In compliance with applicable law, PSERS is required to undergo a third-party audit assessing specific controls in place to ensure accurate reporting and to prevent fraud. PSERS chose to conduct the audit in accordance with System Organizational Controls (SOC) 1 Type 2 standards, which are the most rigorous available. In addition to being among the first public pension systems to complete an audit using SOC 1 Type 2 standards, PSERS received a gold standard rating.
The audit delivered the unqualified opinion, the top level of assurance, confirming that the system’s controls were sound and effective throughout the testing period. The rating underscores PSERS’ commitment to strong governance, operational excellence, and continuous improvement on behalf of its members.
In the name of transparency, PSERS made public a memorandum issued by the third-party assessor highlighting key control objectives in the audit, which is available on its website.
As noted in the memorandum, the report is not intended to be publicly shared because it contains sensitive information that bad actors could use to obtain unauthorized access to members’ personally identifiable information – therefore public disclosure of the report would expose PSERS to increased cybersecurity and fraud risk.
As such, PSERS did not accommodate a request from the media to share the full report. The reporter filed an appeal with the Office of Open Records (OOR) requesting the report. On appeal, PSERS asserted that the report should not be made public because its disclosure would jeopardize member data and computer security, which is protected under Pennsylvania’s Right-to-Know Law. Alternatively, we asked that the OOR permit us to make redactions of the information that could compromise member data security. Our final appeal to the OOR seeking redactions to the report of information we considered sensitive was ultimately unsuccessful.
Consequently, we filed a Petition for Review in the Pennsylvania Commonwealth Court challenging the OOR’s determination that the unredacted report should be publicly disclosed.
Pending the decision of the courts on the requested release of the report, members can rest assured we will take all appropriate measures to protect their data and PSERS’ computer security. We remain committed to doing so while also delivering on our promise to members of a secure retirement.