TUSD Internal Audit Charter is graded as a set of failed work!!!
- John Blackshire
- 1 day ago
- 4 min read
This is the second review of Entity Level controls at the Tucson Unified School District.
Internal Audit Function Charter.
On August 14, 2026, I completed an Independent Review of the TUSD Internal Audit Function Charter. The purpose was not simply to determine whether TUSD has an Internal Audit Charter—it does. The more important question was whether the Charter establishes the governance structure necessary for Internal Audit to operate with the independence, authority, resources, accountability, professional competence, and Governing Board support expected of a modern public-sector Internal Audit function.
Why This Is an Entity-Level Control
I consider the Internal Audit Function Charter to be an important entity-level control because it establishes the governance framework for one of the Governing Board's principal independent assurance functions.
The effectiveness of Internal Audit depends on much more than the technical competence of the Internal Auditor. The governance structure must protect the function's independence, provide adequate resources and authority, establish accountability, and ensure that Internal Audit can report significant issues without management interference.
The existing Charter contains several important strengths. It establishes direct reporting to the Governing Board, broad access to District records and personnel, protection against assuming operational responsibilities, risk-based audit planning, a Quality Assurance and Improvement Program, periodic external assessments, and continuing professional education.
The primary weakness is that the Charter is considerably more effective at defining what the Internal Auditor is authorized to do than it is at defining how the Governing Board and Audit Committee are responsible for governing the Internal Audit function.
Scope of the Review
The Charter was evaluated against nationally and internationally recognized Internal Audit, internal control, and public-sector governance practices, including:
The Institute of Internal Auditors' 2025 Global Internal Audit Standards
The IIA Model Internal Audit Charter
COSO Internal Control—Integrated Framework
U.S. Government Accountability Office Standards for Internal Control in the Federal Government (Green Book)
Government Auditing Standards (Yellow Book)
Government Finance Officers Association (GFOA) best practices
These criteria were used to evaluate such matters as Internal Audit independence, functional reporting, governance accountability, resources, performance oversight, and the relationship among the Internal Auditor, Audit Committee, Governing Board, and District management.
Twenty Governance Improvement Opportunities
The review identified 20 governance findings:
5 Critical Findings
8 High-Risk Findings
7 Moderate-Risk Findings
The five Critical findings involve fundamental governance safeguards:
Functional Reporting Relationship — Functional reporting responsibilities are not fully defined.
Audit Committee Functional Oversight — The Audit Committee's continuing oversight responsibilities are not fully established.
Internal Audit Budget and Resources — Governance responsibility for determining whether Internal Audit has adequate resources is not sufficiently defined.
Performance Evaluation — A formal process for evaluating the Internal Auditor has not been established.
Appointment and Removal Authority — Responsibility for appointment, reappointment, compensation, and removal of the Internal Auditor is not clearly defined.
These are significant issues because simply stating that the Internal Auditor reports to the Governing Board does not, by itself, establish organizational independence. Independence must be supported by governance mechanisms determining who protects the Internal Auditor from interference, evaluates performance, assesses resource sufficiency, and controls significant employment decisions affecting the Internal Auditor.
Contents of the Review
The 70-page report includes:
An Executive Summary
A Governance Dashboard presenting all 20 findings by governance area and risk
5 Critical, 8 High, and 7 Moderate findings
Detailed analyses using Condition, Criteria, Cause, Consequence, Risk, Recommendation, and Value Created
Recommended management priorities
Suggested Charter language
References to applicable professional standards
A comparison against leading governance practices
The Governance Dashboard provides an executive-level view of the issues and identifies independence, governance, resources, oversight, audit planning, risk management, quality assurance, fraud governance, enterprise risk, cybersecurity, staffing, professionalism, and continuous improvement among the areas requiring attention.
Overall Assessment
My conclusion is not that the existing Internal Audit Charter is a failed document.
The Charter establishes a credible foundation for the Internal Audit function. It is particularly strong in defining Internal Audit's mission and purpose, audit authority, access rights, operational independence, risk-based planning, professional development, and quality assurance.
However, it does not yet establish a leading-practice governance framework. Its principal weaknesses concern functional governance, Audit Committee oversight, resource accountability, performance evaluation, appointment and removal authority, ongoing monitoring of Internal Audit effectiveness, and accountability for several enterprise-wide risks.
In my view, this distinction is extremely important.
TUSD has employed a capable Internal Auditor and still have a weak entity-level control if the governance system surrounding that individual does not adequately protect the Internal Audit function.
Good governance should not depend upon the personalities of the individuals currently occupying positions of authority. It should depend upon clearly documented responsibilities. That is one of the central conclusions of this review.
The Opportunity for TUSD
The good news is that TUSD does not need to rebuild its Internal Audit function from the ground up. The fundamental structure already exists.
The opportunity is to move the Charter from primarily an operational Internal Audit document to a comprehensive Internal Audit governance charter, with clearly established responsibilities for the Governing Board, Audit Committee, Internal Auditor, and District management.
The report recommends that the five Critical findings be addressed first, including establishment of a complete functional reporting relationship, clearly defined Audit Committee oversight responsibilities, annual Internal Audit resource and budget review, a formal performance evaluation process, and explicit Governing Board authority over appointment, reappointment, compensation, and removal of the Internal Auditor.
The objective should not merely be to improve the wording of the Charter.
The objective should be to establish an Internal Audit governance structure that protects independence, clarifies accountability, provides adequate resources, measures performance, directs audit resources toward TUSD's greatest risks, and gives the Governing Board a reliable source of independent assurance.
Comments