Governance risk and controls

Complex business environments demand a more proactive approach to governance. Improve risk oversight, and drive compliant, sustainable performance with Wipfli’s governance services.

Webinar: Balancing risk, resilience and growth
Webinar: Balancing risk, resilience and growth

Operational, tech, cyber and AI risks are all interconnected. Learn practical ways to assess and prioritize risk.

How we help you

Wipfli’s services for governance, risk and controls help you foster resilience with informed decision-making and deliver proactive enterprise risk management services that align risk with growth and your strategic plan. 

Maintain trust with legal, ethical and transparent operations.

Stay ahead of evolving privacy regulations.

Mitigate enterprise risk across increasingly complex operations and technology.

Strengthen governance and manage enterprise risk

Our integrated team takes you from governance and risk strategies to tactical execution across your organization.

Explore our governance risk and controls services

Insights and Resources

  • A Lady using Laptop.

    ARTICLE

    UDS reporting: Turn compliance into strategic value

    For federally qualified health centers (FQHCs), the Uniform Data System (UDS) can be a cumbersome burden — a backward-facing, compliance-driven reporting task that ties up critical assets every year between New Year’s and Valentine’s Day, costing personnel hours and operational efficiency. But for health centers interested in a data-driven future, UDS reporting can present a unique opportunity to modernize and even gain critical insights. A smarter approach to UDS reporting leads to enhanced federal compliance for FQHCs, plus improved behind-the-scenes efficiency and improved patient outcomes. What is UDS reporting in healthcare and how is it used? UDS is an annual reporting system through which FQHCs report their clinical and financial data to federal regulators, enabling authorities to monitor healthcare trends, allocate resources effectively and further data-driven decision-making about community needs. Federal UDS reporting is often contemporaneous with analogous reporting to state agencies, on similar or complimentary benchmarks. UDS data is also used to evaluate the performance of health centers, improve standards of care and identify centers of excellence. By providing insights into disease patterns, treatment costs and patient demographics, UDS serves as a vital tool for managing and tracking critical data from healthcare access points nationwide. Traditionally, UDS data has been used primarily for monitoring purposes, with limited direct consequences for inaccuracies or deviations from the norm. However, the landscape is shifting, and there are now more reasons than ever for FQHCs to insist on accurate data, both from an accountability perspective and because of the potential high value of the insights offered through the data. During the COVID-19 crisis, certain grant awards were directly tied to the total number of patients served, as reported through UDS. This allocation method may continue into the future, underscoring the importance of accurate and comprehensive data reporting for FQHCs seeking to secure vital funding and resources. Today, UDS is commonly used to compare and contrast health centers, particularly along the lines of staffing ratios, quality scores, and financial efficiency. It’s become more common for lenders, funders, and regulators to consult UDS data as a way to benchmark FQHCs against one another. Additionally, savvy Boards of Directors often consult their health center’s public data, monitor year-to-date reporting, and seek to engage executives to understand how (and why) data is trending. The challenges behind meeting the data reporting requirements With a strict reporting deadline of February 15, many FQHCs rush at the beginning of the year to allocate resources to collect the necessary data and organize the reporting. If centers haven’t been checking data quality and outcomes throughout the year, it can make for a stressful Valentine’s Day. To effectively address the challenges associated with UDS reporting, it is crucial to first identify the specific pain points within an FQHC’s data collection and management operations. Common hurdles include: Lack of dedicated resources: Many FQHCs don’t have the resources to dedicate personnel to the UDS reporting process. Often, data entry and reporting responsibilities are assigned to staff members whose training is in other areas, leading to potential oversights or inaccuracies. Data silos and fragmentation: In some cases, data may be scattered across multiple systems or departments within an FQHC, preventing a comprehensive view of the organization’s operations and patient population. Technical complexities: Navigating the intricacies of EHR systems, financial software and the UDS reporting platform itself can pose significant technical challenges in getting systems to generate the correct data sets, particularly for organizations with limited IT resources or expertise. Manual data entry and error-prone processes: Reliance on manual data entry and lack of automated processes is a time-consuming process, tying up valuable resources on tedious work that can also introduce human error, compromising the accuracy and integrity of the reported data. Lack of staff training and engagement: Inadequate training and limited staff engagement can lead to misunderstandings or misinterpretations of data collection and reporting requirements, resulting in inaccurate submissions that don’t capture the full quality of an FQHC’s services. Changing requirements: UDS regulations change every year, meaning FQHCs need to annually invest additional resources into keeping up with the latest updates. Identifying these pain points can help FQHCs develop targeted strategies and leverage available resources to address the specific challenges they face, paving the way for more efficient and accurate UDS reporting and a greater benefit for the FQHCs themselves. Building a more effective UDS reporting process How can FQHCs ease the burden of UDS reporting? And what modifications can be put into place to turn the onerous process of data collection and management into a source of added value for the organization? FQHCs can simplify the UDS reporting process and position themselves for success in an increasingly data-driven marketplace by focusing on five critical areas for improvement: Creating a data governance committee: Establish a cross-functional data governance committee that brings together stakeholders from various departments, including clinical, operational, financial and quality teams. This committee should be responsible for overseeing how data is coded, collected and managed, identifying areas for improvement and driving organizational alignment. Technical enhancementsto the system: Conduct a comprehensive analysis of data workflows and map the journey of data from its point of capture to its ultimate destination within the reporting systems. This exercise can help identify system limitations, bottlenecks, redundancies and opportunities to streamline processes. Monthly data analysis: Pull and discuss data every month in order to identify issues and squash them early. Data can be compared against prior-year trends and, in the case of variance, can be tracked and analyzed to determine why the variance is occurring. It’s much easier to proactively address issues than to try troubleshooting late in the year with the February 15 deadline fast approaching. Data quality audits: Implement regular data quality audits to validate the accuracy and completeness of the data being collected and reported. These audits can involve sampling techniques, cross-referencing multiple data sources and leveraging data analytics tools to identify discrepancies or anomalies. Staff training and engagement: Invest in ongoing staff training and engagement initiatives to ensure that all stakeholders understand the importance of accurate data collection and reporting. Additionally, by identifying early in the process who is responsible for what, more tasks can be managed in a timely fashion, and everyone will be working from the same playbook from the start. By addressing these key issues, organizations can begin to transform their once-dreaded UDS workload into a valuable chance for growth and operational improvement. Use UDS data reporting to spark growth Follow these steps so your FQHC can successfully harness data to its strategic advantage. Make UDS a monthly priority by reviewing it regularly with leadership and the board. Include UDS in routine reporting alongside financial and clinical metrics. Benchmark against peers to identify unusual trends or potential issues. Compare UDS data to internal reports and clinician insights to uncover discrepancies. Establish clear data governance by defining a source of truth for different needs across competing systems such as UDS, EHR, payroll, accounting and Population Health System. Treat UDS as an ongoing process rather than a once-a-year burden to drive operational improvements, efficiency and growth opportunities. Turning UDS reporting into value UDS can provide more than just peace of mind for your organization. By shifting to a value-producing approach rather than a compliance-only focus, your organization can derive significant benefits from the annual exercise. Automating and integrating data to improve operational efficiency Manually pulling data together is a time-intensive process that ties up key resources just to meet regulatory deadlines. But shifting to an automated data collection system and implementing integration tools that can pull data from all of your systems can minimize data handling while improving accuracy. This provides value by reducing preparation time and staff costs , while also freeing up resources to focus on patient care or operational improvements. Additionally, real-time access to your data can be used to monitor performance on an ongoing basis, not just during UDS prep time. Turning UDS preparation into a continuous quality improvement cycle UDS preparation at many health centers is reactive, with efforts focused merely on submitting a complete product or on avoiding UDS quality-control questions in a rush to get the process done. But by using the process as a catalyst for ongoing quality improvement, you can have regular visibility into actionable data to monitor improvement in clinical care, financial reporting and operational processes, leading to better outcomes for your organization. Using UDS data to enhance patient care with higher-quality reporting Your data can help create actionable insights that can improve the quality of the care you provide. Your preparations already include reporting on standard clinical quality measures, which matter to funders, your community and — most of all — your patients. UDS provides a valuable opportunity for leadership to monitor these quality measures on an ongoing basis and take steps to improve them before undesirable trends become entrenched. Don’t just consider these isolated reporting activities — this data can be used to make real-time decisions. Improving quality metrics is often tied to reimbursement under value-based care models, and may generate quality incentive payments from payers, so your bottom line benefits as well. Improving staff efficiency and engagement through process standardization UDS preparation can overburden staff, leading to burnout, inefficiency and potential reporting errors. But a standardized process with streamlined workflows for data collection, review and submission can help ensure smoother operations, reduced redundancy and less stressed-out staff. Involve clinical staff in audit readiness programs so they can grasp the link between checking boxes in the EHR, day-to-day care delivery and quality metrics that are ultimately reported publicly. This also leads to a more proactive quality-first culture, decreasing the need for a last-minute scramble to gather and process relevant data come February. Ultimately, UDS offers your health center a wealth of opportunities. It’s up to your organization to determine what that might mean for your operations. How much of a role UDS plays in your day-to-day may differ among organizations, but whatever your desired level of involvement is, it’s important to choose a vision, document it and work toward implementation. Read more 4 workforce strategies for FQHC financial health Improving rural healthcare RCM with data analytics The tech infrastructure that can drive your rural health transformation

  • A businessman looking out window.

    ARTICLE

    Enterprise risk management: A strategy for turning risk visibility into business wins

    Learn how an enterprise risk management strategy can help your business adapt to an unpredictable environment, improve performance and even find new growth opportunities.

  • a startup office

    ARTICLE

    Cybersecurity risk assessment: A guide to identifying and prioritizing cyber risks

    The cybersecurity landscape is more volatile than ever. Is your business prepared to meet this challenging moment? To find out — and to help ensure your organization is prepared and resilient — conduct a cybersecurity risk assessment. A risk assessment helps you understand the threats you face and strengthen your defenses . Keep reading to learn more about what a cybersecurity risk assessment is and how to start yours. Plus, we’ve put together a downloadable checklist to guide your risk assessment. What is a cybersecurity risk assessment? A cybersecurity risk assessment is an in-depth review of your business’s cybersecurity program and risk level. The goal of an assessment is to evaluate your threat environment and then align your cybersecurity efforts to better protect against those risks. A risk assessment includes both external threats, like phishing scams or ransomware attacks and internal threats, like employee fraud. An assessment will consider your specific industry. A manufacturing company faces different risks than a financial services firm, which will also differ from a construction company that contracts with the military. During the assessment, you’ll also evaluate your security controls to determine whether those controls can successfully mitigate your threats to an acceptable level or need improvements. Cybersecurity risk assessment vs. cybersecurity audit: What’s the difference? A cybersecurity risk assessment and a cybersecurity audit are two different, but related activities. Here are the key differences: Cybersecurity risk assessment Cybersecurity audit Goal Big-picture evaluation to understand your cybersecurity threats, controls, gaps and overall level of risk. Audit to determine whether your security controls meet the standards of a specific cybersecurity framework like NIST CSF or ISO 27001. Purpose Help you make business decisions about managing risk. Demonstrate compliance with a cybersecurity framework. Focus Identifying threats. Evaluating specific controls Primary audience Your executives, board and IT leadership (although it may be useful to external stakeholders too). Customers, clients, partners, investors and regulators Outcome A clearer awareness of your enterprise-level cybersecurity risks and how to manage them. External stakeholders are satisfied that you meet their standards or requirements for doing business. Why cybersecurity risk assessments matter for business leaders Business leaders increasingly understand that cybersecurity is a financial business risk . However, you probably don’t know your specific vulnerabilities or which threats you should prioritize. A cybersecurity risk assessment will help you better evaluate your risk of threats like: Data breaches Unauthorized network access A ransomware or malware incident Unauthorized funds transfer or fraud Business email compromise Business interruption Risks associated with a mobile workforce or remote work During an assessment, you’ll get a better sense of how these and other cybersecurity threats affect your specific business and if you have the controls and governance needed to defend against them. This is a key step toward making your business not just more secure but also more cyber-resilient . A cybersecurity risk assessment offers additional strategic benefits Beyond understanding your threat environment, risk levels and priorities, completing a cybersecurity risk assessment can also offer additional strategic benefits. These include: Meeting compliance standards: For businesses that operate in regulated industries, an assessment helps you understand whether you meet security compliance requirements. Satisfying insurers: A cyber risk assessment is increasingly a requirement to get cybersecurity insurance, especially if you want to pay reasonable rates. Demonstrating a board-level commitment to security: Boards don’t get a pass on cybersecurity oversight anymore, and are required to take more responsibility for managing organizational cyber risk. Fulfilling due diligence requirements: Cybersecurity due diligence is an essential element of any transaction, with sellers needing to prepare their businesses for scrutiny (and potentially command a higher price ) and buyers wanting to clearly understand the risks they could be taking on. Establish trust: Conducting a cybersecurity risk assessment demonstrates a level of organizational maturity that impresses partners, customers, clients and other external stakeholders. Protect your reputation: Managing your cybersecurity risk is also an investment in protecting your reputation from damaging incidents that could hurt your public image. Better understand AI risks: There’s significant overlap between cyber and AI risks, so a risk assessment can also help you better understand the risks you face as you integrate AI more deeply into your organization. What does a cybersecurity risk assessment include? A cybersecurity risk assessment typically involves working with a third-party cybersecurity advisor to evaluate your risk and cyber readiness levels so you can manage them more effectively. Key elements of an effective assessment include: Choose a cybersecurity risk advisor Most successful cybersecurity risk assessments start by bringing in an external partner to conduct the assessment. This is the gold standard. You shouldn’t even consider trying to do an assessment in-house unless you have a skilled, knowledgeable internal audit team in place (and even then, your internal team may be too close to your business to offer the most useful perspective). Evaluate cybersecurity as part of a broader enterprise risk assessment Cybersecurity risk is intertwined with other enterprise-level risks, like operational risk, AI risk and technology risk. Mature organizations will typically do a cybersecurity risk assessment as part of a broader enterprise risk assessment that evaluates all these areas. If you can, take this approach, because it offers a holistic perspective that’s invaluable to understanding the complete risk picture, which leads to smarter business decisions. Include a business impact analysis A good risk assessment should include a business impact analysis to evaluate how a disruption to each department within your business would affect your business as a whole. This involves identifying the type of information each department is using and how downtime in a particular department would hurt your operations or reputation. Align your approach to industry standards Consider how your industry as a whole manages risk and cybersecurity. Many industries use a particular risk or cybersecurity framework, like NIST or ISO. Align your assessment to whatever your industry standard framework is, while also adapting for areas like AI that may not be incorporated into existing frameworks. How to conduct a cybersecurity risk assessment A cybersecurity risk assessment is a process that includes several stages. While your particular assessment may align with a specific risk framework like NIST 800-30, here are key steps that you should expect to see in most assessments: 1. Define assessment objectives Establish a clear scope for your assessment as well as the specific outcomes you plan to achieve. 2. Inventory systems and data Create an inventory of all systems and data that are vulnerable to cybersecurity-related threats. 3. Identify threats and vulnerabilities Based on your inventory, look for what are called inherent risks or threats that exist prior to implementing mitigating controls. 4. Evaluate likelihood and impact Assess your risks to determine which are the most dangerous or likely to occur, classifying the most urgent as high-likelihood, high-impact. 5. Prioritize and address risks You can’t defend against every risk at all times, so you want to create a risk management roadmap that establishes priorities based on the likelihood and impact analysis you’ve completed, then implement controls to mitigate those risks. 6. Monitor and reassess Risks are constantly changing, so think of risk assessment as an evolving process that involves periodic formal assessments, regular testing and ongoing monitoring. Cybersecurity risk assessment checklist Download Wipfli’s cybersecurity risk assessment checklist to get an actionable one-pager that lays out how to get ready for, conduct and learn from a cybersecurity risk assessment. Get your cybersecurity risk assessment checklist Read more Cybersecurity is now a major financial risk for businesses Nation-state actors represent a growing cybersecurity threat The right cybersecurity framework boosts a business’s value | Wipfli

Perspective changes everything.

Receive timely industry developments, regulatory changes and other news impacting your success.

Reach out to our team

Talk to our team to see how you can better navigate complex governance, risk and compliance challenges.

FAQs about enterprise risk management services