Loading...
HomeMy WebLinkAbout2026-07-07; City Council; Resolution 2026-150Exhibit 1 RESOLUTION NO. 2026-150 . A RESOLUTION OF THE CITY COUNCIL OF THE CITY OF CARLSBAD, CALIFORNIA, APPROVING THE FISCAL YEAR 2026-27 INTERNAL AUDIT PLAN WHEREAS, the City Council of the City of Carlsbad, California, has determined that the Internal Audit Manager performs independent and objective assurance services to safeguard city resources and improve city operations; and WHEREAS, the services provided may include internal audits of any city department, division, function or program; and WHEREAS, as required by City Council Policy No. 89, the Internal Audit Manager has presented a Fiscal Year 2026-27 Internal Audit Plan (Attachment A) for the City Council’s review and approval; and WHEREAS, the purpose of the Internal Audit Plan is to outline internal audits and other value- added engagements the Internal Audit Manager proposes to conduct during the fiscal year; and WHEREAS, the Fiscal Year 2026-27 Internal Audit Plan includes information about the basis for audit engagement selection, preliminary objectives and the consideration of resources; and WHEREAS, once approved, the Fiscal Year 2026-27 Internal Audit Plan will serve as the operating roadmap for the city’s Internal Audit Manager. NOW, THEREFORE, BE IT RESOLVED by the City Council of the City of Carlsbad, California, as follows: 1.That the above recitations are true and correct. 2. That the proposed action is not a “project” as defined by California Environmental Quality Act, or CEQA, Section 21065 and CEQA Guidelines Section 15378(b)(5) and does not require environmental review under CEQA Guidelines Sections 15060(c)(3) and 15061(b)(3) because the proposed action to adopt the Fiscal Year 2026-27 Internal Audit Plan is an organizational or administrative government activity that does not involve any commitment to any specific project which may result in a potentially significant physical impact on the environment. Any subsequent action or direction stemming from the proposed action may require preparation of an environmental document in accordance with CEQA or the CEQA Guidelines. 3.That the City Council approves the Fiscal Year 2026-27 Internal Audit Plan in Attachment A. July 7, 2026 Item #14 Page 6 of 55 Docusign Envelope ID: B440FDA8-718D-84DD-82F0-778AAAED673E PASSED, APPROVED AND ADOPTED at a Regular Meeting of the City Council of the City of Carlsbad on the 7th day of July, 2026, by the following vote, to wit: AYES: Blackburn, Bhat-Patel, Acosta, Burkholder, Shin. NAYS: None. ABSTAIN: None. ABSENT: None. ______________________________________ KEITH BLACKBURN, Mayor ______________________________________ SHERRY FREISINGER, City Clerk (SEAL) July 7, 2026 Item #14 Page 7 of 55 Docusign Envelope ID: B440FDA8-718D-84DD-82F0-778AAAED673E Attachment A CITY OF CARLSBAD Internal Audit Plan for Fiscal Year 2026-27 Overview City Council Policy 89, Internal Audit Framework, requires the Internal Audit Division to prepare an annual internal audit plan and to submit it to the City Manager and City Council for review and approval. The plan includes a listing of audits scheduled for FY 2026-27 and other work performed by the Internal Audit Division. The previous fiscal year’s plan involved a detailed risk assessment which yielded more potential audit topics than can be completed in one year with current audit resources. Consequently, another risk assessment was not needed this year. Work for FY 2026-27 includes three performance audits, oversight of the transit occupancy tax audit and administration of the Fraud, Waste and Abuse Hotline. This report provides an overview of the risk assessment and audit selection processes, the resources (time) available for the Internal Audit Division, and budget estimates for the proposed audits and other work. In keeping with City Council Policy 89, the plan is flexible and includes unallocated audit hours to accommodate any subsequent requests for work from the City Manager or City Council. If such work is substantial, the plan can be amended, and the City Council will be informed of any impact on audit schedules. July 7, 2026 Item #14 Page 8 of 55 Docusign Envelope ID: B440FDA8-718D-84DD-82F0-778AAAED673E 2 How areas are selected for audit •Is the area or risk event within the competency of Internal Audit and the jurisdiction of the City of Carlsbad? 1. Is the area amenable to audit? •Are there large, adverse potential impacts on the city's finances, or on the health, safety, security and welfare of our residents? 2. Evaluate inherent risks •Mitigating factors: Stability of a function; strong internal controls; favorable, recent prior audit findings, other oversight. •Exacerbating factors:Significant economic, regulatory, or technological changes; high staff turnover; City Council and management concerns. 3. Consider additional factors •Research issues and audit findings at similar municipalities •Discuss potential audit areas with Deputy City Managers, Chiefs, Department Directors and staff. 4. Identify potential audit areas •Solicit additional mangement and leadership feedback. •Consider audit resources and schedules constraints. •Obtain City Manger and City Council approval. 5. Develop an annual audit plan medium Communicate risks, if changes July 7, 2026 Item #14 Page 9 of 55 Docusign Envelope ID: B440FDA8-718D-84DD-82F0-778AAAED673E 3 Considerations in audit selection • Auditable areas Although some areas may be exposed to various risks, they may not be auditable if they fall outside the jurisdiction of a city and involve state or federal activities or international events. For example, there is little a city can do to mitigate the risk of an oil spill in the ocean, even though it may have to contend with a prolonged and costly beach cleanup. • Inherent risk Inherent risk is the natural level of risk that exists within a place or activity. Risk can be assigned to departments, programs and processes. For example, a municipal skate park carries an inherent risk of injury to skaters. Factors that impact the assessed level of risk include the size of an area, measured by budgeted personnel expenses, operational costs and the number of employees employed within it; the nature of the work and potential impact on public health, safety and security; and the prospect of a large financial loss (whether acute or long-term). • Mitigating or exacerbating factors Some activities and events can modify the level of risk. Continuing with the prior example about the skate park, the frequency and severity of injuries can be reduced by requiring skaters to wear protective helmets, elbow pads and knee guards. In general, significant economic, staffing, regulatory, or technological changes in an area tend to raise the level of risk because breakdowns are more likely to occur during transitional periods. • Identify potential audit areas Potential audit areas are identified by reviewing City Council meeting agendas, prior internal audit reports at the City of Carlsbad and other government agencies and soliciting input from the City Manager, deputy city managers and department directors and City Council members. • Audit resources One full-time auditor can provide approximately 1,500 audit hours annually, with other time allocated to administrative work and required continuing professional education. Budgeting for performance audits entails informed guesswork, as each audit subject differs from previous ones. In contrast, budgeting for annual financial and compliance audits tend to be accurate because they are based on past budgets and can build on previous work. After their initial creation, financial and compliance audit plans and procedures require minimal modification – except when there are significant changes in regulations or systems. July 7, 2026 Item #14 Page 10 of 55 Docusign Envelope ID: B440FDA8-718D-84DD-82F0-778AAAED673E 4 Proposed internal audits for fiscal year 2026-27 Category Hours Transit Occupancy Tax – Oversight 160 Utilities – Wastewater Operations 400 Library and Cultural Arts 400 Worker’s Compensation 320 220 Total audit hours 1,500 The audit budgets are built by adding weekly estimates of various audit phases: planning and research, evidence gathering, analysis, report writing and quality control and review. The audits in this plan are estimated to take 8 to 12 weeks. Transient Occupancy Tax The city contracts with a public accounting firm to audit a sample of businesses every year to ensure that hotels and other businesses are properly accounting for and remitting transit occupancy taxes. The internal auditor provides oversight of the contractor and facilitates their work. The three performance audits listed met the selection threshold of $5 million or 10 full-time equivalent personnel established in the risk assessment. A further discussion of auditable topics and issues within these areas is presented below. Utilities – Wastewater Operations Audits of wastewater and sewer operations across California municipalities generally show that agencies comply with regulatory requirements such as maintaining Sewer System Management Plans, but that they face ongoing challenges in the management of aging infrastructure. • Wastewater systems consist of wastewater treatment plants and hundreds of miles of pipelines that require significant long-term investment. However, condition assessments and capital planning are frequently incomplete or not fully aligned with actual system risk. • The prevention of sewer system overflows remains the primary indicator of system performance and regulatory compliance. But even well-managed systems experience overflows due to root intrusion, grease buildup, and wet-weather inflow, underscoring the importance of robust preventive maintenance programs and accurate, data-driven monitoring. July 7, 2026 Item #14 Page 11 of 55 Docusign Envelope ID: B440FDA8-718D-84DD-82F0-778AAAED673E 5 • Audits frequently identify gaps in maintenance practices, data quality, and the use of technology, all of which can limit an agency’s ability to proactively manage risk. • Finally, audits highlight broader governance and operational issues, including delays in capital project delivery, underutilization of budgets, and the need for clearer policies and procedures. Library and Cultural Arts Audits of libraries and the programs that they oversee often encompass administrative matters such as governance, best practices, policies and procedures, resource levels (i.e. funding and staffing), resource utilization (operating hours and scheduling), as well as community engagement. Safety and security, performance measures, and facility conditions are other areas that may be covered. More technical audit topics include digital services and technology usage, cybersecurity and patron privacy, collection management, and analytics. Worker’s Compensation Audits of workers’ compensation programs in California find that errors in claims handling are common and can have significant financial and legal consequences. Workers’ compensation systems are inherently prone to operational errors due to regulatory complexity, high claim volumes, and reliance on third-party administrators. Missing statutory deadlines can result in penalties and corrective actions. Even large, well-resourced agencies can struggle with the complexity of claims administration. Late payments, improper benefit calculations, and inconsistent adherence to statutory requirements are common findings. Pooled risk authorities conduct detailed file reviews of claims and score performance against key indicators, demonstrating that compliance monitoring remains necessary even in mature programs. Recommendations include strengthening internal controls, better monitoring of third-party administrators, and improved financial reporting to ensure that costs are properly managed and liabilities are accurately estimated. Staff turnover, inadequate training, and lax oversight can contribute to uneven performance across departments or claim handlers, further increasing the risk of noncompliance and cost escalation. Using workers’ compensation claims data as a feedback loop for risk management is one of the areas where audits find unrealized value. Many agencies are effective at processing claims but do not analyze claims data to prevent future injuries. This data can reveal patterns such as recurring injuries in specific job classifications (e.g., maintenance workers, police, fire), common injury types (strains, slips, repetitive motion), or high-risk locations and tasks. Yet audits frequently reveal that this information is either underutilized or siloed within third-party administrators, with limited integration into broader safety or operational decision-making. By identifying trends—such as frequent back injuries tied to manual lifting, or slip-and-fall incidents concentrated in certain facilities—organizations can implement targeted interventions: ergonomic improvements, revised work procedures, enhanced training, or facility upgrades. Difficulties in proactively managing worker’s compensation programs result July 7, 2026 Item #14 Page 12 of 55 Docusign Envelope ID: B440FDA8-718D-84DD-82F0-778AAAED673E 6 from poor data quality, inconsistent coding of injury types and causes, lack of analytical tools, and limited staff capacity to perform trend analysis. Additionally, when claims administration is outsourced, municipalities may not receive timely or sufficiently detailed data to support meaningful analysis. July 7, 2026 Item #14 Page 13 of 55 Docusign Envelope ID: B440FDA8-718D-84DD-82F0-778AAAED673E