top of page
Search

TUSD Governance: Management’s Job Is More Than Answering the Board’s Questions

19 hours ago
8 min read

There is a fundamental distinction between answering questions from a Governing Board and providing the Governing Board with the information it needs to exercise effective oversight.


That distinction matters at the Tucson Unified School District.


A governance philosophy in which senior management views its responsibility primarily as responding to questions posed by Governing Board or Audit Committee members creates a significant problem: How are those oversight bodies supposed to ask the right questions if management has not first identified and communicated the risks, control deficiencies, emerging financial problems and other significant issues that management knows—or should know—about?


Effective governance cannot operate as a game of “ask me the right question and I will give you the answer.”


Management operates the District every day. The Governing Board does not.


That difference is precisely why management has affirmative responsibilities for internal control, risk management, financial reporting and communication with those charged with governance.


The Fundamental Governance Distinction: Management Manages; the Board Oversees

One of the clearest ways to understand the issue is through the COSO Internal Control—Integrated Framework. This is the gold standard for having effective controls in large organizations like TUSD. The Government tailored framework based on COSO is the GAO's Green Book.


COSO defines internal control as a process involving the board, management and other personnel that provides reasonable assurance regarding achievement of objectives involving operations, reporting and compliance.


The responsibilities, however, are not identical.


The Board exercises oversight.


Management is responsible for establishing and operating the organization, including its system of internal control.


COSO's Control Environment principles make this distinction particularly important. The Board is expected to exercise oversight of the development and performance of internal control, while management establishes—with Board oversight—the organizational structures, reporting lines, authorities and responsibilities necessary to accomplish the organization's objectives.


That means the Board cannot simply be treated as another customer requesting information from management.


Management must provide the information necessary for the Board to perform its oversight responsibilities.


Management Owns the Internal-Control System

The distinction becomes even clearer when the organization is viewed through the Three Lines Model.


Management is the first line.


Internal Audit is not the owner of TUSD's controls. The Audit Committee is not the owner of TUSD's controls. Individual Governing Board members are not responsible for operating the District's controls.


Management is responsible for maintaining effective internal control in the District's day-to-day operations.


Internal Audit independently evaluates those controls.


The Audit Committee assists with oversight.


The Governing Board ultimately exercises governance oversight.


Confusing these responsibilities can create a serious governance weakness.


If management waits for Internal Audit, the Audit Committee or Governing Board to identify problems before management acts, the District has effectively pushed part of management's first-line responsibility upward to its oversight bodies.


That is backwards.


Entity-Level Controls Include Governance

Internal controls are sometimes mistakenly viewed as accounting procedures: approvals, reconciliations, purchase orders, segregation of duties and similar transactional controls.

Those controls are important, but internal control starts considerably higher in the organization.


The Control Environment is one of COSO's five components of internal control.

It includes such matters as:

  • organizational governance;

  • integrity and ethical expectations;

  • assignment of authority and responsibility;

  • accountability;

  • organizational structure;

  • reporting relationships;

  • management's philosophy and operating style; and

  • the ability of the governing body to exercise meaningful oversight.


These are entity-level controls.


Consequently, the relationship among TUSD management, the Governing Board, the Audit Committee and the Office of Internal Audit is itself part of the District's control environment.


Management therefore has responsibilities associated with maintaining that governance infrastructure.


TUSD's Own Policies Recognize Governance as an Internal-Control Issue

This is not simply an outside governance theory being imposed on TUSD.


TUSD Governing Board Policy DIFA establishes an Office of Internal Audit whose mission includes evaluating and contributing to improvement of the District's governance, risk-management and control processes.


The policy describes Internal Audit's responsibilities as including evaluation of governance processes and reporting significant risk exposures, control issues, fraud risks and governance issues.


That language is important.


Governance is expressly within TUSD's internal-control and assurance structure.


TUSD's published description of its Audit Committee is equally instructive. The District says Audit Committee members assist the Governing Board in meeting its fiduciary oversight obligations, strengthening internal financial controls and improving transparency over stewardship of taxpayer resources.


The Audit Committee is therefore an oversight mechanism.


It should not have to become a substitute management function.


Consider the Logical Problem With a "Just Ask Me" Governance Model

Suppose management possesses information indicating that:

  • enrollment is falling faster than budget assumptions;

  • revenues are materially below projections;

  • expenditures are exceeding sustainable levels;

  • cash reserves are deteriorating;

  • a significant internal control is not operating;

  • a major financial assumption has changed;

  • a regulatory compliance problem has emerged;

  • a fraud risk has increased;

  • a major information technology risk has developed; or

  • an important Board policy is not being followed.


Under an effective governance model, management evaluates the matter, determines its significance and escalates material information to the appropriate oversight body.


Now consider the alternative.


Management possesses the information but waits.


A Board member must somehow become aware of the issue, understand its significance, develop the appropriate question, place the matter before management and request the information.


Only then does management respond.


That is not a robust information-and-communication control.


It makes governance dependent upon the investigative ability of part-time Governing Board members.


TUSD's Fraud Risk Policy Provides an Excellent Example

TUSD's own Fraud Risk Policy, DIFC, demonstrates that management responsibilities can be affirmative rather than merely responsive.


The policy requires the Superintendent or designee to design, implement and monitor internal controls intended to address fraud risk. Significantly, it also calls for periodic reporting to the Board concerning identified fraud risks, the fraud-management program and investigative procedures. In my three plus years around the Audit Committee TUSD Management has never provide a Fraud Risk Assessment to the Audit Committee for its review and then review by the Governing Board.


That is an important governance concept.


The policy does not say management should wait until a Governing Board member happens to ask:

"Have we identified any new fraud risks?"


The reporting responsibility exists because management has information that the oversight body needs.


The same basic governance principle should apply to other material financial, operational, compliance and internal-control risks.


Information and Communication Are Internal Controls

COSO does not treat communication as an administrative courtesy.


Information and Communication is one of the five components of internal control.

For oversight to function, relevant information must reach the appropriate people in a form and timeframe that allows them to carry out their responsibilities.


This creates an important question for TUSD:

Does the Governing Board routinely receive the information necessary to identify significant financial, operational, compliance and governance risks without first having to know enough about the problem to ask management the right question?

That is a much more important question than whether management technically answered a question after it was asked.


The Audit Committee Faces the Same Problem

The issue becomes even more significant with TUSD's Audit Committee.


TUSD says the Committee assists the Governing Board with its fiduciary oversight responsibilities and reviews the soundness, adequacy and application of accounting, financial and operating controls.


To perform that function effectively, the Audit Committee needs information.


It needs significant audit findings.


It needs management's risk assessments.


It needs significant control deficiencies.


It needs unresolved audit recommendations.


It needs major financial-reporting issues.


It needs information about suspected fraud and significant compliance issues.


It needs significant changes in financial assumptions and emerging risks.


And it should receive that information through a defined governance reporting process—not simply when an Audit Committee member happens to ask the right question.


Internal Audit Cannot Fix Management's Responsibility

There is another important distinction.


TUSD's Internal Audit Charter appropriately protects Internal Audit's independence. The charter states that the Internal Auditor does not have operational responsibility over audited activities and should not develop procedures or implement internal controls.


That is exactly as it should be.


Internal Audit can evaluate a control.


Internal Audit can identify a weakness.


Internal Audit can recommend improvement.


Internal Audit can report whether corrective action occurred.


But Internal Audit should not become the owner of management's internal-control system.


Otherwise, the auditor eventually ends up auditing controls that the auditor helped design or operate.


The same principle applies to the Audit Committee.


The Committee oversees. It should challenge management and ask difficult questions.


But management must give it the information necessary to do so.


The Governance Information Flow Should Work Upward

An effective governance structure should generally operate something like this:


Operations and Finance → Senior Management → Superintendent → Audit Committee/

Governing Board


At the same time:


Internal Audit → Independent Assurance → Audit Committee/Governing Board


Those reporting streams serve different purposes.


Management reports what it knows about the organization, its performance, risks and controls.


Internal Audit independently assesses whether management's representations and controls can be relied upon.


The Board and Audit Committee then use both sources of information to perform oversight.


That is considerably stronger than:


Board asks question → Management answers question.


The latter is a reactive information-request process.


A couple of years ago, I directly asked the Superintendent about his outstanding Arizona Income Tax liability on over $500,000 in unreported income and / or disallowed deductions. I have yet to get an answer from him.


What TUSD Should Be Able to Demonstrate

Rather than debating personalities, TUSD can address the governance question objectively.


The District should be able to demonstrate that it has documented processes specifying:

  • What must be reported. Material financial risks, budget variances, liquidity issues, control deficiencies, compliance matters, fraud risks, significant audit findings and emerging operational risks should have defined escalation criteria.

  • Who is responsible. Responsibility for identifying, evaluating and escalating each category of information should be assigned to management positions.

  • Who receives the information. Certain matters belong with the Superintendent, others with the Audit Committee, and significant governance matters ultimately belong before the Governing Board.

  • When reporting occurs. Material information should not remain buried in management until the next routine presentation or until somebody asks about it.

  • How unresolved matters are tracked. Significant deficiencies and corrective actions should remain visible until appropriately resolved.


These are basic entity-level controls.


The Governing Board Cannot Oversee What It Does Not Know

The Governing Board certainly has responsibilities of its own.


Board members must read the information provided to them. They must challenge management. They must ask probing questions. They must understand the District's financial condition and major risks. And they must hold management accountable.


But oversight cannot operate effectively when the information architecture requires Board members to discover management problems independently.


There is a simple governance principle at work:

Management has access to the organization every day. The Governing Board does not. Therefore, management has an affirmative responsibility to surface material information needed for oversight—not merely answer questions after someone else discovers the issue.

That distinction should be central to any examination of governance at Tucson Unified School District.


The Question TUSD Should Be Asking

The question is not:

"Did management answer the Board member's question?"


The better governance question is:

"Did management identify and communicate the significant issue to the Governing Board or Audit Committee before they had to ask?"


That question changes the entire discussion.


It moves the focus away from personalities and individual Board meetings and toward the design and effectiveness of TUSD's entity-level controls.


For an organization responsible for public funds, thousands of employees and the education of tens of thousands of students, that is where the focus belongs.


Good governance is not a question-and-answer session. It is a system of accountability, information, internal control and independent oversight.

 
 
 

Recent Posts

See All

Comments


Subscribe Form

Thanks for submitting!

479-200-4373

  • Facebook
  • Twitter
  • LinkedIn
  • Twitter
  • LinkedIn
  • Facebook

©2026 by The Accountware Group. Proudly created with Wix.com

bottom of page