ANNUAL RISK ASSESSMENT REPORT.PDF
Extracted text (via pymupdf)
8319 characters
RISK ASSESSMENT REPORT
Internal Audit Department
June 2022
Internal Audit Analyzes County
Risks to Prioritize Audit Work
Internal Audit defines risk as the possibility of an
event occurring that will have an adverse impact
on the achievement of the County’s objectives.
County management is responsible for managing
risks by implementing strong business processes
and internal controls. Internal Audit aids in the
assessment of risks by analyzing the operating
environment and identifying conditions that may
impair the County’s ability to achieve its goals.
Internal Audit performs audits to provide
reasonable assurance that the controls designed
to address risks are operating effectively.
This report describes the County’s risk environment and demonstrates how Internal Audit prioritizes
audit areas and develops an annual audit plan for approval by the County Board of Supervisors (Board).
The Board, as the County’s governing body, provides resources to implement and manage internal
controls that provide assurance that the Board’s strategic objectives will be met.
Risk Management is
Everyone’s Responsibility
2
Risks Influence the Audit
Plan
3
Audit Resources Influence
the Audit Plan
5
Fiscal Year 2023 Audit Plan
6
Graphic by macrovector – freepik.com
2
RISK MANAGEMENT IS EVERYONE’S RESPONSIBILITY
The Board and County leadership establish the direction of County operations through the
development of a four-year strategic plan as a road map for the future. Through the development of
strategic goals and performance measures, County leaders and managers are entrusted to execute the
plan. Risks that threaten the strategic plan can be difficult to manage due to Maricopa County’s
diverse physical, financial, and operational environment.
Roles of Risk Management
Effective risk management requires collaboration by several roles to identify, assess, and respond to
risk.
Management is responsible for identifying, assessing, controlling, and monitoring risk on a day-to-
day basis. Without management support, employees may not be effective in controlling the risk they
encounter. In a perfect world, this would be the only role needed; however, in the real world, internal
controls do not operate perfectly.
Oversight functions such as finance, budget, risk management, procurement, information technology,
and human resources play an important role in managing risk. They are the advisors who monitor
countywide risk management practices. Some County agencies also have internal functions that serve
this purpose. These activities range from quality control reporting to inspecting and reconciling
County records.
Managing Risk is an Enterprise-wide Responsibility
Management
Front line operating management that owns and
manages risks and controls
Includes: Department Management
Oversight
Advisors that monitor and support
risk-related matters.
Includes: Finance, Risk Management,
Procurement, Information Technology, etc.
Internal Audit
Evaluates the
effectiveness
of County risk
management
processes
3
Code of Conduct & Other
County Policies
Outlines appropriate and
ethical behavior
Addresses current issues
through regular updates
Training & Employee
Orientation
Reinforces high expectations
for ethical behavior
Internal Audit
Evaluates County operations
and issues recommendations
that may deter fraud
Provides tools and resources
to County leadership
Internal Audit provides independent and objective assurance on the adequacy and effectiveness of
governance, risk management, and internal controls, including the manner in which the other roles
achieve risk management and control objectives. Internal Audit reviews a small number of County
operations each year to ensure that management is identifying, assessing, controlling, and monitoring
risks. Internal Audit also serves as a resource to managers and supervisors in identifying areas for
improvement.
In addition to the roles discussed above, the County is subject to external reviews and audits from
various regulators and independent parties. These parties can provide external insights into risk
evaluation and improvement opportunities.
Ethics and Fraud
Risk management is further reinforced by fraud prevention efforts. Fraud is an act of intentional
deception to secure unfair or unlawful gain at the expense of an organization or individual. While
fraud risk cannot be eliminated, it can be mitigated through a strong ethical framework, effective
controls, and education. Awareness is fundamental to fraud mitigation, and is enhanced through
effective use of the following tools:
RISKS INFLUENCE THE AUDIT PLAN
Internal Audit uses a risk-based approach to prioritize work and develop an annual audit plan, as
required by professional audit standards.
Continuous Risk Assessment and Agile Auditing
Internal Audit continues to adapt our continuous risk assessment and agile audit practices to improve
our responsiveness to the ever-changing County environment. In addition to preparing an annual audit
plan, we also review process level risks for many areas throughout the year to identify potential audits.
Agile audits target key risks and limit reporting to specific areas which may result in shorter and more
frequent engagements.
4
Internal Audit considers several factors when evaluating risks and developing an annual audit plan.
Finalizing the Audit Plan
Once risk levels are evaluated, we develop a draft audit plan for the upcoming year by:
• Considering requirements for audits on a defined schedule and for mandated audits.
• Analyzing audit resources and related competencies needed to complete the work and
preliminarily identify engagements that may require specialized expertise.
• Discussing the draft audit plan with the Citizens’ Audit Advisory Committee and County
leadership.
After the draft audit plan has been prepared and reviewed, we seek formal approval for the audit plan
from the Board prior to the start of the new fiscal year. The FY2022 Board-approved audit plan is on
page six.
AUDIT RESOURCES INFLUENCE THE AUDIT PLAN
The Board establishes our staffing level, balancing risk and budgetary requirements. A well-staffed
internal audit function that regularly audits high-risk areas can identify costly activities such as fraud,
waste, and non-compliance, and assist management in the decision to avoid, share, reduce, or accept
risks. Our body of work provides meaningful assurance, advice, and insight to the Board on key risks
so they can make informed decisions. We apply professional judgement and experience to prioritize
high-risk areas and maximize limited resources using internal staff and external specialists (subject-
matter experts).
Factors that Influence the Annual Audit Plan
5
FISCAL YEAR 2023 AUDIT PLAN
Agency Engagements
Air Quality – IT General Controls
Constables
Office of Enterprise Technology – IT Contracts
Public Defense Services – Contracted Attorney Contracts
Facilities Management – Maintenance Contracts
Environmental Services – Food Facility Inspections (Risk Assessment Only)
Emergency Management – Security Services
Planning and Development –Inspections (Risk Assessment Only)
Sheriff’s Office – Enforcement Support (Posse Program)
Sheriff’s Office – Inmate Tablet Program
Countywide Engagements
Construction Contracts – 225 W. Madison St.
Countywide Customer Service
Countywide Vendor Controls
Out-of-State Workers (Risk Assessment Only)
Countywide IT Governance
Single Audit Reporting Compliance – Grant Subrecipients
Other Services Upon Request
Continuous Monitoring
Capital Improvement Projects
Cellular Device Management
P-Cards
Other Areas as Determined
Accounting Reviews
Juvenile Probation
9 Justice Courts
Other Reports
Audit Recommendations Outstanding More than One Year
Citizens Financial Condition Report
Risk Assessment Report
Internal Audit Department Performance Report