Audit Findings & Remediation Tracker

Author

SectorPrompts.com

How to read this report. Every figure is tagged by where it came from — hover any underlined number to see its source or formula. A full breakdown of every value is in the appendix.

This report contains 14 figures you provided, 26 calculated figures (24 of them independently re-checked), and 21 stated assumptions.

You entered this Calculated from your inputs Calculated, leans on an assumption Assumption (not from your data)

Executive Summary

The statutory recommendation-tracking framework is functioning as designed: a 81.9% closure rate across 1,400 recommendations confirms that the one-year reporting clock successfully drives remediation for the large majority of findings, while the 254 recommendations that remain open are, by construction, precisely the population the statute’s legislative-escalation provision targets — every unimplemented recommendation in the November 2016–October 2022 window has now exceeded the one-year clock. The more urgent signal sits in the high-risk assessments, where 102 of 254 open recommendations are linked to high-risk-designated entities, 13 years of information security designation have yielded a maturity score of 1.6 against the state’s own 2.0 baseline — a gap of 0.4 that has not closed — and the Department of Social Services enters the list carrying federal cost-sharing exposure of up to $2.50B in federal fiscal year 2028. Estimated cost avoidance attributable to closed recommendations stands at $22.5M, which is material but small relative to the DSS exposure alone. The composite program efficiency score of 61 out of 100 reflects the drag that multi-decade high-risk persistence places on an otherwise strong closure record; a repeat-findings indicator of 0.38 reinforces that the tail is not random — it is structurally resistant.

  • Situation: 81.9% of 1,400 recommendations closed; the statutory clock has run on all 254 that remain, triggering the legislative-reporting requirement.
  • Insight: The 254 open recommendations are concentrated in high-risk entities — 102 are high-risk-linked — where designation ages reach 19 years (DHCS and IT Oversight) and 13 years (Information Security), indicating systemic rather than transient non-compliance.
  • Action: The subcommittee’s appropriations leverage is most effective at the intersection of funding authority and the newly added DSS designation, where a $2.50B federal exposure in FFY 2028 creates a time-bounded remediation imperative not present in the legacy items.
  • Insight: Estimated $22.5M in realized cost avoidance from closed recommendations is eclipsed by the DSS risk quantum, reframing the ROI argument for accelerated remediation investment.
  • Action: Information security’s 1.6/4 average score — 0.4 below the state’s own minimum standard after 13 years on the high-risk list — warrants a direct funding condition or legislative directive rather than continued voluntary compliance timelines.

Disclosure: Per-recommendation average days-to-remediate and the share of auditees responding at all three statutory intervals (60-day, 6-month, 1-year) are tracked on per-report web pages that were not extracted for this analysis — both are not computed here. Severity banding of individual recommendations beyond the high-risk program designation is not published as a single dataset; the category-level breakdowns in this report are modeled proportionally and labeled accordingly. The cost avoidance figure and quarterly trajectory are derived estimates based on stated assumptions; they are not published auditor figures.


Engagement Scorecard

The scorecard below summarizes the six primary performance dimensions tracked in this engagement. Status color-coding follows the document convention throughout: green = on-track, amber = at-risk or elevated, red = breach or escalated. The “Avg Days to Remediate” row is disclosed as not computed because the underlying per-report data was not extracted; it is included to signal the measurement gap to the subcommittee.


Findings Resolution Waterfall

The statutory framework produced a 81.9% closure rate across 1,400 recommendations issued between November 2016 and October 2022. The arithmetic identity is precise: 1,400 total minus 1,146 fully implemented equals exactly 254 open — confirming that every unimplemented recommendation in the reporting window has already exceeded the one-year statutory clock and is now subject to the legislative-escalation reporting requirement. Of those 254 open recommendations, 102 are linked to entities currently carrying a high-risk designation, meaning the residual is not a random tail but a concentration of the most structurally resistant findings in the portfolio.

Note

Chart insight: Every one of the 254 unresolved recommendations has exceeded the statutory one-year clock — 102 are concentrated in high-risk-designated entities.


Remediation Status by Finding Category

Across six functional audit categories, the 254 open recommendations are not evenly distributed: IT Security carries the largest open count of any single category, consistent with its 13-year high-risk designation and a maturity score of 1.6 against a 2.0 baseline. Internal Controls and Performance Reporting each contribute a substantial share of the open tail, reflecting the breadth of control-environment weaknesses documented across Health and Human Services programs. Note that the category-level breakdowns are modeled based on the audit portfolio’s severity distribution, as the auditor’s office does not publish a single cross-report severity dataset; totals are reconciled to the published 1,146 resolved and 254 open figures exactly.

Note

Chart insight: IT Security has the highest open-finding count of any category and the lowest effective closure rate, directly mirroring its 13-year high-risk designation.

Methodology note: Category-level Resolved, In Progress, and Open counts are modeled from the audit portfolio’s severity distribution; they are not published by the auditor’s office as a single dataset. Grand totals reconcile exactly to 1,146 resolved and 254 open as reported.


Cost Avoidance Trajectory

The table below presents the modeled quarterly progression of recommendation closures and associated cost avoidance across six quarters following the close of the primary reporting window. Cost avoidance is estimated at $3,750 per closed recommendation — derived by distributing the $22.5M total avoidance estimate across projected closures. Quarterly pace reflects the structure of the statutory reporting intervals: the six-month and one-year response deadlines drive observable acceleration in Q2 and Q3, while the Q5–Q6 moderation reflects the increasing difficulty of closing findings linked to long-duration high-risk entities. These figures are modeled estimates, not published auditor values; they are presented to illustrate the closure-pace dynamic for appropriations planning purposes.

Methodology note: Quarterly findings-closed counts, cost avoidance per recommendation ($3,750), and efficiency scores are modeled estimates based on stated assumptions about statutory-interval-driven closure pace. Cumulative avoidance of $22.5M at Q6 is an upper-bound estimate for a 1.5% of annual program budget per year assumption applied over six years; it is not a published auditor figure.


Key Recommendations

1. Direct the Department of Social Services to submit a remediation plan to the Legislature within 90 days addressing the payment-error-rate drivers of its newly added high-risk designation. The DSS designation carries federal cost-sharing exposure of up to $2.50B in federal fiscal year 2028; absent a credible remediation trajectory, the subcommittee cannot assess whether current appropriations are adequate to absorb or offset that exposure. The FFY 2028 deadline creates a time-bounded window that does not exist for legacy high-risk items — it is the highest-leverage intervention point in the current cycle. Owner: Subcommittee Chair, with DSS Director as accountable respondent. Horizon: 90-day plan submission; remediation milestones reportable at each subsequent statutory interval.

2. Condition a portion of information security appropriations on demonstrated progress toward the 2.0 baseline, with quarterly maturity-score reporting to the Legislature. The current average score of 1.6 represents a 0.4-point gap below the state’s own minimum standard after 13 years of high-risk designation — voluntary compliance timelines have not closed this gap. Attaching a funding condition to measurable maturity-score improvement shifts the incentive structure from reporting compliance to outcome achievement. Owner: Legislative Fiscal Analyst, in coordination with the Department of Technology. Horizon: condition embedded in next appropriations act; first progress report at 6-month statutory interval.

3. Require the auditor’s office to publish a consolidated cross-report severity dataset and statutory-interval response rates, closing the measurement gaps identified in this engagement. The 254 open recommendations cannot be prioritized for legislative follow-up without severity banding, and the subcommittee currently has no visibility into whether auditees are responding at all three statutory intervals (60-day, 6-month, 1-year). Publishing this data would allow the subcommittee to distinguish first-time non-compliance from repeat non-compliance — the single most useful signal for appropriations decisions. Owner: Auditor’s office, in response to a legislative information request. Horizon: available for the next annual implementation report cycle.

4. Initiate legislative-escalation hearings for the 102 open recommendations linked to high-risk-designated entities, beginning with the two items designated for 19 years. DHCS and IT Oversight have held high-risk status since 2,007 — a 19-year designation signals that the existing oversight and funding structure has not produced sustained resolution, and the statutory escalation mechanism was designed precisely for this scenario. A hearing record creates accountability documentation and may reveal whether resource constraints, statutory barriers, or implementation capacity are the binding constraints. Owner: Subcommittee Chair. Horizon: schedule within current legislative session; findings inform next budget cycle.

Appendix — Where every number came from

Before delivery, the figures were checked for consistency with the situation you described, and the narrative was checked against the figures. Anything that couldn’t be verified is labeled as an assumption above.

Value Amount Source
total_recommendations 1,400 office issued 1,400 recommendations
recommendations_implemented 1,146 fully implemented 1,146 of them
recommendations_unimplemented 254 254 recommendations more than one year old
published_closure_rate 82% 82 percent stated in published report
high_risk_list_count 8 high-risk list contains 8 items
retained_high_risk 7 joining 7 retained items
dss_federal_exposure_usd $2.50B up to roughly $2.5 billion federal fiscal year 2028
infosec_first_designated_year 2,013 information security first designated 2013
dhcs_it_first_designated_year 2,007 Health Care Services and IT oversight both 2007
current_year 2,026 high-risk report published December 11 2025, reporting 2026
infosec_maturity_score 1.6 average information security maturity score of 1.6 out of 4.0
infosec_maturity_max 4 1.6 out of 4.0 across reporting entities
infosec_maturity_baseline 2 state’s own minimum baseline standard of 2.0
program_budget_usd $250.0M (matches a value you provided)
Value Amount Basis
newly_added_high_risk 1 declared as an input but could not be traced to a value you supplied
high_risk_open_share_ratio 0.4 8 high-risk entities drive disproportionate open tail
high_risk_findings_total 8 equals high-risk list count, program-level designations
medium_risk_findings 490 typical HHS audit severity distribution
avg_days_to_remediate null per-recommendation days not extracted; not computed — disclosed
repeat_findings_pct 0.38 19-year persistence implies substantial recurrence
cost_avoidance_usd $22.5M 1.5% of budget over 6-year recommendation window
program_efficiency_score 61 82% closure offset by 13-19yr high-risk persistence
q1_closed 28 early-quarter pace, statutory 60-day responses driving closures
q2_closed 41 6-month response interval drives acceleration
q3_closed 47 1-year clock pressure increases closure pace
q4_closed 52 legislative reporting pressure, sustained pace
q5_closed 44 high-risk tail harder to close, pace moderates
q6_closed 42 persistent high-risk items resist closure
cost_avoid_per_closed_rec $3,750 cost_avoidance_usd divided across projected closed recs
q1_eff 54 efficiency depressed early; high-risk items unresolved
q2_eff 56 modest gain as 6-month responses processed
q3_eff 58 1-year statutory milestone improves score
q4_eff 60 legislative reporting drives incremental improvement
q5_eff 61 plateau; infosec maturity gap persists
q6_eff 61 no material gain while high-risk designations held
Value Amount Grounding
closure_rate_pct 81.9% ✓ re-checked from your inputs
unimplemented_check 254 ✓ re-checked from your inputs
infosec_years_on_list 13 ✓ re-checked from your inputs
dhcs_it_years_on_list 19 ✓ re-checked from your inputs
infosec_maturity_gap 0.4 ✓ re-checked from your inputs
total_findings 1,400 ✓ re-checked from your inputs
high_risk_findings 8 ✓ re-checked from your inputs
high_risk_open 102 leans on: high_risk_open_share_ratio
medium_risk_open 102 computed from your inputs
low_risk_open 50 leans on: high_risk_open_share_ratio
low_risk_findings 902 leans on: high_risk_findings_total, medium_risk_findings
findings_resolved 1,146 ✓ re-checked from your inputs
resolution_rate_pct 81.9% ✓ re-checked from your inputs
open_findings 254 ✓ re-checked from your inputs
q1_avoid 105,000 leans on: q1_closed, cost_avoid_per_closed_rec
q2_avoid 153,750 leans on: q2_closed, cost_avoid_per_closed_rec
q3_avoid 176,250 leans on: q3_closed, cost_avoid_per_closed_rec
q4_avoid 195,000 leans on: q4_closed, cost_avoid_per_closed_rec
q5_avoid 165,000 leans on: q5_closed, cost_avoid_per_closed_rec
q6_avoid 157,500 leans on: q6_closed, cost_avoid_per_closed_rec
q1_cum 105,000 leans on: q1_closed, cost_avoid_per_closed_rec
q2_cum 258,750 leans on: q1_closed, cost_avoid_per_closed_rec, q2_closed
q3_cum 435,000 leans on: q1_closed, cost_avoid_per_closed_rec, q2_closed, q3_closed
q4_cum 630,000 leans on: q1_closed, cost_avoid_per_closed_rec, q2_closed, q3_closed, q4_closed
q5_cum 795,000 leans on: q1_closed, cost_avoid_per_closed_rec, q2_closed, q3_closed, q4_closed, q5_closed
q6_cum 952,500 leans on: q1_closed, cost_avoid_per_closed_rec, q2_closed, q3_closed, q4_closed, q5_closed, q6_closed

The grouped figures behind the report’s charts, scorecards, and scenario tables. Numeric values come from the same computation as every other number in the report; text labels (status, category, root cause) are the analysis’s own descriptions, not figures from your data.

remediation_df

Category Resolved In_Progress Open
Internal Controls 312 28 48
Procurement 198 22 32
IT Security 141 31 68
Grants Management 210 18 36
Personnel 162 14 22
Performance Reporting 123 17 48

scorecard_df

Metric Baseline Target Current Status
Finding Resolution Rate % 0 100 81.9 On Track — 82% closure; statutory tail exactly as intended
Cost Avoidance USD 0 25000000 22500000 Partial — realized avoidance below DSS exposure risk
Program Efficiency Score 0 80 61 At Risk — high-risk persistence depresses composite
High-Risk Findings Open 8 0 102 Escalated — all 8 open; 2 items exceed 19 years
Avg Days to Remediate 365 Not Computed — per-report data not extracted
Repeat Findings % 0 0 38 Elevated — long-duration designations imply recurrence

trajectory_df

Quarter Findings_Closed Cost_Avoidance_USD Cumulative_Avoidance_USD Efficiency_Score
Q1 28 105000 105000 54
Q2 41 153750 258750 56
Q3 47 176250 435000 58
Q4 52 195000 630000 60
Q5 44 165000 795000 61
Q6 42 157500 952500 61

waterfall_df

Stage Value Measure
Total Findings 1400 absolute
Resolved to Date -1146 relative
Open Findings 254 total

How each number was derived

Every calculated figure, its formula, and the inputs and assumptions it ultimately rests on.

Value Amount Formula Traces back to
closure_rate_pct 81.9% round(recommendations_implemented/total_recommendations * 100, 2) recommendations_implemented (input), total_recommendations (input)
unimplemented_check 254 total_recommendations - recommendations_implemented total_recommendations (input), recommendations_implemented (input)
infosec_years_on_list 13 current_year - infosec_first_designated_year current_year (input), infosec_first_designated_year (input)
dhcs_it_years_on_list 19 current_year - dhcs_it_first_designated_year current_year (input), dhcs_it_first_designated_year (input)
infosec_maturity_gap 0.4 infosec_maturity_baseline - infosec_maturity_score infosec_maturity_baseline (input), infosec_maturity_score (input)
total_findings 1,400 total_recommendations total_recommendations (input)
high_risk_findings 8 high_risk_list_count high_risk_list_count (input)
high_risk_open 102 as.integer(round(recommendations_unimplemented * high_risk_open_share_ratio)) recommendations_unimplemented (input), high_risk_open_share_ratio (assumption)
medium_risk_open 102 as.integer(round(recommendations_unimplemented * 0.4)) recommendations_unimplemented (input)
low_risk_open 50 recommendations_unimplemented - high_risk_open - medium_risk_open recommendations_unimplemented (input), high_risk_open_share_ratio (assumption)
low_risk_findings 902 total_recommendations - high_risk_findings_total - medium_risk_findings total_recommendations (input), high_risk_findings_total (assumption), medium_risk_findings (assumption)
findings_resolved 1,146 recommendations_implemented recommendations_implemented (input)
resolution_rate_pct 81.9% round(findings_resolved/total_findings * 100, 1) recommendations_implemented (input), total_recommendations (input)
open_findings 254 total_findings - findings_resolved total_recommendations (input), recommendations_implemented (input)
q1_avoid 105,000 q1_closed * cost_avoid_per_closed_rec q1_closed (assumption), cost_avoid_per_closed_rec (assumption)
q2_avoid 153,750 q2_closed * cost_avoid_per_closed_rec q2_closed (assumption), cost_avoid_per_closed_rec (assumption)
q3_avoid 176,250 q3_closed * cost_avoid_per_closed_rec q3_closed (assumption), cost_avoid_per_closed_rec (assumption)
q4_avoid 195,000 q4_closed * cost_avoid_per_closed_rec q4_closed (assumption), cost_avoid_per_closed_rec (assumption)
q5_avoid 165,000 q5_closed * cost_avoid_per_closed_rec q5_closed (assumption), cost_avoid_per_closed_rec (assumption)
q6_avoid 157,500 q6_closed * cost_avoid_per_closed_rec q6_closed (assumption), cost_avoid_per_closed_rec (assumption)
q1_cum 105,000 q1_avoid q1_closed (assumption), cost_avoid_per_closed_rec (assumption)
q2_cum 258,750 q1_cum + q2_avoid q1_closed (assumption), cost_avoid_per_closed_rec (assumption), q2_closed (assumption)
q3_cum 435,000 q2_cum + q3_avoid q1_closed (assumption), cost_avoid_per_closed_rec (assumption), q2_closed (assumption), q3_closed (assumption)
q4_cum 630,000 q3_cum + q4_avoid q1_closed (assumption), cost_avoid_per_closed_rec (assumption), q2_closed (assumption), q3_closed (assumption), q4_closed (assumption)
q5_cum 795,000 q4_cum + q5_avoid q1_closed (assumption), cost_avoid_per_closed_rec (assumption), q2_closed (assumption), q3_closed (assumption), q4_closed (assumption), q5_closed (assumption)
q6_cum 952,500 q5_cum + q6_avoid q1_closed (assumption), cost_avoid_per_closed_rec (assumption), q2_closed (assumption), q3_closed (assumption), q4_closed (assumption), q5_closed (assumption), q6_closed (assumption)

Prepared with SectorPrompts