RecordingTranscript available105:40

February 23, 2026 Audit Committee

Minneapolis City CouncilTuesday, February 24, 2026
Watch on original source

Document Analysis

Analyze the transcript to extract topics, key quotes, people, and more — then generate focused stories for any topic.

Transcript
Welcome to the regular meeting of the audit committee for February 23rd, 2026. I am Elliot Payne and I am the chair of this committee. I want to offer a friendly reminder to all members, staff, and the public that these meetings are broadcast live to enable greater public participation. These broadcasts include real-time captioning as a further method to increase the accessibility of our proceedings to the community. Therefore, all speakers need to be mindful of the rate of their speech so that our captioners can fully capture and transcribe all comments for the broadcast. We ask all speakers to moderate the speed and clarity of their comments. At this time, I will ask the clerk to call the role so that we can verify a quorum for this meeting. >> Committee member Chungai >> present. Angelhart is absent. Hosbine >> present. >> Omar is absent. Williams >> present. >> Vice Chair Singleton >> present. >> Chair Payne >> present. >> There are five members present. >> Let the record reflect that we have a quorum. Colleagues, our agenda is before us. May I have a motion to adopt the agenda? >> So moved. >> Second. >> All those in favor say I. I. Oppose. Say nay. The eyes have it and the agenda is adopted. Next we have the acceptance of minutes from our when was our last meeting. Mr. Clerk, >> we are accepting two pairs of minutes from our December 8th, 2025 and our organizational meeting of January 26th, 2026. >> Excellent. May have may I have that motion? >> So moved. >> Second. >> All those in favor say I. >> I. oppose say nay. Eyes have it and the minutes are accepted. We have one, two, three, four, five uh items in new business today and we will begin with item number three which has to do with our bianual body camera audit report and I will welcome up Mr. Puja. Welcome. Thank you. Good morning, Chair Payne and the members of the audit committee. My name is Sedartha Bodil and I'm the director of internal audit. Uh our office recently completed the state mandated banial audit of the MPD's body warning camera program. This audit ensures MPD follows state requirement on how BWC data are collected, stored, used and deleted. This is the overview of the presentation. uh I'm going to present about the background audit and objectives scope and methodology conclusion and results observations recommendations and the management action plans. Minnesota statute requires law enforcement agencies that use body one cameras to arrange for an independent bial audit to determine whether state statute requirements are met. The MPD engaged the independent office of city auditor to perform this audit which was designed to ensure MPD maintains the highest standards of transparency and data integrity. In the past um we contracted an external uh vendor to perform this audit. However, now with the auditors who have expertise in reviewing the body warn cameras as well as the IT audit, we decided to brought this audit in house. So the objective of this audit um was to assess compliance with regulations and review relevant policies, procedures and secure routine controls as required by Minnesota statute 13.825 um sub um 9. So the review focused on BWC requirements to verify if the BWC data are collected and classified appropriately. Data are retained according to the state statute requirements. The data is shared appropriately with other agencies. their written procedures are in place to govern access to non-public recordings and only issue uh agency issued um BWC are used to document officer activities and that MPD personnel are adhering to BWC policy and procedures. So our scope covered uh related activities from January 1st 2023 to December 31st 2024. As methods uh we met with MPD to gain an understanding of the BWC program. We also requested received and reviewed relevant documentations such as their policy manuals any associated SOPs with it. Additionally, we also obtained direct access to exxon evidence.com which houses all the body one camera footages to perform an independent review of the video and associated data. And the key risk areas at least from uh this audit perspective is the compliance piece which we're trying to make sure they follow the state statute as well as the operational piece where like how their process works. So overall conclusion we determined that MPD complied with state regulations related to body one camera use. However, although MPD complied with legal requirements, we developed three recommendations to help MPD further align with best practices that we'll cover on the following slides. So those three recommendations uh related to MPD should establish a process for independent third party review assessment reports. MPD should further develop and formally approve existing BWC SOPs and MP MPD should update password configuration requirements. [snorts] So the first observation is related to independent third party assessment report. uh MPD should establish a process for independent third party review as uh of assessment reports. So when we're talking about the assessment reports uh specifically we're talking about the sock 2 and sock 3 reports. So the sock 2 reports includes detailed information on the effectiveness of controls related to security of abability process integrity confidentiality and privacy. It intended for those with a deeper understanding of the internal workings of these controls. So this report is made available from Exxon the service provider for review. However, these uh reviews are not currently being performed. So at least I want to um uh let the the audio committ know. So this is like enterprisewide issue. So it's not specific to MPD based on uh the the resources that it have and also the departments. uh sometimes um these are not done and from audits perspective we'd like the departments to do at least on an annual basis. So we so that's what we recommend. So we recommend that MPD management define a process to periodically request review and document talk to or equivalent assurance reports including documenting roles and responsibilities for performing these reviews. So the next um recommendation is related to standard operating procedures. So standard operating procedures meet statute requirements. However, there's further uh needs for the development. Um so when we look at the written procedures, it adequately captures what needs to be done. But we also want to focus on how it's done as well so that we can train any new employees and rettrain some of the existing employees as well. And in addition to that, we also reviewed the body warn camera activation review SOP which is one of the specific SOPs used by the implementation unit and it describes the activation review process including staff roles, review steps and the use of tools such as Tableau and smart sheets. However, uh this uh SOP was recently developed so hadn't had a chance to go through that uh formal approval process from MPD management. So basically we're recommending to formally approve those SOP as well. So the third um observe um basin and recommendation is related to the password configuration requirements. So when we looked at the Exxon uh system u the evidence.com um the right now the application is configured to require a minimum six um characters length but based on the uh best um industry practices it's required to have at least eight characters long and we when we reviewed the the system we have the ability to set that to at least 10 uh So it's a quick fix as well. Uh so we're recommending to increase that length from six to at least eight. As for the management action plan, um as the observations, recommendation made by audit are suggestions to strengthen the BWC program and since MPD is compliant with the state statute, these are more suggestions and not required. But we encourage MPD to adopt our recommendation to strengthen the BWC program and meet best practices standards as well. And we did have conversation with the MPD in that regard and they recognized the need for it and they have said at least um they'll work on resolving some of these issues in future. Uh uh any questions? Thank you for that report. Any questions? Uh member Hoseb. >> Thank you, Chair Payne. Um I appreciate the executive summary that you had good cooperation through this. I just wanted to check. So, the the body of activities that were reviewed were a two-year period ending December 31st, 2024. >> Yes. >> Um do you think anything that you saw would potentially warrant a double check more soon, especially the last two months or the last year? Um that would warrant just a quicker refresh on some of these um reviews. So based on um so normally the scope wise uh how we choose is so we don't miss any of the years. So that that was the reason we selected the time when the last body warn camera reviews was performed and what was the scope of that we just select the two years after that. So that was one of the reason why we selected for the period that were not covered by the earlier review. uh but um we will be reviewing those um in the next um banial audit. >> Oh yeah. But from uh training perspective u policy and procedures so we do do review those on a current basis because those are the ones that they'll be using but so from any SOPs and policy and procedures we do review uh on like a current practices but from the footage and testing standpoint we do look at the um all the evidence based on the scope. >> Yeah. And I saw that you recommended moving to a annual uh third party assessment with MPD too. So that'll help with that delay in um >> kind of what you can cover versus what would be within the two years. So thank you. >> Any other questions? I just had a quick question on the third party assessment. Is this something that has happened at least sometime in the past but we just aren't leveraging it routinely or is this something that has not been done yet? I'm not aware of that happening in the past but Exxon do have so we did validate it uh when we went to the Exxon website so that report is available uh for us to review and also in addition to that right now the IT department is uh because most of time sock 2 report is more for the you know private industry to make sure so uh it is working with gob ramp which is more tailored towards federal state and local government as well. So it's like a similar process. So right now they're in conversation to make all the vendors to go through that assessment process as well. So so that it's more um up to date because sock 2 it's performed annually but once we go through that gov ramp it's on monthly basis. So the if something is wrong or something is inadequate in the system we'll know within a month versus in annual basis. So it is working on those aspect of the assessment as well. So we just need to make sure we do that in the future. Great. Seeing no further questions or comments, I will direct the clerk to receive and file that report. Thank you, Mr. Pel. Uh next we have item number four which is receiving and filing a a report on the MPD bianual [clears throat] automated license plate reader Alper audit and Mr. Puja. >> Well thank you chairp and the uh member of the audit committee. Similar to body one camera, we also performed uh and completed the statemandated batal audit of the Minneapolis um department's um ALPR program as well. And this ensures um this audit ensures MPDs follows state requirements on how ALPR data are collected, stored, used and deleted. uh similar to body one camera uh as a overview uh I'm going to briefly talk about the background audit objectives scope and methods conclusion and results observation recommendations and management action plan. [clears throat] So automated license plate reader technology may be used to support a wide range of public safety activities including revoked suspended driver introduction stolen vehicle recovery, enforcement of traffic regulations, apprehension of individuals subject to an outstanding warrant and criminal and tourist investigations and introductions. ALPR devices enable police officers to recognize and take immediate actions against vehicles and persons who are subject to investigative detention or arrest. The data collected by APRs can also provide investigative leads to identify unknown vehicles to gather data about known suspect vehicles and to locate potential suspects, witnesses or victims in the vicinity of a crime scene. So Minnesota state statute required law enforcement agencies that use ALPR to arrange an independent binial audit to determine whether state statute requirements are met. So as a result MPD engaged the independent office of city auditor to perform this audit which was designed to ensure the highest standards of transparency and data integrity. So the audit objective of this audit was to re assess compliance with regulations and review relevant policies, procedures and security controls as required by Minnesota statute 13.824 sub uh 6. So in terms of scope and method um this review focused on LPR requirements to verify if LPR data are collected, classified and used appropriately. the ALPR data are destroyed accordingly to this requirements of the statute. A LPR data are locked accurately and there are written procedures in place to make sure uh when we're authorizing the access of data and also making sure the MPD personnel are adhering to LPR policies and procedures. Our scope covered uh related activities from January 1st, 2023 to December 31st, 2024. uh similar to BWC uh we met with MPD to understand the APR program process and practices reviewed the relevant policies procedures and documentations and in this one we obtained access to inside LPR which is the system they use for the housing LPR data to independently review the LPR information and again here similar to BWC the key risk areas that we covered is primarily the compliance um risk and also the operational side of it. So the conclusion is that we determined that MPD complied with state regulation uh related to ALPR use uh although um they complied with the legal requirements we developed two recommendations that we'll cover in the upcoming slides. Uh so the first one is again similar to the um BWC audit as well uh establish a process for independent third party review assessment reports and uh the next one is MPD should further develop and formally approve existing LP ALPRS SOPs. So, so the first issue is exactly same as the BWC. Um, first issue number one as well. Uh, MPD does not have documented process to um, periodically evaluate thirdparty service provided performance for the automated license plate reader system. As a result, assessment uh, reports have not been requested or reviewed as a part of the ongoing vendor oversight. So, basically we uh, recommend MPD to do that in future. And the second one is similar as well regarding the standard uh operating procedures. So standard operating procedures meet the statute u requirements but need further development and then uh approval as well specifically related to system access data retention deletion and the periodic access reviews. uh as a result we recommend MPD management to further develop and formally approve procedures related to those key areas. Um again um observations and recommendation made by audit are suggestion to strengthen the APR program since the MPD is compliant with the state statute management actions are not required. However, we encourage MPD to adopt the recommendation to strengthen the program and meet uh best practices. And also, I would like to quickly thank um Ryan Franson uh who led both of these audits. He's one of the community safety auditors as well as Ella Kings. Uh she's the senior auditor u who focused on the IT portion of it. So, I'd like to formally thank them for this audit performing both these audits. Now, I stand for any questions. Thank you for that presentation. Are there any questions from members? Vice Chair Singleton. >> Uh thank you for this audit. Um I had a couple of questions related to how I guess I'll start with um is um license plate reader data shared with other agencies um both locally and federally and and I guess preliminarily was that within the scope of this audit? >> Uh yes. So basically there so there are certain requirements that we need to meet if that happens but yeah we do review those portions as well >> and were you able to I guess um second part of my question is there's been a lot in the news recently about um uh the service provider flock or the software provider yes >> um is that something that MPD uses and >> to to my knowledge MPD doesn't use his flock system >> and did you see any concerns within um the audit around how LPR data might be shared with with federal agencies. >> Uh at least uh from my perspective, we didn't see any issues related to how MPD is using the ALPR system. >> Okay. Thank you. >> Y >> I was uh reading reading through the statutes and it looks like an outside agency would have to make a request. Yes. Uh do we know of any requests from outside agencies as a part of this audit? >> Uh we did select the scope was uh from 2023 and 2024. So I don't think was there any specific request? No. >> Uh and then the other part of the statute uh it looks like the retention schedule is 60 days and I know that um there has been some interest uh in organiz from like organizations like ACLU in terms of a lot of the federal activity that's happened uh during Metro Surge around uh what our retention schedules were as it related to potential potentially using some of that video footage as evidence in ai civil case. Uh do do we know if our retention schedule because the audit report says we retain within statute but do we know if we're retaining for 60 days or retaining for some shorter period of time? >> So for ALPR so it's unless it's a part of any investigation. So all the data is deleted after 60 days. Okay. >> So we retain up to 60 days after that it's deleted >> and would validate that. >> Would that be true also for like the stationary traffic cameras? Uh so the stationary traffic cameras are not part of the ALPR. Okay. It's uh strictly for all the dash cam and what they consider is a stationary ALPR system. >> But for this scope of the purposes, so any traffic cameras are not considered ALPR. >> Okay. Thank you. >> See, oh uh member Williams, >> thank you. Can you just remind me of the um the scope period of this audit date wise? Uh so uh January 1st, 2023 to um December 31st, 2024. >> Thank you. >> Seeing no other questions or comments, I'll direct the clerk to receive and file this report. I will also direct staff to publish this report and the previous report and direct the city clerk to transmit both of those reports to the appropriate agencies. >> Thank you. Next, we have item number five, which is receiving a filing and filing a report on the 2026 enterprisewide risk assessment. Uh, I will once again invite our audit team up to present on this report. All right. Good morning, Chair Payne. Good morning, audit committee. Uh we are excited to present to you uh some work that we've been uh doing over the last several months uh to develop the 2026 enterprisewide risk assessment as well as the audit plan uh and strategic plan for our office. This first presentation aligns with the report uh on your agenda that will cover some of the high points related to the enterprisewide risk assessment. uh in this presentation I will cover the background and methodology of the work that we did. We will cover some progress made on uh risks that we had identified in 2025 and then we will discuss risks needing special attention in 2026. Uh and finally we will close things out with a bit of a discussion on enterprise risk management which is something that our office has discussed with the audit committee as well as the city council in the past. So for this particular report, we uh surveyed about 120 individuals across the city uh mostly elected leaders, appointed leaders uh and other uh key staff members throughout the organization. We met with management uh and staff across the city holding nearly 30 meetings with city officials to gather their input. We reviewed various budgets and considered prior risk assessments such as uh last year's and the year before. Uh we also looked at risk assessments from other cities uh and different reports. We want to make sure that we are providing uh and following our own best practices uh and industry standards. And so we do regularly look at similar reports from cities uh outside of Minnesota as well. Uh and then we looked at current industry trends and those best practices I mentioned as far as progress made on risks that our office identified in 2025. Uh the first few here focus on uh some actual work and changes that happened within our office. Um we completed four audit reports, five advisory memos in 2025. Uh we anticipate this work to increase significantly now that we have an investment in our office that I'll cover here in a moment. Uh we were able to work with the administration to close 28 audit issues in 2025. We provide updates at each audit committee meeting on those closed issues. And when we get into our auditor update at the end of this meeting, we will talk about a few more closed issues that the administration has taken care of. Uh in 2025, we had the good fortune of council investing in the office of city auditor. We were able to increase our um actual staffing size from 8 FTEEs to 14 FTEES. Uh I will provide a little bit more information on that in the auditor update as well, but that is uh a great investment in oversight and accountability for the city of Minneapolis. Uh and we have started building some momentum towards building out an enterprise risk management um body or group or function and excuse me as the city council continues to uh consider some recommendations in that area. The administration has streamlined the communications department. Uh we've seen this over the last several months uh being beneficial in the emergency response and the communications related to um the emergency response with operation metro surge. And then we've also uh seen some progress with the IT department planning for AI policies uh in a bit in in addition to basic guidelines. So the risks needing special attention in 2026. Uh you'll notice based on the report but also this presentation that we came at it a little bit differently this year rather than looking at risks from your standard operational financial uh reputational those those risks that all audit standards kind of outline. We decided to focus on four key risks that we heard throughout our conversations. We receive feedback throughout our surveys. Uh the first being budgetary risks. There are significant financial risks to the city. Um that will impact service delivery. It will impact surf service levels. Uh it will impact the cost of borrowing and it will impact property tax obligations of residents and businesses. We'll get into the this a little bit more in the next few slides. The second risk that is uh needing special attention this year is related to federal operations and safety of employees uh and citizens and residents within uh the city itself. Uh federal actions increase the risk to resident safety, legal exposure to the city and financial deficit. The third risk is contract oversight. Uh lack of universal policy and inconsistent oversight exposes the city to significant risk of contract fraud, waste, and abuse. And finally, risks related to city culture and trust. Unmanaged organizational culture risk can undermine employee morale and diminish public trust. All right, so getting into the first risk and keep in mind these are risks. Um these are things that were identified by the folks that we interviewed by the surveys that we completed. Um and there are some significant budgetary risks as many of you are aware of that have been exacerbated recently uh by Operation Metro Surge. These risks will affect residents, businesses, and core services. It could lead to higher borrowing costs, staffing shortages, and service reductions. Um, and the city needs to uh really start working and considering what it will look like with um with this change to our revenue. Uh but also to our expenses as they've increased significantly over the last five or six weeks. Uh without new revenue, it will be difficult to sustain the services that residents expect. New revenue in this case may be supported by funding uh that the city requests from the state legislature. Additionally, the city should be prepared to readjust tax levy expectations in future years. Specifically, the budgetary impacts of recent federal actions. Uh these significant and unplanned financial impacts have uh been quite noticeable in our city. Uh the city council recently reallocated $1.5 million to urgent needs including immigration legal services and rental assistance. I want to point out that we finished this report and this presentation prior to the council's last uh cycle where they invested even more funds to help the residents of Minneapolis. um event cancellations, declining visitor traffic, uh all affects the uh revenue of the city as we do have a city sales tax. $5 million of unplanned and unbudgeted overtime. Uh and this number continues to grow. Uh although the uh there is an active draw down in federal agents in the city, um there is a projected $1.5 million cost per week of overtime and expenses. Uh this is all on top of the estimated $23 million that uh has been estimated to impact the overall community. Uh the last bullet item here is the preliminary impact assessment and relief needs overview that came out of the emergency operations department. Um we were able to loan uh one of our auditors to that office over the last five or six weeks. Uh and they actually put a significant amount of time into building out that report. Uh and there is some great information about the costs of the city in that report. So that can be found through the link on the slide here. [snorts] As far as recommendations related to budget, uh the recommendations that we've developed for this risk assessment are not ones that we will track like we normally do with audit recommendations. These are things to be aware of, things to take into uh deliberation, strategic planning. Um but we do recommend that regular risk reviews and budget planning uh is done to reflect different scenarios. I think that uh adopting an enterprise risk management posture goes along with this. We think that the finance department should update its forecasts over the next several years. Uh on page 60 of the budget book, they have some projected forecasts for maximum tax levies uh for the next several years. I believe that those should all be reviewed, updated, and communication should start being developed to provide to residents to understand the real impacts of uh the potential need for increasing revenue. Uh, the city should prioritize core services, set guard rails for any cuts that would occur, and clearly communicate the possibility of property tax increases. Uh, the city should inventory grant dependencies and at risk positions and prepare contingency staffing plans. And the city should increase stakeholder engagement in the budget process, including structured input from the parks board. So we talked a bit about the uh federal operations as it's related to budget but it is such a risk to the city that it gets its own category as well. Uh operation metro surge certainly introduced unprepedented disruptions to regular city operations. uh actions have uh confirmed earlier concerns that our office shared in the 2025 risk assessment, but it's also introduce new risks about compliance, finance, and safety of employees and residents. Um our risk assessment discussions for the 2026 risk assessment started in November and December. Uh and so while we were going through some of these conversations, in fact, um Mr. Mr. Puall and I were sitting in a risk assessment conversation when uh we first learned of increased federal presence um and the the death of Renee Good and things rapidly changed from there. And so the the overall um response that we got related to this this risk assessment changed from general city operations to very hyperfocused operations just in the period of time that we were developing this work. Um so I I do want to point out that the the greatest challenge is that uncertainty. We've learned in the last couple weeks that there is a a draw down in uh the federal presence. Uh and that's good news as it's related to safety of residents, but also the city's budget. Um I do want to note though that recent recognitions such as the city's Nobel Peace Prize nomination does offer hope for improving public perception. Um and at the same time, these risks remain significant. departments are navigating complex federal directives that increase compliance challenges and additional litigation exposure. So, as far as resident employee safety, we've talked about this a little bit, uh, and we elaborate more in the report. Um, but certainly large gatherings, emotionally charged interactions, dynamic scenes, they raise the likelihood of injuries and service delays. Uh residents especially in neighborhoods with that heavy federal activity reporting re have reported heightened fear and anxiety. Uh some residents avoid public spaces, businesses, services uh which reduces their access to care and food and employment. Uh and as I noted, the report that the city recently published has impact has um identified these uh to be about $23 million in uh actual costs to the community. Operation Metro Surge has also led to additional litigation and compliance risk. Uh Minneapolis has joined lawsuits against the federal government challenging both grant conditions and cond contesting the federal surge. The city is facing litigation threats and various federal investigations. Uh resources have been diverted to respond to litigation and inquiries. And uh one of the recommendations that we'll cover here uh is uh if if possible moving some funding to the city attorney's office to help with some of this litigation work. The city's incident response. One thing that I do want to talk about and I'm happy to answer questions about when I'm done with this presentation. uh the the office of city auditor um like so many people in this city has felt hope helpless sorry over the last several weeks because our work is typically retrospective. We look back uh at response. So while things have been unfolding we have tried to pull in as much information as possible. We have tried to uh get into a position where if a request is later made for our office to review any city actions related to operation metro surge, we'd be in good position to do that. Um and as such, we have uh assessed generally the city's response and thought quite highly of the communications and the emergency response. We think the emergency operations department has done a fine job and the uh the J has also done a nice job of communicating both with city staff and residents. The reason I bring this up is because this past summer we had recommendations to improve the communication flow um when there was an ICE activity in June of 2025 and the city did uh integrate the uh legislative department in their communications channels and that helped with um ensuring that people in the legislative department were on the same page with the administration. recommend recommendations related to federal operations and safety. Uh I'm not going to read through all of these, but the city is actively doing most of them. Um just to touch on a few. It's uh we need to continue that unified communication. We need to provide uh that communication in multiple languages. is we need to get it out to members of the public as quickly as possible uh to help avoid any um any rumors, any inaccuracies in information. Uh we certainly need to manage fatigue of staff and protect staff's physical and mental health. Um and then we need to as I mentioned strengthen the legal capacity within our office uh of city attorney. The third of four risks that we're highlighting this year is contract oversight. This is not new to the audit committee as we've uh looked at specific contracts over the last year uh and also made general comments about the city's contract oversight. The decentralized contract management that the city operates under does create risk of errors and misuse. Uh there is non-standardized contract language, inconsistent compliance documentation, uh lack of proper vendor vetting, and uh a a insufficient formal reporting pro process for nonprofit vendor misconduct. The city has made efforts to improve contract oversight through staff training. The city attorney's office has trained well over a 100red individuals across the city in contract management. Um but training only goes so far if there's not policy that goes along with it. And so we recommend that those um standard policies be created by the administration for contract oversight. We also think that a cross-dep departmental team to provide contract oversight support should be built. Uh this is similar to um a a governance team of sorts, one that can help build out contract oversight policy, one that can answer questions. Um we have some departments such as public works that do many many contracts a year and do a great job of of managing those. And we have others um such as the office of city auditor that may have one or two contracts a year. um and these smaller offices certainly have less support uh in that contract management and oversight. We do think that those capacity checks and additional training to ensure vendors can meet city requirements. Um we as a city try to make the the barriers to entry for our vendors as as low as possible because we want local vendors helping with our city works. Um, but that does come with risks that we need to mitigate. And then finally, strengthening reporting mechanisms to make it easy to report concerns of wrongdoing or fraud. This is something that our office will take to the administration, make it easier within our websites and our different uh communication channels for residents and staff to report wrongdoing. All right, the last of four risks that we're highlighting this year are related to culture and trust. Keep in mind, these are things that we heard from those uh leaders we've interviewed, those staff members and and key personnel that we uh received survey responses from. Uh and some of the things that we heard are that there are communication gaps that exist between the council and the administration as well as departments that there are unclear roles, responsibilities. Uh and sometimes that unclear communication can lead to duplication of efforts, operational drag, departments operating in silos, which is a theme we heard regularly. uh loss of experienced staff and inconsistent messaging that could erode public trust and confidence in this area. The recommendations that we have are to uh have the administration, the council, any leaders throughout the city help define roles and responsibilities and expectations through enterprisewide policies. Now, we're aware that there is some work that is being done to create a process for uh developing tracking um updating enterprisewide policies. And so, we want to also acknowledge the good work that's been started in this area. Uh we recommend that continue and that those policies get uh documented. We think that standardizing internal and external communication practices would be beneficial. One thing that we heard from respondents was um that individuals don't know who is allowed to talk to the media and who's not. Individuals don't know who has the authority to um disseminate information outside of the city and who does not. And we see that um as a risk to the city. We think there should be standard processes and uh delegated authorities for various communications. We think that there should be joint training for elected officials and staff. Of course, this is something that's been ongoing, something that's been um going since the first week of this particular term, and I think that should continue. Uh we think that there should be standard uh uh excuse me, there should be a standing governance oversight committee. The administration right now um does not seem to have a governance committee. Um, of course, everybody is welcome to operate their uh organizations as they see fit, but I do think that having an enterprise riskmanagement uh posture along with a governance committee uh certainly helps with tone at the top. It helps with policym, it helps with uh decision making and it certainly will help with communication as well. Uh and then finally, we think that there should be quarterly departmental reports that are offered to the city council. I think some of this communication is being built into the 2026 um session here and these are again things that we've heard through our conversations and we wanted to make sure to highlight them. All right. So in conclusion with the risk assessment, managing those four risks can help um certainly um reduce costs, certainly uh help improve service delivery to residents. Uh but it does take a coordinated effort across leadership departments and elected offices. Uh all of these risks are interconnected as you saw between budget and the federal operations um and culture and trust. I mean they are all interrelated. Um and that is why risk management is so important as I promised. Uh the biggest recommendation to come from our office on this risk assessment is that the city should um bolster its risk management posture. Enterprise risk management can help in all of the things that we've discussed. The Office of City Auditor or internal audit in general is one of three legs of a stool when you consider risk management. The image on the screen here is uh something that is regularly referred to by our office but also audit shops across the country. Um the IIA which is one of the governing bodies of the audit standards that we follow uh does a good job of talking about risk management. Uh the USGAO also has um what's colloially known as the green book and we've talked about this with the audit committee in the past. Um it is something that we think the administration should adopt as far as standards of internal control. We think all organizations should have some sort of standards of internal control and these were specifically de developed for the federal government but many local and state governments have adopted them because they fit so well and in fact they are a companion to the GAO government auditing standards that we follow. Um, so an effective erm framework should align risks with responsible staff, continuously monitor and adapt controls, improve early detection and escalation of issues, and break down those information silos that we've talked about. Uh, the city should dedicate that risk management staff. This is something that we talked about and that there was some momentum in 2025 with. Um, and I do know that it's a carry forward item that the council will be taking up again in 2026. Uh, we think that the city should create a risk committee for oversight and internal control standards. Uh, this could be the same as that governance body we talked about or the policy body. Um, but all of these these uh ideas are to ensure that people across all departments are communicating about risk on a regular basis. uh we think that there should be training related to erm and internal control frameworks and then finally we think the city should adopt either the green book or some other um internal control standards. I will say that um one of the recommendations we made last year was for the city to focus more on using the green book. We built that into the uh the audit charter this year and so it is something that we will use as criteria in our audits going forward. Um and it is something that we will use to educate the administration as far as best practices with internal controls as well. All right. So that brings me to the end of the risk assessment presentation and I can take questions related to this before we move on to the audit plan. Any questions or comments from members? Um on the for me on the uh recommendation for culture and trust around creating a standing governance committee. Uh I'm assuming your intention for that recommendation is for the administration to create that committee, [clears throat] not like a city council committee, right? Correct. Okay. >> That's correct. Uh and then I'm wondering, you know, we have uh the for instance the permanent review committee committee just this last cycle there was some discussion on city council around suspending the PRC during the duration of metro search that actually did not pass city council. We as a body agreed that we think we should have those controls in place. Um but then last year we also adopted the uh policy the guide to the city's enterprise policy framework formally as city council. But the rub is uh in all of the discussion around this is around the authority of council versus the administration. And I think this is where at least in my conversations around culture as a risk is we constantly get in the way of each other when it comes to that separation of power. And I think that it's not just that the admin needs to set up a committee. I mean I I'm kind of maybe meandering a little bit here, but just to say we already have the permanent review committee as a governance body. Uh there's the policy review group as a separate body that's discussed in the policy framework. Is the recommendation to consolidate those under one oversight and governance committee? That's question one. And then question two is I think that that wouldn't go far enough just for the administration to have that consolidated single point of reference. I think there needs to be an integration and alignment with the city council. And I'm just wondering how how you think about that. >> Yeah, I I think you are right, Cher Payne. I think that um combining the two committees may be expanding the scope beyond what one committee should do. Um I think that the the policy uh framework that is has been adopted in 2025 and that's going to move forward in 2026. Honestly, I think that's a great start towards addressing some of the risks uh and concerns that we had coming out of this risk assessment. Um I think that um more connection between the council and the administration, top leadership would be valuable. Um, I do think that if there were opportunities for the mayor's office and legislative leadership to meet and connect and discuss strategic priorities, um, that would be incredibly valuable because that could lead the work of a governance team within the administration. But I also think that once uh or if a governance team like that is is fully operational, there should be ties to the city council. So to your concerns about um you know the the maybe the misunderstanding about roles uh I think that those all can be documented developed and then agreed upon and so that there isn't duplication of efforts and quite frankly I think the legislative department's done a good job of trying to reach out and set up these um these conversations to get the ball rolling. So again, I want to I want to mention these are risks. I think that many of them are already the safeguards are being developed. They're in the works. Um, but it I guess if if it were up to me, the structure I would see or like to see is a governance committee within the administration that has um a similar structure as a policy committee that would have ties directly into the council. And then um the internal controls, enterprise risk management, that group, that team um would be led by an individual responsible and held responsible for ensuring internal controls and um a a posture of risk management exists in this city. And that individual is responsible for holding department heads and others uh responsible for ensuring that there are safeguards, risk assessments, things of that nature. Um this will take time and it is something that I know that the council has reached out to me again recently to start those conversations as far as the enterprise risk management piece goes. Um, and our office is happy to have those conversations because I think that um, having that erm um, partner in the administration that uh, can help hold people responsible for the audit findings that we have uh, will ensure that the work is valuable and um, honestly to ensure that our recommendations are followed through on. >> Excellent. Uh, member Hosman. >> Thank you, Chair Payne. Uh, thank you, Mr. Chie Me, for this. Um, and I really appreciate you and your team being so, uh, flexible and fluid with this as the last eight weeks have unfolded. Um, I would say, um, I'm looking at this kind of green triangle or, uh, I don't know, square image. Um, and it feels like the ERM piece is kind of the green underneath all of this. >> Sure. And um and I just while I think it is critical that you have these four buckets of um risks needing special attention, the erm that now is kind of at the back of this presentation report impacts all of this and I just don't want the administration and others to lose track of that because I think a lot of those things that we've been seeing even before Operation Metro Surge are just going to continued to get amplified, which is what you've covered here beautifully. And had we had that, so much of these other pieces would have, I think, really fallen into place a lot easier. Um, and then I wanted to, um, I think you for the culture and trust because we've talked a lot about that kind of if folks don't feel like they have that support, they're going to continue to leave or continue to not know the right thing to do. um just from any of your reviews or your team's reviews at this current time with kind of heightened work um emotional work, people getting frustrated potentially with resources not getting to the community. Um, I know that's been a big kind of as a community member on this uh uh board, the the aid that is being offered is not necessarily being easily transfor transferred to the those that are most needing it. How do we ensure that it's not just the manager of that department or that manager of that person that's helping support that frustration to the right path and them just not saying sure let's just get it out as fast as we can which is also kind of personally my my urge right now too. Um, and I just think that that's going to be critical for this year in addition to these kind of open items, but having that management level training of support of how that um, ends up kind of playing out here and kind of the flexibility that might need with other heightened risks that come up as we kind of see what this looks like in two to four to six to four years. I don't know. Um, so anyway, thank you for that. I um, I just yeah, the ERM piece really feels like the baseline to a lot of this. Um, and if it doesn't get prioritized, we're going to see more fractures in this. >> Yeah, Cher Payne and Committee Member Hosein, the I I really like the way that you put that and I now wish we would have called that green square enterprise risk management in next year. I think we will. Um, which is nice to have this partnership. So my plan this year is to distribute this to administration leaders uh as well as city council members. Uh as you probably noticed and I will talk a little bit more about with the audit plan, we separated the audit plan and the risk assessment this year for a very specific reason and that is we wanted the risk assessment to be something that could be held in hand and used while leaders go through their strategic planning, their budget planning and They don't have to answer all of these questions. They don't have to address all of these recommendations, but they have to be aware of them. These are risks to the city that we should be building safeguards against. Um, and so to your uh your question about managers having the right decision-making authority or or the right people getting the the funds to the right organizations. I think that those are those types of risks that need to be considered on an annual basis so we can proactively answer those questions rather than be so reactionary in nature. >> Member Williams. >> Uh thank you. I was going to ask this question on on six, but I'm going to ask it now and I'm comfortable if you want to wait until six. I completely understand the proactive nature of creating the special needs a as well as the strategic plan. But the concern I have is the reactive nature that is sometimes needed. An example of this 120 days if I would have asked you to create these four boxes something tells me it wouldn't have looked like this. And I understand one of the challenges that any audit group has is that you said it earlier is that you audit things that have already happened. But I am curious of your opinion and and maybe approach on if something unexpected were to happen in 40 days. How does this plan as well as the audit and strategic plan adjust quick enough so that we're not talking about it in two years about all the things that we should have done, but we are coming up with an actionable plan as soon as we can to protect the city on something else that could happen as well. Uh, sure. Chair Payne and uh, committee member Williams. That's that's a really great question and it it is often a feeling of being between a rock and a hard place when it comes to audit. We do have the good fortune of being able to provide advisory services and those advisory services in my opinion are incredibly important to be built into governing bodies to be built into enterprise riskmanagement committees and to be built into policym committees. Um and so all of those committees when they are forming when they are uh even considering um an individual policy audit should have a seat at that table because audit can look at things through a uh a lens of risk and provide recommendations in live time. And so audit does have the ability in those situations to be um be lifetime help to be proactive help in that way as far as looking at I mean your assessment on this 40 days from now versus 120 days ago. I mean it's spot on and that's why the enterprise risk management recommendation is the key. That's why it is the conclusion to this year's risk uh assessment because that is the that is the foundation for uh the city to be able to uh respond react but in a manner that is prepared. Uh, I do think that based on our observations over the last five, six weeks, the emergency operations division as well as communications and and others across the city um have done a a a job that um they weren't expecting and I do think that they demonstrated some good um preparation for responding to that. Um, but to answer your question specifically about audit, I think we just need to continue to offer our services in Lifetime for those advisory services. When we get to the audit plan, you'll see we did build in some time for that. Um, and we also need for others, including folks on the audit committee, to remind those uh those bodies, those committees, those decision-making um leaders that they should be talking with audit. They should be thinking about risk. And if they're not doing that, they should be asking audit to be thinking about risk. And that's a service we can offer. Yeah, I would add um building off of the advisory services component uh after the Lake Street raid in June, that afteraction review had a number of recommendations including strengthening the separation ordinance and including some operational changes to how communications happened. And we passed that separation ordinance strength uh the strength and separation ordinance in December of last year. And when Metro Surge was stood up, we certainly learned from the June incident and the lack of communication and had much better communication between council members and um and our emergency operations and the joint information center, which is the component of emergency operations that we most tied into. So I think part of it is just understanding what the risk assessment scope is and then also being having systems, structures and resources in place for other aspects of our audit capacity so that we can be much more responsive. So and I think the advisory services is actually a reflection of that. So yeah, >> thank you. Uh, not seeing anyone else [snorts] with comments or questions, I will uh direct the clerk to receive and file this report and direct staff to publish the report. And we will take up item number six, which is receiving and filing the 2026 audit and strategic plan for approval. And I will once again have Mr. Timberman present on that item. >> All right. Thank you, Chair Payne. Audit committee. um the audit plan and strategic plan this year. Um we will uh cover what's different about it. We will talk about the purpose and the background. We'll get into those audits that we are proposing for 2026 and then we will cover the new strategic plan uh which the office has not uh formalized in the past. So, what is different? And this is all in the audit plan report uh in the executive summary. Um but as I mentioned, we separated out the enterprisewide risk assessment because we want that to be a document that leaders can use in their decision-m. But we also want the audit plan to be a document that you as the audit committee can use, the city council can use, and other leaders can use to know what's coming up this year. We included our updated mission, vision, and values. Uh I know I've shared these in the past. We're also going to uh share them and attach them to the RCA with the auditor updates uh with this uh audit committee meeting so they get into the uh the public record. Um we prioritized work by considering risk capacity and optimization of auditor hours. We developed preliminary objective questions for each audit uh which will help get the audit rolling more quickly uh as well as the preliminary scope for each audit. And we also added strategic priorities which we'll get to. All right. So as I mentioned we included in our report this year our updated mission, vision and values. Um the in the last year we updated all of these. We developed a vision statement which we had not had in the past and we documented the values that lead our work each and every day. Uh independence and objectivity of course are the guiding principles that we safeguard closely but it's important that we also uh document the values in which we uh want to bring into all of our work. The audit plan informs the audit committee, the council, administration, and members of the public of our planned activities for the upcoming year. The city ordinance and professional auditing standards require this work. It is designed this year to be flexible as new risks may emerge. Uh so, committee me member Williams, we are trying to maintain some hours to be flexible. uh as you noted. Uh and then also the uh the plan is intended to be flexible. So if something does come up, we can bring changes to you uh and update the audit plan throughout the year. All right. So the purpose and background of the audit plan, the as I mentioned the uh city ordinances require the uh office of city auditor to follow two sets of go of auditing standards. One is the government auditing standards uh and one is the global internal audit standards. These standards require strict adherence to ensure accountability, transparency and quality in all engagements. They also require planning um which the audit plan does for 2026. This is the first year that we've looked at or considered resource utilization. Um it is standard in many government audit shops to uh calculate based on a 70% uh resource utilization rate. which means that of your auditors you uh start with the assumption that 70% of the 280 hours is auditable hours. Um this year because of some of the strategic priorities that we have because half of our staff is new within the last three months and we have two more staff that we will be bringing on in the coming three months. Um that we've developed this calculation based on a 50% utilization rate. These these are estimates. These are things that are adjusted throughout the year. And you'll see that when we get to the audit plan, we've uh indicated how many hours we think each audit will take, which we also need to be flexible with. All right. So, as far as the audit plan goes, we'll start with those that are in progress. Um the body worn camera audits, those are effectively done. Maybe a few hours left here just to wrap things up uh as far as um getting things attached to the RCA, things of that nature. Um we've got the afteraction reviews of the death of Allison Lucer, the shooting of Davis Matri. Um we believe that this work uh will use a few hundred more hours uh internally as well as more time uh from our contracted uh law firm that's helping with this work. >> [snorts] >> We've got the NSD contract management and contractor oversight audit. This is in the works. Um this is scoped for 2020 to 2025. Again, with any audit where we're looking at contracts or um vendor payments, uh we are going to create and reiterate recommendations for contract oversight for the enterprise as a whole. Um and so we expect there to be some recommendations for enterprisewide policy and oversight changes that come from this particular review. Uh a new audit that we will begin uh and we've uh actually started some of the preliminary work is uh reviewing the behavioral crisis response program. Uh is the contractor meeting requirements that are outlined in the contract with the city? Is the city providing effective oversight? Um, so this one is uh one that is owned by the fire department. Uh, Meet Minneapolis. We're going to take a look at the contract and the relationships with Meet Minneapolis. It's been many years since this uh organization, quasi governmental organization was audited. So, we will be taking a look at that. They have certain key performance indicators there to meet. So, we will use those as audit criteria. um we will ensure that they have effective internal controls and that those are being followed. Uh shot spotter was one that the uh city council had requested that is one that is in the works uh right now as well. Um that is looking at the placement of sensors based on uh objective shooting data rather than demographic factors. Um, we want to be able to develop a a an opinion or a conclusion about the effective level of policing in specific neighborhoods related to the placement of those. Uh, we'll look at average response time and uh, effectively make an assessment on the benefits of that program. Overall, bodywn camera. So, we heard about MPD's bodywn camera program today. Uh the parks police also has to meet that state statute requirement to have that audit done every two years. Uh we presented one for parks police to you last year and we'll be presenting one uh again this year. So uh those bodywn camera audits we'll see pretty regularly since they are required. the management of afteraction reviews. Uh this is a an audit to determine where afteraction reviews belong within the city's structure, whether that's the office of city auditor, whether that's civil rights, whether that's a new group organization. Um and so this will review what the current structure looks like and if additional investment needs to be made to handle uh these types of reviews. Data governance has been a hot topic. It came up quite a bit in our risk assessments. Keep in mind our risk assessment informs our audit plan. Um data governance is the city uh efficiently or sorry sufficiently uh managing the data that it creates. Uh is there policy? Is there a framework to manage that? um what does ownership of data look like and what does training in this area look like? So, as you can imagine, the city creates data with every meeting, every word that we speak in public, uh every camera that we have. And so, there really does need to be a robust overview of the city's data governance, continuity of operations. Uh this is one that I think any organization should audit regularly. Uh certainly with some of the things that have occurred in the last five or six weeks, this has um elevated in priority for our audit plan. Uh and so this is one we will do uh in 2026. Citywide fleet management. Does the city have effective design controls and processes in place to manage its vehicles? Uh this is one that the office of city auditor did uh years ago. Um but I think that it is an important one especially as technology has um developed as far as GPS tracking um and the efficiency of vehicles as well. Uh we have an IT auditor which we are blessed to have. I think many organizations uh find it difficult to staff an IT auditor. Um and so we are going to be inventorying the software across the city. something that um will work closely with it and then we will start doing access audits. Of course, we want to make sure that only the right people access the right systems. Um and this inventory will also help us uh develop future IT audits down the road. With the city council's investment in the office of city auditor, we committed to developing a program evaluation uh process or or report that is similar to what the office of the legislative auditor at the state level has. These will be deeper dives into programs, units uh or functions within the city. They will act as uh half educational report for the audit committee in the city council and half uh audit report where there are recommendations associated with each program. Uh to get that work started we have selected three programs to evaluate this year. One is the misconduct complaints intake in the police department. Another is the ethics board policies implementation and oversight. I think it is important that not only um we ensure that staff are following all of those requirements, but that the ethics board itself is um making sure that those are relevant, updated um and aligning with the uh the work that is continuously changing throughout the city. Uh and then the last program evaluation will be the permitting process um within CPAD from um a resident requesting an application all the way until the uh certificate of occupancy is granted. So we we have a lot of work this year. Uh I am hopeful that we will be able to effectively implement our resources. Uh we are well on our way in several of these audits. Um, and as I mentioned, we did save some time for that ad hoc um, fraud, waste, and abuse uh, investigations, on demand advisory services. 1,200 hours is certainly not enough for all of this, but it is the placeholder. Uh, and then we adjust as we need to. So again, this is intended to be a flexible and fluid plan. um and um hopefully it is a realistic plan for 2026. All right. So then getting into the strategic plan, as I mentioned, we have not uh developed or communicated a strategic plan in the past. Um but I think that it's really important for our office to continue the momentum that we've created over the last year. Um, and the first item on that strategic plan is to complete our organizational right sizing. Um, we need to ensure that all of our recently hired team members are fully integrated and equipped to succeed. We need to operationalize our quality assurance and training manager. Um, who I would like to welcome today, Jessica Peterson, who's joined us. Um she will be joining the office of city auditors leadership team uh developing our quality review program as well as um helping build out our audit manual. This role is paramount to uh us meeting audit standards. Um and Jessica will be helping us invite the Association of Local Government Auditors in 2026 to audit our shop. Uh, as I've shared with some of you in the past, we have spent a lot of time strategically this last year in 2025 getting the shop into a place where we will be meeting professional audit standards across the board. Um, and any recommendations that we receive from that review, we will share with the audit committee. We will adjust our practices because it is uh important that the auditor gets audited and that the auditor follows up on recommendations we receive. Uh the second item on our strategic plan is to strengthen auditor resources. Uh we want to develop that audit manual I mentioned that will guide auditor work. It will assist in uh ensuring we're also meeting professional requirements. We're going to refresh all of our audit workpapers, our presentation templates, our reports. Uh we've done a good job of updating a number of these templates, especially the the public facing ones over the last year. Um but it has been kind of a a building effect. And so now we want to finalize these get them as templates within our own work. Uh we want to implement a structured quality review process to create actionable feedback for auditors and we want to promote certifications and participation in conferences and trainings so we can maintain cutting edge expertise. The third item on our strategic plan is to uphold professional standards. Uh we want to maintain the highest standard of audit quality and compliance. uh we want to strengthen our uh our own compliance by developing a robust internal review process. That's that quality review function I mentioned. Uh as I said, we're going to engage uh ELGA to perform a peer review of our work and we're going to expand internal training opportunities. Uh we're all required to get um give or take 40 hours of CPE a year. um and having the quality review uh or sorry uh quality assurance manager on board, we're going to actually be able to perform some training inhouse which will be a cost savings to our office. Uh and then the fourth item, enhancing independence. This is something you've heard me talk a lot about over the last year. We've done a great job enhancing independence in 2025. We're going to continue that momentum in 2026. To further strengthen our organizational autonomy, we will recommend revisions to the city code to further clarify independence and align with professional standards. When we wrote the um audit committee rules that you approved at your organizational meeting uh last month, there were some items that I identified that could be strengthened within city code. So, we will work through those. Um, and then we're also going to collaborate with the city attorney, IGR, and state legislators to secure uh necessary authority for our office to get subpoena authority. Uh there does need to be some uh state legislation that occurs, but um there is a path to get there and I think having that subpoena authority will certainly help us down the road. The last item on our strategic plan is to advance non- audit projects. Um, we've talked about a few of those already, but we want to enterprise uh finalize our enterprisewide workforce optimization and comparative benchmarking study to provide city leaders with information to enhance strategic and budget planning. That's a study that um we brought on a vendor um called 65th North Group to help with to look at five sister cities to determine um are our staffing resources in the right places? might we learn something from other cities? Um, so really more of a study with some soft recommendations, but that should be released at our April audit committee meeting. Um, we want to develop an auditable universe of all units and programs and divisions across the enterprise. I mentioned this with software systems, but we also want to do this uh to develop a full universe of auditable functions in the city that will help inform our audit plans going forward. Uh, and then as I mentioned that centralized inventory of software. All right, so that's a lot. I feel like I'm losing my voice. Um, but as I transition to taking questions, I do want to note the back page of the audit plan. I took the liberty of uh using whitespace because uh I needed to offer some gratitude. Um, I think that the staff in the office of city auditor has done an amazing job in the last year. I think that we have been responsive to some requests from the audit committee, some requests from the city council. Um, and I think that with pleasure they've taken on some very difficult work. Every day they demonstrate integrity, professionalism, and a commitment to excellence. Um, and I also want to express my gratitude to the audit committee, to the council, to leadership across the city. Uh I do think that uh just in the year that I've been here there has been some real acknowledgment that um the audit function was asked to step up. The audit function in 2021 was asked to become more visible. um and voters through the the charter change in 2021 um built the office of city auditor and created the city auditor position. And so over the last year and over the next year uh we will continue to try to elevate the function of the office of city auditor. But I do think that with your support, with the council's support, um with staff support, um we're well on our way. So thank you for your support. All right, that is it for the audit plan. Hopefully I can answer any questions you have about that. Any questions for members? Well, I I will just say much gratitude to you. I mean, your very first day you were in council chambers and the [clears throat] family of Alice and Lucer were demanding justice and I mean you stepped completely into that space and you know we're waiting with great anticipation for the conclusion of that investigation but the fact that you were able to just move so adeptly through just many many challenges throughout the last year it's it's just much gratitude to you for that. So, thank you. >> Thank you, chair. >> Uh, and seeing no other questions or comments, I will direct the clerk to, uh, receive and file that report. Uh, and may I have a motion to approve the 2026 audit plan. >> So, moved. >> Second. >> All those in favor say I. >> I. Oppose say nay. >> The eyes have it. And that carries. And last is [snorts] the report of the city auditor. and I will again welcome Mr. Timberman. >> All right. Thank you, Chair Payne and audit committee. I will try to be quick through these first few slides because we've talked about a number of these things, but uh as is our tradition, we we like to provide you an update of the work in progress, what we've done since we last met. Um and so we will cover completed and in progress audit work. We will uh just quickly highlight uh fraud, waste, and abuse investigations. As you know, those are um things that we normally just share the number of of uh reviews we're working on because of the sensitivity of those. Uh and then we will talk about those prior audit issues and findings that have been closed. Uh finally, we'll close it out with some personnel updates. I introduced Jessica, but I'd like to introduce two other uh new auditors as well. So, we'll do that at the end. and then um I'll just get some documents in the public record that I want to make sure are available to the public. All right, so completed work. We talked about MPD body worn camera audits. So we also talked about AOPR audit. We're just going to keep going. Uh we also talked about the risk assessment and the strategic audit plan. other progress or in progress work I I briefly talked about but we will uh just quickly highlight these to make sure that I didn't miss anything. Uh NSD we're doing that contract management audit I mentioned. The objective of that is to review the NSD contract process including administration management reporting oversight and monitoring to ensure that controls are established and operating effectively. This is currently in the fieldwork stage. We're getting good cooperation from NSD. Um, and do we have an estimate? June, >> April. Uh, we're looking at April for a release of this particular report. Uh, the parks bodywn camera audit, we just sent out the uh the kickoff notice for that, I believe, last week. So, that one uh now that we've done a couple of these will go rather quickly. Um the afteraction reviews these um I do hope that um we will have them wrapped up. Our plan is to have them presented at the April either audit committee or some other structure of a committee. Um I know that there's significant interest both by the public and the city council in these uh reviews. So, uh, we may, uh, work with the clerk in the attorney's office to combine committee meetings with the city council. Um, but more to come on that. So, please know it will either be at the April 20th audit committee or sometime around then. Shot spotter we talked about that's to analyze the effectiveness of that program. We are in the planning stages. We've reached out to notify on that audit as well. uh meet Minneapolis. We are doing preliminary background research in this particular audit. And uh we talked a little bit about the 65th Northroup contractor that we're working with on the workforce optimization and comparative benchmarking review. That too will be presented in April. So I will warn you we will have a very heavy April audit committee meeting which is another reason that possibly splitting out uh those afteraction reviews into a separate meeting might make sense. So uh as I mentioned we'll we'll share more once logistics are sorted out. All right, I will hand it over to um Sedartha Pudol, our internal audit director, who will cover uh the last couple items and then I will close out with uh some staffing and budget updates. >> Chair Payne and the members of the audit committee. So, right now we have uh two open investigations that we're working on right now. And regarding some of the prior audit issues, uh we have right now seven open audit issues which is so there's still not been remediated and the tentative um completion date has not been expired. So anytime it's not due yet, we put that in that bucket as open issues. Uh there are like 24 of them are overdue which is beyond that tentative um completion date and there are three audit issues that we received um uh in our um office and we're right now uh basically going through all the supporting documents and their memos to validate whether they have been completed or not. Uh so since the last audit committee meeting uh we have closed two of the issues um and majority of these uh overdue issues and the plan was to complete some of these MPD um open uh audit issues related to fleet management as well but due to um um the events that had been going on in the city um um we weren't able to at at least follow up um and try to complete that as them. Um but the plan was to do that [snorts] but since with the draw down of the ICE officers so hopefully we'll be able to um follow up uh with them to close some of these out because some of the open issues were related to MPD who were involved in that and NCR who were involved finance. So because of that they wanted to prioritize that work first uh and we agreed with them as well but we have been in constant touch to regarding some of these open issues. So we'll be closing more uh in the upcoming uh audit committee meeting. So the couple of our audit issues that we closed um is the first one is related to 2022 hiring and promotion process audit. Uh it was related to the appeals, grievance and other concerns. So right now we just have like one left uh regarding this um audit which we'll I'll cover in the next few slides. And the next one that we closed was 2023 revenue and collection phase one uh related to issue number two which was oversight and monitoring. So right now uh these are the list of all the reports with um at least one open audit issues. Um and uh per the recommendation of the audit committee uh we have started um highlighting all those open audit issues in detail. So you can see the audit uh and the issue number and the title and the issue rating and uh and the issue due date as well. So anytime it's overdue, we just put those at the status. Anything validation in progress, we also put that in the status and um and anything that has not due yet. So we just put that tentative um time or date that's they are due as well. So uh quickly going through some of these open audit issues. So the there are three open issues related to 2019 MPD off of duty work and MPD did provide that their update at the December 8th audit committee meeting. So as they made aware about some of these issues. So some of them is like are like technology related where in which like they're trying to actively resolve uh some of these issues and some of these like policy requirements and oversight and monitoring they will be working as well. Uh so there is one open issue related to 2021 uh personal work issued mobile device policies and controls audit. Uh so we've been working with the management uh to close that one issue with the data related to data governance as well. So related to 2022 hiring and promotion process audit. So there's only one open issue right now related to job studies and class maintenance studies. Uh so right now so the HR is trying to implement that new process. So for uh so basically we're just going to observe what's that completion would be at least at the end of the Q1 2026 and based on what they have implemented uh most likely either in April or June audit committee we should be able to close this one out and uh remove this u as a project right as an audit um so we'll be able to close all the issues related to this audit Um related to 2023 revenue and collection phase one audit we have two open issues uh issue number five asset safeguarding and security and also the mail handling. Um so some of these are partially completed. So basically we just waiting on that last portion of the pieces of the issue so that we can completely close them out. But management is working on completing these two issues right now. So the next one is related to 2023 sexual assault examination kit special project follow-up audit and these uh two issues are non-public. So we won't be able to discuss that in public but the management did uh provide that update uh in June 2nd 2025 audit committee meeting but um we'll be following up with this issue and also um so because these two issue and the MPD property management uh and evidence audit that those two issues are uh like in same vein. So uh we still have seven open issues related to these but we'll be working with management to resolve uh some of these issues as well. Uh so the next one is 2023 pecard spending audit. Um so there's only one open issue. Uh we're just waiting uh we know some of those work has already been done but basically we're just waiting from management to provide the official um memo that we normally require the management to complete as well as the supporting documents but we know for a fact uh so this work has been almost completed as well. So basically we're just waiting on uh some of that supporting documents for us to close this one out. And the next one is the 2024 MPD fleet management audit. So right now we have uh nine open issues um open right now and at least based on our conversation uh with uh one of the com commanders who is responsible on working some of these. So there are already some of the uh issues that has already been closed but we haven't received the appropriate supporting documents to officially close them out but we'll be working with uh them um in near future so that we can close some of these out for the next audit committee meeting. So the next one is related to 2024 NCR city funding to neighborhood organizational audit. Um so there is only one issue left for this one related to NCR risk assessment. Uh but we are working uh with them to close this one out. So the the due date for this one was um January 31st 2026. So, so um because of what they were prioritizing, uh we were not able to close this one out, but we'll be working with them to resolve this issue as well. And the next one is um the NPRB revenue and collection audit. So, this is the audit report um was issued during the December audit committee meeting and right now we have seven open issues. Um and most of these for for most of these issues um the completion tentative completion uh date is June either June 30th 2026 and December 31st 2026. Uh for issue number two policy and procedures uh because for most of these issues there are two part management action plan one from the finance department and another one from the IT department. So for the issue number two policy and procedures the I it's um tenative timeline was by end of the year 2025 which we already validated and they have already completed their piece but we're still waiting on management uh finance department to complete their portion of the management action plan which is not due until June 30th 2026. So once they do that we'll close this issue as a whole at that time. So that's why even though half of the work is complete, we will still keep that open. And now I'd like to inv uh just a comment um for the 24 overdue um items and you've related to this. Um, I know April sounds like a big meeting. Um, and I think whatever folks have needed to do to get through the last eight weeks or more, um, is what they need to do. So, I understand like dep prioritizing some of this, but if we could either via the meeting or otherwise just get a more um list by list update of some of those um that would be really helpful either at the um April meeting or after that just cuz several of these are still kind of in that bucket of 2019 and you know kind of some some older ones that I think would be helpful just to get more of a insight and then once again how can we as the committee help move those forward as well. Um, but yes, no expectation today after what has happened to have that move forward, but I think that shouldn't be a a continuous trend. Sure. >> As we try to work through those. So, thank you for that. >> Thank you. >> Seeing no other questions. All right. All right. Chair Payne Audit Committee. Um, just to close things out here, I wanted to provide a couple administrative updates. Uh, I introduced Jessica Peterson. I'd like to also introduce my Myra Hegley, who joins us from the city of Atlanta as an internal auditor, too. She has hit the ground running and is already um taking on efforts leading an audit project. Remind me which audit project you're starting. >> Oh, Meet Minneapolis. >> The Meet Minneapolis audit project. So thank you Myra for um being ready to go. Um Stephen Kofa also joined us recently as an auditor one. Uh he joins us from the private sector has already been pulled into a number of audits and so I am excited to have them both on board. Um, quickly as far as budget goes, I alluded to this, but formally I wanted to share that the um, the 2026 budget did fund 14 FTEES for the Office of City Auditor. Um, if you remember, we were uh, looking for 15 FTEEs and so I am incredibly grateful that we got as close as we did. Uh I'm grateful to the audit chair for his work in this area um as well as uh the city council and their support of our work. Uh the vacancies that we currently have are the director of special review and advisory services. So this was budgeted but we had to go back to the city council because of the um of the specific classification of this position. So the council just I believe last week approved that. So, it should be getting posted within the next week or two. Um, and then our last position uh is in development right now. It's an auditor 3 lead worker position. It will act as a lead worker over um supporting both of the divisions in the office. Um the final budget update is that our contractor working on the afteraction reviews um because of the uh significant amount of time that this um this review has taken, we do need to request some additional funding. So we will be doing that with the um city council in the next cycle. That would be um out of our existing 2026 budget. Uh and as I mentioned with this work, it will be presented in April. Um I will not go into these documents too much because you've got sorry you've got paper versions. I also shared them at our last uh organizational meeting. Um but I do want to get them into public record. It makes it a lot easier to link to them on our website. Um and so we've got the one pager which is on the screen. Uh we will have the organizational chart as well as our mission, vision, and value statement. That those will all get attached to the RCA after this meeting. Um just to wrap things up, I wanted to provide a uh a final reminder about email communications. The clerk's office has advised that we uh email just to city email addresses. So personal email addresses for audit committee members. Um although we occasionally still send you things just to make sure you get them. Uh please just make it uh a habit to check that at Minneapolis.gov email that you have. Um and then also as we always remind you, please don't reply all. We want to avoid any serial meetings. All right, that is it. That was uh enough for one day, I think. But if you have any questions related to the auditor updates, we'll stand for those now. Not seeing any. So, thank you for that presentation. >> Thank you. >> Uh, I'll ask the clerk to file that report and seeing no f further business to come before us. And without objection, I declare this meeting adjourned.