Risk-Based Audit Plan 2021-2023
Office of the Chief Audit Executive
October 2021
FINAL
1.0 Introduction
This updated two-year risk-based audit plan (2021 to 2023) provides a forward plan of third-line assurance activity for Global Affairs Canada.
Operating Context
The proposed audit coverage is framed by the external and internal context within which the department has and will continue to operate. The level and concurrence of different crises over the last few years has created significant uncertainty, a shift of global priorities, and, in some cases, driven change. This “new normal” is expected to continue for some time, and may result in further uncertainty and challenges. In addition to the impact of these external drivers on the policy priorities and operating context of the department, possible fiscal constraints and the need to maintain a state of perpetual agility will add further stresses to the department’s business model.
Despite these external pressures, and in direct response to them, the department continues to pursue a number of internal reforms that aim to improve the effectiveness and efficiency of the business model and supporting processes through the delivery of key transformations (such as climate finance, data, digital, and trade). When coupled with the external threat environment, this could result in exposure and/or unintended consequences. While governance committees, senior management, and project teams are working to manage these matters, second and third-line functions should continue to provide oversight, monitor, and assess these matters to provide early warning and/or independent insight into drivers or gaps that could lead to potentially undesirable scenarios or exposure.
Departmental Oversight
Internal Audit, together with the Evaluation, Inspection, Enterprise Risk and the other second-line areas such as Internal Controls, have an important role to play in ensuring that the department maintains strong systems of governance, risk management and internal controls. With the finite resources available, Internal Audit will work with other oversight providers to target its engagements and coordinate with existing efforts. Internal audit will also shift some services into the preventative space, through the provision of advisory services and in-flight health checks to assist department in its effort to design fit for purpose, integrated systems and controls through informed risk assessments.
Internal Audit Function
Internal Audit’s strategy is to create value for Global Affairs Canada by leveraging our expertise to drive improvements that support the department in achieving its mandate and contribute to management excellence. To better plan and organize the internal audit function, and in light of the pandemic impacts on departmental operations, the function has developed a Risk-Based Audit Plan (RBAP) for two years to allow for more flexibility to adjust the plan on a year-to-year basis.
2.0 Purpose
The practice of internal audit, including the development of the audit plan, conforms to the Treasury Board Policy on Internal Audit and its Directive. This policy and directive are derived from the International Professional Practices Framework of the Institute of Internal Auditors. Internal Audit is primarily responsible for advising and providing assurance on governance, risk management and internal control issues, consistent with its Internal Audit Charter.
The audit plan identifies the engagements to be undertaken in 2021-2022 and 2022-2023. It establishes the foundation on which the Internal Audit function will add value to the department. The plan was designed to align engagements to reflect the department’s core responsibilities (see 3.2) while addressing areas of high risk and significance.
3.0 Risk-Based Audit Planning
3.1 Methodology
The first step undertaken in the planning process was a review and update of the audit universe using the Departmental Results Framework, which is comprised of 53 programs under six core responsibilities (see Appendix A).
Senior management consultations and material from senior management committees were collected and analayzed. The results from the consultations, documentation review, facilitated risk discussions and a review of outstanding audit recommendations identified areas of significance and risk. This ongoing work allows Internal Audit to monitor new and emerging risks proactively. For the purposes of this plan, the following areas of risk were identified:
- Ongoing COVID-19 Activities – as the pandemic moves into its second year, the department is maintaining critical functions, and resuming regular operations while moving towards new post-pandemic practices and hybrid working options.
- Program Design and Delivery – effective management and controls, and coherence in programming are essential to support the achievement of business objectives and maintain program integrity.
- Transfer Payments – the control framework over transfer payments needs continued focus to support efficient and effective delivery especially given the new Climate Finance Delivery Plan.
- Internal Service Delivery – data and digital solutions must be prioritized to secure information, support program and service delivery. Internal services need to be aligned with policy development and operations. The reliance on internal partners and external partners should be managed to support the achievement of business objectives.
- Transformation – several large transformation initiatives are underway. Risks associated with these initiatives that may warrant oversight include business readiness, financial controls, business process controls, technical solutions, governance, and regulatory aspects.
3.2 Risk Approach
The risk areas were analyzed in relation to departmental priorities, core responsibilities, enterprise risks, and government-wide risk areas. As well, three detailed risk assessements were completed to address mission network risks, Information Technology risks and remote work risks.
In particular, for the mission risk assessement thirteen risk indicators were applied to 178 missions such as hardship, volume of temporary duty assignments, corruption index, financial risk, cash account, spending trends and contracting including method of vendor payment. Following this step, other filters were applied such as number of staff, operating budgets greater than $1.5M, whether previously audited or inspected. This analysis identified ten missions that could be audited over the next two years. Conducting mission audits in the field will depend on ability to travel from a health perspective and country stability from a safety perspective. Currently, the audit plan has a placeholder for four mission audits which provides flexibility for internal audit to decide on the exact locations closer to the start date.
3.3 Other Assurance Providers
Internal Audit coordinates risk-based audit planning activities in consideration of other internal oversight functions (e.g. Evaluation and Inspector General) and external assurance providers (i.e. Office of the Auditor General, Office of the Comptroller General and the Public Service Commission) to align audit coverage of high-risk areas, and to minimize overlap and duplication, thus reducing the engagement burden on the department.
At Parliament’s request, the Office of the Auditor General (OAG) is continuing to focus on selected COVID-19 emergency responses as well as more traditional performance audits. In that regard, the department is currently engaged with the OAG on a performance audit on COVID-19 Vaccine Expenditures. The OAG has not yet determined if the department will be officially scoped into this audit. The department has received official notification for a second OAG performance audit related to Protecting the North. This audit is focused on the implementation of the Arctic and Northern Policy Framework. The department is also involved in the Audit of Public Accounts 2020-2021 that is recurrent every year and continues to focus on pay stabilization as the Government of Canada manages the associated risks with the Phoenix pay system.
The Office of the Comptroller General has issued its two-year audit plan (2021-22 to 2022-23). The Chief Audit Executive, in consultation with senior management, will consider participating in the Horizontal Audit of Departmental Adoption of Digital Standards or will conduct a similar audit on its own to address risks associated with the digital adoption strategy.
The National Security and Intelligence Committee of Parliamentarians (NSICOP) and the National Security and Intelligence Review Committee Agency (NSIRA) are reviewing matters of national security and intelligence activities in the department. More specifically, the department is engaged in two reviews that are expected to be completed by Fall 2021. Internal Audit has provided support to this unit as the work is being conducted and will rely on the results of the review to inform any future audit work in this area.
The methodological approach used to prepare the audit plan is illustrated in the process map below:
Alternative text
- Document Review
- Corporate plans (departmental, investment, security, human resources), Enterprise Risk Profile, Human Resources information, Ministers' Mandate Letters, departmental priorities, Departmental Results Framework
- Departmental Results Reports, Management Accountability Framework Assessment results
- Reports prepared by other internal and external assurance providers
- Consultations
- Ongoing senior management consultations
- Mission operations and functional management
- Internal audit staff and other government departments
- Coordinate with internal oversight providers (Inspection, Evaluation, Internal Controls)
- Coordinate with external assurance providers (OAG, PSC and OCG)
- Risk Identification/ Prioritization
- Synthesize document review and update branch profiles.
- Review outstanding audit recommendations to identify potential risk areas
- Extract relevant data related to missions, country programs and conduct analysis
- Identify and assess risks based on results of analysis
- Prioritize auditable entities based on risk
- Mapping Auditable Entities
- Map auditable entities to OCG government-wide risks, core responsibilities, Enterprise Risk Profile, Ministers' Mandate Letters, and departmental priorities to ensure adequate coverage
- Consider work conducted by other assurance providers
- Developing the RBAP
- Prioritize auditable entities for each fiscal year
- Ensure engagements are focused on areas of highest risk
- Assess whether audit/advisory is the right tool
- Document the plan and submit for approval
3.4 Prioritization and Finalization
Following this work, the list of potential topics was prioritized for each fiscal year and engagements were selected based on areas of highest risk. The Internal Audit team also assessed which tool, audit or advisory, would be best to support the program area and/or function. The remaining document outlines the engagements to be undertaken.
Alternative text
Core Responsibilities
- International Advocacy and Diplomacy
- Trade and Investment
- Development, Peace and Security Programming
- Help for Canadians Abroad
- Support for Canada's Presence Abroad
- Internal Services
Enterprise Risks
- Health, Safety & Well-being
- Digital Transformation
- Resilience & Cyber/ Digital Security
- Human Resources Capacity
- Management & Security of Real Property
Audit Risks / 2021-2023 Engagements
Ongoing COVID-19 Activities
Year #1:
- Remote Work Assessment
- Follow-up on COVID-19 After Action Review
Program Design & Delivery
Year #1:
- CSDP Procurement, Management of Honorary Consuls, Duty of Care
Year #2:
- Country Program Audit, Mission Audits, CSDP – Procurement – Washington, Berlin, Brussels, Trade Regional Operations
Transfer Payments
Year #1:
- Grants & Contributions, International Assistance Innovation Program, Feminist International Assistance Program
Year #2:
- Repayable Contributions – climate finance
Internal Service Delivery
Year #1:
- Costing Methodology, Mission Acquisition Cards, IT Risk Assessment , Privacy Practices, Real Property, Internal Controls, IT Application Portfolio Management, IT Project Management, and Departmental Sustainable Development Strategy
Year #2:
- Real Property – minor capital projects and maintenance
Transformation
Year #2:
- Costing S4Hana
4.0 Two-year Risk-Based Audit Plan
4.1 Overview
This section presents an overview of the 2021-2022 to 2022-2023 Risk-based Audit Plan. Descriptions of the planned engagements for the years are in Appendices B, C, and D respectively.
Table 1: Risk-Based Audit Plan
Year 1: 2021-2022 | Year 2: 2022-2023 |
---|---|
|
|
Reserve List | |
|
*Based on the risk assessment, Tanzania, Mozambique or Ethiopia could be selected for the country program audit.
** Based on the mission risk assessment the following missions could be selected for the mission audits - Dar Es Salaam, Port au Prince, Kinshasa, Accra, Ouagadougou, Dakar, Dhaka, Havana, Colombo, Kyiv or Lima.
4.2 Audit Coverage
The engagements deemed to be of high risk and high priority have been included in the two-year plan. The variety of engagements covered in the plan cover a broad spectrum of core responsibilities, departmental priorities, ministers’ mandate letters, enterprise risks, and government-wide risks (see Appendix E).
4.3 Changes to the Audit Plan
The audit plan is updated annually with adjustments made during the year based on an environmental scan of departmental context and emerging risks. The following engagements have been affected by the prioritization exercise:
- Export Import Control System – to be covered in the Audit of IT Project Management
- GAC Data Strategy – to be completed jointly with Evaluation in 2023-24
- Digital Strategy – to be completed jointly with the Office of the Comptroller General
- Foreign Service Directives – Oversight and Administration – on the reserve list
- Organizational Culture – replaced with the Remote Work Risk Assessment
- New Direction in Staffing – Five-year Cycle Assessment – completed by the Human Resources Branch and submitted to Public Service Commission.
The six mission audits were postponed due to COVID-19 travel restrictions and have been replaced with a series of seven remote audits examining procurement delivery from the various Common Service Delivery Points. The points of delivery are from Mexico, Washington, Berlin, Brussels, London, Manila and Delhi. These hubs service the mission network in the delivery of commons services such as finance, HR, contracting and procurement.
4.4 Challenges in Implementing the Audit Plan
Internal audit has identified the following risk factors that could impede the successful implementation of the audit plan:
- The ongoing impact of the pandemic on operations such as the continued international travel restrictions
- The pace of change, the growing complexity and large transformational initiatives in the department are challenges. Management is facing complex issues, requiring Internal Audit to be agile to react in a timely manner to the changing environment.
- Competing priorities and new demands from stakeholders may adversely affect Internal Audit’s ability to deliver on expected results.
Given this context, the audit plan remains flexible to respond to emerging risks and policy/program changes. If these changes emerge and suggest higher priority audit activity, the plan will be adjusted, so that we respond accordingly.
Internal audit has adopted an approach whereby internal resources are supplemented with qualified contractors when specialized services are required or when the function is faced with a shortage of its own qualified auditors. The renewal of the Professional Audit Support Services Supply Arrangement (PASS) in 2021-2022 will provide the internal audit function with professional contract auditors from pre-qualified firms. These resources allow the internal audit function to supplement audit teams with subject matter expertise and allows the function to continue to provide opportunites for its staff to take on departmental assignments abroad, within headquarters or with other organizations.
4.5 Internal Audit Services
Internal audit’s suite of services includes assurance, advisory, health checks, milestone-based funding validation and consulting. The type of service chosen is based on the best fit for the department. The services are carefully designed to add value and improve the department’s operations (see Appendix F).
4.6 Delivering the Audit Plan – Resources
Internal audit currently has a human resource allocation of 40 full-time equivalent (FTE) staff. Currently, the division supports six staff on various one to two-year assignments (1 with the Public Health Agency undertaking COVID support; 1 with the International Space Agency – Internal Audit; 2 staff on rotational assignments abroad; and one on a six-month assignment with the Peace and Stabilization Operations team in the department). We also have four vacant positions at the auditor level.
Overall, the remaining team of 30 staff are well positioned to deliver on the current two-year plan and have approximately 45,000 hours available each fiscal year to devote to engagements taking into consideration leave and professional development. As mentioned, co-sourcing will be used as required to increase audit expertise and/or capacity.
Salaries ($) | Operating ($) | Total ($) | |
---|---|---|---|
Assurance & Advisory Services | 2,399,952 | 2,399,952 | |
Office of the Chief Audit Executive | 431,673 | 350,624 | 782,297 |
Professional Practices Unit | 895,280 | 895,280 | |
Departmental Audit Committee Activities | 55,000 | 500 | 55,500 |
Professional Services | 513,204 | 513,204 | |
Training | 80,500 | 80,500 | |
Travel | TBD | ||
Total | 3,781,905 | 944,828 | 4,726,733 |
International Advocacy and Diplomacy | Trade and Investment | Development, Peace and Security Programming | Help for Canadians Abroad | Support for Canada’s Presence Abroad | Internal Services |
---|---|---|---|---|---|
|
|
|
|
|
|
Appendix B – Description of 2021-2022 Engagements
# | Year #1 – 2021-2022 | Link to Program Inventory & Enterprise Risk | Description | Tabling Date |
1 | Carry Forward Audit of Grants and Contributions – Oversight and Monitoring | International Advocacy and Diplomacy Trade and Investment Development Peace and Security Programming Internal Financial Management | Objective: to assess whether appropriate grants and contributions oversight and program monitoring are in place and operating effectively to support the achievement of departmental objectives Scope: The audit examined the management and operational practices and controls at headquarters and at the program and project levels, including both centralized and decentralized programs. Background:
| May 2021 |
2 | Carry Forward Audit of Privacy Practices | Internal Services Operations | Objective: to provide assurance that the department has policies, procedures, processes and controls in place to ensure compliance with the Privacy Act and the effective delivery of programs and services Scope: The audit examined the privacy-related policies, procedures, processes and systems. Background:
| June 2021 |
3 | Carry Forward Audit of Real Property – Portfolio Management | Support for Canada’s Presence Abroad Management and Security of Real Property and Assets | Objective: to assess the management control framework in place to support effective real property portfolio planning and investment planning Scope: The audit includes current planning processes and practices as well as modernization initiatives that are underway. Background:
| November 2021 |
4 | Carry Forward Audit of Mission Acquisition Cards (Data Analytics) | Internal Services Internal Financial Management | Objective: to assess the effectiveness of controls in place to ensure that the department complies with legislative requirements and relevant policies on the use of acquisition cards at missions Scope: The engagement examines acquisition card transactions across the 178 missions for calendar years 2019 and 2020. Background:
| December 2021 |
5 | Audit of Mexico Common Service Delivery Point - Procurement | Support for Canada’s Presence Abroad Internal Financial Management | Objective: to determine whether effective controls are in place to support mission procurement activities are compliant with applicable regulations and policies Scope: The audit will procurement activities through contracts and invoices in the 26 missions served by the CSDP in Mexico using data analytics. Background:
| January 2022 |
6 | Carry Forward Audit of Costing Methodology | Internal Services Internal Financial Management | Objective: to determine whether departmental processes and frameworks are in place to provide costing information to support decision-making Scope: The audit will examine financial and human resource components of costing projects/programs that are used to support attestation by the Chief Financial Officer. Background:
| March 2022 |
7 | Audit of Management of Honorary Consuls | Support for Canada’s Presence Aboard External Engagement | Objective: to examine the appointment, oversight and expenditures of operations related to Honorary Consuls Scope: The audit will examine processes and procedures for appointing honorary consuls abroad for the last two fiscal years. Background:
| March 2022 |
8 | Audit of Internal Controls Over Financial Management | Internal Services Internal Financial Management | Objective: examine the framework to manage, monitor, and report on key controls of selected business processes for compliance and operating effectiveness Scope: The audit will focus on those selected business processes for the last two fiscal years and may exclude acquisition cards given recent audit work. Background:
| June 2022 |
9 | Audit of IT Application Portfolio Management | Internal Services Resilience & Cyber/Digital Security IT Infrastructure | Objective: to assess the adequacy and effectiveness of processes in place to manage the portfolio of applications and platforms throughout their life cycle Scope: The audit will include how the health of the applications and platforms is continuously monitored, how aging IT and application/platform security risks are managed, how enterprise architecture is considered to limit duplicate applications and platforms, and how the move to cloud or Shared Services Canada’s enterprise data centers is considered and aligned to the Government of Canada’s direction. Background:
| June 2022 |
10 | Audit of Trade Service – Regional Operations | Trade and Investment External Engagement | Objective: to review and assess optimization and integration of regional activities within the overall Trade Commissioner Service (TCS) transformation initiative Scope: The audit will examine the role of the regions vis-à-vis headquarters and mission operations, change management related to the transformation and privacy practices. Background:
| Fall 2022 |
11 | Carry Forward Feminist International Assistance Policy (FIAP) Implementation | International Advocacy and Diplomacy Development Peace and Security Programming Internal Financial Management | Objective: to provide advice to DME on the implementation of the FIAP and steps taken by the department to improve the effectiveness of international assistance Scope: this review included the governance and accountability; planning strategies and policy guidance; and monitoring and reporting activities undertaken to support the department’s implementation of FIAP from April 2018 to March 2020. Background:
| May 2021 |
12 | Carry Forward Duty of Care – Governance & Spending Advisory | Support for Canada’s Presence Abroad Management and Security of Real Property and Assets | Objective: to provide advice on the Duty of Care envelope as it relates to governance, how the department monitors progress, accounts for the money spent, and accurately reports to senior management and central agency Scope: The engagement scope includes governance, spending, reporting and monitoring activities undertaken to support the delivery of Duty of Care initiatives. Background:
| December 2021 |
13 | Carry Forward International Assistance Innovation Program Advisory | International Advocacy and Diplomacy Development Peace and Security Programming Policy, Program and Service Delivery | Objective: to provide advice to management on the appropriate governance structure to support the implementation of the International Assistance and Innovation Program (IAIP) Scope: This engagement focused on key aspects of the design framework for innovative programming initiatives including governance, roles, responsibilities and accountabilities and common blended finance practices. Background:
| December 2021 |
14 | Carry Forward IT Risk Assessment Advisory | Internal Services IT Infrastructure | Objective: to define the department’s IT audit universe, conduct a risk assessment and identify potential audits to be included in the audit plan Scope: The assessment defined the IT audit universe, identified the risks and prioritized areas requiring further examination. Background:
| May 2021 |
15 | Carry Forward COVID-19 - Remote Work Assessment Advisory | Internal Services Operations – Health Safety and Well-being | Objective: to identify and assess the risks related to remote work practices to inform senior management and to prioritize areas that may require further examination Scope: This advisory engagement assessed risk areas related to remote work such as governance and accountability, health and safety, IM/IT and cyber security as well as people management. Background:
| June 2021 |
Appendix C – Description of 2022-2023 Engagements
# | Year #2 – 2022-2023 | Link to Program Inventory & Enterprise Risk | Description | Tabling Date |
---|---|---|---|---|
1 | Follow-up audit - Pandemic After Action Review | Internal Services Health Safety and Well-being | Preliminary Objective: to determine progress towards addressing issues identified in the After Action Review. Preliminary Scope: This review will be limited to the areas identified in the After Action Report. Background: This engagement will continue to support the department’s pandemic response by tracking implementation of recommendations derived from the lessons learned exercises. | March 2022 |
2 | Audit of Washington Common Service Delivery Point – Procurement | Support for Canada’s Presence Abroad Internal Financial Management | Objective: to determine whether effective controls are in place to support mission procurement activities that are compliant with applicable regulations and policies Scope: The audit will examine procurement activities through contracts and invoices in the missions served by the CSDP in Washington using data analytics. Background:
| June 2022 |
3 | Audit of IT Project Management | IT Infrastructure | Preliminary Objective: to assess the governance, risk management practices and internal controls in place to support the successful management of IT-enabled projects. Preliminary Scope: The scope will encompass project management processes and the departmental project management framework. A sample of projects could be selected to assess if departmental processes are being followed and working as they were intended. Background:
| January 2023 |
4 | Audit of Departmental Sustainable Development Strategy (DSDS) | International Advocacy and Diplomacy Trade and Investment Development Peace and Security Programming Internal Financial Management | Preliminary Objective: The audit will assess the progress made to implement the departmental Sustatinable Development Strategy 2020 to 2023. Preliminary Scope: The scope will encompass the strategy and the three goals related to Greening government, Effective Action on Climate Change and Clean Growth as delivered by the Material Mangement, IT, Acquisition Management and Trade. Background:
| January 2023 |
5 | Audit of Berlin Common Service Delivery Point – Procurement | Support for Canada’s Presence Abroad Internal Financial Management | Preliminary Objective: to determine whether effective controls are in place to support mission procurement activities that are compliant with applicable regulations and policies Preliminary Scope: The audit will examine procurement activities through contracts and invoices in the missions served by the CSDP in Berlin using data analytics. Background: The results of 20 mission audits have found that procurement is one of the high risk areas. In lieu of doing mission audits due to pandemic travel restrictions, data analytics methodology is being employed to examine the procurement practices flowing through the common service delivery points (CSDP). | January 2023 |
6 | Audit of Country Program* | International Advocacy and Diplomacy Trade and Investment Development Peace and Security Programming External Engagement Policy, Programs & Services | Preliminary Objective: to provide assurance that the management of the country program is well governed, risk managed with effective internal controls to achieve program objectives. Preliminary Scope: The audit will focus on the activities of a particular country program including a governance, risk practices, strategic and financial planning, HR, a review of projects, processes and practices. Background: Prior to amalgamation, CIDA provided development funding (international and humanitarian assistance) to countries that were determined to be “countries of focus.” Following amalgamation, DFATD continued the practice of country program audits with the Audit of Burkina Faso in 2014, and both the Colombia and Mali Development programs in 2015. Given the materiality of development funding in the department, specific Grants and Contributions programs have continued to be audited over the years, however, auditing an entire country program will provide a holistic assessment of all of the business lines and activities within that country (e.g. international assistance, humanitarian assistance, peace operations, trade activities, foreign policy strategies). Based on the risk assessment, Tanzania, Mozambique or Ethiopia could be selected for the country program audit. | June 2023 |
7 | Audit of Brussels Common Service Delivery Point – Procurement | Support for Canada’s Presence Abroad Internal Financial Management | Preliminary Objective: to determine whether effective controls are in place to support mission procurement activities are compliant with applicable regulations and policies Preliminary Scope: The audit will examine procurement activities through contracts and invoices in the missions served by the CSDP in Brussels using data analytics. Background: The results of 20 mission audits have found that procurement is one of the high risk areas. In lieu of doing mission audits due to pandemic travel restrictions, data analytics methodology is being employed to examine the procurement practices flowing through the common service delivery points (CSDP). | January 2023 |
8 | Follow-up audit of Repayable Contributions | Internal Financial management Policy, Programs & Services | Preliminary Objective: to provide reasonable assurance that an effective management framework supports the repayable contributions program in meeting its priorities and to follow-up on the recommendations from the 2018 Audit of Repayable Contributions Preliminary Scope: The audit will focus on the key components of the management control framework. | June 2023 |
9 | Audit of Real Property – Minor Capital Projects and Maintenance | Support for Canada’s Presence Abroad Management and Security of Real Property & Assets | Preliminary Objective: to determine whether there are effective processes and structures in place to manage the delivery of minor capital projects and maintenance Preliminary Scope: The audit will examine governance, risk management practices and internal controls related to the delivery of the minor capital projects and maintenance. The scope may include investment decision-making and accountability. A sample of minor capital and maintenance projects will be reviewed. | June 2023 |
10 | S4Hana – Transformation Advisory | Internal Services IT Infrastructure Project Management | Preliminary Objective: to provide on-going health checks for the implementation of the S4Hana project to support project delivery and assurance that may be required for funding decision points. Preliminary Scope: The first health check will be focused on governance for the project. Background:
| Ongoing reporting |
11 12 13 14 | Mission Audit Mission 1 Mission 2 Mission 3 Mission 4 | Support for Canada’s Presence Abroad Financial & Asset Management: - Mission Operations - LES Workforce - IM/IT Management | Preliminary Objective: to determine whether sound management practices and effective controls are in place to ensure good stewardship of resources at the mission in support of the achievement of GAC’s objectives. Preliminary Scope: The audit will examine select elements of a mission’s common services, property, consular and readiness programs. Background:
| 2022-2023 |
Appendix D – Reserve List of Engagements 2021-2023
# | Year 1 & Year 2 | Link to Program Inventory | Further Information |
---|---|---|---|
1 | Audit of Common Service Delivery Point – Procurement (Manila or London or Delhi) | Support for Canada’s Presence Abroad | To determine whether sound management practices and effective controls are in place to ensure good stewardship of resources at the mission in support of the achievement of Global Affairs Canada’s (GAC) objectives. |
2 | Grants and Contributions Transformation (Advisory) | Internal Services | To ensure that this large IT Transformation meets its stated objectives. Examine governance structures, roles, responsibilities, and accountabilities, as well as ensuring strong risk management practices and controls around change management and IT project management. |
3 | GAC Reno Health Check (Advisory) | Support for Canada’s Presence Abroad | To ensure that the GAC Reno is on track, within budget, and meeting business requirements, that risks have been identified and mitigated. This engagement may include the examination of specific projects to ensure the GAC Reno initiative will meet its stated objectives. |
4 | Audit of Key Financial Controls | Internal Services | To examine the framework to manage, monitor, and report on key financial controls of selected business processes for compliance and operating effectiveness. |
5 | Audit on the Adoption of Digital Standards (in conjunction with OCG) | Internal Services | OCG has issued its two-year audit plan (2021-22 to 2022-23). The CAE, in consultation with senior management, will consider participating in the Horizontal Audit of Departmental Adoption of Digital Standards or will conduct a similar audit of its own. |
6 | Audit of Asset Management (including Fine Art Collection) | Internal Services | To examine the management framework for compliance to the TB requirements, compliance with relevant departmental policies to purchase, dispose and track assets. |
7 | Nexus – Transformation (Advisory) | Development, Peace & Security programming; International Advocacy and Diplomacy; and Trade and Investment | To review the strategic direction, oversight/governance and risk management framework associated with this transformation. |
9 | Audit of Return from Post | Support for Canada’s Presence Abroad | To examine the HR management practices and controls in place to support the continued development process of rotational staff so that meaningful positions are identified in a timely manner and staff have a positive work experience at headquarters. |
10 | Audit of Real Property - Major Capital Projects | Support for Canada’s Presence Abroad | To examine the management control framework over major capital projects as it relates to governance, risk management and internal controls. |
11 | Audit of Locally Engaged Staff Benefits | Support for Canada’s Presence Aboard | To examine the management control framework for Locally Engaged Staff benefits in support of the achievement of GAC’s objectives. |
Appendix E – 2021-2023 Engagements Mapped to Priorities
2021-22 Departmental Priorities | ||||||||
---|---|---|---|---|---|---|---|---|
Core Responsibilities | Engagements | Contributing to a Rules-Based International System that advances Canadian interests | Supporting Canadian exporters and economic recovery, building economic resilience, and working toward the renewal of the rules-based multilateral trading system | Deepening Canada’s engagement in the world | Eradicating Poverty | Mandate Letters | Enterprise Risks | OCG RisksFootnote 1 |
International Advocacy and Diplomacy | Grants & Contributions – Oversight & Monitoring | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
Feminist International Assistance Policy Implementation | ✓ | ✓ | ✓ | ✓ | ✓ | |||
International Assistance Innovation Program | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | |
Year #2: | ||||||||
Departmental Sustainable Development Strategy | ✓ | ✓ | ✓ | ✓ | ✓ | |||
Trade and Investment | Grants & Contributions – Oversight & Monitoring | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
Trade Commissioner Services Regional Operations | ✓ | ✓ | ✓ | |||||
Year #2: | ||||||||
Departmental Sustainable Development Strategy | ✓ | ✓ | ✓ | ✓ | ✓ | |||
Development, Peace and Security Programming | Grants & Contributions – Oversight & Monitoring | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
Feminist International Assistance Policy Implementation | ✓ | ✓ | ✓ | ✓ | ||||
International Assistance Innovation Program | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | |
Year #2 | ||||||||
Country Program Audit | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | |
Repayable Contributions | ✓ | ✓ | ✓ | |||||
Departmental Sustainable Development Strategy | ✓ | ✓ | ✓ | ✓ | ✓ | |||
Help for Canadians Abroad | Honorary Consuls | ✓ | ✓ | ✓ | ✓ | |||
Support for Canada’s Presence Abroad | Duty of Care – Governance & Spending | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | |
Real Property – Portfolio Management | ✓ | ✓ | ||||||
Mission Acquisition Cards | ✓ | ✓ | ✓ | ✓ | ✓ | |||
Mexico Common Service Delivery Point - Procurement | ✓ | ✓ | ✓ | ✓ | ||||
Year #2: | ||||||||
Mission Audits (1 to 4) | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ||
Washington Common Service Delivery Point - Procurement | ✓ | ✓ | ✓ | ✓ | ||||
Berlin Common Service Delivery Point - Procurement | ✓ | ✓ | ✓ | ✓ | ||||
Brussels Common Service Delivery Point - Procurement | ✓ | ✓ | ✓ | ✓ | ||||
Real Property – Minor capital projects and maintenance | ✓ | ✓ | ✓ | |||||
Internal Services | Privacy Practices | ✓ | ✓ | |||||
Costing Methodology | ✓ | ✓ | ||||||
Internal Controls Over Financial Management | ✓ | ✓ | ||||||
IT Application Portfolio Management | ✓ | ✓ | ||||||
IT Risk Assessment | ✓ | ✓ | ||||||
COVID-19 Remote Work Assessment | ✓ | ✓ | ||||||
Pandemic After Action | ✓ | ✓ | ||||||
Year #2: | ||||||||
IT Project Management | ✓ | ✓ | ||||||
S4Hana – Transformation | ✓ | ✓ |
Appendix F – Internal Audit Suite of Services
Alternative text
Office of the Chief Audit Executive (OCAE)
Assurance and Advisory Services
Assurance
- Internal Audits – independent and objective assessments of governance, risk management and control processes against defined criteria
- Data Analytics – automated collection and analysis of data and indicators from IT systems to test the effectiveness of controls
Other Services
- Review Engagements are requested by management seeking independent advice on a matter of importance.
- Health Checks for transformation initiatives to provide formal structured quick reviews covering a specific program aspect
- Funding Milestone Assessments for transformation initiatives to provide formal, structured, and quick validation of milestone completion
- Risk Assessments – assessments of inherent and residual risks to inform management of risk exposure that may require further examination
Professional Practices
Risk-based Audit Plan
A multi-year plan that considers areas of highest risk and significance
Quality Assurance and Improvement Program
Systematic process to ensure IIA Standards are met relating to quality of engagements and internal audit activity
Management Action Plan Follow-Up
Status updates to Departmental Audit Committee of management action plans to address recommendations
External Assurance Liaison
Single point of contact to coordinate activities with external assurance providers
Departmental Audit Committee Secretariat
Coordination of essential part of internal audit governance that provides objective advice and recommendations to the Deputy Minister
Other Support
Contribution to corporate reports, and review and advice regarding Treasury Board submissions and audit reports of multilateral organizations.