Audit Committee Meeting Summary - January 9, 2026
Audit Committee Meeting Summary - January 9, 2026
The Audit Committee convened on January 9, 2026, to review the Baker Tilly Water and Sewer Risk Assessment, approve the 2026 Internal Audit Plan, and adopt the revised Audit Advisory and Internal Audit Charters. The meeting also served as a forum to address public concerns regarding the Parrot Island Water Park's financial loss and determine the appropriate audit approach to restore public trust.
Consent Calendar
- Minutes: The minutes from the July 10 meeting were reviewed and unanimously approved via voice vote.
Public Comments & Testimony
- Citizen Concerns: A citizen (former board member) expressed strong alarm regarding a reported $385,000 loss at Parrot Island in 2025, questioning how a 300% swing from typical profits was achieved and why management was unaware of the issue prior to public disclosure. They highlighted a specific incident where an $8,000 check for a school event was misplaced by the management company.
- Trust and Oversight: The speaker expressed that public trust is eroding due to a lack of transparency and detailed reporting, noting that previous financial statements provided to the board were cursory and often lacked the detail needed to verify that tax dollars were being spent correctly.
- Recommendation: The speaker advocated for a thorough, third-party examination of the Water Park's operations and finances rather than relying on internal reviews, emphasizing that families and children who use the park have no one arguing on their behalf.
Discussion Items
- Baker Tilly Risk Assessment Presentation: Stacy Rush Bragg presented the draft risk assessment for the Water and Sewer utility departments. She detailed a methodology using surveys (85% management response rate, 43% staff response rate) and an audit universe to rate risks based on impact and likelihood. The top risk functional area identified was "Sewer system maintenance" with a critical score of 16. She proposed 11 potential audit areas, noting that while some align with the top risk areas, the risk matrix was intended to guide audits over a multi-year horizon rather than a single year's plan.
- Proposed 2026 Internal Audit Plan: Amanda Strange presented the 2026 Internal Audit Plan, developed by synthesizing the Baker Tilly risk assessment, historical audit data, and committee priorities. The plan outlines nine proposed audits with budgeted hours totaling approximately 3,400 of the 4,500 available capacity, leaving room for unplanned investigative work. The committee noted that hour estimates are preliminary for non-financial audits and discussed the need for a software tool to track progress against the plan.
- Charter Revisions: The committee reviewed and approved minor revisions to both the Audit Advisory Committee Charter and the Internal Audit Charter. Changes included:
- Audit Advisory Charter: Revising meeting frequency language from "will meet up to five times" to "intends to meet a minimum of five times" and adding a requirement to receive quarterly updates on the status of the annual audit plan.
- Internal Audit Charter: Adding a specific requirement for the annual filing of disclosure forms to maintain independence and changing the word "assume" to "ensure" regarding the confidentiality of records.
- Parrot Island Water Park Audit Strategy: The committee and external auditor David discussed how to proceed following reports of financial irregularities. While the board requested a financial statement audit, the auditor advised that an "Agreed Upon Procedures" (AUP) engagement is more appropriate immediately to address specific concerns about cash receipts, disbursements, and operational controls without the scope limitations of a traditional audit. The committee decided to have the AUPs drafted, reviewed by the board at a study session, and voted on by the full Board of Directors before engagement.
Key Outcomes
- Risk Assessment: The Baker Tilly risk assessment report was accepted, with the committee requesting further linkage between the proposed audits and the identified high-risk functional areas (e.g., sewer system maintenance) to ensure clarity.
- 2026 Audit Plan: The 2026 Internal Audit Plan was approved by the committee to be forwarded to the full Board of Directors for formal adoption.
- Charter Approval: The revised Audit Advisory Committee and Internal Audit Charters were approved by the committee and will be recommended for Board approval with the specified changes.
- Water Park Action Item: The committee directed Internal Audit Director Amanda Strange to finalize the proposed Agreed Upon Procedures for the Water Park based on committee input and present them at the next study session for Board review and vote. The audit is anticipated to occur during the week of March 30th if approved.
- Next Meeting: A follow-up committee meeting is scheduled for late March or early April 2026 to review internal audit progress and the status of the Water Park AUPs.
Meeting Transcript
And on the roll call, we're gonna use it just a little bit different. Um, just because we are reporting and to make sure that we have clarity on our recordings. I'm gonna ask your things over on the room and just say your name and position that way can we do the voice with the voice you recording that's clear if you speaking. So I'm Dina Infield, I'm chair of the committee, and I'm a citizen member. Russell Bragg, uh citizen member Lacretia Parkinson's staff auditor. Amanda Strange, director of internal audit Christie Fisher staff auditor's chief financial officer, Neil Martin board member Christina Gassava City Director. Thank you all. Um has provided the um agenda for the meeting and first on the agenda is approval and the minutes from the July 10th meeting. Those were sent around to if there are any changes to those of those or accept a motion to make those approved. So moved. So all in favor say aye. Aye, aye. Those minutes are considered approved. So next on the agenda is the draft of the um water and sewer risk assessment by silly and SICE is electronic and is going to use on the call and is going to go over the draft report with us. Hey Stacy. Yes, hi there, hi everyone, committee members. Thanks so much for having me. Um I am going to share my screen. I will walk through the PowerPoint report that you should have a copy of. As I'm going through, if there's any questions, um, you know, it may get answered in subsequent slides, but um if anything's really top of mind, feel free to just jump in um and interrupt. Okay. All right. So we conducted the risk assessment of the water and sewer utility departments. The scope of this was just within those two departments, and our objective here was to get a comprehensive perspective on risk that could potentially impact the strategic objectives specific to those departments, um, get insights into any opportunities, challenges, um, you know, or concerns as it relates to the various types of risk. So this you know could encompass strategic risk, financial risk, operational compliance, public perception technology kind of across the board. Um then lastly, it was to identify and be able to prioritize risk across these departments to propose potential audits to be conducted in the future by internal audit. Our approach for this, um, we pulled together a survey, one for management and one for employees designated within those departments as well as at the upper management level to you know gain um sort of insights into the different functional areas, um, you know, what any potential issues, concerns, um, existing risks, uh, kind of the critical things that could potentially impact those areas in consideration of you know what the ultimate um purpose, intention, and objectives are for each of those areas. We also had some subsequent um meetings, both with members of management employees, and spoke with um uh a number of the audit committee members. We took the information that we gathered both obtained from the survey, interviews, as well as um some you know key background documentation that we gathered to really get an understanding of what are those areas where there are um those more high priority risks. So the way that we did this is we developed what we call an audit universe, and that's really kind of starting with um within the departments. So the way that we did this is we developed what we call an audit universe, and that's really kind of starting within the departments, what are the key functional areas within those departments? And then we have a structured risk rating methodology. So I'll get into that a little more later, but but that's really what we're using to conduct the risk assessment and to try and you know prioritize those risk that we identify across the board. We used the information gathered from the survey, you know, pulled themes based on responses. We leveraged you know things that we've seen kind of just within the industry that are top risk and top of mind and use that to you know incorporate into what we call our risk matrix matrix to be able to prioritize those risks. So the way that we know assess risks is really based on a methodology that considers the impact and the likelihood of risk that exist. So the impact is thinking through, you know, what would be the impact, what would be the severity of the consequences if these risk events were to occur, and then the likelihood would consider you know how probable is it that this risk event could happen. So taking those two components, we come up with an overall risk score. The survey results within this portion of the report, uh, it's just reporting and showing you a little insight into you know some of the more general survey questions, what those results looked like. Um I'll go through this a little quickly, but if you have any questions, please let me know. But this is really, you know, just gonna show you some graphs in terms of what responses were to some of these more general questions that we had. So as far as the survey responses, like I said, we had a survey that went out to members of management, as well as a survey that went out to other lower levels employees. So we had received 28 responses to the management survey and 81 staff responses. So we got about an 85% response rate on the management one and 43% response rate on staff. Some of the general responses that we got, you'll see here on the left, it's kind of showing, you know, in general we asked, you know, what they see as kind of the top five risk areas for these departments, and um across the board, the staff you can kind of see from one to 10 what those top areas were: reputation, planning, budgeting, economy, leadership, and citizen demands. Um, and then on the right, that's sort of the management responses where you will see kind of a lot of similar themes across the two. The second one is um, you know, where have there been areas of significant change? So change is definitely something to consider when you're assessing risk and thinking about it. So this is sort of what the responses looked like. Obviously, having just recently gone through a change in org structure, um, that was the top area that participants noted.
openpublica.com