ANNUAL RISK ASSESSMENT REPORT.PDF

Maricopa County — Formal (2023-06-14)

View PDF Item 71 Meeting page

Extracted text (via pymupdf) 8160 characters
Internal Audit Analyzes County Risks 
to Prioritize Audit Work  
Internal Audit defines risk as the possibility of 
an event occurring that will have an adverse 
impact on the achievement of County 
objectives.  County management is responsible 
for establishing risk management and control 
processes, while Internal Audit evaluates its 
effectiveness and make recommendations.  
Internal Audit also establishes a risk-based 
audit plan annually to determine the priorities of 
audit work.   
This report describes risk management roles 
and responsibilities, along with key factors that 
Internal Audit considers when evaluating risks 
and developing an audit plan.   
Analyze Risk 
& Prepare 
Audit Plan
Board 
Approves  
Audit Plan
Conduct 
Audit Work
Publish 
Audit 
Reports 
Perform 
Follow Up
 
Risk Management is 
Everyone’s Responsibility 
2 
Audit Work is Prioritized 
Based on Risk 
3 
Audit Resources 
Influence the Audit Plan 
5 
Fiscal Year 2024 Audit 
Plan 
6 
Graphic by macrovector – freepik.com 
RISK ASSESSMENT REPORT 
Internal Audit Department 
June 2023

Maricopa County Internal Audit 
 
Risk Assessment Report (June 2023) 
Page 2 
RISK MANAGEMENT IS EVERYONE’S RESPONSIBILITY 
 
The Board and County leadership establish the direction of County operations through the 
development of a four-year strategic plan as a road map for the future.  Through the 
development of strategic goals and performance measures, County leaders and managers are 
entrusted to execute the plan.  Risks that threaten the strategic plan can be difficult to manage 
due to Maricopa County’s diverse physical, financial, and operational environment.   
 
Roles for Successful Risk Management 
Effective risk management requires collaboration by several roles to identify, assess, and 
respond to risk.  
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
Management is responsible for identifying, assessing, controlling, and monitoring risk on a day-
to-day basis.  Without management support, employees may not be effective in controlling the 
risk they encounter.  In a perfect world, this would be the only role needed; however, in the real 
world, internal controls do not operate perfectly.  
 
Managing Risk is an Enterprise-wide Responsibility 
Management
Front line and upper-level management that owns and
manages risks and controls.
Oversight
Advisors that monitor and support 
risk-related matters.
Includes: Finance, Risk Management, 
Procurement, Information Technology, etc.
Internal Audit
Evaluates the 
effectiveness 
of County risk 
management
processes.

Maricopa County Internal Audit 
 
Risk Assessment Report (June 2023) 
Page 3 
Code of Conduct & Other County 
County Policies
▪Outlines appropriate and 
ethical behavior
▪Addresses current issues
through regular updates
Employee Training
▪Informs and reinforces high
expectations for ethical    
behavior
Internal Audit
▪Evaluates County operations
and issues recommendations
that may deter fraud
▪Provides tools and resources
▪Fraud hotline deployment
FY24
 
Oversight functions such as finance, budget, risk management, procurement, information 
technology, and human resources play an important role.  As a second line of defense, they 
are advisors who provide support and help ensure risk and controls are managed.  Some 
County agencies also have internal functions that serve this purpose.  These activities range 
from quality control reporting to inspecting and reconciling County records. 
 
Internal Audit provides independent and objective assurance on the adequacy and 
effectiveness of the County’s governance, risk management, and control processes.  Each year, 
we review a limited number of County activities to ensure that management is identifying, 
assessing, controlling, and monitoring risks.  We also serve as a resource to managers and 
supervisors in identifying areas for improvement. 
 
In addition to the roles discussed above, the County is subject to external reviews and audits 
from various regulators and independent parties.  These parties can provide external insights 
into risk evaluation and improvement opportunities.            
 
Ethics and Fraud   
Risk management is further reinforced by fraud prevention efforts.  Fraud is an act of 
intentional deception to secure unfair or unlawful gain at the expense of an organization or 
individual.  While fraud risk cannot be eliminated, it can be mitigated through a strong ethical 
framework, effective controls, and education.  Awareness is fundamental to fraud mitigation, 
and is enhanced through effective use of the following tools:  
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
AUDIT WORK IS PRIORITIZED BASED ON RISK 
 
Internal Audit uses a risk-based approach to prioritize work and develop an annual audit plan, 
as required by professional audit standards.

Maricopa County Internal Audit 
 
Risk Assessment Report (June 2023) 
Page 4 
 
Continuous Risk Assessment and Agile Auditing 
We continue to adapt our continuous risk assessment and agile audit practices to improve our 
responsiveness to the ever-changing County environment.  In addition to preparing an annual 
audit plan, we also review process level risks for many areas throughout the year to identify 
potential audits.  Agile audits target key risks and limit reporting to specific areas which may 
result in shorter and more frequent engagements.     
 
We consider several factors when evaluating risks and developing an annual audit plan.   
        
 
 
 
 
Finalizing the Audit Plan 
 
Once risks are evaluated, we develop a draft audit plan for the upcoming year by: 
• Considering requirements for audits on a defined schedule and for mandated audits. 
• Analyzing audit competency requirements and resources to complete the work. 
• Discussing the draft audit plan with County leadership. 
 
Factors that Influence the Annual Audit Plan 
Annual Audit 
Plan
Public 
Impact & 
Reputation 
Risk
Emerging 
Trends
Financial 
Impact
Executive 
Leadership 
Input & 
Expectations
IT Risk
Auditor 
Judgement
Audit 
Resources

Maricopa County Internal Audit 
 
Risk Assessment Report (June 2023) 
Page 5 
After the draft audit plan has been prepared and reviewed, we seek formal approval for the 
audit plan from the Board prior to the start of the new fiscal year.  The fiscal year 2024 Board-
approved audit plan is on page six.  
 
AUDIT RESOURCES INFLUENCE THE AUDIT PLAN 
 
The Board establishes our staffing level, balancing risk and audit coverage with budgetary 
requirements.  A well-staffed internal audit function that regularly audits high-risk areas can 
identify costly activities such as fraud, waste, and non-compliance.  It can also assist 
management in the decision to avoid, share, reduce, or accept risks.  Our work provides 
meaningful assurance, advice, and insight to the Board on key risks so they can make informed 
decisions.  We apply professional judgement and experience to prioritize high-risk areas and 
maximize limited resources using internal staff and external specialists (subject-matter 
experts).

Maricopa County Internal Audit 
 
Risk Assessment Report (June 2023) 
Page 6 
FISCAL YEAR 2024 AUDIT PLAN 
 
Agency Engagements 
Correctional Health Services – Medication Administration 
MCDOT Information Technology Center – Service Delivery 
Public Health – Risk Assessment 
Sheriff’s Office – Detention Use of Force 
Sheriff’s Office – Purchase Cards and Mobile Device Management 
Countywide Engagements 
Control Environment – Maturity Assessment  
Policy Change Compliance: 
• Fee Level Reviews 
• Mobile Devices 
• Non-Capital Assets 
• Purchase Cards 
• TikTok Ban 
Revenue Contracts 
Single Audit Reporting Compliance – Grant Subrecipients 
Travel & Mileage Reimbursements 
Other Services Upon Request 
Continuous Monitoring 
Capital Improvement Projects 
Mobile Device Management 
Purchase Cards 
Other Areas as Determined 
Accounting Reviews 
Clerk of Superior Court 
9 Justice Courts  
Other Reports 
Audit Plan Report 
Audit Recommendations Outstanding More than One Year 
County ERM Goal Support 
Fraud Hotline Deployment 
Internal Audit Department Performance Report