Audit 39988

FY End
2022-06-30
Total Expended
$39.88M
Findings
24
Programs
28
Organization: Chicago State University (IL)
Year: 2022 Accepted: 2023-03-29

Organization Exclusion Status:

Checking exclusion status...

Findings

ID Ref Severity Repeat Requirement
42782 2022-004 Significant Deficiency - N
42783 2022-004 Significant Deficiency - N
42784 2022-004 Significant Deficiency - N
42785 2022-004 Significant Deficiency - N
42786 2022-003 Significant Deficiency - N
42787 2022-003 Significant Deficiency - N
42788 2022-004 Significant Deficiency - N
42789 2022-005 Significant Deficiency - N
42790 2022-005 Significant Deficiency - N
42791 2022-004 Significant Deficiency - N
42792 2022-004 Significant Deficiency - N
42793 2022-006 Significant Deficiency Yes L
619224 2022-004 Significant Deficiency - N
619225 2022-004 Significant Deficiency - N
619226 2022-004 Significant Deficiency - N
619227 2022-004 Significant Deficiency - N
619228 2022-003 Significant Deficiency - N
619229 2022-003 Significant Deficiency - N
619230 2022-004 Significant Deficiency - N
619231 2022-005 Significant Deficiency - N
619232 2022-005 Significant Deficiency - N
619233 2022-004 Significant Deficiency - N
619234 2022-004 Significant Deficiency - N
619235 2022-006 Significant Deficiency Yes L

Programs

ALN Program Spent Major Findings
84.268 Federal Direct Student Loans $20.17M Yes 3
84.063 Federal Pell Grant Program $4.21M Yes 2
84.038 Federal Perkins Loan Program $1.26M Yes 1
93.925 Scholarships for Health Professions Students From Disadvantaged Backgrounds $860,306 Yes 1
84.047 Trio_upward Bound $854,993 - 0
84.382 Strengthening Minority-Serving Institutions $608,442 - 0
84.425 Education Stabilization Fund $526,079 Yes 0
84.033 Federal Work-Study Program $432,302 Yes 1
84.066 Trio_educational Opportunity Centers $428,376 - 0
84.007 Federal Supplemental Educational Opportunity Grants $359,412 Yes 1
93.600 Head Start $221,355 - 0
84.325 Special Education - Personnel Development to Improve Services and Results for Children with Disabilities $207,342 - 0
47.049 Mathematical and Physical Sciences $82,227 - 0
93.859 Biomedical Research and Research Training $74,068 - 0
47.074 Biological Sciences $37,675 - 0
84.031 Higher Education_institutional Aid $35,734 - 0
43.008 Office of Stem Engagement $31,059 - 0
47.076 Education and Human Resources $27,547 - 0
84.379 Teacher Education Assistance for College and Higher Education Grants (teach Grants) $26,878 Yes 2
94.006 Americorps $26,380 - 0
45.312 National Leadership Grants $24,509 - 0
43.002 Aeronautics $22,157 - 0
45.310 Grants to States $18,747 - 0
43.008 Education $18,650 - 0
93.575 Child Care and Development Block Grant $16,837 - 0
84.335 Child Care Access Means Parents in School $12,458 - 0
47.070 Computer and Information Science and Engineering $2,482 - 0
93.093 Affordable Care Act (aca) Health Profession Opportunity Grants $1,211 - 0

Contacts

Name Title Type
PJ66MZ7MFZ16 Rona Lagdamen Auditee
7739952044 Marites Sy Auditor
No contacts on file

Notes to SEFA

Title: Loan/loan guarantee outstanding balances Accounting Policies: The accompanying schedule of expenditures of federal awards includes the federal grant activity for the year ended June 30, 2022, and is presented on the accrual basis of accounting. Such expenditures are recognized following the cost principles contained in the Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards (Uniform Guidance), wherein certain types of expenditures are not allowable or are limited as to reimbursement. The information in this schedule is presented in accordance with the requirements of the Uniform Guidance. The University has elected not to use the 10 percent de minimis indirect cost rate allowed under the Uniform Guidance. De Minimis Rate Used: N Rate Explanation: The auditee did not use the de minimis cost rate. FEDERAL PERKINS LOAN PROGRAM (84.038) - Balances outstanding at the end of the audit period were 1196204.
Title: NOTE 3 - TOTAL NEW FEDERAL STUDENT LOANS Accounting Policies: The accompanying schedule of expenditures of federal awards includes the federal grant activity for the year ended June 30, 2022, and is presented on the accrual basis of accounting. Such expenditures are recognized following the cost principles contained in the Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards (Uniform Guidance), wherein certain types of expenditures are not allowable or are limited as to reimbursement. The information in this schedule is presented in accordance with the requirements of the Uniform Guidance. The University has elected not to use the 10 percent de minimis indirect cost rate allowed under the Uniform Guidance. De Minimis Rate Used: N Rate Explanation: The auditee did not use the de minimis cost rate. During the year ended June 30, 2022, the University awarded $20,166,174 federal student loans. There were no administrative costs charged to the loan program.
Title: NOTE 4 - NONMONETARY ASSISTANCE Accounting Policies: The accompanying schedule of expenditures of federal awards includes the federal grant activity for the year ended June 30, 2022, and is presented on the accrual basis of accounting. Such expenditures are recognized following the cost principles contained in the Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards (Uniform Guidance), wherein certain types of expenditures are not allowable or are limited as to reimbursement. The information in this schedule is presented in accordance with the requirements of the Uniform Guidance. The University has elected not to use the 10 percent de minimis indirect cost rate allowed under the Uniform Guidance. De Minimis Rate Used: N Rate Explanation: The auditee did not use the de minimis cost rate. During the period, the University did not have any nonmonetary assistance.
Title: NOTE 5 - INSURANCE DISCLOSURES Accounting Policies: The accompanying schedule of expenditures of federal awards includes the federal grant activity for the year ended June 30, 2022, and is presented on the accrual basis of accounting. Such expenditures are recognized following the cost principles contained in the Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards (Uniform Guidance), wherein certain types of expenditures are not allowable or are limited as to reimbursement. The information in this schedule is presented in accordance with the requirements of the Uniform Guidance. The University has elected not to use the 10 percent de minimis indirect cost rate allowed under the Uniform Guidance. De Minimis Rate Used: N Rate Explanation: The auditee did not use the de minimis cost rate. During the period, there was no federally-funded insurance in effect.

Finding Details

2022-004. FINDING Noncompliance with Special Tests and Provisions ? Student Financial Aid Information Security Federal Agency: U.S. Department of Education Assistance Listing Numbers: 84.007; 84.033; 84.038; 84.063; 84.268; 84.379; 93.925 Program Names: Student Financial Assistance Cluster - Federal Supplemental Educational Opportunity Grants Federal Work-Study Program Federal Perkins Loan Program Federal Pell Grant Program Federal Direct Student Loans Teacher Education Assistance for College and Higher Education Grants Scholarships for Health Professions Students from Disadvantaged Background Program Expenditures: $359,412; $432,302; $1,264,604; $4,213,853; $20,166,174; $26,878; $860,306 Award Numbers: P007A221121; P033A221121; P063P211351; P268K221351; P379T221351 Questioned Costs: None The Chicago State University (University) did not perform risk assessment procedures and document safeguards for each risk identified in relation to student financial aid information. According to the University?s Program Participation Agreement with the Department of Education, the University is required to protect student financial aid information. During our testing, we noted the University had not conducted a risk assessment identifying internal and external risks to the security, confidentiality, and integrity of student information. The Standards for Safeguarding Customer Information, required by the Gramm-Leach-Bliley Act (GLBA) (16 CFR ? 314.4 (b)), require the University to identify reasonable foreseeable internal and external risks to the security, confidentiality, and integrity of student information that could result in the unauthorized disclosure, misuse, alteration, destruction or other compromise of such information, and assess the sufficiency of any safeguards in place to control these risks. At a minimum, such a risk assessment should include consideration of risk in each relevant area of operations, including: 2022-004. FINDING Noncompliance with Special Tests and Provisions ? Student Financial Aid Information Security (Continued) (1) Employee training and management; (2) Information systems, including network and software design, as well as information processing, storage, transmission and disposal; and (3) Detecting, preventing and responding to attacks, intrusions, or other system failures. Additionally, the Uniform Guidance (2 CFR ? 200.303) requires nonfederal entities receiving federal awards to establish and maintain effective internal control designed to reasonably ensure compliance with federal laws, statutes, regulations, and the terms and conditions of the federal award. In addition, the Framework for Improving Critical Infrastructure Cybersecurity published by the National Institute of Standards and Technology (NIST) requires entities to perform a risk assessment and establish a risk mitigation plan to minimize identified risks. University management indicated the issues were due to the vacancy of an Information Technology Security Officer position. Without a risk assessment, the University is at risk of noncompliance with the GLBA. In addition, the University?s systems and information could be vulnerable to attacks or intrusions, and these attacks may not be detected in a timely manner. (Finding Code No. 2022-004) RECOMMENDATION We recommend the University strengthen controls to ensure adequate risk assessment procedures are performed and documentation of safeguards for each risk identified in relation to student information security is maintained. UNIVERSITY RESPONSE The University agrees with the finding and is developing a corrective action plan for implementation.
2022-004. FINDING Noncompliance with Special Tests and Provisions ? Student Financial Aid Information Security Federal Agency: U.S. Department of Education Assistance Listing Numbers: 84.007; 84.033; 84.038; 84.063; 84.268; 84.379; 93.925 Program Names: Student Financial Assistance Cluster - Federal Supplemental Educational Opportunity Grants Federal Work-Study Program Federal Perkins Loan Program Federal Pell Grant Program Federal Direct Student Loans Teacher Education Assistance for College and Higher Education Grants Scholarships for Health Professions Students from Disadvantaged Background Program Expenditures: $359,412; $432,302; $1,264,604; $4,213,853; $20,166,174; $26,878; $860,306 Award Numbers: P007A221121; P033A221121; P063P211351; P268K221351; P379T221351 Questioned Costs: None The Chicago State University (University) did not perform risk assessment procedures and document safeguards for each risk identified in relation to student financial aid information. According to the University?s Program Participation Agreement with the Department of Education, the University is required to protect student financial aid information. During our testing, we noted the University had not conducted a risk assessment identifying internal and external risks to the security, confidentiality, and integrity of student information. The Standards for Safeguarding Customer Information, required by the Gramm-Leach-Bliley Act (GLBA) (16 CFR ? 314.4 (b)), require the University to identify reasonable foreseeable internal and external risks to the security, confidentiality, and integrity of student information that could result in the unauthorized disclosure, misuse, alteration, destruction or other compromise of such information, and assess the sufficiency of any safeguards in place to control these risks. At a minimum, such a risk assessment should include consideration of risk in each relevant area of operations, including: 2022-004. FINDING Noncompliance with Special Tests and Provisions ? Student Financial Aid Information Security (Continued) (1) Employee training and management; (2) Information systems, including network and software design, as well as information processing, storage, transmission and disposal; and (3) Detecting, preventing and responding to attacks, intrusions, or other system failures. Additionally, the Uniform Guidance (2 CFR ? 200.303) requires nonfederal entities receiving federal awards to establish and maintain effective internal control designed to reasonably ensure compliance with federal laws, statutes, regulations, and the terms and conditions of the federal award. In addition, the Framework for Improving Critical Infrastructure Cybersecurity published by the National Institute of Standards and Technology (NIST) requires entities to perform a risk assessment and establish a risk mitigation plan to minimize identified risks. University management indicated the issues were due to the vacancy of an Information Technology Security Officer position. Without a risk assessment, the University is at risk of noncompliance with the GLBA. In addition, the University?s systems and information could be vulnerable to attacks or intrusions, and these attacks may not be detected in a timely manner. (Finding Code No. 2022-004) RECOMMENDATION We recommend the University strengthen controls to ensure adequate risk assessment procedures are performed and documentation of safeguards for each risk identified in relation to student information security is maintained. UNIVERSITY RESPONSE The University agrees with the finding and is developing a corrective action plan for implementation.
2022-004. FINDING Noncompliance with Special Tests and Provisions ? Student Financial Aid Information Security Federal Agency: U.S. Department of Education Assistance Listing Numbers: 84.007; 84.033; 84.038; 84.063; 84.268; 84.379; 93.925 Program Names: Student Financial Assistance Cluster - Federal Supplemental Educational Opportunity Grants Federal Work-Study Program Federal Perkins Loan Program Federal Pell Grant Program Federal Direct Student Loans Teacher Education Assistance for College and Higher Education Grants Scholarships for Health Professions Students from Disadvantaged Background Program Expenditures: $359,412; $432,302; $1,264,604; $4,213,853; $20,166,174; $26,878; $860,306 Award Numbers: P007A221121; P033A221121; P063P211351; P268K221351; P379T221351 Questioned Costs: None The Chicago State University (University) did not perform risk assessment procedures and document safeguards for each risk identified in relation to student financial aid information. According to the University?s Program Participation Agreement with the Department of Education, the University is required to protect student financial aid information. During our testing, we noted the University had not conducted a risk assessment identifying internal and external risks to the security, confidentiality, and integrity of student information. The Standards for Safeguarding Customer Information, required by the Gramm-Leach-Bliley Act (GLBA) (16 CFR ? 314.4 (b)), require the University to identify reasonable foreseeable internal and external risks to the security, confidentiality, and integrity of student information that could result in the unauthorized disclosure, misuse, alteration, destruction or other compromise of such information, and assess the sufficiency of any safeguards in place to control these risks. At a minimum, such a risk assessment should include consideration of risk in each relevant area of operations, including: 2022-004. FINDING Noncompliance with Special Tests and Provisions ? Student Financial Aid Information Security (Continued) (1) Employee training and management; (2) Information systems, including network and software design, as well as information processing, storage, transmission and disposal; and (3) Detecting, preventing and responding to attacks, intrusions, or other system failures. Additionally, the Uniform Guidance (2 CFR ? 200.303) requires nonfederal entities receiving federal awards to establish and maintain effective internal control designed to reasonably ensure compliance with federal laws, statutes, regulations, and the terms and conditions of the federal award. In addition, the Framework for Improving Critical Infrastructure Cybersecurity published by the National Institute of Standards and Technology (NIST) requires entities to perform a risk assessment and establish a risk mitigation plan to minimize identified risks. University management indicated the issues were due to the vacancy of an Information Technology Security Officer position. Without a risk assessment, the University is at risk of noncompliance with the GLBA. In addition, the University?s systems and information could be vulnerable to attacks or intrusions, and these attacks may not be detected in a timely manner. (Finding Code No. 2022-004) RECOMMENDATION We recommend the University strengthen controls to ensure adequate risk assessment procedures are performed and documentation of safeguards for each risk identified in relation to student information security is maintained. UNIVERSITY RESPONSE The University agrees with the finding and is developing a corrective action plan for implementation.
2022-004. FINDING Noncompliance with Special Tests and Provisions ? Student Financial Aid Information Security Federal Agency: U.S. Department of Education Assistance Listing Numbers: 84.007; 84.033; 84.038; 84.063; 84.268; 84.379; 93.925 Program Names: Student Financial Assistance Cluster - Federal Supplemental Educational Opportunity Grants Federal Work-Study Program Federal Perkins Loan Program Federal Pell Grant Program Federal Direct Student Loans Teacher Education Assistance for College and Higher Education Grants Scholarships for Health Professions Students from Disadvantaged Background Program Expenditures: $359,412; $432,302; $1,264,604; $4,213,853; $20,166,174; $26,878; $860,306 Award Numbers: P007A221121; P033A221121; P063P211351; P268K221351; P379T221351 Questioned Costs: None The Chicago State University (University) did not perform risk assessment procedures and document safeguards for each risk identified in relation to student financial aid information. According to the University?s Program Participation Agreement with the Department of Education, the University is required to protect student financial aid information. During our testing, we noted the University had not conducted a risk assessment identifying internal and external risks to the security, confidentiality, and integrity of student information. The Standards for Safeguarding Customer Information, required by the Gramm-Leach-Bliley Act (GLBA) (16 CFR ? 314.4 (b)), require the University to identify reasonable foreseeable internal and external risks to the security, confidentiality, and integrity of student information that could result in the unauthorized disclosure, misuse, alteration, destruction or other compromise of such information, and assess the sufficiency of any safeguards in place to control these risks. At a minimum, such a risk assessment should include consideration of risk in each relevant area of operations, including: 2022-004. FINDING Noncompliance with Special Tests and Provisions ? Student Financial Aid Information Security (Continued) (1) Employee training and management; (2) Information systems, including network and software design, as well as information processing, storage, transmission and disposal; and (3) Detecting, preventing and responding to attacks, intrusions, or other system failures. Additionally, the Uniform Guidance (2 CFR ? 200.303) requires nonfederal entities receiving federal awards to establish and maintain effective internal control designed to reasonably ensure compliance with federal laws, statutes, regulations, and the terms and conditions of the federal award. In addition, the Framework for Improving Critical Infrastructure Cybersecurity published by the National Institute of Standards and Technology (NIST) requires entities to perform a risk assessment and establish a risk mitigation plan to minimize identified risks. University management indicated the issues were due to the vacancy of an Information Technology Security Officer position. Without a risk assessment, the University is at risk of noncompliance with the GLBA. In addition, the University?s systems and information could be vulnerable to attacks or intrusions, and these attacks may not be detected in a timely manner. (Finding Code No. 2022-004) RECOMMENDATION We recommend the University strengthen controls to ensure adequate risk assessment procedures are performed and documentation of safeguards for each risk identified in relation to student information security is maintained. UNIVERSITY RESPONSE The University agrees with the finding and is developing a corrective action plan for implementation.
2022-003. FINDING Failure to Obtain Student Verification Documents Federal Agency: U.S. Department of Education Assistance Listing Numbers: 84.063; 84.268 Program Names: Student Financial Assistance Cluster - Federal Pell Grant Program Federal Direct Student Loans Program Expenditures: $4,213,853; $20,166,174 Award Numbers: P063P211351; P268K221351 Questioned Costs: None The Chicago State University (University) did not obtain and review student verification documents. For Academic Year 2021-2022, the Department of Education waived the verification of most Free Application for Federal Student Aid (FAFSA) information, except for Identity/Statement of Educational Purpose and High School Completion Status. During testing of 25 students selected for verification, we noted the University did not obtain supporting documentation to verify the identity of two (8%) students. The sample methods used in performing this testing were not statistically valid. The Federal Student Aid Publication (GEN-21-05) ? Changes to 2021-2022 Verification Requirements, dated July 13, 2021, waived verification of information of students applying for financial assistance except for verification of documents for Identity/Statement of Educational Purpose and High School Completion Status of certain verification groups. Additionally, the Uniform Guidance (2 CFR ? 200.303) requires nonfederal entities receiving federal awards to establish and maintain effective internal control designed to reasonably ensure compliance with federal laws, statutes, regulations, and the terms and conditions of the federal award. University management indicated the failure to obtain verification documents was due to oversight. Failure to obtain verification documents in accordance with federal regulations may result in students receiving awards for which they are ineligible and the University incurring unallowable costs. (Finding Code No. 2022-003) 2022-003. FINDING Failure to Obtain Student Verification Documents (Continued) RECOMMENDATION We recommend the University ensure student verification documents are obtained, reviewed, and maintained. UNIVERSITY RESPONSE The University agrees with the finding and is developing a corrective action plan for implementation.
2022-003. FINDING Failure to Obtain Student Verification Documents Federal Agency: U.S. Department of Education Assistance Listing Numbers: 84.063; 84.268 Program Names: Student Financial Assistance Cluster - Federal Pell Grant Program Federal Direct Student Loans Program Expenditures: $4,213,853; $20,166,174 Award Numbers: P063P211351; P268K221351 Questioned Costs: None The Chicago State University (University) did not obtain and review student verification documents. For Academic Year 2021-2022, the Department of Education waived the verification of most Free Application for Federal Student Aid (FAFSA) information, except for Identity/Statement of Educational Purpose and High School Completion Status. During testing of 25 students selected for verification, we noted the University did not obtain supporting documentation to verify the identity of two (8%) students. The sample methods used in performing this testing were not statistically valid. The Federal Student Aid Publication (GEN-21-05) ? Changes to 2021-2022 Verification Requirements, dated July 13, 2021, waived verification of information of students applying for financial assistance except for verification of documents for Identity/Statement of Educational Purpose and High School Completion Status of certain verification groups. Additionally, the Uniform Guidance (2 CFR ? 200.303) requires nonfederal entities receiving federal awards to establish and maintain effective internal control designed to reasonably ensure compliance with federal laws, statutes, regulations, and the terms and conditions of the federal award. University management indicated the failure to obtain verification documents was due to oversight. Failure to obtain verification documents in accordance with federal regulations may result in students receiving awards for which they are ineligible and the University incurring unallowable costs. (Finding Code No. 2022-003) 2022-003. FINDING Failure to Obtain Student Verification Documents (Continued) RECOMMENDATION We recommend the University ensure student verification documents are obtained, reviewed, and maintained. UNIVERSITY RESPONSE The University agrees with the finding and is developing a corrective action plan for implementation.
2022-004. FINDING Noncompliance with Special Tests and Provisions ? Student Financial Aid Information Security Federal Agency: U.S. Department of Education Assistance Listing Numbers: 84.007; 84.033; 84.038; 84.063; 84.268; 84.379; 93.925 Program Names: Student Financial Assistance Cluster - Federal Supplemental Educational Opportunity Grants Federal Work-Study Program Federal Perkins Loan Program Federal Pell Grant Program Federal Direct Student Loans Teacher Education Assistance for College and Higher Education Grants Scholarships for Health Professions Students from Disadvantaged Background Program Expenditures: $359,412; $432,302; $1,264,604; $4,213,853; $20,166,174; $26,878; $860,306 Award Numbers: P007A221121; P033A221121; P063P211351; P268K221351; P379T221351 Questioned Costs: None The Chicago State University (University) did not perform risk assessment procedures and document safeguards for each risk identified in relation to student financial aid information. According to the University?s Program Participation Agreement with the Department of Education, the University is required to protect student financial aid information. During our testing, we noted the University had not conducted a risk assessment identifying internal and external risks to the security, confidentiality, and integrity of student information. The Standards for Safeguarding Customer Information, required by the Gramm-Leach-Bliley Act (GLBA) (16 CFR ? 314.4 (b)), require the University to identify reasonable foreseeable internal and external risks to the security, confidentiality, and integrity of student information that could result in the unauthorized disclosure, misuse, alteration, destruction or other compromise of such information, and assess the sufficiency of any safeguards in place to control these risks. At a minimum, such a risk assessment should include consideration of risk in each relevant area of operations, including: 2022-004. FINDING Noncompliance with Special Tests and Provisions ? Student Financial Aid Information Security (Continued) (1) Employee training and management; (2) Information systems, including network and software design, as well as information processing, storage, transmission and disposal; and (3) Detecting, preventing and responding to attacks, intrusions, or other system failures. Additionally, the Uniform Guidance (2 CFR ? 200.303) requires nonfederal entities receiving federal awards to establish and maintain effective internal control designed to reasonably ensure compliance with federal laws, statutes, regulations, and the terms and conditions of the federal award. In addition, the Framework for Improving Critical Infrastructure Cybersecurity published by the National Institute of Standards and Technology (NIST) requires entities to perform a risk assessment and establish a risk mitigation plan to minimize identified risks. University management indicated the issues were due to the vacancy of an Information Technology Security Officer position. Without a risk assessment, the University is at risk of noncompliance with the GLBA. In addition, the University?s systems and information could be vulnerable to attacks or intrusions, and these attacks may not be detected in a timely manner. (Finding Code No. 2022-004) RECOMMENDATION We recommend the University strengthen controls to ensure adequate risk assessment procedures are performed and documentation of safeguards for each risk identified in relation to student information security is maintained. UNIVERSITY RESPONSE The University agrees with the finding and is developing a corrective action plan for implementation.
2022-005. FINDING Failure to Notify Students Upon Disbursement of Funds Federal Agency: U.S. Department of Education Assistance Listing Numbers: 84.268; 84.379 Program Names: Student Financial Assistance Cluster - Federal Direct Student Loans Teacher Education Assistance for College and Higher Education Grants Program Expenditures: $20,166,174; $26,878 Award Number: P268K221351 Questioned Costs: None The Chicago State University (University) did not notify the students upon disbursement of grant funds and loans. During testing of nine students, who received Teacher Education Assistance for College and Higher Education Grants (TEACH) totaling $21,220, we noted six (67%) students with grant disbursements totaling $16,505 were not notified by the University indicating the funds were credited to the students? accounts. The sample methods used in performing this testing were not statistically valid. In addition, during testing of 25 students, who received Federal Direct Student Loans totaling $447,363, we noted 25 (100%) students were not notified by the University indicating the funds were credited to the students? accounts. The sample methods used in performing this testing were not statistically valid. The Code of Federal Regulations (Code) (34 CFR ? 668.165 (a)(3)(i)) requires the University to notify students or parents in writing no earlier than 30 days before, and no later than 30 days after, crediting the students? ledger account at the University with TEACH Grant funds or Federal Direct Student Loans. Further, the Code (2 CFR ? 200.303) requires the nonfederal entity receiving federal awards to establish and maintain effective internal control over the federal award to provide reasonable assurance the nonfederal entity is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award. Effective internal controls include procedures to ensure timely notification of disbursements to students receiving TEACH Grants and Federal Direct Loans. University management indicated the failure to timely notify students upon disbursements of TEACH grants and Direct Loans was due to resource constraints. 2022-005. FINDING Failure to Notify Students Upon Disbursement (Continued) Failure to timely notify students upon disbursement of funds resulted in noncompliance with the Code. (Finding Code No. 2022-005) RECOMMENDATION We recommend the University strengthen controls to ensure timely notification is sent to students upon disbursement of grant funds and loans. UNIVERSITY RESPONSE The University agrees with the finding and is developing a corrective action plan for implementation.
2022-005. FINDING Failure to Notify Students Upon Disbursement of Funds Federal Agency: U.S. Department of Education Assistance Listing Numbers: 84.268; 84.379 Program Names: Student Financial Assistance Cluster - Federal Direct Student Loans Teacher Education Assistance for College and Higher Education Grants Program Expenditures: $20,166,174; $26,878 Award Number: P268K221351 Questioned Costs: None The Chicago State University (University) did not notify the students upon disbursement of grant funds and loans. During testing of nine students, who received Teacher Education Assistance for College and Higher Education Grants (TEACH) totaling $21,220, we noted six (67%) students with grant disbursements totaling $16,505 were not notified by the University indicating the funds were credited to the students? accounts. The sample methods used in performing this testing were not statistically valid. In addition, during testing of 25 students, who received Federal Direct Student Loans totaling $447,363, we noted 25 (100%) students were not notified by the University indicating the funds were credited to the students? accounts. The sample methods used in performing this testing were not statistically valid. The Code of Federal Regulations (Code) (34 CFR ? 668.165 (a)(3)(i)) requires the University to notify students or parents in writing no earlier than 30 days before, and no later than 30 days after, crediting the students? ledger account at the University with TEACH Grant funds or Federal Direct Student Loans. Further, the Code (2 CFR ? 200.303) requires the nonfederal entity receiving federal awards to establish and maintain effective internal control over the federal award to provide reasonable assurance the nonfederal entity is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award. Effective internal controls include procedures to ensure timely notification of disbursements to students receiving TEACH Grants and Federal Direct Loans. University management indicated the failure to timely notify students upon disbursements of TEACH grants and Direct Loans was due to resource constraints. 2022-005. FINDING Failure to Notify Students Upon Disbursement (Continued) Failure to timely notify students upon disbursement of funds resulted in noncompliance with the Code. (Finding Code No. 2022-005) RECOMMENDATION We recommend the University strengthen controls to ensure timely notification is sent to students upon disbursement of grant funds and loans. UNIVERSITY RESPONSE The University agrees with the finding and is developing a corrective action plan for implementation.
2022-004. FINDING Noncompliance with Special Tests and Provisions ? Student Financial Aid Information Security Federal Agency: U.S. Department of Education Assistance Listing Numbers: 84.007; 84.033; 84.038; 84.063; 84.268; 84.379; 93.925 Program Names: Student Financial Assistance Cluster - Federal Supplemental Educational Opportunity Grants Federal Work-Study Program Federal Perkins Loan Program Federal Pell Grant Program Federal Direct Student Loans Teacher Education Assistance for College and Higher Education Grants Scholarships for Health Professions Students from Disadvantaged Background Program Expenditures: $359,412; $432,302; $1,264,604; $4,213,853; $20,166,174; $26,878; $860,306 Award Numbers: P007A221121; P033A221121; P063P211351; P268K221351; P379T221351 Questioned Costs: None The Chicago State University (University) did not perform risk assessment procedures and document safeguards for each risk identified in relation to student financial aid information. According to the University?s Program Participation Agreement with the Department of Education, the University is required to protect student financial aid information. During our testing, we noted the University had not conducted a risk assessment identifying internal and external risks to the security, confidentiality, and integrity of student information. The Standards for Safeguarding Customer Information, required by the Gramm-Leach-Bliley Act (GLBA) (16 CFR ? 314.4 (b)), require the University to identify reasonable foreseeable internal and external risks to the security, confidentiality, and integrity of student information that could result in the unauthorized disclosure, misuse, alteration, destruction or other compromise of such information, and assess the sufficiency of any safeguards in place to control these risks. At a minimum, such a risk assessment should include consideration of risk in each relevant area of operations, including: 2022-004. FINDING Noncompliance with Special Tests and Provisions ? Student Financial Aid Information Security (Continued) (1) Employee training and management; (2) Information systems, including network and software design, as well as information processing, storage, transmission and disposal; and (3) Detecting, preventing and responding to attacks, intrusions, or other system failures. Additionally, the Uniform Guidance (2 CFR ? 200.303) requires nonfederal entities receiving federal awards to establish and maintain effective internal control designed to reasonably ensure compliance with federal laws, statutes, regulations, and the terms and conditions of the federal award. In addition, the Framework for Improving Critical Infrastructure Cybersecurity published by the National Institute of Standards and Technology (NIST) requires entities to perform a risk assessment and establish a risk mitigation plan to minimize identified risks. University management indicated the issues were due to the vacancy of an Information Technology Security Officer position. Without a risk assessment, the University is at risk of noncompliance with the GLBA. In addition, the University?s systems and information could be vulnerable to attacks or intrusions, and these attacks may not be detected in a timely manner. (Finding Code No. 2022-004) RECOMMENDATION We recommend the University strengthen controls to ensure adequate risk assessment procedures are performed and documentation of safeguards for each risk identified in relation to student information security is maintained. UNIVERSITY RESPONSE The University agrees with the finding and is developing a corrective action plan for implementation.
2022-004. FINDING Noncompliance with Special Tests and Provisions ? Student Financial Aid Information Security Federal Agency: U.S. Department of Education Assistance Listing Numbers: 84.007; 84.033; 84.038; 84.063; 84.268; 84.379; 93.925 Program Names: Student Financial Assistance Cluster - Federal Supplemental Educational Opportunity Grants Federal Work-Study Program Federal Perkins Loan Program Federal Pell Grant Program Federal Direct Student Loans Teacher Education Assistance for College and Higher Education Grants Scholarships for Health Professions Students from Disadvantaged Background Program Expenditures: $359,412; $432,302; $1,264,604; $4,213,853; $20,166,174; $26,878; $860,306 Award Numbers: P007A221121; P033A221121; P063P211351; P268K221351; P379T221351 Questioned Costs: None The Chicago State University (University) did not perform risk assessment procedures and document safeguards for each risk identified in relation to student financial aid information. According to the University?s Program Participation Agreement with the Department of Education, the University is required to protect student financial aid information. During our testing, we noted the University had not conducted a risk assessment identifying internal and external risks to the security, confidentiality, and integrity of student information. The Standards for Safeguarding Customer Information, required by the Gramm-Leach-Bliley Act (GLBA) (16 CFR ? 314.4 (b)), require the University to identify reasonable foreseeable internal and external risks to the security, confidentiality, and integrity of student information that could result in the unauthorized disclosure, misuse, alteration, destruction or other compromise of such information, and assess the sufficiency of any safeguards in place to control these risks. At a minimum, such a risk assessment should include consideration of risk in each relevant area of operations, including: 2022-004. FINDING Noncompliance with Special Tests and Provisions ? Student Financial Aid Information Security (Continued) (1) Employee training and management; (2) Information systems, including network and software design, as well as information processing, storage, transmission and disposal; and (3) Detecting, preventing and responding to attacks, intrusions, or other system failures. Additionally, the Uniform Guidance (2 CFR ? 200.303) requires nonfederal entities receiving federal awards to establish and maintain effective internal control designed to reasonably ensure compliance with federal laws, statutes, regulations, and the terms and conditions of the federal award. In addition, the Framework for Improving Critical Infrastructure Cybersecurity published by the National Institute of Standards and Technology (NIST) requires entities to perform a risk assessment and establish a risk mitigation plan to minimize identified risks. University management indicated the issues were due to the vacancy of an Information Technology Security Officer position. Without a risk assessment, the University is at risk of noncompliance with the GLBA. In addition, the University?s systems and information could be vulnerable to attacks or intrusions, and these attacks may not be detected in a timely manner. (Finding Code No. 2022-004) RECOMMENDATION We recommend the University strengthen controls to ensure adequate risk assessment procedures are performed and documentation of safeguards for each risk identified in relation to student information security is maintained. UNIVERSITY RESPONSE The University agrees with the finding and is developing a corrective action plan for implementation.
2022-006. FINDING Lack of Adherence to Controls and Noncompliance with Requirement Applicable to the Education Stabilization Fund Federal Agency: U.S. Department of Education Assistance Listing Numbers: 84.425E; 84.425F; 84.425L Program Names: Higher Education Stabilization Fund - COVID-19 - Higher Education Emergency Relief Fund - Student Aid Portion COVID-19 - Higher Education Emergency Relief Fund - Institutional Portion COVID-19 - Higher Education Emergency Relief Fund - Minority Serving Institutions Program Expenditures: $4,008,386; $3,338,668; $436,450 Award Numbers: 425E201661; P425F201393; P425L200359 Questioned Costs: None The Chicago State University (University) did not utilize the updated quarterly reporting form to report its Higher Education Emergency Relief Fund (HEERF) student and institutional aid awards. During testing, we noted one of four (25%) quarterly reporting forms utilized for reporting HEERF awards was outdated. As such, the information reported by the University did not include certain data required by the Department of Education. On March 27, 2020, the Coronavirus Aid, Relief, and Economic Security Act (CARES Act) was enacted into Public Law 116-136. Section 18004(a)(1) of the CARES Act established the HEERF I program which authorizes the Secretary of Education (Secretary) to allocate funding to eligible institutions of higher education to prevent, prepare for, and respond to the coronavirus pandemic (COVID-19). Subsequently, additional grants from the Coronavirus Response and Relief Supplemental Appropriations Act (CRRSAA) and the American Rescue Plan Act of 2021 (ARP) were received, establishing the HEERF II and HEERF III programs, respectively, to continuously support public and non-profit institutions and students. Under the CARES, CRRSSA, and ARP Acts, an institution is required to complete and post on its website a quarterly and annual report of its HEERF grant expenditures using the form designed by the Department of Education to help ensure funding transparency and public accountability. 2022-006. FINDING Lack of Adherence to Controls and Noncompliance with Requirement Applicable to the Education Stabilization Fund (Continued) The Higher Education Emergency Relief Fund III Frequently Asked Questions, Question 36, published by the Department of Education, requires the University to utilize the new quarterly reporting form beginning June 30, 2022, reporting period. The new quarterly reporting form includes new reporting categories on mental health spending, HEERF (a)(2) construction flexibilities, and lost revenue and combines the separate institutional and student reporting requirement. The Code of Federal Regulations (Code) (2 CFR ? 200.303) requires the University to establish and maintain effective internal control over the federal award to provide reasonable assurance the University is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award. Effective internal controls should include procedures to ensure compliance with grant reporting requirements. This finding was first reported in Fiscal Year 2020. In subsequent years, the University has been unsuccessful in implementing appropriate procedures to improve its controls over HEERF awards. University management indicated the failure to use the correct reporting form was due to lack of coordination between staff involved in the reporting process. Failure to comply with the grant reporting requirements of the HEERF programs results in noncompliance with the CARES, CRRSAA, and ARP Acts, grant agreements, and the Code. (Finding Code No. 2022-006, 2021-004, 2020-005) RECOMMENDATION We recommend the University strengthen its controls to ensure updated forms are used to report its HEERF student and institutional aid awards. UNIVERSITY RESPONSE The University agrees with the finding and has implemented a corrective action plan to improve internal controls related to posting of HEERF reports and submission of the Governor's Emergency Education Relief Fund reports.
2022-004. FINDING Noncompliance with Special Tests and Provisions ? Student Financial Aid Information Security Federal Agency: U.S. Department of Education Assistance Listing Numbers: 84.007; 84.033; 84.038; 84.063; 84.268; 84.379; 93.925 Program Names: Student Financial Assistance Cluster - Federal Supplemental Educational Opportunity Grants Federal Work-Study Program Federal Perkins Loan Program Federal Pell Grant Program Federal Direct Student Loans Teacher Education Assistance for College and Higher Education Grants Scholarships for Health Professions Students from Disadvantaged Background Program Expenditures: $359,412; $432,302; $1,264,604; $4,213,853; $20,166,174; $26,878; $860,306 Award Numbers: P007A221121; P033A221121; P063P211351; P268K221351; P379T221351 Questioned Costs: None The Chicago State University (University) did not perform risk assessment procedures and document safeguards for each risk identified in relation to student financial aid information. According to the University?s Program Participation Agreement with the Department of Education, the University is required to protect student financial aid information. During our testing, we noted the University had not conducted a risk assessment identifying internal and external risks to the security, confidentiality, and integrity of student information. The Standards for Safeguarding Customer Information, required by the Gramm-Leach-Bliley Act (GLBA) (16 CFR ? 314.4 (b)), require the University to identify reasonable foreseeable internal and external risks to the security, confidentiality, and integrity of student information that could result in the unauthorized disclosure, misuse, alteration, destruction or other compromise of such information, and assess the sufficiency of any safeguards in place to control these risks. At a minimum, such a risk assessment should include consideration of risk in each relevant area of operations, including: 2022-004. FINDING Noncompliance with Special Tests and Provisions ? Student Financial Aid Information Security (Continued) (1) Employee training and management; (2) Information systems, including network and software design, as well as information processing, storage, transmission and disposal; and (3) Detecting, preventing and responding to attacks, intrusions, or other system failures. Additionally, the Uniform Guidance (2 CFR ? 200.303) requires nonfederal entities receiving federal awards to establish and maintain effective internal control designed to reasonably ensure compliance with federal laws, statutes, regulations, and the terms and conditions of the federal award. In addition, the Framework for Improving Critical Infrastructure Cybersecurity published by the National Institute of Standards and Technology (NIST) requires entities to perform a risk assessment and establish a risk mitigation plan to minimize identified risks. University management indicated the issues were due to the vacancy of an Information Technology Security Officer position. Without a risk assessment, the University is at risk of noncompliance with the GLBA. In addition, the University?s systems and information could be vulnerable to attacks or intrusions, and these attacks may not be detected in a timely manner. (Finding Code No. 2022-004) RECOMMENDATION We recommend the University strengthen controls to ensure adequate risk assessment procedures are performed and documentation of safeguards for each risk identified in relation to student information security is maintained. UNIVERSITY RESPONSE The University agrees with the finding and is developing a corrective action plan for implementation.
2022-004. FINDING Noncompliance with Special Tests and Provisions ? Student Financial Aid Information Security Federal Agency: U.S. Department of Education Assistance Listing Numbers: 84.007; 84.033; 84.038; 84.063; 84.268; 84.379; 93.925 Program Names: Student Financial Assistance Cluster - Federal Supplemental Educational Opportunity Grants Federal Work-Study Program Federal Perkins Loan Program Federal Pell Grant Program Federal Direct Student Loans Teacher Education Assistance for College and Higher Education Grants Scholarships for Health Professions Students from Disadvantaged Background Program Expenditures: $359,412; $432,302; $1,264,604; $4,213,853; $20,166,174; $26,878; $860,306 Award Numbers: P007A221121; P033A221121; P063P211351; P268K221351; P379T221351 Questioned Costs: None The Chicago State University (University) did not perform risk assessment procedures and document safeguards for each risk identified in relation to student financial aid information. According to the University?s Program Participation Agreement with the Department of Education, the University is required to protect student financial aid information. During our testing, we noted the University had not conducted a risk assessment identifying internal and external risks to the security, confidentiality, and integrity of student information. The Standards for Safeguarding Customer Information, required by the Gramm-Leach-Bliley Act (GLBA) (16 CFR ? 314.4 (b)), require the University to identify reasonable foreseeable internal and external risks to the security, confidentiality, and integrity of student information that could result in the unauthorized disclosure, misuse, alteration, destruction or other compromise of such information, and assess the sufficiency of any safeguards in place to control these risks. At a minimum, such a risk assessment should include consideration of risk in each relevant area of operations, including: 2022-004. FINDING Noncompliance with Special Tests and Provisions ? Student Financial Aid Information Security (Continued) (1) Employee training and management; (2) Information systems, including network and software design, as well as information processing, storage, transmission and disposal; and (3) Detecting, preventing and responding to attacks, intrusions, or other system failures. Additionally, the Uniform Guidance (2 CFR ? 200.303) requires nonfederal entities receiving federal awards to establish and maintain effective internal control designed to reasonably ensure compliance with federal laws, statutes, regulations, and the terms and conditions of the federal award. In addition, the Framework for Improving Critical Infrastructure Cybersecurity published by the National Institute of Standards and Technology (NIST) requires entities to perform a risk assessment and establish a risk mitigation plan to minimize identified risks. University management indicated the issues were due to the vacancy of an Information Technology Security Officer position. Without a risk assessment, the University is at risk of noncompliance with the GLBA. In addition, the University?s systems and information could be vulnerable to attacks or intrusions, and these attacks may not be detected in a timely manner. (Finding Code No. 2022-004) RECOMMENDATION We recommend the University strengthen controls to ensure adequate risk assessment procedures are performed and documentation of safeguards for each risk identified in relation to student information security is maintained. UNIVERSITY RESPONSE The University agrees with the finding and is developing a corrective action plan for implementation.
2022-004. FINDING Noncompliance with Special Tests and Provisions ? Student Financial Aid Information Security Federal Agency: U.S. Department of Education Assistance Listing Numbers: 84.007; 84.033; 84.038; 84.063; 84.268; 84.379; 93.925 Program Names: Student Financial Assistance Cluster - Federal Supplemental Educational Opportunity Grants Federal Work-Study Program Federal Perkins Loan Program Federal Pell Grant Program Federal Direct Student Loans Teacher Education Assistance for College and Higher Education Grants Scholarships for Health Professions Students from Disadvantaged Background Program Expenditures: $359,412; $432,302; $1,264,604; $4,213,853; $20,166,174; $26,878; $860,306 Award Numbers: P007A221121; P033A221121; P063P211351; P268K221351; P379T221351 Questioned Costs: None The Chicago State University (University) did not perform risk assessment procedures and document safeguards for each risk identified in relation to student financial aid information. According to the University?s Program Participation Agreement with the Department of Education, the University is required to protect student financial aid information. During our testing, we noted the University had not conducted a risk assessment identifying internal and external risks to the security, confidentiality, and integrity of student information. The Standards for Safeguarding Customer Information, required by the Gramm-Leach-Bliley Act (GLBA) (16 CFR ? 314.4 (b)), require the University to identify reasonable foreseeable internal and external risks to the security, confidentiality, and integrity of student information that could result in the unauthorized disclosure, misuse, alteration, destruction or other compromise of such information, and assess the sufficiency of any safeguards in place to control these risks. At a minimum, such a risk assessment should include consideration of risk in each relevant area of operations, including: 2022-004. FINDING Noncompliance with Special Tests and Provisions ? Student Financial Aid Information Security (Continued) (1) Employee training and management; (2) Information systems, including network and software design, as well as information processing, storage, transmission and disposal; and (3) Detecting, preventing and responding to attacks, intrusions, or other system failures. Additionally, the Uniform Guidance (2 CFR ? 200.303) requires nonfederal entities receiving federal awards to establish and maintain effective internal control designed to reasonably ensure compliance with federal laws, statutes, regulations, and the terms and conditions of the federal award. In addition, the Framework for Improving Critical Infrastructure Cybersecurity published by the National Institute of Standards and Technology (NIST) requires entities to perform a risk assessment and establish a risk mitigation plan to minimize identified risks. University management indicated the issues were due to the vacancy of an Information Technology Security Officer position. Without a risk assessment, the University is at risk of noncompliance with the GLBA. In addition, the University?s systems and information could be vulnerable to attacks or intrusions, and these attacks may not be detected in a timely manner. (Finding Code No. 2022-004) RECOMMENDATION We recommend the University strengthen controls to ensure adequate risk assessment procedures are performed and documentation of safeguards for each risk identified in relation to student information security is maintained. UNIVERSITY RESPONSE The University agrees with the finding and is developing a corrective action plan for implementation.
2022-004. FINDING Noncompliance with Special Tests and Provisions ? Student Financial Aid Information Security Federal Agency: U.S. Department of Education Assistance Listing Numbers: 84.007; 84.033; 84.038; 84.063; 84.268; 84.379; 93.925 Program Names: Student Financial Assistance Cluster - Federal Supplemental Educational Opportunity Grants Federal Work-Study Program Federal Perkins Loan Program Federal Pell Grant Program Federal Direct Student Loans Teacher Education Assistance for College and Higher Education Grants Scholarships for Health Professions Students from Disadvantaged Background Program Expenditures: $359,412; $432,302; $1,264,604; $4,213,853; $20,166,174; $26,878; $860,306 Award Numbers: P007A221121; P033A221121; P063P211351; P268K221351; P379T221351 Questioned Costs: None The Chicago State University (University) did not perform risk assessment procedures and document safeguards for each risk identified in relation to student financial aid information. According to the University?s Program Participation Agreement with the Department of Education, the University is required to protect student financial aid information. During our testing, we noted the University had not conducted a risk assessment identifying internal and external risks to the security, confidentiality, and integrity of student information. The Standards for Safeguarding Customer Information, required by the Gramm-Leach-Bliley Act (GLBA) (16 CFR ? 314.4 (b)), require the University to identify reasonable foreseeable internal and external risks to the security, confidentiality, and integrity of student information that could result in the unauthorized disclosure, misuse, alteration, destruction or other compromise of such information, and assess the sufficiency of any safeguards in place to control these risks. At a minimum, such a risk assessment should include consideration of risk in each relevant area of operations, including: 2022-004. FINDING Noncompliance with Special Tests and Provisions ? Student Financial Aid Information Security (Continued) (1) Employee training and management; (2) Information systems, including network and software design, as well as information processing, storage, transmission and disposal; and (3) Detecting, preventing and responding to attacks, intrusions, or other system failures. Additionally, the Uniform Guidance (2 CFR ? 200.303) requires nonfederal entities receiving federal awards to establish and maintain effective internal control designed to reasonably ensure compliance with federal laws, statutes, regulations, and the terms and conditions of the federal award. In addition, the Framework for Improving Critical Infrastructure Cybersecurity published by the National Institute of Standards and Technology (NIST) requires entities to perform a risk assessment and establish a risk mitigation plan to minimize identified risks. University management indicated the issues were due to the vacancy of an Information Technology Security Officer position. Without a risk assessment, the University is at risk of noncompliance with the GLBA. In addition, the University?s systems and information could be vulnerable to attacks or intrusions, and these attacks may not be detected in a timely manner. (Finding Code No. 2022-004) RECOMMENDATION We recommend the University strengthen controls to ensure adequate risk assessment procedures are performed and documentation of safeguards for each risk identified in relation to student information security is maintained. UNIVERSITY RESPONSE The University agrees with the finding and is developing a corrective action plan for implementation.
2022-003. FINDING Failure to Obtain Student Verification Documents Federal Agency: U.S. Department of Education Assistance Listing Numbers: 84.063; 84.268 Program Names: Student Financial Assistance Cluster - Federal Pell Grant Program Federal Direct Student Loans Program Expenditures: $4,213,853; $20,166,174 Award Numbers: P063P211351; P268K221351 Questioned Costs: None The Chicago State University (University) did not obtain and review student verification documents. For Academic Year 2021-2022, the Department of Education waived the verification of most Free Application for Federal Student Aid (FAFSA) information, except for Identity/Statement of Educational Purpose and High School Completion Status. During testing of 25 students selected for verification, we noted the University did not obtain supporting documentation to verify the identity of two (8%) students. The sample methods used in performing this testing were not statistically valid. The Federal Student Aid Publication (GEN-21-05) ? Changes to 2021-2022 Verification Requirements, dated July 13, 2021, waived verification of information of students applying for financial assistance except for verification of documents for Identity/Statement of Educational Purpose and High School Completion Status of certain verification groups. Additionally, the Uniform Guidance (2 CFR ? 200.303) requires nonfederal entities receiving federal awards to establish and maintain effective internal control designed to reasonably ensure compliance with federal laws, statutes, regulations, and the terms and conditions of the federal award. University management indicated the failure to obtain verification documents was due to oversight. Failure to obtain verification documents in accordance with federal regulations may result in students receiving awards for which they are ineligible and the University incurring unallowable costs. (Finding Code No. 2022-003) 2022-003. FINDING Failure to Obtain Student Verification Documents (Continued) RECOMMENDATION We recommend the University ensure student verification documents are obtained, reviewed, and maintained. UNIVERSITY RESPONSE The University agrees with the finding and is developing a corrective action plan for implementation.
2022-003. FINDING Failure to Obtain Student Verification Documents Federal Agency: U.S. Department of Education Assistance Listing Numbers: 84.063; 84.268 Program Names: Student Financial Assistance Cluster - Federal Pell Grant Program Federal Direct Student Loans Program Expenditures: $4,213,853; $20,166,174 Award Numbers: P063P211351; P268K221351 Questioned Costs: None The Chicago State University (University) did not obtain and review student verification documents. For Academic Year 2021-2022, the Department of Education waived the verification of most Free Application for Federal Student Aid (FAFSA) information, except for Identity/Statement of Educational Purpose and High School Completion Status. During testing of 25 students selected for verification, we noted the University did not obtain supporting documentation to verify the identity of two (8%) students. The sample methods used in performing this testing were not statistically valid. The Federal Student Aid Publication (GEN-21-05) ? Changes to 2021-2022 Verification Requirements, dated July 13, 2021, waived verification of information of students applying for financial assistance except for verification of documents for Identity/Statement of Educational Purpose and High School Completion Status of certain verification groups. Additionally, the Uniform Guidance (2 CFR ? 200.303) requires nonfederal entities receiving federal awards to establish and maintain effective internal control designed to reasonably ensure compliance with federal laws, statutes, regulations, and the terms and conditions of the federal award. University management indicated the failure to obtain verification documents was due to oversight. Failure to obtain verification documents in accordance with federal regulations may result in students receiving awards for which they are ineligible and the University incurring unallowable costs. (Finding Code No. 2022-003) 2022-003. FINDING Failure to Obtain Student Verification Documents (Continued) RECOMMENDATION We recommend the University ensure student verification documents are obtained, reviewed, and maintained. UNIVERSITY RESPONSE The University agrees with the finding and is developing a corrective action plan for implementation.
2022-004. FINDING Noncompliance with Special Tests and Provisions ? Student Financial Aid Information Security Federal Agency: U.S. Department of Education Assistance Listing Numbers: 84.007; 84.033; 84.038; 84.063; 84.268; 84.379; 93.925 Program Names: Student Financial Assistance Cluster - Federal Supplemental Educational Opportunity Grants Federal Work-Study Program Federal Perkins Loan Program Federal Pell Grant Program Federal Direct Student Loans Teacher Education Assistance for College and Higher Education Grants Scholarships for Health Professions Students from Disadvantaged Background Program Expenditures: $359,412; $432,302; $1,264,604; $4,213,853; $20,166,174; $26,878; $860,306 Award Numbers: P007A221121; P033A221121; P063P211351; P268K221351; P379T221351 Questioned Costs: None The Chicago State University (University) did not perform risk assessment procedures and document safeguards for each risk identified in relation to student financial aid information. According to the University?s Program Participation Agreement with the Department of Education, the University is required to protect student financial aid information. During our testing, we noted the University had not conducted a risk assessment identifying internal and external risks to the security, confidentiality, and integrity of student information. The Standards for Safeguarding Customer Information, required by the Gramm-Leach-Bliley Act (GLBA) (16 CFR ? 314.4 (b)), require the University to identify reasonable foreseeable internal and external risks to the security, confidentiality, and integrity of student information that could result in the unauthorized disclosure, misuse, alteration, destruction or other compromise of such information, and assess the sufficiency of any safeguards in place to control these risks. At a minimum, such a risk assessment should include consideration of risk in each relevant area of operations, including: 2022-004. FINDING Noncompliance with Special Tests and Provisions ? Student Financial Aid Information Security (Continued) (1) Employee training and management; (2) Information systems, including network and software design, as well as information processing, storage, transmission and disposal; and (3) Detecting, preventing and responding to attacks, intrusions, or other system failures. Additionally, the Uniform Guidance (2 CFR ? 200.303) requires nonfederal entities receiving federal awards to establish and maintain effective internal control designed to reasonably ensure compliance with federal laws, statutes, regulations, and the terms and conditions of the federal award. In addition, the Framework for Improving Critical Infrastructure Cybersecurity published by the National Institute of Standards and Technology (NIST) requires entities to perform a risk assessment and establish a risk mitigation plan to minimize identified risks. University management indicated the issues were due to the vacancy of an Information Technology Security Officer position. Without a risk assessment, the University is at risk of noncompliance with the GLBA. In addition, the University?s systems and information could be vulnerable to attacks or intrusions, and these attacks may not be detected in a timely manner. (Finding Code No. 2022-004) RECOMMENDATION We recommend the University strengthen controls to ensure adequate risk assessment procedures are performed and documentation of safeguards for each risk identified in relation to student information security is maintained. UNIVERSITY RESPONSE The University agrees with the finding and is developing a corrective action plan for implementation.
2022-005. FINDING Failure to Notify Students Upon Disbursement of Funds Federal Agency: U.S. Department of Education Assistance Listing Numbers: 84.268; 84.379 Program Names: Student Financial Assistance Cluster - Federal Direct Student Loans Teacher Education Assistance for College and Higher Education Grants Program Expenditures: $20,166,174; $26,878 Award Number: P268K221351 Questioned Costs: None The Chicago State University (University) did not notify the students upon disbursement of grant funds and loans. During testing of nine students, who received Teacher Education Assistance for College and Higher Education Grants (TEACH) totaling $21,220, we noted six (67%) students with grant disbursements totaling $16,505 were not notified by the University indicating the funds were credited to the students? accounts. The sample methods used in performing this testing were not statistically valid. In addition, during testing of 25 students, who received Federal Direct Student Loans totaling $447,363, we noted 25 (100%) students were not notified by the University indicating the funds were credited to the students? accounts. The sample methods used in performing this testing were not statistically valid. The Code of Federal Regulations (Code) (34 CFR ? 668.165 (a)(3)(i)) requires the University to notify students or parents in writing no earlier than 30 days before, and no later than 30 days after, crediting the students? ledger account at the University with TEACH Grant funds or Federal Direct Student Loans. Further, the Code (2 CFR ? 200.303) requires the nonfederal entity receiving federal awards to establish and maintain effective internal control over the federal award to provide reasonable assurance the nonfederal entity is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award. Effective internal controls include procedures to ensure timely notification of disbursements to students receiving TEACH Grants and Federal Direct Loans. University management indicated the failure to timely notify students upon disbursements of TEACH grants and Direct Loans was due to resource constraints. 2022-005. FINDING Failure to Notify Students Upon Disbursement (Continued) Failure to timely notify students upon disbursement of funds resulted in noncompliance with the Code. (Finding Code No. 2022-005) RECOMMENDATION We recommend the University strengthen controls to ensure timely notification is sent to students upon disbursement of grant funds and loans. UNIVERSITY RESPONSE The University agrees with the finding and is developing a corrective action plan for implementation.
2022-005. FINDING Failure to Notify Students Upon Disbursement of Funds Federal Agency: U.S. Department of Education Assistance Listing Numbers: 84.268; 84.379 Program Names: Student Financial Assistance Cluster - Federal Direct Student Loans Teacher Education Assistance for College and Higher Education Grants Program Expenditures: $20,166,174; $26,878 Award Number: P268K221351 Questioned Costs: None The Chicago State University (University) did not notify the students upon disbursement of grant funds and loans. During testing of nine students, who received Teacher Education Assistance for College and Higher Education Grants (TEACH) totaling $21,220, we noted six (67%) students with grant disbursements totaling $16,505 were not notified by the University indicating the funds were credited to the students? accounts. The sample methods used in performing this testing were not statistically valid. In addition, during testing of 25 students, who received Federal Direct Student Loans totaling $447,363, we noted 25 (100%) students were not notified by the University indicating the funds were credited to the students? accounts. The sample methods used in performing this testing were not statistically valid. The Code of Federal Regulations (Code) (34 CFR ? 668.165 (a)(3)(i)) requires the University to notify students or parents in writing no earlier than 30 days before, and no later than 30 days after, crediting the students? ledger account at the University with TEACH Grant funds or Federal Direct Student Loans. Further, the Code (2 CFR ? 200.303) requires the nonfederal entity receiving federal awards to establish and maintain effective internal control over the federal award to provide reasonable assurance the nonfederal entity is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award. Effective internal controls include procedures to ensure timely notification of disbursements to students receiving TEACH Grants and Federal Direct Loans. University management indicated the failure to timely notify students upon disbursements of TEACH grants and Direct Loans was due to resource constraints. 2022-005. FINDING Failure to Notify Students Upon Disbursement (Continued) Failure to timely notify students upon disbursement of funds resulted in noncompliance with the Code. (Finding Code No. 2022-005) RECOMMENDATION We recommend the University strengthen controls to ensure timely notification is sent to students upon disbursement of grant funds and loans. UNIVERSITY RESPONSE The University agrees with the finding and is developing a corrective action plan for implementation.
2022-004. FINDING Noncompliance with Special Tests and Provisions ? Student Financial Aid Information Security Federal Agency: U.S. Department of Education Assistance Listing Numbers: 84.007; 84.033; 84.038; 84.063; 84.268; 84.379; 93.925 Program Names: Student Financial Assistance Cluster - Federal Supplemental Educational Opportunity Grants Federal Work-Study Program Federal Perkins Loan Program Federal Pell Grant Program Federal Direct Student Loans Teacher Education Assistance for College and Higher Education Grants Scholarships for Health Professions Students from Disadvantaged Background Program Expenditures: $359,412; $432,302; $1,264,604; $4,213,853; $20,166,174; $26,878; $860,306 Award Numbers: P007A221121; P033A221121; P063P211351; P268K221351; P379T221351 Questioned Costs: None The Chicago State University (University) did not perform risk assessment procedures and document safeguards for each risk identified in relation to student financial aid information. According to the University?s Program Participation Agreement with the Department of Education, the University is required to protect student financial aid information. During our testing, we noted the University had not conducted a risk assessment identifying internal and external risks to the security, confidentiality, and integrity of student information. The Standards for Safeguarding Customer Information, required by the Gramm-Leach-Bliley Act (GLBA) (16 CFR ? 314.4 (b)), require the University to identify reasonable foreseeable internal and external risks to the security, confidentiality, and integrity of student information that could result in the unauthorized disclosure, misuse, alteration, destruction or other compromise of such information, and assess the sufficiency of any safeguards in place to control these risks. At a minimum, such a risk assessment should include consideration of risk in each relevant area of operations, including: 2022-004. FINDING Noncompliance with Special Tests and Provisions ? Student Financial Aid Information Security (Continued) (1) Employee training and management; (2) Information systems, including network and software design, as well as information processing, storage, transmission and disposal; and (3) Detecting, preventing and responding to attacks, intrusions, or other system failures. Additionally, the Uniform Guidance (2 CFR ? 200.303) requires nonfederal entities receiving federal awards to establish and maintain effective internal control designed to reasonably ensure compliance with federal laws, statutes, regulations, and the terms and conditions of the federal award. In addition, the Framework for Improving Critical Infrastructure Cybersecurity published by the National Institute of Standards and Technology (NIST) requires entities to perform a risk assessment and establish a risk mitigation plan to minimize identified risks. University management indicated the issues were due to the vacancy of an Information Technology Security Officer position. Without a risk assessment, the University is at risk of noncompliance with the GLBA. In addition, the University?s systems and information could be vulnerable to attacks or intrusions, and these attacks may not be detected in a timely manner. (Finding Code No. 2022-004) RECOMMENDATION We recommend the University strengthen controls to ensure adequate risk assessment procedures are performed and documentation of safeguards for each risk identified in relation to student information security is maintained. UNIVERSITY RESPONSE The University agrees with the finding and is developing a corrective action plan for implementation.
2022-004. FINDING Noncompliance with Special Tests and Provisions ? Student Financial Aid Information Security Federal Agency: U.S. Department of Education Assistance Listing Numbers: 84.007; 84.033; 84.038; 84.063; 84.268; 84.379; 93.925 Program Names: Student Financial Assistance Cluster - Federal Supplemental Educational Opportunity Grants Federal Work-Study Program Federal Perkins Loan Program Federal Pell Grant Program Federal Direct Student Loans Teacher Education Assistance for College and Higher Education Grants Scholarships for Health Professions Students from Disadvantaged Background Program Expenditures: $359,412; $432,302; $1,264,604; $4,213,853; $20,166,174; $26,878; $860,306 Award Numbers: P007A221121; P033A221121; P063P211351; P268K221351; P379T221351 Questioned Costs: None The Chicago State University (University) did not perform risk assessment procedures and document safeguards for each risk identified in relation to student financial aid information. According to the University?s Program Participation Agreement with the Department of Education, the University is required to protect student financial aid information. During our testing, we noted the University had not conducted a risk assessment identifying internal and external risks to the security, confidentiality, and integrity of student information. The Standards for Safeguarding Customer Information, required by the Gramm-Leach-Bliley Act (GLBA) (16 CFR ? 314.4 (b)), require the University to identify reasonable foreseeable internal and external risks to the security, confidentiality, and integrity of student information that could result in the unauthorized disclosure, misuse, alteration, destruction or other compromise of such information, and assess the sufficiency of any safeguards in place to control these risks. At a minimum, such a risk assessment should include consideration of risk in each relevant area of operations, including: 2022-004. FINDING Noncompliance with Special Tests and Provisions ? Student Financial Aid Information Security (Continued) (1) Employee training and management; (2) Information systems, including network and software design, as well as information processing, storage, transmission and disposal; and (3) Detecting, preventing and responding to attacks, intrusions, or other system failures. Additionally, the Uniform Guidance (2 CFR ? 200.303) requires nonfederal entities receiving federal awards to establish and maintain effective internal control designed to reasonably ensure compliance with federal laws, statutes, regulations, and the terms and conditions of the federal award. In addition, the Framework for Improving Critical Infrastructure Cybersecurity published by the National Institute of Standards and Technology (NIST) requires entities to perform a risk assessment and establish a risk mitigation plan to minimize identified risks. University management indicated the issues were due to the vacancy of an Information Technology Security Officer position. Without a risk assessment, the University is at risk of noncompliance with the GLBA. In addition, the University?s systems and information could be vulnerable to attacks or intrusions, and these attacks may not be detected in a timely manner. (Finding Code No. 2022-004) RECOMMENDATION We recommend the University strengthen controls to ensure adequate risk assessment procedures are performed and documentation of safeguards for each risk identified in relation to student information security is maintained. UNIVERSITY RESPONSE The University agrees with the finding and is developing a corrective action plan for implementation.
2022-006. FINDING Lack of Adherence to Controls and Noncompliance with Requirement Applicable to the Education Stabilization Fund Federal Agency: U.S. Department of Education Assistance Listing Numbers: 84.425E; 84.425F; 84.425L Program Names: Higher Education Stabilization Fund - COVID-19 - Higher Education Emergency Relief Fund - Student Aid Portion COVID-19 - Higher Education Emergency Relief Fund - Institutional Portion COVID-19 - Higher Education Emergency Relief Fund - Minority Serving Institutions Program Expenditures: $4,008,386; $3,338,668; $436,450 Award Numbers: 425E201661; P425F201393; P425L200359 Questioned Costs: None The Chicago State University (University) did not utilize the updated quarterly reporting form to report its Higher Education Emergency Relief Fund (HEERF) student and institutional aid awards. During testing, we noted one of four (25%) quarterly reporting forms utilized for reporting HEERF awards was outdated. As such, the information reported by the University did not include certain data required by the Department of Education. On March 27, 2020, the Coronavirus Aid, Relief, and Economic Security Act (CARES Act) was enacted into Public Law 116-136. Section 18004(a)(1) of the CARES Act established the HEERF I program which authorizes the Secretary of Education (Secretary) to allocate funding to eligible institutions of higher education to prevent, prepare for, and respond to the coronavirus pandemic (COVID-19). Subsequently, additional grants from the Coronavirus Response and Relief Supplemental Appropriations Act (CRRSAA) and the American Rescue Plan Act of 2021 (ARP) were received, establishing the HEERF II and HEERF III programs, respectively, to continuously support public and non-profit institutions and students. Under the CARES, CRRSSA, and ARP Acts, an institution is required to complete and post on its website a quarterly and annual report of its HEERF grant expenditures using the form designed by the Department of Education to help ensure funding transparency and public accountability. 2022-006. FINDING Lack of Adherence to Controls and Noncompliance with Requirement Applicable to the Education Stabilization Fund (Continued) The Higher Education Emergency Relief Fund III Frequently Asked Questions, Question 36, published by the Department of Education, requires the University to utilize the new quarterly reporting form beginning June 30, 2022, reporting period. The new quarterly reporting form includes new reporting categories on mental health spending, HEERF (a)(2) construction flexibilities, and lost revenue and combines the separate institutional and student reporting requirement. The Code of Federal Regulations (Code) (2 CFR ? 200.303) requires the University to establish and maintain effective internal control over the federal award to provide reasonable assurance the University is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award. Effective internal controls should include procedures to ensure compliance with grant reporting requirements. This finding was first reported in Fiscal Year 2020. In subsequent years, the University has been unsuccessful in implementing appropriate procedures to improve its controls over HEERF awards. University management indicated the failure to use the correct reporting form was due to lack of coordination between staff involved in the reporting process. Failure to comply with the grant reporting requirements of the HEERF programs results in noncompliance with the CARES, CRRSAA, and ARP Acts, grant agreements, and the Code. (Finding Code No. 2022-006, 2021-004, 2020-005) RECOMMENDATION We recommend the University strengthen its controls to ensure updated forms are used to report its HEERF student and institutional aid awards. UNIVERSITY RESPONSE The University agrees with the finding and has implemented a corrective action plan to improve internal controls related to posting of HEERF reports and submission of the Governor's Emergency Education Relief Fund reports.