Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Audit And Risk topic

No spam. Unsubscribe anytime.

CalSTRS audit committee approves 2025–26 risk‑based audit plan; hears external auditor and risk‑management updates

3585864 · May 16, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

The CalSTRS Audit, Risk and Management Committee approved a risk‑based audit plan for 2025–26 and received presentations from internal audit, Crowe LLP (external auditor) and enterprise risk and compliance leads on maturity, software procurement and Benefit Connect implementation.

The Audit, Risk and Management (ARM) Committee of the California State Teachers' Retirement System approved a risk‑based audit plan for fiscal year 2025–26 and heard presentations on the external financial statement audit, enterprise risk and compliance maturity work and the enterprise risk report.

Committee action and votes took place by voice vote. The committee approved routine items including the agenda and minutes, consent item 3 (audit services plan update) and, after presentation and discussion, the proposed 2025–26 risk‑based audit plan for internal and employer audits.

The approved audit plan centers employer audit work on special pay and salary reporting — areas the presenters described as the highest risk for employer reporting and the parts of compensation with the greatest potential impact on the pension plan. Chris Wall, assistant director over employer audits, said the employer‑audit team uses data analytics (including Power BI) to identify outliers in reported pay rates, earnings, special pay and unused sick leave and to select employers for audit. He told the committee the team reserves flexibility to adjust the schedule during the year as new risks emerge.

Erin Satterwhite, internal audit manager, described the internal audit risk‑assessment process as considering industry trends, leadership input, the CalSTRS strategic plan, enterprise risks and prior audits to update the audit universe and prioritize audits by risk and complexity. Satterwhite and other audit staff emphasized that the plan is resource‑constrained — the number and scope of audits reflect available staff hours.

The committee was told the employer‑audit program will change terminology in audit reports: what had been called "base compensation" will be referred to as "salary" in draft reports issued after July 1, 2025, to align with the Creditable Compensation Simplification project.

Crowe LLP, the independent external auditor for the June 30, 2025 financial statements, presented its client service plan. Jen Aras, partner, and Hamze Khitan, senior manager, described a year‑round audit approach that includes interim IT testing, testing of census data early (because that data feeds the pension‑liability estimate) and presentation of the audit opinion and required communications in November. Crowe said it does not consider Benefit Connect materially significant for the 2025 audit because transactions from that system are not yet used in the 2025 financial statements, but the firm is performing pre‑implementation procedures and expects Benefit Connect to be financially significant for 2026.

Lynn Bichal and Linda Shaw presented enterprise risk management and enterprise compliance services materials. The staff gave an 18‑month maturity plan closeout report, noting most initiatives were completed or carried forward and that procurement delays slowed the technology elements; CalSTRS has now procured enterprise risk management software and will roll remaining work into the FY2025–26 plan. The staff also explained a one‑time decision to defer branch‑level risk assessments for 2025 to allow staff working on the pension solution project to prioritize that implementation; the committee heard support for that pause.

Board member Dr. Yetman praised the deliberate, careful pace of the maturity work, saying, "It's been deliberate. It's been careful. And most importantly, it hasn't been rushed." Committee members also commended staff for professional development achievements: several staff earned compliance and governance certifications.

Other administrative items included a proposed ARM work plan for FY2025–26 (committee meeting schedule changes to accommodate contract timelines) and a request to review the ARM policy in the governance manual (a routine update the committee approved staff to pursue).

Votes at a glance - Approval of agenda — motion moved and seconded; voice vote recorded as "Aye"; outcome: approved (voice vote). - Approval of minutes — motion moved and seconded; voice vote recorded as "Aye"; outcome: approved (voice vote). - Consent action, item 3: Audit services plan update — moved and seconded as a consent action; voice vote recorded as "Aye"; outcome: approved (consent action). - Item 4: Approval of the proposed 2025–26 risk‑based audit plan (internal + employer audits) — motion moved by Ken; seconded by Elizabeth; voice vote recorded as "Aye"; outcome: approved.

Why it matters CalSTRS oversees pension benefits for California public school educators; the audit and risk programs provide independent assurance over the accuracy of employer reporting, financial statements, and the operation of large IT initiatives such as Benefit Connect, which is expected to supply materially significant data for the 2026 financial statements. The committee's decisions set audit priorities and staffing allocations that determine which employers and systems receive audit scrutiny in the coming year.

What didn’t change Crowe and internal audit said they are coordinating on Benefit Connect testing so as not to impede the implementation team. Crowe reiterated its independence and outlined the plan to issue opinions and management letters if significant deficiencies are found.

Looking ahead Staff will carry forward unfinished technology and software‑related items into the FY2025–26 maturity plan, begin using the newly procured risk management software, and continue pre‑implementation audit work related to Benefit Connect with the expectation of more extensive testing for the 2026 audit cycle.