Internal Audit Report. Right of Way Acquisition TxDOT Office of Internal Audit

Size: px
Start display at page:

Download "Internal Audit Report. Right of Way Acquisition TxDOT Office of Internal Audit"

Transcription

1 Internal Audit Report Right of Way Acquisition TxDOT Office of Internal Audit

2 Objective Evaluate the right of way acquisition process for efficiency and compliance. Opinion Based on the audit scope areas reviewed, control mechanisms are effective and substantially address risk factors and exposures considered significant relative to impacting operational execution and compliance. The organization's system of internal controls provides reasonable assurance that key goals and objectives will be achieved despite control gap corrections and improvement opportunities identified. Control gap corrections and improvement opportunities identified have the potential to negatively impact the achievement of the organization's business/control objectives. Overall Engagement Assessment Satisfactory Finding 1 Title Management and Security of Appraisal and Negotiation Records Findings Control Design Operating Effectiveness Rating x x Needs Improvement Management concurs with the above finding and prepared a management action plan to address the deficiencies. Control Environment Overall, there is a positive tone in the right of way environment, as demonstrated through attention and focus on addressing potential issues regarding right of way acquisition. In addition, ROW management exhibited a zero tolerance risk appetite for non-compliance and expressed interest in the benefits of an audit of their operations. Summary Results Finding Scope Area Evidence 1 Appraisal & Negotiation Appraisal and negotiation records are maintained in multiple locations (Right of Way Division headquarters, district offices, and other offices) and geographic areas (North, South, East and West). Records for 54 parcels sampled in 5 areas were located at 19 different locations (parcels represented projects from 11 districts). Records were also found to be unsecured at 3 of 5 sites visited. The team visited the Right of Way Division headquarters and geographic areas in the North (Dallas), South (Austin), East (Houston) and West (Lubbock). March 19,

3 Audit Scope The audit was performed by Dennis Frazier, Anuradha Masand, Yania Munro, Augustine Nwoko, and Raymond Martinez (Engagement Lead). The audit was conducted during the period from September 25 to November 26, This audit focused on the appraisal and negotiation functions and records for right of way acquired by the Right of Way (ROW) Division. Methodology The methodology used to complete the objectives of this audit for the appraisal and negotiation scope areas included: Selected a sample of 54 out of 674 right of way parcels acquired by the ROW Division in Fiscal Year The sample provided coverage from all four geographic areas (North, South, East and West) including at least two districts in each geographic area. The team visited the Right of Way Division offices and four district offices (Dallas, Austin, Houston and Lubbock) where the files were located or delivered. Reviewed the relevant appraisal records for the sampled parcels to determine if the parcels were acquired in accordance with select appraisal requirements. This included the verification of the following: o a written appraisal report o appraisal report was prepared before negotiations o appraiser was properly certified o appraisal was properly reviewed and approved by different individuals o records were properly safeguarded Reviewed the relevant negotiation records to determine if the parcels were acquired in accordance with select negotiation requirements. This included the verification of the following: o supporting evidence that a copy of Landowner s Bill of Rights was provided o a written offer o offer letter was delivered by certified mail o supporting evidence that there was a reasonable effort to negotiate o title information was reviewed and title insurance was obtained o final offer wasn t less than appraised value or excessively more than appraised value o counter offer was properly approved o records were properly safeguarded Verified the appraisal and negotiation processes in each of the five sites visited and evaluated the timelines for key milestone dates to determine if the efficiency of the processes can be improved. Also determined if 2 key appraisal dates and 2 key negotiation dates (discussed in Observation (a)) in the files matched the dates in Right of Way Information System (ROWIS). Interviewed management and staff involved with the appraisal and negotiation functions in each geographic area to get the necessary information to complete the audit work. March 19,

4 Background This report is prepared for the Texas Transportation Commission, TxDOT Administration and Management. The report presents the results of the Right of Way Acquisition Audit which was conducted as part of the Fiscal Year 2014 Audit Plan. Right of way acquisition is the purchasing of parcels of property from private individuals, businesses or city/county/state entities for public purposes. It can include the appraisal of property, negotiation of payment based on just compensation, relocation services, administrative settlement (e.g. when an offer isn t accepted), and condemnation/eminent domain (e.g. when a settlement can t be reached). The ROW Division is responsible for acquiring the needed right of way in accordance with the legal requirements and in a timely manner so the department can let transportation projects. The ROW Division was recently centralized to include headquarters staff in Austin, project delivery staff throughout the four geographic areas of the state, and all the records that support right of way acquisition. We conducted this performance audit in accordance with Generally Accepted Government Auditing Standards and in conformance with the International Standards for the Professional Practice of Internal Auditing. Those standards require that we plan and perform the audit to obtain sufficient, appropriate evidence to provide a reasonable basis for our findings and conclusions based on our audit objectives. Recommendations to mitigate risks identified were provided to management during the engagement to assist in the formulation of the management action plans included in this report. We believe that the evidence obtained provides a reasonable basis for our findings and conclusions based on our audit objectives. The Office of Internal Audit transitioned to Committee of Sponsoring Organizations of the Treadway Commission (COSO) Internal Control Integrated Framework version 2013 in December A defined set of control objectives was utilized to focus on the operational and compliance goals for the identified scope areas. Our audit opinion is an assessment of the health of the overall control environment based on (1) the effectiveness of the enterprise risk management activities throughout the audit period and (2) the degree to which the defined control objectives were being met. Our audit opinion is not a guarantee against operational sub-optimization or non-compliance, particularly in areas not included in the scope of this audit. March 19,

5 Detailed Findings and Management Action Plans (MAP) Finding No. 1: Management and Security of Appraisal and Negotiation Records Condition Appraisal and negotiation records are maintained in multiple locations (e.g. Right of Way Division headquarters, district offices, and other offices) and by geographic areas (North, South, East and West). Additionally, records were found unsecured at 3 of 5 sites visited where offices or file cabinets were not consistently locked or adequately controlled. These records included non-public, private information. Effect/Potential Impact Maintaining these records at multiple locations makes them more difficult to retrieve and safeguard. This condition also increases the complexity of ensuring that required documents, reviews, and approvals are retained and increases the potential for inconsistent or multiple versions of a document. Not securing the records that contain non-public, private information increases the likelihood of information breach, identity theft and a negative impact to the department s reputation. Criteria & Cause Having one file of record is a best practice for effectively and efficiently documenting and managing right of way acquisition records. The Right of Way Appraisal and Review Manual (Chapter 2, Section 7) states that appraisal reports must be confidential and may only be disclosed after all parcels on a project have been acquired. The records were maintained at multiple locations due to the following reasons identified: Right of Way (R/W) managers/supervisors throughout the state need certain records for reviews, approvals, and payments agents throughout the state need certain records to support the appraisal and negotiation activities the work is sometimes spread out to various agents in a geographic area in order to meet the demands of the area the records involve hard copy documents and there is no central repository The records were found unsecured due to the following reasons identified: limited policies and procedures on protecting private or confidential information inconsistent practices reliance on a locked or badge controlled building(s) Evidence The 54 sampled parcels of right of way for the four geographic areas tested were maintained in hard copy documents at 19 different locations throughout the state: 26 parcels; projects from 2 districts in the North were maintained at 7 offices 9 parcels; projects from 3 districts in the South were maintained at 4 offices 9 parcels; projects from 3 districts in the East were maintained at 4 offices 10 parcels; projects from 3 districts in the West were maintained at 4 offices March 19,

6 Additionally, the right of way hard copy files were found unsecured at the following three sites: Austin Division Headquarters one entrance to the office where the right of way files were kept was not locked or controlled by badge access North geographic area the file cabinets with right of way files did not have locks at one location East geographic area the file cabinets and office where right of way files were kept was not locked at one location Management Action Plan (MAP): MAP Owner: Hilda Correa, Director of R/W Asset Management MAP 1.1: The Right of Way Division serves as the office of record for all real property transactions. This includes right of way documents for the four R/W Project Delivery geographical areas of responsibility located in 25 district offices statewide. 1. Access controls, Right of Way Division (RA 118) In Process The ROW Division Headquarters is served by two entrances. The division has coordinated with TxDOT Security Operations Supervisor to ensure that all entrances to ROW division are secured. Short-term goals December 1, Physical security was increased for the main entrance to ROW Division Headquarters (west entrance), utilized by external customers and TxDOT Division personnel. A ROW division customer service representative for the Document Information Exchange Center (DIEC) is required to be present during normal business hours. The customer service representative will: o Monitor to ensure visitor sign in at the front desk o Enforce visitor escort into and out of the ROW division December 1, Assign a designated employee(s) as security officer(s) to review and improve security of physical facility and files. December 1, Enforce Division policies that consist of escorting non- TxDOT visitors within the division by division employees. 2. Internal Asset Management and File Control Long-term goal The ROW Division is furthering efforts to secure documentation by implementing statewide use of the department s Electronic Document Management System (EDMS). Update, publish, and enforce standard operating procedures (SOPs) for access to right of way files. March 19,

7 3. External Right of Way Project Delivery In-Process Conduct site visits to review and assess security measures for R/W assets and records management at the distributed R/W Project Delivery office locations. Perform annual physical security reviews of R/W Project Delivery sites. Mid-term goal Develop policies and procedures for safeguarding right of way assets, files, and documents Communicate and disseminate policies through standard operating procedures (SOPs) to R/W Project Delivery workforce. Completion Date: May 15, 2014 March 19,

8 Observations and Recommendations Audit Observation (a): Right of Way Information System (ROWIS) Information As part of the review of key dates in ROWIS for appraisal and negotiation milestones, some dates were not recorded in ROWIS and some dates did not match dates in files. In addition, for appraisal milestones, some date stamps were not located in the files. Effect/Potential Impact Two key appraisal dates and two key negotiation dates were selected from a sample of 14 parcels from the four geographic areas. The dates were not recorded in ROWIS in 20 of 56 (36%) instances and the dates in ROWIS did not match the dates in the files in 12 of 56 (21%) instances. Attributes Receipt Date Appraisal Dates Approval Date Total Date of Initial Offer Negotiation Dates Date of Acceptance Total Date not in ROWIS of of 28 Date did not match file of of 28 In addition, the auditors checked for the date stamp on appraisal report in the file for a sample of 54 parcels from the four geographic areas and found that 35 of 54 (65%) parcels did not have a date stamp on appraisal report. The date stamp helps ensure that appraisal services are paid in timely manner and was used to assess efficiency. Audit Recommendation The Right of Way Division should determine whether incomplete or inaccurate dates in ROWIS are negatively impacting users of ROWIS. March 19,

9 Summary Results Based on Enterprise Risk Management Framework Closing Comments The results of this audit were discussed with the Right of Way Division Director and staff. We appreciate the assistance and cooperation received from the Right of Way Division management and staff contacted during this audit. We would also like to thank the employees who gathered and delivered the right of way project files for our review. March 19,

Internal Audit Report. Highway Condition Reporting TxDOT Office of Internal Audit

Internal Audit Report. Highway Condition Reporting TxDOT Office of Internal Audit Internal Audit Report Highway Condition Reporting TxDOT Office of Internal Audit Objective To evaluate data integrity in the Highway Condition Report. Opinion Based on the audit scope areas reviewed, control

More information

Internal Audit Report. Receivables Management Statement of Cost TxDOT Office of Internal Audit

Internal Audit Report. Receivables Management Statement of Cost TxDOT Office of Internal Audit Internal Audit Report Receivables Management Statement of Cost TxDOT Office of Internal Audit Objective The audit objective is to evaluate whether monitoring and accounting for outstanding construction

More information

Internal Audit Report. Toll Operations Contract Management TxDOT Office of Internal Audit

Internal Audit Report. Toll Operations Contract Management TxDOT Office of Internal Audit Internal Audit Report Toll Operations Contract Management TxDOT Office of Internal Audit Objective To determine whether the Toll Operations Division (TOD) contract management structure is designed and

More information

TxDOT Internal Audit Report Disaster Recovery - IT

TxDOT Internal Audit Report Disaster Recovery - IT TxDOT Internal Audit Report Disaster Recovery - IT Objective Determine if adequate plans and the ability to ensure critical TxDOT operations are not impacted by business interruptions to IT infrastructure.

More information

Internal Audit Follow-Up Report. Equipment Maintenance and Repair. TxDOT Office of Internal Audit. Jan J

Internal Audit Follow-Up Report. Equipment Maintenance and Repair. TxDOT Office of Internal Audit. Jan J Internal Audit Follow-Up Report Equipment Maintenance and Repair TxDOT Office of Internal Audit Jan J Objective Assess the status of corrective actions for high risk Management Action Plans (MAPs) previously

More information

SCDA and SCDA Member Benefits Group

SCDA and SCDA Member Benefits Group SCDA and SCDA Member Benefits Group HIPAA Privacy Policy 1. PURPOSE The purpose of this policy is to protect personal health information (PHI) and other personally identifiable information for all individuals

More information

TxDOT Internal Audit Report Equipment Maintenance and Repair

TxDOT Internal Audit Report Equipment Maintenance and Repair TxDOT Internal Audit Report Equipment Maintenance and Repair Objective Determine if there are adequate policies, procedures, and practices for ensuring the adequate inspection, maintenance, and repair

More information

CREATIVE SOLUTIONS IN HEALTHCARE, INC. Privacy Policy

CREATIVE SOLUTIONS IN HEALTHCARE, INC. Privacy Policy CREATIVE SOLUTIONS IN HEALTHCARE, INC. Privacy Policy Amended as of February 12, 2010 on the authority of the HIPAA Privacy Officer for Creative Solutions in Healthcare, Inc. TABLE OF CONTENTS ARTICLE

More information

INTERNAL AUDIT CHARTER AND TERMS OF REFERENCE

INTERNAL AUDIT CHARTER AND TERMS OF REFERENCE INTERNAL AUDIT CHARTER AND TERMS OF REFERENCE CHARTERED INSTITUTE OF INTERNAL AUDIT DEFINITION OF INTERNAL AUDIT Internal auditing is an independent, objective assurance and consulting activity designed

More information

October 2007 Report No. 08-006. An Audit Report on The Medical Transportation Program at the Texas Department of Transportation

October 2007 Report No. 08-006. An Audit Report on The Medical Transportation Program at the Texas Department of Transportation John Keel, CPA State Auditor An Audit Report on The Medical Transportation Program at the Texas Department of Transportation Report No. 08-006 An Audit Report on The Medical Transportation Program at the

More information

University Audit and Compliance. Internal Controls Enterprise-Wide Risk Assessment

University Audit and Compliance. Internal Controls Enterprise-Wide Risk Assessment Internal Controls Enterprise-Wide Risk Assessment Balancing Risk and Controls In order to achieve goals and objectives, management needs to effectively balance risks and controls. Control procedures need

More information

HIPAA Policy, Protection, and Pitfalls ARTHUR J. GALLAGHER & CO. BUSINESS WITHOUT BARRIERS

HIPAA Policy, Protection, and Pitfalls ARTHUR J. GALLAGHER & CO. BUSINESS WITHOUT BARRIERS HIPAA Policy, Protection, and Pitfalls Overview HIPAA Privacy Basics What s covered by HIPAA privacy rules, and what isn t? Interlude on the Hands-Off Group Health Plan When does this exception apply,

More information

SAMPLE TEMPLATE. Massachusetts Written Information Security Plan

SAMPLE TEMPLATE. Massachusetts Written Information Security Plan SAMPLE TEMPLATE Massachusetts Written Information Security Plan Developed by: Jamy B. Madeja, Esq. Erik Rexford 617-227-8410 [email protected] Each business is required by Massachusetts law

More information

REAL ESTATE ACQUISITION

REAL ESTATE ACQUISITION REAL ESTATE ACQUISITION Summary of Real Estate Acquisition Guidelines Planning Phase 1. Define the right-of-way needed through preliminary design of the project; 2. Obtain surveys for right-of-way needed;

More information

Audit of IT Asset Management Report

Audit of IT Asset Management Report Audit of IT Asset Management Report Recommended by the Departmental Audit Committee for approval by the President on Approved by the President on September 4, 2012 e-doc : 3854899 1 Table of Contents EXECUTIVE

More information

REPORT 2014/078 INTERNAL AUDIT DIVISION

REPORT 2014/078 INTERNAL AUDIT DIVISION INTERNAL AUDIT DIVISION REPORT 2014/078 Audit of the Office for the Coordination of Humanitarian Affairs (OCHA) Managing Agent role for the Somalia Common Humanitarian Fund Overall results relating to

More information

June 2008 Report No. 08-037. An Audit Report on The Texas Education Agency s Oversight of Alternative Teacher Certification Programs

June 2008 Report No. 08-037. An Audit Report on The Texas Education Agency s Oversight of Alternative Teacher Certification Programs John Keel, CPA State Auditor An Audit Report on The Texas Education Agency s Oversight of Alternative Teacher Certification Programs Report No. 08-037 An Audit Report on The Texas Education Agency s Oversight

More information

Information Technology Internal Audit Report

Information Technology Internal Audit Report Information Technology Internal Audit Report Report #2013-03 August 9, 2013 Table of Contents Page Executive Summary... 3 Background Information... 4 Background... 4 Audit Objectives... 4 Scope... 5 Testing

More information

Student Assessment Administrative Review Phase 1

Student Assessment Administrative Review Phase 1 Internal Audit Student Assessment Administrative Review Phase 1 Issue Date: March 2015 Report Number: FY2015-02 Executive Summary AUDIT OF: Student Assessment DATE: Fieldwork performed January 2015 February

More information

Policies and Procedures Audit Checklist for HIPAA Privacy, Security, and Breach Notification

Policies and Procedures Audit Checklist for HIPAA Privacy, Security, and Breach Notification Policies and Procedures Audit Checklist for HIPAA Privacy, Security, and Breach Notification Type of Policy and Procedure Comments Completed Privacy Policy to Maintain and Update Notice of Privacy Practices

More information

SCHOOL DISTRICT OF BLACK RIVER FALLS HIPAA PRIVACY AND SECURITY POLICY

SCHOOL DISTRICT OF BLACK RIVER FALLS HIPAA PRIVACY AND SECURITY POLICY SCHOOL DISTRICT OF BLACK RIVER FALLS HIPAA PRIVACY AND SECURITY POLICY School Board Policy 523.5 The School District of Black River Falls ( District ) is committed to compliance with the health information

More information

ACCOUNTING AND FINANCIAL REPORTING REGULATION MANUAL

ACCOUNTING AND FINANCIAL REPORTING REGULATION MANUAL ACCOUNTING AND FINANCIAL REPORTING REGULATION MANUAL STATE BOARD OF ACCOUNTS 302 West Washington Street Room E418 Indianapolis, Indiana 46204-2769 Issued January 2011 Revised April 2012 TABLE OF CONTENTS

More information

Administrative Guidelines on the Internal Control Framework and Internal Audit Standards

Administrative Guidelines on the Internal Control Framework and Internal Audit Standards Administrative Guidelines on the Internal Control Framework and Internal Audit Standards GCF/B.09/18 18 February 2015 Meeting of the Board 24 26 March 2015 Songdo, Republic of Korea Agenda item 24 Page

More information

STANDARD ADMINISTRATIVE PROCEDURE

STANDARD ADMINISTRATIVE PROCEDURE STANDARD ADMINISTRATIVE PROCEDURE 16.99.99.M0.26 Investigation and Response to Breach of Unsecured Protected Health Information (HITECH) Approved October 27, 2014 Next scheduled review: October 27, 2019

More information

DATA ANALYSIS: THE CORNERSTONE OF EFFECTIVE INTERNAL AUDITING. A CaseWare IDEA Research Report

DATA ANALYSIS: THE CORNERSTONE OF EFFECTIVE INTERNAL AUDITING. A CaseWare IDEA Research Report DATA ANALYSIS: THE CORNERSTONE OF EFFECTIVE INTERNAL AUDITING A CaseWare IDEA Research Report CaseWare IDEA Inc. is a privately held software development and marketing company, with offices in Toronto

More information

Protecting Electronic Data and Trade Secrets

Protecting Electronic Data and Trade Secrets Protecting Electronic Data and Trade Secrets Presenter: Robert W. Kent, Jr. Baker & McKenzie International is a Swiss Verein with member law firms around the world. In accordance with the common terminology

More information

FINAL May 2005. Guideline on Security Systems for Safeguarding Customer Information

FINAL May 2005. Guideline on Security Systems for Safeguarding Customer Information FINAL May 2005 Guideline on Security Systems for Safeguarding Customer Information Table of Contents 1 Introduction 1 1.1 Purpose of Guideline 1 2 Definitions 2 3 Internal Controls and Procedures 2 3.1

More information

September 28, 2011. Audit s Role in Governance, Risk Management and Internal Control

September 28, 2011. Audit s Role in Governance, Risk Management and Internal Control September 28, 2011 Internal Audit Overview Audit s Role in Governance, Risk Management and Internal Control Mission Provide independent, objective assurance and advisory services designed to add value

More information

OVERALL RATING: PARTIALLY SATISFACTORY

OVERALL RATING: PARTIALLY SATISFACTORY INTERNAL AUDIT DIVISION REPORT 2016/059 Audit of the use of consultants and individual contractors in the United Nations Support Office in Somalia Overall results relating to the effective management of

More information

MEMORANDUM INTERNAL CONTROL REQUIREMENTS FOR NON-PROFITS

MEMORANDUM INTERNAL CONTROL REQUIREMENTS FOR NON-PROFITS DIVISION OF CHILD CARE AND EARLY CHILDHOOD EDUCATION HEALTH AND NUTRITION UNIT P O BOX 1437, SLOT S 155 501-320-8982 FAX: 501-682-2334 TDD: 501-682-1550 TO: NON-PROFIT INSTITUTIONS FROM: HEALTH AND NUTRITION

More information

Aboriginal Affairs and Northern Development Canada. Internal Audit Report. Audit of Internal Controls Over Financial Reporting.

Aboriginal Affairs and Northern Development Canada. Internal Audit Report. Audit of Internal Controls Over Financial Reporting. Aboriginal Affairs and Northern Development Canada Internal Audit Report Audit of Internal Controls Over Financial Reporting Prepared by: Audit and Assurance Services Branch Project #: 14-05 November 2014

More information

Data Analysis: The Cornerstone of Effective Internal Auditing. A CaseWare Analytics Research Report

Data Analysis: The Cornerstone of Effective Internal Auditing. A CaseWare Analytics Research Report Data Analysis: The Cornerstone of Effective Internal Auditing A CaseWare Analytics Research Report Contents Why Data Analysis Step 1: Foundation - Fix Any Cracks First Step 2: Risk - Where to Look Step

More information

Management and Set up for Cash and Credit Card Handling Procedures

Management and Set up for Cash and Credit Card Handling Procedures Management and Set up for Cash and Credit Card Handling Procedures This presentation is designed to give managers a brief outline of key procedures and controls that should be in place to safeguard cash

More information

AUDIT REPORT. Audit of the UNOG contracts for furniture supplies FINAL OVERALL RATING: PARTIALLY SATISFACTORY

AUDIT REPORT. Audit of the UNOG contracts for furniture supplies FINAL OVERALL RATING: PARTIALLY SATISFACTORY INTERNAL AUDIT DIVISION AUDIT REPORT Audit of the UNOG contracts for furniture supplies Overall results relating to acquisition and management of the contracts for furniture supplies were initially assessed

More information

SAMPLE FINANCIAL PROCEDURES MANUAL

SAMPLE FINANCIAL PROCEDURES MANUAL SAMPLE FINANCIAL PROCEDURES MANUAL Approved by (organization s) Board of Directors on (date) I. GENERAL 1. The Board of Directors formulates financial policies, delegates administration of the financial

More information

HIPAA Auditing Tool. Department: Site Location: Visit Date:

HIPAA Auditing Tool. Department: Site Location: Visit Date: HIPAA Auditing Tool Department: Site Location: Visit Date: Auditor: Staff Interviewed: Notice of Privacy Practice 164.520(c) A covered entity must make the notice required by this section available on

More information

Information Technology Internal Audit Report

Information Technology Internal Audit Report Information Technology Internal Audit Report Report #2014-05 July 25, 2014 Table of Contents Page Executive Summary... 3 Background Information... 4 Background... 4 Audit Objectives... 4 Scope and Testing

More information

Division of Insurance Internal Control Questionnaire For the period July 1, 2013 through June 30, 2014

Division of Insurance Internal Control Questionnaire For the period July 1, 2013 through June 30, 2014 Official Audit Report Issued March 6, 2015 Internal Control Questionnaire For the period July 1, 2013 through June 30, 2014 State House Room 230 Boston, MA 02133 [email protected] www.mass.gov/auditor

More information

Internal Audit. Audit of the Inventory Control Framework

Internal Audit. Audit of the Inventory Control Framework Internal Audit Audit of the Inventory Control Framework June 2010 Table of Contents EXECUTIVE SUMMARY...4 1. INTRODUCTION...7 1.1 BACKGROUND...7 1.2 OBJECTIVES...7 1.3 SCOPE OF THE AUDIT...7 1.4 METHODOLOGY...8

More information

A Risk-Based Audit Strategy November 2006 Internal Audit Department

A Risk-Based Audit Strategy November 2006 Internal Audit Department Mental Health Mental Retardation Authority of Harris County ENTERPRISE RISK MANAGEMENT A Framework For Assessing, Evaluating And Measuring Our Agency s Risk A Risk-Based Audit Strategy November 2006 Internal

More information

Master Document Audit Program

Master Document Audit Program Activity Code 11510 B-1 Planning Considerations Information Technology General System Controls Audit Specific Independence Determination Members of the audit team and internal specialists consulting on

More information

Audit of the Test of Design of Entity-Level Controls

Audit of the Test of Design of Entity-Level Controls Audit of the Test of Design of Entity-Level Controls Canadian Grain Commission Audit & Evaluation Services Final Report March 2012 Canadian Grain Commission 0 Entity Level Controls 2011 Table of Contents

More information

Ford & Thomas Insurance Agency

Ford & Thomas Insurance Agency Ford & Thomas Insurance Agency PRIVACY POLICY NOTICE (As of February 14, 2012) PURPOSE OF THIS NOTICE As provided by law, we are generally prohibited from sharing nonpublic personal information about you

More information

Contracts Management Software as a Tool for SOX Compliance

Contracts Management Software as a Tool for SOX Compliance Contracts Management Software as a Tool for SOX Compliance White Paper (281) 334-6970 [email protected] www.prodagio.com In 2002, following the scandals involving corporations such as Enron, WorldCom,

More information

PRACTICE GUIDE. Formulating and Expressing Internal Audit Opinions

PRACTICE GUIDE. Formulating and Expressing Internal Audit Opinions PRACTICE GUIDE Formulating and Expressing Internal Audit Opinions 2 of 23 Table of Contents 1. Executive Summary... 1 2. Introduction... 2 3. Planning the Expression of an Opinion... 3 3.1 Expressing an

More information

UCLA Policy 360: Internal Control Guidelines for Campus Departments

UCLA Policy 360: Internal Control Guidelines for Campus Departments UCLA Policy 360: Internal Control Guidelines for Campus Departments Issuing Officer: Assistant Vice Chancellor, Corporate Financial Services Responsible Dept: Financial Management Programs Effective Date:

More information

What is a definition of risk?

What is a definition of risk? What is a definition of risk? Definition of Risk Risk is the probability or threat of any negative occurrence caused by internal or external vulnerabilities interfering with achieving objectives that may

More information

YEARENDED31DECEMBER2013 RISKMANAGEMENTDISCLOSURES

YEARENDED31DECEMBER2013 RISKMANAGEMENTDISCLOSURES RISKMANAGEMENTDISCLOSURES 2015 YEARENDED31DECEMBER2013 ACCORDINGTOCHAPTER7(PAR.34-38)OFPARTCANDANNEXXIOFTHECYPRUSSECURITIES ANDEXCHANGECOMMISSIONDIRECTIVEDI144-2007-05FORTHECAPITALREQUIREMENTSOF INVESTMENTFIRMS

More information

Written Information Security Plan (WISP) for. HR Knowledge, Inc. This document has been approved for general distribution.

Written Information Security Plan (WISP) for. HR Knowledge, Inc. This document has been approved for general distribution. Written Information Security Plan (WISP) for HR Knowledge, Inc. This document has been approved for general distribution. Last modified January 01, 2014 Written Information Security Policy (WISP) for HR

More information

Health Insurance Portability and Accountability Act (HIPAA) Compliance Audit Final Report

Health Insurance Portability and Accountability Act (HIPAA) Compliance Audit Final Report Health Insurance Portability and Accountability Act (HIPAA) Compliance Audit Final Report April 2009 promoting efficient & effective local government Background The Health Insurance Portability and Accountability

More information

IT audit updates. Current hot topics and key considerations. IT risk assessment leading practices

IT audit updates. Current hot topics and key considerations. IT risk assessment leading practices IT audit updates Current hot topics and key considerations Contents IT risk assessment leading practices IT risks to consider in your audit plan IT SOX considerations and risks COSO 2013 and IT considerations

More information

SANTA ANA UNIFIED SCHOOL DISTRICT LEAD INTERNAL AUDITOR

SANTA ANA UNIFIED SCHOOL DISTRICT LEAD INTERNAL AUDITOR SANTA ANA UNIFIED SCHOOL DISTRICT LEAD INTERNAL AUDITOR JOB SUMMARY: This management position will report to the Deputy Superintendent and/or designee. The Internal Auditor will supervise, monitor, review,

More information

Anti-Money Laundering and Counter- Terrorism Financial Policy

Anti-Money Laundering and Counter- Terrorism Financial Policy Anti-Money Laundering and Counter- Terrorism Financial Policy Version: March 2014 1. INTRODUCTION...3 2. DEFINITIONS...3 3. RISK-BASED APPROACH...3 4. AML COMPLIANCE OFFICER...4 5. SUSPICIOUS TRANSACTION

More information

Risk Management of Outsourced Technology Services. November 28, 2000

Risk Management of Outsourced Technology Services. November 28, 2000 Risk Management of Outsourced Technology Services November 28, 2000 Purpose and Background This statement focuses on the risk management process of identifying, measuring, monitoring, and controlling the

More information

INITIAL APPROVAL DATE INITIAL EFFECTIVE DATE

INITIAL APPROVAL DATE INITIAL EFFECTIVE DATE TITLE AND INFORMATION TECHNOLOGY RESOURCES DOCUMENT # 1107 APPROVAL LEVEL Alberta Health Services Executive Committee SPONSOR Legal & Privacy / Information Technology CATEGORY Information and Technology

More information

HIPAA Compliance: Are you prepared for the new regulatory changes?

HIPAA Compliance: Are you prepared for the new regulatory changes? HIPAA Compliance: Are you prepared for the new regulatory changes? Baker Tilly CARIS Innovation, Inc. April 30, 2013 Baker Tilly refers to Baker Tilly Virchow Krause, LLP, an independently owned and managed

More information

Appendix D Components and Competencies for School Business and Support Services

Appendix D Components and Competencies for School Business and Support Services Appendix D Components and Competencies for School Business and Support Services The Region 10 Education Service Center in Richardson, Texas, under a project contract to the Texas Education Agency, has

More information

Revenue Audits Article by Eamon Staunton, MBA AITI, CPA, Examiner - Formation 2 Taxation

Revenue Audits Article by Eamon Staunton, MBA AITI, CPA, Examiner - Formation 2 Taxation Revenue Audits Article by Eamon Staunton, MBA AITI, CPA, Examiner - Formation 2 Taxation What is a Revenue Audit A Revenue audit is an examination of the information and figures shown by a taxpayer in

More information

DSU Identity Theft Prevention Policy No. DSU 802.7.001

DSU Identity Theft Prevention Policy No. DSU 802.7.001 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 IDENTITY THEFT PREVENTION DSU Policy No. 802.7.001 SOURCE: Fair and Accurate

More information

REPORT 2016/035 INTERNAL AUDIT DIVISION

REPORT 2016/035 INTERNAL AUDIT DIVISION INTERNAL AUDIT DIVISION REPORT 2016/035 Audit of the use of consultants and individual contractors in the United Nations Stabilization Mission in Haiti Overall results relating to the effective hiring

More information

SECURITY RISK ASSESSMENT SUMMARY

SECURITY RISK ASSESSMENT SUMMARY Providers Business Name: Providers Business Address: City, State, Zip Acronyms NIST FIPS PHI EPHI BA CE EHR HHS IS National Institute of Standards and Technology Federal Information Process Standards Protected

More information

Table of Contents: Chapter 2 Internal Control

Table of Contents: Chapter 2 Internal Control Table of Contents: Chapter 2 Chapter 2... 2 2.1 Establishing an Effective System... 2 2.1.1 Sample Plan Elements... 5 2.1.2 Limitations of... 7 2.2 Approvals... 7 2.3 PCard... 7 2.4 Payroll... 7 2.5 Reconciliation

More information

GUIDELINES FOR THE MANAGEMENT OF OPERATIONAL RISK FOR CREDIT UNIONS

GUIDELINES FOR THE MANAGEMENT OF OPERATIONAL RISK FOR CREDIT UNIONS SUPERVISORY AND REGULATORY GUIDELINES Guidelines Issued: 22 December 2015 GUIDELINES FOR THE MANAGEMENT OF OPERATIONAL RISK FOR CREDIT UNIONS 1. INTRODUCTION 1.1 The Central Bank of The Bahamas ( the Central

More information

MISSION STATEMENT OBJECTIVES IN ACCOMPLISHING OUR MISSION

MISSION STATEMENT OBJECTIVES IN ACCOMPLISHING OUR MISSION MISSION STATEMENT Internal Audit exists to support administration and the Board of Directors in the effective discharge of their responsibilities. Using our knowledge and professional judgment, we will

More information

MONROE COUNTY WATER AUTHORITY IDENTITY THEFT PREVENTION POLICY REVISED MARCH 2014

MONROE COUNTY WATER AUTHORITY IDENTITY THEFT PREVENTION POLICY REVISED MARCH 2014 MONROE COUNTY WATER AUTHORITY IDENTITY THEFT PREVENTION POLICY REVISED MARCH 2014 Section 41.90 of Title 12 of the Code of Federal Regulations (the Regulations ) requires every utility that offers or maintains

More information

Follow-up Audit Vital Registry and Health Statistics Program

Follow-up Audit Vital Registry and Health Statistics Program Follow-up Audit Vital Registry and Health Statistics Program March 2000 City Auditor s Office City of Kansas City, Missouri 990-023 March 8, 2000 Honorable Mayor and Members of the City Council: This

More information

Nassau County Office of the Comptroller

Nassau County Office of the Comptroller Nassau County Office of the Comptroller Bank Account Review Department of Social Services Child Support Collection Unit Bank Account GEORGE MARAGOS Comptroller March 29, 2016 1 NASSAU COUNTY OFFICE OF

More information

The following paragraphs, identified to coincide with the OHSAS 18001:2007 numbering system, provide a clause-by-clause summary of the standard.

The following paragraphs, identified to coincide with the OHSAS 18001:2007 numbering system, provide a clause-by-clause summary of the standard. Summary of OHSAS 18001:2007 Requirements With this article, the 18000 store provides a brief and clear summary of the OHSAS 18001:2007 requirements. First of all, OHSAS 18001 is an international standard

More information

LOCAL GOVERNMENT MANAGEMENT ASSESSMENT OVERVIEW AND QUESTIONNAIRE

LOCAL GOVERNMENT MANAGEMENT ASSESSMENT OVERVIEW AND QUESTIONNAIRE LOCAL GOVERNMENT MANAGEMENT ASSESSMENT OVERVIEW AND QUESTIONNAIRE The Comptroller s Economic Development and Analysis (EDA) Division provides education and direct assistance to local governments, helping

More information

USES AND DISCLOSURES OF HEALTH INFORMATION

USES AND DISCLOSURES OF HEALTH INFORMATION HIPAA Privacy Policy NOTICE OF PRIVACY PRACTICES This notice describes how health information about you may be used and disclosed. Please review carefully. The privacy of your health information is important

More information

Achieve. Performance objectives

Achieve. Performance objectives Achieve Performance objectives Performance objectives are benchmarks of effective performance that describe the types of work activities students and affiliates will be involved in as trainee accountants.

More information

GAO DEFENSE CONTRACT AUDITS. Actions Needed to Improve DCAA's Access to and Use of Defense Company Internal Audit Reports

GAO DEFENSE CONTRACT AUDITS. Actions Needed to Improve DCAA's Access to and Use of Defense Company Internal Audit Reports GAO United States Government Accountability Office Report to the Committee on Armed Services, U.S. Senate December 2011 DEFENSE CONTRACT AUDITS Actions Needed to Improve DCAA's Access to and Use of Defense

More information

OVERVIEW. In all, this report makes recommendations in 14 areas, such as. Page iii

OVERVIEW. In all, this report makes recommendations in 14 areas, such as. Page iii The Office of the Auditor General has conducted a procedural review of the State Data Center (Data Center), a part of the Arizona Strategic Enterprise Technology (ASET) Division within the Arizona Department

More information