Colorado IT office aims to complete 82% of 102 audit findings by 2026
The office also targets 98% by the end of the fiscal year and completion of all findings a year later. Auditors review evidence after OIT submits work as complete.
Published at
Colorado’s Office of Information Technology aims to complete 82% of 102 open audit findings by the end of calendar 2026, its director told lawmakers. The office’s later targets are 98% by the end of the fiscal year and all findings one year later.
At an Oct. 6 meeting, OIT Executive Director and Chief Information Officer Sarah Tunberg told the Joint Technology Committee that two audits remained open. She said OIT submits findings when it considers them complete. Auditors then review the evidence, provide feedback and may ask OIT to revise its submission, so OIT’s implementation status does not necessarily mean an auditor has accepted or closed a finding. In its 2025 statewide audit, the Office of the State Auditor assessed part of a prior recommendation as only partially implemented, although OIT considered it implemented.
The targets are separate from the state’s statutory oversight process. Under Senate Bill 26-185, OIT’s security officer must report annually to the committee on compliance with security standards and open State Auditor recommendations, including remediation timelines and mitigation plans. Agencies must provide requested access and information for system evaluations.
The law also allows the Joint Technology Committee, within 90 days after a compliance report is filed, to vote to ask the Legislative Audit Committee to direct a special security audit. That option applies if a State Auditor recommendation remains unresolved at least two years past its implementation date, or if the compliance report materially conflicts with a prior audit finding. The statutory process is distinct from OIT’s percentage targets.