assurance-and-compliance

Chan 2018 Results: What Happened and Why It Still Matters

The 2018 Chan results emerged from a period of intensified regulatory focus and public scrutiny on governance, risk, and compliance. They reflected a set of assessments, audits,...

Mara Ellison
Chan 2018 Results: What Happened and Why It Still Matters

Introduction to the 2018 Chan Results

The 2018 Chan results emerged from a period of intensified regulatory focus and public scrutiny on governance, risk, and compliance. They reflected a set of assessments, audits, and evaluations conducted across organizations, jurisdictions, and functional areas. Rather than a single report, the phrase refers to aggregated findings that influenced policies, controls, and oversight practices. This evergreen explainer outlines the context, content, and lasting implications of the 2018 Chan results for audit, compliance, and enterprise risk management.

Context Leading Into 2018

In the years preceding 2018, regulators and boards demanded stronger assurance around financial controls, cybersecurity, and operational resilience. High-profile incidents and evolving rules meant that internal audit and risk functions needed clearer evidence of effectiveness. The Chan 2018 results should be understood against this backdrop of heightened expectations, increased scrutiny, and the need for more standardized evidence across the enterprise.

The Regulatory and Market Environment

Regulatory expectations in 2018 emphasized outcome-oriented controls and demonstrable governance. Stakeholders required more transparent reporting on risk management and compliance, while technology-driven threats made assurance processes more complex. In this environment, the Chan assessments provided a structured way to benchmark controls, clarify accountability, and communicate residual risk to leadership and boards.

What the 2018 Chan Results Covered

The 2018 Chan results typically spanned governance, risk, and compliance domains, including financial controls, operational resilience, data protection, and third-party risk. The assessments combined testing of policies, procedures, and technical controls with interviews and sampling to measure design effectiveness and operational consistency. The outcomes were synthesized into metrics, observations, and recommended improvements intended to guide remediation and oversight.

Key Domains and Evaluation Areas

  • Financial reporting and internal controls over financial reporting (ICFR)
  • Enterprise risk management and oversight processes
  • Cybersecurity and data privacy controls
  • Third-party and vendor risk management
  • Compliance with laws, regulations, and standards

Findings and Observations From 2018

Across the 2018 Chan results, common themes included control gaps in timely exception reporting, inconsistent segregation of duties in key processes, and variability in evidence quality across regions. Cybersecurity assessments highlighted exposure through third-party connections and patch management delays. Compliance workstreams noted documentation deficiencies and inconsistent application of policy, particularly in high-risk jurisdictions.

Representative Findings (Illustrative)

Attribute Verified Detail or Typical Finding Source Type
Control Effectiveness Mixed evidence; design strong but inconsistent execution in several key processes Audit testing and interviews
Financial Reporting (ICFR) Top weaknesses in reconciliations and approval thresholds SOX testing and workpaper review
Cybersecurity Exposure through unpatched systems and weak access controls on privileged accounts Vulnerability scans and access reviews
Third-Party Risk Insufficient ongoing monitoring for critical vendors Vendor questionnaires and audit evidence
Compliance Documentation gaps and regional variance in policy application Document reviews and interviews

How the 2018 Chan Results Were Used

Organizations translated the 2018 Chan results into prioritized remediation plans, assigning owners, timelines, and estimated resourcing. Many findings fed into annual workplans, board risk packages, and external audit preparations. The results also informed policy updates, control enhancements, and technology investments aimed at reducing recurring weaknesses and improving overall assurance quality.

Typical Uses of the Results

  • Informing risk-based audit planning and resource allocation
  • Strengthening board and executive reporting on risk and controls
  • Guiding investments in controls, automation, and tooling
  • Supporting regulatory interactions and external audit readiness
  • Establishing baselines for tracking control performance over time

Lasting Impact on Governance and Practice

The 2018 Chan results helped standardize how assurance outcomes are reported, making it easier to compare findings across regions and functions over time. They underscored the importance of evidence quality, clear root-cause analysis, and measurable remediation targets. Subsequent assessments and frameworks have built on these lessons, emphasizing continuous monitoring, data-driven insights, and more explicit risk appetites.

Long-Term Implications

  • More structured reporting that links findings to business impact
  • Greater use of analytics and sampling plans to improve coverage
  • Clearer remediation tracking and accountability at the executive level
  • Tighter integration between internal audit, risk, and compliance functions
  • Enhanced disclosures to boards and regulators on residual risk

Limitations and Considerations

Any Chan assessments, including the 2018 results, reflect the scope, timing, and methodologies in place at the time. They are snapshots rather than guarantees and may not capture emerging risks that arose after the testing window. Stakeholders should interpret the results within the context of their own risk profiles, control environments, and industry dynamics, and supplement with ongoing monitoring and targeted testing.

Conclusion

The Chan 2018 results remain a useful reference point for understanding how assurance, governance, and risk practices evolved in the late 2010s. They highlight common control vulnerabilities, the value of standardized reporting, and the ongoing need for clear accountability and measurable remediation. For audit, compliance, and risk leaders, the 2018 findings continue to inform frameworks, benchmarks, and conversations about risk management effectiveness in the years that followed.