Corrective Action Plans

Browse how organizations respond to audit findings

Total CAPs
61,436
In database
Filtered Results
23,815
Matching current filters
Showing Page
19 of 953
25 per page

Filters

Clear
Active filters: Questioned Costs
Finding 2025-002 DTMB, IT General Controls Management Views The Department of Technology, Management, and Budget (DTMB) agrees it did not perform the annual review of privileged accounts for the operating system servers. As stated in the finding, DTMB performed the recertification process after the ...
Finding 2025-002 DTMB, IT General Controls Management Views The Department of Technology, Management, and Budget (DTMB) agrees it did not perform the annual review of privileged accounts for the operating system servers. As stated in the finding, DTMB performed the recertification process after the issue was brought to its attention. Planned Corrective Action DTMB performed its user access recertification processes in November 2025. Anticipated Completion Date Completed Responsible Individual(s) Manny Rosales, DTMB
Finding 2025-055 Social Services Block Grant, ALN 93.667 - Post-Expenditure Report Management Views MDHHS agrees with the finding. Planned Corrective Action MDHHS is modifying the process to obtain the required post-expenditure report data to ensure all individuals receiving Social Services Block Gr...
Finding 2025-055 Social Services Block Grant, ALN 93.667 - Post-Expenditure Report Management Views MDHHS agrees with the finding. Planned Corrective Action MDHHS is modifying the process to obtain the required post-expenditure report data to ensure all individuals receiving Social Services Block Grant supported services are appropriately included. Also, MDHHS will add a program validation step to review the applicable federal regulations and confirm the data extracted is accurate and complete. In addition, MDHHS will revise and resubmit the fiscal year 2025 report by September 30, 2026. Anticipated Completion Date September 30, 2026 Responsible Individual(s) Tiffany Clarke, MDHHS Rebecca Jones, MDHHS Mary Lou Mahoney, MDHHS Aimee McDaniel, MDHHS
Finding 2025-007 MiSACWIS Security Management and Access Controls Management Views MDHHS agrees with the finding. Planned Corrective Action For part a., MDHHS currently has a process in place to review the user narrative describing the incompatible role exceptions within the DSA Michigan Statewide A...
Finding 2025-007 MiSACWIS Security Management and Access Controls Management Views MDHHS agrees with the finding. Planned Corrective Action For part a., MDHHS currently has a process in place to review the user narrative describing the incompatible role exceptions within the DSA Michigan Statewide Automated Child Welfare Information System (MiSACWIS) request as part of the approval process. Also, MDHHS added an incompatible role form in the DSA MiSACWIS request with automated routing for appropriate approval on November 11, 2025. In addition, MDHHS provides ongoing education during the quarterly LOSC webinars, where guidance is shared with the LOSCs on security management and access control topics, such as the correct procedures for processing system access requests. For part b., during April 2025, MDHHS updated the renewal processing start date to 15 days earlier to ensure renewal requests are reviewed prior to the annual recertification date. Anticipated Completion Date Completed Responsible Individual(s) Tim Kwast, MDHHS Alana Lowe, MDHHS
Finding 2025-051 Low-Income Home Energy Assistance, ALN 93.568 - Eligibility Determinations Management Views MDHHS agrees with the finding. Planned Corrective Action In May 2025, MDHHS issued memo 2025-20, which implemented mandatory training requirements for all eligibility staff and their managers...
Finding 2025-051 Low-Income Home Energy Assistance, ALN 93.568 - Eligibility Determinations Management Views MDHHS agrees with the finding. Planned Corrective Action In May 2025, MDHHS issued memo 2025-20, which implemented mandatory training requirements for all eligibility staff and their managers to address audit-related findings. The State Emergency Relief (SER) training courses occur biannually, in March and August, and cover verification of client income, client contribution payments, and proof of energy crisis. To ensure accuracy of payment processing, in October 2025, MDHHS issued memo 2025-48 which implemented the mandatory SER Reconciliation Report requirement. As part of this updated process, each county office must run the SER Energy Reconciliation Report weekly and review all energy-related payments to ensure accuracy and confirm that required documentation is maintained. In addition, MDHHS will continue to communicate with BSCs and local offices regarding the requirements to maintain sufficient documentation to support SER processing through formal internal communication channels. MDHHS will also continue to provide direct SER guidance and clarification through the SER mailbox. Further, MDHHS will explore a potential system enhancement that will provide automated solutions for an added layer of efficiency and compliance. Should such an improvement be identified, it will be submitted through the Departmental Work Intake Process for prioritization and implementation by the Bridges technical team. Anticipated Completion Date MDHHS has not yet determined an anticipated completion date because the completion date is dependent on the priority assigned to system enhancements as determined by the Departmental Work Intake Process. Responsible Individual(s) Bethany Cabanaw, MDHHS Kent Schulze, MDHHS Julie McLaughlin, MDHHS
Finding 2025-049 Refugee and Entrant Assistance State/Replacement Designee Administered Programs, ALN 93.566 - FFATA Reporting Management Views LEO agrees with the finding. LEO is fully committed to improving its FFATA process. It is LEO’s position that the switch from the FFATA Subaward Reporting S...
Finding 2025-049 Refugee and Entrant Assistance State/Replacement Designee Administered Programs, ALN 93.566 - FFATA Reporting Management Views LEO agrees with the finding. LEO is fully committed to improving its FFATA process. It is LEO’s position that the switch from the FFATA Subaward Reporting System to SAM for FFATA reporting in March 2025 contributed to some of the cited deficiencies. Planned Corrective Action The LEO Finance Division is currently working with the LEO Grants Division to determine a better process of notification for new subawards and amendments so that they can be reported within the required timeframe. The process will be documented in an updated formal procedure which focuses on timely communication as the primary control and SIGMA Business Intelligence queries as a secondary control to ensure completeness of reporting. Anticipated Completion Date June 30, 2026 Responsible Individual(s) Heidi Parker, LEO Chris Johnson, LEO
Finding 2025-048 Refugee and Entrant Assistance State/Replacement Designee Administered Programs, ALN 93.566 - Assistance to Ineligible Refugees Management Views LEO and MDHHS agree with the finding. Planned Corrective Action MDHHS acknowledges that documentation supporting compliance with refugee c...
Finding 2025-048 Refugee and Entrant Assistance State/Replacement Designee Administered Programs, ALN 93.566 - Assistance to Ineligible Refugees Management Views LEO and MDHHS agree with the finding. Planned Corrective Action MDHHS acknowledges that documentation supporting compliance with refugee cash assistance work registry requirements must be consistently maintained in the electronic case record. The issue identified pertains to documentation of ongoing work registration requirements within the case record to maintain eligibility, noting that the clients were eligible at the time of application approval. Beginning January 2026, MDHHS implemented a monthly manual review of active cases to ensure required documentation is present. MDHHS is also pursuing a Bridges system enhancement to automate generation and storage of the DHS-4785R (Refugee Employment Program Appointment Notice) in the electronic case file. This enhancement will be submitted through the Departmental Work Intake Process for prioritization and implementation by the Bridges technical team. Anticipated Completion Date MDHHS has not yet determined an anticipated completion date because the date is dependent on the priority assigned to the system enhancement as determined by the Departmental Work Intake Process. Responsible Individual(s) Benjamin Cabanaw, LEO Nicole Adams, LEO Bethany Cabanaw, MDHHS Kent Schulze, MDHHS Mariah Schaefer, MDHHS
Finding 2025-047 Refugee and Entrant Assistance State/Replacement Designees Administered Programs, ALN 93.566 - Salesforce Security Management and Access Controls Management Views LEO agrees with the finding. For part a., the LEO Office of Global Michigan (OGM) maintains a limited number of internal...
Finding 2025-047 Refugee and Entrant Assistance State/Replacement Designees Administered Programs, ALN 93.566 - Salesforce Security Management and Access Controls Management Views LEO agrees with the finding. For part a., the LEO Office of Global Michigan (OGM) maintains a limited number of internal Salesforce user licenses. As a result, internal user access is inherently constrained and proactively monitored based on employment status. LEO OGM’s existing process for validating continued need is tied to personnel changes: internal user access remains appropriate as long as the employee occupies a position with assigned Salesforce responsibilities, and access is removed when employees separate or move to roles that do not require use of the system. Because license allocation is strictly managed and user roles are position-based, LEO OGM has considered this process to constitute ongoing monitoring rather than an annual recertification process. However, LEO OGM acknowledges that this practice does not fully meet the specific requirement for a documented annual review as noted in SOM Technical Standard 1340.00.020.01 (Access Control Standard). Planned Corrective Action For part a., LEO OGM will formalize and implement an internal user account review process, including conducting and documenting an annual review of all user access accounts in accordance with the Access Control Standard. For part b., LEO OGM will work collaboratively with program and system administrators to strengthen controls around identifying and timely deactivating inactive internal and external user accounts. LEO OGM will establish clearer procedures, increase review frequency, and document the actions taken to ensure accounts exceeding inactivity thresholds are disabled consistently and timely. Anticipated Completion Date September 30, 2026 Responsible Individual(s) Ben Cabanaw, LEO Nicole Adams, LEO
Finding 2025-046 Temporary Assistance for Needy Families, ALN 93.558 - Child Support Non-Cooperation Management Views MDHHS agrees with the finding. Planned Corrective Action MDHHS ESA will review each finding with the local offices responsible for the identified error cases. MDHHS ESA will issue a ...
Finding 2025-046 Temporary Assistance for Needy Families, ALN 93.558 - Child Support Non-Cooperation Management Views MDHHS agrees with the finding. Planned Corrective Action MDHHS ESA will review each finding with the local offices responsible for the identified error cases. MDHHS ESA will issue a memo to local office staff by September 30, 2026, emphasizing the importance of taking appropriate action when clients are either cooperating or not cooperating with child support requirements. Additionally, MDHHS ESA policy staff will collaborate with the Bridges technical team by September 30, 2026, to determine whether system enhancements are needed to ensure sanctions and cooperations are applied in a timely manner. If enhancements are determined to be necessary, a Bridges work request will be developed and scheduled according to established processes and timeframes. Anticipated Completion Date MDHHS has not yet determined an anticipated completion date because the date is dependent on the potential system enhancements identified. Responsible Individual(s) Bethany Cabanaw, MDHHS Kenton Schultz, MDHHS Brian Sanborn, MDHHS
Finding 2025-044 Temporary Assistance for Needy Families, ALN 93.558 - Inappropriate TANF-Funded Emergency Foster Care Assistance Management Views MDHHS agrees with the finding. Planned Corrective Action MDHHS redetermined the Foster Care Title IV-E (Title IV-E) eligibility after the birth certifica...
Finding 2025-044 Temporary Assistance for Needy Families, ALN 93.558 - Inappropriate TANF-Funded Emergency Foster Care Assistance Management Views MDHHS agrees with the finding. Planned Corrective Action MDHHS redetermined the Foster Care Title IV-E (Title IV-E) eligibility after the birth certificate was received and the youth was determined to be Title IV-E eligible. MDHHS has already reclassified the funds to the appropriate funding source, allowing the department to claim Title IV-E for the eligible placement, and repaying any TANF overpayments. Reconciliations between different fund sources, or recoupments for overpayments, will be created within 30 calendar days of receipt of supporting documentation and approved timely by management. All recoupment and reconciliation records will be approved by management no later than September 30 each fiscal year to ensure compliance with year-end requirements. Anticipated Completion Date September 30, 2026 Responsible Individual(s) Nancy Berger, MDHHS
Finding 2025-043 Temporary Assistance for Needy Families, ALN 93.558 - Non-Financial Eligibility Documentation Management Views MDHHS agrees with the finding. Planned Corrective Action MDHHS will issue a memo to reinforce documentation requirements for TANF eligibility determinations by September 30...
Finding 2025-043 Temporary Assistance for Needy Families, ALN 93.558 - Non-Financial Eligibility Documentation Management Views MDHHS agrees with the finding. Planned Corrective Action MDHHS will issue a memo to reinforce documentation requirements for TANF eligibility determinations by September 30, 2026. The memo will clarify expectations for obtaining, uploading, and retaining all required non-financial eligibility verifications in accordance with federal regulations and MDHHS policy. MDHHS will also address each individual case-specific issue with the appropriate local office. In addition, these findings will be addressed as part of TANF mandatory audit training for local office staff scheduled in July 2026. This training will emphasize the importance of maintaining complete eligibility records, proper use of the Work and Self Sufficiency Rules (DHS-1538) form, verification of age and relationship, and timely completion of the Family Automated Screening Tool. Further, MDHHS ESA policy staff are working with the MDHHS Bridges technical team to implement a system modification during September 2026 that will enhance the application review process. Anticipated Completion Date September 30, 2026 Responsible Individual(s) Bethany Cabanaw, MDHHS Kenton Schulze, MDHHS Brian Sanborn, MDHHS Ashley Soper, MDHHS
Finding 2025-006 ADP Security Program Management Views MDHHS and DTMB agree with the finding. Planned Corrective Action For 2 of the 3 systems cited, the Authority to Operate (ATO) was successfully re-established on July 8, 2025, and October 10, 2025, respectively. For the remaining system, MDHHS an...
Finding 2025-006 ADP Security Program Management Views MDHHS and DTMB agree with the finding. Planned Corrective Action For 2 of the 3 systems cited, the Authority to Operate (ATO) was successfully re-established on July 8, 2025, and October 10, 2025, respectively. For the remaining system, MDHHS and DTMB will complete a comprehensive update to the System Security Plan, incorporate all missing control assessments into the risk analysis, and implement the ATO by August 30, 2026. Anticipated Completion Date August 30, 2026 Responsible Individual(s) Nathan Buckwalter, DTMB Heather Frick, DTMB Veronica Maxson, MDHHS Jim Bowen, MDHHS Kasi Hunziger, MDHHS Lyndia Deromedi, MDHHS
Finding 2025-034 CCDF Cluster, ALN 93.575 and 93.596 - FFATA Reporting Management Views MiLEAP agrees with the finding. Planned Corrective Action MiLEAP implemented a process for FFATA reporting in September 2025 and also hired additional staff in fiscal year 2026 who are responsible for reporting r...
Finding 2025-034 CCDF Cluster, ALN 93.575 and 93.596 - FFATA Reporting Management Views MiLEAP agrees with the finding. Planned Corrective Action MiLEAP implemented a process for FFATA reporting in September 2025 and also hired additional staff in fiscal year 2026 who are responsible for reporting required FFATA data for all federal grants to ensure subaward information is reported timely. Anticipated Completion Date Completed Responsible Individual(s) Lora MacKay, MiLEAP Dawn Lake, MiLEAP
Finding 2025-010 MDE, Change Management Process Management Views MDE partially agrees with the finding. MDE agrees that testing results were not fully documented. However, MDE does not agree that post implementation validation could be performed. The scan-vulnerability process could not be performed...
Finding 2025-010 MDE, Change Management Process Management Views MDE partially agrees with the finding. MDE agrees that testing results were not fully documented. However, MDE does not agree that post implementation validation could be performed. The scan-vulnerability process could not be performed in the production environment in this instance without significantly impacting system performance for users, making post implementation validation infeasible. Planned Corrective Action MDE management will review the testing documentation maintained in DevOps for all tickets classified as tasks and associated with change management activities and deployments and will remind staff of the required documentation standards for all DevOps tickets linked to a deployment. Additionally, MDE will evaluate whether an alternative method of validating the scan-vulnerability process in production is feasible. If no alternative method is identified, MDE will document that post implementation validation cannot be performed due to system constraints. Anticipated Completion Date December 31, 2026 Responsible Individual(s) Monica Butler, MDE
Finding 2025-009 MDE, Security Management and Access Controls Management Views MDE agrees with the finding. Planned Corrective Action For part a., management will review the exceptions with the team responsible for processing security forms to reinforce appropriate review and processing. MDE will al...
Finding 2025-009 MDE, Security Management and Access Controls Management Views MDE agrees with the finding. Planned Corrective Action For part a., management will review the exceptions with the team responsible for processing security forms to reinforce appropriate review and processing. MDE will also implement an automated security access request process, which will eliminate any human error as a result of processing forms. For part b., management will refine the NexSys annual recertification process to reduce errors. NexSys staff will improve internal user list reviews and confirm completeness during the upcoming recertification cycle prior to management’s final review. MDE is currently developing an automated process to handle the annual recertification of the Grant Electronic Monitoring System/Michigan Administrative Review System (GEMS/MARS) users and anticipates implementation in September 2026. For part c., MDE updated the procedure for disabling accounts in April 2026 to strengthen and clarify the process to ensure MDE disables inactive user accounts after 18 months. Anticipated Completion Date a. May 2027 b. NexSys: October 2026 GEMS/MARS: September 2026 c. Completed Responsible Individual(s) Monica Butler, MDE Joshua Long, MDE Drew Finkbeiner, MDE
Finding 2025-001 SIGMA High-Risk Activity Monitoring Management Views The Michigan Department of Lifelong Education, Advancement, and Potential (MiLEAP) agrees with the finding. Planned Corrective Action MiLEAP started monitoring its high-risk activity report weekly to ensure users performed only au...
Finding 2025-001 SIGMA High-Risk Activity Monitoring Management Views The Michigan Department of Lifelong Education, Advancement, and Potential (MiLEAP) agrees with the finding. Planned Corrective Action MiLEAP started monitoring its high-risk activity report weekly to ensure users performed only authorized override actions in SIGMA beginning June 20, 2025. Anticipated Completion Date Completed Responsible Individual(s) Lora MacKay, MiLEAP Dawn Lake, MiLEAP Erica Nowland, MiLEAP
Finding 2025-063 Special Education Cluster (IDEA), ALN 84.027 and 84.173 Management Views MDE disagrees with the finding. MDE maintains that its current monitoring approach satisfies federal requirements. The MDE Office of Special Education’s (OSE) monitoring framework is consistent with the risk-ba...
Finding 2025-063 Special Education Cluster (IDEA), ALN 84.027 and 84.173 Management Views MDE disagrees with the finding. MDE maintains that its current monitoring approach satisfies federal requirements. The MDE Office of Special Education’s (OSE) monitoring framework is consistent with the risk-based requirements of the Uniform Guidance (2 CFR 200.332). The Uniform Guidance does not require routine review of underlying supporting documentation for every subrecipient in every monitoring cycle. Rather, source documentation review is one available monitoring tool, which MDE OSE uses, when warranted, based on risk, audit results, identified concerns, or other relevant information. MDE OSE’s monitoring activities include budget review and approval, budget-to-actual analysis, review of expenditure activity, direct engagement and technical assistance with subrecipients, review of single audit reports, issuance of management decisions (when applicable), and enhanced review procedures for higher-risk subrecipients. These activities collectively provide reasonable assurance that funds are used for authorized purposes and in compliance with applicable requirements. MDE OSE also notes that subrecipient single audits have not routinely identified questioned costs or significant noncompliance, which supports the effectiveness of the existing monitoring framework. Planned Corrective Action MDE disagrees with the finding and does not believe corrective action is required to resolve noncompliance. However, MDE OSE will update its internal monitoring procedures to document the circumstances under which expenditure sampling may be performed for medium- and low-risk subrecipients to enhance clarity of MDE OSE procedures. Anticipated Completion Date September 30, 2026 Responsible Individual(s) Sean McLaughlin, MDE
Finding 2025-060 Coronavirus Capital Projects Fund, ALN 21.029 Management Views LEO agrees with the finding. Planned Corrective Action The LEO Finance Division and the LEO Grants Division have identified the deficiencies that led to the audit finding. LEO will correct the internal FFATA reporting pr...
Finding 2025-060 Coronavirus Capital Projects Fund, ALN 21.029 Management Views LEO agrees with the finding. Planned Corrective Action The LEO Finance Division and the LEO Grants Division have identified the deficiencies that led to the audit finding. LEO will correct the internal FFATA reporting process to ensure that new and amended subaward contract information is received by the LEO Finance Division in a timely manner and in accordance with FFATA requirements. LEO will utilize the EGrAMS vendor to update software functionality that will generate an email notification to the LEO Finance Division when a grant agreement is finalized or amended. This notification will ensure communication with the LEO Finance Division occurs in a timely manner and in accordance with FFATA requirements. Anticipated Completion Date June 30, 2026 Responsible Individual(s) Jennifer Duffey, LEO Heidi Parker, LEO
Finding 2025-029 Coronavirus State and Local Fiscal Recovery Funds, ALN 21.027 - MiGrants Security Management and Access Controls Management Views The Department of Natural Resources (DNR) agrees with the finding. Planned Corrective Action DNR recognizes the importance of maintaining strong security...
Finding 2025-029 Coronavirus State and Local Fiscal Recovery Funds, ALN 21.027 - MiGrants Security Management and Access Controls Management Views The Department of Natural Resources (DNR) agrees with the finding. Planned Corrective Action DNR recognizes the importance of maintaining strong security and access controls for the MiGrants system. While DNR has updated many internal processes to align with revised SOM technical standards, additional actions are needed to further strengthen its controls and ensure comprehensive documentation. For part a., each DNR division administrator will maintain thorough documentation of all internal roles assigned related to MiGrants access and verify adequate justification is provided for each role assigned. Each division administrator will be responsible for creating a procedure that identifies the process that captures appropriate approval information for the internal roles assigned by their division. The system administrator will establish a shared repository in a centralized location where the information is stored. For part b., DNR will implement a formal recertification review for all MiGrants users annually, ensuring that supporting documentation is complete and properly retained. For part c., DNR received an exception in June 2026 from the DTMB Technical Review Board to SOM Technical Standard 1340.00.020.01 (Access Control Standard) that extends the requirement for disabling inactive user accounts from 60 days to 365 days. Anticipated Completion Date a. February 28, 2027 b. December 31, 2026 c. Completed Responsible Individual(s) Leah Babcock, DNR Bobbi Audette, DNR Kerry Grey, DNR
Finding 2025-026 Coronavirus State and Local Fiscal Recovery Funds, ALN 21.027 - Insufficient Respite Payment Controls Management Views MDHHS agrees with the finding. Planned Corrective Action MDHHS implemented a post payment review process for the final respite payments issued through the Medical S...
Finding 2025-026 Coronavirus State and Local Fiscal Recovery Funds, ALN 21.027 - Insufficient Respite Payment Controls Management Views MDHHS agrees with the finding. Planned Corrective Action MDHHS implemented a post payment review process for the final respite payments issued through the Medical Services Administration Manual Payment System during fiscal year 2025 and finalized the review during fiscal year 2026, noting no improper payments. As all respite payments concluded at the end of fiscal year 2025, this review is no longer applicable moving forward. Anticipated Completion Date Completed Responsible Individual(s) Crystal Kline, MDHHS
Finding 2025-025 Coronavirus State and Local Fiscal Recovery Funds, ALN 21.027 - PTMS Security Management and Access Controls Management Views MDOT agrees that security management and access controls should be fully established for the Public Transportation Management System (PTMS). Planned Correcti...
Finding 2025-025 Coronavirus State and Local Fiscal Recovery Funds, ALN 21.027 - PTMS Security Management and Access Controls Management Views MDOT agrees that security management and access controls should be fully established for the Public Transportation Management System (PTMS). Planned Corrective Action Because PTMS is a legacy system that is being retired, MDOT will not re-create historical user data that was deleted due to a system limitation. Rather, MDOT EIM and the MDOT Office of Passenger Transportation (OPT) will collaborate and provide oversight to ensure that the new system, the Public Transportation Information Management System (PTIMS), which is scheduled for full implementation August 31, 2026, has fully established security management and access controls and that there is pertinent documentation regarding users’ roles. Also, EIM and OPT will continue to ensure that PTMS, and PTIMS after its implementation, user access is reviewed at least annually in accordance with SOM Technical Standard 1340.00.040.01 (Audit and Accountability Standard). Under the existing process, the designated system security administrators obtain, verify, and document the written approval for all identified users, and access is modified/removed timely and as appropriate based on responses received or removed when no response is received. Anticipated Completion Date September 2026 Responsible Individual(s) Sandy Lovell, MDOT Gina Huhn, MDOT Jean Ruestman, MDOT Kyle Nelson, MDOT Andy Esch, MDOT
Finding 2025-024 Coronavirus State and Local Fiscal Recovery Funds, ALN 21.027 - MiSSG Security Management and Access Controls Management Views MiLEAP agrees with the finding. Planned Corrective Action For part a., for the exceptions noted in the finding, MiLEAP had the contractors complete the acce...
Finding 2025-024 Coronavirus State and Local Fiscal Recovery Funds, ALN 21.027 - MiSSG Security Management and Access Controls Management Views MiLEAP agrees with the finding. Planned Corrective Action For part a., for the exceptions noted in the finding, MiLEAP had the contractors complete the access forms and has approved their access. MiLEAP also updated its procedures to ensure that contractors complete the Michigan Student Aid Scholarships and Grants (MiSSG) access forms before access is granted to the system. For part b., MiLEAP updated its procedures to ensure that it maintains sufficient documentation of its recertification review of internal users. Anticipated Completion Date Completed Responsible Individual(s) Diann Cosme, MiLEAP
Finding 2025-023 Coronavirus State and Local Fiscal Recovery Funds, ALN 21.027 - EGrAMS Security Management and Access Controls Management Views LEO agrees with the finding. Planned Corrective Action For part a., LEO has a process to maintain documentation and support for internal users. For externa...
Finding 2025-023 Coronavirus State and Local Fiscal Recovery Funds, ALN 21.027 - EGrAMS Security Management and Access Controls Management Views LEO agrees with the finding. Planned Corrective Action For part a., LEO has a process to maintain documentation and support for internal users. For external users, LEO will ask the vendor to upgrade the system so it logs every external user activation, including the approving LEO staff member’s name and the timestamp, rather than overwriting previous external user activation records. For part b., LEO established a user reconciliation process in March 2026 that will be managed by the LEO Grants Division. For part c., LEO will change its policy requiring the disablement of user accounts inactive for over 60 days to comply with SOM Technical Standard 1340.00.020.01 (Access Control Standard). LEO will work with DTMB to complete a system security plan so user accounts will be automatically deactivated after 60 days of inactivity. LEO will also explore options to address the issue of EGrAMS users who typically only access the system every 90 days to complete required system reports. Anticipated Completion Date a. December 31, 2026 b. Completed c. December 31, 2026 Responsible Individual(s) Jason Hamblin, LEO
Finding 2025-022 Coronavirus State and Local Fiscal Recovery Funds, ALN 21.027 - Concur Security Management and Access Controls Management Views The Michigan Strategic Fund (MSF) agrees that Concur was not written as an exception in the identified policy but disagrees that there is a control deficie...
Finding 2025-022 Coronavirus State and Local Fiscal Recovery Funds, ALN 21.027 - Concur Security Management and Access Controls Management Views The Michigan Strategic Fund (MSF) agrees that Concur was not written as an exception in the identified policy but disagrees that there is a control deficiency. MSF maintains effective controls within its control environment that effectively mitigate risks associated with exempting Concur from the identified policy and provide reasonable assurance MSF is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. Planned Corrective Action Based on the factors that led MSF to exempt Concur from SECU.01.020.01 (Access Control Standard), including risk assessments and MSF’s existing control environment, Concur will be included in the policy as a written exception. Anticipated Completion Date September 30, 2026 Responsible Individual(s) Alex Fox, MSF Ian McCorvie, MSF Calvin Myers, MSF William Chaffee, MSF
Finding 2025-021 Coronavirus State and Local Fiscal Recovery Funds, ALN 21.027 - AASHTOWare Security Management and Access Controls Management Views MDOT agrees it did not fully establish effective security management and access controls over the American Association of State Highway and Transportat...
Finding 2025-021 Coronavirus State and Local Fiscal Recovery Funds, ALN 21.027 - AASHTOWare Security Management and Access Controls Management Views MDOT agrees it did not fully establish effective security management and access controls over the American Association of State Highway and Transportation Officials software (AASHTOWare) users. Planned Corrective Action For part a., the MDOT Office of Enterprise Information Management (EIM), Bureau of Field Services-Construction Field Services Division, and Bureau of Development-Design Division will collaborate and provide oversight to ensure that internal user access for AASHTOWare is reviewed at least annually. MDOT will implement an improved process, which will be facilitated by the designated system security administrators, to ensure an internal user review at least annually. For part b., MDOT worked with DTMB in May 2026 to correct and enhance the auto-disabler function of the AASHTOWare program. In addition, MDOT will continue to monitor this functionality as part of its improved access control process to ensure users who have not accessed AASHTOWare within 365 days for internal user accounts and 18 months for external user accounts are disabled timely. Anticipated Completion Date a. September 30, 2026 b. Completed Responsible Individual(s) Mark Shulick, MDOT Dan Burns, MDOT Kristin Schuster, MDOT Dee Parker, MDOT Lindsey Renner, MDOT Jason Gutting, MDOT Kyle Nelson, MDOT Andy Esch, MDOT
Finding 2025-012 SNAP Cluster, ALN 10.551 and 10.561 and Summer Electronic Benefits Transfer Program for Children, ALN 10.646 - System and Organization Controls Management Views MDHHS agrees with the finding. Planned Corrective Action MDHHS is currently evaluating the two System and Organization Con...
Finding 2025-012 SNAP Cluster, ALN 10.551 and 10.561 and Summer Electronic Benefits Transfer Program for Children, ALN 10.646 - System and Organization Controls Management Views MDHHS agrees with the finding. Planned Corrective Action MDHHS is currently evaluating the two System and Organization Controls (SOC) reports and will document the evaluation and determination of whether a review is required. Based on these evaluations, if MDHHS determines reviews are required, MDHHS will document the SOC report reviews by June 30, 2026. Also, MDHHS will assess the current SOC review process and implement any needed improvements to ensure subservice organizations are properly evaluated, formally documented, and that SOC report reviews are submitted within 60 days of receiving each report, by September 30, 2026. Anticipated Completion Date September 30, 2026 Responsible Individual(s) Tony Weber, MDHHS Veronica Maxson, MDHHS Dani Wager, MDHHS Tim Kubu, MDHHS
« 1 17 18 20 21 953 »