Corrective Action Plans

Browse how organizations respond to audit findings

Total CAPs
61,436
In database
Filtered Results
9,763
Matching current filters
Showing Page
47 of 391
25 per page

Filters

Clear
Active filters: § 200.303
FINDING 2025-003 CNC Eligibility Finding Subject: Child Nutrition Cluster - Eligibility Contact Person Responsible for Corrective Action: Patty Kelley Contact Phone Number and Email Address: 812-913-9622 pkelley@bhsc.school Views of Responsible Officials: We concur with the finding Description of Co...
FINDING 2025-003 CNC Eligibility Finding Subject: Child Nutrition Cluster - Eligibility Contact Person Responsible for Corrective Action: Patty Kelley Contact Phone Number and Email Address: 812-913-9622 pkelley@bhsc.school Views of Responsible Officials: We concur with the finding Description of Corrective Action Plan: The Direct Certification downloads will be done once a month by the Cafeteria Director. The Cafeteria Director will sign the report and forward it to the Treasurer for verification and a second signature. The Direct Certification reports will be kept at the central office. Anticipated Completion Date: This process will be in place by the end of the current fiscal year, June 30, 2026.
REFERENCE: 2025-101 CFDA NUMBER: 10.558 – CHILD AND ADULT CARE FOOD PROGRAM U.S. DEPARTMENT OF AGRICULTURE - FOOD AND NUTRITION - 2025 PASSED THROUGH ARIZONA STATE DEPARTMENT OF EDUCATION GRANT NUMBER 256AZ003N1199 CLIENT RESPONSE AND CORRECTIVE ACTION PLAN We concur with the condition. 1. Name of t...
REFERENCE: 2025-101 CFDA NUMBER: 10.558 – CHILD AND ADULT CARE FOOD PROGRAM U.S. DEPARTMENT OF AGRICULTURE - FOOD AND NUTRITION - 2025 PASSED THROUGH ARIZONA STATE DEPARTMENT OF EDUCATION GRANT NUMBER 256AZ003N1199 CLIENT RESPONSE AND CORRECTIVE ACTION PLAN We concur with the condition. 1. Name of the contact person responsible for corrective action: Claudia Cordova, Director 2. Corrective action planned: AAFDCP will continue to follow the menu reading policy of reading 100% of all menus/OERS before submitting the Claim to The ADE and of double checking each person’s work by exchanging menus/OERs to include checking for clerical errors and creditable food components. The person reviewing the menus/OERs will initial the form to indicate it has been reviewed. All visit forms will be checked by The Director, Claudia Cordova, Assistant Director Cathy Reagan and Bi-lingual Specialist Veronica Mendoza before entering the data into KidKare to ensure all information is complete and accurate. The initials of the person double checking the form will be added to the bottom of the visit form along with the date it was reviewed. 3. Anticipated completion date: Ongoing process already implemented
Corrective action plan: The CAPPS Financials team uses Pathlock to monitor and log privileged user activities. Pathlock maintains documentation of approvals and business justifications. Documentation of recurring privileged access reviews will be maintained as appropriate across all dedicated CAPPS ...
Corrective action plan: The CAPPS Financials team uses Pathlock to monitor and log privileged user activities. Pathlock maintains documentation of approvals and business justifications. Documentation of recurring privileged access reviews will be maintained as appropriate across all dedicated CAPPS Financial modules. IAM team will establish a documented process through which it will coordinate with the CAPPS Financial team to perform quarterly reviews of accounts and audit logs to strengthen privileged access provisioning. The review process will include documented approval, business justification, and periodic revalidation for all elevated roles in CAPPS Financial. Pathlock software is being used to manage single sign-on for granting privileged access to allowed users. With this software, the IAM team can grant access to a user, who would then login as themselves and then switch to the appropriate privileged role. Once the user switches to a privileged role, the Pathlock software maintains the audit log of user activity. Implementation date: February 27, 2026 Responsible persons: Daniel Kellogg, Deputy Chier Information Officer (DCIO), Infrastructure Services Leatha Marr, DCIO & Chief Product Officer, System Applications
Corrective action plan: Long Term Care Regulation will enhance existing internal controls to ensure timely completion and distribution of Form 2567 to the providers. Implementation date: March 31, 2026 Responsible person: Michelle Dionne-Vahalik, Associate Commissioner, Long Term Care Regulations
Corrective action plan: Long Term Care Regulation will enhance existing internal controls to ensure timely completion and distribution of Form 2567 to the providers. Implementation date: March 31, 2026 Responsible person: Michelle Dionne-Vahalik, Associate Commissioner, Long Term Care Regulations
Corrective action plan: HHS Information Security: • Has implemented a centralized governance process to ensure completion of all required biennial risk assessments. • Will establish and maintain oversight, validation, and escalation procedures for overdue assessments to ensure sustained adherence to...
Corrective action plan: HHS Information Security: • Has implemented a centralized governance process to ensure completion of all required biennial risk assessments. • Will establish and maintain oversight, validation, and escalation procedures for overdue assessments to ensure sustained adherence to federal and state requirements. • Will establish an inventory of systems to ensure information owners and custodians are assigned. • Will create an automated compliance dashboard to facilitate monthly reporting to executive leadership. • Will prioritize high-risk Medicaid systems, targeting completion within three months and achieving full compliance with Texas Administrative Code (TAC) 202 requirements within twelve months. The Deputy Chief Information Officers (DCIO) and Chief Product Officers for System Applications, Public Health Applications, and Texas Integrated Eligibility Redesign System (TIERS)/Medicaid Enterprise Systems (MES) will provide support and assistance to the program areas in creating Plan of Actions and Milestones and completing risk assessments for all systems provided in the executive report for their respective areas related to the audit. Implementation date: February 28, 2027 Responsible persons: Anil Koindala, Chief Information Security Officer Leatha Marr, DCIO and Chief Product Officer, System Applications Madhavi Koganti, DCIO and Chief Product Officer, Public Health Applications James Huang, DCIO and Chief Product Officer, TIERS/MES
Corrective action plan: FDCM/OI has developed a comprehensive action plan to modernize and increase our detection of fraud in the child care program. Part of this modernization will include increased and more “real-time” monitoring of Board collection efforts. FDCM/OI is partnering with our Informat...
Corrective action plan: FDCM/OI has developed a comprehensive action plan to modernize and increase our detection of fraud in the child care program. Part of this modernization will include increased and more “real-time” monitoring of Board collection efforts. FDCM/OI is partnering with our Information, Innovation, and Insight Division (I3) to develop new dashboards and reports based upon weekly uploaded PIRTS data. This will allow FDCM/OI to generate weekly reports of Board collection letter non-compliance. If a Board fails to issue collection letters in a timely fashion, FDCM/OI will send a report to the Board Executive Director notifying them of non-compliance. Boards are also now required to have a Fraud Point of Contact (POC) that will be FDCM/OI’s direct liaison with the Board for all fraud matters. Additionally, FDCM/OI is conducting weekly PIRTS trainings throughout February for Boards. Boards have been asked to submit up to 5 fact finders who will be responsible for fraud case entry and management. The Board POC is ultimately responsible for every case. FDCM/OI is also reviewing our collection letters as a part of this process and generating prosecution referrals for cases which meet our criteria. It is our belief this will underscore the seriousness of the collection letters and increase their effectiveness. Finally, FDCM/OI will ensure that all relevant controlling documents, e.g. a new Workforce Development Letter, and all previous guidance is updated with this information. Implementation date: February 27, 2026 Responsible person: Jason Stalinsky, Division Director, Division of Fraud Deterrence and Compliance Monitoring.
Corrective action plan: HHSC cannot commit to the specific designation of CAPPS-Financials as the improvement solution for FFATA reporting. However, HHSC continues to be engaged in long-term planning related to improving FFATA reporting. Implementation date: September 1, 2027 Responsible person: Ari...
Corrective action plan: HHSC cannot commit to the specific designation of CAPPS-Financials as the improvement solution for FFATA reporting. However, HHSC continues to be engaged in long-term planning related to improving FFATA reporting. Implementation date: September 1, 2027 Responsible person: Ariana Torres, Deputy Director, Federal Funds
Corrective action plan: The Office of Area Agencies on Aging (OAAA) will update the General Revenue allocation procedures and workbook to allocate general revenue to Area Agencies on Aging (AAAs) in proportion to the associated federal awards to ensure they are not supplanting non-federal funds rela...
Corrective action plan: The Office of Area Agencies on Aging (OAAA) will update the General Revenue allocation procedures and workbook to allocate general revenue to Area Agencies on Aging (AAAs) in proportion to the associated federal awards to ensure they are not supplanting non-federal funds related to supportive services and senior centers. OAAA will provide in-service training for the OAAA Budget Analyst and Financial Analysts on the revised procedures and workbook. OAAA will provide training for AAAs on the revised procedures and workbook for managing Older Americans Act funds, General Revenue, and associated regulations. Implementation date: September 30, 2026 Responsible person: Lori Conner, Manager, OAAA Fiscal and Contract Oversight
Corrective action plan: TANF/SEGIF: To ensure that correct UEIs are included on all Early Childhood Initiatives (ECI) contracts, the Early Childhood Initiatives (ECI) program has implemented a review system of the contracts and amendments prior to routing them through CAPPS FIN. The contract develop...
Corrective action plan: TANF/SEGIF: To ensure that correct UEIs are included on all Early Childhood Initiatives (ECI) contracts, the Early Childhood Initiatives (ECI) program has implemented a review system of the contracts and amendments prior to routing them through CAPPS FIN. The contract developer will create the document, and the assigned performance specialist will review the data included in the contract/amendment to ensure it is accurate before the contract is routed for approval. SUBG: Behavioral Health Services’ pass-through agreements effective September 1, 2026, will include 2 CFR §200.332 requirements. Implementation dates: TANF/SEGIF: September 1, 2025 SUBG: December 31, 2026 Responsible persons: TANF/SEGIF: Janene Roch, Manager, ECI Contracts and Finance SUBG: Roderick Swan, Associate Commissioner, Behavioral Health Services Operations
Corrective action plan: HHSC will run quarterly expenditure reports for this grant to monitor administrative earmarking thresholds. Implementation date: July 31, 2026 Responsible person: Roderick Swan, Associate Commissioner, Behavioral Health Services Operations
Corrective action plan: HHSC will run quarterly expenditure reports for this grant to monitor administrative earmarking thresholds. Implementation date: July 31, 2026 Responsible person: Roderick Swan, Associate Commissioner, Behavioral Health Services Operations
Corrective action plan: HHSC implemented a final review by all agencies who receive SSBG funding and all HHSC staff. In the future, the federal funds office will coordinate efforts with the Federal Reporting personnel to ensure the amounts noted on the ACF-196 report are consistent with the amount o...
Corrective action plan: HHSC implemented a final review by all agencies who receive SSBG funding and all HHSC staff. In the future, the federal funds office will coordinate efforts with the Federal Reporting personnel to ensure the amounts noted on the ACF-196 report are consistent with the amount on the Post Expenditure Report. Implementation date: March 30, 2026 Responsible person: Racheal Kane, Director, Federal Funds Office
Corrective action plan: ITS will: • Work with HR and Security to analyze and validate the size and scope of the late submission of access termination requests for separated employees. Communicate the analysis results and recommendations on or before May 1, 2026. • Work with the Information Security ...
Corrective action plan: ITS will: • Work with HR and Security to analyze and validate the size and scope of the late submission of access termination requests for separated employees. Communicate the analysis results and recommendations on or before May 1, 2026. • Work with the Information Security Office for continuation of periodic reconciliation of HR data and network accounts. Schedule for reconciliation to be established on or before May 1, 2026. • Work with Human Resources to establish a schedule of periodic reconciliation for HR data and case management application accounts. Schedule for reconciliation to be established on or before May 1, 2026. • Review existing business process for offboarding separated employees and provided recommendations to HR for training and communication for staff. Recommendations to be provided by May 1, 2026. • Determine what technology solution may be needed by August 31, 2026, with consideration of effectiveness of mitigation actions, as noted above. Implementation dates: See Corrective action plan Responsible person: Angie Lindemann, Deputy Chief Information Officer
Corrective action plan: Program staff will ensure that a formal review by the Team Lead and the Manager of Fiscal and Reporting is completed prior to submission. The Team Lead will initiate the process by obtaining the obligation amount from the LIHEAP Contract Specialist and entering the amount int...
Corrective action plan: Program staff will ensure that a formal review by the Team Lead and the Manager of Fiscal and Reporting is completed prior to submission. The Team Lead will initiate the process by obtaining the obligation amount from the LIHEAP Contract Specialist and entering the amount into the quarterly report. The Manager of Fiscal and Reporting will review and confirm the amount to be submitted. Implementation date: April 30, 2026 Responsible persons: Michael De Young, Director of Community Affairs Cathy Jung, Senior Manager of Finance and Reporting
Corrective action plan: The Department will enhance current procedures for the compilation and review of the Period 1 clearance pattern calculation in accordance with the Cash Management Improvement Act (CMIA) and as required in the Texas-State Agreement. The Manager of Accounting will use the State...
Corrective action plan: The Department will enhance current procedures for the compilation and review of the Period 1 clearance pattern calculation in accordance with the Cash Management Improvement Act (CMIA) and as required in the Texas-State Agreement. The Manager of Accounting will use the State Auditor Office’s template spreadsheet provided to agencies to calculate their annual Period 1 calculation and retain the worksheet as supporting documentation. The Director of Financial Administration will review the spreadsheet and calculation prior to CMIA certification. Implementation date: August 2026 Responsible persons: Jose Guevara, Director of Financial Administration Cristina Ortega, Manager of Accounting.
Corrective action plan: Vendor System Safeguards: TWC's I3 (Department of Analytics & Evaluation), IT (Information Technology), and WFA (Workforce Automation) resources will require our WorkInTexas.com vendor, Geographic Solutions Inc (GSI), to implement additional system safeguards to prevent the d...
Corrective action plan: Vendor System Safeguards: TWC's I3 (Department of Analytics & Evaluation), IT (Information Technology), and WFA (Workforce Automation) resources will require our WorkInTexas.com vendor, Geographic Solutions Inc (GSI), to implement additional system safeguards to prevent the duplication of hour entries when extracting data from the WIT system and creating files. TWC resources will maintain oversight of the implementation and ongoing effectiveness of these safeguards. Joint Anomaly Detection: TWC's I3 (Department of Analytics & Evaluation), IT (Information Technology), and WFA (Workforce Automation) resources will require our WorkInTexas.com vendor, Geographic Solutions Inc (GSI), to establish automated validation checks to identify anomalies such as duplicate lines, unexpected variances, and irregular hour totals prior to ingesting vendor files into TWC systems. TWC resources will maintain oversight of the implementation and ongoing effectiveness of these validation checks. TWC IT Data Reconciliation: TWC IT (Information Technology) will enhance supervisory review vendor procedures to reconcile data received from third-party vendors against source records, verifying completeness and accuracy before supplying to I3 (Department of Analytics & Evaluation) for inclusion in federal reporting. Implementation date: December 31, 2026 Responsible persons: Greg Waugh, Director, Workforce Automation (WFA), TWC Richard Yashewski, Director, IT Maintenance & Operations, TWC Geoffrey Miller, Director, Department of Analytics & Evaluation (I3), TWC
Corrective action plan: HHSC will conduct an end-to-end review of the sanctions process to identify and implement any needed changes to the business process, training, or system. Implementation date: May 31, 2026 Responsible person: Carrie Robertson, Manager, Strategy and Innovation–Business Integra...
Corrective action plan: HHSC will conduct an end-to-end review of the sanctions process to identify and implement any needed changes to the business process, training, or system. Implementation date: May 31, 2026 Responsible person: Carrie Robertson, Manager, Strategy and Innovation–Business Integration and Support
Corrective action plan: HHSC has taken steps to improve the consistency and reliability of financial reporting related to Maintenance of Effort (MOE) expenditures, specifically, amounts reported on the ACF 204, submitted by HHSC Budget and the ACF 196R, submitted by HHSC Federal Reporting (FR). To a...
Corrective action plan: HHSC has taken steps to improve the consistency and reliability of financial reporting related to Maintenance of Effort (MOE) expenditures, specifically, amounts reported on the ACF 204, submitted by HHSC Budget and the ACF 196R, submitted by HHSC Federal Reporting (FR). To address potential discrepancies and strengthen internal controls, HHSC Federal Reporting has implemented and documented a formal reconciliation process. This process involves the following key components: • Implementation and documentation of a formal reconciliation process that compares all MOE expenditures for HHSC, TEA, and TWC reported on the ACF 204 to those reported on the ACF 196R before report submission. The process outlines specific steps for data cross-referencing and validation to ensure completeness and accuracy. • Research, resolve, and correct any discrepancies identified during the reconciliation process before the reports are finalized and submitted for management review. • Reinforcement of management review and documentation of the reconciliation between the ACF-204 and ACF-196R will be incorporated into the approval process prior to report certification. Implementation date: February 28, 2026 Responsible person: Alan Flynn, Manager, Federal Reporting
Corrective action plan: THECB ITS will: • Develop and implement a standardized process for all user access reviews, including a required template which documents review date, reviewer identity, scope, results, and remediation actions. • Maintain all documentation in a centralized location on our ITS...
Corrective action plan: THECB ITS will: • Develop and implement a standardized process for all user access reviews, including a required template which documents review date, reviewer identity, scope, results, and remediation actions. • Maintain all documentation in a centralized location on our ITS SharePoint site. • Implement regular monitoring to ensure reviews are performed time, and the proper documentation is retained. • We will seek to automate processes where possible. Implementation date: July 1, 2026 Responsible person: Layla Young, Brian Nolte, Joel Anguiano
Corrective action plan: TCEQ will provide targeted training to program staff on federal procurement requirements, including the necessity of coordinating all purchases through the Procurements & Contracts Section and completing required vendor compliance checks. Training will emphasize procedures fo...
Corrective action plan: TCEQ will provide targeted training to program staff on federal procurement requirements, including the necessity of coordinating all purchases through the Procurements & Contracts Section and completing required vendor compliance checks. Training will emphasize procedures for sole source or limited source procurements and reinforce staff responsibilities under 2 CFR procurement and internal control standards. Regular refresher sessions and documented guidance will help ensure consistent understanding and adherence to required procurement practices across all program areas. Implementation date: May 31, 2026 Responsible person: Yolanda Davis, Deputy Director, Financial Administration Division
Corrective action plan: ITS Management will establish a formal, documented user access review program applicable to both privileged and non-privileged network users. Key actions include: 1. Policy Updates: Revise information technology access control policies and procedures to re-quire periodic (at ...
Corrective action plan: ITS Management will establish a formal, documented user access review program applicable to both privileged and non-privileged network users. Key actions include: 1. Policy Updates: Revise information technology access control policies and procedures to re-quire periodic (at least annual) reviews of all network user access. 2. Standardized Process and Documentation: Implement a consistent, documented review process and maintain records in a centralized repository to ensure accountability and auditability. 3. Monitoring and Oversight: Implement oversight procedures to track completion of access re-views and remediation of identified issues, with reporting to IT and information security leadership to support governance. Implementation dates: 1. Policy and procedure updates: Expected completion by April 30, 2026 2. Standardized process and repository implementation: Expected completion by May 31, 2026 3. First completed annual review under the revised process: Expected completion by June 30, 2026 Responsible persons: Tara Mitchell, Director of IT Operations Sean Peterson, Chief Information Officer
Corrective action plan: TWC will establish a new policy of 3 defined roles (preparation, review, and approval) and a standardized process for each role on each report. TWC will establish a log to capture the name and date of the staff completing each role for each report, and we will use the log to ...
Corrective action plan: TWC will establish a new policy of 3 defined roles (preparation, review, and approval) and a standardized process for each role on each report. TWC will establish a log to capture the name and date of the staff completing each role for each report, and we will use the log to confirm that no individual performs more than one role on a given report. For all staff with any participation in the ETA reporting function, TWC will have training on the new policy, procedures and log. Implementation date: June 30, 2026 Responsible person: Terri Warren, Unemployment Insurance Administration & Operational Support Department Director
Corrective action plan: A formalized process will be implemented, utilizing Standard Operating Procedures, to cover changes of hardware or software in relationship with network and infrastructure components. A change management tracking and approval system is under development that will be utilized ...
Corrective action plan: A formalized process will be implemented, utilizing Standard Operating Procedures, to cover changes of hardware or software in relationship with network and infrastructure components. A change management tracking and approval system is under development that will be utilized to track and provide audit logs of all network and infrastructure changes. Implementation date: August 31, 2026 Responsible person: Lars Hjaltman, CIO
Corrective action plan: • IT will coordinate with HR on strengthening the separation process, to include HR running separation reports quarterly and sending to IT to cross check. Will perform regular scheduled meetings to discuss the separation process/issues. • IT is testing automatic scripts that ...
Corrective action plan: • IT will coordinate with HR on strengthening the separation process, to include HR running separation reports quarterly and sending to IT to cross check. Will perform regular scheduled meetings to discuss the separation process/issues. • IT is testing automatic scripts that will aid in the process and will be implemented this year. • IT will document quarterly access reviews which are already done. • IT will work on enhancing automation and controls; Will utilize AI to assist. Implementation date: May 2026 Responsible person: Chris Bunton, CIO, Texas Department of Agriculture
Management Response: The University agrees with the finding. The identified issue was isolated and only impacted fall graduates. This issue was fully addressed when the university filed its fall 2025 enrollment reporting. The university has conducted an internal audit to identify students that were ...
Management Response: The University agrees with the finding. The identified issue was isolated and only impacted fall graduates. This issue was fully addressed when the university filed its fall 2025 enrollment reporting. The university has conducted an internal audit to identify students that were reported incorrectly and has manually updated files to ensure dates were properly reflected. At current state, internal monitoring and manual edits are made if discrepancies appear. The university has been in contact with PeopleSoft software related to the issue. Should the software issue not be resolved, the university plans to continue with manual edits to ensure proper reporting. Contact Person: Stacy Ramsey, University Registrar srramse@ilstu.edu Completion Date: December 2025
Information on the federal program: Subject: Special Education Cluster (IDEA) –Earmarking Federal Agency: Department of Education Federal Programs: Special Education Grants to States, Special Education Preschool Grants Assistance Listing Numbers: 84.027, 84.173 Federal Award Numbers and Years (or Ot...
Information on the federal program: Subject: Special Education Cluster (IDEA) –Earmarking Federal Agency: Department of Education Federal Programs: Special Education Grants to States, Special Education Preschool Grants Assistance Listing Numbers: 84.027, 84.173 Federal Award Numbers and Years (or Other Identifying Numbers): 22611-047-PN01, 22611-047-ARP, 23611-047-PN01, 22619-047-PN01, 22619-047-ARP, 23619-047-PN01 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Matching, Level of Effort, and Earmarking Audit Finding: Significant Deficiency, Other Matters Condition: An effective internal control system was not in place at the School Corporation in order to ensure compliance with requirements related to the grant agreement and the earmarking portion of the Matching, Level of Effort, Earmarking compliance requirement. Context: The School Corporation did not meet the earmarking requirements for the grants, which concluded during the audit period. Both the Special Education Grants to States and Special Education Preschool Grants required a proportionate share of their funding to be spent on non-public school students with disabilities. The 22611-047-PN01, 22611-047-ARP, 23611-047-PN01, 22619-047-PN01, 22619-047-ARP, and 23619-047-PN01 grant awards were fully expended during the audit period with minimum Non-Public Proportionate Share earmarking requirements of $27,189, $5,074, $26,124, $1,171, $453, and $1,929, respectively. There were not sufficient non-public school expenditures incurred to meet the non-public proportionate share requirement for any of the six grants. The non-public school expenditures fell short of the minimum requirement by $11,679, $3,176, $16,405, $1,171, $4, and $1,929, respectively. Views of Responsible Officials and Corrective Action Plan: Management agrees with the finding. The cooperative has developed a written procedure for documenting expenditures related to the proportionate share earmarking requirement at the School Corporation level to address this issue going forward. The School Corporation will maintain the proper documentation to support the Non-Public Proportionate Share earmarking requirement and validate the earmarking requirement is met at the end of the grant’s period of performance or once fully expended. Responsible Party and Timeline for Completion: The corrective action plan has been put into place for the 2025-26 school year. Tracy Albertson, Director of Finance, and Sarah Claton, Director of Cooperative School Services, will oversee the corrective action plan.
« 1 45 46 48 49 391 »