Minneapolis City Council — Transcript
Monday, February 23, 2026
MPD Biannual Body Camera Audit Report
MPD Biannual Automated License Plate Reader (ALPR) Audit Report
2026 Enterprisewide Risk Assessment
2026 Audit and Strategic Plan Approval
Report of the City Auditor (Updates)
Votes (5)
Biannual Body Camera Audit Report (MPD)
Dissent: None
Moved by null · Seconded by null
Sedartha Bodil, Director of Internal Audit, presented the findings from the biannual audit of the MPD's body-worn camera program. The audit, covering January 2023 to December 2024, concluded that MPD complied with state regulations but offered three recommendations: establishing a process for independent third-party reviews of assessment reports (like Sock 2/3), further developing and formally approving BWC SOPs, and increasing the password length requirement for the evidence management system (evidence.com) from six to at least eight characters. Discussion touched on the transition to in-house auditing and the importance of annual third-party assessments for continuous improvement.
MPD Biannual Automated License Plate Reader (ALPR) Audit Report
Dissent: None
Moved by null · Seconded by null
Sedartha Bodil presented the biannual audit of MPD's ALPR program, covering January 2023 to December 2024. The audit found MPD compliant with state statute 13.824 sub 6, but offered two recommendations: establishing a process for independent third-party review of vendor assessment reports and further developing/formally approving ALPR SOPs related to data access, retention, and deletion. Vice Chair Singleton inquired about data sharing with other agencies and the use of the 'Flock' system, confirming MPD does not use Flock and that data sharing is reviewed. Chair Payne clarified that ALPR data is deleted after 60 days unless part of an investigation.
2026 Enterprisewide Risk Assessment
Dissent: None
Moved by null · Seconded by null
City Auditor Ryan Timberman presented the 2026 Enterprisewide Risk Assessment, identifying four critical areas: budgetary risks (exacerbated by Operation Metro Surge), federal operations and safety, contract oversight, and city culture and trust. He outlined progress on 2025 risks, including increased audit staffing and efforts towards Enterprise Risk Management (ERM). The report's key recommendation was to strengthen the city's ERM posture, suggesting dedicated staff, a risk committee, and adoption of internal control standards. Discussion with Chair Payne and Member Hoseb emphasized the foundational importance of ERM to mitigate broader city challenges and the need for better integration between the administration and city council on governance.
2026 Audit and Strategic Plan for Approval
Dissent: None
Moved by Member Hoseb [1:03:02] · Seconded by Member Williams [1:03:04]
City Auditor Ryan Timberman presented the 2026 Audit and Strategic Plan, highlighting its separation from the risk assessment, updated mission/vision/values, and a 50% resource utilization rate due to new staff. The audit plan includes recurring audits (e.g., BWC), in-progress reviews (e.g., after-action reviews for specific incidents), and new audits focusing on programs like Behavioral Crisis Response and Meet Minneapolis. The strategic plan emphasized organizational right-sizing, strengthening auditor resources, upholding professional standards (including a peer review by ALGA), enhancing independence (seeking subpoena authority), and advancing non-audit projects like a workforce optimization study. The committee moved to approve the plan.
Report of the City Auditor (Auditor Updates)
Dissent: None
Moved by null · Seconded by null
The City Auditor's office provided updates, including two open fraud, waste, and abuse investigations and a status report on prior audit issues. It was noted that 24 audit issues are overdue, with follow-up on several MPD and NCR issues impacted by Operation Metro Surge. Two issues were closed: one related to the 2022 hiring/promotion process and another to 2023 revenue/collection. Personnel updates included new hires Jessica Peterson (Quality Assurance and Training Manager), Myra Hegley (Internal Auditor II), and Stephen Kofa (Auditor I), bringing the office to 14 funded FTEs. Additional funding for the after-action reviews contractor will be sought. Member Hosman requested more detailed updates on overdue issues to facilitate committee assistance.
Notable Quotes (19)
overall conclusion we determined that MPD complied with state regulations related to body one camera use. However, although MPD complied with legal requirements, we developed three recommendations to help MPD further align with best practices that we'll cover on the following slides.
So the first observation is related to independent third party assessment report. uh MPD should establish a process for independent third party review as uh of assessment reports. So when we're talking about the assessment reports uh specifically we're talking about the sock 2 and sock 3 reports.
So the third um observe um basin and recommendation is related to the password configuration requirements. So when we looked at the Exxon uh system u the evidence.com um the right now the application is configured to require a minimum six um characters length but based on the uh best um industry practices it's required to have at least eight characters long and we when we reviewed the the system we have the ability to set that to at least 10 uh So it's a quick fix as well. Uh so we're recommending to increase that length from six to at least eight.
So Minnesota state statute required law enforcement agencies that use ALPR to arrange an independent binial audit to determine whether state statute requirements are met. So as a result MPD engaged the independent office of city auditor to perform this audit which was designed to ensure the highest standards of transparency and data integrity.
So the conclusion is that we determined that MPD complied with state regulation uh related to ALPR use uh although um they complied with the legal requirements we developed two recommendations that we'll cover in the upcoming slides.
is um license plate reader data shared with other agencies um both locally and federally and and I guess preliminarily was that within the scope of this audit? >> Uh yes. So basically there so there are certain requirements that we need to meet if that happens but yeah we do review those portions as well
So for ALPR so it's unless it's a part of any investigation. So all the data is deleted after 60 days. Okay. >> So we retain up to 60 days after that it's deleted
We decided to focus on four key risks that we heard throughout our conversations. We receive feedback throughout our surveys. Uh the first being budgetary risks. There are significant financial risks to the city. Um that will impact service delivery. It will impact surf service levels. Uh it will impact the cost of borrowing and it will impact property tax obligations of residents and businesses.
these significant and unplanned financial impacts have uh been quite noticeable in our city. Uh the city council recently reallocated $1.5 million to urgent needs including immigration legal services and rental assistance. I want to point out that we finished this report and this presentation prior to the council's last uh cycle where they invested even more funds to help the residents of Minneapolis.
The biggest recommendation to come from our office on this risk assessment is that the city should um bolster its risk management posture. Enterprise risk management can help in all of the things that we've discussed.
we constantly get in the way of each other when it comes to that separation of power. And I think that it's not just that the admin needs to set up a committee. I mean I I'm kind of maybe meandering a little bit here, but just to say we already have the permanent review committee as a governance body. Uh there's the policy review group as a separate body that's discussed in the policy framework. Is the recommendation to consolidate those under one oversight and governance committee? That's question one. And then question two is I think that that wouldn't go far enough just for the administration to have that consolidated single point of reference. I think there needs to be an integration and alignment with the city council. And I'm just wondering how how you think about that.
I just don't want the administration and others to lose track of that because I think a lot of those things that we've been seeing even before Operation Metro Surge are just going to continued to get amplified, which is what you've covered here beautifully. And had we had that, so much of these other pieces would have, I think, really fallen into place a lot easier.
We separated out the enterprisewide risk assessment because we want that to be a document that leaders can use in their decision-m. But we also want the audit plan to be a document that you as the audit committee can use, the city council can use, and other leaders can use to know what's coming up this year.
This is the first year that we've looked at or considered resource utilization. Um it is standard in many government audit shops to uh calculate based on a 70% uh resource utilization rate. which means that of your auditors you uh start with the assumption that 70% of the 280 hours is auditable hours. Um this year because of some of the strategic priorities that we have because half of our staff is new within the last three months and we have two more staff that we will be bringing on in the coming three months. Um that we've developed this calculation based on a 50% utilization rate.
With the city council's investment in the office of city auditor, we committed to developing a program evaluation uh process or or report that is similar to what the office of the legislative auditor at the state level has. These will be deeper dives into programs, units uh or functions within the city. They will act as uh half educational report for the audit committee in the city council and half uh audit report where there are recommendations associated with each program.
Uh I do think that uh just in the year that I've been here there has been some real acknowledgment that um the audit function was asked to step up. The audit function in 2021 was asked to become more visible. um and voters through the the charter change in 2021 um built the office of city auditor and created the city auditor position. And so over the last year and over the next year uh we will continue to try to elevate the function of the office of city auditor.
So right now we have uh two open investigations that we're working on right now. And regarding some of the prior audit issues, uh we have right now seven open audit issues which is so there's still not been remediated and the tentative um completion date has not been expired.
if we could either via the meeting or otherwise just get a more um list by list update of some of those um that would be really helpful either at the um April meeting or after that just cuz several of these are still kind of in that bucket of 2019 and you know kind of some some older ones that I think would be helpful just to get more of a insight and then once again how can we as the committee help move those forward as well.
The vacancies that we currently have are the director of special review and advisory services. So this was budgeted but we had to go back to the city council because of the um of the specific classification of this position. So the council just I believe last week approved that. So, it should be getting posted within the next week or two.
Ordinances & Resolutions (14)
State statute requiring law enforcement agencies using body worn cameras to arrange for an independent biennial audit.
System housing body worn camera footages; subject to password configuration review.
Assessment reports on the effectiveness of controls related to security and data integrity, recommended for third-party review.
Government-tailored assessment process similar to Sock 2 for federal, state, and local government vendors.
Tool used in the body worn camera activation review SOP.
Tool used in the body worn camera activation review SOP.
State statute requiring law enforcement agencies using ALPR to arrange for an independent biennial audit.
System used for housing ALPR data.
Report from the emergency operations department detailing costs of federal actions to the community.
US Government Accountability Office (GAO) standards of internal control, recommended for city adoption.
Document that now incorporates using the Green Book as criteria for audits.
Will be recommended for revisions to further clarify auditor independence and align with professional standards.
Strengthened in December last year, referenced in discussion about city's response to federal activities.
Vendor collaborating on the workforce optimization and comparative benchmarking study.