2025-2026 Chief Audit Executive Annual Report

  • Prepared by Véronique Desjardins, Chief Audit Executive
  • Presented at the June 30, 2026 Audit & Evaluation Committee Meeting

Introduction

The 2025-26 Chief Audit Executive (CAE) Annual Report marks my first as CAE since joining the Office of the Information Commissioner (OIC) in April 2026.

I was appointed Deputy Commissioner, Corporate Services, Strategic Planning and Transformation Services, just as this reporting year was wrapping up. As such, this report focuses on the work of my predecessor, France Labine, and marks the final chapter of her tenure. I would like to take this opportunity to thank France for her contribution to the OIC and the Audit & Evaluation Committee. In her time at the OIC, she had a transformative impact to the internal audit function by formalizing processes and helping manage risk through numerous challenges. Highlights include the development of a multi-year risk based internal control testing plan, a corporate risk register, and leading numerous internal evaluations.

It is a privilege to take on the role of Chief Audit Executive, building on experience in oversight and risk management across corporate functions and programs in both small and large organizations. My goal for the audit and evaluation function is to provide objective assurance and advice that strengthen governance, risk management and controls, empowering our organization to navigate an increasingly complex and fast-changing risk landscape with confidence and accountability.

This report summarizes the work undertaken by the CAE at the OIC for the 2025-26 fiscal year. Among the highlights were contributing the to development of new core values that will guide the OIC over the next several years. The Corporate Risk profile was also updated this year to reflect the changing environment both internally and externally. This led to an update to the multi-year Risk Based Audit & Evaluation Plan and Internal Control Testing plan to ensure that planned evaluation work is inline with key risks. The CAE also continued to monitor progress made on made management actions plans from prior evaluations.

Meetings

The CAE was the Secretary of the Audit & Evaluation Committee for four meetings:

  • July 10, 2025
  • September 17, 2025
  • November 25, 2025
  • April 8, 2026

The minutes for the meetings can be found on the OIC website: Record of Meetings

Policy on Internal Audit

As per the Treasury Board Secretariat Policy on Internal Audit, the CAE confirms the following:

  • She reports directly to the Information Commissioner of Canada
  • She has not been assigned any management or operational responsibilities that may compromise her independence* and objectivity with respect to her internal audit responsibilities
  • She has unrestricted access to the AEC
  • She has unrestricted access to all records, databases, workplaces and employees to carry out internal audit activity
  • She has unimpaired ability to carry out his responsibilities, including reporting issues to the Commissioner, to the AEC and, as appropriate, to the Comptroller General of Canada

* Due to the size of the organization the CAE is also combining other corporate services functions such as IT, HR, ATIP, Security and Finance. As required, the CAE will use external auditors or evaluators to perform key QA, audits and assessments.

Role of the Chief Audit Executive

The objective of the CAE is to ensure:

  • Sound stewardship of public resources and accountability to Canadians
  • Oversight informed by a professional and objective internal audit function
  • Independent advice and guidance to management

Audits, Reviews, Assessments

Significant audits and evaluations completed by the CAE during the year include:

2024-25 Audited Financial Statements

  • Office of the Auditor General (OAG) audit resulted in no material misstatements being identified nor any significant internal control issues
  • Completed and approved in September 2025

Multi-year Internal Control Testing Plan and Results

  • Results of internal control testing were presented at the September 2025 meeting
  • Work was performed on payroll and entity-level controls
  • No significant issues were identified, and it was concluded that controls are working effectively

Follow-up on Management Action Plans

  • An update on the Complaint Consultation was presented at the July 2025 meeting. High priority findings have been addressed, and other recommendations will be reevaluated as the OIC adopts new technologies.
  • An update on the Cyber Security Self Assessment and the Tabletop Exercise was presented at the November 2025 meeting. Work is progressing on addressing the recommendations, and a number of risks have been eliminated as the OIC continues its transition towards cloud computing.
  • An update on the work undertaken to resolve over and under payments caused by Phoenix was presented at the July 2025 meeting. Significant progress has been made over the last year.

Corporate Risk Profile

  • The Corporate Risk Profile was updated to reflect evolving risks across the organization and its external environment. It was presented to the Committee at the April 2026 meeting.

Risk-based Audit and Evaluation Plan

  • An updated multi-year Risk-based and Evaluation Plan was presented to the AEC at the April 2026 meeting
  • The plan was adjusted based on changes in government-wide risks and priorities
  • Planned audit of employee retention was delayed, and an audit of procurement activities was advanced

Important items Reviewed by the AEC

The CAE also contributed to the following documents presented to the AEC during the year:

  • Strategic Plan
  • Departmental Plan
  • Departmental Results Report
  • Regular Budget Updates and Financial Results
  • Investigation inventory, processes and performance
  • Legal Services
  • Parliamentary Activities and Communications
Date modified:
Submit a complaint