ANNUAL AUDIT PLANNING FOR FY27 REPORT.PDF
Extracted text (via pymupdf)
7595 characters
Internal Audit’s Annual Planning Process The Maricopa County Internal Audit Department strives to provide independent, objective assurance and advisory services designed to add value and improve the County’s operations. We help strengthen the County’s ability to create, protect, and sustain value by providing the Board of Supervisors and County Management with independent, risk-based, and objective assurance, advice, insight, and foresight. Internal Audit establishes, in accordance with global audit standards, a risk-based audit plan annually to determine the priorities of audit work. This report describes the process we take when evaluating risks and developing an audit plan. Audit Work is Prioritized Based on Risk 2 Annual Audit Planning 3 Fiscal Year 2027 Audit Plan 5 ANNUAL PLANNING FOR FY 2027 Internal Audit Department June 2026 Google Images iStock (Eric Mischke) Review the County Strategic Direction Interview Key Support Departments Meet with County Management Meet with Select Department Management Review Areas of Identified Risk Prepare Annual Audit Plan Board Approves the Audit Plan Maricopa County Internal Audit Annual Planning for FY 2027 (June 2026) Page 2 AUDIT WORK IS PRIORITIZED BASED ON RISK Internal Audit defines risk as the possibility of an event occurring that will have an uncertain impact on the achievement of County objectives. County management is responsible for establishing risk management and control processes, while Internal Audit evaluates their effectiveness and makes recommendations. The Board of Supervisors (Board) and County leadership establish the direction of County operations through the development of a multi-year strategic plan as a roadmap for the future. County leaders and managers are entrusted to execute the plan through the development of strategic goals and performance measures. Risks that threaten the strategic plan can be difficult to manage due to Maricopa County’s diverse physical, financial, and operational environment. Internal Audit relies on a continuous risk assessment process to improve our responsiveness to the ever-changing County environment. The annual planning process starts with understanding the Board’s established strategic direction, obstacles that may impede progress, and areas deferred during the prior year’s planning process. Additional information is obtained through discussions with those who have key roles throughout the County. Roles for Successful Governance, Risk Management, and Control Processes Effective governance, risk management, and control processes require collaboration by several roles to implement strategies, achieve objectives, and manage risks. An Enterprise-wide Effort is Essential Management Front line and upper-level management that own and manage strategies, objectives, risks, and controls. Internal Support Monitors and contributes to achievement of the objectives. Internal Audit Evaluates the effectiveness of County efforts. Maricopa County Internal Audit Annual Planning for FY 2027 (June 2026) Page 3 Management is responsible for developing strategies and objectives to achieve the overall mission and vision. Success requires the implementation of effective governance, risk management, and internal controls. To assist in developing the annual audit plan, we met with the Board, County leadership, and departmental leadership to gain a better understanding of their processes. Internal support such as finance, budget, risk management, procurement, information technology, continuous improvement, and human resources play important roles. As a second line of defense, these functions support management and help them in achieving their strategies and objectives. We met with internal support departments to learn their impressions of management’s governance, risk management, and control processes. Internal Audit provides independent and objective assurance on the adequacy and effectiveness of the County’s governance, risk management, and control processes. We also serve as a resource to managers and supervisors in identifying areas for improvement. We reviewed process level risks for many areas throughout the year to identify potential audits. We then applied the risk-related insights and knowledge we gained to the annual audit planning process. In addition to the roles discussed above, the County is subject to external reviews and audits from various regulators and independent parties. These parties can provide external insights into risk evaluation and improvement opportunities. We considered these external reviews and audits when developing our annual audit plan. ANNUAL AUDIT PLANNING In addition to the feedback described above, we considered several other factors when evaluating risks and developing the annual audit plan: Public Impact Emerging Trends Financial Impact Executive Leadership Input & Expectation Technology Risk Reputation Risk Auditor Judgment Audit Resources Factors that Influence the Annual Audit Plan Maricopa County Internal Audit Annual Planning for FY 2027 (June 2026) Page 4 Audit Resources Influence the Audit Plan The Board establishes our staffing level, balancing risk and audit coverage with budgetary requirements. A well-staffed internal audit function that regularly audits high-risk areas can identify waste and non-compliance. It can also assist management in the decision to avoid, share, reduce, or accept risks. Our work provides meaningful assurance, advice, and insight to the Board on key risks so they can make informed decisions. We apply professional judgment and experience to prioritize high-risk areas and maximize limited resources using internal staff and external specialists (subject-matter experts). Finalizing the Audit Plan Once risks were evaluated, we developed a draft audit plan for the upcoming year by: • Considering requirements for audits on a defined schedule and for mandated audits. • Analyzing audit competency requirements and resources available to complete the work. • Discussing the draft audit plan with County leadership. After the draft audit plan has been prepared and reviewed, we seek formal approval for the audit plan from the Board prior to the start of the new fiscal year. The fiscal year 2027 Board- approved audit plan is on page five. Maricopa County Internal Audit Annual Planning for FY 2027 (June 2026) Page 5 FISCAL YEAR 2027 AUDIT PLAN Agency Engagements Correctional Health Services - Information Technology General Controls (Carryover) Enterprise Technology and Innovation – Identity & Access Management Environmental Services & Planning and Development – Permit Center Public Fiduciary – Ward Assets Management Sheriff’s Office – Administration Division Treasurer’s Office – Investment Portfolio Countywide Engagements Artificial Intelligence Security Review Cash Handling Contracts and Intergovernmental Agreements Vehicle Usage Single Audit Reporting Compliance – Grant Subrecipients Other Requested Engagements Continuous Monitoring Capital Improvement Projects Mobile Device Management Purchase Cards Other Areas as Determined Accounting Reviews Clerk of the Superior Court 8 Justice Courts Other Reports Audit Plan Report Audit Recommendations Outstanding More than One Year Internal Audit Department Performance Report