Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Internal Audit topic

No spam. Unsubscribe anytime.

Norman staff presents final draft of triennial audit plan, flags missing p‑card policy

2766745 · March 25, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

At a March 25 council conference, a staff presenter outlined the City of Norman’s final draft triennial audit plan for fiscal years 2025–2027, describing the risk-assessment process, the audit universe, department workshops and a gap: no comprehensive purchasing‑card (p‑card) policy despite about 50 city credit cards.

Staff member presented the final draft of the City of Norman’s triennial audit plan for fiscal years 2025–2027 to Mayor Bridal and the City Council at a March 25, 2025, city council conference.

The draft identifies an ‘‘audit universe’’ and a prioritized list of audits based on a risk assessment and input from departments and councilors. The presenter said the city’s risk-assessment process included surveys to management, department-level workshops and control self-assessments.

“My hope with that, my hope,” the presenter said, “we have a final draft for the comprehensive audit plan of fiscal year 25 through fiscal year 27.” The presenter told the council the risk assessment produced an audit universe of about 235 units and identified auditable units for future review. The presentation also stated that control self-assessments were conducted and that departments at all levels contributed feedback.

The presenter listed the risk criteria used to prioritize audits: appropriateness and comprehensiveness of documented policies; awareness of and adherence by employees; effectiveness of preventive, detective and corrective controls; segregation of duties to prevent conflicts of interest; automation versus manual process dependencies; and business continuity and disaster recovery planning.

The presenter flagged a specific gap in internal controls: the city’s credit‑card program. “We have credit cards. I I think now we’re at 50, maybe 50 plus and we don’t have a comprehensive p card policy,” the presenter said, urging that the plan address the issue. The draft lists the credit‑card/p‑card area as a proposed audit topic.

The presentation noted council input was solicited to align audit priorities with elected officials’ concerns. The transcript of this session records an explanation of methods and scope but does not show a formal council motion or vote adopting the plan during the conference.

What happens next was not specified in the transcript: the presentation described the final draft and the process used to develop it, but no formal adoption, direction to staff, or implementation timetable was recorded in the provided excerpt.