ANNUAL AUDIT PLANNING FOR FY26 REPORT.PDF
Extracted text (via pymupdf)
7696 characters
Internal Audit’s Annual Planning Process The Maricopa County Internal Audit Department strives to provide independent, objective assurance and advisory services designed to add value and improve the County’s operations. We help strengthen the County’s ability to create, protect, and sustain value by providing the Board of Supervisors and County Management with independent, risk-based, and objective assurance, advice, insight, and foresight. Internal Audit establishes, in accordance with global audit standards, a risk-based audit plan annually to determine the priorities of audit work. This report describes the process we take when evaluating risks and developing an audit plan. Audit Work is Prioritized Based on Risk 2 Annual Audit Planning 3 Fiscal Year 2026 Audit Plan 5 ANNUAL PLANNING FOR FY 2026 Internal Audit Department June 2025 Google Images iStock (Eric Mischke) Review the County Strategic Direction Interview Key Support Departments Meet with County Management Meet with Select Department Management Review Areas of Identified Risk Prepare Annual Audit Plan Board Approves the Audit Plan Maricopa County Internal Audit Annual Planning for FY 2026 (June 2025) Page 2 AUDIT WORK IS PRIORITIZED BASED ON RISK Internal Audit defines risk as the possibility of an event occurring that will have an uncertain impact on the achievement of County objectives. County management is responsible for establishing risk management and control processes, while Internal Audit evaluates their effectiveness and makes recommendations. The Board of Supervisors (Board) and County leadership establish the direction of County operations through the development of a multi-year strategic plan as a road map for the future. County leaders and managers are entrusted to execute the plan through the development of strategic goals and performance measures. Risks that threaten the strategic plan can be difficult to manage due to Maricopa County’s diverse physical, financial, and operational environment. Internal Audit relies on a continuous risk assessment process to improve our responsiveness to the ever-changing County environment. The annual planning process starts with understanding the Board’s established strategic direction, obstacles that may impede progress, and areas deferred during the prior year’s planning process. Additional information is obtained through discussions with those having key roles throughout the County. Roles for Successful Governance, Risk Management, and Control Processes Effective governance, risk management, and control processes require collaboration by several roles to implement strategies, achieve objectives, and manage risks. An Enterprise-wide Effort is Essential Management Front line and upper-level management that own and manage strategies, objectives, risks, and controls. Internal Support Monitors and contributes to achievement of the objectives. Internal Audit Evaluates the effectiveness of County efforts. Maricopa County Internal Audit Annual Planning for FY 2026 (June 2025) Page 3 Management is responsible for developing strategies and objectives to achieve the overall mission and vision. Success requires the implementation of effective governance, risk management, and internal controls. To assist in developing the annual audit plan, we met with the Board, County leadership, and departmental leadership to gain a better understanding of their processes. Internal support such as finance, budget, risk management, procurement, information technology, continuous improvement, and human resources play important roles. As a second line of defense, these functions support management and help them in achieving their strategies and objectives. We met with each internal support department to learn their impressions of management’s governance, risk management, and control processes. Internal Audit provides independent and objective assurance on the adequacy and effectiveness of the County’s governance, risk management, and control processes. We also serve as a resource to managers and supervisors in identifying areas for improvement. We reviewed process level risks for many areas throughout the year to identify potential audits. We then applied the risk-related insights and knowledge we gain to the annual audit planning process. In addition to the roles discussed above, the County is subject to external reviews and audits from various regulators and independent parties. These parties can provide external insights into risk evaluation and improvement opportunities. We considered these external reviews and audits when developing our annual audit plan. ANNUAL AUDIT PLANNING In addition to the feedback described above, we considered several other factors when evaluating risks and developing the annual audit plan: Public Impact Emerging Trends Financial Impact Executive Leadership Input & Expectation Technology Risk Reputation Risk Auditor Judgment Audit Resources Factors that Influence the Annual Audit Plan Maricopa County Internal Audit Annual Planning for FY 2026 (June 2025) Page 4 Audit Resources Influence the Audit Plan The Board establishes our staffing level, balancing risk and audit coverage with budgetary requirements. A well-staffed internal audit function that regularly audits high-risk areas can identify waste and non-compliance. It can also assist management in the decision to avoid, share, reduce, or accept risks. Our work provides meaningful assurance, advice, and insight to the Board on key risks so they can make informed decisions. We apply professional judgment and experience to prioritize high-risk areas and maximize limited resources using internal staff and external specialists (subject-matter experts). Finalizing the Audit Plan Once risks were evaluated, we developed a draft audit plan for the upcoming year by: • Considering requirements for audits on a defined schedule and for mandated audits. • Analyzing audit competency requirements and resources available to complete the work. • Discussing the draft audit plan with County leadership. After the draft audit plan has been prepared and reviewed, we seek formal approval for the audit plan from the Board prior to the start of the new fiscal year. The fiscal year 2026 Board- approved audit plan is on page five. Maricopa County Internal Audit Annual Planning for FY 2026 (June 2025) Page 5 FISCAL YEAR 2026 AUDIT PLAN Agency Engagements Air Quality – Compliance & Enforcement Correctional Health Services – Information Technology General Controls Enterprise Technology and Innovation – IT Applications Security Reviews Facilities Management – Contract Review Library District – Operations Public Fiduciary – Caseload Management Sheriff’s Office – Radio Inventory Management Sheriff’s Office and Correctional Health Services – Intake Process Treasurer’s Office – Financial Services Countywide Engagements Information Technology – Data Management and Classification Information Technology – User Access Management Single Audit Reporting Compliance – Grant Subrecipients Other Requested Engagements Continuous Monitoring Capital Improvement Projects Mobile Device Management Purchase Cards Other Areas as Determined Accounting Reviews Juvenile Probation Department 9 Justice Courts Other Reports Audit Plan Report Audit Recommendations Outstanding More than One Year Internal Audit Department Performance Report