HomeMy WebLinkAbout2026-07-07; City Council; Resolution 2026-150Exhibit 1 RESOLUTION NO. 2026-150 .
A RESOLUTION OF THE CITY COUNCIL OF THE CITY OF CARLSBAD,
CALIFORNIA, APPROVING THE FISCAL YEAR 2026-27 INTERNAL AUDIT PLAN
WHEREAS, the City Council of the City of Carlsbad, California, has determined that the Internal
Audit Manager performs independent and objective assurance services to safeguard city resources and
improve city operations; and
WHEREAS, the services provided may include internal audits of any city department, division,
function or program; and
WHEREAS, as required by City Council Policy No. 89, the Internal Audit Manager has presented
a Fiscal Year 2026-27 Internal Audit Plan (Attachment A) for the City Council’s review and approval; and
WHEREAS, the purpose of the Internal Audit Plan is to outline internal audits and other value-
added engagements the Internal Audit Manager proposes to conduct during the fiscal year; and
WHEREAS, the Fiscal Year 2026-27 Internal Audit Plan includes information about the basis for
audit engagement selection, preliminary objectives and the consideration of resources; and
WHEREAS, once approved, the Fiscal Year 2026-27 Internal Audit Plan will serve as the
operating roadmap for the city’s Internal Audit Manager.
NOW, THEREFORE, BE IT RESOLVED by the City Council of the City of Carlsbad, California, as
follows:
1.That the above recitations are true and correct.
2. That the proposed action is not a “project” as defined by California Environmental
Quality Act, or CEQA, Section 21065 and CEQA Guidelines Section 15378(b)(5) and does
not require environmental review under CEQA Guidelines Sections 15060(c)(3)
and 15061(b)(3) because the proposed action to adopt the Fiscal Year 2026-27 Internal
Audit Plan is an organizational or administrative government activity that does not
involve any commitment to any specific project which may result in a potentially
significant physical impact on the environment. Any subsequent action or direction
stemming from the proposed action may require preparation of an environmental
document in accordance with CEQA or the CEQA Guidelines.
3.That the City Council approves the Fiscal Year 2026-27 Internal Audit Plan in Attachment
A.
July 7, 2026 Item #14 Page 6 of 55
Docusign Envelope ID: B440FDA8-718D-84DD-82F0-778AAAED673E
PASSED, APPROVED AND ADOPTED at a Regular Meeting of the City Council of the City
of Carlsbad on the 7th day of July, 2026, by the following vote, to wit:
AYES: Blackburn, Bhat-Patel, Acosta, Burkholder, Shin.
NAYS: None.
ABSTAIN: None.
ABSENT: None.
______________________________________
KEITH BLACKBURN, Mayor
______________________________________
SHERRY FREISINGER, City Clerk
(SEAL)
July 7, 2026 Item #14 Page 7 of 55
Docusign Envelope ID: B440FDA8-718D-84DD-82F0-778AAAED673E
Attachment A
CITY OF CARLSBAD
Internal Audit Plan for Fiscal Year 2026-27
Overview
City Council Policy 89, Internal Audit Framework, requires the Internal Audit Division to prepare
an annual internal audit plan and to submit it to the City Manager and City Council for review
and approval. The plan includes a listing of audits scheduled for FY 2026-27 and other work
performed by the Internal Audit Division. The previous fiscal year’s plan involved a detailed risk
assessment which yielded more potential audit topics than can be completed in one year with
current audit resources. Consequently, another risk assessment was not needed this year.
Work for FY 2026-27 includes three performance audits, oversight of the transit occupancy tax
audit and administration of the Fraud, Waste and Abuse Hotline.
This report provides an overview of the risk assessment and audit selection processes, the
resources (time) available for the Internal Audit Division, and budget estimates for the
proposed audits and other work.
In keeping with City Council Policy 89, the plan is flexible and includes unallocated audit hours
to accommodate any subsequent requests for work from the City Manager or City Council. If
such work is substantial, the plan can be amended, and the City Council will be informed of any
impact on audit schedules.
July 7, 2026 Item #14 Page 8 of 55
Docusign Envelope ID: B440FDA8-718D-84DD-82F0-778AAAED673E
2
How areas are selected for audit
•Is the area or risk event within the competency of Internal Audit and the jurisdiction of the City of Carlsbad?
1. Is the area amenable to audit?
•Are there large, adverse potential impacts on the city's finances, or on the health, safety, security and welfare of our residents?
2. Evaluate inherent risks
•Mitigating factors: Stability of a function; strong internal controls; favorable, recent prior audit findings, other oversight.
•Exacerbating factors:Significant economic, regulatory, or technological changes; high staff turnover; City Council and management concerns.
3. Consider additional factors
•Research issues and audit findings at similar municipalities
•Discuss potential audit areas with Deputy City Managers, Chiefs, Department Directors and staff.
4. Identify potential audit areas
•Solicit additional mangement and leadership feedback.
•Consider audit resources and schedules constraints.
•Obtain City Manger and City Council approval.
5. Develop an annual audit plan
medium
Communicate
risks, if
changes
July 7, 2026 Item #14 Page 9 of 55
Docusign Envelope ID: B440FDA8-718D-84DD-82F0-778AAAED673E
3
Considerations in audit selection
• Auditable areas
Although some areas may be exposed to various risks, they may not be auditable if they fall
outside the jurisdiction of a city and involve state or federal activities or international
events. For example, there is little a city can do to mitigate the risk of an oil spill in the
ocean, even though it may have to contend with a prolonged and costly beach cleanup.
• Inherent risk
Inherent risk is the natural level of risk that exists within a place or activity. Risk can be
assigned to departments, programs and processes. For example, a municipal skate park
carries an inherent risk of injury to skaters.
Factors that impact the assessed level of risk include the size of an area, measured by
budgeted personnel expenses, operational costs and the number of employees employed
within it; the nature of the work and potential impact on public health, safety and security;
and the prospect of a large financial loss (whether acute or long-term).
• Mitigating or exacerbating factors
Some activities and events can modify the level of risk. Continuing with the prior example
about the skate park, the frequency and severity of injuries can be reduced by requiring
skaters to wear protective helmets, elbow pads and knee guards.
In general, significant economic, staffing, regulatory, or technological changes in an area
tend to raise the level of risk because breakdowns are more likely to occur during
transitional periods.
• Identify potential audit areas
Potential audit areas are identified by reviewing City Council meeting agendas, prior
internal audit reports at the City of Carlsbad and other government agencies and soliciting
input from the City Manager, deputy city managers and department directors and City
Council members.
• Audit resources
One full-time auditor can provide approximately 1,500 audit hours annually, with other
time allocated to administrative work and required continuing professional education.
Budgeting for performance audits entails informed guesswork, as each audit subject differs
from previous ones. In contrast, budgeting for annual financial and compliance audits tend
to be accurate because they are based on past budgets and can build on previous work.
After their initial creation, financial and compliance audit plans and procedures require
minimal modification – except when there are significant changes in regulations or systems.
July 7, 2026 Item #14 Page 10 of 55
Docusign Envelope ID: B440FDA8-718D-84DD-82F0-778AAAED673E
4
Proposed internal audits for fiscal year 2026-27
Category Hours
Transit Occupancy Tax – Oversight 160
Utilities – Wastewater Operations 400
Library and Cultural Arts 400
Worker’s Compensation 320
220
Total audit hours 1,500
The audit budgets are built by adding weekly estimates of various audit phases: planning and
research, evidence gathering, analysis, report writing and quality control and review. The audits
in this plan are estimated to take 8 to 12 weeks.
Transient Occupancy Tax
The city contracts with a public accounting firm to audit a sample of businesses every year to
ensure that hotels and other businesses are properly accounting for and remitting transit
occupancy taxes. The internal auditor provides oversight of the contractor and facilitates their
work.
The three performance audits listed met the selection threshold of $5 million or 10 full-time
equivalent personnel established in the risk assessment. A further discussion of auditable topics
and issues within these areas is presented below.
Utilities – Wastewater Operations
Audits of wastewater and sewer operations across California municipalities generally show that
agencies comply with regulatory requirements such as maintaining Sewer System Management
Plans, but that they face ongoing challenges in the management of aging infrastructure.
• Wastewater systems consist of wastewater treatment plants and hundreds of miles of
pipelines that require significant long-term investment. However, condition assessments
and capital planning are frequently incomplete or not fully aligned with actual system risk.
• The prevention of sewer system overflows remains the primary indicator of system
performance and regulatory compliance. But even well-managed systems experience
overflows due to root intrusion, grease buildup, and wet-weather inflow, underscoring the
importance of robust preventive maintenance programs and accurate, data-driven
monitoring.
July 7, 2026 Item #14 Page 11 of 55
Docusign Envelope ID: B440FDA8-718D-84DD-82F0-778AAAED673E
5
• Audits frequently identify gaps in maintenance practices, data quality, and the use of
technology, all of which can limit an agency’s ability to proactively manage risk.
• Finally, audits highlight broader governance and operational issues, including delays in
capital project delivery, underutilization of budgets, and the need for clearer policies and
procedures.
Library and Cultural Arts
Audits of libraries and the programs that they oversee often encompass administrative matters
such as governance, best practices, policies and procedures, resource levels (i.e. funding and
staffing), resource utilization (operating hours and scheduling), as well as community
engagement. Safety and security, performance measures, and facility conditions are other
areas that may be covered. More technical audit topics include digital services and technology
usage, cybersecurity and patron privacy, collection management, and analytics.
Worker’s Compensation
Audits of workers’ compensation programs in California find that errors in claims handling are
common and can have significant financial and legal consequences. Workers’ compensation
systems are inherently prone to operational errors due to regulatory complexity, high claim
volumes, and reliance on third-party administrators. Missing statutory deadlines can result in
penalties and corrective actions. Even large, well-resourced agencies can struggle with the
complexity of claims administration. Late payments, improper benefit calculations, and
inconsistent adherence to statutory requirements are common findings.
Pooled risk authorities conduct detailed file reviews of claims and score performance against
key indicators, demonstrating that compliance monitoring remains necessary even in mature
programs.
Recommendations include strengthening internal controls, better monitoring of third-party
administrators, and improved financial reporting to ensure that costs are properly managed
and liabilities are accurately estimated. Staff turnover, inadequate training, and lax oversight
can contribute to uneven performance across departments or claim handlers, further increasing
the risk of noncompliance and cost escalation.
Using workers’ compensation claims data as a feedback loop for risk management is one of the
areas where audits find unrealized value. Many agencies are effective at processing claims but
do not analyze claims data to prevent future injuries. This data can reveal patterns such as
recurring injuries in specific job classifications (e.g., maintenance workers, police, fire), common
injury types (strains, slips, repetitive motion), or high-risk locations and tasks. Yet audits
frequently reveal that this information is either underutilized or siloed within third-party
administrators, with limited integration into broader safety or operational decision-making.
By identifying trends—such as frequent back injuries tied to manual lifting, or slip-and-fall
incidents concentrated in certain facilities—organizations can implement targeted
interventions: ergonomic improvements, revised work procedures, enhanced training, or
facility upgrades. Difficulties in proactively managing worker’s compensation programs result
July 7, 2026 Item #14 Page 12 of 55
Docusign Envelope ID: B440FDA8-718D-84DD-82F0-778AAAED673E
6
from poor data quality, inconsistent coding of injury types and causes, lack of analytical tools,
and limited staff capacity to perform trend analysis. Additionally, when claims administration is
outsourced, municipalities may not receive timely or sufficiently detailed data to support
meaningful analysis.
July 7, 2026 Item #14 Page 13 of 55
Docusign Envelope ID: B440FDA8-718D-84DD-82F0-778AAAED673E