Corrective Action Plans

Browse how organizations respond to audit findings

Total CAPs
61,701
In database
Filtered Results
20,219
Matching current filters
Showing Page
279 of 809
25 per page

Filters

Clear
Context: During sample testing of 60 students for eligibility, we noted 3 instances where there was no documented review by someone other than the individual making the eligibility determination. The lack of review was isolated to paper applications. Contact Person Responsible for Corrective Action:...
Context: During sample testing of 60 students for eligibility, we noted 3 instances where there was no documented review by someone other than the individual making the eligibility determination. The lack of review was isolated to paper applications. Contact Person Responsible for Corrective Action: Tami Wyant, FSD Contact Phone Number: (765) 963-2560 Ext: 1172 Views of Responsible Official: We concur with the finding. Description of Corrective Action Plan: Prior the start of each school year, the FSD will verify within Skyward Food Service Management System that the eligibility guidelines that have been loaded for use in determining free & reduced lunch status are correct according to the published guidelines. During the eligibility review of applications, the Food Service Director will provide the first review to make her initial determination and the applications will have a second review done by the Asst. Food Service Director, who will put her initials on the paper applications as proof of review. For any online applications that are submitted during the school year the FSD will review online and then push the applications onward within Skyward for final processing since the guidelines have already been verified prior to the start of the school year. The FSD will keep a printed copy of the guidelines loaded in Skyward and the Assistant FSD will verify and initial as a second review and keep on file for audit purposes. Anticipated Completion Date: All paper applications that have been received since the start of the school year, 2024-25, will have a second review done and so noted by the reviewer’s initials. Moving forward, all applications received, whether in paper format or online submission, will have the review done prior to approval. Applications are received throughout the year, so action to remedy this situation will take place immediately for any new applications received.
Context: For the I sample item tested, we noted the School Corporation expended $500,000 on septic tank upgrades in the prior audit period which was charged to the ESSER III (84.425U) grant award. It was noted only $311,614 of these capital asset acquisitions were reported on the capital asset listi...
Context: For the I sample item tested, we noted the School Corporation expended $500,000 on septic tank upgrades in the prior audit period which was charged to the ESSER III (84.425U) grant award. It was noted only $311,614 of these capital asset acquisitions were reported on the capital asset listing for the School Corporation as of June 30, 2024. Contact Per on Responsible for Corrective Action: Michele Harrison/ Corporation treasurer Brian Byrum / Superintendent Contact Phone Number: M. Harrison:765-492-5101 B. Byrum: 765-492-5102 Vie" s of Responsible Official: We concur with the finding. Description of Correcti e Action Plan: Our capital asset inventory is contracted out through Brett Lewis from Adtech. The management team contacted Mr. Lewis with the finding. The correct amount will be added to the next capitol asset inventory. Anticipated Completion Date: 3/7/2025
Context: The School Corporation was required to submit two Annual Data Reports to the Indiana Department of Education (IDOE) during the audit period to meet federal reporting requirements for ESSER grant awards. We noted that the ESSER I and ESSER II amounts reported for the reports covering the FY2...
Context: The School Corporation was required to submit two Annual Data Reports to the Indiana Department of Education (IDOE) during the audit period to meet federal reporting requirements for ESSER grant awards. We noted that the ESSER I and ESSER II amounts reported for the reports covering the FY22 time period ($90,217 and $238,439, respectively) did not agree to the underlying expenditure records ($81,958 and $400,439 respectively, for the period of July 1, 2021 through June 30, 2022). Contact Person Responsible for Corrective Action: Michele Harrison/ Corporation treasurer Brian Byrum I Superintendent Contact Phone Number: M. Harrison:765-492-5101 B. Byrum: 765-492-5102 Views of Responsible Official: We concur with the finding. De cription of Corrective Acti0n Pl an: Our management team noted that the ESSER 1 and ESSR II spreadsheet submitted to the state was incorrect; however, the actual expenditures were correct every month. The spreadsheet was corrected in the following annual submission to the DOE (which is outside this audit window). The next Audit will show the corrected spreadsheet for ESSER I and ESSER II. It is also noted that the management team will implement more internal controls with regard to the preparer and reviewer being different personnel. For year 5 collection, the corporation treasurer will provide the expenditure reports, an outside consultant will prepare the spreadsheet, and have the current superintendent review before submitting. Anticipated Completion Date: 3/7/2025
Context: We noted there was no secondary, documented formal review for the seven sample accounts payable vouchers. All the payroll vouchers selected were properly reviewed. Contact Person Responsible for Corrective Action: Michele Harrison/ Corporation treasurer Brian Byrum / Superintendent Contact ...
Context: We noted there was no secondary, documented formal review for the seven sample accounts payable vouchers. All the payroll vouchers selected were properly reviewed. Contact Person Responsible for Corrective Action: Michele Harrison/ Corporation treasurer Brian Byrum / Superintendent Contact Phone Number: M. Harrison:765-492-5101 B. Byrum: 765-492-5102 Views of Re ponsible Official: We concur with the finding. Description of Corrective Action Plan: Prior to printing accounts payable checks, the corporation treasurer prints the AP voucher register for the superintendent to review and sign. After this internal control, the treasurer processes the checks. Once checks are printed, the voucher is paired with the invoice, initialled by the corporation treasurer and signed by the superintendent. Anticipated Completion Date: 3/7/2025
Context: During testing over controls for eligibility, we noted there was no formal, secondary review for the applications entered in the food service software determining eligibility. Additionally, there was no documented annual review by School Corporation personnel of the income eligibility guide...
Context: During testing over controls for eligibility, we noted there was no formal, secondary review for the applications entered in the food service software determining eligibility. Additionally, there was no documented annual review by School Corporation personnel of the income eligibility guidelines used by the food service software. Contact Person Responsible for Corrective Action: Michele Harrison/ Corporation treasurer Brian Byrum / Superintendent Contact Phone Number: M. Harrison:765-492-5101 B. Byrum: 765-492-5102 Views of Responsible Officia.l : We concur with the finding. Description of Corrective Action Plan: Prior to printing accounts payable checks, the corporation treasurer prints the AP voucher register for the superintendent to review and sign. After this internal control, the treasurer processes the checks. Once checks are printed, the voucher is paired with the invoice, initialled by the corporation treasurer and signed by the superintendent. Anticipated Completion Date: 3/7/2025
Action Plan: CCC’s managerial and quality assurance review processes include reviews of all client files to ensure appropriate documentation of eligibility, services rendered, and client progress. These reviews happen at intake and periodic intervals to ensure the accuracy and quality of the client ...
Action Plan: CCC’s managerial and quality assurance review processes include reviews of all client files to ensure appropriate documentation of eligibility, services rendered, and client progress. These reviews happen at intake and periodic intervals to ensure the accuracy and quality of the client record. We acknowledge that in some cases, management did not specifically document the management review of eligibility documentation, however the review process did ensure that all files did include appropriate documentation of client eligibility. Moving forward, we will ensure that all client files specifically evidence managerial confirmation of client eligibility with one or more of the following: 1. a signed checklist containing potential eligibility documents 2. a signature on the actual eligibility document or referral 3. an electronic case note to the file confirming review and presence of eligibility documentation. We have already begun working with relevant departments to implement these improvements and will monitor the implemented changes to ensure their effectiveness as we are committed to maintaining and enhancing our internal controls environment and the quality of services provided to the individuals and families we serve.
Responsible Contact Person(s): Naveen Abraham, Chief Core Infrastructure Services Corrective Action Planned: Ensuring that infrastructure suppliers fulfill all contractual requirements with respect to Commonwealth security policies and standards necessitates a programmatic, continuous improvement ap...
Responsible Contact Person(s): Naveen Abraham, Chief Core Infrastructure Services Corrective Action Planned: Ensuring that infrastructure suppliers fulfill all contractual requirements with respect to Commonwealth security policies and standards necessitates a programmatic, continuous improvement approach. VITA has made improved cybersecurity a primary goal and major initiatives have completed and are underway. Based on the improved SLAs and with the improved tools previously implemented, VITA will continue to monitor and improve the security of infrastructure services through ongoing governance, including the requirements of architecture documentation, system security plans, and audit reports. VITA’s infrastructure services group will work with our security group to confirm that the current state achieves security standards compliance. VITA will also continue to work with agencies to drive continued vulnerability remediation and access to log data and to further refine documentation regarding SOPs of the security program and regarding the responsibilities of VITA vs the responsibilities of agencies and suppliers. Estimated Completion Date: 6/30/2025
Responsible Contact Person(s): Barry Davis, Chief Information Security Officer Karen Holt, Human Resource Business Process Consultant Corrective Action Planned: An agency-wide work group will be established to determine the exact processes need to implement the controls necessary to address this fi...
Responsible Contact Person(s): Barry Davis, Chief Information Security Officer Karen Holt, Human Resource Business Process Consultant Corrective Action Planned: An agency-wide work group will be established to determine the exact processes need to implement the controls necessary to address this finding. Estimated Completion Date: 6/30/2025
Responsible Contact Person(s): Kevin Platea, Chief Information Officer Stephen Schleck, Associate Director of Enterprise Business Solutions Angela Morse, Benefit Programs Corrective Action Planned: A Change Request (CR), for the management system was developed 2 years ago and DSS is reviewing the CR...
Responsible Contact Person(s): Kevin Platea, Chief Information Officer Stephen Schleck, Associate Director of Enterprise Business Solutions Angela Morse, Benefit Programs Corrective Action Planned: A Change Request (CR), for the management system was developed 2 years ago and DSS is reviewing the CR to determine a status. It was agreed by Line of Business and ITS EBS and the O&M provider that there will be an iterative approach to completing the record retention and purge rules for implementation in the management system. DSS anticipates the first of a series of changes to address this finding to be implemented in the February 2024 Information Technology Services release. DSS is planning for the final phase of Purge by quarter three of 2025 and will include the following scope: • Scope of change is 150 EDBC tables across all programs beyond a defined cut-off date. • A one-time purge process and on-going purge process will be developed to purge the Uncertified/Unauthorized, Non-current Eligibility Determination. • Develop ongoing purge process for the Phase 1 and Phase 2 tables. • Purge Data files and Data logs App/Batch server. Estimated Completion Date: 12/30/2025
Responsible Contact Person(s): Kevin Platea, Chief Information Officer Corrective Action Planned: This finding was marked as FOIA Exempt (FOIAE) and as a result, the State Comptroller has determined that the resulting corrective actions are FOIAE under §2.2-3705.2 (9.) of the Code of Virginia. Fede...
Responsible Contact Person(s): Kevin Platea, Chief Information Officer Corrective Action Planned: This finding was marked as FOIA Exempt (FOIAE) and as a result, the State Comptroller has determined that the resulting corrective actions are FOIAE under §2.2-3705.2 (9.) of the Code of Virginia. Federal awarding agencies and pass-through entities, please see the Appendix titled “Applicable Management Contacts for Findings and Questioned Costs” to request the corrective action planned from the applicable entity. Estimated Completion Date: 12/31/2025
Responsible Contact Person(s): Barry Davis, Chief Information Security Officer and Director of Information Security & Risk Management Corrective Action Planned: DSS Information Security and Risk Management security awareness and training assets will develop role based training for system administrat...
Responsible Contact Person(s): Barry Davis, Chief Information Security Officer and Director of Information Security & Risk Management Corrective Action Planned: DSS Information Security and Risk Management security awareness and training assets will develop role based training for system administrators and data custodians. Estimated Completion Date: 6/30/2025
Responsible Contact Person(s): Barry Davis, Chief Information Security Officer and Director of Information Security & Risk Management John Vosper, Assistant Director of Information Security & Risk Management Corrective Action Planned: DSS has contracted external IT auditors to perform IT audits once...
Responsible Contact Person(s): Barry Davis, Chief Information Security Officer and Director of Information Security & Risk Management John Vosper, Assistant Director of Information Security & Risk Management Corrective Action Planned: DSS has contracted external IT auditors to perform IT audits once every three years on an ongoing rotating basis in accordance with yellow book audit standards. Estimated Completion Date: 12/15/2025
Responsible Contact Person(s): Mike Jones, Chief Information Officer Steve Hanoka, Information Security Officer Corrective Action Planned: Vulnerability Management policies and procedures exist. These include scanning for both vulnerabilities and baseline configuration. They are being tracked acco...
Responsible Contact Person(s): Mike Jones, Chief Information Officer Steve Hanoka, Information Security Officer Corrective Action Planned: Vulnerability Management policies and procedures exist. These include scanning for both vulnerabilities and baseline configuration. They are being tracked according to SEC530 resolution standards. Goal is to ensure that all vulnerabilities are remediated within the SLA or have approved exceptions by May 30, 2025. In addition, DMAS has gained guidance from VITA on acceptable alternatives to penetration testing and are tracking completion. Estimated Completion Date: 5/30/2025
Responsible Contact Person(s): Kevin Platea, Chief Information Officer Corrective Action Planned: This finding was marked as FOIA Exempt (FOIAE) and as a result, the State Comptroller has determined that the resulting corrective actions are FOIAE under §2.2-3705.2 (9.) of the Code of Virginia. Fede...
Responsible Contact Person(s): Kevin Platea, Chief Information Officer Corrective Action Planned: This finding was marked as FOIA Exempt (FOIAE) and as a result, the State Comptroller has determined that the resulting corrective actions are FOIAE under §2.2-3705.2 (9.) of the Code of Virginia. Federal awarding agencies and pass-through entities, please see the Appendix titled “Applicable Management Contacts for Findings and Questioned Costs” to request the corrective action planned from the applicable entity. Estimated Completion Date: 6/30/2025
Responsible Contact Person(s): Kavansa Gardner, IT Manager Corrective Action Planned: DSS performed an annual access review of user accounts for the system. As of December 20, 2024, the DSS projected completion date for the 2024 system Annual Review was December 31, 2024. The IT Manager is waiting f...
Responsible Contact Person(s): Kavansa Gardner, IT Manager Corrective Action Planned: DSS performed an annual access review of user accounts for the system. As of December 20, 2024, the DSS projected completion date for the 2024 system Annual Review was December 31, 2024. The IT Manager is waiting for eight more FIPs to submit screenshots of roles that have been removed or changed. The IT Manager has been in contact with all noncompliant agencies and has meetings scheduled to ensure all necessary documentation is obtained prior to the cutoff point. DSS will be reviewing final documents to certify the accuracy of the review before deadline. Estimated Completion Date: 1/31/2025
Responsible Contact Person(s): Angela Morse, Director of Benefit Programs Kavansa Gardner, IT Manager Corrective Action Planned: DSS will perform and document a conflicting access review for the management system to identify the combinations of roles that could pose separation of duties conflicts an...
Responsible Contact Person(s): Angela Morse, Director of Benefit Programs Kavansa Gardner, IT Manager Corrective Action Planned: DSS will perform and document a conflicting access review for the management system to identify the combinations of roles that could pose separation of duties conflicts and ensure compensating controls are in place to mitigate risks arising from those conflicts. Additionally, DSS will work with the vendor to update the role-based security access documentation to reflect all system changes from prior case management system related releases when there are proposed changes to the roles matrix. Estimated Completion Date: 12/31/2025
Responsible Contact Person(s): Barry Davis, Chief Information Security Officer and Director of Information Security & Risk Management Kevin Platea, Chief Information Officer Corrective Action Planned: This finding was marked as FOIA Exempt (FOIAE) and as a result, the State Comptroller has determine...
Responsible Contact Person(s): Barry Davis, Chief Information Security Officer and Director of Information Security & Risk Management Kevin Platea, Chief Information Officer Corrective Action Planned: This finding was marked as FOIA Exempt (FOIAE) and as a result, the State Comptroller has determined that the resulting corrective actions are FOIAE under §2.2-3705.2 (9.) of the Code of Virginia. Federal awarding agencies and pass-through entities, please see the Appendix titled “Applicable Management Contacts for Findings and Questioned Costs” to request the corrective action planned from the applicable entity. Estimated Completion Date: 12/31/2026
Responsible Contact Person(s): Kevin Platea, Chief Information Officer Dwayne Sneade, Director of Cybersecurity Corrective Action Planned: This finding was marked as FOIA Exempt (FOIAE) and as a result, the State Comptroller has determined that the resulting corrective actions are FOIAE under §2.2-3...
Responsible Contact Person(s): Kevin Platea, Chief Information Officer Dwayne Sneade, Director of Cybersecurity Corrective Action Planned: This finding was marked as FOIA Exempt (FOIAE) and as a result, the State Comptroller has determined that the resulting corrective actions are FOIAE under §2.2-3705.2 (9.) of the Code of Virginia. Federal awarding agencies and pass-through entities, please see the Appendix titled “Applicable Management Contacts for Findings and Questioned Costs” to request the corrective action planned from the applicable entity. Estimated Completion Date: 12/31/2025
Responsible Contact Person(s): Barry Davis, Chief Information Security Officer and Director of Information Security & Risk Management John Vosper, Assistant Director of Information Security & Risk Management Sam Owusu, IT Risk Manager of Information Security & Risk Management Corrective Action Plann...
Responsible Contact Person(s): Barry Davis, Chief Information Security Officer and Director of Information Security & Risk Management John Vosper, Assistant Director of Information Security & Risk Management Sam Owusu, IT Risk Manager of Information Security & Risk Management Corrective Action Planned: This finding was marked as FOIA Exempt (FOIAE) and as a result, the State Comptroller has determined that the resulting corrective actions are FOIAE under §2.2-3705.2 (9.) of the Code of Virginia. Federal awarding agencies and pass-through entities, please see the Appendix titled “Applicable Management Contacts for Findings and Questioned Costs” to request the corrective action planned from the applicable entity. Estimated Completion Date: 12/31/2026
Responsible Contact Person(s): Mike Jones, Chief Information Officer Corrective Action Planned: This finding was marked as FOIA Exempt (FOIAE) and as a result, the State Comptroller has determined that the resulting corrective actions are FOIAE under §2.2-3705.2 (9.) of the Code of Virginia. Federa...
Responsible Contact Person(s): Mike Jones, Chief Information Officer Corrective Action Planned: This finding was marked as FOIA Exempt (FOIAE) and as a result, the State Comptroller has determined that the resulting corrective actions are FOIAE under §2.2-3705.2 (9.) of the Code of Virginia. Federal awarding agencies and pass-through entities, please see the Appendix titled “Applicable Management Contacts for Findings and Questioned Costs” to request the corrective action planned from the applicable entity. Estimated Completion Date: 4/30/2025
Responsible Contact Person(s): Steve Hanoka, Information Security Officer Corrective Action Planned: 1. The requirements in the IT Security Governance or general requirements in SEC 530 are going to be addressed as part of the IT Security Planning and IT Security Program Management Policies and Pr...
Responsible Contact Person(s): Steve Hanoka, Information Security Officer Corrective Action Planned: 1. The requirements in the IT Security Governance or general requirements in SEC 530 are going to be addressed as part of the IT Security Planning and IT Security Program Management Policies and Procedures which are targeted to be complete by February 28, 2025. In addition, as part of this effort DMAS will publicize and communicate to system owners those control families which will have general / organizational procedures and which will require system specific procedures. 2. Access Management policies and procedures are in place. As part of annual SSP reviews DMAS is now verifying compliance or issues found 3. All SSPs are current and under SEC530 4. Incident Response Policies and Procedures exist 5. Vulnerability Management policies and procedures exist. These include scanning for both vulnerabilities and baseline configuration. They are being tracked according to SEC530 resolution standards. Goal is to ensure that all vulnerabilities are remediated within the SLA or have approved exceptions by May 30, 2025. In addition, DMAS has gained guidance from VITA on acceptable alternatives to penetration testing and are tracking completion. 6. Comprehensive third-party Management procedures are being developed and will be implemented by March 31, 2025. 7. Security Training is up to date and compliant Estimated Completion Date: 5/31/2025
Responsible Contact Person(s): Steve Hanoka, Information Security Officer Corrective Action Planned: Third-party Management that will cover ensuring all deliverables required are part of a procedure and work instruction. In addition, to specifically address the points in the finding, ISO will ensure...
Responsible Contact Person(s): Steve Hanoka, Information Security Officer Corrective Action Planned: Third-party Management that will cover ensuring all deliverables required are part of a procedure and work instruction. In addition, to specifically address the points in the finding, ISO will ensure that the work instructions cover obtaining a confirmation on the geographic location of sensitive data monthly and vulnerability scan results at least every 90 days.  During this procedure implementation, ISO will also work to specifically obtain these deliverables from the vendor in question.  Estimated Completion Date: 3/31/2025
Responsible Contact Person(s): Mike Jones, Chief Information Officer Corrective Action Planned: Language has been added to the Conduent contract renewal for option years 1 and 2 to require the SOC 1 Type II. The renewal is in the process of being reviewed and executed to go into effect July 1, 2025...
Responsible Contact Person(s): Mike Jones, Chief Information Officer Corrective Action Planned: Language has been added to the Conduent contract renewal for option years 1 and 2 to require the SOC 1 Type II. The renewal is in the process of being reviewed and executed to go into effect July 1, 2025. Language added to contract renewal: Contractor Internal Controls Reports The Contractor shall provide the Department, at a minimum; annual, unredacted reports from its independent external auditor on the effectiveness of the Contractor’s internal controls conducted in accordance with the AICPA Statement on Standards for Attestation Engagements. If the reports disclose deficiencies in internal controls, the Contractor shall include management’s corrective action plans to remediate the deficiency. The Contractor shall provide the following reports: · SOC 1 Type 2 Report that reports on the controls at the service organization which are relevant to the user entities’ internal control over financial reporting · SOC 2 Type 2 Report covering all five Trust Services Criteria (Security, Availability, Processing Integrity, Privacy and Confidentiality) The contractor shall provide the Department with these internal control reports within 30 days of the report’s issue date. Reports shall cover a period of 12 months beginning from the end date of the prior audit period with the first report covering a period of 12 months from the execution date of this contract. The contractor shall provide unredacted SOC 1 Type 2 and/or SOC 2 Type 2 reports as described above for any subservice organizations which provide a service to the Contractor that may impact the Department’s financial, program operations, or data security as determined by the Department. Estimated Completion Date: 7/1/2026
Responsible Contact Person(s): Angela Morse, Director of Benefit Programs Frank Smith, Associate Director of Benefit Programs Corrective Action Planned: DSS will perform an analysis of identified reporting errors to determine causality and the appropriate actions to resolve reporting errors. Additio...
Responsible Contact Person(s): Angela Morse, Director of Benefit Programs Frank Smith, Associate Director of Benefit Programs Corrective Action Planned: DSS will perform an analysis of identified reporting errors to determine causality and the appropriate actions to resolve reporting errors. Additionally, DSS will create a systems modification request to correct errors that are identified as occurring as a result of inaccurate programming in the data modification phase of federal report creation. Estimated Completion Date: 12/31/2025
Responsible Contact Person(s): Ida Witherspoon, Chief Financial Officer Corrective Action Planned: Send periodic e-mail reminders to program staff responsible for submitting FFATA data to the Federal Reporting Unit for submission to the federal government. Estimated Completion Date: 3/15/2025
Responsible Contact Person(s): Ida Witherspoon, Chief Financial Officer Corrective Action Planned: Send periodic e-mail reminders to program staff responsible for submitting FFATA data to the Federal Reporting Unit for submission to the federal government. Estimated Completion Date: 3/15/2025
« 1 277 278 280 281 809 »