Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Audit And Finance topic
No spam. Unsubscribe anytime.
Commission auditor presents risk-based audit plan; commissioners narrow priorities to contracts, ERP and billing
Summary
Forvis Mazars representatives presented a risk‑based audit plan to the City of Pembroke Pines Commission on Feb. 5, proposing updates to past operational audits, contract‑compliance reviews of large vendors and an enterprise resource planning (ERP) review with a focus on roles, permissions and vendor master‑file controls.
Get email alerts on the Audit And Finance topic
No spam. Unsubscribe anytime.
Forvis Mazars representatives presented a risk‑based audit plan to the City of Pembroke Pines Commission on Feb. 5, proposing updates to past operational audits, contract‑compliance reviews of large vendors and an enterprise resource planning (ERP) review with a focus on roles, permissions and vendor master‑file controls.
The presentation, led by Dan O'Keefe of Forvis Mazars, introduced a multi‑phase risk assessment and a slate of suggested projects including contract compliance for major vendors, an ERP/segregation‑of‑duties review, cybersecurity testing aligned to the NIST Cybersecurity Framework, and bond‑compliance monitoring should the city issue general obligation bonds in March.
Why it matters: Commissioners said the work could surface fraud, waste or abuse, ensure bond proceeds and vendor payments are tracked correctly, and address recurring resident complaints about utility billing. The commission gave staff directional guidance on which audits to prioritize and asked the auditor to proceed with a comprehensive risk assessment to produce a final, prioritized audit program.
Forvis Mazars outlined several candidate projects and methods. The firm recommended identifying vendors that received $10,000,000 or more over a three‑year window for contract compliance reviews and suggested updating prior operational audits for building permitting and transportation. It proposed ERP testing focused on segregation of duties, roles and permissions, and vendor‑master file controls — including review of bank‑account changes tied to vendor records. The firm also proposed further IT testing to align the city with recently enacted Florida statutes that align government cybersecurity practices to the NIST framework.
Dan O'Keefe said the firm uses a data‑driven approach: “We can use our data tools to test an entire population,” and explained the risk‑assessment deliverables would include a heat map of inherent and residual risks and a recommended audit coverage plan.
Commissioners pressed on specific topics. Vice Mayor Good and others endorsed an updated risk assessment and highlighted the city’s upcoming $230 million bond referendum, which Mayor Angelo Castillo said will increase the need for oversight. Eddie Castaneda of Forvis Mazars outlined proposed contract targets (including Waste Pro, Calvin Giordano & Associates, Facility Contract Services, and others) and encouraged a focused scope if the commission did not want to authorize the full slate immediately.
After extended discussion, the commission gave these directions to staff and the auditor (staff to return with formal scopes and cost estimates): - Remove the City of Hollywood utilities contract from the initial contract‑compliance list and focus on the remaining vendor targets. - Do not initiate a city‑funded review of the PACE (Property Assessed Clean Energy) program; instead, staff will check Broward County’s current status and report back. Assistant City Manager Mike Sam told the commission the city does not administer PACE providers and that authorization historically came from the state and county. - Prioritize ERP and billing‑related work (including accounts payable and utility billing) and fold related prior audit topics into the ERP project where appropriate. - Add a focused review of lobbying contracts to the candidate list.
Commissioner Schwartz urged auditing billing and construction‑related change orders and noted the public complaints about inconsistent billing cycles. Commissioner Hernandez asked the auditors to provide an estimated timeline; Forvis Mazars said a comprehensive risk assessment — including interviews and surveys — could be completed in roughly three to four weeks if schedules permit, with contract audits to follow once scopes are finalized.
The presentation also included operational controls testing recommendations for new ERP systems, vendor‑payment analytics to detect duplicates or anomalies, and a suggestion to monitor bond proceeds if the March 11 bond referendum is approved.
The commission did not take an immediate formal vote to approve a fixed workplan or budget during the meeting; instead members collectively directed staff and the auditor to refine scopes and return with cost and scheduling information.
Ending: Forvis Mazars will carry out a comprehensive risk assessment and return to the commission with a final audit plan, timeline and estimated costs. Commissioners identified contracts, ERP/billing, transportation and lobbyist contracts as near‑term priorities.

