Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Audit Report topic
No spam. Unsubscribe anytime.
CalPERS audit: BDO expects clean opinion; management letter finds ARIES access control gap
Summary
External auditors (BDO) reported an expected clean opinion on CalPERS’ FY2025 financial statements and no material weaknesses, but the draft management letter identified a segregation‑of‑duties control deficiency in the internally developed ARIES real‑estate system; management removed improper access and will implement biannual user reviews.
Get email alerts on the Audit Report topic
No spam. Unsubscribe anytime.
BDO, the board’s independent external auditor, presented findings to the Risk & Audit Committee on Nov. 18 and said it expects to issue a clean opinion on the fiscal‑year 2025 financial statements, with no material weaknesses or significant deficiencies identified that would require qualified reporting.
BDO described three audit areas that required heightened attention: valuation of private equity and real asset investments (including procedures to roll forward audited fund values to CalPERS’ June‑30 year end), the perennial risk of management override of controls (addressed with targeted journal‑entry testing), and actuarial estimates for the long‑term care fund. BDO confirmed the audit included confirmations of underlying fund statements and independent actuarial review steps.
In its draft management letter BDO reported one control deficiency in ARIES, CalPERS’ internally developed automated real‑estate investment system. Auditors found a user who had both developer and approver privileges in the ARIES development environment, creating a segregation‑of‑duties conflict; BDO could not validate that a secondary approver configuration had been enforced for the entire audit period and found monitoring of change logs and database access was not performed regularly.
CalPERS staff responded that they promptly removed developer access for the affected user, confirmed no unauthorized changes occurred, reviewed user access across ARIES, and committed to independent biannual user access reviews and role checks. Staff also noted ARIES is an internally developed system that will be replaced under the broader investment data and technology modernization program.
Trustees accepted BDO’s audit report and the draft management letter by voice vote. Committee members pressed staff about ongoing modernization plans and whether existing detective controls could be strengthened while the replacement is implemented.

