Marion Watch

THE COST OF NON COMPLIANCE: MAYOR COLLINS RESPONDS TO SIXTEEN YEARS OF SILENT SABOTAGE IN MARION OHIO

Reading Time 8.42 mintues

For about sixteen years, the City of Marion operated on a financial and information technology foundation that was structurally unsound. The New World ERP system, deployed in 2009, was never properly configured, never fully implemented, and never maintained according to industry standards. As a result, critical financial controls failed, audit trails were incomplete or missing, and taxpayers paid for software features the city did not use.

Our investigation began because the symptoms were clear.

Reconciliation failures, unexplained financial discrepancies, missing audit logs, shared passwords, and disabled modules were not isolated issues. They were indicators of a system that had been mismanaged for more than a decade.

Our network includes systems administrators, legal professionals, financial analysts, and investigators with decades of experience.. The problems in Marion matched the same patterns seen in other cases where misconfigurations and poor oversight led to operational breakdowns. The forensic accounting firm Veritas identified many issues that were clues to a trained IT administrator and confirmation of Marion Watch and our network’s theories and suspicions.

Read the full Silent Sabotage Series below:


THE MAYOR’S REVELATION: YET ANOTHER CONFIRMATION OF SYSTEM FAILURE

In January 2026, Mayor Bill Collins took a step no previous administration had taken. After reviewing the annual Tyler Technologies maintenance invoice, he instructed the Auditor’s Office not to pay the 2026 bill, totaling 145,825.78, until the city could determine which modules were actually being used.

His review found that the city did not use 80 percent or more of the modules listed on the bill. Mayor Collins disclosed this to MarionWatch.com Investigates Friday.

From the Mayor’s email:


“We certainly should not be paying for things now or for the past I don’t know how many years that we don’t even use.”

This was not the first confirmation of Marion’s system failures. It was yet another confirmation of what our investigation had documented since 2019:

• The system was misconfigured from the beginning
• Critical modules were never used
• Financial controls were not functioning
• Audit trails were missing or disabled
• The city had been paying for unused software for more than a decade

A meeting with Tyler Technologies was scheduled for July 14, 2026, to conduct a line by line audit of the modules and costs.




THE IT DIRECTOR’S FAILURE TO RELEASE RECORDS

AND THE ESCALATING CONFLICT OVER ACCOUNTABILITY

This revelation came after a scorching email to the IT department and Marion City officials in response to our seven month old record request for logs or confirmation of inappropriate access, elevated permissions, and other serious violations. These issues have been corroborated by many current and former officials and city workers.

Critical records requested in December 2025 remain withheld, including:

• Historical user permissions
• Documentation of improper access
• Records of elevated administrative privileges
• Lists of former officials with write, modify, or delete access
• Internal misconduct reports
• Module configuration histories

These records are essential for reconstructing the system and determining who had access to public funds. Their continued denial is not a cybersecurity matter.

It is an accountability failure.


THE WEAPONIZATION OF CYBERSECURITY

Requests for operational information such as permissions, module configurations, or audit logs were labeled as security risks, even though they did not contain sensitive information. Operational failures are not cybersecurity threats. They are accountability records.





EARLY SIGNS FROM GO LIVE: MISCONFIGURED FROM THE FIRST DAY

The earliest signs of failure appeared immediately when the New World ERP system went live in 2009. From the first day of operation, the system displayed symptoms that only occur when an ERP is deployed without proper configuration of software safety modules or controls.

These indicators included:

• Reconciliation processes failing immediately
• Reconciliation cycles unable to complete
• General ledger controls not enforcing appropriation limits
• Modules installed but not functioning or drastically misconfigured
• Audit logs failing to populate or populating incomplete entries
• User accounts without appropriate role based access restrictions
• Errors and corruption consistent with rushed or skipped setup steps
• Illegal spending above appropriations

These symptoms are classic indicators of a rushed deployment where required configuration steps were skipped or performed incorrectly. Every failure that followed over the next sixteen years can be traced back to the same root cause:

THE SYSTEM WAS NEVER CONFIGURED CORRECTLY FROM THE BEGINNING.


UNDOCUMENTED WORKAROUNDS CREATED DURING THE CARR TENURE

Because the system was broken from go live, staff in the Auditor’s Office during the Carr administration began creating manual workarounds to keep daily operations functioning. These workarounds were not part of the New World system, not supported by the vendor, and not compliant with internal control standards.

These workarounds included:

• Manual reconciliation steps performed outside the system
• Spreadsheet based tracking to replace disabled modules
• Off the books adjustments to compensate for failed audit logs
• Informal processes for correcting general ledger errors
• Unlogged changes made directly in financial modules

None of these workarounds were documented.
None were shared with incoming staff.
None were preserved as part of the city’s operational record.

Incoming auditor staff were handed a system that did not work and were not told how previous staff had been compensating for its failures. This created several consequences:

• Incoming staff were blamed for failures they did not cause
• Critical knowledge was intentionally withheld
• The city’s financial accuracy deteriorated further
• Staff were forced to discover hidden workarounds through trial and error


OVERSIGHT FAILURES BY THE OHIO AUDITOR OF STATE

Beginning in 2019, our investigation uncovered a critical fact: staff within the Ohio Auditor of State’s Office were aware of many of Marion’s catastrophic internal control failures and did not act to force correction.

Under Ohio Revised Code 117.10 and 117.103, the Auditor of State must examine public office financial records, identify internal control weaknesses, issue findings, require corrective action, and ensure remediation. These requirements are not optional.

Despite knowing about:

• Disabled audit logs
• Shared administrative passwords
• Unused reconciliation modules
• Misconfigured general ledger override settings
• Undocumented workarounds
• Improper access levels
• Failed financial controls

No corrective action was ordered.
No findings were issued.
No remediation was enforced.

This failure allowed Marion’s broken system to continue for more than a decade.


LEGAL CONSEQUENCES FOR MISCONFIGURED SYSTEMS AND FAILED CONTROLS

Information technology systems and financial controls in public agencies are part of the legal framework that protects public funds. When those systems are misconfigured, intentionally disabled, or allowed to fail, responsibility does not fall only on IT staff. It also falls on administrators and elected officials who knew about the failures or allowed them to continue.

Under Ohio Revised Code 149.351, intentional destruction, concealment, or misconfiguration that prevents access to public records can result in civil liability and criminal penalties.

Federal courts have repeatedly treated serious IT failures as evidence of negligence or worse. Cases such as In re Capital One Data Security Breach Litigation, Guo Wengui v. Clark Hill PLC, and Rutter’s Data Breach Litigation show that disabled audit logs and misconfigured systems are central to determining responsibility.


BRIEF LEGAL FRAMEWORK FOR PUBLIC RECORDS DENIAL

Ohio’s Public Records Act requires agencies to provide public records and allows only narrow exemptions. In State ex rel. Mauk v. Sheldon, the Ohio Supreme Court held that withholding operational IT records, including access logs, constituted an unlawful denial of public records and warranted statutory damages.

Operational IT records such as usernames, permission levels, access logs, and module configurations are generally public records. Denying them outright is unlawful.


HOW BAD CONTROL CULTURES FORM AND WHY THEY WORSEN IF NOT STOPPED

The failures in Marion’s system did not begin with New World. They were part of a long pattern documented in audits from 1983, 1997, 1998, and 2009 through 2021.

The GAO Green Book and COSO Internal Control Framework both warn that weak control environments worsen over time, normalize improper practices, and increase the risk of fraud and mismanagement.

Marion’s long standing acceptance of shared passwords, missing security policies, unused reconciliation modules, undocumented workarounds, and misconfigured general ledger overrides created exactly this kind of culture.


THE SYMPTOMS OF FAILURE

The problems in Marion’s system were consistent and long standing. They included:

• A reconciliation module that was never used
• General ledger override settings that allowed spending outside appropriations
• Shared administrative passwords
• Disabled or missing audit logs
• No off site backups
• No disaster recovery plan
• Users with access far beyond their job requirements
• Modules purchased but never implemented

By 2018, we were certain the system was compromised. By 2019, we began publishing our findings. When we relaunched in December 2024, council minutes, vendor communications, and firsthand accounts from officials confirmed nearly everything we had documented.


THE INVOICE: WHAT TAXPAYERS PAID FOR BUT DID NOT RECEIVE

The Tyler Technologies invoice shows dozens of modules across finance, HR, utilities, inspections, GIS, analytics, and self service systems. Many were never activated or configured. The total annual cost was 145,825.78.

Our assessment confirmed that most of these modules had never been used.


THE PUBLIC’S RIGHT TO KNOW

The public has a right to know:

• Who had access to the financial system
• Which modules were disabled or misconfigured
• How much taxpayer money was wasted
• Why previous administrations concealed these failures
• Why critical records are still being withheld

The receipts exist.
The law requires their release.
And we will continue pursuing them.


CLOSING STATEMENT

Marion’s financial system did not collapse overnight. It was allowed to fail, piece by piece, year after year, while those responsible looked away, improvised shortcuts, or buried the evidence.

Every warning sign was visible.
Every failure was preventable.
Every confirmation, including the Mayor’s, proves what should have been addressed long ago.

The cost of silence is written into every missing audit log, every unused module, every undocumented workaround, and every year taxpayers paid for a system that never worked.

MarionWatch did not uncover a mystery. We documented a pattern. And that pattern shows that when public systems fail, they fail because people in positions of responsibility choose convenience over compliance, secrecy over transparency, and denial over correction.

The public deserves better.
The record demands better.
And the truth will not be buried again.

Marion’s system will be rebuilt.
The failures will be documented.
And the silence that protected this dysfunction for sixteen years ends here.