
PORT COMMISSION AUDIT COMMITTEE MEETING MINUTES
THURSDAY, MARCH 28, 2024
• the Port’s opportunity to revise its procedures on future TRA projects in order to decrease the
potential of reimbursing unallowable or duplicate costs within general conditions.
Management provided their responses noting their agreement with the recommendation to improve future
TRA contract language. The stated they will work with other project delivery groups and risk management
to establish clear guidelines as they relate to acceptable insurance requirements and thresholds.
Management also noted a project team will work with the Aviation Department that generates TRAs to
determine the required documentation for reimbursement for general requirements and standard operating
procedures will be updated to require adequate backup document to support reimbursement requests.
Discussion ensued regarding:
• if there is an estimated timeline to update the standard operating procedures;
• a working group meeting every two weeks to incorporate recommendations by 2025;
• the North Terminal Tenant Reimbursement Agreement not being within the scope of this audit;
• Delta not passing along insurance amount requirements to Hensel Phelps;
• the need to require amounts of general contractors in standard operating procedures for the Port’s
contract with the main party;
• being cautious about forbidding a higher amount of insurance for general contractors;
• how legal is involved when there are inconsistencies between the contract and what the Port
agreed to;
• making it clear that any proposed changes to a Tenant Reimbursement Agreement needs to be
submitted via change order;
• if changes can be implemented now; and
• why lump sum invoicing was used.
Members of the Committee thanked Internal Audit for their audit report and management for their response.
INFORMATION TECHNOLOGY AUDITS
8. Payment Card Industry (PCI) – Qualified Security Assessor (QSA) Assessment Results (See
Report)
Presenters:
Glenn Fernandes, Director, Internal Audit
The presentation addressed:
• The 2023 PCI assessment completed on December 14, 2023, by Secured Net Solutions Inc., an
external party, and a Qualified Security Assessor (QSA) with the work performed to assure the
Port’s compliance with the Payment Card Industry Data Security Standard (PCI DSS) version
3.2.1.;
• PCI requirements for merchants to complete an annual Self-Assessment Questionnaire (SAQ) to
verify to their acquirer that their security controls over credit card data handling meets
requirements;
• the Port accepts credit card payments for taxi driver usage fees, moorage services at its marina
facilities, and parking at the Seattle-Tacoma International Airport;
• the Port received an overall “Compliant” rating, demonstrating full compliance with the PCI
requirements.