Loading...
HomeMy WebLinkAbout03/23/2026 - Regular Minutes - City Council - Audit CommitteeMayor John Nichols Mayor Pro Tem William Wright City Manager Bryan C. Woods (*ff" CITY OF COLLEGE STATION Home ofTexuAtM1 Univrniry' Councilmembers Mark Smith David White Bob Yancy Melissa Mcllhaney Scott Schafer Minutes CITY COUNCIL AUDIT COMMITTEE IN -PERSON WITH TELECONFERENCE PARTICIPATION Monday, March 23rd, 2026, at 3:00 pm Audit Committee Members Present: John Nichols, Mayor Melissa Mcllhaney, Councilmember Mark Smith, Councilmember Michelle McMillin, Committee Member Danielle Carlson, Committee Member City Staff: Ty Elliott, City Internal Auditor Matthew Ragaglia, Program Auditor Bryan Woods, City Manager Jeff Capps, Deputy City Manager (Left at 3:42 PM.) Jeff Kersten, Assistant City Manager Jennifer Prochazka, Assistant City Manager Leslie Whitten, Assistant City Attorney Mary Ellen Leonard, Finance Director (Left at 4:04 PM.) Michael DeHaven, Assistant Finance Director Anita Dorsey, Controller (Left at 4:04 PM.) Sam Riveria, Chief Information Officer (Left at 4:06 PM.) 1. Call meeting to order and Announce a Ouorum is Present. With a quorum present, the Audit Committee of College Station was called to order by Mayor Nichols at 3:02 pm on March 23, 2026, in the 1938 Executive Conference Room of the City of College Station City Hall. 2. Hear Visitors There were no hear visitors. 3. Agenda Items 3.1 Presentation, discussion, and possible action of minutes for the City Council Audit Committee meeting held on December 15, 2025. MOTION: Upon a motion made by Councilmember Mark Smith and a second by Committee Member Michelle McMillin, the Audit Committee voted five (5) for and zero (0) opposed to approve the December 15, 2025, Audit Committee minutes. The motion carried unanimously. 3.2 Presentation, discussion, and possible action regarding the Annual External Audit and Annual Comprehensive Financial Report (ACFR). John DeBurro of Weaver, the City's external auditing firm, presented the results of the annual audit. The audit resulted in unmodified ("clean") opinions on the financial statements and compliance with Uniform Guidance, with no deficiencies identified in internal control. MOTION: Upon a motion made by Councilmember Melissa Mcllhaney and a second by Councilmember Mark Smith, the Audit Committee voted five (5) for and zero (0) opposed to accept Annual Audit and Annual Comprehensive Financial Report (ACFR). The motion carried unanimously. 3.3 Presentation, discussion, and possible action regarding the Audit of Payroll Superuser Governance & Activity Oversight. Matthew Ragaglia presented the Audit of Payroll Superuser Governance & Activity Oversight, noting that this engagement was a continuation of the 2024 audit of Segregation of Duties within ERP Role - Based Access, which previously identified payroll superuser access as a high risk area. The purpose of this audit was to evaluate the design and effectiveness of controls governing payroll superuser access. The audit team reported that payroll superuser permissions provide unrestricted access to both payroll and certain human resources functions, including the ability to modify payroll records and elements of the employee master file without independent approval. While no instances of fraud, waste, or abuse were identified through testing, the audit demonstrated that the risks identified in the prior audit are not merely theoretical. Specific scenarios reviewed indicated that the existing system design could allow inappropriate transactions to be processed in a manner that would appear legitimate and be difficult to detect due to the volume and nature of payroll activity by staff in payroll operations. Ty Elliott further explained that the underlying cause of this control weakness is the system design established by the vendor. As such, the most efficient and sustainable solution would be for the vendor to redesign the payroll superuser permission to better segregate HR and payroll access, a recommendation with which management concurred during the audit. Ty Elliott also noted that replacing the system may not be a reasonable solution given the significant cost and complexity of implementation, as well as the likelihood that alternative systems may present similar control limitations. Management acknowledged the risks identified and indicated that mitigating controls outside of Tyler Munis may address aspects of the risk. The audit team indicated they will continue to monitor this high - risk area. During discussion, Ty Elliott noted that organizations must balance operational efficiency with the design and implementation of effective internal controls, and that elevated access is often granted to facilitate complex processes. He further stated that it is the role of the Audit Committee to evaluate whether the level of risk is acceptable given the existing control environment and available mitigation strategies. Councilmember Melissa Mcllhaney expressed concern thatt. the level of risk associated with payrdll superuser access exceeds the City's risk tolerance, even if the mitigating controls. described by management are functioning as intended. She requested that the City Manager's Office formally communicate the City's concerns to the vendor and explore potential solutions to address the identified control weakness. MOTION: Upon a motion made by Councilmember Melissa Mcllhaney and a second by Councilmember Mark Smith, the Audit Committee voted five (5) for and zero (0) opposed to accept the Audit of Payroll Superuser Governance & Activity Oversight and direct the City Manager's Officer to contact Tyler Munis to request changes to the payroll superuser permission. The motion carried unanimously. 3.4 Presentation. discussion, and possible action to provide an update on the progress of the Fiscal Year 2026 Audit Plan. Ty Elliott provided an update on the progress of the FY26 Audit Plan, noting the audit team is approximately halfway through the fiscal year and remains on track. He highlighted ongoing development of the ThirdLine continuous risk assessment program, along with the development of an agile auditing approach for more routine audit areas. He also discussed efforts to document evidence of a functioning quality assurance program in alignment with Red Book standards to support a future peer review, noting that draft policies and procedures have been developed and that supporting forms are being created to ensure compliance. Ty Elliott stated that, once the Red Book transition is complete, the team may explore opportunities to incorporate advisory services. Additionally, preliminary survey work has begun for planned audits, including Fleet Management, Cybersecurity Follow -Up, and Segregation of Duties (SoD), and the audit team will complete its annual follow-up on all outstanding audit recommendations. He further informed the Committee that action on the FY27 Audit Plan will occur at the September 21 meeting based on a list of potential audit topics. Committee members acknowledged the progress made and supported the current activities of the audit function, indicating that the audit team should continue with its planned work. Councilmember Melissa Mcllhaney commented that, even prior to the Red Book transition, she has been impressed with the volume and thoroughness of the audit team's work given its current staffing levels. 4. Discussion and possible action on future agenda items. There were no future agenda items discussed. 5. Adjourn. There being no further business, the Mayor adjourned the meeting1 pm on Monday, March 23, 2026. Nichols, Mayor ATTEST: Kimberly A. Dick , Records Managent Administrator