’t come at the expense of your team’s well-being or your firm’s reputation. With the right systems and the right partners in place, it’s possible to deliver every audit on time, with the quality and confidence your clients expect. The ultimate benefit is not just a timely report either, but a sustainable practice. Leveraging proactive steps and strategic partnerships like Scrubbed allows CPA firms to reduce staff stress and burnout, increase the efficiency of review cycles, and consistently deliver high-quality reports, solidifying trust with clients. Don’t let the next busy season dictate your schedule. Partner with Scrubbed to build a resource plan that helps your team meet deadlines without burnout, and deliver quality audits every time.

Read More >
Blogs

The ESG Translation Gap: Why Good Accounting Data Fails Sustainability Audits

The ESG Translation Gap: Why Good Accounting Data Fails Sustainability Audits

If I had to name the first common mistake I see growing companies make when they tackle ESG reporting, it is foundational: They don’t know if the data they are using is complete and accurate. More than that, they often don’t even know if it is the data they should be using. For years, ESG reporting was largely voluntary, a way to answer the public’s demand for accountability and show investors you were responsible. But as optional guidelines transition into emerging laws and requirements, the landscape shifts. Investors and regulators no longer want marketing campaigns. They want accurate data provided with assurance. This brings us to a harsh reality I share with teams newly subject to these regulations: If you are required to file a report in 2027 based on 2026 data, and you wait until 2026 to start preparing, you are already late. Leaders often assume their existing accounting systems are naturally ready to handle ESG reporting. They almost never are. The Illusion of Alignment I see leadership teams fall into this trap constantly. They look at their organizational chart, see a separate Finance team and a separate ESG team, and assume they are covered. But in practice, these two teams are working in silos, speaking entirely different languages. I see this pattern constantly with companies that have been publishing ESG reports voluntarily for a number of years. As they prepare for mandated regulatory reporting, leadership feels secure because their ESG team is getting the exact reports they requested from Finance. But the moment you dig into the architecture and bridge the two teams, the gaps become obvious. Here is how the breakdown usually happens: The Ask: The ESG team needs data to calculate emissions, so they ask Finance for certain reports. The Hand-off: Finance, wanting to be helpful, pulls the data and hands it over. The Gap: Finance teams are wired to be compliant with accounting standards, but they aren’t trained to understand ESG reporting. ESG teams are great at translating finance data into emissions, but they don’t have the concept of an audit. Because the ESG team didn’t have an audit background, they didn’t know how to establish completeness and accuracy. They didn’t know how to look for certain accounting transactions that would otherwise be considered emission or non-emissive (i.e., advance or duplicate payments, reversed entries in the vendor reports). They were running calculations on raw data. The people didn’t fail: the structure simply wasn’t built to translate between the two departments. The Reality of Retroactive Cleanup The true operational complexity of ESG reporting reveals itself when you try to force accounting data into sustainability buckets. Take something as standard as a growing portfolio of leased facilities. From a purely financial perspective, a company might have these perfectly recorded. But you cannot translate that 1:1 to ESG data. For ESG, you have to review the business structure to see who actually holds ‘operational control’ so you can assign those facilities to the proper emissions categories.. When a company’s data architecture isn’t set up for this level of granularity, teams are forced to go back and manually revisit hundreds of outstanding contracts. What should take a minute to encode upfront easily turns into a multi-month project just to find the proper data sources. When you wait to build the system, you force your teams to look backward instead of forward. What You Need to Check Today The fix is actively bridging the technical gap. You need professionals who can translate complex sustainability metrics into an accounting standard, and vice versa. If you are a CFO or sustainability leader reading this today, before making your next public ESG commitment, take a hard look at your architecture. Ask yourself these three questions: Are my on-book activities scoped properly? Check if all financial transactions have been mapped to the appropriate ESG requirement. Are my off-book activities accounted for? Ensure your people management, technology, and operational data are fully captured. Are all stakeholders involved? If ESG reporting is falling entirely on your Finance team, or solely on your ESG team without Finance’s oversight, you have a translation gap. Operations, HR, and Tech must understand the why and the how of the data they are providing. A calm, predictable reporting cycle is designed, never improvised. Build the data architecture a year or two before the regulations hit, and ensure your financial execution naturally supports confident sustainability reporting.

Read More >

Contact Information

SF Bay Area Headquarters
111 Anza Boulevard, Suite 320, Burlingame, CA 94010, United States

Phone: (800)837-5160
Email: [email protected]

"Scrubbed" is the brand name under which Scrubbed Advisory, LLC and Scrubbed Assurance, LLP provide professional services. Scrubbed Advisory, LLC and Scrubbed Assurance, LLP practice in an alternative practice structure in accordance with the AICPA Code of Professional Conduct and applicable law, regulations, and professional standards. Scrubbed Assurance, LLP is a licensed independent CPA firm that provides attest services to its clients, and Scrubbed Advisory, LLC provides tax, finance, and support services to its clients. Scrubbed Advisory, LLC is not a licensed CPA firm.

Copyright © Scrubbed. All rights reserved.