Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Fleet It Audit topic
No spam. Unsubscribe anytime.
Knox County audit committee: fleet GPS gaps, missing accident records and sheriff IT inventory shortfalls identified
Summary
Internal auditors told the Knox County Audit Committee they found noncompliance and record gaps in the county fleet program (take-home vehicle rules, GPS coverage and accident documentation) and incomplete inventory records, vendor-tracking errors and improper hard-drive disposal at the sheriff’s office; management has concurred and auditors will follow up.
Get email alerts on the Fleet It Audit topic
No spam. Unsubscribe anytime.
Auditors presenting to the Knox County Audit Committee on June 20 identified several operational gaps in the county’s fleet program and the Knox County Sheriff’s Office (KCSO) IT inventory that they say expose the county to administrative and data-security risk.
Richard Pew, an internal auditor, reviewed the finalized fleet management audit and said auditors tested four major areas — take-home vehicles, accident response documentation, vehicle maintenance and driver safety/eligibility — and found meaningful exceptions despite generally effective controls. "We tested 38 drivers from that list, and found that only 10 were meeting that threshold," Pew said of a 500-mile-per-month take-home driver criterion noted in the fleet safety manual. Pew also reported that some county vehicles were not equipped with GPS devices despite a GPS acknowledgement in the manual, and that many elected offices had effectively 'opted out' of the GPS program. He recommended either enforcing the existing criteria or updating county policy to match current practice, along with a formal application and cost-analysis routed to risk management, payroll and the fleet service center.
On accident documentation, Pew said auditors found 12 missing pieces of required documentation across their sample of 38 accidents, most often scene photographs and supervisor investigation reports. "Mainly photos from the vehicle scene," Pew said when summarizing what was missing. He urged follow-up with departments to ensure required records are captured and retained.
Pew also described recordkeeping mismatches: payroll and the fleet service center maintained inconsistent lists of take-home drivers, raising the risk that fringe benefits might not be treated consistently. On preventative maintenance, auditors found most maintenance was timely but identified some past-due inspections and recommended stronger enforcement and clearer rules in code.
The committee heard a separate, related audit of the Knox County Sheriff’s Office IT inventory. Pew said the IT review generally found sufficient control environments but flagged three main issues: incomplete IT records when employees did not log devices into automated tracking systems, inaccuracies in a ThermoCopy vendor spreadsheet that tracks printers, and an instance of improper hard-drive disposal. "There were some devices that probably should have been surplus," Pew said, noting that older or idle devices can fall out of automated tracking.
Pew said auditors sampled 24 employees and identified six laptops not present in the endpoint or MAS360 tracking systems and noted roughly 20 non-cellular iPads that required better documentation. On hard-drive disposal, auditors found a KCSO staff member had taken surplus hard drives home and drilled them before returning them for surplus — a practice auditors recommended moving in-house to avoid data exposure. KCSO personnel told the committee they plan to acquire equipment (a drill press at an offsite location) and formalize destruction and surplus procedures.
KCSO Captain Aaron Yarnell praised audit staff during the meeting. "That was extremely professional," Yarnell said of the audit team’s work, commending their responsiveness and thoroughness.
Auditors and management told the committee they have begun or completed many of the recommended changes, including adding GPS to most vehicles and improving interdepartmental communication; the auditors plan to follow up within a year and perform retesting where warranted.
The audit committee did not take formal enforcement action at the meeting; members asked for documented responses and for the internal audit office to track remediation status and return for follow-up testing on significant items.
The audits as presented stressed risk mitigation through clearer written policy, stronger record reconciliation across systems and implementation of internal controls to prevent data loss or incomplete records.

