OIG
Office of Compliance, California Department of Corrections, Audit Functions, Management Review
Read the report at CDCR ↗
OFFICE OF THE INSPECTOR GENERAL
STEVE WHITE, INSPECTOR GENERAL
• PROMOTING INTEGRITY •
MANAGEMENT REVIEW OF THE AUDIT FUNCTIONS
OF THE CALIFORNIA DEPARTMENT OF CORRECTIONS
OFFICE OF COMPLIANCE
OCTOBER 2002
GRAY DAVIS, GOVERNOR
OFFICE OF THE INSPECTOR GENERAL
STEVE WHITE, INSPECTOR GENERAL
MANAGEMENT REVIEW OF THE AUDIT FUNCTIONS OF THE
CALIFORNIA DEPARTMENT OF CORRECTIONS
OFFICE OF COMPLIANCE
REPORT
OCTOBER 2002
• PROMOTING INTEGRITY •
STATE OF CALIFORNIA CONFIDENTIAL GRAY DAVIS, GOVERNOR
OFFICE OF THE INSPECTOR GENERAL PAGE 1
C
ONTENTS
EXECUTIVE SUMMARY...................................................................................................... 3
INTRODUCTION...................................................................................................................... 4
BACKGROUND................................................................................................................. 4
OBJECTIVES, SCOPE, AND METHODOLOGY................................................. 6
FINDINGS AND RECOMMENDATIONS........................................................................ 8
FINDING 1....................................................................................................................... 8
FINDING 2....................................................................................................................... 9
FINDING 3....................................................................................................................... 12
FINDING 4....................................................................................................................... 14
FINDING 5....................................................................................................................... 15
FINDING 6....................................................................................................................... 17
FINDING 7....................................................................................................................... 19
APPENDIX ................................................................................................................................. 22
ATTACHMENTS
ATTACHMENT A: RESPONSE OF THE DEPARTMENT
OF CORRECTIONS.................................................................... 27
ATTACHMENT B: COMMENTS OF THE OFFICE OF THE INSPECTOR
GENERAL.................................................................................... 41
STATE OF CALIFORNIA CONFIDENTIAL GRAY DAVIS, GOVERNOR
OFFICE OF THE INSPECTOR GENERAL PAGE 2
EXECUTIVE SUMMARY
This report presents the results of a management review conducted by the Office of the Inspector
General of the audit functions of the California Department of Corrections Office of Compliance.
The review, which was performed under the Inspector General’s oversight responsibilities under
California Penal Code Section 6126, examined the management practices and administrative
procedures of the units within the Office of Compliance that carry out performance, financial-
related, and information security audits. The review was conducted in February and March 2002.
The Office of the Inspector General identified serious policy and operational deficiencies as a
result of the review of the auditing activities of the Office of Compliance. The deficiencies
require the attention of the California Department of Corrections. The most important
deficiencies are the following:
• The Office of Compliance does not adhere to appropriate professional standards, calling into
question its ability to accomplish its objectives and meet its assigned responsibilities.
• Audit planning and communication with the department executive staff is inadequate.
• The management of the Program and Fiscal Audits Branch does not target internal audit
activity toward issues that pose the highest risk.
• The Program and Fiscal Audits Branch of the Office of Compliance is not responsive to
executive management requests for special audits.
• The Office of Compliance does not adequately monitor the status of audit projects.
• The Program Compliance Unit of the Program and Fiscal Audits Branch uses a highly
structured auditing approach that may fail to reveal important issues relating to the entities
under audit.
• The audit functions of the California Department of Corrections are fragmented, with a lack
of coordination of audit activities and incomplete coverage of areas requiring audit, resulting
in a failure to comply with state law governing financial accountability.
The Office of the Inspector General recommends that the Department of Corrections consolidate
all of its auditing activities into a professional internal auditing unit consistent with standards
prescribed in Standards for the Professional Practice of Internal Auditing. The chief of internal
audits should report to the chief deputy director for Support Services. The chief of internal
audits should possess training, knowledge, and experience necessary to manage an internal
auditing unit.
STATE OF CALIFORNIA CONFIDENTIAL GRAY DAVIS, GOVERNOR
OFFICE OF THE INSPECTOR GENERAL PAGE 3
INTRODUCTION
California Penal Code Section 6125 established the Office of the Inspector General to provide
oversight of the Youth and Adult Correctional Agency and its subordinate departments. The
management review of the Office of Compliance of the California Department of Corrections
was conducted pursuant to California Penal Code Section 6126, which authorizes the Inspector
General to initiate an investigation or an audit on his own accord to identify areas of
noncompliance with policies and procedures, specify deficiencies, and recommend corrective
actions. The purpose of the review was to determine whether or not the management practices
and administrative procedures relating to the audit functions of the Office of Compliance are
being carried out in accordance with applicable laws, regulations, policies, and procedures. The
review also assessed the efficiency and effectiveness of these functions in fulfilling the
department’s mission and responsibilities, and measured the performance of these functions
based on criteria established by professional standards.
BACKGROUND
The audit functions of the Office of Compliance of the California Department of Corrections
were established to fulfill the requirements of California Penal Code Sections 5057. That section
provides as follows:
Subject to the powers of the Department of Finance under Section 13300 of the Government
Code, the director must establish an accounting and auditing system for all of the agencies and
institutions including the prisons which comprise the department, except the Youth Authority, in
such form as will best facilitate their operation, and may modify the system from time to time.
As specified in California Department of Corrections Operations Manual, Section 11010.26, the
Office of Compliance was established to support and serve the department’s divisions and
offices and to provide internal program audits, external vendor audits, inmate appeal reviews,
and consulting services on management and operational issues. The Office of Compliance is
located at the Aerojet Facility in Rancho Cordova, eighteen miles east of California Department
of Corrections headquarters in Sacramento, California.
In April 2000, the Department of Corrections implemented an operational restructuring and
budget realignment plan, which changed the makeup of the Office of Compliance, rendering
some of the related provisions of the present California Department of Corrections Operations
Manual obsolete. The review by the Office of the Inspector General addresses the organizational
structure of the Office of Compliance in effect at the time of the review, as shown below:
Office of
Compliance
Program and Fiscal Inmate Appeals Information
Audits Branch Branch Security Unit
Fiscal and Business Correctional Program
Management Audits Business Internal Compliance
Unit Audits Unit Unit
STATE OF CALIFORNIA CONFIDENTIAL GRAY DAVIS, GOVERNOR
OFFICE OF THE INSPECTOR GENERAL PAGE 4
At the time of the review, the Office of Compliance was under the management of an assistant
director, who reported to the chief deputy of support services, who in turn reported to the
department director. The office had an operating budget of almost $6 million supporting 80
positions consisting of professional, custody, and clerical staff. Fifty positions were budgeted in
the Program and Fiscal Audits Branch and Information Security Unit, 25 positions were
budgeted for the Inmate Appeals Branch, and five positions served as administrative support for
the office. Since the time of the review, the Department of Corrections has further reorganized
the Office of Compliance. In June 2002, the Office of Compliance was combined with the Office
of Correctional Planning to form the Policy and Evaluation Division. The Program and Fiscal
Audits Branch, the Information Security Office, and the Inmate Appeals Branch now report to
the deputy director of the Policy and Evaluation Division. The deputy director reports to the
chief deputy director of Support Services, who in turn reports to the department director. The
functions and responsibilities of the units included in the Office of the Inspector General’s
review have not changed. Those functions and responsibilities are described below.
Program and Fiscal Audits Branch. The Program and Fiscal Audits Branch, the primary audit
entity within the Department of Corrections, is responsible for providing timely, objective, and
professional audit services to management. The branch consists of the following three units:
• Fiscal and Business Management Audits Unit. The Fiscal and Business Management
Audits Unit is the largest of the three units, with most of the positions in the unit
management auditor positions. The unit is responsible for performing performance and
financial-related audits that include:
(cid:131) Contract and interagency agreement audits that determine whether private contractors are
in conformance with applicable contract provisions, laws, rules and regulations.
(cid:131) Jail rate audits and desk reviews of city and county detention facilities that receive
reimbursement for housing parole violators.
(cid:131) Fiscal consultant activities advising executive management on key issues involving state
laws and regulations, contract terms, and requirements. The unit’s responsibilities also
include providing advice on how to strengthen internal controls and improve program
processes.
• Correctional Business Internal Audits Unit. The Correctional Business Internal Audits Unit
is responsible for performing management assessment audits of business services within the
Department of Corrections. The unit is also responsible for performing special reviews at the
request of management and advises executive management on the status of its internal
business operations. The unit is staffed with seven management auditor positions. The areas
audited include:
(cid:131) Personnel
(cid:131) Inmate trust accounting
(cid:131) Materials management
(cid:131) Food services
(cid:131) Plant operations
(cid:131) Occupational health and safety
(cid:131) Environmental health and safety
(cid:131) Fire protection
STATE OF CALIFORNIA CONFIDENTIAL GRAY DAVIS, GOVERNOR
OFFICE OF THE INSPECTOR GENERAL PAGE 5
• Program Compliance Unit. The Program Compliance Unit conducts performance audits,
which include program compliance audits and court compliance audits at the institutions.
This unit has eight custody positions and one program analyst. The specific programs
audited include:
(cid:131) Administrative segregation and due process
(cid:131) Security of sensitive information
(cid:131) Community correctional facilities
(cid:131) Special audits as requested by executive management.
Inmate Appeals Branch. The Inmate Appeals Branch provides the third and final level of review
for the inmate appeals process, which affords inmates and parolees their due process rights and
offers them the opportunity to address grievances by filing an appeal.
Information Security Unit. The Information Security Unit, which consists of one data
processing manager and one associate information services analyst, is responsible for the overall
security of the department’s information system—a responsibility that includes conducting
information technology security audits. The unit provides institutions with technical support in
the development of individual information disaster recovery plans and serves as the departmental
contact for handling and reporting information security incidents.
OBJECTIVES, SCOPE AND METHODOLOGY
The management review of the audit functions of the Department of Corrections Office of
Compliance examined the policies and procedures developed by the Office of Compliance
management and looked at the extent to which the management of the Department of Corrections
uses the Office of Compliance in addressing key issues facing the department.
The Office of the Inspector General also examined the operations of the Office of Compliance
for adherence to applicable laws, regulations, policies, and procedures, evaluated the quality of
its operational practices, and measured the performance of its audit functions based on criteria
established by professional standards.
The review scope included all operational aspects of the Program and Fiscal Audits Branch and
its three sub-units as delineated earlier. The review of the Information and Security Unit was
limited to obtaining and reviewing work plans and work products and to the unit’s coordination
with executive management and other lateral reporting units within the Office of Compliance.
The Office of the Inspector General reviewed the operations of the Inmate Appeals Branch and
reported findings and recommendations resulting from that review to the director of the
Department of Corrections in February 2001. The Inmate Appeals Branch was not reviewed
during the present engagement.
The review procedures included, but were not necessarily limited to the following:
• Interviews with management and staff from the Office of Compliance;
• Review of policies and procedures related to the operations of the Office of Compliance;
• Review of staff qualifications and continuing education;
STATE OF CALIFORNIA CONFIDENTIAL GRAY DAVIS, GOVERNOR
OFFICE OF THE INSPECTOR GENERAL PAGE 6
• Review of systems used to monitor, track, and manage audits;
• Review of audit reports, audit work papers, and related documentation;
• Review of contracts and related documentation with outside entities used to provide audit
services to the Department of Corrections;
• Review of Department of Corrections budget and expenditure data.
The review was performed during February and March 2002 at the Office of Compliance. The
Office of the Inspector General received excellent cooperation in the course of the review from
the management and staff of the Department of Corrections.
STATE OF CALIFORNIA CONFIDENTIAL GRAY DAVIS, GOVERNOR
OFFICE OF THE INSPECTOR GENERAL PAGE 7
FINDINGS AND RECOMMENDATIONS
FINDING 1
The Office of the Inspector General found that the Program and Fiscal Audits Branch does
not adhere to professional standards for internal auditing.
Under its mission and responsibilities as set out in the California Department of Corrections
Operations Manual, the Program and Fiscal Audits Branch constitutes an “internal audit unit” as
defined by the Institute of Internal Auditors and, as such, is required by state law to abide by the
Standards for the Professional Practice of Internal Auditing. The Office of the Inspector
General found, however, that the branch does not follow the standards and that the Program and
Fiscal Audits Branch management, in fact, is not knowledgeable about their provisions. Many of
the problems identified in other findings in this report can be attributed to the failure to adhere to
the standards, with the problem compounded by a lack of management oversight and direction
from the executive staff at the California Department of Corrections. As a result, the value added
by the auditing efforts of the Program and Fiscal Audits Branch does not appear to be
commensurate with the resources expended.
California Government Code Section 1236 requires all state agencies having their own internal
auditors to adhere to the Standards for the Professional Practice of Internal Auditing of the
Institute of Internal Auditors. The Institute of Internal Auditors describes internal auditing as
follows:
(I)nternal auditing is an independent, objective assurance and consulting activity designed to add
value and improve an organization’s operations. It helps an organization accomplish its
objectives by bringing a systematic, disciplined approach to evaluate and improve the
effectiveness of risk management, control, and governance processes.
The Department of Corrections and the management of the Program and Fiscal Audits Branch,
however, have made no discernible effort to ensure that the branch follows professional internal
auditing standards. In reviewing the branch’s operations, processes, and procedures, the Office
of the Inspector General found a number of areas in which the branch failed to adhere to the
standards.
Some of the most significant departures from standards are listed below. A more complete
summary of the departures from internal auditing standards noted by the Office of the Inspector
General is provided in an Appendix to this report.
• Section 1110 – Organizational Independence. The standard provides: “The chief audit
executive should report to a level within the organization that allows the internal audit
activity to fulfill its responsibilities.” Practice Advisory 1110-1 of the Institute of Internal
Auditors provides additional guidance concerning organizational independence. The
advisory states: “Ideally, the chief audit executive should report functionally to the audit
committee, board of directors, or other appropriate governing authority, and administratively
to the chief executive office of the organization.”
At present the Program and Fiscal Audits Branch reports to the assistant director of the
Office of Compliance, who reports to the chief deputy director for Support Services, who
STATE OF CALIFORNIA CONFIDENTIAL GRAY DAVIS, GOVERNOR
OFFICE OF THE INSPECTOR GENERAL PAGE 8
reports to the department director. A reorganization to allow the Program and Fiscal Audits
Branch to report directly to the chief deputy director for Support Services or to the
department director would more effectively ensure that internal audit activity is free from
interference in determining internal auditing scope, performing work, and communicating
results. The direct reporting relationship would also provide the chief of the Program and
Fiscal Audits Branch with a clear line of communication with respect to department
priorities.
(cid:131) Section 1210 – Proficiency. The standard provides: “Internal auditors should possess the
knowledge, skills and other competencies needed to perform their individual
responsibilities.” The standards often refer to the responsibilities of the “chief audit
executive.” In the case of the Program and Fiscal Audits Branch, the chief is a correctional
administrator who does not have proficiency in applying internal auditing standards,
procedures, or techniques.
(cid:131) Section 1300 – Quality Assurance and Improvement Program. The standard provides:
“The chief audit executive should develop and maintain a quality assurance and improvement
program that covers all aspects of the internal audit activity and continuously monitors its
effectiveness. The program should be designed to help the internal auditing activity add
value and improve the organization’s operations and to provide assurance that the internal
audit activity is in conformity with the Standards and the Code of Ethics.” No such program
presently exists within the Program and Fiscal Audits Branch.
(cid:131) Section 2000 – Managing the Internal Audit Activity. The standard provides: “The chief
audit executive should effectively manage the internal audit activity to ensure it adds value to
the organization.” As discussed more fully in a later finding in this report, the Program and
Fiscal Audits Branch does not use a tracking or information system to provide the
information necessary to determine whether the internal audit activity adds value to the
organization.
FINDING 2
The Office of the Inspector General found that the Program and Fiscal Audits Branch,
which performs most of the department’s audit work, is not effectively communicating
with the department’s executive staff in planning annual audit activities and in reporting
audit performance.
The Office of the Inspector General found a lack of communication between the Department of
Corrections executive staff and the Program and Fiscal Audits Branch. The Program and Fiscal
Audits Branch does not prepare a comprehensive annual work plan as required by professional
auditing standards and by the California Department of Corrections Operations Manual. Nor
does the Program and Fiscal Audits Branch routinely provide reports to the department executive
staff summarizing the results of auditing activities. An annual work plan is an effective means of
providing input to the department’s internal audit function, and periodic reporting to the
executive staff provides a means of evaluating audit performance in relation to the plan. Such
communication is essential in meeting the goals of the department and in realizing the greatest
possible benefit from the internal audit activity, particularly given the magnitude and complexity
STATE OF CALIFORNIA CONFIDENTIAL GRAY DAVIS, GOVERNOR
OFFICE OF THE INSPECTOR GENERAL PAGE 9
of the department’s programs and operations. The absence of communication evident here may
be attributable in part to the fact that the Program and Fiscal Audits Branch is headed by a
correctional administrator with a custody background who may lack the understanding necessary
to managing an audit operation of this size.
Following is a more detailed analysis of the issues involved.
• The Program and Fiscal Audits Branch does not prepare an annual work plan. Although
each unit within the Program and Fiscal Audits Branch prepares its own schedule of audits to
be completed during the year, the branch management does not perform a risk-based
assessment for prioritizing audit projects for the branch as a whole. As a result, instead of the
branch management establishing priority and allocating staff resources accordingly, the
selection of audit assignments is left primarily to the discretion and judgment of the
supervisors and staff of each individual unit within the branch.
The purpose of the annual work plan is to contribute to the effective management of the
internal audit activity by ensuring that scheduled projects add value to the organization. The
development of the annual plan also affords the executive staff an opportunity to provide
input to the planning process in determining audit priority. California Department of
Corrections Operations Manual Sections 22080.8 and 22080.8.1 require the Program and
Fiscal Audits Branch to establish an annual work plan and to distribute the plan to the
executive staff for review and comment. Those requirements are consistent with Section
2010A1 of the Standards for the Professional Practice of Internal Auditing of the Institute of
Internal Auditors, which provides as follows:
The internal audit activity’s plan of engagements should be based on a risk assessment,
undertaken at least annually. The input of senior management and the board should be
considered in this process.
The Office of the Inspector General found that only the Fiscal and Business Management
Audits Unit of the Program and Fiscal Audits Branch submits its annual plan for review and
that only some of the department deputy directors and assistant directors receive the plan.
Moreover, from the responses to the plan and the subsequent actions of the branches, it is
apparent that there is no clear understanding on the part of the department executive staff
about what the reviews are intended to accomplish or, in fact, do accomplish. For example:
• The deputy director of the Department of Corrections Institutions Division, when asked
to review and respond to the Fiscal and Business Management Audits Unit audit plan for
the 2000 calendar year, responded in a hand-written note, “I signed the first one some
time ago & commented that I don’t know why I am signing this, as I don’t know the
issues and don’t have the staff or expertise to do any review which would be of any
value.”
• In a memorandum dated March 16, 2000, a deputy director, in responding to the plan for
2000 calendar year, said that she was given insufficient time to review the list and she
disputed the assertion of the branch that she had been previously contacted for input on
the audits. She also said that the assistant deputy director expected the community
correctional facilities to be audited using the financial management handbook and the
STATE OF CALIFORNIA CONFIDENTIAL GRAY DAVIS, GOVERNOR
OFFICE OF THE INSPECTOR GENERAL PAGE 10
contract between the facility and the department as the basis for the audits. Yet there is
no evidence that this comment was considered.
• In responding to a proposed audit plan for 2001-02 fiscal year on July 6, 2001, an
assistant deputy director requested an immediate audit of a contractor, noting that the
contractor “is not in contract compliance. They are in heavy debt.” The assistant deputy
director further noted that the issue was urgent and was of interest to the director and the
legislature. Yet, that audit request was never formally incorporated into the audit plan
and the audit was not initiated until March 25, 2002, after the Office of the Inspector
General inquired about the status of the request.
• The Program and Fiscal Audits Branch does not routinely report audit performance. The
Office of the Inspector General found minimal evidence that the Program and Fiscal Audits
Branch prepares annual or periodic reports to the executive staff summarizing the results of
the audits. The Program and Fiscal Audits Branch was able to produce only one report—
apparently prepared as a briefing document for the new California Department of Corrections
director in December 2001—summarizing the results of past audit activities and significant
issues identified during past audits. The Office of the Inspector General reviewed the briefing
document and concluded that it was not sufficient to allow management to assess the
workload and activities of the branch and, furthermore, might be somewhat misleading. For
example, the document listed 19 audit projects for the Fiscal and Business Management
Audits Unit as audits performed from January 2001 through October 2001. It reported
approximately $1.4 million as potential cost recovery from the 19 audit projects. A detailed
review of the information, however, reveals that $76,000 had actually been recovered during
the 2001 calendar year. Of the remaining 1.3 million, slightly more than half was attributable
to two audits for which the fieldwork was completed in July 1998—not 2001, and the
balance was from audits that were still pending. Some of the pending audits were far from
completion, raising the possibility that the amounts could change as the audits progressed.
Furthermore, the report failed to disclose the number of audits that had been scheduled, but
not yet performed, an issue discussed in more detail in Finding 5 of this report.
The Standards for the Professional Practice of Internal Auditing address the need for
reporting to senior management in Section 2060—Reporting to the Board and Senior
Management:
The chief audit executive should report periodically to the board and senior management on the
internal audit activity’s purpose, authority, responsibility, and performance relative to its plans.
Reporting should also include significant risk exposures and control issues, corporate
governance issues, and other matters needed or requested by the board and senior management.
• Response by the management of the Office of Compliance. The acting assistant director of
the Office of Compliance told the Office of the Inspector General that he meets with the chief
deputy director of the department every two weeks and that this ensures that the Program and
Fiscal Audits Branch is adequately communicating with executive staff and meeting the
needs of the department. Although regular meetings with the chief deputy director with
responsibility for the Office of Compliance are appropriate, such meetings are not sufficient
STATE OF CALIFORNIA CONFIDENTIAL GRAY DAVIS, GOVERNOR
OFFICE OF THE INSPECTOR GENERAL PAGE 11
to satisfy the requirement for communication with executive staff in planning the audit
activity.
The Office of the Inspector acknowledges that the Program and Fiscal Audits Branch does
provide executive summaries or full copies of audit reports to the deputy director and chief
deputy director of the program under audit to inform them of findings in areas of operation
within their respective responsibilities. Unreasonable delays in issuing audit reports, as
discussed more fully in Finding 5, however, may affect the usefulness of the information.
FINDING 3
The Office of the Inspector General found that the management of the Program and Fiscal
Audits Branch does not target internal audit activity toward issues that pose the highest
risk.
The Office of the Inspector General found no evidence that the Program and Fiscal Audit Branch
management has performed a risk assessment of the Department of Corrections operations to
establish priorities and target issues that pose the highest risk to ensure that audit resources are
deployed in the most efficient and effective manner. As a result, the branch conducts a number of
audits that appear to be unnecessary or that could be performed less frequently, while many other
vital areas of department and institution operations are not audited at all.
The Standards for the Professional Practice of Internal Auditing require the chief audit
executive establish risk-based plans to determine the priorities of the internal audit activity and
ensure that internal audit resources are effectively deployed to achieve the approved plan.
Without a carefully considered risk assessment and appropriate management oversight and
intervention, the department cannot achieve the maximum value possible from its internal audit
resources.
Following are examples of audits of questionable value presently being conducted by the
Program and Fiscal Audit Branch, as well as examples of audits that could be conducted less
frequently:
• Audits of administrative segregation and due process issues. Since at least 1997, the
Program Compliance Unit has been conducting audits of administrative segregation and due
process issues at the state’s 33 adult prisons on a two-year cycle. The intent is to assess the
condition of the institutions’ administrative segregation units to ensure that the inmates’ due
process rights are being observed. In 2001, the branch also began follow-up audits of the
corrective action plans developed in response to previous audit findings. The chief of the
Program and Fiscal Audits Branch said that these audits are conducted under Section 22080.9
of the California Department of Corrections Operations Manual, which requires the Program
and Fiscal Audits Branch to schedule on-site program compliance evaluations for
headquarters divisions and field units no less than once during each two-year period. The
branch chief said that the audits are conducted for the purpose of avoiding litigation. The
Office of the Inspector General noted, however, that many other programs at the institutions
carry the same or greater potential for lawsuits. If the purpose of the audits is to avoid
STATE OF CALIFORNIA CONFIDENTIAL GRAY DAVIS, GOVERNOR
OFFICE OF THE INSPECTOR GENERAL PAGE 12
litigation, focusing all efforts on the administrative segregation unit while failing to audit
other programs and issues at the institutions and at the California Department of Corrections
headquarters that might require more attention appears to be counterproductive.
• Audits of treatment of condemned inmates at San Quentin State Prison. The Program
Compliance Unit conducts quarterly audits of the treatment of condemned inmates at San
Quentin State Prison to ensure compliance with a consent decree that has been in effect since
1980. The Office of the Inspector General noted that the quarterly audits of the treatment of
condemned inmates have resulted in no recent findings of significance, calling into question
the need to continue the audits on a quarterly basis.
• Pelican Bay State Prison use-of-force audits. A June 1996 court order in the Madrid v.
Gomez case required the development of a quarterly audit to be performed by the Department
of Corrections of use of force incidents at Pelican Bay State Prison. Instead, the Program and
Fiscal Audits Branch has been conducting the audits monthly. The court-appointed special
master in the case closely monitored the monthly audits performed by the Program and Fiscal
Audits Branch for the compliance period of February 1999 through December 2000, and, on
April 20, 2001, issued a report praising the audits. In the report, the special master
recommended the termination of additional monitoring of the audits. The recommendation
was adopted by the court on May 10, 2001. The Program and Fiscal Audits Branch has
nonetheless continued to audit the use of force at Pelican Bay State Prison monthly. A review
by the Office of the Inspector General of 13 of the use-of-force audit reports for audits
conducted between January 2001 through January 2002 found that the audits revealed no
substantive findings concerning use-of-force incidents. The special master, moreover, has
told the Office of the Inspector General that the monthly use-of-force audits could be done
less frequently.
• Pelican Bay State Prison health care delivery system audits. The Program Compliance Unit
audits the health care service delivery system at the Pelican Bay State Prison three times a
year. Unit staff told the Office of the Inspector General that these audits are also mandated by
the Madrid v. Gomez case, but the Department of Corrections Legal Division advised the
Office of the Inspector General that the audits are not court-mandated. The court-appointed
special master for the case also told the Office of the Inspector General that he has advised
the California Department of Corrections to discontinue these audits because they provide
little value.
The Office of the Inspector General found no evidence that the management of the Program and
Fiscal Audits Branch has used a risk-based approach in choosing to conduct these repeat audits.
In devoting all of its audit resources to field operations, the branch has failed to audit
headquarters operations and activities, which often pose a higher degree of risk. Furthermore,
California Department of Corrections Operations Manual Section 22080.9 requires the Program
and Fiscal Audit Branch to schedule on-site program compliance evaluations for headquarters
divisions and field units no less than once during each two-year period. The Office of the
Inspector General found, however, that a number of areas determined to be high risk have not
been audited. For example:
STATE OF CALIFORNIA CONFIDENTIAL GRAY DAVIS, GOVERNOR
OFFICE OF THE INSPECTOR GENERAL PAGE 13
• In August 2000, the Department of Finance conducted a risk assessment of Parole and
Community Services Division Parole Regions I and II. The risk assessment revealed
material weaknesses in the division’s management and oversight, as well as inadequate
internal controls in many field offices. The report found, for example, that some field offices
had initiated new financial assistance activities, such as providing parolees with Wal-Mart
gift cards. The cards had not been authorized and their use was not restricted, allowing them
to be used to purchase alcohol, tobacco, and hunting equipment. Yet, the Program and Fiscal
Audits Branch management has not considered the results of this review in scheduling its
audits.
• In March 1999, the Department of Finance conducted an audit of Department of Corrections
headquarters and found material weaknesses in control of department property serious
enough to conclude that no reliance could be placed on the department’s $173 million special
fund property or its $16 million general fund property balances. The chief of the Program and
Fiscal Audit Branch has not considered the results of this audit in scheduling audits.
FINDING 4
The Office of the Inspector General found that the Program and Fiscal Audits Branch is
not responsive to executive management requests for special audits.
Section 22080.8 of the California Department of Corrections Operations Manual requires that
the Program and Fiscal Audits Branch annual work plan include conducting special reviews
requested by department administrators. In reviewing the work schedules of the various units, the
Office of the Inspector General found, however, that such requests have been rare. Some of the
management staff interviewed said they refrain from requesting special audits out of the belief
that the branch staff is too busy. Another reason may be that management requests have not been
given high priority in the past. The examples noted include:
• An audit requested in 1998 still has not been completed. The acting assistant director of the
Office of Community Resources wrote an e-mail to the assistant director of the Office of
Compliance on June 22, 2000 stating:
Please accept this as a formal request…This is a request that your office audit the Inmate Match
Program –Match Two Sponsors. Audit to focus on the provision of services required by the
contract. With shrinking resources, I think the department needs to know quickly whether or not
we are getting a reasonable service for this money. If the audit is done soon, whoever succeeds
me can plan to either continue, rebid (sic), or change the use of the funds. This audit was
originally requested in June, 1998. Now I think it’s imperative that it be done.
The assistant director of the Office of Compliance responded in a memorandum that it would
be difficult to add the audit because of staffing shortages, but that it would be scheduled in
the following calendar year. Fieldwork for the audit finally began on October 2, 2000 and
was completed on November 21, 2000. As of March 18, 2002, the final audit report still had
not been issued.
• An audit requested by an assistant director in April 2000 has not been completed. The
acting assistant director of the Office of Substance Abuse Programs requested a contract
compliance audit of a provider in a letter dated April 10, 2000. The assistant director of the
STATE OF CALIFORNIA CONFIDENTIAL GRAY DAVIS, GOVERNOR
OFFICE OF THE INSPECTOR GENERAL PAGE 14
Office of Compliance instructed the chief of the Program and Fiscal Audits Branch to
schedule an audit by May 2, 2000. Fieldwork was completed July 13, 2000, but as of March
18, 2002, a draft report had not been prepared for this audit.
• An audit requested by an assistant director in February 2000 has not been completed. On
February 28, 2000, the acting assistant deputy director of the Office of Financial
Management and Support Services requested an audit of a contract between the Health Care
Services Division and a medical doctor, noting that the hours billed during a six-month
period appeared to be excessive. The assistant deputy director of the Office of Compliance
forwarded the request to the manager and an audit supervisor of the Fiscal and Business
Management Audits Unit inquiring whether the audit could be performed. Fieldwork was
performed between April 10, 2000 and November 3, 2000, but as of March 18, 2002, an
audit report had not been prepared.
• An audit may have been completed too late to be useful. On January 10, 2000, the Office of
Compliance received a request for an audit of a Los Angeles provider from the chief of the
Women and Children’s Services office of the Department of Corrections. According to the
documentation provided to the Office of the Inspector General staff, the chief made the
request because of numerous fiscal problems with the contractor, including late payment of
vendors. The contract was due to expire on June 30, 2000, and the chief wanted the audit
performed before the close of the contract. In a memorandum to the assistant director of the
Office of Community Resources, the assistant director of the Office of Compliance agreed to
perform the audit only if one other audit planned could be postponed. The audit fieldwork
was performed between July 10, 2000 and September 14, 2000, but the final audit report was
not issued until May 29, 2001—nearly a year after the contract expired. This delay in issuing
the report is not in compliance with the Standards for the Professional Practice of Internal
Auditing, which requires prompt communication of engagement results.
FINDING 5
The Office of the Inspector General found that the Office of Compliance does not monitor
the status of audit projects.
The Office of Compliance does not track the status of audit projects and therefore cannot ensure
that they are completed in a proper and timely manner. The Office of the Inspector General
requested from the management of the Program and Fiscal Audits Branch a listing of audits
completed in recent years and a listing of the status of all current audits. But the branch
management answered that the information was not readily available because the branch does
not use a management information system to record, track, and report the status of audits.
Although a budget is assigned to each audit based on available resources, there are no procedures
for tracking the audit start dates or the hours spent on the assignment either by month or
cumulatively. As a result, management has no formal means of determining whether
assignments are completed within designated budgetary timeframes.
The Office of the Inspector General subsequently received and reviewed a document compiled
by the units within the Program and Fiscal Audits Branch giving the status of various audit
projects and identified a number of deficiencies that could have been addressed by the branch
STATE OF CALIFORNIA CONFIDENTIAL GRAY DAVIS, GOVERNOR
OFFICE OF THE INSPECTOR GENERAL PAGE 15
management if management had been monitoring the status of the audits. The problems noted
included the following:
• Audits are not completed in a timely manner. The annual plan for the 2001-02 fiscal year of
the Fiscal and Business Management Audits Unit lists 24 audits that had begun in previous
years and had not been completed. A review of these carryover assignments shows that the
fieldwork phase of the audits had been completed between March 2, 2000 and August 2001.
But as of March 2, 2002, only two of the 24 audit reports had been completed. In the oldest
case, the total time required to complete audit fieldwork was 17 days (February 14, 2000 to
March 2, 2000), and yet the audit report still had not been completed two years later. The
Office of the Inspector General noted, moreover, that the list in the annual plan was
incomplete, in that it did not reflect all assignments still outstanding. For example, the Office
of the Inspector General found that the final report for an audit for which fieldwork was
completed on May 17, 1999 had not been issued as of March 2002, but the project was not
reflected in the annual plan listing prepared by the Fiscal and Business Management Audit
Unit.
• The Information Security Unit is also not completing its audit reports. The Office of the
Inspector General found that none of the 20 audits performed by the Information Security
Unit in 2001 had been completed and issued as of March 2002.
• Audit productivity at the Fiscal and Business Management Audits Unit is low. The Fiscal
and Business Management Audits Unit is the largest unit within the Program and Fiscal
Audits Branch. Although the unit had six vacant positions at the time of this review, the unit
staff was still comprised of 11 auditors, two analysts, three audit supervisors, and one
manager, for a staffing total of 17 professional positions. Yet the unit completes only a
fraction of its planned audits. In its fiscal year 2001-02 audit plan, the unit listed a total of
101 audits, one of which was erroneously listed twice. As of March 1, 2002, two-thirds of
the way through the fiscal year, the unit had initiated only 17 of the 101 audits in the audit
plan and only one had been completed. According to the work plan, the total budget for the
17 audits was 7,900 hours. Further review revealed that fieldwork on one of the 17 audits
was actually completed during calendar year 2000 and that the final report was issued on
May 29, 2001—indicating that the audit should not have been included in the 2001-02 fiscal
year audit plan. In addition, most of the 17 audits in the audit plan do not appear to be
particularly complex, in that only three were budgeted for 700 hours or more—one for 700
hours, one for 750 hours, and the third for 1,950 hours.
Because the branch does not track the time the staff spend on projects, it is not possible to
determine whether the time devoted to the audit assignments was reasonable. The branch
management has asserted that the six vacant positions precluded the unit from completing all
of the planned assignments, but with a professional staff of 17, one would expect a higher
productivity level in an eight-month period than the completion of four audits, two of which
were carryovers from previous years.
• Unreasonable delays in the processing of final audit reports. At the time of the Office of
the Inspector General’s fieldwork, the Program and Fiscal Audits Branch administrative staff
had numerous draft reports awaiting final editing before they can be issued as final reports.
STATE OF CALIFORNIA CONFIDENTIAL GRAY DAVIS, GOVERNOR
OFFICE OF THE INSPECTOR GENERAL PAGE 16
The staff does not know how many reports are outstanding because the branch administrative
unit does not keep track of how many draft reports it has received and how many have been
released. Consequently, there is no systematic process for assigning priority to the report
workflow. Since at least July 2000, most of the draft audit reports have been significantly
delayed before being issued as final reports. The Office of the Inspector General found, for
example, that of the 12 draft reports issued by the Correctional Business Internal Audits Unit
during the 2000-01 fiscal year, six still had not been issued as final reports as of March 28,
2002. At that time, an average of 303 days had elapsed since the institutions’ corrective
action plans in response to the reports had been received. In one case, the draft report was
issued on July 21, 2000 and the institution’s corrective action plan was received on February
2, 2001; yet, after 419 days, the report still had not been finalized. According to the Office of
Compliance management, the backlog of draft reports has been caused by a lack of clerical
support.
FINDING 6
The Office of the Inspector General found that the Program Compliance Unit of the
Program and Fiscal Audits Branch uses a highly structured auditing approach that may
fail to reveal important issues relating to the entities under audit.
The Program Compliance Unit uses a highly structured approach for most of its audits in which
the staff develops a checklist identifying the program requirements for each of the programs
audited and then performs reviews to determine the degree of compliance with the program
requirements. For example, for audits of community correctional facilities, the Program
Compliance Unit uses a checklist that includes 82 compliance requirements to be reviewed. In
conducting the audit, the audit team assesses the audited entity’s operations and assigns a rating
of compliance, partial compliance, noncompliance, not applicable, or not ratable to each of the
requirements on the checklist. The rating is summarized with a total score showing the
percentage of the program requirements that the audit team found to be in compliance.
From a processing standpoint, the checklist approach has the advantage of being easy to
administer, as it clearly prescribes the audit parameters by listing the areas to be audited and the
criteria for evaluating compliance. In addition, the checklist approach requires little report
preparation time, as the staff simply assigns a rating with brief explanatory comments explaining
the basis for each rating. But conducting audits using this structured approach carries the risk that
material issues not included in the checklist may be overlooked. An audit of the Folsom
Community Correctional Facility conducted by the Program Compliance Unit provides an
example. In that audit, which was conducted in August 2000 with a report issued more than a
year later on September 13, 2001, the Program Compliance Unit assigned the facility a 90
percent compliance rate with no findings of apparent significance. The Office of the Inspector
General, in contrast, conducted an audit of the same entity and issued a report on January 15,
2002 that identified numerous significant on-going problems and recommended that the state
terminate its contract with the City of Folsom for the operation of the facility. The scope of the
audit conducted by the Office of the Inspector General of the Folsom Community Correctional
Facility was similar to the scope of the audit conducted by the Program Compliance Unit.
Moreover, the problems identified by the Office of the Inspector General existed at the time the
STATE OF CALIFORNIA CONFIDENTIAL GRAY DAVIS, GOVERNOR
OFFICE OF THE INSPECTOR GENERAL PAGE 17
Program Compliance Unit conducted its audit. In reviewing and analyzing the Program
Compliance Unit audit report, the Office of the Inspector concluded that the differences in the
audit results were caused by the following:
• The Program Compliance Unit checklist is overly limited. The checklist used by the
Program Compliance Unit did not cover some of the issues noted by the Office of the
Inspector General because the issues were unique to the Folsom Community Correctional
Facility. For example, the audit by the Office of the Inspector General revealed significant
problems with the operation of the facility’s recycling plant and program. The checklist used
by the Program Compliance Unit contains no provision in this regard since no other
community correctional facility operates a recycling plant. Similarly, while the Office of the
Inspector General report identified significant health and safety problems at the recycling
plant resulting from exposure of the staff and inmates to hazardous working conditions,
medical waste, and chemical spills, the Program Compliance Unit report rated the facility as
in compliance in the area of safety. The Program Compliance Unit was able to issue this
rating because the checklist calls for evaluating only whether the facility has written
procedures governing fire safety, whether quarterly fire drills are conducted, and whether
there are written procedures governing hazardous material. The audit checklist does not
provide for considering whether such procedures are adequate or whether they are followed.
• The Program Compliance Unit audit did not fully validate information in documents. In
the area of program cost reports, for example, the Program Compliance Unit audit team
purportedly “examined Folsom CCF’s quarterly and annual program cost reports and
interviewed staff.” The audit concluded that the facility was in compliance because it
submitted the quarterly and annual reports to the California Department of Corrections. The
Office of the Inspector General reviewed the program cost reports and other financial reports
and found evidence of widespread fiscal mismanagement at the Folsom Community
Correctional Facility, as well as misinformation about fiscal matters and misdirection of
funds intended to benefit inmates. In reviewing the composition of the Program Compliance
Unit audit team members assigned to this audit, the Office of the Inspector General noted that
all members have custody background and none possesses the experience and skill necessary
to properly evaluate the program cost issues.
• The Program Compliance Unit audit placed too much reliance on superficial factors. The
Program Compliance Unit audit of the Folsom Community Correctional Facility relied
heavily on surface appearances, staff representations, and the existence of written policies
and procedures. It is apparent from the audit report that much of the audit work of the
Program Compliance Unit consisted of cursory observation, staff interviews, and
determination of whether written policies or procedures governing the area under audit
existed. Although these are necessary and appropriate audit steps, they do not constitute
sufficient and competent evidence for drawing conclusions. Written policies and procedures
may have been intentionally or unintentionally ignored. Staff interviews do not always
provide accurate and reliable results. Systemic deficiencies or hazardous conditions may not
be apparent at the time the audit staff makes its observation and may require closer
examination of records and documents.
STATE OF CALIFORNIA CONFIDENTIAL GRAY DAVIS, GOVERNOR
OFFICE OF THE INSPECTOR GENERAL PAGE 18
Program Compliance Unit audits do not identify causes or recommend solutions. The Office of
the Inspector General found in addition that although the checklist audit approach may identify
instances of noncompliance with program requirements, the Program Compliance Audit staff has
made little attempt to place issues into perspective by quantifying the cause and effect of the
problems. Nor does the Program Compliance Unit recommend changes to resolve the problems.
Instead, it relies on the entity under audit to provide a corrective action plan to address the
problems—yet, it is often not possible to assess the adequacy of the corrective action plan unless
the causes and effects of the problems have been identified. For example, in the Folsom
Community Correctional Facility audit performed in April 1999, the Program Compliance Unit
staff found that the facility did not provide a pre-release program meeting program requirements.
The facility responded by stating that budget reductions by the California Department of
Corrections in 1993 had eliminated funding for the program and that the facility could not
provide the service without additional funding. Following the checklist approach, the Program
Compliance Unit did not pursue the issue further by analyzing the underlying cause and effect of
this important matter—even though the very mission of a community correctional facility is to
prepare inmates for parole. Then, during a second audit of the facility conducted by the Program
Compliance Unit in August 2000, the staff judged the requirement for a pre-release program “not
ratable” because of the “discontinued budget for this program,” as asserted by the Folsom
Community Correctional Facility. Because the Program Compliance Unit audit team did not
include anyone with a financial auditing background, the audit team was not aware that the
contract budget for the Folsom Community Correctional Facility provided $41,000 for inmate
programs, yet the city only spent between $796 and $10,877 on inmate programs for each of the
fiscal years from 1997 through 2001. In reviewing past reports issued by the Program
Compliance Unit of audits conducted on a cyclical basis, the Office of the Inspector General
further noted that many findings were repeated from audit to audit, suggesting that the
institutions had failed to address the cause of the problems or to provide remedies.
FINDING 7
The Office of the Inspector General found that the audit functions of the California
Department of Corrections are fragmented, with a lack of coordination of audit activities
and incomplete coverage of areas requiring audit, resulting in a failure to comply with state
law governing financial accountability.
Other units within the Department of Corrections in addition to the Program and Fiscal Audits
Branch are engaged in audit activities. The Program Development Unit of the Parole and
Community Services Division conducts audits of designated reentry programs as well as audits
of contractors providing services to parolees. The department also recently formed a resource
review team to conduct audits of state prison programs and operations on an institution-wide
basis. In addition, the Department of Finance conducts audits of various aspects of Department
of Corrections operations. For example, the Department of Finance has statutory responsibility
for performing audits of state prison inmate welfare funds. In the 1998-99 fiscal year budget, the
Department of Finance received an increase in its budget of four positions and a redirection of
seven positions to conduct internal control audits for the Department of Corrections. Subsequent
to the audit by the Office of the Inspector General of the Folsom Community Correctional
STATE OF CALIFORNIA CONFIDENTIAL GRAY DAVIS, GOVERNOR
OFFICE OF THE INSPECTOR GENERAL PAGE 19
Facility, the department also entered into an interagency agreement with the Department of
Finance to conduct audits of all community correctional facilities.
Despite the resources available to the Department of Corrections for auditing department
operations, the Office of the Inspector General found that the department has not established a
mechanism for planning and coordinating audit activities to eliminate gaps in coverage and avoid
possible duplication of effort. As a result:
• The department is not complying with state law. Under the Financial Integrity and State
Manager’s Accountability Act of 1983, state agency heads are responsible for establishing
and maintaining a system or systems of internal accounting and administrative control within
their agencies. The act requires the agency head to prepare and submit a report on the
adequacy of the agency systems of internal accounting and administrative controls on a two-
year cycle. The Department of Finance has issued an audit guide that separates internal
controls into five transaction cycles: budget, income, expenditures, fixed assets, and financial
reporting. The cycle approach assists the auditor in identifying the flow of transactions from
the point of authorization through execution, the recording of transactions, and accountability
for any assets. Under the California Department of Corrections Operations Manual, the
Program and Fiscal Audits Branch is responsible for conducting internal and fiscal
compliance audits to ensure compliance with the Financial Integrity and State Manager’s
Accountability Act.
As mentioned previously, in the 1998-99 fiscal year budget, the Department of Finance
received an increase in its budget of four positions and a redirection of seven positions to
conduct internal control audits for the Department of Corrections. In reviewing the various
audit activities conducted by the California Department of Corrections and the Department of
Finance, the Office of the Inspector General found that there has not been an audit of the
budget cycle or the financial reporting cycle of the Department of Corrections since at least
1995. Moreover, citing budgetary constraints, the Department of Finance has not developed
a plan or assigned staff resources to perform internal control audits of the California
Department of Corrections. Yet, apparently under the belief that the Department of Finance
will continue to perform the internal control audits, the Program and Fiscal Audits Branch
management is proposing to delete from its responsibilities the requirement that it conduct
internal and fiscal compliance audits to ensure compliance with the Financial Integrity and
State Manager’s Accountability Act.
The Office of the Inspector General also found that department administrators appear to lack
the understanding of internal control issues and necessary corrective actions needed to fulfill
the department’s reporting responsibility under the Financial Integrity and State Manager’s
Accountability Act. For example, the department director who certified the adequacy of the
department’s internal controls in a December 31, 2001 document relied in part on
Department of Finance “audits” of two parole regions that in fact were not audits, but only
limited scope surveys. The surveys disclosed significant problems resulting from weak
management and internal control at the two parole regions. When the survey disclosed the
deficiencies, the next reasonable step would have been for the director to order a full-scale
audit to quantify the possible extent of the problems. Instead, the department simply took
actions to address the specific issues noted in the survey without requesting an audit of the
STATE OF CALIFORNIA CONFIDENTIAL GRAY DAVIS, GOVERNOR
OFFICE OF THE INSPECTOR GENERAL PAGE 20
two parole regions (and the two other parole regions) by either the Department of Finance or
the Program and Fiscal Audits Branch.
• Audit efforts may be duplicated. The recently established resource review team was formed
to perform cyclical reviews of the operations, programs, and activities of the state prisons on
an institution-wide basis. Meanwhile, the Program and Fiscal Audits Branch also conducts
audits and reviews of selected operations and functions, such as administrative segregation
units, business offices, and information security units within institutions. There appears to be
limited coordination between the units to avoid duplication of effort.
RECOMMENDATION
The Office of the Inspector General recommends that the California Department of
Corrections consolidate all department auditing activities into a professional
internal auditing unit consistent with standards prescribed in Standards for the
Professional Practice of Internal Auditing. The chief of internal audits should
possess the training, knowledge, and experience to manage an internal auditing unit
and should report to the chief deputy director for Support Services.
STATE OF CALIFORNIA CONFIDENTIAL GRAY DAVIS, GOVERNOR
OFFICE OF THE INSPECTOR GENERAL PAGE 21
APPENDIX
Departures from the Standards for the Professional Practice of Internal Auditing noted by the
Office of the Inspector General in its review of the Program and Fiscal Audits Branch.
SECTION STANDARDS FOR THE PROFESSIONAL PRACTICE OF INTERNAL
NUMBER ACCOUNTING
ATTRIBUTE STANDARD DEPARTURE FROM STANDARD
1110 Organizational Independence
The chief audit executive should report to a level The chief of the Program and Fiscal Audits Branch
within the organization that allows the internal audit reports to the assistant director of the Office of
activity to fulfill its responsibilities. Compliance, who reports to the chief deputy director
for Support Services, who reports to the department
director. Ideally, the chief audit executive should
report functionally to the audit committee, board of
directors, or other appropriate governing authority,
and administratively to the chief executive officer of
the organization.
1210 Proficiency
Internal auditors should possess the knowledge, skills, Neither the current nor the former chief of the
and other competencies needed to perform their Program and Fiscal Audits Branch has had audit
individual responsibilities. The internal audit activity experience or training. Similarly, many staff
collectively should possess or obtain the knowledge, members have had no audit experience or training.
skills, and other competencies needed to perform its
responsibilities.
1230 Continuing Professional Development
Internal auditors should enhance their knowledge, No evidence exists that Program and Fiscal Audits
skills, and other competencies through continuing Branch auditors obtained education that would
professional development. provide information about improvements and
current developments in internal auditing standards.
1300 Quality Assurance and Improvement Program
The chief audit executive should develop and No such program exists. The Program and Fiscal
maintain a quality assurance and improvement Audits Branch does not use a tracking system to
program that covers all aspects of the internal audit provide even basic information.
activity and continuously monitors its effectiveness.
The program should be designed to help the internal
auditing activity add value and improve the
organization’s operations and to provide assurance
that the internal audit activity is in conformity with
the Standards and the Code of Ethics.
1310 Quality Program Assessments
The internal audit activity should adopt a process to No such program exists.
monitor and assess the overall effectiveness of the
quality program. The process should include both
internal and external assessments.
1311 Internal Assessments
Internal assessments should include: No such assessment exists.
• Ongoing reviews of the performance of the
internal audit activity; and
STATE OF CALIFORNIA CONFIDENTIAL GRAY DAVIS, GOVERNOR
OFFICE OF THE INSPECTOR GENERAL PAGE 22
• Periodic reviews performed through self-
assessment or by other persons within the
organization, with knowledge of internal auditing
practices and the Standards.
1312 External Assessments
External assessments, such as quality assurance No evidence of such assessment exists.
reviews, should be conducted at least once every five
years by a qualified, independent reviewer or review
team from outside the organization.
1320 Reporting on the Quality Program
The chief audit executive should communicate the No evidence of such assessment exists.
results of external assessments to the board.
1330 Use of “Conducted in Accordance with the
Standards”
Internal auditors are encouraged to report that their Standards for the Professional Practice of Internal
activities are “conducted in accordance with the Auditing not followed by the Program and Fiscal
Standards for the Professional Practice of Internal Audits Branch.
Auditing.” However, internal auditors may use the
statement only if assessments of the quality
improvement program demonstrate that the internal
audit activity is in compliance with the Standards.
1340 Disclosure of Noncompliance
Although the internal audit activity should achieve Standards for the Professional Practice of Internal
full compliance with the Standards and internal Auditing not followed by the Program and Fiscal
auditors with the Code of Ethics, there may be Audits Branch.
instances in which full compliance is not achieved.
When noncompliance impacts the overall scope or
operation of the internal audit activity, disclosure
should be made to senior management and the board.
PERFORMANCE STANDARDS
2000 Managing the Internal Audit Activity
The chief audit executive should effectively manage The Program and Fiscal Audits Branch does not use
the internal audit activity to ensure it adds value to the a tracking or information system to provide the
organization. information necessary to determine if the internal
audit activity adds value to the organization. (See
Finding 5)
2010 Planning
The chief audit executive should establish risk-based The Program and Fiscal Audits Branch does not
plans to determine the priorities of the internal audit perform risk-based analysis for the purpose of
activity, consistent with the organization’s goals. setting priorities. Each unit within the branch
separately prepares a schedule of audits to be
completed during the year. The branch does not
assess and prioritize the audit projects proposed by
the units to develop a comprehensive work plan for
the branch. (See Finding 2)
2010.A1 The internal audit activity’s plan of engagements Same as above. (See Finding 2)
should be based on a risk assessment, undertaken at
least annually. The input of senior management and
the board should be considered in this process.
STATE OF CALIFORNIA CONFIDENTIAL GRAY DAVIS, GOVERNOR
OFFICE OF THE INSPECTOR GENERAL PAGE 23
2020 Communication and Approval
The chief audit executive should communicate the The plans are not submitted to all executive staff for
internal audit activity’s plans and resource review and comment. (See Finding 2)
requirements, including significant interim changes, to
senior management and to the board for review and
approval. The chief audit executive should also
communicate the impact of resource limitations.
2030 Resource Management
The chief audit executive should ensure that internal The Program and Fiscal Audits Branch management
audit resources are appropriate, sufficient, and has no system or procedures in place to properly
effectively deployed to achieve the approved plan. manage audit resources. (See Findings 3 and 5)
2040 Policies and Procedures
The chief audit executive should establish policies and The Program and Fiscal Audits Branch has no
procedures to guide the internal audit activity. written policies or procedures for the guidance of the
internal audit activity. The Fiscal Business
Management Audits Unit has an audit manual, but it
does not follow the correct standards.
2050 Coordination
The chief audit executive should share information Minimal coordination exists of audits between the
and coordinate activities with other internal and Program and Fiscal Audits Branch and other groups
external providers of relevant assurance and conducting audits. (See Finding 7)
consulting services to ensure proper coverage and
minimize duplication of efforts.
2060 Reporting to the Board and Senior Management
The chief audit executive should report periodically to No evidence of any such reporting was found except
the board and senior management on the internal audit for a briefing document filed in December 2001.
activity’s purpose, authority, responsibility, and (See Finding 2)
performance relative to its plan. Reporting should
also include significant risk exposures and control
issues, corporate governance issues, and other matters
needed or requested by the board and senior
management.
2100 Nature of Work
The internal audit activity evaluates and contributes to Audits performed by the Program and Fiscal Audits
the improvement of risk management, control and Branch provide little value in the improvement of
governance systems. risk management, control, and governance systems.
2110 Risk Management
The internal audit activity should assist the The audit objectives of the Program Compliance
organization by identifying and evaluating significant Unit do not address risks, controls, and governance
exposures to risk and contributing to the improvement process.
of risk management and control systems.
2120.A1 Based on the results of the risk assessment, the Few of the Program and Fiscal Audits Branch audit
internal audit activity should evaluate the adequacy activities are risk-based.
and effectiveness of controls encompassing the
organization’s governance, operations, and
information systems. This should include:
• Reliability and integrity of financial and
operational information.
• Effectiveness and efficiency of operations.
STATE OF CALIFORNIA CONFIDENTIAL GRAY DAVIS, GOVERNOR
OFFICE OF THE INSPECTOR GENERAL PAGE 24
• Safeguarding of assets.
• Compliance with laws, regulations, and contracts.
2120.A2 Internal auditors should ascertain the extent to which No evidence of such evaluation exists.
operating and program goals and objectives have been
established and conform to those of the organization.
2120.A3 Internal auditors should review operations and No evidence of such evaluation exists.
programs to ascertain the extent to which results are
consistent with established goals and objectives to
determine whether operations and programs are being
implemented or performed as intended.
2120.A4 Adequate criteria are needed to evaluate controls. No evidence of such evaluation exists.
Internal auditors should ascertain the extent to which
management has established adequate criteria to
determine whether objectives and goals have been
accomplished. If adequate, internal auditors should
use such criteria in their evaluation. If inadequate,
internal auditors should work with management to
develop appropriate evaluation criteria.
2130 Governance
The internal audit activity should contribute to the No evidence of such evaluation exists.
organization’s governance process by evaluating and
improving the process through which (1) values and
goals are established and communicated, (2) the
accomplishment of goals is monitored, (3)
accountability is ensured, and (4) values are
preserved.
2130.A1 Internal auditors should review operations and No evidence of such evaluation exists.
programs to ensure consistency with organizational
values.
2200 Engagement Planning
Internal auditors should develop and record a plan for Program Compliance Unit and Correctional
each engagement Business Internal Audits Unit are structured with
an audit instrument (checklist) that is used for
each audit. Planning is not done for each
individual audit.
2201 Planning Considerations
In planning the engagement, internal auditors should Only the Fiscal Business Management Audit Unit
consider: prepares audit-planning memoranda. However,
• The objectives of the activity being reviewed and elements in the memoranda are not fully developed.
the means by which the activity controls its
performance.
• The significant risks to the activity, its objectives,
resources, and operations and the means by which
the potential impact of risk is kept to an
acceptable level.
• The adequacy and effectiveness of the activity’s
risk management and control systems compared
to a relevant control framework or model.
• The opportunities for making significant
improvements to the activity’s risk management
and control systems.
STATE OF CALIFORNIA CONFIDENTIAL GRAY DAVIS, GOVERNOR
OFFICE OF THE INSPECTOR GENERAL PAGE 25
2210 Engagement Objectives
The engagement’s objectives should address the risks, No evidence that such objectives have been
controls, and governance processes associated with considered during the audit process.
the activities under review.
2210.A1 When planning the engagement, the internal auditor No evidence that such evaluation exists.
should identify and assess risks relevant to the activity
under review. The engagement objectives should
reflect the results of the risk assessment.
2210.A2 The internal auditor should consider the probability of No evidence that such evaluation exists.
significant error, irregularities, noncompliance, and
other exposures when developing the engagement
objectives.
2220 Engagement Scope
The established scope should be sufficient to satisfy Because the Program Compliance Unit and the
the objectives of the engagement. Correctional Business Unit use checklist type audit
instruments, the scope of the audit is predetermined
and is not established for each individual audit.
2220.A1 The scope of the engagement should include Scope is predetermined and is not established for
consideration of relevant systems, records, personnel, each individual audit.
and physical properties, including those under the
control of third parties.
2400 Communicating Results
Internal auditors should communicate the engagement Audit reports are not issued in a timely manner.
results promptly. (See Finding 5)
2410 Criteria for Communicating
Communications should include the engagement’s Reports do not always clearly quantify the cause and
objectives and scope as well as applicable effect of the problems and make recommendations
conclusions, recommendations, and action plans. to resolve the problems (See Finding 5)
2420 Quality of Communications
Communications should be accurate, objective, clear, Same as above.
concise, constructive, complete, and timely.
2500 Monitoring Progress
The chief audit executive should establish and The Program and Fiscal Audits Branch has no
maintain a system to monitor the disposition of results formal system to monitor the progress of corrective
communicated to management. action taken by management.
2500.A1 The chief audit executive should establish a follow-up The Program and Fiscal Audits Branch has no
process to monitor and ensure that management formal system to monitor the progress of corrective
actions have been effectively implemented or that action taken by management.
senior management has accepted the risk of not taking
action.
STATE OF CALIFORNIA CONFIDENTIAL GRAY DAVIS, GOVERNOR
OFFICE OF THE INSPECTOR GENERAL PAGE 26
ATTACHMENT A
RESPONSE OF THE DEPARTMENT OF CORRECTIONS
STATE OF CALIFORNIA CONFIDENTIAL GRAY DAVIS, GOVERNOR
OFFICE OF THE INSPECTOR GENERAL PAGE 27
ATTACHMENT B
COMMENTS OF THE OFFICE OF THE INSPECTOR GENERAL
STATE OF CALIFORNIA CONFIDENTIAL GRAY DAVIS, GOVERNOR
OFFICE OF THE INSPECTOR GENERAL PAGE 41
COMMENTS OF THE OFFICE OF THE INSPECTOR GENERAL
ON THE RESPONSE OF THE DEPARTMENT OF CORRECTIONS TO THE DRAFT REPORT
FINDING 1
The department maintains that the Program and Fiscal Audits Branch is not an
internal audit organization and therefore is not required to adhere to the Standards
for the Professional Practice of Internal Auditing. This contention is incorrect and
illustrates a lack of understanding of the internal audit function.
Although it is true that the California Department of Corrections Operations
Manual does not reflect all of the structural and policy changes that have occurred
over the years, the mission of the Program and Fiscal Audits Branch as described in
Sections 11010.26.3 and 22080.3 of the manual remains the same:
The Program and Fiscal Audits Branch exists to independently review, evaluate, and
better assure that institutions, parole regions, and headquarters are operated in
accordance with CDC standards, State and federal law, and court mandates.
PFAB shall assist the Director and other departmental executives with increasing the
effectiveness of management by systematically reviewing departmental activities to
provide recommendations for improvements.
These statements embody the very definition of internal auditing as set forth in the
Standards for the Professional Practice of Internal Auditing of the Institute of
Internal Auditors — standards to which California Government Code Section 1236
specifically requires all state agencies that have their own internal auditors or that
perform internal audit activities adhere. That definition reads:
[I]nternal auditing is an independent, objective assurance and consulting activity
designed to add value and improve an organization’s operations. It helps an
organization accomplish its objectives by bringing a systematic, disciplined
approach to evaluate and improve the effectiveness of risk management, control, and
governance processes.
As the department explains in its response, the Program and Fiscal Audits Branch
consists of three audit units, each of which performs specific types of audits — but
the essential factor to note is that all of the audits are performed for the purpose of
providing Department of Corrections management with information needed to
evaluate and improve department operations. Regardless of how the audits conducted
by the Program and Fiscal Audits Branch are labeled —“management assessment
reviews” “program compliance audits,” or “management reviews”— they fall into the
meaning of internal audit activity under California Government Code Section 1236
and as such are required to be conducted in accordance with the Standards for the
Professional Practice of Internal Auditing.
STATE OF CALIFORNIA CONFIDENTIAL GRAY DAVIS, GOVERNOR
OFFICE OF THE INSPECTOR GENERAL PAGE 42
The department also asserts in its response that the department was relieved of its
duty to comply with the Standards for the Professional Practice of Internal Auditing
when it transferred responsibility for performing internal control audits formerly
conducted by its internal audit unit to the Department of Finance. But transferring
those audits to another department does not relieve the Department of Corrections of
responsibility for adhering to the Standards for the Professional Practice of Internal
Auditing for all of its other internal audit activities.
The department further asserts that the Fiscal and Business Management Audits Unit
of the Program and Fiscal Audits Branch adheres to Generally Accepted Government
Auditing Standards, and that those standards, rather than the Standards for the
Professional Practice of Internal Auditing, are appropriate for the work that unit
performs. Although using Generally Accepted Government Auditing Standards for
specific types of outside audit engagements may be beneficial and is not prohibited,
the Fiscal and Business Management Audits Unit, as a component of a larger internal
audit organization, is nonetheless required by law to adhere to the Standards for the
Professional Practice of Internal Auditing in conducting internal audits. When
Generally Accepted Government Auditing Standards are to be used, the management
of the audit organization must carefully assess the audit work to be performed to
ensure that appropriate standards are followed.
That other state agencies may follow generally accepted government auditing
standards is irrelevant. The work performed by the Program and Fiscal Audits Branch
constitutes internal audit activity, and as such, must be conducted according to the
Standards for the Professional Practice of Internal Auditing. Not only does
California Government Code Section 1236 require that the standards be followed for
internal audit work, California Government Code Section 1239 requires agencies to
obtain a waiver from the Joint Legislative Audit Committee if the standards are to be
waived.
We would further point out that following the Standards for the Professional Practice
of Internal Auditing would effectively address the problems described in the
remaining findings of this report. Although, as the department correctly noted in its
response, Generally Accepted Government Auditing Standards are similar in some
respects to the Standards for the Professional Practice of Internal Auditing, the latter
provide essential management components lacking in the former.
FINDING 2
The response from the department reflects an apparent misinterpretation of Finding 2.
The finding makes two separate points: First, that the Program and Fiscal Audits
Branch does not prepare the comprehensive annual work plan required by
professional auditing standards and by the California Department of Corrections
Operations Manual; and second, that it does not communicate effectively with the
department executive staff in planning annual audit activities and reporting audit
performance.
STATE OF CALIFORNIA CONFIDENTIAL GRAY DAVIS, GOVERNOR
OFFICE OF THE INSPECTOR GENERAL PAGE 43
The department acknowledges that the branch does not prepare an annual work plan,
but goes on to describe the reporting of individual audit findings to the wardens,
deputy directors, and chief deputy directors. The Office of the Inspector General
described that system of reporting in the last paragraph of Finding 2. The substance of
Finding 2, however, is that the department executive staff does not actively
participate in the audit planning process and that the Program and Fiscal Audits
Branch does not provide management with necessary information about overall audit
activities. The finding speaks to the need for a periodic reporting to the executive
staff on internal audit activity performance as a whole. The purpose of this reporting
is not to communicate individual audit findings, but rather to evaluate how the audit
department’s performance is helping to fulfill the purpose and responsibilities of the
agency.
FINDING 3
That the Program and Fiscal Audits Branch has begun to re-evaluate the need and
frequency of the audit projects is a positive development, but the response gives no
indication that the management of the Program and Fiscal Audits Branch is using a
risk based approach to determine audit priorities, which is the main point of the
finding.
FINDING 4
The department’s response merely serves to underscore the finding that the Program
and Fiscal Audits Branch is not responsive to executive management requests for
special audits and that, apparently as a result, such requests have been rare. With 50
auditing positions, a well-managed internal audit organization should have conducted
many more special audits over a four-year period than the handful cited in the
department’s response. A review of the list of special requests presented in the
department’s response, moreover, reveals that most were limited to specific segments
of the institutions’ operations and that none related to department-wide policies and
procedures.
FINDING 5
The audit plan provided to the Office of the Inspector General staff lists 101 audits in
the fiscal year June 30, 2002 in addition to 24 audits reported as in progress and
carried over from previous years. Although the Program and Fiscal Audits Branch
management now claims in its response that a single audit may consist of multiple
contracts, the audit plan provided to the Office of the Inspector General individually
lists each contract with a separate audit hour budget assigned and the criteria used to
select the individual contract for audit. To argue that several of the contracts actually
represent one audit is disingenuous and appears to be an attempt to divert attention
from the fact that nearly three quarters of the way through the fiscal year, and with an
auditing staff of 50 positions, only one final audit report has been issued.
STATE OF CALIFORNIA CONFIDENTIAL GRAY DAVIS, GOVERNOR
OFFICE OF THE INSPECTOR GENERAL PAGE 44
FINDING 6
The division management argues that the checklist approach used by the Program
Compliance Unit in performing audits of the Folsom Community Correctional
Facility was appropriate because the audits were limited in scope. The Office of the
Inspector General agrees that a narrow audit scope may be appropriate in particular
circumstances in order to provide management with a focused response to a specific
question. But the checklist method also precludes broadening the scope of an audit in
situations where evidence suggests the need for an expanded scope and encourages a
tunnel vision that hinders auditors in providing management with a thorough
assessment of the overall operation of the facility. The audits of the Folsom
Community Correctional Facility provide an excellent example of how a highly
structured audit approach may fail to reveal important issues relating to the entity
under audit.
The division also points out that separate audits were performed on the Folsom
Community Correctional Facility by the Program Compliance Unit and by the Fiscal
and Business Management Audits Unit. But this fragmented audit approach obscures
the relationship of financial matters to other programs in the facility and hinders the
ability of management to consider the information in its totality.
The methodology used by the Office of the Inspector General in auditing the Folsom
Community Correctional Facility is not unique to the Office of the Inspector General,
but rather has been developed by professional authoritative bodies and is well
accepted by practitioners in the profession. The finding points to the need for using
experienced auditors in developing audit plans, audit programs, and audit procedures
to carry out the department’s auditing function.
FINDING 7
Although the Department of Corrections has taken steps to consolidate some of its
audit activities, audits are still being conducted outside the Program and Fiscal Audits
Branch. This fragmented approach does not lend itself to an efficient and effective
audit function. In addition, despite the division management’s argument to the
contrary, the Department of Corrections cannot absolve itself of its own
responsibilities under the Financial Integrity and State Managers Accountability Act
by virtue of having transferred its internal control audits to the Department of
Finance. The Department of Corrections director retains ultimate responsibility for
internal and administrative control of the department, and the internal control audits
the Department of Finance is funded to perform remain an integral part of
establishing management accountability.
STATE OF CALIFORNIA CONFIDENTIAL GRAY DAVIS, GOVERNOR
OFFICE OF THE INSPECTOR GENERAL PAGE 45