- The Town Board did not adequately design, implement, or monitor internal controls over the town’s financial activities. The supervisor did not provide effective oversight of the work performed by the bookkeeper to address her incompatible financial duties. Because the bookkeeper can initiate transactions, make accounting entries, and perform bank reconciliations without any supervision, there is a risk that she could initiate and conceal inappropriate transactions that could go undetected and uncorrected. Further, the Board did not conduct an annual audit of the records of officials and employees who receive and disburse cash. The Board’s failure to perform an annual audit diminishes its ability to effectively monitor the town’s financial operations and could result in errors or irregularities that are undetected and uncorrected.
- The Board did not design and implement policies over online banking that would have ensured the protection of the town’s assets and data. The town did not establish a written policy for online banking that defined the Board’s intentions. While the town’s bank has an “Internet User Agreement,” town officials were unaware of its provisions or that it existed. The bank’s agreement did not address which town officials were authorized to initiate online transfers or security procedures for authenticating transactions. Without a comprehensive online banking policy, it is possible that an unauthorized individual could initiate an online transfer and that it would remain undetected and uncorrected.
- The supervisor has not adequately segregated the bookkeeper’s online banking duties. Also, the supervisor had not reviewed or supervised the bookkeeper’s online banking transactions totaling more than $1.8 million made during the first six months of 2012. In addition, the town has not established a confirmation process with its bank for online transfers of town moneys. Although we did not find any discrepancies with the $1.8 million in online transfers, because the bookkeeper’s incompatible online banking duties are not adequately segregated, there is an increased risk that moneys may be transferred improperly, or that online transfers will not be properly recorded and documented.
- The audit disclosed additional areas in need of improvement concerning IT controls, which, because of their confidential nature, were disclosed separately to town officials.
(Continued on Next Page)