INTERNAL AUDIT REPORT

Similar documents
SECTION J QUALITY ASSURANCE AND IMPROVEMENT PROGRAM

INTERNAL AUDIT REPORT

Audit Committee Charter. St Andrew s Insurance (Australia) Pty Ltd St Andrew s Life Insurance Pty Ltd St Andrew s Australia Services Pty Ltd

Audit Status Report As of March 23, 2010

OKLAHOMA BOARD OF NURSING PERFORMANCE AUDIT FOR THE PERIOD JANUARY 1, 2007 THROUGH JUNE 30, Oklahoma State Auditor & Inspector

MSB FINANCIAL CORP. MILLINGTON BANK AUDIT COMMITTEE CHARTER

VALLEYVIEW AUTOMATED PAYROLL SYSTEM

Internal Audit Charter and operating standards

Audit Committee Charter

.100 POLICY STATEMENT

Procedures for Payments Made to or on Behalf of International Students, Visitors and Vendors

Process Improvement Center of Excellence Service Proposal Recommendation. Operational Oversight Committee Report Submission

American Recovery and Reinvestment Act Reporting Policy

CASSOWARY COAST REGIONAL COUNCIL POLICY ENTERPRISE RISK MANAGEMENT

Chicago Department of Finance. Tax Audit Process

Gravesham Borough Council

The report was approved by the Audit Committee at its June 23, 2004 meeting at which time it became public record.

ES PROCEDURES FOR OVERPAYMENT RECOVERY

Business Continuity Management Policy

Version: Modified By: Date: Approved By: Date: 1.0 Michael Hawkins October 29, 2013 Dan Bowden November 2013

Wire Transfer Request

FHWA Compliance Assessment Program (CAP) Guidance

CHARTER OF THE COMPENSATION COMMITTEE OF THE BOARD OF DIRECTORS OF UPLAND SOFTWARE, INC.

April 29, 2013 INTRODUCTION ORGANIZATIONAL OVERVIEW PROJECT OVERVIEW

Appendix H. Annual Risk Assessment and Audit Plan 2013/14

RATIONALE TERMS OF REFERENCE FOR THE QUALITY COMMITTEE UNDER THE EXCELLENT CARE FOR ALL ACT. Authority

Systems Support - Extended

Multi-Year Accessibility Policy and Plan for NSF Canada and NSF International Strategic Registrations Canada Company,

PENETRATION TEST OF THE INDIAN HEALTH SERVICE S COMPUTER NETWORK

SETTING UP A SYNDICATE SERVICE COMPANY IN HONG KONG

Request for Resume (RFR) CATS II Master Contract. All Master Contract Provisions Apply

Impact Partnership Business Plan 2011/12. Impact Partnership Payroll Services. Business Plan 2011/12

10 th May Dear Peter, Re: Audit Quality in Australia: A Strategic Review

Grants Accounting. Effort Certification

Data Warehouse Scope Recommendations

TrustED Briefing Series:

Corporate Standards for data quality and the collation of data for external presentation

Auditor General s Office

North Carolina Department of Commerce Division of Employment Security

GUIDELINE INFORMATION MANAGEMENT (IM) PROGRAM PLAN

WHAT YOU NEED TO KNOW ABOUT. Protecting your Privacy

95 Executive Parkway, Suite 500 Hudson, OH Ohio STS Prices December 2014

SECTION I.1 AUDIT ENGAGEMENT PLANNING

Controller-Treasurer Department Internal Audit Division

Risk Management Policy AGL Energy Limited

IT CHANGE MANAGEMENT POLICY

DATE APPROVED March Version Date Comments / Changes 1.0 March 2011 Initial policy released

ISO Management Systems. Guidance on understanding the benefits of an ISO Management System

Electronic Data Interchange (EDI) Requirements

EJttilb Health. The University of Texas Medical Branch Audit Services. Audit Report. Epic In-Basket Management Audit. Engagement Number

AUDIT AND RISK COMMITTEE TERMS OF REFERENCE

CARRIER COORDINATION TEAM Plan for Operations Committee

GENERAL MOTORS COMPANY AUDIT COMMITTEE CHARTER. Most Recently Amended: December 8, 2015

How to Fill Out a Timesheet

Sources of Federal Government and Employee Information

Corporate Credit Card Policy

To Receive CPE Credit

Project Startup Report Presented to the IT Committee June 26, 2012

Duty Statement Manager The Early Years at Seymour (TEYS)

The Illinis Labratry Advisry Cmmittee Act

NEW FUTURES APPLICATION

Employee Benefits Liability Policy

Service Level Agreement (SLA) Hosted Products. Netop Business Solutions A/S

The Town of Fort Frances

Web Development the Next Steps

FINANCIAL SERVICES FLASH REPORT

Database Services - Extended

Newborn Blood Spot Failsafe Solution (NBSFS) Operational Level Agreements. Part B: Child Health Record Department (CHRD) Users

Chapter 7 Business Continuity and Risk Management

Strategic Goal 2. Timely, Accurate, and Responsive Customer Service U.S. OFFICE OF PERSONNEL MANAGEMENT RECRUIT, RETAIN, AND HONOR

CLIENT AGREEMENT School Based Trainees

CU Payroll Data Entry

Financial Planning Agreement

UNIVERSITY OF CALIFORNIA MERCED PERFORMANCE MANAGEMENT GUIDELINES

expertise hp services valupack consulting description security review service for Linux

Waitemata District Health Board, 15 Shea Terrace, Takapuna

Training will be conducted in the following areas:

ERISA Compliance FAQs: Fiduciary Responsibilities

Chief Finance and Operations Officer IfM Education and Consultancy Services (IfM ECS)

Engineering Society Financial Handbook

Fraud Prevention Techniques for Higher Education

CMS Eligibility Requirements Checklist for MSSP ACO Participation

Symantec User Authentication Service Level Agreement

We will record and prepare documents based off the information presented

Original Date01/04/2011 Revision 1 Date: 02/06/2011 Document Owner: Operations Manager CLIENT AGREEMENT

Network Security Trends in the Era of Cloud and Mobile Computing

Presentation: The Demise of SAS 70 - What s Next?

Cell Phone & Data Access Policy Frequently Asked Questions

Financial Accountability Handbook

PUBLIC COMPANY ACCOUNTING OVERSIGHT BOARD

Table of Contents. Welcome to Employee Self Service... 3 Who Do I Call For Help?... 3

HIPAA 5010 Implementation FAQs for Health Care Professionals

Third Party Originator Application

Research Report. Abstract: Advanced Malware Detection and Protection Trends. September 2013

Communicating Deficiencies in Internal Control to Those Charged with Governance and Management

How To Be An Administrative Assistant

SEC FLASH REPORT. June 28, 2011

COPIES-F.Y.I., INC. Policies and Procedures Data Security Policy

Directives to LHINs in respect of Reporting Requirements under the BPSAA. Issued By Minister of Health and Long-Term Care

This report provides Members with an update on of the financial performance of the Corporation s managed IS service contract with Agilisys Ltd.

Transcription:

REPORT PAYROLL SYSTEM ISSUE DATE: DECEMBER 1, 2015 REPORT NO. 2015-12

EXECUTIVE SUMMARY AUDIT OBJECTIVES AND SCOPE The purpse f the audit was t determine whether management cntrls ver the Payrll System are adequate t ensure: 1. Accuracy and timeliness f payrll disbursements. 2. Cmpliance with applicable legal requirements. We reviewed infrmatin fr the perid January 1, 2013 August 31, 2015. Details f ur audit s scpe and methdlgy are n page 3. BACKGROUND The Prt uses the PepleSft Human Capital Management (HCM) mdule t manage all human resurce and payrll prcessing activities. This mdule is used frm hiring t resignatin. All emplyee and payrll-related infrmatin resides in this mdule. The Prt uses this mdule t administer ver $215 millin annually in pay, benefits and taxes fr Prt emplyees. Fr purpses f this audit, nly the prcesses related t prducing bi-weekly and weekly payrlls are within scpe. The Prt has used the HCM mdule since 1997, and has undergne five upgrades since that time. The mst recent upgrade was in Octber 2015. This upgrade ensures cntinued technical supprt and nging sftware updates and security patches frm the sftware vendr. The Prt emplys apprximately 1,800 FTEs. It prcesses the majrity f payrll bi-weekly. It issues a weekly payrll fr abut 50 emplyees. O AUDIT RESULT Management cntrls ver the Payrll System are adequate t ensure (1) accuracy and timeliness f payrll disbursements and (2) cmpliance with applicable legal requirements. i

TABLE OF CONTENTS EXECUTIVE SUMMARY...i I. TRANSMITTAL LETTER... 1 II. BACKGROUND... 2 III. FINANCIAL HIGHLIGHTS... 2 IV. HIGHLIGHTS AND ACCOMPLISHMENTS... 3 V. AUDIT SCOPE AND METHODOLOGY... 3 VI. CONCLUSION... 4

TRANSMITTAL LETTER Audit Cmmittee Prt f Seattle Seattle, Washingtn We have cmpleted an audit f the management cntrls ver and transactin prcessing in the Payrll System. We reviewed infrmatin relating t the Payrll System frm January 1, 2013 August 31, 2015. We cnducted this perfrmance audit in accrdance with Generally Accepted Gvernment Auditing Standards and the Internatinal Standards fr the Prfessinal Practice f Internal Auditing. Thse standards require that we plan and perfrm the audit t btain sufficient, apprpriate evidence t prvide a reasnable basis fr ur findings and cnclusins based n ur audit bjectives. We believe that the evidence btained prvides a reasnable basis fr ur findings and cnclusins based n ur audit bjectives. We extend ur appreciatin t management and staff f the Accunting and Financial Reprting Department fr their assistance and cperatin during the audit. Jyce Kirangi, CPA, CGMA Internal Audit, Directr AUDIT TEAM Ruth Riddle, Senir Auditr Jack Hutchinsn, Audit Manager RESPONSIBLE MANAGEMENT TEAM Duane Hill, Senir Manager, Disbursements, AFR Rudy Caluza, Directr, AFR 1

BACKGROUND The Prt uses the PepleSft Human Capital Management (HCM) mdule t manage all human resurce and payrll prcessing activities. This mdule is used frm hiring t resignatin. All emplyee and payrll-related infrmatin resides in this mdule. The Prt uses the system t administer ver $215 millin annually in pay, benefits and taxes fr Prt emplyees. Fr purpses f this audit, nly the prcesses related t prducing bi-weekly and weekly payrlls are within scpe. The Prt has used the HCM mdule since 1997, and has undergne five upgrades since that time. The Prt upgraded t Versin 9.1 in 2013 and Versin 9.2 in Octber 2015. The mst recent upgrade ensures cntinued technical supprt and nging sftware updates and security patches frm the sftware vendr. The Payrll Wrk Grup cnsists f five staff. They are respnsible fr prcessing bi-weekly payrll fr apprximately 1800 FTEs, plus a weekly payrll fr abut 50 f ttal FTEs. Pay perids end n Saturday. Time reprts must be submitted t the Payrll Wrk Grup n later than 2 p.m., n the fllwing Mnday. Between Mnday and Wednesday, the Payrll Wrk Grup cnducts a rigrus prcess f verifying the submitted time, addressing all system-flagged exceptins, and prducing a final cnfirmed payrll register. Bank uplads fr direct depsits and hard cpy checks typically ccur by clse-f-business Wednesday. Direct depsits are available in emplyees persnal bank accunts n Friday mrning. FINANCIAL HIGHLIGHTS AVERAGE BI-WEEKLY PAYROLL YEAR Average Payrll Average % f Represented Staff Average % f Nn- Represented Staff Average Number Checks Prcessed Ttal Annual Salaries and Wages Expense 2013 $ 5,854,078 39 61 1780 $151,718,831 2014 $ 6,082,446 41 59 1817 $ 153,495,732 Data Surce: PepleSft Financials 2

HIGHLIGHTS AND ACCOMPLISHMENTS Management cntinues t reduce hard cpy payrll checks. As f August 2015, the majrity (96%) f the Prt s apprximately 1,800 staff receives salary and wage payments by direct depsit t persnal bank accunts r pay cards. This accmplishment prvides multiple benefits: Eliminates printing and mailing f paper checks. Reduces fraud risk f stlen r altered checks. Eliminates emplyees trips t the bank. Facilitates payments t emplyees during emergencies and natural disasters. Management, in cncert with the Prt s Cntinuus Prcess Imprvement team, Human Resurces and Develpment, and Labr Relatins, has revisited varius payrll prcesses, t decrease prcessing steps, increase efficiencies, and reduce risk f errrs. The Payrll Wrk Grup cmpletes its rigrus prcess frm receipt f timesheet submissin t prductin f final payrll register within 2.5 days fr apprximately 1,800 FTEs. In keeping with the Prt f Seattle s G Green Initiative, management implemented electrnic W-2s, in lieu f paper, which has reduced printing and mailing csts. AUDIT SCOPE AND METHODOLOGY We reviewed infrmatin fr the perid January 1, 2013 August 31, 2015. We utilized a risk-based apprach frm planning t testing. We gathered infrmatin thrugh research, interviews, bservatins, and analytical review, in rder t btain a cmplete understanding f management cntrls ver and transactin prcessing in the payrll system. We evaluated risk and tested the mitigating cntrls, t determine whether they were perating as intended. The key management cntrls we tested and the detailed tests we perfrmed are as fllws: 1. T determine whether management cntrls are adequate t ensure: a. Payrll is accurate: i. We evaluated the prcess fr assigning and authrizing access t the payrll system. ii. We determined whether there was adequate management versight f user accunts t ensure users are current and valid. 3

iii. We tested authrizatins f user accunts fr 1 st quarter 2013, 3 rd quarter 2014, and 2 nd quarter 2015. iv. We determined whether cnflictive respnsibilities were segregated: Data entry. Apprval f changes. Recnciliatin f data entry. Transmissin f withhlding. Custdy f hard cpy checks. v. Fr the pay perid ended 8-22-15, we recnciled payrll issued t underlying time submissins. vi. Fr the perid ended 8-22-15, we recnciled payrll withhlding t subsequent payments fr: Federal withhlding. Retirement. Charitable cntributins. vii. Fr the perid 5-1-15 t 9-21-15, we traced psitive pay exceptins t supprting dcuments. b. Payrll is timely: i. We reviewed payrll prcessing frm submissin f staff s time t issuance f payrll. ii. We reviewed the timeline fr entering adjustments/crrectins in the system iii. Fr the pay perid ended 8-22-15, we identified the date by which payrll staff: Cmpleted payrll prcessing. Prduced the final payrll register. Upladed psitive pay advice t the payrll bank accunt and prduced hard cpy checks. VII. T determine whether management cntrls are adequate t ensure payrll is in cmpliance with applicable legal requirements, we reviewed the prcesses and cnducted detailed tests as fllws: c. Submissin f federal withhlding. d. Submissin f retirement deductins. e. Remittance f charitable deductins. f. We determined whether the fllwing withhlding and deductins were remitted t the apprpriate recipients i. Federal withhlding (pay perid ended 8-22-15). ii. Retirement deductins (pay perid ended 8-22-15). iii. Charitable deductins (2 nd quarter 2015). CONCLUSION Management cntrls ver the Payrll System are adequate t ensure (1) accuracy and timeliness f payrll disbursements and (2) cmpliance with applicable legal requirements. 4