Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Internal Audit topic

No spam. Unsubscribe anytime.

School board endorses starting internal audits of cybersecurity and contract administration

3540719 · May 28, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

At a May 27 Clay County School Board workshop auditors outlined a top-10 risk list and the audit committee recommended three audits; the board gave consensus to begin with cybersecurity and contract administration and asked staff to place a contract on a future consent agenda.

Auditors presented a district-specific risk assessment and recommended starting internal audits of cybersecurity and contract administration, with timekeeping identified as a close third priority.

The audit presentation to the Clay County School Board at its May 27 workshop framed the work as the start of a new internal audit function. The consultant said the audit committee and auditors converged on three recommended engagements — cybersecurity, contract administration and timekeeping — and recommended that the board decide which one or two to start in the coming year.

The auditors said the top-10 risk list was developed from nearly 30 interviews with board members and senior leaders, plus the firm’s experience in other school districts. The consultant explained cybersecurity would include internal and external penetration testing while contract administration would evaluate post‑award contract management and invoice testing. Timekeeping audits would examine segregation of duties, approvals, overtime and payroll adjustments across decentralized sites.

Board members discussed timing, costs and staff impact. The consultant estimated an internal penetration and external penetration test could be completed in about two months, while a typical contract administration or timekeeping audit generally runs eight to 12 weeks. The presenter also cautioned that auditing a process that is mid‑implementation (for example, internal accounts being added to the ERP) can be disruptive.

After discussion the board reached consensus to begin with two audits — cybersecurity and contract administration — and directed staff to bring the corresponding contract(s) to a future board meeting for approval. No formal roll‑call vote was recorded during the workshop; the decision was recorded as a board consensus during discussion.

Board and staff emphasized the audits are intended to assess controls and risk posture, not to presume existing problems. As the consultant put it during the workshop, "just because something's on this list doesn't mean that we think there's a problem; it just means it's an area of high risk and a good candidate for an audit." Ending: The district will return the selected audit scopes, estimated fees and a proposed contracting timeline to a future board meeting so the board can formally authorize work and allocate funding.