Audit Committee
Regular MeetingAthens-Clarke County, GA · August 14, 2019
Minutes
AUDIT COMMITTEE MEETING MINUTES
Wednesday, August 14, 2019
Committee Members Present: Visiting:
Commissioner Melissa Link, Committee Chair Deborah Lonon, Assistant Manager
Commissioner Patrick Davenport Josh Edwards, Assistant Manager
Commissioner Ovita Thornton Glenn Coleman, Assistant Director,
Public Utilities
Committee Members Absent: David Fluck, Director, Central Services
Commissioner Allison Wright Michael Smith, Community Citizen
Commissioner Russell Edwards Lee Shearer, Athens Banner Herald
Nancy Hamby, Community Citizen
Staff: Tommy Hamby, Community Citizen
Stephanie Maddox, Internal Auditor
Deborah Allen, Recorder
Committee Chair Link called the meeting to order at 6:04 pm.
A. Approval of Minutes:
The Committee unanimously approved the Minutes of the June 12, 2019 meeting.
B. 2018 Work Plan Update:
Internal Auditor Maddox provided a brief status update on the annual work plan:
Public Utilities Department – Water Business Office
Central Services Department – Fleet Management Program
Sheriff’s Office
The Committee agreed to make a formal request for the Internal Auditor to present the
results of the Sheriff’s Office audit report at the next available work session.
C. General Discussion:
Upon request, staff developed a PowerPoint presentation of a new audit selection tool. The
Committee expressed interest in continuing the audit selection discussion at the next
meeting.
D. Items for Discussion at September 11, 2019 meeting:
Internal Auditor Maddox will conduct a live simulation of the audit selection tool at the
September meeting.
The next meeting is scheduled on Wednesday, September 11 from 6:00 – 7:30 p.m.; City
Hall; Room 301.
The meeting adjourned at 6:54 p.m.
The above summation is an interpretation of the items discussed and decisions reached at the
above-referenced meeting, not a transcript of the meeting. A digital recording of the meeting
is available upon request.
Page 1 of 1
Agenda
AGENDA
Audit Committee
Wednesday, August 14, 2019
6:00 pm – 7:00 pm
City Hall, Room 103
A. Review and approval of the Wednesday, June 12, 2019 Meeting Minutes
B. 2018 Work Plan Update
Sheriff’s Office – Inmate medical services
Public Utilities Department — Water Business Office
Central Services Department — Fleet Management Program
C. Development of the Annual Audit Work Plan –
Alternative Approach to Audit Selection - Risk Assessments
D. Items for Discussion at next meeting
Attachments:
1. Draft Minutes from the June 12 meeting
2. Meeting Agenda – August 14, 2019
3. Status of Work Plan Activity
4. Risk Assessment Presentation
The next meeting is scheduled for
Wednesday, September 11, 2019
Note: The Audit Committee Meeting is open to the public. However, public comments are not received unless
the Committee Chair requests that an individual provide information to the Committee.
O FFI CE O F O P ER A TI O N AL A N AL YSI S
T H E U N I F I E D G O V E R N M E N T O F A T H E NS -C L A R K E C O U N T Y , G E O R G I A
300 College Avenue, Suite 202 • Athens, Georgia 30601 • (706) 613-3012
www. at h en sc lar k e c o unt y. c o m / 2 3 6 / O per at i on al - An al ys is - Of f i ce
AUDIT STATUS REPORT
DATE: August 12, 2019
TO: Mayor and Commission
FROM: Stephanie Maddox, Internal Auditor
Office of Operational Analysis (formerly, the Auditor’s Office)
SUBJECT: Status of 2018 Work Plan Activity
The following table summarizes the current status of each audit according to audit stages. Please find a
description of the audit stages below.
WORK IN PROGRESS
Status Completion
Audit Percentage indicates completion level Forecast
Operational Audit of the Pre-Audit Planning – 100 % Final report submitted to March 2019
Clarke County Sheriff’s Discovery Stage – 100% Clerk of Commission for
Office Analysis – 100 % acceptance at the August 2,
Conclusions – 100% 2019, Mayor and
Recommendations – 100% Commission Meeting.
NOTE: Audit report completed March 2019; final responses from the Sheriff’s Office received May 2019
Public Utilities Department – Pre-Audit Planning – 100 % Additional follow-up August 2019
Water Business Office Discovery Stage – 100% interviews completed with
Analysis – 100% WBO supervisory staff;
Conclusions – 95% audit report writing near
Recommendations – 95% completion.
Central Services Department – Pre-Audit Planning – 100% Audit plan finalized; survey October 2019
Fleet Management Program Discovery Stage – 55% results received; review and
Analysis – 25% analysis underway;
Conclusions – 0% interviews anticipated to
Recommendations – 0% start August 2019.
Audit Stages
PRE-AUDIT PLANNING: OOA staff conducts literature reviews, identifies benchmark communities,
creates the pre-audit survey(s), and prepares a list of documents to request from various ACC
departments related to the audit client.
OOA staff schedules a pre-conference meeting with the audit client/department leadership to discuss the
audit process, the timing of fieldwork, and answer any questions.
DISCOVERY: Interviews, information validation, observations and surveys. As this stage is critical to
the preparation of a complete and meaningful audit, it consumes the majority of time involved.
ANALYSIS: Assigning meaning/value to the information; determining what it reveals related to the
scope of the audit. Defines systems, processes and practices in terms of effectiveness and efficiency.
CONCLUSIONS: Identifies and describes constraints and opportunities regarding developments and
implementation of needed improvements.
RECOMMENDATIONS: Suggests action that can be taken in consideration of the constraints and
opportunities.
Risk Assessment
U N I F I ED G OVE R NMEN T O F AT HE N S -CLA RK E CO U N T Y
O F F I CE O F O P E R AT I O NA L A N A LY S IS
AU G U ST 2 0 1 9
Auditing Responsibility
According to the Institute of Internal Auditors (IIA) International Standards for
the Professional Practice of Internal Auditing, Section 2120.A.1 – The internal
audit activity must evaluate risk exposures relating to the organization’s
governance, operations, and information systems regarding the:
• Achievement of the organization’s strategic objectives.
• Reliability and integrity of financial and operational information.
• Effectiveness and efficiency of operations and programs.
• Safeguarding of assets.
• Compliance with laws, regulations, policies, procedures, and contracts.
What is a Risk Assessment?
Risk assessment, as defined by the IIA, is a systematic process for
assessing and integrating professional judgments about probable
adverse conditions and/or events.
An Internal Audit Risk Assessment is the identification,
measurement, and prioritization of risks for the purpose of
selecting and developing auditable areas.
Definitions:
Risk
The possibility of an event occurring that will have an impact on the achievement
of objectives and is measured in terms of impact (severity) and likelihood
(probability).
Risk Management
A process to identify, assess, manage, and control potential events or situations
to provide reasonable assurance regarding the achievement of the organization’s
objectives.
Risk Appetite
The level of risk that an organization is willing to accept.
Office of Operational Analysis (OOA) Risk
Assessment vs. Safety & Risk Management
OOA Risk Assessment
• Focus: Assessing a departments level of operational risk to determine audit
necessity.
• The purpose of a risk assessment conducted by OOA is to identify and assess a
departments operational risks. Based on the results of an assessment, Audit
Committee members may make an objective decision as to which audits should be
conducted by OOA.
Safety & Risk Management
• Focus: Employee and property safety
• The Safety & Risk Division of HR manages insurance, injury, and illness claims
against and generated by ACC for damage to persons and ACC property, provides
safety training (e.g. trench safety, CRASE, DDC, CPR/AED/First Aid, etc.), conducts
safety audits of ACC facilities, and handles workers compensation claims.
Step 1: Identify Risks
What is included in a Risk Assessment?
• A questionnaire is developed to compile information on the potential departments to be
audited (auditable units) and to address all risk factors.
• The following information may be requested from the departments in the questionnaire:
• Description of the departments activities and functions.
• Business objectives, risks, and exposures.
• Systems utilized.
• Lists of major vendors and estimated annual payments.
• Total expenditures for a designated period of time.
• Budgets for a designated period of time.
• Number of authorized employees.
• Number of vacant positions and length of time the position(s) have been vacant.
• Questions to address specific risk factors listed by OOA.
• Additional risks identified by the auditable unit.
Risk Factors
Risk factors are developed using knowledge of the Athens-Clarke
County Unified Government and best practices in internal auditing.
Each risk factor is scored based on the impact and likelihood of the risk
occurring to the department being audited.
• Likelihood – The measure of the probability of an unfavorable event
occurring.
• Impact – The measure of the consequence of an unfavorable event
occurring.
Risk Categories
The impact of each risk factor is based on three categories: financial,
operational, and/or compliance, and the impact each will have on ACC.
The overall goal of the risk scoring approach is to ensure that OOA includes
high-risk areas in the audit plan and considers routine audits on those areas.
The three risk categories are defined as follows:
• Financial Risk – Impact related to revenues, expenditures, assets, liabilities,
and equity decisions.
• Operational Risk – Risk is exposed if operating objectives are not being met
through the effective and efficient use of resources. This includes potential for
fraud, business disruptions, customer service, and safety.
• Compliance Risk – Risk is exposed if operating (or potentially operating)
outside of applicable laws and regulations.
Step 2: Measure Risks
Risk Assessment Criteria
• The primary purpose of a risk assessment is to identify risks, assess
them, and reduce them to an acceptable level.
• Before operational risks can be assessed, the risk criteria and risk
factors from which to measure and score must be established and
defined.
• To achieve this, a measurement system that includes a baseline (an
organization’s acceptable risk level) and a method of scoring (a risk
scoring system) must be established.
• The criteria are derived from the organization’s culture and industry,
external and internal context or controls, applicable laws, standards
and other requirements.
Sample Risk Factors Categorized
Risk Categories: O – Operational Risk Impact; F – Financial Risk Impact; C – Compliance
Risk Impact
Risk
Risk Factors Weight Description
Category
Compliance with Impact of compliance risk increases with more reliance on
Regulations, Laws, O, F, C federal and/or state laws, regulations, and funding, and
Policies, and SOPs prior issues.
Risk of asset misappropriation, depreciation of obsolete
Inventory F items, or nonexistent items recorded as inventory.
Impact and likelihood or risk increases with more cash
Handling of Cash O, F collection and less resources to monitor.
Departmental A dynamic change in employees increases the probability
O, F of inefficiencies as well as errors occurring.
Changes
Quality of Internal Reliability of internal control system is important in
O, F, C detecting and preventing operational and systemic errors.
Control System
Sample Risk Factors
• Compliance with Regulations, • Inventory
Laws, Policies and SOPs
• Handling of Cash
• Objectives/Projects
• Instances of Fraud, Waste, &
• Service User Experience Abuse
• Business Continuity • Complexity of Transactions
• Publicity/Reputation • Departmental Changes
• Injury • Information Technology Changes
• Audit History, Prior Audit Results • Quality of Internal Control System
Step 3: Prioritize Risks
Risk Identification
Some categories in which to identify risk:
• People, processes, systems, and • Fraud.
events.
• Internal fraud
• Employment practices and workplace
safety. • External fraud
• Turnover rates • False expense claims
• Vacancy rates (position vacancies
and time vacant) • Compliance with laws, regulations,
• Tenure of the department/division contracts, policies, and procedures.
and senior management
• External/criminal threats
• Staff size in relation to activity
volumes
• Reliance on key staff and
management succession
Risk Identification (continued)
• Effectiveness and efficiency of • Reliability and integrity of financial and
operations. operational systems and information.
• Organizational changes • Misuse of systems
• Misuse of confidential information
• Complexity
• Access control and security
• Activity volumes
• Volume, severity, and duration of
• New or changing product or process system outages
• Customer satisfaction • Volume, severity, and type of
security incidents
• Degree and complexity of projects
• System response time
• Processing, storage, and data • Mainframe and network availability
communication
Understanding the Operational Area of an Audit
People Processes Systems
• What is the department’s position • Workflow processes • Major systems and
within the organization? components (hardware
and software)
• What is the department’s • Dependencies and interfaces
organizational structure? with other departments and/or • System interfaces
external service providers (internal and external)
• Are there clear, direct, and
sufficiently high reporting lines? • Outsourcing vendors
• Transaction volumes and dollar
• What data, reports, or amounts • Security
responsibilities flow across
departments? • Risk and control assessments
• Are departmental activities and • Procedures
management’s roles clearly
defined?
• Monitoring of reports
• What is the experience level and
expertise of management and key
staff?
Sample Scoring – Risk Factors Likelihood
(probability) and Consequences (severity)
Risk Factor Negligible Minor Moderate Major Catastrophic
Rating Likelihood Description
5 Frequent Represents a risk with a 90% or greater chance of
Compliance Minor non- Singular failure to Repeated failure Repeated failure to Gross failure to
occurrence and will significantly impact the achievement
with compliance with meet internal to meet internal meet external meet external
of departmental goals and objectives.
Regulations, internal policies or SOPs. standards or standards. Failure standards.
Laws, Policies standards. Small Minor follow protocols. to meet local, Repeated failure to
and SOPs number of minor recommendation Important State, and/or meet local, State,
issues requiring s which can be recommendation Federal and/or Federal
4 Probable Given the current work environment, there is a 65% up to improvement. easily addressed s that can be regulations. regulations.
90% chance of risk occurring with a possibility of repeated by management. addressed with Critical report or Severely critical
incidents. an appropriate substantial number report with
management of significant possible major
3 Occasional Represents an area or problem that has a 35% up to 65% action plan. findings and/or reputational or
chance of occurring and may prevent achieving lack of adherence financial
departmental goals and objectives. to regulations. implications.
2 Remote Represents an area that has a 10% to 35% chance of
occurrence with little impact on achieving the Objectives/ Barely noticeable Minor reduction Reduction in Significant project Inability to meet
department’s goals and objectives. Projects reduction in in scope, quality scope or quality over-run. project objectives.
scope, quality or or schedule. of project; Reputation of the
1 Improbable Represents an area with less than a 10% chance of schedule. project objectives organization
occurrence and has little to no impact on achieving goals or schedule. seriously damaged.
and objectives.
Risk Values
(likelihood x severity)
Level of Severity
Likelihood of
Risk Negligible Minor Moderate Major Catastrophic
(1) (2) (3) (4) (5)
Frequent
(5)
5 10 15 20 25
Probable
(4)
4 8 12 16 20
Occasional
(3)
3 6 9 12 15
Remote
(2)
2 4 6 8 10
Improbable
(1)
1 2 3 4 5
Step 4: Select and Develop Audits
Audit Selection
• Questionnaires are developed to compile information and to identify
if any departmental risks exist and if so, to what level.
• Using established risk factors and criteria, levels of risk indicated
through the questionnaires are measured.
• Audit Committee prioritizes risks identified and the level of severity.
• Audit Committee selects audits to be conducted by OOA.
Risk Assessment Process Overview
Step 2 Step 4
• Identify • Prioritize
Risks • Measure Risks • Select and
Risks Develop
Audits
Step 1 Step 3
Key Points
• A risk-based audit planning approach adds value to an internal audit.
• Risk identification is the most important step in the process.
Questions?
Get email alerts for Athens-Clarke County
A daily email when new agendas and minutes are posted.