Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Internal Audit topic
No spam. Unsubscribe anytime.
Board adopts three‑year internal audit plan to prioritize financial management, grants and IT security
Summary
The Board of Regents approved a flexible internal audit plan for fiscal years 2026–2028 that prioritizes financial management and purchasing, grants accounting and—beginning FY2027—IT security and cyber resilience; the risk‑based plan will be revisited annually.
Get email alerts on the Internal Audit topic
No spam. Unsubscribe anytime.
The University of Guam Board of Regents on June 3 approved a three‑year internal audit plan that establishes a risk‑based work program for fiscal years 2026 through 2028.
Renee, the university’s risk officer and head of internal audit, explained the plan’s development: the office built an "audit universe" of auditable units, applied risk criteria (financial impact, regulatory exposure, operational complexity and prior findings) and scored units to prioritize focus areas. "Our approach...is where we identify key positives and unions within the university and then we assess the level of those units that we've identified," the presenter said during the meeting.
Key focus areas for the coming three years include financial management and purchasing, federal grant accounting and contract compliance (FY2026), an IT and cyber‑security engagement planned for FY2027, and continuing financial management with additional emphasis on facilities, health and safety and human‑resources processes in FY2028. The registrar and audit committee will receive written details in the packet and the plan will be adjusted annually based on the risk register.
The board approved the internal audit plan by voice vote. Committee members asked about coordination with external oversight (Office of Public Accountability) and the presenters said the internal plan is intended to complement external audits and to improve efficiency and internal controls. The university indicated corrective actions and follow‑up reporting will be part of the internal audit function’s outputs.
The approval tasks the internal audit office to begin scheduled engagements, report results to the committee and update the risk register annually.

