§ 143B‑216.51.  Department of Health and Human Services office of the Internal Auditor; Department audits.

(a) To ensure that Department audits are performed in accordance with applicable auditing standards, the Internal Auditor shall possess the following qualifications:

(1) A bachelors degree from an accredited college or university with a major in accounting, or with a major in business which includes five courses in accounting, and five years' experience as an internal auditor or independent postauditor, electronic data processing auditor, accountant, or any combination thereof. The experience shall, at a minimum, consist of audits of units of government or private business enterprises operating for profit or not for profit;

(2) A masters degree in accounting, business administration, or public administration from an accredited college or university and four years of experience as required in subdivision (1) of this subsection; or

(3) A certified public accountant license issued pursuant to law or a certified internal audit certificate issued by the Institute of Internal Auditors or earned by examination, and four years' experience as required in subdivision (1) of this subsection.

The Internal Auditor shall, to the extent both necessary and practicable, include on the Internal Auditor's staff individuals with electronic data processing auditing experience.

(b) In carrying out the auditing duties and responsibilities of this Part, the Internal Auditor shall review and evaluate internal controls necessary to ensure the fiscal accountability of the Department. The Internal Auditor shall conduct financial, compliance, electronic data processing, and performance audits of the Department and prepare audit reports of findings. The scope and assignment of the audits shall be determined by the Internal Auditor; however, the Secretary may at any time direct the Internal Auditor to perform an audit of a special program, function, or organizational unit. The performance of the audit shall be under the direction of the Internal Audit.

(c) Audits undertaken pursuant to this Part shall be conducted in accordance with auditing standards prescribed by the State Auditor. All audit reports issued by internal audit staff shall include a statement that the audit was conducted pursuant to these standards.

(d) The Internal Auditor shall maintain, for 10 years, a complete file of all audit reports and reports of other examinations, investigations, surveys, and reviews issued under the Internal Auditor's authority. Audit work papers and other evidence and related supportive material directly pertaining to the work of his office shall be retained according to an agreement between the Internal Auditor and State Archives. To promote cooperation and avoid unnecessary duplication of audit effort, audit work papers related to issued audit reports shall be, unless otherwise prohibited by law, made available for inspection by duly authorized representatives of the State and federal governments in connection with some matter officially before them. Except as otherwise provided in this subsection, or upon subpoena issued by a duly authorized court or court official, audit work papers shall be kept confidential. Audit reports shall be public records to the extent that they do not include information which, under State laws, is confidential and exempt from Chapter 132 of the General Statutes or would compromise the security systems of the Department.

(e) The Internal Auditor shall submit the final report to the Secretary.

(f) The State Auditor shall review a sample of the Department's internal audit reports and related work papers when determined by the State Auditor that, when conducting audits, it would be efficient to consider the work of the Internal Auditor. If the State Auditor finds deficiencies in the work of the Internal Auditor, the State Auditor shall include a statement of these findings in the audit report of the Department. The office of the Internal Auditor will cause to be made an external quality control review at least once every three years by a qualified organization not affiliated with the office of the Internal Auditor. The external quality review should determine whether the Department's internal quality control system is in place and operating effectively to provide reasonable assurance that established policies and procedures and applicable audit standards are being followed.

(g) The Internal Auditor shall monitor the implementation of the Department's response to any audit of the Department conducted by the State Auditor pursuant to law. No later than six months after the State Auditor publishes a report of the audit of the Department, the Internal Auditor shall report to the Secretary on the status of corrective actions taken. A copy of the report shall be filed with the Joint Legislative Commission on Governmental Operations.

(h) The Internal Auditor shall develop long‑term and annual audit plans based on the findings of periodic risk assessments. The plan, where appropriate, should include postaudit samplings of payments and accounts. The plan shall show the individual audits to be conducted during each year and related resources to be devoted to the respective audits. The State Controller may utilize audits performed by the Internal Auditor. The plan shall be submitted to the Secretary for approval. A copy of the approved plan shall be submitted to the State Auditor. (1997‑443, s. 12.21(c).)