Internal Audit Division FY 17 - Audit Plan Overview

Similar documents
August 14, Dear Ms. Gula:

Benchmarking Report Share, Compare, Validate SAMPLE. Year: 2017 Your Organization Date

Independent Validation of the Internal Auditing Self-Assessment

Office of Internal Auditing

From Dubai to Beijing

UNIVERSITY OF COLORADO DEPARTMENT OF INTERNAL AUDIT 2018 AUDIT PLAN As of June 1, 2017

INTERNAL AUDIT OFFICE

Agenda. Enterprise Risk Management Defined. The Intersection of Enterprise-wide Risk Management (ERM) and Business Continuity Management (BCM)

risk and compliance department business plan

1. Definition & Mission

Service Business Plan

See your auditor clearly. Transparency report: How we perform quality audit engagements

Office of Audit Services Annual Audit Plan For the Year Ending August 31, 2018

INTERNAL AUDIT OFFICE

Internal Oversight Division. Internal Audit Strategy

Enterprise Risk Management Handbook. June, 2010

RSA ARCHER MATURITY MODEL: AUDIT MANAGEMENT

Guidance Note: Corporate Governance - Audit Committee. March Ce document est aussi disponible en français.

Internal audit strategic planning Making internal audit s vision a reality during a period of rapid transformation

Quality Assurance and Improvement Program (QAIP)

Research Shared Services:

Fraud Risk Management

Enterprise Risk Management

Office of Information Technology (OIT) Strategic Plan FY

INFORMATION TECHNOLOGY SERVICES. KEY PRIORITIES for CSU Information Technology In support of Graduation Initiative 2025

Developing an Integrated Anti-Fraud, Compliance, and Ethics Program

The Red (Book) Rocks The Latest and Greatest Audit Standards

Sarbanes-Oxley Act of 2002 Can private businesses benefit from it?

IT Governance Overview

University System of Georgia Enterprise Risk Management (ERM) Creating A More Educated Georgia

DIRECTOR TRAINING AND QUALIFICATIONS: SAMPLE SELF-ASSESSMENT TOOL February 2015

Risk Advisory Services Developing your organisation s governance for competitive advantage

Operational Plan

KING III CHECKLIST. We do it better

A New Framework for Risk Management

Strengthening Your Enterprise Risk Management Process

Quality Assessments what you need to know

Value-Added Internal Audit: Myth or Reality?

Strategic Cost Management: Vanderbilt s Transformation Journey

FY INTERNAL AUDIT ACCOMPLISHMENTS REPORT AND ANNUAL STRATEGIC WORK PLAN

FY17-FY18 Audit Plan. Office of Internal Auditing

Office of Compliance, Risk and Ethics Program Report. January 2016 December 2016

Practice Guide. Developing the Internal Audit Strategic Plan

Catching Fraud During a Recession Through Superior Internal Controls. FICPA s 25 th Annual Accounting Show. J. Stephen Nouss September 29, 2010

Effective implementation of COSO s new anti-fraud guidance

2013 COSO Internal Control Framework Update. September 5, 2013

Good Practices of the Audit Committee

National Defense University. Strategic Plan 2012/2013 to 2017/18 One University Evolution

CORPORATE GOVERNANCE KING III COMPLIANCE REGISTER 2017

King iii checklist 2013

Internal Audit Department

Risk Management Strategy

Our Vision: To establish a standard of partnership, innovation, value added resource maximization, and financial expertise such that:

Caribbean Association of Audit Committee Members Inc. Independent Quality Assurance Assessment of the Internal Audit function

The University of Texas at San Antonio 2014 External Quality Assessment of the Auditing and Consulting Services Office

SOLUTION BRIEF RSA ARCHER AUDIT MANAGEMENT

This charter defines the purpose, authority and responsibility of News Corporation s (the Company ) Corporate Audit Department.

IBM Impact Grants. Offering Portfolio

CLAconnect.com/creditunions. Impact the Future of Credit Unions

Integrating COSO s Fraud Risk Management Guide on an Enterprise Scale

Strategic Planning Process

: Chief Financial Officer and Head of Corporate Services

Internal Audit Policy and Procedures Internal Audit Charter

LEVERAGING COSO ACROSS THE THREE LINES OF DEFENSE

THE BODY OF KNOWLEDGE FOR MEDICAL PRACTICE MANAGEMENT A FRAMEWORK FOR SUCCESS

Taking ERM to a. 6 GRC Today / October 2015

Drive Your Career Forward IIA Certifications and Qualifications

Internal Audit Challenges & Opportunities Speaker: Laurie Shen, Director, Grant Thornton LLP

Strategic Direction #7 Business Operations. Final Report

The Future of Internal Auditing:

Internal Auditing in the Great City Schools

Strategic Plan

What We Will Cover Today

Using a Compliance Program Assessment to Elevate Institutional Compliance Effectiveness

2014 Global Council. Dubai, UAE 6-9 March 2014 DAY 2. globaliia.org

THE BODY OF KNOWLEDGE FOR MEDICAL PRACTICE MANAGEMENT

Enterprise Risk Management Implementation Foundations and Reflections of a University Chief Risk Officer at the Five Year Milestone

COLLEGE OF PHYSICIANS AND SURGEONS OF ONTARIO GOVERNANCE PROCESS MANUAL

Ethical leadership and corporate citizenship. Applied. Applied. Applied. Company s ethics are managed effectively.

Ministry of Finance Comptroller General Victoria, BC

SVP/Chief Information Officer Executive President and CEO Exempt

Brink's Modern Internal Auditing

Measuring Compliance Program Effectiveness

June 2016 Issue 05/2016

King lll Principle Comments on application in 2013 Reference in 2013 Integrated Report

President & Chief Executive Officer

ISACA. The recognized global leader in IT governance, control, security and assurance

Session 6C Internal audit value Developing metrics to present IA value

INTERNAL AUDIT CHARTER

AUDITING. Auditing PAGE 1

FINANCE & BUSINESS AT PENN STATE...

Concept of Operations. Disaster Cycle Services Program Essentials DCS WC OPS PE

DeVry Approach to ERM

Session 7: Corporate Governance

RICH GERMANO, JR Wildwind Court Nashville, TN Professional Profile

This document contains a summary of the Group s application of all of the principles contained in King III.

Office of Inspector General and Director of Compliance NEWS

Patty Miller, CIA, QIAL, CPA, CRMA, CISA PKMiller Risk Consulting, LLC

ISO Standards in Strengthening Organizational Resilience, Mitigating Risk & Addressing Sustainability Concerns

King lll Principle Comments on application in 2016 Reference Chapter 1: Ethical leadership and corporate citizenship Principle 1.

Transcription:

Division FY 17 - Audit Plan Overview Our Value Proposition - Objective Insight and Catalyst for Positive Change delivers value-added services that are catalysts for positive institutional change in governance, risk remediation, and the design of process controls. By improving the intuition's capabilities to anticipate and respond to current and emerging risks and challenges, we support management s journey toward achieving Emory s strategic plan and objectives Mission Provide independent, objective assurance Add value and improve operations of Emory University (EU) and Emory Healthcare (EHC) Evaluate and improve the effectiveness of risk management, control, and governance processes Promote the safeguarding and effective use of enterprise assets and resources Table of Contents Our Value Proposition... 1 Mission... 1 Guiding Principles... 2 Highlights of IA s Assurance and Advisory Services... 3 Continuous Risk Assessment. and Monitoring... 5 FY16 Accomplishments... 5 Our People & Organizational Structure... 6 Appendix A Menu of Value Added Services... 7 Appendix B Three Lines o f Defense... 8 Appendix C Staff... 9 Appendix D FY17 Budget... 10 1 )

Guiding Principles We deliver best-in-class services to the institution, using a dynamic risk assessment process. We support the advancement of corporate governance and enterprise risk management by providing assurance and advisory services that focus on value preservation and value creation. Risk Assessment Risk Focus Perspective Testing Strategy Staffing Strategy Dynamic process to prioritize and address current and emerging risks during the year Focus on risks that matter (Enterprise Risk Management (ERM), including strategic and reputational risks) Adjust plan during the year as necessary Deliver holistic business assurance across enterprise risks Emphasis on Board and senior leadership needs Focus on high level monitoring controls ( 2nd line of defense ) - See Appendix B for a description of the lines of defense Provide future oriented services (value creation), in addition to traditional value preservation focus (see description of services in Appendix A) Provide forward looking value-added expertise to mitigate risks (e.g., during implementations, education/awareness, data analytics) Evaluate risk from an institutional perspective Analyze complete populations of data Strengthen data analytics platform (continuous auditing/monitoring) Recruit and retain a diverse team (skills, experiences, education) to support assurance and advisory services on broad institutional risks (see listing of staff at Appendix C) Safeguard and allocate resources for higher risk work: o Limit (cap) staff hours on lower risk investigations Continue to offer professional development opportunities to Emory business officers through the Governance, Risk, and Control (GRC) Program 2

Highlights of IA s Assurance and Advisory Services A Look Back (FY 16) and a Look Ahead (FY 17) Emory s Division (IA) strives to dynamically align our efforts with the strategic direction of the Emory enterprise, so that we may serve at the forefront of the most relevant risks. As part of our service, we continuously seek opportunities to extend our traditional assurance provider role into a proactive trusted advisor role. Outlined below are highlights of IA s work performed in FY 16, with a look ahead towards proposed areas of coverage in FY 17. ERM Risk Domain FY 16: Highlights of IA s Coverage FY 17: Key Areas of IA s Proposed Coverage Academic and Student Affairs International Programs Student Health, Safety and Security Data Governance and Management IPEDS Reporting Affirmative Action Plan (AAP) Data Management Advisory (Education and Training Materials) Student Immunization Compliance Minors on Campus Campus Safety and Physical Plant EU Physical Access and Security Active Shooter/Bomb Threat Preparedness and Response Finance and Investment Donor Intent GBS Executive Education Wire Transfers Data Analytics (Disbursements) Financial Attestation Process Alleged Financial Fraud Investigations Financial Commitment Authority Financial Conflict of Interest (COI) Office of the President and Cabinet (Disbursements) Data Analytics (Disbursements) Financial Attestation Process Alleged Financial Fraud Investigations Governance and Corporate Affairs ERM Steering Committee PeopleSoft Steering Committee IT Steering Committee Compliance Coordinating Committee 1- Note: Select projects may span multiple ERM risk domains; in such cases, these are categorized under the primary ERM risk domain that they support. 3

Highlights of IA s Assurance and Advisory Services A Look Back (FY 16) and a Look Ahead (FY 17) ERM Risk Domain FY 16: Highlights of IA s Coverage Healthcare Pharmacy Governance Structure Shared savings/population management EHC Quality Data Reporting J-Wing Construction FY 17: Key Areas of IA s Proposed Coverage Revenue Cycle Patient Satisfaction Drug Diversion Monitoring Contract Management System J-Wing Construction Library and Information Technology (LIT) EHC Information Services IT Disaster Recovery to Support Business Continuity Planning (BCP) ** Note: BCP is a foundational governance control necessary for business functions across the Emory enterprise BCP and IT Disaster Recovery IT Compliance Framework Cybersecurity Governance Framework Identity and Access Management Research Research Administration Lifecycle Process Flows Effort Reporting Finance, Grants, and Contracts (FGC) - Quality Assurance: Award Set-Up Human Resources Form I-9 Compliance 4

Continuous Risk Assessment and Monitoring Our team keeps informed on emerging risks through ongoing discussions with leadership, and engagement in a variety of enterprise-wide forums, including: Financial Attestation Process (FAP) Steering Committee Anti-Fraud Steering Committee Enterprise Risk Management (ERM) Steering Committee Executive Compliance Committee Data Advisory Committee (DAC) Information Technology (IT) Steering Committee Business Continuity Planning (BCP) & Disaster Recovery (DR) PeopleSoft 9.2 Upgrade Executive & Steering Committees EHC Finance Administrative Team, 340B Drug Pricing Program Governance, EHC Compliance Council, Clinical Claims and Review Council, Shared Savings Agreement and Population Management, Value Acceleration Process and several more New projects are added to the audit plan throughout the year based on these on-going risk assessment processes and discussions. FY16 Accomplishments In FY16, we provided enterprise-wide value through ongoing risk assessment dialogues with management, excellent service, and thought leadership. In each project, we considered the institution s perspective, and promoted consideration of opportunities to adopt consistent best practices systemwide. Several of our FY16 initiatives resulted in the elevation of risks into Emory s ERM program for formal monitoring and reporting. Below is a summary of select areas where we partnered with management to enhance Emory s risk management capabilities: Business continuity planning and IT disaster recovery planning Emory Healthcare Information Services governance and risk management Campus safety and security International programs - Student health and safety Pharmacy governance structure Shared savings/population management J-Wing construction Data management EHC quality data reporting 5

Our People Excellent analytical and communication skills, along with a deep knowledge of our institution s research, teaching, and patient care functions, are capabilities embedded within our team of 11 audit professionals. What brings us together in is an unwavering focus and shared appreciation for the importance of what we provide to the Emory enterprise and its various schools, units/facilities, and programs. We recruit and welcome professionals with diverse personal and professional backgrounds. All team members perform with passion for excellence, integrity, and a desire to work collaboratively with management to enhance Emory s governance and risk mitigation capabilities. Organizational Chart 6

Risk = Likelihood x Impact RISK MORE LESS Appendix A: Menu of Value Added Services HIGH ADVISORY STRENGTHEN Provide consulting, fact finding and monitoring relative to risk mitigation and process development efforts. ASSURANCE AUDIT Perform a review to confirm controls and processes are well defined and working effectively. DATA ANALYTICS MONITOR Support Management in monitoring trends to determine if the risk profile changes and action is required to enhance controls. ADVISORY SELF ASSESS Provide tools to management to self assess the strength of controls, as required. MODERATE DEFINED Design of Internal Controls/Processes 7

MORE Appendix B: Responding to Risk - Internal Audit s Role in the Three Lines of Defense 1 st LINE OF DEFENSE Business Operations 2 nd LINE OF DEFENSE Oversight Functions 3 rd LINE OF DEFENSE Independent & Objective Assurance School/Unit/Program Operational & Functional Management Responsible for operating business processes and practices (control) to manage risk: Vision and Strategy Ethical culture & tone at the top Risk identification and mitigation Process and internal control design, implementation and effectiveness Compliance with laws, regulations and policies Business Administration Offices Responsible for defining policy and for monitoring the effectiveness of business operation controls to mitigate risk. Such functions include (but not limited to) Dean s Office /Chief Business Officer, Human Resources, Finance, Research Administration, IT, Campus Service, etc. Risk Management Responsible for establishing and maintaining an Enterprise Risk Management (ERM) framework to assist with risk prioritization and reporting Responsible for providing objective and independent assurance (to the Board) on the effectiveness at first and second line processes and controls to mitigate risk. Services include: Assurance Advisory/Consultative Governance Support Data Analytics/Business Intelligence Investigations 8

Appendix C - Staff Name Title Education Scott Stevenson Chief Audit Officer MBA, Averett University BS, Accounting, Wake Forest University Professional Certification (s) CPA, CIA Deepa Pawate Associate Chief Audit Officer MBA, Emory University BA, Computer Science, Emory University CISA Stacy Wood Director of Healthcare MBA, University of North Carolina at Charlotte BS, Business Administration, James Madison University CIA, CRMA Mark Hafitz Director, Data Analytics MS, Business Information Systems, Georgia State University BS, English Literature, Emory University CIA Christine Habib Senior Manager, University MBA, Charleston Southern University BS, Accounting & Management Science, University of South Carolina CFE Courtney Ruckert Manager, University BS, Accounting, Tennessee Technological University CPA, CIA Nadine Alliance Manager, Healthcare MBA, University of Phoenix BS, Legal Studies, St. John's University CHC, CFE Jay Thomas Manager, Healthcare MS, Accounting, Rutgers University BS, Accounting, Kennesaw State University CPA, CIA CGAP, CGFM Alexis Schaaf Senior Auditor, Healthcare MPA, Accounting, Georgia State University BS, Accounting, University of Georgia CPA Sean Liang Senior Auditor, University MBA, Georgia Institute of Technology BS, Management, Georgia Institute of Technology CPA Saleem Khan Senior Manager, IT Audit MBA, Georgia Institute of Technology BS, Computer Engineering, Louisiana State University and Agricultural and Mechanical College CISA Starlyss McSlade Executive Administrative Assistant BA, Commercial Design, Fort Valley State University - 9

Appendix D - FY17 Budget Description Budget Salaries and Fringe $1,900,000 Other Operating Expenses $277,248 Total: $2,177,248 10