Onondaga Cortland Madison Board of Cooperative Educational Services – Building Access (S9-26-2)

Issued Date
August 14, 2026

[read complete report – pdf]

Audit Objective

Did Onondaga Cortland Madison Board of Cooperative Educational Services (OCM BOCES) officials properly manage and monitor building access accounts and devices?

Audit Period

July 1, 2024 – November 30, 2025

We extended our audit period to January 21, 2026, to review access activity logs.

Understanding the Audit Area

Building access controls are essential for enhancing security and enabling school officials to manage and monitor entry points within educational institutions. These systems authenticate a user through devices such as key fobs, keycards, badges, or similar technologies, helping to ensure only authorized individuals can enter school buildings. By limiting access in this way, schools can better safeguard their facilities and maintain a safe and secure environment for students, teachers, staff and visitors.

OCM BOCES utilizes a building access management system (system) with 1,308 active building access accounts (accounts), including 846 devices issued to current employees and 443 issued to non-employees, of which 251 are shared devices.1 Each of the OCM BOCES’ 12 buildings have a single public point of entry. Employees may also access the buildings through additional secured entry points, which require a device for entry.

Audit Summary

OCM BOCES officials did not properly manage and monitor building access accounts and devices (badges). As a result, there was a potential risk for unauthorized access to OCM BOCES school buildings, compromising building security and safety for students, teachers, staff and visitors. Specifically, of the accounts we reviewed, OCM BOCES had active, but unneeded, accounts with assigned badges in the system:

  • 141 active individual non-employee accounts and badges were not needed. One of these badges was assigned to an individual who OCM BOCES officials did not recognize and were unable to identify why this individual had access. 
  • 86 shared accounts and badges were not needed and should be deactivated. OCM BOCES officials could not locate 11 of these badges. 

In addition, OCM BOCES officials did not independently verify the background checks for 14 individual non-employees who had direct contact with students, such as third-party service providers, to whom they provided accounts and badges.

Although OCM BOCES officials had a written procedure for adding accounts in the system for employees and non-employees, there was no process to promptly disable or delete accounts when no longer needed. Furthermore, these issues occurred because no one periodically reviewed active accounts to determine whether they were needed. 

The report includes four recommendations that, if implemented, will help OCM BOCES officials improve management and monitoring of building access accounts and badges. OCM BOCES officials generally agreed with our recommendations and their response is included in Appendix B. Appendix C includes our comments about issues raised in OCM BOCES’ response.

This audit was conducted pursuant to Article V, Section 1 of the State Constitution and the Office of the New York State Comptroller’s (OSC’s) authority as set forth in Article 3 of New York State General Municipal Law (GML). The audit’s methodology and standards are included in Appendix D. 

The OCM BOCES Board of Education (Board) has the responsibility to initiate corrective action. A written corrective action plan (CAP) that addresses the findings and recommendations in this report must be prepared and provided to our office within 90 days, pursuant to Section 35 of GML, Section 2116-a (3)(c) of the New York State Education Law and Section 170.12 of the Regulations of the Commissioner of Education. To the extent practicable, implementation of the CAP must begin by the end of the next fiscal year. For more information on preparing and filing your CAP, please refer to the OSC brochure, Responding to an OSC Audit Report, which was provided with the draft audit report. The CAP should be posted on the OCM BOCES’s website for public review.


1 A shared account or device is assigned to a user for a specific role or function but not assigned to a specific individual (e.g., vendors or first responders).