Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Audit And Risk topic

No spam. Unsubscribe anytime.

CalHFA audit committee reports clean audits, strong cybersecurity score; board amends audit charter to include enterprise risk

California Housing Finance Agency · October 25, 2024
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

CalHFA’s audit committee reported an unmodified (clean) audit opinion for fiscal year ending 6/30/2023, compliance reviews with no findings on MyHome and Dream for All, and a National Cybersecurity Review score of 6.36/7. The board voted unanimously to amend the audit charter to encompass enterprise risk oversight (Resolution 24‑20).

Director Sotelo reported the audit committee met in September and October and that independent auditors provided an unmodified, or clean, opinion on both the GAAP financial statements and the single audit for the year ending June 30, 2023. The committee also reviewed agreed‑upon procedures for the MyHome and Dream for All programs and heard that those compliance reviews revealed no findings.

Sotelo said IT staff briefed the committee on a cybersecurity review that produced a score of 6.36 out of 7 under the National Cybersecurity Review, and that the audit committee intends to broaden its remit to evaluate enterprise risk in addition to traditional audit responsibilities.

Rebecca Franklin, acting chief deputy director and director of enterprise risk management and compliance, described existing enterprise risk practices and the agency’s plan to integrate risk reporting with board oversight. "Operational risk shall always be kind of really managed in oversight through the leadership of the executive director, but the board should be provided regular assurance that we're managing risk," she said.

The board considered proposed charter changes to formally expand the audit committee’s role to include enterprise risk assessment and reporting. Director Sotelo moved to adopt the amended charter (Resolution 24‑20); Doctor White seconded. After no public comment, a roll call recorded unanimous approval.

The change aligns the committee with common practice—combining audit and risk oversight—so the board can evaluate credit, market, compliance, technology and business-continuity risks against strategic objectives and staffing capacity before approving major program rollouts.