Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Online Banking Policy topic

No spam. Unsubscribe anytime.

Audit committee debates online banking policy, cites vendor-setup and fraud controls

Port Washington Union Free School District Audit Committee · June 17, 2026
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

The Port Washington audit committee reviewed a draft online banking policy and agreed to a short, global policy with detailed procedures in regulations; members pressed for stronger vendor-setup controls, dual approvals, and multi-factor authentication to reduce invoice/BI fraud risks.

The Port Washington Union Free School District audit committee reviewed a draft online banking policy intended to address corrective-action findings and to formalize online payment practices the district already uses. Committee members and staff said the document should be high-level policy language with detailed procedures captured in regulations that define vendor-setup, template controls, approval chains and monitoring.

Discussion focused on which online activities the policy must cover. Committee members confirmed the draft should address internal transfers, investments, payroll, vendor payments and both ACH and wire transfers. Several members noted the district has performed online payments without a formal policy and urged explicit language about who can set up vendor banking instructions and how changes to templates are verified.

Speakers described recent vendor-fraud scenarios in which attackers compromise email accounts and alter banking instructions on otherwise legitimate invoices. Members recommended multi-step verification for any vendor-bank-account changes—examples included a verified phone call to a known contact, requiring vendors to complete and sign a physical form in person, or otherwise using procedures that cannot rely solely on emailed requests.

Committee members emphasized dual controls: separating the person who establishes vendor templates from the person who initiates payments, requiring secondary approvals for external transfers, and involving accounts payable and the internal claims auditor in verification. The committee discussed placing general delegation language in the policy (for example, delegating procedure development to the assistant superintendent for business with assistance from the treasurer) and reserving technical details—including daily or per-transaction limits, positive-pay bank services, and multifactor authentication—for regulations.

Staff and auditors agreed to draft a more global policy statement committing the district to dual controls and regular review, and to produce detailed regulations and sample templates (auditors offered templates) for the committee and policy committee to review. Committee members suggested the regulations require monthly (or more frequent) monitoring by the internal claims auditor and clear documentation (W-9s, POs, invoice–PO matching) for vendor setup and changes.

The committee did not adopt the policy at the meeting; members asked staff and auditors to return with a draft policy and corresponding regulations for circulation or board consideration before the fall board meeting.

Next steps: auditors and district staff will prepare a concise policy and a companion regulation that details vendor verification steps, template controls, and authentication standards for online banking.