NCAA Sports Wagering and Tampering Risks May Not Easily Lend Themselves to Traditional Auditing Practices

By Josh Lens

College athletics constituents, casual observers, and the national media decry the current college athletics landscape as lacking rules or effective enforcement of them. As of this writing, however, the judge and jury of the National Collegiate Athletics Association’s (NCAA) rules enforcement system – the Committee on Infractions (COI) – has processed nearly 50 infractions cases since January 1, 2025. This is on par with the most cases the COI has ever processed in a similar time span.

Two of the NCAA rules frequently at issue in these cases are the NCAA’s sports wagering ban and what is colloquially known as its tampering prohibition. The risks that accompany a COI adjudication that a violation of either rule occurred are significant:

  • Dozens of collegiate athletes have lost their collegiate competition eligibility for their involvement in illicit sports wagering in 2025 and 2026.
  • Numerous athletics staff members and coaches have been suspended or terminated from their positions due to sports wagering or tampering violations.
  • These penalties on involved individuals are in addition to the significant resources that universities must expend when going through the NCAA’s rules enforcement process.

This article describes trends in recent NCAA infractions cases, specifically the relatively high number of cases involving violations of the NCAA’s sports wagering and tampering prohibitions, as well as the penalties and effects that universities generally encounter when their constituents violate these rules. Finally, the article suggests that auditors may need to be creative when providing assurance or advisory support in these areas, as traditional auditing practices may not easily apply to them.

Sports Wagering

Nearly half of the 50 infractions cases the COI has processed in 2025 and 2026 involve a student-athlete, athletics administrator, and/or coach violating the NCAA’s prohibition on sports wagering. Despite widespread legalization of sports betting by state legislatures, the NCAA has maintained its long-held position that collegiate athletes, coaches, and athletics administrators should largely refrain from wagering on sports. Specifically, throughout its three divisions, the NCAA sports wagering rule prohibits these individuals – and non-athletics department staff members with responsibilities within or over the athletics department (e.g., president or chancellor, faculty athletics representative) – from knowingly participating in sports wagering or providing information to individuals involved in or associated with sports wagering.

The NCAA’s definition of sports wagering includes placing a wager on any intercollegiate, amateur, or professional team or contest in which the NCAA conducts championships. Thus, these individuals may not bet on professional sporting events like regular season NFL games or the Super Bowl or college games like those during men’s or women’s March Madness. The NCAA’s sport wagering ban generally extends to prop bets on collegiate and professional athletes and games and many fantasy sports leagues and contests.

When caught violating the rule, athletes often lose their collegiate competition eligibility. Coaches and administrators can face lengthy suspensions and jeopardize their employment. The ease with which individuals can bet (e.g., through their smartphones), the increasing societal acceptance and legalization of sport wagering, and the presumption that they will not be caught may lead some to disregard or risk the potentially harsh consequences.

Many violations of the NCAA’s sports wagering prohibition come to light as a result of the NCAA’s integrity monitoring system, which it touts as the world’s largest. The system monitors tens of thousands of collegiate athletics competitions for suspicious betting and playing activity. Some universities and athletics conferences, including the Southeastern Conference, utilize additional integrity monitoring programs for sports wagering activities.

Given the ease with which individuals can place bets on their personal devices and the existence of these integrity monitoring systems, traditional auditing practices may not easily apply to sports wagering in university athletics departments. However, given the significant risk and frequency with which student-athletes, coaches, and administrators have been ensnared in illicit sports wagering, auditors may have a role in assessing related education and monitoring activities.

One area in which auditors could engage is examining whether athletics department staff members – likely the individual(s) with compliance responsibilities – have provided sufficient education on the NCAA’s sports wagering prohibition to student-athletes, athletics staff, and coaches. At a minimum, this should include general rules education at the beginning and end of academic years and at certain times of the year when constituents may be tempted to wager on sports, like around the Super Bowl or March Madness. When doing so, individuals with compliance responsibilities can point to recent instances where individuals ranging from high-profile college coaches to student managers working in football equipment rooms lost their jobs, and dozens of men’s basketball student-athletes lost their competition eligibility due to illicit sport wagering. When processing cases involving coaches’ and athletics staff members’ sport wagering violations, the COI has examined whether the involved individuals received such education from the athletics department. A failure to satisfy this inquiry could lead to additional violations and/or penalties for a university.

Tampering

NCAA rules prohibit coaches, athletics staff, and boosters at Division I and II universities from engaging in what the national media and college athletics constituents commonly refer to as “tampering.” In this context, tampering means communicating with a student-athlete enrolled at another four-year university before that individual’s information is entered in the transfer portal. The rule for Division III athletics staff and boosters differs but generally prohibits contact with individuals enrolled at another four-year university prior to receiving written permission to communicate with them if their university does not utilize the transfer portal (portal usage is currently optional in Division III but becomes mandatory on August 1, 2026). The rules go so far as to prohibit indirect communication with individuals associated with the student-athlete (e.g., family members, high school coaches, advisors) before the appropriate time.

Coaches and the national media describe tampering as widespread, and the rules prohibiting it as generally unenforced. In reality, however, the COI has processed numerous cases since January 1, 2025, that included a tampering violation. These cases include high-profile coaches and/or sport programs at Oklahoma State University, UCLA, Virginia Tech University, and the University of Iowa.

In the latter case, the COI explained that the NCAA’s tampering prohibition “…is clear, and there is no gray area. … The student-athlete must enter the transfer portal for any contact to be permissible.” These comments were on the heels of the COI’s statement in the UCLA case that “tampering conduct is relatively straightforward and uncomplicated.”

The risk of getting caught tampering is significant. Not only do these violations often result in fines of tens of thousands of dollars, but coaches are also often suspended, among other penalties. These consequences are in addition to the significant resources that universities expend throughout the NCAA’s infractions process.

Though NCAA rules prohibiting tampering are “straightforward,” monitoring compliance with them is not. Illicit tampering like indirect contact between sport staff members and student-athletes enrolled at other four-year universities – perhaps through their agents – occurs frequently and is difficult for athletics administrators, including compliance directors, to monitor. Compliance directors can attempt to cover their bases from a monitoring standpoint by doing things like:

  • Having sport staff members sign a form annually in which they confirm that they did not engage in pre-portal contact with student-athletes enrolled at other four-year universities.
  • Having incoming student-athletes review and sign a form acknowledging that they did not engage in, and are unaware of, pre-portal contact with coaches at the university.
  • Refusing to conduct academic evaluations of potential transfers until the athlete’s information is entered into the transfer portal.
  • Reviewing sport staff members’ phone call logs to ensure pre-portal communication has not occurred.

Given the significant risk and frequency with which tampering occurs, auditors may be able to help support compliance by evaluating related education and monitoring processes. First steps could include becoming familiar with the education that sports staff members receive regarding tampering and the processes that athletics staff with compliance responsibilities utilize to monitor for tampering. Auditors could perform targeted testing by, for example, analyzing a subset of coaches’ phone records to ensure that compliance administrators did not overlook any instances of pre-portal communication when performing their monitoring.

Conclusion

The NCAA’s rules prohibiting sports wagering and tampering are straightforward and carry significant risk when violated. However, recent data shows they are among the NCAA’s most often violated rules. While traditional auditing practices may not easily apply, auditors can help ensure that athletics administrators provide appropriate education regarding these rules and utilize effective monitoring systems to look for – and deter – instances of noncompliance.

Sharing OU’s Journey to Improve Anonymous Ethics and Compliance Reporting

By Carolyn Clink

Anonymous ethics and compliance reporting programs are a critical component of institutional governance in higher education, yet their effectiveness depends on far more than awareness alone. Posters, training reminders, and website links may create visibility, but utilization is ultimately shaped by trust in the system, clarity of the reporting process, and the institution’s follow-through once a concern is raised.

Over the past five years, the University of Oklahoma (OU) undertook a series of incremental but deliberate enhancements to its anonymous reporting hotline and case management practices that collectively strengthened utilization, improved the experience for reporters and case managers, and produced more reliable data for oversight and improvement. The results offer a practical example for institutions seeking to move beyond awareness toward sustained performance.

Enhancing the Hotline Intake Process

OU transitioned from a single general intake site launched in 2016 to campus‑branded “Report It!” sites in 2021 and expanded the program to all system campuses. Although branding may appear primarily visual, it also serves to reassure users that the reporting site is an official institutional channel, which can enhance credibility and encourage reporting. Ease of access can be the difference between a completed report and an abandoned attempt. OU improved usability through the addition of mobile reporting access, streamlined intake questionnaires, and automatic system responses which allowed reporters the comfort that their complaint was being addressed.

One of the most common friction points in hotline intake is asking reporters to choose from an overwhelming list of reporting categories. OU reduced its issue types from 46 to 26, aiming to make selection faster and more consistent. Better taxonomy helps reporters spend less time guessing where their issue fits and also benefits case managers with clearer issue routing. OU also refined issue categories to better align with institutional risk areas.

OU added process overviews and resource links directly to the intake sites. This created a more transparent reporting pathway by giving users additional context about how the process works and where to find related support resources. In 2025, OU also added a detailed “Your Obligations as a Reporter” statement to the websites, reinforcing expectations around good faith reporting, non-retaliation, and the consequences of false reporting. This type of clarity can reduce misuse while strengthening confidence in the integrity of the process.

With the reporting process easier to navigate, OU focused next on ensuring students, employees, and other stakeholders knew when and how to use it.

Awareness Efforts

Intake improvements were paired with sustained awareness efforts for the Report It! program rather than initiating a one‑time launch. Highlights across the timeline included:

  • 2021 enhancement launch: posters, a presidential mass email, an internal newsletter article, and integration into manager orientation.
  • 2022 refresh: adding digital signs and improving poster placement through walkthroughs and public-space targeting.
  • 2023–present: collaboration with enterprise risk stakeholders to meet specific group needs.
  • 2024–2025: expansions into student-facing channels, including wallet cards at events, move-in initiatives, arena signage, tabling, and training touchpoints.

Over time, awareness efforts were implemented through successive outreach activities tailored to different campus settings, audiences, and communication channels.

Case Handling Improvements

Enhancing awareness and the reporter experience, however, represented only half of the effort. The second half is ensuring the internal system supports consistency, speed, and reliable outcomes. OU’s enhancements for case managers included:

  • Reducing duplication in questionnaires and data capture.
  • Clarifying definitions and aligning stakeholders on issue type meaning.
  • Adding search functionality to find and manage cases more efficiently.
  • Single sign-on to reduce access friction.
  • Training for subject matter experts after software enhancements.
  • Expansion of functional add-ons, including a Clery Act CSA reporting tool in 2024.

These changes positively affected cycle times, documentation quality, and reporting consistency, which influenced reporter confidence in the overall process.

To further support consistency, OU formalized case management standards with clear timelines and required documentation. Cases were assigned within 24 hours, status updates were expected within two business days, and post-closure follow-up was required. Defined case closure protocols and required data fields, including outcome, action taken, Clery indicators, and synopsis notes, were established to improve comparability across cases and time periods. OU also established a five-business-day post-closure period during which reporters may provide clarification or supplemental information, which is particularly valuable for anonymous reports that initially lack sufficient detail for investigation.

These standards enabled more reliable monitoring, reporting, and benchmarking and reduced variability that can undermine KPI analysis.


KPIs and Benchmarking

With structured data in place, OU developed a KPI framework that examined both intake and outcomes. Key metrics included:

  • Intake volume by campus and issue type
  • Intake method
  • Anonymous reporting rate
  • Open versus closed case counts
  • Average case closure time
  • Substantiation rate
  • Outcomes and actions taken
  • Anonymous follow-up rate

These metrics supported internal monitoring, transparency with senior leadership and the Board of Regents, and continuous improvement discussions with subject matter experts. Importantly, metrics were used as management tools rather than static scorecards, enabling conversations about awareness, investigative effectiveness, policy clarity, and organizational culture.

One notable KPI goal was to reduce the number of anonymous reports. This sounds like the opposite of what a hotline program desires. A consistently high anonymous rate may suggest concern about retaliation, limited trust, or uncertainty about the reporting process. OU’s rationale was aligned with mature program thinking. Named reporters tend to be more engaged, and increased trust often reduces the perceived need for anonymity. Additionally, better collaboration with the reporter supports faster resolution and increased trust.

Once consistent metrics were in place, the program moved from basic volume tracking to broader questions about patterns, policy implications, and preventive action. OU’s reporting and analysis approach supports:

  • Trend analysis and risk identification
  • Targeted recommendations for program improvements
  • Better governance reporting for transparency
  • Reinforcement of behavioral expectations (e.g., recommendations for improved employee civility expectations; student antibullying and social media expectations)
  • Feedback loops into academic units to monitor follow-through and actions taken

This way hotline programs can contribute to institutional value: by addressing individual cases while also informing policy, systems, and culture over time.

Results of the Improvements

The cumulative impact of these enhancements was measurable. Case intake increased in each reporting period reviewed, with growth of 58 percent from 2020 to 2021, 23 percent from 2021 to 2022, 24 percent from 2022 to 2023, and 16 percent from 2024 to 2025. Viewed collectively, these trends suggest that coordinated improvements to intake design, awareness, and case management can support sustained utilization rather than temporary spikes.

OU’s intake rate increases between 2020-2024 (metrics by Carolyn Clink)

In addition to increased volume, the quality and disposition of reports provided further insight into program effectiveness. In calendar year 2024, 55 percent of hotline reports contained sufficient information and/or reporter engagement to support an investigation, representing 303 cases investigated to resolution. Thirty-five percent of reports lacked sufficient information to resolve the matter, while the remaining 10 percent were either referred outside the University or determined to be frivolous. These results highlight both the value of increased utilization and the continued importance of enhancing report quality and reporter engagement.

Over time, improved data allowed OU Internal Audit to analyze trends and make recommendations to management to refine policies such as employee civility and student conduct expectations, and to provide more targeted feedback to academic and administrative units.

OU’s ongoing efforts also include a focus on consolidated incident reporting across disparate systems, with stakeholders working to cross-reference data and report consistent KPIs across platforms so stakeholders can compare trends, strengthen management visibility, and identify emerging risks more consistently.

Key Takeaways for Higher Education Programs

For institutions reviewing anonymous reporting programs, OU’s experience highlights the following practical considerations:

  • Simplify intake – Reduce friction, clarify categories, and add clear guidance.
  • Support trust – Branding, transparency, and follow-through can influence whether individuals report.
  • Fix the internal workflow – Case manager experience shapes speed, consistency, and data quality.
  • Standardize case handling – Clear timelines, definitions, and required closure fields improve consistency and reporting quality.
  • Use KPIs that inform action – Metrics are most useful when they support operational and governance decisions.
  • Plan for cross-system visibility – Multiple reporting platforms require stronger coordination over time.

For higher education institutions, anonymous reporting systems are most effective when usability, process discipline, and performance measurement are addressed together. OU’s experience suggests that incremental operational changes can improve both utilization and consistency over time.

Metrics that Matter: How KPIs Define and Demonstrate Success

By Lisa Beymer and the ACUA Audit and Accounting Principles Subcommittee

While the term “Key Performance Indicator” (KPI) is not used in the Institute of Internal Auditor’s (IIA) revised Global Internal Audit Standards for considering the internal audit department’s effectiveness, it is clear that performance measurement is not optional. The underlying expectations call for internal audit functions to clearly define, monitor, and report on meaningful measures of performance. These measures are essential not only for demonstrating conformance to the Standards but also serve as objective evidence of Internal Audit’s effectiveness and value.

The following key Standards elevate the importance of performance measurement:

  • Standard 8.3 requires the Chief Audit Executive (CAE) to maintain a quality assurance and improvement program that evaluates efficiency and effectiveness.
  • Standard 8.4 has the expectation that external quality assessments evaluate whether the internal audit function is actively monitoring performance.
  • Standard 9.2 requires supporting initiatives that align with Internal Audit’s strategy.
  • Standard 12.2 specifically calls for developing objectives to measure performance.

Additionally, the IIA has released their IIA Performance Measurement Tool that provides guidance on conforming with Standard 12.2 on performance measurement.

KPI Examples for Internal Auditors

Are your KPIs addressing the right risks and making a meaningful impact? Effective KPIs should directly align with your department’s strategy, areas of improvement needed, and stakeholder expectations. KPIs can also be internal or external – designed for the benefit of the internal audit shop or to furnish outside leadership with performance information.

Measuring Activity and Value in Thoughtful KPI Design

Take your KPIs even farther by tying them to goals to drive positive action rather than simply reporting activity. Rather than only reporting the quantity of engagements completed during the year, set a desired completion rate as a goal. For example, “we completed 18 of 20 planned engagements,” can be tied to a goal by stating “we completed 90% of our planned audits, which exceeds our goal of 85%.”

Make sure your goals are SMART – specific, measurable, achievable, relevant, and timely. For example, a goal to “decrease time spent in reporting” can become a SMART goal by adding details, such as “decrease average days spent in reporting from 45 to 30 by the end of this calendar year.”

Monitoring KPIs can be achieved using the simplest of manual Excel spreadsheets to embedded dashboards and modules from audit workpaper management software. Progress on KPIs is often shared with senior management and the board through annual reports and board presentations.

The Double-Edged Sword of KPIs

Well-designed KPIs drive quality, accountability, and continuous improvement. On the other hand, poorly designed or managed KPIs can encourage shortcuts, misaligned priorities, or even unintended manipulation. For example, overly emphasizing a shorter audit cycle time could lead to rushed fieldwork. Encouraging a high number of audit findings could lead to auditors making mountains out of molehills, which may negatively affect your department’s credibility.

There are numerous challenges to developing a KPI system. The ability to gather and update data from multiple sources can be time consuming, and data reliability may become a factor. There is a risk of only measuring the activity versus its impact. KPI results may be misinterpreted by management, and CAEs may be tempted to skew the statistics to appear more favorable. Additionally, the audit team may be reluctant to adapt to new goals.

When creating balanced and relevant KPIs, consider the following practical implementation tips:

  • Measure what is most meaningful, not just what is easiest to track.
  • Focus on outcomes, not just activity.
  • Define KPIs clearly to avoid confusion in how they are measured.
  • Avoid KPI overload – keep the team focused on the metrics that matter most.
  • Be balanced – include multiple dimensions of performance measurement.
  • Involve the team to promote accountability and buy-in.
  • Periodically review KPIs to ensure they are not outdated or irrelevant.

Well-defined KPIs can improve the audit department’s effectiveness and efficiency while addressing the new Global Internal Audit Standards. With the new fiscal year approaching, this is a great time to evaluate and enhance your department’s KPIs.

Honeypots: An Advanced Solution in IT Threat Detection

By Mark Ledman

Cybersecurity threats continue to evolve and broaden the threat landscape. In this time of artificial intelligent (AI) technology advancement, the threat actors, who used to be highly skilled technical people, are no longer dependent on advanced technical knowledge. Conversely, we have learned through the CrowdStrike Global Threat Report  about organized threat actor organizations, their behaviors, and the types of cyberattacks they are involved in. The skills of some threat actors have increased to the level where think tank organizations are recognizing that some of the threat actors have the skills of data scientists.

During this time of change and advancement of generative and agentic AI and AI malware, many organizations are rethinking their security strategy. An important aspect of their security strategy, or security posture, is an improvement in their threat detection. If one layer of your organization’s defense strategy does not detect an attack, ideally another layer will.

Educause—a nonprofit association and large community of IT leaders—reports year-over-year growth in cyberattacks against higher education, with education now the most targeted sector globally. A topic that auditors should be asking their Chief Information Officer (CIO), Chief Information Security Officer (CISO), or Information Technology Security Officer (ITSO), is what changes or improvements are being made in their defense strategy as part of the changing cybersecurity threat landscape? Is your CIO considering using honeypots as part of their cybersecurity strategy?

The purpose of this article is to provide some information on a security tool and strategy that I have become familiar and intrigued with while observing a work team build and deploy a decoy network and series of honeypots. A honeypot can be used as a security mechanism to detect cyberattacks. Essentially, a honeypot is set up as a decoy to lure cyber attackers and detect, deflect, and study hacking attempts to gain unauthorized access to information systems. The results were immediate. In under eight minutes a newly deployed honeypot was experiencing threat activity. While I was impressed this activity happened very quickly, a security engineer informed me the average time for threat actor activity on a new honeypot is usually less than two minutes!

Honeypot Management Systems

A Honeypot Management System manages networks of honeypots and provides real-time data and real-time blocking of threat actors. Such a tool can leverage the strength of a consortium of colleges, universities, and other research institutions (collectively “Higher Ed”) that share real-time data with each other to block threat actors. For example, if a threat actor begins engaging with a honeypot on the West Coast, the moment the honeypot blocks the threat actor at the Higher Ed institution, the system immediately relays the threat intel to a central server. One can  visualize this as a central hub with threat intel going to the hub and then relaying that same information simultaneously back out to the participating Higher Ed institutions blocking the threat actor IPs and Autonomous System Numbers (ASNs) in real time.

The education sector is now the most attacked industry globally, with institutions facing an average of 4,388 cyberattacks per week in 2025 [source:deepstrike.io]. One such Honeypot Management System, called STINGAR, purports to have over 100 participating Higher Ed organizations. Each organization identifies and blocks new IP addresses and ASNs and shares this information with other users to reduce the risk of their organizations being attacked and penetrated by known malicious actors. By collectively identifying and addressing threats, an institution on average could block half a million cyber threat actors per week using this security tool. That is potentially an average of over 20 million attacks per year!

Good questions to ask your CISO include: “What kind of policy or procedural enhancements are you making as a result of your alert or error analysis? How much time is being used to follow up on false positives? How much time is your security team working with the vendor to keep the solution up-to-date? The Honeypot Management System solution helps to check the boxes. Once the automated solution is set, there is minimal ITSO support required. From time to time, some higher ed organizations will move the various honeypots around to confuse or change the environment to provide a new look for a would-be threat actor. Honeypots can be deployed on-premise or in a cloud environment.

STINGAR was developed by the Security Operations Team at Duke University and provides this service to the higher ed community. The STINGAR website includes information about the product plus statistical information compiled from their threat detection system.  The system gathers various types of threat data such as threats from other countries. A map of the globe is on the website that provides data points where the threat activity is coming from and a list of top countries by malicious IPs and number of ASNs.

How Honeypots Work

The following is a graphic to understand just how a decoy network with honeypots might look within a typical university network.

Honeypot diagram provided by STINGAR Team, IT Security Office, Duke University

A typical enterprise network connects to the Internet through a high-speed wide area network (WAN) via an edge router. Incoming data packets from the Internet are first processed by this router, which then forwards the packets into the internal enterprise network. These packets are typically inspected by a dedicated security system known as a firewall(or, more broadly, an intrusion detection or prevention system, IDS/IPS).

The firewall applies a set of predefined rules to evaluate incoming traffic, filtering out packets that match known malicious patterns or signatures. Packets identified as harmful are discarded (“dropped”), while the remaining traffic is allowed to proceed. However, not all malicious activity is easily identifiable—many attacker packets appear benign and do not match known signatures. As a result, a significant portion of potentially harmful traffic can pass through to internal network segments (such as Finance, Legal, Human Resources, Engineering, and the Registrar) and ultimately reach enterprise systems, including email and web servers, databases, user devices, and other connected equipment.

To address this limitation, organizations deploy honeypots—specialized systems designed to detect and study malicious activity. Honeypots are typically installed on a small number of systems within the network and function as controlled decoys (see image with honeypot magnifying glass for example). They are intentionally configured to appear vulnerable, thereby attracting attackers who are scanning for weaknesses.

When an attacker interacts with a honeypot—such as attempting to access a simulated service, exploiting a perceived vulnerability, or installing malicious software—the activity is immediately detected and recorded. This information is then transmitted to the honeypot management platform.

The platform aggregates this data and updates a “blocklist,” which is a continuously maintained list of identified malicious sources. This blocklist is automatically distributed to network enforcement points such as firewalls and edge routers. Once updated, these systems can identify and block any subsequent traffic originating from those malicious sources, preventing further access to the enterprise network.

This detection and response occurs automatically within seconds. From the attacker’s perspective, the enterprise network may appear to become unreachable, effectively cutting off further interaction.

In practice, this approach can significantly reduce malicious traffic within the network—often by a factor of 10 to 100 times. Under certain high-volume attack conditions, such as distributed denial-of-service (DDoS) events, reductions can be even greater, with the system blocking extremely large volumes of unwanted traffic. This both helps protect enterprise assets while allowing normal network operations to continue without manual intervention.

So, what does it take to build these honeypots? There are a couple of ways they can be built. At Duke University, STINGAR was first introduced in 2016, and has been in use for the past 10 years to protect Duke’s network. The people that are managing these have learned many of the behaviors and activities the cyber threat actors use. One way to build a honeypot is for your team of security architects and software engineers to build these from the ground up. Another way is to use an AI-agent tool to build the honeypot for you. The AI-agent tool includes an AI-agent for quality assurance to ensure your build is according to business needs and specifications.

There are many different types of honeypots, and each type will have a different profile visible to the attacker and mimic different behaviors of computer resources they represent, and each has a different level of allowable interaction with the threat actor before the trap is sprung. Once the honeypot is deployed, attack analysis reports are available in real time and brute force attacks on the network will be identified.

Conclusion

There is a continuous virtual arms race between the attackers using various threat exploits and the network defense teams. Attackers are continuously looking for different types of targets and data. AI-powered bots are scanning for high value research or user credentials, attempting to run cryptocurrency mining code on university CPU & GPU hardware assets, and other malicious scenarios. Honeypot management systems provide a live dashboard report indicating these attacks and where they came from in real time while blocking the source of the attacks to prevent further impact.

AAP Roundtable: Strategies for Risk Assessments, Developing Findings, and Follow-up

By Susie Geiger and the AAP Subcommittee

On January 14, 2026, the Auditing and Accounting Principles (AAP) Subcommittee of the Association of College and University Auditors (ACUA) hosted a roundtable to help institutions strengthen conformance with Domain V of the updated Institute of Internal Auditor’s Global Internal Audit Standards. The session focused on three standards central to effective engagement execution: Standard 13.2 on engagement risk assessments, Standard 14.2 on analyses and developing potential findings, and Standard 15.2 on confirming the implementation of recommendations or action plans. Nearly 50 ACUA members participated by sharing challenges, comparing practices, and identifying strategies to improve consistency, efficiency, and quality across their audit functions.

This highly interactive roundtable was facilitated by AAP Committee members Hollie Andrus, Patty Davidson, Jennifer Dent, Erin Egan, John McDaniel, and Agnessa Vartanova. After sharing the requirements of each of the Standards, the participants met in breakout rooms to discuss how institutions conduct and document risk assessments, analyze information to identify findings, and perform follow-up activities. These discussions are summarized below.

Standard 13.2 – Engagement Risk Assessments

Standard 13.2 requires internal auditors to understand the activity under review, assess relevant risks, evaluate governance and compliance processes, and identify the significance of risks, including fraud risks. Institutions reported that meeting these expectations consistently remains a significant challenge. In the breakout rooms, participants were asked to discuss the question “How does your institution conduct and document your engagement risk assessments?”

Challenges in Risk Assessment

Several audit shops struggle with training auditors to identify and analyze risks in a consistent manner across diverse engagements. Limited subject‑matter expertise, particularly in IT and fraud, further complicates risk identification. Many offices also lack tools or data analytics capabilities to support more sophisticated assessments.

Organizational dynamics add another layer of difficulty. Risk tolerance varies widely across campus units, and leadership turnover can disrupt expectations. Smaller audit shops, in particular, often lack a centralized risk management function to help define institutional risk tolerance and appetite. Communication barriers also arise when auditors and clients use terminology differently, leading to misunderstandings that hinder risk identification.

Strategies for Improving Risk Identification and Evaluation

Despite these challenges, participants shared a range of practical strategies for effectively identifying and evaluating risks. Many offices have adopted standard templates to document risk assessments and utilize inventories of common risks, including ones specifically related to fraud. Others conduct team brainstorming sessions at the start of each engagement to determine potential risks.

Audit functions are also drawing on diverse information sources such as prior audit reports, peer institution audits, policies, strategic plans, regulatory guidance, and ACUA resources such as the Risk Dictionary. Some offices incorporate frameworks like the Association of Certified Fraud Examiner’s (ACFE) Occupational Fraud Framework to strengthen evaluation of fraud and other types of risks. Some shops work directly with their institution’s risk management office to get an understanding of the institution’s risk tolerance and appetite. A few institutions have hired a Certified Fraud Examiner or are encouraging existing auditors to pursue the designation with the support of the office.

To improve consistency, several participants described developing scoring systems for prioritizing risks and creating standard lists of client questions to guide kickoff meetings. Others emphasized the value of pre‑engagement research and the use of asking the client open‑ended questions such as “what can go wrong?” to uncover contextual risks. Another suggestion was to provide audit clients with a confidential method for communicating their concerns to internal audit.

Standard 14.2 – Analyses and Potential for Engagement Findings

Standard 14.2 requires auditors to analyze relevant, reliable, and sufficient information to develop potential findings and evaluate identified differences between the evaluation criteria and the existing state (condition) to determine which are reportable findings. In the breakout rooms, members shared several challenges they have faced in developing testing observations into reportable findings and worked together to brainstorm strategies for improving conformance with this standard. Participants were asked to discuss the questions “How does your institution conduct and document your engagement risk assessments?” and “How much testing is needed for assurance engagements to develop an issue?”

Challenges in Testing and Analysis

Higher education institutions often have multiple decentralized systems that do not interface, leading to inconsistent datasets that complicate testing.  Participants also identified inconsistent testing methodologies, lack of standard templates, and difficulty balancing over‑ and under‑documentation as common concerns which can lead to poor quality assurance.

Some offices reported experimenting with AI tools but expressed uncertainty about evaluating the reliability of AI‑generated results. Others noted that some clients may not fully understand internal controls, making it harder to validate observations or explain findings. Several participants also said that their offices have trouble performing root cause analysis, especially for newer auditors who may be tempted to rely on assumptions rather than structured analysis.

Strategies for Enhancing Finding Development

Participants shared several approaches to improve testing quality and consistency. Many offices use verification between data sources to validate accuracy. Others have adopted standard testing templates with required fields but built‑in flexibility to accommodate diverse audit areas.  Some shops have created specialized procedures and templates for conducting and documenting the testing of regularly reviewed processes like travel expenses and procurement card transactions.

Training plays a central role, and many offices are emphasizing documentation expectations during onboarding and ongoing professional development. Audit management software, such as TeamMate, helps some teams link risks, controls, and testing more effectively. To strengthen root cause analysis, participants recommended techniques such as the “five whys” and incorporating client input. AI tools may also support testing when procedures are carefully designed and validated.

Determining the Extent of Testing

Participants also discussed how much testing is needed to develop a finding. Resource constraints and inconsistent access to data prevent audit functions from effectively employing population-level analysis at a significant scale, leading many offices to rely on judgmental sampling. Some auditors also struggle to move beyond inquiry and neglect to corroborate client statements with evidence. Several participants said that their offices do not have procedures for assessing and prioritizing/ranking identified observations.

To address these issues, offices are developing standard definitions of “relevant, reliable, and sufficient” information aligned with Standard 14.1. Others use external frameworks (AICPA, FASB) to guide finding criteria. Risk decision matrices help some teams evaluate materiality and determine whether an observation warrants verbal communication or a formal finding. Some shops are making efforts to transition from testing small samples to population-level testing when feasible. Auditors are also being trained that inquiry is often not sufficient to confirm or dismiss a finding; they should corroborate management statements with observation, examination, or reperformance.

Standard 15.2 – Confirming the Implementation of Recommendations or Action Plans

Standard 15.2 requires internal audit functions to confirm whether management has implemented action plans and, when they have not, to follow the CAE’s established guidelines for management acceptance of risk. Participants were asked to discuss the question “How does your institution monitor and perform follow-up activities?” and discussed the following related challenges and strategies in the breakout rooms.

Challenges in Follow‑Up

Follow‑up processes are often less structured than planning or testing phases. Many offices rely heavily on e-mail and phone communication and lack standardized tools for tracking status updates. Some participants felt the follow‑up process is treated like an afterthought and receives much less attention and standardization than the planning and testing phases.

Delays in management action plan completion are common, and some clients do not provide explanations or updated timelines. Auditors also struggle to balance accountability with maintaining positive client relationships. Determining what constitutes sufficient verification, especially when deciding between retesting and reviewing client-provided evidence, remains a challenge.

Strategies for Effective Follow‑Up

Participants highlighted several practices that improve follow‑up effectiveness, including transitioning from “trust but don’t verify” cultures to more evidence-based follow-up procedures. Some offices include follow‑up activities directly in the audit plan to signal their importance to leadership and audit committees. Many have also developed standard templates for documenting action plan status updates.

Regular follow‑up cadences, such as every 90-120 days, help maintain momentum. Some offices conduct interim check‑ins rather than waiting for due dates, which has improved implementation rates. Prioritization methodologies also help identify high‑risk findings that require closer monitoring or escalation.

Clear communication is essential. Some offices have the client determine the specific action plan, with internal audit approval, to mitigate each finding rather than prescribing action plans they may not fully understand. During reporting, auditors define what “implemented” will look like for each action plan and explain how non‑responsiveness may be escalated. Some offices require written justifications for non‑implementation or use standard forms for documenting risk acceptance. Others report overdue action plans to leadership using dashboards and visualizations, and a few require clients to present their rationale for non‑implementation directly to the audit committee.

Conclusion

This roundtable generated discussion that was fruitful and varied, allowing participants to find comfort in shared struggles while also coming together to share creative ideas for solutions. Participants reported in a post-event survey that they found the roundtable valuable and would be interested in attending future roundtables focused on the Standards, as well as other topics.

The AAP Subcommittee will host another roundtable focused on conformance with Standards 13.2, 14.2, and 15.2, this time from the lens of conducting advisory work. This event is tentatively scheduled for Wednesday April 15, 2026, and invitations to register for the session will be e-mailed soon.

Athletics Business Office: Emerging Changes and Challenges

By Rachel Flenner, Bret Malone, and Marie Jackson

With recent developments such as Name, Image, and Likeness (NIL) regulations and emerging revenue‑sharing models as a result of the House vs NCAA settlement, many institutions may not fully recognize how significantly these changes impact the Athletics Business Office (ABO). The ABO is now responsible for executing payments to student-athletes arising from revenue-sharing agreements. Also, the ABO must update their NCAA reporting related to new line items related to the House settlement implementation and may need to update or create new structures in existing financial systems to accurately capture these costs. Not only must coaches and student‑athletes stay informed, but ABO staff must also ensure policies, procedures, and internal controls are functioning appropriately to keep pace. This article highlights key areas auditors should consider as they work to support the ABO in a rapidly evolving collegiate athletics environment.

Background

The College Sports Commission (CSC) is the entity created by the “Power” conferences (Atlantic Coast Conference (ACC), Big Ten, Big XII, and Southeastern Conference (SEC)) to oversee the implementation of the House settlement, including mandating the use of two new systems:

  • NIL Go  is the online platform used by student-athletes to report new third-party NIL deals over $600, with reporting expected within 5 days of each executed deal.
  • College Athlete Payment System (CAPS) is for entering revenue-sharing payments made against the annual cap ($20.5 million in FY25-26).

Financial Management

The first area of biggest impact is on the financial stability of athletics’ operations. Key risks to keep in mind regarding financial implications include:

  • Financial instability leads to the elimination or reduction of key services, personnel, and non-revenue generating sports.
  • Inability to sustain maintenance or facility improvements, debt service, or salaries.
  • Use of restricted or unallowable sources of funds to cover revenue-sharing expenses.
  • Failure to adapt and innovate financial modeling needs to consider both cost reduction and revenue maximization.
  • Increased travel and booking costs due to conference realignments.
  • Misalignment with institution leadership regarding how revenue share payments will be allocated among sports.
  • Overcommitment of funds through coaching decisions, contractual guarantees, offered Alston settlement benefits, incremental scholarships, or contingent payments included in agreements.
  • Financial statement misstatement due to improper allocation or reporting of revenue‑sharing funds.
  • Future litigation in the NIL and revenue-sharing space could lead to unexpected financial losses.
  • Inaccurate tracking, which results in financial penalties for exceeding the revenue-sharing cap or incremental scholarship cap.
  • Long-term financial risks related to private equity investment.

Contract Management

Another area to consider involves contract management. Organizations use contracts to obtain different services or products at all levels of athletics. Additionally, contracts are now being used more frequently to guarantee payments to student-athletes, adding a new risk area. ABOs should consult with university counsel to create standard agreement templates to reduce contract risks. In some areas, ABOs may work in collaboration with Athletics Compliance to institute new procedures to mitigate these risks. Some specific risks related to contract management with student-athletes include:

  • Student-athletes and coaches create informal NIL agreements and do not properly document them in an approved contract format.
  • Staffing shortages delay contract processing, approval and or payment, particularly during new enrollment and transfer portal periods.
  • Student-athletes fail to report NIL deals with third parties via the NIL Go Clearinghouse (for fair market value and valid business purpose review).
  • There is no centralized process to ensure revenue-sharing contracts are appropriately tracked and reported to the ABO for financial processing.
  • Standardized revenue sharing agreements are unenforceable or fail to address early departures, ineligibility, buy-outs, or other unique terms.
  • Contract language that creates risks for international student-athletes receiving payments, based on their visa type.
  • Institutional contracts combine NIL and revenue share distributions, creating tracking complexity (only allowable if NIL payment is from the institution not a third party; any guaranteed institutional NIL included in these contracts must also count towards the revenue-sharing cap).
  • Contracts overstate or over-promise funds or commitments to student-athletes that must be paid out regardless of situation (e.g., student-athlete leaving early with large upfront payments already occurring).
  • Inadequate third party contracts for services or software to issue or track payments to student-athletes.
  • Managing potential conflict with pre-existing institutional partnerships and exclusivity clauses.
  • Contracted payment dates to student-athletes that do not consider internal or third-party lead-time needed to establish payment processing (e.g., can you pay the student-athlete on day one of enrollment? This is especially important with portal management).
  • Exposure of sensitive student-athlete data (i.e., banking information, contract terms, etc.).
  • Over reliance or misunderstanding related to third-party tools and reporting (e.g., are roles and responsibilities clearly defined between parties, are data inputs and outputs well understood, and is there monitoring in place to identify issues?).
  • Future compliance issues with Title IX based on revenue-sharing allocations.

ABO Potential Procedures

With so many new and expanded risks, the ABO should consider implementing the following additional controls and procedures:

Roles and Responsibilities

  • Identify the finance and budget lead.
  • Identify revenue share and NIL point personnel.
  • Establish approval authority for revenue contracts (Athletic Director involvement, coach authority, etc.).
  • Verify separation of duties for revenue sharing and NIL (i.e., contract creation, contract approval, disbursement, and reconciliation).
  • Create new processes to initiate and record revenue-sharing agreements by contracted dates.
  • Ensure that new processes incorporate all types of revenue-sharing benefits (e.g., is your institution providing additional benefits such as Alston requirements?).
  • Ensure access to private data (i.e., contract amounts and bank routing information) is limited to applicable employees, and there are privacy safeguards within the software, excel spreadsheets, google docs, etc.

Reconciling and Monitoring

  • Verify gross conference distributions against revenue sharing payments.
  • Ensure agreement between the CAPS system to actual disbursements to contracted amounts ,and document known differences or offsets, in preparation for year-end CSC reporting of revenue-sharing payments.
  • Reconcile revenue share payments in total to per-sport allocations.
  • Identify communication channels to ensure ongoing collaboration and monitoring (likely by Compliance) to ensure payments are made only to eligible student-athletes included on rosters.
  • Monitor cap balances regularly to ensure alignment with institutional allocations.
  • Consider timely communication with stakeholders, and when approaching key thresholds (e.g., 75% of allowable distributions made).
  • Potentially build multi-year forecasts and implications to the budget.
  • Confirm payment distribution method (i.e., direct deposit, monthly, quarterly, tax withholdings, etc.).
  • Verify NIL opportunities exceeding $600 are disclosed, tracked separately from revenue sharing, and are reported through NIL Go.

Training and Communication

  • Train ABO staff and other applicable staff members involved in the NIL and revenue-sharing transactions on NCAA and CSC regulations, as well as applicable institution policies regarding contract management, revenue handling, and disbursement procedures.
  • Train ABO staff and other applicable staff members on the new software that will be used in the NIL and revenue-share process, including privacy (HIPAA/FERPA) and security awareness.
  • Verify staff knowledge aligns with the new tasks, such as financial forecasting and planning.
  • Ensure staff capacities are not being exceeded, leading to gaps in other business office processes.
  • Meet with coaches/administrative staff to ensure all are aligned on the procedures and update them regularly regarding current cap balances and applicable finance situations.
  • Review institutional travel policies and ensure institutional compliance can be maintained with the increase in travel costs due to conference realignments.
  • Document and communicate revenue-sharing allocation methodology to ensure applicable ABO staff members and others (i.e., coaches, ABO, Compliance, institutional leadership, etc.) are aligned and tracked toward agreed amounts.

Internal Audit’s Role

So, you are probably asking yourself, “How can Internal Audit help?” or “I am not an expert on the new requirements, what can I do?” Athletics, despite operating in a very public and rapidly changing environment, can benefit from Internal Audit in a similar way as any other campus unit. For example, Internal Audit can:

  • Evaluate the governance framework in place related to revenue-sharing allocations and strategies.
  • Help evaluate risks and offer an independent and objective assessment of the controls in place to mitigate these risks.
  • Review reconciliation processes for student-athlete payments and assess segregation of duties within revenue‑processing workflows.
  • Evaluate communication and training related to NCAA bylaw and CSC rules requirements for NIL licensing and revenue-sharing.
  • Conduct advisory engagements on new or evolving processes.
  • Ensure process changes still align with institution policy.

While this is just sample of considerations for the ABO, oversight by other offices is also important (i.e., Athletic Compliance, Office of the General Counsel, Tax Office, etc.) Feel free to share this article with your contacts in the ABO. Even sharing best practices and relevant articles with your ABO can provide value. It is more important than ever that the ABO knows where every dollar is going, why it is going there, and whether it aligns with applicable policies and procedures. As Athletics continues to evolve rapidly, auditors play a critical role in ensuring transparency, strong internal controls, and responsible stewardship of university resources.

Methodology Madness: New Standards Guidance for Formalizing Audit Processes

By Kara Hefner

It has been one year since the implementation of the Institute of Internal Auditors’ (IIA) new Global Internal Audit Standards (Standards). Everyone can agree the Standards have become more prescriptive, with more “musts” and “shoulds” than in prior guidance. Another term has come to the forefront: the word “methodology” is found 109 times throughout the 120-page document. There are 13 standards that require documented methodologies, and 17 more that recommend either implementing methodologies or having documented methodologies to provide evidence of conformance.

Gone are the days of simply relying on professional judgment, winging it, and relying on passing the smell test. This article outlines the required and recommended methodologies to aid in consistently application of audit processes.

What are Methodologies?

The term “methodologies” is defined in the Standards’ glossary as “policies, processes, and procedures established by the chief audit executive to guide the internal audit function and enhance its effectiveness.”

As described in Standard 9.3 on Methodology, the chief audit executive must establish methodologies to guide the internal audit function in a systematic and disciplined manner to implement the internal audit strategy, develop the internal audit plan, and conform with the Standards. These methodologies must be evaluated and updated as necessary to improve the internal audit function and respond to significant changes that affect the function. Internal auditors should be trained in the methodologies to ensure consistency within the department.

Documented methodologies are often found in the department’s formal procedure manual, audit charter, and board charter. Some methodologies can be built into workpaper templates, and ratings methodologies are sometimes included for transparency in the final audit reports. It is important that all auditors are familiar with the department’s methodologies, and that reviewers ensure methodologies are consistently applied.

Required Methodologies

Excluding the Methodology standard 9.3 discussed above, the following 12 standards require methodologies to be in place:

StandardMethodology Requirement (abbreviated)
2.2  Safeguarding ObjectivityThe chief audit executive must establish methodologies to address impairments to objectivity. Internal auditors must discuss impairments and take appropriate actions according to relevant methodologies.
4.1 Conformance with the Global Internal Audit StandardsThe internal audit function’s methodologies must be established, documented, and maintained in alignment with the Standards.
11.2 Effective CommunicationThe chief audit executive must establish and implement methodologies to promote accurate, objective, clear, concise, constructive, complete, and timely internal audit communications.
12.1 Internal Quality AssessmentThe chief audit executive must establish a methodology for internal assessments, as described in Standard 8.3 Quality, that includes ongoing monitoring, periodic self-assessments, and communication with the board and senior management about the results of internal assessments.
12.2 Performance MeasurementThe chief audit executive must develop a performance measurement methodology to assess progress toward achieving the function’s objectives and to promote the continuous improvement of the internal audit function.
12.3 Oversee and Improve Engagement PerformanceThe chief audit executive must establish and implement methodologies for engagement supervision, quality assurance, and the development of competencies. To assure quality, the chief audit executive must verify whether engagements are performed in conformance with the Standards and the internal audit function’s methodologies. The chief audit executive must ensure that evidence of supervision is documented and retained, according to the internal audit function’s established methodologies.
13.1 Engagement CommunicationAt the end of an engagement, if internal auditors and management do not agree on the engagement results, internal auditors must follow an established methodology to allow both parties to express their positions regarding the content of the final engagement communication and the reasons for any differences of opinion regarding the engagement results.
13.3 Engagement Objectives and ScopeIf a resolution on scope limitations cannot be achieved with management, the chief audit executive must elevate the scope limitation issue to the board according to an established methodology.
13.6 Work ProgramThe engagement work program must identify methodologies, including the analytical procedures to be used, and tools to perform the tasks.
14.3 Evaluation of FindingsInternal auditors must determine whether to report identified risks as findings, based on the circumstances and established methodologies. Internal auditors must prioritize each engagement finding based on its significance, using methodologies established by the chief audit executive.
14.4 Recommendations and Action PlansIf internal auditors and management disagree about the engagement recommendations and/ or action plans, internal auditors must follow an established methodology to allow both parties to express their positions and rationale and to determine a resolution.
15.2 Confirming the Implementation of Recommendations or Action PlansInternal auditors must confirm that management has implemented their action plans following an established methodology, which includes inquiring about progress, performing follow-up assessments, and updating tracking systems.

Recommended Methodologies

The Standards also recommend implementing methodologies for other topics under their Considerations for Implementation and Evidence of Conformance categories. These recommendations are summarized below by domain:

  • Domain II: Ethics & Professionalism – Methodologies may be created for addressing ethical issues, disclosing objectivity impairments, and handling illegal or discreditable behavior by internal auditors. Methodologies can specify actions internal auditors are expected to take in response to legal or regulatory violations of which they become aware. Memorialize the manner in which internal audit staff are properly supervised and the permissible ways auditors may  access information. (Standards 1.2, 1.3, 2.3, and 5.2)
  • Domain III: Governance – Consider documenting methodologies to be followed when an organizational impairment is suspected or identified. Formally document the board’s expectations. The external quality assessment should include a comprehensive review of methodologies and their adequacy. (Standards 7.1, 8.1, and 8.4)
  • Domain IV – Managing – Methodologies are recommended for creating and reviewing the internal audit strategy, creation of the annual audit plan, communicating with the board and senior management, handling of errors and omissions, and evaluating external providers of assurance and advisory services. To develop and retain internal auditors, have a methodology for staff training, project supervision, evaluating performance, improving competencies, and promoting professional development. Develop methodologies for communicating the acceptance of risks with collaboration from the board. (Standards 9.2, 9.4, 9.5, 10.2, 11.1, 11.4, and 11.5)
  • Domain V: Performing – Adopt methodologies for when to perform additional analysis, considering the adequacy of controls, significance, and cost benefit analysis. Implement a rating scale for determining the effectiveness of controls for the final report. For example, develop a scale to identify satisfactory, partially satisfactory, needs improvement, or unsatisfactory. (Standards14.2, 14.5, and 14.6)

Establishing and Improving Methodologies

Now that most internal audit shops have adopted the new Standards, this is a good time to check up on the required and recommended methodologies. Review the Standards against the procedure manual, charters, and workpaper templates and identify any methodologies that should be created or enhanced. Consider formalizing rating scales to aid in ranking findings and conclusions for final reports. Discuss methodology enhancements with your board to ensure alignment.

Once established, perform ongoing monitoring to ensure methodologies are in place and used consistently. Reviewers should verify workpapers follow the established methodology and help coach their team on process deviations. Periodic self-assessments and external assessments can also aid in providing feedback on the effectiveness of your methodologies.

Prioritizing Rest to Become a Better Auditor

By Tyler Morgan

“And from that period on, I was in a wormhole. You couldn’t get me out of the room. I would come home from school, sleep for like 30 minutes, go into a room for four hours, and that was it.” 

The above quote comes from Rick Rubin’s interview of singer/songwriter John Mayer on the former’s Tetragrammaton podcast, and Mayer is describing his teenage years when he was learning how to play guitar. Practicing an instrument for four hours a day will tend to result in one becoming rather proficient. But maybe there was something else contributing to Mayer’s aptitude on the guitar. He does not dwell on it, but embedded subtly in the middle of Mayer’s quote may be a key insight into how he became such a generational talent: he took time to rest.

As it turns out, Mayer is not the only highly successful person to benefit (consciously or unconsciously) from the power of rest. There are numerous examples of highly successful people who prioritized rest as a way to achieve peak cognitive performance, including iconic politicians, inventors, business leaders, writers, artists, and musicians. Instead of viewing rest as a waste of time that could otherwise be used to get more things done, these individuals understood that adequate rest was essential to ensure their working time was used effectively and efficiently. While internal auditors are busy people, it is clear from numerous examples of prolific and impactful individuals from outside the auditing world that even the busiest among us can benefit from prioritizing rest.

Perhaps the most likely objection to using rest as a way to become a more effective internal auditor is the belief that internal auditors simply have too much to do to be able to prioritize rest, but history suggests otherwise. Take, for instance, Winston Churchill during World War II. Churchill first served as the British prime minister from 1940-1945, and there clearly was a lot riding on his performance during this time, with each day being filled with a monumental list of items for him to handle. However, Churchill had a longstanding habit of taking an afternoon nap, and he deemed the fate of the free world resting on his shoulders as no excuse for missing his afternoon slumber. The naps continued during the war. He did not consider napping to be a luxury but rather viewed an afternoon nap as an essential way to maintain his legendary daily productivity. Churchill wrote, “Nature had not intended mankind to work from eight in the morning until midnight without the refreshment of blessed oblivion which, even if it only lasts 20 minutes, is sufficient to renew all the vital forces.” Naps were not a decadent activity to be enjoyed solely when little was going on, but they instead functioned as a way for Churchill to stay in tune with immutable biological rhythms and maintain peak cognitive performance during a historical period when every decision was critical. 

Since internal auditors are knowledge workers, they tend to be judged on the quality of their work rather than quantity. And since work quality is positively correlated with cognitive performance, and cognitive performance is enhanced with adequate rest, it follows that rest is a lever internal auditors can pull to increase the quality of their work. University stakeholders likely will not be impressed that an internal auditor regularly works 60-hour weeks or that they never take breaks during the workday. Instead, internal auditors will be judged on the quality of their output and how beneficial it is to their university, especially as artificial intelligence and other technological innovations likely will reduce the amount of time needed to be spent on mundane, low-value administrative tasks. Instead of focusing on work quantity, internal auditors should prioritize producing high-quality, meaningful output that goes far beyond cookie-cutter reports and trite recommendations. In a world where ChatGPT can quickly spew elegant, professional-sounding reports with all the right buzzwords but little substance or original insight, internal auditors who are able to think critically and apply their institutional knowledge to solve tough problems will increasingly stand out from the crowd and be extremely valuable to university stakeholders.

There is strong evidence that prioritizing rest will enhance internal auditors’ critical thinking skills and problem-solving abilities. While a nap to break up the workday may not be a realistic possibility for many, the good news is that rest is not just limited to naps. There are lots of ways to rest, and the remaining paragraphs will explore a few tips, tricks, and key insights backed by science to help you get the rest you need. 

Walk

It may seem counterintuitive to list exercise as a way to rest, but there is plenty of evidence supporting the idea that physical exertion can help boost cognitive performance and improve memory. While countless forms of exercise may achieve these results, many studies have focused on walking in particular. This is great news for higher education internal auditors, as college campuses are often some of the loveliest places to take a walk. A campus walk can also be a great way to become more informed about what is going on at your university, whether by walking through unfamiliar buildings or by having informal conversations with faculty and staff you encounter. Walking outside also provides the added bonus of getting sunlight, which has been linked to better mood regulation and other cognitive benefits. The combination of physical exertion and sunlight exposure may even improve sleep. 

Sleep

Even if workday naps are not a realistic possibility for you, there are many things you can do to at least ensure the quality of your nighttime sleep. In addition to regular exercise, consistently going to bed at the same time each night ensures your sleep is aligned with your circadian rhythm. Limiting screens and other overstimulating devices near bedtime may make it easier to fall asleep, and the same can be said for caffeine consumption. Even if you can fall asleep a few hours after drinking coffee, there is strong evidence that your sleep quality will suffer even if you are unable to perceive it. This is because caffeine typically takes a long time to break down in the body. In his book Why We Sleep: The New Science of Sleep and Dreams, Matthew Walker points out that caffeine has an average half-life of five to seven hours. This means that half of the caffeine you consumed six hours ago may still be circulating in your system, though this amount could be higher or lower depending on your individual caffeine metabolism. Many of us would never drink six ounces of coffee right before bedtime, so it is worthwhile to consider the fact that having twelve ounces of coffee at four o’clock might be functionally equivalent. Therefore, it may be wise to skip that late-afternoon latte.

Play

We live in a golden age for picking up new hobbies. Given the staggering amount of content available on YouTube and similar platforms, it has never been easier to learn to, say, bake a loaf of sourdough, play the drums, or plant that vegetable garden. Maintaining meaningful pursuits outside of work can help reduce the odds of burnout and ensure that your identity is not completely tied up with your occupation. Promisingly, there is evidence that Americans are increasingly prioritizing hobbies and leisure.

Unfortunately, however, the time we spend with others appears to be declining, despite strong evidence that our relationships and a sense of community are correlated positively with numerous quality of life measures. But hobbies do not have to be solitary pursuits, and combining hobbies with socialization and a sense of community likely will augment their restorative effects. One need look no further than America’s current obsession with pickle ball, a sport often played in groups of four. Is it possible that our love of pickle ball has something to do with its ability to bring us together? If you are not into pickle ball, there are plenty of other activities that you can enjoy with others, such as book clubs, board game nights, running and walking clubs, bowling leagues, volunteering for a nonprofit, and playing in a band.

Leave

According to a 2023 Pew Research Center survey, nearly half of all U.S. workers surveyed who receive paid time off from their employer used less leave than they were offered. While this number might be skewed somewhat by the lack of a distinction between personal and sick leave, it is clear that at least some of the unused leave stems from workers being concerned about their work performance, with 49% of those with unused leave citing a fear of falling behind at work as a reason for forfeiting leave. Similarly, about one in five of those surveyed with forfeited leave were concerned about hindering their chances for advancement. However, if we again apply the logic that being a valuable internal auditor relies on peak cognitive performance, and peak cognitive performance demands adequate rest and a lack of burnout, then it does not follow that forfeiting our vacation time will necessarily make us better internal auditors, and it could be doing the opposite.

Whatever You Do, Do Not Unrest

While engaging in fulfilling and restorative rest pursuits is important, it may be even more important to actively avoid activities that keep your brain stimulated at all times. This is because there is strong evidence that our brains perform important functions when they are not busy dealing with a demanding task or trying to find a solution to a pesky problem. This brain state—characterized by introspection during times when an individual is not deeply concentrating on their external environment—is known as the default mode network (DMN), and the DMN likely assists with problem solving and planning for the future.

The DMN was discovered essentially by accident. Scientists researching which areas of the brain were activated during cognitively demanding tasks noticed that these “active” areas of the brain became deactivated in between tasks, as expected, but something else happened during these rest periods that caught them by surprise. Instead of seeing a brain with minimal activity, they noticed that other areas of the brain began to light up, indicating that though participants might have been at rest, their brains were not. This paved the way for a critical insight: just because we may be taking a mental break, our brains continue furiously working away in the background on our behalf.  As we learn more about the DMN—it was only discovered in 2001—it is appearing increasingly likely that our modern digital environments, saturated with numerous distractions that keep us in a state of perpetual stimulation, are holding the DMN back from performing its important functions. Whether it is out of an attempt to maximize productivity, or just to ward off boredom, we rarely allow our brains a moment to rest. Instead, the moments of time that used to be the domain of boredom are now filled with social media scrolling, listening to podcasts, and replying to texts and e-mails. At the time the DMN was discovered, this level of constant mental stimulation would have been almost impossible, but in just a couple of decades we have transformed into individuals who almost never have to be alone with our own thoughts. This should alarm us since it is clear our brains are doing something important during times of mental rest. Therefore, purposefully abstaining from mentally stimulating activities for at least some time each day may be worthwhile. It may seem like you are wasting time, but in reality you are taking a positive step to ensure that your brain can perform at its best, and hopefully you will quickly notice the benefits of a little rest. 

Strengthening Compliance: Building Alliances Between Internal Audit & Research Administration Through Collaboration

By Monika Cami, Jackie Kimmel, and Jennifer Vitale

Editor’s Note: This article is reprinted from NCURA Magazine, 56(5), published by the National Council of University Research Administrations. It is used with permission from the publisher. Consider sharing this article with your research team and learn about common audit findings in research from our ACUA member authors.

Research universities and institutions are governed by strict regulations. Non-compliance can lead to severe monetary penalties, reputational damage, and impacts on funding. Therefore, it is crucial to proactively manage and mitigate risks. In this landscape, where adherence to complex regulations and standards is non-negotiable, the synergy between internal audit and research administration holds the promise of enhancing compliance. By jointly leveraging their expertise, maintaining open communication, and adopting a unified strategy towards risk management, these partnerships not only foster a culture of compliance and accountability, but also contribute to the overall integrity and efficacy of the research enterprise and continuous improvement across the institution.

Both internal audit and research administration share the common goal of compliance and risk mitigation. By working in tandem, they can ensure that their efforts are complementary and more effective. This article offers a few strategies for fostering productive collaboration with internal audit and provides a synopsis of common outcomes and recommendations. While not an all-inclusive list, we hope these insights will be beneficial when conducting self-assessments of your research operations or as you prepare for a future internal audit of research-related processes.

Tips for working with your internal audit team

  • Be Honest and Open: The audit will be more valuable and more efficient if you are (e.g., if you’re asked for a policy/procedure document and you don’t have one, just say you don’t have one, don’t try to create one at the last minute).
  • Share Your Knowledge:  You are the expert in your area; auditors are experts on risks and internal controls; help us understand your environment, what is working well and what are your concerns. Share this with your team as well. Prepare them for the audit and set expectations for transparency.
  • Be Responsive:  The more responsive you are, the faster we can be out of your hair; if you’re busy and can’t get to us for a few days, respond and let us know when to expect a response so we can plan.
  • Assign a Lead:  Assign someone to coordinate and facilitate with the auditors, get status updates from the audit team, and help remove obstacles.
  • Ask Questions:  We want you to be comfortable and work with us; if you’re curious or confused – just ask; we’ll try not to use too much audit jargon, but if we slip – request clarification.
  • Maintain A Positive Attitude:  Be receptive to recommendations; this is an exercise in continuous improvement; it is faster to talk about/work toward fixing something or making it better than it is to be defensive, blame others, explain all the reasons it is the way it is, refuse, etc. Focus on the solutions, not the problem itself.
  • Collaborate:  We may share a recommendation that doesn’t work in your environment – work with us, suggest alternatives – we can often address the same risk in multiple ways; we want to agree on a solution that makes sense for you.
  • Make a Plan:  Agree on how we will share documents/information (Dropbox, shared drive), schedule regular status check-ins, etc.
  • Provide Access:  Facilitate access to space, intranets, data, etc.; help us schedule interviews, tours, and walkthroughs.
  • Prepare for Future Audits:
  • Address the findings/recommendations from your previous audit
  • Pay particular attention to:
  • Good housekeeping of documentation
  • Monitoring and oversight
  • Governance
  • Maintain an Ongoing Relationship:  Reach out when you have questions and be proactive.
  • Provide Evidence: “Show me” is going to be a common phrase. We have to ‘trust but verify’, so help us ‘see’ the internal controls.
  • Don’t Be Afraid: Audits are collaborative, not punitive, processes.

Common Internal Audit Findings: Missing or ineffective controls

Regardless of the industry or type of business, or even the subject matter of an audit, internal audit findings are very often rooted in one of these common problems: 

  1. A lack of written policies and procedures
  2. Having unclear roles and responsibilities
  3. Not enough or ineffective oversight processes

A house made of strong internal controls requires good housekeeping. Policies and procedures (big and small) should be documented and reviewed from time to time. The foundation of any control is having a clear picture of what you do, how you do it, and who is doing it. Writing this all down for all phases and levels of research administration and clearly understanding who is responsible for each part is packed with benefits such as:

  • Faster and smoother onboarding of new employees.
  • Less disruption when key employees leave (either planned or unexpectedly).
  • Less duplication of efforts (or data).
  • Less loss of institutional knowledge from long-term employees who leave (and take their knowledge with them).
  • Greater productivity when everyone shares the same understanding of a process.
  • Better forecasting of the upstream and downstream effects of a proposed process or business change.
  • More effective and efficient oversight activities by knowing where things can go wrong and identifying easier ways to measure/monitor for them.
  • Faster (and more employee-friendly) adaptation to change.
  • Better protection of your data when you know where it lives and who has access to it.
  • Clearer compliance with laws and regulations.

Other common audit findings include: 



Onboarding/Offboarding Processes: Lack of robust onboarding and offboarding activities, unclear roles and responsibilities, inappropriately granting or removing access (physical and system), no documentation.  

Data and Intellectual Property Protections: Inadequate data management practices, including insufficient data security, improper handling of confidential information, and failure to back up research data. Failure to maintain effective application controls, encryption, authentication, backups, intrusion detection, cloud security controls. Insufficient reaction time to intrusions or business disruptions.  

Expense Approval Processes: Lack of expense support, non-compliance with procurement policies, lack of separation of duties, lack of proper approval, unauthorized delegation of approval.  

Grant Sponsor Reporting: Late or incomplete/inaccurate reporting. Lack of documentation around sponsor communications. Failure to disclose inventions to the sponsoring agency or institution as required by the award and institutional policy.  

Financial Monitoring: Lack of expense reconciliations, inadequate budgeting, unjustified budget or cost transfers. Improper cost sharing allocations.

Indirect Cost Calculations: Incorrect indirect cost calculations, lack of support or justification for the calculations.  

Unallowable Direct Charges: Using grant funds for purposes not directly related to the research project, such as unrelated travel or personal purchases. Lack of justification or support for the charges.

Subrecipient Monitoring: Lack of oversight over subawards, inadequate (undocumented) assurance that the subrecipient is compliant with funding terms and conditions.  
Record Retention: Lack of expectation for retention of: proposal, pre-award, and post-award communications; budget and financial records; research data, results, and analysis; laboratory notebooks or research journals; documentation of materials and methods used in research; publication and presentations resulting from the research; intellectual property disclosures or patents; subrecipient monitoring communications and reviews.  

Asset Management: Insufficient equipment or inventory tracking processes. Unauthorized relocation of sponsor-owned equipment. Improperly secured sponsor-owned equipment. Improper disposal.

Management of contracts and other agreements: Lack of timely review, unclear ownership, lack of termination and change notice requirements, missing other components (right to audit, arbitration) required by general counsel.  

Regulatory Compliance: Unidentified or non-compliant export controls: failure to update Technology Control Plans (TCP); failure to report international travel.  

Training: Failure to complete Responsible Conduct of Research (RCR) Training, purchasing and purchasing card training, expense report training. Failure to track training completion and maintain training records.  

Conflict of Interest: Failure to disclose, review, manage, or report financial conflicts of interest that may affect research integrity. Failure by management to monitor the conflict reporting process.  

Confidentiality and Acceptable Use Policies: Failure to execute nondisclosure/confidentiality agreements, materials transfer agreements, data use agreements.    

Conclusion

Whether you are grappling with complex decisions, developing new processes, or simply looking for guidance or comfort that your operations are on the right track, do not hesitate to connect with the internal audit team at your institution. They are there to serve as a resource for you. By reaching out to internal audit, not only will you benefit from independent and professional advice, but you will also be taking proactive steps towards strengthening department operations and research practices.

Through a collaborative approach, we aim to identify opportunities for improvement, enhance risk management, and ensure effective controls are in place. Remember, by involving us early in your planning and decision-making processes, we can help you reduce or mitigate risks before they become issues and support you in achieving your objectives more efficiently and effectively.

Albert Einstein said, “I have no special talents. I am only passionately curious.” The next time you work with an internal auditor, remember they are just passionately curious and will ask many questions. It is through our curiosity and a desire to learn more about your operations that we often uncover opportunities for enhancing the control environment. In essence, consider internal audit as a resourceful ally within the organization. Whenever you are in doubt or in need of a fresh perspective, reach out; let’s work together to bring out the best in our operations and institutions.

Regulation Updates: Third-Party Topical Requirement, GRC Reporting, and 529 Plan Changes

By the ACUA Auditing & Accounting Principles Subcommittee

The ACUA Auditing and Accounting Principles Subcommittee is committed to providing members with emerging information in our field. This article features the recently released IIA Third-Party Topical Requirement, clarification on the new reporting requirements on governance, risk management, and controls, plus modifications to the 529 education savings plan that allows tax savings for professional certification expenses.

Understanding the IIA’s Topical Requirements for Third-Party Relationships

Topical Requirements are a new, mandatory component of the Institute of Internal Auditors’ (IIA) Global Internal Audit Standards. Internal auditors must apply the Topical Requirements for assurance engagements in the following situations:

  • The topic is included in your audit plan as an assurance engagement.
  • The topic is identified during the course of an audit engagement.
  • The topic is requested as a new engagement, even if it was not part of your original audit plan.

What’s New?

The Third-Party Topical requirement was finalized on September 15, 2025, and will become effective September 15, 2026. According to the IIA, a third-party is “an external individual, group, or entity with whom an organization (‘the primary organization’) has a business relationship.” In simpler terms, this means any person, group, or business your institution works with.

Importantly, the requirement does not just apply to your direct third-party relationships. It also covers any subcontracted relationships, even those several layers down, such as fourth-level subcontractors, if your contract allows them. This broad scope ensures that risks are managed throughout your entire supply chain.

What does the Third-Party Topical Requirement involve?

Internal auditors need to assess their institution’s contract management throughout the third-party life cycle, consisting of selecting, contracting, onboarding, monitoring, and offboarding. Internal auditors should consider these stages when assessing the requirements for these three key areas:

  • Governance: Internal auditors must evaluate how their institution decides with whom to contract, how these relationships are managed, and who communicates with third parties and stakeholders. This includes assessing whether the organization has clearly defined roles and responsibilities for managing third-party relationships, and whether established policies and procedures align with regulations and are updated regularly. Auditors should confirm there is a formal approach to contracting third parties and there are protocols for communicating with relevant stakeholders.
  • Risk Management: Internal auditors must review how their institution identifies, assesses, and monitors third-party risks. This begins with examining due diligence procedures for onboarding third parties. There should be ongoing monitoring and corrective action for deviations, and risk assessments should classify and rank third-party risk. Check for escalation and remediation processes in place for unresolved issues, including remediation or termination.
  • Controls: Internal auditors should assess the controls in place to manage and monitor the risks associated with third parties. Review procurement controls for appropriate sourcing and selecting of third parties and ensure there is an appropriate approval process. Determine whether there is centralized contract management and verify contracts contain risk mitigation clauses, performance expectations, compliance obligations, and are reviewed and updated periodically. Review ongoing third-party monitoring and periodic evaluation, and the monitoring of contract renewal dates and offboarding plans.

By understanding and applying these requirements, your institution can better manage third-party risks and strengthen its overall governance.

Download the Third-Party Topical Requirement and a user guide from the IIA at:

https://www.theiia.org/en/standards/2024-standards/topical-requirements/third-party/

Other topical requirements to be aware of:

Cybersecurity – effective February 5, 2026

Organization Behavior – public comment period ended, pending finalization.

Organizational Resilience – pending public comment.

https://www.theiia.org/en/standards/2024-standards/topical-requirements

New Reporting Requirements for GRC

The new IIA Global Internal Audit Standards, effective January 9, 2025, introduce more structured and rigorous reporting requirements for Governance, Risk Management, and Controls (GRC). They emphasize clarity, consistency, and alignment with stakeholder expectations.

During an engagement, the Internal Audit function must evaluate the governance processes to ensure the organization promotes ethical behavior, accountability, and transparency. Auditors must identify key risks and ensure they are managed effectively, and review the control framework to identify control deficiencies, weaknesses, and failures.

Standard 14.5 Engagement Conclusions requires internal auditors to develop an engagement conclusion that summarizes the results relative to the engagement objectives. In addition, this standard states “assurance engagement conclusions must include the internal auditor’s judgment regarding the effectiveness of the governance, risk management, and control processes of the activity under review, including an acknowledgment of when processes are effective.”

The considerations for implementation of this standard recommend having methodologies for the internal audit function in the form of a rating scale indicating whether reasonable assurance exists regarding the effectiveness of controls. An example is developing criteria for a scale that indicates “satisfactory, partially satisfactory, needs improvement, or unsatisfactory.”

The AAP Committee aggregated the ratings used by the committee members and created the following example of a rating methodology that is applicable to report ratings and GRC ratings:

Example of Report/GRC Ratings

Standard 15.1 Final Engagement Communication states the final communication for assurance engagements must include a “conclusion regarding the effectiveness of the governance, risk management, and control processes of the activity required,” in addition to the continuing requirements of objectives, scope, recommendations, and any action plans. Auditors are encouraged to use their engagement conclusions derived from their methodologies to meet this reporting standard.

529 College Savings Plans Expanded to Cover Professional Certifications

A provision in the One Big Beautiful Bill Act (OBBBA) that was signed into law in July 2025 included changes in 529 education savings plans that may benefit ACUA members. Traditionally 529 plans were reserved for undergraduate and graduate degree programs, but now certain professional certification and credentialing programs are covered as qualifying expenses. This includes several of our most sought-after certifications, including the Certified Internal Auditor (CIA), the Certified Information Systems Auditor (CISA), and the Certified Public Accountant (CPA).

This is a great opportunity to invest in your professional development, especially if your department does not cover or reimburse certification expenses. Eligible expenses can include study materials, exam fees, and even continuing education required to maintain your credential.

See Section 70414 of the OBBBA for more information. As always, everyone’s tax situation is different, so please consult with your tax advisor to confirm eligibility. Check with your financial institution for assistance setting up a 529 plan.