Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Forensic Audit topic
No spam. Unsubscribe anytime.
East Point council hears forensic-audit findings; sheriff, DA notified and council finds conflict of interest
Summary
Plant Moran forensic auditors presented findings including phishing-related losses, gaps in procurement and controls, large unlabeled capital assets and inventory discrepancies. Auditors and city staff said the sheriff's office and district attorney will investigate. Council voted that a conflict of interest determination exists for one councilor;
Get email alerts on the Forensic Audit topic
No spam. Unsubscribe anytime.
East Point — At a special Sept. 22 meeting, the East Point City Council heard a forensic audit presentation and discussed recommendations to tighten finance, procurement and cybersecurity controls after auditors and city staff identified multiple weaknesses, a phishing-related loss and vendors requiring follow-up.
Plant Moran forensic auditors summarized tests that flagged deleted vendor codes, payments recorded outside normal check or vendor processes, unlabeled capital assets and an approximately $1.5 million inventory write-down. City staff and the auditors said the matter includes possible criminal elements tied to a phishing scheme; the city manager reported the sheriff's office "has agreed to investigate and the district attorney should it merit has agreed to take up prosecution." The city manager and auditors said arrests have been made in the broader criminal investigation.
The findings matter because they prompted referrals to outside law enforcement and because they exposed internal-control gaps that auditors said allowed fraudulent payments and inconsistent recordkeeping. Council members questioned procurement steps for certain vendors and asked city staff for follow-up and documentation.
Plant Moran lead Michelle McHale described the team's role as narrowly forensic and evidence-focused: "We are fact finders," she told council. Her associate, Kyle Sutton, described a set of standard red-flag analytics used in such engagements — address matches between the employee and vendor master files, round-dollar invoices, sequential invoice numbers — and said the tests identified two vendors of particular interest.
Phishing incident, recoveries and cyber controls
Auditors and the city manager said the city experienced a phishing scheme that resulted in net losses after recoveries. City staff said law enforcement and cyber-insurance recoveries returned roughly $434,000 from law enforcement and about $200,000 from cyber insurance, for a combined recovery of approximately $634,000; the city manager characterized the net loss at roughly $585,000 after recoveries and reimbursements reported during the meeting. Staff said the incident exploited weaknesses in practice and communication rather than insider collusion; the auditors said their separate background checks and mapping did not identify city employees as perpetrators.
City Manager Jones said the city "has beefed up considerably our cyber security" and described new layers of email and endpoint protections, annual mandatory training tied to system access, and other bank-level verifications intended to prevent repeat attacks.
Vendors flagged: Men of Intelligence (MOIA/MOIA) and NAACP of Atlanta
As part of expanded analytics, auditors flagged two vendors that tripped multiple red flags during the engagement: the Men of Intelligence Association (appearing in some city files as MOIA or MOI) and a vendor listed as the NAACP of Atlanta. Auditors reported round-dollar, sequential invoices and address matches between the vendor master file and the employee master file as reasons for additional review.
City staff said they have paused renewals with Men of Intelligence while the manager's office conducts a contract-to-payment reconciliation. The city manager told council he has located contracts and extensions accounting for roughly $550,000 in contractual obligations and that accounting records show a total of about $678,000 paid to the organization since 2021; he said he is still working to reconcile an apparent gap of about $178,000 between payments and documented contractual obligations.
Auditors noted an invoice (identified in the audit materials as invoice #4) for $60,000 that lacked supporting detail in the files the auditors received. Council members and staff said additional supporting reports and emails were supplied to the city after the auditors' report; the auditors said they are willing to examine supplemental information and produce follow-up analysis if the council requests it.
Procurement and contract documentation
Council and staff discussed whether services were procured via memorandum of understanding (MOU), request-for-qualifications (RFQ) or formal contract at various points in the vendor relationship. The city attorney said an MOU was located (dated Feb. 2023) and that the city has a standard contract template with indemnification language that was revised in 2022; she also cautioned that state law constrains the city’s ability to accept certain indemnity language from vendors. Staff said some procurement records were scattered across offices and not centralized, and the city manager proposed better centralized recordkeeping and quarterly audit-log reviews.
Accounting, systems and reconciliations
Auditors identified 44 instances where a vendor code was deleted in the city's BS&A accounting software, but they said the deletions were largely a technical or process issue: "what was deleted is the vendor code," the auditor said, and payments still appeared in the check register. Auditors recommended regular review of BS&A access rights and said the city's migration to a cloud version of BS&A has already restricted deletion rights.
Auditors also reported that bank reconciliations were not performed timely during parts of the testing period and that some disbursements could not be reconciled to vendor payment processes, recommending steps to bring reconciliations current and to increase staffing or external assistance to complete them promptly.
Fixed assets and inventory
The forensic team reported roughly $11 million in capital assets that lacked descriptive detail in the fixed-asset ledger; many entries predated the audit scope and had not been adequately described in BS&A. Auditors recommended reevaluation and cleanup; staff said earlier capital-asset inventories and recent contractor work (OHC Advisors) had already reduced that gap.
Separate from capital assets, auditors pointed to an inventory write-down recorded for the year ended June 30, 2021, with an approximate $1.5 million impact to the general fund driven by inconsistent inventory counts. Staff said they plan to engage consultants and a centralized inventory system to correct, modernize and digitize warehouse and inventory controls.
Credit cards, positive pay and bank records
The forensic team said it was initially unable to obtain credit-card transaction data from the issuing bank in a usable format and therefore performed only limited testing; auditors recommended that the city enforce a policy requiring supporting documentation for all corporate Citi card purchases and pursue a meeting with the bank to secure CSV/extractable data. City staff said the bank has since indicated it can provide extractable data and that the city and auditors will meet to pursue deeper testing.
Auditors also flagged lapses in the city's use of the bank's positive-pay fraud-prevention tool. Positive pay depends on the city reviewing exceptions that the bank returns; auditors found instances where bank-flagged exceptions were not reviewed or were granted exceptions prematurely. Staff said the bank will hold payment on positive-pay exceptions until the city approves them and said the city has added additional matching rules to reduce false positives.
Utility accounts and conflict-of-interest issues
As an expanded test, auditors ran address and employee/vendor comparisons against utility account data and identified three residential accounts over $10,000. Two large balances were later attributed by staff to water leaks and pipe breaks and were described as operational issues; the third — an account connected to a property associated with a council member in audit documents — had a balance the forensic report listed at about $13,007.53 as of July 23, 2024 (city staff reported an updated outstanding balance of $15,782.28 as of Sept. 1).
Auditors noted that the existence of a substantial unpaid account at a property linked to a council member "presents a potential, whether actual or perceived, conflict of interest." The city manager described the utility billing program (budget billing/equalization) used for many customers and said the city has not previously exercised the ordinance-authorized automatic lien process for delinquent utility balances. Staff told council they plan to implement an automatic-lien process and related collections protocols in November and to consider collection agency use for rental accounts.
Council action and next steps
During the meeting the council voted on a motion finding that a conflict of interest exists for one council member in connection with related audit findings; the motion was made and seconded and passed by roll call. The council followed municipal ordinance language discussed in the meeting that directs a public servant who is determined to have a conflict to leave the governing body's seat and, for public meetings, to occupy the portion of the room reserved for the public while the matter is considered. (The meeting record shows the council took the formal determination and then proceeded to discuss implementation of audit recommendations.)
The council also passed procedural motions earlier in the meeting to open discussion and to reserve auditor questions until the end of the auditors' presentation so auditors could complete their scope before departing the meeting.
Staff and auditors said they will continue targeted follow-up: the auditors offered to analyze supplementary documentation the city supplies about Men of Intelligence and other vendors; city staff said they will pursue bank meetings to obtain machine-readable credit-card transaction data, implement stronger BS&A access controls and routing, complete reconciliations, implement the automatic utility-lien procedure, centralize procurement records and consider a dedicated internal-audit or continuous-improvement position. The council set a recurring placeholder to receive forensic-audit updates on the first meeting of each month.
Ending
Council members and staff emphasized that the presentation and follow-up are focused on internal controls, transparency and restoring public trust rather than political attack. The auditors and city manager requested that supplemental documents and bank extracts be shared with the audit team for any supplemental analysis the council requests.

