Corrective Action Plans

Browse how organizations respond to audit findings

Total CAPs
59,856
In database
Filtered Results
9,391
Matching current filters
Showing Page
8 of 376
25 per page

Filters

Clear
Active filters: § 200.303
Corrective Actions to Be Implemented: The organization is moving from MIP Fund Accounting to QuickBooks online Advanced which will remove the multi-step data entry process currently used for time capture and payroll processing. Simultaneously, we are implementing Hourtimesheet, a Defense Contract Au...
Corrective Actions to Be Implemented: The organization is moving from MIP Fund Accounting to QuickBooks online Advanced which will remove the multi-step data entry process currently used for time capture and payroll processing. Simultaneously, we are implementing Hourtimesheet, a Defense Contract Audit Agency (DCAA) compliant time tracking system which does not allow time entries outside of each employee assigned grant allocations. It has a native integration with Quickbooks and is the gold standard for government contract compliance. • QuickBooks Online Advanced anticipated completion: June 1, 2026 • Hourtimesheet anticipated completion: September 1, 2026 Responsible Parties: Brandi Senters, Finance Director, will be responsible for implementation, with oversight from the Executive Director, Erin Broussard.
Finding 2025-061 Epidemiology and Laboratory Capacity for Infectious Diseases (ELC), ALN 93.323 and Block Grants for Prevention and Treatment of Substance Abuse, ALN 93.959 Management Views MDHHS agrees with the finding. Planned Corrective Action MDHHS is actively pursuing the implementation of an A...
Finding 2025-061 Epidemiology and Laboratory Capacity for Infectious Diseases (ELC), ALN 93.323 and Block Grants for Prevention and Treatment of Substance Abuse, ALN 93.959 Management Views MDHHS agrees with the finding. Planned Corrective Action MDHHS is actively pursuing the implementation of an API for the submission of FFATA data to the federal system, SAM, to improve both timeliness and accuracy through automation. This API will connect EGrAMS with SAM, enabling backend communication between the systems and allowing SAM to automatically retrieve data directly from EGrAMS. To ensure accurate reporting until the API is established, MDHHS will continue reviewing validation errors when submitting web-based information to SAM and will work with the SAM federal helpline to report federal system issues and identify interim alternatives to submit the required data. Also, MDHHS implemented an enhancement in August 2025 that validates federal funding sources in EGrAMS against their effective dates, reducing coding errors and improving data reliability. In addition, the query used to obtain certain FFATA data elements was modified during fiscal year 2026 to improve accuracy of reporting. Anticipated Completion Date December 31, 2027 Responsible Individual(s) Matt Blackburn, MDHHS Jeanette Hensler, MDHHS Rebecca Jones, MDHHS
Finding 2025-004 Bridges Security Management and Access Controls Management Views MDHHS agrees with the finding. Planned Corrective Action For parts a., b., c., and d., MDHHS implemented the Database Security Application (DSA) on October 2, 2023, which includes documenting incompatible role exceptio...
Finding 2025-004 Bridges Security Management and Access Controls Management Views MDHHS agrees with the finding. Planned Corrective Action For parts a., b., c., and d., MDHHS implemented the Database Security Application (DSA) on October 2, 2023, which includes documenting incompatible role exception requests and user access request approvals, semi-annual review of privileged users, and annual review for all users. Security management and access control processes will continue to be a standing agenda item for ongoing quarterly training sessions with local office security coordinators (LOSC). For parts a., c., and d., the Access Management Section began implementing a process to conduct quarterly reconciliations of the DSA to the Bridges Integrated Automated Eligibility Determination System (Bridges) during March 2025. Due to the complexity of the reconciliations and time constraints, MDHHS requested the Bridges technical team to develop a consolidated Excel based report to add a level of automation to the process. The report is now available on an ad hoc basis, and the Access Management Section began utilizing it during April 2026 to conduct reviews and provide remediation with the LOSCs and end users. Full automation of the report remains in progress due to significant competing priorities and limited resources. For part b., MDHHS implemented the automated DSA periodic access review process (PAR) during January 2026 to review all users every 90 days, instead of the current 180 days for privileged users. MDHHS updated its policy to require initiation of the PAR in the DSA for all users every 90 days, without exception, to comply with State standards. For part e., MDHHS local office directors, district managers, or designees review a monthly sample of high-risk Bridges transactions to ensure documentation was properly maintained. Beginning September 2024, MDHHS Business Service Centers (BSC) implemented a monitoring process to ensure monthly reviews are completed by the local offices timely and that the documentation is properly maintained. To strengthen compliance, MDHHS will reinforce expectations through manager training and emphasize the requirement to maintain complete records and to sign and date all review reports within 30 days of the report run date. Additional training sessions will be repeated as needed to ensure consistent adherence to documentation and timeliness standards across all local offices. Anticipated Completion Date a., c., and d. Ongoing b. Completed e. September 30, 2026 Responsible Individual(s) a., b., c., and d. Tim Kwast, MDHHS e. Tim Kwast and Veronica Maxson, MDHHS
Finding 2025-003 Bridges Interface Controls Management Views DTMB agrees with the finding. Planned Corrective Action DTMB will establish a process to verify that the total number of processed, exception, and skipped records matches the number of records read from the data source. DTMB will investiga...
Finding 2025-003 Bridges Interface Controls Management Views DTMB agrees with the finding. Planned Corrective Action DTMB will establish a process to verify that the total number of processed, exception, and skipped records matches the number of records read from the data source. DTMB will investigate discrepancies identified through this validation process and implement appropriate corrective measures to resolve the issues. Anticipated Completion Date September 30, 2026 Responsible Individual(s) Nathan Buckwalter, DTMB
Finding 2025-002 DTMB, IT General Controls Management Views The Department of Technology, Management, and Budget (DTMB) agrees it did not perform the annual review of privileged accounts for the operating system servers. As stated in the finding, DTMB performed the recertification process after the ...
Finding 2025-002 DTMB, IT General Controls Management Views The Department of Technology, Management, and Budget (DTMB) agrees it did not perform the annual review of privileged accounts for the operating system servers. As stated in the finding, DTMB performed the recertification process after the issue was brought to its attention. Planned Corrective Action DTMB performed its user access recertification processes in November 2025. Anticipated Completion Date Completed Responsible Individual(s) Manny Rosales, DTMB
Finding 2025-006 ADP Security Program Management Views MDHHS and DTMB agree with the finding. Planned Corrective Action For 2 of the 3 systems cited, the Authority to Operate (ATO) was successfully re-established on July 8, 2025, and October 10, 2025, respectively. For the remaining system, MDHHS an...
Finding 2025-006 ADP Security Program Management Views MDHHS and DTMB agree with the finding. Planned Corrective Action For 2 of the 3 systems cited, the Authority to Operate (ATO) was successfully re-established on July 8, 2025, and October 10, 2025, respectively. For the remaining system, MDHHS and DTMB will complete a comprehensive update to the System Security Plan, incorporate all missing control assessments into the risk analysis, and implement the ATO by August 30, 2026. Anticipated Completion Date August 30, 2026 Responsible Individual(s) Nathan Buckwalter, DTMB Heather Frick, DTMB Veronica Maxson, MDHHS Jim Bowen, MDHHS Kasi Hunziger, MDHHS Lyndia Deromedi, MDHHS
Finding 2025-010 MDE, Change Management Process Management Views MDE partially agrees with the finding. MDE agrees that testing results were not fully documented. However, MDE does not agree that post implementation validation could be performed. The scan-vulnerability process could not be performed...
Finding 2025-010 MDE, Change Management Process Management Views MDE partially agrees with the finding. MDE agrees that testing results were not fully documented. However, MDE does not agree that post implementation validation could be performed. The scan-vulnerability process could not be performed in the production environment in this instance without significantly impacting system performance for users, making post implementation validation infeasible. Planned Corrective Action MDE management will review the testing documentation maintained in DevOps for all tickets classified as tasks and associated with change management activities and deployments and will remind staff of the required documentation standards for all DevOps tickets linked to a deployment. Additionally, MDE will evaluate whether an alternative method of validating the scan-vulnerability process in production is feasible. If no alternative method is identified, MDE will document that post implementation validation cannot be performed due to system constraints. Anticipated Completion Date December 31, 2026 Responsible Individual(s) Monica Butler, MDE
Finding 2025-009 MDE, Security Management and Access Controls Management Views MDE agrees with the finding. Planned Corrective Action For part a., management will review the exceptions with the team responsible for processing security forms to reinforce appropriate review and processing. MDE will al...
Finding 2025-009 MDE, Security Management and Access Controls Management Views MDE agrees with the finding. Planned Corrective Action For part a., management will review the exceptions with the team responsible for processing security forms to reinforce appropriate review and processing. MDE will also implement an automated security access request process, which will eliminate any human error as a result of processing forms. For part b., management will refine the NexSys annual recertification process to reduce errors. NexSys staff will improve internal user list reviews and confirm completeness during the upcoming recertification cycle prior to management’s final review. MDE is currently developing an automated process to handle the annual recertification of the Grant Electronic Monitoring System/Michigan Administrative Review System (GEMS/MARS) users and anticipates implementation in September 2026. For part c., MDE updated the procedure for disabling accounts in April 2026 to strengthen and clarify the process to ensure MDE disables inactive user accounts after 18 months. Anticipated Completion Date a. May 2027 b. NexSys: October 2026 GEMS/MARS: September 2026 c. Completed Responsible Individual(s) Monica Butler, MDE Joshua Long, MDE Drew Finkbeiner, MDE
Finding 2025-060 Coronavirus Capital Projects Fund, ALN 21.029 Management Views LEO agrees with the finding. Planned Corrective Action The LEO Finance Division and the LEO Grants Division have identified the deficiencies that led to the audit finding. LEO will correct the internal FFATA reporting pr...
Finding 2025-060 Coronavirus Capital Projects Fund, ALN 21.029 Management Views LEO agrees with the finding. Planned Corrective Action The LEO Finance Division and the LEO Grants Division have identified the deficiencies that led to the audit finding. LEO will correct the internal FFATA reporting process to ensure that new and amended subaward contract information is received by the LEO Finance Division in a timely manner and in accordance with FFATA requirements. LEO will utilize the EGrAMS vendor to update software functionality that will generate an email notification to the LEO Finance Division when a grant agreement is finalized or amended. This notification will ensure communication with the LEO Finance Division occurs in a timely manner and in accordance with FFATA requirements. Anticipated Completion Date June 30, 2026 Responsible Individual(s) Jennifer Duffey, LEO Heidi Parker, LEO
Finding 2025-029 Coronavirus State and Local Fiscal Recovery Funds, ALN 21.027 - MiGrants Security Management and Access Controls Management Views The Department of Natural Resources (DNR) agrees with the finding. Planned Corrective Action DNR recognizes the importance of maintaining strong security...
Finding 2025-029 Coronavirus State and Local Fiscal Recovery Funds, ALN 21.027 - MiGrants Security Management and Access Controls Management Views The Department of Natural Resources (DNR) agrees with the finding. Planned Corrective Action DNR recognizes the importance of maintaining strong security and access controls for the MiGrants system. While DNR has updated many internal processes to align with revised SOM technical standards, additional actions are needed to further strengthen its controls and ensure comprehensive documentation. For part a., each DNR division administrator will maintain thorough documentation of all internal roles assigned related to MiGrants access and verify adequate justification is provided for each role assigned. Each division administrator will be responsible for creating a procedure that identifies the process that captures appropriate approval information for the internal roles assigned by their division. The system administrator will establish a shared repository in a centralized location where the information is stored. For part b., DNR will implement a formal recertification review for all MiGrants users annually, ensuring that supporting documentation is complete and properly retained. For part c., DNR received an exception in June 2026 from the DTMB Technical Review Board to SOM Technical Standard 1340.00.020.01 (Access Control Standard) that extends the requirement for disabling inactive user accounts from 60 days to 365 days. Anticipated Completion Date a. February 28, 2027 b. December 31, 2026 c. Completed Responsible Individual(s) Leah Babcock, DNR Bobbi Audette, DNR Kerry Grey, DNR
Finding 2025-027 Coronavirus State and Local Fiscal Recovery Funds, ALN 21.027 - Salesforce Security Management and Access Controls Management Views MSF agrees that Salesforce was not written as an exception in the identified policy but disagrees that there is a control deficiency. MSF maintains eff...
Finding 2025-027 Coronavirus State and Local Fiscal Recovery Funds, ALN 21.027 - Salesforce Security Management and Access Controls Management Views MSF agrees that Salesforce was not written as an exception in the identified policy but disagrees that there is a control deficiency. MSF maintains effective controls within its control environment that effectively mitigate risks associated with exempting Salesforce from the identified policy and provide reasonable assurance MSF is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. Planned Corrective Action Based on the factors that led MSF to exempt Salesforce from SECU.01.020.01 (Access Control Standard), including risk assessments and MSF’s existing control environment, Salesforce will be included in the policy as a written exception. Anticipated Completion Date September 30, 2026 Responsible Individual(s) Alex Fox, MSF Ian McCorvie, MSF Calvin Myers, MSF William Chaffee, MSF
Finding 2025-026 Coronavirus State and Local Fiscal Recovery Funds, ALN 21.027 - Insufficient Respite Payment Controls Management Views MDHHS agrees with the finding. Planned Corrective Action MDHHS implemented a post payment review process for the final respite payments issued through the Medical S...
Finding 2025-026 Coronavirus State and Local Fiscal Recovery Funds, ALN 21.027 - Insufficient Respite Payment Controls Management Views MDHHS agrees with the finding. Planned Corrective Action MDHHS implemented a post payment review process for the final respite payments issued through the Medical Services Administration Manual Payment System during fiscal year 2025 and finalized the review during fiscal year 2026, noting no improper payments. As all respite payments concluded at the end of fiscal year 2025, this review is no longer applicable moving forward. Anticipated Completion Date Completed Responsible Individual(s) Crystal Kline, MDHHS
Finding 2025-025 Coronavirus State and Local Fiscal Recovery Funds, ALN 21.027 - PTMS Security Management and Access Controls Management Views MDOT agrees that security management and access controls should be fully established for the Public Transportation Management System (PTMS). Planned Correcti...
Finding 2025-025 Coronavirus State and Local Fiscal Recovery Funds, ALN 21.027 - PTMS Security Management and Access Controls Management Views MDOT agrees that security management and access controls should be fully established for the Public Transportation Management System (PTMS). Planned Corrective Action Because PTMS is a legacy system that is being retired, MDOT will not re-create historical user data that was deleted due to a system limitation. Rather, MDOT EIM and the MDOT Office of Passenger Transportation (OPT) will collaborate and provide oversight to ensure that the new system, the Public Transportation Information Management System (PTIMS), which is scheduled for full implementation August 31, 2026, has fully established security management and access controls and that there is pertinent documentation regarding users’ roles. Also, EIM and OPT will continue to ensure that PTMS, and PTIMS after its implementation, user access is reviewed at least annually in accordance with SOM Technical Standard 1340.00.040.01 (Audit and Accountability Standard). Under the existing process, the designated system security administrators obtain, verify, and document the written approval for all identified users, and access is modified/removed timely and as appropriate based on responses received or removed when no response is received. Anticipated Completion Date September 2026 Responsible Individual(s) Sandy Lovell, MDOT Gina Huhn, MDOT Jean Ruestman, MDOT Kyle Nelson, MDOT Andy Esch, MDOT
Finding 2025-024 Coronavirus State and Local Fiscal Recovery Funds, ALN 21.027 - MiSSG Security Management and Access Controls Management Views MiLEAP agrees with the finding. Planned Corrective Action For part a., for the exceptions noted in the finding, MiLEAP had the contractors complete the acce...
Finding 2025-024 Coronavirus State and Local Fiscal Recovery Funds, ALN 21.027 - MiSSG Security Management and Access Controls Management Views MiLEAP agrees with the finding. Planned Corrective Action For part a., for the exceptions noted in the finding, MiLEAP had the contractors complete the access forms and has approved their access. MiLEAP also updated its procedures to ensure that contractors complete the Michigan Student Aid Scholarships and Grants (MiSSG) access forms before access is granted to the system. For part b., MiLEAP updated its procedures to ensure that it maintains sufficient documentation of its recertification review of internal users. Anticipated Completion Date Completed Responsible Individual(s) Diann Cosme, MiLEAP
Finding 2025-023 Coronavirus State and Local Fiscal Recovery Funds, ALN 21.027 - EGrAMS Security Management and Access Controls Management Views LEO agrees with the finding. Planned Corrective Action For part a., LEO has a process to maintain documentation and support for internal users. For externa...
Finding 2025-023 Coronavirus State and Local Fiscal Recovery Funds, ALN 21.027 - EGrAMS Security Management and Access Controls Management Views LEO agrees with the finding. Planned Corrective Action For part a., LEO has a process to maintain documentation and support for internal users. For external users, LEO will ask the vendor to upgrade the system so it logs every external user activation, including the approving LEO staff member’s name and the timestamp, rather than overwriting previous external user activation records. For part b., LEO established a user reconciliation process in March 2026 that will be managed by the LEO Grants Division. For part c., LEO will change its policy requiring the disablement of user accounts inactive for over 60 days to comply with SOM Technical Standard 1340.00.020.01 (Access Control Standard). LEO will work with DTMB to complete a system security plan so user accounts will be automatically deactivated after 60 days of inactivity. LEO will also explore options to address the issue of EGrAMS users who typically only access the system every 90 days to complete required system reports. Anticipated Completion Date a. December 31, 2026 b. Completed c. December 31, 2026 Responsible Individual(s) Jason Hamblin, LEO
Finding 2025-022 Coronavirus State and Local Fiscal Recovery Funds, ALN 21.027 - Concur Security Management and Access Controls Management Views The Michigan Strategic Fund (MSF) agrees that Concur was not written as an exception in the identified policy but disagrees that there is a control deficie...
Finding 2025-022 Coronavirus State and Local Fiscal Recovery Funds, ALN 21.027 - Concur Security Management and Access Controls Management Views The Michigan Strategic Fund (MSF) agrees that Concur was not written as an exception in the identified policy but disagrees that there is a control deficiency. MSF maintains effective controls within its control environment that effectively mitigate risks associated with exempting Concur from the identified policy and provide reasonable assurance MSF is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. Planned Corrective Action Based on the factors that led MSF to exempt Concur from SECU.01.020.01 (Access Control Standard), including risk assessments and MSF’s existing control environment, Concur will be included in the policy as a written exception. Anticipated Completion Date September 30, 2026 Responsible Individual(s) Alex Fox, MSF Ian McCorvie, MSF Calvin Myers, MSF William Chaffee, MSF
Finding 2025-021 Coronavirus State and Local Fiscal Recovery Funds, ALN 21.027 - AASHTOWare Security Management and Access Controls Management Views MDOT agrees it did not fully establish effective security management and access controls over the American Association of State Highway and Transportat...
Finding 2025-021 Coronavirus State and Local Fiscal Recovery Funds, ALN 21.027 - AASHTOWare Security Management and Access Controls Management Views MDOT agrees it did not fully establish effective security management and access controls over the American Association of State Highway and Transportation Officials software (AASHTOWare) users. Planned Corrective Action For part a., the MDOT Office of Enterprise Information Management (EIM), Bureau of Field Services-Construction Field Services Division, and Bureau of Development-Design Division will collaborate and provide oversight to ensure that internal user access for AASHTOWare is reviewed at least annually. MDOT will implement an improved process, which will be facilitated by the designated system security administrators, to ensure an internal user review at least annually. For part b., MDOT worked with DTMB in May 2026 to correct and enhance the auto-disabler function of the AASHTOWare program. In addition, MDOT will continue to monitor this functionality as part of its improved access control process to ensure users who have not accessed AASHTOWare within 365 days for internal user accounts and 18 months for external user accounts are disabled timely. Anticipated Completion Date a. September 30, 2026 b. Completed Responsible Individual(s) Mark Shulick, MDOT Dan Burns, MDOT Kristin Schuster, MDOT Dee Parker, MDOT Lindsey Renner, MDOT Jason Gutting, MDOT Kyle Nelson, MDOT Andy Esch, MDOT
Finding 2025-059 Airport Improvement Program, Infrastructure Investment and Jobs Act Programs, and COVID-19 Airports Programs, ALN 20.106 Management Views MDOT agrees that it did not ensure revenues and program income generated by non-commercial airports were expended for airport capital or operatin...
Finding 2025-059 Airport Improvement Program, Infrastructure Investment and Jobs Act Programs, and COVID-19 Airports Programs, ALN 20.106 Management Views MDOT agrees that it did not ensure revenues and program income generated by non-commercial airports were expended for airport capital or operating costs, the local airport system, or other local facilities. Planned Corrective Action MDOT will review existing procedures, including the MDOT Office of Aeronautics Project Manager/Engineering Manual and block grant conditions, to assess whether updates are needed and if resources will be prioritized to help ensure monitoring and oversight efforts are performed relating to revenue and program income requirements. Anticipated Completion Date September 30, 2026 Responsible Individual(s) Bryan Budds, MDOT
Finding 2025-058 Airport Improvement Program, Infrastructure Investment and Jobs Act Programs, and COVID-19 Airports Programs, ALN 20.106 Management Views MDOT agrees that it did not ensure weekly certified payrolls were obtained from contractors. Planned Corrective Action MDOT will provide training...
Finding 2025-058 Airport Improvement Program, Infrastructure Investment and Jobs Act Programs, and COVID-19 Airports Programs, ALN 20.106 Management Views MDOT agrees that it did not ensure weekly certified payrolls were obtained from contractors. Planned Corrective Action MDOT will provide training and guidance to pertinent staff to help ensure contract compliance and that weekly certified payrolls are obtained from contractors. In addition, MDOT will review existing procedures to assess whether updates are needed. Anticipated Completion Date September 30, 2026 Responsible Individual(s) Bryan Budds, MDOT
Finding 2025-057 Airport Improvement Program, Infrastructure Investment and Jobs Act Programs, and COVID-19 Airports Programs, ALN 20.106 Management Views MDOT agrees that policies and procedures should be implemented to ensure that equipment and real property purchased with federal funds is properl...
Finding 2025-057 Airport Improvement Program, Infrastructure Investment and Jobs Act Programs, and COVID-19 Airports Programs, ALN 20.106 Management Views MDOT agrees that policies and procedures should be implemented to ensure that equipment and real property purchased with federal funds is properly tracked, recorded, and safeguarded. Planned Corrective Action MDOT will work with the Federal Aviation Administration to address variances between the Uniform Guidance requirements and program guidance so that policies and procedures can be updated as necessary. Anticipated Completion Date September 30, 2026 Responsible Individual(s) Bryan Budds, MDOT
Finding 2025-056 WIOA Cluster, ALN 17.258, 17.259, and 17.278 Management Views LEO agrees with the finding. LEO management recognizes the importance of timely and accurate FFATA reporting and acknowledges that internal processes can be strengthened to better support reporting consistency, particular...
Finding 2025-056 WIOA Cluster, ALN 17.258, 17.259, and 17.278 Management Views LEO agrees with the finding. LEO management recognizes the importance of timely and accurate FFATA reporting and acknowledges that internal processes can be strengthened to better support reporting consistency, particularly during high-volume periods such as quarter-end. LEO remains committed to compliance and continuous improvement. Planned Corrective Action LEO will improve existing FFATA reporting processes by reinforcing internal timelines, clarifying staff responsibilities, and implementing an additional review step prior to submission to help ensure subaward information is reported timely and accurately. Management will train appropriate staff responsible for FFATA reporting to strengthen understanding of reporting requirements, deadlines, and review expectations. These improvements are intended to enhance process consistency, improve communication, and reduce the likelihood of future timing or minor reporting discrepancies. LEO will enhance documented procedures that outline specific FFATA reporting processes related to the Workforce Innovation and Opportunity Act (WIOA). Anticipated Completion Date September 30, 2026 Responsible Individual(s) Arica Johnson, LEO
Finding 2025-002: Clean Water State Revolving Fund - Suspension and Debarment U.S. Environmental Protection Agency, Passed through Pennsylvania Infrastructure Investment Authority (PENNVEST) - Assistance Using Number 66.458 Questioned Costs: None Condition: The Township did not follow internal contr...
Finding 2025-002: Clean Water State Revolving Fund - Suspension and Debarment U.S. Environmental Protection Agency, Passed through Pennsylvania Infrastructure Investment Authority (PENNVEST) - Assistance Using Number 66.458 Questioned Costs: None Condition: The Township did not follow internal control procedures designed to ensure compliance with suspension and debarment requirertients for covered contracts. During our testing of procurement transactions subject to suspension and debarment requirements, we noted that the Township did not retain documentation demonstrating that it had reviewed the System for Award Management (SAM.gov) exclusion records prior to entering into contractual agreements. Specifically, there was no evidence that a SAM.gov printout was reviewed or approved to verify that vendors were not suspended or debarred at the time of contract execution. In conjunction with the audit, we reviewed the SAM Exclusions for all transactions in our sample and we noted that no transactions were with entities that were suspended or debarred. Action: The Township will add suspension and debarment to all agreements. For the agreements that have been administered, the Township will review SAM.gov to ensure the client is not in the system. This will take effect immediately. If the United States Environmental Protection Agency has questions regarding this plan, please contact Mary Soroka at 724-776-4806 x1108.
Finding 2025-001 Federal Grantor: United States Department of Health and Human Services Planned Corrective Actions: Responsible Official – Dawn Ksepka, VP of Finance and System Controller Anticipated completion date – June 30, 2026 Management agrees with the finding. Remediation: Fairview has correc...
Finding 2025-001 Federal Grantor: United States Department of Health and Human Services Planned Corrective Actions: Responsible Official – Dawn Ksepka, VP of Finance and System Controller Anticipated completion date – June 30, 2026 Management agrees with the finding. Remediation: Fairview has corrected the payroll reimbursement request for the inaccurate payroll charges identified in the finding. To prevent recurrence, Fairview will enhance controls over payroll review processes to ensure accuracy prior to submission. These enhancements include reinforcing review expectations with project directors and including detailed review procedures for validating pay rate and wage calculations prior to reimbursement submissions. Management believes these actions will improve the accuracy of payroll charges and ensure compliance with federal program requirements.
Finding 2025-002 Federal Agency Name: U.S. Department of Treasury Program Name: Coronavirus State and Local Fiscal Recovery Funds FFALN # 21.027 Finding Summary: Eide Bailly LLP prepared our single audit for Federal Coronavirus State and Local Fiscal Recovery Funds where the Town is a subrecipient t...
Finding 2025-002 Federal Agency Name: U.S. Department of Treasury Program Name: Coronavirus State and Local Fiscal Recovery Funds FFALN # 21.027 Finding Summary: Eide Bailly LLP prepared our single audit for Federal Coronavirus State and Local Fiscal Recovery Funds where the Town is a subrecipient to Douglas County who is the recipient of the funds. Eide Bailly LLP identified that the Town did not have documented or consistently applied internal controls to ensure compliance with the County’s subrecipient guidance requiring the submission of formal special reports for ALN 21.027. Responsible Individuals: Mark Henderson, Assistant Director of Castle Rock Water Corrective Action Plan: Staff will complete quarterly reports including project progress and estimated project infrastructure costs. The reports will be reviewed by management prior to submission to the recipient of the Federal Funds (Douglas County). Anticipated Completion Date: Ongoing during the period that the Town is a subrecipient of these funds for the project.
Federal Program: Consolidated Health Centers Grant Assistance Listing No. 93.224 & 93.527 Recommendation: Our auditors recommend the Organization to review internal controls in regards to the approval of federal fund drawdown requests. Explanation of disagreement with audit finding: There is no disa...
Federal Program: Consolidated Health Centers Grant Assistance Listing No. 93.224 & 93.527 Recommendation: Our auditors recommend the Organization to review internal controls in regards to the approval of federal fund drawdown requests. Explanation of disagreement with audit finding: There is no disagreement with the audit finding. Action taken in response to finding: The Organization is in agreement with finding. The control issue was due to turnover in finance staff during fiscal year 2025. Under the direction of the Organization’s new CFO, the following revised procedures for cash management have been implemented for fiscal year 2026: • Payroll Documentation: A staff accountant or the controller will compile payroll expense details along with supporting documentation for each drawdown. • Review and Approval: This documentation is submitted to the CFO for review prior to any fund transfer. • Drawdown Execution: Upon approval, the CFO will initiate the drawdown from PMS. • Frequency: Drawdowns are processed on a biweekly basis and reflect expenses from the preceding payroll cycle. Upon completion of the drawdown, the CFO will save a copy of the drawdown request to the internal drive. • This drawdown receipt is reviewed by a second staff member, either the controller or senior accountant. • Drawdowns are also reviewed during monthly bank reconciliations.
« 1 6 7 9 10 376 »