Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Procurement Process Audit topic

No spam. Unsubscribe anytime.

OAG audit finds inconsistent vendor-approval rules, urges FCPS to streamline procurement and cyber reviews

AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

The Office of the Auditor General reported three moderate findings, one low finding and one observation after reviewing 63 FY2024 contracts, calling for clearer approval authority, tailored vendor questionnaires, and KPIs to measure procurement performance.

The Office of the Auditor General reported March 17 that Fairfax County Public Schools’ procurement and third‑party vendor review processes include conflicting guidance, inflexible questionnaire requirements and limited performance monitoring, and recommended the division align rules and add performance measures.

The audit, presented to the Audit Committee by Luke Robertson and Tim Tishman of the Office of the Auditor General, examined procurement activity in fiscal year 2024 and reviewed a sample of 63 contract files, related FCPS regulations and procedure documents, and guidance from the Office of Procurement Services (OPS), Office of Cybersecurity (OCS) and Technology Architecture and Assessment (TAA). It also compared practices to the Fairfax County purchasing resolution, the Virginia Public Procurement Act and Government Accountability Office guidance.

The audit’s “why it matters” is operational: auditors said inconsistent language about who approves vendor products and when questionnaires must be completed can delay needed purchases and risk administrative inefficiency.

Key findings and recommendations

- Conflicting approval authority: The OAG found “conflicting and inconsistent language within their policies, regulations and internal and external guidance regarding the shared vendor approval process functions of OPS, OCS and TAA,” and recommended the offices document a single, standardized risk‑assessment process and revise regulations to align with that process. Luke Robertson said the inconsistency spans FCPS regulations and internal SOPs and can slow decisions.

- Questionnaires not risk‑tiered: Auditors flagged that OCS and TAA require a single, comprehensive vendor questionnaire in many cases regardless of the contract’s technological complexity. The audit recommends scoping questionnaires to the product or service, considering third‑party risk management software, and accepting industry certifications (for example, ISO 27001 or SOC 2) in lieu of full questionnaires when appropriate.

- Limited procurement performance monitoring: The audit found OPS, OCS and TAA lack key performance indicators (KPIs) and consistent milestone tracking in the contract request and management (CRAM) system, limiting management’s ability to measure effectiveness. The OAG recommended building KPIs and baseline measures into procurement processes.

- Contract file documentation gaps (low risk): Nine of 63 contract files were missing documentation required by FCPS regulations and SOPs; auditors recommended OPS ensure required documentation is maintained and consider updating Regulation 50‑12 to document cooperative procurement methods more explicitly.

- Supplier diversity observation: The audit noted FCPS lacks a standalone supplier‑diversity program like the county’s and recommended OPS consult with division counsel and county procurement to determine whether FCPS must or should adopt a separate program and to advertise resources for SWaM (small, women‑owned, minority‑owned and service‑disabled‑veteran‑owned) vendors.

Responses and committee discussion

Members pressed auditors and staff on whether questionnaires or independent certifications should be primary risk mitigants. Mr. Moon, an audit committee member, asked whether FCPS could accept certifications in place of questionnaires and how other districts handle vendor vetting. An FCPS cybersecurity representative explained ISO 27001 and SOC 2 as industry‑recognized attestations that examine information‑security controls; committee members and Superintendent Reid said they would rely on the cyber team’s risk recommendations when setting division policy.

Auditors said questionnaire length and limited milestone tracking contributed to vendors not responding or taking months to complete questionnaires, which can cause FCPS to forfeit timely access to services.

What happens next

The OAG asked OPS, OCS and TAA to collaborate to (1) standardize risk assessment and vendor review responsibilities, (2) scope questionnaires by use case and consider accepting recognized certifications, and (3) adopt KPIs and milestone tracking in CRAM to monitor effectiveness. Committee members asked staff to benchmark other large school divisions and report back.

The audit report contains more detail and a 1‑page summary and 2‑page executive summary presented to the committee.