Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Internal Audit Update topic

No spam. Unsubscribe anytime.

Internal audit reports 31% implementation rate, proposes reporting changes; committee approves FY2026 audit plan

University of Minnesota Board of Regents Audit & Compliance Committee · June 12, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

Chief Auditor told Regents the implementation rate for essential recommendations is 31%, noted clusters of open and past‑due items in UMD Athletics and HIPAA governance, proposed moving to holistic follow-up metrics and high/medium/low risk ratings, and the committee approved the FY2026 audit plan.

Chief Auditor Gaalswyk told the University of Minnesota Board of Regents Audit and Compliance Committee that internal audit’s implementation of essential recommendations stood at 31% in the most recent follow-up cycle and that the office plans to change how it measures and reports remediation progress.

Gaalswyk said 68 items remained unresolved, 47 of them within the first year of follow-up and 21 newly in follow-up, and that "34% of the outstanding items are past due." He said past-due items were clustered primarily in two audits: UMD Athletics and HIPAA governance. Gaalswyk described three audits with items open longer than two years — University Health, Safety, and Risk Management; School of Dentistry; and the Bell Museum — noting in the Bell Museum’s case that water and facilities issues had delayed inventory and valuation work.

To give the committee a more complete view of remediation activity, Gaalswyk proposed shifting from the historical 40% implementation goal toward a more holistic basket of metrics and to change issue ratings from "essential/significant" to a simple high/medium/low scale. He also proposed removing certain progress-visualization schedules that the office does not follow up on and said auditors will flag instances when management chooses to accept risk and will bring those cases to the committee for discussion.

On the FY2026 audit plan, Gaalswyk walked through the process used to build the plan — quantitative and qualitative risk assessments across an audit universe of roughly 175 units, peer benchmarking, and input from institutional leaders — and highlighted tier 1 audits the office committed to complete. Planned work includes a broad review of the University Police Department, an IACUC governance audit, targeted purchasing process audits tied to PEAK and the financial operations center, and a review of the Minnesota Supercomputing Institute’s security posture.

Following discussion and a motion to approve, the committee voted to approve the FY2026 audit plan and will forward the plan to the full Board for final approval. Gaalswyk said any material changes to tier 1 audits would return to the committee and Board, while tier 2 items could be adjusted during the year.

The committee also received an information item on the annual institutional risk and financial reports required by Board policy.