Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Internal Audit topic

No spam. Unsubscribe anytime.

Audit committee approves updated charters and 2025 internal audit plan to align with IIA standards

2590305 · February 27, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

The University of Tennessee Board of Trustees Audit and Compliance Committee approved revisions to the committee charter, a replacement internal audit departmental charter, and the systemwide 2025 internal audit plan to conform with the IIA Global Internal Audit Standards.

The Board of Trustees Audit and Compliance Committee approved revisions to its committee charter, a replacement internal audit departmental charter and the University of Tennessee System'wide 2025 internal audit plan during its open session.

The changes align the university's audit governance documents with the IIA Global Internal Audit Standards and expand the internal audit function's focus on systemwide internal controls, IT auditing and connected risk.

Committee chair DeCosta Jenkins called the meeting to order and introduced Andrea Addis, interim executive director of internal audit, to present the items. Addis told trustees the new IIA standards required updates to both the committee-level charter and the internal audit departmental charter. "The new standards really redefined how the internal audit function will be managed," Addis said, describing a complete replacement of the departmental charter using the IIA standards template and revisions to committee language to preserve independence.

Addis said the internal audit charter revision separates compliance activities from the audit charter so compliance is not portrayed as falling under audit standards. "This removes the compliance activities from appearing to fall under the audit standards," she said. The replacement charter also introduces the concept of an "internal audit mandate" that defines roles, responsibilities and the scope of audit services.

Addis presented the 2025 internal audit plan, which she described as risk-based and agile. Key goals include connecting Audit Board modules used for operations and compliance (to enable shared data), mapping systemwide internal controls in support of the DASH rollout, strengthening IT audit capacity, and developing performance indicators for audit work. The plan lists 21 risk-based audits, 11 annual audits and roughly 13 advisory projects as the team's target mix for 2025.

Addis noted the department will expand IT-focused audits, perform an internal quality assurance review in fall 2025 and use a vendor for capital construction cost audits on major projects. She said the department aims to cover about 82% of identified risks in the plan and about 64% of executive-team strategic risks.

Questions from trustees touched on the balance between advisory services and independent audit work. Jenkins and Addis reiterated safeguards: advisory engagements will be disclosed and auditors who perform an advisory service will not be assigned later to audit the same area.

Chair Jenkins then sought a single motion to approve the committee charter changes, the internal audit departmental charter and the 2025 internal audit plan. The committee approved all three items by voice vote.

The committee noted that, by Tennessee law, the revised internal audit charter will be forwarded to the state comptroller's office for the state audit office's review as a next step.

Ending: Trustees received the materials and approved the charters and plan; the internal audit office will continue implementation and a fall 2025 internal quality review was planned to confirm conformance with the IIA standards.