2 CFR 200 § 200.303

Findings Citing § 200.303

Internal controls.

Total Findings
99,897
Across all audits in database
Showing Page
265 of 1998
50 findings per page
About this section
Section 200.303 requires recipients and subrecipients of Federal awards to establish and maintain effective internal controls to ensure compliance with Federal laws and award conditions. This section affects organizations receiving Federal funding, mandating them to monitor compliance, address noncompliance promptly, and protect sensitive information.
View full section details →
FY End: 2024-06-30
Madison Consolidated Schools
Compliance Requirement: E
FINDING 2024-005 Subject: Title I Grants to Local Educational Agencies - Eligibility Federal Agency: Department of Education Federal Program: Title I Grants to Local Educational Agencies Assistance Listings Number: 84.010 Federal Award Numbers and Years (or Other Identifying Numbers): S010A210014, S010A220014, S010A230014 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Eligibility Audit Findings: Material Weakness, Modified Opinion Repeat Finding This is a repeat fin...

FINDING 2024-005 Subject: Title I Grants to Local Educational Agencies - Eligibility Federal Agency: Department of Education Federal Program: Title I Grants to Local Educational Agencies Assistance Listings Number: 84.010 Federal Award Numbers and Years (or Other Identifying Numbers): S010A210014, S010A220014, S010A230014 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Eligibility Audit Findings: Material Weakness, Modified Opinion Repeat Finding This is a repeat finding from the immediately prior audit report. The prior audit finding number was 2022-003. INDIANA STATE BOARD OF ACCOUNTS 23 MADISON CONSOLIDATED SCHOOLS SCHEDULE OF FINDINGS AND QUESTIONED COSTS (Continued) Condition and Context Eligibility for Title I is determined on the Eligible School Summary of the Tile I application. Enrollment and Poverty numbers are automatically pulled from the Indiana Department of Education's (IDOE) Official Pupil Enrollment (PE) count for each school into the Eligible School Summary page of the Tile I application. These counts that are prepopulated should be based on the School Corporation's records as of October of the prior fiscal year. One person compiled and uploaded enrollment data, including poverty status for Real Time (RT) reports, to the IDOE without a documented oversight or review process to ensure that the information was accurate and retained for audit. In addition, there was no review by the School Corporation of the enrollment and poverty counts that were prepopulated into the School Corporation's Title I grant application. The IDOE used the October 1 RT reports for fiscal years 2021-2022 and 2022-2023, as provided by the School Corporation, to determine Eligibility for the 2022-2023 and 2023-2024 grant programs, respectively. The October 1 RT report could not be presented for audit for 2021-2022, which would have been used to pull in enrollment and poverty information for the 2022-2023 grant. As such, we were unable to verify the amounts reported in the grant application. Additionally, the Indiana State Board of Accounts was unable to verify if the correct socioeconomic status was properly reported for any of the students. Enrollment and poverty numbers for any nonpublic schools are manually entered into the application by the School Corporation. The School Corporation had not established an effective process to review the listing of students from the nonpublic schools for enrollment and poverty counts to be entered into the Title I application and to retain this information for audit. We were unable to determine if the enrolled student count and their poverty status in the application was accurate. The lack of internal controls and lack of information submitted for audit was a systemic issue throughout the audit period. Criteria 2 CFR 200.303 states in part: "The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in 'Standards for Internal Control in the Federal Government' issued by the Comptroller General of the United States or the 'Internal Control Integrated Framework', issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). . . ." 2 CFR 200.334 states in part: "Financial records, supporting documents, statistical records, and all other non-Federal entity records pertinent to a Federal award must be retained for a period of three years from the date of submission of the final expenditure report or, for the Federal awards that are renewed quarterly or annual, from the date of submission of the quarterly or annual financial report, respectively, as reported to the Federal awarding agency or pass-through entity in the case of a subrecipient. . . ." INDIANA STATE BOARD OF ACCOUNTS 24 MADISON CONSOLIDATED SCHOOLS SCHEDULE OF FINDINGS AND QUESTIONED COSTS (Continued) Cause A proper system of internal controls was not designed by management of the School Corporation, which would include segregation of key functions, to ensure all records pertinent to the federal award were retained for audit. After a change in software providers, information from the previous provider could not be obtained for audit. Effect Without the proper implementation of an effectively designed system of internal controls, the internal control system cannot be capable of effectively preventing, or detecting and correcting, material noncompliance. As a result, RT reports and nonpublic school enrollment documentation were not maintained for audit, and, as such, the Indiana State Board of Accounts could not determine if the School Corporation complied with the Eligibility compliance requirement. Noncompliance with the provisions of federal statutes, regulations, and the terms and conditions of the federal award could result in the loss of future federal funding to the School Corporation. Questioned Costs There were no questioned costs identified. Recommendation We recommended that the management of the School Corporation establish a proper system of internal controls and develop policies and procedures to ensure RT reports, and nonpublic school enrollment documentation are maintained for audit. Views of Responsible Officials For the views of responsible officials, refer to the Corrective Action Plan that is part of this report.

FY End: 2024-06-30
Madison Consolidated Schools
Compliance Requirement: E
FINDING 2024-005 Subject: Title I Grants to Local Educational Agencies - Eligibility Federal Agency: Department of Education Federal Program: Title I Grants to Local Educational Agencies Assistance Listings Number: 84.010 Federal Award Numbers and Years (or Other Identifying Numbers): S010A210014, S010A220014, S010A230014 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Eligibility Audit Findings: Material Weakness, Modified Opinion Repeat Finding This is a repeat fin...

FINDING 2024-005 Subject: Title I Grants to Local Educational Agencies - Eligibility Federal Agency: Department of Education Federal Program: Title I Grants to Local Educational Agencies Assistance Listings Number: 84.010 Federal Award Numbers and Years (or Other Identifying Numbers): S010A210014, S010A220014, S010A230014 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Eligibility Audit Findings: Material Weakness, Modified Opinion Repeat Finding This is a repeat finding from the immediately prior audit report. The prior audit finding number was 2022-003. INDIANA STATE BOARD OF ACCOUNTS 23 MADISON CONSOLIDATED SCHOOLS SCHEDULE OF FINDINGS AND QUESTIONED COSTS (Continued) Condition and Context Eligibility for Title I is determined on the Eligible School Summary of the Tile I application. Enrollment and Poverty numbers are automatically pulled from the Indiana Department of Education's (IDOE) Official Pupil Enrollment (PE) count for each school into the Eligible School Summary page of the Tile I application. These counts that are prepopulated should be based on the School Corporation's records as of October of the prior fiscal year. One person compiled and uploaded enrollment data, including poverty status for Real Time (RT) reports, to the IDOE without a documented oversight or review process to ensure that the information was accurate and retained for audit. In addition, there was no review by the School Corporation of the enrollment and poverty counts that were prepopulated into the School Corporation's Title I grant application. The IDOE used the October 1 RT reports for fiscal years 2021-2022 and 2022-2023, as provided by the School Corporation, to determine Eligibility for the 2022-2023 and 2023-2024 grant programs, respectively. The October 1 RT report could not be presented for audit for 2021-2022, which would have been used to pull in enrollment and poverty information for the 2022-2023 grant. As such, we were unable to verify the amounts reported in the grant application. Additionally, the Indiana State Board of Accounts was unable to verify if the correct socioeconomic status was properly reported for any of the students. Enrollment and poverty numbers for any nonpublic schools are manually entered into the application by the School Corporation. The School Corporation had not established an effective process to review the listing of students from the nonpublic schools for enrollment and poverty counts to be entered into the Title I application and to retain this information for audit. We were unable to determine if the enrolled student count and their poverty status in the application was accurate. The lack of internal controls and lack of information submitted for audit was a systemic issue throughout the audit period. Criteria 2 CFR 200.303 states in part: "The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in 'Standards for Internal Control in the Federal Government' issued by the Comptroller General of the United States or the 'Internal Control Integrated Framework', issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). . . ." 2 CFR 200.334 states in part: "Financial records, supporting documents, statistical records, and all other non-Federal entity records pertinent to a Federal award must be retained for a period of three years from the date of submission of the final expenditure report or, for the Federal awards that are renewed quarterly or annual, from the date of submission of the quarterly or annual financial report, respectively, as reported to the Federal awarding agency or pass-through entity in the case of a subrecipient. . . ." INDIANA STATE BOARD OF ACCOUNTS 24 MADISON CONSOLIDATED SCHOOLS SCHEDULE OF FINDINGS AND QUESTIONED COSTS (Continued) Cause A proper system of internal controls was not designed by management of the School Corporation, which would include segregation of key functions, to ensure all records pertinent to the federal award were retained for audit. After a change in software providers, information from the previous provider could not be obtained for audit. Effect Without the proper implementation of an effectively designed system of internal controls, the internal control system cannot be capable of effectively preventing, or detecting and correcting, material noncompliance. As a result, RT reports and nonpublic school enrollment documentation were not maintained for audit, and, as such, the Indiana State Board of Accounts could not determine if the School Corporation complied with the Eligibility compliance requirement. Noncompliance with the provisions of federal statutes, regulations, and the terms and conditions of the federal award could result in the loss of future federal funding to the School Corporation. Questioned Costs There were no questioned costs identified. Recommendation We recommended that the management of the School Corporation establish a proper system of internal controls and develop policies and procedures to ensure RT reports, and nonpublic school enrollment documentation are maintained for audit. Views of Responsible Officials For the views of responsible officials, refer to the Corrective Action Plan that is part of this report.

FY End: 2024-06-30
Madison Consolidated Schools
Compliance Requirement: I
FINDING 2024-006 Subject: Special Education Cluster (IDEA) - Procurement and Suspension and Debarment Federal Agency: Department of Education Federal Programs: Special Education Grants to States, Special Education Preschool Grants, COVID-19 - Special Education Grants to States, COVID-19 - Special Education Preschool Grants Assistance Listings Numbers: 84.027, 84.173 Federal Award Numbers and Years (or Other Identifying Numbers): HO27A220084, 21611-127-PN01, 22611-127-ARP, 22611-127-PN01, 23611-1...

FINDING 2024-006 Subject: Special Education Cluster (IDEA) - Procurement and Suspension and Debarment Federal Agency: Department of Education Federal Programs: Special Education Grants to States, Special Education Preschool Grants, COVID-19 - Special Education Grants to States, COVID-19 - Special Education Preschool Grants Assistance Listings Numbers: 84.027, 84.173 Federal Award Numbers and Years (or Other Identifying Numbers): HO27A220084, 21611-127-PN01, 22611-127-ARP, 22611-127-PN01, 23611-127-PN01, 23619-127-ARP, 22619-127-PN01, 23619-127-PN01 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Procurement and Suspension and Debarment Audit Finding: Significant Deficiency Condition and Context An effective internal control system was not in place at the School Corporation to ensure compliance with requirements related to the grant agreement and suspension and debarment compliance requirements. INDIANA STATE BOARD OF ACCOUNTS 25 MADISON CONSOLIDATED SCHOOLS SCHEDULE OF FINDINGS AND QUESTIONED COSTS (Continued) Prior to entering into subawards and covered transactions with the Special Education Cluster (SPED) award funds, recipients are required to verify that such contractors and subrecipients are not suspended, debarred, or otherwise excluded. "Covered transactions" include, but are not limited to, contracts for goods and services awarded under a nonprocurement transaction (i.e., grant agreement) that are expected to equal or exceed $25,000. The verification is to be done by checking the Excluded Parties List System, collecting a certification from that person, or adding a clause or condition to the covered transactions with that person. There was no internal control in place, such as an oversight, review, or approval process, to ensure that contractors or subrecipients were not suspended, debarred, or otherwise excluded. The lack of internal controls was a systemic issue throughout the audit period. Criteria 2 CFR 200.303 states in part: "The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in 'Standards for Internal Control in the Federal Government' issued by the Comptroller General of the United States or the 'Internal Control Integrated Framework', issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). . . ." Cause The School Corporation did not have internal controls in pace to ensure the suspension and debarment status for covered transactions it intended to pay with federal funds of the major program were properly verified. Effect Without the proper design or implementation of internal controls, the internal control system cannot be capable of effectively preventing, or detecting and correcting, material noncompliance. This could result in the School Corporation paying a contractor who has been suspended or debarred, which would be unallowable. Questioned Costs There were no questioned costs identified. Recommendation We recommended that management of the School Corporation strengthen its system of internal controls to ensure that suspension and debarment is verified for all covered transactions of $25,000 or more. Views of Responsible Officials For the views of responsible officials, refer to the Corrective Action Plan that is part of this report

FY End: 2024-06-30
Madison Consolidated Schools
Compliance Requirement: I
FINDING 2024-006 Subject: Special Education Cluster (IDEA) - Procurement and Suspension and Debarment Federal Agency: Department of Education Federal Programs: Special Education Grants to States, Special Education Preschool Grants, COVID-19 - Special Education Grants to States, COVID-19 - Special Education Preschool Grants Assistance Listings Numbers: 84.027, 84.173 Federal Award Numbers and Years (or Other Identifying Numbers): HO27A220084, 21611-127-PN01, 22611-127-ARP, 22611-127-PN01, 23611-1...

FINDING 2024-006 Subject: Special Education Cluster (IDEA) - Procurement and Suspension and Debarment Federal Agency: Department of Education Federal Programs: Special Education Grants to States, Special Education Preschool Grants, COVID-19 - Special Education Grants to States, COVID-19 - Special Education Preschool Grants Assistance Listings Numbers: 84.027, 84.173 Federal Award Numbers and Years (or Other Identifying Numbers): HO27A220084, 21611-127-PN01, 22611-127-ARP, 22611-127-PN01, 23611-127-PN01, 23619-127-ARP, 22619-127-PN01, 23619-127-PN01 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Procurement and Suspension and Debarment Audit Finding: Significant Deficiency Condition and Context An effective internal control system was not in place at the School Corporation to ensure compliance with requirements related to the grant agreement and suspension and debarment compliance requirements. INDIANA STATE BOARD OF ACCOUNTS 25 MADISON CONSOLIDATED SCHOOLS SCHEDULE OF FINDINGS AND QUESTIONED COSTS (Continued) Prior to entering into subawards and covered transactions with the Special Education Cluster (SPED) award funds, recipients are required to verify that such contractors and subrecipients are not suspended, debarred, or otherwise excluded. "Covered transactions" include, but are not limited to, contracts for goods and services awarded under a nonprocurement transaction (i.e., grant agreement) that are expected to equal or exceed $25,000. The verification is to be done by checking the Excluded Parties List System, collecting a certification from that person, or adding a clause or condition to the covered transactions with that person. There was no internal control in place, such as an oversight, review, or approval process, to ensure that contractors or subrecipients were not suspended, debarred, or otherwise excluded. The lack of internal controls was a systemic issue throughout the audit period. Criteria 2 CFR 200.303 states in part: "The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in 'Standards for Internal Control in the Federal Government' issued by the Comptroller General of the United States or the 'Internal Control Integrated Framework', issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). . . ." Cause The School Corporation did not have internal controls in pace to ensure the suspension and debarment status for covered transactions it intended to pay with federal funds of the major program were properly verified. Effect Without the proper design or implementation of internal controls, the internal control system cannot be capable of effectively preventing, or detecting and correcting, material noncompliance. This could result in the School Corporation paying a contractor who has been suspended or debarred, which would be unallowable. Questioned Costs There were no questioned costs identified. Recommendation We recommended that management of the School Corporation strengthen its system of internal controls to ensure that suspension and debarment is verified for all covered transactions of $25,000 or more. Views of Responsible Officials For the views of responsible officials, refer to the Corrective Action Plan that is part of this report

FY End: 2024-06-30
Madison Consolidated Schools
Compliance Requirement: I
FINDING 2024-006 Subject: Special Education Cluster (IDEA) - Procurement and Suspension and Debarment Federal Agency: Department of Education Federal Programs: Special Education Grants to States, Special Education Preschool Grants, COVID-19 - Special Education Grants to States, COVID-19 - Special Education Preschool Grants Assistance Listings Numbers: 84.027, 84.173 Federal Award Numbers and Years (or Other Identifying Numbers): HO27A220084, 21611-127-PN01, 22611-127-ARP, 22611-127-PN01, 23611-1...

FINDING 2024-006 Subject: Special Education Cluster (IDEA) - Procurement and Suspension and Debarment Federal Agency: Department of Education Federal Programs: Special Education Grants to States, Special Education Preschool Grants, COVID-19 - Special Education Grants to States, COVID-19 - Special Education Preschool Grants Assistance Listings Numbers: 84.027, 84.173 Federal Award Numbers and Years (or Other Identifying Numbers): HO27A220084, 21611-127-PN01, 22611-127-ARP, 22611-127-PN01, 23611-127-PN01, 23619-127-ARP, 22619-127-PN01, 23619-127-PN01 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Procurement and Suspension and Debarment Audit Finding: Significant Deficiency Condition and Context An effective internal control system was not in place at the School Corporation to ensure compliance with requirements related to the grant agreement and suspension and debarment compliance requirements. INDIANA STATE BOARD OF ACCOUNTS 25 MADISON CONSOLIDATED SCHOOLS SCHEDULE OF FINDINGS AND QUESTIONED COSTS (Continued) Prior to entering into subawards and covered transactions with the Special Education Cluster (SPED) award funds, recipients are required to verify that such contractors and subrecipients are not suspended, debarred, or otherwise excluded. "Covered transactions" include, but are not limited to, contracts for goods and services awarded under a nonprocurement transaction (i.e., grant agreement) that are expected to equal or exceed $25,000. The verification is to be done by checking the Excluded Parties List System, collecting a certification from that person, or adding a clause or condition to the covered transactions with that person. There was no internal control in place, such as an oversight, review, or approval process, to ensure that contractors or subrecipients were not suspended, debarred, or otherwise excluded. The lack of internal controls was a systemic issue throughout the audit period. Criteria 2 CFR 200.303 states in part: "The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in 'Standards for Internal Control in the Federal Government' issued by the Comptroller General of the United States or the 'Internal Control Integrated Framework', issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). . . ." Cause The School Corporation did not have internal controls in pace to ensure the suspension and debarment status for covered transactions it intended to pay with federal funds of the major program were properly verified. Effect Without the proper design or implementation of internal controls, the internal control system cannot be capable of effectively preventing, or detecting and correcting, material noncompliance. This could result in the School Corporation paying a contractor who has been suspended or debarred, which would be unallowable. Questioned Costs There were no questioned costs identified. Recommendation We recommended that management of the School Corporation strengthen its system of internal controls to ensure that suspension and debarment is verified for all covered transactions of $25,000 or more. Views of Responsible Officials For the views of responsible officials, refer to the Corrective Action Plan that is part of this report

FY End: 2024-06-30
Madison Consolidated Schools
Compliance Requirement: I
FINDING 2024-006 Subject: Special Education Cluster (IDEA) - Procurement and Suspension and Debarment Federal Agency: Department of Education Federal Programs: Special Education Grants to States, Special Education Preschool Grants, COVID-19 - Special Education Grants to States, COVID-19 - Special Education Preschool Grants Assistance Listings Numbers: 84.027, 84.173 Federal Award Numbers and Years (or Other Identifying Numbers): HO27A220084, 21611-127-PN01, 22611-127-ARP, 22611-127-PN01, 23611-1...

FINDING 2024-006 Subject: Special Education Cluster (IDEA) - Procurement and Suspension and Debarment Federal Agency: Department of Education Federal Programs: Special Education Grants to States, Special Education Preschool Grants, COVID-19 - Special Education Grants to States, COVID-19 - Special Education Preschool Grants Assistance Listings Numbers: 84.027, 84.173 Federal Award Numbers and Years (or Other Identifying Numbers): HO27A220084, 21611-127-PN01, 22611-127-ARP, 22611-127-PN01, 23611-127-PN01, 23619-127-ARP, 22619-127-PN01, 23619-127-PN01 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Procurement and Suspension and Debarment Audit Finding: Significant Deficiency Condition and Context An effective internal control system was not in place at the School Corporation to ensure compliance with requirements related to the grant agreement and suspension and debarment compliance requirements. INDIANA STATE BOARD OF ACCOUNTS 25 MADISON CONSOLIDATED SCHOOLS SCHEDULE OF FINDINGS AND QUESTIONED COSTS (Continued) Prior to entering into subawards and covered transactions with the Special Education Cluster (SPED) award funds, recipients are required to verify that such contractors and subrecipients are not suspended, debarred, or otherwise excluded. "Covered transactions" include, but are not limited to, contracts for goods and services awarded under a nonprocurement transaction (i.e., grant agreement) that are expected to equal or exceed $25,000. The verification is to be done by checking the Excluded Parties List System, collecting a certification from that person, or adding a clause or condition to the covered transactions with that person. There was no internal control in place, such as an oversight, review, or approval process, to ensure that contractors or subrecipients were not suspended, debarred, or otherwise excluded. The lack of internal controls was a systemic issue throughout the audit period. Criteria 2 CFR 200.303 states in part: "The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in 'Standards for Internal Control in the Federal Government' issued by the Comptroller General of the United States or the 'Internal Control Integrated Framework', issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). . . ." Cause The School Corporation did not have internal controls in pace to ensure the suspension and debarment status for covered transactions it intended to pay with federal funds of the major program were properly verified. Effect Without the proper design or implementation of internal controls, the internal control system cannot be capable of effectively preventing, or detecting and correcting, material noncompliance. This could result in the School Corporation paying a contractor who has been suspended or debarred, which would be unallowable. Questioned Costs There were no questioned costs identified. Recommendation We recommended that management of the School Corporation strengthen its system of internal controls to ensure that suspension and debarment is verified for all covered transactions of $25,000 or more. Views of Responsible Officials For the views of responsible officials, refer to the Corrective Action Plan that is part of this report

FY End: 2024-06-30
Madison Consolidated Schools
Compliance Requirement: I
FINDING 2024-006 Subject: Special Education Cluster (IDEA) - Procurement and Suspension and Debarment Federal Agency: Department of Education Federal Programs: Special Education Grants to States, Special Education Preschool Grants, COVID-19 - Special Education Grants to States, COVID-19 - Special Education Preschool Grants Assistance Listings Numbers: 84.027, 84.173 Federal Award Numbers and Years (or Other Identifying Numbers): HO27A220084, 21611-127-PN01, 22611-127-ARP, 22611-127-PN01, 23611-1...

FINDING 2024-006 Subject: Special Education Cluster (IDEA) - Procurement and Suspension and Debarment Federal Agency: Department of Education Federal Programs: Special Education Grants to States, Special Education Preschool Grants, COVID-19 - Special Education Grants to States, COVID-19 - Special Education Preschool Grants Assistance Listings Numbers: 84.027, 84.173 Federal Award Numbers and Years (or Other Identifying Numbers): HO27A220084, 21611-127-PN01, 22611-127-ARP, 22611-127-PN01, 23611-127-PN01, 23619-127-ARP, 22619-127-PN01, 23619-127-PN01 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Procurement and Suspension and Debarment Audit Finding: Significant Deficiency Condition and Context An effective internal control system was not in place at the School Corporation to ensure compliance with requirements related to the grant agreement and suspension and debarment compliance requirements. INDIANA STATE BOARD OF ACCOUNTS 25 MADISON CONSOLIDATED SCHOOLS SCHEDULE OF FINDINGS AND QUESTIONED COSTS (Continued) Prior to entering into subawards and covered transactions with the Special Education Cluster (SPED) award funds, recipients are required to verify that such contractors and subrecipients are not suspended, debarred, or otherwise excluded. "Covered transactions" include, but are not limited to, contracts for goods and services awarded under a nonprocurement transaction (i.e., grant agreement) that are expected to equal or exceed $25,000. The verification is to be done by checking the Excluded Parties List System, collecting a certification from that person, or adding a clause or condition to the covered transactions with that person. There was no internal control in place, such as an oversight, review, or approval process, to ensure that contractors or subrecipients were not suspended, debarred, or otherwise excluded. The lack of internal controls was a systemic issue throughout the audit period. Criteria 2 CFR 200.303 states in part: "The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in 'Standards for Internal Control in the Federal Government' issued by the Comptroller General of the United States or the 'Internal Control Integrated Framework', issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). . . ." Cause The School Corporation did not have internal controls in pace to ensure the suspension and debarment status for covered transactions it intended to pay with federal funds of the major program were properly verified. Effect Without the proper design or implementation of internal controls, the internal control system cannot be capable of effectively preventing, or detecting and correcting, material noncompliance. This could result in the School Corporation paying a contractor who has been suspended or debarred, which would be unallowable. Questioned Costs There were no questioned costs identified. Recommendation We recommended that management of the School Corporation strengthen its system of internal controls to ensure that suspension and debarment is verified for all covered transactions of $25,000 or more. Views of Responsible Officials For the views of responsible officials, refer to the Corrective Action Plan that is part of this report

FY End: 2024-06-30
Weld County School District Re-8
Compliance Requirement: E
Criteria or Specific Requirement: The Uniform Guidance in 2 CFR Section 200.303, Internal Controls, requires that non-Federal recipients and subrecipients must establish, document, and maintain effective internal control over the Federal award that provides reasonable assurance the award is in compliance with the Federal Statutes, regulations, and the terms and conditions of the Federal award. Condition: The District's control over maintaining the monthly Eligibility Direct Certification report...

Criteria or Specific Requirement: The Uniform Guidance in 2 CFR Section 200.303, Internal Controls, requires that non-Federal recipients and subrecipients must establish, document, and maintain effective internal control over the Federal award that provides reasonable assurance the award is in compliance with the Federal Statutes, regulations, and the terms and conditions of the Federal award. Condition: The District's control over maintaining the monthly Eligibility Direct Certification reports for the School Breakfast, National School Lunch, and Summer Food Service Programs was not followed and insufficient documentation was retained. One instance in which annual eligibility determination was incorrect. Questioned Costs: No Context: A sample of 40 applications were selected for testing: • 16 direct certification eligibility determinations were unable to be compared to the State’s direct certify reports. • 1 annual eligibility determination was eligible under the 'Free' meal classification and was incorrectly classified as 'Paid'. Cause: The District did not retain any of the State’s monthly direct certification reports. The District relied on their food service system for determination of eligibility instead of calculating it themselves resulting in an applicant not receiving the benefits they were entitled to. Effect: Lack of documentation retention could result in students receiving benefits they are not entitled to or students not receiving benefits that they are entitled. Repeat Finding: No Recommendation: We recommend the District retain all direct certification reports from the State and for the District to review applications submitted electronically through food service system to determine correct eligibility determination is made. Views of Responsible Officials: There is no disagreement with the audit finding.

FY End: 2024-06-30
Weld County School District Re-8
Compliance Requirement: E
Criteria or Specific Requirement: The Uniform Guidance in 2 CFR Section 200.303, Internal Controls, requires that non-Federal recipients and subrecipients must establish, document, and maintain effective internal control over the Federal award that provides reasonable assurance the award is in compliance with the Federal Statutes, regulations, and the terms and conditions of the Federal award. Condition: The District's control over maintaining the monthly Eligibility Direct Certification report...

Criteria or Specific Requirement: The Uniform Guidance in 2 CFR Section 200.303, Internal Controls, requires that non-Federal recipients and subrecipients must establish, document, and maintain effective internal control over the Federal award that provides reasonable assurance the award is in compliance with the Federal Statutes, regulations, and the terms and conditions of the Federal award. Condition: The District's control over maintaining the monthly Eligibility Direct Certification reports for the School Breakfast, National School Lunch, and Summer Food Service Programs was not followed and insufficient documentation was retained. One instance in which annual eligibility determination was incorrect. Questioned Costs: No Context: A sample of 40 applications were selected for testing: • 16 direct certification eligibility determinations were unable to be compared to the State’s direct certify reports. • 1 annual eligibility determination was eligible under the 'Free' meal classification and was incorrectly classified as 'Paid'. Cause: The District did not retain any of the State’s monthly direct certification reports. The District relied on their food service system for determination of eligibility instead of calculating it themselves resulting in an applicant not receiving the benefits they were entitled to. Effect: Lack of documentation retention could result in students receiving benefits they are not entitled to or students not receiving benefits that they are entitled. Repeat Finding: No Recommendation: We recommend the District retain all direct certification reports from the State and for the District to review applications submitted electronically through food service system to determine correct eligibility determination is made. Views of Responsible Officials: There is no disagreement with the audit finding.

FY End: 2024-06-30
Weld County School District Re-8
Compliance Requirement: E
Criteria or Specific Requirement: The Uniform Guidance in 2 CFR Section 200.303, Internal Controls, requires that non-Federal recipients and subrecipients must establish, document, and maintain effective internal control over the Federal award that provides reasonable assurance the award is in compliance with the Federal Statutes, regulations, and the terms and conditions of the Federal award. Condition: The District's control over maintaining the monthly Eligibility Direct Certification report...

Criteria or Specific Requirement: The Uniform Guidance in 2 CFR Section 200.303, Internal Controls, requires that non-Federal recipients and subrecipients must establish, document, and maintain effective internal control over the Federal award that provides reasonable assurance the award is in compliance with the Federal Statutes, regulations, and the terms and conditions of the Federal award. Condition: The District's control over maintaining the monthly Eligibility Direct Certification reports for the School Breakfast, National School Lunch, and Summer Food Service Programs was not followed and insufficient documentation was retained. One instance in which annual eligibility determination was incorrect. Questioned Costs: No Context: A sample of 40 applications were selected for testing: • 16 direct certification eligibility determinations were unable to be compared to the State’s direct certify reports. • 1 annual eligibility determination was eligible under the 'Free' meal classification and was incorrectly classified as 'Paid'. Cause: The District did not retain any of the State’s monthly direct certification reports. The District relied on their food service system for determination of eligibility instead of calculating it themselves resulting in an applicant not receiving the benefits they were entitled to. Effect: Lack of documentation retention could result in students receiving benefits they are not entitled to or students not receiving benefits that they are entitled. Repeat Finding: No Recommendation: We recommend the District retain all direct certification reports from the State and for the District to review applications submitted electronically through food service system to determine correct eligibility determination is made. Views of Responsible Officials: There is no disagreement with the audit finding.

FY End: 2024-06-30
Weld County School District Re-8
Compliance Requirement: E
Criteria or Specific Requirement: The Uniform Guidance in 2 CFR Section 200.303, Internal Controls, requires that non-Federal recipients and subrecipients must establish, document, and maintain effective internal control over the Federal award that provides reasonable assurance the award is in compliance with the Federal Statutes, regulations, and the terms and conditions of the Federal award. Condition: The District's control over maintaining the monthly Eligibility Direct Certification report...

Criteria or Specific Requirement: The Uniform Guidance in 2 CFR Section 200.303, Internal Controls, requires that non-Federal recipients and subrecipients must establish, document, and maintain effective internal control over the Federal award that provides reasonable assurance the award is in compliance with the Federal Statutes, regulations, and the terms and conditions of the Federal award. Condition: The District's control over maintaining the monthly Eligibility Direct Certification reports for the School Breakfast, National School Lunch, and Summer Food Service Programs was not followed and insufficient documentation was retained. One instance in which annual eligibility determination was incorrect. Questioned Costs: No Context: A sample of 40 applications were selected for testing: • 16 direct certification eligibility determinations were unable to be compared to the State’s direct certify reports. • 1 annual eligibility determination was eligible under the 'Free' meal classification and was incorrectly classified as 'Paid'. Cause: The District did not retain any of the State’s monthly direct certification reports. The District relied on their food service system for determination of eligibility instead of calculating it themselves resulting in an applicant not receiving the benefits they were entitled to. Effect: Lack of documentation retention could result in students receiving benefits they are not entitled to or students not receiving benefits that they are entitled. Repeat Finding: No Recommendation: We recommend the District retain all direct certification reports from the State and for the District to review applications submitted electronically through food service system to determine correct eligibility determination is made. Views of Responsible Officials: There is no disagreement with the audit finding.

FY End: 2024-06-30
Weld County School District Re-8
Compliance Requirement: E
Criteria or Specific Requirement: The Uniform Guidance in 2 CFR Section 200.303, Internal Controls, requires that non-Federal recipients and subrecipients must establish, document, and maintain effective internal control over the Federal award that provides reasonable assurance the award is in compliance with the Federal Statutes, regulations, and the terms and conditions of the Federal award. Condition: The District's control over maintaining the monthly Eligibility Direct Certification report...

Criteria or Specific Requirement: The Uniform Guidance in 2 CFR Section 200.303, Internal Controls, requires that non-Federal recipients and subrecipients must establish, document, and maintain effective internal control over the Federal award that provides reasonable assurance the award is in compliance with the Federal Statutes, regulations, and the terms and conditions of the Federal award. Condition: The District's control over maintaining the monthly Eligibility Direct Certification reports for the School Breakfast, National School Lunch, and Summer Food Service Programs was not followed and insufficient documentation was retained. One instance in which annual eligibility determination was incorrect. Questioned Costs: No Context: A sample of 40 applications were selected for testing: • 16 direct certification eligibility determinations were unable to be compared to the State’s direct certify reports. • 1 annual eligibility determination was eligible under the 'Free' meal classification and was incorrectly classified as 'Paid'. Cause: The District did not retain any of the State’s monthly direct certification reports. The District relied on their food service system for determination of eligibility instead of calculating it themselves resulting in an applicant not receiving the benefits they were entitled to. Effect: Lack of documentation retention could result in students receiving benefits they are not entitled to or students not receiving benefits that they are entitled. Repeat Finding: No Recommendation: We recommend the District retain all direct certification reports from the State and for the District to review applications submitted electronically through food service system to determine correct eligibility determination is made. Views of Responsible Officials: There is no disagreement with the audit finding.

FY End: 2024-06-30
Frontier School Corporation
Compliance Requirement: E
Information on the federal program: Subject: Child Nutrition Cluster - Internal Controls Federal Agency: Department of Agriculture Federal Program: School Breakfast Program, National School Lunch Program Assistance Listing Number: 10.553, 10.555 Federal Award Numbers and Years (or Other Identifying Numbers): FY2023, FY2024 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Eligibility Audit Finding: Material Weakness Criteria: 2 CFR section 200.303 states in part: "The ...

Information on the federal program: Subject: Child Nutrition Cluster - Internal Controls Federal Agency: Department of Agriculture Federal Program: School Breakfast Program, National School Lunch Program Assistance Listing Number: 10.553, 10.555 Federal Award Numbers and Years (or Other Identifying Numbers): FY2023, FY2024 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Eligibility Audit Finding: Material Weakness Criteria: 2 CFR section 200.303 states in part: "The non-Federal entity must: (a) Establish and maintain effective internal control over Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal awards in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in 'Standards for Internal Control in the Federal Government' issued by the Comptroller General of the United States or the 'Internal Control Integrated Framework', issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). . . ." Condition: An effective internal control system was not in place at the School Corporation in order to ensure compliance with requirements related to the grant agreement and the eligibility compliance requirement. Cause: The School Corporation's management had not developed a system of internal controls to ensure compliance with eligibility requirements. Effect: The failure to establish an effective internal control system placed the School Corporation at risk of noncompliance with the grant agreement and the compliance requirements. A lack of segregation of duties within an internal control system could have also allowed noncompliance with the compliance requirements and allowed the misuse and mismanagement of federal funds and assets by not having proper oversight, reviews, and approvals over the activities of the programs. Questioned Costs: There were no questioned costs identified. Context: During testing over controls for eligibility, we noted there was no formal, secondary review for the applications entered in the food service software determining eligibility. Additionally, there was no documented annual review by School Corporation personnel of the income eligibility guidelines used by the food service software. Identification as a repeat finding, if applicable: No. Recommendation: We recommended that the School Corporation's management establish a system of internal controls related to the grant agreement and eligibility compliance requirements. Views of Responsible Officials and Planned Corrective Actions: Management agrees with the finding and has prepared a corrective action plan.

FY End: 2024-06-30
Frontier School Corporation
Compliance Requirement: E
Information on the federal program: Subject: Child Nutrition Cluster - Internal Controls Federal Agency: Department of Agriculture Federal Program: School Breakfast Program, National School Lunch Program Assistance Listing Number: 10.553, 10.555 Federal Award Numbers and Years (or Other Identifying Numbers): FY2023, FY2024 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Eligibility Audit Finding: Material Weakness Criteria: 2 CFR section 200.303 states in part: "The ...

Information on the federal program: Subject: Child Nutrition Cluster - Internal Controls Federal Agency: Department of Agriculture Federal Program: School Breakfast Program, National School Lunch Program Assistance Listing Number: 10.553, 10.555 Federal Award Numbers and Years (or Other Identifying Numbers): FY2023, FY2024 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Eligibility Audit Finding: Material Weakness Criteria: 2 CFR section 200.303 states in part: "The non-Federal entity must: (a) Establish and maintain effective internal control over Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal awards in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in 'Standards for Internal Control in the Federal Government' issued by the Comptroller General of the United States or the 'Internal Control Integrated Framework', issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). . . ." Condition: An effective internal control system was not in place at the School Corporation in order to ensure compliance with requirements related to the grant agreement and the eligibility compliance requirement. Cause: The School Corporation's management had not developed a system of internal controls to ensure compliance with eligibility requirements. Effect: The failure to establish an effective internal control system placed the School Corporation at risk of noncompliance with the grant agreement and the compliance requirements. A lack of segregation of duties within an internal control system could have also allowed noncompliance with the compliance requirements and allowed the misuse and mismanagement of federal funds and assets by not having proper oversight, reviews, and approvals over the activities of the programs. Questioned Costs: There were no questioned costs identified. Context: During testing over controls for eligibility, we noted there was no formal, secondary review for the applications entered in the food service software determining eligibility. Additionally, there was no documented annual review by School Corporation personnel of the income eligibility guidelines used by the food service software. Identification as a repeat finding, if applicable: No. Recommendation: We recommended that the School Corporation's management establish a system of internal controls related to the grant agreement and eligibility compliance requirements. Views of Responsible Officials and Planned Corrective Actions: Management agrees with the finding and has prepared a corrective action plan.

FY End: 2024-06-30
Frontier School Corporation
Compliance Requirement: E
Information on the federal program: Subject: Child Nutrition Cluster - Internal Controls Federal Agency: Department of Agriculture Federal Program: School Breakfast Program, National School Lunch Program Assistance Listing Number: 10.553, 10.555 Federal Award Numbers and Years (or Other Identifying Numbers): FY2023, FY2024 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Eligibility Audit Finding: Material Weakness Criteria: 2 CFR section 200.303 states in part: "The ...

Information on the federal program: Subject: Child Nutrition Cluster - Internal Controls Federal Agency: Department of Agriculture Federal Program: School Breakfast Program, National School Lunch Program Assistance Listing Number: 10.553, 10.555 Federal Award Numbers and Years (or Other Identifying Numbers): FY2023, FY2024 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Eligibility Audit Finding: Material Weakness Criteria: 2 CFR section 200.303 states in part: "The non-Federal entity must: (a) Establish and maintain effective internal control over Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal awards in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in 'Standards for Internal Control in the Federal Government' issued by the Comptroller General of the United States or the 'Internal Control Integrated Framework', issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). . . ." Condition: An effective internal control system was not in place at the School Corporation in order to ensure compliance with requirements related to the grant agreement and the eligibility compliance requirement. Cause: The School Corporation's management had not developed a system of internal controls to ensure compliance with eligibility requirements. Effect: The failure to establish an effective internal control system placed the School Corporation at risk of noncompliance with the grant agreement and the compliance requirements. A lack of segregation of duties within an internal control system could have also allowed noncompliance with the compliance requirements and allowed the misuse and mismanagement of federal funds and assets by not having proper oversight, reviews, and approvals over the activities of the programs. Questioned Costs: There were no questioned costs identified. Context: During testing over controls for eligibility, we noted there was no formal, secondary review for the applications entered in the food service software determining eligibility. Additionally, there was no documented annual review by School Corporation personnel of the income eligibility guidelines used by the food service software. Identification as a repeat finding, if applicable: No. Recommendation: We recommended that the School Corporation's management establish a system of internal controls related to the grant agreement and eligibility compliance requirements. Views of Responsible Officials and Planned Corrective Actions: Management agrees with the finding and has prepared a corrective action plan.

FY End: 2024-06-30
Frontier School Corporation
Compliance Requirement: L
Information on the federal program: Subject: Child Nutrition Cluster - Internal Controls Federal Agency: Department of Agriculture Federal Program: School Breakfast Program, National School Lunch Program Assistance Listing Number: 10.553, 10.555 Federal Award Numbers and Years (or Other Identifying Numbers): FY2023, FY2024 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Reporting Audit Finding: Material Weakness Criteria: 2 CFR section 200.303 states in part: "The no...

Information on the federal program: Subject: Child Nutrition Cluster - Internal Controls Federal Agency: Department of Agriculture Federal Program: School Breakfast Program, National School Lunch Program Assistance Listing Number: 10.553, 10.555 Federal Award Numbers and Years (or Other Identifying Numbers): FY2023, FY2024 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Reporting Audit Finding: Material Weakness Criteria: 2 CFR section 200.303 states in part: "The non-Federal entity must: (a) Establish and maintain effective internal control over Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal awards in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in 'Standards for Internal Control in the Federal Government' issued by the Comptroller General of the United States or the 'Internal Control Integrated Framework', issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). . . ." Condition: An effective internal control system was not in place at the School Corporation in order to ensure compliance with requirements related to the grant agreement and the reporting compliance requirement. Cause: The School Corporation's management had not developed a system of internal controls to ensure compliance with the reporting requirements. Effect: The failure to establish an effective internal control system placed the School Corporation at risk of noncompliance with the grant agreement and the compliance requirements. A lack of segregation of duties within an internal control system could have also allowed noncompliance with the compliance requirements and allowed the misuse and mismanagement of federal funds and assets by not having proper oversight, reviews, and approvals over the activities of the programs. Questioned Costs: $349 overstatement, $161 understatement of claimed meals Context: We noted that for two claims in a sample of four, the Food Service Director prepared the reimbursement claim without a secondary, documented review to ensure the accuracy of the reimbursement claim. Additionally, the number of meals claimed on two of the four claims sampled did not agree to the supporting meal system reports. There was a gross overstatement of meals claimed of $349 and a gross understatement of meals claimed of $161 resulting in a net over reimbursement amount of $188. Identification as a repeat finding, if applicable: This is a repeat finding from the immediately prior audit. The prior finding number was 2022-004. Recommendation: We recommended that the School Corporation implement a documented, formal review of the claims before they are submitted for reimbursement. Views of Responsible Officials and Planned Corrective Actions: Management agrees with the finding and has prepared a corrective action plan.

FY End: 2024-06-30
Frontier School Corporation
Compliance Requirement: L
Information on the federal program: Subject: Child Nutrition Cluster - Internal Controls Federal Agency: Department of Agriculture Federal Program: School Breakfast Program, National School Lunch Program Assistance Listing Number: 10.553, 10.555 Federal Award Numbers and Years (or Other Identifying Numbers): FY2023, FY2024 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Reporting Audit Finding: Material Weakness Criteria: 2 CFR section 200.303 states in part: "The no...

Information on the federal program: Subject: Child Nutrition Cluster - Internal Controls Federal Agency: Department of Agriculture Federal Program: School Breakfast Program, National School Lunch Program Assistance Listing Number: 10.553, 10.555 Federal Award Numbers and Years (or Other Identifying Numbers): FY2023, FY2024 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Reporting Audit Finding: Material Weakness Criteria: 2 CFR section 200.303 states in part: "The non-Federal entity must: (a) Establish and maintain effective internal control over Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal awards in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in 'Standards for Internal Control in the Federal Government' issued by the Comptroller General of the United States or the 'Internal Control Integrated Framework', issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). . . ." Condition: An effective internal control system was not in place at the School Corporation in order to ensure compliance with requirements related to the grant agreement and the reporting compliance requirement. Cause: The School Corporation's management had not developed a system of internal controls to ensure compliance with the reporting requirements. Effect: The failure to establish an effective internal control system placed the School Corporation at risk of noncompliance with the grant agreement and the compliance requirements. A lack of segregation of duties within an internal control system could have also allowed noncompliance with the compliance requirements and allowed the misuse and mismanagement of federal funds and assets by not having proper oversight, reviews, and approvals over the activities of the programs. Questioned Costs: $349 overstatement, $161 understatement of claimed meals Context: We noted that for two claims in a sample of four, the Food Service Director prepared the reimbursement claim without a secondary, documented review to ensure the accuracy of the reimbursement claim. Additionally, the number of meals claimed on two of the four claims sampled did not agree to the supporting meal system reports. There was a gross overstatement of meals claimed of $349 and a gross understatement of meals claimed of $161 resulting in a net over reimbursement amount of $188. Identification as a repeat finding, if applicable: This is a repeat finding from the immediately prior audit. The prior finding number was 2022-004. Recommendation: We recommended that the School Corporation implement a documented, formal review of the claims before they are submitted for reimbursement. Views of Responsible Officials and Planned Corrective Actions: Management agrees with the finding and has prepared a corrective action plan.

FY End: 2024-06-30
Frontier School Corporation
Compliance Requirement: L
Information on the federal program: Subject: Child Nutrition Cluster - Internal Controls Federal Agency: Department of Agriculture Federal Program: School Breakfast Program, National School Lunch Program Assistance Listing Number: 10.553, 10.555 Federal Award Numbers and Years (or Other Identifying Numbers): FY2023, FY2024 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Reporting Audit Finding: Material Weakness Criteria: 2 CFR section 200.303 states in part: "The no...

Information on the federal program: Subject: Child Nutrition Cluster - Internal Controls Federal Agency: Department of Agriculture Federal Program: School Breakfast Program, National School Lunch Program Assistance Listing Number: 10.553, 10.555 Federal Award Numbers and Years (or Other Identifying Numbers): FY2023, FY2024 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Reporting Audit Finding: Material Weakness Criteria: 2 CFR section 200.303 states in part: "The non-Federal entity must: (a) Establish and maintain effective internal control over Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal awards in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in 'Standards for Internal Control in the Federal Government' issued by the Comptroller General of the United States or the 'Internal Control Integrated Framework', issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). . . ." Condition: An effective internal control system was not in place at the School Corporation in order to ensure compliance with requirements related to the grant agreement and the reporting compliance requirement. Cause: The School Corporation's management had not developed a system of internal controls to ensure compliance with the reporting requirements. Effect: The failure to establish an effective internal control system placed the School Corporation at risk of noncompliance with the grant agreement and the compliance requirements. A lack of segregation of duties within an internal control system could have also allowed noncompliance with the compliance requirements and allowed the misuse and mismanagement of federal funds and assets by not having proper oversight, reviews, and approvals over the activities of the programs. Questioned Costs: $349 overstatement, $161 understatement of claimed meals Context: We noted that for two claims in a sample of four, the Food Service Director prepared the reimbursement claim without a secondary, documented review to ensure the accuracy of the reimbursement claim. Additionally, the number of meals claimed on two of the four claims sampled did not agree to the supporting meal system reports. There was a gross overstatement of meals claimed of $349 and a gross understatement of meals claimed of $161 resulting in a net over reimbursement amount of $188. Identification as a repeat finding, if applicable: This is a repeat finding from the immediately prior audit. The prior finding number was 2022-004. Recommendation: We recommended that the School Corporation implement a documented, formal review of the claims before they are submitted for reimbursement. Views of Responsible Officials and Planned Corrective Actions: Management agrees with the finding and has prepared a corrective action plan.

FY End: 2024-06-30
Frontier School Corporation
Compliance Requirement: I
Information on the federal program: Subject: Child Nutrition Cluster – Internal Controls Federal Agency: Department of Agriculture Federal Program: School Breakfast Program, National School Lunch Program Assistance Listing Number: 10.553, 10.555 Federal Award Numbers and Years (or Other Identifying Numbers): FY2023, FY2024 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Procurement and Suspension and Debarment Audit Finding: Material Weakness Criteria: 2 CFR 200.303 ...

Information on the federal program: Subject: Child Nutrition Cluster – Internal Controls Federal Agency: Department of Agriculture Federal Program: School Breakfast Program, National School Lunch Program Assistance Listing Number: 10.553, 10.555 Federal Award Numbers and Years (or Other Identifying Numbers): FY2023, FY2024 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Procurement and Suspension and Debarment Audit Finding: Material Weakness Criteria: 2 CFR 200.303 states in part: "The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in 'Standards for Internal Control in the Federal Government' issued by the Comptroller General of the United States or the 'Internal Control Integrated Framework', issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). . . ." 2 CFR 200.318(a) states: "The non-Federal entity must use its own documented procurement procedures which reflect applicable State, local, and tribal laws and regulations, provided that the procurements conform to applicable Federal law and the standards identified in this part." 2 CFR 200.320 states in part: "The non-Federal Entity must use one of the following methods of procurement. . . . (b) Procurement by small purchase procedures. Small purchase procedures are those relatively simple and informal procurement methods for securing services, supplies, or other property that do not cost more than the Simplified Acquisition Threshold. If small purchase procedures are used, price or rate quotations must be obtained from an adequate number of qualified sources. Condition: An effective internal control system was not in place at the School Corporation to ensure compliance with requirements related to the Child Nutrition Program and Procurement and Suspension and Debarment compliance requirements. Cause: The School Corporation's management had not developed a system of internal controls that would have ensured compliance with the Procurement and Suspension and Debarment compliance requirement. Effect: The failure to establish an effective internal control system placed the School Corporation at risk of noncompliance with the grant agreement and the compliance requirements. A lack of segregation of duties within an internal control system could have also allowed noncompliance with the compliance requirements and allowed the misuse and mismanagement of federal funds and assets by not having proper oversight, reviews, and approvals over the activities of the programs. Questioned Costs: There were no questioned costs identified. Context: The School Corporation had one vendor which exceeded the simplified acquisition threshold which was selected for testing. The School Corporation was unable to provide any supporting documentation for the procurement process required under School Corporation policy. The sample item amount disbursed was $160,827 for food purchases in FY23. Additionally, the School Corporation did not have any support to show the vendor was not debarred or suspended. Identification as a repeat finding, if applicable: This is a repeat finding from the immediately prior audit. The prior finding number was 2022-003. Recommendation: We recommended that the School Corporation's management establish a system of internal controls related to ensure that the School Corporation’s procurement policy is adhered to and all documentation is maintained for the procurements performed by the School Corporation. Additionally, we recommend management monitor annual vendor activity to ensure vendors that exceed small purchase threshold and suspension and debarment threshold in aggregate are reviewed for potential analysis and suspension and debarment checks required by federal and state regulations. Views of Responsible Officials and Planned Corrective Actions: Management agrees with the finding and has prepared a corrective action plan.

FY End: 2024-06-30
Frontier School Corporation
Compliance Requirement: I
Information on the federal program: Subject: Child Nutrition Cluster – Internal Controls Federal Agency: Department of Agriculture Federal Program: School Breakfast Program, National School Lunch Program Assistance Listing Number: 10.553, 10.555 Federal Award Numbers and Years (or Other Identifying Numbers): FY2023, FY2024 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Procurement and Suspension and Debarment Audit Finding: Material Weakness Criteria: 2 CFR 200.303 ...

Information on the federal program: Subject: Child Nutrition Cluster – Internal Controls Federal Agency: Department of Agriculture Federal Program: School Breakfast Program, National School Lunch Program Assistance Listing Number: 10.553, 10.555 Federal Award Numbers and Years (or Other Identifying Numbers): FY2023, FY2024 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Procurement and Suspension and Debarment Audit Finding: Material Weakness Criteria: 2 CFR 200.303 states in part: "The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in 'Standards for Internal Control in the Federal Government' issued by the Comptroller General of the United States or the 'Internal Control Integrated Framework', issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). . . ." 2 CFR 200.318(a) states: "The non-Federal entity must use its own documented procurement procedures which reflect applicable State, local, and tribal laws and regulations, provided that the procurements conform to applicable Federal law and the standards identified in this part." 2 CFR 200.320 states in part: "The non-Federal Entity must use one of the following methods of procurement. . . . (b) Procurement by small purchase procedures. Small purchase procedures are those relatively simple and informal procurement methods for securing services, supplies, or other property that do not cost more than the Simplified Acquisition Threshold. If small purchase procedures are used, price or rate quotations must be obtained from an adequate number of qualified sources. Condition: An effective internal control system was not in place at the School Corporation to ensure compliance with requirements related to the Child Nutrition Program and Procurement and Suspension and Debarment compliance requirements. Cause: The School Corporation's management had not developed a system of internal controls that would have ensured compliance with the Procurement and Suspension and Debarment compliance requirement. Effect: The failure to establish an effective internal control system placed the School Corporation at risk of noncompliance with the grant agreement and the compliance requirements. A lack of segregation of duties within an internal control system could have also allowed noncompliance with the compliance requirements and allowed the misuse and mismanagement of federal funds and assets by not having proper oversight, reviews, and approvals over the activities of the programs. Questioned Costs: There were no questioned costs identified. Context: The School Corporation had one vendor which exceeded the simplified acquisition threshold which was selected for testing. The School Corporation was unable to provide any supporting documentation for the procurement process required under School Corporation policy. The sample item amount disbursed was $160,827 for food purchases in FY23. Additionally, the School Corporation did not have any support to show the vendor was not debarred or suspended. Identification as a repeat finding, if applicable: This is a repeat finding from the immediately prior audit. The prior finding number was 2022-003. Recommendation: We recommended that the School Corporation's management establish a system of internal controls related to ensure that the School Corporation’s procurement policy is adhered to and all documentation is maintained for the procurements performed by the School Corporation. Additionally, we recommend management monitor annual vendor activity to ensure vendors that exceed small purchase threshold and suspension and debarment threshold in aggregate are reviewed for potential analysis and suspension and debarment checks required by federal and state regulations. Views of Responsible Officials and Planned Corrective Actions: Management agrees with the finding and has prepared a corrective action plan.

FY End: 2024-06-30
Frontier School Corporation
Compliance Requirement: I
Information on the federal program: Subject: Child Nutrition Cluster – Internal Controls Federal Agency: Department of Agriculture Federal Program: School Breakfast Program, National School Lunch Program Assistance Listing Number: 10.553, 10.555 Federal Award Numbers and Years (or Other Identifying Numbers): FY2023, FY2024 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Procurement and Suspension and Debarment Audit Finding: Material Weakness Criteria: 2 CFR 200.303 ...

Information on the federal program: Subject: Child Nutrition Cluster – Internal Controls Federal Agency: Department of Agriculture Federal Program: School Breakfast Program, National School Lunch Program Assistance Listing Number: 10.553, 10.555 Federal Award Numbers and Years (or Other Identifying Numbers): FY2023, FY2024 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Procurement and Suspension and Debarment Audit Finding: Material Weakness Criteria: 2 CFR 200.303 states in part: "The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in 'Standards for Internal Control in the Federal Government' issued by the Comptroller General of the United States or the 'Internal Control Integrated Framework', issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). . . ." 2 CFR 200.318(a) states: "The non-Federal entity must use its own documented procurement procedures which reflect applicable State, local, and tribal laws and regulations, provided that the procurements conform to applicable Federal law and the standards identified in this part." 2 CFR 200.320 states in part: "The non-Federal Entity must use one of the following methods of procurement. . . . (b) Procurement by small purchase procedures. Small purchase procedures are those relatively simple and informal procurement methods for securing services, supplies, or other property that do not cost more than the Simplified Acquisition Threshold. If small purchase procedures are used, price or rate quotations must be obtained from an adequate number of qualified sources. Condition: An effective internal control system was not in place at the School Corporation to ensure compliance with requirements related to the Child Nutrition Program and Procurement and Suspension and Debarment compliance requirements. Cause: The School Corporation's management had not developed a system of internal controls that would have ensured compliance with the Procurement and Suspension and Debarment compliance requirement. Effect: The failure to establish an effective internal control system placed the School Corporation at risk of noncompliance with the grant agreement and the compliance requirements. A lack of segregation of duties within an internal control system could have also allowed noncompliance with the compliance requirements and allowed the misuse and mismanagement of federal funds and assets by not having proper oversight, reviews, and approvals over the activities of the programs. Questioned Costs: There were no questioned costs identified. Context: The School Corporation had one vendor which exceeded the simplified acquisition threshold which was selected for testing. The School Corporation was unable to provide any supporting documentation for the procurement process required under School Corporation policy. The sample item amount disbursed was $160,827 for food purchases in FY23. Additionally, the School Corporation did not have any support to show the vendor was not debarred or suspended. Identification as a repeat finding, if applicable: This is a repeat finding from the immediately prior audit. The prior finding number was 2022-003. Recommendation: We recommended that the School Corporation's management establish a system of internal controls related to ensure that the School Corporation’s procurement policy is adhered to and all documentation is maintained for the procurements performed by the School Corporation. Additionally, we recommend management monitor annual vendor activity to ensure vendors that exceed small purchase threshold and suspension and debarment threshold in aggregate are reviewed for potential analysis and suspension and debarment checks required by federal and state regulations. Views of Responsible Officials and Planned Corrective Actions: Management agrees with the finding and has prepared a corrective action plan.

FY End: 2024-06-30
Commonwealth of Virginia
Compliance Requirement: P
2024-010: Obtain, Review, and Document System and Organization Control Reports of Third-Party Service Providers Applicable to: Department of Social Services Prior Year Finding Number: 2023-085; 2022-089; 2021-019 Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: N/A ALPT or Cluster Name and ALN: Pandemic EBT Food Benefits - 10.542 Federal Award Number and Year: Not Applicable - 2024 Name of Federa...

2024-010: Obtain, Review, and Document System and Organization Control Reports of Third-Party Service Providers Applicable to: Department of Social Services Prior Year Finding Number: 2023-085; 2022-089; 2021-019 Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: N/A ALPT or Cluster Name and ALN: Pandemic EBT Food Benefits - 10.542 Federal Award Number and Year: Not Applicable - 2024 Name of Federal Agency: U.S. Department of Agriculture Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(a) Known Questioned Costs: $0 Social Services continues to not obtain, review, and document System and Organization Controls (SOC) reports, specifically SOC 1, Type 2 reports, to gain assurance over its third-party service providers’ internal controls relevant to financial reporting. SOC 1, Type 2 reports address the service organization’s internal controls and the effect those internal controls may have on the user entity’s financial statements. Social Services uses service organizations to perform functions that are significant to its financial operations such as administering the electronic benefit transfer (EBT) process for several of its public assistance programs. For instance, during fiscal year 2024, one of Social Services’ third-party service providers issued more than $2 billion in financial assistance to beneficiaries on EBT cards. Topic 10305 of the CAPP Manual requires agencies to have adequate interaction with service providers to appropriately understand the service provider’s internal control environment and maintain oversight over service providers to gain assurance over outsourced operations. Additionally, 2 CFR § 200.303(a) requires non-federal entities to establish, document, and maintain effective internal control over the federal award that provides reasonable assurance that the non-federal entity is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award. Social Services’ tasks contract administrators with responsibility for obtaining, reviewing, and documenting SOC 1, Type 2 reports. However, contract administrators are often not familiar with the CAPP Manual requirements, and Social Services has not made them aware of the expectations for obtaining, reviewing, and documenting SOC 1, Type 2 reports through a documented policy and procedure. As a result, contract administrators have not been obtaining, reviewing, and documenting SOC 1, Type 2 reports. Without adopting a policy and procedure over SOC 1, Type 2 reports and communicating those expectations to contract administrators, Social Services is unable to ensure its complementary user entity controls are sufficient to support their reliance on the service providers’ control design, implementation, and operating effectiveness. Additionally, Social Services is unable to address any internal control deficiencies and/or exceptions identified in the SOC 1, Type 2 reports. In effect, Social Services is increasing the risk that it will not detect a weakness in a service provider’s environment by not obtaining the necessary SOC 1, Type 2 reports timely or properly documenting its review of the reports. Social Services should designate a resource within the agency, who is knowledgeable of the CAPP Manual and SOC 1, Type 2 report requirements, with responsibility for developing an office-wide policy and procedure that contract administrators can use for obtaining, reviewing, and documenting SOC 1, Type 2 reports. At a minimum, Social Services’ policy and procedure should include the timeframes for obtaining SOC 1, Type 2 reports from service providers, documentation requirements for user entity complementary controls, the steps needed to address internal control deficiencies and/or exceptions found in reviews, and the staff responsible for any corrective actions necessary to mitigate the risk to the Commonwealth until the service provider corrects the deficiency. Thereafter, Social Services should communicate the policy and procedure to all individuals responsible for overseeing service provider operations to ensure compliance with federal and state regulations. Finally, Social Services should retain this information as part of its annual Agency Risk Management and Internal Control Standard certification. Views of Responsible Officials: The views of responsible officials are included in the report related to their applicable organization, which can be found at www.apa.virginia.gov and, in summary, do not express disagreement with the finding.

FY End: 2024-06-30
Commonwealth of Virginia
Compliance Requirement: P
2024-032: Improve Database Security Applicable to: Department of Education - Direct Aid to Public Education Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Configuration Management; Audit and Accountability ALPT or Cluster Name and ALN: Coronavirus State and Local Fiscal Recovery Funds (CSLFRF) - 21.027; Supporting Effective Instruction State Grants (formerly Improv...

2024-032: Improve Database Security Applicable to: Department of Education - Direct Aid to Public Education Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Configuration Management; Audit and Accountability ALPT or Cluster Name and ALN: Coronavirus State and Local Fiscal Recovery Funds (CSLFRF) - 21.027; Supporting Effective Instruction State Grants (formerly Improving Teacher Quality State Grants) - 84.367 Federal Award Number and Year: Various - 2024 Name of Federal Agency: U.S. Department of Treasury; U.S. Department of Education Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Education does not implement some of the required controls to protect the database that supports Education’s system of record. The Commonwealth’s Information Security Standard, SEC530 (Security Standard), and industry best practices, such as the Center for Internet Security, prescribe certain required and recommended security controls to safeguard systems that contain or process sensitive data. The Security Standard requires and industry best practices recommend implementing specific controls to reduce unnecessary risk to data confidentiality, integrity, and availability. We communicated three control weaknesses to management in a separate document marked Freedom of Information Act Exempt (FOIAE) under § 2.2-3705.2 of the Code of Virginia due to it containing descriptions of security mechanisms. By not meeting the minimum requirements in the Security Standard and not aligning the database’s settings and configurations with industry best practices, Education cannot appropriately manage and maintain the database and ensure data integrity. Education should allocate the necessary resources to ensure database configurations, controls, and processes align with the requirements in the Security Standard and industry best practices. Implementing these controls will help maintain the confidentiality, integrity, and availability of the sensitive and mission critical data stored or processed in the database. Views of Responsible Officials: The views of responsible officials are included in the report related to their applicable organization, which can be found at www.apa.virginia.gov and, in summary, do not express disagreement with the finding.

FY End: 2024-06-30
Commonwealth of Virginia
Compliance Requirement: P
2024-032: Improve Database Security Applicable to: Department of Education - Direct Aid to Public Education Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Configuration Management; Audit and Accountability ALPT or Cluster Name and ALN: Coronavirus State and Local Fiscal Recovery Funds (CSLFRF) - 21.027; Supporting Effective Instruction State Grants (formerly Improv...

2024-032: Improve Database Security Applicable to: Department of Education - Direct Aid to Public Education Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Configuration Management; Audit and Accountability ALPT or Cluster Name and ALN: Coronavirus State and Local Fiscal Recovery Funds (CSLFRF) - 21.027; Supporting Effective Instruction State Grants (formerly Improving Teacher Quality State Grants) - 84.367 Federal Award Number and Year: Various - 2024 Name of Federal Agency: U.S. Department of Treasury; U.S. Department of Education Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Education does not implement some of the required controls to protect the database that supports Education’s system of record. The Commonwealth’s Information Security Standard, SEC530 (Security Standard), and industry best practices, such as the Center for Internet Security, prescribe certain required and recommended security controls to safeguard systems that contain or process sensitive data. The Security Standard requires and industry best practices recommend implementing specific controls to reduce unnecessary risk to data confidentiality, integrity, and availability. We communicated three control weaknesses to management in a separate document marked Freedom of Information Act Exempt (FOIAE) under § 2.2-3705.2 of the Code of Virginia due to it containing descriptions of security mechanisms. By not meeting the minimum requirements in the Security Standard and not aligning the database’s settings and configurations with industry best practices, Education cannot appropriately manage and maintain the database and ensure data integrity. Education should allocate the necessary resources to ensure database configurations, controls, and processes align with the requirements in the Security Standard and industry best practices. Implementing these controls will help maintain the confidentiality, integrity, and availability of the sensitive and mission critical data stored or processed in the database. Views of Responsible Officials: The views of responsible officials are included in the report related to their applicable organization, which can be found at www.apa.virginia.gov and, in summary, do not express disagreement with the finding.

FY End: 2024-06-30
Commonwealth of Virginia
Compliance Requirement: P
2024-032: Improve Database Security Applicable to: Department of Education - Direct Aid to Public Education Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Configuration Management; Audit and Accountability ALPT or Cluster Name and ALN: Coronavirus State and Local Fiscal Recovery Funds (CSLFRF) - 21.027; Supporting Effective Instruction State Grants (formerly Improv...

2024-032: Improve Database Security Applicable to: Department of Education - Direct Aid to Public Education Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Configuration Management; Audit and Accountability ALPT or Cluster Name and ALN: Coronavirus State and Local Fiscal Recovery Funds (CSLFRF) - 21.027; Supporting Effective Instruction State Grants (formerly Improving Teacher Quality State Grants) - 84.367 Federal Award Number and Year: Various - 2024 Name of Federal Agency: U.S. Department of Treasury; U.S. Department of Education Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Education does not implement some of the required controls to protect the database that supports Education’s system of record. The Commonwealth’s Information Security Standard, SEC530 (Security Standard), and industry best practices, such as the Center for Internet Security, prescribe certain required and recommended security controls to safeguard systems that contain or process sensitive data. The Security Standard requires and industry best practices recommend implementing specific controls to reduce unnecessary risk to data confidentiality, integrity, and availability. We communicated three control weaknesses to management in a separate document marked Freedom of Information Act Exempt (FOIAE) under § 2.2-3705.2 of the Code of Virginia due to it containing descriptions of security mechanisms. By not meeting the minimum requirements in the Security Standard and not aligning the database’s settings and configurations with industry best practices, Education cannot appropriately manage and maintain the database and ensure data integrity. Education should allocate the necessary resources to ensure database configurations, controls, and processes align with the requirements in the Security Standard and industry best practices. Implementing these controls will help maintain the confidentiality, integrity, and availability of the sensitive and mission critical data stored or processed in the database. Views of Responsible Officials: The views of responsible officials are included in the report related to their applicable organization, which can be found at www.apa.virginia.gov and, in summary, do not express disagreement with the finding.

FY End: 2024-06-30
Commonwealth of Virginia
Compliance Requirement: P
2024-032: Improve Database Security Applicable to: Department of Education - Direct Aid to Public Education Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Configuration Management; Audit and Accountability ALPT or Cluster Name and ALN: Coronavirus State and Local Fiscal Recovery Funds (CSLFRF) - 21.027; Supporting Effective Instruction State Grants (formerly Improv...

2024-032: Improve Database Security Applicable to: Department of Education - Direct Aid to Public Education Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Configuration Management; Audit and Accountability ALPT or Cluster Name and ALN: Coronavirus State and Local Fiscal Recovery Funds (CSLFRF) - 21.027; Supporting Effective Instruction State Grants (formerly Improving Teacher Quality State Grants) - 84.367 Federal Award Number and Year: Various - 2024 Name of Federal Agency: U.S. Department of Treasury; U.S. Department of Education Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Education does not implement some of the required controls to protect the database that supports Education’s system of record. The Commonwealth’s Information Security Standard, SEC530 (Security Standard), and industry best practices, such as the Center for Internet Security, prescribe certain required and recommended security controls to safeguard systems that contain or process sensitive data. The Security Standard requires and industry best practices recommend implementing specific controls to reduce unnecessary risk to data confidentiality, integrity, and availability. We communicated three control weaknesses to management in a separate document marked Freedom of Information Act Exempt (FOIAE) under § 2.2-3705.2 of the Code of Virginia due to it containing descriptions of security mechanisms. By not meeting the minimum requirements in the Security Standard and not aligning the database’s settings and configurations with industry best practices, Education cannot appropriately manage and maintain the database and ensure data integrity. Education should allocate the necessary resources to ensure database configurations, controls, and processes align with the requirements in the Security Standard and industry best practices. Implementing these controls will help maintain the confidentiality, integrity, and availability of the sensitive and mission critical data stored or processed in the database. Views of Responsible Officials: The views of responsible officials are included in the report related to their applicable organization, which can be found at www.apa.virginia.gov and, in summary, do not express disagreement with the finding.

FY End: 2024-06-30
Commonwealth of Virginia
Compliance Requirement: P
2024-032: Improve Database Security Applicable to: Department of Education - Direct Aid to Public Education Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Configuration Management; Audit and Accountability ALPT or Cluster Name and ALN: Coronavirus State and Local Fiscal Recovery Funds (CSLFRF) - 21.027; Supporting Effective Instruction State Grants (formerly Improv...

2024-032: Improve Database Security Applicable to: Department of Education - Direct Aid to Public Education Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Configuration Management; Audit and Accountability ALPT or Cluster Name and ALN: Coronavirus State and Local Fiscal Recovery Funds (CSLFRF) - 21.027; Supporting Effective Instruction State Grants (formerly Improving Teacher Quality State Grants) - 84.367 Federal Award Number and Year: Various - 2024 Name of Federal Agency: U.S. Department of Treasury; U.S. Department of Education Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Education does not implement some of the required controls to protect the database that supports Education’s system of record. The Commonwealth’s Information Security Standard, SEC530 (Security Standard), and industry best practices, such as the Center for Internet Security, prescribe certain required and recommended security controls to safeguard systems that contain or process sensitive data. The Security Standard requires and industry best practices recommend implementing specific controls to reduce unnecessary risk to data confidentiality, integrity, and availability. We communicated three control weaknesses to management in a separate document marked Freedom of Information Act Exempt (FOIAE) under § 2.2-3705.2 of the Code of Virginia due to it containing descriptions of security mechanisms. By not meeting the minimum requirements in the Security Standard and not aligning the database’s settings and configurations with industry best practices, Education cannot appropriately manage and maintain the database and ensure data integrity. Education should allocate the necessary resources to ensure database configurations, controls, and processes align with the requirements in the Security Standard and industry best practices. Implementing these controls will help maintain the confidentiality, integrity, and availability of the sensitive and mission critical data stored or processed in the database. Views of Responsible Officials: The views of responsible officials are included in the report related to their applicable organization, which can be found at www.apa.virginia.gov and, in summary, do not express disagreement with the finding.

FY End: 2024-06-30
Commonwealth of Virginia
Compliance Requirement: P
2024-089: Perform an Evaluation of Student Information System Access Roles Applicable to: Northern Virginia Community College Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: N/A ALPT or Cluster Name and ALN: Student Financial Assistance Cluster Federal Award Number and Year: Various - 2024 Name of Federal Agency: U.S. Department of Education Type of Compliance Req...

2024-089: Perform an Evaluation of Student Information System Access Roles Applicable to: Northern Virginia Community College Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: N/A ALPT or Cluster Name and ALN: Student Financial Assistance Cluster Federal Award Number and Year: Various - 2024 Name of Federal Agency: U.S. Department of Education Type of Compliance Requirement - Criteria: Other - 16 CFR § 200.303(e) Known Questioned Costs: $0 NVCC staff did not properly grant student information system roles and privileges. Specifically, we found seven of 45 (16%) employees have access to financial aid data beyond the requirements to complete their job responsibilities. The underlying cause of improper access is due to management not aligning the assignment of access roles with the concept of least privilege and not properly reviewing access levels of staff. By not properly assigning access based on job responsibilities, NVCC increases the risk it will have employees with improper access levels that do not align with concept of least privilege nor allow for segregation of duties. In accordance with 16 CFR § 200.303(e), the non-federal entity must take reasonable measures to safeguard protected personally identifiable information and other information the federal awarding agency or pass-through entity designates as sensitive, or the non-federal entity considers sensitive, consistent with applicable, federal, state, and local laws regarding privacy and responsibility over confidentiality. In addition, the International Organization for Standardization and International Electrotechnical Commission Standard (ISO Standard), states that care should be taken with role-based access control systems to ensure that employees are not granted conflicting roles. Roles should be carefully designed and provisioned to minimize access problems if a role is removed or reassigned. The ISO Standard further states that care should be taken when specifying access control rules to consider establishing rules based on the premise of least privilege. NVCC information security staff and management should perform a thorough evaluation of employees and grant student information system roles based upon the concept of least privilege and considering job responsibilities. Views of Responsible Officials: The views of responsible officials are included in the report related to their applicable organization, which can be found at www.apa.virginia.gov and, in summary, do not express disagreement with the finding.

FY End: 2024-06-30
Commonwealth of Virginia
Compliance Requirement: P
2024-089: Perform an Evaluation of Student Information System Access Roles Applicable to: Northern Virginia Community College Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: N/A ALPT or Cluster Name and ALN: Student Financial Assistance Cluster Federal Award Number and Year: Various - 2024 Name of Federal Agency: U.S. Department of Education Type of Compliance Req...

2024-089: Perform an Evaluation of Student Information System Access Roles Applicable to: Northern Virginia Community College Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: N/A ALPT or Cluster Name and ALN: Student Financial Assistance Cluster Federal Award Number and Year: Various - 2024 Name of Federal Agency: U.S. Department of Education Type of Compliance Requirement - Criteria: Other - 16 CFR § 200.303(e) Known Questioned Costs: $0 NVCC staff did not properly grant student information system roles and privileges. Specifically, we found seven of 45 (16%) employees have access to financial aid data beyond the requirements to complete their job responsibilities. The underlying cause of improper access is due to management not aligning the assignment of access roles with the concept of least privilege and not properly reviewing access levels of staff. By not properly assigning access based on job responsibilities, NVCC increases the risk it will have employees with improper access levels that do not align with concept of least privilege nor allow for segregation of duties. In accordance with 16 CFR § 200.303(e), the non-federal entity must take reasonable measures to safeguard protected personally identifiable information and other information the federal awarding agency or pass-through entity designates as sensitive, or the non-federal entity considers sensitive, consistent with applicable, federal, state, and local laws regarding privacy and responsibility over confidentiality. In addition, the International Organization for Standardization and International Electrotechnical Commission Standard (ISO Standard), states that care should be taken with role-based access control systems to ensure that employees are not granted conflicting roles. Roles should be carefully designed and provisioned to minimize access problems if a role is removed or reassigned. The ISO Standard further states that care should be taken when specifying access control rules to consider establishing rules based on the premise of least privilege. NVCC information security staff and management should perform a thorough evaluation of employees and grant student information system roles based upon the concept of least privilege and considering job responsibilities. Views of Responsible Officials: The views of responsible officials are included in the report related to their applicable organization, which can be found at www.apa.virginia.gov and, in summary, do not express disagreement with the finding.

FY End: 2024-06-30
Commonwealth of Virginia
Compliance Requirement: P
2024-089: Perform an Evaluation of Student Information System Access Roles Applicable to: Northern Virginia Community College Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: N/A ALPT or Cluster Name and ALN: Student Financial Assistance Cluster Federal Award Number and Year: Various - 2024 Name of Federal Agency: U.S. Department of Education Type of Compliance Req...

2024-089: Perform an Evaluation of Student Information System Access Roles Applicable to: Northern Virginia Community College Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: N/A ALPT or Cluster Name and ALN: Student Financial Assistance Cluster Federal Award Number and Year: Various - 2024 Name of Federal Agency: U.S. Department of Education Type of Compliance Requirement - Criteria: Other - 16 CFR § 200.303(e) Known Questioned Costs: $0 NVCC staff did not properly grant student information system roles and privileges. Specifically, we found seven of 45 (16%) employees have access to financial aid data beyond the requirements to complete their job responsibilities. The underlying cause of improper access is due to management not aligning the assignment of access roles with the concept of least privilege and not properly reviewing access levels of staff. By not properly assigning access based on job responsibilities, NVCC increases the risk it will have employees with improper access levels that do not align with concept of least privilege nor allow for segregation of duties. In accordance with 16 CFR § 200.303(e), the non-federal entity must take reasonable measures to safeguard protected personally identifiable information and other information the federal awarding agency or pass-through entity designates as sensitive, or the non-federal entity considers sensitive, consistent with applicable, federal, state, and local laws regarding privacy and responsibility over confidentiality. In addition, the International Organization for Standardization and International Electrotechnical Commission Standard (ISO Standard), states that care should be taken with role-based access control systems to ensure that employees are not granted conflicting roles. Roles should be carefully designed and provisioned to minimize access problems if a role is removed or reassigned. The ISO Standard further states that care should be taken when specifying access control rules to consider establishing rules based on the premise of least privilege. NVCC information security staff and management should perform a thorough evaluation of employees and grant student information system roles based upon the concept of least privilege and considering job responsibilities. Views of Responsible Officials: The views of responsible officials are included in the report related to their applicable organization, which can be found at www.apa.virginia.gov and, in summary, do not express disagreement with the finding.

FY End: 2024-06-30
Commonwealth of Virginia
Compliance Requirement: P
2024-089: Perform an Evaluation of Student Information System Access Roles Applicable to: Northern Virginia Community College Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: N/A ALPT or Cluster Name and ALN: Student Financial Assistance Cluster Federal Award Number and Year: Various - 2024 Name of Federal Agency: U.S. Department of Education Type of Compliance Req...

2024-089: Perform an Evaluation of Student Information System Access Roles Applicable to: Northern Virginia Community College Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: N/A ALPT or Cluster Name and ALN: Student Financial Assistance Cluster Federal Award Number and Year: Various - 2024 Name of Federal Agency: U.S. Department of Education Type of Compliance Requirement - Criteria: Other - 16 CFR § 200.303(e) Known Questioned Costs: $0 NVCC staff did not properly grant student information system roles and privileges. Specifically, we found seven of 45 (16%) employees have access to financial aid data beyond the requirements to complete their job responsibilities. The underlying cause of improper access is due to management not aligning the assignment of access roles with the concept of least privilege and not properly reviewing access levels of staff. By not properly assigning access based on job responsibilities, NVCC increases the risk it will have employees with improper access levels that do not align with concept of least privilege nor allow for segregation of duties. In accordance with 16 CFR § 200.303(e), the non-federal entity must take reasonable measures to safeguard protected personally identifiable information and other information the federal awarding agency or pass-through entity designates as sensitive, or the non-federal entity considers sensitive, consistent with applicable, federal, state, and local laws regarding privacy and responsibility over confidentiality. In addition, the International Organization for Standardization and International Electrotechnical Commission Standard (ISO Standard), states that care should be taken with role-based access control systems to ensure that employees are not granted conflicting roles. Roles should be carefully designed and provisioned to minimize access problems if a role is removed or reassigned. The ISO Standard further states that care should be taken when specifying access control rules to consider establishing rules based on the premise of least privilege. NVCC information security staff and management should perform a thorough evaluation of employees and grant student information system roles based upon the concept of least privilege and considering job responsibilities. Views of Responsible Officials: The views of responsible officials are included in the report related to their applicable organization, which can be found at www.apa.virginia.gov and, in summary, do not express disagreement with the finding.

FY End: 2024-06-30
Commonwealth of Virginia
Compliance Requirement: P
2024-089: Perform an Evaluation of Student Information System Access Roles Applicable to: Northern Virginia Community College Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: N/A ALPT or Cluster Name and ALN: Student Financial Assistance Cluster Federal Award Number and Year: Various - 2024 Name of Federal Agency: U.S. Department of Education Type of Compliance Req...

2024-089: Perform an Evaluation of Student Information System Access Roles Applicable to: Northern Virginia Community College Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: N/A ALPT or Cluster Name and ALN: Student Financial Assistance Cluster Federal Award Number and Year: Various - 2024 Name of Federal Agency: U.S. Department of Education Type of Compliance Requirement - Criteria: Other - 16 CFR § 200.303(e) Known Questioned Costs: $0 NVCC staff did not properly grant student information system roles and privileges. Specifically, we found seven of 45 (16%) employees have access to financial aid data beyond the requirements to complete their job responsibilities. The underlying cause of improper access is due to management not aligning the assignment of access roles with the concept of least privilege and not properly reviewing access levels of staff. By not properly assigning access based on job responsibilities, NVCC increases the risk it will have employees with improper access levels that do not align with concept of least privilege nor allow for segregation of duties. In accordance with 16 CFR § 200.303(e), the non-federal entity must take reasonable measures to safeguard protected personally identifiable information and other information the federal awarding agency or pass-through entity designates as sensitive, or the non-federal entity considers sensitive, consistent with applicable, federal, state, and local laws regarding privacy and responsibility over confidentiality. In addition, the International Organization for Standardization and International Electrotechnical Commission Standard (ISO Standard), states that care should be taken with role-based access control systems to ensure that employees are not granted conflicting roles. Roles should be carefully designed and provisioned to minimize access problems if a role is removed or reassigned. The ISO Standard further states that care should be taken when specifying access control rules to consider establishing rules based on the premise of least privilege. NVCC information security staff and management should perform a thorough evaluation of employees and grant student information system roles based upon the concept of least privilege and considering job responsibilities. Views of Responsible Officials: The views of responsible officials are included in the report related to their applicable organization, which can be found at www.apa.virginia.gov and, in summary, do not express disagreement with the finding.

FY End: 2024-06-30
Commonwealth of Virginia
Compliance Requirement: P
2024-032: Improve Database Security Applicable to: Department of Education - Direct Aid to Public Education Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Configuration Management; Audit and Accountability ALPT or Cluster Name and ALN: Coronavirus State and Local Fiscal Recovery Funds (CSLFRF) - 21.027; Supporting Effective Instruction State Grants (formerly Improv...

2024-032: Improve Database Security Applicable to: Department of Education - Direct Aid to Public Education Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Configuration Management; Audit and Accountability ALPT or Cluster Name and ALN: Coronavirus State and Local Fiscal Recovery Funds (CSLFRF) - 21.027; Supporting Effective Instruction State Grants (formerly Improving Teacher Quality State Grants) - 84.367 Federal Award Number and Year: Various - 2024 Name of Federal Agency: U.S. Department of Treasury; U.S. Department of Education Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Education does not implement some of the required controls to protect the database that supports Education’s system of record. The Commonwealth’s Information Security Standard, SEC530 (Security Standard), and industry best practices, such as the Center for Internet Security, prescribe certain required and recommended security controls to safeguard systems that contain or process sensitive data. The Security Standard requires and industry best practices recommend implementing specific controls to reduce unnecessary risk to data confidentiality, integrity, and availability. We communicated three control weaknesses to management in a separate document marked Freedom of Information Act Exempt (FOIAE) under § 2.2-3705.2 of the Code of Virginia due to it containing descriptions of security mechanisms. By not meeting the minimum requirements in the Security Standard and not aligning the database’s settings and configurations with industry best practices, Education cannot appropriately manage and maintain the database and ensure data integrity. Education should allocate the necessary resources to ensure database configurations, controls, and processes align with the requirements in the Security Standard and industry best practices. Implementing these controls will help maintain the confidentiality, integrity, and availability of the sensitive and mission critical data stored or processed in the database. Views of Responsible Officials: The views of responsible officials are included in the report related to their applicable organization, which can be found at www.apa.virginia.gov and, in summary, do not express disagreement with the finding.

FY End: 2024-06-30
Commonwealth of Virginia
Compliance Requirement: P
2024-089: Perform an Evaluation of Student Information System Access Roles Applicable to: Northern Virginia Community College Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: N/A ALPT or Cluster Name and ALN: Student Financial Assistance Cluster Federal Award Number and Year: Various - 2024 Name of Federal Agency: U.S. Department of Education Type of Compliance Req...

2024-089: Perform an Evaluation of Student Information System Access Roles Applicable to: Northern Virginia Community College Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: N/A ALPT or Cluster Name and ALN: Student Financial Assistance Cluster Federal Award Number and Year: Various - 2024 Name of Federal Agency: U.S. Department of Education Type of Compliance Requirement - Criteria: Other - 16 CFR § 200.303(e) Known Questioned Costs: $0 NVCC staff did not properly grant student information system roles and privileges. Specifically, we found seven of 45 (16%) employees have access to financial aid data beyond the requirements to complete their job responsibilities. The underlying cause of improper access is due to management not aligning the assignment of access roles with the concept of least privilege and not properly reviewing access levels of staff. By not properly assigning access based on job responsibilities, NVCC increases the risk it will have employees with improper access levels that do not align with concept of least privilege nor allow for segregation of duties. In accordance with 16 CFR § 200.303(e), the non-federal entity must take reasonable measures to safeguard protected personally identifiable information and other information the federal awarding agency or pass-through entity designates as sensitive, or the non-federal entity considers sensitive, consistent with applicable, federal, state, and local laws regarding privacy and responsibility over confidentiality. In addition, the International Organization for Standardization and International Electrotechnical Commission Standard (ISO Standard), states that care should be taken with role-based access control systems to ensure that employees are not granted conflicting roles. Roles should be carefully designed and provisioned to minimize access problems if a role is removed or reassigned. The ISO Standard further states that care should be taken when specifying access control rules to consider establishing rules based on the premise of least privilege. NVCC information security staff and management should perform a thorough evaluation of employees and grant student information system roles based upon the concept of least privilege and considering job responsibilities. Views of Responsible Officials: The views of responsible officials are included in the report related to their applicable organization, which can be found at www.apa.virginia.gov and, in summary, do not express disagreement with the finding.

FY End: 2024-06-30
Commonwealth of Virginia
Compliance Requirement: P
2024-089: Perform an Evaluation of Student Information System Access Roles Applicable to: Northern Virginia Community College Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: N/A ALPT or Cluster Name and ALN: Student Financial Assistance Cluster Federal Award Number and Year: Various - 2024 Name of Federal Agency: U.S. Department of Education Type of Compliance Req...

2024-089: Perform an Evaluation of Student Information System Access Roles Applicable to: Northern Virginia Community College Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: N/A ALPT or Cluster Name and ALN: Student Financial Assistance Cluster Federal Award Number and Year: Various - 2024 Name of Federal Agency: U.S. Department of Education Type of Compliance Requirement - Criteria: Other - 16 CFR § 200.303(e) Known Questioned Costs: $0 NVCC staff did not properly grant student information system roles and privileges. Specifically, we found seven of 45 (16%) employees have access to financial aid data beyond the requirements to complete their job responsibilities. The underlying cause of improper access is due to management not aligning the assignment of access roles with the concept of least privilege and not properly reviewing access levels of staff. By not properly assigning access based on job responsibilities, NVCC increases the risk it will have employees with improper access levels that do not align with concept of least privilege nor allow for segregation of duties. In accordance with 16 CFR § 200.303(e), the non-federal entity must take reasonable measures to safeguard protected personally identifiable information and other information the federal awarding agency or pass-through entity designates as sensitive, or the non-federal entity considers sensitive, consistent with applicable, federal, state, and local laws regarding privacy and responsibility over confidentiality. In addition, the International Organization for Standardization and International Electrotechnical Commission Standard (ISO Standard), states that care should be taken with role-based access control systems to ensure that employees are not granted conflicting roles. Roles should be carefully designed and provisioned to minimize access problems if a role is removed or reassigned. The ISO Standard further states that care should be taken when specifying access control rules to consider establishing rules based on the premise of least privilege. NVCC information security staff and management should perform a thorough evaluation of employees and grant student information system roles based upon the concept of least privilege and considering job responsibilities. Views of Responsible Officials: The views of responsible officials are included in the report related to their applicable organization, which can be found at www.apa.virginia.gov and, in summary, do not express disagreement with the finding.

FY End: 2024-06-30
Commonwealth of Virginia
Compliance Requirement: L
2024-102: Implement Internal Controls over TANF Federal Special Reporting Applicable to: Department of Social Services Prior Year Finding Number: 2023-106 Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: N/A ALPT or Cluster Name and ALN: Temporary Assistance for Needy Families (TANF) - 93.558 Federal Award Number and Year: 2401VATANF - 2024 Name of Federal Agency: U.S. Department of Health and H...

2024-102: Implement Internal Controls over TANF Federal Special Reporting Applicable to: Department of Social Services Prior Year Finding Number: 2023-106 Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: N/A ALPT or Cluster Name and ALN: Temporary Assistance for Needy Families (TANF) - 93.558 Federal Award Number and Year: 2401VATANF - 2024 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Reporting - 2 CFR § 200.303(a) Known Questioned Costs: $0 Benefit Programs has not documented its process for preparing the ACF’s Annual Report on State MOE Programs (ACF-204) for the TANF federal grant program. ACF requires Social Services submit this data annually and uses the information in reports to Congress about how TANF programs are evolving, in assessing State and Territory MOE expenditures, and in assessing the need for legislative changes. Title 2 CFR § 200.303(a) requires the non-federal entity to establish, document, and maintain effective internal control over the federal award that provides reasonable assurance that the recipient is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award. During fiscal year 2024, Benefit Programs performed an analysis of ACF-204 reporting errors identified during the prior audit to determine causality and has taken actions to resolve those errors. Additionally, Benefit Programs created a systems modification request to correct errors that it identified as occurring due to inaccurate programming in the data modification phase of the federal report creation. However, Benefit Programs has not yet documented its processes for preparing the ACF-204 report through a written policy and procedure. Documented policies and procedures will help Social Services maintain continuity with its processes to comply with laws and regulations. Without documented policies and procedures, there is a risk that Social Services could report inaccurate information to the federal government that could lead to Social Services incurring fines and/or penalties. Benefit Programs should dedicate the necessary resources to document its processes for preparing the ACF-204 report to ensure reasonably accurate reporting of TANF MOE Programs to ACF in accordance with the ACF-204 reporting instructions. Views of Responsible Officials: The views of responsible officials are included in the report related to their applicable organization, which can be found at www.apa.virginia.gov and, in summary, do not express disagreement with the finding.

FY End: 2024-06-30
Commonwealth of Virginia
Compliance Requirement: L
2024-106: Strengthen Internal Controls over FFATA Reporting Applicable to: Department of Social Services Prior Year Finding Number: 2023-107; 2022-106 Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: N/A ALPT or Cluster Name and ALN: Temporary Assistance for Needy Families (TANF) - 93.558 Federal Award Number and Year: 2401VATANF - 2024 Name of Federal Agency: U.S. Department of Health and Human...

2024-106: Strengthen Internal Controls over FFATA Reporting Applicable to: Department of Social Services Prior Year Finding Number: 2023-107; 2022-106 Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: N/A ALPT or Cluster Name and ALN: Temporary Assistance for Needy Families (TANF) - 93.558 Federal Award Number and Year: 2401VATANF - 2024 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Reporting - 2 CFR Part 170 Appendix A Known Questioned Costs: $0 Finance is not maintaining adequate internal control over Federal Funding Accountability and Transparency Act (FFATA) reporting. FFATA reporting is intended to provide full disclosure of how entities and organizations are obligating federal funds. During fiscal year 2024, Social Services disbursed approximately $660 million in federal funds from roughly 5,300 subawards. While auditing FFATA reporting for the TANF federal grant program, we noted that Finance did not file any FFATA reports for its subrecipients. Social Services awarded over $72 million in nearly 300 new TANF subawards during fiscal year 2024. Title 2 CFR Part 170 Appendix A requires the non-federal entity to report each obligating action that equals or exceeds $30,000 to the FFATA Subaward Reporting System (FSRS) by the end of the month following the obligating action. This also applies to any subaward modifications that increase the amount to equal or exceed $30,000. Finally, 2 CFR § 200.303(a) states that the non-federal entity must establish, document, and maintain effective internal control over the federal award that provides reasonable assurance that the non-federal entity is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award. Finance uses a decentralized approach to fulfil its FFATA reporting responsibilities since it does not determine which subrecipients will receive federal funding. Since there is an elevated risk that Finance will not report all subaward information to FSRS, it has obtained a report of subrecipients from its financial reporting system and identified those who spent $30,000 or more in TANF funds during fiscal year 2024. However, Finance management did not compare this report to its FSRS submissions to verify that the agency submitted the submissions accurately and timely. As a result, Finance management did not recognize that it did not comply with the FFATA reporting requirements. When Social Services does not upload all obligating actions meeting the reporting threshold to FSRS as required, a citizen or federal official may have a distorted view as to how Social Services is obligating federal funds. Finance management should provide sufficient oversight to confirm that the agency is submitting FFATA reporting submissions timely. Specifically, Finance management should periodically compare the report of subrecipients from its financial reporting system to FSRS to ensure it is reporting all subawards to FSRS and escalate any concerns that hinder its ability to comply with federal regulations. Views of Responsible Officials: The views of responsible officials are included in the report related to their applicable organization, which can be found at www.apa.virginia.gov and, in summary, do not express disagreement with the finding.

FY End: 2024-06-30
Commonwealth of Virginia
Compliance Requirement: L
2024-102: Implement Internal Controls over TANF Federal Special Reporting Applicable to: Department of Social Services Prior Year Finding Number: 2023-106 Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: N/A ALPT or Cluster Name and ALN: Temporary Assistance for Needy Families (TANF) - 93.558 Federal Award Number and Year: 2401VATANF - 2024 Name of Federal Agency: U.S. Department of Health and H...

2024-102: Implement Internal Controls over TANF Federal Special Reporting Applicable to: Department of Social Services Prior Year Finding Number: 2023-106 Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: N/A ALPT or Cluster Name and ALN: Temporary Assistance for Needy Families (TANF) - 93.558 Federal Award Number and Year: 2401VATANF - 2024 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Reporting - 2 CFR § 200.303(a) Known Questioned Costs: $0 Benefit Programs has not documented its process for preparing the ACF’s Annual Report on State MOE Programs (ACF-204) for the TANF federal grant program. ACF requires Social Services submit this data annually and uses the information in reports to Congress about how TANF programs are evolving, in assessing State and Territory MOE expenditures, and in assessing the need for legislative changes. Title 2 CFR § 200.303(a) requires the non-federal entity to establish, document, and maintain effective internal control over the federal award that provides reasonable assurance that the recipient is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award. During fiscal year 2024, Benefit Programs performed an analysis of ACF-204 reporting errors identified during the prior audit to determine causality and has taken actions to resolve those errors. Additionally, Benefit Programs created a systems modification request to correct errors that it identified as occurring due to inaccurate programming in the data modification phase of the federal report creation. However, Benefit Programs has not yet documented its processes for preparing the ACF-204 report through a written policy and procedure. Documented policies and procedures will help Social Services maintain continuity with its processes to comply with laws and regulations. Without documented policies and procedures, there is a risk that Social Services could report inaccurate information to the federal government that could lead to Social Services incurring fines and/or penalties. Benefit Programs should dedicate the necessary resources to document its processes for preparing the ACF-204 report to ensure reasonably accurate reporting of TANF MOE Programs to ACF in accordance with the ACF-204 reporting instructions. Views of Responsible Officials: The views of responsible officials are included in the report related to their applicable organization, which can be found at www.apa.virginia.gov and, in summary, do not express disagreement with the finding.

FY End: 2024-06-30
Commonwealth of Virginia
Compliance Requirement: L
2024-106: Strengthen Internal Controls over FFATA Reporting Applicable to: Department of Social Services Prior Year Finding Number: 2023-107; 2022-106 Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: N/A ALPT or Cluster Name and ALN: Temporary Assistance for Needy Families (TANF) - 93.558 Federal Award Number and Year: 2401VATANF - 2024 Name of Federal Agency: U.S. Department of Health and Human...

2024-106: Strengthen Internal Controls over FFATA Reporting Applicable to: Department of Social Services Prior Year Finding Number: 2023-107; 2022-106 Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: N/A ALPT or Cluster Name and ALN: Temporary Assistance for Needy Families (TANF) - 93.558 Federal Award Number and Year: 2401VATANF - 2024 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Reporting - 2 CFR Part 170 Appendix A Known Questioned Costs: $0 Finance is not maintaining adequate internal control over Federal Funding Accountability and Transparency Act (FFATA) reporting. FFATA reporting is intended to provide full disclosure of how entities and organizations are obligating federal funds. During fiscal year 2024, Social Services disbursed approximately $660 million in federal funds from roughly 5,300 subawards. While auditing FFATA reporting for the TANF federal grant program, we noted that Finance did not file any FFATA reports for its subrecipients. Social Services awarded over $72 million in nearly 300 new TANF subawards during fiscal year 2024. Title 2 CFR Part 170 Appendix A requires the non-federal entity to report each obligating action that equals or exceeds $30,000 to the FFATA Subaward Reporting System (FSRS) by the end of the month following the obligating action. This also applies to any subaward modifications that increase the amount to equal or exceed $30,000. Finally, 2 CFR § 200.303(a) states that the non-federal entity must establish, document, and maintain effective internal control over the federal award that provides reasonable assurance that the non-federal entity is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award. Finance uses a decentralized approach to fulfil its FFATA reporting responsibilities since it does not determine which subrecipients will receive federal funding. Since there is an elevated risk that Finance will not report all subaward information to FSRS, it has obtained a report of subrecipients from its financial reporting system and identified those who spent $30,000 or more in TANF funds during fiscal year 2024. However, Finance management did not compare this report to its FSRS submissions to verify that the agency submitted the submissions accurately and timely. As a result, Finance management did not recognize that it did not comply with the FFATA reporting requirements. When Social Services does not upload all obligating actions meeting the reporting threshold to FSRS as required, a citizen or federal official may have a distorted view as to how Social Services is obligating federal funds. Finance management should provide sufficient oversight to confirm that the agency is submitting FFATA reporting submissions timely. Specifically, Finance management should periodically compare the report of subrecipients from its financial reporting system to FSRS to ensure it is reporting all subawards to FSRS and escalate any concerns that hinder its ability to comply with federal regulations. Views of Responsible Officials: The views of responsible officials are included in the report related to their applicable organization, which can be found at www.apa.virginia.gov and, in summary, do not express disagreement with the finding.

FY End: 2024-06-30
Commonwealth of Virginia
Compliance Requirement: L
2024-104: Implement Internal Controls over LIHEAP Federal Special Reporting Applicable to: Department of Social Services Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: N/A ALPT or Cluster Name and ALN: Low-Income Home Energy Assistance Program (LIHEAP) - 93.568 Federal Award Number and Year: 2401VALIEA - 2024 Name of Federal Agency: U.S. Department of Health and ...

2024-104: Implement Internal Controls over LIHEAP Federal Special Reporting Applicable to: Department of Social Services Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: N/A ALPT or Cluster Name and ALN: Low-Income Home Energy Assistance Program (LIHEAP) - 93.568 Federal Award Number and Year: 2401VALIEA - 2024 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Reporting - 2 CFR § 200.303(a); 45 CFR § 96.82(a) Known Questioned Costs: $0 Benefit Programs has not documented its processes for preparing and verifying the information reported in the LIHEAP federal grant program’s Annual Household Report. The federal government requires Social Services to annually submit this data and uses this information to provide reports to Congress for assessing the uses of funds for the assistance of households in need. Benefit Programs uses a third-party service provider to produce data reports from its case management system that program staff use to populate the LIHEAP Annual Household Report and Benefit Programs relies on the third-party service provider’s internal controls during the data extraction process. Benefit Programs could not substantiate the information reported for four out of seven (57%) of the line items in Section I - Number of assisted households of the most recent LIHEAP Annual Household Report. Specifically, we noted the following inconsistencies: Benefit Programs reported 2,571 households assisted on the Emergency Furnace Repair and Replacement line, which is 12 percent higher than the information in the case management system. Benefit Programs reported 118,347 households assisted on the Any Type of LIHEAP Assistance line, which is 21 percent lower than the information in the case management system. Benefit Programs reported 117,274 households assisted on the Bill Payment Assistance line, which is 20 percent higher than the information in the case management system. Benefit Programs could not provide support to substantiate the Weatherization line. Title 2 CFR § 200.303(a) requires the non-federal entity to establish, document, and maintain effective internal control over the federal award that provides reasonable assurance that the recipient is managing the federal award in compliance with federal statutes, regulations, and its terms and conditions. Further, 45 CFR § 96.82(a) requires each grantee, whether a State or an insular area, that receives an annual allotment of at least $200,000 to submit this data for the 12-month period preceding the federal fiscal year in which the grantee requests the funds. The grantee must report the data separately for LIHEAP heating, cooling, crisis, and weatherization assistance. If Social Services does not submit this report properly, ACF may not grant them their LIHEAP grant allotment as per 45 CFR § 96.82(c). Benefit Programs has not dedicated the necessary resources to document its processes for preparing the LIHEAP Annual Household Report. Documented policies and procedures will help Social Services maintain continuity with its processes to comply with laws and regulations. Without documented policies and procedures, there is a risk that Social Services could report inaccurate information to the federal government that could lead to Social Services incurring fines and/or penalties. Additionally, reporting potentially inaccurate information prevents the federal government from adequately monitoring Social Services’ overall performance for the LIHEAP federal grant program. Therefore, Benefit Programs should dedicate the necessary resources to document its processes for preparing the LIHEAP Annual Household Report, including the processes used to verify the data provided by its third-party service provider. Views of Responsible Officials: The views of responsible officials are included in the report related to their applicable organization, which can be found at www.apa.virginia.gov and, in summary, do not express disagreement with the finding.

FY End: 2024-06-30
Commonwealth of Virginia
Compliance Requirement: L
2024-104: Implement Internal Controls over LIHEAP Federal Special Reporting Applicable to: Department of Social Services Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: N/A ALPT or Cluster Name and ALN: Low-Income Home Energy Assistance Program (LIHEAP) - 93.568 Federal Award Number and Year: 2401VALIEA - 2024 Name of Federal Agency: U.S. Department of Health and ...

2024-104: Implement Internal Controls over LIHEAP Federal Special Reporting Applicable to: Department of Social Services Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: N/A ALPT or Cluster Name and ALN: Low-Income Home Energy Assistance Program (LIHEAP) - 93.568 Federal Award Number and Year: 2401VALIEA - 2024 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Reporting - 2 CFR § 200.303(a); 45 CFR § 96.82(a) Known Questioned Costs: $0 Benefit Programs has not documented its processes for preparing and verifying the information reported in the LIHEAP federal grant program’s Annual Household Report. The federal government requires Social Services to annually submit this data and uses this information to provide reports to Congress for assessing the uses of funds for the assistance of households in need. Benefit Programs uses a third-party service provider to produce data reports from its case management system that program staff use to populate the LIHEAP Annual Household Report and Benefit Programs relies on the third-party service provider’s internal controls during the data extraction process. Benefit Programs could not substantiate the information reported for four out of seven (57%) of the line items in Section I - Number of assisted households of the most recent LIHEAP Annual Household Report. Specifically, we noted the following inconsistencies: Benefit Programs reported 2,571 households assisted on the Emergency Furnace Repair and Replacement line, which is 12 percent higher than the information in the case management system. Benefit Programs reported 118,347 households assisted on the Any Type of LIHEAP Assistance line, which is 21 percent lower than the information in the case management system. Benefit Programs reported 117,274 households assisted on the Bill Payment Assistance line, which is 20 percent higher than the information in the case management system. Benefit Programs could not provide support to substantiate the Weatherization line. Title 2 CFR § 200.303(a) requires the non-federal entity to establish, document, and maintain effective internal control over the federal award that provides reasonable assurance that the recipient is managing the federal award in compliance with federal statutes, regulations, and its terms and conditions. Further, 45 CFR § 96.82(a) requires each grantee, whether a State or an insular area, that receives an annual allotment of at least $200,000 to submit this data for the 12-month period preceding the federal fiscal year in which the grantee requests the funds. The grantee must report the data separately for LIHEAP heating, cooling, crisis, and weatherization assistance. If Social Services does not submit this report properly, ACF may not grant them their LIHEAP grant allotment as per 45 CFR § 96.82(c). Benefit Programs has not dedicated the necessary resources to document its processes for preparing the LIHEAP Annual Household Report. Documented policies and procedures will help Social Services maintain continuity with its processes to comply with laws and regulations. Without documented policies and procedures, there is a risk that Social Services could report inaccurate information to the federal government that could lead to Social Services incurring fines and/or penalties. Additionally, reporting potentially inaccurate information prevents the federal government from adequately monitoring Social Services’ overall performance for the LIHEAP federal grant program. Therefore, Benefit Programs should dedicate the necessary resources to document its processes for preparing the LIHEAP Annual Household Report, including the processes used to verify the data provided by its third-party service provider. Views of Responsible Officials: The views of responsible officials are included in the report related to their applicable organization, which can be found at www.apa.virginia.gov and, in summary, do not express disagreement with the finding.

FY End: 2024-06-30
Commonwealth of Virginia
Compliance Requirement: P
2024-011: Improve Fiscal Agent Oversight Applicable to: Department of Medical Assistance Services Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: N/A ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 Federal Award Number and Year: 2405VA5MAP - 2024 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Require...

2024-011: Improve Fiscal Agent Oversight Applicable to: Department of Medical Assistance Services Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: N/A ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 Federal Award Number and Year: 2405VA5MAP - 2024 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(a) Known Questioned Costs: $0 Medical Assistance Services did not obtain and review a System and Organization Controls (SOC) report, specifically a SOC I, Type 2 report, to gain assurance over its fiscal agent’s internal controls relevant to financial reporting. In addition to services related to information systems management and security, Medical Assistance Services contracts with the fiscal agent to perform accurate and timely payments of Medicaid claims to providers and maintain an accounts receivable ledger for the collection of provider funds owed to Medical Assistance Services. The fiscal agent processed over $22 billion in Medicaid-related payments during fiscal year 2024. Medical Assistance Services obtained a SOC 2, Type 2 report related to the fiscal agent’s controls over information systems management and security, however, this report did not provide an opinion over internal controls relevant to Medical Assistance Services’ significant fiscal activity and financial reporting. The Commonwealth’s Accounting Policies and Procedures Manual Topic 10305 requires agencies to have adequate interaction with service providers to appropriately understand the service provider’s internal control environment. It also states that agencies must also maintain oversight over service providers to gain assurance over outsourced operations. Additionally, Title 2 U.S. Code of Federal Regulations (CFR) § 200.303(a) requires non-federal entities to establish and maintain effective internal control over the federal award that provides reasonable assurance that the non-federal entity is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award. The existing contract between Medical Assistance Services and the fiscal agent does not require the fiscal agent to obtain an independent review opining to the effectiveness of internal controls related to Medical Assistance Services’ significant fiscal activities and financial reporting. Management asserted that they are currently working to modify the contract with the provider to add this requirement. Although management maintains a high degree of interaction with its fiscal agent, they cannot adequately ensure the fiscal agent has designed and implemented sufficient controls, and whether the controls are operating effectively without obtaining and reviewing a SOC I, Type 2 report. This issue increases the risk that management will not detect a weakness in the fiscal agent’s environment, which could negatively impact the Commonwealth. Medical Assistance Services should continue to work with the fiscal agent to add language to the contract that would require the fiscal agent to obtain an appropriate independent audit of its internal controls relevant to Medical Assistance Services’ financial activities and reporting. Once the new contract language is in effect, Medical Assistance Services’ management should obtain and review the SOC I, Type 2 report annually to ensure the fiscal agent is meeting contractual obligations and has proper internal controls over Medical Assistance Services’ significant fiscal activities and financial reporting. Views of Responsible Officials: The views of responsible officials are included in the report related to their applicable organization, which can be found at www.apa.virginia.gov and, in summary, do not express disagreement with the finding.

FY End: 2024-06-30
Commonwealth of Virginia
Compliance Requirement: P
2024-017: Improve IT Third-Party Oversight Process Applicable to: Department of Medical Assistance Services Prior Year Finding Number: 2023-086; 2022-090 Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Third-Party Service Providers (Information Systems) ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 Federal Award Number and Year: 2405VA5MAP - 2024 Name of Federal Agency:...

2024-017: Improve IT Third-Party Oversight Process Applicable to: Department of Medical Assistance Services Prior Year Finding Number: 2023-086; 2022-090 Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Third-Party Service Providers (Information Systems) ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 Federal Award Number and Year: 2405VA5MAP - 2024 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Medical Assistance Services has made progress to document and implement a formal process for maintaining oversight for three of its IT third-party service providers that manage and support its Medicaid management system. The Medicaid management system encompasses different functions, such as member and provider reporting, financial reporting, and federal reporting. Since the prior year audit, Medical Assistance Services developed its Information Technology (IT) Third Party Risk Management Procedure, which was effective on February 1, 2024, to facilitate the implementation of its IT System and Services Acquisition Policy. However, Medical Assistance Services is still working to implement the new procedure, which has resulted in the agency not yet verifying the following required controls and processes for one of the Medicaid management system IT service providers that is not covered by the Virginia Information Technologies Agency (VITA) Commonwealth of Virginia Risk and Authority Management Program. Medical Assistance Services does not confirm the geographic location of sensitive data monthly for IT service providers. Without confirming the geographic location of sensitive data, Medical Assistance Services may be unable to enforce contract requirements, laws, and standards due to the data falling outside of the United States’ jurisdiction. Medical Assistance Services does not confirm whether IT service providers perform vulnerability scans every 90 days. By not obtaining and analyzing the vulnerability scan results from the IT service provider, Medical Assistance Services increases the risk that the IT service providers are not remediating legitimate vulnerabilities in a timely manner. Medical Assistance Services experienced delays in implementing its new procedure due to limited staffing to properly communicate and train those responsible for monitoring IT service providers. Medical Assistance Services expects to complete its implementation by October 2024. Medical Assistance Services should dedicate the resources necessary to finish implementing its Third-Party Risk Management Procedure. Additionally, Medical Assistance Services should ensure that those tasked with monitoring IT service providers are confirming the geographic location of sensitive data and the provider’s performance of vulnerability scanning and remediation efforts per the Security Standard. Medical Assistance Services should also ensure the individuals responsible for monitoring consistently perform formal oversight processes in a timely manner, which will help maintain the confidentiality, integrity, and availability of sensitive and mission-critical data. Views of Responsible Officials: The views of responsible officials are included in the report related to their applicable organization, which can be found at www.apa.virginia.gov and, in summary, do not express disagreement with the finding.

FY End: 2024-06-30
Commonwealth of Virginia
Compliance Requirement: P
2024-022: Improve Information Security Program and Controls Applicable to: Department of Medical Assistance Services Prior Year Finding Number: 2023-010; 2022-024; 2021-024; 2020-024 Type of Finding: Internal Control and Compliance Severity of Deficiency: Material Weakness Information System Security Control Family: Access Control; Awareness and Training; Incident Response; Information Security Roles and Responsibilities; Planning; Risk Assessment; Security Assessment and Authorization; ...

2024-022: Improve Information Security Program and Controls Applicable to: Department of Medical Assistance Services Prior Year Finding Number: 2023-010; 2022-024; 2021-024; 2020-024 Type of Finding: Internal Control and Compliance Severity of Deficiency: Material Weakness Information System Security Control Family: Access Control; Awareness and Training; Incident Response; Information Security Roles and Responsibilities; Planning; Risk Assessment; Security Assessment and Authorization; System and Services Acquisition ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 Federal Award Number and Year: 2405VA5MAP - 2024 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Medical Assistance Services continues to address weaknesses in its information technology (IT) general controls originally identified in a 2020 audit and confirmed in a 2023 audit covering the same IT general controls conducted by Medical Assistance Services’ Internal Audit division. During the 2023 audit, Internal Audit tested 105 controls required by the Commonwealth’s previous version of the Information Security Standard, SEC501, and identified 61 individual control weaknesses, a 58% non-compliance rate, that Internal Audit grouped into eight findings. Medical Assistance Services addressed four of the eight findings during fiscal year 2024. Noncompliance with required security controls increases the risk for unauthorized access to mission-critical systems and data in addition to weakening Medical Assistance Services ability to respond to malicious attacks to its IT environment. Medical Assistance Services has experienced delays in addressing these findings due to the number of findings and resources required to remediate the weaknesses. Medical Assistance Services updated its corrective action plan for the four remaining findings in June 2024, stating corrective actions are still ongoing with an estimated completion date of September 2024. Medical Assistance Services should prioritize and dedicate the necessary resources to ensure timely completion of its corrective action plans and to become compliant with the current version of the Commonwealth’s Information Security Standard, SEC530 (Security Standard). These actions will help maintain the confidentiality, integrity, and availability of sensitive and mission-critical data. Views of Responsible Officials: The views of responsible officials are included in the report related to their applicable organization, which can be found at www.apa.virginia.gov and, in summary, do not express disagreement with the finding.

FY End: 2024-06-30
Commonwealth of Virginia
Compliance Requirement: P
2024-023: Improve Database Security Applicable to: Department of Medical Assistance Services Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Access Control; Audit and Accountability; Configuration Management; Contingency Planning; Identification and Authentication; System and Information Integrity ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.7...

2024-023: Improve Database Security Applicable to: Department of Medical Assistance Services Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Access Control; Audit and Accountability; Configuration Management; Contingency Planning; Identification and Authentication; System and Information Integrity ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 Federal Award Number and Year: 2405VA5MAP - 2024 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Medical Assistance Services does not have formal policies, procedures, and a baseline configuration that outlines requirements and justifications for securing and maintaining the database supporting its primary system for financial accounting and reporting operations in accordance with the Security Standard, and industry best practices, such as the Center for Internet Security Benchmarks (CIS Benchmark). As a result, Medical Assistance Services has not implemented some required controls over the database. We communicated the weaknesses to management in a separate document marked Freedom of Information Act Exempt (FOIAE) under § 2.2-3705.2 of the Code of Virginia due to it containing descriptions of security mechanisms. The Security Standard requires Medical Assistance Services to develop, document, and disseminate information security policies and procedures that align with the control requirements in the Security Standard. Additionally, the Security Standard requires Medical Assistance Services to develop, document, and maintain a current baseline configuration of the system and apply more restrictive security configurations for sensitive systems. The Security Standard also requires Medical Assistance Services to review and update the policies, procedures, and baseline configuration on an annual basis and following an environmental change. Without detailed policies, procedures, and a baseline configuration that outlines requirements and justifications for securing and maintaining its database, Medical Assistance Services increases the risk that the system will not meet the minimum security requirements and recommendations to protect its sensitive data from malicious parties. Medical Assistance Services has experienced a lack of resources which has contributed to the absence of documentation outlining control requirements and procedures needed to properly secure the database. The absence of this documentation contributed to the deficiencies communicated in the FOIAE document and as a result, Medical Assistance Services has not consistently evaluated and applied security controls. Medical Assistance Services should dedicate the resources necessary to develop and implement formal policies and procedures to support its database based on the Security Standard requirements and settings recommended by industry best practices, such as the CIS Benchmark. Medical Assistance Services should develop a formal baseline configuration for the database that defines required security controls outlined in industry best practices, such as the CIS Benchmark. The baseline configuration should define deviations from recommended and expected security configurations as well as business justification and approval for any deviations. Additionally, Medical Assistance Services should develop a process to review the database’s configuration against its established baseline configuration on a scheduled basis and after major changes occur to help detect and address potential misconfigurations timely. Furthermore, Medical Assistance Services should implement the security controls and processes communicated in the FOIAE document to address risks present in the database to ensure the configuration aligns with the Security Standard and CIS Benchmark. These actions will help maintain the confidentiality, availability, and integrity of Medical Assistance Services’ sensitive and mission-critical data. Views of Responsible Officials: The views of responsible officials are included in the report related to their applicable organization, which can be found at www.apa.virginia.gov and, in summary, do not express disagreement with the finding.

FY End: 2024-06-30
Commonwealth of Virginia
Compliance Requirement: P
2024-024: Continue Improving IT Risk Management Program Applicable to: Department of Social Services Prior Year Finding Number: 2023-014; 2022-030; 2021-026; 2020-027; 2019-063; 2018-025 Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Planning; Risk Assessment ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 Federal Award Number and Year: 2405VA5MAP - 2024 Name of Federal ...

2024-024: Continue Improving IT Risk Management Program Applicable to: Department of Social Services Prior Year Finding Number: 2023-014; 2022-030; 2021-026; 2020-027; 2019-063; 2018-025 Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Planning; Risk Assessment ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 Federal Award Number and Year: 2405VA5MAP - 2024 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Social Services continues to not have a formal and effective IT risk management program that aligns with the requirements in the Security Standard. Since we first issued this finding in 2018, Social Services remediated some risk management and contingency planning issues. However, Social Services continues not to: accurately verify and validate data and system sensitivity ratings; create risk assessments for 90 percent of its sensitive systems; create system security plans for the 55 current systems identified as sensitive; review risk assessments for 100 percent of its existing documentation; and implement corrective actions identified in risk assessments. We communicated the details of these weaknesses to management in a separate document marked FOIAE under § 2.2-3705.2 of the Code of Virginia, due to it containing descriptions of security mechanisms. The Security Standard requires agencies to implement certain controls that reduce unnecessary risk to the confidentiality, integrity, and availability of Social Services’ information systems and data. ISRM and TSD defined and documented a new risk assessment policy and procedure in April 2024. Social Services also established a new risk assessment process that engages system administrators and system owners to complete a risk assessment worksheet to submit to ISRM for evaluation. ISRM meets with system administrators, system owners, and the Agency Head, to review the resulting risk assessment report and establish a risk mitigation plan. However, Social Services has not yet matured the new risk assessment process due to recently formalizing the process. Social Services established the Cybersecurity Team as part of TSD in fiscal year 2024; therefore, the Cybersecurity Team and ISRM have not yet assessed and integrated the various risk management processes. Additionally, the new risk assessment procedure does not define and document the requirements and processes Social Services must follow to implement the corrective action responsibilities. ISRM should work with TSD, the Cybersecurity Team, and business units to ensure Social Services establishes and maintains an up-to-date sensitive systems list. The Information Security Officer, in conjunction with system and data owners, should classify agency IT systems and data based on sensitivity. Following its new risk assessment procedure and process, ISRM and the Cybersecurity Team should prioritize completing risk assessments and system security plans for its sensitive systems and review those documents annually to validate that the information reflects the current environment. Additionally, TSD should implement security controls to mitigate the risks and vulnerabilities identified in its risk assessments. Improving the IT risk management program will help to ensure the confidentiality, integrity, and availability of the agency’s sensitive systems and mission-essential functions. Views of Responsible Officials: The views of responsible officials are included in the report related to their applicable organization, which can be found at www.apa.virginia.gov and, in summary, do not express disagreement with the finding.

FY End: 2024-06-30
Commonwealth of Virginia
Compliance Requirement: P
2024-025: Improve Web Application Security Applicable to: Department of Social Services Prior Year Finding Number: 2023-015; 2022-029; 2021-025; 2020-026; 2019-037 Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Audit and Accountability; Configuration Management; Risk Assessment; System and Information Integrity ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 Federal Award...

2024-025: Improve Web Application Security Applicable to: Department of Social Services Prior Year Finding Number: 2023-015; 2022-029; 2021-025; 2020-026; 2019-037 Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Audit and Accountability; Configuration Management; Risk Assessment; System and Information Integrity ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 Federal Award Number and Year: 2405VA5MAP - 2024 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Social Services continues to not configure a sensitive web application in accordance with the Security Standard. During fiscal year 2024, Social Services remediated two of the five previously identified weaknesses; however, these two weaknesses existed during the fiscal year under review. Additionally, Social Services has not remediated three of the previously identified weaknesses. We communicated the weaknesses to management in a separate document marked FOIAE under § 2.2-3705.2 of the Code of Virginia, due to it containing descriptions of security mechanisms. The Security Standard requires agencies to implement certain controls that reduce unnecessary risk to the confidentiality, integrity, and availability of Social Services’ information systems and data. Lacking and insufficient procedures and processes to manage the web application contributed to the five weaknesses outlined in the separate FOIAE document. Social Services prioritizing other projects also contributed to the weaknesses persisting. TSD, ISRM, and business owners should work together to remediate the remaining weaknesses to secure the web application and meet the minimum requirements in its internal policies and the Security Standard. Addressing these weaknesses will help to ensure the confidentiality, integrity, and availability of sensitive and mission-critical data and achieve compliance with both internal policies and the Security Standard. Views of Responsible Officials: The views of responsible officials are included in the report related to their applicable organization, which can be found at www.apa.virginia.gov and, in summary, do not express disagreement with the finding.

FY End: 2024-06-30
Commonwealth of Virginia
Compliance Requirement: P
2024-035: Improve Information Security Program and IT Governance Applicable to: Department of Social Services Prior Year Finding Number: 2023-027; 2022-022 Type of Finding: Internal Control and Compliance Severity of Deficiency: Material Weakness Information System Security Control Family: Information Security Roles and Responsibilities ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 Federal Award Number and Year: 2405VA5MAP - 2024 Name of Federal Agency: U.S. ...

2024-035: Improve Information Security Program and IT Governance Applicable to: Department of Social Services Prior Year Finding Number: 2023-027; 2022-022 Type of Finding: Internal Control and Compliance Severity of Deficiency: Material Weakness Information System Security Control Family: Information Security Roles and Responsibilities ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 Federal Award Number and Year: 2405VA5MAP - 2024 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Social Services continues to have an insufficient governance structure to manage and maintain its information security program in accordance with the Security Standard. Specifically, Social Services does not assess information security requirements for its information technology (IT) projects and prioritize information security and IT resources to ensure its information security program effectively protects sensitive Commonwealth data in accordance with the Security Standard. We communicated the control weaknesses to management in a separate document marked Freedom of Information Act Exempt (FOIAE) under § 2.2-3705.2 of the Code of Virginia due to its sensitivity and description of security controls. The Security Standard requires the agency head to maintain an information security program that is sufficient to protect the agency’s IT systems and to ensure the agency documents and effectively communicates the information security program. Not prioritizing IT resources to properly manage its information security program can result in a data breach or unauthorized access to confidential and mission-critical data, leading to data corruption, data loss, or system disruption if accessed by a malicious attacker, either internal or external. The control weaknesses described in the communication marked FOIAE are the result of Social Services not assessing information security requirements prior to project implementation, in addition to Social Services not prioritizing information security within the IT environment. Social Services has hindered its ability to consistently and timely remediate findings from management recommendations issued during prior year audits and bring the information security program in compliance with the Security Standard by not dedicating the necessary IT resources to information security. During fiscal year 2024, Social Services created a cybersecurity team under the Technology Services Division (TSD) to liaison between TSD and the Division of Information Security and Risk Management (ISRM) to help bring the information security program in compliance with the Security Standard. However, due to the magnitude of the project, TSD, the cybersecurity team, ISRM, and the executive team have not yet completed efforts to remediate this finding. TSD, ISRM, and Social Services’ Cybersecurity and Executive teams should continue to work together to bring the IT security program in compliance with the Security Standard. TSD and ISRM should continue to evaluate IT resource levels to ensure sufficient resources are available and dedicated to prioritizing and implementing IT governance changes and address the control deficiencies discussed in the communication marked FOIAE. Additionally, Social Services should evaluate the organizational placement of the Information Security Officer (ISO) to ensure effective implementation of the information security program and controls. Implementing these recommendations will help to ensure Social Services protects the confidentiality, integrity, and availability of its sensitive and mission-critical data. Views of Responsible Officials: The views of responsible officials are included in the report related to their applicable organization, which can be found at www.apa.virginia.gov and, in summary, do not express disagreement with the finding.

FY End: 2024-06-30
Commonwealth of Virginia
Compliance Requirement: P
2024-041: Evaluate Separation of Duty Conflicts within the Case Management System Applicable to: Department of Social Services Prior Year Finding Number: 2023-034 Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Access Control ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 Federal Award Number and Year: 2405VA5MAP - 2024 Name of Federal Agency: U.S. Department of Health ...

2024-041: Evaluate Separation of Duty Conflicts within the Case Management System Applicable to: Department of Social Services Prior Year Finding Number: 2023-034 Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Access Control ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 Federal Award Number and Year: 2405VA5MAP - 2024 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Benefit Programs, which is the owner of Social Services’ case management system, has not performed nor documented a conflicting access review to identify the combination of roles that could pose a separation of duties conflict or to ensure compensating controls are in place to mitigate risks arising from those conflicts. Social Services uses the case management system to determine applicant eligibility and authorize benefit payments for the Medicaid, SNAP, CCDF, LIHEAP, and TANF federal grant programs. Social Services authorized over $17 billion in public assistance payments to beneficiaries from these federal programs through its case management system during fiscal year 2024. The Security Standard requires the agency to separate duties of individuals as necessary, document separation of duties of individuals, and define information system access authorizations to support the separation of duties. Further, Social Services’ Information Security Policy states that the system owner is responsible for identifying and documenting separation of duties of individuals and defining system access authorizations to support separation of duties. Without performing and documenting a conflicting access review, Social Services does not know which combination of roles may pose a separation of duties conflict and is unable to implement compensating controls. In effect, this increases the possibility of a system breach or other malicious attack on Social Services’ data and places Social Services’ reputation at risk. Benefit Programs has not yet begun their corrective action efforts and ISRM has not included this finding in its Plan of Actions and Milestones (POAM) report, which is its internal corrective action plan that it shares with Social Services’ Executive Team. As a result, Social Services’ Executive Team was not aware that Social Services continues to be non-compliant with the Security Standard and its Information Security Policy. According to Social Services’ Organizational Structure Report, ISRM provides guidance to system owners about security requirements and is ultimately responsible for protecting Social Services’ information systems by addressing security compliance and risk. Benefit Programs should conduct a conflicting access review for the case management system and collaborate with ISRM to ensure it performs and documents this review in accordance with Social Services’ Information Security Policy. Additionally, ISRM should monitor this finding’s progress through its POAM report and provide periodic updates to Social Services’ Executive Team. Views of Responsible Officials: The views of responsible officials are included in the report related to their applicable organization, which can be found at www.apa.virginia.gov and, in summary, do not express disagreement with the finding.

FY End: 2024-06-30
Commonwealth of Virginia
Compliance Requirement: P
2024-042: Perform Annual Review of Case Management System Access Applicable to: Department of Social Services Prior Year Finding Number: 2023-035 Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Access Control ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 Federal Award Number and Year: 2405VA5MAP - 2024 Name of Federal Agency: U.S. Department of Health and Human Service...

2024-042: Perform Annual Review of Case Management System Access Applicable to: Department of Social Services Prior Year Finding Number: 2023-035 Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Access Control ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 Federal Award Number and Year: 2405VA5MAP - 2024 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Benefit Programs, which is the owner of Social Services’ case management system, continues to not perform the required annual access review. Social Services uses the case management system to determine applicant eligibility and authorize benefit payments for the Medicaid, SNAP, CCDF, LIHEAP, and TANF federal grant programs. Social Services authorized over $17 billion in public assistance payments to beneficiaries from these federal programs through its case management system during fiscal year 2024. The Security Standard requires the agency to review accounts for compliance with account management on an annual basis. Additionally, ISRM’s Procedures Manual for State and Local Security Officers requires system owners and security officers to review user access privileges annually. System owners and security officers must complete this review within 364 days from the completion date of the last security review. Benefit Programs last completed a security review over the case management system in June 2022. Benefit Programs is responsible for obtaining the case management system’s access listing from ISRM, coordinating the annual review with the security officers, and working with ISRM to modify user access privileges as necessary. However, Benefit Programs did not perform the required annual access review for the case management system because it did not initiate the process with ISRM, and ISRM did not include this finding in its POAM report, which is its internal corrective action plan that it shares with Social Services’ Executive Team. As a result, Social Services’ Executive Team was not aware that Social Services continues to be non-compliant with the Security Standard and its Procedures Manual for State and Local Security Officers. According to Social Services’ Organizational Structure Report, ISRM provides guidance to System Owners about security requirements and is ultimately responsible for protecting Social Services’ information systems by addressing security compliance and risk. Social Services increases the risk of improper or unnecessary access to sensitive systems by not reviewing access to the case management system annually, which could potentially result in a system breach or other malicious attack on Social Services’ data and adversely affect its reputation. Benefit Programs should perform the required annual security review for the case management system and collaborate with ISRM to ensure it completes this review in accordance with the Procedures Manual for State and Local Officers. Additionally, ISRM should monitor this finding’s progress through its POAM report and provide periodic updates to Social Services’ Executive Team. Views of Responsible Officials: The views of responsible officials are included in the report related to their applicable organization, which can be found at www.apa.virginia.gov and, in summary, do not express disagreement with the finding.

« 1 263 264 266 267 1998 »