Laserfiche WebLink
9 <br />2023-2024 San Mateo County Civil Grand Jury <br />The Civil Grand Jury focused on responses to three questions from the survey: <br /> <br />1. Do you have an established process in place to identify organizational risks (also known <br />as Enterprise Risk Management, or ERM)? The tables below refer to this question as <br />‘ERM?’. <br />2. Other than outside audits of your organization's financial statements, have you or your <br />organization performed an assessment of your organization's "internal controls" within <br />the last 18 months? The tables below refer to this as ‘Assessment?’. <br />3. Was a written report of the assessment produced? The tables below refer to this as <br />‘Report?’. <br /> <br /> <br />Identifying risks to an entity is a critical part of effective internal controls. See Principle 7 in the <br />Green Book Principles of Internal Controls Table above. <br /> <br />Eighteen entities responded that they had performed an assessment of internal controls in the <br />prior 18 months. Each entity must assess its internal controls. State guidelines require established <br />mechanisms to hold management responsible for internal control responsibilities and to align <br />incentives with the fulfillment of internal control responsibilities. <br /> <br />Four entities responded that they prepared a report regarding assessments of internal controls. <br />Each governing board must oversee its entity’s internal controls. State guidelines require <br />established mechanisms to hold management responsible for internal control responsibilities and <br />to align incentives with goals and objectives. Management should both internally and externally <br />communicate the results of its assessments of internal controls. If management does not <br />communicate the results of its assessments of internal controls, others may see this as an <br />opportunity to commit fraud or waste government assets. Management should communicate the <br />results of its assessments of internal controls in writing to its governing board. <br /> <br />6.C. - Page 13 of 22 <br />92