Report to the Audit Committee

Size: px
Start display at page:

Download "Report to the Audit Committee"

Transcription

1 Report to the Audit Committee Agenda of: JANUARY 14, 2014 From: Rahoof Wally Oyewole, Departmental Audit Manager ITEM: V SUBJECT: INTERNAL AUDIT WORKPLAN THROUGH FISCAL YEAR AND POSSIBLE COMMITTEE ACTION Recommendation: That the Audit Committee consider the proposed Internal Audit workplan through Fiscal Year (FY) ; and recommend the workplan to the Board for approval. Discussion: Internal Audit is responsible for developing, for Audit Committee consideration, a flexible audit plan using an appropriate risk based methodology. In order to meet the International Standards for the Professional Practice of Internal Auditing (IIA Standards), Internal Audit s Workplan is required to be approved by LACERS s Audit Committee and/or the Board. The workplan is intended to remain flexible to allow necessary changes as a result of ongoing changes to risk factors, organizational needs, resource limitations or a request from management and/or the Board. Updates information regarding changes to the plan will be provided to the Committee at each Committee meeting during the Fiscal Year. Internal Audit Risk Assessment Process To assess the relative importance of potential audit subjects, the IAS prepares an annual risk assessment (Attachment 1) covering all divisions and functions performed by LACERS. This department-wide risk assessment focuses on comparisons between different programs and functions, with the primary purpose of identifying high impact audit areas. Risk is measured through an analysis of various information sources on each critical process/function/unit. Internal Audit has established a methodology to evaluate the relative importance of potential audit projects. Individual project priority ranking is based on risk factors of impact and likelihood. Internal Audit has identified key processes or programs and the following five risk criteria: 1. Strategic & Operational - The significance of the process or area to LACERS strategic success, or impact of process disruption. 2. Financial Materiality - The magnitude of financial exposure, the degree of regulatory oversight, or possible financial penalties. The higher the financial exposure of an area, the higher the risk. Committee Report 1 January 14, 2014

2 3. Complexity of Operations/Regulations - Considers the complexity of programs, activities, and/or functions. The number of individuals, entities, and processes involved, and the degree to which professional judgment or technical expertise is applied. The more complex the operations, the higher the risk. 4. Organizational and System Change Risk Considers changes in the control environment. How much the process has been altered and the change of personnel carrying out the process. The more recent changes, the higher the risk. 5. Political/Reputation (including impact to Members) - The degree of public interest and awareness, the visibility of the process to the media. The higher the interest, the higher the risk. The following three steps were used to score each potential audit project. Step 1 s For each potential audit area, Internal Audit assign an impact risk score relative to each of the above five factors, as follows: High Step 2 Probability or Likelihood s In assigning probability scores, Internal Audit considers inputs provided by senior staff and Board Members, as summarized in Attachment 2, interviews with staff and LACERS external auditors, review of policies, and the Internal Control Self-Assessment completed by division management. Internal Audit then assigns a probability score for each potential audit area, as follows: Probability of Risk High probability or likelihood of significant problems occurring Moderate probability of significant problems and/or high probability of improvements needed probability of significant problems and/or low probability of improvement needed Step 3 Final Risk s To determine final risk scores, impact scores were sub-totaled for each potential audit area and multiplied by the estimated probability of an adverse event occurring in each audit project area. Committee Report 2 January 14, 2014

3 Proposed Audit Projects for the Audit Workplan (Attachment 3) Based on the result of the risk assessment and final risk scores, Internal Audit recommends scheduling the following audit projects: 1. Business Continuity/Disaster Recovery Plan (Final Risk 17.7) - The purpose of a business continuity/disaster recovery is to enable an organization to continue operation in the event of a disruption and to survive a disastrous interruption to its information systems. The objective of an audit of Business Continuity Plan (BCP) will be to evaluate LACERS BCP to determine its adequacy and currency in comparison to appropriate standards; verify the plan is effective by reviewing previous test results; and evaluate the ability of the System and user personnel to respond effectively in emergency situations. 2. Investment Manager Fees (Final Risk 16.8) In FY , LACERS paid approximately $48 million in investment management fees, with $27 million (56%) of this amount attributed to real estate and alternative investments. It is has become increasingly difficult for Fiscal staff and LACERS external auditors to validate the accuracy of fees paid, particularly for real estate and private equity investments. This is primarily because of the limited supporting documentation submitted with invoices. The objective of an audit of fees will be to recalculate fees that LACERS paid to a sample of investment managers during FY , to ensure they are accurate and in accordance with contract terms approved by the Board. It should be noted that a few months ago, LAFPP Board approved an appropriation for the Department to engage a CPA firm to re-calculate fees paid for alternative investments management. 3. Employer Audit (Final Risk 16.8) The objective of this audit will be to evaluate the accuracy of enrollment information, and deductions remitted to LACERS for employees. The focus will be to evaluate procedures in place to ensure individuals are placed in correct tier and/or plan. The audit will also assess procedures to ensure accurate deductions are remitted, particularly for employees who receive non-traditional lump sum payments that are subject to retirement contributions. 4. Benefit Determination and Payments (Final Risk 14.7) - The objective of this audit will be to determine the efficiency of benefit setup process and whether benefits calculations are accurate and properly supported. The audit will also assess the accuracy and timeliness of ongoing payments after the initial setup to determine whether the process is efficient, effective and in accordance with the Administrative Codes. 5. System Access, Change Control & Data Security (Final Risk 14.4) - The objective of this audit will be to evaluate whether employees access to various systems are appropriate based on their duties. This audit will also evaluate procedures to ensure adequate data security and change control procedures. 6. Network Vulnerability and Penetration Testing (Final Risk 17.5) Penetration testing is often referred to as ethical hacking and is intended to mimic an experienced hacker attacking a live site. Many organizations engage security professionals to perform penetration testing to find vulnerabilities so that they can fix them before an attack. Penetration testing should only be performed by experienced and qualified professionals who are aware of the risks and can limit any damage resulting from a successful break-in. This project is contingent on the Board s appropriating necessary funds in the FY Budget to engage an outside security firm with expertise in penetration testing to complete the project. Committee Report 3 January 14, 2014

4 In accordance with the Internal Audit Charter, the workplan also set aside some hours for consulting activities to assist management during the Fiscal Year. Staff will also take active roles in managing the external audit contract as well as the upcoming implementation of the new GASB 67. As LACERS needs and priorities change, Internal Audit will use professional judgment as to determine the order in which audit projects are completed. Staff will focus on efficiency and effectiveness in performing work and will make effort to review all areas identified in this workplan. Staff will provide Audit Committee a quarterly update on the workplan. At the end of FY , any remaining projects will be re evaluated during the Annual Risk Assessment process for consideration in the next Fiscal Year audit plan. This report was prepared by Rahoof Wally Oyewole, Departmental Audit Manager, Internal Audit Section. RWO Attachments: 1) LACERS Internal Audit s Universe Risk Assessment January ) Risk Assessment Survey Results 3) LACERS Internal Audit Proposed Workplan Through FY Committee Report 4 January 14, 2014

5 LACERS Internal Audit Section Universe Risk Assessment - January 2014 ATTACHMENT 1 Risk Rankings High High to to Definitions Factors Division Systems Systems Auditable Unit/Process Materiality / Financial / Compliance Strategic / Operational Change / Stability Complexity of Operations or Regulations Political / Reputation (Including to Members) Subtotal Probability Final Risk Business Continuity / Disaster Recovery Plan Web-Based Network Vulnerabilities, Penetration Test Rank Order Investments Investment Manager Fees Plan Sponsor Services Systems City - Accuracy of Enrollment & Deductions Remitted to LACERS Benefits Determination, Setup & Payments System Access,Change Control & Data Security Process Services Reciprocity & Service Purchase Process Services Disability Process Services Health Admin Death Comparison/Member Status Verification Process Account Reconciliation, Billing and Invoices Health Admin Medical Subsidy Process Services Survivor Claims/Family Death Benefits Services Privacy of Member Data Health Admin Medial Premium Reimbursement Program (for members out of regular coverage area) - MPRP Services Member Refunds/Lump Sum Payments Page 1 of 3

6 LACERS Internal Audit Section Universe Risk Assessment - January 2014 ATTACHMENT 1 Risk Rankings High High to to Definitions Factors Division Auditable Unit/Process Materiality / Financial / Compliance Strategic / Operational Change / Stability Complexity of Operations or Regulations Political / Reputation (Including to Members) Subtotal Probability Final Risk Rank Order Investments Risk Management Program & Investment Compliance Monitoring Process Investments Due Diligence Process Member Support Services- Health Admin Communication Investments Investment RFP Process (manager selection, reporting, renewal, and termination) Health Admin Enrollment & Dependent Eligibility Verification Process Health Admin Medicare Enrollment and Medicare Part B premium reimbursements Services Larger Annuity Porgram Review Accounting Investment Accounting and Valuation Systems Wire Transfer and Check Receipt Process Office Services RFP and Procurement Process, and Contracting Practices Investments Investment Reconciliations Services Stale Dated Checks Human Resources Temporary Employees - Recruitment and Monitoring Process Office Services Budgets Systems/Fiscal Actuarial/Member Demographic Data Page 2 of 3

7 LACERS Internal Audit Section Universe Risk Assessment - January 2014 ATTACHMENT 1 Risk Rankings High High to to Definitions Division Auditable Unit/Process Materiality / Financial / Compliance Strategic / Operational Factors Change / Stability Complexity of Operations or Regulations Political / Reputation (Including to Members) Subtotal Probability Final Risk Accounting Contribution Accounting - Member, City Services Benefits Overpayment & Collection Process Office Services Fixed Assets Inventory Systems IT Governance Rank Order Investments Asset Allocation Services Service Counseling Process Accounting Cash Management Accounting General Ledger/Financial Reporting Office Services Vendor Contract Compliance Board Governance & Ethics Accounting Accounts Payable Human Resources HR Processes Accounting Travel/Office expenses Services Record Management and Retention Systems Pension Administration System - Data Conversion and Post Implemetation review Page 3 of 3

8 ATTACHMENT 2 Internal Audit Risk Assessment Survey Results As part of its risk assessment process, Internal Audit surveyed senior staff, executive management and Board Members. Ten responses were received (eight from senior staff and two from Board Members). The purpose of the survey was to seek inputs as to what operational areas and critical functions staff believe need improvement and/or could benefit from audit attention. The following are the areas/concerns identified by staff, along with the number of times mentioned: 1. Accuracy and timeliness of benefit processing (4 times) 2. Making sure that political pressure does not determine investments (4 times) 3. Disaster/business continuity plan (3 times) 4. Employer Audit - accuracy of employee information and contributions (3 times) 5. Inconsistent application/interpretation of policies (including HR-related) and Admin Code (special accommodation for employees at certain level) (3 times) 6. Disconnect between frontline staff and management (3 times) 7. Customer service -monitoring of outgoing communications to Members (3 times) 8. Certain Board members may be stepping out of policy making and oversight arena into operational areas (3 times) 9. System access/controls & data security (2 times) 10. IRC compliance - (2 times) 11. Accurate reporting to stakeholders (2 times) 12. Monitoring of investment managers to ensure compliance with investment policy (2 times) 13. Inability to track international deaths- Risk of continuing payments after Member's death (2 times) 14. Budget monitoring and reporting - lack of systematic data (1 time) 15. Succession planning - reliance on few subject matter experts (1 time) 16. Lack of system to promptly identify concerns (1 time) 17. Preventing & recovering benefit overpayments (1 time) 18. Authentication of external documents (1 time) 19. Untimely communication from management regarding change that impact processing or delivery of benefits (1 time) 20. Inequitable span of control (1 time) 21. LACERS should pursue legal access rights (same as LACERA and CalPERS) to Members banking information for monitoring (1 time)

9 LACERS INTERNAL AUDIT SECTION AUDIT PLAN THROUGH FY ATTACHMENT 3 Internal Audit Projects Description/Audit Objective Rank Based on Risk s Estimated Hours Business Continuity/Disaster Recovery Plan (BCP) Investment Manager Fees Employer Audit Benefit Determination & Payments System Access, Change Control & Data Security Follow -Up Program To evaluate LACERS' BCP to determine its adequacy and currency, review previous test results and evaluate staff's ability to respond effectively in emergency situations To determine whether investment management fees paid during FY are accurate in accordance with contract terms approved by the Board To evaluate the accuracy of enrollment information, and deductions remitted to LACERS on behalf of employees To determine the efficiency and effectiveness of benefit setup process, and whether benefits calculations are accurate and properly supported To evaluate employees' access rights, change control and data security procedures for reasonableness and effectiveness Establish a Follow-up Program to track and follow up on prior audit recommendations. 400 Internal Audit Subtotal 2,500 External Audits Network Vulnerability & Penetration Testing Perform vulnerability assessment and penetration testing to identify any weaknesses that need to be addressed Annual Financial Statement Audit Performed by external auditors 100 External Audit Subtotal 350 Non-Audit Projects Consulting Activities As requested by Executive Management 600 GASB 67 Implementation Task Force participation 150 (1) This workplan assumes two auditors effective April 1, 2014 (5,220 available hours from 4/1/14 to 6/30/15). Page 1 of 2

10 LACERS INTERNAL AUDIT SECTION AUDIT PLAN THROUGH FY ATTACHMENT Risk Assessment/Audit Plan Annual risk assessment and preparation of subsequent audit plan 200 Internal Control Self Assessment Provide management with internal control worksheets and review responses. 150 Non-Audit Subtotal 1,100 Administration Preparation and attendance at Audit Committee, other Committees and Board Committee and Board Meetings meetings. 200 General Administration Audit administrative duties, staff meetings & other duties 300 Lay the groundwork for acquiring and implementing electronic workpaper and computer-assisted data analysis software (research different tools, obtain quotes and Audit Software Implementation make recommendation) 80 Administration Subtotal 580 Leave/Time Off Training/Conferences Training to maintain CPA and other certifications, APPFA, IIA or ALGA Conferences 200 Leave Holidays and Time Off 490 Leave/Time Off Grand Total Hours 690 5,220 (1) This workplan assumes two auditors effective April 1, 2014 (5,220 available hours from 4/1/14 to 6/30/15). Page 2 of 2

Proposed Audit Plan for Fiscal Year 2015-16 and Preliminary Audit Plan for Fiscal Year 2016-17

Proposed Audit Plan for Fiscal Year 2015-16 and Preliminary Audit Plan for Fiscal Year 2016-17 Page 1 of 13 Proposed Audit Plan for Fiscal Year 2015-16 and Preliminary Audit Plan for Fiscal Year 2016-17 A June 2015 Page 2 of 13 Table of Contents Section I FY 2015-16 Proposed Audit Plan Pension and

More information

THIRD PARTY. T i m L i e t z R e g i o n a l P r a c t i c e L e a d e r R i s k A d v i s o r y S e r v i c e s

THIRD PARTY. T i m L i e t z R e g i o n a l P r a c t i c e L e a d e r R i s k A d v i s o r y S e r v i c e s MANAGING THIRD PARTY RISK T i m L i e t z R e g i o n a l P r a c t i c e L e a d e r R i s k A d v i s o r y S e r v i c e s Experis -- a different kind of talent company. Experis Tuesday, January 08,

More information

Maryland Health Insurance Plan

Maryland Health Insurance Plan Audit Report Maryland Health Insurance Plan April 2012 OFFICE OF LEGISLATIVE AUDITS DEPARTMENT OF LEGISLATIVE SERVICES MARYLAND GENERAL ASSEMBLY This report and any related follow-up correspondence are

More information

The Procter & Gamble Company Board of Directors Audit Committee Charter

The Procter & Gamble Company Board of Directors Audit Committee Charter The Procter & Gamble Company Board of Directors Audit Committee Charter I. Purposes. The Audit Committee (the Committee ) is appointed by the Board of Directors for the primary purposes of: A. Assisting

More information

Los Angeles County Metropolitan Transportation Authority Office of the Inspector General Medicare Part B Reimbursements to Retirees

Los Angeles County Metropolitan Transportation Authority Office of the Inspector General Medicare Part B Reimbursements to Retirees Los Angeles County Metropolitan Transportation Authority Medicare Part B Reimbursements to Retirees Several procedural refinements are needed to ensure that reimbursements are discontinued for deceased

More information

Compliance Department No. COMP.1000.18 Title: EFFECTIVE SYSTEM FOR ROUTINE MONITORING, AUDITING, AND IDENTIFICATION OF COMPLIANCE RISKS (ELEMENT 6)

Compliance Department No. COMP.1000.18 Title: EFFECTIVE SYSTEM FOR ROUTINE MONITORING, AUDITING, AND IDENTIFICATION OF COMPLIANCE RISKS (ELEMENT 6) Page: 1 of 9 I. SCOPE: This policy applies to (1) Tenet Healthcare Corporation and its wholly-owned subsidiaries and affiliates (each, an Affiliate ); and (2) any other entity or organization in which

More information

Get More Out of Your Risk Assessment. Austin Chapter of the IIA

Get More Out of Your Risk Assessment. Austin Chapter of the IIA Get More Out of Your Risk Assessment Austin Chapter of the IIA Speakers Alyssa G. Martin, CPA Dallas Executive Partner, Advisory Services 25 years of public accounting experience, with a practice emphasis

More information

Internal Audit and Advisory Services DRAFT

Internal Audit and Advisory Services DRAFT Internal Audit and Advisory Services DRAFT PAGE(S) Message from the Internal Audit and Advisory Services...1-2 Internal Audit and Advisory Services Plan...3-5 Objectives...6-7 Risk Assessment Process...8

More information

Mecklenburg County Department of Internal Audit. Park and Recreation Department Contract Management Investigation Report 1401

Mecklenburg County Department of Internal Audit. Park and Recreation Department Contract Management Investigation Report 1401 Mecklenburg County Department of Internal Audit Park and Recreation Department Contract Management Investigation Report 1401 September 22, 2014 Internal Audit s Mission Through open communication, professionalism,

More information

LOCAL GOVERNMENT MANAGEMENT ASSESSMENT OVERVIEW AND QUESTIONNAIRE

LOCAL GOVERNMENT MANAGEMENT ASSESSMENT OVERVIEW AND QUESTIONNAIRE LOCAL GOVERNMENT MANAGEMENT ASSESSMENT OVERVIEW AND QUESTIONNAIRE The Comptroller s Economic Development and Analysis (EDA) Division provides education and direct assistance to local governments, helping

More information

FIRST CITIZENS BANCSHARES, INC. FIRST-CITIZENS BANK & TRUST COMPANY CHARTER OF THE JOINT AUDIT COMMITTEE

FIRST CITIZENS BANCSHARES, INC. FIRST-CITIZENS BANK & TRUST COMPANY CHARTER OF THE JOINT AUDIT COMMITTEE FIRST CITIZENS BANCSHARES, INC. FIRST-CITIZENS BANK & TRUST COMPANY CHARTER OF THE JOINT AUDIT COMMITTEE As amended, restated, and approved by the Boards of Directors on July 28, 2015 This Charter sets

More information

OUTSOURCING DUE DILIGENCE FORM

OUTSOURCING DUE DILIGENCE FORM OUTSOURCING DUE DILIGENCE FORM SERVICE TO BE OUTSOURCED 1. Type of service to be outsourced: Accounting/Finance: Compliance Consulting: Legal Services: Administrative Functions: Information Technology:

More information

SCOPE OF WORK FOR PERFORMING INTERNAL CONTROL AND STATUTORY/REGULATORY COMPLIANCE AUDITS FOR RECIPIENTS OF SPECIAL MUNICIPAL AID

SCOPE OF WORK FOR PERFORMING INTERNAL CONTROL AND STATUTORY/REGULATORY COMPLIANCE AUDITS FOR RECIPIENTS OF SPECIAL MUNICIPAL AID SCOPE OF WORK FOR PERFORMING INTERNAL CONTROL AND STATUTORY/REGULATORY COMPLIANCE AUDITS FOR RECIPIENTS OF SPECIAL MUNICIPAL AID State of New Jersey Department of Community Affairs Division of Local Government

More information

THE STRATEGIC PLAN OF THE INDIANA PUBLIC RETIREMENT SYSTEM FOR THE PERIOD OF FISCAL YEARS

THE STRATEGIC PLAN OF THE INDIANA PUBLIC RETIREMENT SYSTEM FOR THE PERIOD OF FISCAL YEARS THE STRATEGIC PLAN OF THE INDIANA PUBLIC RETIREMENT SYSTEM FOR THE PERIOD OF FISCAL YEARS 2016-2018 TABLE OF CONTENTS INTRODUCTION TO THE STRATEGIC PLAN 4 GOALS, OBJECTIVES & KEY OPERATIONAL REQUIREMENTS

More information

BOARD OF EDUCATION OF BALTIMORE COUNTY OFFICE OF INTERNAL AUDIT - OPERATIONS MANUAL INTERNAL AUDIT OPERATIONS MANUAL

BOARD OF EDUCATION OF BALTIMORE COUNTY OFFICE OF INTERNAL AUDIT - OPERATIONS MANUAL INTERNAL AUDIT OPERATIONS MANUAL BOARD OF EDUCATION OF BALTIMORE COUNTY INTERNAL AUDIT OPERATIONS MANUAL BACKGROUND The Office of Internal Audit Operations Manual was developed to be used as a guide and resource for the Office of Internal

More information

Annual Risk Assessment and Audit Plan Fiscal Year 2015/2016

Annual Risk Assessment and Audit Plan Fiscal Year 2015/2016 Annual Risk Assessment and Audit Plan Fiscal Year 2015/2016 Office of the Internal Auditor May 2015 Table of Contents Introduction... 3 Risk Assessment Process... 3 Interpreting Risk Assessment Results...

More information

The ADT Corporation. Audit Committee Charter. December 2014

The ADT Corporation. Audit Committee Charter. December 2014 The ADT Corporation Audit Committee Charter December 2014 1 TABLE OF CONTENTS Purpose... 3 Authority... 3 Composition... 3 Meetings... 3 Responsibilities... 4 Financial Statements... 4 External Audit...

More information

Charter of the Audit Committee of the Board of Directors of Woodward, Inc.

Charter of the Audit Committee of the Board of Directors of Woodward, Inc. AUDIT COMMITTEE CHARTER Charter of the Audit Committee of the Board of Directors of Woodward, Inc. Purpose The Audit Committee (the Committee ) is appointed by the Board of Directors to oversee the accounting

More information

June 2008 Report No. 08-038. An Audit Report on The Department of Information Resources and the Consolidation of the State s Data Centers

June 2008 Report No. 08-038. An Audit Report on The Department of Information Resources and the Consolidation of the State s Data Centers John Keel, CPA State Auditor An Audit Report on The Department of Information Resources and the Consolidation of the State s Data Centers Report No. 08-038 An Audit Report on The Department of Information

More information

Operational Risk Management Policy

Operational Risk Management Policy Operational Risk Management Policy Operational Risk Definition A bank, including a development bank, is influenced by the developments of the external environment in which it is called to operate, as well

More information

Sample Financial institution Risk Management Policy 2011

Sample Financial institution Risk Management Policy 2011 Sample Financial institution Risk Management Policy 2011 1 Contents Risk Management Program...2 Internal Control and Risk Management Diagram... 2 General Control Environment... 2 Specific Internal Control

More information

Administrative Guidelines on the Internal Control Framework and Internal Audit Standards

Administrative Guidelines on the Internal Control Framework and Internal Audit Standards Administrative Guidelines on the Internal Control Framework and Internal Audit Standards GCF/B.09/18 18 February 2015 Meeting of the Board 24 26 March 2015 Songdo, Republic of Korea Agenda item 24 Page

More information

ERM Program. Enterprise Risk Management Guideline

ERM Program. Enterprise Risk Management Guideline ERM Program Enterprise Management Guideline Table of Contents PREAMBLE... 2 When should I refer to this Guideline?... 3 Why do we need a Guideline?... 4 How do I use this Guideline?... 4 Who is responsible

More information

GAO. Standards for Internal Control in the Federal Government. Internal Control. United States General Accounting Office.

GAO. Standards for Internal Control in the Federal Government. Internal Control. United States General Accounting Office. GAO United States General Accounting Office Internal Control November 1999 Standards for Internal Control in the Federal Government GAO/AIMD-00-21.3.1 Foreword Federal policymakers and program managers

More information

October 20, 2015. Sincerely. Anthony Chavez, CIA, CGAP, CRMA Director, Internal Audit Division

October 20, 2015. Sincerely. Anthony Chavez, CIA, CGAP, CRMA Director, Internal Audit Division Internal Audit Annual Report Fiscal Year 2015 October 20, 2015 Honorable Greg Abbott, Governor Members of the Legislative Budget Board Members of the Sunset Advisory Commission Mr. John Keel, CPA, State

More information

December 2014 Report No. 15-017. An Audit Report on The Telecommunications Managed Services Contract at the Health and Human Services Commission

December 2014 Report No. 15-017. An Audit Report on The Telecommunications Managed Services Contract at the Health and Human Services Commission John Keel, CPA State Auditor An Audit Report on The Telecommunications Managed Services Contract at the Health and Human Services Commission Report No. 15-017 An Audit Report on The Telecommunications

More information

NORTHERN TRUST CORPORATION BUSINESS RISK COMMITTEE CHARTER

NORTHERN TRUST CORPORATION BUSINESS RISK COMMITTEE CHARTER NORTHERN TRUST CORPORATION BUSINESS RISK COMMITTEE CHARTER Effective January 20, 2015 (Supersedes the Business Risk Committee Charter Effective October 21, 2014) The By-laws of Northern Trust Corporation

More information

AGA Kansas City Chapter Data Analytics & Continuous Monitoring

AGA Kansas City Chapter Data Analytics & Continuous Monitoring AGA Kansas City Chapter Data Analytics & Continuous Monitoring Agenda Market Overview & Drivers for Change Key challenges that organizations face Data Analytics What is data analytics and how can it help

More information

Domain 1 The Process of Auditing Information Systems

Domain 1 The Process of Auditing Information Systems Certified Information Systems Auditor (CISA ) Certification Course Description Our 5-day ISACA Certified Information Systems Auditor (CISA) training course equips information professionals with the knowledge

More information

815 CMR 9.00: DEBT COLLECTION AND INTERCEPT. Section

815 CMR 9.00: DEBT COLLECTION AND INTERCEPT. Section 815 CMR 9.00: DEBT COLLECTION AND INTERCEPT Section 9.01: Purpose, Application and Authority 9.02: Definitions 9.03: Billing Entity Requirements for Collection of Debts 9.04: Simultaneous Submission of

More information

KANSAS CITY, MISSOURI RESPONSES TO THE FISCAL YEAR 2013 AUDIT MANAGEMENT LETTER

KANSAS CITY, MISSOURI RESPONSES TO THE FISCAL YEAR 2013 AUDIT MANAGEMENT LETTER KANSAS CITY, MISSOURI RESPONSES TO THE FISCAL YEAR 2013 AUDIT MANAGEMENT LETTER Material Weaknesses (0) No material weaknesses were reported for FY 2013. Significant Deficiencies (1) Grant Receivable Accounting

More information

AUDIT REPORT. The Energy Information Administration s Information Technology Program

AUDIT REPORT. The Energy Information Administration s Information Technology Program U.S. Department of Energy Office of Inspector General Office of Audits and Inspections AUDIT REPORT The Energy Information Administration s Information Technology Program DOE-OIG-16-04 November 2015 Department

More information

Internal Audit RFP 2013 Questions and Answers

Internal Audit RFP 2013 Questions and Answers Question set 1: 1. What do you like about your current outsource IA arrangement and what has prompted your consideration of alternative providers? IIT policy requires periodic placement of IA business

More information

How To Set Up A Committee To Check On Cit

How To Set Up A Committee To Check On Cit CIT Group Inc. Charter of the Audit Committee of the Board of Directors Adopted: October 22, 2003 Last Amended: April 20, 2015 I. PURPOSE The purpose of the Committee is to assist the Board in fulfilling

More information

815 CMR: COMPTROLLER'S DIVISION 815 CMR 9.00: DEBT COLLECTION AND INTERCEPT. Section

815 CMR: COMPTROLLER'S DIVISION 815 CMR 9.00: DEBT COLLECTION AND INTERCEPT. Section 815 CMR 9.00: DEBT COLLECTION AND INTERCEPT Section 9.01: Purpose, Application and Authority 9.02: Definitions 9.03: Billing Entity Requirements for Collection of Debts 9.04: Simultaneous Submission of

More information

TECK RESOURCES LIMITED AUDIT COMMITTEE CHARTER

TECK RESOURCES LIMITED AUDIT COMMITTEE CHARTER Page 1 of 7 A. GENERAL 1. PURPOSE The purpose of the Audit Committee (the Committee ) of the Board of Directors (the Board ) of Teck Resources Limited ( the Corporation ) is to provide an open avenue of

More information

Adding Value to the UK Community

Adding Value to the UK Community 2011 ANNUAL REPORT Adding Value to the UK Community Table of Contents Director s Message 1 In-House Quality Initiatives 2-3 Governance 4 Metric Scorecard 5-7 UKIA Staff 8-9 Internal Audit assists the University

More information

UNIVERSAL AMERICAN CORP. CHARTER OF THE AUDIT COMMITTEE OF THE BOARD OF DIRECTORS

UNIVERSAL AMERICAN CORP. CHARTER OF THE AUDIT COMMITTEE OF THE BOARD OF DIRECTORS Organization UNIVERSAL AMERICAN CORP. CHARTER OF THE AUDIT COMMITTEE OF THE BOARD OF DIRECTORS This charter governs the operations of the Audit Committee of Universal American Corp. (the Company ). The

More information

The principal purposes of the Audit Committee ( Committee ) of the Board of Directors ( Board ) of CSRA Inc. (the Company ) are to:

The principal purposes of the Audit Committee ( Committee ) of the Board of Directors ( Board ) of CSRA Inc. (the Company ) are to: CSRA Inc. AUDIT COMMITTEE CHARTER (EFFECTIVE December 16, 2015) I. PURPOSES OF THE COMMITTEE The principal purposes of the Audit Committee ( Committee ) of the Board of Directors ( Board ) of CSRA Inc.

More information

Insurance Administration

Insurance Administration Insurance Administration City of Tulsa Internal Auditing June 2009 Insurance Administration City of Tulsa Internal Auditing Ron Maxwell, CIA, CFE Chief Internal Auditor Phil Wood, CIA, CFA City Auditor

More information

ASTRAZENECA GLOBAL POLICY SAFEGUARDING COMPANY ASSETS AND RESOURCES

ASTRAZENECA GLOBAL POLICY SAFEGUARDING COMPANY ASSETS AND RESOURCES ASTRAZENECA GLOBAL POLICY SAFEGUARDING COMPANY ASSETS AND RESOURCES THIS POLICY SETS OUT THE REQUIREMENTS FOR SAFEGUARDING COMPANY ASSETS AND RESOURCES TO PROTECT PATIENTS, STAFF, PRODUCTS, PROPERTY AND

More information

Performance Audit City s Payment Process

Performance Audit City s Payment Process Performance Audit City s Payment Process January 2013 City Auditor s Office City of Kansas City, Missouri 18-2011 Office of the City Auditor 21 st Floor, City Hall 414 East 12 th Street (816) 513-3300

More information

Subject Area Descriptions

Subject Area Descriptions Subject Area Descriptions The CPE Fields of Study curriculum contains 23 subject matter areas. They are Accounting, Accounting (Governmental), Administrative Practice, Auditing, Auditing (Governmental),

More information

Table of Contents. Transmittal Letter... 1. Executive Summary... 2-3. Background... 4-5. Objectives and Approach... 6. Issues Matrix...

Table of Contents. Transmittal Letter... 1. Executive Summary... 2-3. Background... 4-5. Objectives and Approach... 6. Issues Matrix... Internal Audit Committee of Brevard County, Florida Internal Audit Review of Accounts Payable Prepared By: Internal Auditors of Brevard County September 22, 2010 Table of Contents Transmittal Letter...

More information

Operational Risk Publication Date: May 2015. 1. Operational Risk... 3

Operational Risk Publication Date: May 2015. 1. Operational Risk... 3 OPERATIONAL RISK Contents 1. Operational Risk... 3 1.1 Legislation... 3 1.2 Guidance... 3 1.3 Risk management process... 4 1.4 Risk register... 7 1.5 EBA Guidelines on the Security of Internet Payments...

More information

8/12/2013. Then. Now. Managing risk and compliance. August 14, 2013

8/12/2013. Then. Now. Managing risk and compliance. August 14, 2013 GLOBAL/INTERNATIONAL PAYROLL THE GROUND WORK August 14, 2013 Then Identifying & tracking the assignees Drafting a policy document Implementing a mobility process Deploying an assignment management system

More information

ATTACHMENT A - STATEMENT OF WORK REQUEST FOR PROPOSALS FOR INDEPENDENT BENEFIT CONSULTING, ACTUARIAL AND AUDITING SERVICES DMS-13/14-018

ATTACHMENT A - STATEMENT OF WORK REQUEST FOR PROPOSALS FOR INDEPENDENT BENEFIT CONSULTING, ACTUARIAL AND AUDITING SERVICES DMS-13/14-018 4050 Esplanade Way Tallahassee, Florida 32399-0950 Tel: 850.488.2786 Fax: 850. 922.6149 Rick Scott, Governor Craig J. Nichols, Agency Secretary ATTACHMENT A - STATEMENT OF WORK REQUEST FOR PROPOSALS FOR

More information

中 國 通 信 服 務 股 份 有 限 公 司

中 國 通 信 服 務 股 份 有 限 公 司 中 國 通 信 服 務 股 份 有 限 公 司 CHINA COMMUNICATIONS SERVICES CORPORATION LIMITED (A joint stock limited company incorporated in the People s Republic of China with limited liability) (Stock Code: 552) AUDIT COMMITTEE

More information

Financial Statements. Nova Scotia Association of Health Organizations (Group Insurance Fund) March 31, 2015

Financial Statements. Nova Scotia Association of Health Organizations (Group Insurance Fund) March 31, 2015 Financial Statements Nova Scotia Association of Health Organizations INDEPENDENT AUDITORS REPORT To the Members of the Nova Scotia Association of Health Organizations We have audited the accompanying financial

More information

Audit of Employee Health and Pension Benefits:

Audit of Employee Health and Pension Benefits: Report # 2011-01 Audit of Employee Health and Pension Benefits: The Administration Of Health Benefits Has Strengthened, But Areas Of Concern Remain The City s Current Methods For Determining Premium Amounts

More information

Questionnaire/Compliance Form for COBRA Administration

Questionnaire/Compliance Form for COBRA Administration Form for COBRA Administration Questionnaire/Compliance 1. General Information 1.1 Total number of employees in your company. 1.2 Your company shall submit renewal fees to the district no later than February

More information

Revenue Cycle Assessment

Revenue Cycle Assessment Revenue Cycle Assessment Your Challenge Maintaining the status quo can be costly. As health care operating margins shrink, hospitals need to find efficient and innovative ways to capture and collect revenues.

More information

PENSION FUND OF THE PENSION PLAN FOR NON-PROFESSIONAL STAFF OF THE UNIVERSITY OF GUELPH. For the Year Ended September 30, 2011

PENSION FUND OF THE PENSION PLAN FOR NON-PROFESSIONAL STAFF OF THE UNIVERSITY OF GUELPH. For the Year Ended September 30, 2011 PENSION FUND OF THE PENSION PLAN FOR NON-PROFESSIONAL STAFF OF THE UNIVERSITY OF GUELPH March 8, 2012 Independent Auditor s Report To the Board of Governors We have audited the accompanying financial statements

More information

Federal Spending Data Quality Plan

Federal Spending Data Quality Plan Federal Spending Data Quality Plan July 23, 2010 PBGC Federal Spending Data Quality Plan Introduction The PBGC is a federal corporation created by the Employee Retirement Income Security Act of 1974. It

More information

Final Report. Audit of the Project Management Framework. December 2014

Final Report. Audit of the Project Management Framework. December 2014 Final Report Audit of the Project Management Framework December 2014 Audit of the Project Management Framework Table of Contents Executive summary... i A - Introduction... 1 1. Background... 1 2. Audit

More information

Board of Directors and Senior Management 2. Audit Management 4. Internal IT Audit Staff 5. Operating Management 5. External Auditors 5.

Board of Directors and Senior Management 2. Audit Management 4. Internal IT Audit Staff 5. Operating Management 5. External Auditors 5. Table of Contents Introduction 1 IT Audit Roles and Responsibilities 2 Board of Directors and Senior Management 2 Audit Management 4 Internal IT Audit Staff 5 Operating Management 5 External Auditors 5

More information

RISK MANAGEMENT SYSTEM

RISK MANAGEMENT SYSTEM Page 1 of 7 RISK MANAGEMENT SYSTEM 1) Disclose the following: (a) Overall management philosophy of the company; The Company has adopted a management policy that establishes a culture of disclosing, evaluating

More information

SCHOOL DISTRICT BUSINESS LEADER

SCHOOL DISTRICT BUSINESS LEADER SCHOOL DISTRICT BUSINESS LEADER Test Design The School District Business Leader assessment consists of two tests. Each test contains a section with multiplechoice questions and a section with written assignments.

More information

Audit of the Test of Design of Entity-Level Controls

Audit of the Test of Design of Entity-Level Controls Audit of the Test of Design of Entity-Level Controls Canadian Grain Commission Audit & Evaluation Services Final Report March 2012 Canadian Grain Commission 0 Entity Level Controls 2011 Table of Contents

More information

Maryland Automobile Insurance Fund

Maryland Automobile Insurance Fund Audit Report Maryland Automobile Insurance Fund September 2012 OFFICE OF LEGISLATIVE AUDITS DEPARTMENT OF LEGISLATIVE SERVICES MARYLAND GENERAL ASSEMBLY This report and any related follow-up correspondence

More information

DATA ANALYSIS: THE CORNERSTONE OF EFFECTIVE INTERNAL AUDITING. A CaseWare IDEA Research Report

DATA ANALYSIS: THE CORNERSTONE OF EFFECTIVE INTERNAL AUDITING. A CaseWare IDEA Research Report DATA ANALYSIS: THE CORNERSTONE OF EFFECTIVE INTERNAL AUDITING A CaseWare IDEA Research Report CaseWare IDEA Inc. is a privately held software development and marketing company, with offices in Toronto

More information

ALAMOS GOLD INC. AUDIT COMMITTEE CHARTER

ALAMOS GOLD INC. AUDIT COMMITTEE CHARTER ALAMOS GOLD INC. Organization AUDIT COMMITTEE CHARTER This charter governs the operations of the Audit Committee (the Committee ) of Alamos Gold Inc. (the Company ). The purpose, composition, responsibilities,

More information

Commonwealth of Pennsylvania Governor's Office

Commonwealth of Pennsylvania Governor's Office Commonwealth of Pennsylvania Governor's Office Subject: Payroll Advances Number: 525.6 Amended Date: By Direction of: September 16, 2013 Charles B. Zogby, Secretary of the Budget Contact Agency: Office

More information

Executive Summary of the Defined Benefit Plan Engineering Financial and Economic Security for Multiple Generations

Executive Summary of the Defined Benefit Plan Engineering Financial and Economic Security for Multiple Generations Executive Summary of the Defined Benefit Plan Engineering Financial and Economic Security for Multiple Generations Benefit Focused vs. Lump Sum Focused Overview: What distinguishes a retirement plan which

More information

Chapter 11 ALLOWANCE FOR LOAN AND LEASE LOSSES TABLE OF CONTENTS

Chapter 11 ALLOWANCE FOR LOAN AND LEASE LOSSES TABLE OF CONTENTS Chapter 11 ALLOWANCE FOR LOAN AND LEASE LOSSES TABLE OF CONTENTS ALLOWANCE FOR LOAN AND LEASE LOSSES... 11-1 Examination Objectives... 11-1 Associated Risks... 11. 1 Overview... 11. 1.. Definitions...

More information

Department of Information Technology Data Center Disaster Recovery Audit Report Final Report. September 2006

Department of Information Technology Data Center Disaster Recovery Audit Report Final Report. September 2006 Department of Information Technology Data Center Disaster Recovery Audit Report Final Report September 2006 promoting efficient & effective local government Executive Summary Our audit found that a comprehensive

More information

Credit Union Liability with Third-Party Processors

Credit Union Liability with Third-Party Processors World Council of Credit Unions Annual Conference Credit Union Liability with Third-Party Processors Andrew (Andy) Poprawa CEO, Deposit Insurance Corporation of Ontario Canada 1 Credit Union Liability with

More information

SCHEDULE NO. 30 FINANCIAL RECORDS

SCHEDULE NO. 30 FINANCIAL RECORDS COLORADO MUNICIPAL RECORDS RETENTION SCHEDULE 30.010 SCHEDULE NO. 30 FINANCIAL RECORDS General Description: Records documenting and ensuring accountability for the receipt and expenditure of public funds.

More information

GUIDELINES FOR THE MANAGEMENT OF OPERATIONAL RISK FOR CREDIT UNIONS

GUIDELINES FOR THE MANAGEMENT OF OPERATIONAL RISK FOR CREDIT UNIONS SUPERVISORY AND REGULATORY GUIDELINES Guidelines Issued: 22 December 2015 GUIDELINES FOR THE MANAGEMENT OF OPERATIONAL RISK FOR CREDIT UNIONS 1. INTRODUCTION 1.1 The Central Bank of The Bahamas ( the Central

More information