Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Finance Audit topic
No spam. Unsubscribe anytime.
State auditors report $428,000 vendor-payment loss; city staff outline immediate reforms
Summary
The Washington State Auditor's Office reported an accountability finding that inadequate controls over vendor payment changes contributed to a $428,000 loss; city staff said they notified law enforcement and the state auditor, engaged a private accounting firm and implemented supervisory reviews and new fraud-detection software.
Get email alerts on the Finance Audit topic
No spam. Unsubscribe anytime.
The Washington State Auditor's Office presented the City of Mercer Island's fiscal-year 2024 exit conference on Feb. 3, reporting an accountability finding that inadequate internal controls over vendor payment changes contributed to a loss of $428,000 in public funds.
Auditor summary: Kai Nguyen, audit lead, said the accountability audit found that the city lacked a policy requiring sufficient verification when vendor information is changed and did not centralize requests for vendor-payment changes. "We determined that there is inadequate internal controls over the city's vendor payments that contributed to a loss of $428,000 of public funds," Nguyen said.
Scope and opinion: auditors told the council they performed an accountability audit (covering compliance with state law and internal controls) and a financial-statement audit for the same period. The financial-statement audit received an unmodified (clean) opinion; auditors reported no material misstatements in the city's financial statements.
Immediate staff response: City Manager Jesse Vaughn (identified in the packet as Jesse Bond earlier in the evening) and Finance Director Matt Mornick said staff took immediate actions after learning of the incident, including notifying the police and the State Auditor's Office, contacting banking partners, retaining a private accounting firm to perform an internal review of accounts payable procedures, implementing secondary supervisory review for vendor-information changes, deploying fraud-notification software and increasing staff training.
What the auditors recommended: the auditors recommended that the city formalize verification procedures for vendor-information changes, centralize change requests to a single department or position to ensure consistent verification, and ensure staff consistently follow the new process.
Council questions and context: councilmembers asked whether similar phishing and electronic-fund-transfer losses have occurred elsewhere; the auditors said phishing and cyber-enabled vendor-payment fraud have increased statewide. Council also asked about the GAAP paragraph in the report; auditors explained the city prepares statements on a cash basis (regulatory basis) which requires a paragraph about GAAP.
Next steps and publication: the auditors said the audit reports and exit packet will be published on the auditor's website and that the city will receive further information about corrective actions. Finance Director Mornick said the city has been pursuing both criminal recovery and internal controls changes and that the organization had initiated a cultural shift toward stronger safeguards.
Why it matters: while the financial statements as a whole were deemed materially correct, the accountability finding identifies a control weakness that resulted in a significant one-time loss and prompted immediate policy and practice changes. The council requested follow-up material and said staff should keep the public and council informed about recovery efforts and policy implementation.

