Corrective Action Plans

Browse how organizations respond to audit findings

Total CAPs
56,350
In database
Filtered Results
53,365
Matching current filters
Showing Page
681 of 2135
25 per page

Filters

Clear
Responsible Contact Person(s): Angela Morse, Director of Benefit Programs Kavansa Gardner, IT Manager Corrective Action Planned: DSS will perform and document a conflicting access review for the management system to identify the combinations of roles that could pose separation of duties conflicts an...
Responsible Contact Person(s): Angela Morse, Director of Benefit Programs Kavansa Gardner, IT Manager Corrective Action Planned: DSS will perform and document a conflicting access review for the management system to identify the combinations of roles that could pose separation of duties conflicts and ensure compensating controls are in place to mitigate risks arising from those conflicts. Additionally, DSS will work with the vendor to update the role-based security access documentation to reflect all system changes from prior case management system related releases when there are proposed changes to the roles matrix. Estimated Completion Date: 12/31/2025
Responsible Contact Person(s): Barry Davis, Chief Information Security Officer and Director of Information Security & Risk Management Kevin Platea, Chief Information Officer Corrective Action Planned: This finding was marked as FOIA Exempt (FOIAE) and as a result, the State Comptroller has determine...
Responsible Contact Person(s): Barry Davis, Chief Information Security Officer and Director of Information Security & Risk Management Kevin Platea, Chief Information Officer Corrective Action Planned: This finding was marked as FOIA Exempt (FOIAE) and as a result, the State Comptroller has determined that the resulting corrective actions are FOIAE under §2.2-3705.2 (9.) of the Code of Virginia. Federal awarding agencies and pass-through entities, please see the Appendix titled “Applicable Management Contacts for Findings and Questioned Costs” to request the corrective action planned from the applicable entity. Estimated Completion Date: 12/31/2026
Responsible Contact Person(s): Kevin Platea, Chief Information Officer Dwayne Sneade, Director of Cybersecurity Corrective Action Planned: This finding was marked as FOIA Exempt (FOIAE) and as a result, the State Comptroller has determined that the resulting corrective actions are FOIAE under §2.2-3...
Responsible Contact Person(s): Kevin Platea, Chief Information Officer Dwayne Sneade, Director of Cybersecurity Corrective Action Planned: This finding was marked as FOIA Exempt (FOIAE) and as a result, the State Comptroller has determined that the resulting corrective actions are FOIAE under §2.2-3705.2 (9.) of the Code of Virginia. Federal awarding agencies and pass-through entities, please see the Appendix titled “Applicable Management Contacts for Findings and Questioned Costs” to request the corrective action planned from the applicable entity. Estimated Completion Date: 12/31/2025
Responsible Contact Person(s): Barry Davis, Chief Information Security Officer and Director of Information Security & Risk Management John Vosper, Assistant Director of Information Security & Risk Management Sam Owusu, IT Risk Manager of Information Security & Risk Management Corrective Action Plann...
Responsible Contact Person(s): Barry Davis, Chief Information Security Officer and Director of Information Security & Risk Management John Vosper, Assistant Director of Information Security & Risk Management Sam Owusu, IT Risk Manager of Information Security & Risk Management Corrective Action Planned: This finding was marked as FOIA Exempt (FOIAE) and as a result, the State Comptroller has determined that the resulting corrective actions are FOIAE under §2.2-3705.2 (9.) of the Code of Virginia. Federal awarding agencies and pass-through entities, please see the Appendix titled “Applicable Management Contacts for Findings and Questioned Costs” to request the corrective action planned from the applicable entity. Estimated Completion Date: 12/31/2026
Responsible Contact Person(s): Mike Jones, Chief Information Officer Corrective Action Planned: This finding was marked as FOIA Exempt (FOIAE) and as a result, the State Comptroller has determined that the resulting corrective actions are FOIAE under §2.2-3705.2 (9.) of the Code of Virginia. Federa...
Responsible Contact Person(s): Mike Jones, Chief Information Officer Corrective Action Planned: This finding was marked as FOIA Exempt (FOIAE) and as a result, the State Comptroller has determined that the resulting corrective actions are FOIAE under §2.2-3705.2 (9.) of the Code of Virginia. Federal awarding agencies and pass-through entities, please see the Appendix titled “Applicable Management Contacts for Findings and Questioned Costs” to request the corrective action planned from the applicable entity. Estimated Completion Date: 4/30/2025
Responsible Contact Person(s): Steve Hanoka, Information Security Officer Corrective Action Planned: 1. The requirements in the IT Security Governance or general requirements in SEC 530 are going to be addressed as part of the IT Security Planning and IT Security Program Management Policies and Pr...
Responsible Contact Person(s): Steve Hanoka, Information Security Officer Corrective Action Planned: 1. The requirements in the IT Security Governance or general requirements in SEC 530 are going to be addressed as part of the IT Security Planning and IT Security Program Management Policies and Procedures which are targeted to be complete by February 28, 2025. In addition, as part of this effort DMAS will publicize and communicate to system owners those control families which will have general / organizational procedures and which will require system specific procedures. 2. Access Management policies and procedures are in place. As part of annual SSP reviews DMAS is now verifying compliance or issues found 3. All SSPs are current and under SEC530 4. Incident Response Policies and Procedures exist 5. Vulnerability Management policies and procedures exist. These include scanning for both vulnerabilities and baseline configuration. They are being tracked according to SEC530 resolution standards. Goal is to ensure that all vulnerabilities are remediated within the SLA or have approved exceptions by May 30, 2025. In addition, DMAS has gained guidance from VITA on acceptable alternatives to penetration testing and are tracking completion. 6. Comprehensive third-party Management procedures are being developed and will be implemented by March 31, 2025. 7. Security Training is up to date and compliant Estimated Completion Date: 5/31/2025
Responsible Contact Person(s): Steve Hanoka, Information Security Officer Corrective Action Planned: Third-party Management that will cover ensuring all deliverables required are part of a procedure and work instruction. In addition, to specifically address the points in the finding, ISO will ensure...
Responsible Contact Person(s): Steve Hanoka, Information Security Officer Corrective Action Planned: Third-party Management that will cover ensuring all deliverables required are part of a procedure and work instruction. In addition, to specifically address the points in the finding, ISO will ensure that the work instructions cover obtaining a confirmation on the geographic location of sensitive data monthly and vulnerability scan results at least every 90 days.  During this procedure implementation, ISO will also work to specifically obtain these deliverables from the vendor in question.  Estimated Completion Date: 3/31/2025
Responsible Contact Person(s): Mike Jones, Chief Information Officer Corrective Action Planned: Language has been added to the Conduent contract renewal for option years 1 and 2 to require the SOC 1 Type II. The renewal is in the process of being reviewed and executed to go into effect July 1, 2025...
Responsible Contact Person(s): Mike Jones, Chief Information Officer Corrective Action Planned: Language has been added to the Conduent contract renewal for option years 1 and 2 to require the SOC 1 Type II. The renewal is in the process of being reviewed and executed to go into effect July 1, 2025. Language added to contract renewal: Contractor Internal Controls Reports The Contractor shall provide the Department, at a minimum; annual, unredacted reports from its independent external auditor on the effectiveness of the Contractor’s internal controls conducted in accordance with the AICPA Statement on Standards for Attestation Engagements. If the reports disclose deficiencies in internal controls, the Contractor shall include management’s corrective action plans to remediate the deficiency. The Contractor shall provide the following reports: · SOC 1 Type 2 Report that reports on the controls at the service organization which are relevant to the user entities’ internal control over financial reporting · SOC 2 Type 2 Report covering all five Trust Services Criteria (Security, Availability, Processing Integrity, Privacy and Confidentiality) The contractor shall provide the Department with these internal control reports within 30 days of the report’s issue date. Reports shall cover a period of 12 months beginning from the end date of the prior audit period with the first report covering a period of 12 months from the execution date of this contract. The contractor shall provide unredacted SOC 1 Type 2 and/or SOC 2 Type 2 reports as described above for any subservice organizations which provide a service to the Contractor that may impact the Department’s financial, program operations, or data security as determined by the Department. Estimated Completion Date: 7/1/2026
Responsible Contact Person(s): Angela Morse, Director of Benefit Programs Diana Clark, Assistant Director of Division of Benefit Programs Frank Smith, Associate Director of Benefit Programs Mark Golden, Economic Assistance and Employment Manager - Division of Benefit Programs Corrective Action Plan...
Responsible Contact Person(s): Angela Morse, Director of Benefit Programs Diana Clark, Assistant Director of Division of Benefit Programs Frank Smith, Associate Director of Benefit Programs Mark Golden, Economic Assistance and Employment Manager - Division of Benefit Programs Corrective Action Planned: DSS will work to provide additional training to local agency eligibility workers on how to properly determine and document eligibility determinations in the case management system. Additionally, DSS will consider monitoring local agency eligibility worker’s use of manual overrides to confirm that they properly document eligibility determinations in the case management system. Estimated Completion Date: 12/31/2025
View Audit 345214 Questioned Costs: $1
Responsible Contact Person(s): Angela Morse, Director of Benefit Programs Frank Smith, Associate Director of Benefit Programs Corrective Action Planned: DSS will perform an analysis of identified reporting errors to determine causality and the appropriate actions to resolve reporting errors. Additio...
Responsible Contact Person(s): Angela Morse, Director of Benefit Programs Frank Smith, Associate Director of Benefit Programs Corrective Action Planned: DSS will perform an analysis of identified reporting errors to determine causality and the appropriate actions to resolve reporting errors. Additionally, DSS will create a systems modification request to correct errors that are identified as occurring as a result of inaccurate programming in the data modification phase of federal report creation. Estimated Completion Date: 12/31/2025
Responsible Contact Person(s): Ida Witherspoon, Chief Financial Officer Corrective Action Planned: Send periodic e-mail reminders to program staff responsible for submitting FFATA data to the Federal Reporting Unit for submission to the federal government. Estimated Completion Date: 3/15/2025
Responsible Contact Person(s): Ida Witherspoon, Chief Financial Officer Corrective Action Planned: Send periodic e-mail reminders to program staff responsible for submitting FFATA data to the Federal Reporting Unit for submission to the federal government. Estimated Completion Date: 3/15/2025
Responsible Contact Person(s): Angela Morse, Director of Benefit Programs Diana Clark, Assistant Director of Division of Benefit Programs Frank Smith, Associate Director of Benefit Programs Mark Golden, Economic Assistance and Employment Manager - Division of Benefit Programs Corrective Action Plann...
Responsible Contact Person(s): Angela Morse, Director of Benefit Programs Diana Clark, Assistant Director of Division of Benefit Programs Frank Smith, Associate Director of Benefit Programs Mark Golden, Economic Assistance and Employment Manager - Division of Benefit Programs Corrective Action Planned: DSS will work to provide additional training to local agency eligibility workers on how to properly determine and document eligibility determinations in the case management system. Additionally, DSS will consider monitoring local agency eligibility worker’s use of manual overrides to confirm that they properly document eligibility determinations in the case management system. Estimated Completion Date: 3/31/2025
View Audit 345214 Questioned Costs: $1
Responsible Contact Person(s): Angela Morse, Director of Benefit Programs Frank Smith, Associate Director of Benefit Programs Corrective Action Planned: DSS will perform an analysis of identified reporting errors to determine causality and the appropriate actions to resolve reporting errors. Additio...
Responsible Contact Person(s): Angela Morse, Director of Benefit Programs Frank Smith, Associate Director of Benefit Programs Corrective Action Planned: DSS will perform an analysis of identified reporting errors to determine causality and the appropriate actions to resolve reporting errors. Additionally, DSS will create a systems modification request to correct errors that are identified as occurring as a result of inaccurate programming in the data modification phase of federal report creation. Benefit Program is working with appropriate parties to resolve outstanding errors. Estimated Completion Date: 6/30/2025
Responsible Contact Person(s): Angela Morse, Director of Benefit Programs Mark Golden, Economic Assistance and Employment Manager - Division of Benefit Programs Corrective Action Planned: Perform an analysis of identified reporting errors to determine causality and the appropriate actions to resolve...
Responsible Contact Person(s): Angela Morse, Director of Benefit Programs Mark Golden, Economic Assistance and Employment Manager - Division of Benefit Programs Corrective Action Planned: Perform an analysis of identified reporting errors to determine causality and the appropriate actions to resolve reporting errors. Create a systems modification request to correct errors that are identified as occurring as a result of inaccurate programming in the data modification phase of federal report creation. A Change Request has been submitted to address these findings. The results of the implementation and effectiveness of the implemented changes will be analyzed. Benefit Program working with appropriate parties to resolve outstanding errors. Estimated Completion Date: 6/30/2025
Responsible Contact Person(s): Diana Clark, Associate Director Senior Corrective Action Planned: A spreadsheet to track monitoring activities by the BP SRM Coordinator was developed and implemented to ensure that Program Consultants adhere to the developed schedule. The BP SRM Coordinator reviews t...
Responsible Contact Person(s): Diana Clark, Associate Director Senior Corrective Action Planned: A spreadsheet to track monitoring activities by the BP SRM Coordinator was developed and implemented to ensure that Program Consultants adhere to the developed schedule. The BP SRM Coordinator reviews the completed audit documents to ensure that all required audit documents are uploaded to the enterprise management application timely and that reviews are conducted in accordance with the SRM Plan. A SRM monitoring desk tool will be created for Practice Consultants as a quick reference to the SRM Plan. Training for all Program Consultants conducting SRM will be provided on the new updated monitoring plan as well as ongoing training for newly hired Program Consultants. Estimated Completion Date: 3/31/2025
Responsible Contact Person(s): Diana Clark, Associate Director Senior Corrective Action Planned: A risk assessment tool was developed as part of the SFY2024 SRM Plan and will be implemented with the new plan. Risk Assessments were included in the FY2024 and FY2025 Business Plan Subrecipient Monitori...
Responsible Contact Person(s): Diana Clark, Associate Director Senior Corrective Action Planned: A risk assessment tool was developed as part of the SFY2024 SRM Plan and will be implemented with the new plan. Risk Assessments were included in the FY2024 and FY2025 Business Plan Subrecipient Monitoring plans. Both the Regional Practice Consultants and Home Office staff completing SRM are required to complete Risk Assessments for the upcoming review year. DSS has found some issues with a few staff members not completely understanding the process; however, after additional trainings were completed, this should not occur with the FY2026 review cycle. Estimated Completion Date: 8/1/2025
Responsible Contact Person(s): Ousman Kah, Subrecipient Monitoring Coordinator Kevin Platea, Chief Information Officer Corrective Action Planned: A Grants Management solution is being pursued by DSS in anticipation that it can be deployed with Subrecipient Monitoring capabilities needed to comply wi...
Responsible Contact Person(s): Ousman Kah, Subrecipient Monitoring Coordinator Kevin Platea, Chief Information Officer Corrective Action Planned: A Grants Management solution is being pursued by DSS in anticipation that it can be deployed with Subrecipient Monitoring capabilities needed to comply with these requirements. A new budget request has been submitted for funding of a contingent Subrecipient Monitoring System solution. This will help bridge the deficiencies noted until an integrated permanent solution is implemented. Additionally, an interim solution is being considered where these subrecipients will be reviewed and tracked through a manual system. Estimated Completion Date: 6/30/2025
Responsible Contact Person(s): Michele Skaggs, Director of General Services Adrienne Childress, Strategic Sourcing Purchasing Manager Ousman Kah, Subrecipient Monitoring Coordinator Corrective Action Planned: DSS will dedicate the necessary resources to reviewing federal regulations to include all r...
Responsible Contact Person(s): Michele Skaggs, Director of General Services Adrienne Childress, Strategic Sourcing Purchasing Manager Ousman Kah, Subrecipient Monitoring Coordinator Corrective Action Planned: DSS will dedicate the necessary resources to reviewing federal regulations to include all required information in subaward renewal agreements. Estimated Completion Date: 12/31/2025
Responsible Contact Person(s): Kimberly Boehme, OPGS Director Corrective Action Planned: Policies and procedures for grant management - to include subrecipient monitoring and FFATA reporting - will be revised. Oversight responsibilities will be determined for the Office of Grant Management, Office...
Responsible Contact Person(s): Kimberly Boehme, OPGS Director Corrective Action Planned: Policies and procedures for grant management - to include subrecipient monitoring and FFATA reporting - will be revised. Oversight responsibilities will be determined for the Office of Grant Management, Office of Purchasing and General Services, and Office of Financial Management. Employees responsible for managing grants and subrecipients will receive training on the new process. Estimated Completion Date: 12/31/2025
Responsible Contact Person(s): Kimberly Boehme, OPGS Director Corrective Action Planned: Policies and procedures for grant management - to include subrecipient monitoring and FFATA reporting - will be revised. Oversight responsibilities will be determined for the Office of Grant Management, Office...
Responsible Contact Person(s): Kimberly Boehme, OPGS Director Corrective Action Planned: Policies and procedures for grant management - to include subrecipient monitoring and FFATA reporting - will be revised. Oversight responsibilities will be determined for the Office of Grant Management, Office of Purchasing and General Services, and Office of Financial Management. Employees responsible for managing grants and subrecipients will receive training on the new process. Estimated Completion Date: 12/31/2025
Responsible Contact Person(s): Kimberly Boehme, OPGS Director Corrective Action Planned: VDH will develop an agency-wide process for compiling and maintaining contracts, utilizing the features of the system contract module. The process will determine who is responsible for contract and funding data ...
Responsible Contact Person(s): Kimberly Boehme, OPGS Director Corrective Action Planned: VDH will develop an agency-wide process for compiling and maintaining contracts, utilizing the features of the system contract module. The process will determine who is responsible for contract and funding data and connecting data in two systems for the ability to track and report on contracts and related expenditures. The process will also factor in complexities of grants funding contracts in multiple work units and ensuring that information can be compiled centrally. Employees responsible for contract execution and administration will receive training to ensure that the data is consistent and thorough. Estimated Completion Date: 12/31/2025
Responsible Contact Person(s): Sherika Charity, Director of Financial Aid Linsha Xie, Controller Corrective Action Planned: Step 1: The Financial Aid Office and Controller's Office will jointly review the current reconciliation process for federal assistance programs. This will include identifying ...
Responsible Contact Person(s): Sherika Charity, Director of Financial Aid Linsha Xie, Controller Corrective Action Planned: Step 1: The Financial Aid Office and Controller's Office will jointly review the current reconciliation process for federal assistance programs. This will include identifying all steps involved in the reconciliation process, documenting the roles and responsibilities of each office, and pin pointing areas where communication breakdowns have occurred in the past. Step 2: Based on the review, the offices will enhance the reconciliation procedures to address identified weaknesses. This will include developing standardized templates for reconciliations, establishing clear timelines for each step of the process, defining specific procedures for investigating and resolving reconciling differences, and implementing a system of checks and balances to ensure accuracy. Step 3: Formalize communication protocols between the Financial Aid Office and the Controller's Office to facilitate timely and effective information sharing related to federal assistance programs. This will include designated points of contact in each office, regular meetings and reminders for discussing reconciliation issues, and a shared folder for archiving reconciliation working paper and supporting documents. Estimated Completion Date: 6/30/2025
Responsible Contact Person(s): Carla L. Dailey, Director of Financial Aid Corrective Action Planned: NSU Financial Aid Office will ensure that the Direct Loan Notification Process will be sent out timely to all students with Direct Loan disbursements. Additional personnel have been named back-up to...
Responsible Contact Person(s): Carla L. Dailey, Director of Financial Aid Corrective Action Planned: NSU Financial Aid Office will ensure that the Direct Loan Notification Process will be sent out timely to all students with Direct Loan disbursements. Additional personnel have been named back-up to ensure notifications are submitted timely. The Student Accounts Office will notify the NSU department via email when disbursement of aid occurs. Calendar notifications can be created to ensure notifications are sent out timely. Estimated Completion Date: 8/31/2025
GMU Responsible Contact Person(s): Alethia Shipman, Director, Student Financial Aid Corrective Action Planned: George Mason will implement the following plan of action: - Management will enhance its communications relating to enrollment reporting in the Registrar and Financial Aid Offices. - Implem...
GMU Responsible Contact Person(s): Alethia Shipman, Director, Student Financial Aid Corrective Action Planned: George Mason will implement the following plan of action: - Management will enhance its communications relating to enrollment reporting in the Registrar and Financial Aid Offices. - Implement corrective actions to ensure that the University reports accurate and timely student enrollment status changes to the National Student Loan Data System. - Management will consider implementing a quality control review process to monitor the accuracy of campus and program-level batch submissions, such as implementing regularly scheduled self-audits of NSC data. Estimated Completion Date: 12/31/2025 NSU Responsible Contact Person(s): Carla L. Dailey, Director of Financial Aid Corrective Action Planned: The University has developed detailed procedures to improve reporting to NSLDS. These procedures include reviewing and updating Colleague system processing, designating staff members in both the Registrar and Financial Aid Offices to process, review and resolve reporting issues, and continued monitoring and verification of reports transmitted to NSLDS from the National Student Clearinghouse. Estimated Completion Date: 8/31/2025 NVCC Responsible Contact Person(s): Angelique Robinson, College Registrar Zina Jemison, Associate College Registrar Corrective Action Planned: Step 1: College Registrar (CR) and Associate College Registrar (ACR) will review National Student Loan Data System trainings, documentation, and initiate training sessions with appropriate NSLDS staff to answer any outstanding questions about the system. Step 2: CR and ACR will review important NSLDS deadlines and incorporate lessons learned from the trainings to set the tone for internal deadline processing changes so that the semi-automated graduation process can be performed in a faster manner. The CR and ACR will also determine which additional team members within the College Records Office will assist in the completion of record updating and reporting requirements within NSLDS, outlining the specific tasks that will need to be done by each participating member and the information system queries that will be used for internal auditing purposes. Step 3: CR and ACR will consult with Financial Aid staff to finalize new internal record adjustment processing deadlines to ensure that the changes in procedures are made in a timely manner and in support of Financial Aid processes. Estimated Completion Date: 6/30/2025 ODU Responsible Contact Person(s): Carrie John, University Registrar Corrective Action Planned: The University is taking corrective action to ensure accurate and timely reporting of student enrollment changes to NSLDS. Corrective actions include enhancing procedures, providing additional training, and improving internal reviews. Estimated Completion Date: 6/30/2026 RU Responsible Contact Person(s): Katie Piper, Registrar Corrective Action Planned: The Registrar's Office has met and completed initial planning and timelines to address procedural changes needed to report the loan data timely. Estimated Completion Date: 12/31/2025 UVA Responsible Contact Person(s): Steve Kimata, Associate Vice President for Enrollment and University Registrar Corrective Action Planned: The University will implement additional controls to ensure the accuracy and timeliness of enrollment data reported to NSLDS. This includes working collaboratively with Student Financial Services and Information Technology Services to monitor and report late withdrawals, review and update the information system process for creating enrollment files, and implement a quality control review to check student status change batches for accuracy and timeliness. Estimated Completion Date: 6/30/2025 VSU Responsible Contact Person(s): Nedra Jones, University Registrar Corrective Action Planned: 1) VSU has implemented an automated alert system to notify staff of upcoming reporting deadlines, cross-referenced information system data with the SCHEV Degree Inventory Report, and are actively collaborating with SCHEV to resolve discrepancies. These items are complete. 2) Additionally, VSU is in the process of implementing the following additional corrective actions: A.) A comprehensive review of current enrollment reporting processes; B.) Closer collaboration with VSU third-party service provider to streamline and improve the enrollment reporting; C.) Designating an individual within the Registrar's Office to oversee National Student Clearinghouse (NSC) and NSLDS reporting duties; and D.) establishing a quality control process to include monthly random sample audits of enrollment data. Additionally, VSU will reconcile student addresses between the information system and NSLDS for Federal Direct Loan borrowers. Estimated Completion Date: 12/31/2025
Responsible Contact Person(s): Sherika Charity, Director of Financial Aid Corrective Action Planned: Step 1: Review and update the FISAP Completion Documentation to clearly identify sources of data. This will include notating the specific data points for reporting enrollment and total tuition and fe...
Responsible Contact Person(s): Sherika Charity, Director of Financial Aid Corrective Action Planned: Step 1: Review and update the FISAP Completion Documentation to clearly identify sources of data. This will include notating the specific data points for reporting enrollment and total tuition and fees from VCCS provided reports and reviewing the FISAP for accuracy before submitting. Estimated Completion Date: 8/30/2025
« 1 679 680 682 683 2135 »