rocket domain was triggered too early. This is usually an indicator for some code in the plugin or theme running too early. Translations should be loaded at the init action or later. Please see Debugging in WordPress for more information. (This message was added in version 6.7.0.) in /home/leftri6/public_html/wpexplore/wp-includes/functions.php on line 6170megamenu-pro domain was triggered too early. This is usually an indicator for some code in the plugin or theme running too early. Translations should be loaded at the init action or later. Please see Debugging in WordPress for more information. (This message was added in version 6.7.0.) in /home/leftri6/public_html/wpexplore/wp-includes/functions.php on line 6170acf domain was triggered too early. This is usually an indicator for some code in the plugin or theme running too early. Translations should be loaded at the init action or later. Please see Debugging in WordPress for more information. (This message was added in version 6.7.0.) in /home/leftri6/public_html/wpexplore/wp-includes/functions.php on line 6170~
Government finance teams have never faced more obligations with fewer resources. As key personnel retire or leave for other opportunities, organizations risk losing institutional knowledge around managing critical finance functions like debt service and reporting. At the same time, new accounting standards around items like leases and subscriptions have added layers of complexity to already overstretched personnel.
If your state or local government finance team is still tracking your accounting and disclosures manually or relying on trustees to notify you about debt service payments, technology solutions may provide a way to ease key pain points and help you better manage your debt.
Many finance teams currently rely on elaborate Excel spreadsheets to track balances, payments, and disclosures related to municipal bonds, notes, loans, and other debt obligations. This reliance introduces a high degree of risk, as a departure or error by the one staff member familiar with the spreadsheet structure can lead to miscalculations and missed payments. Excel’s limitations in providing an audit trail and reporting functionality further hinder robust financial management.
Amid growing debt and lease burdens, state and local governments are also suffering acute talent losses as employees seek better compensation or workplace flexibility elsewhere. Governments face a shortage of personnel skilled in specialized areas like defeasance, premium amortization, and derivative valuation — aggravated by constant turnover and migration between organizations. This lack of a stable workforce poses a threat to effective fiscal management, leaving critical positions vacant. Relying on a sole employee or only a few individuals for complex accounting and debt management exposes your organization to the risk of disruption if those key people leave.
With manual systems taxing finance teams, increasing the potential for error, and becoming more challenging as demands on human resources grow, many state and local governments have turned to debt management software as a solution. This technology offers a lifeline for state and local governments by automating key elements of the debt lifecycle while improving controls and staff productivity. Municipal debt management software handles complex calculations and disclosures — including amortization schedules, refunding eligibility, premium and discount calculations, gains or losses on refunding calculations, costs of issuance amortization, defeasance tracking, and custom reporting.
Here are five critical ways debt management automation can help improve your efficiency and empower your team:
Many government finance teams rely on multiple disconnected data sources — from Excel spreadsheets to paper records in filing cabinets. By eliminating decentralized information and data silos, automated systems provide a consolidated view and a single source of truth, thereby significantly decreasing the likelihood of using outdated or conflicting information.
Manual financial calculations (such as premium/discount amortization) open the door for errors. A few mistakes can lower trust and confidence in the data, raising questions around the accuracy of the reporting. Acting as a safeguard against errors in high-stakes financial transactions, automated systems ensure precise calculations — reducing the potential for human error and the chances of missing a debt service payment or creating material misstatements.
The professionals on your team who are “Excel wizards”, creating intricate formulas to simplify accounting tasks, are great… until they leave or retire, and other people have to step into their roles and recreate or unravel their work. Automated systems provide consistency and accuracy, reducing the risk associated with relying on intricate Excel systems and mitigating disruptions due to sudden departures.
Many finance teams are still struggling to put processes in place to remain compliant with new lease and subscription accounting standards from the Governmental Accounting Standards Board (GASB). Automated cloud-based software significantly eases the implementation workload, helping track contracts, aggregate data, and generate reports required for GASB-87 and GASB-96 compliance.
Time is a valuable commodity for any professional. This is particularly true for state and local government finance teams, which are often understaffed and crunched for resources. Automated solutions reduce reliance on manual processes, enabling your finance team to focus more on strategic initiatives rather than routine data entry. With less time drained by debt management, your people can focus more on critical operations.

With state and local governments facing expanding responsibilities and diminishing resources, automating critical finance functions like debt management presents a timely opportunity. Establishing more modern systems and streamlining processes allows state and local governments to manage debt and lease data more easily and accurately. By eliminating manual busywork, finance staff can focus their efforts on the important strategic projects and high value-add work that moves governments forward. And governments can make decisions founded on complete and consistent financial data.
One option to consider is DebtBook, a leading lease and debt management software for state and local governments that centralizes information and reporting. Public finance teams use DebtBook to create a durable system of record to track all current and historical debt obligations, including all changes over time (reallocation, defeasance, refinancing, etc.). DebtBook helps generate efficiencies across the organization — delivering data consistency and accuracy, while boosting collaboration across internal and external teams.
MGO, in partnership with DebtBook, can assist you with implementation of the system, entering your data, and educating your team on usage and maintenance*. Reach out to us today to learn more about how DebtBook can work for your state or local government.
*Services for audit clients are limited to those that do not impair independence, such as providing advice and validation services to ensure the integrity of the financial information that comes out of the system.
]]>~
At the start of the football season, sports analysts spend a lot of time talking about who will be the player to lead their team to a championship. Yet, as we learn year after year, championships are not won by a single player. It is a collective effort, based on an assembly of individuals pooling their talents together in pursuit of a common goal.
In sports, the common goal is a championship. In business, the goal is to generate profit by establishing customer loyalty for your products or services. In government, the goal is to make our communities ideal places to live, work, and play. To win in all these instances, you need a strong team with contributions from every player.
Football fans often hear the refrain, “offense wins games, but defense wins championships.” Government teams looking to achieve their goals should not overlook the necessity of a robust defense — with internal auditing giving you the upper hand over your opponent.
According to The Institute of Internal Auditors (IIA), internal auditing is an independent, objective assurance and consulting activity designed to add value and improve an organization’s operations. Internal auditing provides a systematic approach to evaluating and improving the effectiveness of governance, risk management, and controls processes.
To simplify: Your organization has goals (objectives). However, obstacles (risks) may exist that keep your organization from reaching its goals. You should develop strategies (internal controls) to prevent those obstacles from occurring, and continuously check to make sure your strategies are working properly (monitoring). To avoid confirmation bias — where you only seek and accept information that supports your goals — you should seek validation from an objective entity (internal audit) to evaluate if your strategies truly position your organization to succeed.
To accomplish all this, you need a coalition of talented individuals that can identify risks, strategize against them, prevent or detect risk infiltration, and consistently monitor emerging risks to provide guidance on how to stay ahead of the curve. In football terms, you need a strong defensive line!
Let’s say that risk is the offensive team. Its goal is to get into your organization’s end zone to disrupt operations. The quarterback could be a hacker, fraudster, or unintentional human error. The offensive team also has other formidable players: fraud risks, cyber-attack risks, liquidity risks, etc.
Organizations need a more skilled, agile, and experienced defensive team to counteract the activity of the risk offense. Enter IIA’s Three Lines Model. This defensive strategy executes three levels of protection designed to keep risk from causing extreme financial or other damage.
The Three Lines Model defines defensive roles and responsibilities as follows:
Let’s look at the organizational playbook to understand the goals of the offensive and defensive teams and the Three Lines defensive strategy.
Organizations are trying to prevent risks from disrupting operations and causing financial and/or other damages. If the risk team scores in your end zone, that means they have exposed a weakness in your organization. Depending on the weakness, it could cost you a little (inefficient operations) or it could cost you a lot (major cyberbreach with financial and reputational damages) … but it will cost you!

The first line of defense consists of the organizational staff associated with daily operations, delivery of goods and services, and identifying and addressing risks. For example, to minimize the risk of hacking via password breaches, this line would create a password policy and accompanying procedure, set up systems requirements accordingly, and follow the policy and procedures in daily operations.

The second line of defense consists of the organizational staff that monitor your organization’s adherence to its own policies and procedures and other required guidance (e.g., regulations, laws, etc.). For example, to ensure that your organization is following its policies and procedures for minimizing hacking via password breaches, this line would periodically analyze data to ensure compliance with internal guidance, industry best practices, etc.

The third line of defense consists of internal audit professionals with knowledge in various industries. Internal audit conducts real-time assessments and communicates any weaknesses in the first two lines. Using the prevention of hacking example from above, in addition to assessing password protocols and practice, internal audit may identify that your organization has improper access controls that increase the risk of hackers infiltrating your organization’s systems. Internal audit would provide recommendations for improvement and express urgency for corrective action.

Internal audit is not an adversary, it is part of your team. Internal audit collaborates with your management and staff, in real time, to understand your organizational goals, concerns, strengths, and weaknesses. Where external audit provides your management with an analysis of a snapshot in time, internal audit continuously and systematically provides value-added feedback to your management and your board and/or audit committee.
Internal audit assists with ensuring your organizational playbook(s) remain relevant. As the third or last line of defense, it analyzes the entire field (the organization) to make sure your defensive strategies (internal controls) are effective at averting risks from scoring (causing financial, operational, reputational, etc., losses).
Part of the analyses conducted by internal audit include (but are not limited to):
Internal audit strengthens your organization’s improvement efforts by bringing reinforcements to your already stellar team. The internal audit group delivers additional resource capacity, skills, and perspectives — including extensive knowledge about various industry standards as internal audit professionals are required to maintain continuing education in their specific areas of focus.
MGO has a defensive line that is ready and motivated to support your organization. Stacked with professionals experienced in areas like state and local government, fraud, audit and assurance, government audit, and cybersecurity, our team is diverse in thought, knowledge, and culture — and we bring those perspectives to the field for you. Contact us today to learn how our internal auditing solutions can boost your organization’s defense.

Coined in a 2004 United Nations report, the term “environmental, social, and governance” (and its accompanying acronym “ESG”) is less than 20 years old. Yet, you would be hard-pressed to find a boardroom today where ESG is not top of mind. It is not just businesses either — ESG is also an increasingly important topic of discussion within government organizations.
State and local governments use ESG-related information as a mechanism to measure and track priorities, footprints, and targets. As governments have matured, ESG reporting and presented information more consistently with year-to-year comparability, investors*, regulators, and the public-at-large have sought out this reporting to help them understand risk and the government entity’s ability to drive positive impact.
*Note: The term “investors” refers to those who are exploring and/or holding investments in government-issued securities (e.g., hedge funds, institutions, individuals, etc.).
To present ESG-related information to the public, many government entities develop and communicate robust “Climate Action Plans”. These plans highlight a myriad of information, including (but not limited to):
As Climate Action Plans continue to evolve, governments are commanding and allocating more financial resources to activate these plans. With the increased focus on climate-related initiatives presented in Climate Action Plans, we are seeing an expansion of ESG-related information disclosed within “Annual Comprehensive Financial Reports” across the country — a sign that financial disclosures are maturing to meet growing interests from investors, regulators, and the public-at-large.

The focus on non-financial risks (including, but not limited to, ESG-related risks) by investors and regulators continues to intensify. When we take a step back to analyze the trend, a few things become clear:
To dive deeper into that last point, where would a finance function start? The short answer is by increasing the integration and collaboration between a government entity’s environmental leaders and the finance functions. The longer answer is that government entities need to develop holistic approaches to collecting and reporting robust ESG-related information to meet the expectations of investors, regulators, and the public-at-large.
The bottom line: As the issuance of and investment in municipal securities continues to grow, the quality of ESG-related information disclosed to the public will need to be enhanced to meet the demands of investors.

With an increase in ESG-related disclosures in annual financial reports by government entities, recent interpretive guidance from the Governmental Accounting Standards Board (GASB) indicates that government entities can expect further scrutiny and regulation as these types of disclosures become more commonplace.
Essentially, it is important for your government to have a robust, well-communicated ESG “story” within a Climate Action Plan — but you also must provide investor-grade transparency within audited financial statements. Government entities are already beginning to meet this challenge. Two examples of local governments with a growing presence of ESG-related information in their Annual Comprehensive Financial Reports are the City and County of San Francisco and the City of Fremont.
The City and County of San Francisco transparently discloses both environmental and social initiatives, capturing details related to its Environmental Protection Fund, as well as specific details related to revenues received from state, federal, and other sources for the preservation of the environment.
The City of Fremont — which is much smaller in terms of population (~230,000) and financial resources (roughly $1.5 billion in total primary government assets from “government activities”) — depicts ESG-related information throughout its annual report, including but not limited to qualitative information in the “management discussion and analysis” section, as well as quantitative information related to “community development and environmental services.”
With ESG-related information becoming more integrated into investor decision-making, your government needs to focus on enhancing its Climate Action Plans and developing “investor grade” disclosures related to ESG risks and opportunities for inclusion within your traditional financial reporting. These initiatives will require additional financial resources and human capital to create and maintain — and further collaboration between environmental, social, and financial leaders will be needed to drive the change.
Incorporating ESG disclosures into financial reporting can pose challenges to states and local governments unfamiliar with ESG reporting standards. With experience providing ESG solutions, our State and Local Government Practice will work with your team to meet requirements and make information “investor-ready,” while also ensuring accountability and transparency.
]]>~
States and local governments are starting to receive the first round of funding from recent settlements with opioid manufacturers, distributors, and retailers. These funds present an important opportunity to make progress against the ongoing opioid crisis through expanded treatment and prevention efforts.
To ensure states and local governments seize the opportunity to combat the opioid epidemic, settlement creators established acceptable uses for how the money can be spent. These requirements were put in place to avoid a repeat of the tobacco settlement of the 1990s, where states reportedly only spent a small portion of funding on tobacco prevention and cessation programs.
The National Opioids Settlement includes specific language to prevent similar misuse, mandating that “at least 85% of the funds going directly to participating states and subdivisions must be used for abatement of the opioid epidemic.” Most states also require local governments to report annual settlement fund expenditures.
As your agency begins to receive, access, and report on funding from opioid settlements, here is an overview of allowable uses, as well as a detailed look at potential reporting requirements.
The opioid crisis has grown exponentially throughout the 2000s, ravaging communities and depleting resources. In response to this, more than 3,000 states and local governments filed lawsuits against opioid makers and distributors to recover tax dollars spent addressing the epidemic. The suits allege that these companies marketed opioids in misleading ways — downplaying risks, exaggerating benefits, and engaging in reckless distribution practices.
As a result of these lawsuits, several opioid manufacturers, distributors, and retailers agreed to pay settlements totaling more than $50 billion to states, counties, and municipalities. The payouts for these settlements will be made incrementally over periods ranging from 6-18 years. Each state’s share of the total settlements is calculated based on factors such as overall population, opioid shipment volumes, opioid use disorder rates, and overdose deaths. Distribution metrics vary from state to state as determined by state legislatures.
The settlements require that funds are to be used for “opioid remediation” activities. To paint a clearer picture of what constitutes a remediation activity, the National Settlement Agreements provide Exhibit E, which outlines allowed uses. Exhibit E has two sections: Schedule A lists high-priority, evidence-based Core Strategies; and Schedule B lists an additional set of broader Approved Uses.
Here are examples of allowable uses for opioid settlement funds from both Schedule A and Schedule B:

Many states add further limitations on how these funds can be used. For example, California created its own High Impact Abatement Activities (HIAAs) list, and the state requires participating subdivisions to spend no less than 50% of their funds on HIAAs.
The idea is to ensure settlement fund expenditures are connected to addressing opioid misuse, treating opioid disorders, and mitigating the epidemic’s effects.
For example, the State of California Department of Health Care Services (DHCS) prohibits spending settlement funds on the following:
Local governments receiving settlement funds must prioritize effective reporting as they move forward. The specific reporting criteria you need to meet will depend on your state. Texas subdivisions currently have no reporting obligations, whereas California subdivisions will need to report expenditures annually.
What and how you report about your fund expenditures will also vary by state. For example, here are six aspects of settlement fund reporting specific to California that may or may not apply to your state (but nonetheless should be on your radar):

The opioid epidemic’s staggering cost defies calculation, with an estimated $1.5 trillion in damages in 2020 alone. Beyond the numbers lie lives lost, families shattered, and communities ravaged. While the National Opioids Settlement can never truly compensate for this immeasurable loss, it does offer states and local governments a chance to reshape the future.
With billions in abatement funding flowing to local communities over the next two decades, ensuring compliance with opioid settlement guidelines will enable you to maximize the impact of every dollar while avoiding the risks of non-compliance. Our experienced state and local government advisors can assist you in tracking allowable spending and meeting reporting requirements so that you can get the most out of these vital funds. Contact our practice today to learn more about how we can help your government achieve its goals.
]]>~
As a government leader, you are no doubt all-too-keenly aware of the challenges inherent in financing capital projects in your community. One popular option to fund infrastructure improvements in developing areas is forming special tax districts — with two of the most common variants being community facilities districts (CFDs) and infrastructure financing districts (IFDs).
While both these types of special tax districts share many similarities, it is their differences that can have a significant impact on how you report them in the financial statements of your organization. In this article, our State and Local Government professionals walk through what you need to know to successfully navigate special tax district reporting.
Before we dive into reporting, here is a glimpse at how each of these special tax districts work and how they are different from one another.
CFDs also known as Mello-Roos Districts (named for the lawmakers behind the legislation that created them), are a popular method of financing certain public capital facilities and services — especially in developing and rehabilitating areas. CFDs impose special taxes on property owners within the district, and proceeds can be used to fund any publicly owned facility with a useful life of five or more years.
This versatile special tax district has many eligible uses — including parks, libraries, childcare and recreation centers, storm drainage systems, and more. Developers frequently establish CFDs to fund initial infrastructure as an area is built out.
IFDs fund capital projects focused on large-scale, community-wide infrastructure needs. This includes major initiatives like highways, transit facilities, sewage treatment plants, dams, flood control systems, and other regionally significant projects.
Unlike CFDs, IFD funding comes from growth in property tax increment above a base-year level, redirecting tax revenue that would otherwise flow to participating jurisdictions like the city, county, and special districts. In essence, those entities waive their rights to extra revenue generated by growth in the IFD area until the established revenue retention period expires (this period may last up to 30 years).
Current accounting standards require your government to include in its financial statements the finances of “component units”. Component units are legally separate entities for which the elected officials of a primary government are financially accountable. The primary government is financially accountable if it appoints a voting majority of the entity’s governing body and: (1) it can impose its will on that entity or (2) there is a potential for the entity to provide specific financial benefits to, or impose specific financial burdens on, the primary government.
Under California law (different states may have different requirements), CFDs and IFDs are legally constituted governmental entities. They are established by and governed by your agency’s legislative body, whether that be the city council or county board of supervisors. This governance structure grants your government the ability to impose its will on the CFDs and IFDs since you can modify budgets or appoint key personnel. Moreover, IFDs create a financial burden by capturing property taxes that would otherwise fund services in participating jurisdictions.
Due to this financial accountability, CFDs and IFDs are considered component units and should be included in the financial reporting entity of the primary government. That means, as a primary government, you are required to report component unit financial information within your financial reporting entity’s financial statements.
While the objective of including component units in your financial statements is to provide an overview of your government based on financial accountability, the method of component unit inclusion – fiduciary, blended, or discretely presented – depends on the closeness of their relationship with your government.
To assess whether a special tax district like a CFD or IFD is a fiduciary activity for reporting purposes, ask these questions:
With CFDs and IFDs, the assets are typically controlled by your government but maintained for the benefit of the district (not external parties). Therefore, their relationships with your government generally do not qualify as fiduciary.
For IFDs, the revenue they receive by capturing incremental property taxes warrants blended reporting within your government’s financial statements. That means their activity is reported like any other fund – blended in the special revenue funds or other reporting units.
Treatment gets trickier for CFDs. The key factor is whether your government is obligated in any manner for repayment of the CFD’s bonded debt in the event of delinquencies or default by property owners. If your government must back the debt, the CFD is considered a financial burden and blending is appropriate. Blending makes the long-term debt obligation clearly visible to financial statement users.
However, if your government has no obligation for CFD debts, the CFD should be reported in fiduciary funds. Here, your government serves as an agent on behalf of property owners and the bondholders within the CFD. The debt service transactions are kept separate from other activities.

Complicating CFD and IFD reporting is the reality that major capital improvements are often funded by a combination of financing mechanisms. You may need to untangle several types of debt and financing sources – such as grants from other governments, general obligation debt, and special assessments. The reporting guidance on CFDs and IFDs is not one-size-fits-all.
As a steward of public resources, it is important to take care to consider all nuances of how districts are established and financed in your government. Accurately reporting CFD and IFD activities is central to upholding your responsibility to constituents. By proactively addressing district reporting, you also minimize audit issues or restatements down the road. Taking the time upfront to thoroughly understand the standards will pay dividends.
While financing capital projects may be challenging, you don’t have to figure it out alone. Our specialized State and Local Government team can guide you through the nuances of CFD and IFD reporting. Contact our professionals today to discuss how we can help you meet the highest standards of accountability and transparency.
]]>To prevent wasting valuable time and resources, it is important to perform assessments of policies, procedures and processes to identify inefficiencies and opportunities for improvement so your organization can succeed in its pursuits.
The COVID-19 pandemic acted as a catalyst for many state and local governments, demonstrating that improvements were needed when it came to their procurement and purchasing processes. Thanks to federal relief programs like the CARES Act, many organizations were able to receive the funds for economic assistance. But these programs had time constraints, meaning the money had to be spent within a relatively short time frame. Many state and local governments were interested in using the funds to purchase goods, such as personal protective equipment, and to contract with subrecipients to provide services to populations in need, such as the homeless.
However, the procurement and contracting processes took time — oftentimes, more time than the state and local governments had with the constraints set by the relief programs. This meant the funds could be wasted if the contracts were not pushed through in a timely manner.
Remote work, which was not prevalent before the pandemic, revealed issues for many state and local governments related to their lack of automated processes. For example, some organizations still collected “wet” signatures on resolutions and contracts instead of using digital programs like DocuSign. They only learned of inefficiencies like these when everyone was working from home, leaving them to wonder how to fix similar and additional issues plaguing them.
Say your organization has an IT department that has a workflow requiring its staff to manage requests in a certain way. Instead of “touching” the request just once and approving it, the purchasing employee must handle the same request three times. This is clearly inefficient, but oftentimes, state and local governments don’t realize the snags their departments are facing throughout their processes.
There are several reasons why this could be. For example, you could have a team that is stretched too thin, with several people doing multiple jobs — there are too many things to process and not enough resources, leading to things slipping through the cracks. Maybe the organization is facing a lot of turnover or new management, and without clearly outlined processes, no one is sure how to spread the workload effectively. Bottlenecks can arise, hindering progress further. Without documented procedures, roles, and responsibilities, your team won’t know who is responsible for what. And if your organization is decentralized — this can lead to even more confusion, slowing down procurement and contracting processes even further.
If one of your departments requires a red truck and puts in a request without any detail, your purchasing department, could take a guess and buy a red truck – which may or may not meet the needs of the department. There are many kinds of red trucks, and by the department not specifying what red truck they want, time is wasted, slowing down whatever project the red truck is needed for. Does the department need to haul something? Does it need four-wheel drive? What will it be used for? Purchasing departments know how to purchase goods and services, but rely on the other departments to provide specific details on what to purchase. Purchasing needs details — and back-and-forth communication is inefficient. The organization needs to set clear responsibilities to determine the scope so purchasing can do its job, making the process far more seamless.
Plainly, state and local governments face major hurdles when trying to get a contract out the door — it can take some governments six to eight months. With many steps, including bids, evaluations, approvals, and negotiations, the process can even stretch into the next fiscal year by the time it’s finally executed. The length of time is tedious — and unnecessary. Is there a way to make the length of time shorter, or make the process more efficient?
A third-party assessment of your procurement and contracting processes will tell you where the inefficiencies lie — and provide recommendations on how to fix them. All you need to know is the process isn’t working, and we can do the rest.
Here is a quick look at some of the steps of an assessment:
State and local governments have distinct responsibilities to their constituents. In order to meet their needs effectively, it is crucial that they identify oversights and fulfill any control duties as efficiently as possible.
At the end of the day, it can require a significant amount of time, resources, and effort for state and local governments to uncover issues and implement best practices. MGO delves deep, utilizing our extensive resources and professionals to go in, identify the issues, and recommend how to fix it — so your procurement and contracting processes flow more seamlessly, no matter your resources, staffing numbers, and size.
MGO’s dedicated State and Local Government team functions as an additional level of control to improve these important processes with comprehensive innovative strategies and solutions so you can focus on minimizing risk, optimizing performance, and exceeding the expectations of your boards, stakeholders, and communities. Contact us to learn more.
]]>State and local governments are frequently constrained by their budgets. Proactive planning spreads both effort and budget into a longer timeframe, which allows investments to be made incrementally and resources to be consistently allocated.
Because cyberattacks are nothing new, many organizations have already prepared some sort of response plan. However, because the pace of cyberattacks and the sophistication of hackers is constantly increasing, your plan should be updated at least annually. A robust plan is a living document that involves cross functional teams that include IT professionals and leadership.
Risks should be identified and prioritized so that urgent needs can be addressed with immediate investments. Although, the complete (or updated) plan may never be complete, the prioritized pieces of it will form a framework through which cybersecurity becomes an ongoing conversation, and a lens through which daily work is viewed.
A contingency plan should be in writing. The process of drafting a detailed plan that addresses many different scenarios is time consuming, and it is also necessary. The thought process and discussions that go into thinking through a robust response to a cybersecurity plan are valuable to the whole organization. When a cyberattack occurs, one of the greatest concerns is to stop the loss of sensitive information. Part of contingency planning will involve creating an information classification policy, so your information systems protect the highest value information with the highest level of security.
Contingency planning also involves a communication plan. In what order do you make phone calls to your incident response team, legal counsel, board of directors, insurance agent, or law enforcement? Who needs to know what, when? How do you document your actions?
If you think having these discussions is overwhelming and stressful in the planning stage, imagine what it would be like to try to make critical decisions when your firewall is open, your information systems are locked, and your daily work has come to a halt.
State and local governments often have older IT systems, some of which have been in use for 20 years. These systems require patches to prevent cybercrime, and in most cases, the various information systems do not “talk” to each other.
One of the first steps you can take is to update your information systems. Part of this may involve a discussion of a policy manual and potentially some training so that people are aware of the risks that are constantly evolving. A standing IT governance committee may initially be dedicated to the upgrade, and later take on the ongoing task of mitigating cyber risks throughout your organization.
Mitigating some of these risks might include reviewing your cyber insurance policies to ensure that you have adequate coverage for overall data recovery and the cost of business interruption. This committee should also review your backup policies and services to ensure reliable storage in a separate location that is tested periodically to ensure compliance with your contracts.
State and local governments should expect to be targeted — they have access to large amounts of personal information and data. Thus, it is crucial to have a plan that can be immediately put into action to protect this sensitive information for the people and communities you serve. Your response within the first 24 hours of the breach is critical to minimizing damage. With proper planning, even an aggressive attack can be survived with minimal losses.
If your organization is not yet prepared for a cyberattack, or you are interested in proactive planning against a breach, schedule a consultation with the MGO Technology Group or learn more about the services we provide here.
]]>The Governmental Audit Quality Center (GAQC) promotes the importance of quality governmental audits and the value of such audits to purchasers of governmental audit services. GAQC is a voluntary membership center for CPA firms and state audit organizations that perform governmental audits. The GASB Matters section of the GAQC site highlights key interest areas, key resources, and advocacy efforts related to state and local government engagements.
GASB Pensions: Issues & Resources page of the GAQC Web site consolidates the various resources available to practitioners to assist with understanding the new standards and developing appropriate audit strategies. This page also includes links to various whitepapers and related auditing interpretations addressing cost-sharing and agent multiple-employer plans.
Comment Letters
The SLCIA updates the Homeland Security Act of 2002 to give the DHS leeway to utilize centers like the Cybersecurity and Infrastructure Security Agency (CISA) and Multi-State Information Sharing and Analysis Center (MS-ISAC). This will allow them to work with state, local, tribal, and territorial governments as needed, upon request.
This collaboration will encourage conducting cybersecurity exercises and hosting trainings meant to address current or future cyber risks or incidents. It will also provide operational and technical assistance to state and local governments to implement security resources, tools, and procedures to improve overall protection against attacks. The goal is to provide state and local governments with the support they need to defend themselves from hackers.
The SLCIA establishes a $500 million DHS grant program that will empower government institutions to increase their focus on cybersecurity. The bill also:
The bill gives state and local governments the push they need to begin defending their networks. This can include the development of new strategies to boost their cybersecurity capabilities and acquisition of the funding needed to ensure their implementation. By investing in cybersecurity ahead of an attack, an entity is more likely to save money and protect its data.
Cybersecurity grants are available to municipalities of all sizes — but it’s important to start strategizing now by considering your IT infrastructure and cybersecurity frameworks. By applying for the grants, you indicate that you are taking your entity’s security seriously and taking the proper steps to qualify.
The State and Local Cybersecurity Improvement Act will provide up to $1 billion in grants for state, local, tribal, and territorial governments, allowing them to directly address their cybersecurity threats and risks. The program’s funding starts at $2 million for 2022, $400 million for 2023, $300 million for 2024, and $100 million for 2025.
To be eligible, an entity must:
While the bill is still waiting on the Committee on Homeland Security and Governmental Affairs there are some things you can do to make sure you are ready. State and local governments should focus on building teams that can handle the grant application process — and be prepared to implement once awarded. This bill indicates that governments are past the point of merely updating a firewall or running a generic virus program — things like multifactor authentication and zero-trust architecture are viewed as the next steps (which was required for federal agencies in a 2021 executive order).
Prior to starting the grant application process, your IT leaders should start thinking about how to handle security gaps with various procedures and consistent tests. MGO can help. Our Technology and Cybersecurity team can provide guidance as you prepare for the future.
Francisco Colon is a Partner at MGO with extensive experience in external audit, fraud examinations, litigation support, operational and internal controls reviews, and buyer/seller due diligence. He specifically focuses on assisting organizations with evaluating and updating their internal controls with a focus on strategic alignment and fraud litigation deterrence management in a variety of industries, including tribal government, gaming, technology, cannabis, hospitality, government contracting, distribution, manufacturing, and private equity. Contact Francisco at FColon@mgocpa.com.
]]>Reporting and disclosure of environmental, social, and governance (ESG)-related information has long been a priority in the private sector and is now emerging as a key area of focus for state and local governments (or “government entities”).
In response to interested parties seeking more ESG-related information (e.g., investors, credit rating agencies, preparers and auditors of financial statements, citizens, policymakers, etc.) from government entities, the Governmental Accounting Standards Board (GASB) has released a publication to clarify how ESG-related information intersects with their existing standards.
The bottom line: GASB’s stakeholders and interested parties are seeking to understand the impacts of ESG-related matters on a government entity’s cash flows, financial position, and overall responsibility for fiscal accountability — and the publication can be seen as a form of interpretive guidance to bridge the gap.
GASB’s “Intersection of Environmental, Social, and Governance Matters with Governmental Accounting Standards” document was released on May 31, 2022, and it provides clear examples for government entities to make new, or enhance existing, ESG-related disclosures by leveraging their current standards and principles.
Up front, the publication acknowledges that “a single consistent definition of ESG is not prevalent in practice today.” However, broad examples are included in the publication for each pillar (note, the below list has been shortened for purposes of this article):

The interpretive portion of the publication goes on to assist government entities with detailed examples of how ESG-related information coincides with the current GASB standards (note, the below are 3 of 25 total examples from the publication):

In publishing this document, GASB is taking a traditional first step to introduce concepts and guidelines that set a foundation ahead for new reporting and disclosure rules in the future (also referred to as “interpretive guidance”).
This is not the first time a regulator or standard setter has issued interpretive guidance specific to ESG. In 2010, the Securities and Exchange Commission (SEC) released their own interpretive guidance to provide clarity to the private sector on how to leverage existing financial reports to make disclosures related to climate change. While it was uncertain how many companies would incorporate climate-related information in their financial reports, many chose to do so (at last count by the SEC in 2020, 33% of the 6,644 filings submitted to the regulator contained some form of climate-related disclosure). The interpretive guidance, therefore, laid the groundwork for a new climate-related proposal issued by the SEC in March 2022.
Essentially, interpretive guidance has historically preceded the release of new, formal guidance and the creation of new standards. If this proves true in the public sector, then we will first see an increase from state and local governments enhancing their existing financial reports and disclosures by incorporating ESG-related information. Subsequently, and after further analysis by GASB of those enhanced disclosures, we will likely see the release of a new ESG-specific standard from GASB.
As demand for ESG-related disclosures increases, pressure will also increase on governments to begin providing or enhancing the disclosures in their financial reports. Further, if your entity issues securities (e.g., municipal bonds), you may encounter pressure from credit rating agencies depending on your approach (or lack thereof) to disclose and address ESG-related risks.
At present, ESG-related disclosures are contingent on a variety of factors (including but not limited to the government entity’s location, the historical or anticipated impacts of climate change, the level of ambition to become a leader in ESG-related reporting, etc.), but at some point these disclosures will shift from voluntary to mandatory.
Many state and local governments have proactively disclosed ESG-related information on their websites or in standalone ESG / sustainability reports; however, GASB’s interpretive guidance demonstrates that ESG-information also needs to be considered when preparing your annual financial reports.
To stay ahead, MGO is helping the public sector as well as the private sector, develop and enhance their ESG disclosure strategies.
If you are interested in learning more, schedule a conversation with our ESG team today.
]]>