Audit Frequently Asked Questions (FAQs)

Q: How are departments selected for an internal audit?

A: We employ a risk-based approach to developing our annual audit plan.  Some factors we consider when assessing the relative risk of an area include the size of your budget, the complexity of your regulations, the time elapsed since your last audit, and any significant changes in leadership or software systems.  We also leave room in our annual schedule for unexpected requests from management in response to a change in circumstances or perceived issue.

Q: How long does a typical audit take? Will it disrupt our daily operations?

A: Because every audit at the University is unique, there isn’t a single timeline that fits every engagement. The overall duration depends on the scope and complexity of the review, as well as external factors like document availability, key stakeholder schedules, and unexpected operational shifts. Your department’s direct involvement—such as kickoff discussions, interviews, and data gathering—will typically be concentrated over a few hours in the beginning two to four weeks of the engagement, with some follow-up questions and requests for you occurring throughout the fieldwork phase (typically four to six weeks). The total project lifecycle extends past this active phase due to an intensive report-writing and quality review process on our end, however, this behind-the-scenes work requires minimal time from your team, allowing you to return your focus to day-to-day operations.

Q: Who sees the final audit reports?

A: All of our final reports are distributed to the Chair of the Audit Committee, President, Provost, Executive Vice President, Chief of Staff, and General Counsel, as well as to the relevant unit leadership (e.g., Dean or Vice President, business manager, department head or chair). 

Q: Does our department have to pay for audit and advisory services out of our operational budget?

A: No. OIRCA is a centrally-funded institutional resource. All of our services—whether a scheduled compliance audit, an IT security review, or a proactive management advisory consultation—are provided to your department at zero cost to your unit’s budget.

Q: What authority does OIRCA have to look at confidential student or research data?

A: Under the Office of Institutional Risk, Compliance, and Audit Charter approved by the Board of Trustees, our auditors have full, unrestricted access to all University functions, records, property, and personnel relevant to the subject of review. We are legally bound by the same strict confidentiality standards (such as FERPA for student data and HIPAA for medical data) as your department is. We handle all sensitive data securely and never publish protected information in our reports.

Q: I want to report a financial concern about my supervisor, but I’m afraid of losing my job. Am I protected?

A: Yes. The University has a strict Whistleblower and Non-Retaliation Policy. Retaliation against any employee who reports a suspected policy violation or fraudulent activity in good faith is a severe offense that results in immediate disciplinary action, up to termination of the retaliating party. If you are still uncomfortable, you can utilize our third-party anonymous hotline.

Q: Can a Vice President, Dean, or department head directly request an audit of their own unit or an area under their purview?

A: Yes. These are called “Management Requests.” If you suspect irregularities or inefficiencies in your unit, you can request a targeted review. We will evaluate the request against our current workload and risk priorities to determine if we can accommodate it.