Muyni
← Back to Athens-Clarke County

Audit Committee

Regular Meeting

Athens-Clarke County, GA · August 14, 2019

AgendaMinutes

Minutes

AUDIT COMMITTEE MEETING MINUTES Wednesday, August 14, 2019 Committee Members Present: Visiting: Commissioner Melissa Link, Committee Chair Deborah Lonon, Assistant Manager Commissioner Patrick Davenport Josh Edwards, Assistant Manager Commissioner Ovita Thornton Glenn Coleman, Assistant Director, Public Utilities Committee Members Absent: David Fluck, Director, Central Services Commissioner Allison Wright Michael Smith, Community Citizen Commissioner Russell Edwards Lee Shearer, Athens Banner Herald Nancy Hamby, Community Citizen Staff: Tommy Hamby, Community Citizen Stephanie Maddox, Internal Auditor Deborah Allen, Recorder Committee Chair Link called the meeting to order at 6:04 pm. A. Approval of Minutes: The Committee unanimously approved the Minutes of the June 12, 2019 meeting. B. 2018 Work Plan Update: Internal Auditor Maddox provided a brief status update on the annual work plan:  Public Utilities Department – Water Business Office  Central Services Department – Fleet Management Program  Sheriff’s Office The Committee agreed to make a formal request for the Internal Auditor to present the results of the Sheriff’s Office audit report at the next available work session. C. General Discussion: Upon request, staff developed a PowerPoint presentation of a new audit selection tool. The Committee expressed interest in continuing the audit selection discussion at the next meeting. D. Items for Discussion at September 11, 2019 meeting: Internal Auditor Maddox will conduct a live simulation of the audit selection tool at the September meeting. The next meeting is scheduled on Wednesday, September 11 from 6:00 – 7:30 p.m.; City Hall; Room 301. The meeting adjourned at 6:54 p.m. The above summation is an interpretation of the items discussed and decisions reached at the above-referenced meeting, not a transcript of the meeting. A digital recording of the meeting is available upon request. Page 1 of 1

Agenda

AGENDA Audit Committee Wednesday, August 14, 2019 6:00 pm – 7:00 pm City Hall, Room 103 A. Review and approval of the Wednesday, June 12, 2019 Meeting Minutes B. 2018 Work Plan Update  Sheriff’s Office – Inmate medical services  Public Utilities Department — Water Business Office  Central Services Department — Fleet Management Program C. Development of the Annual Audit Work Plan –  Alternative Approach to Audit Selection - Risk Assessments D. Items for Discussion at next meeting Attachments: 1. Draft Minutes from the June 12 meeting 2. Meeting Agenda – August 14, 2019 3. Status of Work Plan Activity 4. Risk Assessment Presentation The next meeting is scheduled for Wednesday, September 11, 2019 Note: The Audit Committee Meeting is open to the public. However, public comments are not received unless the Committee Chair requests that an individual provide information to the Committee. O FFI CE O F O P ER A TI O N AL A N AL YSI S T H E U N I F I E D G O V E R N M E N T O F A T H E NS -C L A R K E C O U N T Y , G E O R G I A 300 College Avenue, Suite 202 • Athens, Georgia 30601 • (706) 613-3012 www. at h en sc lar k e c o unt y. c o m / 2 3 6 / O per at i on al - An al ys is - Of f i ce AUDIT STATUS REPORT DATE: August 12, 2019 TO: Mayor and Commission FROM: Stephanie Maddox, Internal Auditor Office of Operational Analysis (formerly, the Auditor’s Office) SUBJECT: Status of 2018 Work Plan Activity The following table summarizes the current status of each audit according to audit stages. Please find a description of the audit stages below. WORK IN PROGRESS Status Completion Audit Percentage indicates completion level Forecast Operational Audit of the Pre-Audit Planning – 100 % Final report submitted to March 2019 Clarke County Sheriff’s Discovery Stage – 100% Clerk of Commission for Office Analysis – 100 % acceptance at the August 2, Conclusions – 100% 2019, Mayor and Recommendations – 100% Commission Meeting. NOTE: Audit report completed March 2019; final responses from the Sheriff’s Office received May 2019 Public Utilities Department – Pre-Audit Planning – 100 % Additional follow-up August 2019 Water Business Office Discovery Stage – 100% interviews completed with Analysis – 100% WBO supervisory staff; Conclusions – 95% audit report writing near Recommendations – 95% completion. Central Services Department – Pre-Audit Planning – 100% Audit plan finalized; survey October 2019 Fleet Management Program Discovery Stage – 55% results received; review and Analysis – 25% analysis underway; Conclusions – 0% interviews anticipated to Recommendations – 0% start August 2019. Audit Stages PRE-AUDIT PLANNING: OOA staff conducts literature reviews, identifies benchmark communities, creates the pre-audit survey(s), and prepares a list of documents to request from various ACC departments related to the audit client. OOA staff schedules a pre-conference meeting with the audit client/department leadership to discuss the audit process, the timing of fieldwork, and answer any questions. DISCOVERY: Interviews, information validation, observations and surveys. As this stage is critical to the preparation of a complete and meaningful audit, it consumes the majority of time involved. ANALYSIS: Assigning meaning/value to the information; determining what it reveals related to the scope of the audit. Defines systems, processes and practices in terms of effectiveness and efficiency. CONCLUSIONS: Identifies and describes constraints and opportunities regarding developments and implementation of needed improvements. RECOMMENDATIONS: Suggests action that can be taken in consideration of the constraints and opportunities. Risk Assessment U N I F I ED G OVE R NMEN T O F AT HE N S -CLA RK E CO U N T Y O F F I CE O F O P E R AT I O NA L A N A LY S IS AU G U ST 2 0 1 9 Auditing Responsibility According to the Institute of Internal Auditors (IIA) International Standards for the Professional Practice of Internal Auditing, Section 2120.A.1 – The internal audit activity must evaluate risk exposures relating to the organization’s governance, operations, and information systems regarding the: • Achievement of the organization’s strategic objectives. • Reliability and integrity of financial and operational information. • Effectiveness and efficiency of operations and programs. • Safeguarding of assets. • Compliance with laws, regulations, policies, procedures, and contracts. What is a Risk Assessment? Risk assessment, as defined by the IIA, is a systematic process for assessing and integrating professional judgments about probable adverse conditions and/or events. An Internal Audit Risk Assessment is the identification, measurement, and prioritization of risks for the purpose of selecting and developing auditable areas. Definitions: Risk The possibility of an event occurring that will have an impact on the achievement of objectives and is measured in terms of impact (severity) and likelihood (probability). Risk Management A process to identify, assess, manage, and control potential events or situations to provide reasonable assurance regarding the achievement of the organization’s objectives. Risk Appetite The level of risk that an organization is willing to accept. Office of Operational Analysis (OOA) Risk Assessment vs. Safety & Risk Management OOA Risk Assessment • Focus: Assessing a departments level of operational risk to determine audit necessity. • The purpose of a risk assessment conducted by OOA is to identify and assess a departments operational risks. Based on the results of an assessment, Audit Committee members may make an objective decision as to which audits should be conducted by OOA. Safety & Risk Management • Focus: Employee and property safety • The Safety & Risk Division of HR manages insurance, injury, and illness claims against and generated by ACC for damage to persons and ACC property, provides safety training (e.g. trench safety, CRASE, DDC, CPR/AED/First Aid, etc.), conducts safety audits of ACC facilities, and handles workers compensation claims. Step 1: Identify Risks What is included in a Risk Assessment? • A questionnaire is developed to compile information on the potential departments to be audited (auditable units) and to address all risk factors. • The following information may be requested from the departments in the questionnaire: • Description of the departments activities and functions. • Business objectives, risks, and exposures. • Systems utilized. • Lists of major vendors and estimated annual payments. • Total expenditures for a designated period of time. • Budgets for a designated period of time. • Number of authorized employees. • Number of vacant positions and length of time the position(s) have been vacant. • Questions to address specific risk factors listed by OOA. • Additional risks identified by the auditable unit. Risk Factors Risk factors are developed using knowledge of the Athens-Clarke County Unified Government and best practices in internal auditing. Each risk factor is scored based on the impact and likelihood of the risk occurring to the department being audited. • Likelihood – The measure of the probability of an unfavorable event occurring. • Impact – The measure of the consequence of an unfavorable event occurring. Risk Categories The impact of each risk factor is based on three categories: financial, operational, and/or compliance, and the impact each will have on ACC. The overall goal of the risk scoring approach is to ensure that OOA includes high-risk areas in the audit plan and considers routine audits on those areas. The three risk categories are defined as follows: • Financial Risk – Impact related to revenues, expenditures, assets, liabilities, and equity decisions. • Operational Risk – Risk is exposed if operating objectives are not being met through the effective and efficient use of resources. This includes potential for fraud, business disruptions, customer service, and safety. • Compliance Risk – Risk is exposed if operating (or potentially operating) outside of applicable laws and regulations. Step 2: Measure Risks Risk Assessment Criteria • The primary purpose of a risk assessment is to identify risks, assess them, and reduce them to an acceptable level. • Before operational risks can be assessed, the risk criteria and risk factors from which to measure and score must be established and defined. • To achieve this, a measurement system that includes a baseline (an organization’s acceptable risk level) and a method of scoring (a risk scoring system) must be established. • The criteria are derived from the organization’s culture and industry, external and internal context or controls, applicable laws, standards and other requirements. Sample Risk Factors Categorized Risk Categories: O – Operational Risk Impact; F – Financial Risk Impact; C – Compliance Risk Impact Risk Risk Factors Weight Description Category Compliance with Impact of compliance risk increases with more reliance on Regulations, Laws, O, F, C federal and/or state laws, regulations, and funding, and Policies, and SOPs prior issues. Risk of asset misappropriation, depreciation of obsolete Inventory F items, or nonexistent items recorded as inventory. Impact and likelihood or risk increases with more cash Handling of Cash O, F collection and less resources to monitor. Departmental A dynamic change in employees increases the probability O, F of inefficiencies as well as errors occurring. Changes Quality of Internal Reliability of internal control system is important in O, F, C detecting and preventing operational and systemic errors. Control System Sample Risk Factors • Compliance with Regulations, • Inventory Laws, Policies and SOPs • Handling of Cash • Objectives/Projects • Instances of Fraud, Waste, & • Service User Experience Abuse • Business Continuity • Complexity of Transactions • Publicity/Reputation • Departmental Changes • Injury • Information Technology Changes • Audit History, Prior Audit Results • Quality of Internal Control System Step 3: Prioritize Risks Risk Identification Some categories in which to identify risk: • People, processes, systems, and • Fraud. events. • Internal fraud • Employment practices and workplace safety. • External fraud • Turnover rates • False expense claims • Vacancy rates (position vacancies and time vacant) • Compliance with laws, regulations, • Tenure of the department/division contracts, policies, and procedures. and senior management • External/criminal threats • Staff size in relation to activity volumes • Reliance on key staff and management succession Risk Identification (continued) • Effectiveness and efficiency of • Reliability and integrity of financial and operations. operational systems and information. • Organizational changes • Misuse of systems • Misuse of confidential information • Complexity • Access control and security • Activity volumes • Volume, severity, and duration of • New or changing product or process system outages • Customer satisfaction • Volume, severity, and type of security incidents • Degree and complexity of projects • System response time • Processing, storage, and data • Mainframe and network availability communication Understanding the Operational Area of an Audit People Processes Systems • What is the department’s position • Workflow processes • Major systems and within the organization? components (hardware and software) • What is the department’s • Dependencies and interfaces organizational structure? with other departments and/or • System interfaces external service providers (internal and external) • Are there clear, direct, and sufficiently high reporting lines? • Outsourcing vendors • Transaction volumes and dollar • What data, reports, or amounts • Security responsibilities flow across departments? • Risk and control assessments • Are departmental activities and • Procedures management’s roles clearly defined? • Monitoring of reports • What is the experience level and expertise of management and key staff? Sample Scoring – Risk Factors Likelihood (probability) and Consequences (severity) Risk Factor Negligible Minor Moderate Major Catastrophic Rating Likelihood Description 5 Frequent Represents a risk with a 90% or greater chance of Compliance Minor non- Singular failure to Repeated failure Repeated failure to Gross failure to occurrence and will significantly impact the achievement with compliance with meet internal to meet internal meet external meet external of departmental goals and objectives. Regulations, internal policies or SOPs. standards or standards. Failure standards. Laws, Policies standards. Small Minor follow protocols. to meet local, Repeated failure to and SOPs number of minor recommendation Important State, and/or meet local, State, issues requiring s which can be recommendation Federal and/or Federal 4 Probable Given the current work environment, there is a 65% up to improvement. easily addressed s that can be regulations. regulations. 90% chance of risk occurring with a possibility of repeated by management. addressed with Critical report or Severely critical incidents. an appropriate substantial number report with management of significant possible major 3 Occasional Represents an area or problem that has a 35% up to 65% action plan. findings and/or reputational or chance of occurring and may prevent achieving lack of adherence financial departmental goals and objectives. to regulations. implications. 2 Remote Represents an area that has a 10% to 35% chance of occurrence with little impact on achieving the Objectives/ Barely noticeable Minor reduction Reduction in Significant project Inability to meet department’s goals and objectives. Projects reduction in in scope, quality scope or quality over-run. project objectives. scope, quality or or schedule. of project; Reputation of the 1 Improbable Represents an area with less than a 10% chance of schedule. project objectives organization occurrence and has little to no impact on achieving goals or schedule. seriously damaged. and objectives. Risk Values (likelihood x severity) Level of Severity Likelihood of Risk Negligible Minor Moderate Major Catastrophic (1) (2) (3) (4) (5) Frequent (5) 5 10 15 20 25 Probable (4) 4 8 12 16 20 Occasional (3) 3 6 9 12 15 Remote (2) 2 4 6 8 10 Improbable (1) 1 2 3 4 5 Step 4: Select and Develop Audits Audit Selection • Questionnaires are developed to compile information and to identify if any departmental risks exist and if so, to what level. • Using established risk factors and criteria, levels of risk indicated through the questionnaires are measured. • Audit Committee prioritizes risks identified and the level of severity. • Audit Committee selects audits to be conducted by OOA. Risk Assessment Process Overview Step 2 Step 4 • Identify • Prioritize Risks • Measure Risks • Select and Risks Develop Audits Step 1 Step 3 Key Points • A risk-based audit planning approach adds value to an internal audit. • Risk identification is the most important step in the process. Questions?

Get email alerts for Athens-Clarke County

A daily email when new agendas and minutes are posted.

Report an issue with this meeting