2 CFR 200 § 200.303

Findings Citing § 200.303

Internal controls.

Total Findings
99,874
Across all audits in database
Showing Page
13 of 1998
50 findings per page
About this section
Section 200.303 requires recipients and subrecipients of Federal awards to establish and maintain effective internal controls to ensure compliance with Federal laws and award conditions. This section affects organizations receiving Federal funding, mandating them to monitor compliance, address noncompliance promptly, and protect sensitive information.
View full section details →
FY End: 2025-06-30
State of Colorado
Compliance Requirement: L
Finding 2025-047 Compliance with Reporting for the Highway Safety Cluster The Department is required to comply with the Federal Funding Accountability and Transparency Act of 2006 (Transparency Act or FFATA) for its Highway Safety Cluster programs, specifically the State and Community Highway Safety [ALN 20.600] and National Priority Safety Programs [ALN 20.616] (Programs). The Transparency Act was created to empower Americans with the ability to hold the government accountable for each spending...

Finding 2025-047 Compliance with Reporting for the Highway Safety Cluster The Department is required to comply with the Federal Funding Accountability and Transparency Act of 2006 (Transparency Act or FFATA) for its Highway Safety Cluster programs, specifically the State and Community Highway Safety [ALN 20.600] and National Priority Safety Programs [ALN 20.616] (Programs). The Transparency Act was created to empower Americans with the ability to hold the government accountable for each spending decision and, as a result, to reduce wasteful spending by the government. The Transparency Act requires the federal government to make certain information on federal awards available to the public, including information about amounts passed through to subrecipients. The Department is required to report information about subgrants, or subawards, given to other governments or to nonprofit organizations (also referred to as subrecipients). Federal regulation [2 CFR 200.1] defines a subaward as an award provided by a pass-through entity, in this case the Department, to an entity to carry out part of a federal grant award received by the pass-through entity. A subrecipient is defined in federal regulation [2 CFR 200.1] as an entity, usually but not limited to non-federal entities, that receives a subaward from a pass-through entity to carry out part of a federal award; but does not include an individual that is a beneficiary of such award. A subrecipient may also be a recipient of other federal awards directly from a federal awarding agency. The Department is required to file FFATA reports through the System for Award Management website, SAM.gov. Once the Department submits a report to SAM.gov, the public can view certain information from the report, including the subrecipient’s name, subaward identification number, subaward obligation/action date, subaward amount, federal awarding agency and subagency, the Department’s name, and the Department’s grant award identification number. In Fiscal Year 2025, the Department reported approximately $12.9 million in total for the Programs’ expenditures. Of this amount, the Department issued about $6.8 million in subawards under the Programs. The Department had 70 subrecipients with subawards it was required to submit FFATA information for through SAM.gov during the fiscal year. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to determine whether the Department had adequate internal controls over and complied with FFATA reporting requirements for the Highway Safety Cluster Programs during Fiscal Year 2025. Another purpose of our audit work was to determine whether the Department implemented our Fiscal Year 2024 audit recommendations to strengthen its internal controls over and to ensure it complies with FFATA reporting requirements for the Highway Safety Cluster Programs. The Department agreed with these recommendations and planned to implement them by June 2025. As part of our audit work, we selected 24 Fiscal Year 2025 subrecipient expenditure transactions out of a total of 70 subrecipient transactions for which FFATA reporting was required for these Programs. We obtained copies of the FFATA reports that the Department uploaded to SAM.gov and obtained subaward agreements and purchase orders for each sample. We compared the Department’s subaward information to the information the Department submitted to SAM.gov to determine whether the Department reported accurate information. In addition, we performed testwork to determine whether the Department submitted the FFATA reports within the month following the month it made the subaward, as required by federal regulations. We also tested the Department’s progress in implementing our prior audit recommendations by reviewing their updated policies and procedures. How were the results of the audit work measured? We measured the results of our audit work against the following: • Federal regulations [2 CFR 170] require direct recipients of federal grants to report subawards of $30,000 or more to SAM.gov by the end of the month following the month in which the award was made. For example, the Department would have to submit a FFATA report to SAM.gov in May 2025 if an award or supplemental award equal to or greater than $30,000 was made in April 2025. Federal regulations [2 CFR 200.303] require the non-federal entity—in this instance the Department—to establish and maintain effective internal controls over the federal award that provides reasonable assurance that the non-federal entity is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award. • Federal regulation [2 CFR 200.332 (a)(1)] states that the Department’s subawards must clearly identify certain information, including but not limited to, the unique entity identifier, the Assistance Listing Number, the federal award date, and the federal award identification number. What problem did the audit work identify? Based on our audit work, we determined that the Department did not fully comply with FFATA reporting requirements for the Programs during Fiscal Year 2025 and did not fully implement our prior audit recommendations. Of the 24 subaward reports selected for testing, we identified issues on 5 subaward reports (21 percent). Specifically, we identified the following issues: • The Department was unable to provide documentation demonstrating that two subaward FFATA reports related to Fiscal Year 2024 awards had been submitted in SAM.gov. These submissions could not be located in SAM.gov. The amount of the subawards not submitted was $375,553. We further noted that these two reports had still not been submitted during Fiscal Year 2025. • For three subawards totaling $771,258, the Department did not maintain adequate documentation to support the amounts reported in SAM.gov. Specifically, the Department reported amounts of $537,573 for the three subawards, which did not agree to the Department’s subaward records, and represented a difference of $233,684. In addition, the Department did not meet the required FFATA reporting timelines for these subawards. Specifically, one subaward was reported 271 days late and two were reported 301 days late. Why did this problem occur? The Department did not have adequate internal controls in place related to FFATA reporting for the Highway Safety Cluster during Fiscal Year 2025 that ensured that reporting occurred as required for subawards of $30,000 or more in SAM.gov by the end of the month following the month the subawards are made. The Department implemented policies and procedures related to FFATA reporting during the fiscal year; however, Department staff indicated that staff were still being trained on these new procedures. In addition, the Department did not have procedures in place to ensure that, when an unsubmitted FFATA report is identified, the report is subsequently filed in SAM.gov, even if the submission is late. Why does this problem matter? By failing to properly report FFATA subawards through SAM.gov, the Department is out of compliance with federal reporting requirements, risks federal sanctions, and does not meet the federal intent of transparency for federal program spending. See "Schedule of Findings and Questioned Costs" for table/chart. Recommendation 2025-047 The Department of Transportation (Department) should strengthen its internal controls over and ensure it complies with Federal Funding Accountability and Transparency Act (FFATA) reporting requirements for the Highway Safety Cluster by: A. Ensuring that FFATA reporting occurs as required for subawards of $30,000 or more by the end of the month following the month the subawards are made and, if an unsubmitted FFATA report is identified, subsequently filing the report as soon as possible through SAM.gov, even if the submission is late. B. Providing training to Department staff to follow FFATA reporting policies and procedures. C. Ensuring Department staff follow the Department’s FFATA policies and procedures to ensure that FFATA reports are accurate and complete. Response Department of Transportation A. Agree Implementation Date: June 2026 The Department agrees with the recommendation. The Department will review, assess, and, where necessary, update existing procedures for FFATA reporting relating to the requirement that state subawards for $30,000+ be submitted within 30 days of committed budget. This will include ensuring that the confirmation date is documented. This process will be a coordinated effort between the Office Transportation Safety (OTS) and the Center for Accounting. This will include updating our reconciliation process to include additional data, reviewing and updating reconciliation and review procedures as needed, and reconciling Grants awarded in prior fiscal years that are still active and ensuring they have been appropriately reported. The findings related to this recommendation are in part the result of a federal reporting system limitation, and a federal system conversion. The legacy reporting system, FSRS, had a system limitation, which prevented the full amount of the award being reported in the case of three awards. Additionally, this conversion resulted in some data conversion issues impacting one additional award B. Agree Implementation Date: June 2026 The Department agrees with this finding and will provide any training needed to staff members to ensure that all components of the FFATA are completed accurately, timely and with proper reviews. This training will include leadership reviewing NHTSA/Federal guidelines and SAM.Gov training on FFATA reporting and requirements, documenting controls and ensuring the approvers have access to all supporting schedules, forms and systems and that they understand the subawards, and process for late submissions if needed. C. Agree Implementation Date: June 2026 The Department agrees with the finding and will ensure that staff follow all internal policies and procedures to maintain accurate and complete FFATA reporting. To achieve this, staff will review existing procedures and make any necessary updates regarding report compilation. Additionally, we will review control points to ensure they are consistently followed and approved by the team supervisor or team manager.

FY End: 2025-06-30
State of Colorado
Compliance Requirement: M
The following finding and recommendation relating to an internal control deficiency classified as a Significant Deficiency was communicated to the Department of Transportation (Department) in the previous year and has not been remediated as of June 30, 2025 because the original implementation date provided by the Department was in a subsequent fiscal year. This complete finding and recommendation can be found within the original report and the complete recommendation can be found within Section ...

The following finding and recommendation relating to an internal control deficiency classified as a Significant Deficiency was communicated to the Department of Transportation (Department) in the previous year and has not been remediated as of June 30, 2025 because the original implementation date provided by the Department was in a subsequent fiscal year. This complete finding and recommendation can be found within the original report and the complete recommendation can be found within Section IV: Disposition of Prior Audit Recommendations of this report. Finding 2024-058 Compliance with Subrecipient Monitoring for the Formula Grants for Rural Areas and Tribal Transit Program, Highway Safety Cluster, and SLFRF The Department receives federal grant funds directly from the federal government for the Formula Grants for Rural Areas and Tribal Transit Program, Highway Safety Cluster, and the Coronavirus State and Local Fiscal Recovery Funds (SLFRF) program and then subgrants, or passes through, a portion of the funds to cities and counties and other organizations that are considered to be either a subrecipient or a contractor. For Fiscal Year 2024, the Department had the following transactions that were subject to subrecipient monitoring testing: • Formula Grants for Rural Areas and Tribal Transit Program – 783 subrecipient transactions totaling $23,075,270. • Highway Safety Cluster – 829 subrecipient transactions totaling $5,669,865. • SLFRF – 232 subrecipient transactions totaling $38,321,493. For the SLFRF program, Intergovernmental Agreements are executed between the Department and subrecipients to communicate all relevant federal award information. For both the Formula Grants for Rural Areas and Tribal Transit Program and Highway Safety Cluster, Subaward Agreements (subawards) are executed between the Department and subrecipients to communicate all relevant federal award information. Intergovernmental Agreements and subawards are signed by authorized State personnel, generally the State Controller and the Department’s Chief Engineer. The Department includes a “Subrecipient Risk Assessment” tool with its Intergovernmental Agreements or subawards, which must be completed by Department staff prior to making the award. The Department’s subrecipient monitoring procedures are dependent on the assessed risk level noted in the Subrecipient Risk Assessment tool. Federal regulations [2 CFR Part 200 Section F] state that a non-federal entity that expends $1,000,000 or more in federal awards during the non-federal entity’s fiscal year must have a Single Audit conducted in accordance with 2 CFR 200.514. The Department’s Internal Audit Division staff tracks and receives Single Audit reports from its subrecipients. As part of the Department’s monitoring procedures, the Internal Audit Division personnel complete a “Single Audit Report Review Summary” form to show they reviewed the subrecipient’s Single Audit report, summarized any findings, and concluded on any risks presented to the Department and any related future actions to be taken. The form is signed by a Department preparer and a Department reviewer. For those subrecipients not required to file a Single Audit, an “Audit Division Single Audit Certification Form” must still be submitted by the subrecipients to the Department. These forms note that the entity was exempt from a Single Audit. What was the purpose of our audit work and what work was performed? The purpose of our audit work was to determine if the Department complied with federal requirements for subrecipient monitoring during Fiscal Year 2024 for the Formula Grants for Rural Areas and Tribal Transit Program, Highway Safety Cluster, and the SLFRF program and to determine whether the Department had adequate internal controls over subrecipient monitoring. As part of our audit work, we reviewed the Department’s internal controls over compliance for subrecipient monitoring and tested the Department’s compliance with federal subrecipient monitoring requirements. Specifically, we performed the following testwork related to each of the following federal programs: • Formula Grants for Rural Areas and Tribal Transit Program—We selected and reviewed a random sample of 40 subrecipient payment transactions. We reviewed subawards, amendments, and other supporting documentation provided by the Department. • Highway Safety Cluster—We selected and reviewed a random sample of 40 subrecipient payment transactions. We reviewed subawards, amendments, and other supporting documentation provided by the Department. • SLFRF—We selected and reviewed a random sample of 29 subrecipient payment transactions. We reviewed Intergovernmental Agreements, amendments, and other supporting documentation provided by the Department. How were the results of the audit work measured? Our audit work was designed to measure the Department’s compliance with the following criteria: • Federal regulation [2 CFR 200.303] states that the Department, as a federal grant recipient, must “establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award.” • Federal regulation [2 CFR 200.332 (a)(1)] states that the Department’s subawards must clearly identify certain information, including but not limited to, the ALN, the Federal Award Date, and the FAIN. • Federal regulation [2 CFR 200.331] states that a pass-through entity, in this case the Department, must make case-by-case determinations as to whether each agreement it makes for the disbursement of federal program funds represents a payment of funds to a subrecipient or a contractor, depending on the role the entity plays. What problems did the audit work identify? We determined that the Department did not fully comply with subrecipient monitoring requirements during Fiscal Year 2024. Specifically, we noted the following: • Formula Grants for Rural Areas and Tribal Transit Program o For 10 of 40 (25 percent) subrecipient payment transactions selected for testing, we determined the subaward documents did not contain the federal award date in the subaward agreement, as required. The 10 transactions totaled $7,432,248 in subrecipient awards. • Highway Safety Cluster o For 1 of 40 (3 percent) subrecipient payment transactions selected for testing, we determined that the subrecipient should have been classified as a contractor, not a subrecipient. The transaction totaled $75,325. The Department had not made an adjusting entry in CORE to reclassify the transaction and correct this error by the end of our audit testwork. o For 5 of 40 (13 percent) subrecipient payment transactions selected for testing, we determined the subaward documents did not contain the federal award date in the subaward agreement. The 5 transactions totaled $25,100 in subrecipient awards. • SLFRF o For 2 of 29 (7 percent) subrecipient payment transactions selected for testing, we determined that the Intergovernmental Agreement did not include the FAIN and Federal Award Dates. The 2 transactions totaled $3,277,779 in subrecipient awards. o For 1 of 29 (3 percent) subrecipient payment transactions selected for testing, we determined the transaction did not include the ALN. This transaction totaled $1,851,279 in subrecipient awards. Why did these problems occur? The Department’s procedures and internal controls were not sufficient to ensure that Intergovernmental Agreements and subawards included all the required information to be included in the subaward, and internal controls did not prevent or detect errors. Department staff were not aware that this information was needed for the subaward to be in compliance with federal regulations. In some situations, the FAIN was only provided to the Department from the U.S. Department of Transportation subsequent to when the subaward was made. In these instances, the Department was not aware that they were required to provide the FAIN to their subrecipients once it was determined by the U.S. Department of Transportation. The Department’s procedures and internal controls were not sufficient to ensure that payments were properly classified as general disbursements or subrecipient payments, and internal controls did not prevent or detect errors. Department staff lacked the appropriate knowledge of the difference in contractors and subrecipients to ensure the proper classification of expenditures. The Department’s reviewers did not complete a sufficient review of the expense classifications to be able to identify the misclassification and propose a subsequent correction. Why do these problems matter? Based on the issues we identified, the Department is out of compliance with federal subrecipient requirements and could face sanctions or other penalties. In addition, by failing to properly report the required federal grant award information at the time of subaward issuance, subrecipients may be uninformed about what funding the subaward related to. This could result in misclassification of subaward information on the subrecipients’ Schedules of Expenditures of Federal Awards (SEFA) and the subrecipient may not know what federal requirements they need to follow as part of receiving the federal award funds. The Department’s improper classification of expenses as general disbursements versus subrecipient payments could lead to misstatements in the amounts reported on the SEFA, both for the State as a whole and at the subrecipient level. See "Schedule of Findings and Questioned Costs" for chart/table. Recommendation 2024-058 The Department of Transportation (Department) should strengthen its internal controls over and ensure that it complies with federal subrecipient monitoring requirements for the Formula Grants for Rural Areas and Tribal Transit Program, the Highway Safety Cluster, and the Coronavirus State and Local Fiscal Recovery Funds. Specifically, the Department should ensure that all required information is included in subawards or intergovernmental agreements or provide amendments to the subawards or intergovernmental once the Department receives the necessary information from the federal government, and that Department staff are sufficiently aware of the difference in subrecipients and contractors and properly classify general disbursements versus subrecipient payments. Response Department of Transportation Agree Implementation Date: June 2026 Department will strengthen controls to ensure that the required award information is provided, once available. Certain information such as Federal Award Identification Number and Federal Transit Administration and National Highway Traffic Safety Administration award date are not available at the time of contracting CDOT is working on a process to provide this information, once it is available in a publicly available format on CDOT’s website or on a subrecipient facing grant management site. We will add a note to the contract explaining where the information will be posted on our site when it becomes available. The Department will also identify staff requiring additional training on classification and coding for contractors vs. subrecipients.

FY End: 2025-06-30
Smith-Green Community Schools
Compliance Requirement: I
FINDING 2025-003 Subject: Special Education Cluster (IDEA) - Procurement and Suspension and Debarment Federal Agency: Department of Education Federal Programs: COVID-19 - Special Education Grants to States, COVID-19 - Special Education Preschool Grants Assistance Listings Numbers: 84.027X, 84.173X Other Identifying Numbers: 22611-042-ARP, 22619-042-ARP Pass-Through Entity: Indiana Department of Education Compliance Requirement: Procurement and Suspension and Debarment Audit Findings: Material We...

FINDING 2025-003 Subject: Special Education Cluster (IDEA) - Procurement and Suspension and Debarment Federal Agency: Department of Education Federal Programs: COVID-19 - Special Education Grants to States, COVID-19 - Special Education Preschool Grants Assistance Listings Numbers: 84.027X, 84.173X Other Identifying Numbers: 22611-042-ARP, 22619-042-ARP Pass-Through Entity: Indiana Department of Education Compliance Requirement: Procurement and Suspension and Debarment Audit Findings: Material Weakness, Modified Opinion Condition and Context The School Corporation is a member of the Northeast Indiana Special Education Cooperative (Cooperative). During fiscal year 2023-2024, the Cooperative operated the special education program and spent the federal money on behalf of all its members. As the grant agreement was between the Indiana Department of Education (IDOE) and each member school, the School Corporation was responsible for ensuring and providing oversight of the Cooperative. The School Corporation did not have internal controls in place to ensure that the Cooperative complied with the Procurement and Suspension and Debarment compliance requirement. The Cooperative did not have adequate procedures in place to ensure that the requirements for the simplified acquisition threshold and for small purchases were met for each applicable procured good or service or to ensure that vendors were not suspended or debarred prior to entering into a covered transaction. Procurement When the value of the procurement for property or services exceeds the simplified acquisition threshold (SAT), or a lower threshold established by a nonfederal entity, formal procurement methods are required. The SAT is typically set at $250,000. However, Indiana Code 5-22-8 has a more restrictive threshold. Therefore, the SAT threshold is set at $150,000. Formal procurement methods require adherence to documented procedures and formal methods such as sealed bids or proposals. When the purchase value exceeds the micro-purchase threshold but is less than the simplified acquisition threshold, a small purchase occurs. Small purchases require documented full and open competition or a documented rationale for limited competition. For 2023-2024, three vendors with disbursements totaling $175,125 were identified as being less than the simplified acquisition threshold of $150,000 but exceeding the $50,000 micropurchase threshold and were selected for testing. The Cooperative did not obtain price or rate quotes for two of the three vendors, and there was no documentation detailing the history of the procurement, which must include the reason for the procurement method used. INDIANA STATE BOARD OF ACCOUNTS 18 SMITH-GREEN COMMUNITY SCHOOLS SCHEDULE OF FINDINGS AND QUESTIONED COSTS (Continued) Suspension and Debarment Prior to entering into subawards and covered transactions with federal award funds, recipients are required to verify that such contractors and subrecipients are not suspended, debarred, or otherwise excluded. "Covered transactions" include, but are not limited to, contracts for goods and services awarded under a nonprocurement transaction (i.e., grant agreement) that are expected to equal or exceed $25,000. The verification is to be done by checking the SAM exclusions, collecting a certification from that vendor, or adding a clause or condition to the covered transaction with that vendor. Upon inquiry of the Cooperative in order to review the procedures in place for verifying that a vendor with which it plans to enter into a covered transaction is not suspended, debarred, or otherwise excluded, the Cooperative disclosed there were not any documented internal controls or procedures. Nine covered transactions were identified. The covered transactions, totaling $803,836, were selected for testing. The Cooperative did not verify the suspension and debarment status of the tested vendors prior to payment. Criteria 2 CFR 200.303 states in part: "The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in 'Standards for Internal Control in the Federal Government' issued by the Comptroller General of the United States or the 'Internal Control Integrated Framework', issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). . . ." 2 CFR 200.320 states in part: "The non-Federal entity must have and use documented procurement procedures, consistent with the standards of this section and §§ 200.317, 200.318, and 200.319 for any of the following methods of procurement used for the acquisition of property or services required under a Federal award or sub-award. (a) Informal procurement methods. When the value of the procurement for property or services under a Federal award does not exceed the simplified acquisition threshold (SAT), as defined in § 200.1, or a lower threshold established by a non-Federal entity, formal procurement methods are not required. The non-Federal entity may use informal procurement methods to expedite the completion of its transactions and minimize the associated administrative burden and cost. The informal methods used for procurement of property or services at or below the SAT include: . . . (2) Small purchases — (i) Small purchase procedures. The acquisition of property or services, the aggregate dollar amount of which is higher than the micro-purchase threshold but does not exceed the simplified acquisition threshold. If small purchase procedures are used, price or rate quotations must be obtained from an adequate number of qualified sources as determined appropriate by the non-Federal entity. . . . INDIANA STATE BOARD OF ACCOUNTS 19 SMITH-GREEN COMMUNITY SCHOOLS SCHEDULE OF FINDINGS AND QUESTIONED COSTS (Continued) (b) Formal procurement methods. When the value of the procurement for property or services under a Federal financial assistance awards exceeds the SAT, or a lower threshold established by a non-Federal entity, formal procurement methods are required. Formal procurement methods require following documented procedures. Formal procurement methods also require public advertising unless a non-competitive procurement can be used in accordance with § 200.319 or paragraph (c) of this section. The following formal methods of procurement are used for procurement of property or services above the simplified acquisition threshold or a value below the simplified acquisition threshold the non-Federal entity determines to be appropriate: (1) Sealed bids. A procurement method in which bids are publicly solicited and a firm fixed-price contract (lump sum or unit price) is awarded to the responsible bidder whose bid, conforming with all the material terms and conditions of the invitation for bids, is the lowest in price. The sealed bids method is the preferred method for procuring construction, if the conditions. . . . (2) Proposals. A procurement method in which either a fixed price or cost-reimbursement type contract is awarded. Proposals are generally used when conditions are not appropriate for the use of sealed bids. . . ." 2 CFR 180.300 states: "When you enter into a covered transaction with another person at the next lower tier, you must verify that the person with whom you intend to do business is not excluded or disqualified. You do this by: (a) Checking SAM Exclusions; or (b) Collecting a certification from that person; or (c) Adding a clause or condition to the covered transaction with that person." Cause The Cooperative noted that the American Rescue Plan (ARP) portion of the Special Education grant was new for 2023-2024. The ARP funding gave opportunity for types of expenditures that do not typically get expensed using special education funding. The transactions noted within the Condition and Context were from the ARP portion of the grant, which provided property or services that exceeded the micro-purchase threshold. Management of the Cooperative was unaware of the procurement requirements when property or services exceed the micro-purchase threshold. In addition, management of the Cooperative was unaware of the suspension and debarment requirements when a covered transaction is expected to equal or exceed $25,000. Effect Without the proper implementation of an effectively designed system of internal controls, including policies and procedures that provide segregation of duties and additional oversight as needed, the internal control system cannot be capable of effectively preventing, or detecting and correcting, material noncompliance. Without following the required methods for procurement, the Cooperative could be overpaying for services. Unverified vendors to whom payments are equal to or in excess of $25,000 could be suspended, debarred, or otherwise excluded. INDIANA STATE BOARD OF ACCOUNTS 20 SMITH-GREEN COMMUNITY SCHOOLS SCHEDULE OF FINDINGS AND QUESTIONED COSTS (Continued) Noncompliance with the provisions of federal statutes, regulations, and terms and conditions of the federal award could result in the reduction of future federal funding to the Cooperative. Questioned Costs There were no questioned costs identified. Recommendation We recommended that the Cooperative's management design and implement a system of internal controls related to procurement and suspension and debarment procedures to ensure procurement requirements are met and to ensure entities are neither suspended nor debarred or otherwise excluded or disqualified prior to entering into any covered transactions. Views of Responsible Officials For the views of responsible officials, refer to the Corrective Action Plan that is part of this report.

FY End: 2025-06-30
Washington Community Schools, Inc.
Compliance Requirement: I
FINDING 2025-001 Subject: Child Nutrition Cluster - Procurement and Suspension and Debarment Federal Agency: Department of Agriculture Federal Programs: School Breakfast Program, National School Lunch Program, Summer Food Service Program for Children Assistance Listings Numbers: 10.553, 10.555, 10.559 Federal Award Numbers and Years (or Other Identifying Numbers): FY 2023-24, FY 2024-25 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Procurement and Suspension and De...

FINDING 2025-001 Subject: Child Nutrition Cluster - Procurement and Suspension and Debarment Federal Agency: Department of Agriculture Federal Programs: School Breakfast Program, National School Lunch Program, Summer Food Service Program for Children Assistance Listings Numbers: 10.553, 10.555, 10.559 Federal Award Numbers and Years (or Other Identifying Numbers): FY 2023-24, FY 2024-25 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Procurement and Suspension and Debarment Audit Findings: Material Weakness, Other Matters Repeat Finding This is a repeat finding from the immediately prior audit report. The prior audit finding number was 2023-002. Condition and Context An effective internal control system was not in place at the School Corporation to ensure compliance with requirements related to the grant agreement and the Procurement and Suspension and Debarment compliance requirement. Procurement Federal regulations allow for informal procurement methods when the value of the procurement for property or services does not exceed the simplified acquisition threshold, which is set at $250,000 unless a lower, more restrictive threshold is set by a nonfederal entity. The State of Indiana has established a more restrictive threshold of $150,000 for informal procurement methods. This informal process allows for methods other than the formal bid process. The informal process is divided between two methods based on thresholds: micro-purchases, typically for those purchases $10,000 or under, and small purchase procedures for those purchases above the micro-purchase threshold but below the simplified acquisition threshold. Small purchase procedures require that price or rate quotations must be obtained from an adequate number of qualified sources or have documented reasoning to support a single source provider. Two vendors were identified that were paid $27,726 and $70,168, respectively, during the audit period using federal funds under the award, thereby requiring small purchase procedures for both procurements. Both vendors were selected for testing. The School Corporation was unable to provide any documentation for the vendor that was paid $70,168 that the procurement method used was appropriate or that the procurement provided full and open competition or rationale to support the determination to limit competition. Additionally, the history of procurement, including the rationale for the method of procurement, selection of the vendor, and the basis for the price, was not adequately documented for the vendor. INDIANA STATE BOARD OF ACCOUNTS 16 WASHINGTON COMMUNITY SCHOOLS, INC. SCHEDULE OF FINDINGS AND QUESTIONED COSTS (Continued) Suspension and Debarment Prior to entering into subawards and covered transactions with federal award funds, recipients are required to verify that vendors and subrecipients are not suspended, debarred, or otherwise excluded from receiving federal funds. "Covered transactions" include, but are not limited to, contracts for goods and services awarded under a nonprocurement transaction (i.e., grant agreement) that are expected to equal or exceed $25,000. The verification is to be done by checking the Excluded Parties List System (EPLS), collecting a certification from that vendor, or adding a clause or condition to the covered transaction with that vendor. Four covered transactions that equaled or exceeded $25,000 were identified. All four transactions totaling $4,082,816 were selected for testing. For two of the four vendors, the School Corporation did not verify the vendor's suspension and debarment status prior to entering into the covered transaction with either vendor. The amount paid to both vendors totaled $97,894. The lack of internal controls and noncompliance were systemic issues throughout the audit period. Criteria 2 CFR 200.303 states in part: "The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in 'Standards for Internal Control in the Federal Government' issued by the Comptroller General of the United States or the 'Internal Control Integrated Framework', issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). . . ." 2 CFR 200.318 states in part: "(a) The non-Federal entity must have and use documented procurement procedures, consistent with State, local, and tribal laws and regulations and the standards of this section, for the acquisition of property or services required under a Federal award or subaward. The non-Federal entity's documented procurement procedures must conform to the procurement standards identified in §§ 200.317 through 200.327. . . . (i) The non-Federal entity must maintain records sufficient to detail the history of procurement. These records will include, but are not necessarily limited to, the following: Rationale for the method of procurement, selection of contract type, contractor selection or rejection, and the basis for the contract price. . . ." 2 CFR 200.320 states in part: "The non-Federal entity must have and use document procurement procedures, consistent with the standards of this section and §§ 200.317, 200.318, and 200.319 for any of the following methods of procurement used for the acquisition of property or services required under a Federal award or sub-award. INDIANA STATE BOARD OF ACCOUNTS 17 WASHINGTON COMMUNITY SCHOOLS, INC. SCHEDULE OF FINDINGS AND QUESTIONED COSTS (Continued) (a) Informal procurement methods. When the value of the procurement for property or services under a Federal award does not exceed the simplified acquisition threshold (SAT), as defined in § 200.1, or a lower threshold established by a non-Federal entity, formal procurement methods are not required. The non-Federal entity may use informal procurement methods to expedite the completion of its transactions and minimize the associated administrative burden and cost. The informal methods used for procurement of property or services at or below the SAT include: . . . (2) Small purchases– (i) Small purchase procedures. The acquisition of property or services, the aggregate dollar amount of which is higher than the micro-purchase threshold but does not exceed the simplified acquisition threshold. If small purchase procedures are used, price or rate quotations must be obtained from an adequate number of qualified sources as determined appropriate by the non-Federal entity. . . . (b) Noncompetitive procurement. There are specific circumstances in which noncompetitive procurement can be used. Noncompetitive procurement can only be awarded if one or more of the following circumstances apply: (1) The acquisition of property or services, the aggregate dollar amount of which does not exceed the micro-purchase threshold (see paragraph (a)(1) of this section); (2) The item is available only from a single source; (3) The public exigency or emergency for the requirement will not permit a delay resulting from publicizing a competitive solicitation; (4) The Federal awarding agency or pass-through entity expressly authorizes a noncompetitive procurement in response to a written request from the non-Federal entity; or (5) After solicitation of a number of sources, competition is determined inadequate." 2 CFR 180.300 states: "When you enter into a covered transaction with another person at the next lower tier, you must verify that the person with whom you intend to do business is not excluded or disqualified. You do this by: (a) Checking the SAM Exclusions; or (b) Collecting a certification from that person; or (c) Adding a clause or condition to the covered transaction with that person." Cause The School Corporation did not have adequate internal controls to ensure compliance with procurement and suspension and debarment requirements. The School Corporation was aware of the Procurement and Suspension and Debarment compliance requirement and relied on its food service management company to ensure compliance. There was not sufficient oversight by the School Corporation to ensure proper procedures were followed. INDIANA STATE BOARD OF ACCOUNTS 18 WASHINGTON COMMUNITY SCHOOLS, INC. SCHEDULE OF FINDINGS AND QUESTIONED COSTS (Continued) Effect The lack of an effective internal control system enabled material noncompliance to occur and remain undetected. Noncompliance with the Procurement and Suspension and Debarment compliance requirement could enable small purchases made by the School Corporation to be uncompetitive and could lead to contracting with vendors who are suspended or debarred from receiving federal grant funding. Noncompliance with the grant agreement and the compliance requirement could result in the loss of future federal funding to the School Corporation. Questioned Costs There were no questioned costs identified. Recommendation We recommended that management of the School Corporation establish a proper system of internal controls and develop policies and procedures to ensure that there are appropriate procurement procedures for goods and services and that contractors and subrecipients, as appropriate, are verified to not be suspended, debarred, or otherwise excluded prior to entering into any contracts or subawards. Views of Responsible Officials For the views of responsible officials, refer to the Corrective Action Plan that is part of this report.

FY End: 2025-06-30
East Porter County School Corporation
Compliance Requirement: G
FINDING 2025-001 Information on the federal program: Subject: Special Education Cluster (IDEA) – Internal Controls Federal Agency: Department of Education Federal Program: Special Education Grants to States, Special Education Preschool Grants Assistance Listings Numbers: 84.027, 84.027X, 84.173X Federal Award Numbers and Years (or Other Identifying Numbers): 22611-046-PN01, 22611-046-ARP, 22619-046-ARP Pass-Through Entity: Indiana Department of Education Compliance Requirement: Earmarking Audit ...

FINDING 2025-001 Information on the federal program: Subject: Special Education Cluster (IDEA) – Internal Controls Federal Agency: Department of Education Federal Program: Special Education Grants to States, Special Education Preschool Grants Assistance Listings Numbers: 84.027, 84.027X, 84.173X Federal Award Numbers and Years (or Other Identifying Numbers): 22611-046-PN01, 22611-046-ARP, 22619-046-ARP Pass-Through Entity: Indiana Department of Education Compliance Requirement: Earmarking Audit Findings: Significant Deficiency Criteria: 2 CFR section 200.303 states in part: "The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal awards in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in 'Standards for Internal Control in the Federal Government' issued by the Comptroller General of the United States or the 'Internal Control Integrated Framework', issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO)...." 2 CFR 200.403 states in part: "Except where otherwise authorized by statute, costs must meet the following general criteria in order to be allowable under Federal awards:… (g) Be adequately documented. . . ." 2 CFR 200.208(b) states in part: "The Federal awarding agency or pass-through entity may adjust specific Federal award conditions as needed . . ." 511 IAC 7-34-7(b) states: "The public agency, in providing special education and related services to students in nonpublic schools must expend at least an amount that is the same proportion of the public agency total subgrant under 20 U.S.C. 1411(f) as the number of nonpublic school students with disabilities, who are enrolled by their parents in nonpublic schools within its boundaries, is to the total number of students with disabilities of the same age range." Condition: An effective internal control system was not in place at the School Corporation in order to ensure compliance with requirements related to the grant agreement and earmarking compliance requirement. Cause: The School Corporation's management had not developed a system of internal controls to ensure compliance with the earmarking requirements. Effect: The failure to establish an effective internal control system placed the School Corporation at risk of noncompliance with the grant agreement and the compliance requirements. A lack of segregation of duties within an internal control system could have also allowed noncompliance with the compliance requirements and allowed the misuse and mismanagement of federal funds and assets by not having proper oversight, reviews, and approvals over the activities of the programs. Questioned Costs: There were no questioned costs identified. Context: The School Corporation is a member of the Porter County Education Services (Cooperative). During fiscal year 2023-2024, the Cooperative operated the special education program and spent the federal money on behalf of all its members. As the grant agreement was between the Indiana Department of Education (IDOE) and each member school, the School Corporation was responsible for ensuring and providing oversight of the Cooperative. The School Corporation did not have internal controls in place to ensure that the Cooperative complied with the earmarking requirements. The Cooperative did not have adequate procedures in place to ensure that the required level of expenditures for non-public school students with disabilities was met for each member school. The Cooperative did not have effective internal controls to ensure non-public school expenditures were appropriately identified and reported. The Non-Public Proportionate Share expenditures for the 22611-046-PN01, 22611-046-ARP, and 22619-046-ARP grant awards could not be verified for the individual member schools. Total grant expenditures were posted as expended. The non-public proportionate share expenditures were determined by applying a percentage to the non-public school budgeted expenditures. As such, we were unable to identify if the minimum amount per each applicable member schools’ grant award was expended and properly reported to IDOE, as required. The lack of internal controls was isolated to the 22611-046-PN01, 22611-046-ARP, and 22619-046-ARP grant awards which were fully expended during fiscal year 2024. These three grant awards had minimum earmarking requirements for the Non-Public Proportionate Share of $18,682, $4,510, and $302 respectively. Identification as a repeat finding, if applicable: This is a repeat finding from the immediately prior audit. The prior finding number was 2023-004. Recommendation: We recommended that management of the School Corporation establish a proper system of internal controls and develop policies and procedures to monitor the Cooperative and ensure non-public proportionate share funds are appropriately allocated to the member school based on expenditures charged directly on behalf of the member school. Supporting documentation for these expenditures should be retained for audit. Views of Responsible Officials and Planned Corrective Actions: Management agrees with the finding and has prepared a corrective action plan.

FY End: 2025-06-30
East Porter County School Corporation
Compliance Requirement: N
Finding 2025-002 Information on the federal program: Subject: Education Stabilization Fund – Special Tests and Provisions - Wage Rate Requirements Federal Agency: Department of Education Federal Program: COVID-19 - Education Stabilization Fund Assistance Listing Number: 84.425U Federal Award Numbers and Years (or Other Identifying Numbers): S425U210013 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Special Tests and Provisions - Wage Rate Requirements Audit Findings...

Finding 2025-002 Information on the federal program: Subject: Education Stabilization Fund – Special Tests and Provisions - Wage Rate Requirements Federal Agency: Department of Education Federal Program: COVID-19 - Education Stabilization Fund Assistance Listing Number: 84.425U Federal Award Numbers and Years (or Other Identifying Numbers): S425U210013 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Special Tests and Provisions - Wage Rate Requirements Audit Findings: Material Weakness, Material Noncompliance, Qualified Opinion Criteria: 2 CFR section 200.303 states in part: "The non-Federal entity must: (a) Establish and maintain effective internal control over Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal awards in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in 'Standards for Internal Control in the Federal Government' issued by the Comptroller General of the United States or the 'Internal Control Integrated Framework', issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). . . ."29 CFR 5.5 states in part: (1) Minimum wages.All laborers and mechanics employed or working upon the site of the work (or under the United States Housing Act of 1937 or under the Housing Act of 1949 in the construction or development of the project), will be paid unconditionally and not less often than once a week, and without subsequent deduction or rebate on any account (except such payroll deductions as are permitted by regulations issued by the Secretary of Labor under the Copeland Act (29 CFR part 3)), the full amount of wages and bona fide fringe benefits (or cash equivalents thereof) due at time of payment computed at rates not less than those contained in the wage determination of the Secretary of Labor which is attached hereto and made a part hereof, regardless of any contractual relationship which may be alleged to exist between the contractor and such laborers and mechanics… (3)(ii)(A) The contractor shall submit weekly for each week in which any contract work is performed a copy of all payrolls to the (write in name of appropriate federal agency) if the agency is a party to the contract, but if the agency is not such a party, the contractor will submit the payrolls to the applicant, sponsor, or owner, as the case may be, for transmission to the (write in name of agency). 2 CFR 200 Appendix II states in part: In addition to other provisions required by the Federal agency or non-Federal entity; all contracts made by the non-Federal entity under the Federal award must contain provisions covering the following, as applicable. . . . (D) Davis-Bacon Act, as amended (40 U.S.C. 3141-3148). When required by Federal program legislation, all prime construction contracts in excess of $2,000 awarded by non-Federal entities must include a provision for compliance with the Davis-Bacon Act (40 U.S.C. 3141-3144, and 3146-3148) as supplemented by Department of Labor regulations (29 CFR Part 5, “Labor Standards Provisions Applicable to Contracts Covering Federally Financed and Assisted Construction”). In accordance with the statute, contractors must be required to pay wages to laborers and mechanics at a rate not less than the prevailing wages specified in a wage determination made by the Secretary of Labor. In addition, contractors must be required to pay wages not less than once a week.. . .” Condition: An effective internal control system was not in place at the School Corporation in order to ensure compliance with requirements related to the grant agreement and the Special Tests and Provisions – Wage Rate Requirements compliance requirements. Cause: The School Corporation's management had not developed a system of internal controls to ensure compliance with the compliance requirements listed above. Effect: The failure to design and implement an effective internal control system enabled material noncompliance to go undetected. Noncompliance with the grant agreement and the Special Tests and Provisions – Wage Rate Requirements compliance requirement could result in the loss of future federal funds to the School Corporation. Questioned Costs: There were no questioned costs identified. Context: The School Corporation did not obtain the weekly payroll reports certifications from a company that performed renovations to replace fan coil units and HVAC equipment in the building. Therefore, no review was performed to ensure that pay rates complied with the federal wage rate requirements. The amount disbursed and reported on the SEFA during the audit period is $119,190 and the labor portion was not determinable by the School Corporation. Identification as a repeat finding, if applicable: This is a repeat finding from the immediately prior audit. The prior audit finding number was 2023-006. Recommendation: We recommend the School Corporation implement a formal process to ensure the required weekly payroll reports certifications are collected and reviewed to ensure compliance with the wage rate requirements. Views of Responsible Officials and Planned Corrective Actions: Management agrees with the finding and has prepared a corrective action plan.

FY End: 2025-06-30
Hazel Crest School District 152.5
Compliance Requirement: L
8. Criteria or specific requirement: Per Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards (2 CFR Part 200) Subpart D, Post Federal Award Requirements Section 200.303, Internal controls, the recipient must establish, document and maintain effective internal control over the Federal award that provides reasonable assurance that the recipient is managing the Federal award in compliance with Federal sta...

8. Criteria or specific requirement: Per Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards (2 CFR Part 200) Subpart D, Post Federal Award Requirements Section 200.303, Internal controls, the recipient must establish, document and maintain effective internal control over the Federal award that provides reasonable assurance that the recipient is managing the Federal award in compliance with Federal statutes, regulations and the terms and conditions of the Federal award. Per 7 CFR Section 210.8(a), the school food authority shall establish internal controls which ensure the accuracy of meal counts prior to the submission of the monthly claim for reimbursement. '9. Condition: One (1) of the monthly claims for reimbursement reported meal counts in excess of those supported by records of the District. The November 2024 claim amounts were consistent with participation levels and reimbursement amounts in other months tested. No anomalies or fluctuations were identified through analytical procedures; however, required supporting documentation was not maintained. '10. Cause: The District's internal controls over compliance were not functioning effectively to ensure claims for reimbursement were accurately prepared. '11. Effect: Claims could not be verified as allowable and properly supported. '12. Questioned Costs: The following questioned costs were computed based on the excess meals claimed for reimbursement times the applicable reimbursement rate: $719 (Project No. 25-4220-00). '13. Context: From the population of eleven (11) monthly claims for reimbursement, a sample of two (2) claims were selected for testing. We noted one (1) month in which the claims for reimbursement reported meal counts in excess of those supported by records of the District as follows: November 2024: Actual breakfast meals served: 8,408; Breakfast meals claimed for reimbursement: 8,661. The difference was due to one (1) day where the supporting documentation was not maintained. A statistically valid sample was not utilized. '14. Recommendation: We recommend that management review its policies and procedures and implement changes to strengthen internal control over compliance. '15. Management's response: The District agrees with the auditor's finding and recommendation.

FY End: 2025-06-30
Weld County School District Re-1
Compliance Requirement: I
2025-003: Material Weakness in Internal Controls over Compliance with Suspension and Debarment Federal Assistance Listing Number: 10.553, 10.555, and 10.582 Federal Award Year: 2025 Program Title: Child Nutrition Cluster Name of Federal Agency: U.S. Department of Agriculture Name of Pass-Through Entity: Colorado Department of Education COVID-19 Program: No Criteria: 2 CFR §200.303 requires that the grant recipient must establish, document, and maintain effective internal control over the Federal...

2025-003: Material Weakness in Internal Controls over Compliance with Suspension and Debarment Federal Assistance Listing Number: 10.553, 10.555, and 10.582 Federal Award Year: 2025 Program Title: Child Nutrition Cluster Name of Federal Agency: U.S. Department of Agriculture Name of Pass-Through Entity: Colorado Department of Education COVID-19 Program: No Criteria: 2 CFR §200.303 requires that the grant recipient must establish, document, and maintain effective internal control over the Federal award that provides reasonable assurance that the recipient is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These controls should align with the guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control- Integrated Framework” issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition: Based on our sample selection of three vendors for testing, we have identified that two of the three vendors tested did not have adequate verification of suspension and debarment. Upon further testing and discussion, the District does not have internal controls in place to verify suspension and debarment on vendors that are paid greater than or equal to $25,000, as required by 2 CFR 200 for various federal awards. Upon further compliance testing, vendors in our testing were in compliance with the requirement. Without internal controls over compliance, the District may not be able to identify noncompliance with a suspended or debarred vendors in a timely manner and may incur potential questioned costs without knowledge of the noncompliance. Questioned Costs: No questioned costs have been identified. Cause: The District’s internal controls over suspension and debarment requirement were not properly designed or implemented. Effect: Without internal controls over compliance, the District may not be able to identify noncompliance with a suspended or debarred vendors in a timely manner and may incur potential questioned costs without knowledge of the noncompliance. Repeat Finding: No. Recommendation: We recommend that the District implement internal controls over the suspension and debarment requirement and add this requirement to the procurement process at the District. In addition, we recommend that the District periodically review federal expenditure reports to identify vendors that may have been paid with federal grants in excess of the $25,000 suspension and debarment threshold to prevent potential noncompliance. Corrective Action Plan: Reported on page 60.

FY End: 2025-06-30
University of Idaho
Compliance Requirement: I
Criteria or specific requirement: In accordance with Uniform Guidance 2 CFR 180.300, nonfederal entities entering into covered transactions must verify that a party is not suspended or debarred from conducting business with the federal government. That verification may be performed by checking exclusions in SAM.gov, obtaining a certification from the vendor, or including a suspension and debarment clause or condition to the covered transaction. Additionally, pursuant to 2 CFR 200.303, the Univer...

Criteria or specific requirement: In accordance with Uniform Guidance 2 CFR 180.300, nonfederal entities entering into covered transactions must verify that a party is not suspended or debarred from conducting business with the federal government. That verification may be performed by checking exclusions in SAM.gov, obtaining a certification from the vendor, or including a suspension and debarment clause or condition to the covered transaction. Additionally, pursuant to 2 CFR 200.303, the University is required to establish and maintain effective internal controls over federal awards to provide reasonable assurance that federal awards are managed in compliance with applicable federal statutes, regulations, and the terms and conditions of the federal award. Condition: During testing of suspension and debarment compliance for vendors with payments exceeding $25,000, CLA noted that 2 of 40 vendors tested did not have documentation evidencing that the vendor was verified as not suspended or debarred prior to entering into a contract. Questioned costs: None. Context: The University of Idaho entered into transactions with 2 vendors prior to verifying that the vendors were not suspended or debarred. Cause: The University of Idaho's control designed to verify vendor suspension and debarment status prior to contract execution is not operating effectively. Effect: There is an increased risk that suspended or debarred vendors could be contracted using federal funds. Repeat finding: No. Recommendation: CLA recommends that the University implement a more effective suspension and debarment policy and establish corresponding controls to ensure vendor eligibility is verified prior to entering into covered transactions. Views of responsible officials: There is no disagreement with the audit finding.

FY End: 2025-06-30
Commonwealth of Virginia
Compliance Requirement: P
2025-066: Improve Web Application Security Applicable to: Department of Health Assigned Topic: Access Control; Configuration Management; System and Communications Protection Prior Finding Number: N/A Finding Type: Internal Control and Compliance Finding Severity: Significant Deficiency Financial Statement Finding: Yes Federal Awards Finding: Yes ALPT - ALN: WIC Special Supplemental Nutrition Program for Women, Infants, and Children - 10.557 Federal Award ID (Year): 251VA707W1006 (2025) Federal A...

2025-066: Improve Web Application Security Applicable to: Department of Health Assigned Topic: Access Control; Configuration Management; System and Communications Protection Prior Finding Number: N/A Finding Type: Internal Control and Compliance Finding Severity: Significant Deficiency Financial Statement Finding: Yes Federal Awards Finding: Yes ALPT - ALN: WIC Special Supplemental Nutrition Program for Women, Infants, and Children - 10.557 Federal Award ID (Year): 251VA707W1006 (2025) Federal Agency: U.S. Department of Agriculture Compliance Requirement: Other - 2 CFR §200.303(e) Known Questioned Costs: $0 Health does not secure the web application, which supports its system used for eligibility determination for the WIC Special Supplemental Nutrition Program for Women, Infants, and Children federal grant program, with the minimum-security controls required by the Security Standard. We communicated the weaknesses to management in a separate document marked Freedom of Information Act Exempt (FOIAE) under § 2.2-3705.2 of the Code of Virginia due to it containing descriptions of security mechanisms. The weaknesses identified resulted from limited management oversight and staffing constraints within OIM. Health should dedicate the resources necessary to develop and maintain adequate documentation and implement all security controls required by the Security Standard. Addressing these weaknesses will help ensure the confidentiality, integrity, and availability of data and support compliance with the Security Standard. Views of Responsible Officials: The views of responsible officials are included in the report related to their organization, which can be found at www.apa.virginia.gov and, in summary, do not express disagreement with the finding.

FY End: 2025-06-30
Commonwealth of Virginia
Compliance Requirement: P
2025-041: Obtain, Review, and Document System and Organization Control Reports of Third-Party Service Providers Applicable to: Department of Social Services Assigned Topic: Third-Party Service Providers (Non-Information Systems) Prior Finding Number: 2024-010; 2023-085; 2022-089; 2021-019 Finding Type: Internal Control and Compliance Finding Severity: Significant Deficiency Financial Statement Finding: Yes Federal Awards Finding: Yes ALPT - ALN: Supplemental Nutrition Assistance Program – 10.551...

2025-041: Obtain, Review, and Document System and Organization Control Reports of Third-Party Service Providers Applicable to: Department of Social Services Assigned Topic: Third-Party Service Providers (Non-Information Systems) Prior Finding Number: 2024-010; 2023-085; 2022-089; 2021-019 Finding Type: Internal Control and Compliance Finding Severity: Significant Deficiency Financial Statement Finding: Yes Federal Awards Finding: Yes ALPT - ALN: Supplemental Nutrition Assistance Program – 10.551; Summer Electronic Benefit Transfer Program for Children - 10.646 Federal Award ID (Year): 251VA407Q3903 (2025); 251VA407N1175 (2025) Federal Agency: U.S. Department of Agriculture Compliance Requirement: Other - 2 CFR § 200.303(a) Known Questioned Costs: $0 Social Services continues to implement its corrective actions for obtaining, reviewing, and documenting System and Organization Control (SOC) reports of third-party service providers, specifically SOC 1, Type 2 reports. In response to prior audit recommendations, Social Services created a policy and procedure outlining the expectations for obtaining, reviewing, and documenting SOC 1, Type 2 reports and designated contract administrators as the party responsible for implementing the policies and procedures. Additionally, Social Services created training and a questionnaire that will guide contract administrators when conducting their review of the SOC 1, Type 2 report. However, because of the extent of its corrective actions, Social Services was unable to fully implement its policy and procedure as of the end of fiscal year 2025. SOC 1, Type 2 reports address the operating effectiveness of third-party service providers’ internal controls and the effect those internal controls may have on a user entity’s financial statements. Social Services uses third-party service providers to perform functions that are significant to its financial operations such as administering the electronic benefit transfer (EBT) process for several of its public assistance programs. During fiscal year 2025, Social Services’ third-party service provider issued nearly $2 billion in financial assistance to beneficiaries on EBT cards. Commonwealth Accounting Policies and Procedures (CAPP) Manual Topic 10305 requires agencies to have adequate interaction with third-party service providers to appropriately understand their internal control environment and maintain oversight over them to gain assurance over outsourced operations. Additionally, 2 CFR § 200.303(a) requires pass-through entities to establish, document, and maintain effective internal control over federal awards to ensure compliance with applicable laws, regulations, and award terms. Without fully implementing its policy and procedure, Social Services may not fully assess whether its complementary user entity controls are sufficient to support reliance on the third-party service providers’ controls. Additionally, by not obtaining the necessary SOC 1, Type 2 reports timely or properly documenting its review of the reports, Social Services may not timely detect a weakness in a third-party service provider’s environment. Social Services should continue to implement its corrective actions for obtaining, reviewing, and documenting SOC 1, Type 2 reports to comply with the CAPP Manual provisions and federal regulations. Views of Responsible Officials: The views of responsible officials are included in the report related to their organization, which can be found at www.apa.virginia.gov and, in summary, do not express disagreement with the finding.

FY End: 2025-06-30
Commonwealth of Virginia
Compliance Requirement: B
2025-013: Improve Financial Management of Federal Grants Applicable to: Department of Wildlife Resources Assigned Topic: Federal Grants Management Prior Finding Number: N/A Finding Type: Internal Control and Compliance Finding Severity: Material Weakness Financial Statement Finding: No Federal Awards Finding: Yes ALPT - ALN: Sport Fish Restoration - 15.605; Wildlife Restoration and Basic Hunter Education and Safety - 15.611; Enhanced Hunter Education and Safety - 15.626 Federal Award ID (Year): ...

2025-013: Improve Financial Management of Federal Grants Applicable to: Department of Wildlife Resources Assigned Topic: Federal Grants Management Prior Finding Number: N/A Finding Type: Internal Control and Compliance Finding Severity: Material Weakness Financial Statement Finding: No Federal Awards Finding: Yes ALPT - ALN: Sport Fish Restoration - 15.605; Wildlife Restoration and Basic Hunter Education and Safety - 15.611; Enhanced Hunter Education and Safety - 15.626 Federal Award ID (Year): F20AF10048 (2020); F20AF11897 (2020); F21AF02409 (2021); F22AF01121 (2022); F23AF00654 (2023); F23AF03173 (2023); F23AF03185 (2023); F24AF02770 (2024); F24AF02896 (2024); F24AF02903 (2024) Federal Agency: U.S. Department of the Interior Compliance Requirement: Allowable Costs/Cost Principles - 2 CFR § 200.302; 2 CFR § 200.303(a); 2 CFR § 200.305; 2 CFR § 200.510(b); 31 CFR § 205.33 Known Questioned Costs: $0 The Department of Wildlife Resources (Wildlife Resources) should improve its financial management of federal grants and documentation of internal controls to ensure compliance with state and federal requirements. Wildlife Resources has experienced recent turnover in its grants staff positions. Wildlife Resources has hired new staff; however, there was no transition period with the previous staff, and the previous grants staff did not sufficiently document internal controls over the federal programs. Staff have started documenting desk procedures, but agency-wide policies and procedures remain lacking. As such, grants staff did not appear to have sufficient knowledge of statewide policies and procedures to adequately perform the federal grants management processes in accordance with federal regulations and the Commonwealth Accounting Policies and Procedures (CAPP) Manual. We identified the following issues: Wildlife Resources should amend its procedures to comply with CAPP Manual requirements for cash management of federal funds. CAPP Manual Topic 20605 states that two methods of recording "split" funded expenses are acceptable. The method preferred by the State Comptroller is to establish procedures to "split code" the expenses by allocating the disbursement between a state fund and the federal fund at the matching ratio prescribed by the grant or contract. A second, and temporary, funding method allows the agency to charge the original expense to a state fund and subsequently, within seven business days, prepare and submit a general ledger journal in the Commonwealth’s accounting and financial reporting system to charge the federal fund for the federal portion of the original expense, referencing the original voucher in the journal reference line for transparency. If a state agency cannot comply, the agency must request approval from the State Comptroller. Wildlife Resources follows the temporary funding method to record its federal expenses. Wildlife Resources spends from state funds and then performs journal entries to move transactions to the federal fund in bulk with some journal entries representing hundreds of individual transactions, which does not allow for transparency regarding the nature of Wildlife Resources federal expenses. Further, our analysis found that Wildlife Resources enters journal entries for federal drawdowns up to three months after the original transaction date which is not consistent with the seven-day requirement in CAPP Manual Topic 20605. Per 2 Code of Federal Regulations (CFR) § 200.302, a recipient must comply with state laws and procedures for expending and accounting for the State's funds. Additionally, the untimely performance of these extensive journal entries may result in Wildlife Resources recording journal entries in the wrong fiscal year, which could result in inaccurate information within the Commonwealth’s Annual Comprehensive Financial Report. Wildlife Resources does not maintain adequate support for its journal entries. CAPP Manual Topic 20405 requires the agency to retain sufficient supporting documentation to provide auditable records containing evidence of required coding elements for journal entries. Wildlife Resources’ journal entries lack documentation related to changes in coding. Further, Wildlife Resources does not maintain supporting documentation for journal entries in one accessible location which would allow for sufficient supervisory review. Not maintaining adequate supporting documentation over journal entries increases the risk of inaccurate or fraudulent transactions. Wildlife Resources also does not have policies and procedures in place that detail how it creates the journal entries, what type of documentation to retain to support journal entries, or how Wildlife Resources ensures it only moves allowable costs to the federal fund. Title 2 CFR § 200.303(a) requires recipients to establish, document, and maintain effective internal control over the federal award that provides reasonable assurance that the recipient or subrecipient is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award. During fiscal year 2025, in response to our Office’s 2024 Internal Control Questionnaire Review, Wildlife Resources established a bimonthly drawdown and journal entry schedule to ensure timely drawdown of federal funds to reimburse expenses originally incurred within state funds and to assist in remediation of its cash flow issues. Per 31 CFR § 205.33, a state must minimize the time between the drawdown of federal funds from the federal government and their disbursement for federal program purposes in accordance with the actual, immediate cash requirements of the state. The timing and amount of funds transfers must be as close as is administratively feasible to a state's actual cash outlay for direct program costs and the proportionate share of any allowable indirect costs. However, based on our analysis of drawdowns, while Wildlife Resources has made progress in the rate of drawdowns since the previous review, due to staff shortages, Wildlife Resources has not fully followed its drawdown schedule to ensure timely drawdowns of federal funds, which could exacerbate the agency’s cash flow issues. Specifically, the drawdown schedule included twenty planned drawdowns, however Wildlife Resources completed only eleven (55%) in accordance with that schedule. Furthermore, Wildlife Resources does not have policies and procedures in place over the completion of drawdowns as required by 2 CFR § 200.302, which requires a recipient to have written procedures to implement the requirements of 2 CFR § 200.305 regarding federal drawdowns. Wildlife Resources did not record program income revenue of approximately $2.3 million in the correct fiscal year for the Fish and Wildlife Cluster. Wildlife Resources recorded the program income received in fiscal year 2025 in a suspense account and did not distribute the income to the proper revenue account until fiscal year 2026. CAPP Manual Topic 20205 requires recording of all state receipts in the Commonwealth’s accounting and financial reporting system in a timely manner within three business days of the deposit. Additionally, the Department of Accounts (Accounts) Fiscal Year-End Closing Procedures require agencies to certify that they properly distributed balances to the correct accounts before final close of Commonwealth’s accounting and financial reporting system. By not properly recording program income, Wildlife Resources may misrepresent financial information to the federal government and report information that does not agree with its accounting records. Wildlife Resources reported federal expenses on its Schedule of Expenditures of Federal Awards (SEFA), a schedule that details Wildlife Resources’ federal expenses for fiscal year 2025, that did not agree to its underlying accounting records. Wildlife Resources reported federal expenses in the SEFA that it recorded as state funds in the Commonwealth’s accounting and financial reporting system due to considering journal entries that they did not record in the system until the next fiscal year. Due to these issues and preparation of the SEFA by a member of management on long-term leave who was not available during the audit, Wildlife Resources could not support amounts totaling over $660,000 in its SEFA. Additionally, Wildlife Resources does not have documented procedures outlining its process for preparing the SEFA in accordance with 2 CFR § 200.510(b), which states that the auditee must prepare a schedule of expenditures of federal awards for the period covered by the auditee’s financial statements which must include the total federal awards expended as determined in accordance with 2 CFR § 200.502. Accounts’ Office of the Comptroller’s Directive No. 1-25 (Comptroller’s Directive) also provides specific directions for compiling the SEFA and supporting schedules to support its preparation of the Commonwealth’s SEFA and related disclosures. Furthermore, the Comptroller’s Directive states that an agency must ensure that it has internal controls in place to avoid material misstatements and/or misclassifications in the attachments and other financial information submitted to Accounts for inclusion in the Commonwealth’s Single Audit. By not implementing adequate internal controls over financial reporting, Wildlife Resources cannot provide reasonable assurance that the financial information it submits to Accounts for inclusion in the Commonwealth’s Single Audit is free of material misstatements. Because of the scope of the matters and errors noted above, we consider this finding to be a material weakness in internal control. Wildlife Resources should improve its financial management of federal funds and documentation of internal controls to ensure compliance with state and federal requirements. The need for strong internal controls is especially important given that Wildlife Resources is exploring additional federal funding opportunities. Wildlife Resources should work with Accounts to develop and implement a federal grants management process that complies with the CAPP Manual. Wildlife Resources should improve its process and controls related to federal fund drawdowns to ensure timely reimbursement of expenses within federal limitations. Further, Wildlife Resources should also improve its controls and procedures related to journal entry processing to ensure it retains adequate support for all entries and enters the entries timely. Additionally, Wildlife Resources should perform a thorough review of its SEFA before submitting it to Accounts and retain supporting documentation to support the SEFA. Finally, Wildlife Resources should develop policies and procedures over all federal grants processes including all compliance requirements. These improvements combined are necessary to ensure accurate accounting and financial reporting in accordance with the CAPP Manual, the Code of Federal Regulations, the Comptroller’s Directives, and applicable accounting standards. Views of Responsible Officials: The views of responsible officials are included in the report related to their organization, which can be found at www.apa.virginia.gov and, in summary, do not express disagreement with the finding.

FY End: 2025-06-30
Commonwealth of Virginia
Compliance Requirement: P
2025-070: Continue to Strengthen Internal Controls over the Vocational Rehabilitation Case Management System Applicable to: Department for Aging and Rehabilitative Services Assigned Topic: Access Control; Audit and Accountability; Information Security Roles and Responsibilities; Personnel Security; Planning; Risk Assessment Prior Finding Number: N/A Finding Type: Internal Control and Compliance Finding Severity: Significant Deficiency Financial Statement Finding: No Federal Awards Finding: Yes A...

2025-070: Continue to Strengthen Internal Controls over the Vocational Rehabilitation Case Management System Applicable to: Department for Aging and Rehabilitative Services Assigned Topic: Access Control; Audit and Accountability; Information Security Roles and Responsibilities; Personnel Security; Planning; Risk Assessment Prior Finding Number: N/A Finding Type: Internal Control and Compliance Finding Severity: Significant Deficiency Financial Statement Finding: No Federal Awards Finding: Yes ALPT - ALN: Rehabilitation Services Vocational Rehabilitation Grants to States - 84.126 Federal Award ID (Year): H126A240069 (2024); H126A250069 (2025); H126A240070 (2024); H126A250070 (2025) Federal Agency: U.S. Department of Education Compliance Requirement: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 The Department for Aging and Rehabilitative Services (Aging and Rehabilitative Services) continues to strengthen internal controls over its Vocational Rehabilitation (VR) case management system. To comply with the provisions in the Commonwealth’s IT Security Audit Standard, SEC502 (IT Audit Standard), Aging and Rehabilitative Services’ Internal Audit Division (Internal Audit) conducted an audit over the agency’s VR case management system and concluded fieldwork in December 2024. The audit included a risk-based selection of security controls from the Commonwealth’s Information Security Standard, SEC530 (Security Standard) sections and control families, in addition to the controls in the IT Audit Standard. Internal Audit identified 25 total findings affecting several control families and sections in the Security Standard and IT Audit Standard. We elected not to disclose the specific findings because they are considered to be Freedom of Information Act exempt (FOIAE) under § 2.2-3705.2 of the Code of Virginia due to containing descriptions of security mechanisms. Aging and Rehabilitative Services developed corrective action plans to remediate the findings Internal Audit communicated in its report and has resolved two of the 25 findings (8%) as of the end of fiscal year 2025. Internal Audit noted that many of the reported findings were the result of insufficient agency resources and/or a lack of formal policies and procedures. The Security Standard requires that system owners maintain compliance with Commonwealth of Virginia information security policies and standards in all IT system activities. Additionally, Title 2 Code of Federal Regulations (CFR) § 200.303(e) requires federal grant recipients to take reasonable cybersecurity and other measures to safeguard information including protected personally identifiable information (PII) and other types of information. Inadequate or lacking IT security controls could potentially lead to a data breach or unauthorized access to confidential and mission-critical data, resulting in data corruption, data loss, or system disruption, if accessed by either internal or external malicious attacker. We recommend that Aging and Rehabilitative Services’ management continue to dedicate the necessary resources to remediate the internal control deficiencies noted in the Internal Audit report covering the VR case management system. Views of Responsible Officials: The views of responsible officials are included in the report related to their organization, which can be found at www.apa.virginia.gov and, in summary, do not express disagreement with the finding.

FY End: 2025-06-30
Commonwealth of Virginia
Compliance Requirement: L
2025-015: Implement Internal Controls over TANF Federal Performance Reporting Applicable to: Department of Social Services Assigned Topic: Federal Grants Management Prior Finding Number: 2024-101; 2023-105; 2022-103 Finding Type: Internal Control and Compliance Finding Severity: Material Weakness Financial Statement Finding: No Federal Awards Finding: Yes ALPT - ALN: Temporary Assistance for Needy Families (TANF) - 93.558 Federal Award ID (Year): 2501VATANF (2025) Federal Agency: U.S. Department...

2025-015: Implement Internal Controls over TANF Federal Performance Reporting Applicable to: Department of Social Services Assigned Topic: Federal Grants Management Prior Finding Number: 2024-101; 2023-105; 2022-103 Finding Type: Internal Control and Compliance Finding Severity: Material Weakness Financial Statement Finding: No Federal Awards Finding: Yes ALPT - ALN: Temporary Assistance for Needy Families (TANF) - 93.558 Federal Award ID (Year): 2501VATANF (2025) Federal Agency: U.S. Department of Health and Human Services Compliance Requirement: Reporting - 45 CFR § 265.7(b) Known Questioned Costs: $0 Benefit Programs does not have adequate internal controls in place to ensure accurate reporting in the Administration for Children and Families’ (ACF) 199 TANF Data Report (ACF-199) and 209 Separate State Programs – Maintenance-of-Effort Data Report (ACF-209). Social Services submits this data to ACF quarterly, and ACF uses the data to determine whether the Commonwealth met the minimum work participation requirements for the Temporary Assistance for Needy Families (TANF) federal grant program. Benefit Programs uses a third-party service provider to produce the ACF-199 and ACF-209 reports and relies solely on their internal controls during the data extraction and data reporting process as of the end of fiscal year 2025. In response to the prior audit findings, Benefit Programs made significant revisions to its planned corrective actions to better address the weaknesses identified in prior audits. Benefit Programs’ revised planned corrective actions include inventorying and documenting the ACF-199 and ACF-209 reporting requirements, researching previous reporting errors to determine their cause, developing change requests to address reporting format adjustments, and partnering with their Business Operations Unit to develop internal controls for validating data from its third-party service provider. However, because of the extent of its corrective actions, Benefit Programs was unable to implement all of them by the end of fiscal year 2025. Benefit Programs anticipates completing its corrective actions for this audit finding by the end of fiscal year 2026. We audited 60 cases and identified 30 instances (50%) where the third-party service provider did not report one or more key line items accurately based on the data Social Services maintains in its case management system or other supporting data, and Benefit Programs did not detect or correct these errors before the third-party service provider submitted the data to ACF. Specifically, we noted that Benefit Programs did not accurately report the following key line items for the ACF-199 and ACF-209 reports submitted during fiscal year 2025: Benefit Programs did not accurately report the “Work Participation Status” key line item for 29 out of 60 (48%) cases tested. Benefit Programs did not accurately report the “Hours of Participation (Job Search and Job Readiness Assistance)” key line item for five out of 57 (9%) cases tested. Benefit Programs did not accurately report the “Type of Family for Work Participation” key line item for one out of 57 (2%) cases tested. Benefit Programs did not accurately report the “TANF Family Exempt from Time Limits” key line item for one out of 57 (2%) cases tested. Benefit Programs did not accurately report the “Number of Months Countable Toward the Federal Time Limit” key line item for one out of 57 (2%) cases tested. Benefit Programs did not accurately report the “Unsubsidized Employment” key line item for one out of 57 (2%) cases tested. Title 45 CFR § 265.7(b) requires States to have complete and accurate reports, which means that the reported data accurately reflects information available in case records, are free of computational errors, and are internally consistent. Additionally, 2 CFR § 200.303(a) requires pass-through entities to establish, document, and maintain effective internal control over federal awards to ensure compliance with applicable laws, regulations, and award terms. Reporting potentially inaccurate or incomplete information prevents ACF from adequately monitoring the Commonwealth’s work participation rates and the overall performance for the TANF federal grant program. Further, ACF can impose a penalty if it finds Social Services did not meet statutory required work participation rates. Because of the scope of this matter and errors noted above, we consider it to be a material weakness in internal control. Additionally, we believe this matter represents material noncompliance since Social Services did not fully comply with the provisions at 45 CFR § 265.7(b). Benefit Programs should continue to implement its planned corrective actions to ensure accurate reporting in the ACF-199 and ACF-209 TANF federal performance reports. Views of Responsible Officials: The views of responsible officials are included in the report related to their organization, which can be found at www.apa.virginia.gov and, in summary, do not express disagreement with the finding.

FY End: 2025-06-30
Commonwealth of Virginia
Compliance Requirement: P
2025-019: Perform Analysis to Identify Service Provider Agencies That Perform Significant Fiscal Processes Applicable to: Department of Social Services Assigned Topic: Federal Grants Management Prior Finding Number: 2022-104 Finding Type: Internal Control and Compliance Finding Severity: Significant Deficiency Financial Statement Finding: No Federal Awards Finding: Yes ALPT - ALN: Social Services Block Grant - 93.667 Federal Award ID (Year): 2501VASOSR (2025) Federal Agency: U.S. Department of H...

2025-019: Perform Analysis to Identify Service Provider Agencies That Perform Significant Fiscal Processes Applicable to: Department of Social Services Assigned Topic: Federal Grants Management Prior Finding Number: 2022-104 Finding Type: Internal Control and Compliance Finding Severity: Significant Deficiency Financial Statement Finding: No Federal Awards Finding: Yes ALPT - ALN: Social Services Block Grant - 93.667 Federal Award ID (Year): 2501VASOSR (2025) Federal Agency: U.S. Department of Health and Human Services Compliance Requirement: Other - 2 CFR § 200.303(a) Known Questioned Costs: $0 Consistent with prior years, Social Services is not performing a comprehensive analysis of service provider agencies during its Agency Risk Management and Internal Control Standards (ARMICS) review to determine if they perform significant fiscal processes. Significant fiscal processes include, but are not limited to, programs or activities that have a high-degree of public visibility; represent areas of concern and high risk to mission-critical business processes for agency managers and stakeholders; or have a significant effect on general ledger account balances. Social Services transferred approximately $53 million to other state agencies or institutions from various federal grant programs during the fiscal year to administer certain grants management functions on its behalf. CAPP Manual Topic 10305 states an agency (primary agency) may use another agency (service provider agency) to perform significant fiscal processes for the primary agency. ARMICS states that decisions about significance should consider not only quantitative, but also qualitative factors, and managers should define any fiscal process as significant if errors or misstatements in the process could have adverse consequences for legal or regulatory obligations. Further, CAPP Manual Topic 10305 states that if a primary agency identifies a service provider agency that performs significant fiscal processes, the primary agency must have adequate interaction with the service provider agency to gain an appropriate understanding of the service provider agency’s control environment and obtain assurances from the service provider agency regarding the state of internal control applicable to the significant fiscal processes performed. Finally, 2 CFR §200.303(a) requires pass-through entities to establish, document, and maintain effective internal control over federal awards to ensure compliance with applicable laws, regulations, and award terms. During its analysis of service provider agencies, Social Services only considered service provider agencies that have a significant effect on general ledger account balances but did not consider qualitative factors like degree of public visibility, areas of concern, or risk to mission-critical business processes. Additionally, Social Services inadvertently indicated that corrective action for this finding was complete during its transition of corrective action plan responsibilities. Without performing a comprehensive analysis of service provider agencies during its ARMICS review, Social Services cannot provide assurance that it obtained adequate coverage over service provider agency operations that are quantitatively or qualitatively significant to its operations. Social Services should identify all service provider agencies and determine which entities provide significant fiscal processes. Thereafter, Social Services should perform a comprehensive analysis to determine if it has an appropriate understanding of the agency’s control environment and obtain assurance from the service provider agency regarding the state of internal control applicable to the significant fiscal processes performed. Views of Responsible Officials: The views of responsible officials are included in the report related to their organization, which can be found at www.apa.virginia.gov and, in summary, do not express disagreement with the finding.

FY End: 2025-06-30
Commonwealth of Virginia
Compliance Requirement: L
2025-025: Strengthen Internal Controls over FFATA Reporting Applicable to: Department of Social Services Assigned Topic: Federal Grants Management Prior Finding Number: 2024-106; 2023-107; 2022-106 Finding Type: Internal Control and Compliance Finding Severity: Significant Deficiency Financial Statement Finding: No Federal Awards Finding: Yes ALPT - ALN: Temporary Assistance for Needy Families (TANF) - 93.558; Foster Care-Title IV-E - 93.658; Social Services Block Grant - 93.667 Federal Award ID...

2025-025: Strengthen Internal Controls over FFATA Reporting Applicable to: Department of Social Services Assigned Topic: Federal Grants Management Prior Finding Number: 2024-106; 2023-107; 2022-106 Finding Type: Internal Control and Compliance Finding Severity: Significant Deficiency Financial Statement Finding: No Federal Awards Finding: Yes ALPT - ALN: Temporary Assistance for Needy Families (TANF) - 93.558; Foster Care-Title IV-E - 93.658; Social Services Block Grant - 93.667 Federal Award ID (Year): 2501VATANF (2025); 2501VASOSR (2025); 2501VAFOST (2025) Federal Agency: U.S. Department of Health and Human Services Compliance Requirement: Reporting - 2 CFR Part 170 Appendix A; 2 CFR § 200.303(a) Known Questioned Costs: $0 Social Services Division of Finance (Finance) continues to lack adequate internal control over Federal Funding Accountability and Transparency Act (FFATA) reporting. FFATA reports disclose how entities and organizations are obligating federal funds. During fiscal year 2025, Social Services disbursed over $700 million in federal funds from roughly 4,800 subawards. In response to prior audit recommendations, Finance revised its FFATA reporting policy to establish procedures for the timely completion and submission of required reports and began submitting FFATA reports to the federal government. However, we noted the following deviations from Finance’s FFATA reporting policy while auditing new subawards granted for the Foster Care, Social Services Block Grant, and TANF federal grant programs during fiscal year 2025: Finance’s Federal Reporting Unit did not file any FFATA reporting submissions for non-locality subrecipients that received TANF funds from the Division of Family Services and the Division of Community and Volunteer Services. These divisions disbursed approximately $10.4 million from 39 new TANF subawards during fiscal year 2025. In a sample of seven report submissions, we identified the following inaccuracies in the System for Award Management (SAM.gov) for TANF subawards that Benefit Programs awarded to non-locality subrecipients: The Federal Reporting Unit reported an inaccurate subaward obligation/action date for four (57%) report submissions. The Federal Reporting Unit reported an inaccurate subaward Unique Entity Identifier (UEI) for one (14%) report submission. The Federal Reporting Unit reported an inaccurate subaward name for one (14%) report submission. The Federal Reporting Unit did not submit FFATA reporting submissions timely for the TANF, Social Services Block Grant, and Foster Care Title IV-E federal grant programs. The Federal Reporting Unit’s delays in FFATA reporting ranged from three months to over one year. Title 2 CFR Part 170 Appendix A requires non-federal entities to report each obligating action that equals or exceeds $30,000 to SAM.gov by the end of the month following the obligating action. This requirement also applies to any subaward modification that increases the award amount to equal or exceed $30,000. Additionally, 2 CFR §200.303(a) requires pass-through entities to establish, document, and maintain effective internal control over federal awards to ensure compliance with applicable laws, regulations, and award terms. Finance uses a decentralized approach to fulfil its FFATA reporting responsibilities since it does not determine which subrecipients will receive federal funding. To mitigate the risk of reporting incomplete and inaccurate information to SAM.gov, Finance and the programmatic divisions developed a Budget Solicitation Form to track and monitor Social Services’ subaward obligations. Additionally, Finance’s Contract and Procurement Team maintains a list of subawards that it makes available to all parties on Social Services’ intranet. Finally, Finance’s Financial Systems Team developed a report from Social Services’ financial accounting and reporting system that reports expenditures by federal program and subaward. However, Finance’s FFATA reporting policy did not indicate how the Federal Reporting Unit should use this information to monitor FFATA reporting compliance. As a result, the Federal Reporting Unit did not use this information, in its entirety, and did not identify the deviations noted above during the normal course of its operations. When Social Services does not upload all obligating actions meeting the reporting threshold to SAM.gov, as required, a citizen or federal official may have a distorted view of how Social Services is obligating federal funds. Finance should update its FFATA reporting policy to document what sources of information the Federal Reporting Unit should use to monitor compliance with the FFATA reporting requirements and apply appropriate oversight to ensure the Federal Reporting Unit submits complete and accurate information to SAM.gov. Views of Responsible Officials: The views of responsible officials are included in the report related to their organization, which can be found at www.apa.virginia.gov and, in summary, do not express disagreement with the finding.

FY End: 2025-06-30
Commonwealth of Virginia
Compliance Requirement: M
2025-014: Perform Responsibilities Outlined in the Agency Monitoring Plan Applicable to: Department of Social Services Assigned Topic: Federal Grants Management Prior Finding Number: 2024-082; 2023-097; 2022-011; 2021-070; 2020-074; 2019-090; 2018-093 Finding Type: Internal Control and Compliance Finding Severity: Material Weakness Financial Statement Finding: Yes Federal Awards Finding: Yes ALPT - ALN: Grants to States for Medicaid – 93.778 Federal Award ID (Year): 2505VA5MAP (2025) Federal Age...

2025-014: Perform Responsibilities Outlined in the Agency Monitoring Plan Applicable to: Department of Social Services Assigned Topic: Federal Grants Management Prior Finding Number: 2024-082; 2023-097; 2022-011; 2021-070; 2020-074; 2019-090; 2018-093 Finding Type: Internal Control and Compliance Finding Severity: Material Weakness Financial Statement Finding: Yes Federal Awards Finding: Yes ALPT - ALN: Grants to States for Medicaid – 93.778 Federal Award ID (Year): 2505VA5MAP (2025) Federal Agency: U.S. Department of Health and Human Services Compliance Requirement: Subrecipient Monitoring - 2 CFR § 200.303(a); 2 CFR § 200.332 Known Questioned Costs: $0 The Department of Social Services (Social Services) Compliance Division (Compliance) continues not to adhere to its established approach for overseeing agency-wide subrecipient monitoring, as outlined in its Agency Monitoring Plan. In response to the prior audit recommendations, Compliance made significant revisions to its Agency Monitoring Plan to include tools for tracking and monitoring division-level subrecipient monitoring reviews, began meeting monthly with division-level subrecipient monitoring coordinators, and developed a quarterly variance report that it will use to report the status of the agency’s subrecipient monitoring activities to Social Services’ Executive Team. Compliance adopted its revised Agency Monitoring Plan in July 2025 and anticipates completing the remainder of its corrective actions by the end of fiscal year 2026. Additionally, Social Services hired a director to lead Compliance in fiscal year 2025. Social Services engaged a consultant in April 2025 to help develop remediation plans for its previous audit findings. However, because of the extent of its corrective actions, Compliance could not design and implement its corrective actions by the end of fiscal year 2025. As a result, we identified the following deviations from the Agency Monitoring Plan: Compliance did not review programmatic division annual subrecipient monitoring plans to ensure they implement a risk-based approach. The Agency Monitoring Plan states that Compliance will use a monitoring plan checklist to evaluate and determine if all the required elements for subrecipient monitoring are present in each division’s plan. As a result, Compliance was not aware that the Division of Benefit Programs' (Benefit Programs) non-locality risk assessment template did not include all required risk factors outlined in the Agency Monitoring Plan. Compliance did not confirm that division-level subrecipient monitoring coordinators are maintaining monitoring documentation in Compliance’s centralized repository. As a result, Compliance could not confirm the completeness of the centralized repository. The Agency Monitoring Plan requires that Compliance monitor whether divisions post monitoring review reports to the centralized repository. Compliance did not review each division’s monitoring activities nor provide the required quarterly reports of variances and noncompliance from the Agency Monitoring Plan to Social Services’ Executive Team. As a result, Compliance and the Executive Team were not aware that Benefit Programs did not comply with certain aspects of its subrecipient monitoring plan, such as maintaining complete sampling documentation, monitoring records and reports, and documenting subsequent corrective action. Title 2 U.S. Code of Federal Regulations (CFR) § 200.303(a) requires pass-through entities to establish, document, and maintain effective internal control over federal awards to ensure compliance with applicable laws, regulations, and award terms. Further, 2 CFR § 200.332 requires pass-through entities to monitor subrecipients to ensure they meet federal requirements. Finally, the Agency Monitoring Plan establishes Compliance’s responsibility to centrally coordinate, review, and report on subrecipient monitoring activities across all divisions. Compliance is responsible for agency-wide compliance and risk mitigation that helps ensure adherence to state and federal legal and regulatory standards. During fiscal year 2025, Social Services disbursed approximately $700 million in federal funds to roughly 350 subrecipients from 37 federal grant programs. Without performing the responsibilities in the Agency Monitoring Plan, Compliance cannot provide the Executive Team with assurance that Social Services’ subrecipient monitoring efforts are adequate to comply with the regulations at 2 CFR § 200.332. Additionally, Compliance places Social Services at risk of disallowed expenditures and/or suspension or termination of its federal awards by not monitoring the agency’s subrecipient monitoring activities. Because of the scope of this matter and the magnitude of Social Services’ subrecipient monitoring responsibilities, we consider these weaknesses collectively to create a material weakness in internal controls since Compliance did not implement its corrective actions by the end of fiscal year 2025. Compliance should continue to implement its planned corrective actions to perform the responsibilities outlined in its Agency Monitoring Plan. Views of Responsible Officials: The views of responsible officials are included in the report related to their organization, which can be found at www.apa.virginia.gov and, in summary, do not express disagreement with the finding.

FY End: 2025-06-30
Commonwealth of Virginia
Compliance Requirement: P
2025-043: Improve IT Third-Party Oversight Process Applicable to: Department of Medical Assistance Services Assigned Topic: Third-Party Service Providers (Information Systems) Prior Finding Number: 2024-017; 2023-086; 2022-090 Finding Type: Internal Control and Compliance Finding Severity: Significant Deficiency Financial Statement Finding: Yes Federal Awards Finding: Yes ALPT - ALN: Grants to States for Medicaid – 93.778 Federal Award ID (Year): 2505VA5MAP (2025) Federal Agency: U.S. Department...

2025-043: Improve IT Third-Party Oversight Process Applicable to: Department of Medical Assistance Services Assigned Topic: Third-Party Service Providers (Information Systems) Prior Finding Number: 2024-017; 2023-086; 2022-090 Finding Type: Internal Control and Compliance Finding Severity: Significant Deficiency Financial Statement Finding: Yes Federal Awards Finding: Yes ALPT - ALN: Grants to States for Medicaid – 93.778 Federal Award ID (Year): 2505VA5MAP (2025) Federal Agency: U.S. Department of Health and Human Services Compliance Requirement: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Medical Assistance Services is continuing its efforts to implement its formal process to maintain oversight for three of its information technology (IT) third-party service providers that manage and support its Medicaid management system. The Medicaid management system encompasses different functions, such as member and provider reporting, financial reporting, and federal reporting. Medical Assistance Services has collected data since the prior audit to implement its IT Third Party Risk Management Procedure, which was effective in February 2024, and comply with its IT System and Services Acquisition Policy. However, Medical Assistance Services is still determining the best method to consistently capture the necessary data, which has resulted in the agency not yet verifying the following required controls and processes for one of the Medicaid management system IT service providers not covered by the Virginia Information Technologies Agency’s (VITA) Commonwealth of Virginia Risk and uthority Management Program. Medical Assistance Services does not confirm the geographic location of sensitive data monthly for the IT service providers. Without confirming the geographic location of sensitive data, Medical Assistance Services may be unable to enforce contract requirements, laws, and standards due to the data falling outside the United States’ jurisdiction. Medical Assistance Services does not confirm whether IT service providers perform vulnerability scans every 90 days. By not obtaining and analyzing the vulnerability scan results from the IT service provider, Medical Assistance Services increases the risk that the IT service providers are not remediating legitimate vulnerabilities in a timely manner. Medical Assistance Services has required additional time to collaborate with its IT service provider to adjust its data collection methods and verification processes. Medical Assistance Services also had to prioritize its resources to remediate ongoing findings from previous audits. Medical Assistance Services should continue its efforts to implement its IT Third Party Risk Management Procedure and ensure those tasked with monitoring IT service providers confirm the geographic location of sensitive data, the provider’s performance of vulnerability scanning, and remediation efforts per the Security Standard. Medical Assistance Services should also ensure the individuals responsible for monitoring consistently perform formal oversight processes in a timely manner, which will help maintain the confidentiality, integrity, and availability of sensitive and mission critical data. Views of Responsible Officials: The views of responsible officials are included in the report related to their organization, which can be found at www.apa.virginia.gov and, in summary, do not express disagreement with the finding.

FY End: 2025-06-30
Commonwealth of Virginia
Compliance Requirement: P
2025-048: Improve Information Security Program and IT Governance Applicable to: Department of Social Services Assigned Topic: Information Security Roles and Responsibilities Prior Finding Number: 2024-035; 2023-027; 2022-022 Finding Type: Internal Control and Compliance Finding Severity: Significant Deficiency Financial Statement Finding: Yes Federal Awards Finding: Yes ALPT - ALN: Grants to States for Medicaid – 93.778 Federal Award ID (Year): 2505VA5MAP (2025) Federal Agency: U.S. Department o...

2025-048: Improve Information Security Program and IT Governance Applicable to: Department of Social Services Assigned Topic: Information Security Roles and Responsibilities Prior Finding Number: 2024-035; 2023-027; 2022-022 Finding Type: Internal Control and Compliance Finding Severity: Significant Deficiency Financial Statement Finding: Yes Federal Awards Finding: Yes ALPT - ALN: Grants to States for Medicaid – 93.778 Federal Award ID (Year): 2505VA5MAP (2025) Federal Agency: U.S. Department of Health and Human Services Compliance Requirement: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Social Services continues to improve its information security program and information technology (IT) governance structure to address the weaknesses identified in prior audits. In August 2024, Social Services established the Innovation, Architecture, and Governance (IAG) Team to coordinate efforts among the Technology Services Division (TSD), the Cybersecurity Team, the Information Security Risk Management (ISRM) Division, and the Executive Team. The IAG Team established a roadmap to track the tasks, task owners, and target dates to bring the information security program in compliance with the Commonwealth’s Information Security Standard, SEC530 (Security Standard). The IAG Team also oversees regularly scheduled coordination working sessions to obtain updates from the owners assigned to each task in the roadmap. Additionally, Social Services changed the reporting structure for the ISRM Division, including the Information Security Officer (ISO). The ISO now reports directly to Social Services’ Commissioner. However, because of the extent of its corrective actions, Social Services has not yet accomplished all the tasks in the established roadmap to complete corrective actions to bring the information security program in compliance with the Security Standard. Although Social Services continues to make significant progress towards prioritizing and implementing IT governance changes to address existing control deficiencies, the IAG Team needed time to establish a roadmap and coordinate efforts among the Cybersecurity Team, the TSD, the IRSM Division, and the Executive Team to be able to ensure effective implementation of the information security program and controls. Due to the number and magnitude of the issues, it will take time for Social Services to complete remediation efforts initiated according to the established roadmap. The Security Standard requires agency heads to maintain a documented and effectively communicated information security program that is sufficient to protect the agency’s IT systems. Unidentified or unresolved vulnerabilities in Social Services’ IT environment could result in a data breach or unauthorized access to confidential and mission-critical data, leading to data corruption, data loss, or system disruption, if accessed by either internal or external malicious attackers. The TSD, the Cybersecurity Team, the ISRM Division, and Social Services’ Executive Team should continue to work together and follow the direction of the IAG Team to improve compliance with the Security Standard. As part of the continued effort, the Cybersecurity Team, the TSD, and the IRSM Division should continue to evaluate IT resource levels to ensure sufficient resources are available and dedicated to prioritizing and implementing the planned IT governance structure changes. Views of Responsible Officials: The views of responsible officials are included in the report related to their organization, which can be found at www.apa.virginia.gov and, in summary, do not express disagreement with the finding.

FY End: 2025-06-30
Commonwealth of Virginia
Compliance Requirement: P
2025-049: Identify and Assign Security Roles for Each Sensitive IT System Applicable to: Department of Social Services Assigned Topic: Information Security Roles and Responsibilities Prior Finding Number: N/A Finding Type: Internal Control and Compliance Finding Severity: Significant Deficiency Financial Statement Finding: Yes Federal Awards Finding: Yes ALPT - ALN: Grants to States for Medicaid – 93.778 Federal Award ID (Year): 2505VA5MAP (2025) Federal Agency: U.S. Department of Health and Hum...

2025-049: Identify and Assign Security Roles for Each Sensitive IT System Applicable to: Department of Social Services Assigned Topic: Information Security Roles and Responsibilities Prior Finding Number: N/A Finding Type: Internal Control and Compliance Finding Severity: Significant Deficiency Financial Statement Finding: Yes Federal Awards Finding: Yes ALPT - ALN: Grants to States for Medicaid – 93.778 Federal Award ID (Year): 2505VA5MAP (2025) Federal Agency: U.S. Department of Health and Human Services Compliance Requirement: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Social Services’ ISO did not identify a system owner for each sensitive IT system and ensure system owners assigned a data owner, system administrator, and data custodian for each sensitive IT system. Social Services manages and maintains 80 sensitive IT systems that require security role assignments. Specifically, our audit identified: The ISO did not identify a system owner for two of its 80 (3%) sensitive systems. The ISO did not confirm that system owners assigned a data owner for five of 80 (6%) sensitive systems. The ISO did not confirm that system owners assigned a system administrator for 40 of 80 (50%) sensitive systems. The ISO did not confirm that system owners assigned a data custodian for ten of 80 (13%) sensitive systems. The Security Standard requires that the agency head or designee identify a system owner for each agency sensitive IT system and requires the system owner to assign a data owner, data custodian, and system administrator for each agency sensitive IT system. Without assigning security roles, Social Services lacks accountability, which may lead to a failure to enforce security policies and lead to a higher risk of security incidents. Social Services designated the ISO with the responsibility for ensuring that it assigns security roles for each sensitive IT system. However, due to an oversight, the ISO did not assign security roles for each sensitive IT system. The ISO should identify a system owner for each sensitive IT system and ensure system owners assign a data owner, system administrator, and data custodian for each sensitive IT system to meet the Security Standard requirements and to maintain the confidentiality, integrity, and availability of sensitive and mission-critical data. Views of Responsible Officials: The views of responsible officials are included in the report related to their organization, which can be found at www.apa.virginia.gov and, in summary, do not express disagreement with the finding.

FY End: 2025-06-30
Commonwealth of Virginia
Compliance Requirement: P
2025-050: Continue Improving IT Risk Management Program Applicable to: Department of Social Services Assigned Topic: Planning; Risk Assessment Prior Finding Number: 2024-024; 2023-014; 2022-030; 2021-026; 2020-027; 2019-063; 2018-025 Finding Type: Internal Control and Compliance Finding Severity: Significant Deficiency Financial Statement Finding: Yes Federal Awards Finding: Yes ALPT - ALN: Grants to States for Medicaid – 93.778 Federal Award ID (Year): 2505VA5MAP (2025) Federal Agency: U.S. Dep...

2025-050: Continue Improving IT Risk Management Program Applicable to: Department of Social Services Assigned Topic: Planning; Risk Assessment Prior Finding Number: 2024-024; 2023-014; 2022-030; 2021-026; 2020-027; 2019-063; 2018-025 Finding Type: Internal Control and Compliance Finding Severity: Significant Deficiency Financial Statement Finding: Yes Federal Awards Finding: Yes ALPT - ALN: Grants to States for Medicaid – 93.778 Federal Award ID (Year): 2505VA5MAP (2025) Federal Agency: U.S. Department of Health and Human Services Compliance Requirement: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Social Services continues to not have a formal and effective IT Risk Management program that aligns with the requirements in the Security Standard. Specifically, Social Services does not: verify and validate the data and system sensitivity ratings of its systems to ensure proper IT system sensitivity ratings. ensure that its sensitive systems list aligns with completed data classifications. create or annually review risk assessments for each sensitive system. create or annually review system security plans for each sensitive system. implement risk treatment plans to mitigate risks following its sensitive systems’ risk assessments. We communicated the details of these weaknesses to management in a separate document marked FOIAE under § 2.2-3705.2 of the Code of Virginia, due to it containing descriptions of security mechanisms. The Security Standard requires Social Services to implement certain controls that reduce unnecessary risk to the confidentiality, integrity, and availability of Social Services’ IT mission-critical systems and data. Social Services’ IT Risk Management program has a complex workflow, along with a complex IT environment, which has slowed the process of remediation and contributed to the identified weaknesses. By not meeting the minimum requirements in the Security Standard, Social Services cannot ensure the confidentiality, integrity, and availability of data within its systems. Social Services should obtain and dedicate the necessary resources to ensure that its IT Risk Management program aligns with the Security Standard. Additionally, Social Services should implement the controls required to address the weaknesses identified in the FOIAE communication. Views of Responsible Officials: The views of responsible officials are included in the report related to their organization, which can be found at www.apa.virginia.gov and, in summary, do not express disagreement with the finding.

FY End: 2025-06-30
Commonwealth of Virginia
Compliance Requirement: P
2025-051: Improve Database Security Applicable to: Department of Social Services Assigned Topic: Access Control; Identification and Authentication Prior Finding Number: N/A Finding Type: Internal Control and Compliance Finding Severity: Significant Deficiency Financial Statement Finding: Yes Federal Awards Finding: Yes ALPT - ALN: Grants to States for Medicaid – 93.778 Federal Award ID (Year): 2505VA5MAP (2025) Federal Agency: U.S. Department of Health and Human Services Compliance Requirement: ...

2025-051: Improve Database Security Applicable to: Department of Social Services Assigned Topic: Access Control; Identification and Authentication Prior Finding Number: N/A Finding Type: Internal Control and Compliance Finding Severity: Significant Deficiency Financial Statement Finding: Yes Federal Awards Finding: Yes ALPT - ALN: Grants to States for Medicaid – 93.778 Federal Award ID (Year): 2505VA5MAP (2025) Federal Agency: U.S. Department of Health and Human Services Compliance Requirement: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Social Services does not require and has not implemented certain requirements in accordance with the Security Standard and industry best practices for its database. We identified two control weaknesses and communicated them to management in a separate document marked FOIAE under § 2.2-3705.2 of the Code of Virginia, due to it containing descriptions of security mechanisms. The Security Standard requires agencies to implement certain controls that reduce unnecessary risk to the confidentiality, integrity, and availability of Social Services’ IT mission critical systems and data. By not meeting the minimum requirements in the Security Standard, Social Services cannot ensure the confidentiality, integrity, and availability of data within its systems. Due to an oversight, Social Services’ management did not identify that the database was not configured according to Security Standard requirements. Social Services began testing and applying the configurations needed to resolve the weaknesses identified in the database during the audit. Social Services should dedicate the necessary resources to ensure database configurations align with the requirements of the Security Standard and industry best practices. Views of Responsible Officials: The views of responsible officials are included in the report related to their organization, which can be found at www.apa.virginia.gov and, in summary, do not express disagreement with the finding.

FY End: 2025-06-30
Commonwealth of Virginia
Compliance Requirement: P
2025-052: Improve Change Management Process Applicable to: Department of Social Services Assigned Topic: Configuration Management; System and Services Acquisition Prior Finding Number: N/A Finding Type: Internal Control and Compliance Finding Severity: Significant Deficiency Financial Statement Finding: Yes Federal Awards Finding: Yes ALPT - ALN: Grants to States for Medicaid – 93.778 Federal Award ID (Year): 2505VA5MAP (2025) Federal Agency: U.S. Department of Health and Human Services Complian...

2025-052: Improve Change Management Process Applicable to: Department of Social Services Assigned Topic: Configuration Management; System and Services Acquisition Prior Finding Number: N/A Finding Type: Internal Control and Compliance Finding Severity: Significant Deficiency Financial Statement Finding: Yes Federal Awards Finding: Yes ALPT - ALN: Grants to States for Medicaid – 93.778 Federal Award ID (Year): 2505VA5MAP (2025) Federal Agency: U.S. Department of Health and Human Services Compliance Requirement: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Social Services does not consistently follow its IT change management process to include elements required by its IT Change Management Process Procedure and the Security Standard. Specifically, our review found: Social Services did not track changes to application code and maintain version control in one of its three (33%) development projects. Social Services did not perform a risk and impact analysis for one of 40 (3%) changes. Social Services did not review the risk and impact analysis and validate the change for four of 40 (10%) changes. Social Services did not establish and document a backout plan for one of 40 (3%) changes. Social Services did not update and attach supporting documentation for the change for 40 of 40 (100%) changes. Social Services did not complete user acceptance testing for six of 40 (15%) changes. Social Services did not validate the change to confirm complete and successful execution for one of 40 (3%) changes. Social Services’ IT Change Management Process Procedure requires that each change include a documented risk and impact rating validated through ISRM oversight; an implementation plan (also known as the Playbook, which verifies technical testing and roles and responsibilities); a clearly defined backout plan; post-implementation validation to verify all acceptance criteria were met (including testing evidence); and attached closure documents that include user acceptance testing and updated supporting documentation, such as technical diagrams and baselines. The Security Standard requires that Social Services document and implement configuration change control processes that involves the systematic proposal, justification, implementation, testing, review, and disposition of system changes, including system upgrades and modifications. Additionally, the Security Standard requires agencies to employ tools and processes for maintaining trusted generations of source code. Social Services established and implemented its current change management procedure and process in September 2024; however, the process has not matured to include the necessary oversight to ensure employees adhere to each of the steps in the procedure. Without consistently implementing a formal change management process that aligns with the requirements of its IT Change Management Process Procedure and the Security Standard, Social Services increases the risk of implementing unauthorized changes to its production environment that may negatively affect the confidentiality, integrity, and availability of its IT systems and data. Social Services should implement an oversight capability to consistently implement and systematically record all changes according to its IT Change Management Process Procedure and the Security Standard. Views of Responsible Officials: The views of responsible officials are included in the report related to their organization, which can be found at www.apa.virginia.gov and, in summary, do not express disagreement with the finding.

FY End: 2025-06-30
Commonwealth of Virginia
Compliance Requirement: P
2025-053: Improve Identity and Access Management Oversight and Controls Applicable to: Department of Social Services Assigned Topic: Access Control; Identification and Authentication; Information Security Roles and Responsibilities Prior Finding Number: N/A Finding Type: Internal Control and Compliance Finding Severity: Significant Deficiency Financial Statement Finding: Yes Federal Awards Finding: Yes ALPT - ALN: Grants to States for Medicaid – 93.778 Federal Award ID (Year): 2505VA5MAP (2025) ...

2025-053: Improve Identity and Access Management Oversight and Controls Applicable to: Department of Social Services Assigned Topic: Access Control; Identification and Authentication; Information Security Roles and Responsibilities Prior Finding Number: N/A Finding Type: Internal Control and Compliance Finding Severity: Significant Deficiency Financial Statement Finding: Yes Federal Awards Finding: Yes ALPT - ALN: Grants to States for Medicaid – 93.778 Federal Award ID (Year): 2505VA5MAP (2025) Federal Agency: U.S. Department of Health and Human Services Compliance Requirement: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Social Services does not conduct organization-wide oversight to ensure the performance of identity and access management (IAM) controls that protect sensitive information in its critical systems in accordance with organizational policies and procedures and the Security Standard. Social Services manages sensitive systems that require strong IAM controls. As a result of not conducting organization-wide oversight, Social Services does not: Examine and evaluate risk for critical IAM elements and maintain risk assessments to capture changes in risk and the control environment to ensure Social Services implements appropriate controls to reduce risk to an acceptable level. Define processes and practices to collect, monitor, and evaluate performance metrics that Social Services has implemented for IAM functions to evaluate how the functions are performing against agreed-upon performance expectations and report results to stakeholders. Revoke access for terminated users timely. Maintain an inventory of service accounts, document the purpose of each account, and centrally manage the service accounts to minimize the potential for misuse. Provide access to users only after the asset owner authorizes access. Social Services Access Control Policy states that the System Owner shall require the implementation team to enforce approved authorizations. The Security Standard states that the agency head is responsible for the security of the agency’s IT systems and data, including designating an ISO for the agency that reports directly to the agency head. The Security Standard states that the ISO is responsible for developing and managing the agency’s information security program. By not conducting organization-wide oversight of IAM controls, Social Services cannot rely on the controls to effectively reduce the risk of compromise to confidentiality, integrity, and availability of sensitive data in its IT environment. Social Services’ decentralized approach to ensuring IAM control compliance contributes to the lack of oversight and lack of efficient and effective implementation of the individual IAM findings outlined above. Social Services should assign oversight of organizational IAM controls to a central person or team. The person or team responsible should subsequently establish and implement a centralized process to oversee IAM controls to ensure Social Services consistently implements access and account management controls. A centralized oversight IAM function will help Social Services manage IAM controls to protect the confidentiality, integrity, and availability of sensitive and mission-critical data. Views of Responsible Officials: The views of responsible officials are included in the report related to their organization, which can be found at www.apa.virginia.gov and, in summary, do not express disagreement with the finding.

FY End: 2025-06-30
Commonwealth of Virginia
Compliance Requirement: P
2025-068: Improve Database Security Applicable to: Department of Medical Assistance Services Assigned Topic: Access Control; Audit and Accountability; Identification and Authentication; System and Information Integrity Prior Finding Number: 2024-023 Finding Type: Internal Control and Compliance Finding Severity: Significant Deficiency Financial Statement Finding: Yes Federal Awards Finding: Yes ALPT - ALN: Grants to States for Medicaid – 93.778 Federal Award ID (Year): 2505VA5MAP (2025) Federal ...

2025-068: Improve Database Security Applicable to: Department of Medical Assistance Services Assigned Topic: Access Control; Audit and Accountability; Identification and Authentication; System and Information Integrity Prior Finding Number: 2024-023 Finding Type: Internal Control and Compliance Finding Severity: Significant Deficiency Financial Statement Finding: Yes Federal Awards Finding: Yes ALPT - ALN: Grants to States for Medicaid – 93.778 Federal Award ID (Year): 2505VA5MAP (2025) Federal Agency: U.S. Department of Health and Human Services Compliance Requirement: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 The Department of Medical Assistance Services (Medical Assistance Services) has made significant progress improving security for the database supporting its primary system for financial accounting and reporting in accordance with its internal procedures, the Commonwealth’s Information Security Standard, SEC530 (Security Standard), and industry best practices, such as the Center for Internet Security Benchmarks (CIS Benchmark). Since the prior year audit, Medical Assistance Services remediated four of the eight weaknesses previously identified. However, Medical Assistance Services does not define deviations from recommended and expected security configurations in its baseline configuration, leading to some weaknesses still existing in the database. We communicated the remaining weaknesses to management in a separate document marked Freedom of Information Act Exempt (FOIAE) under § 2.2-3705.2 of the Code of Virginia due to it containing descriptions of security mechanisms. The Security Standard requires Medical Assistance Services to develop, document, and disseminate information security policies and procedures that align with the control requirements in the Security Standard. Additionally, the Security Standard requires Medical Assistance Services to develop, document, and maintain a current baseline configuration of the system; apply more restrictive security configurations for sensitive systems; and monitor systems for security baseline and policy compliance. Without aligning the database’s settings and configurations with its policies and procedures, the Security Standard, and industry best practices, Medical Assistance Services cannot ensure data integrity within the database. Additionally, without documenting details and the justification for approved deviations, Medical Assistance Services increases the risk that it will not meet minimum-security requirements and recommendations to protect its sensitive data from malicious parties. A lack of resources led to Medical Assistance Services experiencing delays in resolving the remaining weaknesses. Medical Assistance Services should dedicate the resources necessary to review and update its procedures to define deviations from recommended and expected security configurations as well as business justification and approval for any deviations. Additionally, Medical Assistance Services should develop a process to review the database’s configuration against its established procedures on a scheduled basis and after major changes occur to help detect and address potential misconfigurations timely. Furthermore, Medical Assistance Services should implement the security controls and processes communicated in the FOIAE document to address the risks present in the database to ensure the configuration aligns with its procedures, the Security Standard, and CIS Benchmark. These actions will help maintain the confidentiality, availability, and integrity of Medical Assistance Services’ sensitive and mission-critical data. Views of Responsible Officials: The views of responsible officials are included in the report related to their organization, which can be found at www.apa.virginia.gov and, in summary, do not express disagreement with the finding.

FY End: 2025-06-30
Commonwealth of Virginia
Compliance Requirement: P
2025-084: Improve Web Application Security Applicable to: Department of Social Services Assigned Topic: Audit and Accountability Prior Finding Number: 2024-025; 2023-015; 2022-029; 2021-025; 2020-026; 2019-037 Finding Type: Internal Control and Compliance Finding Severity: Significant Deficiency Financial Statement Finding: Yes Federal Awards Finding: Yes ALPT - ALN: Grants to States for Medicaid – 93.778 Federal Award ID (Year): 2505VA5MAP (2025) Federal Agency: U.S. Department of Health and Hu...

2025-084: Improve Web Application Security Applicable to: Department of Social Services Assigned Topic: Audit and Accountability Prior Finding Number: 2024-025; 2023-015; 2022-029; 2021-025; 2020-026; 2019-037 Finding Type: Internal Control and Compliance Finding Severity: Significant Deficiency Financial Statement Finding: Yes Federal Awards Finding: Yes ALPT - ALN: Grants to States for Medicaid – 93.778 Federal Award ID (Year): 2505VA5MAP (2025) Federal Agency: U.S. Department of Health and Human Services Compliance Requirement: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Social Services continues to not configure a sensitive web application in accordance with its internal policies and the Security Standard. Social Services remediated four of the five previously communicated weaknesses but still has not remediated one weakness. We communicated the control weakness to management in a separate document marked FOIAE under § 2.2-3705.2 of the Code of Virginia, due to it containing descriptions of security mechanisms. The Security Standard requires Social Services to implement certain controls that reduce unnecessary risk to the confidentiality, integrity, and availability of Social Services’ IT mission-critical systems and data. By not meeting the minimum requirements in the Security Standard, Social Services cannot ensure the confidentiality, integrity, and availability of data within its systems. Social Services prioritized other projects which contributed to the weakness persisting. Social Services’ TSD, ISRM Division, and business owners should work together to remediate the remaining weakness to secure the web application and meet the minimum requirements in Social Services’ internal policies and the Security Standard. Addressing this weakness will help to ensure that Social Services secures its IT environment and systems to protect its sensitive and mission-critical data and achieve compliance with both internal policies and the Security Standard. Views of Responsible Officials: The views of responsible officials are included in the report related to their organization, which can be found at www.apa.virginia.gov and, in summary, do not express disagreement with the finding.

FY End: 2025-06-30
Commonwealth of Virginia
Compliance Requirement: P
2025-085: Conduct Information Technology Security Audits Applicable to: Department of Social Services Assigned Topic: Audit and Accountability Prior Finding Number: 2024-058; 2023-056 Finding Type: Internal Control and Compliance Finding Severity: Significant Deficiency Financial Statement Finding: Yes Federal Awards Finding: Yes ALPT - ALN: Grants to States for Medicaid – 93.778 Federal Award ID (Year): 2505VA5MAP (2025) Federal Agency: U.S. Department of Health and Human Services Compliance Re...

2025-085: Conduct Information Technology Security Audits Applicable to: Department of Social Services Assigned Topic: Audit and Accountability Prior Finding Number: 2024-058; 2023-056 Finding Type: Internal Control and Compliance Finding Severity: Significant Deficiency Financial Statement Finding: Yes Federal Awards Finding: Yes ALPT - ALN: Grants to States for Medicaid – 93.778 Federal Award ID (Year): 2505VA5MAP (2025) Federal Agency: U.S. Department of Health and Human Services Compliance Requirement: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Social Services is making progress in conducting a comprehensive IT security audit on each sensitive IT system at least once every three years. Social Services identified 78 sensitive IT systems which currently require an IT security audit and completed audits for 30 of these systems during calendar years 2022 and 2023. These systems are due to be audited again during the three-year audit period covering calendar years 2024 to 2026. Additionally, Social Services completed audits for 31 sensitive IT systems during calendar year 2024. However, 17 sensitive IT systems (22%) remain unaudited, including one system that has not been audited since 2017. Social Services hired a contractor to complete an audit over each of the remaining unaudited systems and those due for audit during the audit period covering calendar years 2024 to 2026. Social Services did not perform the remaining IT security audits due to prioritizing required federal audits and needing additional funding to contract out the remaining sensitive system audits. Lack of a documented procedure and process for conducting IT security audits also contributed to the lapse in IT security audits conducted over the last three years. Additionally, Social Services drafted an IT Audit Policy for conducting IT security audits over each sensitive system but has not implemented it since it is pending management’s approval. Social Services indicates it is on track to approve the draft policy and complete the remaining IT security audits by the end of calendar year 2026. The Security Standard requires that each IT system classified as sensitive undergo an IT security audit as required by and in accordance with the current version of the Commonwealth’s IT Security Audit Standard, SEC502 (IT Audit Standard). The IT Audit Standard requires that IT systems containing sensitive data, or systems with an assessed sensitivity of high on any of the criteria of confidentiality, integrity, or availability, receive an IT security audit at least once every three years. Without conducting full IT security audits for each sensitive system once every three years, Social Services increases the risk that IT staff will not detect and mitigate existing weaknesses. Malicious parties taking advantage of continued weaknesses could compromise sensitive and confidential data. Further, such security incidents could lead to mission-critical systems being unavailable. Social Services should finalize and implement its IT Audit Policy then complete all outstanding IT security audits to ensure it meets its IT Audit Policy and Security Standard requirements. Views of Responsible Officials: The views of responsible officials are included in the report related to their organization, which can be found at www.apa.virginia.gov and, in summary, do not express disagreement with the finding.

FY End: 2025-06-30
Commonwealth of Virginia
Compliance Requirement: P
2025-093: Evaluate Separation of Duty Conflicts within the Case Management System Applicable to: Department of Social Services Assigned Topic: Access Control Prior Finding Number: 2024-041; 2023-034 Finding Type: Internal Control and Compliance Finding Severity: Significant Deficiency Financial Statement Finding: Yes Federal Awards Finding: Yes ALPT - ALN: Grants to States for Medicaid – 93.778 Federal Award ID (Year): 2505VA5MAP (2025) Federal Agency: U.S. Department of Health and Human Service...

2025-093: Evaluate Separation of Duty Conflicts within the Case Management System Applicable to: Department of Social Services Assigned Topic: Access Control Prior Finding Number: 2024-041; 2023-034 Finding Type: Internal Control and Compliance Finding Severity: Significant Deficiency Financial Statement Finding: Yes Federal Awards Finding: Yes ALPT - ALN: Grants to States for Medicaid – 93.778 Federal Award ID (Year): 2505VA5MAP (2025) Federal Agency: U.S. Department of Health and Human Services Compliance Requirement: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Benefit Programs continues to implement corrective actions pertaining to evaluating separation of duties conflicts within its case management system. In response to the prior audit findings, Benefit Programs developed a collaborative strategy to address separation of duties conflicts in the case management system and generated a complete listing of current roles and responsibilities. However, because of the extent of its corrective actions, Benefit Programs could not fully develop and implement all corrective actions by the end of fiscal year 2025. Benefit Programs intends to create a matrix to identify individual conflicts, generate a report of users with conflicting roles, and develop justifications and internal controls for these instances by the end of fiscal year 2026. Social Services, in conjunction with local departments of social services, other state agencies, and numerous contractors, uses the case management system to determine applicant eligibility and authorize benefit payments for the Medicaid, SNAP, CCDF Cluster, LIHEAP, and TANF federal grant programs. Social Services authorized over $18 billion in assistance payments to beneficiaries from these federal programs through its case management system during fiscal year 2025. The Security Standard requires the agency to separate duties of individuals as necessary, document separation of duties of individuals, and define information system access authorizations to support the separation of duties. Further, Social Services’ Information Security Policy states that the system owner is responsible for identifying and documenting separation of duties for individuals and defining system access authorizations to support separation of duties. Without identifying and evaluating separation of duties conflicts, Benefit Programs does not know which combination of roles may pose a separation of duties conflict in its case management system. As a result, Benefit Programs is unable to implement compensating controls, which increases the possibility of a system breach or other malicious attack on Social Services’ data and places Social Services’ reputation at risk. Benefit Programs should continue to implement its corrective actions pertaining to evaluating separation of duties within its case management system. Views of Responsible Officials: The views of responsible officials are included in the report related to their organization, which can be found at www.apa.virginia.gov and, in summary, do not express disagreement with the finding.

FY End: 2025-06-30
Commonwealth of Virginia
Compliance Requirement: P
2025-100: Continue Developing Record Retention Requirements and Processes for Electronic Records Applicable to: Department of Social Services Assigned Topic: Contingency Planning Prior Finding Number: 2024-067; 2023-066; 2022-064; 2021-047; 2020-041; 2019-049; 2018-054 Finding Type: Internal Control and Compliance Finding Severity: Significant Deficiency Financial Statement Finding: Yes Federal Awards Finding: Yes ALPT - ALN: Grants to States for Medicaid – 93.778 Federal Award ID (Year): 2505VA...

2025-100: Continue Developing Record Retention Requirements and Processes for Electronic Records Applicable to: Department of Social Services Assigned Topic: Contingency Planning Prior Finding Number: 2024-067; 2023-066; 2022-064; 2021-047; 2020-041; 2019-049; 2018-054 Finding Type: Internal Control and Compliance Finding Severity: Significant Deficiency Financial Statement Finding: Yes Federal Awards Finding: Yes ALPT - ALN: Grants to States for Medicaid – 93.778 Federal Award ID (Year): 2505VA5MAP (2025) Federal Agency: U.S. Department of Health and Human Services Compliance Requirement: Other - 2 CFR § 200.303(e); 45 CFR § 155.1210 Known Questioned Costs: $0 Social Services continues to operate without an adequate data retention process that ensures consistent compliance with retention requirements for its case management system and adherence to federal regulations and state law. Social Services’ case management system stores several types of federal benefit program records with varying retention requirements supporting ten programs and services, such as the Medical Assistance (Medicaid), Supplemental Nutrition Assistance (SNAP), Child Care and Development Fund (CCDF) Cluster, Low-Income Home Energy Assistance (LIHEAP), and TANF federal grant programs. Social Services’ case management system authorized over $18 billion in public assistance payments to beneficiaries from these federal programs during fiscal year 2025. Social Services encountered delays with its record purge and retention project because of the magnitude and complexities associated with effectively implementing a retention and purge process for an integrated eligibility system. Additionally, Social Services identified an additional required element of the purge and retention project following its Release 1 implementation in February 2024. For these reasons, Social Services’ plan includes updating the purge and retention design document and implementing Release 2 in August 2025, then completing the purge and retention project with the final releases, Release 3 and Release 4, by February 2026. Title 45 CFR § 155.1210 governs record retention for Medicaid and requires state agencies to maintain records for ten years. Additionally, the Virginia Public Records Act, outlined in § 42.1-91 of the Code of Virginia, makes an agency responsible for ensuring that its public records are preserved, maintained, and accessible throughout their lifecycle, including converting and migrating electronic records as often as necessary so that the agency does not lose information due to hardware, software, or media obsolescence or deterioration. Further, the Virginia Public Records Act (§ 42.1-76 et seq. of the Code of Virginia) details requirements for the disposition of records. Section § 42.1-86.1 requires that records created after July 1, 2006, and authorized to be destroyed or discarded, must be discarded in a timely manner and such records that contain identifying information as defined by subsection C of § 18.2 - 186.3 of the Code of Virginia shall be destroyed within six months of the expiration of the records retention period. Finally, the Security Standard requires agencies to implement backup and restoration plans that address the retention of the data in accordance with the records retention policy for every IT system identified as sensitive relative to availability. Without implementing records retention requirements, Social Services increases the risk of a data or privacy breach. Additionally, destroying documents that should be available for business processes or audit, or keeping data longer than stated, could expose Social Services to fines, penalties, or other legal consequences. Further, Social Services may not be able to ensure that backup and restoration efforts will provide mission-critical information according to recovery times. Finally, retaining records longer than necessary causes the Commonwealth to spend additional resources to maintain, back-up, and protect information that no longer serves a business purpose. Social Services should complete the record purge and retention project for its case management system and should subsequently implement consistent records retention and destruction processes across business divisions to ensure compliance with laws and regulations. Views of Responsible Officials: The views of responsible officials are included in the report related to their organization, which can be found at www.apa.virginia.gov and, in summary, do not express disagreement with the finding.

FY End: 2025-06-30
Commonwealth of Virginia
Compliance Requirement: P
2025-101: Upgrade End-of-Life Technology Applicable to: Department of Social Services Assigned Topic: System and Information Integrity Prior Finding Number: 2024-064; 2023-058; 2022-060 Finding Type: Internal Control and Compliance Finding Severity: Significant Deficiency Financial Statement Finding: Yes Federal Awards Finding: Yes ALPT - ALN: Grants to States for Medicaid – 93.778 Federal Award ID (Year): 2505VA5MAP (2025) Federal Agency: U.S. Department of Health and Human Services Compliance ...

2025-101: Upgrade End-of-Life Technology Applicable to: Department of Social Services Assigned Topic: System and Information Integrity Prior Finding Number: 2024-064; 2023-058; 2022-060 Finding Type: Internal Control and Compliance Finding Severity: Significant Deficiency Financial Statement Finding: Yes Federal Awards Finding: Yes ALPT - ALN: Grants to States for Medicaid – 93.778 Federal Award ID (Year): 2505VA5MAP (2025) Federal Agency: U.S. Department of Health and Human Services Compliance Requirement: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Social Services continues to use end-of-life technologies in its IT environment and maintains technologies that support mission-essential data on IT systems running software that its vendors no longer support. We communicated the control weaknesses to management in a separate document marked FOIAE under § 2.2-3705.2 of the Code of Virginia, due to it containing descriptions of security mechanisms. The Security Standard prohibits agencies from using software that is end-of-life and which the vendor no longer supports to reduce unnecessary risk to the confidentiality, integrity, and availability of Social Services’ information systems and data. By not meeting the minimum requirements in the Security Standard, Social Services cannot ensure the confidentiality, integrity, and availability of data within its systems. Project delays, including prioritizing other initiatives, slowed remediation efforts. Social Services should dedicate the necessary resources to evaluate and implement the controls and recommendations discussed in the communication marked FOIAE in accordance with the Security Standard. Views of Responsible Officials: The views of responsible officials are included in the report related to their organization, which can be found at www.apa.virginia.gov and, in summary, do not express disagreement with the finding.

FY End: 2025-06-30
Commonwealth of Virginia
Compliance Requirement: P
2025-094: Improve Access Controls for the Grants Management System Applicable to: Department of Behavioral Health and Developmental Services Assigned Topic: Access Control Prior Finding Number: N/A Finding Type: Internal Control and Compliance Finding Severity: Significant Deficiency Financial Statement Finding: Yes Federal Awards Finding: Yes ALPT - ALN: Block Grants for Prevention and Treatment of Substance Abuse - 93.959 Federal Award ID (Year): 1B08TI088137-01 (2025) Federal Agency: U.S. Dep...

2025-094: Improve Access Controls for the Grants Management System Applicable to: Department of Behavioral Health and Developmental Services Assigned Topic: Access Control Prior Finding Number: N/A Finding Type: Internal Control and Compliance Finding Severity: Significant Deficiency Financial Statement Finding: Yes Federal Awards Finding: Yes ALPT - ALN: Block Grants for Prevention and Treatment of Substance Abuse - 93.959 Federal Award ID (Year): 1B08TI088137-01 (2025) Federal Agency: U.S. Department of Health and Human Services Compliance Requirement: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 DBHDS has not implemented adequate access controls for its grants management system. DBHDS has created an administrative manual for its grants management system, which includes information such as granting and approving user access, properly removing user access, and outlining an annual review, as well as roles and responsibilities for individuals within the agency and the grants management system’s service provider. However, DBHDS is not adhering to the controls outlined in this manual nor does it have sufficient documentation of these access controls. As a result, we identified the following deficiencies: DBHDS management does not monitor the activity of system administrators who have privileged role assignments. DBHDS management does not have a formal process for periodically reviewing system access for all users. For four of four (100%) terminated employees tested, DBHDS did not remove access within 24 hours of the employee’s separation with access removal ranging from 144 to 265 days after termination. For nine of 13 (69%) users tested, DBHDS management did not retain supporting documentation to verify the user’s level of access or the supervisor’s approval. For three of 13 (23%) active users tested, DBHDS did not deactivate the user’s account after the employee’s termination. The Security Standard requires reviewing accounts for compliance with account management requirements on an annual basis and following an environmental change; disabling user accounts within 24 hours of when users are terminated or transferred; monitoring privileged role assignments; and creating and enabling accounts in accordance with the agency-defined logical access control policy. By not properly approving system access or terminating access timely, DBHDS increases the risk of unauthorized individuals entering or approving transactions which could affect the integrity of the information within the grants management system. Without a review of user access levels on an annual basis or a process to monitor the activity of privileged users, DBHDS cannot verify that each user’s access is appropriate based on job function, does not violate the principle of least privilege or separation of duties, and has not been used for inappropriate activity. Due to lack of training and management oversight, DBHDS did not perform all access control requirements as outlined by the Security Standard. In addition, users gain access to the grants management system by submitting a ticket to the DBHDS help desk; however, the ticketing system does not require supervisory approval before granting access. DBHDS should improve the design and implementation of access controls for the grants management system to ensure they align with the DBHDS administrative manual and the Security Standard. Specifically, DBHDS should provide training regarding the administrative manual. DBHDS should also ensure supervisors approve access before granting access; remove access timely when employees terminate; and retain all supporting documentation regarding system access including approving, granting, and removing new and existing access. In addition, DBHDS should develop a formal process for periodically reviewing system access as well as reviewing activity for privileged users. Views of Responsible Officials: The views of responsible officials are included in the report related to their organization, which can be found at www.apa.virginia.gov and, in summary, do not express disagreement with the finding.

FY End: 2025-06-30
Commonwealth of Virginia
Compliance Requirement: B
2025-023: Strengthen Internal Controls over Payroll Processes Applicable to: Department for Aging and Rehabilitative Services Assigned Topic: Federal Grants Management Prior Finding Number: N/A Finding Type: Internal Control and Compliance Finding Severity: Significant Deficiency Financial Statement Finding: No Federal Awards Finding: Yes ALPT - ALN: Social Security Disability Insurance - 96.001 Federal Award ID (Year): 04-2404VADI00 (2024); 04-2504VADI00 (2025) Federal Agency: U.S. Social Secur...

2025-023: Strengthen Internal Controls over Payroll Processes Applicable to: Department for Aging and Rehabilitative Services Assigned Topic: Federal Grants Management Prior Finding Number: N/A Finding Type: Internal Control and Compliance Finding Severity: Significant Deficiency Financial Statement Finding: No Federal Awards Finding: Yes ALPT - ALN: Social Security Disability Insurance - 96.001 Federal Award ID (Year): 04-2404VADI00 (2024); 04-2504VADI00 (2025) Federal Agency: U.S. Social Security Administration Compliance Requirement: Allowable Costs/Cost Principles - 2 CFR § 200.303(a); 2 CFR 200.430(g)(1)(i) Known Questioned Costs: $0 Aging and Rehabilitative Services’ Finance Division is not maintaining adequate internal control over several of its key payroll processes. During fiscal year 2025, Aging and Rehabilitative Services spent approximately $213 million in federal funds, of which about $85 million (40%) was for personal service expenses. We identified the following specific weaknesses: Aging and Rehabilitative Services’ Finance Division does not have written, agency-specific payroll policies and procedures governing all critical payroll processes, including payroll reconciliations and payroll certifications. The Department of Accounts’ (Accounts) Commonwealth Accounting Policies and Procedures (CAPP) Manual Topic 10305 requires agencies to develop and maintain their own written policies over critical processes, including payroll, rather than relying solely on system guidance or the CAPP Manual. Aging and Rehabilitative Services’ Finance Division was unable to provide documentation supporting the completion and review of payroll (pay period) reconciliations for five out of the five (100%) payroll (pay period) reconciliations selected. CAPP Manual Topic 50905 requires agencies to complete payroll (pay period) reconciliations to ensure payroll transactions are accurate, complete, and properly reviewed. Aging and Rehabilitative Services’ Finance Division relies on the Accounts’ Cardinal Human Capital Management (HCM) materials and CAPP Manual provisions to support its payroll activities. While the use of Accounts’ guidance provides a foundation for internal control, it is not intended to be a substitute for the agency’s own internal policies and procedures. The absence of documented internal policies and procedures limits consistency, accountability, and management oversight and increases the risk that Aging and Rehabilitative Services will not prevent and/or detect errors or discrepancies in a timely manner. Title 2 CFR § 200.303(a) requires that federal grant recipients establish, document, and maintain effective internal control over the federal award that provides reasonable assurance that the recipient or subrecipient is managing the federal award in compliance with Federal statutes, regulations, and the terms and conditions of the federal award. Further, 2 CFR 200.430(g)(1)(i) states that charges to federal awards for salaries and wages must be supported by a system of internal control that provides reasonable assurance that the charges are accurate, allowable, and properly allocated. Aging and Rehabilitative Services’ Finance Division experienced staffing shortages during the period under review because of turnover and was unable to devote the resources necessary to establish internal controls over several of its key payroll processes. Aging and Rehabilitative Services’ management should devote the necessary resources to establish and maintain proper internal control over its payroll processes. Views of Responsible Officials: The views of responsible officials are included in the report related to their organization, which can be found at www.apa.virginia.gov and, in summary, do not express disagreement with the finding.

FY End: 2025-06-30
Washington Metropolitan Area Transit Authority
Compliance Requirement: I
Finding 2025-002: Lack of Internal Controls Over Key Compliance Requirement Significant Deficiency Federal Agency: U.S. Department of Homeland Security Program Name: Transit Security Grant Programs ALN Number: 97.075 Award Number: 97.075 Award Year: 2025 Criteria: 2 CFR Part 200 Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards, (Uniform Guidance) requires compliance with provisions of procurement, suspension, and debarment. Non-federal entities are ...

Finding 2025-002: Lack of Internal Controls Over Key Compliance Requirement Significant Deficiency Federal Agency: U.S. Department of Homeland Security Program Name: Transit Security Grant Programs ALN Number: 97.075 Award Number: 97.075 Award Year: 2025 Criteria: 2 CFR Part 200 Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards, (Uniform Guidance) requires compliance with provisions of procurement, suspension, and debarment. Non-federal entities are prohibited from contracting with or making subawards under covered transactions to parties that are suspended or debarred. When a non-federal entity enters into a covered transaction with an entity at a lower tier, the non-federal entity must verify that the entity, as defined in 2 CFR section 180.985 and agency adopting regulations, is not suspended or debarred or otherwise excluded from participating in the transaction. 2 CFR § 200.303, also states non-Federal entities must establish and maintain effective internal control over federal awards to ensure compliance with applicable statutes, regulations, and the terms and conditions of the award. Condition: During the audit of the Transit Security Grants Program, we identified a deficiency in the design of internal controls related to the suspension and debarment compliance requirement, particularly concerning certain external government entities. Specifically, the Authority had not established documented procedures, oversight mechanisms, or review processes sufficient to ensure compliance on funded special agreements, including these Memorandums of Understanding, negotiated independent of the procurement process. This design gap limited the entity’s ability to potentially prevent or detect noncompliance effectively. Cause: The Authority had not sufficiently developed or implemented internal control procedures to verify suspension and debarment status for funded memorandums of understanding with external governments involved in the grant. These contracts were negotiated without the participation of the Office of Procurement and Materials of the Authority and therefore were not subject to the procurement process, which includes such controls. Effect or Potential Effect: The internal controls insufficiency creates a reasonable possibility that material noncompliance with the suspension and debarment requirement could occur and not be prevented or detected and corrected in a timely manner. As a result, this represents a significant deficiency in internal control over compliance. Although no federal funds were disbursed to an excluded party, the lack of timely verification represents noncompliance with federal requirements and increases the risk of future violations. Context: Of the three items tested, two lacked documented procedures, and sufficient oversight and review processes to potentially prevent or detect noncompliance. Additionally, one other government entity was identified that may fall under the same compliance gap. Question Costs: None Repeat Finding: Yes. This repeat finding designation results from the concurrent identification of the control deficiency in both fiscal years during the fiscal year 2025 Single Audit and the fiscal year 2024 Schedule of Expenditures of Federal Awards restatement procedures. This deficiency existed in both reporting periods, and the findings for fiscal year 2024 and fiscal year 2025 were evaluated and communicated to management in 2026. Recommendation: We recommend the Authority design and implement internal control procedures to ensure compliance with the suspension and debarment requirements for federal grants. This may include developing written policies, assigning responsibilities, and establishing monitoring and reviewing processes. View of Responsible Officials: Management agrees with the finding: The Authority acknowledges that controls established in the procurement process are not consistently followed for funded special agreements if they are negotiated without participation of the Procurement and Materials. While Procurement and Materials has controls in place to verify whether entities, including government entities, are suspended or debarred prior to awarding any contract, it does not perform these checks for funded special contracts for which they do not participate in the process. The condition identified pertains specifically to funded transactions executed by the Metro Transit Police Department through Memorandums of Understanding in accordance with the Compact and Policy Instructions (PI) 9.6 Delegation of Authority - Special Agreements, which did not go through the standard procurement process. The Authority will revise PI 9.6 to provide clarity on roles, responsibilities, and compliance steps. including a documented process requiring verification of suspension and debarment status through SAM.gov or other appropriate mechanism for all funded transactions under delegated authority. This requirement will be communicated to all departments and integrated into standard operating practices. Additionally, targeted training sessions will be provided to staff on the revised PI 9.6 and SAM.gov verification procedures to ensure consistent application across the Authority.

FY End: 2025-06-30
Inglewood Unified School District
Compliance Requirement: AB
Criteria: 2 CFR, section 200.430 states, in part: (i) Standards for Documentation of Personnel Expenses (1) Charges to Federal awards for salaries and wages must be based on records that accurately reflect the work performed. These records must: (vii) Support the distribution of the employee's salary or wages among specific activities or cost objectives if the employee works on more than one Federal award; a Federal award and non-Federal award; an indirect cost activity and a direct cost activit...

Criteria: 2 CFR, section 200.430 states, in part: (i) Standards for Documentation of Personnel Expenses (1) Charges to Federal awards for salaries and wages must be based on records that accurately reflect the work performed. These records must: (vii) Support the distribution of the employee's salary or wages among specific activities or cost objectives if the employee works on more than one Federal award; a Federal award and non-Federal award; an indirect cost activity and a direct cost activity; two or more indirect activities which are allocated using different allocation bases; or an unallowable activity and a direct or indirect cost activity. 2 CFR, section 200.303 states, in part: The non- Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. CSAM Procedure 905 states, in part: Periodic (Semiannual) Certification Employees who work solely on a single federal award or cost objective need only complete a periodic certification. The periodic certification must:  Be prepared at least semiannually.  Be signed by the employee or the supervisory official having firsthand knowledge of the work performed by the employee.  State the employee worked solely on that single federal program or cost objective during the period covered by the certification. Where multiple employees work on the same cost objective, a blanket certification may be used as the documentation for all employees who worked on the cost objective. Personnel Activity Report Except as provided in “Substitute Systems for Time Accounting” … employees who work on multiple activities or cost objectives of which at least one is federal must complete a personnel activity report (PAR) or equivalent documentation. A PAR may be as detailed as a document that identifies the employee’s activity daily by hours, or it may be as simple as a report of the total hours or percentage of hours spent in each categorical program or cost objective. The level of detail can generally be determined by the diversity and variation of the employee’s work activities. The safest approach is to provide more documentation rather than less. Condition: The District has five employees who must complete PARs on a monthly basis. Upon review of the PARs the following deficiencies were noted.  PARs were not filled out properly from April 2025 through June 2025, which required amendment.  Due to errors on the PARs from April 2025 through June 2025, the Districts year end entries to charge salaries and benefits to Title I were incorrect. Context: Exceptions are recurring among the five employees who are required to fill out PAR forms. Questioned Costs: The net overcharge to Title I, Part A was $29,675 for all five employees. Cause: District personnel do not follow the established procedures as to when and how PAR forms must be prepared. In addition, there is a lack of oversight to ensure that PAR forms are collected after the end of each month, filled out accurately, and signed by the employee as well as their supervisor. Effect: Estimated questioned cost of $29,675 for the 2024-25 fiscal year. Recommendation: The District should provide training to employees regarding how to complete PAR forms and enforce timelines. In conjunction, the District should assign an employee who is responsible for reviewing and ensuring that all PAR forms have been collected and signed by the employee and supervisor. Lastly once it has been verified that the PAR form is complete, a copy should be forwarded to Fiscal Services so that they may ratify the salaries and benefits charged to Title I to reflect the percentage noted on the PAR form. Views of Responsible Officials: The District recognizes the finding and is committed to ensuring that all federal time accounting requirements are properly followed for staff funded through Title I programs. The District understands that accurate and complete Personnel Activity Reports (PARs) are necessary to support appropriate salary and benefit charges to federal resources. To address this, the District will reinforce expectations through additional training and support for employees and supervisors on the correct preparation and monthly submission of PAR forms. The District will also strengthen internal review procedures by assigning responsibility for confirming that PARs are completed accurately, collected on time, and signed by both the employee and the supervising administrator. In addition, the District will ensure PAR documentation is consistently forwarded to Fiscal Services to allow for timely review and necessary adjustments so that payroll expenditures align with the actual percentage of time worked on Title I activities.

FY End: 2025-06-30
Anne Arundel County Board of Education
Compliance Requirement: I
2025-002 Federal Agency: U.S. Department of Agriculture Federal Program Name: Child Nutrition Cluster Assistance Listing Number: 10.553, 10.555, 10.559 Federal Award Identification Number and Year: Not Available Pass-Through Agency: Maryland State Department of Education Pass-Through Number: Not Available Award Period: 7/1/2024 – 6/30/2025 Type of Finding: Significant Deficiency in Internal Control over Compliance, Other Matters Criteria or Specific Requirement: Compliance: Nonfederal entities a...

2025-002 Federal Agency: U.S. Department of Agriculture Federal Program Name: Child Nutrition Cluster Assistance Listing Number: 10.553, 10.555, 10.559 Federal Award Identification Number and Year: Not Available Pass-Through Agency: Maryland State Department of Education Pass-Through Number: Not Available Award Period: 7/1/2024 – 6/30/2025 Type of Finding: Significant Deficiency in Internal Control over Compliance, Other Matters Criteria or Specific Requirement: Compliance: Nonfederal entities are prohibited from contracting with or making subawards under covered transactions to parties that are suspended or debarred. “Covered transactions” include contracts for goods and services awarded under a non-procurement transaction (e.g., grant or cooperative agreement) that are expected to equal or exceed $25,000 or meet certain other criteria as specified in 2 CFR section 180.220. All nonprocurement transactions entered into by a pass-through entity (i.e., subawards to subrecipients), irrespective of award amount, are considered covered transactions, unless they are exempt as provided in 2 CFR section 180.215. 2 CFR 180.300 states that an entity may determine suspension and debarment status by: (a) Checking SAM (System for Award Management) Exclusions; or (b) Collecting a certification from that person; or (c) Adding a clause or condition to the covered transaction with that person. Control: Per 2 CFR section 200.303(a), a nonfederal entity must: Establish and maintain effective internal control over the federal award that provides reasonable assurance that the nonfederal entity is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award. These internal controls should comply with the guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control-Integrated Framework,” issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition/Context: For seven of eight vendors selected for testing, the Board was unable to provide documentation that it had verified the suspension and debarment status before entering into covered transactions with the vendor. Questioned Costs: There are no questioned costs related to this finding as the vendors were not federally suspended or debarred. Cause: The Board’s procedures and internal controls over suspension and debarment were updated in response to finding 2024-001 in the prior year but were not implemented until 4/1/2025. Therefore, all contracts executed prior to this date did not follow the updated suspension and debarment requirements. Effect: Failure to verify the suspension and debarment status of vendors may result in the procurement of goods or services from vendors that are suspended or debarred and result in unallowable expenditures charged to the program. Repeat Finding: Yes, refer to prior year finding 2024-001. Recommendation: We recommend that the Board review its policies and procedures to ensure they include the three options for determining suspension and debarment status listed in 2 CFR 180.300 and that controls are sufficient to ensure that the suspension and debarment status is verified for all vendors prior to entering into covered transactions. Views of Responsible Officials: There is no disagreement with the finding.

FY End: 2025-06-30
Howard Community College
Compliance Requirement: N
U.S. Department of Education 2025-005: Special Tests and Provisions – NSLDS Enrollment Reporting Student Financial Aid Cluster – Assistance Listing No. 84.063, 84.268 Condition: Enrollment status changes were either not reported to NSLDS within 60 days 2025 – 005: Special Tests and Provisions – NSLDS Enrollment & Reporting Federal Agency: U.S. Department of Education Federal Program Name: Student Financial Aid Cluster Assistance Listing Number: 84.063, 84.268 Federal Award Identification Number:...

U.S. Department of Education 2025-005: Special Tests and Provisions – NSLDS Enrollment Reporting Student Financial Aid Cluster – Assistance Listing No. 84.063, 84.268 Condition: Enrollment status changes were either not reported to NSLDS within 60 days 2025 – 005: Special Tests and Provisions – NSLDS Enrollment & Reporting Federal Agency: U.S. Department of Education Federal Program Name: Student Financial Aid Cluster Assistance Listing Number: 84.063, 84.268 Federal Award Identification Number: P063P233052, P063P243052, P268K243052, P268K253052 Award Period: July 1, 2024 – June 30, 2025 Type of Finding: Significant Deficiency in Internal Control over Compliance, Other Matters Criteria or specific requirement: Internal Control – Per 2 CFR section 200.303(a), a non-Federal entity must: Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non- Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). 2025 – 005: Special Tests and Provisions – NSLDS Enrollment & Reporting Federal Agency: U.S. Department of Education Federal Program Name: Student Financial Aid Cluster Assistance Listing Number: 84.063, 84.268 Federal Award Identification Number: P063P233052, P063P243052, P268K243052, P268K253052 Award Period: July 1, 2024 – June 30, 2025 Type of Finding: Significant Deficiency in Internal Control over Compliance, Other Matters Criteria or specific requirement: Internal Control – Per 2 CFR section 200.303(a), a non-Federal entity must: Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non- Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Compliance – The Code of Federal Regulations, 34 CFR 685.309(b), states that: Institutions must have some arrangement to report student enrollment data to NSLDS through an enrollment roster file. The institution is required to report changes in the enrollment status, the effective date of the status, and an anticipated completion date. Also, the Code of Federal Regulations, 34 CFR 682.610, states that institutions must report accurately the enrollment status of all students regardless of if they receive aid from the institution or not. Condition: Enrollment status changes were either not reported to NSLDS within 60 days or did not match the College’s records for a portion of the sampled students. Questioned Costs: None Context: In our statistically valid sample of 60 students, we found 16 cases where enrollment status changes were not reported to NSLDS within 60 days, and 4 cases where the students’ status changes did not match between the College’s records and NSLDS. Cause: The College's internal controls did not identify the errors in compliance with the criteria mentioned above. Effect: Student enrollment status was not reported accurately and/or timely to NSLDS. Repeat Finding: Yes Recommendation: The institution should evaluate their procedures and policies related to reporting status changes and effective dates to NSLDS and enhance as deemed necessary to ensure that accurate information is reported to NSLDS. Views of responsible officials: There is no disagreement with the audit finding.

FY End: 2025-06-30
Clatsop Community College
Compliance Requirement: N
Criteria or specific requirement: 2 CFR part 200 section 200.303 requires that non-Federal entities receiving federal awards (i.e., auditee management) establish and maintain internal control designed to reasonably ensure compliance with Federal statutes, regulations, and the terms and conditions of the federal award. The Code of federal Regulations, 34 CFR 688.164, requires any Title IV federal funds disbursed to a student or parent that are not received or negotiated must be returned to the ap...

Criteria or specific requirement: 2 CFR part 200 section 200.303 requires that non-Federal entities receiving federal awards (i.e., auditee management) establish and maintain internal control designed to reasonably ensure compliance with Federal statutes, regulations, and the terms and conditions of the federal award. The Code of federal Regulations, 34 CFR 688.164, requires any Title IV federal funds disbursed to a student or parent that are not received or negotiated must be returned to the appropriated federal financial aid program no later than 240 days after the check or electronic fund transfer (EFT) was issued. If a check or an EFT is returned, the College may make additional attempts to deliver the funds, provided that those attempts are made no later than 45 days after the funds were returned or rejected. In cases where the College does not make another attempt, the funds must be returned before the end of the initial 45-day period. The College must cease all attempts to disburse the funds and return them no later than 240 days after the date it issued the first check. Under no circumstances may unclaimed Title IV FSA funds escheat to the state, or revert to the college, or any other third party. Condition: The College had outstanding Title IV Federal Student Aid (FSA) checks issued to students that remained unclaimed for more than 240 days from the date of issuance. Questioned Costs: None Context: During testing of outstanding Title IV–funded checks, we identified three checks that exceeded 240 days from the date of issuance and had not been returned to the U.S. Department of Education. Cause: The College’s existing processes do not adequately monitor outstanding Title IV–funded checks to ensure timely identification and return of unclaimed funds. Effect: As a result, the College is not in compliance with federal requirements related to the return of unclaimed Title IV–funded checks issued to students or parents. Repeat Finding: Yes, 2024-003 Recommendation: We recommend the College return the funds related to unclaimed Title IV–funded checks that are older than 240 days. In addition, we recommend that the College review applicable requirements and implement effective controls and procedures to monitor outstanding Title IV–funded checks throughout the year to ensure timely compliance. Views of responsible officials: There is no disagreement with the audit finding.

FY End: 2025-06-30
Clatsop Community College
Compliance Requirement: N
Criteria or Specific Requirement: The Code of Federal Regulations, 34 CFR 682.610, states that institutions must report accurately the enrollment status of all students regardless of if they receive aid from the institution or not. This includes the enrollment effective date and related enrollment status, which must be reported for both the Campus-Level and the Program-Level, as well as the program begin date. Changes to said status are required to be reported within 30 days of becoming aware of...

Criteria or Specific Requirement: The Code of Federal Regulations, 34 CFR 682.610, states that institutions must report accurately the enrollment status of all students regardless of if they receive aid from the institution or not. This includes the enrollment effective date and related enrollment status, which must be reported for both the Campus-Level and the Program-Level, as well as the program begin date. Changes to said status are required to be reported within 30 days of becoming aware of the status change, or with the next scheduled transmission of statuses if the scheduled transmission is within 60 days. In addition, Uniform Grant Guidance (2 CFR 200.303) requires nonfederal entities receiving federal awards establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations, and program compliance requirements. Condition: There were instances in which the College did not report the correct status and effective dates, enrollment was not certified timely, and the status changes were not always reported timely. In addition, the College did not have a control in place to ensure timely and accurate reporting to NSLDS. Questioned Costs: None Context: In our sample of 60 students selected for National Student Loan Data System (NSLDS) enrollment reporting testing, we identified 23 students where the campus enrollment status was not reported correctly, 21 students where the enrollment effective date was not reported correctly, 37 students where the enrollment was not reported timely to NSLDS, and 56 students where enrollment was not certified every 60 days. There was also no control in place to ensure timely and accurate reporting to NSLDS. Cause: The College did not have proper controls or procedures in place to verify students' status in NSLDS matched the institution’s records in a timely manner. Effect: Failure to properly report enrollment status changes on NSLDS could affect the timing of the grace period for repayment of Title IV loans. Additionally, the College was not in compliance with the requirements to properly report student enrollment data correctly or timely to NSLDS. Repeat Finding: Yes, 2024-004 Recommendation: We recommend the College implement an internal control that ensures timely and accurate reporting. We also recommend the College implement changes in process and procedures for NSLDS enrollment reporting and implement an internal control that ensures reporting is both timely and accurate. Views of Responsible Officials: There is no disagreement with the audit finding.

FY End: 2025-06-30
Vermont State Colleges
Compliance Requirement: N
Finding number: 2025-001 Federal agency: U.S. Department of Education Programs: Student Financial Assistance (SFA) Cluster Assistance Listing Number: 84.007, 84.033, 84.268, 84.063 Award year: 2025 Criteria The Code of Federal Regulations, consisting of 2 CFR 200.303, 16 CFR 314.3(a), and 16 CFR 314, requires that financial institutions, including institutions participating in Title IV programs, develop, implement, and maintain a comprehensive written information security program that includes a...

Finding number: 2025-001 Federal agency: U.S. Department of Education Programs: Student Financial Assistance (SFA) Cluster Assistance Listing Number: 84.007, 84.033, 84.268, 84.063 Award year: 2025 Criteria The Code of Federal Regulations, consisting of 2 CFR 200.303, 16 CFR 314.3(a), and 16 CFR 314, requires that financial institutions, including institutions participating in Title IV programs, develop, implement, and maintain a comprehensive written information security program that includes administrative, technical, and physical safeguards appropriate to the sensitivity of the information being protected aligned with federal information security standards. Condition During our testing of the SFA Cluster, we requested the College’s Written Information Security Plan (WISP). The Colleges were unable to provide a formal, documented WISP. The Colleges' general IT policies and procedures provided did not fully meet WISP requirements. Cause The Colleges have not developed or formalized a standalone WISP. Effect Without a formalized WISP, the Colleges are at a heighted risk of inadequate safeguarding of sensitive data, inconsistent application of security practices and procedures, and an increased likelihood of unauthorized access, data loss or misuse. Questioned Costs N/A Perspective Due to its nature, this deficiency is systemic, affecting the entire SFA Cluster population and related programs. Identification as a Repeat Finding, if applicable N/A Recommendation The Colleges should develop, approve, and implement a Written Information Security Plan (WISP) aligned with 16 CFR Part 314 requirements and tailored to the systems and data associated with the SFA Cluster. View of Responsible Officials The Colleges agree with the finding. This issue was the result of information security policies that did not reflect actual current practices. Such current practices were updated over the last two years in response to industry standards, insurance requirements, and Gramm Leach Billey Act requirements, which are believed to meet the requirements of these regulations. However, because they were not documented formally in a comprehensive policy form, they could not be adequately provided during the audit. In early Fall 2025, the Colleges hired a new Chief Information Security Officer (CISO), who has begun overhauling the information security policies to reflect current practices. The CISO has also created a preliminary draft of a WISP that reflects the Colleges current policies and procedures. This WISP is expected to be completed and implemented during fiscal year 2026, pending board review and approval.

FY End: 2025-06-30
Paoli Community School Corporation
Compliance Requirement: I
FINDING 2025-002 Subject: Child Nutrition Cluster - Suspension and Debarment Federal Agency: Department of Agriculture Federal Programs: School Breakfast Program, National School Lunch Program, Summer Food Service Program for Children Assistance Listings Numbers: 10.553, 10.555, 10.559 Federal Award Numbers and Years (or Other Identifying Numbers): FY2023, FY2024 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Procurement and Suspension and Debarment Audit Findings: ...

FINDING 2025-002 Subject: Child Nutrition Cluster - Suspension and Debarment Federal Agency: Department of Agriculture Federal Programs: School Breakfast Program, National School Lunch Program, Summer Food Service Program for Children Assistance Listings Numbers: 10.553, 10.555, 10.559 Federal Award Numbers and Years (or Other Identifying Numbers): FY2023, FY2024 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Procurement and Suspension and Debarment Audit Findings: Material Weakness, Other Matters Condition and Context The School Corporation had not properly designed and implemented a system of internal controls, which would include appropriate segregation of duties, that would likely be effective in preventing, or detecting and correcting, noncompliance related to the Procurement and Suspension and Debarment compliance requirement. Suspension and Debarment Prior to entering into subawards and covered transactions with federal award funds, recipients are required to verify that such contractors and subrecipients are not suspended, debarred, or otherwise excluded. "Covered transactions" include, but are not limited to, contracts for goods and services awarded under a nonprocurement transaction (i.e., grant agreement) that are expected to equal or exceed $25,000. The verification is to be done by checking the SAMs exclusions, collecting a certification from that vendor, or adding a clause or condition to the covered transaction with that vendor. It is the School Corporation's policy that they will either require a certification from the vendor or check the exclusion list prior to entering a covered transaction. The School Corporation entered into three covered transactions during the audit period, and it was unable to provide evidence that it followed its policy for two of those transactions. The total purchases made from these two vendors totaled $93,895. INDIANA STATE BOARD OF ACCOUNTS 15 PAOLI COMMUNITY SCHOOL CORPORATION SCHEDULE OF FINDINGS AND QUESTIONED COSTS (Continued) The lack of internal controls and noncompliance was only noted in the first year of the audit period. Criteria 2 CFR 200.303 states in part: "The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in 'Standards for Internal Control in the Federal Government' issued by the Comptroller General of the United States or the 'Internal Control Integrated Framework', issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). . . ." 2 CFR 180.300 states: "When you enter into a covered transaction with another person at the next lower tier, you must verify that the person with whom you intend to do business is not excluded or disqualified. You do this by: (a) Checking the SAM Exclusions; or (b) Collecting a certification from that person; or (c) Adding a clause or condition to the covered transaction with that person." Cause The School Corporation's management failed to properly design and implement an internal control system that would have ensured that its policy over the Procurement and Suspension and Debarment compliance requirement was adhered to during the audit period. Effect The failure to design and implement an effective internal control system enabled material noncompliance to go undetected. Noncompliance with the grant agreement and the Procurement and Suspension and Debarment compliance requirement could have resulted in the loss of federal funds to the School Corporation. Additionally, the School Corporation could have made payment to a vendor that was suspended or debarred. Payments to such vendors are unallowable. Questioned Costs There were no questioned costs identified. INDIANA STATE BOARD OF ACCOUNTS 16 PAOLI COMMUNITY SCHOOL CORPORATION SCHEDULE OF FINDINGS AND QUESTIONED COSTS (Continued) Recommendation We recommended that the School Corporation's management establish a system of internal controls to ensure compliance and comply with the grant agreement and the Procurement and Suspension and Debarment compliance requirement. The system should be designed to ensure that vendors are not suspended or debarred, or otherwise excluded, prior to the School Corporation entering into a covered transaction. Views of Responsible Officials For the views of responsible officials, refer to the Corrective Action Plan that is part of this report.

FY End: 2025-06-30
City of Lincoln Park, Michigan
Compliance Requirement: B
Assistance Listing, Federal Agency, and Program Name - ALN 14.218, Department of Housing and Urban Development, Community Development Block Grants Federal Award Identification Number and Year - B24MC260070 2025 Pass through Entity - N/A Finding Type - Material weakness Repeat Finding - No Criteria - Per 2 CFR 200.303, the recipient must establish, document, and maintain effective internal control over the federal award that provides reasonable assurance that the recipient is managing the federal...

Assistance Listing, Federal Agency, and Program Name - ALN 14.218, Department of Housing and Urban Development, Community Development Block Grants Federal Award Identification Number and Year - B24MC260070 2025 Pass through Entity - N/A Finding Type - Material weakness Repeat Finding - No Criteria - Per 2 CFR 200.303, the recipient must establish, document, and maintain effective internal control over the federal award that provides reasonable assurance that the recipient is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award. These internal controls should align with the guidance in Standards for Internal Control in the Federal Government, issued by the Comptroller General of the United States, or the Internal Control Integrated Framework, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition - The City initially reported $30,000 of expenditures on the SEFA that related to activity not related to fiscal year 2025. Questioned Costs - N/A If questioned costs are not determinable, description of why known questioned costs were undetermined or otherwise could not be reported - N/A Identification of How Questioned Costs Were Computed - N/A Context - Recipients of federal awards must have controls in place to verify that costs being recorded in the appropriate period. Cause and Effect - The City did not properly allocate the expenditures over the term of the subsciption which led to expenses being improperly recorded in the City's initial SEFA sent to the auditors. Recommendation - We recommend that the City implement stronger internal controls to ensure the expenses are reviewed for cutoff and approved before they are charged to the grant. Views of Responsible Officials and Planned Corrective Actions - The City will ensure that all future expenses under this program go through stronger internal control review for cutoff.

FY End: 2025-06-30
Second Judicial District Court
Compliance Requirement: AB
Criteria or specific requirement: According to 2 CFR §200.303, the recipient must establish, document, and maintain effective internal control over the federal award that provides reasonable assurance that the recipient is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award. According to 2 CFR §200.405(d), if a cost benefits two or more projects or activities in proportions that can be determined without undue effort or c...

Criteria or specific requirement: According to 2 CFR §200.303, the recipient must establish, document, and maintain effective internal control over the federal award that provides reasonable assurance that the recipient is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award. According to 2 CFR §200.405(d), if a cost benefits two or more projects or activities in proportions that can be determined without undue effort or cost, the cost must be allocated to the projects based on the proportional benefit However, when those proportions cannot be determined because of the interrelationship of the work involved, then the costs may be allocated or transferred to benefitted projects on any reasonable documented basis. According to 2 CFR §200.431(b), the cost of fringe benefits in the form of regular compensation paid to employees during periods of authorized absences from the job, such as for annual leave, family-related leave, sick leave, holidays, court leave, military leave, administrative leave, and other similar benefits, are allowable if all of the following criteria are met: (1) They are provided under established written leave policies; (2) The costs are equitably allocated to all related activities, including Federal awards; and, (3) The accounting basis (cash or accrual) selected for costing each type of leave is consistently followed by the recipient or subrecipient or a specified grouping of employees. Condition: During our testing, we noted that the Department did not allocate leave to grants in accordance with the time and effort employees spent on the grants. Questioned costs: $887 Context: During our testing of twenty payroll disbursements, we noted that the Department had a net undercharge of $887 to eight grants. Cause: The Department was unaware of the federal regulations pertaining to leave allocations. Effect: The auditor noted instances of noncompliance. Noncompliance results in possible under or over charges to the grant. Repeat Finding: No. Recommendation: We recommend that the Department develop and implement a written policy for leave allocation consistent with federal regulations. Also, we recommend that the Department provides training to ensure employees understand and comply with the written policy. Views of responsible officials and planned corrective actions: The Department recognizes the audit finding and its responsibility to comply with 2 CFR §200.405(d). Corrective action was taken. The Department revised the procedures and will no longer charge any type of leave activity to a grant, effective July 1, 2025, and for the foreseeable future. An email was sent out by the CFO on June 26, 2025 advising all Department employees about this change. The Federal Aid Cost Tracking System (FACTS) has also been changed to block access to all grants for any leave time reporting code entries. If a system is developed in the future to enable the allocation of leave consistent will the federal regulations, training will be provided for all employees. Responsible Employee Position: CFO Timeline: July 31, 2026

FY End: 2025-06-30
Second Judicial District Court
Compliance Requirement: AB
Criteria or specific requirement: According to 2 CFR §200.303, the recipient must establish, document, and maintain effective internal control over the federal award that provides reasonable assurance that the recipient is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award. According to 2 CFR §200.403(f), except where otherwise authorized by statute, costs must meet not be included as a cost or used to meet cost sharing ...

Criteria or specific requirement: According to 2 CFR §200.303, the recipient must establish, document, and maintain effective internal control over the federal award that provides reasonable assurance that the recipient is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award. According to 2 CFR §200.403(f), except where otherwise authorized by statute, costs must meet not be included as a cost or used to meet cost sharing requirements of any other federally-financed program in either the current or a prior period. Condition: During our testing of drawdowns related to matching, we noted that the Department did not adjust its reimbursement request to account for a duplicate travel reimbursement. Questioned costs: $169 Context: The Department processed a travel reimbursement twice, resulting in a duplicate payment of $225 to the employee. The employee reimbursed the Department for this duplicate payment. However, the Department did not adjust its reimbursement request to reflect the credit in the financial records. Cause: The Department was unaware that the query used for the reimbursement request excluded the credit. Effect: The auditor noted an instance of noncompliance. Noncompliance results in possible under or over charges to the grant. Repeat Finding: No. Recommendation: We recommend that the Department identify the reason for the exclusion of the credit in its query. Additionally, the Department should consider reviewing the query to the general ledger as part of the final review before submitting the reimbursement request. Views of responsible officials and planned corrective actions: The Department recognizes the audit finding and its responsibility to comply with 2 CFR §200.403(f). Corrective action will be taken. The Department revised the policies and procedures for cash disbursements within the Administrative Services Division. Effective immediately, upon running the monthly query of federal expenditures for the cash reimbursement for federal grants, the Federal Financial Analyst will submit the query to the Budget Director and the Accountant/Auditor. A reconciliation to the General Ledger will be completed by them prior to the Federal Financial Analyst requesting the cash reimbursement. Responsible Employee Position: CFO Timeline: July 31, 2026

FY End: 2025-06-30
Greater Jasper Consolidated Schools
Compliance Requirement: F
FINDING 2025-001 Subject: COVID-19 - Education Stabilization Fund - Equipment and Real Property Management Federal Agency: Department of Education Federal Program: COVID-19 - Education Stabilization Fund Assistance Listings Number: 84.425D Federal Award Number and Year (or Other Identifying Number): S425D210013 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Equipment and Real Property Management Audit Findings: Material Weakness, Other Matters INDIANA STATE BOARD OF...

FINDING 2025-001 Subject: COVID-19 - Education Stabilization Fund - Equipment and Real Property Management Federal Agency: Department of Education Federal Program: COVID-19 - Education Stabilization Fund Assistance Listings Number: 84.425D Federal Award Number and Year (or Other Identifying Number): S425D210013 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Equipment and Real Property Management Audit Findings: Material Weakness, Other Matters INDIANA STATE BOARD OF ACCOUNTS 15 GREATER JASPER CONSOLIDATED SCHOOLS SCHEDULE OF FINDINGS AND QUESTIONED COSTS (Continued) Repeat Finding This is a repeat finding from the immediately prior audit report. The prior audit finding number was 2023-006. Condition and Context A property record or capital asset listing would include the following for each asset: a description of the property, a serial number or other identification number, the source of funding for the property (including the federal award identification number (FAIN)), who holds title, the acquisition date, cost of the property, percentage of federal participation in the project costs for the federal award under which the property was acquired, the location, use and condition of the property, and any ultimate disposition data including the date of disposal and sale price of the property. The property record or capital asset listing should be maintained for assets purchased that exceed the School Corporation's capitalization threshold. The School Corporation did not properly design or implement a system of internal controls, which would include appropriate segregation of duties, that would likely be effective in preventing, or detecting and correcting, noncompliance. The School Corporation purchased a laser engraver during the audit period from the ESSER II grant totaling $29,655. The asset was purchased using ESSER II funds obtained by the Special Education Cooperative (Cooperative), for which the School Corporation is the fiscal agent. The asset exceeded the School Corporation's capitalization threshold of $5,000; but was omitted from the capital asset listing. Additionally, proper safeguards were not put in place to protect the asset. The lack of internal controls and noncompliance were systemic issues throughout the audit period. Criteria 2 CFR 200.303 states in part: "The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in 'Standards for Internal Control in the Federal Government' issued by the Comptroller General of the United States or the 'Internal Control Integrated Framework', issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). . . ." 2 CFR 200.313(d) states in part: "Management requirements. Procedures for managing equipment (including replacement equipment), whether acquired in whole or in part under a Federal award, until disposition takes place will, as a minimum, meet the following requirements: (1) Property records must be maintained that include a description of the property, a serial number or other identification number, the source of funding for the property (including the FAIN), who holds title, the acquisition date, cost of the property, percentage of Federal participation in the project costs for the Federal award under which the property was acquired, the location, use and condition of the property, and any ultimate disposition data including the date of disposal and sales price of the property. INDIANA STATE BOARD OF ACCOUNTS 16 GREATER JASPER CONSOLIDATED SCHOOLS SCHEDULE OF FINDINGS AND QUESTIONED COSTS (Continued) (2) A physical inventory of the property must be conducted, and the results must be reconciled with the property records at least once every two years. (3) A control system must be developed to ensure adequate safeguards to prevent loss, damage, or theft of the property. Any loss, damage, or theft must be investigated. . . ." Cause Although management was aware of the equipment purchase by the Cooperative and the related invoice, they misidentified the ownership of the asset, believing it did not belong to the School Corporation. Furthermore, the School Corporation and the Cooperative had not established formalized procedures to ensure that assets acquired under such agreements were identified, communicated, and recorded in accordance with federal guidelines and the School Corporation's capital asset policies. Effect Without the proper implementation of an effectively designed system of internal controls, the internal control system cannot be capable of effectively preventing, or detecting and correcting, material noncompliance. As a result, assets purchased with federal dollars, ESSER funds, were not properly added to the School Corporation's asset listing. In addition, assets on the listing did not denote whether federal funds were used to acquire the asset or an identification number. Questioned Costs There were no questioned costs identified. Recommendation We recommended that management of the School Corporation establish a proper system of internal controls and develop policies and procedures to ensure asset records include all the necessary information and new assets are added, including those of the Cooperative. Views of Responsible Officials For the views of responsible officials, refer to the Corrective Action Plan that is part of this report.

FY End: 2025-06-30
Early Education and Care, Inc.
Compliance Requirement: L
Item 2025-001 Reporting Head Start ALN# 93.600 US Department of Health & Human Services Federal Grant/Contract Number: 04CH01239502 Grant period – 2025 Criteria – Grantees should have controls in place to ensure that grant reports are being submitted to the grantor and that those reports are being properly reviewed and approved prior to submission. 2 CFR 200.303 requires the non-Federal entity to “(a) establish, document and maintain effective internal controls over the Federal award that provid...

Item 2025-001 Reporting Head Start ALN# 93.600 US Department of Health & Human Services Federal Grant/Contract Number: 04CH01239502 Grant period – 2025 Criteria – Grantees should have controls in place to ensure that grant reports are being submitted to the grantor and that those reports are being properly reviewed and approved prior to submission. 2 CFR 200.303 requires the non-Federal entity to “(a) establish, document and maintain effective internal controls over the Federal award that provides reasonable assurance that the recipient is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award.” Condition – Adequate controls were not in place to ensure reports were being submitted to the grantor. One of the two Federal Financial Reports (SF-425) for the Head Start Cluster grants was not properly complete and submitted to the Payment Management System. Cause – The Agency encountered turnover within its fiscal staff during the current year which resulted in a lack of awareness of the report filing requirements and deadlines. Effect – Failure to complete and submit the proper reporting could result in a delay or loss of funding. Questioned Costs – Not applicable. Recommendation – We recommend the Agency implement controls designed to ensure that grant reporting requirements are met on a timely basis. Management’s Response – Management has reviewed and accepted the finding. See “Corrective Action Plan”.

FY End: 2025-06-30
West Lafayette Community School Corporation
Compliance Requirement: G
FINDING 2025-002 Subject: Special Education Cluster (IDEA) - Earmarking Federal Agency: Department of Education Federal Programs: Special Education Grants to States, COVID-19 - Special Education Grants to States, Special Education Preschool Grants, COVID-19 - Special Education Preschool Grants Assistance Listings Numbers: 84.027, 84.027X, 84.173, 84.173X Federal Award Numbers and Years (or Other Identifying Numbers): 22611-021-PN01, 22611-021-ARP, 22619-021-ARP, 23611-021-PN01, 23619-021-PN01 Pa...

FINDING 2025-002 Subject: Special Education Cluster (IDEA) - Earmarking Federal Agency: Department of Education Federal Programs: Special Education Grants to States, COVID-19 - Special Education Grants to States, Special Education Preschool Grants, COVID-19 - Special Education Preschool Grants Assistance Listings Numbers: 84.027, 84.027X, 84.173, 84.173X Federal Award Numbers and Years (or Other Identifying Numbers): 22611-021-PN01, 22611-021-ARP, 22619-021-ARP, 23611-021-PN01, 23619-021-PN01 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Matching, Level of Effort, Earmarking Audit Findings: Material Weakness, Modified Opinion Repeat Finding This is a repeat finding from the immediately prior audit report. The prior audit finding number was 2023-001. INDIANA STATE BOARD OF ACCOUNTS 16 WEST LAFAYETTE COMMUNITY SCHOOL CORPORATION SCHEDULE OF FINDINGS AND QUESTIONED COSTS (Continued) Condition and Context The School Corporation is a member of the Greater Lafayette Area Special Services Cooperative (Cooperative). During fiscal year 2023-2024, the Cooperative operated the special education programs and spent the federal money on behalf of all its members. As the grant agreements were between the Indiana Department of Education (IDOE) and each member school, the School Corporation was responsible for ensuring and providing oversight of the Cooperative. However, there was inadequate oversight performed by the School Corporation to ensure compliance with the Matching, Level of Effort, Earmarking compliance requirement. The School Corporation did not have internal controls in place to ensure that the Cooperative complied with the earmarking requirements. The Cooperative did not have adequate procedures in place to ensure that the required level of expenditures for nonpublic school students with disabilities was met for each member school. The Cooperative did not have effective internal controls to ensure nonpublic school expenditures were appropriately identified and reported. The nonpublic proportionate share expenditures for the 22611-021-PN01, 22611-021-ARP, 22619-021-ARP, 23611-021-PN01, and 23619-021-PN01 grant awards could not be verified for the individual member schools. Total grant expenditures were posted as expended. The nonpublic proportionate share expenditures were determined by applying a percentage to the nonpublic school budgeted expenditures. As such, we were unable to identify if the minimum amount per the grant awards was expended and properly reported to the IDOE as required. The lack of internal controls and noncompliance were isolated to the 22611-021-PN01, 22611-021-ARP, 22619-021-ARP, 23611-021-PN01, and 23619-021-PN01 grant awards. Criteria 2 CFR 200.303 states in part: "The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in 'Standards for Internal Control in the Federal Government' issued by the Comptroller General of the United States or the 'Internal Control Integrated Framework', issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). . . ." 2 CFR 200.403 states in part: "Except where otherwise authorized by statute, costs must meet the following general criteria in order to be allowable under Federal awards: . . . (g) Be adequately documented. . . ." 2 CFR 200.208(b) states in part: "The Federal awarding agency or pass-through entity may adjust specific Federal award conditions as needed . . ." INDIANA STATE BOARD OF ACCOUNTS 17 WEST LAFAYETTE COMMUNITY SCHOOL CORPORATION SCHEDULE OF FINDINGS AND QUESTIONED COSTS (Continued) 511 IAC 7-34-7(b) states: "The public agency, in providing special education and related services to students in nonpublic schools must expend at least an amount that is the same proportion of the public agency total subgrant under 20 U.S.C. 1411(f) as the number of nonpublic school students with disabilities, who are enrolled by their parents in nonpublic schools within its boundaries, is to the total number of students with disabilities of the same age range." Cause Records were not kept at the School Corporation or the Cooperative of funds spent by each member school corporation on nonpublic school students with disabilities. In reporting the amount expended for this purpose, the amounts reported as expenditures for nonpublic school students was based on a percentage to the schools nonpublic budgeted expenditures. Effect Without the proper implementation of an effectively designed system of internal controls, the internal control system cannot be capable of effectively preventing, or detecting and correcting, material noncompliance. As such, the School Corporation's nonpublic proportionate share expenditures could not be determined, and it could not be determined if the School Corporation met its minimum nonpublic proportionate share as required by the grant agreement. Noncompliance with the provisions of federal statutes, regulations, and the terms and conditions of the federal award could result in the loss of future federal funding to the School Corporation. Questioned Costs There were no questioned costs identified. Recommendation We recommended that management of the School Corporation establish a proper system of internal controls and develop policies and procedures to ensure nonpublic proportionate share funds are appropriately allocated to the member school based on expenses charged directly on behalf of the member school. Supporting documentation for these expenses should be retained for audit. Views of Responsible Officials For the views of responsible officials, refer to the Corrective Action Plan that is part of this report.

FY End: 2025-06-30
Show Low Unified School District No. 10
Compliance Requirement: L
2025-001 Child Nutrition Claims Reporting CFDA No: 10.553, 10.555 Program Name: Child Nutrition Cluster Award Number: 7AZ300AZ3 Federal Agency: U.S. Department of Agriculture Pass-Through Grantor: Arizona Department of Education Compliance Requirement: L. Reporting Questioned Costs: N/A Summary of Finding: Significant Deficiency in internal control over major programs Repeat Finding? No Condition For the period reviewed, the District submitted meal counts that did not agree to supporting documen...

2025-001 Child Nutrition Claims Reporting CFDA No: 10.553, 10.555 Program Name: Child Nutrition Cluster Award Number: 7AZ300AZ3 Federal Agency: U.S. Department of Agriculture Pass-Through Grantor: Arizona Department of Education Compliance Requirement: L. Reporting Questioned Costs: N/A Summary of Finding: Significant Deficiency in internal control over major programs Repeat Finding? No Condition For the period reviewed, the District submitted meal counts that did not agree to supporting documentation and accurate claim totals. Specifically, the District: Overreported breakfasts by 2,527 free breakfasts and 143 reduced-price breakfasts Underreported lunches by 2,139 free lunches and 125 reduced-price lunches. These errors indicate that the reported counts used to prepare the District’s Claim for Reimbursement were not accurate and were not adequately reviewed prior to submission. Criteria According to 7 CFR §210.8, the District shall establish internal controls which ensure the accuracy of meal counts prior to the submission of the monthly claim for reimbursement. The Uniform Guidance requires non-federal entities to establish and maintain effective internal control over the federal award to provide reasonable assurance that the entity is managing the award in compliance with federal statutes, regulations, and the terms and conditions of the federal award (2 CFR 200.303). Cause The District did not have adequately designed and/or consistently implemented internal controls over the reporting process to ensure meal counts reported on claims were accurate prior to submission. Effect The District is not in compliance with the requirements of the Uniform Guidance and related federal grant federal regulations. Recommendation The District should ensure adequate supporting documentation is maintained and the monthly meal reimbursements are reviewed by management before submission to the Arizona Department of Education.

FY End: 2025-06-30
Metropolitan School District of Washington Township
Compliance Requirement: I
FINDING 2025-001 Subject: Child Nutrition Cluster - Procurement and Suspension and Debarment Federal Agency: Department of Agriculture Federal Programs: School Breakfast Program, National School Lunch Program, Summer Food Service Program for Children Assistance Listings Numbers: 10.553, 10.555, 10.559 Federal Award Numbers and Years (or Other Identifying Numbers): FY 2024, FY 2025 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Procurement and Suspension and Debarmen...

FINDING 2025-001 Subject: Child Nutrition Cluster - Procurement and Suspension and Debarment Federal Agency: Department of Agriculture Federal Programs: School Breakfast Program, National School Lunch Program, Summer Food Service Program for Children Assistance Listings Numbers: 10.553, 10.555, 10.559 Federal Award Numbers and Years (or Other Identifying Numbers): FY 2024, FY 2025 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Procurement and Suspension and Debarment Audit Findings: Material Weakness, Other Matters Condition and Context An effective internal control system, which would include segregation of duties, was not in place at the School Corporation in order to ensure compliance with requirements related to the grant agreement and the Procurement and Suspension and Debarment compliance requirement. Adequate internal controls were not in place over procurements made under the simplified acquisition threshold for one of two vendors tested during the audit period. The School Corporation made purchases with a vendor in fiscal year 2023-2024 totaling $289,127, but it did not provide audit evidence that methods and procedures performed for the selection of the vendor aligned with requirements related to vendors procured under the simplified acquisition threshold. Adequate internal controls were not in place over procurements made under the small purchase threshold for one of five vendors tested during the audit period. The School Corporation made purchases with a vendor in 2023-2024 totaling $103,519 and in 2024-2025 totaling $111,613, but it did not provide audit evidence that the procurement procedures performed in relation to the award had been reviewed or approved. The School Corporation did not provide documentation that it had entered into a contract with the vendor during either year of the audit period. The lack of internal controls was a systemic issue throughout the audit period. The noncompliance was isolated to procurement requirements. Criteria 2 CFR 200.303 states in part: "The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in 'Standards for Internal Control in the Federal Government' issued by the Comptroller General of the United States or the 'Internal Control Integrated Framework', issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). . . ." INDIANA STATE BOARD OF ACCOUNTS 18 METROPOLITAN SCHOOL DISTRICT OF WASHINGTON TOWNSHIP SCHEDULE OF FINDINGS AND QUESTIONED COSTS (Continued) 2 CFR 200.318(a): "The non-Federal entity must have and use documented procurement procedures, consistent with State, local, and tribal laws and regulations and the standards of this section, for the acquisition of property or services required under a Federal award or subaward. The non- Federal entity's documented procurement procedures must conform to the procurement standards identified in §§ 200.317 through 200.327." 2 CFR 200.320 states in part: "The non-Federal entity must have and use documented procurement procedures, consistent with the standards of this section and §§ 200.317, 200.318, and 200.319 for any of the following methods of procurement used for the acquisition of property or services required under a Federal award or sub-award. (a) Informal procurement methods. When the value of the procurement for property or services under a Federal award does not exceed the simplified acquisition threshold (SAT), as defined in § 200.1, or a lower threshold established by a non-Federal entity, formal procurement methods are not required. The non-Federal entity may use informal procurement methods to expedite the completion of its transactions and minimize the associated administrative burden and cost. The informal methods used for procurement of property or services at or below the SAT include: . . . (1) . . . (iv) Non-Federal entity increase to the micro-purchase threshold up to $50,000. Non-Federal entities may establish a threshold higher than the micro-purchase threshold identified in the FAR in accordance with the requirements of this section. The non-Federal entity may self-certify a threshold up to $50,000 on an annual basis and must maintain documentation to be made available to the Federal awarding agency and auditors in accordance with § 200.334. The self-certification must include a justification, clear identification of the threshold, and supporting documentation of any of the following: (A) A qualification as a low-risk auditee, in accordance with the criteria in § 200.520 for the most recent audit; (B) An annual internal institutional risk assessment to identify, mitigate, and manage financial risks; or, (C) For public institutions, a higher threshold consistent with State law. . . . (b) Formal procurement methods. When the value of the procurement for property or services under a Federal financial assistance award exceeds the SAT, or a lower threshold established by a non-Federal entity, formal procurement methods are required. Formal procurement methods require following documented procedures. Formal procurement methods also require public advertising unless a non-competitive procurement can be used in accordance with § 200.319 or paragraph (c) of this section. The following formal methods of procurement are used for procurement of property or services above the simplified acquisition threshold or a value below the simplified acquisition threshold the non-Federal entity determines to be appropriate: INDIANA STATE BOARD OF ACCOUNTS 19 METROPOLITAN SCHOOL DISTRICT OF WASHINGTON TOWNSHIP SCHEDULE OF FINDINGS AND QUESTIONED COSTS (Continued) (1) Sealed bids. A procurement method in which bids are publicly solicited and a firm fixed-price contract (lump sum or unit price) is awarded to the responsible bidder whose bid, conforming with all the material terms and conditions of the invitation for bids, is the lowest in price. The sealed bids method is the preferred method for procuring construction, if the conditions. (i) In order for sealed bidding to be feasible, the following conditions should be present: (A) A complete, adequate, and realistic specification or purchase description is available; (B) Two or more responsible bidders are willing and able to compete effectively for the business; and (C) The procurement lends itself to a firm fixed price contract and the selection of the successful bidder can be made principally on the basis of price. (ii) If sealed bids are used, the following requirements apply: (A) Bids must be solicited from an adequate number of qualified sources, providing them sufficient response time prior to the date set for opening the bids, for local, and tribal governments, the invitation for bids must be publicly advertised; (B) The invitation for bids, which will include any specifications and pertinent attachments, must define the items or services in order for the bidder to properly respond; (C) All bids will be opened at the time and place prescribed in the invitation for bids, and for local and tribal governments, the bids must be opened publicly; (D) A firm fixed price contract award will be made in writing to the lowest responsive and responsible bidder. Where specified in bidding documents, factors such as discounts, transportation cost, and life cycle costs must be considered in determining which bid is lowest. Payment discounts will only be used to determine the low bid when prior experience indicates that such discounts are usually taken advantage of; and (E) Any or all bids may be rejected if there is a sound documented reason. (2) Proposals. A procurement method in which either a fixed price or costreimbursement type contract is awarded. Proposals are generally used when conditions are not appropriate for the use of sealed bids. They are awarded in accordance with the following requirements: (i) Requests for proposals must be publicized and identify all evaluation factors and their relative importance. Proposals must be solicited from an adequate number of qualified offerors. Any response to publicized requests for proposals must be considered to the maximum extent practical; INDIANA STATE BOARD OF ACCOUNTS 20 METROPOLITAN SCHOOL DISTRICT OF WASHINGTON TOWNSHIP SCHEDULE OF FINDINGS AND QUESTIONED COSTS (Continued) (ii) The non-Federal entity must have a written method for conducting technical evaluations of the proposals received and making selections; (iii) Contracts must be awarded to the responsible offeror whose proposal is most advantageous to the non-Federal entity, with price and other factors considered; and (iv) The non-Federal entity may use competitive proposal procedures for qualifications based procurement of architectural/engineering (A/E) professional services whereby offeror's qualifications are evaluated and the most qualified offeror is selected, subject to negotiation of fair and reasonable compensation. The method, where price is not used as a selection factor, can only be used in procurement of A/E professional services. It cannot be used to purchase other types of services though A/E firms that are a potential source to perform the proposed effort. . . ." Cause Staff responsible for purchasing were not adequately trained on the School Corporation's procurement policy for obtaining bids for purchases above the simplified acquisition threshold and formal contract requirements for purchases above $50,000. Effect Without the proper implementation of an effectively designed system of internal controls, the School Corporation cannot ensure that contractors paid under the small purchase and simplified acquisition methods were awarded the best price for their services. This could result in federal funding not providing as many services or projects as possible. Questioned Costs There were no questioned costs identified. Recommendation We recommended that the School Corporation strengthen its system of internal controls to ensure the proper procurement method is followed and documentation is retained. We also recommended strengthening its policies and procedures to ensure that appropriate audit evidence is retained for audit. Views of Responsible Official For the views of responsible officials, refer to the Corrective Action Plan that is part of this report.

FY End: 2025-06-30
Metropolitan School District of Washington Township
Compliance Requirement: N
FINDING 2025-002 Subject: Title I Grants to Local Educational Agencies - Special Tests and Provisions - Annual Report Card, High School Graduation Rate Federal Agency: Department of Education Federal Program: Title I Grants to Local Educational Agencies Assistance Listings Number: 84.010 Federal Award Numbers and Years (or Other Identifying Numbers): S010A220014; S010A230014 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Special Tests and Provisions - Annual Report ...

FINDING 2025-002 Subject: Title I Grants to Local Educational Agencies - Special Tests and Provisions - Annual Report Card, High School Graduation Rate Federal Agency: Department of Education Federal Program: Title I Grants to Local Educational Agencies Assistance Listings Number: 84.010 Federal Award Numbers and Years (or Other Identifying Numbers): S010A220014; S010A230014 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Special Tests and Provisions - Annual Report Card, High School Graduation Rate Audit Findings: Material Weakness, Modified Opinion Condition and Context The School Corporation had not properly designed or implemented a system of internal controls, which would include appropriate segregation of duties, that would likely be effective in preventing, or detecting and correcting, noncompliance to ensure that documentation regarding the reason for a student being removed from the high school graduation cohort for mobility reasons was prepared, reviewed, and retained. The Special Tests and Provisions - Annual Report Card, High School Graduation Rate compliance requirement necessitated that for students removed from the high school graduation cohort for mobility reasons there be proper written documentation to support the identified mobility code. There were 15 students selected for testing. Of the 15 students tested, 3 students did not have the required supporting documentation to substantiate removal from the cohort for mobility reasons. The lack of internal controls and noncompliance were systemic issues throughout the audit period. Criteria 2 CFR 200.303 states in part: "The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in 'Standards for Internal Control in the Federal Government' issued by the Comptroller General of the United States or the 'Internal Control Integrated Framework', issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). . . ." 20 USC 7801(23)(B) states: "To remove a student from a cohort, a school or local educational agency shall require documentation, or obtain documentation from the State educational agency, to confirm that the student has transferred out, emigrated to another country, or transferred to a prison or juvenile facility, or is deceased." INDIANA STATE BOARD OF ACCOUNTS 22 METROPOLITAN SCHOOL DISTRICT OF WASHINGTON TOWNSHIP SCHEDULE OF FINDINGS AND QUESTIONED COSTS (Continued) 2 CFR 200.334 states in part: "Financial records, supporting documents, statistical records, and all other non-Federal entity records pertinent to a Federal award must be retained for a period of three years from the date of submission of the final expenditure report or, for the Federal awards that are renewed quarterly or annual, from the date of submission of the quarterly or annual financial report, respectively, as reported to the Federal awarding agency or pass-through entity in the case of a subrecipient. . . ." Cause The School Corporation did not have consistent procedures for maintaining and retaining supporting documentation related to student cohort changes. Effect Without the proper implementation of an effectively designed system of internal controls, the internal control system cannot be capable of effectively preventing, or detecting and correcting, material noncompliance. As a result, proper documentation was not maintained for students that were removed from the cohort for mobility reasons. Noncompliance with the grant agreement and the compliance requirement could result in the loss of future federal funds to the School Corporation. Questioned Costs There were no questioned costs identified. Recommendation We recommended that the School Corporation's management establish a proper system of internal controls and develop policies and procedures to ensure proper documentation is maintained for students that are removed from the cohort. Views of Responsible Officials For the views of responsible officials, refer to the Corrective Action Plan that is part of this report.

FY End: 2025-06-30
Metropolitan School District of Washington Township
Compliance Requirement: N
FINDING 2025-003 Subject: COVID-19 - Education Stabilization Fund - Special Tests and Provisions - Wage Rate Requirements Federal Agency: Department of Education Federal Program: COVID-19 - Education Stabilization Fund Assistance Listings Numbers: 84.425D, 84.425U Federal Award Numbers and Years (or Other Identifying Numbers): S425D210013, S425U210013 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Special Tests and Provisions - Wage Rate Requirements Audit Findings:...

FINDING 2025-003 Subject: COVID-19 - Education Stabilization Fund - Special Tests and Provisions - Wage Rate Requirements Federal Agency: Department of Education Federal Program: COVID-19 - Education Stabilization Fund Assistance Listings Numbers: 84.425D, 84.425U Federal Award Numbers and Years (or Other Identifying Numbers): S425D210013, S425U210013 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Special Tests and Provisions - Wage Rate Requirements Audit Findings: Material Weakness, Modified Opinion INDIANA STATE BOARD OF ACCOUNTS 23 METROPOLITAN SCHOOL DISTRICT OF WASHINGTON TOWNSHIP SCHEDULE OF FINDINGS AND QUESTIONED COSTS (Continued) Repeat Finding This is a repeat finding from the immediately prior audit report. The prior audit finding number was 2023-005. Condition and Context Construction contracts in excess of $2,000 financed by federal assistance funds must pay wages not less than those established for the locality of the project (prevailing wage rates) by the Department of Labor (DOL) to its laborers and mechanics. Nonfederal entities are to include in its construction contracts subject to the Wage Rate Requirements a provision that the contractor or subcontractor comply with these requirements and the DOL regulations. This would include a requirement to submit a copy of the payroll and statement of compliance to the entity for each week in which contract work was performed. The School Corporation had not designed nor implemented a system of internal controls to ensure that construction contracts in excess of $2,000 paid from federal grant funds included a prevailing wage rate clause. Seven contracts entered into by the School Corporation during the audit period were to be paid from multiple fund sources, including the COVID-19 - Education Stabilization Fund grant funds. Total expenditures from the COVID-19 - Education Stabilization Fund grant funds during the audit period was $1,267,312. Of the seven contracts, two were tested and did not contain the required prevailing wage rate clause. Furthermore, five invoices were tested and did not include the required certified payrolls from the contractors. The lack of internal controls and noncompliance were systemic issues throughout the audit period. Criteria 2 CFR 200.303 states in part: "The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in 'Standards for Internal Control in the Federal Government' issued by the Comptroller General of the United States or the 'Internal Control Integrated Framework', issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). . . ." 29 CFR 5.5 states in part: "(a) Required contract clauses. The Agency head will cause or require the contracting officer to require the contracting officer to [sic] insert in full, or (for contracts covered by the Federal Acquisition Regulation (48 CFR chapter 1)) by reference, in any contract in excess of $2,000 which is entered into for the actual construction, alteration and/or repair, including painting and decorating, of a public building or public work, or building or work financed in whole or in part from Federal funds or in accordance with guarantees of a Federal agency or financed from funds obtained by pledge of any contract of a Federal agency to make a loan, grant or annual contribution (except where a different meaning is expressly indicated), and which is subject to the labor standards provisions of any of the laws referenced by § 5.1, the following clauses . . . INDIANA STATE BOARD OF ACCOUNTS 24 METROPOLITAN SCHOOL DISTRICT OF WASHINGTON TOWNSHIP SCHEDULE OF FINDINGS AND QUESTIONED COSTS (Continued) (1) Minimum wages– (i) Wage rates and fringe benefits. All laborers and mechanics employed or working upon the site of the work (or otherwise working in construction or development of the project under a development statute), will be paid unconditionally and not less often than once a week, and without subsequent deduction or rebate on any account (except such payroll deductions as are permitted by regulations issued by the Secretary of Labor under the Copeland Act (29 CFR part 3)), the full amount of basic hourly wages and bona fide fringe benefits (or cash equivalents thereof) due at time of payment computed at rates not less than those contained in the wage determination of the Secretary of Labor which is attached hereto and made a part hereof, regardless of any contractual relationship which may be alleged to exist between the contractor and such laborers and mechanics. . . . (3) Records and certified payrolls– . . . (ii) Certified payroll requirements– (A) Frequency and method of submission. The contractor or subcontractor must submit weekly, for each week in which any DBA- or Related Acts-covered work is performed, certified payrolls to the [write in name of appropriate Federal agency] if the agency is a party to the contract, but if the agency is not such a party, the contractor will submit the certified payrolls to the applicant, sponsor, owner, or other entity, as the case may be, that maintains such records, for transmission to the [write in name of agency]. . . ." 2 CFR 200 Appendix II states in part: "In addition to other provisions required by the Federal agency or non-Federal entity; all contracts made by the non-Federal entity under the Federal award must contain provisions covering the following, as applicable. . . . (D) Davis-Bacon Act, as amended (40 U.S.C. 3141-3148). When required by Federal program legislation, all prime construction contracts in excess of $2,000 awarded by non-Federal entities must include a provision for compliance with the Davis-Bacon Act (40 U.S.C. 3141-3144, and 3146-3148) as supplemented by Department of Labor regulations (29 CFR Part 5, 'Labor Standards Provisions Applicable to Contracts Covering Federally Financed and Assisted Construction'). In accordance with the statute, contractors must be required to pay wages to laborers and mechanics at a rate not less than the prevailing wages specified in a wage determination made by the Secretary of Labor. In addition, contractors must be required to pay wages not less than once a week. . . ." Cause The School Corporation did not amend contracts that were entered into prior to the guidance of the wage rate clause being required to be included in the contracts. INDIANA STATE BOARD OF ACCOUNTS 25 METROPOLITAN SCHOOL DISTRICT OF WASHINGTON TOWNSHIP SCHEDULE OF FINDINGS AND QUESTIONED COSTS (Continued) Effect Without the proper implementation of an effectively designed system of internal controls, the internal control system cannot be capable of effectively preventing, or detecting and correcting, material noncompliance. As a result, construction contracts entered into did not contain the required wage rate requirements clauses, nor were certified payrolls obtained by the School Corporation. Noncompliance with the grant agreement and the compliance requirement could result in the loss of future federal funds to the School Corporation. Questioned Costs There were no questioned costs identified. Recommendation We recommended that the School Corporation's management establish a system of internal controls and include the wage rate requirement clause in construction contracts. In addition, certified payrolls should be obtained as required in a timely manner. Views of Responsible Officials For the views of responsible officials, refer to the Corrective Action Plan that is part of this report.

« 1 11 12 14 15 1998 »