IBM Cloud

2024

Turning a fragmented audit process into a scalable product

How a design thinking workshop uncovered an opportunity to rethink audit management at IBM Cloud

My Role

Lead UX Designer

Timeline

1 year

Category

User Research, Workshop Facilitation, Product Strategy

Team

Visual Designer, Design Systems Lead, UX Researcher

IBM Cloud

2024

Turning a fragmented audit process into a scalable product

How a design thinking workshop uncovered an opportunity to rethink audit management at IBM Cloud

My Role

Lead UX Designer

Timeline

1 year

Category

User Research, Workshop Facilitation, Product Strategy

Team

Visual Designer, Design Systems Lead, UX Researcher

Overview

Security teams were spending too much time on compliance

An annual survey of 77 IBM Cloud Security Focals revealed a significant efficiency problem. 79% spent at least a quarter of their time supporting compliance activities, while only 5% were dedicated solely to Security Focal responsibilities.

Results from 2023 Annual Cloud Security Focal Survey

The problem

Security Focals were responsible for keeping products secure and compliant, but repetitive administrative work was consuming a meaningful portion of their time.

We wanted to understand what their biggest pain points were, and how we could give them some time back to focus on securing products.

Security Focals were responsible for keeping products secure and compliant, but repetitive administrative work was consuming a meaningful portion of their time.

We wanted to understand what their biggest pain points were, and how we could give them some time back to focus on securing products.

Discovery

Starting with the people closest to the problem

I partnered with the Security Program Director, Security Focal lead, and UX Researcher to plan and facilitate a four-day, in-person design thinking workshop with 14 Security Focals from across IBM Cloud to dig into where that time was going.

We started by mapping their existing workflows to identify repetitive, time-consuming tasks and create an as-is journey.

In-person workshop with Security Focals at the IBM Austin Design Studio

“Casey was instrumental to the planning and execution of this EDT session. Her facilitation was instrumental to this session's success.”

“Casey was instrumental to the planning and execution of this EDT session. Her facilitation was instrumental to this session's success.”

— IBM Cloud Platform Security Program Director

Audit support emerged as a problem worth solving

The workshop surfaced audit support as one of the biggest opportunities to reduce repetitive compliance work.

Preparing for an audit required Security Focals, Compliance Analysts, and external auditors to coordinate evidence and reviews across multiple disconnected systems.

Current internal audit processes require back and forth between 3 tools

Designing an internal solution would have been relatively straightforward: understand IBM's existing workflow and consolidate it into a better interface, but we wanted the product to eventually serve customers outside IBM.

That meant distinguishing between fundamental audit-management needs and processes that existed simply because that's how IBM had historically operated.

How might we…

Simplify IBM's audit workflow while creating an experience grounded in industry practices that could scale beyond IBM?

Research

Designing for IBM today and external customers tomorrow

The product needed to improve audit management for IBM's internal teams in the short term, but the long-term vision was to offer it to external customers. Simply digitizing IBM's existing process could make the product difficult to scale, while designing only around industry standards could fail to meet the needs of our first users.

Our research focused on answering two questions:

Question 1

What does a mature audit management product need to support?

Question 2

How do IBM's internal processes compare to the broader market?

To answer the first question, I conducted competitive analysis of established platforms.

To answer the first question, I conducted competitive analysis of established platforms.

Competitive analysis of key competitor features

Competitive analysis of key competitor features

Findings:

Most competitors offered mature audit capabilities as part of much larger platforms, the most notable being:

Centralized Dashboard

Understand progress and outstanding work.

Pre-defined frameworks

Support established frameworks such as SOC 2.

Evidence collection

Collect and review manual and automated evidence.

Reporting

Prepare audit information for external auditors.

For the second question, I conducted user research with internal and external users.

For the second question, I conducted user research with internal and external users.

We recruited a diverse sample set of participants in order to get their unique perspectives. We conducted interviews with:

6 Internal compliance analysts

To understand IBM's existing workflows, terminology, and pain points

9 External compliance analysts

To understand industry workflows and expectations

4 Security executives

To understand the broader requirements in organizations

Findings:

Industry terminology conflicted with IBM’s internal language

Industry terminology conflicted with IBM’s internal language

IBM teams had developed their own audit terminology, so industry-standard terms didn’t always match their expectations. We needed to balance familiarity for internal users with language that could scale externally.

Synthesis of research findings

Synthesis of research findings

The concept was easy to use, but internal workflows required more

The concept was easy to use, but internal workflows required more

I collected UMUX-Lite scores to measure both ease of use and whether the concept met participants’ needs. Participants generally found the experience easy to use, but internal users rated its feature coverage lower than external users.

This reinforced a key tension in our strategy: a scalable product could follow industry conventions, but still needed to account for IBM-specific workflows in the short term.

(Left) Internal UMUX Lite scores (Right) External UMUX Lite Scores

(Left) Internal UMUX Lite scores (Right) External UMUX Lite Scores

Automation needed a human checkpoint

Automation needed a human checkpoint

Participants valued the efficiency of an in-platform auditor experience, but wanted to review and approve evidence before it was shared externally. This reinforced that automation needed to preserve human oversight for sensitive audit workflows.

Synthesis of research findings

Synthesis of research findings

““I am a huge fan of automation but some things need manual intervention.”

— Research participant
Strategy

From research to product direction

The research challenged key assumptions about how the product should work. I translated the findings into a North Star experience and presented the vision to leadership to align on product direction.

From there, I worked with product, engineering, and security to prioritize an MVP focused on audit progress, control management, and evidence collection, while laying the foundation for future capabilities.

Competitive analysis of key competitor features

Competitive analysis of key competitor features

Conclusion

Design isn't always about the final UI

This project reinforced that some of design's most valuable work happens before a polished interface exists.

Through research and design thinking, we challenged assumptions, shaped the product strategy, and gave leadership a clearer direction for what to build.

What I learned

Although the product was discontinued before launch, the work taught me that design is as much about creating clarity, influencing decisions, and solving the right problem as it is about the final interface.