Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Data Governance topic
No spam. Unsubscribe anytime.
Milwaukee County audit office says data governance recommendations closed after follow-up
Summary
Comptroller auditors told the County Committee on Audit that final follow-up on a May 2023 data governance audit has closed all recommendations after IMSD provided contract guidance and procurement information.
Get email alerts on the Data Governance topic
No spam. Unsubscribe anytime.
Jennifer Folliard, Comptroller’s director of audits, told the Milwaukee County Committee on Audit on March 3 that the office’s final follow-up on a May 2023 data governance audit has closed all outstanding recommendations.
Folliard said the original audit found Milwaukee County’s data governance was an “emerging discipline,” that the county lacked a formal documented enterprise data governance program at the time of the audit and that there were gaps in contract guidance beyond IMSD’s internal templates. “This is our third follow-up. … we have closed all of our recommendations,” she said during the meeting.
The audit team described data governance using the U.S. Government Accountability Office definition as a framework to make data assets transparent, accessible and of sufficient quality to support government operations and public information. The auditors noted typical data governance implementation timelines of two to four years and that maturity models are used to measure progress. The Comptroller’s Office had issued six core recommendations to address program structure, documentation and cross-departmental contracting guidance.
Jackie Bobo, Chief Information Officer for Milwaukee County’s Information Management Services Division (IMSD), described how IMSD’s Architectural Review Committee (ARC) operates and how contract terms are reviewed. “Our architectural review committee actually consists of our entire IT management staff,” Bobo said, listing directors, deputy CIO and architects who participate in weekly ARC sessions. Bobo said IMSD evaluates security and vendor documentation on a per-application basis — for example, SOC 2 or SOC 3 requirements depend on whether software is hosted on county servers or provided as software-as-a-service — and that IMSD reviews those standards annually as part of contract renewals.
Folliard said the three recommendations that remained open at prior follow-ups related to contract guidance were addressed when IMSD published contract materials and met with procurement to share information. She told the committee the office will not return on this particular audit unless new issues arise.
The item was presented as informational only; no committee action or vote was recorded.
The committee had no public comments on the item and accepted the informational report.
