Red Hook Central School District – Building Access (S9-26-7)

Issued Date
July 31, 2026

[read complete report – pdf]

Audit Objective

Did Red Hook Central School District (District) officials properly manage and monitor building access accounts and devices?

Audit Period

July 1, 2024 – November 30, 2025

We extended our audit period to January 21, 2026, to review access activity logs during our fieldwork.

Understanding the Audit Area

Building access controls are essential for enhancing security and enabling school officials to manage and monitor entry points within educational institutions. These systems authenticate a user through devices such as key fobs, key cards, badges, or similar technologies, helping to ensure only authorized individuals can enter school buildings. By limiting access in this way, schools can better safeguard their facilities and maintain a safe and secure environment for students, teachers, staff and visitors.

The District utilizes a building access management system (system) with 827 active building access accounts (accounts), including 457 devices issued to current employees, and 370 issued to non-employees of which 17 are shared devices.1 Each of the District’s three school buildings has one public point of entry. Employees may also access the buildings through additional secured entry points, which require a device for entry.

Audit Summary

District officials did not properly manage and monitor building access accounts and devices (badges). As a result, there was a potential risk for unauthorized access to District school buildings, compromising building security and safety for students, teachers, staff and visitors. Specifically, of the accounts we reviewed, the District had active, but unneeded, accounts with assigned badges in the system:

  • 37 District employees and 19 non-employees had at least two active badges.
  • 28 non-employee badges were not disabled when no longer needed. These included badges assigned to former employees, consultants and police officers, as well as three individuals that District officials did not recognize.

Although the District had a Board-established policy for issuing badges, including procedures for replacement and access modification, it was outdated and did not align with the District’s actual practices during the audit period. Additionally, there was no regular access review, and District officials neither assigned clear responsibility for account oversight nor ensured access request documentation was retained.

This report includes six recommendations that, if implemented, will help District officials and the Board of Education (Board) improve management and monitoring of building access accounts and badges. District officials generally agreed with our recommendations and their response is included in Appendix B.

This audit was conducted pursuant to Article V, Section 1 of the State Constitution and the State Comptroller’s (OSC’s) authority as set forth in Article 3 of New York State General Municipal Law (GML). This audit’s methodology and standards are included in Appendix C.

The Board has the responsibility to initiate corrective action. A written corrective action plan (CAP) that addresses the findings and recommendations in this report must be prepared and provided to OSC within 90 days, pursuant to Section 35 of the New York State General Municipal Law (GML), Section 2116-a (3)(c) of the New York State Education Law and Section 170.12 of the Regulations of the Commissioner of Education. To the extent practicable, implementation of the CAP must begin by the end of the next fiscal year. For more information on preparing and filing the CAP, please refer to the OSC brochure, Responding to an OSC Audit Report, which was provided with the draft audit report. The CAP should be posted on the District’s website for public review.


1 A shared account or device is assigned to a user for a specific role or function but not assigned to a specific individual (e.g., vendors or first responders).