Corrective Action Plans

Browse how organizations respond to audit findings

Total CAPs
61,701
In database
Filtered Results
23,815
Matching current filters
Showing Page
302 of 953
25 per page

Filters

Clear
Active filters: Questioned Costs
Condition: The University did not return Title IV aid in a timely manner during the fiscal year. Planned Corrective Action: The University resolved immediately upon identification. The University checked all students and found no other student affected. It was an isolated incident that led to the mo...
Condition: The University did not return Title IV aid in a timely manner during the fiscal year. Planned Corrective Action: The University resolved immediately upon identification. The University checked all students and found no other student affected. It was an isolated incident that led to the modification of controls for accurate reporting going forward. Contact person responsible for corrective action: Cassie Tennant Anticipated Completion Date: The university completed this action on June 24, 2024
SECTION III - FEDERAL AWARD FINDINGS AND QUESTIONED COSTS 2024-002 – ACTIVITIES ALLOWED OR UNALLOWED AUDITEE’S RESPONSE AND CORRECTIVE ACTION TAKEN Management reviewed the authorized signatories on all accounts, updating them and retired the manual stamp as of March 2024. The contact person for this...
SECTION III - FEDERAL AWARD FINDINGS AND QUESTIONED COSTS 2024-002 – ACTIVITIES ALLOWED OR UNALLOWED AUDITEE’S RESPONSE AND CORRECTIVE ACTION TAKEN Management reviewed the authorized signatories on all accounts, updating them and retired the manual stamp as of March 2024. The contact person for this finding is John McKeown, Executive Director, and can be reached at 781-293-3088. Completion date of corrective action was March 2024.
Action Plan: CCC’s managerial and quality assurance review processes include reviews of all client files to ensure appropriate documentation of eligibility, services rendered, and client progress. These reviews happen at intake and periodic intervals to ensure the accuracy and quality of the client ...
Action Plan: CCC’s managerial and quality assurance review processes include reviews of all client files to ensure appropriate documentation of eligibility, services rendered, and client progress. These reviews happen at intake and periodic intervals to ensure the accuracy and quality of the client record. We acknowledge that in some cases, management did not specifically document the management review of eligibility documentation, however the review process did ensure that all files did include appropriate documentation of client eligibility. Moving forward, we will ensure that all client files specifically evidence managerial confirmation of client eligibility with one or more of the following: 1. a signed checklist containing potential eligibility documents 2. a signature on the actual eligibility document or referral 3. an electronic case note to the file confirming review and presence of eligibility documentation. We have already begun working with relevant departments to implement these improvements and will monitor the implemented changes to ensure their effectiveness as we are committed to maintaining and enhancing our internal controls environment and the quality of services provided to the individuals and families we serve.
Finding ALN 11.307 During testing of the Economic Adjustment Assistance (ALN 11.307) grant two issues were noted. The federal expenditure amount was reported incorrectly on the SEFA provided by Louisville Metro and information in the loan payment system was incorrect for two written off loans. The a...
Finding ALN 11.307 During testing of the Economic Adjustment Assistance (ALN 11.307) grant two issues were noted. The federal expenditure amount was reported incorrectly on the SEFA provided by Louisville Metro and information in the loan payment system was incorrect for two written off loans. The amount reported on the SEFA was $1,501,755. The correct federal expenditure amount is $3,072,347. An adjustment to the SEFA was made to correct the federal expenditure amount. The loan payment for the written off loan, Barbie Bac’z, did not follow the order of priority. The METCO Board approved $14,699 to be written off for The Limbo LLC per the 12/14/23 METCO memo. However, the amount on the grant portfolio that was written off was $14,577. The difference between the minutes and the grant portfolio is $122. “We recommend communication between the OMB Grants division and the agency handling a federal grant be improved to ensure the SEFA is accurate. Auditor’s Recommendation We recommend management periodically reconcile the RLF loan system to catch errors before too much time has passed and make corrections when needed. We recommend that management correct the next semi-annual report and the information used to prepare the chart attached to the semi-annual report is for the correct fiscal year.” Management Response Management concurs with the auditors’ finding and recommendation. Metro Government will implement controls for periodic reconciliation of the RLF loan system to catch errors before too much time has passed in addition to a year-end review for a secondary supervisor and management review to ensure an accurate outcome before submission for audit review. Anticipated Completion Date Periodic Reconciliation of RLF program quarterly beginning April 1, 2025 Annual Review to be completed by July 15 for fiscal year ending June 30 Contact Responsible For Corrective Action Richard Champion Louisville Metro Finance Director (502) 574-1881
View Audit 345218 Questioned Costs: $1
Responsible Contact Person(s): Naveen Abraham, Chief Core Infrastructure Services Corrective Action Planned: Ensuring that infrastructure suppliers fulfill all contractual requirements with respect to Commonwealth security policies and standards necessitates a programmatic, continuous improvement ap...
Responsible Contact Person(s): Naveen Abraham, Chief Core Infrastructure Services Corrective Action Planned: Ensuring that infrastructure suppliers fulfill all contractual requirements with respect to Commonwealth security policies and standards necessitates a programmatic, continuous improvement approach. VITA has made improved cybersecurity a primary goal and major initiatives have completed and are underway. Based on the improved SLAs and with the improved tools previously implemented, VITA will continue to monitor and improve the security of infrastructure services through ongoing governance, including the requirements of architecture documentation, system security plans, and audit reports. VITA’s infrastructure services group will work with our security group to confirm that the current state achieves security standards compliance. VITA will also continue to work with agencies to drive continued vulnerability remediation and access to log data and to further refine documentation regarding SOPs of the security program and regarding the responsibilities of VITA vs the responsibilities of agencies and suppliers. Estimated Completion Date: 6/30/2025
Responsible Contact Person(s): Barry Davis, Chief Information Security Officer Karen Holt, Human Resource Business Process Consultant Corrective Action Planned: An agency-wide work group will be established to determine the exact processes need to implement the controls necessary to address this fi...
Responsible Contact Person(s): Barry Davis, Chief Information Security Officer Karen Holt, Human Resource Business Process Consultant Corrective Action Planned: An agency-wide work group will be established to determine the exact processes need to implement the controls necessary to address this finding. Estimated Completion Date: 6/30/2025
Responsible Contact Person(s): Kevin Platea, Chief Information Officer Stephen Schleck, Associate Director of Enterprise Business Solutions Angela Morse, Benefit Programs Corrective Action Planned: A Change Request (CR), for the management system was developed 2 years ago and DSS is reviewing the CR...
Responsible Contact Person(s): Kevin Platea, Chief Information Officer Stephen Schleck, Associate Director of Enterprise Business Solutions Angela Morse, Benefit Programs Corrective Action Planned: A Change Request (CR), for the management system was developed 2 years ago and DSS is reviewing the CR to determine a status. It was agreed by Line of Business and ITS EBS and the O&M provider that there will be an iterative approach to completing the record retention and purge rules for implementation in the management system. DSS anticipates the first of a series of changes to address this finding to be implemented in the February 2024 Information Technology Services release. DSS is planning for the final phase of Purge by quarter three of 2025 and will include the following scope: • Scope of change is 150 EDBC tables across all programs beyond a defined cut-off date. • A one-time purge process and on-going purge process will be developed to purge the Uncertified/Unauthorized, Non-current Eligibility Determination. • Develop ongoing purge process for the Phase 1 and Phase 2 tables. • Purge Data files and Data logs App/Batch server. Estimated Completion Date: 12/30/2025
Responsible Contact Person(s): Kevin Platea, Chief Information Officer Corrective Action Planned: This finding was marked as FOIA Exempt (FOIAE) and as a result, the State Comptroller has determined that the resulting corrective actions are FOIAE under §2.2-3705.2 (9.) of the Code of Virginia. Fede...
Responsible Contact Person(s): Kevin Platea, Chief Information Officer Corrective Action Planned: This finding was marked as FOIA Exempt (FOIAE) and as a result, the State Comptroller has determined that the resulting corrective actions are FOIAE under §2.2-3705.2 (9.) of the Code of Virginia. Federal awarding agencies and pass-through entities, please see the Appendix titled “Applicable Management Contacts for Findings and Questioned Costs” to request the corrective action planned from the applicable entity. Estimated Completion Date: 12/31/2025
Responsible Contact Person(s): Barry Davis, Chief Information Security Officer and Director of Information Security & Risk Management Corrective Action Planned: DSS Information Security and Risk Management security awareness and training assets will develop role based training for system administrat...
Responsible Contact Person(s): Barry Davis, Chief Information Security Officer and Director of Information Security & Risk Management Corrective Action Planned: DSS Information Security and Risk Management security awareness and training assets will develop role based training for system administrators and data custodians. Estimated Completion Date: 6/30/2025
Responsible Contact Person(s): Barry Davis, Chief Information Security Officer and Director of Information Security & Risk Management John Vosper, Assistant Director of Information Security & Risk Management Corrective Action Planned: DSS has contracted external IT auditors to perform IT audits once...
Responsible Contact Person(s): Barry Davis, Chief Information Security Officer and Director of Information Security & Risk Management John Vosper, Assistant Director of Information Security & Risk Management Corrective Action Planned: DSS has contracted external IT auditors to perform IT audits once every three years on an ongoing rotating basis in accordance with yellow book audit standards. Estimated Completion Date: 12/15/2025
Responsible Contact Person(s): Mike Jones, Chief Information Officer Steve Hanoka, Information Security Officer Corrective Action Planned: Vulnerability Management policies and procedures exist. These include scanning for both vulnerabilities and baseline configuration. They are being tracked acco...
Responsible Contact Person(s): Mike Jones, Chief Information Officer Steve Hanoka, Information Security Officer Corrective Action Planned: Vulnerability Management policies and procedures exist. These include scanning for both vulnerabilities and baseline configuration. They are being tracked according to SEC530 resolution standards. Goal is to ensure that all vulnerabilities are remediated within the SLA or have approved exceptions by May 30, 2025. In addition, DMAS has gained guidance from VITA on acceptable alternatives to penetration testing and are tracking completion. Estimated Completion Date: 5/30/2025
Responsible Contact Person(s): Kevin Platea, Chief Information Officer Corrective Action Planned: This finding was marked as FOIA Exempt (FOIAE) and as a result, the State Comptroller has determined that the resulting corrective actions are FOIAE under §2.2-3705.2 (9.) of the Code of Virginia. Fede...
Responsible Contact Person(s): Kevin Platea, Chief Information Officer Corrective Action Planned: This finding was marked as FOIA Exempt (FOIAE) and as a result, the State Comptroller has determined that the resulting corrective actions are FOIAE under §2.2-3705.2 (9.) of the Code of Virginia. Federal awarding agencies and pass-through entities, please see the Appendix titled “Applicable Management Contacts for Findings and Questioned Costs” to request the corrective action planned from the applicable entity. Estimated Completion Date: 6/30/2025
Responsible Contact Person(s): Kavansa Gardner, IT Manager Corrective Action Planned: DSS performed an annual access review of user accounts for the system. As of December 20, 2024, the DSS projected completion date for the 2024 system Annual Review was December 31, 2024. The IT Manager is waiting f...
Responsible Contact Person(s): Kavansa Gardner, IT Manager Corrective Action Planned: DSS performed an annual access review of user accounts for the system. As of December 20, 2024, the DSS projected completion date for the 2024 system Annual Review was December 31, 2024. The IT Manager is waiting for eight more FIPs to submit screenshots of roles that have been removed or changed. The IT Manager has been in contact with all noncompliant agencies and has meetings scheduled to ensure all necessary documentation is obtained prior to the cutoff point. DSS will be reviewing final documents to certify the accuracy of the review before deadline. Estimated Completion Date: 1/31/2025
Responsible Contact Person(s): Angela Morse, Director of Benefit Programs Kavansa Gardner, IT Manager Corrective Action Planned: DSS will perform and document a conflicting access review for the management system to identify the combinations of roles that could pose separation of duties conflicts an...
Responsible Contact Person(s): Angela Morse, Director of Benefit Programs Kavansa Gardner, IT Manager Corrective Action Planned: DSS will perform and document a conflicting access review for the management system to identify the combinations of roles that could pose separation of duties conflicts and ensure compensating controls are in place to mitigate risks arising from those conflicts. Additionally, DSS will work with the vendor to update the role-based security access documentation to reflect all system changes from prior case management system related releases when there are proposed changes to the roles matrix. Estimated Completion Date: 12/31/2025
Responsible Contact Person(s): Barry Davis, Chief Information Security Officer and Director of Information Security & Risk Management Kevin Platea, Chief Information Officer Corrective Action Planned: This finding was marked as FOIA Exempt (FOIAE) and as a result, the State Comptroller has determine...
Responsible Contact Person(s): Barry Davis, Chief Information Security Officer and Director of Information Security & Risk Management Kevin Platea, Chief Information Officer Corrective Action Planned: This finding was marked as FOIA Exempt (FOIAE) and as a result, the State Comptroller has determined that the resulting corrective actions are FOIAE under §2.2-3705.2 (9.) of the Code of Virginia. Federal awarding agencies and pass-through entities, please see the Appendix titled “Applicable Management Contacts for Findings and Questioned Costs” to request the corrective action planned from the applicable entity. Estimated Completion Date: 12/31/2026
Responsible Contact Person(s): Kevin Platea, Chief Information Officer Dwayne Sneade, Director of Cybersecurity Corrective Action Planned: This finding was marked as FOIA Exempt (FOIAE) and as a result, the State Comptroller has determined that the resulting corrective actions are FOIAE under §2.2-3...
Responsible Contact Person(s): Kevin Platea, Chief Information Officer Dwayne Sneade, Director of Cybersecurity Corrective Action Planned: This finding was marked as FOIA Exempt (FOIAE) and as a result, the State Comptroller has determined that the resulting corrective actions are FOIAE under §2.2-3705.2 (9.) of the Code of Virginia. Federal awarding agencies and pass-through entities, please see the Appendix titled “Applicable Management Contacts for Findings and Questioned Costs” to request the corrective action planned from the applicable entity. Estimated Completion Date: 12/31/2025
Responsible Contact Person(s): Barry Davis, Chief Information Security Officer and Director of Information Security & Risk Management John Vosper, Assistant Director of Information Security & Risk Management Sam Owusu, IT Risk Manager of Information Security & Risk Management Corrective Action Plann...
Responsible Contact Person(s): Barry Davis, Chief Information Security Officer and Director of Information Security & Risk Management John Vosper, Assistant Director of Information Security & Risk Management Sam Owusu, IT Risk Manager of Information Security & Risk Management Corrective Action Planned: This finding was marked as FOIA Exempt (FOIAE) and as a result, the State Comptroller has determined that the resulting corrective actions are FOIAE under §2.2-3705.2 (9.) of the Code of Virginia. Federal awarding agencies and pass-through entities, please see the Appendix titled “Applicable Management Contacts for Findings and Questioned Costs” to request the corrective action planned from the applicable entity. Estimated Completion Date: 12/31/2026
Responsible Contact Person(s): Mike Jones, Chief Information Officer Corrective Action Planned: This finding was marked as FOIA Exempt (FOIAE) and as a result, the State Comptroller has determined that the resulting corrective actions are FOIAE under §2.2-3705.2 (9.) of the Code of Virginia. Federa...
Responsible Contact Person(s): Mike Jones, Chief Information Officer Corrective Action Planned: This finding was marked as FOIA Exempt (FOIAE) and as a result, the State Comptroller has determined that the resulting corrective actions are FOIAE under §2.2-3705.2 (9.) of the Code of Virginia. Federal awarding agencies and pass-through entities, please see the Appendix titled “Applicable Management Contacts for Findings and Questioned Costs” to request the corrective action planned from the applicable entity. Estimated Completion Date: 4/30/2025
Responsible Contact Person(s): Steve Hanoka, Information Security Officer Corrective Action Planned: 1. The requirements in the IT Security Governance or general requirements in SEC 530 are going to be addressed as part of the IT Security Planning and IT Security Program Management Policies and Pr...
Responsible Contact Person(s): Steve Hanoka, Information Security Officer Corrective Action Planned: 1. The requirements in the IT Security Governance or general requirements in SEC 530 are going to be addressed as part of the IT Security Planning and IT Security Program Management Policies and Procedures which are targeted to be complete by February 28, 2025. In addition, as part of this effort DMAS will publicize and communicate to system owners those control families which will have general / organizational procedures and which will require system specific procedures. 2. Access Management policies and procedures are in place. As part of annual SSP reviews DMAS is now verifying compliance or issues found 3. All SSPs are current and under SEC530 4. Incident Response Policies and Procedures exist 5. Vulnerability Management policies and procedures exist. These include scanning for both vulnerabilities and baseline configuration. They are being tracked according to SEC530 resolution standards. Goal is to ensure that all vulnerabilities are remediated within the SLA or have approved exceptions by May 30, 2025. In addition, DMAS has gained guidance from VITA on acceptable alternatives to penetration testing and are tracking completion. 6. Comprehensive third-party Management procedures are being developed and will be implemented by March 31, 2025. 7. Security Training is up to date and compliant Estimated Completion Date: 5/31/2025
Responsible Contact Person(s): Steve Hanoka, Information Security Officer Corrective Action Planned: Third-party Management that will cover ensuring all deliverables required are part of a procedure and work instruction. In addition, to specifically address the points in the finding, ISO will ensure...
Responsible Contact Person(s): Steve Hanoka, Information Security Officer Corrective Action Planned: Third-party Management that will cover ensuring all deliverables required are part of a procedure and work instruction. In addition, to specifically address the points in the finding, ISO will ensure that the work instructions cover obtaining a confirmation on the geographic location of sensitive data monthly and vulnerability scan results at least every 90 days.  During this procedure implementation, ISO will also work to specifically obtain these deliverables from the vendor in question.  Estimated Completion Date: 3/31/2025
Responsible Contact Person(s): Angela Morse, Director of Benefit Programs Diana Clark, Assistant Director of Division of Benefit Programs Frank Smith, Associate Director of Benefit Programs Mark Golden, Economic Assistance and Employment Manager - Division of Benefit Programs Corrective Action Plan...
Responsible Contact Person(s): Angela Morse, Director of Benefit Programs Diana Clark, Assistant Director of Division of Benefit Programs Frank Smith, Associate Director of Benefit Programs Mark Golden, Economic Assistance and Employment Manager - Division of Benefit Programs Corrective Action Planned: DSS will work to provide additional training to local agency eligibility workers on how to properly determine and document eligibility determinations in the case management system. Additionally, DSS will consider monitoring local agency eligibility worker’s use of manual overrides to confirm that they properly document eligibility determinations in the case management system. Estimated Completion Date: 12/31/2025
View Audit 345214 Questioned Costs: $1
Responsible Contact Person(s): Angela Morse, Director of Benefit Programs Frank Smith, Associate Director of Benefit Programs Corrective Action Planned: DSS will perform an analysis of identified reporting errors to determine causality and the appropriate actions to resolve reporting errors. Additio...
Responsible Contact Person(s): Angela Morse, Director of Benefit Programs Frank Smith, Associate Director of Benefit Programs Corrective Action Planned: DSS will perform an analysis of identified reporting errors to determine causality and the appropriate actions to resolve reporting errors. Additionally, DSS will create a systems modification request to correct errors that are identified as occurring as a result of inaccurate programming in the data modification phase of federal report creation. Estimated Completion Date: 12/31/2025
Responsible Contact Person(s): Angela Morse, Director of Benefit Programs Diana Clark, Assistant Director of Division of Benefit Programs Frank Smith, Associate Director of Benefit Programs Mark Golden, Economic Assistance and Employment Manager - Division of Benefit Programs Corrective Action Plann...
Responsible Contact Person(s): Angela Morse, Director of Benefit Programs Diana Clark, Assistant Director of Division of Benefit Programs Frank Smith, Associate Director of Benefit Programs Mark Golden, Economic Assistance and Employment Manager - Division of Benefit Programs Corrective Action Planned: DSS will work to provide additional training to local agency eligibility workers on how to properly determine and document eligibility determinations in the case management system. Additionally, DSS will consider monitoring local agency eligibility worker’s use of manual overrides to confirm that they properly document eligibility determinations in the case management system. Estimated Completion Date: 3/31/2025
View Audit 345214 Questioned Costs: $1
Responsible Contact Person(s): Angela Morse, Director of Benefit Programs Frank Smith, Associate Director of Benefit Programs Corrective Action Planned: DSS will perform an analysis of identified reporting errors to determine causality and the appropriate actions to resolve reporting errors. Additio...
Responsible Contact Person(s): Angela Morse, Director of Benefit Programs Frank Smith, Associate Director of Benefit Programs Corrective Action Planned: DSS will perform an analysis of identified reporting errors to determine causality and the appropriate actions to resolve reporting errors. Additionally, DSS will create a systems modification request to correct errors that are identified as occurring as a result of inaccurate programming in the data modification phase of federal report creation. Benefit Program is working with appropriate parties to resolve outstanding errors. Estimated Completion Date: 6/30/2025
Responsible Contact Person(s): Sherika Charity, Director of Financial Aid Corrective Action Planned: Step 1: Review and update the FISAP Completion Documentation to clearly identify sources of data. This will include notating the specific data points for reporting enrollment and total tuition and fe...
Responsible Contact Person(s): Sherika Charity, Director of Financial Aid Corrective Action Planned: Step 1: Review and update the FISAP Completion Documentation to clearly identify sources of data. This will include notating the specific data points for reporting enrollment and total tuition and fees from VCCS provided reports and reviewing the FISAP for accuracy before submitting. Estimated Completion Date: 8/30/2025
« 1 300 301 303 304 953 »