Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Fraud Risk topic
No spam. Unsubscribe anytime.
Mantua council adopts strengthened fraud-risk assessment and internal controls, including AI restrictions
Summary
Council unanimously adopted the FY2026 Fraud Risk Assessment and five updated internal-control policies that raise the town’s projected score into the 'Very Low Risk' tier and add an AI section prohibiting ingestion of confidential or personally identifiable information into external AI tools.
Get email alerts on the Fraud Risk topic
No spam. Unsubscribe anytime.
The Town of Mantua Council unanimously approved a revised Fraud Risk Assessment for FY2026 and five updated internal-control policies at its June 18 meeting.
Finance Manager Ronald Wallace summarized the assessment, saying the town’s projected score rose from a baseline of 305 to an estimated 330–335, placing Mantua within the State Auditor’s 'Very Low Risk' band (316–355). Wallace told councilors the State Auditor’s Office now expects fully adopted, written policies that match assessment claims; the emphasis is on documented execution of controls such as segregation of duties and reconciliations.
The council then adopted five standalone policies to align with those expectations. Key policy changes include:
• Cash Receipt and Deposit Policy: prohibits a single employee from receiving, recording and reconciling public funds.
• Financial Clerk / Office Procedures: requires written transaction and approval standards for town office operations.
• IT/Internet/Acceptable Use and Security Policy: formalizes network and email protocols, data classification standards, and restricts software installation to an approved assets registry.
• Password Policy: replaces fixed 90-day rotations with a risk-based reset model triggered by confirmed compromise or IT directive.
• AI section (new): bars the ingestion of confidential or personally identifiable information into external AI tools and requires a human reviewer to vet all AI outputs before use.
The policies also institute a mandatory User Acknowledgement Form for staff to sign, providing audit evidence of internal control commitments. Council Member Henry Dovey moved to adopt the policies; Council Member Scott Ross seconded, and the motions passed with unanimous yes votes.
Councilors said the documentation will improve the town’s position in state audits and help preserve access to low-risk audit tiers.
