AUDIT REPORT. Corporate Access and Identity Management Project Audit Opinion: Satisfactory. July 31, 2015

Size: px
Start display at page:

Download "AUDIT REPORT. Corporate Access and Identity Management Project Audit Opinion: Satisfactory. July 31, 2015"

Transcription

1 AUDIT REPORT Corporate Access and Identity Management Project Audit Opinion: Satisfactory July 31, 2015 Report Number: 2015-IT-02 Corporate Access and Identity Management Project

2 Table of Contents: Page Executive Summary Background 1 Objectives and Scope 1 Audit Opinion 2 Appendices Definitions 3 Distribution 4 Audit Performed By 4 Report Number: 2015-IT-02 Corporate Access and Identity Management Project

3 Executive Summary Background During May 2014, Citizens commenced with establishing a corporate Access and Identity Management (AIM) program to develop stronger governance, process ownership and improved processes across our widely distributed application security environment. Conceptually, identity management refers to the management of the entire life cycle of user and system accounts so that users can be uniquely identified to IT systems before being granted access to sensitive IT assets. Processes in place include: user provisioning; maintenance; deprovisioning; monitoring; and reporting on accounts and related access permissions. During 2010, a Computer Access Management program was developed by IT Security that divided user application access processes between business areas and IT Security for applications considered as high risk. This program has not been effective mainly due to the lack of automation and assignment of resources required to comply with the program requirements from both a business and information technology perspective. With the current project, a renewed emphasis is being applied in the management of access throughout Citizens vast systems infrastructure with the intent to fully distribute user access management processes to the appropriate business areas. Going forward, instead of being the custodian of access management, IT Security will be providing governance oversight and compliance validation functions. The primary objectives of the AIM project are to: Develop a governance framework that provides guidance in security access management as well as a business user access process document to capture and understand processes currently in place. (A more over-arching IT Security Policy is being developed as part of another initiative, which will further strengthen governance and control over system access.) Document and assess current application identity management processes for applications containing data classified as restricted and sensitive. Assess gaps in processes and user access reporting and define improvements needed to effectively manage and monitor these processes. Remediate gaps where necessary to comply with the minimum standards contained in the framework. Results from this project are not intended to provide assurance that single user access is addressed with proper separation of duties across multiple systems. It has a single focus on an application by application basis. Audit Objectives and Scope We evaluated the adequacy and effectiveness of the governance structure associated with the project in accordance with project management best practices as defined in the Global Technology Audit Guide 12, Auditing IT Projects and the Control Objectives for Information and related Technology (COBIT ) 4.1. We also evaluated compliance to the Citizens Enterprise Project Management Methodology. The scope of the audit included the following components that were identified as integral parts of the governance process: Report Number: 2015-IT-02 Corporate Access and Identity Management Project Page 1

4 Executive Summary A sound project governance structure has been established (project team and stakeholders group), objectives have been clearly defined and communicated and a clear escalation path is implemented. Required project artifacts are created and stored in the required location in line with the Project Methodology. Appropriate approvals are obtained for artifacts and significant project decisions. Roles and responsibilities have been delineated and communicated to business application owners and contacts. Tasks, resources and target dates are maintained up to date and periodically reported to the project owner and sponsor. Project risks are being identified as part of project progression. Status reports are being generated and distributed in line with the required Project Methodology time frame. Audit Opinion Based upon our audit work, the overall effectiveness of the governance processes and Citizens Enterprise Project Management Methodology policy compliance evaluated during the audit is rated as Satisfactory. We found that the project governance structure is designed well with an escalation path to a stakeholders group and an executive sponsor. Monthly stakeholder meetings are held to review project status and issues. Appropriate approvals have been obtained for documents requiring such by policy. Primary project team members are available to business owners and application contacts for assistance in completing the current state assessment documents. Formalized status checkpoints have been installed with application owners as the User Access Process documents are being completed between May and November, We would like to thank management and staff in IT Security and the Program Management Office for their cooperation and professional courtesy throughout the course of this audit. Report Number: 2015-IT-02 Corporate Access and Identity Management Project Page 2

5 Appendix 1 Definitions Audit Ratings Satisfactory: Critical internal control systems are functioning in an acceptable manner. There may be no or very few minor issues, but their number and severity relative to the size and scope of the operation, entity, or process audited indicate minimal concern. Corrective action to address the issues identified, although not serious, remains an area of focus. Needs Improvement: Internal control systems are not functioning in an acceptable manner and the control environment will require some enhancement before it can be considered as fully effective. The number and severity of issues relative to the size and scope of the operation, entity, or process being audited indicate some significant areas of weakness. Overall exposure (existing or potential) requires corrective action plan with priority. Unsatisfactory: One or more critical control deficiencies exist which would have a significant adverse effect on loss potential, customer satisfaction or management information. Or the number and severity of issues relative to the size and scope of the operation, entity, or process being audited indicate pervasive, systemic, or individually serious weaknesses. As a result the control environment is not considered to be appropriate, or the management of risks reviewed falls outside acceptable parameters, or both. Overall exposure (existing or potential) is unacceptable and requires immediate corrective action plan with highest priority. Report Number: 2015-IT-02 Corporate Access and Identity Management Project Page 3

6 Appendix 2 Distribution Addressees Copies Mitch Brockbank, Director IT Security and Risk Juan Cocuy, Citizens Audit Committee Chairman Bette Brown, Citizens Audit Committee Member Jim Henderson, Citizens Audit Committee Member Barry Gilway, President/CEO/Executive Director Kelly Booten, Chief Systems and Operations Curt Overpeck, Chief Information Officer John Rollins, Chief Risk Officer Dan Sumner, Chief Legal Officer and General Counsel Christine Ashburn, VP, Legislative and External Affairs and Communications Robert Owens, Director, Program Management Office Bruce Meeks, Inspector General Following Audit Committee Distribution The Honorable Rick Scott, Governor The Honorable Jeff Atwater, Chief Financial Officer The Honorable Pam Bondi, Attorney General The Honorable Adam Putnam, Commissioner of Agriculture The Honorable Andy Gardiner, President of the Senate The Honorable Steve Crisafulli, Speaker of the House of Representatives Audit Performed By Audit Director Under the Direction of Karen Wittlinger, Director IT Audit Joe Martins Chief of Internal Audit Report Number: 2015-IT-02 Corporate Access and Identity Management Project Page 4

AUDIT REPORT. Service Desk and Problem Management Audit Opinion: Satisfactory. November 14, 2014. Report Number: 2014-IT-04

AUDIT REPORT. Service Desk and Problem Management Audit Opinion: Satisfactory. November 14, 2014. Report Number: 2014-IT-04 AUDIT REPORT Service Desk and Problem Management Audit Opinion: Satisfactory November 14, 2014 Report Number: 2014-IT-04 Table of Contents: Page Executive Summary Background 1 Audit Objectives and Scope

More information

AUDIT REPORT. Cloud Software as a Service (SaaS) Procurement and Governance Audit. June 9, 2016

AUDIT REPORT. Cloud Software as a Service (SaaS) Procurement and Governance Audit. June 9, 2016 AUDIT REPORT Cloud Software as a Service (SaaS) Procurement and Governance Audit June 9, 2016 Table of Contents: Page Executive Summary Background 1 Audit Objectives and Scope 1 Management s Assessment

More information

AUDIT REPORT. Citizens Insurance Suite Check Printing Audit Opinion: Needs Improvement. June 11, 2015

AUDIT REPORT. Citizens Insurance Suite Check Printing Audit Opinion: Needs Improvement. June 11, 2015 AUDIT REPORT Citizens Insurance Suite Check Printing Audit Opinion: Needs Improvement June 11, 2015 Citizens Insurance Suite Check Printing Table of Contents: Page Executive Summary Background 1 Objectives

More information

AUDIT REPORT. Citizens Data Warehouse Audit Opinion: Needs Improvement. Date: June 9, 2014. Report Number: 2014-AUD-IT-01

AUDIT REPORT. Citizens Data Warehouse Audit Opinion: Needs Improvement. Date: June 9, 2014. Report Number: 2014-AUD-IT-01 AUDIT REPORT Citizens Data Warehouse Audit Opinion: Date: June 9, 2014 Report Number: 2014-AUD-IT-01 Report Number: 2014-AUD-IT-01 Citizens Data Warehouse Table of Contents: Page Executive Summary Background

More information

FLORIDA COMMISSION ON OFFENDER REVIEW (formerly Florida Parole Commission)

FLORIDA COMMISSION ON OFFENDER REVIEW (formerly Florida Parole Commission) FLORIDA COMMISSION ON OFFENDER REVIEW (formerly Florida Parole Commission) TENA M. PATE, Chair BERNARD R. COHEN, SR., Vice-Chair MELINDA N. COONROD, Secretary RICK SCOTT, Governor PAM BONDI, Attorney General

More information

Audit of Business Continuity Planning

Audit of Business Continuity Planning Cumbria Office of the Police & Crime Commissioner Audit of Business Continuity Planning 0 Cumbria Shared Internal Audit Service Images courtesy of Carlisle City Council except: Parks (Chinese Gardens),

More information

Cumbria Constabulary. Business Continuity Planning

Cumbria Constabulary. Business Continuity Planning Cumbria Constabulary Business Continuity Planning 0 Cumbria Shared Internal Audit Service Images courtesy of Carlisle City Council except: Parks (Chinese Gardens), www.sjstudios.co.uk, Monument (Market

More information

May 2012 Report No. 12-030

May 2012 Report No. 12-030 John Keel, CPA State Auditor Incentive Compensation at the Teacher Retirement System, the Employees Retirement System, and the Permanent School Fund Report No. 12-030 Incentive Compensation at the Teacher

More information

March 2007 Report No. 07-709

March 2007 Report No. 07-709 John Keel, CPA State Auditor the State s Attorney, Assistant Attorney General, and General Counsel Positions Report No. 07-709 the State s Attorney, Assistant Attorney General, and Positions Overall Conclusion

More information

How To Manage Risk At Atb Financial

How To Manage Risk At Atb Financial Guidelines for Financial Institutions Legislative Compliance Management (LCM) Date: July 2004 Introduction Regulatory risk is the risk of non-compliance with applicable regulatory requirements. For the

More information

SENSITIVE DATA SECURITY AND PROTECTION CALIFORNIA STATE UNIVERSITY, LOS ANGELES. Audit Report 11-52 January 3, 2012

SENSITIVE DATA SECURITY AND PROTECTION CALIFORNIA STATE UNIVERSITY, LOS ANGELES. Audit Report 11-52 January 3, 2012 SENSITIVE DATA SECURITY AND PROTECTION CALIFORNIA STATE UNIVERSITY, LOS ANGELES Audit Report 11-52 January 3, 2012 Henry Mendoza, Chair Melinda Guzman, Vice Chair Margaret Fortune Steven M. Glazer William

More information

How To Be A Compliant Customs Organization

How To Be A Compliant Customs Organization Managing Cross Border Regulations Global Customs GM is one of the world s largest manufacturers of passenger motors vehicles GM maintains a family of global brands including: Buick, Cadillac, Chevrolet,

More information

State Web Server Security Audit

State Web Server Security Audit A Report to the Montana Legisl ature I nform ation Systems Audit State Web Server Security Audit Department of Administration January 2008 Legislative Audit Division 0708DP-02 Legislative Audit Committee

More information

Major IT Projects: Continue Expanding Oversight and Strengthen Accountability

Major IT Projects: Continue Expanding Oversight and Strengthen Accountability Secretary of State Audit Report Jeanne P. Atkins, Secretary of State Gary Blackmer, Director, Audits Division Major IT Projects: Continue Expanding Oversight and Strengthen Accountability Summary Information

More information

Internal Controls and Risk Management Report

Internal Controls and Risk Management Report 42 Internal Controls and Risk Management Report Responsibility Our Board of Directors has the overall responsibility to ensure that sound and effective internal controls are maintained, while management

More information

EPA Policy on Assessing Capabilities of Non-Profit Applicants for Managing Assistance Awards

EPA Policy on Assessing Capabilities of Non-Profit Applicants for Managing Assistance Awards Classification No.: 5700.8 Approval Date: 02/23/2009 Review Date: 02/23/2012 1. PURPOSE. EPA Policy on Assessing Capabilities of Non-Profit Applicants for Managing Assistance Awards This Order establishes

More information

DISTRIBUTION: ASSISTANT G-1 FOR CIVILIAN PERSONNEL POLICY, DEPARTMENT OF THE ARMY DIRECTOR, PLANS, PROGRAMS, AND DIVERSITY, DEPARTMENT OF THE NAVY

DISTRIBUTION: ASSISTANT G-1 FOR CIVILIAN PERSONNEL POLICY, DEPARTMENT OF THE ARMY DIRECTOR, PLANS, PROGRAMS, AND DIVERSITY, DEPARTMENT OF THE NAVY DISTRIBUTION: ASSISTANT G-1 FOR CIVILIAN PERSONNEL POLICY, DEPARTMENT OF THE ARMY DIRECTOR, PLANS, PROGRAMS, AND DIVERSITY, DEPARTMENT OF THE NAVY DEPUTY DIRECTOR, PERSONNEL FORCE MANAGEMENT, DEPARTMENT

More information

ADVISORY MEMORANDUM REPORT ON DEVELOPMENT OF THE LOAN MONITORING SYSTEM ADVISORY REPORT NUMBER A1-03 FEBRUARY 23, 2001

ADVISORY MEMORANDUM REPORT ON DEVELOPMENT OF THE LOAN MONITORING SYSTEM ADVISORY REPORT NUMBER A1-03 FEBRUARY 23, 2001 ADVISORY MEMORANDUM REPORT ON DEVELOPMENT OF THE LOAN MONITORING SYSTEM ADVISORY REPORT NUMBER A1-03 FEBRUARY 23, 2001 This report may contain proprietary information subject to the provisions of 18 USC

More information

IDENTITY MANAGEMENT AND COMMON SYSTEM ACCESS HUMBOLDT STATE UNIVERSITY. Audit Report 12-46 December 21, 2012

IDENTITY MANAGEMENT AND COMMON SYSTEM ACCESS HUMBOLDT STATE UNIVERSITY. Audit Report 12-46 December 21, 2012 IDENTITY MANAGEMENT AND COMMON SYSTEM ACCESS HUMBOLDT STATE UNIVERSITY Audit Report 12-46 December 21, 2012 Henry Mendoza, Chair William Hauck, Vice Chair Lupe C. Garcia Steven M. Glazer Hugo N. Morales

More information

03/14/2013 Compensation Update Citizens Property Insurance Corporation Board of Governors Meeting March 22, 2013

03/14/2013 Compensation Update Citizens Property Insurance Corporation Board of Governors Meeting March 22, 2013 03/14/2013 Compensation Update Citizens Property Insurance Corporation Board of Governors Meeting March 22, 2013 Executive Summary As Florida s no profit provider of property insurance, Citizens is continuously

More information

STATE OF NORTH CAROLINA

STATE OF NORTH CAROLINA STATE OF NORTH CAROLINA AUDIT OF THE INFORMATION SYSTEM GENERAL CONTROLS AT VANCE-GRANVILLE COMMUNITY COLLEGE HENDERSON, NORTH CAROLINA JUNE 2004 OFFICE OF THE STATE AUDITOR RALPH CAMPBELL, JR. STATE AUDITOR

More information

Risk/Issue Management Plan

Risk/Issue Management Plan Risk/Issue Management Plan Centralized Revenue Opportunity System November 2014 Version 2.0 This page intentionally left blank Table of Contents 1. Overview... 3 1.1 Purpose... 3 1.2 Scope... 3 2. Roles

More information

Status Report of the Auditor General of Canada to the House of Commons

Status Report of the Auditor General of Canada to the House of Commons 2011 Status Report of the Auditor General of Canada to the House of Commons Chapter 1 Financial Management and Control and Risk Management Office of the Auditor General of Canada The 2011 Status Report

More information

Governmental Oversight and Accountability Committee

Governmental Oversight and Accountability Committee The Florida Senate BILL ANALYSIS AND FISCAL IMPACT STATEMENT (This document is based on the provisions contained in the legislation as of the latest date listed below.) Prepared By: The Professional Staff

More information

State of Minnesota. Enterprise Security Program Policy. Office of Enterprise Technology. Enterprise Security Office Policy. Version 1.

State of Minnesota. Enterprise Security Program Policy. Office of Enterprise Technology. Enterprise Security Office Policy. Version 1. State of Minnesota Enterprise Security Program Policy Office of Enterprise Technology Version 1.00 Approval: Gopal Khanna (Signature on file with the ESO) 06/22/2009 State Chief Information Officer Signature

More information

ESM Management Comments on Board of Auditors Annual Report to the Board of Governors for the period ended 31 December 2014

ESM Management Comments on Board of Auditors Annual Report to the Board of Governors for the period ended 31 December 2014 ESM Management Comments on Board of Auditors Annual Report to the Board of Governors for the period ended 31 December 2014 Dear Chairperson, I would like to thank you for the opportunity to provide management

More information

Charter of the Audit Committee of the Board of Directors

Charter of the Audit Committee of the Board of Directors Charter of the Audit Committee of the Board of Directors Dated as of April 27, 2015 1. Purpose The Audit Committee is a committee of the Board of Directors (the Board ) of Yamana Gold Inc. (the Company

More information

Guide for Conducting Peer Reviews of Audit Organizations of Federal Offices of Inspector General. September 2014

Guide for Conducting Peer Reviews of Audit Organizations of Federal Offices of Inspector General. September 2014 Guide for Conducting Peer Reviews of Audit Organizations of Federal Offices of Inspector General September 2014 Message from the Chair of the Council of the Inspectors General on Integrity and Efficiency

More information

COSO 2013: WHAT HAS CHANGED & STEPS TO TAKE TO ENSURE COMPLIANCE

COSO 2013: WHAT HAS CHANGED & STEPS TO TAKE TO ENSURE COMPLIANCE COSO 2013: WHAT HAS CHANGED & STEPS TO TAKE TO ENSURE COMPLIANCE COMMITTEE OF SPONSORING ORGANIZATIONS (COSO) 2013 The Committee of Sponsoring Organizations (COSO) Internal Controls Integrated Framework,

More information

Office of Inspector General

Office of Inspector General Audit Report OIG-14-035 OCC Needs to Strengthen Supervison of Trading Activities in Light of the JPMorgan Chase Losses May 14, 2014 Office of Inspector General Department of the Treasury This report has

More information

Board of Directors Meeting 12/04/2010. Operational Risk Management Charter

Board of Directors Meeting 12/04/2010. Operational Risk Management Charter Board of Directors Meeting 12/04/2010 Document approved Operational Risk Management Charter Table of contents A. INTRODUCTION...3 I. Background...3 II. Purpose and Scope...3 III. Definitions...3 B. GOVERNANCE...4

More information

John Keel, CPA State Auditor. An Audit Report on The Dam Safety Program at the Commission on Environmental Quality. May 2008 Report No.

John Keel, CPA State Auditor. An Audit Report on The Dam Safety Program at the Commission on Environmental Quality. May 2008 Report No. John Keel, CPA State Auditor An Audit Report on The Dam Safety Program at the Commission on Environmental Quality Report No. 08-032 An Audit Report on The Dam Safety Program at the Commission on Environmental

More information

Administrative Guidelines on the Internal Control Framework and Internal Audit Standards

Administrative Guidelines on the Internal Control Framework and Internal Audit Standards Administrative Guidelines on the Internal Control Framework and Internal Audit Standards GCF/B.09/18 18 February 2015 Meeting of the Board 24 26 March 2015 Songdo, Republic of Korea Agenda item 24 Page

More information

CHAPTER 18 OF THE CONSOLIDATED LAWS EXECUTIVE LAW ARTICLE 45 INTERNAL CONTROL RESPONSIBILITIES OF STATE AGENCIES

CHAPTER 18 OF THE CONSOLIDATED LAWS EXECUTIVE LAW ARTICLE 45 INTERNAL CONTROL RESPONSIBILITIES OF STATE AGENCIES Internal Control Act In 1987, the Legislature enacted a law entitled New York State Governmental Accountability, Audit and Internal Control Act of 1987. This act highlighted the need for agency management

More information

The Federal Financial Management Improvement Act (C)

The Federal Financial Management Improvement Act (C) Omnibus Consolidated Appropriations Act, 1997. PUBLIC LAW 104 208 SEPT. 30, 1996 110 STAT. 3009 *Public Law 104 208 104th Congress An Act Making omnibus consolidated appropriations for the fiscal year

More information

THE SOUTH AFRICAN HERITAGE RESOURCES AGENCY ENTERPRISE RISK MANAGEMENT FRAMEWORK

THE SOUTH AFRICAN HERITAGE RESOURCES AGENCY ENTERPRISE RISK MANAGEMENT FRAMEWORK THE SOUTH AFRICAN HERITAGE RESOURCES AGENCY ENTERPRISE RISK MANAGEMENT FRAMEWORK ACCOUNTABLE SIGNATURE AUTHORISED for implementation SIGNATURE On behalf of Chief Executive Officer SAHRA Council Date Date

More information

CHAPTER 2016-138. Committee Substitute for Committee Substitute for Committee Substitute for House Bill No. 1033

CHAPTER 2016-138. Committee Substitute for Committee Substitute for Committee Substitute for House Bill No. 1033 CHAPTER 2016-138 Committee Substitute for Committee Substitute for Committee Substitute for House Bill No. 1033 An act relating to information technology security; amending s. 20.61, F.S.; revising the

More information

Mapping COBIT 5 with IT Governance, Risk and Compliance at Ecopetrol S.A. By Alberto León Lozano, CISA, CGEIT, CIA, CRMA

Mapping COBIT 5 with IT Governance, Risk and Compliance at Ecopetrol S.A. By Alberto León Lozano, CISA, CGEIT, CIA, CRMA Volume 3, July 2014 Come join the discussion! Alberto León Lozano will respond to questions in the discussion area of the COBIT 5 Use It Effectively topic beginning 21 July 2014. Mapping COBIT 5 with IT

More information

July 2012 Report No. 12-045. An Audit Report on The ReHabWorks System at the Department of Assistive and Rehabilitative Services

July 2012 Report No. 12-045. An Audit Report on The ReHabWorks System at the Department of Assistive and Rehabilitative Services John Keel, CPA State Auditor The ReHabWorks System at the Department of Assistive and Rehabilitative Services Report No. 12-045 The ReHabWorks System at the Department of Assistive and Rehabilitative Services

More information

Public Sector Pension Investment Board

Public Sector Pension Investment Board Public Sector Pension Investment Board Office of the Auditor General of Canada Bureau du vérificateur général du Canada Ce document est également publié en français. Her Majesty the Queen in Right of Canada,

More information

OFFICE OF FINANCIAL REGULATION COLLECTION AGENCY REGISTRATIONS MORTGAGE-RELATED AND CONSUMER COLLECTION AGENCY COMPLAINTS PRIOR AUDIT FOLLOW-UP

OFFICE OF FINANCIAL REGULATION COLLECTION AGENCY REGISTRATIONS MORTGAGE-RELATED AND CONSUMER COLLECTION AGENCY COMPLAINTS PRIOR AUDIT FOLLOW-UP REPORT NO. 2013-031 OCTOBER 2012 OFFICE OF FINANCIAL REGULATION COLLECTION AGENCY REGISTRATIONS MORTGAGE-RELATED AND CONSUMER COLLECTION AGENCY COMPLAINTS PRIOR AUDIT FOLLOW-UP Operational Audit COMMISSIONER

More information

VA HEALTH CARE. Actions Needed to Improve Administration of the Provider Performance Pay and Award Systems. Report to Congressional Requesters

VA HEALTH CARE. Actions Needed to Improve Administration of the Provider Performance Pay and Award Systems. Report to Congressional Requesters United States Government Accountability Office Report to Congressional Requesters July 2013 VA HEALTH CARE Actions Needed to Improve Administration of the Provider Performance Pay and Award Systems GAO-13-536

More information

The University of Texas Southwestern Medical Center TAC 202 Compliance. Internal Audit Report 15:31

The University of Texas Southwestern Medical Center TAC 202 Compliance. Internal Audit Report 15:31 Office of Internal Audit The University of Texas Southwestern Medical Center Internal Audit Report 15:31 October 8, 2015 Executive Summary Background Created in 1977 by the Texas Legislature, the Texas

More information

How quality assurance reviews can strengthen the strategic value of internal auditing*

How quality assurance reviews can strengthen the strategic value of internal auditing* How quality assurance reviews can strengthen the strategic value of internal auditing* PwC Advisory Internal Audit Table of Contents Situation Pg. 02 In response to an increased focus on effective governance,

More information

Compliance. Group Standard

Compliance. Group Standard Group Standard Compliance Serco is committed to good governance practices and the management of risks supported by a robust business compliance process SMS-GS-G2 Compliance July 2014 v1.0 Serco Public

More information

Note The amendments described in this circular will be published in the Immigration New Zealand Operational Manual in due course.

Note The amendments described in this circular will be published in the Immigration New Zealand Operational Manual in due course. 21 July 2015 IMMIGRATION NEW ZEALAND INSTRUCTIONS: Amendment Circular No. 2015/07 To: All Manual Holders AMENDMENTS TO THE IMMIGRATION NEW ZEALAND OPERATIONAL MANUAL Introduction This circular outlines

More information

Standards for the Professional Practice of Internal Auditing

Standards for the Professional Practice of Internal Auditing Standards for the Professional Practice of Internal Auditing THE INSTITUTE OF INTERNAL AUDITORS 247 Maitland Avenue Altamonte Springs, Florida 32701-4201 Copyright c 2001 by The Institute of Internal Auditors,

More information

Audit Report for South Lakeland District Council. People and Places Directorate Neighbourhood Services. Audit of Grounds Maintenance

Audit Report for South Lakeland District Council. People and Places Directorate Neighbourhood Services. Audit of Grounds Maintenance Audit Report for South Lakeland District Council People and Places Directorate Neighbourhood Services Audit of Grounds Maintenance Cumbria Shared Internal Audit Service: Internal Audit Report 7 th November

More information

Audit of the Department of State Information Security Program

Audit of the Department of State Information Security Program UNITED STATES DEPARTMENT OF STATE AND THE BROADCASTING BOARD OF GOVERNORS OFFICE OF INSPECTOR GENERAL AUD-IT-15-17 Office of Audits October 2014 Audit of the Department of State Information Security Program

More information

Annual Governance Statement 2013/14

Annual Governance Statement 2013/14 31 Annual Governance Statement 2013/14 1. SCOPE OF RESPONSIBILITY ESPO is responsible for ensuring that its business is conducted in accordance with the law and proper standards, and that public money

More information

AUDIT REPORT OFFICE OF INSPECTOR GENERAL IG-02-019 PROPERTY CONTROL SYSTEM ANALYSIS REPORTING ON SPACE FLIGHT OPERATIONS CONTRACT SUBCONTRACTORS

AUDIT REPORT OFFICE OF INSPECTOR GENERAL IG-02-019 PROPERTY CONTROL SYSTEM ANALYSIS REPORTING ON SPACE FLIGHT OPERATIONS CONTRACT SUBCONTRACTORS IG-02-019 AUDIT REPORT PROPERTY CONTROL SYSTEM ANALYSIS REPORTING ON SPACE FLIGHT OPERATIONS CONTRACT SUBCONTRACTORS July 8, 2002 OFFICE OF INSPECTOR GENERAL National Aeronautics and Space Administration

More information

Audit of the Policy on Internal Control Implementation

Audit of the Policy on Internal Control Implementation Audit of the Policy on Internal Control Implementation Natural Sciences and Engineering Research Council of Canada Social Sciences and Humanities Research Council of Canada February 18, 2013 1 TABLE OF

More information

TREASURY INSPECTOR GENERAL FOR TAX ADMINISTRATION

TREASURY INSPECTOR GENERAL FOR TAX ADMINISTRATION TREASURY INSPECTOR GENERAL FOR TAX ADMINISTRATION The Internal Revenue Service September 14, 2010 Reference Number: 2010-10-115 This report has cleared the Treasury Inspector General for Tax Administration

More information

INFORMATION MANAGEMENT

INFORMATION MANAGEMENT United States Government Accountability Office Report to the Committee on Homeland Security and Governmental Affairs, U.S. Senate May 2015 INFORMATION MANAGEMENT Additional Actions Are Needed to Meet Requirements

More information

Contract management: renewal and transition. Report to Parliament 10 : 2013 14

Contract management: renewal and transition. Report to Parliament 10 : 2013 14 Contract management: renewal and transition Report to Parliament 10 : 2013 14 Queensland Audit Office Location Level 14, 53 Albert Street, Brisbane Qld 4000 PO Box 15396, City East Qld 4002 Telephone (07)

More information

SOCIAL SECURITY. July 19, 2004

SOCIAL SECURITY. July 19, 2004 SOCIAL SECURITY July 19, 2004 The Honorable E. Clay Shaw, Jr. Chairman, Subcommittee on Social Security Committee on Ways and Means House of Representatives Washington, D.C. 20515 Dear Mr. Shaw: Thank

More information

Internal Audit of the Sport Canada Hosting Program

Internal Audit of the Sport Canada Hosting Program Internal Audit of the Sport Canada Hosting Program Office of the Chief Audit and Evaluation Executive November 2009 Table of Contents Executive Summary...i 1. Introduction and Context...1 1.1 Authority

More information

Management of NEC3 Compensation Events (IA 12 521) Andrew Wolstenholme, Chief Executive. Audit Conclusion: Adequately Controlled and Audit Closed

Management of NEC3 Compensation Events (IA 12 521) Andrew Wolstenholme, Chief Executive. Audit Conclusion: Adequately Controlled and Audit Closed FINAL INTERNAL AUDIT REPORT Management of NEC3 Compensation Events (IA 12 521) Andrew Wolstenholme, Chief Executive Audit Conclusion: Adequately Controlled and Audit Closed 02 December 2013 Number of issues

More information

PRACTICE GUIDE. Formulating and Expressing Internal Audit Opinions

PRACTICE GUIDE. Formulating and Expressing Internal Audit Opinions PRACTICE GUIDE Formulating and Expressing Internal Audit Opinions 2 of 23 Table of Contents 1. Executive Summary... 1 2. Introduction... 2 3. Planning the Expression of an Opinion... 3 3.1 Expressing an

More information

AUDITOR-GENERAL S AUDITING STANDARD 4 (REVISED) THE AUDIT OF SERVICE PERFORMANCE REPORTS. Contents

AUDITOR-GENERAL S AUDITING STANDARD 4 (REVISED) THE AUDIT OF SERVICE PERFORMANCE REPORTS. Contents AUDITOR-GENERAL S AUDITING STANDARD 4 (REVISED) THE AUDIT OF SERVICE PERFORMANCE REPORTS Contents Page Introduction 3-8301 Scope of this Statement 3-8301 Application 3-8303 Objectives 3-8304 Definitions

More information

J u n e 2 0 1 0. N a t i o n a l R e s e a r c h C o u n c i l C a n a d a. I n t e r n a l A u d i t, N R C. Audit of Risk Management.

J u n e 2 0 1 0. N a t i o n a l R e s e a r c h C o u n c i l C a n a d a. I n t e r n a l A u d i t, N R C. Audit of Risk Management. N a t i o n a l R e s e a r c h C o u n c i l C a n a d a Audit of Risk Management I n t e r n a l A u d i t, N R C J u n e 2 0 1 0 June 2010 i 1.0 Executive Summary and Conclusion Background This audit

More information