Audit 333902

FY End
2024-06-30
Total Expended
$38.89M
Findings
10
Programs
18
Organization: Mount Saint Mary's University (CA)
Year: 2024 Accepted: 2024-12-19

Organization Exclusion Status:

Checking exclusion status...

Findings

ID Ref Severity Repeat Requirement
516083 2024-001 Significant Deficiency - N
516084 2024-001 Significant Deficiency - N
516085 2024-001 Significant Deficiency - N
516086 2024-001 Significant Deficiency - N
516087 2024-001 Significant Deficiency - N
1092525 2024-001 Significant Deficiency - N
1092526 2024-001 Significant Deficiency - N
1092527 2024-001 Significant Deficiency - N
1092528 2024-001 Significant Deficiency - N
1092529 2024-001 Significant Deficiency - N

Contacts

Name Title Type
CFLWSHQJQ2L7 Emily Lin Auditee
2134772515 Rebekah Martin Auditor
No contacts on file

Notes to SEFA

Title: Basis of Presentation Accounting Policies: Expenditures reported on the Schedule are reported on the accrual basis of accounting. Such expenditures are recognized following the cost principles contained in the Uniform Guidance, wherein certain types of expenditures are not allowable or are limited as to reimbursement. De Minimis Rate Used: N Rate Explanation: Expenditures reported on the Schedule are reported on the accrual basis of accounting. Such expenditures are recognized following the cost principles contained in the Uniform Guidance, wherein certain types of expenditures are not allowable or are limited as to reimbursement. The accompanying schedule of expenditures of federal awards (the Schedule) includes the federal award activity of the Mount Saint Mary's University (the University) under programs of the federal government for the year ended June 30, 2024. The information in this Schedule is presented in accordance with the requirements of Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards (Uniform Guidance). Because the Schedule presents only a selected portion of the operations of the University, it is not intended to and does not present the financial position, changes in net assets or cash flows of the University.
Title: Federal Student Loan Programs Accounting Policies: Expenditures reported on the Schedule are reported on the accrual basis of accounting. Such expenditures are recognized following the cost principles contained in the Uniform Guidance, wherein certain types of expenditures are not allowable or are limited as to reimbursement. De Minimis Rate Used: N Rate Explanation: Expenditures reported on the Schedule are reported on the accrual basis of accounting. Such expenditures are recognized following the cost principles contained in the Uniform Guidance, wherein certain types of expenditures are not allowable or are limited as to reimbursement. The federal student loan programs listed below are administered directly by the University, and balances and transactions relating to the programs are included in the University's basic financial statements. Loans outstanding at the beginning of the year and loans made during the year are included in the federal expenditures presented in the Schedule. The balance of loans outstanding at June 30, 2024 consists of: 93.364 Nursing Student Loans $354,228
Title: Summary of Significant Accounting Policies Accounting Policies: Expenditures reported on the Schedule are reported on the accrual basis of accounting. Such expenditures are recognized following the cost principles contained in the Uniform Guidance, wherein certain types of expenditures are not allowable or are limited as to reimbursement. De Minimis Rate Used: N Rate Explanation: Expenditures reported on the Schedule are reported on the accrual basis of accounting. Such expenditures are recognized following the cost principles contained in the Uniform Guidance, wherein certain types of expenditures are not allowable or are limited as to reimbursement. Expenditures reported on the Schedule are reported on the accrual basis of accounting. Such expenditures are recognized following the cost principles contained in the Uniform Guidance, wherein certain types of expenditures are not allowable or are limited as to reimbursement.
Title: Indirect Cost Rate Accounting Policies: Expenditures reported on the Schedule are reported on the accrual basis of accounting. Such expenditures are recognized following the cost principles contained in the Uniform Guidance, wherein certain types of expenditures are not allowable or are limited as to reimbursement. De Minimis Rate Used: N Rate Explanation: Expenditures reported on the Schedule are reported on the accrual basis of accounting. Such expenditures are recognized following the cost principles contained in the Uniform Guidance, wherein certain types of expenditures are not allowable or are limited as to reimbursement. Mount Saint Mary's University has not elected to use the 10% de minimis indirect cost rate allowed under the Uniform Guidance.

Finding Details

Criteria: The Gramm-Leach-Bliley Act (Pub. L. No. 106-102) (GLBA) requires institutions to explain their information-sharing practices to their customers and to safeguard sensitive data (16 CFR 314). In 2021, the Federal Trade Commission issued final regulations that altered the current required elements of an information security program and added several new elements. Under the regulations, institutions are required to develop, implement, and maintain a comprehensive information security program that is written in one or more readily accessible parts. The written information security program for institutions must address all elements that apply. The elements for the information security programs set forth in this section 16 CFR 314.4 are high-level principles that set forth basic issues the programs must address, and do not prescribe how they will be addressed. Condition: The University did not have updated procedures and processes in place specific to all the required GLBA elements. The GLBA policy had last been updated in 2019. Cause: The University noted that several items required are in process or being developed to comply with the requirements. Effect: Failure to comply with the requirements of GLBA standards puts the University out of compliance with requirements and potentially at risk of compromising consumer, nonpublic personal information. Questioned costs: Not applicable Context: Not applicable. Recommendation: It is recommended that the University updates its written GLBA Security Policy to address all the required elements. At a minimum, the University should address each of the required minimum elements noted in the GLBA regulations (16 CFR 314.4). Management's Response: The University agrees with the recommendation.
Criteria: The Gramm-Leach-Bliley Act (Pub. L. No. 106-102) (GLBA) requires institutions to explain their information-sharing practices to their customers and to safeguard sensitive data (16 CFR 314). In 2021, the Federal Trade Commission issued final regulations that altered the current required elements of an information security program and added several new elements. Under the regulations, institutions are required to develop, implement, and maintain a comprehensive information security program that is written in one or more readily accessible parts. The written information security program for institutions must address all elements that apply. The elements for the information security programs set forth in this section 16 CFR 314.4 are high-level principles that set forth basic issues the programs must address, and do not prescribe how they will be addressed. Condition: The University did not have updated procedures and processes in place specific to all the required GLBA elements. The GLBA policy had last been updated in 2019. Cause: The University noted that several items required are in process or being developed to comply with the requirements. Effect: Failure to comply with the requirements of GLBA standards puts the University out of compliance with requirements and potentially at risk of compromising consumer, nonpublic personal information. Questioned costs: Not applicable Context: Not applicable. Recommendation: It is recommended that the University updates its written GLBA Security Policy to address all the required elements. At a minimum, the University should address each of the required minimum elements noted in the GLBA regulations (16 CFR 314.4). Management's Response: The University agrees with the recommendation.
Criteria: The Gramm-Leach-Bliley Act (Pub. L. No. 106-102) (GLBA) requires institutions to explain their information-sharing practices to their customers and to safeguard sensitive data (16 CFR 314). In 2021, the Federal Trade Commission issued final regulations that altered the current required elements of an information security program and added several new elements. Under the regulations, institutions are required to develop, implement, and maintain a comprehensive information security program that is written in one or more readily accessible parts. The written information security program for institutions must address all elements that apply. The elements for the information security programs set forth in this section 16 CFR 314.4 are high-level principles that set forth basic issues the programs must address, and do not prescribe how they will be addressed. Condition: The University did not have updated procedures and processes in place specific to all the required GLBA elements. The GLBA policy had last been updated in 2019. Cause: The University noted that several items required are in process or being developed to comply with the requirements. Effect: Failure to comply with the requirements of GLBA standards puts the University out of compliance with requirements and potentially at risk of compromising consumer, nonpublic personal information. Questioned costs: Not applicable Context: Not applicable. Recommendation: It is recommended that the University updates its written GLBA Security Policy to address all the required elements. At a minimum, the University should address each of the required minimum elements noted in the GLBA regulations (16 CFR 314.4). Management's Response: The University agrees with the recommendation.
Criteria: The Gramm-Leach-Bliley Act (Pub. L. No. 106-102) (GLBA) requires institutions to explain their information-sharing practices to their customers and to safeguard sensitive data (16 CFR 314). In 2021, the Federal Trade Commission issued final regulations that altered the current required elements of an information security program and added several new elements. Under the regulations, institutions are required to develop, implement, and maintain a comprehensive information security program that is written in one or more readily accessible parts. The written information security program for institutions must address all elements that apply. The elements for the information security programs set forth in this section 16 CFR 314.4 are high-level principles that set forth basic issues the programs must address, and do not prescribe how they will be addressed. Condition: The University did not have updated procedures and processes in place specific to all the required GLBA elements. The GLBA policy had last been updated in 2019. Cause: The University noted that several items required are in process or being developed to comply with the requirements. Effect: Failure to comply with the requirements of GLBA standards puts the University out of compliance with requirements and potentially at risk of compromising consumer, nonpublic personal information. Questioned costs: Not applicable Context: Not applicable. Recommendation: It is recommended that the University updates its written GLBA Security Policy to address all the required elements. At a minimum, the University should address each of the required minimum elements noted in the GLBA regulations (16 CFR 314.4). Management's Response: The University agrees with the recommendation.
Criteria: The Gramm-Leach-Bliley Act (Pub. L. No. 106-102) (GLBA) requires institutions to explain their information-sharing practices to their customers and to safeguard sensitive data (16 CFR 314). In 2021, the Federal Trade Commission issued final regulations that altered the current required elements of an information security program and added several new elements. Under the regulations, institutions are required to develop, implement, and maintain a comprehensive information security program that is written in one or more readily accessible parts. The written information security program for institutions must address all elements that apply. The elements for the information security programs set forth in this section 16 CFR 314.4 are high-level principles that set forth basic issues the programs must address, and do not prescribe how they will be addressed. Condition: The University did not have updated procedures and processes in place specific to all the required GLBA elements. The GLBA policy had last been updated in 2019. Cause: The University noted that several items required are in process or being developed to comply with the requirements. Effect: Failure to comply with the requirements of GLBA standards puts the University out of compliance with requirements and potentially at risk of compromising consumer, nonpublic personal information. Questioned costs: Not applicable Context: Not applicable. Recommendation: It is recommended that the University updates its written GLBA Security Policy to address all the required elements. At a minimum, the University should address each of the required minimum elements noted in the GLBA regulations (16 CFR 314.4). Management's Response: The University agrees with the recommendation.
Criteria: The Gramm-Leach-Bliley Act (Pub. L. No. 106-102) (GLBA) requires institutions to explain their information-sharing practices to their customers and to safeguard sensitive data (16 CFR 314). In 2021, the Federal Trade Commission issued final regulations that altered the current required elements of an information security program and added several new elements. Under the regulations, institutions are required to develop, implement, and maintain a comprehensive information security program that is written in one or more readily accessible parts. The written information security program for institutions must address all elements that apply. The elements for the information security programs set forth in this section 16 CFR 314.4 are high-level principles that set forth basic issues the programs must address, and do not prescribe how they will be addressed. Condition: The University did not have updated procedures and processes in place specific to all the required GLBA elements. The GLBA policy had last been updated in 2019. Cause: The University noted that several items required are in process or being developed to comply with the requirements. Effect: Failure to comply with the requirements of GLBA standards puts the University out of compliance with requirements and potentially at risk of compromising consumer, nonpublic personal information. Questioned costs: Not applicable Context: Not applicable. Recommendation: It is recommended that the University updates its written GLBA Security Policy to address all the required elements. At a minimum, the University should address each of the required minimum elements noted in the GLBA regulations (16 CFR 314.4). Management's Response: The University agrees with the recommendation.
Criteria: The Gramm-Leach-Bliley Act (Pub. L. No. 106-102) (GLBA) requires institutions to explain their information-sharing practices to their customers and to safeguard sensitive data (16 CFR 314). In 2021, the Federal Trade Commission issued final regulations that altered the current required elements of an information security program and added several new elements. Under the regulations, institutions are required to develop, implement, and maintain a comprehensive information security program that is written in one or more readily accessible parts. The written information security program for institutions must address all elements that apply. The elements for the information security programs set forth in this section 16 CFR 314.4 are high-level principles that set forth basic issues the programs must address, and do not prescribe how they will be addressed. Condition: The University did not have updated procedures and processes in place specific to all the required GLBA elements. The GLBA policy had last been updated in 2019. Cause: The University noted that several items required are in process or being developed to comply with the requirements. Effect: Failure to comply with the requirements of GLBA standards puts the University out of compliance with requirements and potentially at risk of compromising consumer, nonpublic personal information. Questioned costs: Not applicable Context: Not applicable. Recommendation: It is recommended that the University updates its written GLBA Security Policy to address all the required elements. At a minimum, the University should address each of the required minimum elements noted in the GLBA regulations (16 CFR 314.4). Management's Response: The University agrees with the recommendation.
Criteria: The Gramm-Leach-Bliley Act (Pub. L. No. 106-102) (GLBA) requires institutions to explain their information-sharing practices to their customers and to safeguard sensitive data (16 CFR 314). In 2021, the Federal Trade Commission issued final regulations that altered the current required elements of an information security program and added several new elements. Under the regulations, institutions are required to develop, implement, and maintain a comprehensive information security program that is written in one or more readily accessible parts. The written information security program for institutions must address all elements that apply. The elements for the information security programs set forth in this section 16 CFR 314.4 are high-level principles that set forth basic issues the programs must address, and do not prescribe how they will be addressed. Condition: The University did not have updated procedures and processes in place specific to all the required GLBA elements. The GLBA policy had last been updated in 2019. Cause: The University noted that several items required are in process or being developed to comply with the requirements. Effect: Failure to comply with the requirements of GLBA standards puts the University out of compliance with requirements and potentially at risk of compromising consumer, nonpublic personal information. Questioned costs: Not applicable Context: Not applicable. Recommendation: It is recommended that the University updates its written GLBA Security Policy to address all the required elements. At a minimum, the University should address each of the required minimum elements noted in the GLBA regulations (16 CFR 314.4). Management's Response: The University agrees with the recommendation.
Criteria: The Gramm-Leach-Bliley Act (Pub. L. No. 106-102) (GLBA) requires institutions to explain their information-sharing practices to their customers and to safeguard sensitive data (16 CFR 314). In 2021, the Federal Trade Commission issued final regulations that altered the current required elements of an information security program and added several new elements. Under the regulations, institutions are required to develop, implement, and maintain a comprehensive information security program that is written in one or more readily accessible parts. The written information security program for institutions must address all elements that apply. The elements for the information security programs set forth in this section 16 CFR 314.4 are high-level principles that set forth basic issues the programs must address, and do not prescribe how they will be addressed. Condition: The University did not have updated procedures and processes in place specific to all the required GLBA elements. The GLBA policy had last been updated in 2019. Cause: The University noted that several items required are in process or being developed to comply with the requirements. Effect: Failure to comply with the requirements of GLBA standards puts the University out of compliance with requirements and potentially at risk of compromising consumer, nonpublic personal information. Questioned costs: Not applicable Context: Not applicable. Recommendation: It is recommended that the University updates its written GLBA Security Policy to address all the required elements. At a minimum, the University should address each of the required minimum elements noted in the GLBA regulations (16 CFR 314.4). Management's Response: The University agrees with the recommendation.
Criteria: The Gramm-Leach-Bliley Act (Pub. L. No. 106-102) (GLBA) requires institutions to explain their information-sharing practices to their customers and to safeguard sensitive data (16 CFR 314). In 2021, the Federal Trade Commission issued final regulations that altered the current required elements of an information security program and added several new elements. Under the regulations, institutions are required to develop, implement, and maintain a comprehensive information security program that is written in one or more readily accessible parts. The written information security program for institutions must address all elements that apply. The elements for the information security programs set forth in this section 16 CFR 314.4 are high-level principles that set forth basic issues the programs must address, and do not prescribe how they will be addressed. Condition: The University did not have updated procedures and processes in place specific to all the required GLBA elements. The GLBA policy had last been updated in 2019. Cause: The University noted that several items required are in process or being developed to comply with the requirements. Effect: Failure to comply with the requirements of GLBA standards puts the University out of compliance with requirements and potentially at risk of compromising consumer, nonpublic personal information. Questioned costs: Not applicable Context: Not applicable. Recommendation: It is recommended that the University updates its written GLBA Security Policy to address all the required elements. At a minimum, the University should address each of the required minimum elements noted in the GLBA regulations (16 CFR 314.4). Management's Response: The University agrees with the recommendation.