Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Financial Controls topic

No spam. Unsubscribe anytime.

Council audit flags accounts‑payable control weaknesses, duplicate payments and excessive user access

5020107 · June 17, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

An accounts‑payable audit found generally accurate vendor payments but identified weaknesses in policies, excessive user access, duplicate payments of about $3.8 million later identified, and thousands of user accounts that should have been deactivated.

Bridal Parks of the Council Auditor’s Office presented an accounts‑payable audit to the Finance Committee on June 17 that concluded payments to vendors were “overall accurate in amount and properly supported,” but that significant control weaknesses and process deficiencies exist and require correction.

The audit examined invoices and payments from Oct. 1, 2023, through Jan. 31, 2024, and tested 200 randomly selected invoices (100 PO and 100 non‑PO). Parks said the scope excluded wire transfers and payments approved outside of the accounts‑payable module, which are planned for future review in the city’s new financial system environment.

Key findings included: incomplete or outdated written policies for critical AP processes; excessive system access rights (for example, four treasury employees had an invoice‑supervisor role enabling create/edit/delete/validate actions not in their job descriptions, and four non‑accounting staff had invoice approval roles); 241 user accounts in the financial system belonged to former employees or to accounts set up for hires who never started and had not been deactivated as of Sept. 9, 2024; changes to supplier bank account information were made by accounting staff who create payment files; duplicate payments totaling over $3.8 million were processed and later identified by the city; and supplier account duplication and invoices not linked to POs were observed, increasing procurement and payment risks.

Parks said the audit team performed analytical procedures to detect potential duplicate payments, fictitious vendors and timeliness issues. The auditors reported that departments had created “cover letters” that functioned as invoices, defeating internal controls, and that bank reconciliations, credit‑memo processing and refund procedures had weaknesses.

The auditors said departments and finance staff were updating policies as auditors asked questions during the review, but that the absence of documented controls before testing remained a problem. The audit recommends tightening user roles, instituting supplier account controls (including IRS tax‑ID matching), improving invoice templates and linkages to purchase orders and addressing duplicate supplier accounts.

No vote was taken on the audit presentation. Parks said the auditors will follow up after the city implements controls and that unresolved items will be subject to additional reviews.