ANNUAL AUDIT PLANNING FOR FY26 REPORT.PDF

Maricopa County — Formal (2025-06-11)

View PDF Item 106 Meeting page

Extracted text (via pymupdf) 7696 characters
Internal Audit’s Annual Planning Process 
The Maricopa County Internal Audit Department 
strives to provide independent, objective 
assurance and advisory services designed to 
add value and improve the County’s operations.   
We help strengthen the County’s ability to create, 
protect, and sustain value by providing the Board 
of Supervisors and County Management with 
independent, risk-based, and objective 
assurance, advice, insight, and foresight.   
Internal Audit establishes, in accordance with 
global audit standards, a risk-based audit plan 
annually to determine the priorities of audit work. 
This report describes the process we take when 
evaluating risks and developing an audit plan.   
 
Audit Work is Prioritized 
Based on Risk 
2 
Annual Audit Planning 
3 
Fiscal Year 2026 Audit 
Plan 
5 
 
ANNUAL PLANNING FOR FY 2026 
Internal Audit Department 
June 2025 
 
Google Images iStock (Eric Mischke) 
Review the County Strategic Direction
Interview Key Support Departments
Meet with County Management
Meet with Select Department Management
Review Areas of Identified Risk
Prepare Annual Audit Plan
Board Approves the Audit Plan

Maricopa County Internal Audit 
 
Annual Planning for FY 2026 (June 2025) 
Page 2 
AUDIT WORK IS PRIORITIZED BASED ON RISK 
 
Internal Audit defines risk as the possibility of an event occurring that will have an uncertain 
impact on the achievement of County objectives.  County management is responsible for 
establishing risk management and control processes, while Internal Audit evaluates their 
effectiveness and makes recommendations.   
 
The Board of Supervisors (Board) and County leadership establish the direction of County 
operations through the development of a multi-year strategic plan as a road map for the future.  
County leaders and managers are entrusted to execute the plan through the development of 
strategic goals and performance measures.  Risks that threaten the strategic plan can be 
difficult to manage due to Maricopa County’s diverse physical, financial, and operational 
environment. 
 
Internal Audit relies on a continuous risk assessment process to improve our responsiveness to 
the ever-changing County environment.  The annual planning process starts with understanding 
the Board’s established strategic direction, obstacles that may impede progress, and areas 
deferred during the prior year’s planning process.  Additional information is obtained through 
discussions with those having key roles throughout the County.      
   
Roles for Successful Governance, Risk Management, and Control Processes 
Effective governance, risk management, and control processes require collaboration by several 
roles to implement strategies, achieve objectives, and manage risks.  
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
An Enterprise-wide Effort is Essential 
Management
Front line and upper-level management that own and
manage strategies, objectives, risks, and controls.
Internal Support
Monitors and contributes to 
achievement of the objectives.
Internal Audit
Evaluates the 
effectiveness of 
County 
efforts.

Maricopa County Internal Audit 
 
Annual Planning for FY 2026 (June 2025) 
Page 3 
 
Management is responsible for developing strategies and objectives to achieve the overall 
mission and vision.  Success requires the implementation of effective governance, risk 
management, and internal controls.  To assist in developing the annual audit plan, we met with 
the Board, County leadership, and departmental leadership to gain a better understanding of 
their processes. 
 
Internal support such as finance, budget, risk management, procurement, information 
technology, continuous improvement, and human resources play important roles.  As a 
second line of defense, these functions support management and help them in achieving 
their strategies and objectives.  We met with each internal support department to learn their 
impressions of management’s governance, risk management, and control processes. 
 
Internal Audit provides independent and objective assurance on the adequacy and 
effectiveness of the County’s governance, risk management, and control processes.  We also 
serve as a resource to managers and supervisors in identifying areas for improvement.  We 
reviewed process level risks for many areas throughout the year to identify potential audits.  We 
then applied the risk-related insights and knowledge we gain to the annual audit planning 
process. 
 
In addition to the roles discussed above, the County is subject to external reviews and audits 
from various regulators and independent parties.  These parties can provide external insights 
into risk evaluation and improvement opportunities.  We considered these external reviews and 
audits when developing our annual audit plan. 
 
 
ANNUAL AUDIT PLANNING 
 
In addition to the feedback described above, we considered several other factors when 
evaluating risks and developing the annual audit plan: 
 
   
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
Public 
Impact 
Emerging 
Trends
Financial 
Impact
Executive 
Leadership Input 
& Expectation
Technology 
Risk
Reputation 
Risk
Auditor 
Judgment
Audit 
Resources
Factors that Influence the Annual Audit Plan

Maricopa County Internal Audit 
 
Annual Planning for FY 2026 (June 2025) 
Page 4 
Audit Resources Influence the Audit Plan 
The Board establishes our staffing level, balancing risk and audit coverage with budgetary 
requirements.  A well-staffed internal audit function that regularly audits high-risk areas can 
identify waste and non-compliance.  It can also assist management in the decision to avoid, 
share, reduce, or accept risks.  Our work provides meaningful assurance, advice, and insight to 
the Board on key risks so they can make informed decisions.  We apply professional judgment 
and experience to prioritize high-risk areas and maximize limited resources using internal staff 
and external specialists (subject-matter experts). 
 
Finalizing the Audit Plan 
 
Once risks were evaluated, we developed a draft audit plan for the upcoming year by: 
• Considering requirements for audits on a defined schedule and for mandated audits. 
• Analyzing audit competency requirements and resources available to complete the work. 
• Discussing the draft audit plan with County leadership. 
 
After the draft audit plan has been prepared and reviewed, we seek formal approval for the 
audit plan from the Board prior to the start of the new fiscal year.  The fiscal year 2026 Board-
approved audit plan is on page five.

Maricopa County Internal Audit 
 
Annual Planning for FY 2026 (June 2025) 
Page 5 
FISCAL YEAR 2026 AUDIT PLAN 
 
Agency Engagements 
Air Quality – Compliance & Enforcement 
Correctional Health Services – Information Technology General Controls 
Enterprise Technology and Innovation – IT Applications Security Reviews 
Facilities Management – Contract Review 
Library District – Operations 
Public Fiduciary – Caseload Management 
Sheriff’s Office – Radio Inventory Management 
Sheriff’s Office and Correctional Health Services – Intake Process 
Treasurer’s Office – Financial Services 
 
Countywide Engagements 
Information Technology – Data Management and Classification 
Information Technology – User Access Management 
Single Audit Reporting Compliance – Grant Subrecipients 
Other Requested Engagements 
 
Continuous Monitoring 
Capital Improvement Projects 
Mobile Device Management 
Purchase Cards 
Other Areas as Determined 
 
Accounting Reviews 
Juvenile Probation Department 
9 Justice Courts 
 
Other Reports 
Audit Plan Report 
Audit Recommendations Outstanding More than One Year 
Internal Audit Department Performance Report