Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the City Audit topic
No spam. Unsubscribe anytime.
City controller and external auditors report audit plans and findings, including airport capital-asset adjustments and IT governance concerns
Summary
KPMG and MGO presented the annual audit plan and findings to the committee, reporting an airport capital-asset correction and significant deficiencies related to citywide IT governance and subrecipient monitoring; the airport described corrective steps and the CIO outlined plans to hire a citywide CISO.
Get email alerts on the City Audit topic
No spam. Unsubscribe anytime.
The Government and Oversight Committee received presentations on Sept. 17 from the city controller and external auditors summarizing the Comprehensive Annual Financial Report (CAFR) process, recent audit findings and planned audit work for fiscal 2015.
City Controller Ben Rosenfield said the controller's office compiles the fiscal-year financial statements and that external auditors report directly to the audit committee. KPMG senior manager Jamie Cavan presented KPMG's scope for FY2015 audits (including the San Francisco Health Service System, Muni, the Public Utilities Commission and San Francisco International Airport), the audit timeline and a 2014 finding at the airport involving untimely review of capital-asset records that led management to record approximately $41.4 million of adjustments.
Annie Louie of MGO outlined additional single-audit findings and internal-control concerns: a significant deficiency in information-technology governance (lack of centralized citywide IT policy oversight), subrecipient monitoring and reporting weaknesses for federal workforce and Continuum of Care grants, and procurement controls related to suspension/debarment checks. She noted corrective actions in progress for prior findings (payroll system transitions) and upcoming reporting requirements for pension accounting standards (GASB 67/68).
Wallace Tang, Airport Controller for San Francisco International Airport, described actions taken to address the airport's fixed-asset finding: a multi-year cleanup of the fixed-asset database, adjustments booked in FY13-14, creation of a fixed-asset accounting group, updated policies for construction-in-progress and added staffing to confirm assets and sustain annual reviews. Tang said the airport completed 100% confirmation of fixed assets with net book value in FY15.
City CIO Miguel Camino told the committee the city is close to hiring a citywide Chief Information Security Officer to provide centralized authority for security policy and that an architecture and policy review board under the Committee on Information Technology is functioning to coordinate departmental policies. Committee members asked whether any departments are exempt from the proposed CISO oversight; Camino said no and explained a federated model with department-level responsibilities under a citywide umbrella.
The committee received public comment, had no substantive roll-call votes on audit items, and voted to continue the item to the chair for any follow-up.
Representative quotes: "We provided recommendation to management to continue to perform annual reviews of the fixed assets..." — Jamie Cavan, KPMG "We created and updated new construction in progress policies and procedures...we have the staffing plan when we do the upcoming 2-year budget." — Wallace Tang, SFO "We are getting very, very close [to hiring a citywide CISO]." — Miguel Camino, City CIO
Ending: Presentations concluded and the committee continued Item 2 to the chair for follow-up; the committee later convened a closed session for items 3'17 and returned with unanimous recommendations on those ordinances.
