2025-2026 Audit and Evaluation Committee Annual Report
Table of contents
- 2025-26 Audit and Evaluation Committee Annual Report
Foreword from the Chair
2025-26
2025-26 was the first year of Caroline Maynard’s second term as Information Commissioner of Canada. The Office of the Information Commissioner (OIC) used her reappointment as an opportunity to update its Strategic Plan and core values of the OIC. This process also resulted in an updated Corporate Risk Profile and Risk Based Audit & Evaluation Plan, which will help guide the work of the Committee for the next several years.
As Chair, I have been consistently impressed by the leadership demonstrated by the Commissioner, as well as by the dedication and hard work of the organization’s executives and staff. The Audit and Evaluation Committee has been in a privileged position to see how the executives has responded effectively to the unique challenges faced by the organization. The OIC is a small organization, with a limited budget and no control over the volume of work it receives. Despite these challenges, the OIC continues to champion efficiency and innovation, to resolve complaints as quickly as possible, to maintain a contemporary inventory, and to champion improvements to the access to information system in Canada.
Looking ahead to 2026-27 the Committee members are encouraged by the fact that the Commissioner will have an opportunity to be involved in the Government’s legislative review of the Access to Information Act which will give the Commissioner the opportunity to advocate for changes to modernize the access law in Canada.
This year also marked a significant change as France Labine has retired after many years as the Chief Audit and Evaluation Executive at the OIC. The Committee would like to take this opportunity to thank France for her contributions to both the OIC and to this Committee. I would also like to welcome Véronique Desjardins who will bring experience and knowledge on oversight and risk management as she takes on the role of Chief Audit and Evaluation Executive.
I wish to acknowledge the continued contribution of fellow Committee member, André Grondines, who brings rigour and expertise to the Committee.
Janine Sherman
Chair, Audit and Evaluation Committee,
Introduction
The external members of the Audit ad Evaluation Committee (AEC) of the Office of the Information Commissioner (OIC) have prepared this report as a summary for the Information Commissioner of the Committee’s work from April 1, 2025 to March 31, 2026.
The report is also a vehicle for the external members to present their thoughts on areas for improvement at the OIC, based on the Committee’s assessments and deliberations over the last year. The previous Audit and Evaluation Committee Report for 2024-25 was approved at the AEC meeting on July 10, 2025.
Committee Role and Membership
The Committee’s role is to provide the Commissioner with objective advice, guidance and recommendations on the adequacy of the OIC’s control and accountability processes, as well as the use of evaluation within the OIC, to support sound management practices, informed decision-making and improved program performance.
To offer this support, the Committee exercises active oversight of core areas of the OIC’s management control and accountability framework. In so doing, Committee members address high-level strategic issues, as well as ongoing operational ones, to support the independence of internal audit activities within the OIC and the impartiality of the evaluation function. The Committee’s input also helps ensure that internal audit and evaluation results are incorporated into the OIC’s priority setting, and business planning and decision processes.
Committee members, as strategic resources for the Commissioner, also provide such advice and recommendations as she may request on specific emerging priorities, concerns, risks, opportunities and/or accountability reporting. This activity was largely carried out not only during the four Committee meetings held during the past years, but also during meetings with the Commissioner outside of the formal meetings.
The Committee has three members, two of whom are external to the federal government. The external members during 2025-2026 were Janine Sherman (chair) and André Grondines. Together, the external members have broad knowledge and experience in the areas of audit, management controls and risk management in both the public and private sectors, as well as in the operations and responsibilities of Agents of Parliament. Information Commissioner Caroline Maynard is the third member of the Committee.
Permanent Committee members attended meetings during the reporting period:
- France Labine, Chief Financial Officer, Chief Audit and Evaluation Executive and Deputy Commissioner of Corporate Services, Strategic Planning and Transformations Services (all meetings)
- Véronique Desjardins, Chief Financial Officer, Chief Audit and Evaluation Executive and Deputy Commissioner of Corporate Services, Strategic Planning and Transformations Services (April 2026 meeting)
- Layla Michaud, Deputy Commissioner of Investigations and Governance
- Marie-Josée Montreuil, Executive Director and General Counsel of Legal Services
- James Ellard, Senior Director, Public Affairs and Communications Services
- Sébastien Lafond, Deputy Chief Financial Officer (DCFO) and Senior Director, Finance, Procurement, Administration and Security
- Michael Walsh, Financial Management Advisor and
- Catherine Lapalme (2024-25 audit) or Patrick Charbonneau (2025-26 audit), a senior representative of the Office of the Auditor General (OAG)
Various OIC other staff members were also in attendance to present reports and other deliverables, or to give Committee members updates on the OIC’s business and other activities.
Meetings
The Audit and Evaluation Committee met three times between April 1, 2025 and March 31, 2026 with an addition meeting moved to early in the 2025-26 fiscal year:
- July 10, 2025
- September 17, 2025
- November 25, 2025
- April 8, 2026
The Commissioner met with the external members in camera at the conclusion of each meeting. The OIC posted the approved Committee meeting minutes on its website.
Activities
The Committee’s activities fall under nine categories, as set out below. These areas of responsibility are linked in many ways—particularly with regard to risk and strategic priorities —and Committee members take this into account when carrying out their assessments and providing advice.
Values and Ethics
In 2025-26, the OIC reviewed and updated their core values. As part of this process, it was important for the Commissioner to get the input and feedback from all OIC employees. The recommendations from the OIC employees were incorporated into the final core values that were presented to the AEC at the September 17, 2025 meeting.
The Committee reviews any measures OIC management puts in place to exemplify and promote public service values and to ensure compliance with laws, regulations and policies, and standards of ethical conduct. The AEC was satisfied with the degree of which ethics and values are embedded and assessed within OIC operations. There were no reported cases of fraud or wrongdoing and the value and ethics code is being respected. This included violence in the workplace and conflict of interest.
Risk Management
Risk assessment and mitigation are ongoing focuses of the Committee’s work, including reviewing the OIC’s corporate risk profile and risk management strategies and activities. In 2025-26 the OIC updated its Corporate Risk Profile which includes an updated key risk register which was prestned to the AEC at the April 2026 meeting.
Management Control Framework
Activities and discussions pertaining to the management control framework, which is linked to all other areas of responsibility, are ongoing including presentations on the OIC’s internal control mechanisms.
At the September 17, 2025 meeting the results of the 2024-25 internal control testing plan were presented. The testing performed in the year focused on entity level controls and annual testing of key controls over payroll & benefits. There were no significant issues identified during the testing, providing strong assurance that the framework is operating as intended.
Internal Audit
The Committee’s responsibilities with regard to internal audit include reviewing plans for and reports on internal audits, and their resulting management action plans. The updated Risk Based Audit & Evaluation Plan (RBAEP) was presented and approved at the April 8, 2026 meeting.
Evaluation
The Committee’s responsibilities with regard to evaluations include reviewing and approving the OIC’s RBAEP, reports on individual evaluations and management action plans, and receiving status updates on how the OIC implementing the recommendations. The AEC also monitors the Treasury Board Policy on Evaluation for any changes to that policy direction. Like the Policy on Internal Audit, the OIC is not mandated to adhere to either policy as an independent Agent of Parliament but chooses to follow the spirit of the policies.
Follow-up on Management Action Plans
The Committee received regular updates from management on action plans on the status and effectiveness of management follow-up actions.
At the July 10, 2025 meeting, an update was presented on the Complaint Consultation. High priority recommendations have all been addressed. There were several recommendations that were not practical to address at the present given the cost and technological limitations but they will be reevaluated in the future as the OIC adopts new technologies.
At the November 25, 2025 meeting, an update on the Cyber Security Self Assessment and the Tabletop Exercise was presented. Work is progressing well on the findings and that certain risks have been eliminated as the OIC continues its transition toward cloud computing.
At each AEC meeting, members were provided with the minutes and an update of action items arising from those meetings and were satisfied that all actions had been satisfactorily addressed.
Financial Statements and Public Accounts Reporting
At the September 2025 AEC meeting, the OAG presented its annual Financial Audit Report for 2024–2025 with an unmodified opinion, finding no significant deficiencies in internal controls and requiring no financial statement adjustments. The major risk for this audit (and not limited only to the OIC) is related to potential pay errors caused by the Phoenix pay system. The risk remains high but controls in place ensure that the risk is very limited. Based on the test samples, the OAG was comfortable. The 2025-26 Audit Plan of the OAG was presented by the OAG Principal at the Committee meeting on April 8, 2026 and the approach was approved. The AEC confirmed to the OAG that there were no changes to the management’s responsibilities for fraud prevention and detection responsibilities and that there was no knowledge of any instances of fraud or wrongdoing.
Throughout the year, the CFO and the DCFO briefed Committee members on the status of the current year’s budget for 2025-26 and the preparation of the budget allocation exercise for 2026-27.
Accountability Reporting
The Committee reviewed various corporate accountability reports and provided advice to the Commissioner during the year.
External Assurance Provider
The Committee carried out objective assessments regarding the OIC’s operations, results, risks, stewardship and governance.
The Committee carried out its role during the year of satisfactorily providing advice and recommendations on matters for which the Commissioner, as the Deputy Head, serves as the Accounting Officer for the organization.
The Committee received all the information it deemed necessary to fulfil all its mandate obligations.
Consistent with the multiyear RBEAP, no external assurance engagements were completed in 2025-26.
Overall Assessment of Risk Management, Control and Governance
Based on reviews conducted and discussions held throughout 2025-26, the Committee is satisfied that the OIC’s risk management, control and governance processes are functioning well. The Committee also notes the OIC updates their corporate risk profile annually to maintain its relevance and effectiveness in the formal the identification and management of significant risks
The Committee appreciates the due diligence the OIC has exercised in the development of sound management and internal control processes and practices and is encouraged that management strives for constant improvement.
Audit and Evaluation Committee Effectiveness
The Committee’s external members are pleased with the Committee’s ongoing development and maturity in its advisory role. Members were provided with complete, timely and accurate information to enable them to discharge their mandate. Members were pleased with the professionalism of staff, their candour concerning the challenges they face and their willingness to implement suggestions.
The Committee has established itself as an integral part of the OIC’s governance system. Despite the pressures of competing priorities and the multitasking typical of small organizations, the commitment and engagement of senior officials and functional specialists have been invaluable in helping the Committee fulfill its role. Based on our observations over the past year, the two external members of the Committee conclude that the OIC has a systematic and rational approach to addressing its mandate, to monitoring results and to reporting publicly.
The Committee also performed a self assessment which indicated that members believe they have the information, tools and knowledge required for their roles.
Forward Planning
The Committee is scheduled to meet four times during the 2026-27 fiscal year. Its goals are to continue to provide advice that reflects core public sector principles and values, take into account the independence of Agents of Parliament, and encompass innovative and creative perspectives.
The Audit and Evaluation Committee conducted its annual review of next fiscal year (2026-27) and approved the Calendar of Activities at the meeting April 8, 2026.