[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"detail-sidebar-cat-1-en-105":3,"doc-seo-280777-105":53,"doc-detail-280777-en":126},{"code":4,"msg":5,"data":6},0,"success",[7,14,19,24,29,34,39,44,49],{"id":8,"doc_module":9,"doc_module_name":10,"category_name":11,"show_sort_weight":12,"slug":13},11,1,"Template","Presentations",90,"presentations",{"id":15,"doc_module":9,"doc_module_name":10,"category_name":16,"show_sort_weight":17,"slug":18},12,"Resumes",80,"resumes",{"id":20,"doc_module":9,"doc_module_name":10,"category_name":21,"show_sort_weight":22,"slug":23},14,"Invoices",70,"invoices",{"id":25,"doc_module":9,"doc_module_name":10,"category_name":26,"show_sort_weight":27,"slug":28},15,"Posters",60,"posters",{"id":30,"doc_module":9,"doc_module_name":10,"category_name":31,"show_sort_weight":32,"slug":33},16,"Social Media",50,"social-media",{"id":35,"doc_module":9,"doc_module_name":10,"category_name":36,"show_sort_weight":37,"slug":38},17,"Forms",40,"forms",{"id":40,"doc_module":9,"doc_module_name":10,"category_name":41,"show_sort_weight":42,"slug":43},18,"Letters",30,"letters",{"id":45,"doc_module":9,"doc_module_name":10,"category_name":46,"show_sort_weight":47,"slug":48},21,"Paper Templates",5,"papers-templates",{"id":50,"doc_module":9,"doc_module_name":10,"category_name":51,"show_sort_weight":4,"slug":52},158,"General","general-158",{"code":4,"msg":54,"data":55},"ok",{"site_id":56,"language":57,"slug":58,"title":59,"keywords":60,"description":61,"schema_data":62,"social_meta":119,"head_meta":121,"extra_data":123,"updated_unix":125},105,"en","risk-audit-committee-agenda-item-5b-review-of-independent-auditors-management-letter","Risk & Audit Committee - Agenda Item 5b - Review of Independent Auditor’s Management Letter","","Risk & Audit Committee agenda item 5b addresses approval of CalPERS’ independent financial statement auditor’s Management Letter for the fiscal year ended June 30, 2025. The draft, prepared by BDO USA, includes observations and recommendations focused on strengthening internal controls over financial reporting, along with management’s responses and corrective actions. The item outlines the required audit process under Government Code, summarizes current observations and remediation, and discusses budget impacts, benefits, and risks of not implementing recommendations.",{"@graph":63,"@context":118},[64,80,101],{"@type":65,"itemListElement":66},"BreadcrumbList",[67,71,74,77],{"item":68,"name":69,"@type":70,"position":9},"https://docshare.wps.com","Home","ListItem",{"item":72,"name":10,"@type":70,"position":73},"https://docshare.wps.com/template/",2,{"item":75,"name":51,"@type":70,"position":76},"https://docshare.wps.com/template/general/",3,{"item":78,"name":59,"@type":70,"position":79},"https://docshare.wps.com/template/risk-audit-committee-agenda-item-5b-review-of-independent-auditors-management-letter/280777/",4,{"url":78,"name":59,"@type":81,"image":82,"author":87,"headline":59,"publisher":90,"fileFormat":93,"inLanguage":57,"description":61,"dateModified":94,"datePublished":95,"encodingFormat":93,"isAccessibleForFree":96,"interactionStatistic":97},"DigitalDocument",{"url":83,"@type":84,"width":85,"height":86},"https://docshare.wps.com/thumbnails/risk-audit-committee-agenda-item-5b-review-of-independent-auditors-management-letter/280777.png","ImageObject",442,249,{"name":88,"@type":89},"Arica Lee","Person",{"url":68,"name":91,"@type":92},"DocShare","Organization","application/pdf","2026-09-23","2026-09-16",true,{"@type":98,"interactionType":99,"userInteractionCount":73},"InteractionCounter",{"@type":100},"ViewAction",{"@type":102,"mainEntity":103},"FAQPage",[104,110,114],{"name":105,"@type":106,"acceptedAnswer":107},"What decision does Agenda Item 5b request?","Question",{"text":108,"@type":109},"It requests approval of the CalPERS Board of Administration’s independent auditor Management Letter for the fiscal year ended June 30, 2025.","Answer",{"name":111,"@type":106,"acceptedAnswer":112},"What is the main focus of the Management Letter draft?",{"text":113,"@type":109},"It provides comments and recommendations to strengthen internal controls over financial reporting based on the audit of the June 30, 2025 financial statements, including management’s responses and proposed corrective actions.",{"name":115,"@type":106,"acceptedAnswer":116},"What issue was observed in the current year and how was it remediated?",{"text":117,"@type":109},"BDO observed inappropriate access to a developer role that could create segregation of duties conflicts and lacked audit proof for configuration controls. Management removed the developer access from the user who had inappropriate access to the development environment, and regular review of change logs is recommended.","https://schema.org",{"og:url":78,"og:type":120,"og:title":59,"og:site_name":91,"og:description":61},"article",{"robots":122,"canonical":78},"index,follow",{"doc_id":124,"site_id":56},280777,1790133736,{"code":4,"msg":5,"data":127},{"doc_id":124,"user_id":128,"nickname":88,"user_avatar":129,"doc_module":9,"category_id":50,"category_name":51,"doc_title":59,"doc_description":61,"doc_content":130,"file_id":131,"file_url":132,"file_type":133,"file_size":134,"view_count":79,"is_deleted":4,"is_public":9,"is_downloadable":9,"audit_status":9,"page_count":76,"language":135,"language_code":57,"site_id":56,"html_lang":57,"table_of_contents":136,"faqs":137,"seo_title":138,"seo_description":61,"update_tm":139,"read_time":9},8796096645457,"https://ap-avatar.wpscdn.com/avatar/800003749518d68ffe3?x-image-process=image/resize,m_fixed,w_180,h_180&k=1779345340919836971","Risk & Audit Committee  \nAgenda Item 5b  \nNovember 18, 2025  \nItem Name: Review of Independent Auditor’s Management Letter  \nProgram: Audit Services  \nItem Type: Action  \nRecommendation  \nApprove the CalPERS Board of Administration’s (Board) Independent Financial Statement Auditor’s (Independent Auditor) Management Letter for the fiscal year ended June 30, 2025.  \nExecutive Summary  \nThe draft Management Letter, prepared by the Board’s Independent Auditor, BDO USA, (BDO), includes comments and recommendations related to strengthening internal controls over financial reporting based on the audit of the June 30, 2025 financial statements. Management’s concurrence, response, and proposed corrective actions to the observations and recommendations are included in the draft Management Letter. In addition, management reported that the prior year observation was resolved.  \nStrategic Plan  \nThis item is not a specific product of the strategic plan. Government Code section 20228 requires the board to annually employ a certified public accountant, who is not in public employment, to audit the financial statements.  \nBackground  \nBDO completed its audit of CalPERS Basic Financial Statements for the fiscal year ended  \nJune 30, 2025, as required by Government Code section 20228. In connection with the audit of the financial statements, BDO prepared a draft Management Letter that includes comments and recommendations to enhance internal controls over financial reporting (Attachment 1) .  \nThe Management Letter is considered a draft until it is approved by the board and subsequently signed by BDO. The signed Management Letter will be distributed to the board, executive team, and senior management.  \nAnalysis  \nConsistent with the Office of Audit Services Audit Resolution Policy, the status of the Management Letter observations will be reported to the Risk and Audit Committee until management has resolved each noted observation. The table below summarizes current year observations.  \nTable 1 – Status of Observation   \n Observation  Description  Status   \n1 BDO observed that an approver of changes to be released to production had inappropriate access to the developer role of the Automated Real Estate Investment System (AREIS) . The development access allowed this user to develop code modifications to AREIS.  \nWe observed a user had the developer role access which grants the ability to develop logic or code and then access to approve/commit this code for release to production. This results in a segregation of duties conflict because it provides the individual with the potential ability to modify the report logic without a secondary approval. Although CalPERS has segregated developers and deployers on the application level, having access to the development and be an approver could bypass Azure DevOps system functionality, which results in a segregation of duties conflict. Additionally, no audit is being performed of the system change log nor database log-in access report to check for and investigate anomalies. CalPERS does have a configuration that requires code changes to be approved by a second user that was observed to be set to require the second approver, but there was no audit log to prove that this configuration was not changed during the audit period.  \nManagement has removed the developer access from the user who had inappropriate access to the development environment. To strengthen the change management control environment, it is recommended that the change logs be reviewed on a regular basis for appropriateness by an individual who does not have approver access to AREIS.  \nRemediated  \nBudget and Fiscal Impacts  \nThe independent financial statement auditor agreement is from May 1, 2020 to April 30, 2026 fora total amount of $13,250,000 . The fee schedule for the basic financial statements audit for the fiscal year ending 6/30/2025 is $1,060,6301 and $392,760 for the Governmental Accounting Standard Board (GASB) Statement No. 75 audit","cbCaidiHq7WaF4wa","https://ap.wps.com/l/cbCaidiHq7WaF4wa","pdf",179737,"English","# Risk & Audit Committee Agenda Item 5b\n## Review of Independent Auditor’s Management Letter\n## Executive Summary\n## Strategic Plan\n## Background\n## Analysis\n## Budget and Fiscal Impacts\n## Benefits and Risks\n## Attachments","[{\"question\":\"What decision does Agenda Item 5b request?\",\"answer\":\"It requests approval of the CalPERS Board of Administration’s independent auditor Management Letter for the fiscal year ended June 30, 2025.\"},{\"question\":\"What is the main focus of the Management Letter draft?\",\"answer\":\"It provides comments and recommendations to strengthen internal controls over financial reporting based on the audit of the June 30, 2025 financial statements, including management’s responses and proposed corrective actions.\"},{\"question\":\"What issue was observed in the current year and how was it remediated?\",\"answer\":\"BDO observed inappropriate access to a developer role that could create segregation of duties conflicts and lacked audit proof for configuration controls. Management removed the developer access from the user who had inappropriate access to the development environment, and regular review of change logs is recommended.\"}]","Risk & Audit Committee - Agenda Item 5b - Review of Independent Auditor’s Management Letter | PDF",1789556919]