Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Risk Management topic

No spam. Unsubscribe anytime.

CalSTRS closes 18‑month risk and compliance maturity plan, moves to FY25‑26 with new software

California State Teachers Retirement System Audits and Risk Management Committee · May 16, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

CalSTRS reported substantial progress under an 18‑month enterprise risk and compliance maturity plan, will roll remaining work into a shorter FY25‑26 plan, and has procured enterprise risk management software to support ongoing work.

The Audits and Risk Management Committee received a closeout of an 18‑month enterprise risk management and enterprise compliance services maturity plan and approved the transition to a shorter FY25‑26 work plan that will carry forward incomplete items, including technology implementation.

Julie Underwood introduced the closeout and praised staff for training and certifications earned during the initiative. Lynn Bichal, director of enterprise risk and compliance, reviewed accomplishments: charter and framework updates, a consolidated risk universe, a formal training plan, mapping of risk appetite to core values, a compliance monitoring framework aligned to Department of Justice standards, and pilots for policy testing. "They have really made strides to ensure that the work that they've done has brought the programs to a new level of excellence," Underwood said.

Bichal said procurement delays slowed technology initiatives; the enterprise risk management software was procured last month and will be rolled into the FY25‑26 plan. "We hope that this will help to automate some of our risk data collection and reporting, improve analysis of workflows, and strengthen risk reporting across the organization," she said.

Staff explained they elected to defer branch‑level risk assessments for FY24‑25 to allow staff to prioritize the Pension Solution implementation and to focus on configuring the new software; staff said the pause should not materially increase organizational risk because many processes and controls are changing with the new system. Linda Shaw presented the semiannual enterprise risk report as of March 31, 2025, and said information security remains the highest‑scored enterprise risk while some operational risks decreased due to completed projects.

The FY25‑26 plan will emphasize risk tolerances tied to strategic metrics, development of key risk indicators, professional development for risk staff, pilots for compliance policy review, and continued third‑party risk oversight. Board members praised the measured pace and urged staff to continue deliberate progress. The committee recorded no objection and will continue periodic reporting on maturity plan implementation and software roll‑out.