Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Municipal Finance Audit topic
No spam. Unsubscribe anytime.
Audit gives Spring Hill a clean opinion but flags material internal-control and cybersecurity gaps
Summary
Auditors delivered an unmodified opinion on Spring Hill's FY2025 financial statements but reported a material weakness in the financial close and internal-control processes, a material internal-control weakness tied to a federal SAFER grant, and a compliance finding for the city's missing/undocumented cybersecurity plan; management accepted corrected adjustments.
Get email alerts on the Municipal Finance Audit topic
No spam. Unsubscribe anytime.
Auditors told the Spring Hill Budget & Finance Committee on May 4 that they issued an unmodified (clean) opinion on the city's FY2025 financial statements but identified several significant control problems that require attention.
"The audit opinion is an unmodified opinion ... That's the best possible opinion that we can provide," the lead auditor said, noting an "emphasis of matter" for a change in accounting policy — the implementation of GASB 101 on compensated absences — that required restatement of prior-year balances. The auditor also said the internal-control report included a material weakness (finding 2025.001) in the financial close and reporting process and a separate material internal-control weakness (finding 2025.002) related to a tested federal program (the SAFER grant). The audit included an additional compliance finding (2025.003) tied to the state comptroller's audit manual and Tennessee legislation requiring a documented cybersecurity plan.
The auditor explained that the material weakness reflected a collection of problems in the financial-close process that, taken together, could cause the financial statements to be materially misstated if not corrected. "Without the proper internal controls in place the financial statements would have likely been materially misstated," the auditor said. Committee members pressed for scale; one member said, "we're not talking about small numbers ... We're talking about 3,000,000 worth of numbers within either overstated or understated," and the auditor confirmed the firm worked with city staff and that adjustments were recorded and accepted by management.
On the federal program finding, auditors said the city's staff had identified a miscalculation in overtime charged to the SAFER grant, recalculated the amounts with FEMA and reached a resolution, but that an internal-control failure had occurred before the audit procedures. The auditor emphasized that the test work performed showed no noncompliance for the samples tested, but internal-control weaknesses required reporting.
Committee members also questioned the cybersecurity finding. The auditor said Tennessee's comptroller required an official cybersecurity plan and a biennial update; the firm was unable to determine that a properly documented plan had been updated and produced for the auditors. City staff responded that a cybersecurity policy exists but could not be produced because it is held by their third-party vendor, VC3. "There is a cybersecurity policy in place. It's just one that we couldn't produce because of our partnership with VC3," a staff member said, and committee members asked staff to evaluate that vendor relationship and to ensure a producible plan for auditors and the comptroller.
Auditors recommended targeted steps: additional staff training on the financial-close and reporting process, implementation of review and approval procedures for reconciliations and closing entries, clearer interim procedures and calendaring to improve timeliness, and remediation of grant-management internal controls. The audit report also listed corrected misstatements that management accepted and noted that there were no disagreements with management over accounting treatment.
The committee directed staff and the auditors to continue follow-up and to present timelines and milestones for the next audit engagement. The auditors said they will share interim calendaring and improved engagement milestones to help avoid the delays encountered this year.
