Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Internal Controls topic
No spam. Unsubscribe anytime.
NC Pro training urges continuous internal controls, highlights COSO and EGLE tools
Summary
Deloitte trainers for NC Pro reviewed federal and state internal-control expectations for recipients of State Fiscal Recovery Funds, stressing iterative controls, the COSO framework, EGLE self-assessments, PII plans and separation-of-duties "rule of three."
Get email alerts on the Internal Controls topic
No spam. Unsubscribe anytime.
Deloitte consultants reviewed internal-control requirements and common monitoring observations for recipients of North Carolina State Fiscal Recovery Funds (SFRF) during an NC Pro technical assistance webinar on Oct. 25, 2025.
The presentation outlined federal and state expectations for internal controls, emphasized that controls are an iterative organizational practice rather than a one‑time deliverable, and described practical steps agencies and subrecipients can take to reduce risk and improve compliance.
The session opened with Deloitte’s Laura Garman saying that “internal controls are not just a set of policies and procedures or a manual that you create 1 time, but rather that they are iterative processes and actions that are carried out continuously at all levels of an organization.” That theme framed subsequent discussion of federal citations, state tools and commonly observed weaknesses.
Deloitte’s Joe Gorsuch summarized applicable federal guidance and compliance obligations for recipients and subrecipients: “recipients and subrecipients both must establish and maintain effective internal controls, right, to stay in compliance with the US Treasury, the terms and conditions of the federal award.” Presenters referenced the Code of Federal Regulations (2 CFR) as the federal foundation for internal‑control requirements and said recipients should document safeguards, monitoring and prompt corrective action when guidance changes.
The trainers described the Committee of Sponsoring Organizations (COSO) internal‑control framework and walked through its five components—control environment, risk assessment, control activities, information and communication, and monitoring. They noted COSO’s objectives (operations, reporting, compliance) and stressed that controls should be embedded at all organizational levels. Practical examples included approval matrices, reconciliations, separation of duties, and use of automated tools for approvals and data quality.
State‑level tools were highlighted. Presenters explained EGLE (Enhancing Accountability and Government through Leadership and Education) as North Carolina’s annual internal‑control self‑assessment program for state agencies. The EGLE process, they said, includes a major financial assistance section with about 10 subsections (examples given: allowable costs, cost principles, period of performance, suspension and debarment, program income) that mirror topics reviewers request during SFRF monitoring. Deloitte advised agencies to retain self‑assessments and change logs for audit and monitoring purposes.
Protection of personally identifiable information (PII) was raised repeatedly as a recurring control area. Presenters asked recipients to maintain PII plans and policies and to apply state and federal PII protocols when communicating or publishing data. As one presenter put it in a lighter moment, “PII strikes back,” underscoring that PII protection regularly appears in monitoring work.
On financial operations, Deloitte emphasized separation of duties and recommended a minimum "rule of three" for approval workflows: distinct individuals to approve, record and execute payments (with backups). They illustrated how preventative, detective and corrective control types interact—using an ongoing reconciliation process, approvals, inventories and documented corrective steps when discrepancies are detected.
Presenters reported that many of the deficiencies identified in early (cycle 1) monitoring—such as outdated policies and weak separation of duties—have been addressed by recipients. “We have not seen a lot of [those observations] in cycle 2,” Gorsuch said, while urging agencies to keep annual review cadences and maintain controls as staff or regulations change.
The webinar closed with an encouragement to use dashboards, automated monitoring tools and documented procedures to support transparency and audit readiness. Presenters said training and clear lines of responsibility reduce the risk of noncompliance and recommended agencies set annual review schedules for policies and maintain change logs for templates and contract addenda.
The session slides, an FAQ and a recording will be posted on the NC Pro website, presenters said.

