Audit Committee
The full agenda, as filed
All 15 items in the clerk’s order. Each carries the city’s own words: the staff recommendation, what the body decided, and its status. Nothing below is written by us.
AU8.1amended
Election of Chair - Audit Committee
Election of the Chair of the Audit Committee under Municipal Code Chapter 27, Council Procedures, Appendix A-2, for a term of office starting February 16, 2021 and ending November 14, 2022.
The Audit Committee: 1. Elected Councillor Stephen Holyday as Chair of the Audit Committee for a term of office starting February 16, 2021 and ending November 14, 2022.
AU8.2amended
Election of Vice Chair - Audit Committee
Election of the Vice Chair of the Audit Committee under Municipal Code Chapter 27, Council Procedures, Appendix A-2, for a term of office starting February 16, 2021 and ending November 14, 2022.
The Audit Committee: 1. Elected Councillor John Filion as Vice Chair of the Audit Committee for a term of office starting February 16, 2021 and ending November 14, 2022.
AU8.3adopted
Auditor General's 2020 Annual Report - Demonstrating the Value of the Auditor General's Office
This report provides information on the Auditor General's Office 2020 activities and financial and non-financial benefits achieved by the City through its implementation of report recommendations. In 2020, the Auditor General's Office completed 7 audit and investigative and several other reports. We managed the City's Fraud and Waste Hotline with a new complaint management system that allows staff and members of the public to better provide information online, while maintaining anonymity. The Auditor General's Office calculates the return on every dollar invested in the Office by comparing the ratio of five-year audit costs to the cumulative estimated five-year realized savings. Since 2016, total one-time and projected five-year cost savings and revenue increases are approximately $385.3 million. The cumulative costs of operating the Auditor General's Office since 2016 were approximately $30.3 million. For every $1 invested in the Auditor General's Office, the return on investment was approximately $12.70. The identification of cost savings and increased revenue is only one component of the Auditor General's mandate. Equally important is the ongoing evaluation of governance, risk management and internal controls, the impacts of which are not always easily quantified in financial terms.
The Audit Committee recommends that: 1. City Council receive the report (February 2, 2021) from the Auditor General for information.
Staff recommendation as filed
The Auditor General recommends that: 1. City Council receive this report for information.
AU8.4adopted
Auditor General's 2020 Annual Report on the Fraud and Waste Hotline
This report represents the 2020 annual report on fraud, waste and wrongdoing at the City including the activities of the Fraud and Waste Hotline Program (the Hotline Program). It highlights the complaints that have been communicated to the Auditor General's Office. It does not represent an overall picture of fraud or other wrongdoing across the City. In 2020, 848 complaints comprised of approximately 1,350 allegations were received by the Auditor General's Office. The Hotline Program has helped to reduce losses and resulted in the protection of City assets. The actual and potential losses from complaints received from 2016 to 2020 is more than $36.9 million (actual losses) plus $3.4 million (potential losses) had the fraud not been detected. Additional benefits that are not quantifiable include: - the deterrence of fraud or wrongdoing; - strengthened internal controls; - improvements in policies and procedures; - increased operational efficiencies; and - the ability to use complaint data to identify trends, address risks, make action-oriented recommendations to management and inform our audit work plan.
The Audit Committee recommends that: 1. City Council receive the report (February 3, 2021) from the Auditor General for information.
Staff recommendation as filed
The Auditor General recommends that: 1. City Council receive this report for information.
AU8.5amended
Auditor General's Follow-Up of the Outstanding Recommendations - Status Update
The Auditor General reviews the implementation status of recommendations made through her audit and investigation reports. The results of the review are reported to City Council through the Audit Committee. The Auditor General's follow-up work was impacted by the COVID-19 pandemic. In 2020, we deferred our follow-up work that was in-progress to enable City divisions and its agencies and corporations to focus on the delivery of essential services. However, the City divisions and its agencies and corporations, where possible, did continue to work on the implementation of recommendations to realize savings and operational efficiencies. During this time our Office implemented a new audit management technology solution. As an extension of the new system, we integrated continuous tracking of the implementation status of the recommendations included in the audit and investigation reports. This solution will provide a more efficient tracking of the outstanding recommendations to management and reporting to the Audit Committee on management actions to implement these recommendations. As of January 8, 2021, there were 748 outstanding recommendations issued between September 2005 and February 2020. Management reported that 233 (31 per cent) recommendations were fully implemented and three recommendations were no longer applicable. The Auditor General has not verified the management reported status; however, this work is now underway. The results of our review will be submitted to the May 31, 2021 Audit Committee meeting. The purpose of this report is to update the Audit Committee and Council on management actions and plans to implement the outstanding audit and investigation recommendations. Table 1 provides an overview of the status of outstanding audit and investigation recommendations for City divisions, agencies and corporations as reported by management as of January 8, 2021. Table 1 - Status of Outstanding Audit and Investigation Recommendations as Reported by Management as of January 8, 2021 (Status Not Verified by the Auditor General) Service Area High Priority Recs. Other Recs. Total Outstanding Recs. Total FI NFI N/A FI NFI N/A FI NFI N/A City Divisions 68 179 0 116 199 0 184 (33%) 378 (67%) 0 562 Agencies and Corporations 31 46 1 18 88 2 49 (26%) 134 (72%) 3 (2%) 186 Grand Total 99 (13%) 225 (30%) 1 134 (18%) 287 (38%) 2 (1%) 233 (31%) 512 (68%) 3 (1%) 748 The recommendations where a significant amount of savings, or health and safety, or the City's reputation risks are involved, these are considered high priority. In addition, those recommendations that remain outstanding for over five years are also considered high priority. The 99 (13 per cent) high priority fully implemented recommendations are included in the Attachment 1, unless confidential, the one high priority no longer applicable recommendation is included in the Attachment 3, and all confidential recommendations are included in the Confidential Attachment 1. The 225 (30 per cent) high priority not fully implemented recommendations, together with management comments, action plans and implementation due dates are included in the Attachment 2, unless confidential. The confidential high priority not fully implemented recommendations are included in the Confidential Attachment 1.
The Audit Committee recommends that: 1. City Council request the Chief Information Security Officer to report to the May 31, 2021 meeting of the Audit Committee on the implementation status of all outstanding cybersecurity-related audit recommendations, including: a. high priority recommendations where there are still significant risks; b. risks being faced by the City of Toronto as a result of not implementing audit recommendations; c. a risk assessment identifying the impact of the risks after considering any current vulnerabilities; d. any other security risks being faced as a result of the changing cyber threat landscape; and e. short-, medium-, and long-term plans identifying what needs to be done to reduce the risk level for the City of Toronto in an expedited fashion. 2. City Council request the Chief Information Security Officer to report to the General Government and Licensing Committee on a biannual basis regarding the City-wide cybersecurity program, including: a. the status of all outstanding audit recommendations that have not been implemented to date, including any increase to the City's cybersecurity risk profile; b. projects, initiatives, procurement, and operations where cybersecurity requirements or directives were not included in the process; c. embedding "cybersecurity by design" principles to support the City's modernization efforts; and d. any additional supports required to address cybersecurity risks in an expedited manner. 3. City Council request the Auditor General to report on the implementation status of cybersecurity-related audit recommendations in the Auditor General's status report on outstanding recommendations to the Audit Committee. 4. City Council request the Auditor General to provide regular status updates to the Audit Committee on the progress of management's implementation of the Auditor General's recommendations and, unless there are specific requests for special updates, City Council no longer require the City Manager to provide regular status updates to the Audit Committee, as outlined in Item 2020.AU5.11 headed "Management Update on the Implementation Status of Outstanding Auditor General Recommendations (City-Wide)". 5. City Council direct that Confidential Attachment 1 to the report (February 4, 2021) from the Auditor General remain confidential in its entirety, as it contains information on the security of property belonging to the City of Toronto, information explicitly supplied in confidence to the City of Toronto which, if disclosed, could reasonably be expected to impact the safety and security of the City and its services, labour relations or employee negotiations, and litigation or potential litigation that affects the City of Toronto.
Staff recommendation as filed
The Auditor General recommends that: 1. City Council direct that the confidential information contained in Confidential Attachment 1 remain confidential in its entirety, as it involves the security of property belonging to the City of Toronto, it is about the safety and security of the City and its services, labour relations or employee negotiations and about litigation or potential litigation that may affect the City of Toronto.
AU8.6amended
Getting to the Root of the Issues: A Follow-Up to the 2019 Tree Maintenance Services Audit
In April 2019, the Auditor General released her report, "Review of Urban Forestry - Ensuring Value for Money for Tree Maintenance Services", on the results of her audit of tree planting and maintenance services. http://app.toronto.ca/tmmis/viewAgendaItemHistory.do?item=2019.AU2.4 In October 2019, the General Manager, Parks, Forestry, and Recreation reported: "Parks, Forestry and Recreation (PFR) has vigorously undertaken steps to meet the AG's recommendations, improve management oversight, explore options associated with contractual agreements with vendors and, in collaboration with the City Solicitor, pursue legal action if needed to recover any losses." http://app.toronto.ca/tmmis/viewAgendaItemHistory.do?item=2019.AU4.14 In July 2020, the City Solicitor and the General Manager, Parks, Forestry and Recreation reported to the Infrastructure and Environment Committee on PFR's review of work performed by tree maintenance vendors and provided related legal advice. A supplementary report was presented when the matter was considered by City Council. http://app.toronto.ca/tmmis/viewAgendaItemHistory.do?item=2020.IE14.8 City Council requested the Auditor General to report further to the Audit Committee on this matter. To be able to respond to Council's request, the Auditor General conducted a limited scope follow-up review of certain aspects of tree maintenance services to assess the Parks, Forestry and Recreation Division's progress towards addressing issues and recommendations identified in our April 2019 audit report, "Review of Urban Forestry - Ensuring Value for Money for Tree Maintenance Services". This report presents the results of the Auditor General's limited scope follow-up review.
The Audit Committee recommends that: 1. City Council request the City Manager to report to the Infrastructure and Environment Committee in the fourth quarter of 2021 on a cross-divisional and agency review of the delivery of insourced and outsourced environmental services, including forestry, horticulture, parks, and other outdoor maintenance, with a view to improving service, program design, organization, oversight, value, efficiency, procurement, and contract and resource management. 2. City Council request the City Manager to report to the Audit Committee in the first quarter of 2022 with a consolidated summary and analysis of all forestry services-related complaints in 2021, whether internal or external, and to provide overall summary information on the actions and outcomes arising from these complaints. 3. City Council direct the City Manager to review the organizational and management structure of Urban Forestry operations to ensure the proper alignment with other City operations and make necessary changes to improve operational efficiencies and effectiveness, including improvements to contract management practices. 4. City Council request the City Manager to put contract management controls in place to ensure that vendors are complying with the terms of the tree maintenance services contract. 5. City Council request the City Manager and the General Manager, Parks, Forestry and Recreation to ensure that Forestry Performance Inspection Reports are only conducted after a Forestry crew commences work to enable the City to evaluate whether time is being used efficiently and whether the City is receiving value for money. 6. City Council direct the General Manager, Parks, Forestry and Recreation to: a. report directly to the May 5 and 6, 2021 meeting of City Council with an update on the progress made with respect to the 60-day actions in Getting to the Root of the Issues: 30/60/90 Day Plan of Action - Parks, Forestry and Recreation that was presented at the February 16, 2021 meeting of the Audit Committee; and b. report to the May 31, 2021 meeting of the Audit Committee with an update on the progress made with respect to the 90-day actions in Getting to the Root of the Issues: 30/60/90 Day Plan of Action - Parks, Forestry and Recreation that was presented at the February 16, 2021 meeting of the Audit Committee. 7. City Council request the General Manager, Parks, Forestry and Recreation to periodically perform discreet physical observation of tree maintenance vendors for multiple whole days to ascertain the accuracy and reliability of reported work completed and paid for based on an hourly rate. 8. City Council request the General Manager, Parks, Forestry and Recreation to improve City and contracted tree maintenance crew productivity, outputs, and outcomes by planning, assigning, and monitoring work to: a. maximize the amount of time spent actively working on tree maintenance activities (i.e., pruning, removal, stumping, fill and seed, etc.); b. reduce the time spent on supporting activities (i.e., time spent at the yard, dumping, driving, etc.); and c. minimize non-productive time (i.e., time waiting for parked vehicles to be moved, idle time, unreported breaks, etc.). 9. City Council direct that, to support the effective analysis and monitoring of productivity, Urban Forestry Forepersons or Supervisors must verify that crews accurately record information (including locations, activities, and times) on their daily logs and review the logs for productivity and completeness on a sample basis; the sample should include at least one daily log per crew within every two-week period; and, where issues are noted on a selected daily log, additional logs should be reviewed and, where necessary, daily logs and invoices should be adjusted in accordance with the contract. 10. City Council request the General Manager, Parks, Forestry and Recreation to: a. track all tree maintenance complaints to provide indicators of where contractor performance needs closer monitoring; b. include complaints in contract management and contractor performance evaluations, with a special emphasis on recurring issues; and c. remind staff of their obligation to report any allegations of potential wrongdoing involving City resources, including potential wrongdoing against the City by third-party vendors, to the Auditor General for further investigation. 11. City Council request the General Manager, Parks, Forestry and Recreation to ensure that Forestry Performance Inspection Records accurately reflect the actual scope of the inspection or review performed and note any inspection criteria that staff are unable to assess based on work activities observed at the time of the inspection. 12. City Council request the General Manager, Parks, Forestry and Recreation to: a. obtain precise route information (in accordance with contracts), which includes specific geo-location (latitude and longitude) at frequent (minute-by-minute) intervals and not just fixed addresses associated with tree locations; b. investigate any discrepancy between the reported geo-location and GPS geo-location exceeding an acceptable threshold no greater than 25 metres; any challenge to the GPS accuracy should be supported by GPS service providers' direct confirmation to the City that the data recorded by their GPS device is faulty; and explanations and supporting evidence for discrepancies should be properly documented; c. request crews to submit geo-tagged photos of each tree, showing the tree before and after work has been completed; and Urban Forestry staff should review these photos when signing off on crews' daily logs; and d. update Urban Forestry tree maintenance records with current geo-tagged photos of trees submitted by tree maintenance crews. 13. City Council request the General Manager, Parks, Forestry and Recreation to improve crew management at the operations yards to reduce daily yard time and increase efficiency on tree maintenance work and City Council request Urban Forestry management to monitor whether there is any improvement to operational efficiency when taking this action. 14. City Council request the General Manager, Parks, Forestry and Recreation to: a. analyze why certain crews report parked vehicles at a higher frequency or longer duration than other crews and implement measures to reduce related downtime; b. request crews to submit geo-tagged photos of the location of parked vehicles obstructing work at the time these obstructions occur; and Urban Forestry Forepersons should reconcile reported parked car time to the submitted evidence of the obstruction when they review and sign off on daily logs; and c. expedite how the Division will minimize downtime related to parked vehicles obstructing work from proceeding, temporarily directing, until this issue can be properly addressed, tree maintenance crews to carry on to the next tree location if they cannot gain access and then return when parking enforcement and towing can be arranged; and Urban Forestry management should monitor whether there is any improvement to operational efficiency when taking this action. 15. City Council request the General Manager, Parks, Forestry and Recreation to: a. ensure that Urban Forestry or vendor staff are pre-arranging all required hydro hold-offs, wherever possible, to minimize downtime spent waiting for a hold-off; and the time of pre-scheduled hold-off, the time when hold-off was actually received, and any time waiting should be clearly noted on daily logs; and b. ensure that any need for an emergency hold-off is reported to the Urban Forestry Foreperson and is noted on their daily log; and the time when the request for hold-off was called in, the time when hold-off was actually received, and any time waiting should be clearly noted on daily logs. 16. City Council request the General Manager, Parks, Forestry and Recreation to ensure that payment for services is consistent with the express terms of the contract. 17. City Council request the General Manager, Parks, Forestry and Recreation to: a. verify that vendors fulfill their contractual responsibilities for ensuring complete compliance with all regulations and provisions contained in, or issued under, the Occupational Health and Safety Act, the Arborist Industry Safe Work Practices, the Infrastructure Health and Safety Association (formerly the Electrical Utilities Safety Rules) Rule Book, the Highway Traffic Act, and any other applicable regulations, and any amendments to the foregoing acts and regulations and any new applicable acts or regulations that are enacted from time to time; b. ensure that non-compliance is properly documented as part of vendor contract performance management processes; and c. pursue measures up to, and including, contract termination for repeated non-compliance with safety provisions of tree maintenance contracts. 18. City Council direct the General Manager, Parks, Forestry and Recreation to remind all vendors of their responsibilities under the Occupational Health and Safety Act and to ensure that safety records are verified on an ongoing basis. 19. City Council request the General Manager, Parks, Forestry and Recreation to: a. obtain GPS routes travelled information that includes actual location coordinates (longitude and latitude) that are routinely captured by vendors' GPS systems every minute (or more frequent) and whenever there is a vehicle change (start, stop, change in direction, power take off on/off, etc.); and b. retain all GPS records needed to support invoiced amounts in accordance with the City's records retention policy. 20. City Council request the General Manager, Parks, Forestry and Recreation to: a. define expected outcomes for tree maintenance service delivery and include related performance measures directly within the contracts; b. specify actions and remedies for not meeting performance outcomes in the contracts; and c. consider contract terms that allow the City to base the assignment of tree maintenance work packages or hourly rate work based on how crews perform relative to other crews. 21. City Council request the General Manager, Parks, Forestry and Recreation to compare performance measures and outcomes achieved by City and contracted tree maintenance crews and use this information to determine the appropriate type and volume of work to allocate to City crews and outsourced service providers. 22. City Council request the General Manager, Parks, Forestry and Recreation to ensure that contracts make clear the roles and responsibilities of City staff and the vendor for resolving problems that impact performance outcomes, including crew productivity. 23. City Council request the General Manager, Parks, Forestry and Recreation to require tree maintenance vendors' vehicles to clearly indicate in large font text, easily readable at a distance, identifying: a. the vehicle is on contract to the City of Toronto; b. a unique vehicle identification number; and c. an appropriate contact telephone number for the City of Toronto in case of complaints. 24. City Council direct the General Manager, Parks, Forestry and Recreation, in consultation with the City Solicitor, the Executive Director, Municipal Licensing and Standards, and the Toronto Police Service, to report to the May 31, 2021 meeting of the Audit Committee on an improved system to deal with parked vehicles that impede tree maintenance crews which could include options to expedite the removal of legally-parked vehicles, including the feasibility of issuing legal notices to residents to authorize the expedited removal of parked vehicles. 25. City Council request the Controller to implement additional supports and greater accountability City-wide for the effective monitoring and management of significant outsourced contracts which may include: a. well-defined control objectives for which divisions are expected to have designed and implemented key controls to reinforce effective oversight, monitoring, and management of outsourced services in accordance with the express terms of the contract; b. a structured approach to documenting contracting risks and controls with divisional management certifying or signing off that key contract management controls have been appropriately designed and implemented in practice; and c. an independent compliance review process to verify the key contract monitoring and contract management controls that divisions have put into place are operating effectively, including extensive physical observation of contracted service providers from time to time. 26. City Council request the General Manager, Fleet Services, in consultation with the Chief Technology Officer and the General Manager, Parks, Forestry and Recreation and other client divisions, to: a. explore an enterprise-wide procurement of a telematics solution that can be leveraged into vehicles of outsourced service providers to support contract management and monitoring; and b. establish guidelines for how to leverage or integrate GPS data to support contract management and monitoring, including data analytics. 27. City Council request the Auditor General to report to the Audit Committee on the status of the implementation of the recommendations in Item 2019.AU2.4 headed "Review of Urban Forestry - Ensuring Value for Money for Tree Maintenance Services" and Item 2021.AU8.6 headed "Getting to the Root of the Issues: A Follow-Up to the 2019 Tree Maintenance Services Audit". 28. City Council direct that future contracts for forestry services not include payment for breaks or for the duplication of tree inspections and that an evaluation of past performance by contractors on City contracts be built into the process for the award of contracts. 29. City Council direct that Confidential Attachment 1 to the report (February 2, 2021) from the Auditor General remain confidential in its entirety, as it contains information about litigation or potential litigation that affects the City of Toronto. 30. City Council direct that Confidential Attachment 1 to the report (February 8, 2021) from the Director, Internal Audit remain confidential in its entirety, as it contains information pertaining to litigation or potential litigation that affects the City of Toronto.
Staff recommendation as filed
The Auditor General recommends that: 1. City Council request the General Manager, Parks, Forestry and Recreation Division, to periodically perform discreet physical observation of tree maintenance vendors for multiple whole days to ascertain the accuracy and reliability of reported work completed and paid for based on an hourly rate. 2. City Council request the General Manager, Parks, Forestry and Recreation Division, to improve City and contracted tree maintenance crew productivity, outputs and outcomes by planning, assigning, and monitoring work to: a. maximize the amount of time spent actively working on tree maintenance activities (i.e., pruning, removal, stumping, fill and seed, etc.); b. reduce the time spent on supporting activities (i.e., time spent at the yard, dumping, driving, etc.); and c. minimize non-productive time (e.g., time waiting for parked vehicles to be moved, idle time, unreported breaks, etc.). To support effective analysis and monitoring of productivity, Forestry Forepersons or Supervisors must verify crews accurately record information (including locations, activities, and times) on their daily logs and review the logs for productivity and completeness on a sample basis. The sample should include at least one daily log per crew within every two-week period. Where issues are noted on a selected daily log, additional logs should be reviewed and where necessary, daily logs and invoices should be adjusted in accordance with the contract. 3. City Council request the General Manager, Parks, Forestry and Recreation Division, to: a. track all tree maintenance complaints to provide indicators of where contractor performance needs closer monitoring; b. include complaints in contract management and contractor performance evaluations, with a special emphasis on recurring issues; and c. remind staff of their obligation to report any allegations of potential wrongdoing involving City resources, including potential wrongdoing against the City by third-party vendors, to the Auditor General for further investigation. 4. City Council request the General Manager, Parks, Forestry and Recreation Division, to ensure Forestry Performance Inspection records accurately reflect the actual scope of the inspection or review performed and note any inspection criteria that staff are unable to assess based on work activities observed at the time of inspection. 5. City Council request the General Manager, Parks, Forestry and Recreation Division, to: a. obtain precise route information (in accordance with contracts), which includes specific geo-location (latitude and longitude) at frequent (minute-by-minute) intervals and not just fixed addresses associated with tree locations; b. investigate any discrepancy between reported geo-location and GPS geo-location exceeding an acceptable threshold no greater than 25 metres. Any challenge to the GPS accuracy should be supported by GPS service providers' direct confirmation to the City that the data recorded by their GPS device is faulty. Explanations and supporting evidence for discrepancies should be properly documented; c. request crews to submit geo-tagged photos of each tree, showing the tree before and after work has been completed. Urban Forestry staff should review these photos when signing off on crews' daily logs; and d. update Urban Forestry tree maintenance records with current geo-tagged photos of trees submitted by tree maintenance crews. 6. City Council request the General Manager, Parks, Forestry and Recreation Division, to improve crew management at the operations yards to reduce daily yard time and increase efficiency on tree maintenance work. Urban Forestry management should monitor whether there is any improvement to operational efficiency when taking this action. 7. City Council request the General Manager, Parks, Forestry and Recreation Division, to: a. analyze why certain crews report parked vehicles at higher frequency or longer duration than other crews and implement measures to reduce related downtime; b. request crews submit geo-tagged photos of the location of parked vehicles obstructing work at the time these obstructions occur. Urban Forestry forepersons should reconcile reported parked car time to the submitted evidence of the obstruction when they review and sign off on daily logs; and c. expedite how it will minimize downtime related to parked vehicles obstructing work from proceeding, temporarily directing, until this issue can be properly addressed, tree maintenance crews to carry on to the next tree location if they cannot gain access and then return when parking enforcement and towing can be arranged. Urban Forestry management should monitor whether there is any improvement to operational efficiency when taking this action. 8. City Council request the General Manager, Parks, Forestry and Recreation Division, to: a. ensure Urban Forestry or vendor staff are pre-arranging all required hydro hold-offs, wherever possible, to minimize downtime spent waiting for a hold-off. The time of pre-scheduled hold-off, time when hold-off was actually received and any time waiting should be clearly noted on daily logs; and b. ensure any need for an emergency hold-off is reported to the Urban Forestry foreperson and is noted on their daily log. The time when request for hold-off was called in, time when hold-off was actually received and any time waiting should be clearly noted on daily logs. 9. City Council request the General Manager, Parks, Forestry and Recreation Division, to ensure that payment for services is consistent with the express terms of the contract. 10. City Council request the General Manager, Parks, Forestry and Recreation Division, to: a. verify that vendors fulfill their contractual responsibilities for ensuring complete compliance with all regulations and provisions contained in or issued under the Occupational Health and Safety Act, Arborist Industry - Safe Work Practices, Infrastructure Health and Safety Association (Formerly EUSA) Rule Book, the Highway Traffic Act, and any other applicable regulations, and any amendments to the foregoing acts and regulations and any new applicable act or regulation enacted from time to time; b. ensure non-compliance is properly documented as part of vendor contract performance management processes; and c. pursue measures up to and including contract termination for repeated non-compliance with safety provisions of tree maintenance contracts. 11. City Council request the General Manager, Parks, Forestry and Recreation Division, to: a. obtain GPS routes travelled information that includes actual location coordinates (longitude and latitude) that are routinely captured by vendors' GPS systems every minute (or more frequent) and whenever there is a vehicle change (start, stop, change in direction, power take off on/off, etc.); and b. retain all GPS records needed to support invoiced amounts in accordance with the City's record retention policy. 12. City Council request the General Manager, Fleet Services Division, in consultation with the Chief Technology Officer, and management of Parks, Forestry and Recreation and of other client divisions, to: a. explore an enterprise-wide procurement of a telematics solution that can be leveraged into vehicles of outsourced service providers to support contract management and monitoring; and b. establish guidelines for how to leverage or integrate GPS data to support contract management and monitoring, including data analytics. 13. City Council request the General Manager, Parks, Forestry and Recreation Division, to: a. define expected outcomes for tree maintenance service delivery and include related performance measures directly within the contracts; b. specify actions and remedies for not meeting performance outcomes in the contracts; and c. consider contract terms that allow the City to base assignment of tree maintenance work packages or hourly rate work based on how crews perform relative to other crews. 14. City Council request the General Manager, Parks, Forestry and Recreation Division, to compare performance measures and outcomes achieved by City and contracted tree maintenance crews and use this information to determine the appropriate type and volume of work to allocate to City crews and outsourced service providers. 15. City Council request the General Manager, Parks, Forestry and Recreation Division, to ensure contracts make clear the roles and responsibilities of City staff and the vendor for resolving problems that impact performance outcomes including crew productivity. 16. City Council request the General Manager, Parks, Forestry and Recreation Division, to require tree maintenance vendors' vehicles to clearly indicate in large font text, easily readable at a distance, identifying: a. the vehicle is on contract to the City of Toronto; b. a unique vehicle identification number; and c. an appropriate contact phone number for the City of Toronto in case of complaints. 17. City Council request the Controller to implement additional supports and greater accountability City-wide for effective monitoring and management of significant outsourced contracts, which may include: a. well-defined control objectives for which divisions are expected to have designed and implemented key controls to reinforce effective oversight, monitoring, and management of outsourced services in accordance with the express terms of contract; b. a structured approach to documenting contracting risks and controls with divisional management certifying or signing-off that key contract management controls have been appropriately designed and implemented in practice; and c. independent compliance review process to verify the key contract monitoring and contract management controls divisions have put into place are operating effectively, including extensive physical observation of contracted service providers from time to time. 18. City Council direct that the confidential information contained in Confidential Attachment 1 remain confidential in its entirety, as it contains information about litigation or potential litigation that affects the City of Toronto.
AU8.7amended
Toronto Business Improvement Areas (BIAs) Accounts Payable Fraud Investigation
The attached report summarizes the results of the Auditor General's review of allegations of fraud. The case involved two BIAs resulting from the actions of a consultant who worked for each Business Improvement Area (BIA) at different times beginning in 2017. This investigation was initiated based on concerns raised by the City's BIA office of the Economic Development and Culture Division. After concluding our investigation but before our public report was issued, we were apprised by law enforcement that "the police conducted their investigation independently of the Auditor General. The suspect has been identified and arrested by police, and has been charged with fraud." The consultant was not interviewed as part of the Auditor General's work in order to retain separation of the work conducted by the Auditor General's Office and the criminal investigative process. The Board members at BIA 1 should be commended for catching and pursuing this matter once it was detected. The purpose of this report is to identify areas where BIAs in general can improve internal controls to prevent similar situations from occurring, and to identify opportunities for the City to support the BIAs in doing so. While we recognize that Boards are comprised of volunteers who already spend considerable personal time on these activities, information about key internal controls is relevant and critical to any enterprise that relies on volunteers, consultants and other professionals for support. The Association of Certified Fraud Examiners (ACFE) in its 2020 Report to the Nations notes that: "Non-profit organizations can be more susceptible to fraud due to having fewer resources available to help prevent and recover from a fraud loss. This sector is particularly vulnerable because of less oversight and lack of certain internal controls." The Auditor General has made three recommendations to lessen the risk to other BIAs. Note that although these recommendations relate specifically to either BIA 1 or BIA 2, the lessons learned should benefit all BIAs and all City organizations. Management has agreed to all three recommendations.
The Audit Committee recommends that: 1. City Council request the General Manager, Economic Development and Culture to improve the existing training of Business Improvement Area Board members to: a. ensure that all Business Improvement Area Board members are provided with the opportunity to receive relevant training in relation to strengthening financial governance, internal controls, and fraud prevention for Business Improvement Areas; and b. consider leveraging Internal Audit to help review key financial controls in support of Business Improvement Areas and provide support and/or guidance in this area. 2. City Council request the General Manager, Economic Development and Culture to improve the existing training of Business Improvement Area Board members by ensuring that all Business Improvement Area Board members: a. are made aware of their responsibility before issuing payments to ensure supporting documentation is obtained and that services have been provided; as well as perform monthly bank reconciliations to ensure that payments processed were approved; and b. are supported to ensure that there is appropriate segregation of duties, including potentially hiring someone to assist all Business Improvement Areas in performing bank reconciliations, where necessary. 3. City Council request the General Manager, Economic Development and Culture to consult with Business Improvement Area Board members to identify any other emerging needs that the City can support Business Improvement Areas on including, but not limited to, information technology security support. 4. City Council request the General Manager, Economic Development and Culture to assist the City of Toronto's Business Improvement Areas to work with the City's Open Data technology staff to provide, in a suitable format and to be placed on an annual basis on the City's Open Data Portal, the following: a. all publicly disclosed financial information from the Business Improvement Areas' Annual Reports and financial filings that are submitted to the City for income and expenses; and b. all publicly disclosed financial information pertaining to major projects that the City of Toronto has partially or fully funded.
Staff recommendation as filed
The Auditor General recommends that: 1. City Council request the General Manager, Economic Development and Culture, to improve existing training of Business Improvement Area Board members to: a. ensure that all Business Improvement Area Board members be provided with the opportunity to receive relevant training in relation to strengthening financial governance, internal controls and fraud prevention for Business Improvement Areas; and b. consider leveraging Internal Audit to help review key financial controls in support of Business Improvement Areas and provide support and/or guidance in this area. 2. City Council request the General Manager, Economic Development and Culture, to improve existing training of Business Improvement Area Board members by ensuring all Business Improvement Area Board members: a. are made aware of their responsibility before issuing payments to ensure supporting documentation is obtained and that services have been provided; as well as perform monthly bank reconciliations to ensure payments processed were approved; and b. are supported to ensure there is appropriate segregation of duties, including potentially hiring someone to assist all Business Improvement Areas in performing bank reconciliations, where necessary. 3. City Council request the General Manager, Economic Development and Culture, to consult with Business Improvement Area Board members to identify any other emerging needs that the City can support Business Improvement Areas on, including but not limited to, Information Technology security support.
AU8.8amended
The City of Toronto implemented a new human resource (HR) system in 2019 to replace its old HR modules in human resource management and administration. This new integrated HR system provides an end-to-end workflow, from recruitment to hiring and onboarding for new staff. It collects and stores a significant amount of human resources information for employees and elected officials. Because of this, it is extremely important that the system has strong cybersecurity and privacy controls in place. In early 2020, the Auditor General became aware of a cybersecurity incident related to the implementation of this new system. Given the importance of information privacy and cybersecurity, the Auditor General immediately initiated a review of the system implementation process in the context of overall information security at the City. Cybersecurity and information privacy have always been high priority areas for the Auditor General. Since 2015, the Auditor General has performed a number of audits of the City's IT infrastructure and critical systems, and has recommended controls to improve cybersecurity and information privacy. The Auditor General will continue to perform audits and assess evolving cybersecurity and information privacy risks. The objective of this review was to assess the implementation of information privacy and cybersecurity controls of this new HR system. The findings are categorized into three areas where the City needs to improve cybersecurity and information privacy: - strengthening project governance; - improving user access controls and activity logging processes; and - strengthening on end-to-end system testing including user acceptance testing. We have made 10 recommendations to address the weaknesses identified during our review. Implementation of our recommendations will strengthen project governance and improved controls to address cybersecurity and information privacy risks when implementing large technology systems. Detailed management comments and action plan for each of the recommendations is provided in Appendix 1 included in the attached report.
The Audit Committee recommends that: 1. City Council request the Chief Technology Officer to enhance the management of cybersecurity and privacy risks, as part of its information technology project governance, by: a. ensuring that cybersecurity and information privacy requirements and related budget are part of the acquisition, development, design, and testing phases of technology projects; and the Office of the Chief Information Security Officer and the City Clerk must review and endorse the requirements and budget allocated for cybersecurity and information privacy for all City technology initiatives, transformations, and procurements; b. ensuring that a process is in place to identify, analyze, and communicate all cybersecurity and information privacy risks to all stakeholders at each project phase through a documented risk mitigation plan; and the identified risks are either mitigated or formally accepted by the division head/project sponsor and communicated to the City's Senior Leadership Team before the system is launched; c. ensuring that the remediation of open risks is completed within a specified timeline and are signed off by the division head/project sponsor before moving to the next project development stage; and d. identifying new or reallocated resource requirements required by the Office of the Chief Information Security Officer or the City Clerk needed to support the information technology project through its life cycle. 2. City Council request the Chief Technology Officer to extend the actions in Recommendation 1 above to existing in-progress technology projects and all future implementations. 3. City Council request the Chief Technology Officer to enhance the City's incident response process by: a. ensuring that all incidents are logged in a consistent manner and addressed and communicated to the appropriate stakeholders in a timely manner; b. actively monitoring remediation actions and ensuring that processes are in place to test the post-remediation environment; c. coordinating with the City Clerk to integrate the privacy incident response process with the Office of the Chief Information Security Officer's Cyber Incident Response Plan and the Technology Services Division's Major Incident Management Process; and d. integrating the applicable sections of the Technology Services Division's Major Incident Management Process into the Office of the Chief Information Security Officer's Cyber Incident Response Plan. 4. City Council request the Chief Technology Officer to consider the actions in Recommendation 3 above in addition to the previous recommendation in the supplementary report (June 19, 2019) from the Auditor General headed "Establishment of City Wide Cyber Security Breach Incident Management Procedures Required" (Item 2019.AU3.12a). 5. City Council request the Chief Technology Officer to enhance project governance by: a. ensuring that all projects fully comply with the Project Review Team gating approvals; and exceptions relating to cybersecurity and privacy must be reviewed by the Chief Information Security Officer and the City Clerk for a go/no-go decision; b. ensuring that project management gating criteria include a clear support transition plan when projects move from development to operations or from one stage to the next, depending on which project management methodology is used, such as Agile project management; and c. ensuring that project managers are trained in change management methodology. 6. City Council request the Chief Technology Officer to: a. in coordination with the Chief Information Security Officer and the City Clerk, prioritize and direct resources to develop a training program for project managers and key staff involved in the implementation of technology initiatives to receive cybersecurity and information privacy training focused on managing technology projects; and b. conduct an assessment to determine the feasibility of extending this training program to major agencies and corporations. 7. City Council request the Chief Technology Officer to enhance the project governance and project management framework by ensuring that: a. all stakeholders' roles and responsibilities are clearly defined and key stakeholders are involved from the pre-procurement stage; b. a clear support transition plan when a project is moved from development to operations at Gate 4, the last gate before the system is moved to operations; c. the Chief Information Security Officer and the City Clerk are part of the project steering committee for all key technology initiatives and transformations; and d. criteria are developed to determine projects with high risks that have not been mitigated prior to moving to production be escalated to the Senior Leadership Team; and the developed criteria should be shared with the City Manager for City-wide implementation. 8. City Council request the Chief Technology Officer to enhance the project management framework by: a. including a review of internal controls for systems that involve financial transactions; and b. involving the Controller or the Director, Internal Audit in the review of user roles in relation to financial transaction processing to ensure that the appropriate segregation of duties is maintained for all user roles. 9. City Council request the Chief Technology Officer improve the user permissions framework of the Human Resources application, including: a. conducting a cybersecurity and information privacy review of the various roles created in the Human Resources system; b. reviewing the users with a Super Administrator role and limiting the number of users with that role considering the industry's best practices and professional bodies; c. ensuring that user access roles are designed with cybersecurity and information privacy in mind; and access roles should be provided to users on a "need to have" basis; d. defining a process for the approval of access roles for support staff; instead of providing Super Administrator access, support staff should be provided access on a "need to have" basis; and e. eliminating the use of generic and anonymous accounts; if these roles are needed as an exception for operational reasons, detailed monitoring and logging procedures should be developed and implemented for these roles; and, in addition, the review of elevated access roles and the use of generic or anonymous users should be extended to the SAP enterprise application. 10. City Council request the Chief Technology Officer to develop standards and minimum criteria for logging user activity details for information technology systems, with steps including, but not limited, to: a. ensuring that user access logs capture account activity for users with elevated access, such as users with Super Administrator or Divisional Administrator roles; and b. implementing a user activity review process for roles with elevated access on a periodic basis to ensure that access is aligned with the roles. 11. City Council request the Chief Technology Officer to implement a process to ensure that comprehensive system testing and user acceptance testing is part of the overall information technology project management methodology, including: a. assigning staff having functional subject matter expertise in the Technology Services Division, cybersecurity subject matter expertise in the Office of the Chief Information Security Officer, and privacy subject matter expertise in the City Clerk's Office to review the test scope, test cases, and test cycle defect management; b. ensuring that user acceptance testing is started early in the project stage and performed by respective divisions (users); and, in situations where testing is performed by staff other than the User Division, the test results must be formally approved by the respective Division Lead contact on the project; and c. ensuring that each test cycle goes through a formal approval process and mandatory security and privacy testing prior to commencing the next test cycle. 12. City Council request the Chief Technology Officer to: a. research options to automate the move of configuration of systems, including cybersecurity and privacy configuration, from testing to the production environment; and b. alternatively, include a peer review (Quality Assurance) to verify post-implementation configuration in the system after it has been moved to the production environment. 13. City Council request the Chief Procurement Officer, in consultation with the Chief Information Security Officer and the City Clerk, to report to the General Government and Licensing Committee by the end of the third quarter of 2021 on how to embed privacy and security by design principles and mandatory privacy and cybersecurity requirements from the Chief Information Security Officer and the City Clerk into the City's current procurement process and a governance process to manage exceptions. 14. City Council direct the Chief Information Security Officer to prepare a complete inventory of all business applications, systems, and connected technology assets in the City and its applicable agencies and corporations by the end of the third quarter of 2021 and City Council direct all Division Heads and request, as appropriate, the City's applicable agencies and corporations to provide the complete inventory information above to the Chief Information Security Officer and to identify a single accountable business owner for each inventory item. 15. City Council request the Chief Information Security Officer to report to the General Government and Licensing Committee on a transformation and implementation plan for an independent and centralized information technology risk and compliance, privacy, and cybersecurity function or functions which addresses organizational design, governance, oversight, accountability, authority, procurement, services, talent, human, and financial resources.
Staff recommendation as filed
The Auditor General recommends that: 1. City Council request the Chief Technology Officer enhance the management of cybersecurity and privacy risks as part of its IT project governance by: a. ensuring that cybersecurity and information privacy requirements and related budget are part of the acquisition, development and design phases of technology projects. The Office of the Chief Information Security Officer and the City Clerk should be consulted to review the budget allocated for cybersecurity and information privacy for all City technology initiatives, transformations and procurements; b. ensuring a process is in place to identify, analyze and communicate all cybersecurity and information privacy risks to all stakeholders at each project phase through a documented risk mitigation plan. The identified risks are either mitigated or formally accepted by the division head/project sponsor before the system is launched; and c. ensuring the remediation of open risks is completed within a specified timeline and are signed off by the division head/project sponsor before moving to next project development stage. These actions should be extended to existing in-progress technology projects and all future implementations. 2. City Council request the Chief Technology Officer enhance the City's incident response process by: a. ensuring all incidents are logged in a consistent manner and addressed and communicated to the appropriate stakeholders in a timely manner; b. actively monitoring remediation actions and ensuring that processes are in place to test the post-remediation environment; and c. coordinating with the City Clerk to integrate the privacy incident response process with the Office of the CISO's Cyber incident response plan and Technology Services Division's Major Incident Management process. These actions should be considered in addition to the Auditor General's previous recommendation included in the report entitled "Establishment of City-wide Cybersecurity Breach Incident Management Procedures Required". 3. City Council request the Chief Technology Officer to enhance project governance by: a. ensuring all projects fully comply with the Project Review Team gating approvals. Exceptions relating to cybersecurity and privacy should be reviewed by the Chief Information Security Officer and the City Clerk for a Go/No-go decision; b. ensuring project management gating criteria include a clear support transition plan when projects move from development to operations or from one stage to the next, depending on which project management methodology is used, such as Agile project management; and c. ensuring project managers are trained in change management methodology. 4. City Council request the Chief Technology Officer in coordination with the Chief Information Security Officer and the City Clerk develop a training program for project managers and key staff involved in the implementation of technology initiatives to receive cybersecurity and information privacy training focused on managing technology projects. In addition, the Chief Information Officer conduct an assessment to determine the feasibility of extending this training program to major agencies and corporations. 5. City Council request the Chief Technology Officer to enhance the project governance and project management framework by ensuring: a. all stakeholders' roles and responsibilities are clearly defined and key stakeholders are involved from the project initiation stage; b. a clear support transition plan when project is moved from development to operations at Gate 4, the last gate before the system is moved to operations; c. the City Clerk and the Chief Information Security Officer are part of the project steering committee for all key technology initiatives and transformations that involve privacy and security risks; and d. criteria are developed to determine projects with high risks that have not been mitigated prior to moving to production be escalated to the Senior Leadership Team (SLT). The developed criteria should be shared with the City Manager for city-wide implementation. 6. City Council request the Chief Technology Officer to enhance project management framework by including a review of internal controls for systems that involve financial transactions. The Controller's Office or Internal Audit should be involved in the review of user roles in relation to financial transaction processing to ensure appropriate segregation of duties is maintained for all user roles. 7. City Council request the Chief Technology Officer improve the user permissions framework of the Human Resources application. This includes: a. conducting the cybersecurity and information privacy review of the various roles created in the HR system; b. reviewing the users with a Super Administrator role and limiting the number of users with that role considering the industry's best practices and professional bodies; c. ensuring that user access roles are designed with cybersecurity and information privacy in mind. The access roles should be provided to users on a 'need to have' basis; d. defining a process for the approval of access roles for support staff. Instead of providing Super Administrator access, the support staff should be provided access on a 'need to have' basis; and e. eliminating the use of generic and anonymous accounts. If these roles are needed as an exception for operational reasons, detailed monitoring and logging procedures should be developed and implemented for these roles. In addition, the review of elevated access roles, use of generic or anonymous users should be extended to the SAP enterprise application. 8. City Council request the Chief Technology Officer to develop standards and minimum criteria for logging user activity details for IT systems. Steps include but are not limited to: a. ensuring user access logs capture account activity for users with elevated access, such as, users with Super Administrator or Divisional Administrator roles; and b. implementing a user activity review process for roles with elevated access on a periodic basis to ensure access is aligned with the role. 9. City Council request the Chief Technology Officer to implement a process to ensure comprehensive system testing and user acceptance testing is part of the overall IT project management methodology. This includes: a. assigning staff having subject matter expertise in Technology Services Division or Office of the Chief Information Security Officer to review the test scope, test cases and test cycle defect management; b. ensuring that user acceptance testing is started early in the project stage and performed by respective divisions (users). In situations where, testing is performed by staff other than the User Division, the test results must be formally approved by the respective Division Lead contact on the project; and c. ensuring each test cycle go through a formal approval process and mandatory security testing prior to commencing the next test cycle. 10. City Council request the Chief Technology Officer to research options to automate the move of configuration of systems from testing to the production environment. Alternatively, include a peer review (Quality Assurance) to verify post implementation configuration in the system after it has been moved to the production environment.
AU8.9adopted
Over the past decade, the City of Toronto, like other large organizations, is increasingly conducting business and key operations online in a networked environment. This makes operations more efficient and citizens are served better. The purpose of this report is to communicate security incidents that occurred at a City division and a City organization and to highlight the importance and urgency for the City to have a standard incident management process developed and implemented across City divisions and its agencies and corporations. A standard incident management process will enable the Chief Information Security Officer (CISO) to analyze these attacks and develop a coordinated response on any potential cyberattacks. This will enhance City-wide cybersecurity. In a 2019 Report for Action, the Auditor General highlighted the importance and urgency for the City to develop a standard incident management process and implement it across City divisions, agencies and corporations. We have made additional recommendations in one other report entitled "Information Technology Projects Implementation: Information Privacy and Cybersecurity Review of Human Resource System" that is also being tabled at the February 16, 2021 Audit Committee. The confidential report attached provide more details of the nature of incident and management actions. The work performed in relation to this report does not constitute an audit conducted in accordance with Generally Accepted Government Auditing Standards (GAGAS). However, we believe we have performed sufficient work and gathered sufficient appropriate evidence to provide for a reasonable basis to support our observations and recommendations. This public report contains two administrative recommendations. The confidential information and recommendations are presented separately to this report in Confidential Attachment 1. The confidential report will be made public at the discretion of the Auditor General after discussing with appropriate City Official.
The Audit Committee recommends that: 1. City Council request the Auditor General to provide presentations to City organizations, including major agencies and corporations, on the City cybersecurity reports and lessons learned. 2. City Council adopt the confidential instructions to staff in Confidential Attachment 1 to the report (February 4, 2021) from the Auditor General. 3. City Council request the City Manager to forward Confidential Attachment 1 to the report (February 4, 2021) from the Auditor General to City Division Heads and Chief Executive Officers of major City agencies and corporations and request them to review and implement the confidential instructions that may be relevant to their respective operations. 4. City Council direct that Confidential Attachment 1 to the report (February 4, 2021) from the Auditor General be released publicly at the discretion of the Auditor General, after discussions with the appropriate City Officials, as it contains information involving the security of property belonging to the City or one of its agencies and corporations and information explicitly supplied in confidence to the City of Toronto which, if disclosed, could reasonably be expected to impact the safety and security of the City and its services.
Staff recommendation as filed
The Auditor General recommends that: 1. City Council request the Auditor General to provide presentations to City organizations (major agencies and corporations) on the City cybersecurity reports and lessons learned. 2. City Council adopt the confidential recommendations contained in Confidential Attachment 1 to the report (February 4, 2021) from the Auditor General. 3. City Council direct that Confidential Attachment 1 be released publicly at the discretion of the Auditor General, after discussions with the appropriate City Officials, as it contains information involving the security of property belonging to the City or one of its agencies and corporations and information explicitly supplied in confidence to the City of Toronto which, if disclosed, could reasonably be expected to impact the safety and security of the City and its services. 4. City Council request the City Manager to forward Confidential Attachment 1 to City Division Heads and Chief Executive Officers of major City agencies and corporations and request them to review and implement the recommendations that may be relevant to their respective operations.
AU8.10adopted
On October 23, 2020, the Audit Committee reviewed and amended two items, Item 2020.AU6.1, Employee Health Benefits Fraud Involving a Medical Spa and Item 2020.AU6.4, Continuous Controls Monitoring Program: Opportunities to Reduce Cost of Dental Benefits. Both items were considered by City Council on October 27, 28, and 30, 2020. During the review of the Order Paper on October 27, 2020, City Council adopted procedural motions to remove both items from the Audit Committee and bring it forward to City Council for consideration which were carried. City Council subsequently adopted both items without amendments. This report responds to the motions by providing the status of each of the recommendations within the October 23, 2020 Audit Committee reports referenced above.
The Audit Committee recommends that: 1. City Council direct that Confidential Attachment 1 to the report (February 1, 2021) from the Controller remain confidential in its entirety, as it contains advice on labour relations.
Staff recommendation as filed
The Controller recommends that: 1. City Council direct that the confidential information contained in Confidential Attachment 1 remain confidential in its entirety, as it contains advice on labour relations.
AU8.11adopted
Audit of Winter Road Maintenance Contracts - Fleet Services Division's Update
The purpose of this report is to report back to the Audit Committee in the first quarter of 2021 on which City and contracted vehicles are equipped with GPS devices and which others, if any, should have them. The Auditor General's Office recently completed the Audit of Winter Road Maintenance Program - Phase One: Leveraging Technology and Improving Design and Management of Contracts to Achieve Service Level Outcomes (Item 2020.AU6.2). The audit identified deficiencies in the reliability of the data provided by GPS (telematics) devices installed on contractor-owned, winter operations vehicles. The audit was considered by City Council on October 27, 28, and 30, 2020, with one motion requesting the General Manager, Fleet Services, to report back to the Audit Committee in the first quarter of 2021.
The Audit Committee recommends that: 1. City Council request the General Manager, Fleet Services to report to the Audit Committee in the fourth quarter of 2021 with recommendations on a fully integrated, enterprise-wide telematics solution and implementation plan for City of Toronto and contracted vehicles.
Staff recommendation as filed
The General Manager, Fleet Services recommends that: 1. City Council request the General Manager, Fleet Services, to report to the Audit Committee in the fourth quarter of 2021 with recommendations on a fully integrated, enterprise-wide telematics solution and implementation plan for City of Toronto and contracted vehicles.
AU8.12adopted
City of Toronto Audit Planning Report for the Year Ending December 31, 2020
KPMG LLP presenting the City of Toronto Audit Planning Report for the Year Ending December 31, 2020 for the 2020 audit of the consolidated financial statements for the City of Toronto, prepared in accordance with Canadian Public Sector Accounting Standards. The City of Toronto Audit Planning Report for the Year Ending December 31, 2020 includes KPMG LLP's views on COVID-19, group reporting, audit and business risks, audit materiality, quality control, initial audit engagement, and current developments and audit trends.
The Audit Committee: 1. Received the City of Toronto Audit Planning Report for the Year Ending December 31, 2020 (November 13, 2020) from Kevin Travers, Lead Audit Engagement Partner, City of Toronto and Related Entities, KPMG LLP and Paul Simonetta, Executive Relationship Partner, KPMG LLP for information.
Staff recommendation as filed
That: 1. The Audit Committee receive the City of Toronto Audit Planning Report for the Year Ending December 31, 2020 (November 13, 2020) from Kevin Travers, Lead Audit Engagement Partner, City of Toronto and Related Entities, KPMG LLP, and Paul Simonetta, Executive Relationship Partner, KPMG LLP, for information.
AU8.13adopted
Bob Gore, Robert Gore & Associates Chartered Professional Accountants, reporting on the Auditor General's Office for the City of Toronto - Report on the Results of Applying Specified Auditing Procedures to Financial Information Other Than Financial Statements for the Year Ended December 31, 2019.
The Audit Committee recommends that: 1. City Council receive the report (November 30, 2020) from Bob Gore, Robert Gore & Associates Chartered Professional Accountants for information.
Staff recommendation as filed
That: 1. City Council receive the report (November 30, 2020) from Bob Gore, Robert Gore & Associates Chartered Professional Accountants, for information.
AU8.14amended
Arenas - 2019 Audited Financial Statements (Report 2)
The purpose of this report is to provide the Audit Committee and City Council with the 2019 audited financial statements of Arenas. The 2019 audited financial statements for the eight City Arenas are presented to the Audit Committee after approval by their respective Boards or Committees of Management. The external auditor, Welch LLP, advise that where they have comments on internal controls, they would provide these by way of a report to the Board. Of the eight City Arenas, the audited financial statements for four Arenas were previously presented at the October 2020 Audit Committee. This report presents the Independent Auditor's Report, accompanying financial statements and, where applicable, the internal control letter for two additional City Arenas as well as the Independent Auditor's Report and accompanying amended (for Note 4) financial statements for one arena that was previously presented. The audits of the two remaining Arenas are in progress at the time of preparation of this report.
The Audit Committee recommends that: 1. City Council receive the 2019 audited financial statements and internal control letter for the George Bell Arena, the Ted Reeve Community Arena, and the Moss Park Arena in Attachments 1-3 to the report (February 4, 2021) from the Auditor General. 2. City Council request the City Manager, in consultation with the Board of Management of Ted Reeve Community Arena, to report to the November 2, 2021 meeting of the Audit Committee on the status of the implementation of the recommendations in the management letter (December 22, 2020) from Christa Casey, Partner, Welch LLP, and Kathy Steffan, Partner, Welch LLP in Attachment 2 to the report (February 4, 2021) from the Auditor General. 3. City Council request the City Manager to forward City Council's decision to the Board of Management of Ted Reeve Community Arena.
Staff recommendation as filed
The Auditor General recommends that: 1. City Council receive the 2019 audited financial statements and internal control letter of the Arenas attached to this report.
AU8.15adopted
Community Centres - 2019 Audited Financial Statements (Report 2)
The purpose of this report is to provide the Audit Committee and City Council with the 2019 audited financial statements of Community Centres. The 2019 audited financial statements for the 10 Community Centres are presented to Audit Committee after approval by their respective Boards of Management. The external auditor, Welch LLP, advise that they have provided their comments on internal controls to some organizations by way of a report to the Board. Of the 10 City Community Centres, the audited financial statements for nine Community Centres were previously presented at the October 2020 Audit Committee. This report presents the Independent Auditor's Report and accompanying financial statements for the remaining one Community Centre.
The Audit Committee recommends that: 1. City Council receive the 2019 audited financial statements for the Central Eglinton Community Centre in Attachment 1 to the report (February 1, 2021) from the Auditor General.
Staff recommendation as filed
The Auditor General recommends that: 1. City Council receive the 2019 audited financial statements of the Community Centre attached to this report.