Audit Objective
Did Batavia City School District (District) officials properly manage and monitor building access accounts and devices?
Audit Period
July 1, 2024 – November 30, 2025
We extended our audit period to January 22, 2026 to review access activity logs.
Understanding the Audit Area
Building access controls are essential for enhancing security and enabling school officials to manage and monitor entry points within educational institutions. These systems authenticate a user through devices such as key fobs, keycards, badges, or similar technologies, helping to ensure only authorized individuals can enter school buildings. By limiting access in this way, schools can better safeguard their facilities and maintain a safe and secure environment for students, teachers, staff and visitors.
The District utilizes a building access management system (system) with 749 active building access accounts (accounts), including 601 access devices issued to current employees and 191 issued to non-employees, of which 35 are shared devices.1 Each of the District’s five buildings has a single public point of entry. Employees may also access the buildings through additional secured entry points, which require a device for entry.
Audit Summary
District officials did not properly manage and monitor building access accounts and devices (key fobs). As a result, there was a potential risk for unauthorized access to District school buildings, compromising building security and safety for students, teachers, staff and visitors. Specifically, of the accounts we reviewed, the District had active, but unneeded, accounts with assigned key fobs in the system:
- 16 District employees had a total of 34 active key fobs, including one employee who was assigned four active key fobs.
- Seven non-employee key fobs we identified were not deactivated when no longer needed.
- Four shared key fobs, which District officials could not locate and had no record of whom they were provided to, were not deactivated.
Although District officials had a process for adding accounts in the system for employees and non-employees, no one periodically reviewed active accounts to determine whether they were needed. Furthermore, these issues occurred in part because District officials did not establish written procedures that clearly assigned who was responsible for managing and monitoring accounts or develop written policies and procedures for issuing and monitoring key fobs.
This report includes four recommendations that, if implemented, will help District officials improve management and monitoring of building access accounts and key fobs. District officials agreed with our recommendations and have initiated or indicated they planned to initiate corrective action.
This audit was conducted pursuant to Article V, Section 1 of the State Constitution and the State Comptroller’s (OSC’s) authority as set forth in Article 3 of New York State General Municipal Law (GML). The audit’s methodology and standards are included in Appendix C.
The Board of Education (Board) has the responsibility to initiate corrective action. A written corrective action plan (CAP) that addresses the findings and recommendations in this report must be prepared and provided to OSC within 90 days, pursuant to Section 35 of GML, Section 2116-a (3)(c) of the New York State Education Law and Section 170.12 of the Regulations of the Commissioner of Education. To the extent practicable, implementation of the CAP must begin by the end of the next fiscal year. For more information on preparing and filing your CAP, please refer the OSC brochure, Responding to an OSC Audit Report, which was provided with the draft audit report. The CAP should be posted on the District’s website for public review.
1 A shared account or device is assigned to a user for a specific role or function but not assigned to a specific individual (e.g., vendors or first responders).