Toronto Transit Commission - Audit, Finance and Risk Management Committee
The full agenda, as filed
All 4 items in the clerk’s order. Each carries the city’s own words: the staff recommendation, what the body decided, and its status. Nothing below is written by us.
TTA4.1adopted
KPMG LLP’s Audit Plan for Year Ended December 31, 2025
This report from the TTC's external auditors, KPMG LLP, outlines the audit plan for the audit of the TTC's consolidated financial statements and its subsidiary company, TTC Insurance Company Ltd., for the year ended December 31, 2025.
The Audit & Risk Management Committee 1. Received this report for information.
Staff recommendation as filed
It is recommended that the Audit & Risk Management Committee 1. Receive this report for information.
TTA4.2adopted
Audit, Risk and Compliance - 2026 Audit Plan and Departmental Evaluation
ARC Audit Plan The Audit, Risk, and Compliance (ARC) Audit Plan outlines the reviews and nature of internal audit work that ARC intends to conduct in 2026. By focusing ARC internal audit resources on key areas, we aim to maximize benefits for the TTC, such as enhancing operational efficiency, ensuring regulatory compliance, and providing valuable insights for informed decision-making. ARC takes into consideration a variety of inputs to identify planned audit work for the year. These inputs include: Interaction and discussion with Executive Management and select Senior Management; Interaction and discussion with the External Auditor; Interaction and discussion with the Audit & Risk Management Committee (ARMC); An audit universe risk assessment; Enterprise risks; and External literature and news events from professional bodies and organizations. The Proposed Audit Plan for 2026 consists of four comprehensive assurance projects and four follow-up validation projects, the results of which will be reported to the ARMC as part of regular ARC Audit Plan Status Updates. This Proposed Plan (see Attachment 2) is being submitted for review and approval by the Committee. An additional project on overtime management is being considered for inclusion in the audit plan. Analysis is being performed prior to making a final recommendation. This project or an alternative will be suggested at the next ARMC for approval. This work will be completed in addition to any ad hoc advisory work and special requests submitted to ARC throughout the year. ARC Audit Charter An audit charter serves as a foundational document that defines the purpose, authority, and responsibility of the internal audit function and establishes its role within the organization. It provides the TTC a blueprint for how internal audit will operate and explains the value of internal audit's independence in providing assurance and advisory services to the TTC. There is no update to the approved Audit Charter. Independence and Objectivity Per the new Institute of Internal Audit (IIA) standards, the internal audit function must be positioned within the organization to ensure independence and objectivity. The function must report functionally to the Board and administratively to Senior Management. There is a requirement to report any impairment(s) to the independence of the internal audit function. ARC notes that there have not been any impairments to independence to date for 2025. Quality Assurance and Improvement Program (QAIP) It is mandated in the Audit Charter that ARC will maintain a QAIP. The program covers all aspects of the ARC Internal Audit function and requires conformance with the Institute of Internal Audit (IIA)'s Standards. The program consists of continuous oversight and review of each engagement, an annual internal assessment of conformance with the Standards, and the engagement of a qualified external party to perform an assessment of the internal audit function every five years. An internal assessment is currently underway to identify opportunities for improvement. The findings will be reported at the next ARMC meeting.
The Audit & Risk Management Committee: 1. Approved the ARC Audit Plan (2026) - attached as Attachment 2 to this report.
Staff recommendation as filed
It is recommended that the Audit & Risk Management Committee: 1. Approve the ARC Audit Plan (2026) - attached as Attachment 2 to this report.
TTA4.3adopted
Audit, Risk and Compliance - 2025 Year-End Enterprise Risk Management Update
The Audit, Risk and Compliance Department (ARC) has been tasked with progressing the maturity of the Enterprise Risk Management (ERM) Program at the TTC and provides this report to the Audit & Risk Management Committee (ARMC) to share information on the status of the ERM Program. This report provides an overview of the following items: Key Enterprise Risks Overview: Provides an overview of the 10 Key Enterprise Risks that the TTC has identified as inherent to its operations and business environment. The identification and assessment of these Key Enterprise Risks define the types and level of exposure that the TTC may encounter in the pursuit of its objectives and Corporate Plan. The identification, assessment, monitoring, and reporting of these Key Enterprise Risks is intended to assist in the prioritization of proactive mitigation strategies and to provide information to support decision-making. Risk Appetite Statements Update: ARC facilitated the development of Risk Appetite Statements for the TTC's 10 Key Enterprise Risks as communicated in the 2025 ERM Roadmap. The development of these Risk Appetite Statements was completed in collaboration with key stakeholders throughout 2025 and articulates the acceptable levels of risks the TTC is willing to accept or take in relation to each Key Enterprise Risk. The use of these Risk Appetite Statements and forthcoming tolerance limits will enable the organization to promote consistency in decision-making related to risks, manage the effects of uncertainty, and build stakeholder confidence. 2025 ERM Roadmap Update: This report provides the details of ARC's annual roadmap of deliverables that were highlighted in March 2025. Evaluating progress against annual goals ensures adequate progress and allows for refinement of actions, if necessary, to adapt to any changing priorities or emerging threats in the business environment. ARC has successfully completed all planned activities as outlined in this roadmap and will now commence the development of the 2026 ERM Roadmap.
The Audit & Risk Management Committee: 1. Received this report for information. 2. Authorized that the information contained in the Confidential Attachment remain confidential as it contains information about the security of the property of the local board.
Staff recommendation as filed
It is recommended that the Audit & Risk Management Committee: 1. Receive this report for information. 2. Authorize that the information contained in the Confidential Attachment remain confidential as it contains information about the security of the property of the local board.
TTA4.4adopted
Fare Compliance Action Plan - Update
The Audit & Risk Management Committee will receive an in-camera presentation, providing an update on the Fare Compliance Action Plan.
The Audit & Risk Management Committee: 1. Received the Confidential Attachment and authorized that the information contained in the Confidential Attachment remain confidential as it relates to the security of the property of the municipality or local board.
Staff recommendation as filed
It is recommended that the Audit & Risk Management Committee: 1. Receive the Confidential Attachment and authorize that the information contained in the Confidential Attachment remain confidential as it relates to the security of the property of the municipality or local board.