Audit Objective
Did Orange-Ulster Board of Cooperative Educational Services (OU BOCES) officials properly manage and monitor building access accounts and devices?
Audit Period
July 1, 2024 – November 30, 2025
We extended our audit period to March 11, 2026, to review access activity logs.
Understanding the Audit Area
Building access controls are essential for enhancing security and enabling school officials to manage and monitor entry points within educational institutions. These systems authenticate a user through devices such as key fobs, key cards, badges, or similar technologies, helping to ensure only authorized individuals can enter school buildings. By limiting access in this way, schools can better safeguard their facilities and maintain a safe and secure environment for students, teachers, staff and visitors.
The OU BOCES utilizes a building access management system (system) with 1,535 active building access accounts (accounts), including 1,414 devices issued to current employees, and 121 issued to non-employees, of which 21 are shared devices.1 Each of the OU BOCES’s eight school buildings has a single public point of entry. Employees may also access the buildings through additional secured entry points, which require a device for entry.
Audit Summary
OU BOCES officials did not properly manage and monitor building access accounts and devices (badges). As a result, there was a potential risk for unauthorized access to OU BOCES school buildings, compromising building security and safety for students, teachers, staff and visitors. Specifically, of the accounts we reviewed, OU BOCES had active, but unneeded, accounts with assigned badges in the system:
- 102 OU BOCES employees had two or more active badges, including six employees who were assigned as many as three active badges.
- 30 non-employee badges including four shared badges were not tracked or disabled when no longer needed.
- 28 active badges which OU BOCES officials could not locate, including 16 duplicate employee badges and three shared badges.
Although OU BOCES officials had a process for adding accounts in the system for employees and for non-employees, no one periodically reviewed active accounts to determine whether they were needed. Furthermore, although OU BOCES officials developed written procedures requiring the Safety and Security Department and the Technology Department to regularly review active badges to ensure individuals are promptly removed when access is no longer needed, the procedures were not effectively implemented and responsibilities for performing and documenting these reviews were not clearly defined.
This report includes four recommendations that, if implemented, will help OU BOCES officials improve management and monitoring of building access accounts and badges. OU BOCES officials generally agreed with our recommendations and their response is included in Appendix B.
This audit was conducted pursuant to Article V, Section 1 of the State Constitution and the State Comptroller’s (OSC’s) authority as set forth in Article 3 of New York State General Municipal Law (GML). This audit’s methodology and standards are included in Appendix C.
The OU BOCES Cooperative Board (Board) has the responsibility to initiate corrective action. A written corrective action plan (CAP) that addresses the findings and recommendations in this report must be prepared and provided to OSC within 90 days, pursuant to Section 35 of GML Section 2116-a (3)(c) of the New York State Education Law and Section 170.12 of the Regulations of the Commissioner of Education. To the extent practicable, implementation of the CAP must begin by the end of the next fiscal year. For more information on preparing and filing the CAP, please refer to the OSC brochure, Responding to an OSC Audit Report, which was provided with the draft audit report. The CAP should be posted on OU BOCES’ website for public review.
1 A shared account or device is assigned to a user for a specific role or function but not assigned to a specific individual (e.g., vendors or first responders).