Year Finding Originated: 2025 Title and Assistance Listing Number of Federal Program: Staffing for Adequate Fire and Emergency Response 97.083 Federal Award Identification Number and Year: EMW-2022-FF-00974 Name of Federal Agency: Department of Homeland Security Questioned Costs: $0 Criteria: Per 2 CFR § 200.303(a), the non-Federal entity must establish, document, and maintain effective internal control over Federal awards to ensure compliance with federal statutes, regulations, and terms and conditions of the federal awards. Condition: During testing of reporting requirements for the SAFER grant, the District could not provide documentation evidencing management review and approval of required federal reports prior to submission. Discussions with management indicated that reports were prepared and submitted by District personnel; however, formal documentation evidencing management review and approval was not maintained. Cause: The District relied on informal communication and oversight rather than detailed review procedures to ensure required federal reports are accurately prepared prior to submission. Effect: While no instances of noncompliance were noted, the lack of documented controls in practice increases the risk that future required reports could be incomplete, inaccurate, or untimely. Recommendation: We recommend that the District enhance and document internal controls over financial reporting, including a detailed review and approval process for required federal reports prior to submission, including maintaining documentation evidencing such review. Views of responsible officials: See management’s response to finding on Page 59.
2025-004 Reporting ALN 21.027 Coronavirus State and Local Fiscal Funds US Department of the Treasury Fiscal Year 2025 Funding Grant Y5314 Criteria: 2 CFR 200.303 requires non-federal entities to establish and maintain effective internal controls. Reports should be subject to independent review to verify completeness, validity, and timeliness of submission. Condition: The City’s controls over reports issued to U.S. Treasury failed to operate correctly as the underlying data contained errors which were noted on the report issued to the US Treasury. Cause of the condition: The City did not have a proper review of the underlying data for the reports sent to the US Treasury as the underlying data caused the reports to be incorrect. Potential effect of condition: Reports submitted could contain errors or could be incomplete. Questioned costs: None noted. Reported finding is a deficiency in internal control. Recommendation: The City should review the underlying data along with the report to ensure the report agrees with the support and the underlying data is correct. Management Response: Management recognizes the importance of accurate and complete reporting to the U.S. Treasury. While procedures were in place, the review of underlying data was not sufficient to ensure accuracy and completeness prior to submission. The issue was limited to a single report and was corrected in the subsequent U.S. Treasury reporting cycle in accordance with program requirements. To prevent recurrence, management has enhanced its review procedures over grant reporting to include reconciliation of underlying data and validation checks for inconsistencies prior to report submission. Additionally, a secondary level of review will be performed to ensure reports are complete and accurate before submission to the U.S. Treasury.
2025-003 Suspension and Debarment ALN 21.027 Coronavirus State and Local Fiscal Funds US Department of the Treasury Fiscal Year 2025 Funding Criteria: CFR 180.300 requires the City to ensure vendors and contractors are not disqualified, excluded, or debarred prior to entering into a covered transaction. Per 2 CFR 200.303 requires non-federal entities to establish and maintain effective internal controls. The City should have a process to ensure compliance with 2 CFR 180.300. Condition: The City did not have documented controls over the review of verifying vendors are not debarred or suspended. Cause of the condition: The City completes SAM checks of all vendors however, the City does not have a review process to verify the vendor is not suspended or debarred before a contract or payment with the vendor. Potential effect of condition: The City may have covered transactions with federally debarred vendors. Questioned Costs: None noted. Reported finding is a deficiency in internal control. Recommendation: The City should put controls in place to verify SAM checks before authorizing a contract or a purchase order with a vendor for a covered transaction. Management Response: Management recognizes the importance of compliance with federal suspension and debarment requirements. Management has implemented procedures to ensure compliance with suspension and debarment requirements for federally funded transactions. As part of the procurement process, vendors responding to solicitations for grant-funded projects will be required to provide evidence of active SAM registration and certify that they are not suspended or debarred. In addition, prior to execution of contracts or issuance of purchase orders for covered transactions, management will perform and document an independent SAM.gov verification as part of standard pre-award procedures to confirm vendor eligibility.
Assistance Listing, Federal Agency, and Program Name ALN 93.982, U.S. Department of Health and Human Services, Mental Health Disaster Assistance and Emergency Mental Health Regular Services Program Wayne County Strong Federal Award Identification Number and Year 20255313 00, 2025 Pass through Entity Michigan Department of Health and Human Services Finding Type Significant deficiency Repeat Finding No Criteria Per 2 CFR 200.303, the recipient must establish, document, and maintain effective internal control over the federal award that provides reasonable assurance that the recipient is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award. These internal controls should align with the guidance in Standards for Internal Control in the Federal Government, issued by the Comptroller General of the United States, or the Internal Control Integrated Framework, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition DWIHN’s internal controls were not sufficiently designed and/or operating effectively to prevent the submission of unallowable costs for reimbursement under the federal award. Questioned Costs None If questioned costs are not determinable, description of why known questioned costs were undetermined or otherwise could not be reported Not applicable Identification of How Questioned Costs Were Computed Not applicable Context DWIHN submitted unallowable costs for reimbursement to the funding agency, including unallowable indirect costs and a duplicate invoice from one vendor. While DWIHN had a detective control in place to review expenditures included in reimbursement requests, the control was performed after the expenditures had been paid and included in reimbursement submissions. Due to the timing of this review, the detective control did not prevent DWIHN from paying the unallowable costs and subsequently requesting reimbursement for those costs. Upon identification of the unallowable expenditures, DWIHN took prompt corrective action, including recoupment of the funds from the applicable sources and repayment to the funding agency for the disallowed amounts. Ultimately, the grant was properly accounted for at the end of the grant period. Cause and Effect Although DWIHN had preventive and detective controls in place related to reimbursement requests, those controls did not operate effectively as designed for this grant program. As a result, unallowable costs were reimbursed to DWIHN by the granting agency prior to being identified and remediated. Recommendation We recommend that DWIHN strengthen and timely execute its review procedures over reimbursement requests and supporting documentation to ensure that all expenditures submitted for reimbursement comply with the terms and conditions of the grant award. This may include enhancing preventive controls or adjusting the timing of existing reviews to ensure unallowable or duplicate costs are identified and excluded prior to submission to the funding agency. Views of Responsible Officials and Corrective Action Plan DWIHN concurs with the finding. However, it should be noted that it is customary and standard practice to charge the indirect de minimis rate to federal grants in accordance with 2 CFR 200.414(f) Indirect Costs and the Department of Health & Human Services Grants Policy Statement section 2.3.4.6. Indirect Cost Rates. In addition, one (1) out of the seven (7) contracted vendors submitted FSR’s with indirect costs to the project; six (6) providers submitted the FSR’s without indirect cost thus adhering to the instructions. Further, the unallowed costs and duplicate payment were identified, corrected, and remediated by the finance staff prior to submission of the final reports, closeout of the grant and audit fieldwork. Finally, program and finance staff responsible for the approving and processing of FSR’s have been informed of the need to review FSR’s in greater detail before they are submitted, approved, and payment occurs. A more detailed review of the FSR’s as adherence to established policies and procedures, will eliminate the risk of errors and omissions.
Finding 2025-003 – Internal Controls over Federal Awards (Significant Deficiency) Information on the Federal Program: U.S. Department of Health and Human Services, Assistance Listing #93.243 Substance Abuse and Mental Health Services Projects of Regional and National Significance and Assistance Listing #93.959 Block Grants for Prevention and Treatment of Substance Abuse. Criteria: 2 CFR section 200.303 establishes the requirements for non‑federal entities to establish and maintain effective internal control over federal awards to provide reasonable assurance that transactions are properly authorized. Condition: The Council’s Grant Management Policies & Procedures Manual requires credit card purchase requests be submitted on the Council's approval form at least two weeks prior to the date needed and must have the signed approval of the Executive Director. In three of the 35 transactions tested, the credit card purchase approval form was dated after the date of purchase. Cause: Purchase requests were not consistently submitted and approved in advance of the purchase date, indicating a breakdown in adherence to established procurement timelines. . Effect: Although the transactions were ultimately approved and the costs were otherwise allowable, allocated, and properly charged to the program, failure to obtain timely approval increases the risk that purchases may be made without appropriate prior authorization. Questioned Costs: None Recommendation: We recommend management reinforce procurement procedures to ensure purchase requests are submitted and approved in accordance with the established policy requiring approval at least two weeks prior to the date needed, thereby strengthening internal controls over procurement and disbursements. Views of Responsible Officials: See Management’s View and Corrective Action Plan at the end of the report.
SD 2025-001 REPORTING Department of Commerce ALN 11.463 – Habitat Conservation Federal Award ID Number: FX463C0051 2025 Funding Criteria: Per 2 CFR 200.303, non-Federal entities must establish and maintain effective internal controls over Federal awards that provide reasonable assurance the entity is managing the award in compliance with Federal statutes, regulations, and the terms and conditions of the award. In addition, pursuant to 2 CFR Part 170, recipients of Federal awards are required to report first-tier subawards and executive compensation data in accordance with the Federal Funding Accountability and Transparency Act (FFATA). Specifically, subaward information must be reported in the Federal Subaward Reporting System (FSRS) by the end of the month following the month in which the subaward was obligated, as required by the terms and conditions of the Federal award. Condition: The FFATA report was not filed during the year as subawards were granted. Cause: The Council was unaware of the requirement to file the FFATA. Effect: Potential for unintended errors to occur without being immediately identified and corrected. The Council was not in compliance with the Uniform Guidance and the Habitat Conservation Program. Questioned Costs: None. The finding is for reporting which does not relate to questioned costs. Perspective: None of the FFATA reports were filed during 2025 for all 10 subrecipients. Recommendation: The Federal Funding Accountability and Transparency Act (FFATA) reporting requirement is a general term and condition from the Department of Commerce and should be completed as required and reviewed by someone other than the preparer before submission. Management Response: The FFATA reporting requirement was not a specific award condition on the grant award to the IRL Council from NOAA Fisheries. However, it is a standard general term and condition from the Department of Commerce which is referenced on the grant award. The subawards for the NOAA grant have now been input into SAM.gov. The IRL Council will review the specific FFATA requirements required by the Department of Commerce (different than the EPA requirements) and will make sure that the IRL Council continues to be in compliance.
Federal Agency: Environmental Protection Agency Federal Program Name: Water Pollution Control Assistance Listing Numbers: 66.419 Federal Award Identification Number: 98339418 Pass-Through Agency: N/A Pass-Through Number(s): N/A Award Period: 10/1/2023 - 12/30/2025 Compliance Requirement: Procurement Type of Finding: Significant Deficiency in Internal Control over Compliance, Other Matter Criteria or specific requirement: Compliance: Non-federal entities other than states, including those operating federal programs as subrecipients of states, must follow the procurement standards set out at 2 CFR §200.318 through §200.327. They must use their own documented procurement procedures, which reflect applicable state and local laws and regulations, provided that the procurements conform to applicable federal statutes and the procurement requirements identified in 2 CFR Part 200. Small purchase procedures are used for purchases that exceed the micro-purchase amount but do not exceed the simplified acquisition threshold ($250,000). If small purchase procedures are used, price or rate quotations must be obtained from an adequate number of qualified sources (2 CFR §200.320(b)). Control: Per 2 CFR §200.303(a), a non-Federal entity must: Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-federal entity is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award. These internal controls should comply with the guidance in "Standards for Internal Control in the Federal Government" issued by the Comptroller General of the United States or the "Internal Control-Integrated Framework," issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition/Context: For two of five procurements selected for testing, the Commission was unable to provide documentation (completed requisition form) to demonstrate compliance with their procurement policy. Questioned costs: Undetermined. Cause: Controls were not operating effectively to ensure that the Commission’s procurement policies were followed for procurements entered into where expenses were charged to the federal program. Effect: The Commission was unable to provide documentation to support compliance with Federal requirements. Repeat Finding: No. Recommendation: We recommend that the Commission ensure that it follows its procurement policies for all goods and services charged to the program and that documentation be readily available for audit. Views of responsible officials: To prevent future noncompliance the Commission will 1)clarify vendor coverage on existing agreements, 2) strengthen controls over procurement threshold, 3) monitor cumulative spending by vendor, and 4) reinforce training and communication.
Payroll Federal Agency: Department of Housing and Urban Development Federal Program Name: Community Development Block Grants Cluster Entitlements/Special Purpose Assistance Listing Number: 14.218 Federal Award Identification Number and Year: B-23-UN-12-0002 and B-25-UU-12-0003 Award Period: November 11, 2023 – November 20, 2029 and January 16, 2025 – June 6, 2031 Type of Finding: Significant Deficiency in Internal Control over Compliance, Other Matters Criteria: 2 CFR 200.302(b)(3) states that the recipient must maintain records that sufficiently identify the amount, source, and expenditure of funds for federally-funded activities. These records must contain information pertaining to federal awards, authorizations, financial obligations, unobligated balances, assets, expenditures, income and interest and be supported by source documentation. 2CFR 200.403 states that costs must be adequately documented. 2 CFR section 200.303(a) states a non-Federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non-Federal entity is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award. These internal controls should comply with guidance in Standards for Internal Control in the Federal Government issued by the Comptroller General of the United States or the Internal Control Integrated Framework issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition: There were two conditions present: • One employee had duplicate hours for three pay periods. • Two employees had incorrect pay rates used for the calculation of allowable payroll costs for seven pay periods. Questioned costs: • $3,974 - B-23-UN-12-0002 • $81 - B-25-UU-12-0003 Context: Forty employee pay periods were selected for testing. • One employee had a total of twenty-four hours duplicated over four pay periods. • Two employees had incorrect pay rates across seven pay periods. Cause: Allowable payroll costs are performed using a manual process. While the calculation was reviewed and approved, a cross check between the KRONOS report and the allowable cost calculation was not performed. Allowable payroll costs are calculated using pay rates at end of the quarter. When there are no changes during the quarter, this methodology results in an accurate calculation. However, if a pay rate changes during the quarter, this methodology results in a misstatement for the calculation of allowable payroll costs. Effect: Using incorrect hours or pay rates to calculate wages recorded quarterly can result in overcharging grant and submitting inaccurate expenditures to the grant which may lead to non-compliance with grant requirements. Repeat Finding: No Recommendation: It is recommended the County modify its procedure to include: • Improve reconciliation procedures to verify hours per pay period recorded in quarterly spreadsheet agrees to hours recorded in the KRONOS system. • Record grant wages using the pay rate at the beginning of the quarter if recorded on a quarterly basis or use pay rates for each pay period if recorded on a pay period basis. Views of responsible official and planned corrective actions: Management concurs with the auditor’s recommendations. Action taken in response to finding: • Document the audit process in a formalized SOP and cross train all reviewers from SRGA Admin, Budget, and Fiscal. • Create a checklist to accompany each personnel draw to ensure that after rates are verified that SRGA Admin certifies that no RPAs or pay adjustments were approved during the pay periods reported and if there were, a second pay rate is entered for that draw and hours are split according to accurate rates/dates. • Document the cure process in the SOP to ensure that any errors found after the fact will be corrected with HUD to remain compliant and to ensure that no funds drawn in error are retained. • Include a date verification process prior to submission of the draw to ensure that staff did not duplicate any dates. This verification will be an audit of the Time Tracking Review completed by Admin staff. Ongoing training and coaching will be administered should duplicate entries be found on final draw reports. • Audit of all personnel draws for both allocations of CDBG-DR grants will be completed using the new SOP and verification tools before the end of fiscal year 2026.
Assistance Listing, Federal Agency, and Program Name 93.870, Maternal, Infant, and Early Childhood Home Visiting Grant Federal Award Identification Number and Year S-MIEC-F-2025-9-1 Pass through Entity Children's Trust of South Carolina Finding Type Significant deficiency Repeat Finding No Criteria Per 2 CFR 200.303, the recipient must establish, document, and maintain effective internal control over the federal award that provides reasonable assurance that the recipient is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award. These internal controls should align with the guidance in Standards for Internal Control in the Federal Government, issued by the Comptroller General of the United States, or the Internal Control-Integrated Framework, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition The Organization was reimbursed $22,968 under the grant award but amounts were outside of performance year of the grant. The control in place to review expenditures was not effective in identifying expenditures that were outside the grant period. Questioned Costs $22,968 If questioned costs are not determinable, description of why known questioned costs were undetermined or otherwise could not be reported N/A Identification of How Questioned Costs Were Computed The question costs were determined by totaling all of the expenses that were identified to be outside the period of performance of the grant. Context Two contracts were entered into during the year with both having costs that were to be incurred in future period not covered by grant, but both were fully charged to grant for current fiscal year. Through testing of procurement noted that contract term started part way though grant year and for period after end of the grant's period of preformance. As through procurement there were only two contracts entered into the total cost is $22,968 of expenditures related to future period. Cause and Effect The Organization's control over contractor payments was not designed effectively to ensure costs incurred prior to requesting for reimbursement. The failure to have an effective control in place caused the Organization to charge a cost to the program that the Organization had not yet incurred. Recommendation We recommend that the review of process ensure that items have been expended prior to charging amount to the grant. Views of Responsible Officials and Planned Corrective Actions The Organization acknowledges that the expenditure was reimbursed outside of the grant’s period of performance under review due to the nature of the expenditure and accounting treatment selected. The Organization will implement enhanced review procedures of federal expenditures sought for reimbursement to better align with the underlying accounting treatment.
Finding 2025-001: Review of Compliance Matrices and Narratives - Special Tests and Provisions Federal Program Name: National Railroad Passenger Corporation Grants Assistance Listing No. 20.315 Federal Award Nos.: 69A36525520030AMTDC 69A36525520040AMTDC 69A36524520000AMTDC 69A36523504100AMTDC 69A36523504110AMTDC FR-AMT-0025-22 FR-AMT-0026-22 FR-AMT-0028-22 FR-AMT-0027-22 Federal Agency: Department of Transportation, Federal Railroad Administration Criteria 1. The code of federal regulations – 2 CFR 200.302 Financial management requires that: (a) Each state must expend and account for the Federal award in accordance with State laws and procedures for expending and accounting for the State’s funds. All recipient and subrecipient financial management systems, including records documenting compliance with Federal statutes, regulations, and the terms of the conditions of the federal award, must be sufficient to permit the preparation of reports required by the terms and conditions; and tracking expenditures to establish that funds have been used in accordance with Federal statutes, regulations, and the terms and conditions of the Federal award. 2. The code of federal regulations – 2 CFR 200.303 Internal controls requires that recipients and subrecipients must: (a) Establish, document, and maintain effective internal control over the Federal award that provides reasonable assurance that the recipient or subrecipient is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should align with the guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control-Integrated Framework” issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). (b) Comply with the U.S. Constitution, Federal statutes, regulations, and the terms and conditions of the Federal award. (c) Evaluate and monitor the recipient’s or subrecipient’s compliance with statutes, regulations, and the terms and conditions of Federal awards. Condition The following exceptions to the criteria were observed during the performance of the audit procedures: 1. For the compliance matrix that is maintained for the annual grants under Assistance Listing No. 20.315, Ernst & Young (EY) identified that for two provisions, the wording contained within the matrix did not match in its entirety to the respective grant agreement. Additionally, EY noted that two provisions that were present in the grant agreements were not included in the matrix. 2. For the compliance matrix that is maintained for Infrastructure Investment and Jobs Act (IIJA) grants under Assistance Listing No. 20.315, EY identified that two provisions present in the grant agreements were not included in the matrix. 3. For the compliance matrices maintained for both the annual grants and IIJA grants under Assistance Listing No. 20.315, EY identified a lack of evidence to support management's assessment of certain provisions as not applicable. Cause In reviewing management’s internal controls, the key internal control identified by management is not designed such that consistent, proactive monitoring and/or review occurs to ensure all compliance requirements and any changes to the wording of specific provisions are updated and reviewed within the compliance matrices and narratives. Effect or Potential Effect Amtrak is not in compliance with the 2 CFR 200.302 (a) and 2 CFR 200.303. This may also put Amtrak at greater risk of non-compliance with specific provisions in accordance with the federal awards. Questioned Costs None identified. Context EY reviewed the federal awards in scope and compared them to the compliance matrices and compliance narrative maintained by the company as part of the audit procedures in connection with the testing of the special tests and provisions compliance requirement. Per review of the grant agreements, a total of 159 provisions exist of which EY identified six provisions as missing or inaccurate as described in the condition section above. As such, this finding relates to 3.77% of the total population of provisions. Identification as a Repeat Finding This is a repeat finding of 2024-002. Recommendation EY recommends that Amtrak update the control design with enough precision to ensure that reviews and updates to the compliance matrices are made on a regular cadence to ensure that any updates, amendments or changes are monitored and updated timely. Views of Responsible Officials Amtrak recognizes the need to improve our controls over the updates of the compliance matrices and will review its control processes by the end of FY2026.
Finding 2025-002: Equipment and Real Property Management Federal Program Name: National Railroad Passenger Corporation Grants Assistance Listing No. 20.315 Federal Award Nos.: 69A36524520000AMTDC 69A36524520010AMTDC FR-AMT-0025-22 FR-AMT-0026-22 69A36523504100AMTDC 69A36523504110AMTDC FR-AMT-0019-20 FR-AMT-0020-20 FR-AMT-0003-14-01-02 FR-AMT-0022-21 FR-AMT-0023-21 DTFRDV-07-G-00002 DTFRDV-09-G-00002 FY2000 Appropriation FY1975 Appropriation Federal Agency: Department of Transportation, Federal Railroad Administration Criteria The code of federal regulations – 2 CFR 200.313 Equipment (d) Management Requirements requires that: (2) A physical inventory of the property must be conducted, and the results must be reconciled with the property records at least once every two years. (3) A control system must be in place to ensure safeguards for preventing property loss, damage, or theft. Any loss, damage, or theft of equipment must be investigated. The recipient or subrecipient must notify the Federal agency or pass-through entity of any loss, damage, or theft of equipment that will have an impact on the program. The code of federal regulations 2 CFR 200.303 Internal Controls states the recipient must: (a) Establish, document, and maintain effective internal control over the Federal award that provides reasonable assurance that the recipient or subrecipient is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should align with the guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control-Integrated Framework” issued by COSO. (d) Take prompt action when instances of noncompliance are identified. Condition The following exceptions to the criteria were observed during the performance of the audit procedures: 1. For three of the equipment samples reviewed (approximately $1.1 million net book value), it was observed that the assets within Penn Coach Yard, in Philadelphia PA, lacked adequate safeguards to prevent property loss, damage or theft, as evidenced by the occurrence of two instances of property damage in the current year. EY notes Amtrak performed satisfactory investigations into both instances. 2. During EY's procedures performed for two assets (approximately $7.2 million net book value), EY identified that no inventory had occurred for the assets, even though they had been placed in service over two years prior and would have required an inventory prior to EY's observation. As this came to EY's attention after the inventory was required and during observation procedures, EY investigated further and could not obtain alternative evidence to support that an inventory had occurred within the two-year period. Cause The lack of adequate safeguards at Penn Coach Yard is attributable to a variety of insufficiencies related to security at Penn Coach Yard. The nature of much of Amtrak’s equipment is composed of moving assets on the tracks, operating up and down the corridors, operating around the yards, or moving from location to location in a geographical region to achieve daily operational objectives thus making tracking timely inventories more challenging. Furthermore, Amtrak resources are deployed such that managers and supervisors oversee geographical regions and equipment that are stationed throughout various routes, often connecting through multiple states with many unmanned and less traveled stations. In reviewing management’s internal controls, the key internal controls identified by management are not designed to ensure consistent, timely, and proactive monitoring to verify that inventory observations occur no less than once every two years. While there is an identified internal control stating that “On a monthly basis, these reports will identify all equipment that has not been observed within 2 years and communicate to the Enterprise Asset Management and Disposition Team (EAMDT) and other appropriate parties for action to be taken. EAMDT is responsible for ensuring the observations of equipment are completed. Once the equipment is observed, information is updated in the departmental source system and subsequently updated within the EAMDT reports,” the internal control does not establish a clear action plan or expected timeframe for responsible parties to respond to or remediate identified items. Further, the internal control is designed to identify assets that are already out of compliance, rather than to proactively monitor assets approaching the two‑year threshold. As a result, the internal control design is detective in nature and may not identify the risk of noncompliance until after noncompliance has occurred. Effect or Potential Effect Noncompliance with 2 CFR 200.313 (d) (2) and (3), and potential refund of grant funds used to purchase noncompliant assets. Questioned Costs The questioned costs below represent the total underlying net book value associated with EY's five equipment selections with exceptions. Assistance Listing No. 20.315 69A36524520000AMTDC/69A36524520010AMTDC $ 4,868,340 FR-AMT-0025-22/FR-AMT-0026-22 2,624,469 69A36523504100AMTDC/69A36523504110AMTDC 590,078 FY2000 Appropriation 110,077 FR-AMT-0019-20/FR-AMT-0020-20 98,376 FR-AMT-0003-14-01-02 88,840 DTFRDV-07-G-00002 30,532 FY1975 Appropriation 9,097 FR-AMT-0022-21/FR-AMT-0023-21 5,831 DTFRDV-09-G-00002 (94,917) Total Questioned Costs $ 8,330,723 Context EY performed equipment observations as a part of the testing of the equipment compliance area, randomly selecting 60 equipment units, and performing live observations with Amtrak personnel at the site with the equipment. EY performed inquiries relating to Amtrak’s safeguarding and maintenance procedures along with an inspection of the property records. Identification as a Repeat Finding Condition 2 represents a repeat finding of 2023-001. Condition 1 is not a repeat finding. Recommendation EY recommends Amtrak set up a system with certain criteria for identifying sites at a higher risk for noncompliance with safeguard requirements, and creates an action plan for evaluating, and remediating potential noncompliance. EY recommends that management consider redesigning one of its key controls to help ensure that the monitoring of the observations is occurring on a preventive basis to help identify any exposure to non-compliance before it occurs and clearly identifies any follow-up steps and actions. For example, there should be established a protocol as well as timeline for when required observations are to take place, additionally, as it is known in advance, which items are coming up for inventory, Amtrak could prepare an annual schedule of inventories, that could be revised quarterly. Views of Responsible Officials Amtrak acknowledges the recommendation that Amtrak should have a system with certain criteria for identifying sites at a higher risk for noncompliance with safeguard requirements and create an action plan for evaluating and remediating potential noncompliance. As part of this effort, the EAMDT will work with Corporate Security to review and, as appropriate, align existing governance processes to reduce the likelihood of similar noncompliance. Amtrak agrees with the recommendation to redesign key controls to help ensure that the monitoring of the observations happens on a preventive basis to help identify any exposure to non-compliance before it occurs. Amtrak published an updated Equipment Control Policy and created an eLearning course, as well as implemented several processes, technologies, and reports that help to proactively monitor and identify equipment that is 90 days or less from needing an inventory. This has improved the compliance rate from less than 70% in FY22 to over 97% in FY25. Amtrak understands that this is a repeat finding and will review with the Amtrak departmental owner of equipment that was out of compliance to strengthen the practice and reduce the likelihood of noncompliance.
Assistance Listing, Federal Agency, and Program Name - 93.045/93.053, Department of Health and Human Services, Aging Cluster Federal Award Identification Number and Year - N/A Pass through Entity - Area Aging on Aging 1C Finding Type - Material weakness Repeat Finding - Yes 2024-15 Criteria - Per 2 CFR 200.303, nonfederal entities must establish and maintain effective internal control over the federal award that provides reasonable assurance that the nonfederal entity is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award. Per 2 CFR 200.318(b), recipients must maintain oversight to ensure contractors perform in accordance with the terms, conditions, and specifications of their contracts. Per the “Minimum Nutrition Program Standards” issued Commission on Services to the Aging, individuals receiving certain nutrition benefits to undergo a periodic reassessment of eligibility that includes obtaining confirmation of medical necessity for certain benefit levels. Condition - The County engaged a third party contractor to perform certain eligibility reassessments, including obtaining verification of medical necessity, when required. While the County had a process in place to properly identify when reassessment was required and to follow up with the contractor about the status of reassessments, controls did not ensure the third party contractor followed through on reassessments on a timely basis. Questioned Costs - None If questioned costs are not determinable, description of why known questioned costs were undetermined or otherwise could not be reported - N/A Identification of How Questioned Costs Were Computed - N/A Context - The County is responsible for ensuring participants who receive meals are eligible under the terms of the grant. The County did not have a control over home delivered meal participants that ensured the third party contractor timely reassessed participants every six months. 3 of the 43 samples selected did not have updated assessment forms within six months of receiving meals and 17 of the 43 samples did not have updated assessment forms. Cause and Effect - The County's controls were not adequate to ensure that the third party contractor was reassessing participants every six months. The lack of controls could result in the County providing meals to ineligible participants. Recommendation - We recommend the County update its policy on the reassessment process, including actions to be taken when participants refuse to complete the reassessment or cannot be contacted. This plan should also include a schedule for actions to be taken when participants do not complete reassessment submissions timely. The County should also implement the appropriate controls to monitor the third-party contractor and ensure reassessments are being performed timely. Views of Responsible Officials and Corrective Action Plan - The Department of Senior Services would like to clarify that the third-party contractor is contracted through The Senior Alliance, the Area Agency on Aging for region 1 C and not Wayne County. Wayne County Senior Services will continue to monitor the third-party vendor for timely assessments and reassessments through the existing controls which include: • Providing the third-party contractor monthly lists of clients in need of assessment/reassessment • Generating monthly lists of outstanding reassessments (clients not reassessed from the monthly list) • Reminding clients of the requirement for six-month reassessments • Obtaining updated information (phone numbers, emergency contacts, etc.) twice per year • Providing updated information to third-party contractor • Documentation of communicated information regarding third-party contractor’s performance to The Senior Alliance
Assistance Listing, Federal Agency, and Program Name - 93.045/93.053, Department of Health and Human Services, Aging Cluster Federal Award Identification Number and Year - N/A Pass through Entity - Area Aging on Aging 1C Finding Type - Material weakness Repeat Finding - No Criteria - Uniform Guidance at 2 CFR 200.510(b) requires the auditee to prepare a Schedule of Expenditures of Federal Awards (SEFA) that accurately reports total federal expenditures for each federal program. In addition, effective internal control over compliance, as required by 2 CFR 200.303, requires controls that ensure expenditures reported on the SEFA are complete, accurate, and properly reconciled to underlying accounting records and amounts billed to the funding agency. Condition - The County did not maintain effective internal control over the reconciliation of expenditures reported on the Schedule of Expenditures of Federal Awards to amounts billed to the funding agency. If questioned costs are not determinable, description of why known questioned costs were undetermined or otherwise could not be reported - None Identification of How Questioned Costs Were Computed - N/A Context - The SEFA is a key component of the Single Audit and serves as the primary basis for determining major programs subject to audit under the Uniform Guidance. As part of the SEFA preparation process, management compiles federal expenditures from multiple sources, including underlying accounting records and amounts billed to funding agencies. Accurate reconciliation of these sources is critical to ensure that federal expenditures are reported completely and accurately, and that major program determinations are appropriately made. As a result of the audit, it was identified that expenditures related to the Aging Cluster were understated by approximately $126,000 on the preliminary SEFA due to the omission of expenditures that had been billed to the funding agency but backed out of amounts reported on the SEFA during the reconciliation process. Management recorded an adjustment to correct the understatement prior to issuance of the final SEFA. Cause and Effect - The County’s SEFA preparation process did not include a sufficiently designed and implemented control to ensure the accuracy of reconciling items between expenditures reported on the SEFA to amounts billed to the funding agency. As a result of this deficiency, expenditures in the Aging Cluster were understated by approximately $126,000 on the preliminary SEFA. The correction of this error on the final SEFA increased total expenditures for the Aging Cluster, resulting in the program being classified as a Type A program rather than a Type B program for major program determination purposes. Because the deficiency resulted in a material misstatement of the SEFA that was not prevented or detected by internal control, it is considered a material weakness in internal control over compliance. Recommendation - We recommend that management design and implement effective controls over the preparation of the SEFA, including maintaining adequate support for adjustments and reconciling items. Such controls should be performed and reviewed by personnel independent of the SEFA preparation process to ensure the completeness and accuracy of federal expenditures reported. Views of Responsible Officials and Planned Corrective Actions - The County has established procedures for reconciling general ledger activity to supporting documentation and Federal Financial Reports (FFRs/FSRs) throughout the fiscal year, including additional reconciliation procedures performed at year end to capture late or adjusting entries. The condition was further impacted by timing differences between departmental reporting and subsequent adjusting entries, as well as the aggregation of adjustments across multiple programs without sufficient program-level detail at the time of review. While follow-up was initiated to obtain supporting breakdowns, the process did not require resolution of these items prior to final classification and inclusion in year-end reporting. The County is strengthening internal controls over grant-related financial activity and SEFA preparation by enhancing and enforcing requirements for accurate transaction recording, supporting documentation, and independent validation. Key improvements include: • Enhanced documentation and classification requirements for grant-related entries • Strengthened review and validation controls to ensure proper support and classification • Improved reconciliation and adjustment protocols, including postreporting revalidation • Control enforcement and escalation for unsupported or unresolved items • Training and guidance on federal compliance requirements
2025-001 – Allowable Cost Federal Agency: Department of Homeland Security Federal Program Name: Disaster Grants - Public Assistance (Presidentially Declared Disasters) Assistance Listing Number: 97.036 Pass-Through Agency: Florida Division of Emergency Management Pass-Through Numbers: Z2891 and Z4745 Award Period: September 23, 2022 to March 29, 2024 and October 5, 2024 to April 11, 2025 Type of Finding: Material Weakness in Internal Control over Compliance Other Matters Criteria or specific requirement: Per 2 CFR §200.303(a), the County must establish and maintain effective internal controls over federal awards that provide reasonable assurance of compliance with federal statutes, regulations, and award terms. Internal controls should ensure that employees' hours worked and documented on Activity Logs are accurately reflected in the amounts submitted to the grantor for reimbursement. Condition: During our testing, we noted that employees' hours reported on the Activity Logs did not reconcile to the corresponding amounts requested for reimbursement, resulting in discrepancies between the supporting documentation and the reimbursement requests submitted. Questioned costs: $7,568 of known questioned costs. There are also unknown questioned costs because the extent of the discrepancies between the employees' hours reported on the Activity Logs and the amounts requested for reimbursement could not be determined without further details of the activity performed during fiscal years 2022 and 2025. Context: During our testing of 40 employees, we noted 24 instances (60%) where employees' hours reported on the Activity Logs did not reconcile to the corresponding amounts requested for reimbursement. Cause: The County had not established adequate review and reconciliation procedures to ensure that employees' hours reported on Activity Logs were accurately reflected on reimbursement requests. Effect: Without adequate review and reconciliation procedures, there is an increased risk that inaccurate reimbursement amounts could be submitted to the grantor, potentially resulting in questioned costs, noncompliance with award terms, or the requirement to return federal funds. Repeat Finding: No. Recommendation: We recommend the County implement a formal review and reconciliation process to ensure that employees' hours reported on Activity Logs are verified against the reimbursement request prior to submitting it to the grantor. This review should be performed by personnel knowledgeable of the grant requirements and documented to evidence the review was completed. Views of responsible officials: There is no disagreement with the finding.
2025-002 – Reporting Federal Agency: Department of Homeland Security Federal Program Name: Disaster Grants - Public Assistance (Presidentially Declared Disasters) Assistance Listing Number: 97.036 Pass-Through Agency: Florida Division of Emergency Management Pass-Through Numbers: Z2891, Z0581, Z4745, Z4858 Award Period: September 23, 2022 to March 29, 2024; September 4, 2017 to March 10, 2019; October 5, 2024 to April 11, 2026; and October 5, 2024 to April 11, 2025 Type of Finding: Material Weakness in Internal Control over Compliance Criteria or specific requirement: Per 2 CFR §200.303(a), the County must establish and maintain effective internal controls over federal awards that provide reasonable assurance of compliance with federal statutes, regulations, and award terms. Internal controls should include procedures to ensure that required reports are accurate, complete, and subject to appropriate supervisory review prior to submission. Condition: During our testing, we reviewed 5 quarterly reports submitted to the grantor and noted that noted that none contained evidence of supervisory review or approval to ensure the accuracy and completeness of the reported information prior to submission. Questioned costs: None Context: 5 of the 12 quarterly reports were reviewed as part of the audit. No documentation of review or approval was identified for any of the reports tested. Cause: The County had not established or implemented formal review and approval procedures over the preparation and submission of grant reporting. Effect: The absence of documented review and approval controls increases the risk that errors or omissions in required reports may not be detected and corrected prior to submission, resulting in inaccurate information being provided to grantors. This could impact funding decisions, compliance with grant requirements, or future reimbursements. Repeat Finding: No. Recommendation: We recommend the County establish and implement formal procedures requiring supervisory review and approval of all reports submitted to grantors. Evidence of review should be documented and retained, including the reviewer’s signature or electronic approval, the date of review, and the date of submission, to support compliance with reporting requirements. Views of responsible officials: There is no disagreement with the finding.
Finding No.: 2025-001 Federal Agency: Environmental Protection Agency AL No. and Title: 66.039 Diesel Emission Reduction Act (DERA) National Grants 98T80301 Federal Award No.: Area: Procurement and Suspension and Debarment Criteria: 2 CFR 180.300 requires entities entering into a covered transaction with another person at the next lower tier to verify that the person with whom they intend to do business is not excluded or disqualified. Such verification can be made by (a) checking SAM.gov Exclusions, or (b) collecting a certification from that person; or (c) adding a clause or condition to the covered transaction with that person. 2 CFR 180.220 (b) (1) states that a contract for goods and services is a covered transaction if the contract is awarded by a participant in a nonprocurement transaction covered under §180.210, and the contract amount is expected to equal or exceed $25,000. 2 CFR 200.303 requires that a non-federal entity must “(a) establish, document, and maintain effective internal control over the federal award that provides reasonable assurance that the recipient or subrecipient is managing the federal award in compliance with Federal statutes, regulations, and the terms and conditions of the federal award. These internal controls should align with the guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control-Integrated Framework” issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO).” Condition: For one covered transaction during fiscal year 2025, the Authority represented that it performed verification of suspension or debarment from SAM.gov Exclusions, however, no formal documentation is kept on file to demonstrate compliance at the time of procurement. Cause: The Authority does not have formal policy requiring documentation of procedures performed to verify that the person in a covered transaction with whom they intend to do business is not excluded or disqualified. Effect or potential effect: The Authority lacked the formal documentation of procedures performed to demonstrate compliance to 2 CFR 180.300. Finding No.: 2025-001, continued Federal Agency: Environmental Protection Agency AL No. and Title: 66.039 Diesel Emission Reduction Act (DERA) National Grants 98T80301 Federal Award No.: Area: Procurement and Suspension and Debarment Questioned costs: None Context: There was only one covered transaction. The audit team verified that vendor is not excluded or disqualified. Recommendation: The Authority should formalize its policies and procedures in documenting procedures performed in verifying that the person in a covered transaction with whom they intend to do business is not excluded or disqualified. Views of responsible officials: The Authority agrees to the finding. Refer to the corrective action plan.
Finding: 2025-002 – Cash Management – Significant Deficiency in Controls over Compliance and immaterial instance of non-compliance Department: United States Department of Health and Human Services Program Name: Assistance for Torture Victims Federal Assistance Listing Number: 93.604 Criteria: 2 CFR 200.303: The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework” issued by COSO. 2 CFR 200.305 mandates that federal payments, including reimbursement, must minimize the time elapsing between fund transfer and disbursement. Condition/Context: During our walkthroughs of the cash draw process, the Organization indicated that evidence supporting preparation of the draw and review of the draw is not retained in its books and records. Additionally, the Organization drew funds in excess of their immediate cash needs, totaling approximately $350,000. Cause: Management did not have a documented policy and set of documented procedures in place to ensure consistent application of an independent review and memorializing that review. Effect: Draws in excess of amounts incurred may not be spent within three days. Further, any amounts claimed that are not allowable grant expenditures may be disallowed by the granting agency. Questioned Costs: None Repeat finding: This is a repeat finding – see prior year 2024-002. Recommendation: We recommend that the Organization establish a written policy and procedures for cash management that should be reviewed and approved by those charged with governance. The policy should require that all draws be reviewed by someone independent of the individual calculating the draw. The review should be documented in the Organization’s books and records. Views of responsible officials and planned corrective actions: Management agrees with the recommendation and has established a written policy and implemented a documented process for the preparation and review of federal drawdowns, including clear evidence of review such as signoffs or electronic approvals.
Finding 2025-002: Significant Deficiency in Internal Control Over Financial Statements – Inadequate Review of Expenditures Federal Programs 15.904 and 14.251 U.S Department of the Interior and U.S. Department of Housing and Urban Development Criteria: Under 2 CFR 200.303 and 2 CFR 200.508, the Organization must maintain effective internal control over compliance with federal award requirements, including documented evidence that disbursements are properly authorized, supported, and made in accordance with applicable grant agreements and organizational policies. Condition: During disbursement testing for the above federal programs, approvals were often evidenced only by the President’s signature on checks. Approval was not consistently documented on underlying invoices or in the accounting system, and practices for documenting preapproval of grant-related expenditures were not uniform. Cause: The Organization has not fully implemented a formal, documented expense approval process that requires and evidences review and authorization at the invoice or transaction level. Effect: Inconsistent documentation of approvals increases the risk that federal program disbursements may be processed without appropriate review, may not comply with grant requirements or organizational policies, or may be recorded in the wrong period or account. This represents a significant deficiency in internal control over compliance, although no unallowable or improper costs were identified in our testing. Questioned Costs: None. Recommendation: Implement a formal expense approval policy for federal program expenditures that requires documented approval at the invoice or transaction level (for example, signatures/initials on invoices or documented electronic approvals in QuickBooks Online). Establish an approval matrix with defined thresholds and authorized approvers to reduce reliance on the President and promote consistent application across programs. Views of responsible officials: See attached corrective action plan.
FINDING 2025‐001—ALLOWABLE COSTS/COST PRINCIPLES AND ACTIVITIES ALLOWED AND UNALLOWED AND SPECIAL TEST – DRAWDOWNS OF HOME/HOME ARP FUNDS—MATERIAL WEAKNESS IN INTERNAL CONTROLS OVER COMPLIANCE FEDERAL PROGRAM: Home Investment Partnerships Program (HOME) ASSISTANCE LISTING NUMBER: 14.239 YEAR(S): 2025 FEDERAL AGENCY: Department Of Housing and Urban Development (HUD) PASS‐THROUGH AGENCIES: Idaho Housing and Finance Association Criteria - In accordance with 2 CFR 200.303 the recipient and subrecipient must establish, document, and maintain effective internal control over the Federal award that provides reasonable assurance that the recipient or subrecipient is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. Condition/Context - On a periodic basis management submits draw-down requests to the pass-through agency. Management could not provide documentation to evidence that a review was performed over 100% of the draw-down requests prior to their submission. Further, during the testing of the underlying expenses, which are the primary inputs into the above-mentioned drawdown requests, management was able to evidence their review of payroll expenses via approved time sheets. However, non-payroll expenses and their associated indirect cost allocation calculations did not have evidence of management’s review for allowability. Cause - Management did not design and implement a control that required documented evidence of review and approval of the drawdown request. The control also did not ensure that the evidence of review of the underlying non-payroll expenses and indirect cost allocation calculations were retained. Effect - Management may not be able to detect and prevent unallowable expenses from being submitted to the passthrough agency for reimbursement, which could result in unallowed expenses being charged to the grant. Questioned Cost - Not Applicable Recommendation - Management should design and implement a control that ensures sufficient evidence of approval is obtained and retained, including underlying indirect cost allocation calculations and non-payroll costs. View of Responsible Officials - See Corrective Action Plan.
GRANT REPORTING U.S. Department of Homeland Security ALN 97.036 – Disaster Grants – Public Assistance Contract No. PA-B3-06-74-01-312 and PA-DR-06-74-01-166 Passed through the Florida Division of Emergency Management 2025 Funding Criteria: 2 CFR 200.303 requires non-federal entities to establish and maintain effective internal controls. Reports and reimbursement requests should be subject to independent review for the full fiscal year to verify completeness, validity and timeliness of submission. The grant agreement requires quarterly progress reports to be filed with the pass-through entity, Florida Division of Emergency Management. Condition: Review of quarterly reports and reimbursement requests were not documented by the City before submittal. Cause of condition: The department at the City that is responsible for managing the grant does not have a process in place to document their review of quarterly reports and reimbursement requests submitted to the Florida Division of Emergency Management. Potential effect of condition: Reports submitted to the Florida Division of Emergency Management may be incomplete, include errors, or be submitted late. Perspective: The department of the City that manages the grant did not have a documented process in place for the review and approval of quarterly reports and reimbursement requests prior to submittal to the grantor. Questioned costs: None noted. Reported finding is a deficiency in internal control. Recommendation: The City should develop procedures to ensure documented management review of all reporting prior to submission to grantors. Management’s Response: The City updated its control process to ensure that reports prepared are reviewed by City staff or management prior to being submitted to grantor.
Finding 2025-001: Finding Type: Noncompliance and significant deficiency in internal control Federal Department: U.S. Department of Health and Human Services Identification of the Federal Program: Assistance Listing Number 93.297 – Teenage Pregnancy Prevention Program, United States Department of Health and Human Services (HHS) Award Number: 5 TP1AH000315-02-00 Compliance Requirements: Matching, Level of Effort, and Earmarking and Reporting Criteria Per 2 CFR 200.303 (Internal Controls), non-federal entities must establish and maintain effective internal control over federal awards that provides reasonable assurance of compliance with federal statutes, regulations, and terms and conditions of the award. Effective internal controls should ensure these requirements are consistently met. Per 2 CFR 200.306 (Cost Sharing), cost-sharing contributions, including third-party in-kind contributions, must be properly documented and allowable. Per 2 CFR 200.328 (Financial Reporting), financial reports must be accurate and complete. The SF-425 Federal Financial Report (FFR) instructions require recipients to report recipient share of expenditures (including cost matching or cost sharing). The Notice of Funding Opportunity #AH-TP1-23-001 for Advancing Equity in Adolescent Health through Evidence-Based Teen Pregnancy Prevention Programs and Services issued by HHS states at section D.3.b.1.s: “For awards that do not require matching or cost sharing by statute or regulation, where ‘cost sharing’ refers to costs of a project in addition to Federal funds requested that you voluntarily propose in your budget, if your application is successful, we will include this non-federal cost sharing in the approved budget and you will be held accountable for the non-federal cost-sharing funds as shown in the Notice of Award (NOA). Failure to meet a cost sharing or matching obligation that is part of the approved project budget on the NOA may result in the disallowance of federal funds. If you are funded, you will be required to report cost sharing or matching funds on your quarterly Federal Financial Reports.” Condition The Fund did not formally track or record the in-kind contribution required for federal award #5 TP1AH000314-02-00 for budget period July 1, 2024 through June 30, 2025. The Fund did not report the recipient share of expenditures on the quarterly SF-425 Federal Financial Reports (FFR) during fiscal year 2025. Through review of supporting documentation compiled subsequent to fiscal year 2025, the auditor verified that the Fund received third-party in-kind contributions via donated services performed during the budget period of July 1, 2024 through June 30, 2025 of $1,119,156, which is $22,521 less than the required cost share per the NOA. However, the Fund submitted a grant amendment to HHS on February 28, 2025 via the Grant Solutions system to reduce the Project Director's effort from 100% to 25% (because she was reassigned to another federal program), which would have reduced the required cost share amount to $1,039,482. Had the Fund's grant amendment request been approved, the Fund would have met and exceeded the required in-kind cost share. The Fund has made numerous attempts to contact HHS to obtain resolution regarding the outstanding grant amendment approval request, to no avail. As of May 29, 2026, the grant amendment has yet to be approved by HHS, and it appears as "in progress" in the Grant Solutions system. Therefore, the auditor was unable to determine whether the in-kind cost share was fully met. Cause When applying for the New York City Teens Connection Expansion project funds for budget period July 1, 2024 through June 30, 2025, the Fund included a voluntary non-federal cost share amount of $1,141,677 in their proposed budget. Upon receiving the federal award, HHS included the $1,141,677 cost share on the NOA as a requirement of the federal award. The Fund was aware of the required cost share, but did not formally track or report the donated services provided toward the cost share requirement during fiscal year 2025 because they thought that voluntary cost share amounts are not required to be formally tracked or reported on the FFR. Effect The Fund’s internal controls did not ensure that #93.297 in-kind contributions were formally documented and reported in accordance with Uniform Guidance requirements during fiscal year 2025. Recipient share of expenditures on the quarterly FFRs was underreported and the federal awarding agency may not have been able to verify the Fund’s compliance with matching requirements. Questioned Costs None. Recommendation We recommend that the Fund implement internal control procedures whereby someone reviews NOAs for any specified cost sharing or matching amounts, including those which are voluntary, and ensure that compliance with such requirements are formally tracked and reported over the life of the award. View of Responsible Officials Management agrees with the recommendation. The Organization’s corrective action plan is on page 45.
2025-006 – Internal Control over Compliance and Compliance with Activities Allowed or Unallowed and Allowable Costs/Cost Principles Requirement (Significant Deficiency) Information on the Major Federal Program - Federal Agency: United States Agency for International Development (USAID) Program Name: USAID Foreign Assistance for Program Overseas Assistance Listing Number: 98.001 Award Number: 72052122CA00007 Award Period: June 13, 2022 – February 26, 2025 Criteria – The Uniform Guidance in 2 CFR Section 200.303 requires that non-Federal entities receiving Federal awards (i.e., auditee management) establish and maintain internal control designed to reasonably ensure compliance with Federal statues, regulations, and the terms and conditions of the Federal award. Per 2 CFR Section 200.403, “Except where otherwise authorized by statute, costs must meet the following general criteria in order to be allowable under Federal awards: (a) Be necessary and reasonable for the performance of the Federal award and be allocable thereto under these principles. (b) Conform to any limitations or exclusions set forth in these principles or in the Federal award as to types or amount of cost items. (c) Be consistent with policies and procedures that apply uniformly to both federally-financed and other activities of the non-Federal entity. (d) Be accorded consistent treatment. A cost may not be assigned to a Federal award as a direct cost if any other cost incurred for the same purpose in like circumstances has been allocated to the Federal award as an indirect cost. (e) Be determined in accordance with generally accepted accounting principles (GAAP), except, for state and local governments and Indian tribes only, as otherwise provided for in this part. (f) Not be included as a cost or used to meet cost sharing or matching requirements of any other federally-financed program in either the current or a prior period. (g) Be adequately documented.” Condition – During our testing of expenses charged to the federal program, we identified three (3) out of 43 sampled transactions where full supporting documentation, including evidence of transaction approval, were not available for our review. Based on discussions with management, the source documentation was shipped from the Haiti program location and was lost in transit. As a result, complete records to support the three expenses and evidence of approval of expenses were not readily available. Cause – This appears to have resulted from insufficient controls over the transfer, retention, and tracking of project documentation during closeout, particularly for records originating from Haiti, where significant security and logistical challenges increase the risk associated with transporting original hard-copy files. Effect - Without adequate internal controls in place to ensure costs are properly reviewed for allowability and documentation, Corus could be noncompliant with the allowability requirement and could request funds for costs that are unallowed. Questioned Costs – Below reportable threshold. Context – This is a condition identified per review of Corus’ compliance with the specified requirements. Repeat Finding - This is not a repeat finding. Recommendation – We recommend that management strengthen controls over the transfer, retention, and accessibility of project documentation during closeout, particularly for records originating from Haiti, which is currently operating in a distressed location with significant security and logistical challenges. Given the heightened risk of loss, delay, or inaccessibility of hard-copy records in a war zone–like environment, management should implement procedures to scan and retain electronic copies of all critical financial, contractual, and approval documentation, including signed journal vouchers, before shipment; maintain a detailed shipping manifest of all files transferred; and track shipments through receipt and inventory confirmation at headquarters. These steps would help mitigate the elevated risk associated with transporting original records from a high-risk environment and support timely access to documentation for accounting, audit, and compliance purposes. Views of Responsible Officials - Corus management agrees with the findings and recommendations. The planned corrective actions are presented in Corus management’s corrective action plan attached as Appendix B to the Single Audit Report.
FINDING 2025-056 WIOA Cluster, ALN 17.258, 17.259, and 17.278 See Schedule of Findings and Questioned Costs for chart/table. Criteria or specific requirement: Compliance: Per the Federal Funding Accountability and Transparency Act (FFATA), prime (direct) recipients of grants or cooperative agreements are required to report first-tier subawards of $30,000 or more to the Federal Funding Accountability and Transparency Act Subaward Reporting System (FSRS). Reports must be filed in FSRS by the end of the month following the month in which the prime recipient awards any sub-grant greater than or equal to $30,000. If the initial award is below $30,000 but subsequent grant modifications result in a total award equal to or over $30,000, the award will be subject to the reporting requirements as of the date the award exceeds $30,000. If the initial award equals or exceeds $30,000 but funding is subsequently de-obligated such that the total award amount falls below $30,000, the award continues to be subject to FFATA reporting requirements. On March 8, 2025, FSRS.gov was retired, and all subaward reporting data and functionality transitioned to SAM.gov after that date. The following key data elements must be reported: Subawardee Name and Data Universal Numbering System (DUNS) number; Amount of Subaward (inclusive of modifications); Subaward Obligation/Action Date; Date of Report Submission; Subaward Number; Project Description; and Names and Compensation of Highly Compensated Officers. (Names and Compensation of Highly Compensated Officers must only be reported when the entity in the preceding fiscal year received 80 percent or more of its annual gross revenues in Federal awards; and $25,000,000 or more in annual gross revenues from Federal awards; and the public does not have access to this information about the compensation of the senior executives of the entity through periodic reports filed under section 13(a) or 15(d) of the Securities Exchange Act of 1934 (15 U.S.C. §§ 78m(a), 78o(d)) or section 6104 of the Internal Revenue Code of 1986.) Control: Per 2 CFR section 200.303(a), a non-Federal entity must: Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should comply with guidance in "Standards for Internal Control in the Federal Government" issued by the Comptroller General of the United States or the "Internal Control Integrated Framework", issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition: The Department of Labor and Economic Opportunity (LEO) did not report subaward information to SAM.gov timely or accurately. Context: Eight subawards were selected for testing and the following exceptions were noted: • 2 of 8 subawards were not reported timely. The subawards were issued in March 2025 and should have been reported by April 30, 2025, but were not reported until May 13, 2025, or thirteen days late. • 2 of 8 subawards were not reported accurately: o The total of subaward 58128 25-19 was $192,109 but $194,030 was reported which is a variance of $1,921. o The total of subaward 58140 25-19 was $152,340 but $153,863 was reported which is a variance of $1,523. See Schedule of Findings and Questioned Costs for chart/table. Cause: LEO's procedures and controls were not operating effectively to ensure that subawards were reported timely and accurately. Program financial staff indicated to auditors that the late reports were due to conflicting quarter-end priorities and that the inaccurate reports were due to rounding errors. Effect: Subawards were not reported timely or accurately to SAM.gov. Questioned costs: None noted. Recommendation: We recommend that LEO review and enhance procedures and internal controls to ensure that all required subawards are reported timely to SAM.gov by the end of the month following the month in which each subaward is issued. Controls should be designed to operate effectively throughout the year, including during peak workload periods and competing deadlines. We further recommend that LEO should have sufficient controls in place to verify the accuracy of FFATA reporting before submission, including controls to detect and correct rounding variances and other reporting errors. Views of Responsible Officials: Management Views LEO agrees with the finding.
FINDING 2025-057 Airport Improvement Program, Infrastructure Investment and Jobs Act Programs, and COVID-19 Airports Programs, ALN 20.106 See Schedule of Findings and Questioned Costs for chart/table. Criteria or specific requirement: Compliance: 2 CFR 200.313 prescribes the requirements for non-federal entities regarding equipment and real property management. Requirements include the following: Property records must be maintained that include a description of the property, a serial number or other identification number, the source of funding for the property (including the federal award identification number), who holds title, the acquisition date, cost of the property, percentage of federal participation in the project costs for the federal award under which the property was acquired, the location, use and condition of the property, and any ultimate disposition data including the date of disposal and sales price of the property. A physical inventory of the property must be taken and the results reconciled with the property records at least once every two years. Control: Per 2 CFR section 200.303(a), a non-Federal entity must: Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should comply with guidance in "Standards for Internal Control in the Federal Government" issued by the Comptroller General of the United States or the "Internal Control Integrated Framework", issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition: The Michigan Department of Transportation (MDOT) did not manage equipment nor maintain property records in accordance with federal requirements. MDOT does not have sufficient policies and controls to adequately oversee equipment and real property purchased with program funds. Context: MDOT awards Airport Improvement Program Funding in accordance with provisions outlined in a Memorandum of Understanding with the Federal Aviation Administration to recipient airports across the State. MDOT is not the end recipient of the program funds, however, MDOT makes direct payments to vendors on behalf of Block Grant Program recipient airports in accordance with FAA policies and procedures. MDOT determined that the agreements it has with the non-primary airports are contractual relationships and not subrecipient. Therefore, despite programmatic requirements being part of the agreement, federal program requirements have not been passed on to the public airports and MDOT is responsible for adherence to applicable federal program requirements specified in the federal award. Auditors selected eight of the forty-three airports for testing and noted the following: • MDOT contracts contain requirements for the airports to manage equipment or maintain property records in accordance with federal requirements, however, MDOT did not require airports to report two-year equipment inventories or real property in a manner that allowed for verification that equipment and real property was acquired and managed by the airports in accordance with federal requirements in a timely manner. • 4 of 8 airports selected for testing did not provide equipment listings. MDOT was unable to provide auditors with a complete list of equipment and real property purchased with program funds to confirm the airports that did not submit information did not have any property or equipment purchases to report. • Two-year physical inventory verifications were not performed nor reconciled. Cause: MDOT informed us that due to variances between the Uniform Guidance and program guidance, MDOT exercised operational discretion and good faith and also sustained program continuity by following and executing program guidance. Effect: MDOT lacks assurance that equipment and real property purchased with federal funds is properly recorded, safeguarded, and used in accordance with program requirements. The absence of complete property records and required physical inventories increases the risk of loss, misuse, or unauthorized disposition of federally funded assets, and that noncompliance could occur and remain undetected. This condition may subject the program to federal actions such as increased oversight, withholding of funds, or other enforcement actions. Questioned costs: None. Recommendation: We recommend that MDOT strengthen its internal controls over equipment and real property in accordance with federal requirements. Specifically, MDOT should develop and implement policies and procedures to ensure that equipment and real property purchased with federal funds is properly tracked, recorded, and safeguarded. If MDOT determines that these requirements should be handled through a subrecipient agreement with the airports, MDOT should update policies and procedures, contracts, and controls regarding subrecipient relationships to ensure the federal requirements are passed through to the subrecipient in accordance with the federal requirements, and update reporting within the schedule of expenditures of federal awards to report subrecipient payments accordingly. Views of Responsible Officials: Management Views MDOT agrees with the finding.
FINDING 2025-058 Airport Improvement Program, Infrastructure Investment and Jobs Act Programs, and COVID-19 Airports Programs, ALN 20.106 See Schedule of Findings and Questioned Costs for chart/table. Criteria or specific requirement: Compliance: All laborers and mechanics employed by contractors or subcontractors to work on construction contracts in excess of $2,000 financed by federal assistance funds must be paid wages not less than those established for the locality of the project (prevailing wage rates) by the Department of Labor (DOL) (40 USC 3141–3147). Nonfederal entities shall include in their construction contracts subject to the Wage Rate Requirements (which still may be referenced as the Davis-Bacon Act) a provision that the contractor or subcontractor comply with those requirements and the DOL regulations (29 CFR Part 5, Labor Standards Provisions Applicable to Contracts Governing Federally Financed and Assisted Construction). This includes a requirement for the contractor or subcontractor to submit to the nonfederal entity weekly, for each week in which any contract work is performed, a copy of the payroll and a statement of compliance (certified payrolls) (29 CFR sections 5.5 and 5.6; the A-102 Common Rule (section 36(i)(5)); OMB Circular A-110 (2 CFR Part 215, Appendix A, Contract Provisions); 2 CFR Part 176, Subpart C; and 2 CFR section 200.326). Control: Per 2 CFR section 200.303(a), a non-Federal entity must: Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should comply with guidance in "Standards for Internal Control in the Federal Government" issued by the Comptroller General of the United States or the "Internal Control Integrated Framework", issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition: The Michigan Department of Transportation (MDOT) did not ensure that contractors complied with Davis-Bacon wage rate requirements. It did not properly obtain weekly certified payrolls from contractors to monitor compliance. Context: MDOT determined that the agreements it has with the non-primary airports are contractual relationships and not subrecipient. Therefore, federal program requirements have not been passed on to the public airports and MDOT is responsible for adherence to applicable federal program requirements specified in the federal award. Auditors selected eight of the forty-three airports for testing Davis-Bacon wage rate requirements and noted the following exceptions: • 5 of the 8 contractors did not have certified payrolls, therefore, MDOT did not review payroll data during the fiscal year to ensure contractors complied with wage rate requirements in a timely manner. • For 2 of 8 contracts, MDOT included Davis-Bacon wage rate requirements in the bid documentation, but not in the executed contracts as required by program requirements. Cause: MDOT does not have sufficient procedures or internal controls to ensure that it monitors contractors' compliance with Davis-Bacon wage rate requirements. Effect: MDOT's failure to include Davis-Bacon wage rate requirements in its contracts and to obtain current year certified payrolls from contractors reduces its ability to monitor compliance with program requirements. As a result, there is an increased risk that contractors were not paid in accordance with required prevailing wage rates, which could result in noncompliance with federal requirements and potential questioned costs. Additionally, continued noncompliance may subject the program to sanctions such as withholding of funds, increased oversight, or other federal enforcement actions. Questioned costs: None. Recommendation: We recommend that MDOT strengthen its internal controls over compliance with Davis-Bacon wage rate requirements. Specifically, MDOT should ensure that contractors are appropriately informed of applicable wage rate requirements by incorporating these provisions into contracts and related documents. In addition, MDOT should develop and implement procedures to ensure that weekly certified payrolls are submitted by contractors and are reviewed in a timely manner to verify compliance. MDOT should also establish follow-up procedures to address instances of noncompliance and ensure timely resolution. If MDOT determines that these requirements should be handled through a subrecipient agreement with the airports, MDOT should update policies and procedures, contracts, and controls regarding subrecipient relationships to ensure the federal requirements are passed through to the subrecipient in accordance with the federal requirements, and update reporting within the schedule of expenditures of federal awards to report subrecipient payments accordingly. Views of Responsible Officials: Management Views MDOT agrees with the finding.
FINDING 2025-059 Airport Improvement Program, Infrastructure Investment and Jobs Act Programs, and COVID-19 Airports Programs, ALN 20.106 See Schedule of Findings and Questioned Costs for chart/table. Criteria or specific requirement: Compliance: All revenues generated by a public airport must be expended for the capital or operating costs of the airport, the local airport system, or other local facilities that are owned or operated by the owner or operator of the airport and are directly and substantially related to the actual air transportation of passengers or property. Control: Per 2 CFR section 200.303(a), a non-Federal entity must: Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should comply with guidance in "Standards for Internal Control in the Federal Government" issued by the Comptroller General of the United States or the "Internal Control Integrated Framework", issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition: The Michigan Department of Transportation (MDOT) did not ensure that revenues generated by non-commercial airports were expended for the capital or operating costs of the airport, the local airport system, or other local facilities that are owned or operated by the owner or operator of the airport and are directly and substantially related to the actual air transportation of passengers or property. Context: MDOT determined that the agreements it has with the non-primary public airports are contractual relationships and not subrecipient. Therefore, federal program requirements have not been passed on to the public airports and MDOT is responsible for adherence to applicable federal program requirements specified in the federal award. Auditors selected eight of the forty-three airports for testing and for the eight airports selected, MDOT did not ensure that revenue diversion requirements were met. The contracts executed by MDOT included the program's revenue diversion requirements, but MDOT did not monitor the airports' compliance with these requirements and is unable to provide documentation that revenue diversion requirements were met. Cause: MDOT has not prioritized its monitoring and oversight efforts to help ensure that contractors comply with revenue and program income requirements to prevent revenue diversion. Effect: MDOT is unable to ensure that public airports used revenue in accordance with federal requirements. There is an increased risk of revenue diversion occurring or going undetected, potentially resulting in noncompliance with program requirements and questioned costs. Continued noncompliance may also subject the program to federal actions such as increased oversight, withholding of funds, or other enforcement actions. Questioned costs: None. Recommendation: We recommend that MDOT strengthen its internal controls over compliance with revenue diversion requirements. Specifically, MDOT should develop and implement monitoring procedures to ensure that public airports comply with contractual provisions prohibiting revenue diversion. Such procedures should include periodic reviews of financial and supporting documentation, documentation of monitoring activities performed, and timely follow-up on any identified instances of noncompliance to ensure appropriate corrective action is taken. If MDOT determines that these requirements should be handled through a subrecipient agreement with the airports, MDOT should update policies and procedures, contracts, and controls regarding subrecipient relationships to ensure the federal requirements are passed through to the subrecipient in accordance with the federal requirements, and update reporting within the schedule of expenditures of federal awards to report subrecipient payments accordingly. Views of Responsible Officials: Management Views MDOT agrees with the finding.
FINDING 2025-021 Coronavirus State and Local Fiscal Recovery Funds, ALN 21.027, Activities Allowed or Unallowed, Allowable Costs/Cost Principles, and Period of Performance - AASHTOWare Security Management and Access Controls See Schedule of Findings and Questioned Costs for chart/table. Condition MDOT did not fully establish effective security management and access controls over AASHTOWare users. MDOT program staff utilize AASHTOWare to administer construction contracts and approve payments to contractors. We noted: a. MDOT did not fully review internal users on an annual basis. b. MDOT did not disable 88 (4%) of 2,287 users who had not accessed the application within 365 days for internal user accounts and 18 months for external user accounts as of September 30, 2025. Our review disclosed: (1) For the 650 internal user accounts, 14 (2%) users had not logged into the application within 365 days, ranging from 1,399 to 4,597 days and 18 (3%) users had not logged in since access was granted. (2) For the 1,637 external user accounts, 56 (3%) users had not logged in since access was granted. Criteria Federal regulation 2 CFR 200.303 requires the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. According to State of Michigan Administrative Guide to State Government policy 1340.00, security controls must be implemented to protect State of Michigan information from unauthorized access, use, disclosure, modification, destruction, or denial and to ensure confidentiality, integrity, and availability of State of Michigan information. SOM Technical Standard 1340.00.020.01 requires accounts to be reviewed annually to validate their continued need and the information system to automatically disable inactive internal user accounts after 60 days and inactive external user accounts after 18 months. However, MDOT has a documented business need to allow user access to remain enabled until 365 days of inactivity. Cause MDOT's internal control and monitoring activities were not sufficient to ensure all appropriate parties adhered to established policies. Effect Without effective security management and access controls, individuals may maintain unauthorized or inappropriate access to AASHTOWare. Known Questioned Costs None. Recommendation We recommend MDOT fully establish effective security management and access controls over AASHTOWare users. Management Views MDOT agrees with the finding.
FINDING 2025-022 Coronavirus State and Local Fiscal Recovery Funds, ALN 21.027, Activities Allowed or Unallowed, Allowable Costs/Cost Principles, and Period of Performance - Concur Security Management and Access Controls See Schedule of Findings and Questioned Costs for chart/table. Condition The Michigan Strategic Fund (MSF), in conjunction with the Michigan Economic Development Corporation (MEDC), did not fully implement effective security management and access controls over Concur. MSF and MEDC program staff utilize Concur to approve subrecipient* reimbursement requests. We noted: a. MSF did not fully implement an effective annual recertification process of non-privileged and privileged accounts. MSF did not review active employees' user accounts to ensure users still require system access and the users' access was assigned in accordance with their job responsibilities. b. MSF did not disable 8 (11%) of 73 Concur user accounts able to approve invoices who did not access the application in over 60 days as of September 30, 2025. In 7 instances, users last logged in between 190 to 1,406 days prior and in the other instance, the user had not logged in since access was granted. Criteria Federal regulation 2 CFR 200.303 requires the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. MEDC Standard SECU.01.020.01 requires accounts to be reviewed annually to validate the necessity of all accounts and ensure data permissions assigned to each account are based on the principle of least privilege. The Standard also requires monthly reviews of accounts with no activity for 60 days and determine which inactive accounts should be disabled. Cause MSF informed us its current policy does not apply to Concur because of undocumented risk assessments. However, MSF, in conjunction with MEDC, did not document any exceptions to the policy for Concur. Effect Without effective user access controls, individuals may maintain unauthorized or inappropriate access to Concur. As a result, an increased risk exists because MSF cannot ensure the security of the Concur application and data used to issue payments to subrecipients of federal awards. Known Questioned Costs None. Recommendation We recommend MSF, in conjunction with MEDC, fully implement effective security management and access controls over Concur. Management Views MSF agrees that Concur was not written as an exception in the identified policy, but disagrees that there is a control deficiency. MSF maintains effective controls within its control environment that effectively mitigate risks associated with exempting Concur from the identified policy and provide reasonable assurance MSF is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. Auditor's Comments to Management Views MSF believes it has reasonable assurance federal awards are being managed in compliance with federal statutes, regulations, and the terms and conditions of federal awards. However, federal regulation 2 CFR 200.303 states internal control should align with the guidance in Standards for Internal Control in the Federal Government issued by the Comptroller General of the United States (Green Book) or the "Internal Control-Integrated Framework" issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Appendix I of the Green Book requires management to document the results of risk assessments including identification, analysis, and response to risks. This includes documentation of the consideration of risks related to information security, which could impact the internal control system. While MSF disagrees a control deficiency exists, it acknowledges it does not have a written exception identified in the referenced policy; it also does not have documentation of its risk assessment related to Concur security, which could impact the internal control system and the response to additional risks by exempting this information system from policy. Therefore, the finding stands as written.
FINDING 2025-023 Coronavirus State and Local Fiscal Recovery Funds, ALN 21.027, Activities Allowed or Unallowed, Allowable Costs/Cost Principles, and Period of Performance - EGrAMS Security Management and Access Controls See Schedule of Findings and Questioned Costs for chart/table. Condition The Department of Labor and Economic Opportunity (LEO) did not fully establish effective security management and access controls over EGrAMS users. LEO utilizes EGrAMS to approve subrecipient reimbursement requests. We noted: a. LEO did not maintain documentation to support the appropriate individual approved the system role for 4 of 6 sampled EGrAMS users, of which all 4 were external users. b. LEO did not establish a process to review internal user accounts on an annual basis. c. LEO did not disable 1,069 (76%) of 1,403 EGrAMS user accounts not accessing the application in over 60 days as of September 30, 2025, ranging from 62 to 838 days since last login. Criteria Federal regulation 2 CFR 200.303 requires the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. According to State of Michigan Administrative Guide to State Government policy 1340.00, security controls must be implemented to protect State of Michigan information from unauthorized access, use, disclosure, modification, destruction, or denial and to ensure confidentiality, integrity, and availability of State of Michigan information. SOM Technical Standard 1340.00.020.01 requires agencies to implement and document baseline controls, such as access authorizations. The Standard also requires accounts to be reviewed annually to validate their continued need and the information system to automatically disable inactive user accounts after 60 days. Cause LEO's internal control and monitoring activities were not sufficient to ensure all appropriate parties adhered to established policies. Effect Without effective user access controls, individuals may obtain or maintain unauthorized or inappropriate access to EGrAMS. As a result, an increased risk exists LEO cannot ensure the security of the EGrAMS application and data used to issue payments to subrecipients of federal awards. Known Questioned Costs None. Recommendation We recommend LEO fully establish effective security management and access controls over EGrAMS users. Management Views LEO agrees with the finding.
FINDING 2025-024 Coronavirus State and Local Fiscal Recovery Funds, ALN 21.027, Activities Allowed or Unallowed, Allowable Costs/Cost Principles, and Period of Performance - MiSSG Security Management and Access Controls See Schedule of Findings and Questioned Costs for chart/table. Condition MiLEAP did not fully establish effective security management and access controls over the Michigan Student Aid Scholarships and Grants (MiSSG) users. MiLEAP program staff utilize MiSSG to administer Michigan Reconnect scholarships and approve payments to community colleges on behalf of Michigan students. We noted: a. MiLEAP did not maintain documentation for 2 of 7 sampled MiSSG access request forms. b. MiLEAP did not maintain sufficient documentation of its recertification review of internal users. Criteria Federal regulation 2 CFR 200.303 requires the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. According to State of Michigan Administrative Guide to State Government policy 1340.00, security controls must be implemented to protect State of Michigan information from unauthorized access, use, disclosure, modification, destruction, or denial and to ensure confidentiality, integrity, and availability of State of Michigan information. SOM Technical Standard 1340.00.020.01 requires agencies to implement and document baseline controls, such as access authorization. The Standard also requires accounts to be reviewed annually to validate their continued need. Cause MiLEAP informed us internal control and monitoring activities were not sufficient to ensure all appropriate parties adhered to established policies and procedures. Effect Without effective security management and access controls, individuals may obtain or maintain unauthorized or inappropriate access to MiSSG. Known Questioned Costs None. Recommendation We recommend MiLEAP fully establish effective security management and access controls over MiSSG. Management Views MiLEAP agrees with the finding.
FINDING 2025-025 Coronavirus State and Local Fiscal Recovery Funds, ALN 21.027, Activities Allowed or Unallowed, Allowable Costs/Cost Principles, and Period of Performance - PTMS Security Management and Access Controls See Schedule of Findings and Questioned Costs for chart/table. Condition MDOT did not fully establish effective security management and access controls over PTMS users. MDOT program staff utilize PTMS to approve subrecipient budget and payment requests. We noted MDOT did not maintain a sufficient audit trail to document the users' roles in place during the audit period. As a result, we were unable to isolate a population of users who received access to PTMS during fiscal year ending on September 30, 2025. Criteria Federal regulation 2 CFR 200.303 requires the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. According to State of Michigan Administrative Guide to State Government policy 1340.00, security controls must be implemented to protect State of Michigan information from unauthorized access, use, disclosure, modification, destruction, or denial and to ensure confidentiality, integrity, and availability of State of Michigan information. SOM Technical Standard 1340.00.040.01 requires the information system owner to ensure the logging of user access management activities, such as additions, modifications, and deletions of user accounts. Cause MDOT informed us, because of a system limitation, historical user access data was deleted when an existing user received a new role. Effect Without effective user access controls, individuals may obtain or maintain unauthorized or inappropriate access to PTMS. As a result, an increased risk exists where MDOT cannot ensure the security of the PTMS application and data used to issue payments to subrecipients of federal awards. Known Questioned Costs None. Recommendation We recommend MDOT fully implement effective security management and access controls over PTMS users. Management Views MDOT agrees with the finding.
FINDING 2025-026 Coronavirus State and Local Fiscal Recovery Funds, ALN 21.027, Activities Allowed or Unallowed, Allowable Costs/Cost Principles, and Period of Performance - Insufficient Respite Payment Controls See Schedule of Findings and Questioned Costs for chart/table. Condition MDHHS did not have sufficient controls in place to prevent or detect and correct payment errors made to respite grant recipients. We noted MDHHS did not review and approve respite grant payments subsequent to manual input into the Medical Services Administration Manual Payment System (MSAPay). Criteria Federal regulation 2 CFR 200.303 requires the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. Also, Subpart E of federal regulation 2 CFR 200 requires costs charged to federal programs be necessary and reasonable for the administration of the federal award and be in accordance with the relative benefits received by the program. Cause MDHHS's internal control and monitoring activities were not sufficient to ensure it documented its review and approval of respite grant payments in MSAPay. Effect These deficiencies could potentially result in improper payments to recipients. The federal grantor agency could issue sanctions or disallowances related to noncompliance. Known Questioned Costs None. Recommendation We recommend MDHHS improve its controls to prevent or detect and correct payment errors made to respite grant recipients. Management Views MDHHS agrees with the finding.
FINDING 2025-027 Coronavirus State and Local Fiscal Recovery Funds, ALN 21.027, Activities Allowed or Unallowed, Allowable Costs/Cost Principles, Period of Performance, and Subrecipient Monitoring - Salesforce Security Management and Access Controls See Schedule of Findings and Questioned Costs for chart/table. Condition MSF, in conjunction with MEDC, did not fully implement effective security management and access controls over Salesforce. Program subrecipients utilize Salesforce to submit expenditure reports and reimbursement requests to MSF. Also, MEDC program staff utilize Salesforce to review and approve reimbursement requests. We noted: a. MSF did not fully implement an effective annual recertification process of non-privileged and privileged accounts. MSF did not review active employees' user accounts to ensure users still required access and the users' access was assigned privileges in accordance with their job responsibilities. b. MSF did not disable 14 (4%) of 347 Salesforce user accounts not accessing the application in over 60 days as of September 30, 2025, ranging from 117 to 2,128 days since last login. Criteria Federal regulation 2 CFR 200.303 requires the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. MEDC Standard SECU.01.020.01 requires accounts to be reviewed annually to validate the necessity of all accounts and data permissions assigned to each account are based on the principle of least privilege. The Standard also requires monthly reviews of accounts with no activity for 60 days to determine which inactive accounts should be disabled. Cause MSF informed us its current policy does not apply to Salesforce because of undocumented risk assessments. However, MSF, in conjunction with MEDC, did not document any exceptions to the policy for Salesforce. Effect Without effective user access controls, individuals may maintain unauthorized or inappropriate access to Salesforce. As a result, an increased risk exists where MSF cannot ensure the security of the Salesforce application and data used to issue payments to subrecipients of federal awards. Known Questioned Costs None. Recommendation We recommend MSF, in conjunction with MEDC, fully implement effective security management and access controls over Salesforce. Management Views MSF agrees that Salesforce was not written as an exception in the identified policy, but disagrees that there is a control deficiency. MSF maintains effective controls within its control environment that effectively mitigate risks associated with exempting Salesforce from the identified policy and provide reasonable assurance MSF is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. Auditor's Comments to Management Views MSF believes it has reasonable assurance federal awards are being managed in compliance with federal statutes, regulations, and the terms and conditions of federal awards. However, federal regulation 2 CFR 200.303 states internal control should align with the guidance in Standards for Internal Control in the Federal Government issued by the Comptroller General of the United States (Green Book) or the "Internal Control-Integrated Framework" issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Appendix I of the Green Book requires management to document the results of risk assessments including identification, analysis, and response to risks. This includes documentation of the consideration of risks related to information security, which could impact the internal control system. While MSF disagrees a control deficiency exists, it acknowledges it does not have a written exception identified in the referenced policy; it also does not have documentation of its risk assessment related to Salesforce security, which could impact the internal control system and the response to additional risks by exempting this information system from policy. Therefore, the finding stands as written.
FINDING 2025-029 Coronavirus State and Local Fiscal Recovery Funds, ALN 21.027, Subrecipient Monitoring - MiGrants Security Management and Access Controls See Schedule of Findings and Questioned Costs for chart/table. Condition The Department of Natural Resources (DNR) did not fully establish effective security management and access controls over MiGrants. DNR program staff utilize MiGrants to approve subrecipient reimbursement requests. We noted: a. DNR did not maintain documentation to support the appropriate individual approved the system role for 2 (8%) of 24 sampled MiGrants user accounts. Of the 22 user accounts reviewed, DNR did not ensure it properly approved 1 (5%) user account prior to granting access to MiGrants. b. DNR did not maintain documentation of its annual recertifications for 10 (91%) of 11 sampled internal MiGrants user accounts. c. DNR did not disable 219 (16%) of 1,391 MiGrants user accounts not accessing the application in over 60 days as of September 30, 2025, ranging from 61 to 363 days since last login. Criteria Federal regulation 2 CFR 200.303 requires the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. According to State of Michigan Administrative Guide to State Government policy 1340.00, security controls must be implemented to protect State of Michigan information from unauthorized access, use, disclosure, modification, destruction, or denial and to ensure confidentiality, integrity, and availability of State of Michigan information. SOM Technical Standard 1340.00.020.01 requires agencies to implement and document baseline controls, such as access authorizations. The Standard also requires accounts should be reviewed annually to validate their continued need and the information system to automatically disable inactive user accounts after 60 days. Cause DNR's internal control and monitoring activities were not sufficient to ensure all appropriate parties adhered to established policies. Effect Without effective user access controls, individuals may obtain or maintain unauthorized or inappropriate access to MiGrants. As a result, an increased risk exists where DNR cannot ensure the security of the MiGrants application and data used to issue payments to subrecipients of federal awards. Known Questioned Costs None. Recommendation We recommend DNR fully establish effective security management and access controls over MiGrants. Management Views DNR agrees with the finding.
FINDING 2025-060 Coronavirus Capital Projects Fund, ALN 21.029 See Schedule of Findings and Questioned Costs for chart/table. Criteria or specific requirement: Compliance: Per the Federal Funding Accountability and Transparency Act (FFATA), prime (direct) recipients of grants or cooperative agreements are required to report first-tier subawards of $30,000 or more to the Federal Funding Accountability and Transparency Act Subaward Reporting System (FSRS). Reports must be filed in FSRS by the end of the month following the month in which the prime recipient awards any sub-grant greater than or equal to $30,000. If the initial award is below $30,000 but subsequent grant modifications result in a total award equal to or over $30,000, the award will be subject to the reporting requirements as of the date the award exceeds $30,000. If the initial award equals or exceeds $30,000 but funding is subsequently de-obligated such that the total award amount falls below $30,000, the award continues to be subject to FFATA reporting requirements. On March 8, 2025, FSRS.gov was retired, and all subaward reporting data and functionality transitioned to SAM.gov after that date. For the Coronavirus Capital Projects Fund program, FSRS was inaccessible to recipients due to a technical configuration problem until August 2023. Due to this technical issue, Treasury issued guidance requesting that recipients complete FSRS reporting by no later than June 30, 2024. The following key data elements must be reported: Subawardee Name and Data Universal Numbering System (DUNS) number; Amount of Subaward (inclusive of modifications); Subaward Obligation/Action Date; Date of Report Submission; Subaward Number; Project Description; and Names and Compensation of Highly Compensated Officers. (Names and Compensation of Highly Compensated Officers must only be reported when the entity in the preceding fiscal year received 80 percent or more of its annual gross revenues in Federal awards; and $25,000,000 or more in annual gross revenues from Federal awards; and the public does not have access to this information about the compensation of the senior executives of the entity through periodic reports filed under section 13(a) or 15(d) of the Securities Exchange Act of 1934 (15 U.S.C. §§ 78m(a), 78o(d)) or section 6104 of the Internal Revenue Code of 1986.) Control: Per 2 CFR section 200.303(a), a non-Federal entity must: Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should comply with guidance in "Standards for Internal Control in the Federal Government" issued by the Comptroller General of the United States or the "Internal Control Integrated Framework", issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition: The Department of Labor and Economic Opportunity (LEO) did not report subaward information timely. Context: Seven of eight subawards selected for testing were not reported timely. Specifically, we noted the following: • 5 of 8 subawards, totaling $50,553,778, were issued in 2023 and early 2024 and, per Treasury's reporting guidance, should have been reported in FSRS no later than June 30, 2024. Two of the subawards were reported in March 2025 and three of the subawards were reported in September 2025, which was eight to thirteen months after Treasury's extended deadline. • 2 of 8 subawards, totaling $9,739,385, were issued on August 1, 2024, but were not reported until January and February 2025, or four to five months late. See Schedule of Findings and Questioned Costs for chart/table. Cause: LEO's procedures and controls were not operating effectively to ensure that subawards were reported timely, in accordance with FFATA reporting requirements and Treasury's reporting guidance. Effect: Subawards were not reported timely to FSRS or SAM.gov. Questioned costs: None noted. Recommendation: We recommend that LEO review and enhance its procedures and internal controls to ensure that all required subawards are reported timely and accurately to SAM.gov no later than the end of the month following the month of issuance of each subaward, or in accordance with deadlines established by Treasury. Views of Responsible Officials: Management Views The Department of Labor and Economic Opportunity (LEO) agrees with the finding.
FINDING 2025-009 MDE, Security Management and Access Controls See Schedule of Findings and Questioned Costs for chart/table. Condition The Michigan Department of Education (MDE) did not fully establish effective security management and access controls over the Grant Electronic Monitoring System/Michigan Administrative Review System (GEMS/MARS) and Next Generation Grant, Application and Cash Management System (NexSys). We noted: a. MDE did not consistently follow its established policies and procedures over the granting of access to NexSys. Our review disclosed MDE did not maintain documentation to support it approved the system role for 1 (2%) of 47 sampled NexSys users. Of the 46 forms received, we noted MDE did not properly approve 1 (2%) form prior to granting access to NexSys. Also, MDE did not ensure the access rights were consistent with the most recently approved NexSys forms for 2 (4%) of 46 sampled users. b. MDE did not document or properly review its annual recertification of internal users. Our results are summarized in the following table: See Schedule of Findings and Questioned Costs for chart/table. c. MDE did not disable 317 (5%) of 5,798 NexSys user accounts who did not access the application in over 18 months as of September 30, 2025. Criteria Federal regulation 2 CFR 200.303 requires the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. Federal regulation 45 CFR 98.68 requires MiLEAP to describe in its CCDF State Plan the internal control in place to help ensure program integrity. MiLEAP's CCDF State Plan for Federal Fiscal Years 2025-2027 describes specific procedures for program integrity and accountability, including program violations and administrative errors. Also, the CCDF State Plan provides specific requirements for child care assistance, which MiLEAP utilizes an information system for approving grant applications and authorizing payment requests for services. The State of Michigan establishes Statewide technical standards for all State information systems. According to State of Michigan Administrative Guide to State Government policy 1340.00, security controls must be implemented to protect State of Michigan information from unauthorized access, use, disclosure, modification, destruction, or denial and to ensure confidentiality, integrity, and availability of State of Michigan information. SOM Technical Standard 1340.00.020.01 requires agencies to implement and document baseline controls, such as access authorizations. The Standard also requires separation of duties must be supported through defined system access authorizations, accounts should be reviewed annually to validate their continued need, and the information system to automatically disable inactive internal user accounts after 60 days. However, MDE requested and received an approved exception, which allows user accounts to not be disabled until after 18 months. Cause MDE's internal control and monitoring activities were not sufficient to ensure all appropriate parties adhered to established policies. Effect Without effective user access controls, individuals may obtain or maintain unauthorized or inappropriate access to MDE's systems. Known Questioned Costs None. Recommendation We recommend MDE fully establish effective security management and access controls over GEMS/MARS and NexSys. Management Views MDE agrees with the finding.
FINDING 2025-010 MDE, Change Management Process See Schedule of Findings and Questioned Costs for chart/table. Condition MDE did not fully implement an effective change management process over NexSys. We sampled 11 NexSys change deployments and noted: See Schedule of Findings and Questioned Costs for chart/table. Criteria Federal regulation 2 CFR 200.303 requires the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. Federal regulation 45 CFR 98.68 requires MiLEAP to describe in its CCDF State Plan the internal control in place to help ensure program integrity. MiLEAP's CCDF State Plan for Federal Fiscal Years 2025-2027 describes specific procedures for program integrity and accountability, including program violations and administrative errors. Also, the CCDF State Plan provides specific requirements for child care assistance, which MiLEAP utilizes an information system for approving grant applications and authorizing payment requests for services. The State of Michigan establishes Statewide technical standards for all State information systems. State of Michigan Administrative Guide to State Government policy 1340.00 establishes the configuration management standard and procedures to address the controls implemented within systems and organizations. SOM Technical Standard 1340.00.060.04 requires the business owner to perform post-implementation validation. SOM Technical Procedure 1340.00.060.04.01 requires each test type to have its own set of documentation. Cause MDE informed us because of an oversight, it did not document the testing results and perform post-implementation validation. Effect Without an effective change management process, individuals may make unauthorized or inappropriate changes to NexSys. As a result, an increased risk exists where MDE cannot ensure NexSys is configured and operating securely and as intended. Known Questioned Costs None. Recommendation We recommend MDE fully implement an effective change management process over NexSys. Management Views MDE partially agrees with the finding. MDE agrees that testing results were not fully documented. However, MDE does not agree that post implementation validation could be performed. The scan-vulnerability process could not be performed in the production environment in this instance without significantly impacting system performance for users, making post implementation validation infeasible. Auditor's Comments to Management Views MDE acknowledged it did not perform post-implementation validation in the production environment because it would significantly impact system performance. Contrary to MDE's views, not conducting post-implementation testing increases the risk of potential vulnerabilities or system failure, and testing is required by SOM technical standards. Further, MDE has indicated it plans to take some corrective action by evaluating alternative methods for post-implementation validation. During this evaluation, MDE could consider implementing alternative testing strategies to minimize operational disruptions, such as conducting vulnerability scans and deployments outside normal business hours. Therefore, the finding stands as written.
FINDING 2025-006 ADP Security Program See Schedule of Findings and Questioned Costs for chart/table. Condition MDHHS and DTMB did not ensure a comprehensive ADP security program was fully implemented for information systems used to administer their federal programs. We reviewed 6 significant systems and noted MDHHS and DTMB did not complete all necessary updates to the system security plan for 3 systems during fiscal year 2025, including not updating the risk analyses which resulted in the expiration of the authority to operate and/or missing control assessments for the systems. Criteria Federal regulations 7 CFR 272.10 and 45 CFR 95.621 make state agencies responsible for security of information systems used to administer federal programs. In part, the regulations require state agencies to establish and maintain an ADP security program, including a security plan and a program for conducting periodic risk analyses. In addition, federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. Cause MDHHS and DTMB indicated resources were focused on meeting federal and State mandates while maintaining operational needs and addressing information technology (IT) security risks highlighted in prior audits. MDHHS and DTMB also indicated limited resources caused delays in the completion of a comprehensive ADP security program. Effect MDHHS and DTMB cannot demonstrate they have implemented effective controls to ensure the confidentiality, integrity, and availability of their information systems and cannot ensure they comply with applicable direct and material federal compliance requirements, such as the Medicaid Cluster special tests and provisions - ADP risk analysis and system security review requirement. Outdated or incomplete system security plans and risk analyses put the security of critical systems at risk by failing to mitigate potential vulnerabilities. The federal grantor agency could issue sanctions and/or disallowances related to noncompliance. Known Questioned Costs None. Recommendation We recommend MDHHS and DTMB ensure a comprehensive ADP security program is fully implemented for information systems used to administer federal programs. Management Views MDHHS and DTMB agree with the finding.
FINDING 2025-002 DTMB, IT General Controls See Schedule of Findings and Questioned Costs for chart/table. Background The Michigan Department of Health and Human Services (MDHHS) and the Department of Technology, Management, and Budget (DTMB) are jointly responsible for maintenance and operation of Bridges Integrated Automated Eligibility Determination System* (Bridges), Michigan Statewide Automated Child Welfare Information System (MiSACWIS), Community Health Automated Medicaid Processing System (CHAMPS), Medicaid Audit Recovery and Investigation System (MARIS), and Michigan Adult Integrated Management System (MiAIMS). The Michigan Department of Transportation (MDOT) and DTMB are jointly responsible for maintenance and operation of AASHTOWare and Public Transportation Management System (PTMS). DTMB provides support for these applications' operating system. Condition DTMB did not fully implement effective general controls* over Bridges, MiSACWIS, CHAMPS, MARIS, MiAIMS, AASHTOWare, and PTMS operating system servers. Our review of fiscal year 2025 activity disclosed DTMB did not review privileged accounts* for the operating system servers. After bringing this matter to management's attention, DTMB corrected the issue noted. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. Federal regulation 45 CFR 98.68 requires MiLEAP to describe in its CCDF State Plan the internal control in place to help ensure program integrity. MiLEAP's CCDF State Plan for Federal Fiscal Years 2025-2027 describes specific procedures for program integrity and accountability, including program violations and administrative errors. Also, the CCDF State Plan provides specific requirements for child care assistance, including the utilization of an information system for determining eligibility and benefit amounts. Title 42, section 1397a(a)(2)(A) of the United States Code (USC) indicates states are entitled to payment for services that meet the goals of the Social Services Block Grant (SSBG). Federal regulation 45 CFR 96.30 requires MDHHS to have fiscal controls and accounting procedures sufficient to permit the tracing of SSBG funds to document MDHHS did not use SSBG funds in violation of the restrictions and prohibitions of SSBG laws and regulations. MDHHS utilizes an information system for processing SSBG payments. Federal law 42 USC 8624 requires the State to expend funds in accordance with the Low-Income Home Energy Assistance Program (LIHEAP) State Plan and allows MDHHS to use LIHEAP funds to intervene in energy-related crisis situations and assist eligible households to meet the costs of home energy. MDHHS utilizes an information system for determining eligibility. The State of Michigan establishes Statewide technical standards for all State information systems. According to State of Michigan Administrative Guide to State Government policy 1340.00, security controls must be implemented to protect State of Michigan information from unauthorized access, use, disclosure, modification, destruction, or denial and to ensure confidentiality, integrity, and availability of State of Michigan information. SOM Technical Standard 1340.00.020.01, effective through May 26, 2025, requires accounts be reviewed for compliance with account management requirements semiannually for privileged accounts. DTMB revised its policy, effective May 27, 2025, to indicate access agreements be reviewed annually, including verification access is required for system accounts. Cause DTMB informed us competing priorities contributed to its inability to recertify the users' roles. Effect Without timely review and recertification, individuals may maintain unauthorized or inappropriate access or make inappropriate changes to the Bridges, MiSACWIS, CHAMPS, MARIS, MiAIMS, AASHTOWare, and PTMS operating system servers. Known Questioned Costs None. Recommendation We recommend DTMB fully implement effective general controls over Bridges, MiSACWIS, CHAMPS, MARIS, MiAIMS, AASHTOWare, and PTMS operating system servers. Management Views DTMB agrees with the finding.
FINDING 2025-003 Bridges Interface Controls See Schedule of Findings and Questioned Costs for chart/table. Background MDHHS uses Bridges for determining eligibility and benefit amounts for food assistance, cash assistance, child care assistance, medical assistance, and emergency assistance programs. MDHHS and DTMB are jointly responsible for maintenance and operation of Bridges. Condition DTMB did not always ensure its interface controls over the Bridges data exchanges were operating as prescribed. We noted DTMB did not ensure the file control and batch summary tables used to reconcile Bridges interfaces consistently represented control totals of information processed for 3 of the 9 interfaces sampled. For these 3 interfaces, we sampled 30 daily, monthly, and quarterly files and noted 5 (17%) files did not reconcile. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. Federal regulation 45 CFR 98.68 requires MiLEAP to describe in its CCDF State Plan the internal control in place to help ensure program integrity. MiLEAP's CCDF State Plan for Federal Fiscal Years 2025-2027 describes specific procedures for program integrity and accountability, including program violations and administrative errors. Also, the CCDF State Plan provides specific requirements for child care assistance, including the utilization of an information system for determining eligibility and benefit amounts. Federal law 42 USC 8624 requires the State to expend funds in accordance with the LIHEAP State Plan and allows MDHHS to use LIHEAP funds to intervene in energy-related crisis situations and assist eligible households to meet the costs of home energy. MDHHS utilizes an information system for determining eligibility. The State of Michigan establishes Statewide technical standards for all State information systems. According to State of Michigan Administrative Guide to State Government policy 1340.00, security controls must be implemented to protect State of Michigan information from unauthorized access, use, disclosure, modification, destruction, or denial and to ensure confidentiality, integrity, and availability of State of Michigan information. In addition, the U.S. Government Accountability Office's (GAO's) Federal Information System Controls Audit Manual* (FISCAM) recommends interface controls be established and implemented to reasonably ensure data transferred from a source system to a receiving system is processed accurately, completely, and timely. Also, effective interface reconciliation procedures should include the use of control totals, records, counts, and other logging techniques. Cause DTMB informed us because of a reconciliation procedure issue and clean-up efforts, some record counts either were not documented or exception tables were removed. Effect DTMB's weakness in maintaining sufficient internal control over federal program compliance could result in noncompliance not being detected or corrected in a timely manner. Known Questioned Costs None. Recommendation We recommend DTMB ensure its interface controls over Bridges data exchanges are operating as prescribed. Management Views DTMB agrees with the finding.
FINDING 2025-004 Bridges Security Management and Access Controls* See Schedule of Findings and Questioned Costs for chart/table. Condition MDHHS had not established effective security management and access controls over Bridges users. We noted: a. MDHHS did not maintain documentation for 1 (2%) of 51 sampled Bridges incompatible role exception requests. Of the 50 forms received, we noted MDHHS did not properly approve 8 (16%) forms prior to granting the exception requests. b. MDHHS did not maintain documentation for 7 (9%) of 80 sampled local office security monitoring reports. Also, MDHHS did not complete timely reviews for 7 (10%) of 73 sampled security monitoring reports. c. MDHHS did not properly approve 3 (8%) of 40 sampled Bridges application security agreements prior to granting access to Bridges. d. MDHHS did not document or properly review its annual recertification of 3 (9%) of 35 sampled Bridges non-privileged user accounts. e. MDHHS did not maintain documentation for 3 (15%) of 20 sampled local office high-risk Bridges transaction monitoring reports. Of the 17 reports received, MDHHS did not document its review date for 2 (12%) of the reports. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. Federal regulation 45 CFR 98.68 requires MiLEAP to describe in its CCDF State Plan the internal control in place to help ensure program integrity. MiLEAP's CCDF State Plan for Federal Fiscal Years 2025-2027 describes specific procedures for program integrity and accountability, including program violations and administrative errors. Also, the CCDF State Plan provides specific requirements for child care assistance, including the utilization of an information system for determining eligibility and benefit amounts. Federal law 42 USC 8624 requires the State to expend funds in accordance with the LIHEAP State Plan and allows MDHHS to use LIHEAP funds to intervene in energy-related crisis situations and assist eligible households to meet the costs of home energy. MDHHS utilizes an information system for determining eligibility. The State of Michigan establishes Statewide technical standards for all State information systems. According to State of Michigan Administrative Guide to State Government policy 1340.00, security controls must be implemented to protect State of Michigan information from unauthorized access, use, disclosure, modification, destruction, or denial and to ensure confidentiality, integrity, and availability of State of Michigan information. SOM Technical Standard 1340.00.020.01 requires agencies to implement and document baseline controls, such as access authorizations and the principle of least privilege. The Standard also requires separation of duties must be supported through defined system access authorizations and accounts should be reviewed annually to validate their continued need. In addition, the GAO's FISCAM recommends compensating controls, such as additional monitoring and supervision, should be in place where segregation of duties'* conflicts exist. Cause For parts a., c., and d., MDHHS's internal control and monitoring activities were not sufficient to ensure all appropriate parties adhered to established policies and procedures. For parts b. and e., MDHHS's internal control and monitoring activities need improvement to ensure all appropriate parties maintain and timely complete their review of the local office security monitoring reports and high-risk Bridges transaction monitoring reports. Effect We consider these issues to be a material weakness because, without effective security management and access controls, individuals may obtain or maintain unauthorized or inappropriate access to Bridges. As a result, an increased risk exists MDHHS cannot ensure the security of the Bridges application and data used to help determine eligibility and benefit levels for the SNAP Cluster, Summer Electronic Benefit Transfer Program for Children, CCDF Cluster, Medicaid Cluster, Temporary Assistance for Needy Families (TANF), Refugee and Entrant Assistance State/Replacement Designee Administered Programs (REAP), LIHEAP, and Children's Health Insurance Program (CHIP). Known Questioned Costs None. Recommendation We recommend MDHHS establish effective security management and access controls over Bridges users. Management Views MDHHS agrees with the finding.
FINDING 2025-061 Epidemiology and Laboratory Capacity for Infectious Diseases (ELC), ALN 93.323 and Block Grants for Prevention and Treatment of Substance Abuse, ALN 93.959 2025-061 U.S. Department of Health and Human Services Epidemiology and Laboratory Capacity for Infectious Diseases, 93.323 Block Grants for Prevention and Treatment of Substance Abuse, 93.959 Reporting Material Weakness in Internal Control over Compliance and Material Noncompliance Grant Award Number/Year: Affects grant award #NU51CK000362 (8/1/24 - 7/31/29) under assistance listing 93.323 and grant awards #B08TI083947 (9/1/21 - 9/30/25), #B08TI087045 (10/1/23 - 9/30/25), and #B08TI088112 (10/1/24 - 9/30/26) under assistance listing 93.959. Criteria: Title 2 U.S. Code of Federal Regulations (CFR) Part 200 Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards (Uniform Guidance) section 200.303 provides that recipients must establish and maintain effective internal control that provides reasonable assurance that the recipient is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award (applicable for the Epidemiology program). The Federal Funding Accountability and Transparency Act (FFATA) requires direct recipients of certain federal awards to report subaward information by the end of the month following the month in which the prime awardee obligates a subgrant award equal to or greater than $30,000 (applicable for the Epidemiology and Substance Abuse programs). Condition: In some instances, subaward information was not reported, not reported accurately, or not reported timely. In addition, evidence of the performance of control activities, such as review procedures or segregation of duties, was not documented to support that the control activity occurred. Cause: The Michigan Department of Health and Human Services (MDHHS) informed us they received validation errors when attempting to submit the subaward information required. Re-submissions were not always attempted and new submissions were not always reconciled to successful or unsuccessful past attempts. MDHHS did not have adequate internal controls to ensure subaward information was submitted in accordance with the FFATA. In addition, MDHHS did not ensure internal controls were documented and maintained. Effect: Subaward obligations were not reported in the FSRS accurately, and, therefore, inaccurate information is included on the FFATA's website for public information disclosure. In some instances, the subaward obligations were not reported in the FSRS timely, and, therefore, were not available for public information disclosure in a timely manner. Questioned Costs: None Context/Sampling: Epidemiology and Laboratory Capacity for Infectious Diseases A nonstatistical sample of 21 out of a population of 138 applicable subaward obligations was selected for testing. The summary of errors was noted as follows: See Schedule of Findings and Questioned Costs for chart/table. Total subawards of $19,180,449 were reported with inaccurate obligations; however, $11,957,365 of those obligations were reported, thus leaving a net variance of $7,223,084 in underreported obligations. Block Grants for Prevention and Treatment of Substance Abuse A nonstatistical sample of 13 out of a population of 85 applicable subaward obligations was selected for testing. The summary of errors was noted as follows: See Schedule of Findings and Questioned Costs for chart/table. Total subawards of $9,949,532 were reported with inaccurate obligations; however, $3,872,549 of those obligations were reported, thus leaving a net variance of $6,076,983 in underreported obligations. In addition, documentation of control activities performed was not maintained for any of the subaward obligations tested for both programs. Repeat Finding from Prior Year: No Recommendation: We recommend MDHHS enhance internal controls to ensure subaward information is submitted in accordance with the FFATA and that evidence of control activities, such as segregation of duties, is documented and maintained. Views of Responsible Officials: MDHHS agrees with this finding.
Finding 2025-001: Allowable Costs/Cost Principles – Significant Deficiency in Internal Control over Compliance Program: 16.575 – U.S. Department of Justice, Office of Justice Programs, Office for Victims of Crimes: Passed-through Texas Office of the Governor, Criminal Justice Division (CJD) Crime Victim Assistance Criteria: The 2 CFR section 200.303 requires that non-Federal entities receiving Federal awards establish and maintain internal control over the Federal awards that provides reasonable assurance that the non-Federal entity is managing the Federal awards in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. Condition: During our audit, we noted that unallowable payroll costs were charged to the grant. Cause: Controls were not in place to verify the accuracy of payroll amounts charged to the grant. Effect or Potential Effect: Payroll costs charged to the grant exceeded actual costs incurred by staff administering the grant. Questioned Costs: Amount is below the threshold of $25,000. Context: During our testing of payroll amounts charged to the grant, we selected a sample size of 8 payroll amounts and identified 2 instances where the grant was not charged in accordance with actual time spent on administering the grant per the employees’ time sheets. Recommendation: A policy should be established and enforced to require secondary review of costs to be charged to the grant prior to entry into the accounting software and inclusion in requests for reimbursement that are submitted to granting agencies. Repeat Finding: No. Views of Responsible Officials: Management agrees with the audit finding and a response is included in the corrective action plan.
Program Information: U.S. Department of Health and Human Services Tribal Self-Governance and Determination Cluster Assistance Listing #93.441 Award Numbers: HHS-I-241-2022-00004 and HHS-I-241-2019-00003 Award Period: 10/1/2024-9/30/2027 and 10/1/2020-9/30/2021 Rural Health Outreach and Rural Network Development Program Assistance Listing #93.912 Award Numbers: 6 G28RH46294-03-00 and 6 HB1RH47073-03-02 Award Period: 9/30/2022-9/29/2025 and 9/1/2022-8/31/2026 Criteria: Assistance Listing #93.441 Per the compliance supplement and 42 CFR 136.12, eligible individuals include those of Indian descent belonging to the local Indian community, as evidenced by tribal membership or similar factors. Additional eligibility covers non-Indian women pregnant with an eligible Indian’s child, certain non-Indian household members for public health reasons, and specific children and spouses per 25 USC 1680c(a)-(b) and Section 813 of the Indian Health Care Improvement Act. For Purchased/Referred Care (PRC), individuals must reside in the U.S. within a PRC Delivery Area, be a member of or have close ties to the relevant tribe(s), and meet requirements for students, transients, and foster children as specified in the supplement. Assistance Listing #93.912 Per discussion with the program’s Chief Behavioral Health Officer, individuals must provide documentation of membership in a federally recognized Tribe (e.g., Tribal enrollment card, Certificate of Indian Blood, or proof of lineal descent) and a signed consent to receive services. Registration staff are responsible for screening and securely filing these documents in the practice management system. Per 2 CFR § 200.303, recipients must establish and maintain effective internal controls over federal awards to ensure compliance with applicable regulations. Condition/Context: Assistance Listing #93.441 Of the 60 samples selected for testing, documentation to evidence review and approval was not provided. Assistance Listing #93.912 Of the 5 samples selected for testing, documentation to evidence review and approval was not provided. [ ] Compliance Finding [ X ] Significant Deficiency [ ] Material Weakness Cause: The program did not have adequate internal controls to ensure that all eligibility files included documentation of review and approval. This appears to be due to a lack of oversight and monitoring procedures to track compliance with this documentation requirement. Effect: Without adequate documentation of review and approval, there is an increased risk that ineligible individuals may receive services, and the entity may not be able to demonstrate compliance with federal eligibility requirements. This could result in questioned costs or findings in future audits. Questioned Cost: N/A – none of the samples selected for testing were determined to be ineligible to receive services. Prior Year Finding: Yes, 2024-004. Recommendation: We recommend that management implement and enforce procedures to ensure that all eligibility determinations are reviewed and approved, and that supporting documentation of such review and approval is consistently maintained in the appropriate system or file. Views of Responsible Officials and Planned Corrective Action: Management agrees with the finding and has prepared corrective action as detailed in its Corrective Action Plan.
Program Information: U.S. Department of the Interior Services to Indian Children, Elderly and Families Assistance Listing #15.025 Award Numbers: A24AV00213, A18AV00060, A23AV00656, A25AV00471, Unknown Award Period: 10/1/2023-9/30/2026 U.S. Department of Health and Human Services Substance Abuse and Mental Health Services Projects of Regional and National Significance Assistance Listing #93.243 Award Numbers: 5H79SM086440-03, 1H79SM089733-01, and 5H79TI086315-02 Award Period: 9/30/2022-9/29/2027, 9/30/2024-9/29/2029, and 9/30/2023-9/29/2028 Criteria: Assistance Listing #15.025 Per discussion with the program’s management the following reports are required to be submitted: • Quarterly SF-425 Federal Financial Reports • Annual Narrative Report • FASSR Report • ICWA Annual Report Assistance Listing #93.243 Per discussion with the program’s management the following reports are required to be submitted: • Annual SF-425 Federal Financial Reports • SF-424 Application for Federal Assistance • Mid-year Programmatic Progress Reports • Annual Programmatic Progress Reports • SPARS Reports Per 2 CFR § 200.303, recipients must establish and maintain effective internal controls over federal awards to ensure compliance with applicable regulations. Assistance Listing #15.025 • 1 of 2 Quarterly SF-425 Federal Financial Reports were submitted after the required due date. • 1 of 1 Annual Narrative Report had no documentation of approval. • 1 of 1 Annual FASSR Report had no documentation of approval and was submitted after the required due date. • 1 of 1 ICWA Annual Report had no documentation of approval and was submitted after the required due date. Assistance Listing #93.243 • 1 of 3 SF-425 Federal Financial Reports was submitted after the required due date. • 1 of 1 Mid-year Programmatic Progress Report had no documentation of approval or date of submission. • 2 of 2 Annual Programmatic Progress Reports had no documentation of approval or date of submission. • 1 of 1 SPARS Report had no documentation of approval. [ X ] Compliance Finding [ X ] Significant Deficiency [ ] Material Weakness Cause: Management did not have adequately designed and implemented controls to ensure required federal reports were prepared, reviewed, approved, and submitted timely. In addition, evidence of supervisory review and approval was not consistently maintained. Effect: Late or inadequately documented reports increase the risk that the Department will not comply with federal award reporting requirements and may be unable to demonstrate compliance during monitoring or audit. In addition, the lack of documented review or approval increases the risk that reporting errors, omissions, or incomplete information may not be detected before submission. Questioned Cost: N/A. No questioned costs were identified as the finding relates to late reporting and lack of documented review/approval. Prior Year Finding: No. Recommendation: We recommend that the Department strengthen internal controls over federal reporting by implementing procedures to ensure all required reports are prepared, reviewed, approved, and submitted timely. Such procedures should include maintaining a reporting calendar of required due dates, assigning responsibility for report preparation and submission, documenting supervisory review and approval, and periodically monitoring compliance with reporting requirements. Views of Responsible Officials and Planned Corrective Action: Management agrees with the finding and has prepared corrective action as detailed in its Corrective Action Plan.
Finding 2025.003: Cash Management - Significant Deficiency Name of Federal Agency: U.S. Department of Health and Human Services Federal Program Names: Health Center Program Cluster: Health Center Program Grants for New and Expanded Services under the Health Center Program COVID-19 - Grants for New and Expanded Services under the Health Center Program Federal Assistance Listing Numbers: 93.224 and 93.527 Federal Award Identification Number and Year: H80CS11299 - 2024 and 2025, Q8MCS49109 - 2024, H2ECS45512 - 2024 and H8LCS51634 - 2024 Criteria In accordance with §200.305, Federal Payment, grantees and subgrantees that receive grant funds are responsible for maintaining controls regarding the management of federal program funds under the Uniform Guidance in 2 CFR 200.302 and 200.303. Condition The Organization's drawdowns did not illustrate review and approval by management. Cause The Organization did not have adequate controls to ensure drawdowns were properly approved and such approval is documented. Effect or Potential Effect The condition may lead to inaccurate or improper drawdowns. Questioned Costs None. Context We selected 7 drawdowns for testing of cash management. We noted there was no formal approval or evidence of review for all 7 drawdowns. Identification of Repeat Finding Not a repeat finding. Recommendation The Organization should develop written procedures to review all drawdowns that occur in order to ensure accuracy. Views of Responsible Officials Management and the Board of Directors agree with the finding and will implement additional controls to ensure there is formal evidence of review being performed.
The Uniform Guidance, 2 CFR 200.303, requires non-federal entities receiving federal awards (i.e., auditee management) to establish and maintain effective internal controls over the federal award which provide reasonable assurance the non-federal entity is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award. Additionally, 2 CFR 200.501, requires a non-Federal entity that expends $750,000 or more in Federal awards during the non-Federal entity’s fiscal year to have a single or program-specific audit conducted for that year in accordance with the provisions of this part. The Alabama Emergency Management Agency did not obtain and review audit reports for two of the four subrecipients reviewed. The Alabama Emergency Management Agency did not have sufficient internal controls in place to ensure subrecipient audits were conducted, received, and reviewed. Alabama Emergency Management Agency is unable to ensure that subrecipients are taking corrective action on significant developments that negatively affect the subaward as a result of key audit findings.
45 CFR Sections 75.420 through 75.475 establishes the principles to be applied in establishing the allowability of certain items involved in determining costs charged to federal awards. The Uniform Guidance, 2 CFR 200.303, requires non-Federal entities receiving Federal awards (i.e., auditee management) to establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal Award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. Expenditure transactions for the Social Services Block Grant program at the Alabama Department of Human Resources consist of payments for multiple services. Client services rendered are entered into the Family, Adult, and Child Tracking System (FACTS) by Resource Management staff based on invoices approved at the county level. Those services are used to determine payment amounts to clients. During the review of twenty-five (25) expenditure transactions, we identified one transaction consisting of seven duplicate service payments totaling $4,900.00. Program staff entered services received by seven eligible clients twice into FACTS. The Alabama Department of Human Resources did not have adequate controls in place to prevent, detect, and correct the error in a timely manner. As a result, unallowable costs were incorrectly charged to the Social Services Block Grant program.
The Uniform Guidance, 2 CFR 200.303, requires non-Federal entities receiving Federal awards (i.e., auditee management) to establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal Award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. The Uniform Guidance, 2 CFR Part 200, Appendix XI Compliance Supplement, November 2025, states that the federal share of state Adoption Assistance Subsidy Payments is the Federal Medical Assistance Program (FMAP) percentage. The FMAP percentage is entered into the Alabama Department of Human Resources’ (DHR) State of Alabama Accounting and Resource System (STAARS), their system of official record, which calculates the federal share of the State’s Adoption Assistance Subsidy Payments. This percentage varies by state and fiscal year. The FMAP percentage in STAARS has not been updated since fiscal year 2022. When verifying compliance with matching requirements, we determined the FMAP percentage in STAARS was incorrect. As a result, DHR 's automated cost allocation calculations resulted in an understatement of the matching requirement. Upon further review, it was determined DHR utilized spreadsheets as their primary tool to calculate matching requirements instead of STAARS for fiscal year 2025. After performing additional audit procedures, it was determined the matching requirement was met. DHR did not have adequate controls in place to ensure the FMAP percentages were updated annually in STAARS which could lead to the required federal share not being met for the Adoption Assistance Program.
Finding 2025-001 Procurement Controls (Significant Deficiency) Federal Programs Assistance Listing and Program Title* U.S. Agency For International Development 98.001 USAID Foreign Assistance for Programs Overseas Prime Contract #AID-391-A-17-00002 Award Year: Fiscal Year Ended September 30, 2025 Repeat Finding - No Criteria: Under 2 CFR 200.303, non-federal entities are required to establish and maintain effective internal controls over federal awards to provide reasonable assurance that federal awards are managed in compliance with applicable laws, regulations, and award terms and conditions. Such controls should include appropriate vendor due diligence, procurement oversight, monitoring of high-risk transactions, verification of vendor representations, and review controls over advance payments and procurement documentation. Condition: The Organization identified procurement irregularities and fraudulent representations by a vendor associated with the acquisition of mobile X-ray equipment under a federally funded program in Pakistan. Subsequent investigation determined that: • procurement advertisements had not been properly published, • falsified procurement support documentation had been submitted, • vendor representations regarding geographic code compliance were inaccurate, • and procurement controls did not timely identify irregularities associated with vendor selection and advance payment processing. The investigation further identified deficiencies in procurement oversight, vendor verification procedures, and monitoring controls, including insufficient review of supporting procurement documentation and inadequate safeguards surrounding an advance payment to the vendor. Upon identification of the matter, the Organization conducted internal and external investigations, terminated the procurement arrangement, and reduced the amount charged to the contract by approximately $2.2 million. Cause: Procurement oversight and vendor monitoring controls within the affected program location were not sufficiently designed and/or operating effectively to verify vendor representations, assess procurement risk indicators, validate procurement support documentation, and monitor compliance with procurement requirements on a timely basis. Effect: Improper procurement-related charges were incurred by the Organization. Questioned Costs: None. Recommendations: We recommend the Organization continue strengthening procurement oversight and compliance monitoring controls, particularly for high-risk and international procurements, including: • enhanced vendor due diligence procedures, • verification of critical procurement documentation, • strengthened review and approval controls over advance payments, • additional monitoring of vendor certifications and compliance representations, • escalation procedures for procurement irregularities, • and increased centralized oversight of significant procurement activities. Views of Responsible Officials and Planned Corrective Actions: Management concurs with the finding and has implemented corrective actions, including enhanced procurement oversight procedures, additional monitoring controls, and remediation activities within the affected country operations.