​​​

Audit and Advisory Services Division Charter​​

THE CALIFORNIA STATE UNIVERSITY
AUDIT AND ADVISORY SERVICES CHARTER

Establishment

Education Code Section 89045, enacted by Chapter 1406 of the Statutes of 1969, provides for the establishment of an internal auditing function reporting directly to the Trustees of the California State University.

Purpose

The purpose of Audit and Advisory Services is to strengthen the California State University’s (CSU) ability to create ,protect, and sustain value by providing the Trustees and management with independent, risk-based, and objective assurance, advice, insight, and foresight. Audit and Advisory Services will carry out its mandate by bringing a systematic, disciplined approach to evaluate and improve the effectiveness of risk management, control, and governance processes across the CSU.

Standards for the Professional Practice of Internal Auditing

Audit and Advisory Services is committed to the professional practice of internal auditing and will govern itself by adherence to the elements of the Institute of Internal Auditors’ International Professional Practices Framework, including the Global Internal Audit Standards, Topical Requirements, and Global Guidance (the Standards).

The Vice Chancellor and Chief Audit Officer will report periodically to senior management and the Trustees regarding Audit and Advisory Services’ conformance to the Standards.

Organization and Authority

The Vice Chancellor and Chief Audit Officer reports directly to the Board and reports administratively to the Chancellor for purposes of general administration, staff personnel, budget, and space, and is evaluated by the Board following consultation with the Chancellor.

Oversight of the audit function provided by Audit and Advisory Services, including the priority of work assignments, shall be the responsibility of the Committee on Audit, which shall report on such matters to the Board of Trustees. To establish, maintain, and assure that Audit and Advisory Services has sufficient authority to fulfill its duties, the Committee on Audit of the Board of Trustees will perform the responsibilities and have the authority as outlined in the California State University Audit Committee Charter.

Audit and Advisory Services is free from interference in determining the scope of auditing, performing work, and communicating results and has full, free, and unrestricted access to all records, property, and personnel of the university and recognized auxiliary organizations.

Independence and Objectivity

The Vice Chancellor and Chief Audit Officer will ensure that Audit and Advisory Services carries out its responsibilities in an unbiased manner, including matters of audit selection, scope, procedures, frequency, timing, and report content. If the Vice Chancellor and Chief Audit Officer determines that independence or objectivity may be impaired in fact or appearance, the details of the impairment will be discussed with appropriate parties.

Audit and Advisory Services has no authority to make operating decisions, direct anyone in operations, or take action or implement any of its recommendations. Accordingly, internal auditors do not implement controls, develop procedures, install systems, prepare records, or engage in any other activity that may impair their judgment. These tasks are the responsibility of university and auxiliary management.

Scope of Work

Audit and Advisory Services provides university management and the Trustees with evidence-based examinations. Major objectives include providing ongoing assurance that critical risks are being mitigated to acceptable levels and the California State University is operating efficiently and effectively; adding value by contributing to the improvement of governance, risk management, operations, and control processes, and by promoting continuous improvement; enhancing awareness and understanding of risk and control; and promoting appropriate ethics and values.

The scope of work of Audit and Advisory Services is to determine whether the university’s risk management, control, and governance processes as designed and represented by management are adequate and functioning effectively to help reasonably ensure that:

  • The governance process promotes appropriate ethics and values and ensures effective organizational performance management and accountability.
  • Risk management processes, including risks relating to the achievement of CSU’s strategic objectives, are effective, and significant risks are appropriately identified, assessed, and managed.
  • Communication of risk and control information to appropriate areas of the organization, as well as coordination of activities and communication of information among various governance groups, occurs as needed.
  • Programs, plans, and objectives support and align with the university’s mission and are achieved.
  • Financial, operational, and managerial information and the means used to identify, measure, analyze, classify, and report such information are accurate, reliable, and timely.
  • Resources are acquired economically, used efficiently, accounted for accurately, and protected adequately.
  • The potential for the occurrence of fraud is evaluated, and fraud risk is managed.
  • Actions and decisions are in compliance with applicable laws, regulations, policies, procedures, contracts, and standards.
  • Information technology governance and systems support achievement of the university’s strategic goals, and security practices adequately protect information assets.
  • Quality and continuous improvement are fostered in the university’s risk management and control processes.

Audit and Advisory Services engagements are categorized as follows:

Assurance Services
Assurance services include objective assessments to provide opinions or conclusions regarding the entity, operation, function, process, system, or other subject matter according to the risk-based audit plan. The nature and scope are determined by the internal auditors assigned to the engagements and approved by the Vice Chancellor and Chief Audit Officer. A formal report is typically generated for assurance engagements, and results and recommendations are disclosed to management and the Committee on Audit. Assurance reports are published on the Audit and Advisory Services website for public viewing.

Advisory Services
Advisory services are performed at the request of management and are intended to identify solutions for business issues, offer opportunities to improve the efficiency and effectiveness of operating areas, and assist with special requests, while ensuring the consideration of related internal control issues. The nature and scope of advisory services are subject to agreement with relevant stakeholders. Results and recommendations are shared with management through an agreed-upon medium.

Investigations
Investigations are independent evaluations of allegations generally focused on improper activities, including misuse of university resources, fraud, financial irregularities, significant control weaknesses, and unethical behavior or actions. In alignment with systemwide policy, universities are responsible for conducting investigations of fiscal improprieties and reporting them to the Office of the Chancellor when required. Audit and Advisory Services may also receive allegations or requests to conduct investigations from the Chancellor, Board of Trustees, senior management, or California State Auditor.

Other Engagements
Audit and Advisory Services may engage in both formal and informal opportunities to educate and inform the CSU community about various topics, such as risk management, internal controls, and emerging regulatory and compliance requirements. The work from such engagements may or may not generate a formal work product.

The Vice Chancellor and Chief Audit Officer coordinates activities, where possible, and considers relying upon the work of other internal and external assurance and consulting service providers as needed.

Responsibility

Audit and Advisory Services functions pursuant to state law under the policies established by the Trustees of the California State University and university management and is subject to all the rules and procedures established by the Office of the Chancellor. In this context, the Vice Chancellor and Chief Audit Officer is responsible for:

  • All administrative duties and requirements pertaining to the operation of Audit and Advisory Services, including the budget, establishment of policies for auditing and advisory services, and direction of the office’s technical and administrative functions.
  • Maintaining a work environment where internal auditors demonstrate integrity, objectivity, and competency in their work and behavior as defined and required by the Standards and apply due professional care in planning and performing audit and advisory services.
  • The sufficiency of audit resources, including the recruitment, development, and retention of professional staff with sufficient knowledge, skills, experience, and professional certifications to meet the requirements of the Charter.
  • Developing and executing a flexible and comprehensive risk-based audit plan, which is submitted to the Committee on Audit for approval, that supports the achievement of the California State University’s objectives, and ensures evaluation of management controls provided over all university and auxiliary organization activities, although the Board of Trustees reserves the right to assign Audit and Advisory Services to review any area within its jurisdiction. Material changes made to the audit plan must be approved by the Chair of the Committee on Audit. Additionally, the Chancellor or trustees may request changes to the audit plan with approval from the Chair of the Committee on Audit. Investigations will be conducted in accordance with the CSU policy on the Campus Reporting of Fiscal Improprieties.
  • Reviewing the responsiveness of the corrective action taken to ensure improvements are adequate, effective, and timely, and determining whether additional action may be required. Reports of follow-up activity will be made at each meeting of the Committee on Audit.
  • Establishing and implementing methodologies to promote accurate, objective, clear, concise, constructive, and timely communications. This includes communicating the results of Audit and Advisory Services engagements to management, the Committee on Audit, and appropriate stakeholders. Audit reports will be maintained in accordance with applicable regulations, CSU, and division retention policies.
  • Communicating and consulting with the Committee on Audit through the Chair of the Committee. At each meeting of the Committee on Audit, the Vice Chancellor and Chief Audit Officer will report the assignment workload showing the status of audits in progress, and disposition taken on completed audit assignments.
  • Acting as the liaison for the California State University in all relationships with outside audit agencies, including, but not limited to, the California State Auditor and other federal and state regulators. As such, the Vice Chancellor and Chief Audit Officer is the point of contact for all entrance and exit conferences held with the Office of the Chancellor by outside audit agencies and coordinates all system responses to audits performed by outside audit agencies. This responsibility does not include acting as a liaison with the external auditor for the financial statements audit and single audit, as this is the responsibility of the Chief Financial Officer of the California State University. The Committee on Audit is responsible for oversight and selection of the external financial auditor, as required by the Audit Committee Charter.

Management has the responsibility to:

  • Within the time period mutually agreed upon by the Vice Chancellor and Chief Audit Officer and the campus president or Chancellor, furnish a written report of planned or completed actions to address the recommendations outlined in the internal audit report.
  • Report to the Vice Chancellor and Chief Audit Officer in writing the status of implementation of audit recommendations.

Quality Assurance and Improvement Program

Audit and Advisory Services will maintain a quality assurance and improvement program that covers all aspects of the internal audit activity. The program will include an evaluation of Audit and Advisory Services’ conformance with the Standards and an evaluation of whether internal auditors apply the ethics and professionalism domain principals as outlined in the Standards. The program will also assess the efficiency and effectiveness of Audit and Advisory Services and identify opportunities for improvement.

The Vice Chancellor and Chief Audit Officer will initiate an external quality assurance review, conducted at least once every five years by a qualified, independent assessor or assessment team from outside the California State University, in accordance with the Standards. The independent assessor or assessment team must be approved by the Chair of the Committee on Audit. Results of these reviews will be communicated to senior management and the Board through the Committee on Audit. 

Review/Revision Dates

  • Last Reviewed by Audit Management: May 2025
  • Last Approved by the Board of Trustees Committee on Audit: May 2025