Audit Objective
Did Palmyra-Macedon Central School District (District) officials appropriately inventory, track and safeguard information technology (IT) assets?
Audit Period
July 1, 2024 – June 18, 2026
Understanding the Audit Area
District officials are responsible for establishing procedures to appropriately inventory, track and safeguard IT assets and ensuring those procedures are followed because maintaining complete and accurate inventory records and appropriately tracking and safeguarding IT assets helps officials account for district resources and reduces the risk that assets and the information they contain are lost, stolen, misused or accessed by unauthorized individuals.
From July 1, 2024 through April 30, 2026, the District purchased IT assets totaling approximately $655,100.
Audit Summary
District officials did not appropriately inventory, track and safeguard IT assets. Because the Board of Education (Board) did not adopt an IT asset inventory policy, District officials lacked detailed guidance for the maintenance of IT asset inventory records. As a result, the Director of Instructional Technology (Director) did not maintain complete, accurate and up-to-date inventory records to properly account for IT assets. Specifically:
- The District’s IT asset inventory records did not include all IT assets and none of the IT asset inventory records contained adequate information to sufficiently track or identify the District’s IT assets.
- The records had incomplete or inaccurate information and did not contain certain asset-identifying information, such as an asset’s serial number, make and model, location, employee or student assigned, acquisition date, cost and disposal date.
- Although the Director and an IT Department employee told us that they conducted annual physical inventory counts, these were not documented to support that IT assets were properly accounted for and safeguarded.
The lack of adequate IT asset inventory records exposes IT assets to loss, theft or misuse. During our physical inventory walkthrough, and subsequent Director follow-up, District officials were unable to locate one of the 50 IT assets we selected for testing, which was a printer costing approximately $400.
The report includes three recommendations that, if implemented, will improve the District’s processes for inventorying, tracking and safeguarding IT assets and help ensure IT assets are properly accounted for and protected from loss, theft or misuse.
This audit was conducted pursuant to Article V, Section 1 of the State Constitution and the Office of the New York State Comptroller’s (OSC’s) authority as set forth in Article 3 of the New York State General Municipal Law (GML). The audit’s methodology and standards are included in Appendix C.
The Board has the responsibility to initiate corrective action. A written corrective action plan (CAP) that addresses the findings and recommendations in this report must be prepared and provided to OSC within 90 days, pursuant to Section 35 of GML, Section 2116-a (3)(c) of the New York State Education Law and Section 170.12 of the Regulations of the Commissioner of Education. To the extent practicable, implementation of the CAP must begin by the end of the next fiscal year. For more information on preparing and filing the CAP, please refer to the OSC brochure, Responding to an OSC Audit Report, which was provided with the draft audit report. The CAP should be posted on the District’s website for public review.