Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Audits Criminal Justice Data topic
No spam. Unsubscribe anytime.
County auditor finds gaps in Criminal Justice Services’ data entry and access controls; agency agrees to most recommendations
Summary
An audit of Criminal Justice Services (CJS) found inconsistent case‑management data entry for drug testing, gaps in access‑termination procedures and uneven application access revocation. CJS agreed to most recommendations; the auditor assigned a significant risk rating for case‑management entry issues and plans a follow‑up audit.
Get email alerts on the Audits Criminal Justice Data topic
No spam. Unsubscribe anytime.
The Salt Lake County Auditor’s Office presented an audit of Criminal Justice Services’ (CJS) data access and protections covering calendar year 2023 and identified several opportunities to improve controls, data consistency and access termination procedures.
Auditors said their objectives were to review internal controls, compliance with applicable policies and procedures, and protections of confidential client data. The audit team, led by County Auditor Chris Harding with auditors Tammy Brake, Anthony Cornelius, Brenda Nelson and Shauna Alborn, reported the agency agreed to 10 of 12 recommendations and would update policies and monitoring practices.
A central finding concerned data entry in the agency’s case‑management system (e‑supervision). Auditors tested a sample of 45 client drug‑testing dates and found only 6 were correctly and completely recorded in e‑supervision; 21 of 45 had no data entered and 18 of 45 had incomplete or nonspecific entries. Auditors assigned that finding a “significant” risk rating because inconsistent or missing entries reduce reasonable assurance that internal controls comply with policy. CJS management agreed that its policy needed revision to reflect current practice and that monitoring should improve; it disagreed with the auditors’ risk ranking.
Auditors also examined processes for removing network and application access when CJS employees leave. In 2023 the agency had 21 separations: auditors found three employees had no formal request submitted to remove network access (IT ultimately revoked accounts after a weekly off‑boarding report), and they found examples of untimely or missing removals for three county applications used by CJS. The auditors noted mitigating activities: Utah Web Infrastructure for Treatment Services (UWITS) automatically locked an inactive account after 40 days, and the sheriff’s office conducted an offender management system (OMS) user review in late 2023 and removed former CJS accounts as appropriate.
Recommendations included clarifying and documenting responsibilities and timing for access removal (CJS later set a 5‑business‑day target and records retention for five years), updating case‑note policy to standardize how drug tests are recorded, expanding quality‑assurance reviews, and adding annual trainings. CJS committed to policy updates, clarifying responsibilities and improving monitoring and training.
Auditors said they would follow up on implementation no earlier than six months after the report’s issuance. Council members asked clarifying questions; auditors reiterated the importance of clear, auditable policies and consistent data entry to support oversight and service delivery.
No formal council action was taken at the briefing; the audit will remain posted to the auditor’s website and the auditor’s office will issue a follow‑up report on implementation progress.
