Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Doit Audit topic
No spam. Unsubscribe anytime.
Audit finds weaknesses in Department of Information Technology controls; 14 observations and two items may need statutory change
Summary
State legislative auditors told the Fiscal Committee that the Department of Information Technology had not established adequate internal controls over revenues and expenditures and issued 14 observations, two of which the auditors said may require legislative action.
Get email alerts on the Doit Audit topic
No spam. Unsubscribe anytime.
State legislative auditors presented an assessment of internal controls at the Department of Information Technology to the Fiscal Committee on Jan. 30, 2025, saying DOIT had not established adequate controls over revenues and expenditures and that 14 observations and recommendations resulted from the review.
The audit, covering receipts, deposits, recording and reporting of revenues and the authorization, payment and reporting of expenditures for the nine months ended March 31, 2024, found several deficiencies including incomplete documentation of the cost‑allocation methodology (the audit said auditors could not recalculate three of 45 sampled allocations), weaknesses in accounts payable and activity‑code management, segregation‑of‑duties gaps in requisition systems, telecommunications billing control weaknesses, incomplete payroll monitoring, insufficient audit trails for invoice approval in the state financial system, and gaps in continuity and contingency testing.
Auditors said two recommendations may require legislative action (the report references the need for administrative rules or statutory clarification for certain DOIT authorities and position classifications). The audit noted the department had not fully remediated a set of prior findings dating to earlier audits (references in the report include findings from audits in 02/06 and 02/18), and that the appendix shows 12 findings resolved, 9 in remediation and 10 unresolved.
“We do care about this stuff and we're taking what we see here seriously,” Commissioner Dennis Goulet told the committee, describing work already under way to replace the legacy cost‑allocation software (described in testimony as “cap 95” / cap plus) with a modern system. Goulet said the agency is running the new system in parallel with the old and anticipates a cutover at the fiscal‑year boundary; he said the new system provides improved transparency and that many deficiencies reflect documentation gaps rather than demonstrable mischarging.
Auditor Kimberly Bissen summarized key observations and told the committee that some accounting processes were “overly complex, outdated, insufficiently documented, lacked oversight, or did not fully comply with state law.” The report recommended DOIT establish comprehensive written policies, a corrective‑action plan to address prior audit findings, an improved audit trail for invoice batch approval (a state‑wide change the report directed to the Department of Administrative Services for consideration), annual testing of backup processes, and formalized payroll and termination‑payout procedures.
Committee members pressed DOIT on remediation timelines and requested the department provide legislative language for items auditors marked as needing statutory clarification. Commissioner Goulet said DOIT would submit proposals for statutory revision and asked for committee assistance to include necessary language in the upcoming HB 2 deliberations.
The committee accepted the DOIT audit presentation and placed the report on file; members asked the department and the Governor's office to provide stronger tracking of outstanding audit findings so repeated issues are resolved more quickly.
The committee record shows discussions of implementation steps and a request from members that DOIT return with a corrective‑action plan and timelines for closing the open findings.

