Citizen Portal

Get email alerts on the Internal Controls topic

No spam. Unsubscribe anytime.

NYSERDA committee recommends updates to Internal Control Manual, cites AI and cybersecurity among risks

Audit and Finance Committee, New York State Energy Research and Development Authority · January 26, 2026

Summary

CFO Pam Poisson told the Audit and Finance Committee that proposed amendments to the Authority’s Internal Control Manual incorporate the Authority’s updated mission and policy alignment, clarify monitoring of federal and state actions, and add references to AI and other emerging technology threats and opportunities; the Committee recommended the changes to the Board by unanimous vote.

Pam Poisson, the Authority’s Chief Financial Officer, presented the Committee with a risk assessment update and proposed amendments to the Internal Control Manual (ICM). Poisson said the "proposed updates incorporate the Authority’s updated mission, vision and promise; highlight its leadership role on the State Energy Planning Board and acknowledge the evolution of the energy landscape; clarify the scope of our monitoring of federal and state legislative and regulatory actions to stay well prepared and aligned with New York State direction; and add reference to key policy and practice updates addressing Artificial Intelligence ("AI") and other emerging technology threats and opportunities."

Poisson described substantive progress on risks identified in the Authority's most recent risk and controls self‑assessment (RCSA), including better process definition, staff training, and technology updates to enable faster, more streamlined controls and improved business intelligence. She also confirmed that the proposed ICM updates would enable a more systematic internal audit process and that the Internal Audit Plan for the coming fiscal year will be informed by the upcoming RCSA. The Committee adopted Resolution No. 521 by unanimous voice vote, recommending Board approval of the ICM amendments with non‑substantive editorial discretion granted to the President and CEO.

The presentation noted that the proposed budget supports necessary upgrades to keep controls robust amid a dynamic threat environment, and that the Authority’s Information Security team and Data Governance Counsel are providing ongoing guardrails. The recommendation goes to the Board for final action.

AI generated

The text on this page is AI generated. Summaries, highlights, analysis, and video transcripts are all produced from the original source material.

AI can make mistakes, so if you spot one, and we will fix it for everyone.

Note: the source content is unaltered by us. Any content source we link to, be it a video, an audio recording, or a document, is presented exactly as its publisher released it. That publisher is usually a government body, sometimes an individual official or another organisation.

Source