Blog

Internal Audit Newswire - September 20, 2026

Internal Audit Newswire

Subscribe now to join the Risk Register community:

Hero image

Attorney General Schwalb Secures $9.3 Million from Two DC Landlords in RealPage Price‑Fixing Scheme

Source: Office of the Attorney General for the District of Columbia (oag.dc.gov)

Summary: On September 14, 2026, the DC Office of the Attorney General announced settlements totaling $9.3 million with JBG Associates, L.L.C. (JBG Smith) and Mid‑America Apartments (MAA) in its antitrust case tied to RealPage’s pricing software. The landlords agreed to pay and modify business practices the OAG alleged inflated rents across thousands of District units. JBG Smith owns over 4,500 units in DC; MAA owns 269. The agreements resolve part of a broader suit that originally named RealPage and 14 landlord defendants, underscoring regulatory attention on third‑party algorithmic pricing tools.

Internal Audit Implications: Treat algorithmic pricing as an antitrust control domain, not just a revenue tool. This quarter, internal audit should inventory every system influencing prices or rents, including vendor software, and update the risk register to reflect antitrust exposure from algorithm‑driven recommendations. Test third‑party due diligence and procurement controls: legal review sign‑offs, antitrust compliance attestations, and contract clauses restricting competitor data sharing and mandating cooperation with investigations. Assess control design around how recommendations are used: documented decision rights, evidence that management exercises independent judgment, approval thresholds for price moves, and monitoring for anomalous correlation with competitor pricing. Review access management and change‑management over pricing tools; confirm logging captures who viewed, changed, or accepted algorithmic outputs, and that overrides and exceptions are reviewed. Evaluate training and communications controls for antitrust compliance, especially for pricing, revenue management, and vendor‑management staff. Inspect data‑governance controls to prevent ingestion of competitively sensitive data and to segregate internal data from any multi‑client pools. For governance, confirm risk oversight includes periodic reporting on algorithmic pricing risks, with clear trigger criteria for pausing or exiting a vendor tool. Expect audit committee questions: Are we using RealPage or similar products? What controls prevent tacit coordination via shared algorithms? What evidence shows independent pricing decisions? How are vendors monitored for antitrust risk? If regulators inquire, can we produce logs, approvals, and training records? Ensure these answers are supported by tested controls and retained evidence.


Hero image

CenterPoint Energy Confirms Data Breach; Files SEC Form 8‑K Disclosing Unauthorized Access to Customer Information

Source: Shattered (security reporting reproducing SEC filing)

Summary: Security reporting reproduced that CenterPoint Energy filed a Form 8‑K on September 14, 2026, disclosing an unauthorized third party obtained a dataset containing certain customer information via an externally accessible system. The company became aware after a public post in September 2026 claimed to contain customer data; the SEC filing served as the regulatory disclosure and referenced the incident and potential customer‑impact scope. The coverage ties the disclosure to that date, highlighting governance around cyber incident detection, escalation, and investor reporting under Item 1.05.

Internal Audit Implications: Internal audit should treat this as a live drill on disclosure controls and IT risk. Start by testing incident‑response controls from detection to disclosure: how public‑source intelligence (e.g., posts claiming leaked data) is monitored, triaged, validated, and escalated; the playbook for externally accessible systems; and the handoff to legal, security, and the disclosure committee for Item 1.05 determinations. Inspect evidence of timelines, decision memos, and approvals. Evaluate control design over externally accessible systems: asset inventory accuracy, data classification, least‑privilege access, MFA, vulnerability management, logging, and retention sufficient to scope what data was accessed. Confirm procedures for containing access, preserving forensics, and assessing customer‑impact scope are documented and rehearsed via tabletops. For SOX 404 and ICFR, verify that disclosure controls capture cyber incidents that may require SEC reporting and that responsibilities between security, legal, finance, and investor relations are defined, with a repeatable workflow to produce complete and accurate Form 8‑K language. Test the accuracy controls over incident facts used in filings. Expect audit committee questions: Did we detect this type of issue ourselves or learn of it from the public? Which externally accessible systems hold customer data, and how are they governed? What are our escalation triggers for Item 1.05? How are remediation actions tracked and validated? Come prepared with test results and any required control remediation plans.


Hero image

Twelve Individuals Charged in $10M Home Daycare Fraud Schemes

Source: U.S. Department of Justice (justice.gov)

Summary: On September 15, 2026, the Department of Justice announced charges against 12 individuals in coordinated actions alleging roughly $10 million in fraud involving home daycare programs. According to DOJ, more than 250 federal, state, and local officials executed arrests and 12 search warrants in the takedown. The complaint alleges false claims were submitted to obtain taxpayer‑funded childcare subsidies and benefits. The enforcement scale and alleged losses underscore how provider‑submitted claims can be exploited at volume when oversight and detection controls are weak.

Internal Audit Implications: Use this case to harden payment integrity controls where funds flow to providers. Internal audit should map the end‑to‑end claims lifecycle and perform a targeted risk assessment, then test controls at enrollment (identity/TIN verification, bank‑account ownership), eligibility determination, and ongoing provider recertification. Evaluate monitoring for red flags: claims exceeding capacity, duplicate or overlapping service periods, implausible attendance patterns, and sudden spikes by new or previously dormant providers. Assess governance over provider oversight (these are vendor‑like relationships): sanctions screening, site visits or virtual verification, segregation of duties in claims approval, and a clear process to suspend payments pending review. Test data‑matching controls that cross‑check claims to independent data sources, and confirm exception queues are worked promptly with documented outcomes and recoveries. Strengthen detective controls with analytics and continuous monitoring; validate that hotline tips route to investigations with defined SLAs. Examine contract or program‑participation terms for audit rights and clawback mechanisms, and verify their use when fraud is suspected. Expect audit committee questions: Where are we most exposed to false claims today? What analytics are live, and how effective are they? How quickly can we suspend questionable payments and initiate reviews? Which gaps from this review are added to the risk register with owners and timelines? Bring quantified testing coverage, exception rates, and remediation actions.


Disclaimer: This content is provided for general informational purposes only and does not constitute legal, accounting, tax, investment, or other professional advice. Portions were generated using AI tools from public web sources and may contain errors or omissions — verify important details against the primary sources linked above before relying on them. Any example prompts, scripts, templates, or other artifacts are provided “as is” without warranty of any kind, express or implied; test them on non-production data and apply your own professional judgement before use. Cherry Hill Advisory disclaims all liability for any loss or damage arising from the use of, or reliance on, this content or any artifact it contains.

Subscribe now to join the Risk Register community: