Internal Audit Charter (T06-061)

Internal Audit Charter (T06-061)

Doc. T06-061, as amended
Passed by the Board of Trustees on November 8, 2006
Latest revision: April 8, 2026

Mission and Purpose

University Internal Audit (Internal Audit) provides independent, risk based and objective assurance, advisory services and insight designed to create, protect and sustain value and improve the University’s operations. Internal Audit helps the University accomplish its objectives by bringing a systematic, disciplined approach to evaluate and improve the effectiveness of control, risk management, compliance and governance processes. 

Internal Audit is committed to adhering to the mandatory elements of The Institute of Internal Auditors' (IIA) International Professional Practices Framework, which are the Global Internal Audit Standards and Topical Requirements (Standards). 

Independence and Objectivity

Internal Audit reports functionally to the Audit and Risk Committee of the University's Board of Trustees and administratively to the University's President. This positioning provides Internal Audit's Chief Audit Officer (CAO) the organizational authority and status to bring matters directly to the University's President and escalate matters to the Audit and Risk Committee, when necessary, without interference, and it supports Internal Audit's ability to maintain objectivity. The CAO will disclose to the President and, if necessary, the Audit and Risk Committee any interference Internal Audit encounters related to the scope, performance or communication of internal audit work and results.

To maintain Internal Audit’s independence and objectivity, the CAO and Internal Audit’s staff shall have no direct operational responsibility or authority over any activities Internal Audit reviews. In addition, Internal Audit shall not develop or implement procedures, prepare records, make management decisions, or engage in any other activity that could be reasonably construed to impair its independence and objectivity. In addition, Internal Audit’s staff shall not assess specific operations for which they had responsibility within the previous year or where circumstances or a relationship exist which may impair their judgment, and they shall not initiate or approve transactions external to the internal audit function. Internal Audit’s staff are required to disclose any circumstances or relationships that may potentially impair their judgment to the CAO.

The CAO shall confirm to the Audit and Risk Committee, at least annually, the organizational independence of Internal Audit, including reporting relationships and responsibilities and, if they exist, potential impairments to independence or objectivity.

Authority and Access

Authority is granted to Internal Audit to have full, free and unrestricted access to the University’s President, Chancellors, the Audit and Risk Committee, the Chair of the Board of Trustees, and any and all of the University’s personnel, records, systems, data, and physical properties as necessary to fulfill its mission and purpose. Information obtained by Internal Audit is maintained and safeguarded with appropriate confidentiality (see Confidentiality section). No University personnel may interfere with the determination of Internal Audit’s scope, its performance of work or communication of results. Internal Audit is authorized to allocate resources, set frequencies, select subjects, determine scopes of work, apply techniques and issue communications to accomplish its objectives. Internal Audit may also obtain assistance from the necessary personnel and other specialized service providers from within or outside the University to provide internal audit services. This authority and access is created by Internal Audit’s direct reporting relationship to the Audit and Risk Committee.

Scope and Responsibility

Internal Audit is responsible for all internal audits and for monitoring all other audit activity throughout the University, including, but not limited to, external contracted audits as well as federal and state audits.

The scope of Internal Audit’s responsibilities includes, but is not limited to, the following:

  • Developing a risk-based audit plan consistent with University strategic objectives and goals, that considers the University’s President’s, Chancellors’, Management’s and the Audit and Risk Committee’s input, with the flexibility to respond to unplanned needs.

  • Communicating to the Audit and Risk Committee if there are significant interim changes to the approved audit plan.

  • Conducting audit engagements that provide Management and the Audit and Risk Committee with assurance about the design, effectiveness and efficiency of the University’s controls, governance, use of resources and risk management activities related to operations, finance, information systems and compliance with laws and regulations.

  • Reviewing if operations are aligned with strategic goals and being carried out as planned.

  • Conducting advisory services based on the potential to improve controls, governance, risk management, compliance, information systems and operations to the extent agreed upon with Management. Improvement opportunities will be communicated to the appropriate level of Management.

  • Maintaining the University’s confidential and anonymous Ethics and Fraud Hotline.

  • Investigating allegations of fraudulent financial activities per the Board of Trustee’s Policy on Fraudulent Financial Activities and Guidelines (T00-051).

  • Briefing the Audit and Risk Committee Chair and Vice Chair on the results of investigations into fraudulent financial activities or credible whistleblower complaints.

  • Confirming and reporting on the effective implementation of Management’s action plans provided in response to audit observations and recommendations.

  • Acting as a liaison to the MA Office of the State Auditor, the University’s Independent External Auditor (as defined in the Audit and Risk Committee Charter (T03-030)) and other external auditors.

  • As per the Audit and Risk Committee Charter, providing the Audit and Risk Committee with:

    • the audit plan for review and approval;

    • a periodic report on all audit activity at the University;

    • sufficient opportunity to meet privately with the CAO; and

    • opportunity to annually review and, if necessary, approve revisions to the Internal Audit Charter.

Quality Assurance and Improvement Program

Internal Audit will maintain a quality assurance and improvement program that includes:

  • Establishing and ensuring adherence to methodologies and processes designed to guide the administration of Internal Audit and its engagements.

  • Maintaining a professional and objective audit staff who:

    • have the knowledge, skills and other competencies needed to fulfill Internal Audit’s responsibilities;

    • conforms with the Standards and the IIA’s principles of Ethics and Professionalism; and

    • encourages and promotes ethical behavior and can recognize conduct to the contrary.

  • Benchmarking Internal Audit’s staffing and resources periodically and discussing the results with the Audit and Risk Committee Chair.

  • Ongoing monitoring, periodic self-assessments and independent external assessments of Internal Audit’s conformance with the Standards and established methodologies.

Internal audit will annually communicate with the Audit and Risk Committee Chair and President about its quality assurance and improvement program, including results of periodic external and internal assessments.

General Protocol

Internal Audit Engagement Communications

The annual audit plan will be provided to the Audit Liaisons (as defined herein). A written notification will be sent to appropriate person(s) prior to the start of an Internal Audit engagement. Certain engagements may be carried out without prior notice at the discretion of the CAO or Audit and Risk Committee where a lack of advance notice is necessary or in the best interests of the University. When appropriate, a formal planning memo will be provided to the Audit Liaison and appropriate person(s) that outlines the objectives, scope, resource allocation and related engagement communications. Preliminary observations will be communicated to Management and when appropriate a formal exit meeting will be conducted, followed by the draft report. Management will provide official action plan responses to all reported observations within fifteen (15) business days of receiving the final draft report, including the individual(s) responsible for the completion of the action plan and applicable due date(s). The final report will be distributed to the University’s President and relevant Chancellor or President’s Office Leadership and copied to relevant Management and the Chair and Vice Chair of the Audit and Risk Committee.

Audit Liaison

The Senior Vice President and the campus Vice Chancellors for Administration and Finance will each appoint an individual to serve as a liaison (Audit Liaison) for the President’s Office and campuses, respectively, to function as the principal contact for all related audit matters. The Audit Liaison will work with Internal Audit to ensure proper coordination and monitoring of all audit matters. It is the Audit Liaison’s responsibility to timely notify Internal Audit whenever Management engages a firm to perform audit services or when an outside agency notifies the campus or President’s Office that it will be conducting an audit or investigation as well as to provide periodic status updates, preliminary audit results and Management’s draft and final responses. Internal Audit will provide assistance where required.

The Audit Liaison or Management is required to inform the CAO if the University’s Independent External Auditor is being considered to perform audit or non-audit services in order for the Audit and Risk Committee Chair or Audit and Risk Committee to review and if necessary, pre-approve proposed services in accordance with the Audit and Risk Committee Charter (T03-030, as amended). The CAO and Office of General Counsel will assess the proposed engagement to determine if it is prohibited by the Audit and Risk Committee Charter. If it is an allowed service, the CAO will present it to the Audit and Risk Committee Chair for approval. The CAO will inform the Audit Liaison or Management if the engagement is or is not approved.

Other Matters

Internal Audit Charter

Internal Audit shall annually review and when necessary, revise the Internal Audit Charter as conditions dictate. The Internal Audit Charter is exempt from the process required for issuing and revising University Board Policies outlined in the Policy for Creating and Establishing Board Policy and Standards (T13-093). Any revisions to the Internal Audit Charter must be reviewed by the Office of General Counsel. When revisions are made, the Audit and Risk Committee must approve the revisions and vote to recommend the Board of Trustees approve the Internal Audit Charter.

Confidentiality

All University documents and electronic records related to the engagements conducted by Internal Audit and external auditors, including supporting workpapers and reports will be considered confidential and protected as such. Reports, memorandum or other audit related documents and work product will not be publicly disclosed except as directed by law or regulation, or as determined by the CAO, University General Counsel or University President.

Doc. T06-061, as amended | Internal Audit Charter
Passed by the Board of Trustees on November 8, 2006
Revised:
February 24, 2010
December 14, 2011
December 12, 2012
December 11, 2013
December 10, 2014
December 9, 2015
December 9, 2016
December 8, 2017
December 13, 2018
December 18, 2019
December 10, 2020
April 8, 2026

Book Category
Board Policy: Fiscal & General Administrative