52013DC0606

REPORT FROM THE COMMISSION TO THE EUROPEAN PARLIAMENT AND THE COUNCIL Annual Report to the Discharge Authority on Internal Audits carried out in 2012 (Article 99(5) of the Financial Regulation) /* COM/2013/0606 final */


REPORT FROM THE COMMISSION TO THE EUROPEAN PARLIAMENT AND THE COUNCIL

Annual Report to the Discharge Authority on Internal Audits carried out in 2012 (Article 99(5) of the Financial Regulation)

TABLE OF CONTENTS

1........... Introduction.................................................................................................................... 5

2........... The IAS Mission: Independence, objectivity and accountability........................................ 5

3........... Audit production............................................................................................................. 6

3.1........ Implementation of the 2012 IAS audit plan...................................................................... 6

3.2........ New recommendations and acceptance rate.................................................................... 7

3.3........ Implementation of recommendations made during 2008-12.............................................. 8

4........... Main findings and recommendations................................................................................ 8

4.1........ Horizontal audits............................................................................................................. 8

4.1.1..... Annual Activity Report process (multi-DG)..................................................................... 8

4.1.2..... Management and monitoring of staff allocation (multi-DG)............................................... 9

4.1.3..... Chargeback and internal billing systems (multi-DG)........................................................ 10

4.2........ Agriculture, Natural Resources and Health.................................................................... 11

4.2.1..... Control Strategy audits (DGs MARE, SANCO)........................................................... 11

4.2.2..... Control Strategy — Directorate J (DG AGRI).............................................................. 11

4.3........ Cohesion...................................................................................................................... 12

4.3.1..... Closure 2000-06 Programming Period (DG REGIO, DG EMPL)................................. 12

4.3.2..... Implementation of 2007-13 Programmes (DG REGIO)................................................. 13

4.4........ Research, energy and transport..................................................................................... 13

4.4.1..... Control Strategy audits (DG ENER)............................................................................. 13

4.5........ External Aid, development and enlargement................................................................... 14

4.5.1..... Set-up of internal organisation in EU delegations (DG DEVCO).................................... 14

4.6........ Education and citizenship.............................................................................................. 14

4.6.1..... Lifelong Learning Programme (DG EAC/EACEA)........................................................ 14

4.6.2..... Control Strategy audits (DG HOME)............................................................................ 15

4.6.3..... Monitoring the implementation EU Law (DG JUST)...................................................... 15

4.7........ Economic and financial affairs........................................................................................ 15

4.7.1..... Implementation by the EIF of the CIP Programme (DG ECFIN)................................... 15

4.7.2..... Off-budget operations (DG ECFIN)............................................................................. 16

4.7.3..... Control Strategy audits (DG ENTR)............................................................................. 16

4.7.4..... Monitoring the implementation EU Law (DG TAXUD).................................................. 16

4.8........ General services and HR............................................................................................... 17

4.8.1..... Statistical data production, development and dissemination (DG ESTAT)....................... 17

4.9........ IT audits....................................................................................................................... 17

4.9.1..... Local IT systems management (DG DEVCO, DG TRADE).......................................... 18

4.9.2..... IT Governance and performance (DG SANCO/EAHC)................................................ 18

4.9.3..... Horizon 2020 (DG RTD, DG CNECT, ERCEA).......................................................... 18

5........... Consultation with the Commission’s Financial Irregularities Panel................................... 19

6........... Conclusions.................................................................................................................. 19

1.           Introduction

This report on the work carried out by the Commission’s Internal Audit Service (IAS) informs the Discharge Authority, as required by Article 99(5) of the Financial Regulation. It is based on the report that the Commission’s Internal Auditor drew up under Article 99(3) of the Regulation, regarding IAS audit- and consulting reports completed in 2012[1] on Commission Directorates-General, Services and Executive Agencies[2]. It describes the identified weaknesses and action taken to remedy these, and includes information on significant risk exposure, control issues and governance aspects[3].

The Commission has already responded to some of these recommendations in the synthesis Report[4].

2.           The IAS Mission: Independence, objectivity and accountability

The mission of the IAS is to contribute to sound management in the European Commission by auditing internal management and control systems to assess their effectiveness with a view to achieving on-going improvements.

The IAS is under the authority of the Member of the Commission responsible for Audit and is accountable to the APC. The independence of the IAS is enshrined in the Financial Regulation and its Mission Charter adopted by the Commission.

The IAS performs its work in accordance with the Financial Regulation and the International Standards for the Professional Practice of Internal Auditing and the Code of Ethics of the Institute of Internal Auditors.

The IAS does not audit the Member States’ systems of control over the Commission’s funds. Such audits, which reach down to the level of individual beneficiaries, are carried out by Member States’ internal auditors, national Audit Authorities, other individual Commission DGs and the European Court of Auditors (ECA). The IAS does, however, audit measures taken by the Commission services to supervise and audit bodies in the Member States, and other bodies which are responsible for disbursing EU funds, such as the United Nations. As provided for in the FR, the IAS can carry-out these duties on the spot, including in the Member States.

Overall opinion on the Commission’s financial management

As required by its charter, the IAS issued its third overall opinion on the Commission’s financial management.

The overall opinion for 2012 is based on the audits in the area of financial management in the Commission carried out by both the IAS and the IACs during the previous three years 2010 to 2012). It also takes into account information from other sources such as the reports from the ECA

The IAS, IACs or the ECA planned to audit all financial auditable entities rated as high risk and which are material for the implementation of the budget by the end of this period to ensure comprehensive coverage The completion of audit engagements in 2012 contributes to ensuring sufficient coverage for the year 2012.

IAS contribution towards mitigating the discharge risk and a more positive Statement of Assurance (‘DAS’)

The discharge procedure entails reputational risks for the Commission. The work of the IAS supports the Commission in mitigating this risk.

Compliance remains the most important aspect of the discussion, though the discharge procedure increasingly focuses on performance. Assessment of compliance is based on the results of the European Court of Auditors’ (ECA) Statement of Assurance (‘DAS’) audit. This is the opinion of the ECA on the reliability of EU accounts and on the legality and regularity of the underlying transactions.

To address the risk of error in payments, the Commission has to ensure that the implemented control strategies are proportionate to the risks. These control strategies need to be effective in preventing and detecting error, and to be accompanied by dissuasive administrative penalties and reports on the residual rate of error.

That is why audits to ensure that a coherent control strategy is being implemented for every significant area of expenditure have priority in the IAS’ Strategic Audit Plan 2010-2012 as well as for 2013-2015. In 2012, audits on control strategies in DGs AGRI, ENER, ENTR, HOME, MARE and SANCO were carried out.

3.           Audit production

3.1.        Implementation of the 2012 IAS audit plan

By the cut-off date of 1 February 2013, the IAS had implemented 100 % of its priority engagements (88 % in 2011) and 62 % of non-priority engagements (69 % in 2011).

In all, 89 reports (including audits, follow-up-audits and consultancy) were finalised, and can be broken down as follows[5]:

|| 2012 || 2011 || 2010

|| Engagements || Reports || Engagements || Reports || Engagements || Reports

AUDIT || 29 || 49 || 20 || 23 || 24 || 28

CONSULTING || 2 || 2 || 1 || 1 || 6 || 6

FOLLOW UP || 32 || 37 || 41 || 50 || 44 || 50

REVIEWS || 1 || 1 || 3 || 3 || 0 || 0

Total || 64 || 89 || 65 || 77 || 74 || 84

The attached Services Working Document summarises all completed audit reports. It includes the objectives, scope, risks and recommendations of each report, the overall state of implementation of recommendations made for 2008-2012 and summaries of conclusions of follow-up engagements.

3.2.        New recommendations and acceptance rate

In 2012, the IAS issued the following number of recommendations, including their acceptance rate:

|| New recommendations || Accepted recommendations || Non-accepted recommendations

Priority || # || # || % || # || %

Critical || 0 || 0 || || 0 ||

Very important || 83 || 83[6] || 100 % || 0 ||

Important || 109 || 108 || 99 % || 1 || 1 %

Desirable || 0 || 0 || || 0 ||

Total || 192 || 191 || 99 % || 1 || 1 %

For all accepted (or partially accepted) recommendations, the auditees drafted action plans that were submitted to the IAS and assessed as satisfactory.

3.3.        Implementation of recommendations made during 2008-12

Auditees reported that 78 % of accepted recommendations issued between 2008 and 2012 had been implemented by the start of 2013. The attached Service Working Document provides an overview of the level of implementation of recommendations (auditees’ assessment).

However, implementation on 29 very important recommendations[7] was overdue by more than six months compared to the initial deadline[8]. No critical recommendation is outstanding. The APC was regularly informed of critical or very important recommendations overdue by more than six months.

A total of 733 recommendations were accepted, for which the IAS conducted follow-up audits by the end of 2012.

The IAS’s follow-up work confirmed that recommendations were being implemented satisfactorily, contributing to the improvement of control systems in the services audited. The IAS closed 88 % of the recommendations followed up during this period.

4.           Main findings and recommendations

4.1.        Horizontal audits

4.1.1.     Annual Activity Report process (multi-DG)

The aim of the audit was to assess the adequacy and effectiveness of the AAR process in the Commission as a whole and, in particular, the extent to which it was effective in supporting the Declaration of Assurance of the different Authorising Officers by Delegation. The IAS analysed the design of the process, the existence of clear guidance and regular monitoring at corporate level, and implementation by individual DGs/Services.

This audit was performed in the SG, in DG BUDG, and in nine operational DGs/Services, DGs CNECT, EAC, REGIO, EMPL, MARE, AGRI, HOME and DEVCO and the OIB.

Overall, the IAS considers that the process is well established and that it has achieved its objective to be an accountability and assurance tool from management to the Institution. However, it identified some very important areas in which there was a need for improvements. In particular, the IAS asked central services to:

(i) provide further instructions on reporting on economy, efficiency and effectiveness of financial and non-financial operations and on cost/effectiveness of controls, so as to adequately support the AOD’s conclusions on sound management and the Declaration of Assurance;

(ii) reinforce the quality control process to focus more on substantive elements of the AAR, such as the reliability of the assurance-building process and the information supporting the Declaration of Assurance, and

(iii) streamline the structure of the AAR to avoid overly long and complex reports and to produce documents that are more useful for the College, the ECA and the Discharge Authority.

The central services accepted the IAS recommendations and prepared an action plan to improve the AAR process, which IAS deemed satisfactory. Some actions have already been implemented in the context of the 2012 AAR exercise.

Concerning the work performed in nine operational DGs/Services, the IAS only identified a major issue[9] at DG DEVCO. A limited audit on the coordination of the Delegations’ contribution to the AAR showed that DG DEVCO should strengthen its accountability system (called ‘control pyramid’) by:

(i) improving the quality of DG DEVCO’s AAR, particularly on information on the internal control system and elements supporting the Declaration of assurance of the AOD;

(ii) promoting reports from Heads of Delegation (EAMR) as "accountability tools’, by requesting to provide more information supporting their declaration of assurance;

(iii) providing further guidance to Heads of Delegation to enable them to obtain comprehensive, consistent information supporting their declaration of assurance, and

(iv) strengthening the role of Headquarters in supporting, coordinating and supervising the reporting obligations of Heads of Delegation. DG DEVCO’s action plan is considered satisfactory.

4.1.2.     Management and monitoring of staff allocation (multi-DG)

The objective of the audit was to assess whether selected Commission Services have adequate procedures and mechanisms in place to manage and monitor staff allocation effectively and efficiently in a context of staff reduction[10].

The audit focused on relevant procedures in four DGs: AGRI, RTD, COMP and DGT, selected in order to have a representative view of the different activities in the Commission. The IAS also carried out a high-level review of staff allocation procedures at corporate level, in SG, DG BUDG and DG HR.

In addition, a general survey was carried out to obtain a comprehensive overview of procedures in place across Commission Services.

The IAS recommended that DG AGRI and DG RTD pursue their efforts to develop mechanisms and tools for task mapping, put in place tools/methods to gather sufficient, reliable information concerning workloads, and develop an HR plan. The DGs accepted all the recommendations. Action plans were assessed by the IAS as being satisfactory overall.

The audit work and the results of the IAS Commission-wide survey revealed weaknesses at operational DG level that can only be resolved and attendant risks mitigated through Central Services’ actions. The IAS recommended that Central Services further develop the corporate framework for managing and monitoring staff allocation, and facilitate the dissemination of good practices between Strategic Planning and Programming (SPP) and Human Resources professionals in this area. Central Services should also improve the corporate framework for reporting and accountability by Commission Services on use of posts redeployed to these services in line with the Commission decisions on staff allocation.

4.1.3.     Chargeback[11] and internal billing systems (multi-DG)

The IAS assessed whether charge-back[12] processes complied with the Financial Regulation and central guidance, and the consistent, transparent cost calculation of services provided. The audit was conducted in DG BUDG (as leading service for managing the budgetary and regulatory framework and for the promotion of sound financial management), DG DIGIT and SCIC. In the absence of central guidance or instruction on the charge-back process, the audit found that the audited DGs defined their own criteria. Overall, these were found to be in line with budgetary rules.

However, the IAS asked auditees to strengthen the process and to enable consistent implementation across the Commission by:

(i) establishing a governance framework with clear attribution of the ownership of the process, the definition of the charge-back process and the endorsement of cost models of the major service providers;

(ii) providing central instruction and guidance (including the criteria to identify services and costs), and

(iii) providing more clarity of budget lines used for financing IT expenditure.

The IAS considers that the ABM Steering Group, as governance body, should own the process and ultimately be the body responsible body for defining the process.

DG BUDG accepted all the recommendations and the resulting action plan is assessed as satisfactory.

DG DIGIT was asked to:

(i) identify more clearly the services and costs to be charged back and propose criteria to identify the IT systems for which hosting costs are charged back, and;

(ii) ensure the governing body endorses significant changes of the cost model.

The resulting action plan for the accepted recommendations is assessed as satisfactory.

4.2.        Agriculture, Natural Resources and Health

(AGRI, ENV, CLIMA, MARE, EAHC, SANCO)

4.2.1.     Control Strategy audits (DGs MARE, SANCO)

DG MARE’s control strategy does not include clear quantifiable and measurable targets relating to the assurance building process, in particular on national audit authorities’ and DG MARE’s own planned coverage. Quantitative and qualitative indicators to measure the performance of DG MARE’s audit activity are insufficient. DG MARE also needs to strengthen its monitoring of national audit strategies and annual control reports, and to improve its controls of the way in which national audit authorities determine sampling and the error rate.

The audit of DG SANCO covered ex-ante and ex post controls. The IAS stressed the need for DG SANCO to finalise its control strategy document.

The action plans to address the issues in both audits were assessed as satisfactory.

4.2.2.     Control Strategy — Directorate J (DG AGRI)

This audit in DG AGRI focused on the design and monitoring of the control strategy for the programming period 2007-2013.

The IAS found that the audit strategy was not sufficiently formalised, and that there were gaps in the definition of the audit universe, the setting up of quantitative and measurable objectives (e.g. audit coverage), and the related capacity analysis.

Given that the next programming period is approaching, the role of assurance providers played by certification bodies in Member States should be reinforced to strengthen controls and optimise the use of DG AGRI’s limited audit resources.

The IAS also noted that audit plans were not sufficiently supported by risk assessments and that there was a significant audit backlog (13 % of engagements of 2007-2010 still open), despite the DG’s efforts to reduce it. The IAS recommended that DG AGRI develop and formalise its control strategy, re-engineer its risk assessments according to the targets established, and ensure proper monitoring through better quantitative and qualitative key performance indicators whose disclosure in the AAR should be improved.

The DG accepted all recommendations, and the IAS assessed its action plan as satisfactory.

4.3.        Cohesion

(REGIO, EMPL)

Four audits were performed in 2012 to provide reassurance on the efforts the DGs were making to tackle high error rates, particularly in DG REGIO. For the first time, the IAS accompanied[13] DG auditors on missions to Member States.

4.3.1.     Closure 2000-06 Programming Period (DG REGIO, DG EMPL)

It is essential that DGs have a well-prepared closure process to demonstrate that all errors and irregularities are detected and corrected.

Although the DGs prepared and managed the closure process for the European Regional Development Fund (DG REGIO) and European Social Fund (DG EMPL) well, there need to be improvements in planning, methodology and guidance, particularly when preparing for the closure of the 2007-2013 programming period and to improve documentation to provide better evidence of checks on closure documents.

The audit of the closure of Cohesion Fund (CF) projects in DG REGIO identified inconsistencies and gaps in the assessment process. Given the high number of projects and the work still to be done, these must be addressed for the remainder of the closure process. In this respect, harmonised templates for the analysis of the winding-up declarations have been put in place since 21 December 2012. These have been designed to address the specific gaps identified by the IAS, in particular the coordination between audit and geographical units and ensuring consistency in the qualitative assessment of closure documents.

These audits also provided DGs with a timely reminder of the need to report on the effectiveness of the closure process for the 2000-2006 period and to demonstrate the multiannual corrective capacity of the control strategy[14].

The DG accepted all recommendations and the IAS assessed its action plans as satisfactory.

4.3.2.     Implementation of 2007-2013 Programmes (DG REGIO)

Recognising the high error rates in Cohesion, the IAS conducted an audit on implementation of the 2007-2013 programming period for the European Regional Development Fund (ERDF) and the Cohesion Fund programmes to assess the extent to which DG REGIO had determined and reported reliable error rates and the extent to which sufficient and appropriate measures had been taken to reduce high error rates.

The IAS referred to the efforts done by DG REGIO to strengthen corrective measures and reduce error rates, but stressed the very high inherent risk involved when the DG has to depend so heavily on the Member States' audit authorities. Despite the efforts already made, this still represents a major challenge for the DG. These authorities have interpreted guidance in different ways, particularly as regards statistical sampling and coverage of the audit universe[15]. In addition, the DG needs to improve its own checks on the audit authorities’ annual control reports, to ensure that auditors are able to reach conclusions on the impact of the reliability of error rates from Member States' audits.

The IAS found significant variations in the extent and depth of on-the-spot tests. Whilst recognising DG REGIO needs to have a risk based approach, on-the-spot work is so crucial to its assurance process that these inconsistencies need to be addressed to minimise the risk of non-detection of system weaknesses and/or errors and irregularities.

The auditees accepted all recommendations and the IAS assessed their action plan as satisfactory.

4.4.        Research, energy and transport[16]

(EACI, ERCEA, CNECT, JRC, REA, RTD, TEN T-EA, MOVE, ENER)

4.4.1.     Control Strategy audits (DG ENER)

The review of controls in DG ENER covered ex ante and ex post controls. It found that complete and consistent audit working papers in post audit files need to be produced. Subsequently, the IAS recommended that DG ENER use a standardised audit programme and produce better evidence for the review and approval of audit issues. The recommendations were accepted and the action plan assessed as satisfactory.

4.5.        External Aid, development and enlargement

(DEVCO, ECHO, ELARG, FPI)

4.5.1.     Set-up of internal organisation in EU delegations (DG DEVCO)

The creation of the European External Action service (EEAS) has required the set-up of a number of new structures and processes, involving both Headquarters and Delegations. The general objective of this limited review was to assess the procedures put in place between the European Commission and the EEAS to ensure the sound financial management of the external aid budget implemented through EU Delegations.

The IAS invited DG DEVCO to consider whether the creation of a middle management function — particularly in the larger EU delegations — might help the Head of Delegation to manage financial assistance. There will be an audit of the effective implementation of these revised arrangements due to on-going modifications in procedures (e.g. revised financial circuits) and the implementation of a revised internal control architecture in the Delegations[17] at the time of the limited review.

4.6.        Education and citizenship

(COMM, EAC, EACEA, HOME, JUST)

4.6.1.     Lifelong Learning Programme (LLP) (DG EAC/EACEA)

The aim of the audit was to assess whether the control strategy in place in EACEA for managing the LLP Programme enables it to obtain reasonable assurance on the legality and regularity of the underlying financial transactions and to assess the adequacy, efficiency and effectiveness of DG EAC’s internal control system for exercising its supervisory role as parent DG in the agency’s implementation of the programme.

The design of the final payments process[18] is well organised and established in EACEA, but the audit highlighted inconsistent implementation of the risk-based control strategy and non-compliance with the non-retroactivity rule.

The internal control system for exercising the supervisory role of DG EAC as parent DG was assessed as adequate, efficient and effective, though weaknesses, such as the absence of an updated supervision strategy, gaps in documentation of the supervisory arrangements and the absence of key performance indicators make it difficult to assess whether the strategic supervision policy has been achieved. The direct involvement of DG EAC in the operational management of the LLP programme may not be the most efficient use of resources.

DG EAC and EACEA accepted all recommendations and EACEA and the action plans were assessed as satisfactory.

4.6.2.     Control Strategy audits (DG HOME)

The IAS highlighted weaknesses in the monitoring of DG HOME’s closure procedures, especially in the lack of adequate tools for monitoring the management of a large number of annual programme closure processes properly. Furthermore, DG HOME had not been recording the late submission of closure documents correctly as non-compliance events. The IAS recommended that the DG comply with the requirements of the Commission’s Internal Control Standards. The DG should strengthen its management and control systems and revise its procedures through a closure checklist and guidelines for closure file documents.

The IAS also identified weaknesses in the DGs’ ex-post audit strategy, and recommended that a methodology be introduced so that the results of ex-post audits could be included in the DG’s assurance model for the AAR. The related action plan is assessed as satisfactory.

4.6.3.     Monitoring the implementation EU Law (DG JUST)

Control on Member States’ correct application of EU legislation is one of the Commission’s core activities, as laid down in the Treaty. The ‘acquis communautaire’ and policy areas of DG JUST, audited in 2012, gives rise to more than 10 % of all Commission-wide active infringement cases. The auditors recognised the good maturity level and the DG’s on-going efforts, but highlighted some shortcomings in their strategic planning and programming procedures, particularly in the coverage given to the issue in Management Plans and AARs. As a consequence, the resources allocated to this activity, and their performance evaluation, are not optimal, despite its importance and size. The related action plan is assessed as satisfactory.

4.7.        Economic and financial affairs

(COMP, ECFIN, ENTR, MARKT, OLAF, TAXUD, TRADE)

4.7.1.     Implementation by the EIF of the CIP Programme (DG ECFIN)

As a part of the wider Competitiveness and Innovation Framework Programme (CIP) and of the Entrepreneurship and Innovation Programme (EIP), the High Growth and Innovative SME Facility (GIF) is a Community financial instrument for small and medium-sized enterprises. The European Investment Fund (EIF) implements GIF on behalf of the Commission on the basis of a Fiduciary Management Agreement (FMA).

The objective of the audit was to assess how effectively the EIF implements GIF, and in particular, (i) how the EIF complies with the FMA and (ii) how effectively and efficiently DG ECFIN supervises GIF so that it achieves its specific objectives.

The audit highlighted two issues:

(i) shortcomings in the indicators used to reflect the objectives of the financial instrument, and

(ii) the definition of events constituting a material change in the FMA.

DG ECFIN accepted all recommendations and the action plans were assessed as satisfactory.

4.7.2.     Off-budget operations (DG ECFIN)

As a consequence of the financial and sovereign debt crisis, the European Union has created new financial instruments to act as a borrower and to lend money to Member States in financial difficulties. The European Commission operates the European Financial Stabilisation Mechanism, a programme of financial assistance under which it may grant loans and fund these by issuing debt instruments in the capital markets.

The audit highlighted two issues in managing the new instrument:

(i) DG ECFIN is faced with new internal and external challenges for which the usual risk management practices were not fit for purpose. The development of controls in the areas of logistic support, IT security and document management was lagging behind, and

(ii) given the environment in which DG ECFIN’s operations take place, it faces the challenge of attracting and retaining competent staff without putting business continuity at risk.

These weaknesses may affect business continuity and the efficiency and effectiveness of operations, resulting in the Commission being exposed to a high reputational risk.

To address the IAS recommendations, DG ECFIN has undertaken a comprehensive risk assessment exercise on how it is implementing its new tasks.

4.7.3.     Control Strategy audits (DG ENTR)

This audit covered ex ante and ex post controls. The IAS recommended that DG ENTR strengthen the role of the internal control coordinator. Furthermore, document management and registration of exceptions should be improved. The DG’s action plan was assessed as satisfactory.

4.7.4.     Monitoring the implementation of EU Law (DG TAXUD)

The IAS carried out an audit in DG TAXUD on monitoring the implementation of EU law. Despite a number of strengths, such as strong professional experience and background of case handlers and effective prioritisation of work, the audit highlighted some shortcomings.

DG TAXUD is one of the three most infringement-prone policy areas, with more than 12 % of all Commission-wide active infringement cases, but this is not reflected fully in the Management Plan, or in the Annual Activity Report. There need to be improvements in measuring performance in this activity. IAS also recommended ensuring better coordination between units to monitor the application of EU law more effectively in the Customs area. The DG’s action plan was assessed as satisfactory.

4.8.        General services and HR

(HR, BUDG, DGT, DIGIT, EPSO, ESTAT, SJ, OIB, OIL, OP, PMO, SCIC, SG)

4.8.1.     Statistical data production, development and dissemination (DG ESTAT)

DG ESTAT (Eurostat) is entrusted with the responsibility of ensuring the production of European statistics according to established rules and statistical principles[19] and through compliance with the European Statistics Code of Practice[20].

The lack of coordination between policy DGs and Eurostat on statistical work was included in DG ESTAT’s 2011 risk register as a critical risk.

The objective of this audit was to assess the adequacy, effectiveness and efficiency of processes related to the production, development and dissemination of statistics managed by DG ESTAT (in coordination with other Commission DGs and Services).

The issues identified that may lead to inconsistencies, gaps/overlaps, low quality of data and disruption to business continuity were:

(i) lack of a clear definition and common understanding of the term ‘statistics’ within the Commission;

(ii) non-alignment of Eurostat’s Community Statistical Programme with the Commission’s strategic planning cycle;

(iii) role and responsibility of Eurostat not fully acknowledged and recognised,

(iv) no assurance on the extent of compliance with the European Statistics Code of Practice, and

(v) lack of coordination at Commission level on the use of external providers of statistical services.

Following the audit, the Commission adopted a new Decision on Eurostat (2012/504/EU) on 17 September 2012 which addresses many of the above findings. The action plan was deemed satisfactory.

4.9.        IT audits

IAS performed several audits in the area of IT, reflecting the contribution of the IAS to the overall monitoring of the technological security and viability of the Commission.

4.9.1.     Local IT systems management (DG DEVCO, DG TRADE)

The audits of local IT in DGs DEVCO and TRADE reviewed the effective and efficient management of IT activities and found well-established IT units. The audit reports placed particular emphasis on the importance of implementing effective IT governance and better IT risk management and protecting the confidentiality of the information handled (DG TRADE) and reinforcing the IT security framework to minimise security breaches (DG DEVCO).

4.9.2.     IT Governance and performance (DG SANCO/EAHC)

DG SANCO has a relatively high IT budget and finances most of its IT spending from operational appropriations. Since the previous audit[21], a significant improvement was noted in the general maturity of IT general controls. This audit focused on governance, performance and quality aspects. A more limited review was performed for EAHC, taking into account its much smaller IT budget.

The auditors found that:

(i) DG SANCO still lacks an overall long-term IT strategic plan/or documented strategy including the EAHC, explaining how it would support business processes in this time frame. Although the IT Master Plan and the Management Plan include some high level key performance indicators, there is no comprehensive performance management process, and

(ii) EAHC should formalise some key procedures (change, performance and quality management).

The action plan is assessed as satisfactory.

4.9.3.     Horizon 2020 (DG RTD, DG CNECT, ERCEA)

The ‘Horizon 2020’ flagship programme for research and innovation aims to secure Europe’s global competitiveness and is a driver for creating new growth and jobs. Several IT projects have been developed to support the management of this project, with DG RTD as system owner and DG CNECT and ERCEA as business managers.

The IAS formulated two very important recommendations:

(i) the need for more information system integration to enable the initiative to go on making progress; including the need for clear procedures and overall governance of IT via an IT Project Steering Committee, and

(ii) the need for DG RTD to define its project work and resource plan better.

As Horizon 2020 is a new, cross-cutting initiative, implementing the recommendations may involve DG DIGIT and other research DGs.

DG RTD developed an action plans which was assessed to be satisfactory.

5.           Consultation with the Commission’s Financial Irregularities Panel

No systemic problems were reported in 2012 by the Financial Irregularities Panel under Article 73(6)[22] of the Financial Regulation applicable to the general budget of the European Communities.

6.           Conclusions

The implementation of action plans drawn up in response to IAS audits in this and in previous years contributes to steady improvement in the Commission’s internal control framework.

The Commission’s services were therefore asked to ensure they took action on recommendations resulting from audits. The IAS will conduct follow-up audits on the execution of action plans that will be examined by the Audit Progress Committee, which will inform the College as appropriate.

The IAS, in close coordination with all IACs, has drawn up a new Strategic Audit Plan covering the period 2013-2015. The IAS will continue to focus on financial/compliance and IT audits will also step up activities in performance auditing.

[1]               The audit and consulting reports finalised by 1 February 2013 are included in this Report.

[2]               The Report does not cover the decentralised European Agencies, the European External Action Service, or other bodies audited by the IAS, which receive separate annual reports.

[3]               Required by the Performance Standard 2060 of the International Standards for the Professional Practice of Internal Auditing (Standards) promulgated by The IIA.

[4]               COM(2013) 334 final.

[5]               One engagement may result in several audit reports in case the engagement covers more than one Directorate-General or Service as auditee.

[6]               4 recommendations were only partially accepted.

[7]               Of these 29 recommendations, two were issued in 2006 of which one is reported as ‘implemented’ by management since March 2013.

[8]               Cut-off date is 1 February 2013.

[9]               Minor areas for improvement detected were submitted to the DG’s attention by way of management letter. The sample DGs replied positively to this letter, committing themselves to take IAS’ observations into account — to the extent possible — as from the current AAR exercise.

[10]             The Commission had proposed a reduction of staff in each EU Institution, body and agency of 5 % during the period 2013-17 through the non-replacement of some departing staff (retiring or with expired contracts). The Commission also established a mechanism to redeploy posts in order to meet its priorities, based upon a linear 1 % levy on all basic job quotas.

[11]             Cost of services of DGs/Services to other DGs/Services or institutions that are transferred from the budget line of the client to the one of the provider (recovery orders, co-delegations and cross sub-delegations). There is no consolidated figure providing an overview of the amounts charged-back to internal and external clients by Commission service providers.

[12]             Cost of services of DGs/Services to other DGs/Services or institutions that are transferred from the budget line of the client to the one of the provider (recovery orders, co-delegations and cross sub-delegations). There is no consolidated figure providing an overview of the amounts charged-back to internal and external clients by Commission service providers.

[13]             In the Audit on implementation of the 2007-13 Programming Period in DG REGIO

[14]             A report on corrective capacity of financial corrections for the period 2000-2006 was submitted to the COCOBU on 12 April 2013.

[15]             DG REGIO has transmitted an updated sampling guidance to Audit Authorities on 4 April 2013. It also organised workshops addressed to these bodies in November 2012 in Brussels and seminars were held in 2013 in some Member States (Italy, Spain, Germany, Slovakia and Czech Republic).

[16]             Extensive audit work, in particular on control strategies, was carried out in this policy area in 2011.

[17]             e.g. revamped External Assistance Management Reports, declaration of assurance from Heads of Delegation.

[18]             Excluding final payments of the administrative budget and procurement, as well as those parts of LLP implemented through the National Agencies in the Member States.

[19]             Regulation (EC) No 223/2009, Article 6.

[20]             COM(2005) 0217 final.

[21]             2006 IT audit on ‘Large scale information systems’.

[22]             Art. 117, RAP stipulates: ‘That annual report [i.e. 99(3) report] shall also mention any systemic problems detected by the specialised panel set up pursuant to Article 73(6) of the Financial Regulation.