Introduction to the 2018 Chan Results
The 2018 Chan results emerged from a period of intensified regulatory focus and public scrutiny on governance, risk, and compliance. They reflected a set of assessments, audits, and evaluations conducted across organizations, jurisdictions, and functional areas. Rather than a single report, the phrase refers to aggregated findings that influenced policies, controls, and oversight practices. This evergreen explainer outlines the context, content, and lasting implications of the 2018 Chan results for audit, compliance, and enterprise risk management.
Context Leading Into 2018
In the years preceding 2018, regulators and boards demanded stronger assurance around financial controls, cybersecurity, and operational resilience. High-profile incidents and evolving rules meant that internal audit and risk functions needed clearer evidence of effectiveness. The Chan 2018 results should be understood against this backdrop of heightened expectations, increased scrutiny, and the need for more standardized evidence across the enterprise.
The Regulatory and Market Environment
Regulatory expectations in 2018 emphasized outcome-oriented controls and demonstrable governance. Stakeholders required more transparent reporting on risk management and compliance, while technology-driven threats made assurance processes more complex. In this environment, the Chan assessments provided a structured way to benchmark controls, clarify accountability, and communicate residual risk to leadership and boards.
What the 2018 Chan Results Covered
The 2018 Chan results typically spanned governance, risk, and compliance domains, including financial controls, operational resilience, data protection, and third-party risk. The assessments combined testing of policies, procedures, and technical controls with interviews and sampling to measure design effectiveness and operational consistency. The outcomes were synthesized into metrics, observations, and recommended improvements intended to guide remediation and oversight.
Key Domains and Evaluation Areas
- Financial reporting and internal controls over financial reporting (ICFR)
- Enterprise risk management and oversight processes
- Cybersecurity and data privacy controls
- Third-party and vendor risk management
- Compliance with laws, regulations, and standards
Findings and Observations From 2018
Across the 2018 Chan results, common themes included control gaps in timely exception reporting, inconsistent segregation of duties in key processes, and variability in evidence quality across regions. Cybersecurity assessments highlighted exposure through third-party connections and patch management delays. Compliance workstreams noted documentation deficiencies and inconsistent application of policy, particularly in high-risk jurisdictions.
Representative Findings (Illustrative)
| Attribute | Verified Detail or Typical Finding | Source Type |
|---|---|---|
| Control Effectiveness | Mixed evidence; design strong but inconsistent execution in several key processes | Audit testing and interviews |
| Financial Reporting (ICFR) | Top weaknesses in reconciliations and approval thresholds | SOX testing and workpaper review |
| Cybersecurity | Exposure through unpatched systems and weak access controls on privileged accounts | Vulnerability scans and access reviews |
| Third-Party Risk | Insufficient ongoing monitoring for critical vendors | Vendor questionnaires and audit evidence |
| Compliance | Documentation gaps and regional variance in policy application | Document reviews and interviews |
How the 2018 Chan Results Were Used
Organizations translated the 2018 Chan results into prioritized remediation plans, assigning owners, timelines, and estimated resourcing. Many findings fed into annual workplans, board risk packages, and external audit preparations. The results also informed policy updates, control enhancements, and technology investments aimed at reducing recurring weaknesses and improving overall assurance quality.
Typical Uses of the Results
- Informing risk-based audit planning and resource allocation
- Strengthening board and executive reporting on risk and controls
- Guiding investments in controls, automation, and tooling
- Supporting regulatory interactions and external audit readiness
- Establishing baselines for tracking control performance over time
Lasting Impact on Governance and Practice
The 2018 Chan results helped standardize how assurance outcomes are reported, making it easier to compare findings across regions and functions over time. They underscored the importance of evidence quality, clear root-cause analysis, and measurable remediation targets. Subsequent assessments and frameworks have built on these lessons, emphasizing continuous monitoring, data-driven insights, and more explicit risk appetites.
Long-Term Implications
- More structured reporting that links findings to business impact
- Greater use of analytics and sampling plans to improve coverage
- Clearer remediation tracking and accountability at the executive level
- Tighter integration between internal audit, risk, and compliance functions
- Enhanced disclosures to boards and regulators on residual risk
Limitations and Considerations
Any Chan assessments, including the 2018 results, reflect the scope, timing, and methodologies in place at the time. They are snapshots rather than guarantees and may not capture emerging risks that arose after the testing window. Stakeholders should interpret the results within the context of their own risk profiles, control environments, and industry dynamics, and supplement with ongoing monitoring and targeted testing.
Conclusion
The Chan 2018 results remain a useful reference point for understanding how assurance, governance, and risk practices evolved in the late 2010s. They highlight common control vulnerabilities, the value of standardized reporting, and the ongoing need for clear accountability and measurable remediation. For audit, compliance, and risk leaders, the 2018 findings continue to inform frameworks, benchmarks, and conversations about risk management effectiveness in the years that followed.