top of page

Why Government Audit Findings Continue to Repeat: How Public Entities Can Reduce Their Risk

  • Writer: Michael J. Caparotta
    Michael J. Caparotta
  • Jul 16
  • 4 min read

Government audit findings are rarely the result of a single major mistake. They often develop over time as routine internal controls become inconsistent due to limited staffing, competing priorities, and increasing compliance requirements.


While every public entity faces unique operational challenges, certain internal control deficiencies appear year after year. According to Griffin & Furman Partner Mike Caparotta, these findings often stem from resource constraints rather than a lack of knowledge.


"Most public entities understand what good internal controls look like," Mike says. "The challenge is having the time and resources to consistently maintain those controls while managing daily operations."


Below are five of the most common internal control deficiencies identified during government audits and practical ways organizations can strengthen them before audit season.


1. Segregation of Duties


Of all the internal control issues encountered during government audits, segregation of duties remains one of the most common.


Smaller municipalities and public entities often rely on a limited number of employees to perform multiple financial responsibilities. One individual may receive payments, process transactions, reconcile bank accounts, and prepare financial reports simply because there are not enough staff members to divide those responsibilities.


"Limited staffing makes proper segregation of duties difficult. One person often ends up performing several key financial functions, which increases the risk that errors or even fraud may go undetected." (Mike Caparotta) 


When additional staffing is not feasible, organizations should implement compensating controls. These may include requiring dual signatures for larger disbursements, establishing secondary approval processes, and providing governing boards with detailed financial reports to increase oversight without significantly increasing costs.


2. Grant Documentation


As federal and state grant funding has increased in recent years, so have documentation and compliance requirements.


Grant-related findings frequently occur because supporting documentation is incomplete, reporting deadlines are missed, or required records are not maintained throughout the grant period.


According to Mike, organizations should view grant documentation as an ongoing process rather than something completed at year-end.


"Grant compliance doesn't begin when the auditors arrive. Maintaining organized records throughout the year makes the audit process much smoother and significantly reduces compliance risk."  


Establishing document retention procedures, maintaining organized grant files, and assigning responsibility for grant reporting can help prevent findings.


3. Cybersecurity and Access Controls


Cybersecurity continues to be one of the fastest-growing areas of risk for government organizations. Shared user accounts, excessive system permissions, and inadequate approval procedures can create opportunities for fraud and unauthorized transactions.


Mike has also seen phishing attempts become increasingly sophisticated.


"We've seen situations where employees received what appeared to be legitimate emails requesting wire transfers from someone posing as the CFO," he says. "The emails looked authentic, and without additional verification procedures, the transactions were processed before anyone realized they were fraudulent."


Regular access reviews, multi-factor authentication, independent wire transfer approvals, and ongoing employee training should all be considered essential components of a strong internal control environment.


4. Bank Reconciliations


Timely bank reconciliations remain one of the most effective internal controls available to public entities.


When reconciliations are delayed, accounting errors, unauthorized transactions, and fraudulent activity can remain undetected for extended periods.


Mike recalls one situation where routine reconciliation procedures identified approximately $10,000 in stolen cash from toll collections. Although the reconciliation ultimately uncovered the theft, the incident also highlighted the importance of preventive controls.


"The reconciliation detected the issue. The lesson was that stronger preventive controls, such as camera monitoring and additional oversight, could have prevented the theft from occurring in the first place." (Mike Caparotta)


Strong internal controls should not only identify problems after they occur but also reduce the likelihood of those problems happening in the first place.


5. Policies and Procedures


Well-written policies provide accountability and guidance for employees responsible for financial operations.


Unfortunately, policies are often updated after an audit finding rather than being reviewed as part of an ongoing governance process. As regulations evolve and operations change, outdated policies and procedures can create unnecessary compliance risks.


Organizations should regularly review financial policies, document changes to internal processes, and ensure employees understand current procedures.


The Most Effective Time to Address Findings


A common mistake public entities make is treating audit findings as an annual exercise instead of an ongoing improvement process.


"Too often, organizations finish the audit, address the findings, and then don't revisit them until the following year. The entities that see the greatest improvement are the ones that implement corrective actions immediately and continue monitoring those controls throughout the year." (Mike Caparotta) 


 It is also important to communicate regularly with your auditors as new accounting standards and regulatory requirements emerge so management can evaluate their impact and implement any necessary changes.


Building Stronger Internal Controls Year-Round


Strong internal controls do more than support a successful audit. They protect public funds, improve operational efficiency, strengthen accountability, and build confidence among governing boards and taxpayers.


At Griffin & Furman, we work alongside government entities throughout the year to help strengthen internal controls, improve financial oversight, and reduce the likelihood of audit findings before they occur. By taking a proactive approach, organizations can spe

nd less time responding to deficiencies and more time serving their communities.


Comments


205 E Lockwood St., Covington, LA 70433 |  985-727-9924

Photography by JSB Productions, LLC

© 2023 by Griffin & Furman, LLC and secured by Wix

Clean Biz Partnership BW
  • Facebook
  • Instagram
  • LinkedIn
bottom of page