ANNUAL RISK ASSESSMENT REPORT.PDF
Extracted text (via pymupdf)
8160 characters
Internal Audit Analyzes County Risks
to Prioritize Audit Work
Internal Audit defines risk as the possibility of
an event occurring that will have an adverse
impact on the achievement of County
objectives. County management is responsible
for establishing risk management and control
processes, while Internal Audit evaluates its
effectiveness and make recommendations.
Internal Audit also establishes a risk-based
audit plan annually to determine the priorities of
audit work.
This report describes risk management roles
and responsibilities, along with key factors that
Internal Audit considers when evaluating risks
and developing an audit plan.
Analyze Risk
& Prepare
Audit Plan
Board
Approves
Audit Plan
Conduct
Audit Work
Publish
Audit
Reports
Perform
Follow Up
Risk Management is
Everyone’s Responsibility
2
Audit Work is Prioritized
Based on Risk
3
Audit Resources
Influence the Audit Plan
5
Fiscal Year 2024 Audit
Plan
6
Graphic by macrovector – freepik.com
RISK ASSESSMENT REPORT
Internal Audit Department
June 2023
Maricopa County Internal Audit
Risk Assessment Report (June 2023)
Page 2
RISK MANAGEMENT IS EVERYONE’S RESPONSIBILITY
The Board and County leadership establish the direction of County operations through the
development of a four-year strategic plan as a road map for the future. Through the
development of strategic goals and performance measures, County leaders and managers are
entrusted to execute the plan. Risks that threaten the strategic plan can be difficult to manage
due to Maricopa County’s diverse physical, financial, and operational environment.
Roles for Successful Risk Management
Effective risk management requires collaboration by several roles to identify, assess, and
respond to risk.
Management is responsible for identifying, assessing, controlling, and monitoring risk on a day-
to-day basis. Without management support, employees may not be effective in controlling the
risk they encounter. In a perfect world, this would be the only role needed; however, in the real
world, internal controls do not operate perfectly.
Managing Risk is an Enterprise-wide Responsibility
Management
Front line and upper-level management that owns and
manages risks and controls.
Oversight
Advisors that monitor and support
risk-related matters.
Includes: Finance, Risk Management,
Procurement, Information Technology, etc.
Internal Audit
Evaluates the
effectiveness
of County risk
management
processes.
Maricopa County Internal Audit
Risk Assessment Report (June 2023)
Page 3
Code of Conduct & Other County
County Policies
▪Outlines appropriate and
ethical behavior
▪Addresses current issues
through regular updates
Employee Training
▪Informs and reinforces high
expectations for ethical
behavior
Internal Audit
▪Evaluates County operations
and issues recommendations
that may deter fraud
▪Provides tools and resources
▪Fraud hotline deployment
FY24
Oversight functions such as finance, budget, risk management, procurement, information
technology, and human resources play an important role. As a second line of defense, they
are advisors who provide support and help ensure risk and controls are managed. Some
County agencies also have internal functions that serve this purpose. These activities range
from quality control reporting to inspecting and reconciling County records.
Internal Audit provides independent and objective assurance on the adequacy and
effectiveness of the County’s governance, risk management, and control processes. Each year,
we review a limited number of County activities to ensure that management is identifying,
assessing, controlling, and monitoring risks. We also serve as a resource to managers and
supervisors in identifying areas for improvement.
In addition to the roles discussed above, the County is subject to external reviews and audits
from various regulators and independent parties. These parties can provide external insights
into risk evaluation and improvement opportunities.
Ethics and Fraud
Risk management is further reinforced by fraud prevention efforts. Fraud is an act of
intentional deception to secure unfair or unlawful gain at the expense of an organization or
individual. While fraud risk cannot be eliminated, it can be mitigated through a strong ethical
framework, effective controls, and education. Awareness is fundamental to fraud mitigation,
and is enhanced through effective use of the following tools:
AUDIT WORK IS PRIORITIZED BASED ON RISK
Internal Audit uses a risk-based approach to prioritize work and develop an annual audit plan,
as required by professional audit standards.
Maricopa County Internal Audit
Risk Assessment Report (June 2023)
Page 4
Continuous Risk Assessment and Agile Auditing
We continue to adapt our continuous risk assessment and agile audit practices to improve our
responsiveness to the ever-changing County environment. In addition to preparing an annual
audit plan, we also review process level risks for many areas throughout the year to identify
potential audits. Agile audits target key risks and limit reporting to specific areas which may
result in shorter and more frequent engagements.
We consider several factors when evaluating risks and developing an annual audit plan.
Finalizing the Audit Plan
Once risks are evaluated, we develop a draft audit plan for the upcoming year by:
• Considering requirements for audits on a defined schedule and for mandated audits.
• Analyzing audit competency requirements and resources to complete the work.
• Discussing the draft audit plan with County leadership.
Factors that Influence the Annual Audit Plan
Annual Audit
Plan
Public
Impact &
Reputation
Risk
Emerging
Trends
Financial
Impact
Executive
Leadership
Input &
Expectations
IT Risk
Auditor
Judgement
Audit
Resources
Maricopa County Internal Audit
Risk Assessment Report (June 2023)
Page 5
After the draft audit plan has been prepared and reviewed, we seek formal approval for the
audit plan from the Board prior to the start of the new fiscal year. The fiscal year 2024 Board-
approved audit plan is on page six.
AUDIT RESOURCES INFLUENCE THE AUDIT PLAN
The Board establishes our staffing level, balancing risk and audit coverage with budgetary
requirements. A well-staffed internal audit function that regularly audits high-risk areas can
identify costly activities such as fraud, waste, and non-compliance. It can also assist
management in the decision to avoid, share, reduce, or accept risks. Our work provides
meaningful assurance, advice, and insight to the Board on key risks so they can make informed
decisions. We apply professional judgement and experience to prioritize high-risk areas and
maximize limited resources using internal staff and external specialists (subject-matter
experts).
Maricopa County Internal Audit
Risk Assessment Report (June 2023)
Page 6
FISCAL YEAR 2024 AUDIT PLAN
Agency Engagements
Correctional Health Services – Medication Administration
MCDOT Information Technology Center – Service Delivery
Public Health – Risk Assessment
Sheriff’s Office – Detention Use of Force
Sheriff’s Office – Purchase Cards and Mobile Device Management
Countywide Engagements
Control Environment – Maturity Assessment
Policy Change Compliance:
• Fee Level Reviews
• Mobile Devices
• Non-Capital Assets
• Purchase Cards
• TikTok Ban
Revenue Contracts
Single Audit Reporting Compliance – Grant Subrecipients
Travel & Mileage Reimbursements
Other Services Upon Request
Continuous Monitoring
Capital Improvement Projects
Mobile Device Management
Purchase Cards
Other Areas as Determined
Accounting Reviews
Clerk of Superior Court
9 Justice Courts
Other Reports
Audit Plan Report
Audit Recommendations Outstanding More than One Year
County ERM Goal Support
Fraud Hotline Deployment
Internal Audit Department Performance Report