Minneapolis City Council — Transcript

Monday, August 24, 2026

Story

City Audit Uncovers Gaps in Software Inventory and Access Management

Story

ShotSpotter Performance Questioned in City Audit Report

2025 State Auditor Management and Compliance Reports

Camera Data Best Practices Advisory Report

Audit Request for Minneapolis Public Housing Authority

City Auditor's Report & Office Independence

Votes (5)

2025 State of Minnesota Office of the State Auditor Management and Compliance Reports

Received and Filed

Karen Stacken presented the annual audit findings. The City of Minneapolis received an unmodified opinion on its financial statements and major federal programs but had four findings for the year ended December 31, 2025: one related to internal control (service organization controls/SOC1 report for the convention center), two for federal program reporting compliance (CDBG), and one for legal compliance (prompt payment of invoices). Three prior year findings for the city were resolved. No findings were reported for the Minneapolis Park Board or the Municipal Building Commission. Discussion focused on the recurring SOC1 finding, the reasons for CDBG reporting delays, and the criteria for the city to regain low-risk audit status.

Software Inventory and Access Audit

Approved

Moved by Unknown [00:51] · Seconded by Unknown [00:51]

Director Sedartha Pujal presented the findings of an audit into the IT department's software and system inventory and access management. The audit identified an incomplete centralized software inventory and a lack of periodic review for Service Now user access. Management acknowledged the findings and committed to corrective actions, including requesting software usage information from departments, documenting software management procedures, and conducting annual reviews of Service Now accounts. Discussion included challenges in tracking web-based or free software and the city's efforts to enhance vendor security assessments through initiatives like GovRAMP and updated RFP requirements for SOC2 reports.

Shotswatter Performance Audit Report

Approved

Moved by Unknown [01:29] · Seconded by Unknown [01:29]

Director Michael Kwaters presented the audit on Shot Spotter, concluding that the city lacks independent mechanisms to verify the system's accuracy or its effectiveness in improving public safety. The report noted the city's reliance on vendor reports for oversight and challenges in data analysis due to sensor placement crossing neighborhood boundaries. Recommendations included independent validation of vendor data, improved documentation of oversight practices, and maintaining a complete list of sensor locations. Committee members, including the Chair, expressed significant skepticism regarding the technology's value and the high bar for future contract renewal, citing concerns about community perception and the lack of clear strategic impact.

Camera Data Best Practices Advisory Report

Approved

Moved by Unknown [01:46] · Seconded by Unknown [01:46]

Director Michael Kwaters presented an advisory report on camera-based surveillance technology data security practices. Findings included varying contract provisions, inconsistent departmental policies, and an outdated city records management policy (last updated in 2002). The report also highlighted inconsistent training for data and records liaisons and urged leveraging the Information Governance Policy Committee. Recommendations focus on standardizing contract terms, updating policies to reflect modern technology and legal requirements, and improving training and engagement of city resources to ensure comprehensive data security.

Receiving a request from the city council to undertake an independent audit of the Minneapolis public housing authorities use of city funds

5-0 Approved

Moved by Chair Payne [01:48] · Seconded by Member Peterson [01:48]

City Auditor Robert Timberman confirmed the office's willingness to perform an independent audit of the Minneapolis Public Housing Authority's (MPHA) use of city funds, as requested by the City Council. He suggested that the audit be targeted for inclusion in the 2027 audit plan due to current workload. The committee voted to accept the request.

Notable Quotes (17)

Our opinions are included in the respective entities's annual financial report and our opinions for the city and the park board were unmodified which means it's a clean opinion and it's the best opinion that can be issued. This means the financial statements are fairly presented and conform with applicable accounting standards.

Audit Director Stacken (Office of the State Auditor) [00:08]
2025 State of Minnesota Office of the State Auditor Management and Compliance Reports

I have just few questions regarding the recurring SOC1 finding. For example, this is a second year of the state auditor has reported the lack of SOC1 type two or SOC1 report for the convention center service organization. What specifically prevented the city from resolving the finding during 2025 and at what point would the city consider replacing the vendor if it cannot provide COC one report?

Member Al Mwafak [00:10]
2025 State of Minnesota Office of the State Auditor Management and Compliance Reports

I think in some of these cases um there is action that has to be taken by the federal agency first and then once the federal agency takes action then you can go in and do the reporting and so I think what happened is that it got updated at the federal agency but the federal agency doesn't always notify the local agency that it's updated and ready and I think they had been checking back um but not as frequently as needed to be to be for the report to be done in that time.

Audit Director Stacken (Office of the State Auditor) [00:12]
2025 State of Minnesota Office of the State Auditor Management and Compliance Reports

Because accurate system inventories and effective access management are foundational controls that help city safeguard data, manage technology risks and ensure consistent IT governance all across departments.

Director Pujal (Internal Audit) [00:25]
Software Inventory and Access Audit

We observed that the city's centralized software systems inventory is incomplete and does not fully capture all the soft software and systems related to information used across departments.

Director Pujal (Internal Audit) [00:32]
Software Inventory and Access Audit

I think the probably the bigger challenges we have and this gets at the self-reporting nature of it um is uh web-based software or there are also tools that people can download and install uh that do not require uh elevated access on the computer and and so if it's free software of that nature, it's very difficult for us through uh the normal sort of monitoring of what's happening on the computer to be able to uh understand what that is.

CIO Cameron (Chief Information Officer) [00:40]
Software Inventory and Access Audit

To answer your question we are moving forward with um contracting with Govramp. Uh that's moving forward in uh the next council cycle or two. So um that will afford some additional protections. In addition uh as as CIO Cameron had uh specified, we have enhanced our RFP process to include requirements for uh the sock 2 type 2 be part of that RFP. So captured as part of the contract.

Director Arco (IT Vendor Management and Contract Services) [00:43]
Software Inventory and Access Audit

Minneapolis continues to rely on Shot Spotter alerts for police and emergency response. Yet, the city lacks independent mechanisms to verify the accuracy of those alerts, evaluate whether they meaningfully improve public safety, or ensure that their use aligns with city policies and community expectations.

City Auditor Timberman [00:53]
Shotswatter Performance Audit Report

The reason why I want to highlight this is because those locations are data driven uh approximately based on volume. Uh and that means that they do not align with the neighborhood. That means it crosses through communities uh which is of course significant when you're trying to compare data because there isn't a clean comparison even within the community itself.

Director Kwaters (Special Reviews and Advisory Services) [00:59]
Shotswatter Performance Audit Report

What I am commenting on is uh we didn't see independent effort by the city for validating that information.

Director Kwaters (Special Reviews and Advisory Services) [01:05]
Shotswatter Performance Audit Report

Something that really strikes me is is this conversation about not knowing where all the sensors are. That scares me. um that that here at the city we don't know where all of the shot spotter sensors are, but we're making the argument that the sky will fall without Shot Spotter. That seems really inconsistent to me.

Member Chug Tai [01:16]
Shotswatter Performance Audit Report

I'm not seeing a reason to renew that contract with what we see in front of us today. Um we see some recommendations on how we might be able to independently verify the um efficacy of this technology for the the stated safety goals. Um it's going to be a really high bar to clear for me to actually see how management responds to uh identifying that independent uh performance of this of this technology.

Chair Payne [01:29]
Shotswatter Performance Audit Report

While Minneapolis does not use certain private systems that have raised regional concerns, such as Flax Safety's license plate reader systems, the public's reaction to those systems and more recently to questions about federal access during Operation Metro Surge underscores a growing community expectation. Surveillance technologies must operate within clear, consistent, and transparent safeguards.

City Auditor Timberman [00:55]
Camera Data Best Practices Advisory Report

The audit states that the auditor office requested but was unable to obtain a comprehensive list of data sharing agreement or MO use with federal law enforcement agencies. Does such a comprehensive inver inventory currently exist? If not, how can the city be confident that surveillance data is not being shared outside established authorization and oversight processes?

Member Al Mwafak [01:34]
Camera Data Best Practices Advisory Report

It is a policy that we did not assess whether or not it it is sufficient. We comment that it was less updated in 2002 and there have been changes in the technology landscape since then.

Director Kwaters (Special Reviews and Advisory Services) [01:38]
Camera Data Best Practices Advisory Report

It feels to me that, you know, a a a records management policy from 2002 there's certainly is not going to reflect the current technology climate. Um it seems that we should have a similar um refresh on how we think about these technologies at least from that kind of maybe maybe that overly simplified three-part framework is not sufficient but something that tries to capture um a comprehensive a policy approach to these technologies because I I feel like that's a big gap here.

Chair Payne [01:44]
Camera Data Best Practices Advisory Report

Chair Payne, I really don't have much to say other than I would request that the audit committee uh move forward with this request to our office. We are willing to take on this work. I would however ask that we target 2027 and we build it into our audit plan in 2027.

City Auditor Timberman [01:47]
Receiving a request from the city council to undertake an independent audit of the Minneapolis public housing authorities use of city funds

Ordinances & Resolutions (21)

2025 State of Minnesota Office of the State Auditor Management and Compliance ReportsOther

Annual audit results for city entities.

Uniform GuidanceOther

Federal requirements related to federal programs, adhered to during audits.

SOC1 Type 2 ReportOther

Service organization controls report, a recurring audit finding for the convention center vendor.

CDBG ProgramOther

Community Development Block Grant program, subject of federal program reporting findings.

FFATAOther

Federal Funding Accountability and Transparency Act, related to CDBG subaward reporting.

Software Inventory and Access Audit ReportOther

Audit of the IT department's software and system inventory and access management.

Service NowOther

Primary system audited for access management and system of record for inventory.

SOC2 Type 2 ReportsOther

Security reports for third-party software, increasingly required in RFP processes.

GovRAMPOther

Government-focused security assessment framework for cloud products, being contracted by the city.

Shot Spotter Performance Audit ReportOther

Audit of the city's acoustic gunshot detection system.

MSTEP MeetingsOther

Public safety leadership meetings where Shot Spotter data is presented for strategy.

Camera Data Best Practices Advisory ReportOther

Advisory report on data security practices for camera-based surveillance technologies.

Information Security PolicyOther

IT directive (Section 11) detailing security for city data.

MPD's Policies and Procedure ManualOther

Departmental manual with specificity related to various requirements.

Section 1305 of the Minnesota StatutesOther

Minnesota Government Data Practices Statutes, compliance recommended across the enterprise.

City records management policyPolicy

Last revised in 2002, cited as outdated given technological changes.

BWC (Body Worn Cameras)Other

Previously reported technology, scoped out of the camera data advisory report.

ALPRs (Automatic License Plate Readers)Other

Previously reported technology, scoped out of the camera data advisory report.

Flex Safety's license plate reader systemsOther

Private system mentioned for raising regional concerns, not used by Minneapolis.

Minneapolis Public Housing Authorities (MPHA) audit requestOther

Request from City Council for an independent audit of MPHA's use of city funds.

Audit CharterOther

Updated in December of last year to strengthen the committee's ability to move items to City Council.

View Source
Minneapolis City Council - Hennepin County Recorder