BOARD OF REGENTS AUDIT/COMPLIANCE AND INVESTMENT COMMITTEE 3 STATE OF IOWA OCTOBER 24-25, 2012 INTERNAL AUDIT REPORTS ISSUED

Similar documents
BOARD OF REGENTS AUDIT/COMPLIANCE AND INVESTMENT COMMITTEE 3 STATE OF IOWA FEBRUARY 6-7, 2013 INTERNAL AUDIT REPORTS ISSUED

BOARD OF REGENTS AUDIT/COMPLIANCE AND INVESTMENT COMMITTEE 2 STATE OF IOWA FEBRUARY 4-5, 2015 INTERNAL AUDIT REPORTS ISSUED

STATE OF IOWA NOVEMBER 2-3, Contact Person: Todd Stewart FY 2006 REVISED INTERNAL AUDIT PLANS

AUDIT/COMPLIANCE AND INVESTMENT COMMITTEE 3a STATE OF IOWA AUGUST 5, Contact: Todd Stewart

QUARTERLY BUSINESS OFFICERS MEETING JANUARY 2017

Annual Financial Sub-certification

CSU COLLEGE REVIEWS. The California State University Office of Audit and Advisory Services. California State University, Northridge

FY17-FY18 Audit Plan. Office of Internal Auditing

College of Engineering and Computer Science Dean's Office

ACADEMIC DEPARTMENT FISCAL REVIEW

Adding Value by Proactively Managing Departmental Risks

Department of Biology

Testing Services - D0046 Baseline Standards FY 2017

The University of Texas MD Anderson Cancer Center Internal Audit Annual Report for FY2016

UNIVERSITY OF ILLINOIS (A Component Unit of the State of Illinois) Report Required Under Government Auditing Standards. Year ended June 30, 2011

Financial Controls Checklist

The University of Texas MD Anderson Cancer Center Internal Audit Annual Report for FY 2017

K-State Athletics, Inc. Report on Internal Controls related to the Contracting, Travel, and Expenditure processes.

Internal Control Questionnaire and Assessment

AUXILIARY ORGANIZATIONS

THE UNIVERSITY OF TEXAS-PAN AMERICAN OFFICE OF AUDITS & CONSULTING SERVICES. Department of Communication Report No

University System of Maryland University of Maryland, College Park

Governance Process ENDS. Board- President Relationship. Executive Limitations

Office of Internal Audit Report for the Quarter Ending September 30, 2017

Audit Committee Presentation FY2011 Audit Plan (annual risk assessment) August 16, 2010

Minnesota State Community and Technical College

STEPHEN F. AUSTIN STATE UNIVERSITY FISCAL YEAR 2013 ANNUAL AUDIT REPORT TABLE OF CONTENTS

Guide to Internal Controls

Stephen F. Austin State University

Internal Control Questionnaire and Assessment

University System of Maryland Bowie State University

University Internal Audit

Maryland School for the Deaf

Internal Audit Work Plan

Fiscal Year 2014 Internal Audit Annual Report

University System of Maryland University of Baltimore

CITY OF CORPUS CHRISTI

Terms of Reference Governance Committee

Understanding Internal Controls Office of Internal Audit

THE BODY OF KNOWLEDGE FOR MEDICAL PRACTICE MANAGEMENT

GRAMBLING STATE UNIVERSITY Risk Assessment Annual Audit Plan

Division of Student Affairs Internal Control Questionnaire FY 2011

Mott Community College Job Description

Third Party Fiduciary Agent. Guam Department of Education. In partial fulfillment of Contract: Monthly Project Status Report.

Financial Services Job Summaries

The Corporation of the City of London Quarterly Report on Internal Audit Results

WAKE TECHNICAL COMMUNITY COLLEGE SUSTAINABLE ENERGY PLAN. Energy Plan

Salt Lake Community College Policies and Procedures

FINANCIAL MANAGEMENT OF SERVICE CENTERS

Internal Audit Policy and Procedures Internal Audit Charter

BOM/BSD 2/November 1994 BANK OF MAURITIUS. Guideline on Maintenance of Accounting and other Records and Internal Control Systems

APPENDIX 2 COMMUNITY DEVELOPMENT COMMISSION FINANCIAL CHECKLIST REQUIRED FOR ALL APPLICANTS (A SITE VISIT MAY BE CONDUCTED LATER)

SEMINOLE COUNTY OFFICE OF MANAGEMENT AND BUDGET PURCHASING DIVISION BLANKET PURCHASE ORDER PROCESS AUDIT. March 31, 1998

Management Excluded Job Description

Sample Result Statement Listing To achieve the company s Strategic Objective.

AUXILIARY ORGANIZATIONS CALIFORNIA STATE UNIVERSITY, FRESNO. Audit Report October 26, 2014

CAPE FEAR COMMUNITY COLLEGE VICE PRESIDENT OF BUSINESS SERVICES

THE BODY OF KNOWLEDGE FOR MEDICAL PRACTICE MANAGEMENT A FRAMEWORK FOR SUCCESS

OBSERVATIONS, RECOMMENDATIONS, AND RESPONSES

Office of Internal Audit Status Report BOARD OF TRUSTEES

Doc P-Card Services Provider RFP

UCSB AUDIT AND ADVISORY SERVICES

UNIVERSITY OF PITTSBURGH POLICY CATEGORY: RESEARCH ADMINISTRATION SECTION: Research SUBJECT:

Regents of the University of Michigan Committee Charters Last updated June 17, 2010

21 & 22 Account Overview. Presented by Campus Services

EXECUTIVE TRAVEL & ENTERTAINMENT SYSTEMWIDE REVIEW

THE UNIVERSITY OF TEXAS AT DALLAS Office of Internal Audit 800 West Campbell Rd., ROC 32, RICHARDSON, TX (972)

Administration Division Public Works Department Anchorage: Performance. Value. Results.

Sonoma County. Internal Audit Report. Auditor Controller Treasurer Tax Collector. Sonoma County Payroll Process

FY 2017 YEAR-END CLOSING CALENDAR Page 1

Streamlining Business Operations Belknap Campus. Town Hall Presentation Belknap Business Operations April 2016

Operational Plan

Finance Committee, Board of Health Elizabeth Bowden, Interim Director of Administrative Services FINANCIAL CONTROLS CHECKLIST

Horizontal Audit of the Acquisition Cards Process

CELL PHONES and OTHER MOBILE DEVICES interim policy

Office of Internal Audit and Compliance

INTERNAL AUDIT OFFICE

Boston College: OFFICE FOR SPONSORED PROGRAMS Effort Reporting Policy

Tab No. F-2 TERMS OF REFERENCE FOR THE AUDIT COMMITTEE

Any observations not included in this report were discussed with your staff at the informal exit conference and may be subject to follow-up.

Office of Internal Audit and Compliance

Cantalician Center Job Description. Assistant to the Chief Financial Officer

Loch Lomond and The Trossachs National Park Authority. Key Controls Report

Enterprise Risk Management

REPORT NO MARCH 2012 UNIVERSITY OF SOUTH FLORIDA. Operational Audit

THE UNIVERSITY OF TEXAS AT EL PASO

CAPRA National Accreditation Standards

LI & FUNG LIMITED ANNUAL REPORT 2016

Shared Service Centers

A U D I T R E P O R T. Audit of Lee County Utilities

Working with the Oracle Chart of Accounts: GL Chart Strings and PTAEOs

Administrative and Student Information Systems Transformation Overview

Seattle Public Schools The Office of Internal Audit

Internal Audit Report. Contract Administration: 601CT Contracts TxDOT Internal Audit Division

Curriculum Vitae. George Omae Ogari, P o Box Nairobi

Corporate Governance Update. SOX 404 and Internal Controls

ROSWELL PARK CANCER INSTITUTE CORPORATION INTERNAL CONTROLS OVER PROCUREMENT AND REVENUES. Report 2005-S-15 OFFICE OF THE NEW YORK STATE COMPTROLLER

Procurement Card Continuous Auditing

ANNUAL AUDIT PLAN Fiscal Year 2014

Administrative Faculty Job Evaluation Model

Transcription:

STATE OF IOWA OCTOBER 24-25, 2012 INTERNAL AUDIT REPORTS ISSUED Action Requested: Receive the original and follow-up internal audit reports. Contact: Todd Stewart Executive Summary: Completed institutional internal audit reports are reported to the Audit/ Compliance and Investment Committee as required by Board Policy. UNIVERSITY OF IOWA ORIGINAL REPORTS CEA* Status Department of Microbiology UI Health Care Enterprise Labor Management System Athletics Operations Apparel and Promotional Items College of Law NCAA Compliance Equipment and Apparel NCAA Student-Athlete Employment Department of Orthopaedics Department of Nursing Export Controls NCAA Financial Aid NCAA Team Travel IOWA STATE UNIVERSITY Graduate Student Admissions Department of Electrical and Computer Engineering Security of Internet-Initiated ACH Transactions UNIVERSITY OF NORTHERN IOWA International Programs Multimodal Transportation Center *Assessment of Controls Efficiencies (CEA) are defined on the following page FOLLOW-UP REPORTS UNIVERSITY OF IOWA Clinical Quality Safety and Performance Improvement Department of Microbiology Epic - Ophthalmology (continued on following page)

STATE OF IOWA PAGE 2 UNIVERSITY OF IOWA (continued) Holden Comprehensive Cancer Center MARS/MAUI Feeder Systems State Hygienic Laboratory UI Health Care Epic Stork UIHC Employee Health Clinic University of Iowa Diagnostics Laboratory IOWA STATE UNIVERSITY Foundation Accounts Spending Non-Employees on Campus Research Data Security Study Abroad Rome Program UNIVERSITY OF NORTHERN IOWA Payment Card Industry Standards Temporary Faculty and Staff ASSESSMENT OF CONTROLS / EFFICIENCIES (CEA) HIGH Could seriously affect several areas within the University. Exposes the University to unacceptable risks or liability if not corrected OR Involves difficult issues requiring the attention of executive management OR Involves compliance with Federal, State, or other laws and could result in serious consequences if not implemented OR Unacceptable weakness in the internal and/or accounting controls OR Substantial savings (perhaps millions) can potentially be realized by correcting. MODERATE Could seriously affect a department or area within the University OR Involves a difficult issue requiring the attention of upper management OR Involves compliance with Federal, State or other law and could result in minor consequences if not implemented OR Weakness in the internal and/or accounting controls OR Savings (perhaps thousands) can potentially be realized by correcting. LOW Can affect a department or may be common to several areas OR Could result in improved internal and accounting control OR Can be corrected relatively easy OR Could result in improved efficiency or effectiveness of operations OR No reportable observations or corrective action taken prior to report issuance. CONSULTATION Auditors provided consultation only, without thorough assessment No audit recommendations at this time. The internal auditors have utilized the colors for the control / efficiency assessment (CEA) in evaluating each overall audit report.

STATE OF IOWA PAGE 3 SUMMARIES OF INTERNAL AUDIT REPORTS ISSUED Department of Microbiology Issued July 13, 2012 Status: The audit was performed to provide reasonable assurance to the new department head that adequate business processes and internal controls are in place and operating as intended. The audit specifically reviewed compliance regarding sponsored programs, financial management and revenue, procurement, and human resources. Primary recommendations included completing monthly account reconciliations, limiting physical access to secure areas, and ensuring appropriate approvals occur on travel requests, travel reimbursements, and procurement card transactions. Management agrees with the findings and expects to complete their action plan after July 2012. UI Health Care Enterprise Labor Management System Issued July 13, 2012 Status: The UI Health Care Enterprise Labor Management System audit was performed to provide reasonable assurance that the system s functionality and the associated business processes are sound and that internal controls are in place and operating as intended. Audit recommendations include reviewing employee s ability to self-approve leave requests, developing training on system reports, and developing a process to delete/deactivate user accounts for individuals transferring outside of UI Health Care. Management agrees with the findings and expects to complete their action plan by October 2012. Athletics Operations Apparel and Promotional Items Status: An audit of the Athletics Department s distribution of apparel and promotional items was performed to ensure transactions are properly documented, controls to monitor auctioned items and support staff are adequately designed, and inventory management of promotional items is reasonable. Audit recommendations included strengthening controls for promotional item inventory and clarifying document retention periods. Management agrees with the findings and expects to complete the action plans by September 2012. College of Law Status: The College of Law audit was performed to assess the effectiveness of the unit s career placement and admissions reporting, as well as the internal controls around its business processes, human resource function, and general computer applications. Specific areas noted for improvement included: accurately reporting bar passage data to the American Bar Association, complying with University cash handling and University procurement card policies, completing account reconciliations, segregating incompatible job duties, fortifying general computer controls, and ensuring human resource termination/transfer verification. Management agrees with the findings and expects to complete their action plan by November 2012.

STATE OF IOWA PAGE 4 NCAA Compliance Audit Equipment and Apparel Status: As a Division I member, is obligated to comply with the National Collegiate Athletics Association (NCAA) legislation. This audit was performed to fulfill the portion of the NCAA s requirement related to equipment and apparel. Review of processes provided evidence that institutional controls have been designed and implemented to monitor and account for athletics equipment and apparel for student-athletes. No findings were identified, and the audit is closed. NCAA Student-Athlete Employment Status: As a Division I member, the University of Iowa is obligated to comply with the National Collegiate Athletic Association (NCAA) legislation. The audit was performed to fulfill the portion of the NCAA s requirement related to student-athlete employment. No findings were identified, and the audit is closed. Department of Orthopaedics Status: The Orthopaedic audit was performed at the request of the Vice President for Medical Affairs. Audit recommendations include improving; IT general computing controls, charge capture process, clinic scheduling criteria, human resources processes, and fiscal management practices. Management agrees with the findings and expects to complete their action plan by January 2013. Department of Nursing Issued September 27, 2012 Status: The audit was performed to provide reasonable assurance that adequate business processes and internal controls are in place and operating as intended. The audit specifically reviewed compliance regarding financial management and revenue, procurement, and human resources. Primary recommendations included developing a procedure manual and cross training for key personnel, updating workflow paths to ensure appropriate segregation of duties, completing monthly reconciliations, completing additional financial education for nurse managers, implementing a monitoring process to ensure all performance appraisals are completed in accordance to University policy, and ensuring appropriate approvals occur on travel, travel reimbursements, and procurement card transactions. Management agrees with the findings and expects to complete their action plan after May 2013.

STATE OF IOWA PAGE 5 Export Controls Issued September 27, 2012 Status: The Export Controls audit examined the internal controls and processes in place to ensure compliance with applicable federal regulations. Actions to be taken include performing an institutional risk assessment to identify areas subject to export control regulations, establishing procedures to mitigate identified risks, assigning responsibility for process implementation and oversight, compiling a comprehensive export control manual, examining staff training needs related to export controls, and expanding electronic document storage techniques. Management expects to complete their action plan before November 2013. NCAA Financial Aid Issued September 27, 2012 Status: As a Division I member, the University of Iowa is obligated to comply with the National Collegiate Athletic Association (NCAA) legislation. This audit was performed to fulfill the portion of the NCAA s requirement related to financial aid. A review of the processes revealed the athletics department has controls in place to monitor and account for student-athlete financial aid in accordance with the NCAA legislation. No findings were identified and the audit is closed. NCAA Team Travel Issued September 27, 2012 Status: As a Division I member, the University of Iowa is obligated to comply with the National Collegiate Athletic Association (NCAA) legislation. This audit was performed to fulfill the portion of the NCAA s requirement related to team travel. A review of the process revealed the athletics department has controls are in place to monitor team travel activities to ensure the NCAA legislation is not being violated. No findings were identified and the audit is closed. Iowa State University Graduate Student Admissions Issued August 21, 2012 Status: The purpose of this audit was to determine whether University-wide and program specific admission requirements were met by a sample of accepted applicants. The audit also included a review of graduate student assistantship compensation and fulfillment of responsibilities. Continuing academic performance was also evaluated by reviewing academic probation procedures. Applicants and graduate students from the 2011-2012 academic year were included in testing. No findings were noted and the audit is closed.

STATE OF IOWA PAGE 6 Iowa State University Department of Electrical and Computer Engineering Issued October 3, 2012 Status: The audit was requested by the former Dean of the College of Engineering. Audit objectives included determining if the internal financial reporting process results in understandable, accurate, and timely information for users. Sponsored programs monitoring activities were evaluated to determine if adequate monitoring activities occur within the department to fulfill ISU and sponsor requirements regarding the administration of sponsored research. Additional objectives included verifying whether processes and procedures exist for conflict of interest and commitment disclosures; for the acquisition, recordkeeping, and disposal of departmental equipment; and for monitoring building access controls. Information technology resources were also reviewed to determine if resources are kept current, and verifying that information technology backup practices are adequate. The development of standard operating procedures for sponsored programs fiscal management and equipment management, implementation of an information technology disaster recovery plan, and an enhanced tool for monitoring building access will strengthen the control environment. Internal Audit will conduct a follow-up in February 2013. Iowa State University Security of Internet-Initiated ACH Transactions Issued October 3, 2012 Status: This audit was requested by the University Treasurer in order to comply with the National Automated Clearing House Association (NACHA) requirement of an annual audit of security practices and procedures. The audit included reviewing the physical security, personnel and access controls to protect against unauthorized access and use, and network security. No issues were noted. University of Northern Iowa International Programs Issued September 21, 2012 Status: The audit was performed to analyze International Programs for reasonable internal controls and processes. Audit procedures included policy review, cash handling, accounts receivable, expenditure and revenue processes, financial performance, and personnel processes. Audit recommendations include development of policies, following expenditure policies, documenting apartment rent calculation, recording and reporting inventory, segregation of duties, and development of a job description. Management agrees with the findings and expects to complete their action plan by June 2013. University of Northern Iowa Multimodal Transportation Center Issued September 21, 2012 Status: The audit was performed to evaluate the operations and financial performance of the University s multimodal transportation center for adequate and effective internal controls and verify FTA requirements are being followed. Cash handling, allocation and recording of parking revenue, procurement processes, allocation and recording of facility expenses, financial performance, facility maintenance with safety and security, and operational and financial reporting were examined. Audit recommendations include improvements in financial performance and setting aside reserves, allocating applicable expenses, monitoring maintenance and repair costs, handling cash and revenue, and submitting required annual reports. Management will implement the recommendations and expects to complete the action plans by June 2013. Internal Audit will begin a follow-up in July 2013.

STATE OF IOWA PAGE 7 STATUS OF AUDIT FOLLOW-UPS University of Iowa Title Report Original 1. UIHC Centralized Pharmacy Inventory Aug 25, 2011 Jan 2012 2. Maintenance and Flood Response Equipment Oct 31, 2011 Apr 2012 3. Anesthesia Dec 1, 2011 Apr 2012 4. UI Heart and Vascular Center Jan 1, 2012 Apr 2012 5. Department of Neurology Dec 1, 2011 June 2012 6. Department of Psychiatry Feb 29, 2012 June 2012 7. University Housing & Dining June 23, 2011 July 2012 8. Athletics Ticket Office May 23, 2012 Sept 2012 9. Campus Recreation and Wellness Center May 23, 2012 Sept 2012 10. IowaCare July 13, 2012 Oct 2012 11. UI Health Care Human Resources Sept 28, 2011 Jan 2013 Revised Action Status 12. The Division of Sponsored Programs Corporate Funded Clinical Trial Agreements Apr 2, 2012 Jan 2013 13. Campus Conflict of Interest Oct 21, 2011 Feb 2013 Iowa State University Title Report Original Revised 14. Employee Separation Procedures Oct 8, 2010 Aug 2011 June 2012 Dec 2012 15. ISU Surplus June 11, 2012 Oct 2012 Action Status 16. Identity and Access Management Nov 1, 2011 Jan 2013 17. Programs for Youth Mar 23, 2012 Jan 2013 18. Extension & Outreach Jan 30, 2012 June 2013 19. Export Controls June 11, 2012 July 2013

STATE OF IOWA PAGE 8 University of Northern Iowa Original Title Report 20. Fringe Benefit Rates and Controls Mar 22, 2012 Oct 2012 21. Events Complex Concessions Jan 4, 2012 Nov 2012 22. Gallagher-Bluedorn Performing Arts Center Jan 4, 2012 Nov 2012 23. Athletic Summer Camps Mar 22, 2012 Jan 2013 24. Graduate Assistantships June 13, 2012 Apr 2013 25. Physical Plant Utility Billing June 13, 2012 Apr 2013 Revised Action Status Legend Planned corrective action and/or follow-up report not completed within 6 months of originally scheduled date. Planned corrective action and/or follow-up report not completed within 3 months of originally scheduled date. Follow-up report is due and is within 3 months of originally scheduled completion date. Follow-up report not yet due. H:\BF\2012\oct2012\Audit Comp & Invest\1012_a&cITEM03--Internal Audit Report.docx