A new audit shows the state Auditor General’s office violated telecommuting and wage overpayment laws, providing new fodder for criticism of Auditor General Malia Cohen, who is running for re-election on Nov. 3.
The audit found that two employees in the treasurer’s office violated state law by working remotely from Idaho, Tennessee and Alabama.
The findings, contained in a report released last week by the National Audit Office, detail cases of waste, inefficiency, misuse of state resources, contract breaches and “other inappropriate government activity” across state agencies investigated over a year.
Although the state’s human resources department issued a notice in early 2022 that employee requests to telecommute on a regular basis outside of California would not be approved, two unnamed employees with the title of “employee services manager” in the control office were found to be living out of state.
An employee has been working and living in Idaho since late 2020 but did not disclose the information to the agency, according to IP address records examined by the state auditor. The audit also reviewed public records showing the employee owned property in Idaho and held an Idaho-issued driver’s license.
“When we interviewed Manager A, he admitted to working in Idaho ‘nearly every day’ for approximately five years,” the audit said.
Some teleworking is allowed, but employees must work from a location where they can easily return to their designated work location during normal commuting hours, the audit said. The telecommuting policy only applies to employees who actively reside in California.
As part of a telecommuting program that had been in place for several years, the employee submitted a California address that he later explained belonged to a family member. He did not disclose his real address to his supervisor because he feared losing his job, the audit said.
The Office of the Comptroller is responsible for the accounting and expenditure of state financial resources.
Login data from the second employee’s IP address showed the employee accessed the Internet from Alabama in the second half of 2025, the audit said. She also sometimes logs in from Tennessee.
The audit found that she said in an email last year that she planned to move to Alabama. In interviews with auditors, she insisted she lived in California, although she sometimes worked in Alabama and Tennessee. The audit found her explanation “not credible.”
However, the audit said most telecommuting policies were not made clear to employees and recommended that the agency clarify obligations and hold employees to the rules. It also recommends some kind of disciplinary or corrective action. The two employees then left the finance director’s office, the audit said, but did not say whether that was the result of such behavior.
The audit also found that two employees in the controller’s office were overcharged $33,000 in wages, but the office spent more than a year trying to recoup the funds.
One employee eventually reached an agreement on the payment, but the Controller’s Office never resolved the issue with the other employee, in violation of state law.
At the same time, officials in the office were discussing filing a claim with the state to argue that the overpayments were not the fault of employees, the audit showed.
Herb Morgan, a Republican from San Diego who is running against Cohen in next month’s election, blasted Cohen’s office for its findings.
“The answer to an office that’s supposed to protect the public’s money and not be able to take back money that’s already been released is to find a way to release more money,” he said. “That’s not oversight. That’s the problem.”
A spokesman for Cohen’s office said the office implemented the auditor’s recommendations before the report was released.
The spokesman said the office “takes seriously its responsibility to protect public funds and strictly adheres to the accountability standards promoted by the state government”.
Regarding the overpayment, the second employee is currently working on a repayment plan, the spokesperson said. As for out-of-state workers, they did not disclose their actual work locations and instead listed California addresses, limiting the office’s ability to detect problems more quickly, the spokesperson said.
In another case, the audit found that a senior law enforcement official abused a confidential database to find family members and other employees without a legitimate business purpose. It did not name the state agency that employs the accused senior law enforcement official because doing so could lead to a breach of identity.
The audit describes the officer searching for the home addresses and vehicle information of six other employees. He searched for information on a deputy district attorney, a local county supervisor and other law enforcement officials without any “identifiable business need,” the audit said.
He reviewed data on more than 60 cars for sale online, and one of his family members later purchased one.
The officer told investigators he conducted multiple searches out of personal curiosity, but said other employees’ home addresses and vehicle information were part of a threat assessment. However, investigators found no documentation of any such threat assessment.
State agency leadership disciplined the officer, the audit said, without providing any details. His case was also shared with the local district attorney, who has the power to prosecute misuse of confidential government information, but the district attorney declined to pursue criminal charges, the audit said.
A total of nine cases were detailed in the audit. The state Auditor’s Office said the cases do not represent a complete picture of its review of improper government activity.
The information in the report “is only a subset of the cases we investigated to serve as a deterrent to state agencies and state employees so they can avoid similar inappropriate government activity,” the audit said.
The gender of the employees in the report may have been changed to protect their identities, the report said.