directors risk management - nd portal2017-19 state budget finalized by legislature the 2017...

4
Spring 2017 Directors Pam Sharp Director of OMB 701-328-4904 www.nd.gov/omb/ Sherry Neas, Director Central Services Division 701-328-1726 John Boyle, Director Facility Management Division 701-328-2471 Sheila Peterson, Director Fiscal Management Division 701-328-2680 Becky Sicble, Interim Director Human Resource Management Services Division 701-328-4735 Tag Anderson, Director Risk Management Division 701-328-7584 e exposures that are faced as a result of an electronic data breach is an increasingly important issue faced by most organizations including state agencies. e liability an agency may have to an individual who has been harmed as a result of protected personal information being wrongfully or negligently disclosed has been an exposure that has long been covered by the Risk Management Fund pursuant to NDCC 32-12.2. However, a data breach also carries with it regulatory notification requirements such as those found in NDCC 51-30. In appropriate circumstances, an agency may also be expected to take measures to lessen the potential impact to affected individuals from a data breach by offering such things as free credit monitoring for a period of time. ese first-party costs are the responsibility of the agency impacted by the data breach. In 2014 and again in 2015, the state was impacted by security breaches that could have resulted in the disclosure of large amounts of personal information. e Risk Management Fund did not receive any third-party claims following these incidents, but the costs incurred by the impacted state entities for notification and offering mitigation services was significant. In order to lessen the hardship to state agencies impacted by a data breach, Risk Management pursued legislation to provide it with authority to assist state agencies in meeting their notification and mitigation responsibilities. House Bill 1088, which was passed this past legislative session, provides Risk Management with authority to spend monies from the Risk Management Fund for notification and remediation costs following a data breach that otherwise would be the responsibility of the impacted state entity. HB 1088 also provides Risk Management with authority to purchase insurance and approve the purchase of insurance by individual state entities to cover exposures from a data breach. Because of fast-paced changes in the availability and cost of commercial insurance products covering data breach exposures, HB 1088 provides flexibility to self- fund and purchase insurance to most cost effectively address both third-party and first- party exposures. R RISK MANAGEMENT data breach notification and mitigation

Upload: others

Post on 03-Oct-2020

2 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Directors RISK MANAGEMENT - ND Portal2017-19 State Budget Finalized by Legislature The 2017 legislature completed their work on the 2017-19 state budget and adjourned sine die on April

Spring 2017

DirectorsPam SharpDirector of OMB701-328-4904www.nd.gov/omb/

Sherry Neas, DirectorCentral Services Division701-328-1726

John Boyle, DirectorFacility ManagementDivision701-328-2471

Sheila Peterson, DirectorFiscal Management Division701-328-2680

Becky Sicble, Interim DirectorHuman ResourceManagement Services Division701-328-4735

Tag Anderson, DirectorRisk Management Division701-328-7584

The exposures that are faced as a result of an electronic data breach is an increasingly important issue faced by most organizations including state agencies. The liability an agency may have to an individual who has been harmed as a result of protected personal information being wrongfully or negligently disclosed has been an exposure that has long been covered by the Risk Management Fund pursuant to NDCC 32-12.2. However,

a data breach also carries with it regulatory notification requirements such as those found in NDCC 51-30. In appropriate circumstances, an agency may also be expected to take measures to lessen the potential impact to affected individuals from a data breach by offering such things as free credit monitoring for a period of time. These first-party costs are the responsibility of the agency impacted by the data breach.

In 2014 and again in 2015, the state was impacted by security breaches that could have resulted in the disclosure of large amounts of personal information. The Risk Management Fund did not receive any third-party claims following these incidents, but the costs incurred by the impacted state entities for notification and offering mitigation services was significant.

In order to lessen the hardship to state agencies impacted by a data breach, Risk Management pursued legislation to provide it with authority to assist state agencies in meeting their notification and mitigation responsibilities. House Bill 1088, which was passed this past legislative session, provides Risk Management with authority to spend monies from the Risk Management Fund for notification and remediation costs following a data breach that otherwise would be the responsibility of the impacted state entity.

HB 1088 also provides Risk Management with authority to purchase insurance and approve the purchase of insurance by individual state entities to cover exposures from a data breach. Because of fast-paced changes in the availability and cost of commercial insurance products covering data breach exposures, HB 1088 provides flexibility to self-fund and purchase insurance to most cost effectively address both third-party and first-party exposures.

RRISK MANAGEMENTdata breach notification and mitigation

Page 2: Directors RISK MANAGEMENT - ND Portal2017-19 State Budget Finalized by Legislature The 2017 legislature completed their work on the 2017-19 state budget and adjourned sine die on April

Page 2 The Standard Spring 2017

FFiscal Management

Fiscal Management continued on page 3

BIENNIUM END DEADLINESAs the biennium end is fast approaching, following are dates to remember for end of the biennium business:

• The last day to process June business will be July 26 at 5:00 pm. • The accounting system will be unavailable July 27 and July 28, which means no 2015-17 or 2017-19

biennium business will be processed. • The system will be back up July 31.

PeopleSoft Time and LaborEffective July 1, 44 state agencies will go-live with PeopleSoft Time and Labor. PeopleSoft Enterprise Time

and Labor is a flexible, integrated solution designed to support the time reporting needs of a wide range of business functions, including payroll, financials, and absences. PeopleSoft Time and Labor automates the processing of payable time.

Comprehensive Annual Financial Report (CAFR)• Training: Need help completing a CAFR Closing Package? CAFR training will be offered this fall and will

coincide with the due dates of the closing packages. Details including dates, times and locations for training will be emailed to CAFR contacts in July. Training will be conducted one-on-one and on a first-come basis, so bring your questions and the information needed to complete your closing package.

• Control Checklist Has a New Look in 2017: The new control checklist will now be completed on an agency basis instead of on a per fund basis. This means that each agency will now only be submitting one control checklist.

• New GASB Standard Relating to Tax Abatements to be Implemented in 2017: GASB 77 will require new note disclosures in the CAFR. The note disclosures will provide the “essential information about the nature and magnitude of the reduction in tax revenues through tax abatement programs”. Agencies will be asked to report their tax abatements on the Miscellaneous Summary Closing Package.

• 2016 CAFR Received GFOA Award: The Government Finance Officers Association of the United States and Canada (GFOA) awarded a Certificate of Achievement for Excellence in Financial Reporting to the State of North Dakota for its CAFR for the fiscal year ended June 30, 2016. This was the 25th consecutive year that ND has achieved this prestigious award. In order to be awarded a Certificate of Achievement, a government must publish an easily readable and efficiently organized comprehensive annual financial report. This report must satisfy both generally accepted accounting principles and applicable legal requirements.

PeopleSoft Financial TrainingMark your calendar! OMB will be offering PeopleSoft training for financial modules on September 19-20. We

will try a new training format--each module will have its own room, and people can come during that day for one-on-one training. More details will be coming later this summer, along with a survey on what agencies would like to see covered.

Transparency WebsiteNew on the transparency website is a category on Purchasing Card Expenditures. This allows viewing purchasing

card transactions by an agency or by merchant starting with the 2015-17 biennium. “Transactions by Agency” displays the total amount of purchasing card transactions by an agency for the biennium with merchant detail. “Transactions by Merchant” shows the total amount of purchasing card transactions for a merchant with agency detail. These transactions are for State Government and Higher Education.

Page 3: Directors RISK MANAGEMENT - ND Portal2017-19 State Budget Finalized by Legislature The 2017 legislature completed their work on the 2017-19 state budget and adjourned sine die on April

The Standard Spring 2017 Page 3

Fiscal Management continued from page 2

Purchasing Card RebateThe state’s purchasing card program had just over $113,599,000 of total spend for the 2016-17 contract year. The

state received a total of $1,833,143 in rebate, with the General Fund receiving $550,308. The rest of the rebate was allocated between the colleges and universities, 11 counties, 57 school districts and 3 cities and boards.

2017-19 State Budget Finalized by LegislatureThe 2017 legislature completed their work on the 2017-19 state budget and adjourned sine die on April 28 of this

year. The total state budget (all funds) for the 2017-19 biennium is $13.55 billion. The General Fund portion of this

amount is $4.31 billion. The decrease in General Fund appropriations from the 2015-17 biennium original appropriation (prior to any allotments) is $1.70 billion. A considerable amount of the $1.70 billion decrease was in one-time spending (roads, capital projects, computer projects, etc.) but the overall decrease is significant for on-going expenditures. Agencies will be challenged to meet their statutory responsibilities and workload demands within these budget limits.

Total state authorized full time equivalencies (FTE) in 2015-17 decreased by 662.87. Of this number, 347.60 FTE were reduced from state agencies and 315.27 were reduced from higher education.

General Fund revenues are projected at $4.33 billion for the 2017-19 biennium. The largest source of General Fund revenue continues to be the sales and use tax. The ending fund balance for the General Fund at June 30, 2017 is projected at $30.9 million and the ending fund balance for the General Fund at June 30, 2019 is projected at $50.4 million.

Increased Security at Capitol Will ContinueThe ND Highway Patrol will continue to provide increased security at the Capitol building. The south (mall/

tunnel) entrance is the ONLY public entry, and is open Monday through Friday from 7:15 a.m. to 5:30 p.m. Weekend hours will be limited during summer months. Metal detectors will remain at the south entrance, staffed by NDHP security during regular business hours. All entrances will remain accessible to state employees with valid state-issued identification card keys.

EventsMany special events are scheduled throughout the Capitol grounds this summer. Two very popular events include

the 4th of July celebration and the Capitol A’Fair. The Bismarck Mandan Symphony Orchestra will kick off the 4th of July celebration by performing on the Capitol Plaza steps at 9:00 pm. This will be followed by a spectacular fireworks display scheduled to begin at approximately 10:30 pm. The Capitol A’Fair is scheduled for August 5-6. Visit the OMB website for a list of other events scheduled to be held on the Capitol complex.

ProjectsThe new governor’s residence project continues to progress on time and on budget. The project team of Chris

Hawley Architects, Northwest Construction, Northern Plains Heating and Air, Magnum Electric and Facility Management are working diligently to ensure the new residence will be available for occupancy by Thanksgiving. Many legislators had positive comments while touring the new residence during this past legislative session.

In an effort to preserve the current governor’s residence, there will be an opportunity for anyone to submit an offer to purchase and relocate it. In mid-June, the advertisement for the request for proposal will be printed in the eight major daily newspapers. All proposals must be submitted to Facility Management no later than July 15. If interested, please contact Julie Thiery at 701.328.2471.

Facility ManagementFacility Management

Page 4: Directors RISK MANAGEMENT - ND Portal2017-19 State Budget Finalized by Legislature The 2017 legislature completed their work on the 2017-19 state budget and adjourned sine die on April

Page 4 The Standard Spring 2017

Central Services CS DGreen Procurement

The State Procurement Office (SPO) is seeking Ideas for 2017 Sustainable Purchasing Initiatives. North Dakota state laws require the state and institutions to purchase recycled paper and encourage the purchase of environmentally preferable and bio-based products. SPO has established contracts that include “green” products and services, such as recycled paper and paper products, hazardous waste disposal, electronic waste recycling, toner and cartridge recycling.

The SPO has funds available in 2017 to develop and promote sustainable purchasing. Last year, funds were used to establish a recycling program for the capitol complex and purchased recycling receptacles for several higher education campuses. Contact Christy Schafer, 701.328.2740, to share ideas for new “green” state contracts or other sustainability initiatives.

HHuman Resource Management ServicesPay Ranges for Classified Employees

Due to ND’s changing job market and budgetary constraints placed on state agencies, the State Personnel Board voted not to change the classified employee pay ranges for the 2017-19 biennium. If ND’s job market improve dramatically during the upcoming biennium, the State Personnel Board and HRMS will reevaluate the classified employee pay ranges.

Voluntary Separation Incentive Program Offered

In an effort to reduce staffing costs or FTEs for the 2017-19 biennium, a Voluntary Separation Incentive Program (VSIP) was offered to employees in 17 state agencies, one of which was OMB. May 22 was the deadline to apply, and approximately 173 applications have been received by all participating agencies. Each agency’s leadership will review their own applications to determine whether to accept the requests based on each position’s assigned job duties and the business needs of the agency.

Legislation Related to Types of ProcurementPublic Improvement NDCC 48-01.2

• Current: $100,000 threshold for bidding. $150,000 threshold for procuring plans, drawings, specifications from an architect or engineer.

• Effective August 1, 2017: SB 2146 provided $150,000 threshold for bidding.• Must advertise by publishing 3 consecutive weeks at least 21 days.• Emergency exception NDCC 48-01.2-04.

Architect, Engineer, and Land Surveying Services NDCC 54-44.7• Current: Direct negotiation permitted for projects not to exceed $25,000. Fees paid during a 12 month period

by a single agency to any one firm may not exceed $50,000.• Effective August 1, 2017: HB 1189 provided for direct negotiation permitted for projects not to exceed

$35,000 pursuant to NDCC 54-44.7-04. Fees paid during a 12 month period by a single agency to any one firm may not exceed $70,000.

• Projects over the thresholds must be noticed and evaluated pursuant to NDCC 54-44.7-03.• Splitting projects to circumvent competition prohibited.

Commodities and Services NDCC 54-44.4• HB 1090 eliminated the report of services required in NDCC 54-44.4-02.1. Amended open record laws in

subsection 6 of NDCC 44-04-18.4 related to bids and proposals to be consistent with NDCC 54-44.4-10.

Supplier Self-RegistrationOffice of Management and Budget is in the process of rolling-out PeopleSoft Supplier Onboarding functionality.

This feature will allow bidders and vendors to self-register by providing their W-9 and application information on-line for Vendor Registry approval. This self-registration will allow vendors the ability to create and maintain their profile information and have access to the most current forms. The go live with this functionality is anticipated by late summer.