Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Internal Audit topic

No spam. Unsubscribe anytime.

Chief auditor reports implementation rate below historical goal; committee approves FY2026 audit plan

University of Minnesota Board of Regents Audit & Compliance Committee · June 12, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

Chief Auditor Mike Gauthier told regents the implementation rate for essential recommendations is 31% (below a historical 40% goal), highlighted clusters of overdue items in UMD Athletics and HIPAA governance, and presented an FY2026 audit plan that the committee approved by voice vote.

The University of Minnesota Audit & Compliance Committee on June 2025 received an internal audit update from Chief Auditor Mike Gauthier that noted mixed remediation results and outlined the FY2026 audit plan, which the committee then approved.

Gauthier told the committee that the implementation rate for essential recommendations over the follow‑up period was 31%, below the office’s historical 40% target. He said there are 68 unresolved items; 47 of those are still within the first year of follow‑up and 34% of the outstanding items are past due. He identified two audit clusters with a concentration of past‑due items: University of Minnesota Duluth (UMD) athletics and HIPAA governance, and said some UMD items require coordination with IT units or external vendors.

Gauthier said the office proposes two reporting changes: removing a detailed visual schedule of follow‑up bar charts (pages 39–49 of the docket) to streamline reporting, and shifting risk‑rating language from the office’s historical “essential/significant” categories to a more standard high/medium/low taxonomy. He emphasized the intent to maintain flags where management chooses to accept risk and to bring such decisions to the committee for discussion.

The chief auditor outlined the FY2026 audit plan and the unit/process priorities that will be tiered (tier 1 = formal commitment; tier 2 = flexible substitutions). Highlighted planned work includes a broad University Police Department audit, audits of purchasing processes (broken into phases), an IACUC governance audit, a review of the Minnesota Supercomputing Institute security profile, a Crookston full‑campus audit, and process audits for twin cities admissions, transfers, and athletics compliance processes. Gauthier said the office also reserves time for special projects and board or management requests (including transition reviews and gift testing).

Regents discussed how the university’s PEAK administrative system enables horizontally scoped (functional) audits instead of only unit audits and asked the chief auditor to ensure the committee is alerted where management formally accepts risk. Several regents expressed support for the proposed shift away from the 40% single‑metric goal in favor of multiple metrics that better reflect larger systems work.

Regent Davenport moved to approve the FY2026 audit plan; the motion received a second and was approved by voice vote. The transcript records the committee approving the audit plan by ayes and noting no opposition; it does not provide a named roll‑call tally.

Why it matters: The audit office’s findings and the committee’s approval of the FY2026 audit plan affect the university’s oversight priorities and set workstreams for campus and process audits over the next year. The committee asked the audit office to continue flagging accepted‑risk decisions and to refine metrics for follow‑up reporting.

The committee then received an information item on the annual institutional risk and financial reports and adjourned.