ANNUAL AUDIT PLANNING FOR FY25 REPORT.PDF
Extracted text (via pymupdf)
7747 characters
Internal Audit’s Annual Planning Process The Maricopa County Internal Audit Department strives to provide independent, objective assurance and consulting services designed to add value and improve the County’s operations. We help the County accomplish its objectives by bringing a systematic, disciplined approach to evaluate and improve the effectiveness of governance, risk management, and control processes. Internal Audit establishes, in accordance with global audit standards, a risk-based audit plan annually to determine the priorities of audit work. This report describes the process we take when evaluating risks and developing an audit plan. Audit Work is Prioritized Based on Risk 2 Annual Audit Planning 3 Fiscal Year 2025 Audit Plan 5 ANNUAL PLANNING FOR FY 2025 Internal Audit Department June 2024 Review the County Strategic Direction Meet with County Management Interview Key Support Departments Meet with Select Department Management Review Areas of Risk Identified Prepare Annual Audit Plan Board Approves the Audit Plan Google Images iStock (Eric Mischke) Maricopa County Internal Audit Annual Planning for FY2025 (June 2024) Page 2 AUDIT WORK IS PRIORITIZED BASED ON RISK Internal Audit defines risk as the possibility of an event occurring that will have an adverse impact on the achievement of County objectives. County management is responsible for establishing risk management and control processes, while Internal Audit evaluates its effectiveness and makes recommendations. The Board of Supervisors (Board) and County leadership establish the direction of County operations through the development of a four-year strategic plan as a road map for the future. Through the development of strategic goals and performance measures, County leaders and managers are entrusted to execute the plan. Risks that threaten the strategic plan can be difficult to manage due to Maricopa County’s diverse physical, financial, and operational environment. Internal Audit relies on a continuous risk assessment process to improve our responsiveness to the ever-changing County environment. The annual planning process starts with understanding the Board’s established strategic direction, obstacles that may impede that direction, and areas deferred during the prior year’s planning process. Additional information is obtained through discussions with those having key roles throughout the County. Roles for Successful Governance, Risk Management, and Control Processes Effective governance, risk management, and control processes require collaboration by several roles to implement strategies, achieve objectives, and manage risks. An Enterprise-wide Effort is Essential Management Front line and upper-level management that own and manage strategies, objectives, risks, and controls. Internal Support Monitors and contributes to achievement of the objectives. Internal Audit Evaluates the effectiveness of County efforts. Maricopa County Internal Audit Annual Planning for FY2025 (June 2024) Page 3 Management is responsible for developing strategies and objectives to achieve the overall mission and vision. Success requires the implementation of effective governance, risk management, and internal controls. To assist in developing the annual audit plan, we met with the Board, County leadership, and departmental leadership to gain a better understanding of their processes. Internal support such as finance, budget, risk management, procurement, information technology, continuous improvement, and human resources play an important role. As a second line of defense, these functions provide support to management and help them achieve their strategies and objectives. We met with each internal support department to learn their impressions of management’s governance, risk management, and control processes. Internal Audit provides independent and objective assurance on the adequacy and effectiveness of the County’s governance, risk management, and control processes. We also serve as a resource to managers and supervisors in identifying areas for improvement. We reviewed process level risks for many areas throughout the year to identify potential audits. We then applied the risk-related insights and knowledge we gain to the annual audit planning process. In addition to the roles discussed above, the County is subject to external reviews and audits from various regulators and independent parties. These parties can provide external insights into risk evaluation and improvement opportunities. We considered these external reviews and audits when developing our annual audit plan. ANNUAL AUDIT PLANNING In addition to the feedback described above, we considered several other factors when evaluating risks and developing the annual audit plan: Public Impact Emerging Trends Financial Impact Executive Leadership Input & Expectation Technology Risk Reputation Risk Auditor Judgment Audit Resources Factors that Influence the Annual Audit Plan Maricopa County Internal Audit Annual Planning for FY2025 (June 2024) Page 4 Audit Resources Influence the Audit Plan The Board establishes our staffing level, balancing risk and audit coverage with budgetary requirements. A well-staffed internal audit function that regularly audits high-risk areas can identify waste and non-compliance. It can also assist management in the decision to avoid, share, reduce, or accept risks. Our work provides meaningful assurance, advice, and insight to the Board on key risks so they can make informed decisions. We apply professional judgment and experience to prioritize high-risk areas and maximize limited resources using internal staff and external specialists (subject-matter experts). Finalizing the Audit Plan Once risks were evaluated, we developed a draft audit plan for the upcoming year by: • Considering requirements for audits on a defined schedule and for mandated audits. • Analyzing audit competency requirements and resources available to complete the work. • Discussing the draft audit plan with County leadership. After the draft audit plan has been prepared and reviewed, we seek formal approval for the audit plan from the Board prior to the start of the new fiscal year. The fiscal year 2025 Board- approved audit plan is on page five. Maricopa County Internal Audit Annual Planning for FY2025 (June 2024) Page 5 FISCAL YEAR 2025 AUDIT PLAN Agency Engagements Animal Care & Control – New Hope & Volunteer Programs County Attorney – Risk Assessment Human Resources – Workday Internal Controls Human Services – Risk Assessment Office of Budget and Finance – Central Service Cost Allocation Office of Enterprise Technology – Device Refresh Program Sheriff’s Office – Investigations Case Management Sheriff’s Office – Off-Duty Employment Countywide Engagements Accounts Payable – Department Level Controls Artificial Intelligence Governance Control Environment – Maturity Assessment (Carryover) Information Technology – Incident Response Management Information Technology – Risk Assessment Refresh Single Audit Reporting Compliance – Grant Subrecipients Other Requested Engagements Continuous Monitoring Capital Improvement Projects Mobile Device Management Purchase Cards Other Areas as Determined Accounting Reviews Adult Probation Department 9 Justice and 1 Municipal Courts Other Reports Audit Plan Report Audit Recommendations Outstanding More than One Year Internal Audit Department Performance Report