Citizen Portal

Get email alerts on the Internal Audit Plan topic

No spam. Unsubscribe anytime.

Committee approves FY 2026–27 internal audit plan; priorities include Green Bank transactions, IT controls and cybersecurity

Energy Research and Development Authority Audit & Finance Committee · April 29, 2026

Summary

Director of Internal Audit Jamie Fernandez presented the annual report and proposed FY 2026–27 plan, which includes audits of New York Green Bank deal transactions, IT general controls, cybersecurity, solicitation/procurement, and advisory engagements; committee approved the plan and noted upcoming staffing and an external quality assessment.

Jamie Fernandez, director of internal audit, summarized the annual internal audit report for the fiscal year ending 03/31/2026 and presented the FY 2026–27 internal audit plan.

Fernandez outlined proposed work streams that include a deals transaction review for New York Green Bank to assess compliance with operational procedures, an IT general controls audit focused on user access, change management and data protection (expected to be outsourced), a joint cybersecurity/information security audit to evaluate threat prevention and incident response, and an audit of solicitation and non‑competitive procurement. Fernandez also described advisory engagements on collateral management and repayment controls and noted the plan includes a continuous monitoring review of payment transactions required for internal controls certification.

Fernandez told members internal audit had extended an offer to a new internal auditor with an anticipated start date of 05/07/2026 and that the function had no concerns regarding independence or impairment; an external quality assessment is required and will cover audits issued after 03/31/2022. "The director of internal audit will disclose to the audit and finance committee any interference… related to the scope, performance, or communication of internal audit work and results," Fernandez said. Committee members voiced strong support for prioritizing cybersecurity and IT audit work, noting the Green Bank's higher profile and potential cyber risks. The committee moved, seconded and voted 'Aye' to approve the internal audit plan for FY 2026–27.

Next steps: internal audit will begin the planned engagements and update the committee on staffing and outsourcing decisions as they are finalized.

AI generated

The text on this page is AI generated. Summaries, highlights, analysis, and video transcripts are all produced from the original source material.

AI can make mistakes, so if you spot one, and we will fix it for everyone.

Note: the source content is unaltered by us. Any content source we link to, be it a video, an audio recording, or a document, is presented exactly as its publisher released it. That publisher is usually a government body, sometimes an individual official or another organisation.

Source