Colorado Springs adopts new rules for council-requested audits

The revised charter requires three councilmembers to start scoping an off-plan audit and five to authorize it, while setting recurring reports on audit work and hotline trends.

Published El Paso County

Colorado Springs City Council has adopted a revised Internal Audit Charter that sets a two-step process for requesting audits outside the city auditor’s annual plan and establishes regular reporting on audit work, resources and hotline trends. The charter took effect Sept. 22. The adopted charter and Resolution 77-26 place the auditor’s reporting relationship with the full council and align the office’s mandate with the Institute of Internal Auditors’ 2024 standards.

Three councilmembers must concur to initiate consideration of an audit outside the plan. The city auditor then prepares a scoping memo outlining the audit’s objectives, timing and resource needs for council review. Five councilmembers must concur before the audit can proceed. Once approved, it is added to the audit plan and included in later status updates.

The charter also preserves the auditor’s professional role in setting audit priorities. Councilmembers, the Audit Committee, city staff and residents may suggest topics for consideration, but suggestions do not require the auditor to conduct an audit. The auditor develops a risk-based plan, while the council provides collective oversight. Individual councilmembers cannot direct the auditor or audit staff. The five-member Audit Committee, which includes councilmembers and citizen members, is advisory rather than operational.

The reporting schedule gives council and the committee recurring ways to monitor the office. Quarterly updates cover audit-plan progress, significant changes and results, staffing and resource use. Semiannual hotline reports cover trends, case outcomes and risk observations; the charter calls for immediate notice to council of a substantiated high-risk fraud or abuse case. Audit reports are delivered as work is completed, and annual follow-up reporting tracks management actions on recommendations and unresolved findings.

At least annually, the auditor must report on independence, the risk-based plan and assessment, resources, significant risks and control issues, audit results and follow-up, and the office’s quality program and conformance with professional standards. An external quality assessment is required at least every five years.

The charter requires reports to council and the Audit Committee but does not guarantee that every briefing or report will be made public. Committee draft reports, working papers and other work products remain confidential until the auditor publishes them.