FINDING 2024-013 Subject: COVID-19 - Education Stabilization Fund - Reporting Federal Agency: Department of Education Federal Program: COVID-19 - Education Stabilization Fund Assistance Listings Numbers: 84.425C, 84.425D, 84.425U Federal Award Numbers and Years (or Other Identifying Numbers): S425C200018, S425D200013, S425D210013, S425U210013 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Reporting Audit Finding: Material Weakness Repeat Finding This is a repeat finding from the immediately prior audit report. The prior audit finding number was 2022-002. INDIANA STATE BOARD OF ACCOUNTS 38 HUNTINGTON COUNTY COMMUNITY SCHOOL CORPORATION SCHEDULE OF FINDINGS AND QUESTIONED COSTS (Continued) Condition and Context An effective internal control system, which would include segregation of duties, was not in place at the School Corporation in order to ensure compliance with requirements related to the grant agreement and the Reporting compliance requirement. The School Corporation had not designed nor implemented a system of internal controls to ensure that the annual Elementary and Secondary School Emergency Relief (ESSER) and the Governor's Emergency Education Relief (GEER) annual Data Collection reports (Reports) were complete and accurately submitted. The Reports were prepared and submitted in JotForm, the online application used by Indiana Department of Education to collect information, by one employee without an oversight or review process in place to prevent, or detect and correct, errors. The lack of internal controls was systemic throughout the audit period. Criteria 2 CFR 200.303 states in part: "The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in 'Standards for Internal Control in the Federal Government' issued by the Comptroller General of the United States or the 'Internal Control Integrated Framework', issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). . . ." Cause Management did not develop a system of internal controls that segregated key functions over the Reports. Effect Without the proper implementation of an effectively designed system of internal controls, the School Corporation is at risk of noncompliance with the grant agreement and the Reporting compliance requirement. Questioned Costs There were no questioned costs identified. Recommendation We recommended that the School Corporation's management establish a system of internal controls related to the grant agreement and the Reporting compliance requirement. Views of Responsible Officials For the views of responsible officials, refer to the Corrective Action Plan that is part of this report.
FINDING 2024-013 Subject: COVID-19 - Education Stabilization Fund - Reporting Federal Agency: Department of Education Federal Program: COVID-19 - Education Stabilization Fund Assistance Listings Numbers: 84.425C, 84.425D, 84.425U Federal Award Numbers and Years (or Other Identifying Numbers): S425C200018, S425D200013, S425D210013, S425U210013 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Reporting Audit Finding: Material Weakness Repeat Finding This is a repeat finding from the immediately prior audit report. The prior audit finding number was 2022-002. INDIANA STATE BOARD OF ACCOUNTS 38 HUNTINGTON COUNTY COMMUNITY SCHOOL CORPORATION SCHEDULE OF FINDINGS AND QUESTIONED COSTS (Continued) Condition and Context An effective internal control system, which would include segregation of duties, was not in place at the School Corporation in order to ensure compliance with requirements related to the grant agreement and the Reporting compliance requirement. The School Corporation had not designed nor implemented a system of internal controls to ensure that the annual Elementary and Secondary School Emergency Relief (ESSER) and the Governor's Emergency Education Relief (GEER) annual Data Collection reports (Reports) were complete and accurately submitted. The Reports were prepared and submitted in JotForm, the online application used by Indiana Department of Education to collect information, by one employee without an oversight or review process in place to prevent, or detect and correct, errors. The lack of internal controls was systemic throughout the audit period. Criteria 2 CFR 200.303 states in part: "The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in 'Standards for Internal Control in the Federal Government' issued by the Comptroller General of the United States or the 'Internal Control Integrated Framework', issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). . . ." Cause Management did not develop a system of internal controls that segregated key functions over the Reports. Effect Without the proper implementation of an effectively designed system of internal controls, the School Corporation is at risk of noncompliance with the grant agreement and the Reporting compliance requirement. Questioned Costs There were no questioned costs identified. Recommendation We recommended that the School Corporation's management establish a system of internal controls related to the grant agreement and the Reporting compliance requirement. Views of Responsible Officials For the views of responsible officials, refer to the Corrective Action Plan that is part of this report.
FINDING 2024-014 Subject: COVID-19 - Education Stabilization Fund - Special Tests and Provisions - Wage Rate Requirements Federal Agency: Department of Education Federal Program: COVID-19 - Education Stabilization Fund Assistance Listings Numbers: 84.425D, 84.425U Federal Award Numbers and Years (or Other Identifying Numbers): S425D210013, S425U210013 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Special Tests and Provisions - Wage Rate Requirements Audit Findings: Material Weakness, Modified Opinion Condition and Context An effective internal control system, which would include segregation of duties, was not in place at the School Corporation in order to ensure compliance with requirements related to the grant agreement and the Special Tests and Provisions - Wage Rate Requirements compliance requirement. All laborers and mechanics employed by contractors or subcontractors to work on construction contracts in excess of $2,000 financed by federal assistance funds must be paid wages not less than those established for the locality of the project (prevailing wage rates) by the Indiana Department of Labor (DOL). Nonfederal entities shall include in their construction contracts subject to the Wage Rate Requirements a provision that the contractor or subcontractor comply with those requirements and the DOL regulations. This includes a requirement for the contractor or subcontractor to submit to the nonfederal entity weekly, for each week in which any contract work is performed, a copy of the payroll and a statement of compliance (certified payrolls). The School Corporation had not implemented procedures to ensure the applicable wage rate requirements were included in the contract and had also not designed or implemented policies or procedures to ensure that contractors or subcontractors submitted certified payrolls weekly. During the audit period, the School Corporation received five contractor pay applications for a construction contract subject to the Wage Rate Requirements which included labor charges that were paid with COVID-19 - Education Stabilization Fund grant awards. Of the five pay applications with labor charges, the School Corporation had obtained some (not all) certified payrolls for three pay applications and had obtained no certified payrolls for two of the pay applications. Through inquiry with the School Corporation, it was determined the certified payrolls that were obtained were obtained as the result of an Indiana Department of Education Construction Monitoring Review request. The lack of internal controls was systemic throughout the audit period. Criteria 2 CFR 200.303 states in part: "The non-Federal entity must: INDIANA STATE BOARD OF ACCOUNTS 40 HUNTINGTON COUNTY COMMUNITY SCHOOL CORPORATION SCHEDULE OF FINDINGS AND QUESTIONED COSTS (Continued) (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in 'Standards for Internal Control in the Federal Government' issued by the Comptroller General of the United States or the 'Internal Control Integrated Framework', issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). . . ." 29 CFR 5.5 states in part: "(a) Required contract clauses. The Agency head will cause or require the contracting officer to require the contracting officer to insert in full, or (for contracts covered by the Federal Acquisition Regulation (48 CFR chapter 1)) by reference, in any contract in excess of $2,000 which is entered into for the actual construction, alteration and/or repair, including painting and decorating, of a public building or public work, or building or work financed in whole or in part from Federal funds or in accordance with guarantees of a Federal agency or financed from funds obtained by pledge of any contract of a Federal agency to make a loan, grant or annual contribution (except where a different meaning is expressly indicated), and which is subject to the labor standards provisions of any of the laws referenced by § 5.1, the following clauses . . . (1) Minimum wages — (i) Wage rates and fringe benefits. All laborers and mechanics employed or working upon the site of the work (or otherwise working in construction or development of the project under a development statute), will be paid unconditionally and not less often than once a week, and without subsequent deduction or rebate on any account (except such payroll deductions as are permitted by regulations issued by the Secretary of Labor under the Copeland Act (29 CFR part 3)), the full amount of basic hourly wages and bona fide fringe benefits (or cash equivalents thereof) due at time of payment computed at rates not less than those contained in the wage determination of the Secretary of Labor which is attached hereto and made a part hereof, regardless of any contractual relationship which may be alleged to exist between the contractor and such laborers and mechanics. . . ." (3) Records and certified payrolls — . . . (ii) Certified payroll requirements — (A) Frequency and method of submission. The contractor or subcontractor must submit weekly, for each week in which any DBA- or Related Acts-covered work is performed, certified payrolls to the [write in name of appropriate Federal agency] if the agency is a party to the contract, but if the agency is not such a party, the contractor will submit the certified payrolls to the applicant, sponsor, owner, or other entity, as the case may be, that maintains such records, for transmission to the [write in name of agency]. . . ." 2 CFR 200 Appendix II states in part: "In addition to other provisions required by the Federal agency or non-Federal entity; all contracts made by the non-Federal entity under the Federal award must contain provisions covering the following, as applicable. . . . INDIANA STATE BOARD OF ACCOUNTS 41 HUNTINGTON COUNTY COMMUNITY SCHOOL CORPORATION SCHEDULE OF FINDINGS AND QUESTIONED COSTS (Continued) (D) Davis-Bacon Act, as amended (40 U.S.C. 3141-3148). When required by Federal program legislation, all prime construction contracts in excess of $2,000 awarded by non-Federal entities must include a provision for compliance with the Davis-Bacon Act (40 U.S.C. 3141-3144, and 3146-3148) as supplemented by Department of Labor regulations (29 CFR Part 5, 'Labor Standards Provisions Applicable to Contracts Covering Federally Financed and Assisted Construction'). In accordance with the statute, contractors must be required to pay wages to laborers and mechanics at a rate not less than the prevailing wages specified in a wage determination made by the Secretary of Labor. In addition, contractors must be required to pay wages not less than once a week. . . ." Cause Management of the School Corporation did not have an effective internal control system in place to detect noncompliance when the contractor did not provide the School Corporation with a copy of the certified payroll and statement of compliance for all construction invoices. Effect Without the proper implementation of an effectively designed system of internal controls, the internal control system cannot be capable of effectively preventing, or detecting and correcting, material noncompliance. As a result, not all certified payrolls were provided to the School Corporation by the contractor. Noncompliance with the provisions of federal statutes, regulations, and the terms and conditions of the federal award could result in the loss of future federal funding to the School Corporation. Questioned Costs There were no questioned costs identified. Recommendation We recommended that management of the School Corporation establish a proper system of internal controls and develop policies and procedures to ensure that all certified payrolls are provided to the School Corporation from the contractor. Views of Responsible Officials For the views of responsible officials, refer to the Corrective Action Plan that is part of this report.
FINDING 2024-014 Subject: COVID-19 - Education Stabilization Fund - Special Tests and Provisions - Wage Rate Requirements Federal Agency: Department of Education Federal Program: COVID-19 - Education Stabilization Fund Assistance Listings Numbers: 84.425D, 84.425U Federal Award Numbers and Years (or Other Identifying Numbers): S425D210013, S425U210013 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Special Tests and Provisions - Wage Rate Requirements Audit Findings: Material Weakness, Modified Opinion Condition and Context An effective internal control system, which would include segregation of duties, was not in place at the School Corporation in order to ensure compliance with requirements related to the grant agreement and the Special Tests and Provisions - Wage Rate Requirements compliance requirement. All laborers and mechanics employed by contractors or subcontractors to work on construction contracts in excess of $2,000 financed by federal assistance funds must be paid wages not less than those established for the locality of the project (prevailing wage rates) by the Indiana Department of Labor (DOL). Nonfederal entities shall include in their construction contracts subject to the Wage Rate Requirements a provision that the contractor or subcontractor comply with those requirements and the DOL regulations. This includes a requirement for the contractor or subcontractor to submit to the nonfederal entity weekly, for each week in which any contract work is performed, a copy of the payroll and a statement of compliance (certified payrolls). The School Corporation had not implemented procedures to ensure the applicable wage rate requirements were included in the contract and had also not designed or implemented policies or procedures to ensure that contractors or subcontractors submitted certified payrolls weekly. During the audit period, the School Corporation received five contractor pay applications for a construction contract subject to the Wage Rate Requirements which included labor charges that were paid with COVID-19 - Education Stabilization Fund grant awards. Of the five pay applications with labor charges, the School Corporation had obtained some (not all) certified payrolls for three pay applications and had obtained no certified payrolls for two of the pay applications. Through inquiry with the School Corporation, it was determined the certified payrolls that were obtained were obtained as the result of an Indiana Department of Education Construction Monitoring Review request. The lack of internal controls was systemic throughout the audit period. Criteria 2 CFR 200.303 states in part: "The non-Federal entity must: INDIANA STATE BOARD OF ACCOUNTS 40 HUNTINGTON COUNTY COMMUNITY SCHOOL CORPORATION SCHEDULE OF FINDINGS AND QUESTIONED COSTS (Continued) (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in 'Standards for Internal Control in the Federal Government' issued by the Comptroller General of the United States or the 'Internal Control Integrated Framework', issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). . . ." 29 CFR 5.5 states in part: "(a) Required contract clauses. The Agency head will cause or require the contracting officer to require the contracting officer to insert in full, or (for contracts covered by the Federal Acquisition Regulation (48 CFR chapter 1)) by reference, in any contract in excess of $2,000 which is entered into for the actual construction, alteration and/or repair, including painting and decorating, of a public building or public work, or building or work financed in whole or in part from Federal funds or in accordance with guarantees of a Federal agency or financed from funds obtained by pledge of any contract of a Federal agency to make a loan, grant or annual contribution (except where a different meaning is expressly indicated), and which is subject to the labor standards provisions of any of the laws referenced by § 5.1, the following clauses . . . (1) Minimum wages — (i) Wage rates and fringe benefits. All laborers and mechanics employed or working upon the site of the work (or otherwise working in construction or development of the project under a development statute), will be paid unconditionally and not less often than once a week, and without subsequent deduction or rebate on any account (except such payroll deductions as are permitted by regulations issued by the Secretary of Labor under the Copeland Act (29 CFR part 3)), the full amount of basic hourly wages and bona fide fringe benefits (or cash equivalents thereof) due at time of payment computed at rates not less than those contained in the wage determination of the Secretary of Labor which is attached hereto and made a part hereof, regardless of any contractual relationship which may be alleged to exist between the contractor and such laborers and mechanics. . . ." (3) Records and certified payrolls — . . . (ii) Certified payroll requirements — (A) Frequency and method of submission. The contractor or subcontractor must submit weekly, for each week in which any DBA- or Related Acts-covered work is performed, certified payrolls to the [write in name of appropriate Federal agency] if the agency is a party to the contract, but if the agency is not such a party, the contractor will submit the certified payrolls to the applicant, sponsor, owner, or other entity, as the case may be, that maintains such records, for transmission to the [write in name of agency]. . . ." 2 CFR 200 Appendix II states in part: "In addition to other provisions required by the Federal agency or non-Federal entity; all contracts made by the non-Federal entity under the Federal award must contain provisions covering the following, as applicable. . . . INDIANA STATE BOARD OF ACCOUNTS 41 HUNTINGTON COUNTY COMMUNITY SCHOOL CORPORATION SCHEDULE OF FINDINGS AND QUESTIONED COSTS (Continued) (D) Davis-Bacon Act, as amended (40 U.S.C. 3141-3148). When required by Federal program legislation, all prime construction contracts in excess of $2,000 awarded by non-Federal entities must include a provision for compliance with the Davis-Bacon Act (40 U.S.C. 3141-3144, and 3146-3148) as supplemented by Department of Labor regulations (29 CFR Part 5, 'Labor Standards Provisions Applicable to Contracts Covering Federally Financed and Assisted Construction'). In accordance with the statute, contractors must be required to pay wages to laborers and mechanics at a rate not less than the prevailing wages specified in a wage determination made by the Secretary of Labor. In addition, contractors must be required to pay wages not less than once a week. . . ." Cause Management of the School Corporation did not have an effective internal control system in place to detect noncompliance when the contractor did not provide the School Corporation with a copy of the certified payroll and statement of compliance for all construction invoices. Effect Without the proper implementation of an effectively designed system of internal controls, the internal control system cannot be capable of effectively preventing, or detecting and correcting, material noncompliance. As a result, not all certified payrolls were provided to the School Corporation by the contractor. Noncompliance with the provisions of federal statutes, regulations, and the terms and conditions of the federal award could result in the loss of future federal funding to the School Corporation. Questioned Costs There were no questioned costs identified. Recommendation We recommended that management of the School Corporation establish a proper system of internal controls and develop policies and procedures to ensure that all certified payrolls are provided to the School Corporation from the contractor. Views of Responsible Officials For the views of responsible officials, refer to the Corrective Action Plan that is part of this report.
FINDING 2024-014 Subject: COVID-19 - Education Stabilization Fund - Special Tests and Provisions - Wage Rate Requirements Federal Agency: Department of Education Federal Program: COVID-19 - Education Stabilization Fund Assistance Listings Numbers: 84.425D, 84.425U Federal Award Numbers and Years (or Other Identifying Numbers): S425D210013, S425U210013 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Special Tests and Provisions - Wage Rate Requirements Audit Findings: Material Weakness, Modified Opinion Condition and Context An effective internal control system, which would include segregation of duties, was not in place at the School Corporation in order to ensure compliance with requirements related to the grant agreement and the Special Tests and Provisions - Wage Rate Requirements compliance requirement. All laborers and mechanics employed by contractors or subcontractors to work on construction contracts in excess of $2,000 financed by federal assistance funds must be paid wages not less than those established for the locality of the project (prevailing wage rates) by the Indiana Department of Labor (DOL). Nonfederal entities shall include in their construction contracts subject to the Wage Rate Requirements a provision that the contractor or subcontractor comply with those requirements and the DOL regulations. This includes a requirement for the contractor or subcontractor to submit to the nonfederal entity weekly, for each week in which any contract work is performed, a copy of the payroll and a statement of compliance (certified payrolls). The School Corporation had not implemented procedures to ensure the applicable wage rate requirements were included in the contract and had also not designed or implemented policies or procedures to ensure that contractors or subcontractors submitted certified payrolls weekly. During the audit period, the School Corporation received five contractor pay applications for a construction contract subject to the Wage Rate Requirements which included labor charges that were paid with COVID-19 - Education Stabilization Fund grant awards. Of the five pay applications with labor charges, the School Corporation had obtained some (not all) certified payrolls for three pay applications and had obtained no certified payrolls for two of the pay applications. Through inquiry with the School Corporation, it was determined the certified payrolls that were obtained were obtained as the result of an Indiana Department of Education Construction Monitoring Review request. The lack of internal controls was systemic throughout the audit period. Criteria 2 CFR 200.303 states in part: "The non-Federal entity must: INDIANA STATE BOARD OF ACCOUNTS 40 HUNTINGTON COUNTY COMMUNITY SCHOOL CORPORATION SCHEDULE OF FINDINGS AND QUESTIONED COSTS (Continued) (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in 'Standards for Internal Control in the Federal Government' issued by the Comptroller General of the United States or the 'Internal Control Integrated Framework', issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). . . ." 29 CFR 5.5 states in part: "(a) Required contract clauses. The Agency head will cause or require the contracting officer to require the contracting officer to insert in full, or (for contracts covered by the Federal Acquisition Regulation (48 CFR chapter 1)) by reference, in any contract in excess of $2,000 which is entered into for the actual construction, alteration and/or repair, including painting and decorating, of a public building or public work, or building or work financed in whole or in part from Federal funds or in accordance with guarantees of a Federal agency or financed from funds obtained by pledge of any contract of a Federal agency to make a loan, grant or annual contribution (except where a different meaning is expressly indicated), and which is subject to the labor standards provisions of any of the laws referenced by § 5.1, the following clauses . . . (1) Minimum wages — (i) Wage rates and fringe benefits. All laborers and mechanics employed or working upon the site of the work (or otherwise working in construction or development of the project under a development statute), will be paid unconditionally and not less often than once a week, and without subsequent deduction or rebate on any account (except such payroll deductions as are permitted by regulations issued by the Secretary of Labor under the Copeland Act (29 CFR part 3)), the full amount of basic hourly wages and bona fide fringe benefits (or cash equivalents thereof) due at time of payment computed at rates not less than those contained in the wage determination of the Secretary of Labor which is attached hereto and made a part hereof, regardless of any contractual relationship which may be alleged to exist between the contractor and such laborers and mechanics. . . ." (3) Records and certified payrolls — . . . (ii) Certified payroll requirements — (A) Frequency and method of submission. The contractor or subcontractor must submit weekly, for each week in which any DBA- or Related Acts-covered work is performed, certified payrolls to the [write in name of appropriate Federal agency] if the agency is a party to the contract, but if the agency is not such a party, the contractor will submit the certified payrolls to the applicant, sponsor, owner, or other entity, as the case may be, that maintains such records, for transmission to the [write in name of agency]. . . ." 2 CFR 200 Appendix II states in part: "In addition to other provisions required by the Federal agency or non-Federal entity; all contracts made by the non-Federal entity under the Federal award must contain provisions covering the following, as applicable. . . . INDIANA STATE BOARD OF ACCOUNTS 41 HUNTINGTON COUNTY COMMUNITY SCHOOL CORPORATION SCHEDULE OF FINDINGS AND QUESTIONED COSTS (Continued) (D) Davis-Bacon Act, as amended (40 U.S.C. 3141-3148). When required by Federal program legislation, all prime construction contracts in excess of $2,000 awarded by non-Federal entities must include a provision for compliance with the Davis-Bacon Act (40 U.S.C. 3141-3144, and 3146-3148) as supplemented by Department of Labor regulations (29 CFR Part 5, 'Labor Standards Provisions Applicable to Contracts Covering Federally Financed and Assisted Construction'). In accordance with the statute, contractors must be required to pay wages to laborers and mechanics at a rate not less than the prevailing wages specified in a wage determination made by the Secretary of Labor. In addition, contractors must be required to pay wages not less than once a week. . . ." Cause Management of the School Corporation did not have an effective internal control system in place to detect noncompliance when the contractor did not provide the School Corporation with a copy of the certified payroll and statement of compliance for all construction invoices. Effect Without the proper implementation of an effectively designed system of internal controls, the internal control system cannot be capable of effectively preventing, or detecting and correcting, material noncompliance. As a result, not all certified payrolls were provided to the School Corporation by the contractor. Noncompliance with the provisions of federal statutes, regulations, and the terms and conditions of the federal award could result in the loss of future federal funding to the School Corporation. Questioned Costs There were no questioned costs identified. Recommendation We recommended that management of the School Corporation establish a proper system of internal controls and develop policies and procedures to ensure that all certified payrolls are provided to the School Corporation from the contractor. Views of Responsible Officials For the views of responsible officials, refer to the Corrective Action Plan that is part of this report.
FINDING 2024-014 Subject: COVID-19 - Education Stabilization Fund - Special Tests and Provisions - Wage Rate Requirements Federal Agency: Department of Education Federal Program: COVID-19 - Education Stabilization Fund Assistance Listings Numbers: 84.425D, 84.425U Federal Award Numbers and Years (or Other Identifying Numbers): S425D210013, S425U210013 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Special Tests and Provisions - Wage Rate Requirements Audit Findings: Material Weakness, Modified Opinion Condition and Context An effective internal control system, which would include segregation of duties, was not in place at the School Corporation in order to ensure compliance with requirements related to the grant agreement and the Special Tests and Provisions - Wage Rate Requirements compliance requirement. All laborers and mechanics employed by contractors or subcontractors to work on construction contracts in excess of $2,000 financed by federal assistance funds must be paid wages not less than those established for the locality of the project (prevailing wage rates) by the Indiana Department of Labor (DOL). Nonfederal entities shall include in their construction contracts subject to the Wage Rate Requirements a provision that the contractor or subcontractor comply with those requirements and the DOL regulations. This includes a requirement for the contractor or subcontractor to submit to the nonfederal entity weekly, for each week in which any contract work is performed, a copy of the payroll and a statement of compliance (certified payrolls). The School Corporation had not implemented procedures to ensure the applicable wage rate requirements were included in the contract and had also not designed or implemented policies or procedures to ensure that contractors or subcontractors submitted certified payrolls weekly. During the audit period, the School Corporation received five contractor pay applications for a construction contract subject to the Wage Rate Requirements which included labor charges that were paid with COVID-19 - Education Stabilization Fund grant awards. Of the five pay applications with labor charges, the School Corporation had obtained some (not all) certified payrolls for three pay applications and had obtained no certified payrolls for two of the pay applications. Through inquiry with the School Corporation, it was determined the certified payrolls that were obtained were obtained as the result of an Indiana Department of Education Construction Monitoring Review request. The lack of internal controls was systemic throughout the audit period. Criteria 2 CFR 200.303 states in part: "The non-Federal entity must: INDIANA STATE BOARD OF ACCOUNTS 40 HUNTINGTON COUNTY COMMUNITY SCHOOL CORPORATION SCHEDULE OF FINDINGS AND QUESTIONED COSTS (Continued) (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in 'Standards for Internal Control in the Federal Government' issued by the Comptroller General of the United States or the 'Internal Control Integrated Framework', issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). . . ." 29 CFR 5.5 states in part: "(a) Required contract clauses. The Agency head will cause or require the contracting officer to require the contracting officer to insert in full, or (for contracts covered by the Federal Acquisition Regulation (48 CFR chapter 1)) by reference, in any contract in excess of $2,000 which is entered into for the actual construction, alteration and/or repair, including painting and decorating, of a public building or public work, or building or work financed in whole or in part from Federal funds or in accordance with guarantees of a Federal agency or financed from funds obtained by pledge of any contract of a Federal agency to make a loan, grant or annual contribution (except where a different meaning is expressly indicated), and which is subject to the labor standards provisions of any of the laws referenced by § 5.1, the following clauses . . . (1) Minimum wages — (i) Wage rates and fringe benefits. All laborers and mechanics employed or working upon the site of the work (or otherwise working in construction or development of the project under a development statute), will be paid unconditionally and not less often than once a week, and without subsequent deduction or rebate on any account (except such payroll deductions as are permitted by regulations issued by the Secretary of Labor under the Copeland Act (29 CFR part 3)), the full amount of basic hourly wages and bona fide fringe benefits (or cash equivalents thereof) due at time of payment computed at rates not less than those contained in the wage determination of the Secretary of Labor which is attached hereto and made a part hereof, regardless of any contractual relationship which may be alleged to exist between the contractor and such laborers and mechanics. . . ." (3) Records and certified payrolls — . . . (ii) Certified payroll requirements — (A) Frequency and method of submission. The contractor or subcontractor must submit weekly, for each week in which any DBA- or Related Acts-covered work is performed, certified payrolls to the [write in name of appropriate Federal agency] if the agency is a party to the contract, but if the agency is not such a party, the contractor will submit the certified payrolls to the applicant, sponsor, owner, or other entity, as the case may be, that maintains such records, for transmission to the [write in name of agency]. . . ." 2 CFR 200 Appendix II states in part: "In addition to other provisions required by the Federal agency or non-Federal entity; all contracts made by the non-Federal entity under the Federal award must contain provisions covering the following, as applicable. . . . INDIANA STATE BOARD OF ACCOUNTS 41 HUNTINGTON COUNTY COMMUNITY SCHOOL CORPORATION SCHEDULE OF FINDINGS AND QUESTIONED COSTS (Continued) (D) Davis-Bacon Act, as amended (40 U.S.C. 3141-3148). When required by Federal program legislation, all prime construction contracts in excess of $2,000 awarded by non-Federal entities must include a provision for compliance with the Davis-Bacon Act (40 U.S.C. 3141-3144, and 3146-3148) as supplemented by Department of Labor regulations (29 CFR Part 5, 'Labor Standards Provisions Applicable to Contracts Covering Federally Financed and Assisted Construction'). In accordance with the statute, contractors must be required to pay wages to laborers and mechanics at a rate not less than the prevailing wages specified in a wage determination made by the Secretary of Labor. In addition, contractors must be required to pay wages not less than once a week. . . ." Cause Management of the School Corporation did not have an effective internal control system in place to detect noncompliance when the contractor did not provide the School Corporation with a copy of the certified payroll and statement of compliance for all construction invoices. Effect Without the proper implementation of an effectively designed system of internal controls, the internal control system cannot be capable of effectively preventing, or detecting and correcting, material noncompliance. As a result, not all certified payrolls were provided to the School Corporation by the contractor. Noncompliance with the provisions of federal statutes, regulations, and the terms and conditions of the federal award could result in the loss of future federal funding to the School Corporation. Questioned Costs There were no questioned costs identified. Recommendation We recommended that management of the School Corporation establish a proper system of internal controls and develop policies and procedures to ensure that all certified payrolls are provided to the School Corporation from the contractor. Views of Responsible Officials For the views of responsible officials, refer to the Corrective Action Plan that is part of this report.
FINDING 2024-003 Subject: Child Nutrition Cluster - Eligibility Federal Agency: Department of Agriculture Federal Programs: School Breakfast Program, National School Lunch Program Assistance Listings Numbers: 10.553, 10.555 Federal Award Numbers and Years (or Other Identifying Numbers): FY22-23, FY23-24 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Eligibility Audit Finding: Material Weakness Condition and Context An effective internal control system, which would include segregation of duties, was not in place at the School Corporation in order to ensure compliance with requirements related to the grant agreement and the Eligibility compliance requirement. Information from free and reduced-price applications was entered into the School Corporation's school nutrition software by the Food Service Director. The software system calculated students' eligibility for free and reduced-price meals based on the parameters within the system. There was no documented oversight, review, or approval process in place to ensure information from the applications was entered into the system correctly. The system parameters were updated at the beginning of each school year by the School Corporation's IT Department, without a documented review or oversight process to ensure the parameters entered were accurate. Additionally, there was no review process in place to ensure that the eligibility determinations made by the software system complied with the requirements of the programs. The lack of internal controls was a systemic issue throughout the audit period. Criteria 2 CFR 200.303 states in part: "The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in 'Standards for Internal Control in the Federal Government' issued by the Comptroller General of the United States or the 'Internal Control Integrated Framework', issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). . . ." Cause The School Corporation's management had not developed a system of internal controls to ensure the information from the free and reduced-price applications were entered into the software system correctly, that the updated software system parameters for eligibility were accurate, and that the eligibility determination made by the software complied with the program requirements. Effect Without the proper implementation of an effectively designed system of internal controls related to the free and reduced-price applications and the eligibility determination process, the internal control system cannot be capable of effectively preventing, or detecting and correcting, material noncompliance related to the Eligibility compliance requirement. Questioned Costs There were no questioned costs identified. Recommendation We recommended that management of the School Corporation design and implement a proper system of internal controls, including policies and procedures that would provide segregation of duties to ensure appropriate reviews, approvals, and oversight are taking place. Views of Responsible Officials For the views of responsible officials, refer to the Corrective Action Plan that is part of this report.
FINDING 2024-004 Subject: Child Nutrition Cluster - Procurement and Suspension and Debarment Federal Agency: Department of Agriculture Federal Programs: School Breakfast Program, National School Lunch Program Assistance Listings Numbers: 10.553, 10.555 Federal Award Numbers and Years (or Other Identifying Numbers): FY22-23, FY23-24 Pass-Through Entity: Indiana Department of Education Compliance Requirements: Procurement and Suspension and Debarment Audit Finding: Material Weakness, Other Matters Repeat Finding This is a repeat finding from the immediately prior audit report. The prior audit finding number was 2022-001. Condition and Context An effective internal control system, which would include segregation of duties, was not in place at the School Corporation in order to ensure compliance with requirements related to the grant agreement and the Procurement and Suspension and the Debarment compliance requirement. Procurement Federal regulations allow for informal procurement methods when the value of the procurement for goods or services does not exceed the simplified acquisition threshold, which is customarily set at $250,000. However, Indiana Code 5-22-8 has a more restrictive threshold of $150,000 or less for when small purchase procedures may be used. The informal process allows for methods other than the formal bid process. The informal process is divided between two methods based on thresholds: micro-purchases, typically for those purchases $10,000 or under, and small purchase procedures for those purchases above the micro-purchase threshold, but below the simplified acquisition threshold. Micro-purchases may be awarded without soliciting competitive price rate quotations. If small purchase procedures are used, then price or rate quotations must be obtained from an adequate number of qualified sources. The School Corporation did not have effective controls in place to ensure that an adequate number of price or rate quotations were obtained for all small purchases. The School Corporation did not obtain price or rate quotations from an adequate number of sources for all three vendors that were tested that met the small purchase threshold. Suspension and Debarment Prior to entering into subawards and covered transactions with the Child Nutrition Cluster (CNC) award funds, recipients are required to verify that such contractors and subrecipients are not suspended, debarred, or otherwise excluded. "Covered transactions" include, but are not limited to, contracts for goods and services awarded under a non-procurement transaction (i.e., grant agreement) that are expected to equal or exceed $25,000. The verification is to be done by checking the SAM exclusions, collecting a certification from that vendor, or adding a clause or condition to the covered transactions with that vendor. The School Corporation did not have effective controls in place to ensure that the verification was completed for all contractors prior to entering into covered transactions. The lack of internal controls and noncompliance were systemic issues throughout the audit period. Criteria 2 CFR 200.303 states in part: "The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in 'Standards for Internal Control in the Federal Government' issued by the Comptroller General of the United States or the 'Internal Control Integrated Framework', issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). . . ." 2 CFR 200.318 states in part: "(a) The non-Federal entity must have and use documented procurement procedures, consistent with State, local, and tribal laws and regulations and the standards of this section, for the acquisition of property or services required under a Federal award or subaward. The non-Federal entity's documented procurement procedures must conform to the procurement standards identified in §§ 200.317 through 200.327. . . . (i) The non-Federal entity must maintain records sufficient to detail the history of procurement. These records will include, but are not necessarily limited to, the following: Rationale for the method of procurement, selection of contract type, contractor selection or rejection, and the basis for the contract price. . . ." 2 CFR 200.320 states in part: "The non-Federal entity must have and use documented procurement procedures, consistent with the standards of this section and §§ 200.317, 200.318, and 200.319 for any of the following methods of procurement used for the acquisition of property or services required under a Federal award or sub-award. (a) Informal procurement methods. When the value of the procurement for property or services under a Federal award does not exceed the simplified acquisition threshold (SAT), as defined in § 200.1, or a lower threshold established by a non-Federal entity, formal procurement methods are not required. The non-Federal entity may use informal procurement methods to expedite the completion of its transactions and minimize the associated administrative burden and cost. The informal methods used for procurement of property or services at or below the SAT include: . . . (2) Small purchases — (i) Small purchase procedures. The acquisition of property or services, the aggregate dollar amount of which is higher than the micro-purchase threshold but does not exceed the simplified acquisition threshold. If small purchase procedures are used, price or rate quotations must be obtained from an adequate number of qualified sources as determined appropriate by the non-Federal entity. . . . Cause Management had not established a system of internal controls to ensure documentation was obtained and retained to demonstrate they had properly procured all small purchases. Management had not established a system of internal controls to ensure that the School Corporation's procedures for verifying a contractor's suspension and debarment status was followed for all contractors. Effect Without a proper design or implementation of internal controls, the internal control system cannot be capable of effectively preventing, or detecting and correcting, material noncompliance. This could result in the School Corporation overpaying for goods or services or paying a contractor who has been suspended or debarred, which would be unallowable. Questioned Costs There were no questioned costs identified. Recommendation We recommended that the School Corporation's management strengthen its system of internal controls to ensure that an adequate number of price or rate quotations are obtained for all small purchases and that suspension and debarment is verified for all covered transaction of $25,000 or more. Views of Responsible Officials For the views of responsible officials, refer to the Corrective Action Plan that is part of this report.
FINDING 2024-003 Subject: Child Nutrition Cluster - Eligibility Federal Agency: Department of Agriculture Federal Programs: School Breakfast Program, National School Lunch Program Assistance Listings Numbers: 10.553, 10.555 Federal Award Numbers and Years (or Other Identifying Numbers): FY22-23, FY23-24 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Eligibility Audit Finding: Material Weakness Condition and Context An effective internal control system, which would include segregation of duties, was not in place at the School Corporation in order to ensure compliance with requirements related to the grant agreement and the Eligibility compliance requirement. Information from free and reduced-price applications was entered into the School Corporation's school nutrition software by the Food Service Director. The software system calculated students' eligibility for free and reduced-price meals based on the parameters within the system. There was no documented oversight, review, or approval process in place to ensure information from the applications was entered into the system correctly. The system parameters were updated at the beginning of each school year by the School Corporation's IT Department, without a documented review or oversight process to ensure the parameters entered were accurate. Additionally, there was no review process in place to ensure that the eligibility determinations made by the software system complied with the requirements of the programs. The lack of internal controls was a systemic issue throughout the audit period. Criteria 2 CFR 200.303 states in part: "The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in 'Standards for Internal Control in the Federal Government' issued by the Comptroller General of the United States or the 'Internal Control Integrated Framework', issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). . . ." Cause The School Corporation's management had not developed a system of internal controls to ensure the information from the free and reduced-price applications were entered into the software system correctly, that the updated software system parameters for eligibility were accurate, and that the eligibility determination made by the software complied with the program requirements. Effect Without the proper implementation of an effectively designed system of internal controls related to the free and reduced-price applications and the eligibility determination process, the internal control system cannot be capable of effectively preventing, or detecting and correcting, material noncompliance related to the Eligibility compliance requirement. Questioned Costs There were no questioned costs identified. Recommendation We recommended that management of the School Corporation design and implement a proper system of internal controls, including policies and procedures that would provide segregation of duties to ensure appropriate reviews, approvals, and oversight are taking place. Views of Responsible Officials For the views of responsible officials, refer to the Corrective Action Plan that is part of this report.
FINDING 2024-004 Subject: Child Nutrition Cluster - Procurement and Suspension and Debarment Federal Agency: Department of Agriculture Federal Programs: School Breakfast Program, National School Lunch Program Assistance Listings Numbers: 10.553, 10.555 Federal Award Numbers and Years (or Other Identifying Numbers): FY22-23, FY23-24 Pass-Through Entity: Indiana Department of Education Compliance Requirements: Procurement and Suspension and Debarment Audit Finding: Material Weakness, Other Matters Repeat Finding This is a repeat finding from the immediately prior audit report. The prior audit finding number was 2022-001. Condition and Context An effective internal control system, which would include segregation of duties, was not in place at the School Corporation in order to ensure compliance with requirements related to the grant agreement and the Procurement and Suspension and the Debarment compliance requirement. Procurement Federal regulations allow for informal procurement methods when the value of the procurement for goods or services does not exceed the simplified acquisition threshold, which is customarily set at $250,000. However, Indiana Code 5-22-8 has a more restrictive threshold of $150,000 or less for when small purchase procedures may be used. The informal process allows for methods other than the formal bid process. The informal process is divided between two methods based on thresholds: micro-purchases, typically for those purchases $10,000 or under, and small purchase procedures for those purchases above the micro-purchase threshold, but below the simplified acquisition threshold. Micro-purchases may be awarded without soliciting competitive price rate quotations. If small purchase procedures are used, then price or rate quotations must be obtained from an adequate number of qualified sources. The School Corporation did not have effective controls in place to ensure that an adequate number of price or rate quotations were obtained for all small purchases. The School Corporation did not obtain price or rate quotations from an adequate number of sources for all three vendors that were tested that met the small purchase threshold. Suspension and Debarment Prior to entering into subawards and covered transactions with the Child Nutrition Cluster (CNC) award funds, recipients are required to verify that such contractors and subrecipients are not suspended, debarred, or otherwise excluded. "Covered transactions" include, but are not limited to, contracts for goods and services awarded under a non-procurement transaction (i.e., grant agreement) that are expected to equal or exceed $25,000. The verification is to be done by checking the SAM exclusions, collecting a certification from that vendor, or adding a clause or condition to the covered transactions with that vendor. The School Corporation did not have effective controls in place to ensure that the verification was completed for all contractors prior to entering into covered transactions. The lack of internal controls and noncompliance were systemic issues throughout the audit period. Criteria 2 CFR 200.303 states in part: "The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in 'Standards for Internal Control in the Federal Government' issued by the Comptroller General of the United States or the 'Internal Control Integrated Framework', issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). . . ." 2 CFR 200.318 states in part: "(a) The non-Federal entity must have and use documented procurement procedures, consistent with State, local, and tribal laws and regulations and the standards of this section, for the acquisition of property or services required under a Federal award or subaward. The non-Federal entity's documented procurement procedures must conform to the procurement standards identified in §§ 200.317 through 200.327. . . . (i) The non-Federal entity must maintain records sufficient to detail the history of procurement. These records will include, but are not necessarily limited to, the following: Rationale for the method of procurement, selection of contract type, contractor selection or rejection, and the basis for the contract price. . . ." 2 CFR 200.320 states in part: "The non-Federal entity must have and use documented procurement procedures, consistent with the standards of this section and §§ 200.317, 200.318, and 200.319 for any of the following methods of procurement used for the acquisition of property or services required under a Federal award or sub-award. (a) Informal procurement methods. When the value of the procurement for property or services under a Federal award does not exceed the simplified acquisition threshold (SAT), as defined in § 200.1, or a lower threshold established by a non-Federal entity, formal procurement methods are not required. The non-Federal entity may use informal procurement methods to expedite the completion of its transactions and minimize the associated administrative burden and cost. The informal methods used for procurement of property or services at or below the SAT include: . . . (2) Small purchases — (i) Small purchase procedures. The acquisition of property or services, the aggregate dollar amount of which is higher than the micro-purchase threshold but does not exceed the simplified acquisition threshold. If small purchase procedures are used, price or rate quotations must be obtained from an adequate number of qualified sources as determined appropriate by the non-Federal entity. . . . Cause Management had not established a system of internal controls to ensure documentation was obtained and retained to demonstrate they had properly procured all small purchases. Management had not established a system of internal controls to ensure that the School Corporation's procedures for verifying a contractor's suspension and debarment status was followed for all contractors. Effect Without a proper design or implementation of internal controls, the internal control system cannot be capable of effectively preventing, or detecting and correcting, material noncompliance. This could result in the School Corporation overpaying for goods or services or paying a contractor who has been suspended or debarred, which would be unallowable. Questioned Costs There were no questioned costs identified. Recommendation We recommended that the School Corporation's management strengthen its system of internal controls to ensure that an adequate number of price or rate quotations are obtained for all small purchases and that suspension and debarment is verified for all covered transaction of $25,000 or more. Views of Responsible Officials For the views of responsible officials, refer to the Corrective Action Plan that is part of this report.
FINDING 2024-003 Subject: Child Nutrition Cluster - Eligibility Federal Agency: Department of Agriculture Federal Programs: School Breakfast Program, National School Lunch Program Assistance Listings Numbers: 10.553, 10.555 Federal Award Numbers and Years (or Other Identifying Numbers): FY22-23, FY23-24 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Eligibility Audit Finding: Material Weakness Condition and Context An effective internal control system, which would include segregation of duties, was not in place at the School Corporation in order to ensure compliance with requirements related to the grant agreement and the Eligibility compliance requirement. Information from free and reduced-price applications was entered into the School Corporation's school nutrition software by the Food Service Director. The software system calculated students' eligibility for free and reduced-price meals based on the parameters within the system. There was no documented oversight, review, or approval process in place to ensure information from the applications was entered into the system correctly. The system parameters were updated at the beginning of each school year by the School Corporation's IT Department, without a documented review or oversight process to ensure the parameters entered were accurate. Additionally, there was no review process in place to ensure that the eligibility determinations made by the software system complied with the requirements of the programs. The lack of internal controls was a systemic issue throughout the audit period. Criteria 2 CFR 200.303 states in part: "The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in 'Standards for Internal Control in the Federal Government' issued by the Comptroller General of the United States or the 'Internal Control Integrated Framework', issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). . . ." Cause The School Corporation's management had not developed a system of internal controls to ensure the information from the free and reduced-price applications were entered into the software system correctly, that the updated software system parameters for eligibility were accurate, and that the eligibility determination made by the software complied with the program requirements. Effect Without the proper implementation of an effectively designed system of internal controls related to the free and reduced-price applications and the eligibility determination process, the internal control system cannot be capable of effectively preventing, or detecting and correcting, material noncompliance related to the Eligibility compliance requirement. Questioned Costs There were no questioned costs identified. Recommendation We recommended that management of the School Corporation design and implement a proper system of internal controls, including policies and procedures that would provide segregation of duties to ensure appropriate reviews, approvals, and oversight are taking place. Views of Responsible Officials For the views of responsible officials, refer to the Corrective Action Plan that is part of this report.
FINDING 2024-004 Subject: Child Nutrition Cluster - Procurement and Suspension and Debarment Federal Agency: Department of Agriculture Federal Programs: School Breakfast Program, National School Lunch Program Assistance Listings Numbers: 10.553, 10.555 Federal Award Numbers and Years (or Other Identifying Numbers): FY22-23, FY23-24 Pass-Through Entity: Indiana Department of Education Compliance Requirements: Procurement and Suspension and Debarment Audit Finding: Material Weakness, Other Matters Repeat Finding This is a repeat finding from the immediately prior audit report. The prior audit finding number was 2022-001. Condition and Context An effective internal control system, which would include segregation of duties, was not in place at the School Corporation in order to ensure compliance with requirements related to the grant agreement and the Procurement and Suspension and the Debarment compliance requirement. Procurement Federal regulations allow for informal procurement methods when the value of the procurement for goods or services does not exceed the simplified acquisition threshold, which is customarily set at $250,000. However, Indiana Code 5-22-8 has a more restrictive threshold of $150,000 or less for when small purchase procedures may be used. The informal process allows for methods other than the formal bid process. The informal process is divided between two methods based on thresholds: micro-purchases, typically for those purchases $10,000 or under, and small purchase procedures for those purchases above the micro-purchase threshold, but below the simplified acquisition threshold. Micro-purchases may be awarded without soliciting competitive price rate quotations. If small purchase procedures are used, then price or rate quotations must be obtained from an adequate number of qualified sources. The School Corporation did not have effective controls in place to ensure that an adequate number of price or rate quotations were obtained for all small purchases. The School Corporation did not obtain price or rate quotations from an adequate number of sources for all three vendors that were tested that met the small purchase threshold. Suspension and Debarment Prior to entering into subawards and covered transactions with the Child Nutrition Cluster (CNC) award funds, recipients are required to verify that such contractors and subrecipients are not suspended, debarred, or otherwise excluded. "Covered transactions" include, but are not limited to, contracts for goods and services awarded under a non-procurement transaction (i.e., grant agreement) that are expected to equal or exceed $25,000. The verification is to be done by checking the SAM exclusions, collecting a certification from that vendor, or adding a clause or condition to the covered transactions with that vendor. The School Corporation did not have effective controls in place to ensure that the verification was completed for all contractors prior to entering into covered transactions. The lack of internal controls and noncompliance were systemic issues throughout the audit period. Criteria 2 CFR 200.303 states in part: "The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in 'Standards for Internal Control in the Federal Government' issued by the Comptroller General of the United States or the 'Internal Control Integrated Framework', issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). . . ." 2 CFR 200.318 states in part: "(a) The non-Federal entity must have and use documented procurement procedures, consistent with State, local, and tribal laws and regulations and the standards of this section, for the acquisition of property or services required under a Federal award or subaward. The non-Federal entity's documented procurement procedures must conform to the procurement standards identified in §§ 200.317 through 200.327. . . . (i) The non-Federal entity must maintain records sufficient to detail the history of procurement. These records will include, but are not necessarily limited to, the following: Rationale for the method of procurement, selection of contract type, contractor selection or rejection, and the basis for the contract price. . . ." 2 CFR 200.320 states in part: "The non-Federal entity must have and use documented procurement procedures, consistent with the standards of this section and §§ 200.317, 200.318, and 200.319 for any of the following methods of procurement used for the acquisition of property or services required under a Federal award or sub-award. (a) Informal procurement methods. When the value of the procurement for property or services under a Federal award does not exceed the simplified acquisition threshold (SAT), as defined in § 200.1, or a lower threshold established by a non-Federal entity, formal procurement methods are not required. The non-Federal entity may use informal procurement methods to expedite the completion of its transactions and minimize the associated administrative burden and cost. The informal methods used for procurement of property or services at or below the SAT include: . . . (2) Small purchases — (i) Small purchase procedures. The acquisition of property or services, the aggregate dollar amount of which is higher than the micro-purchase threshold but does not exceed the simplified acquisition threshold. If small purchase procedures are used, price or rate quotations must be obtained from an adequate number of qualified sources as determined appropriate by the non-Federal entity. . . . Cause Management had not established a system of internal controls to ensure documentation was obtained and retained to demonstrate they had properly procured all small purchases. Management had not established a system of internal controls to ensure that the School Corporation's procedures for verifying a contractor's suspension and debarment status was followed for all contractors. Effect Without a proper design or implementation of internal controls, the internal control system cannot be capable of effectively preventing, or detecting and correcting, material noncompliance. This could result in the School Corporation overpaying for goods or services or paying a contractor who has been suspended or debarred, which would be unallowable. Questioned Costs There were no questioned costs identified. Recommendation We recommended that the School Corporation's management strengthen its system of internal controls to ensure that an adequate number of price or rate quotations are obtained for all small purchases and that suspension and debarment is verified for all covered transaction of $25,000 or more. Views of Responsible Officials For the views of responsible officials, refer to the Corrective Action Plan that is part of this report.
FINDING 2024-003 Subject: Child Nutrition Cluster - Eligibility Federal Agency: Department of Agriculture Federal Programs: School Breakfast Program, National School Lunch Program Assistance Listings Numbers: 10.553, 10.555 Federal Award Numbers and Years (or Other Identifying Numbers): FY22-23, FY23-24 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Eligibility Audit Finding: Material Weakness Condition and Context An effective internal control system, which would include segregation of duties, was not in place at the School Corporation in order to ensure compliance with requirements related to the grant agreement and the Eligibility compliance requirement. Information from free and reduced-price applications was entered into the School Corporation's school nutrition software by the Food Service Director. The software system calculated students' eligibility for free and reduced-price meals based on the parameters within the system. There was no documented oversight, review, or approval process in place to ensure information from the applications was entered into the system correctly. The system parameters were updated at the beginning of each school year by the School Corporation's IT Department, without a documented review or oversight process to ensure the parameters entered were accurate. Additionally, there was no review process in place to ensure that the eligibility determinations made by the software system complied with the requirements of the programs. The lack of internal controls was a systemic issue throughout the audit period. Criteria 2 CFR 200.303 states in part: "The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in 'Standards for Internal Control in the Federal Government' issued by the Comptroller General of the United States or the 'Internal Control Integrated Framework', issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). . . ." Cause The School Corporation's management had not developed a system of internal controls to ensure the information from the free and reduced-price applications were entered into the software system correctly, that the updated software system parameters for eligibility were accurate, and that the eligibility determination made by the software complied with the program requirements. Effect Without the proper implementation of an effectively designed system of internal controls related to the free and reduced-price applications and the eligibility determination process, the internal control system cannot be capable of effectively preventing, or detecting and correcting, material noncompliance related to the Eligibility compliance requirement. Questioned Costs There were no questioned costs identified. Recommendation We recommended that management of the School Corporation design and implement a proper system of internal controls, including policies and procedures that would provide segregation of duties to ensure appropriate reviews, approvals, and oversight are taking place. Views of Responsible Officials For the views of responsible officials, refer to the Corrective Action Plan that is part of this report.
FINDING 2024-004 Subject: Child Nutrition Cluster - Procurement and Suspension and Debarment Federal Agency: Department of Agriculture Federal Programs: School Breakfast Program, National School Lunch Program Assistance Listings Numbers: 10.553, 10.555 Federal Award Numbers and Years (or Other Identifying Numbers): FY22-23, FY23-24 Pass-Through Entity: Indiana Department of Education Compliance Requirements: Procurement and Suspension and Debarment Audit Finding: Material Weakness, Other Matters Repeat Finding This is a repeat finding from the immediately prior audit report. The prior audit finding number was 2022-001. Condition and Context An effective internal control system, which would include segregation of duties, was not in place at the School Corporation in order to ensure compliance with requirements related to the grant agreement and the Procurement and Suspension and the Debarment compliance requirement. Procurement Federal regulations allow for informal procurement methods when the value of the procurement for goods or services does not exceed the simplified acquisition threshold, which is customarily set at $250,000. However, Indiana Code 5-22-8 has a more restrictive threshold of $150,000 or less for when small purchase procedures may be used. The informal process allows for methods other than the formal bid process. The informal process is divided between two methods based on thresholds: micro-purchases, typically for those purchases $10,000 or under, and small purchase procedures for those purchases above the micro-purchase threshold, but below the simplified acquisition threshold. Micro-purchases may be awarded without soliciting competitive price rate quotations. If small purchase procedures are used, then price or rate quotations must be obtained from an adequate number of qualified sources. The School Corporation did not have effective controls in place to ensure that an adequate number of price or rate quotations were obtained for all small purchases. The School Corporation did not obtain price or rate quotations from an adequate number of sources for all three vendors that were tested that met the small purchase threshold. Suspension and Debarment Prior to entering into subawards and covered transactions with the Child Nutrition Cluster (CNC) award funds, recipients are required to verify that such contractors and subrecipients are not suspended, debarred, or otherwise excluded. "Covered transactions" include, but are not limited to, contracts for goods and services awarded under a non-procurement transaction (i.e., grant agreement) that are expected to equal or exceed $25,000. The verification is to be done by checking the SAM exclusions, collecting a certification from that vendor, or adding a clause or condition to the covered transactions with that vendor. The School Corporation did not have effective controls in place to ensure that the verification was completed for all contractors prior to entering into covered transactions. The lack of internal controls and noncompliance were systemic issues throughout the audit period. Criteria 2 CFR 200.303 states in part: "The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in 'Standards for Internal Control in the Federal Government' issued by the Comptroller General of the United States or the 'Internal Control Integrated Framework', issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). . . ." 2 CFR 200.318 states in part: "(a) The non-Federal entity must have and use documented procurement procedures, consistent with State, local, and tribal laws and regulations and the standards of this section, for the acquisition of property or services required under a Federal award or subaward. The non-Federal entity's documented procurement procedures must conform to the procurement standards identified in §§ 200.317 through 200.327. . . . (i) The non-Federal entity must maintain records sufficient to detail the history of procurement. These records will include, but are not necessarily limited to, the following: Rationale for the method of procurement, selection of contract type, contractor selection or rejection, and the basis for the contract price. . . ." 2 CFR 200.320 states in part: "The non-Federal entity must have and use documented procurement procedures, consistent with the standards of this section and §§ 200.317, 200.318, and 200.319 for any of the following methods of procurement used for the acquisition of property or services required under a Federal award or sub-award. (a) Informal procurement methods. When the value of the procurement for property or services under a Federal award does not exceed the simplified acquisition threshold (SAT), as defined in § 200.1, or a lower threshold established by a non-Federal entity, formal procurement methods are not required. The non-Federal entity may use informal procurement methods to expedite the completion of its transactions and minimize the associated administrative burden and cost. The informal methods used for procurement of property or services at or below the SAT include: . . . (2) Small purchases — (i) Small purchase procedures. The acquisition of property or services, the aggregate dollar amount of which is higher than the micro-purchase threshold but does not exceed the simplified acquisition threshold. If small purchase procedures are used, price or rate quotations must be obtained from an adequate number of qualified sources as determined appropriate by the non-Federal entity. . . . Cause Management had not established a system of internal controls to ensure documentation was obtained and retained to demonstrate they had properly procured all small purchases. Management had not established a system of internal controls to ensure that the School Corporation's procedures for verifying a contractor's suspension and debarment status was followed for all contractors. Effect Without a proper design or implementation of internal controls, the internal control system cannot be capable of effectively preventing, or detecting and correcting, material noncompliance. This could result in the School Corporation overpaying for goods or services or paying a contractor who has been suspended or debarred, which would be unallowable. Questioned Costs There were no questioned costs identified. Recommendation We recommended that the School Corporation's management strengthen its system of internal controls to ensure that an adequate number of price or rate quotations are obtained for all small purchases and that suspension and debarment is verified for all covered transaction of $25,000 or more. Views of Responsible Officials For the views of responsible officials, refer to the Corrective Action Plan that is part of this report.
FINDING 2024-002 Subject: COVID-19 - Education Stabilization Fund - Reporting Federal Agency: Department of Education Federal Program: COVID-19 - Education Stabilization Fund Assistance Listings Numbers: 84.425D, 84.425U Federal Award Numbers and Years (or Other Identifying Numbers): S425D210013, S425U210013 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Reporting Audit Findings: Material Weakness, Other Matters Condition and Context An effective internal control system was not designed or implemented at the School Corporation to ensure compliance with requirements related to the grant agreement and the Reporting compliance requirement. The School Corporation had not designed, nor implemented, a system of internal controls to ensure that the annual Elementary and Secondary School Emergency Relief (ESSER) Data Collection reports (Reports) were complete and accurately submitted. The Reports were prepared and submitted by one employee without a documented oversight, review, or approval process in place to prevent, or detect and correct, errors. Due to the lack of effective internal controls, one of the four reports submitted during the audit period was not supported by the School Corporation's records. The following error was noted: For the ESSER III, Year 3 Report, which covered the period July 1, 2022 to June 30, 2023, total expenses reported for Property: Addressing Physical Health and Safety - Mandatory Subgrant funds was $236,023. Total expenses reported for Personnel Services: Meeting Student's Academic, Social, Emotional, and Other Needs was $66,387, for a total of $302,410. This was an overstatement of $271,004. The lack of internal controls was a systemic issue throughout the audit period. Noncompliance was isolated to the ESSER III, Year 3 Report. Criteria 2 CFR 200.303 states in part: "The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in 'Standards for Internal Control in the Federal Government' issued by the Comptroller General of the United States or the 'Internal Control Integrated Framework', issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). . . ." 2 CFR 200.334 states in part: "Financial records, supporting documents, statistical records, and all other non-Federal entity records pertinent to a Federal award must be retained for a period of three years from the date of submission of the final expenditure report or, for the Federal awards that are renewed quarterly or annual, from the date of submission of the quarterly or annual financial report, respectively, as reported to the Federal awarding agency or pass-through entity in the case of a subrecipient. . . ." 2 CFR 200.302(b) states in part: "The financial management system of each non-Federal entity must provide for the following . . . (2) Accurate, current, and complete disclosure of the financial results of each Federal award or program in accordance with the reporting requirements set forth in §§ 200.328 and 200.329. . . ." 34 CFR 76.722 states: "A State may require a subgrantee to submit reports in a manner and format that assists the State in complying with the requirements under 34 CFR 76.720 and in carrying out other responsibilities under the program." Cause A proper system of internal controls was not designed by management of the School Corporation. Two employees collaborated on the preparation of the reports, but there was no documented review of the completed reports by someone other than the preparers to detect errors prior to submission. Effect Without the proper implementation of an effectively designed system of internal controls, the internal control system cannot be capable of effectively preventing, or detecting and correcting, material noncompliance. As a result, the ESSER III, Year 3 Report was not supported by the School Corporation's records. Questioned Costs There were no questioned costs identified. Recommendation We recommended that management of the School Corporation establish a proper system of internal controls and develop policies and procedures to ensure that all reports are supported by the School Corporation's records. Views of Responsible Officials For the views of responsible officials, refer to the Corrective Action Plan that is part of this report.
FINDING 2024-002 Subject: COVID-19 - Education Stabilization Fund - Reporting Federal Agency: Department of Education Federal Program: COVID-19 - Education Stabilization Fund Assistance Listings Numbers: 84.425D, 84.425U Federal Award Numbers and Years (or Other Identifying Numbers): S425D210013, S425U210013 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Reporting Audit Findings: Material Weakness, Other Matters Condition and Context An effective internal control system was not designed or implemented at the School Corporation to ensure compliance with requirements related to the grant agreement and the Reporting compliance requirement. The School Corporation had not designed, nor implemented, a system of internal controls to ensure that the annual Elementary and Secondary School Emergency Relief (ESSER) Data Collection reports (Reports) were complete and accurately submitted. The Reports were prepared and submitted by one employee without a documented oversight, review, or approval process in place to prevent, or detect and correct, errors. Due to the lack of effective internal controls, one of the four reports submitted during the audit period was not supported by the School Corporation's records. The following error was noted: For the ESSER III, Year 3 Report, which covered the period July 1, 2022 to June 30, 2023, total expenses reported for Property: Addressing Physical Health and Safety - Mandatory Subgrant funds was $236,023. Total expenses reported for Personnel Services: Meeting Student's Academic, Social, Emotional, and Other Needs was $66,387, for a total of $302,410. This was an overstatement of $271,004. The lack of internal controls was a systemic issue throughout the audit period. Noncompliance was isolated to the ESSER III, Year 3 Report. Criteria 2 CFR 200.303 states in part: "The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in 'Standards for Internal Control in the Federal Government' issued by the Comptroller General of the United States or the 'Internal Control Integrated Framework', issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). . . ." 2 CFR 200.334 states in part: "Financial records, supporting documents, statistical records, and all other non-Federal entity records pertinent to a Federal award must be retained for a period of three years from the date of submission of the final expenditure report or, for the Federal awards that are renewed quarterly or annual, from the date of submission of the quarterly or annual financial report, respectively, as reported to the Federal awarding agency or pass-through entity in the case of a subrecipient. . . ." 2 CFR 200.302(b) states in part: "The financial management system of each non-Federal entity must provide for the following . . . (2) Accurate, current, and complete disclosure of the financial results of each Federal award or program in accordance with the reporting requirements set forth in §§ 200.328 and 200.329. . . ." 34 CFR 76.722 states: "A State may require a subgrantee to submit reports in a manner and format that assists the State in complying with the requirements under 34 CFR 76.720 and in carrying out other responsibilities under the program." Cause A proper system of internal controls was not designed by management of the School Corporation. Two employees collaborated on the preparation of the reports, but there was no documented review of the completed reports by someone other than the preparers to detect errors prior to submission. Effect Without the proper implementation of an effectively designed system of internal controls, the internal control system cannot be capable of effectively preventing, or detecting and correcting, material noncompliance. As a result, the ESSER III, Year 3 Report was not supported by the School Corporation's records. Questioned Costs There were no questioned costs identified. Recommendation We recommended that management of the School Corporation establish a proper system of internal controls and develop policies and procedures to ensure that all reports are supported by the School Corporation's records. Views of Responsible Officials For the views of responsible officials, refer to the Corrective Action Plan that is part of this report.
FINDING 2024-002 Subject: COVID-19 - Education Stabilization Fund - Reporting Federal Agency: Department of Education Federal Program: COVID-19 - Education Stabilization Fund Assistance Listings Numbers: 84.425D, 84.425U Federal Award Numbers and Years (or Other Identifying Numbers): S425D210013, S425U210013 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Reporting Audit Findings: Material Weakness, Other Matters Condition and Context An effective internal control system was not designed or implemented at the School Corporation to ensure compliance with requirements related to the grant agreement and the Reporting compliance requirement. The School Corporation had not designed, nor implemented, a system of internal controls to ensure that the annual Elementary and Secondary School Emergency Relief (ESSER) Data Collection reports (Reports) were complete and accurately submitted. The Reports were prepared and submitted by one employee without a documented oversight, review, or approval process in place to prevent, or detect and correct, errors. Due to the lack of effective internal controls, one of the four reports submitted during the audit period was not supported by the School Corporation's records. The following error was noted: For the ESSER III, Year 3 Report, which covered the period July 1, 2022 to June 30, 2023, total expenses reported for Property: Addressing Physical Health and Safety - Mandatory Subgrant funds was $236,023. Total expenses reported for Personnel Services: Meeting Student's Academic, Social, Emotional, and Other Needs was $66,387, for a total of $302,410. This was an overstatement of $271,004. The lack of internal controls was a systemic issue throughout the audit period. Noncompliance was isolated to the ESSER III, Year 3 Report. Criteria 2 CFR 200.303 states in part: "The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in 'Standards for Internal Control in the Federal Government' issued by the Comptroller General of the United States or the 'Internal Control Integrated Framework', issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). . . ." 2 CFR 200.334 states in part: "Financial records, supporting documents, statistical records, and all other non-Federal entity records pertinent to a Federal award must be retained for a period of three years from the date of submission of the final expenditure report or, for the Federal awards that are renewed quarterly or annual, from the date of submission of the quarterly or annual financial report, respectively, as reported to the Federal awarding agency or pass-through entity in the case of a subrecipient. . . ." 2 CFR 200.302(b) states in part: "The financial management system of each non-Federal entity must provide for the following . . . (2) Accurate, current, and complete disclosure of the financial results of each Federal award or program in accordance with the reporting requirements set forth in §§ 200.328 and 200.329. . . ." 34 CFR 76.722 states: "A State may require a subgrantee to submit reports in a manner and format that assists the State in complying with the requirements under 34 CFR 76.720 and in carrying out other responsibilities under the program." Cause A proper system of internal controls was not designed by management of the School Corporation. Two employees collaborated on the preparation of the reports, but there was no documented review of the completed reports by someone other than the preparers to detect errors prior to submission. Effect Without the proper implementation of an effectively designed system of internal controls, the internal control system cannot be capable of effectively preventing, or detecting and correcting, material noncompliance. As a result, the ESSER III, Year 3 Report was not supported by the School Corporation's records. Questioned Costs There were no questioned costs identified. Recommendation We recommended that management of the School Corporation establish a proper system of internal controls and develop policies and procedures to ensure that all reports are supported by the School Corporation's records. Views of Responsible Officials For the views of responsible officials, refer to the Corrective Action Plan that is part of this report.
FINDING 2024-002 Subject: COVID-19 - Education Stabilization Fund - Reporting Federal Agency: Department of Education Federal Program: COVID-19 - Education Stabilization Fund Assistance Listings Numbers: 84.425D, 84.425U Federal Award Numbers and Years (or Other Identifying Numbers): S425D210013, S425U210013 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Reporting Audit Findings: Material Weakness, Other Matters Condition and Context An effective internal control system was not designed or implemented at the School Corporation to ensure compliance with requirements related to the grant agreement and the Reporting compliance requirement. The School Corporation had not designed, nor implemented, a system of internal controls to ensure that the annual Elementary and Secondary School Emergency Relief (ESSER) Data Collection reports (Reports) were complete and accurately submitted. The Reports were prepared and submitted by one employee without a documented oversight, review, or approval process in place to prevent, or detect and correct, errors. Due to the lack of effective internal controls, one of the four reports submitted during the audit period was not supported by the School Corporation's records. The following error was noted: For the ESSER III, Year 3 Report, which covered the period July 1, 2022 to June 30, 2023, total expenses reported for Property: Addressing Physical Health and Safety - Mandatory Subgrant funds was $236,023. Total expenses reported for Personnel Services: Meeting Student's Academic, Social, Emotional, and Other Needs was $66,387, for a total of $302,410. This was an overstatement of $271,004. The lack of internal controls was a systemic issue throughout the audit period. Noncompliance was isolated to the ESSER III, Year 3 Report. Criteria 2 CFR 200.303 states in part: "The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in 'Standards for Internal Control in the Federal Government' issued by the Comptroller General of the United States or the 'Internal Control Integrated Framework', issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). . . ." 2 CFR 200.334 states in part: "Financial records, supporting documents, statistical records, and all other non-Federal entity records pertinent to a Federal award must be retained for a period of three years from the date of submission of the final expenditure report or, for the Federal awards that are renewed quarterly or annual, from the date of submission of the quarterly or annual financial report, respectively, as reported to the Federal awarding agency or pass-through entity in the case of a subrecipient. . . ." 2 CFR 200.302(b) states in part: "The financial management system of each non-Federal entity must provide for the following . . . (2) Accurate, current, and complete disclosure of the financial results of each Federal award or program in accordance with the reporting requirements set forth in §§ 200.328 and 200.329. . . ." 34 CFR 76.722 states: "A State may require a subgrantee to submit reports in a manner and format that assists the State in complying with the requirements under 34 CFR 76.720 and in carrying out other responsibilities under the program." Cause A proper system of internal controls was not designed by management of the School Corporation. Two employees collaborated on the preparation of the reports, but there was no documented review of the completed reports by someone other than the preparers to detect errors prior to submission. Effect Without the proper implementation of an effectively designed system of internal controls, the internal control system cannot be capable of effectively preventing, or detecting and correcting, material noncompliance. As a result, the ESSER III, Year 3 Report was not supported by the School Corporation's records. Questioned Costs There were no questioned costs identified. Recommendation We recommended that management of the School Corporation establish a proper system of internal controls and develop policies and procedures to ensure that all reports are supported by the School Corporation's records. Views of Responsible Officials For the views of responsible officials, refer to the Corrective Action Plan that is part of this report.
Criteria: In accordance with 34 CFR Section 668.173 (b) and 2 CFR 200.303, the institutional portion of unearned aid must be returned to the appropriate Title IV, HEA program or Federal Family Education Loan (“FFEL”) lender no later than 45 days after the date of the institution’s determination that the student withdrew. Furthermore, the institution must determine the amount of Title IV grant or loan assistance that the student earned as of the student’s withdrawal date. The Compliance Supplement issued by the Office of Management and Budget requires auditors to review the return of Title IV funds determinations/calculations for conformity with Title IV requirements. Furthermore, according to 34 CFR 668.22, all grant funds relating to post-withdrawal disbursements that are not disbursed to the student’s account, must be disbursed to the student no later than 180 days after the date of the institution’s determination that the student withdrew. Condition: It was noted during our testing of R2T4 calculations that two of 40 students selected for testing had instances of non-compliance. Specifically, one student’s return was not received within the 45-day time limit and one student’s return was not calculated correctly. Questioned Costs: $1,886 Context: During our audit procedures, we noted below instances for R2T4 testing: - One of the 40 total students’ return was not returned within the 45-days requirement. - One of the 40 total student’s R2T4 was incorrectly calculated, resulting in $1,866 in excess funds being returned by the University. Cause: The University implemented controls during the year to improve compliance with Title IV regulations, resulting in a significant reduction in the number of instances of noncompliance (from seven in prior year to one in the current year). Due to the timing of the implementation of these controls, instances of noncompliance with Title IV regulations were still identified. Effect: The cause identified resulted in noncompliance with Title IV regulations. Repeat Finding: Yes, see Finding 2023-001. Recommendation: We recommend that the University improve the existing procedures and controls to ensure compliance with the aforementioned criteria. Views of responsible officials: Management concurs with the finding.
Criteria: In accordance with 34 CFR Section 668.173 (b) and 2 CFR 200.303, the institutional portion of unearned aid must be returned to the appropriate Title IV, HEA program or Federal Family Education Loan (“FFEL”) lender no later than 45 days after the date of the institution’s determination that the student withdrew. Furthermore, the institution must determine the amount of Title IV grant or loan assistance that the student earned as of the student’s withdrawal date. The Compliance Supplement issued by the Office of Management and Budget requires auditors to review the return of Title IV funds determinations/calculations for conformity with Title IV requirements. Furthermore, according to 34 CFR 668.22, all grant funds relating to post-withdrawal disbursements that are not disbursed to the student’s account, must be disbursed to the student no later than 180 days after the date of the institution’s determination that the student withdrew. Condition: It was noted during our testing of R2T4 calculations that two of 40 students selected for testing had instances of non-compliance. Specifically, one student’s return was not received within the 45-day time limit and one student’s return was not calculated correctly. Questioned Costs: $1,886 Context: During our audit procedures, we noted below instances for R2T4 testing: - One of the 40 total students’ return was not returned within the 45-days requirement. - One of the 40 total student’s R2T4 was incorrectly calculated, resulting in $1,866 in excess funds being returned by the University. Cause: The University implemented controls during the year to improve compliance with Title IV regulations, resulting in a significant reduction in the number of instances of noncompliance (from seven in prior year to one in the current year). Due to the timing of the implementation of these controls, instances of noncompliance with Title IV regulations were still identified. Effect: The cause identified resulted in noncompliance with Title IV regulations. Repeat Finding: Yes, see Finding 2023-001. Recommendation: We recommend that the University improve the existing procedures and controls to ensure compliance with the aforementioned criteria. Views of responsible officials: Management concurs with the finding.
Criteria: In accordance with 34 CFR Section 668.173 (b) and 2 CFR 200.303, the institutional portion of unearned aid must be returned to the appropriate Title IV, HEA program or Federal Family Education Loan (“FFEL”) lender no later than 45 days after the date of the institution’s determination that the student withdrew. Furthermore, the institution must determine the amount of Title IV grant or loan assistance that the student earned as of the student’s withdrawal date. The Compliance Supplement issued by the Office of Management and Budget requires auditors to review the return of Title IV funds determinations/calculations for conformity with Title IV requirements. Furthermore, according to 34 CFR 668.22, all grant funds relating to post-withdrawal disbursements that are not disbursed to the student’s account, must be disbursed to the student no later than 180 days after the date of the institution’s determination that the student withdrew. Condition: It was noted during our testing of R2T4 calculations that two of 40 students selected for testing had instances of non-compliance. Specifically, one student’s return was not received within the 45-day time limit and one student’s return was not calculated correctly. Questioned Costs: $1,886 Context: During our audit procedures, we noted below instances for R2T4 testing: - One of the 40 total students’ return was not returned within the 45-days requirement. - One of the 40 total student’s R2T4 was incorrectly calculated, resulting in $1,866 in excess funds being returned by the University. Cause: The University implemented controls during the year to improve compliance with Title IV regulations, resulting in a significant reduction in the number of instances of noncompliance (from seven in prior year to one in the current year). Due to the timing of the implementation of these controls, instances of noncompliance with Title IV regulations were still identified. Effect: The cause identified resulted in noncompliance with Title IV regulations. Repeat Finding: Yes, see Finding 2023-001. Recommendation: We recommend that the University improve the existing procedures and controls to ensure compliance with the aforementioned criteria. Views of responsible officials: Management concurs with the finding.
Criteria: In accordance with 34 CFR Section 668.173 (b) and 2 CFR 200.303, the institutional portion of unearned aid must be returned to the appropriate Title IV, HEA program or Federal Family Education Loan (“FFEL”) lender no later than 45 days after the date of the institution’s determination that the student withdrew. Furthermore, the institution must determine the amount of Title IV grant or loan assistance that the student earned as of the student’s withdrawal date. The Compliance Supplement issued by the Office of Management and Budget requires auditors to review the return of Title IV funds determinations/calculations for conformity with Title IV requirements. Furthermore, according to 34 CFR 668.22, all grant funds relating to post-withdrawal disbursements that are not disbursed to the student’s account, must be disbursed to the student no later than 180 days after the date of the institution’s determination that the student withdrew. Condition: It was noted during our testing of R2T4 calculations that two of 40 students selected for testing had instances of non-compliance. Specifically, one student’s return was not received within the 45-day time limit and one student’s return was not calculated correctly. Questioned Costs: $1,886 Context: During our audit procedures, we noted below instances for R2T4 testing: - One of the 40 total students’ return was not returned within the 45-days requirement. - One of the 40 total student’s R2T4 was incorrectly calculated, resulting in $1,866 in excess funds being returned by the University. Cause: The University implemented controls during the year to improve compliance with Title IV regulations, resulting in a significant reduction in the number of instances of noncompliance (from seven in prior year to one in the current year). Due to the timing of the implementation of these controls, instances of noncompliance with Title IV regulations were still identified. Effect: The cause identified resulted in noncompliance with Title IV regulations. Repeat Finding: Yes, see Finding 2023-001. Recommendation: We recommend that the University improve the existing procedures and controls to ensure compliance with the aforementioned criteria. Views of responsible officials: Management concurs with the finding.
Criteria: In accordance with 34 CFR Section 668.173 (b) and 2 CFR 200.303, the institutional portion of unearned aid must be returned to the appropriate Title IV, HEA program or Federal Family Education Loan (“FFEL”) lender no later than 45 days after the date of the institution’s determination that the student withdrew. Furthermore, the institution must determine the amount of Title IV grant or loan assistance that the student earned as of the student’s withdrawal date. The Compliance Supplement issued by the Office of Management and Budget requires auditors to review the return of Title IV funds determinations/calculations for conformity with Title IV requirements. Furthermore, according to 34 CFR 668.22, all grant funds relating to post-withdrawal disbursements that are not disbursed to the student’s account, must be disbursed to the student no later than 180 days after the date of the institution’s determination that the student withdrew. Condition: It was noted during our testing of R2T4 calculations that two of 40 students selected for testing had instances of non-compliance. Specifically, one student’s return was not received within the 45-day time limit and one student’s return was not calculated correctly. Questioned Costs: $1,886 Context: During our audit procedures, we noted below instances for R2T4 testing: - One of the 40 total students’ return was not returned within the 45-days requirement. - One of the 40 total student’s R2T4 was incorrectly calculated, resulting in $1,866 in excess funds being returned by the University. Cause: The University implemented controls during the year to improve compliance with Title IV regulations, resulting in a significant reduction in the number of instances of noncompliance (from seven in prior year to one in the current year). Due to the timing of the implementation of these controls, instances of noncompliance with Title IV regulations were still identified. Effect: The cause identified resulted in noncompliance with Title IV regulations. Repeat Finding: Yes, see Finding 2023-001. Recommendation: We recommend that the University improve the existing procedures and controls to ensure compliance with the aforementioned criteria. Views of responsible officials: Management concurs with the finding.
Criteria: In accordance with 34 CFR Section 668.173 (b) and 2 CFR 200.303, the institutional portion of unearned aid must be returned to the appropriate Title IV, HEA program or Federal Family Education Loan (“FFEL”) lender no later than 45 days after the date of the institution’s determination that the student withdrew. Furthermore, the institution must determine the amount of Title IV grant or loan assistance that the student earned as of the student’s withdrawal date. The Compliance Supplement issued by the Office of Management and Budget requires auditors to review the return of Title IV funds determinations/calculations for conformity with Title IV requirements. Furthermore, according to 34 CFR 668.22, all grant funds relating to post-withdrawal disbursements that are not disbursed to the student’s account, must be disbursed to the student no later than 180 days after the date of the institution’s determination that the student withdrew. Condition: It was noted during our testing of R2T4 calculations that two of 40 students selected for testing had instances of non-compliance. Specifically, one student’s return was not received within the 45-day time limit and one student’s return was not calculated correctly. Questioned Costs: $1,886 Context: During our audit procedures, we noted below instances for R2T4 testing: - One of the 40 total students’ return was not returned within the 45-days requirement. - One of the 40 total student’s R2T4 was incorrectly calculated, resulting in $1,866 in excess funds being returned by the University. Cause: The University implemented controls during the year to improve compliance with Title IV regulations, resulting in a significant reduction in the number of instances of noncompliance (from seven in prior year to one in the current year). Due to the timing of the implementation of these controls, instances of noncompliance with Title IV regulations were still identified. Effect: The cause identified resulted in noncompliance with Title IV regulations. Repeat Finding: Yes, see Finding 2023-001. Recommendation: We recommend that the University improve the existing procedures and controls to ensure compliance with the aforementioned criteria. Views of responsible officials: Management concurs with the finding.
Criteria: In accordance with 34 CFR Section 668.173 (b) and 2 CFR 200.303, the institutional portion of unearned aid must be returned to the appropriate Title IV, HEA program or Federal Family Education Loan (“FFEL”) lender no later than 45 days after the date of the institution’s determination that the student withdrew. Furthermore, the institution must determine the amount of Title IV grant or loan assistance that the student earned as of the student’s withdrawal date. The Compliance Supplement issued by the Office of Management and Budget requires auditors to review the return of Title IV funds determinations/calculations for conformity with Title IV requirements. Furthermore, according to 34 CFR 668.22, all grant funds relating to post-withdrawal disbursements that are not disbursed to the student’s account, must be disbursed to the student no later than 180 days after the date of the institution’s determination that the student withdrew. Condition: It was noted during our testing of R2T4 calculations that two of 40 students selected for testing had instances of non-compliance. Specifically, one student’s return was not received within the 45-day time limit and one student’s return was not calculated correctly. Questioned Costs: $1,886 Context: During our audit procedures, we noted below instances for R2T4 testing: - One of the 40 total students’ return was not returned within the 45-days requirement. - One of the 40 total student’s R2T4 was incorrectly calculated, resulting in $1,866 in excess funds being returned by the University. Cause: The University implemented controls during the year to improve compliance with Title IV regulations, resulting in a significant reduction in the number of instances of noncompliance (from seven in prior year to one in the current year). Due to the timing of the implementation of these controls, instances of noncompliance with Title IV regulations were still identified. Effect: The cause identified resulted in noncompliance with Title IV regulations. Repeat Finding: Yes, see Finding 2023-001. Recommendation: We recommend that the University improve the existing procedures and controls to ensure compliance with the aforementioned criteria. Views of responsible officials: Management concurs with the finding.
Criteria: In accordance with 34 CFR Section 668.173 (b) and 2 CFR 200.303, the institutional portion of unearned aid must be returned to the appropriate Title IV, HEA program or Federal Family Education Loan (“FFEL”) lender no later than 45 days after the date of the institution’s determination that the student withdrew. Furthermore, the institution must determine the amount of Title IV grant or loan assistance that the student earned as of the student’s withdrawal date. The Compliance Supplement issued by the Office of Management and Budget requires auditors to review the return of Title IV funds determinations/calculations for conformity with Title IV requirements. Furthermore, according to 34 CFR 668.22, all grant funds relating to post-withdrawal disbursements that are not disbursed to the student’s account, must be disbursed to the student no later than 180 days after the date of the institution’s determination that the student withdrew. Condition: It was noted during our testing of R2T4 calculations that two of 40 students selected for testing had instances of non-compliance. Specifically, one student’s return was not received within the 45-day time limit and one student’s return was not calculated correctly. Questioned Costs: $1,886 Context: During our audit procedures, we noted below instances for R2T4 testing: - One of the 40 total students’ return was not returned within the 45-days requirement. - One of the 40 total student’s R2T4 was incorrectly calculated, resulting in $1,866 in excess funds being returned by the University. Cause: The University implemented controls during the year to improve compliance with Title IV regulations, resulting in a significant reduction in the number of instances of noncompliance (from seven in prior year to one in the current year). Due to the timing of the implementation of these controls, instances of noncompliance with Title IV regulations were still identified. Effect: The cause identified resulted in noncompliance with Title IV regulations. Repeat Finding: Yes, see Finding 2023-001. Recommendation: We recommend that the University improve the existing procedures and controls to ensure compliance with the aforementioned criteria. Views of responsible officials: Management concurs with the finding.
Finding 2024-001 – Equipment and Real Property Management — Material Weakness Department of Health and Human Services Research and Development Cluster Department of Health and Human Services, National Institutes of Health, Assistance Listing No. 93.859 (Biomedical Research and Research Training) Federal award year 2023-2024 Criteria: Uniform Guidance (2 CFR 200.303) requires nonfederal entities receiving federal awards to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations, and program compliance requirements. Also, in accordance with 2 CFR 200.313(d)(1), property records must be maintained that included a description of the property, a serial number or other identification number, the source of funding for the property (including the federal award identification number), who holds title, the acquisition date, cost of the property, percentage of federal participation in the project costs for the federal award under which the property was acquired, the location, use and condition of the property, and any ultimate disposition data including the date of disposal and sales price of the property. In accordance with 2 CFR 200.313(d)(2), a physical inventory of equipment and property must be taken, and the results reconciled with property records at least once every two years. Condition: The University’s controls were not operating effectively to reasonably ensure the University maintained property records with the above required information and performed the required physical inventory of equipment within the two previous years. As a result, the University did not comply with the compliance requirements for equipment and real property management. Cause: The University does not have processes and procedures in place related to equipment management, tracking and required physical inventories. Effect or potential effect: The University is not in compliance with federal grant requirements over the tracking and physical inventory of equipment. Improper equipment management procedures could result in actions taken by oversight agencies which could impact future funding. Questioned costs: None Context: The University has five pieces of qualified equipment with an aggregate cost of approximately $119,000. For all sample selections tested in the major program, there was no process of tagging and tracking equipment purchased with federal funding, nor was there any evidence that physical inventories had been performed. Identification as a repeat finding, if applicable: Not applicable. Recommendation: We recommend the University develop processes and procedures to tag and track the equipment purchased with federal funding, and maintain support that physical inventories were performed as required. View of responsible officials: Management agrees with this finding. See corrective action plan.
Finding 2024-002 – Procurement and Suspension and Debarment — Material Weakness Department of Health and Human Services Research and Development Cluster Department of Health and Human Services, National Institutes of Health, Assistance Listing No. 93.859 (Biomedical Research and Research Training) Federal award year 2023-2024 Criteria: The Uniform Guidance (2 CFR 200.303) requires nonfederal entities receiving federal awards to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations, and program compliance requirements. Effective internal controls should include procedures to ensure procurement methods outline by the University are properly followed. In accordance with 2 CFR 200.320, price quotations should be obtained from an adequate number of qualified sources for procurements that meet the small purchase procurement threshold. Condition: The University’s controls were not operating effectively to reasonably ensure the University obtained the proper number of price quotations as required using the small purchase procurement method. The University’s procurement policy requires price quotations be obtained from at least two sources when using the small purchase procurement method. The University only obtained one price quotation and no written documentation as the rational for selection was maintained. As a result, the University did not comply with the compliance requirements for procurement. Cause: The University does not have processes and procedures in place to ensure all procurements of goods and services are in accordance with Uniform Guidance and in accordance with it’s own procurement policy. Effect or potential effect: The University is not in compliance with federal grant requirements over small purchase procurements. Improper procurement procedures could result in actions taken by oversight agencies which could impact future funding. Questioned costs: None Context: For all sample selections tested in the major program, one price quotation was obtained and no documentation was maintained as to the rationale for selection of the underlying vendor. Identification as a repeat finding, if applicable: Not applicable. Recommendation: We recommend the University develop processes and procedures to obtain the required number of price quotations required under the small purchase procurement method, and maintain support for the required number of price quotations received under the small purchase procurement method. View of responsible officials: Management agrees with this finding. See corrective action plan.
Finding 2024-003 – Procurement and Suspension and Debarment — Material Weakness Department of Health and Human Services Research and Development Cluster Department of Health and Human Services, National Institutes of Health, Assistance Listing No. 93.859 (Biomedical Research and Research Training) Federal award year 2023-2024 Criteria: The Uniform Guidance (2 CFR 200.303) requires nonfederal entities receiving federal awards to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations, and program compliance requirements. Effective internal controls should include procedures to ensure vendors are not suspended or debarred. In accordance with 2 CFR 200.212 and 200.318(h)), when a nonfederal entity enters into a contract or purchase with an entity (vendor or subrecipient), the nonfederal entity must verify the entity is not suspended or debarred from participation in federal programs/grants when expending $25,000 or more in a year (or any amount in the case of a subrecipient). Condition: The University’s controls were not operating effectively to reasonably ensure the University verified the vendor was not suspended or debarred from participation in federal programs/grants prior to entering into a contract with the vendor. The University’s procurement policy requires vendor transactions equal to or greater than $25,000 undergo verification to ensure the vendor is not suspended or debarred, prior to entering into a contract with the vendor. Cause: A lack of controls to reasonably ensure this verification was performed. Effect or potential effect: The University did not have controls in place to reasonably ensure compliance with suspension and debarment requirements of the Uniform Guidance. The potential effect is submitting unallowable costs, or loss of federal funding. Questioned costs: $0 Context: For all sample selections tested in the major program, documentation was not maintained that could provide evidence that the University had performed the required verification. None of the samples tested were identified as suspended or debarred entities. Identification as a repeat finding, if applicable: Not applicable. Recommendation: We recommend the University develop proper controls and procedures to determine whether vendors have been suspended or debarred prior to entering into contracts or purchase orders for all transactions, and maintain documentation supporting this verification. View of responsible officials: Management agrees with this finding. See corrective action plan.
Finding 2024-004 – Subrecipient Monitoring — Material Weakness Department of Health and Human Services Research and Development Cluster National Science Foundation, Assistance Listing No. 47.076 (STEM Education) Federal award year 2023-2024 Criteria: The Uniform Guidance (2 CFR 200.303) requires nonfederal entities receiving federal awards to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations, and program compliance requirements. Effective internal controls should include procedures to ensure that risk assessment and monitoring are formally documented over subrecipient monitoring. In accordance with 2 CFR 200.332(b) and 2 CFR 200.332(e), a pass-through entity is required to evaluate each subrecipient’s risk of noncompliance with federal statutes, regulations, and the terms and conditions of each sub-award for purposes of determining appropriate subrecipient monitoring requirements. Depending on the risk assessment, the pass-through entity should identify monitoring procedures to be performed in order to ensure proper accountability and compliance with program requirements and achievements of performance goals. Condition: The University’s controls were not operating effectively to reasonably ensure the University performed risk assessment and monitoring procedures for its subrecipients. As a result, the University did not comply with the compliance requirements for subrecipient monitoring. Cause: The University does not have processes and procedures in place related to risk assessment and subrecipient monitoring. Effect or potential effect: The University is not in compliance with federal grant requirements over subrecipient monitoring. Lack of properly documented evidence of subrecipient monitoring policies and procedures performed, including required risk assessments, could result in actions taken by oversight agencies which could impact future funding. Questioned costs: None Context: The University has two active awards under the program with subrecipients with an aggregate award value of approximately $71,000. The University has two subrecipients and for both subrecipients tested in the major program, there was no evidence that a risk assessment or monitoring of those subrecipients was performed. Identification as a repeat finding, if applicable: Not applicable. Recommendation: We recommend the University develop processes and procedures to perform the required risk assessments and related monitoring, and maintain support that the risk assessments and related monitoring were performed as required. View of responsible officials: Management agrees with this finding. See corrective action plan.
Finding 2024-001 – Equipment and Real Property Management — Material Weakness Department of Health and Human Services Research and Development Cluster Department of Health and Human Services, National Institutes of Health, Assistance Listing No. 93.859 (Biomedical Research and Research Training) Federal award year 2023-2024 Criteria: Uniform Guidance (2 CFR 200.303) requires nonfederal entities receiving federal awards to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations, and program compliance requirements. Also, in accordance with 2 CFR 200.313(d)(1), property records must be maintained that included a description of the property, a serial number or other identification number, the source of funding for the property (including the federal award identification number), who holds title, the acquisition date, cost of the property, percentage of federal participation in the project costs for the federal award under which the property was acquired, the location, use and condition of the property, and any ultimate disposition data including the date of disposal and sales price of the property. In accordance with 2 CFR 200.313(d)(2), a physical inventory of equipment and property must be taken, and the results reconciled with property records at least once every two years. Condition: The University’s controls were not operating effectively to reasonably ensure the University maintained property records with the above required information and performed the required physical inventory of equipment within the two previous years. As a result, the University did not comply with the compliance requirements for equipment and real property management. Cause: The University does not have processes and procedures in place related to equipment management, tracking and required physical inventories. Effect or potential effect: The University is not in compliance with federal grant requirements over the tracking and physical inventory of equipment. Improper equipment management procedures could result in actions taken by oversight agencies which could impact future funding. Questioned costs: None Context: The University has five pieces of qualified equipment with an aggregate cost of approximately $119,000. For all sample selections tested in the major program, there was no process of tagging and tracking equipment purchased with federal funding, nor was there any evidence that physical inventories had been performed. Identification as a repeat finding, if applicable: Not applicable. Recommendation: We recommend the University develop processes and procedures to tag and track the equipment purchased with federal funding, and maintain support that physical inventories were performed as required. View of responsible officials: Management agrees with this finding. See corrective action plan.
Finding 2024-002 – Procurement and Suspension and Debarment — Material Weakness Department of Health and Human Services Research and Development Cluster Department of Health and Human Services, National Institutes of Health, Assistance Listing No. 93.859 (Biomedical Research and Research Training) Federal award year 2023-2024 Criteria: The Uniform Guidance (2 CFR 200.303) requires nonfederal entities receiving federal awards to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations, and program compliance requirements. Effective internal controls should include procedures to ensure procurement methods outline by the University are properly followed. In accordance with 2 CFR 200.320, price quotations should be obtained from an adequate number of qualified sources for procurements that meet the small purchase procurement threshold. Condition: The University’s controls were not operating effectively to reasonably ensure the University obtained the proper number of price quotations as required using the small purchase procurement method. The University’s procurement policy requires price quotations be obtained from at least two sources when using the small purchase procurement method. The University only obtained one price quotation and no written documentation as the rational for selection was maintained. As a result, the University did not comply with the compliance requirements for procurement. Cause: The University does not have processes and procedures in place to ensure all procurements of goods and services are in accordance with Uniform Guidance and in accordance with it’s own procurement policy. Effect or potential effect: The University is not in compliance with federal grant requirements over small purchase procurements. Improper procurement procedures could result in actions taken by oversight agencies which could impact future funding. Questioned costs: None Context: For all sample selections tested in the major program, one price quotation was obtained and no documentation was maintained as to the rationale for selection of the underlying vendor. Identification as a repeat finding, if applicable: Not applicable. Recommendation: We recommend the University develop processes and procedures to obtain the required number of price quotations required under the small purchase procurement method, and maintain support for the required number of price quotations received under the small purchase procurement method. View of responsible officials: Management agrees with this finding. See corrective action plan.
Finding 2024-003 – Procurement and Suspension and Debarment — Material Weakness Department of Health and Human Services Research and Development Cluster Department of Health and Human Services, National Institutes of Health, Assistance Listing No. 93.859 (Biomedical Research and Research Training) Federal award year 2023-2024 Criteria: The Uniform Guidance (2 CFR 200.303) requires nonfederal entities receiving federal awards to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations, and program compliance requirements. Effective internal controls should include procedures to ensure vendors are not suspended or debarred. In accordance with 2 CFR 200.212 and 200.318(h)), when a nonfederal entity enters into a contract or purchase with an entity (vendor or subrecipient), the nonfederal entity must verify the entity is not suspended or debarred from participation in federal programs/grants when expending $25,000 or more in a year (or any amount in the case of a subrecipient). Condition: The University’s controls were not operating effectively to reasonably ensure the University verified the vendor was not suspended or debarred from participation in federal programs/grants prior to entering into a contract with the vendor. The University’s procurement policy requires vendor transactions equal to or greater than $25,000 undergo verification to ensure the vendor is not suspended or debarred, prior to entering into a contract with the vendor. Cause: A lack of controls to reasonably ensure this verification was performed. Effect or potential effect: The University did not have controls in place to reasonably ensure compliance with suspension and debarment requirements of the Uniform Guidance. The potential effect is submitting unallowable costs, or loss of federal funding. Questioned costs: $0 Context: For all sample selections tested in the major program, documentation was not maintained that could provide evidence that the University had performed the required verification. None of the samples tested were identified as suspended or debarred entities. Identification as a repeat finding, if applicable: Not applicable. Recommendation: We recommend the University develop proper controls and procedures to determine whether vendors have been suspended or debarred prior to entering into contracts or purchase orders for all transactions, and maintain documentation supporting this verification. View of responsible officials: Management agrees with this finding. See corrective action plan.
Finding 2024-004 – Subrecipient Monitoring — Material Weakness Department of Health and Human Services Research and Development Cluster National Science Foundation, Assistance Listing No. 47.076 (STEM Education) Federal award year 2023-2024 Criteria: The Uniform Guidance (2 CFR 200.303) requires nonfederal entities receiving federal awards to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations, and program compliance requirements. Effective internal controls should include procedures to ensure that risk assessment and monitoring are formally documented over subrecipient monitoring. In accordance with 2 CFR 200.332(b) and 2 CFR 200.332(e), a pass-through entity is required to evaluate each subrecipient’s risk of noncompliance with federal statutes, regulations, and the terms and conditions of each sub-award for purposes of determining appropriate subrecipient monitoring requirements. Depending on the risk assessment, the pass-through entity should identify monitoring procedures to be performed in order to ensure proper accountability and compliance with program requirements and achievements of performance goals. Condition: The University’s controls were not operating effectively to reasonably ensure the University performed risk assessment and monitoring procedures for its subrecipients. As a result, the University did not comply with the compliance requirements for subrecipient monitoring. Cause: The University does not have processes and procedures in place related to risk assessment and subrecipient monitoring. Effect or potential effect: The University is not in compliance with federal grant requirements over subrecipient monitoring. Lack of properly documented evidence of subrecipient monitoring policies and procedures performed, including required risk assessments, could result in actions taken by oversight agencies which could impact future funding. Questioned costs: None Context: The University has two active awards under the program with subrecipients with an aggregate award value of approximately $71,000. The University has two subrecipients and for both subrecipients tested in the major program, there was no evidence that a risk assessment or monitoring of those subrecipients was performed. Identification as a repeat finding, if applicable: Not applicable. Recommendation: We recommend the University develop processes and procedures to perform the required risk assessments and related monitoring, and maintain support that the risk assessments and related monitoring were performed as required. View of responsible officials: Management agrees with this finding. See corrective action plan.
Finding 2024-001 – Equipment and Real Property Management — Material Weakness Department of Health and Human Services Research and Development Cluster Department of Health and Human Services, National Institutes of Health, Assistance Listing No. 93.859 (Biomedical Research and Research Training) Federal award year 2023-2024 Criteria: Uniform Guidance (2 CFR 200.303) requires nonfederal entities receiving federal awards to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations, and program compliance requirements. Also, in accordance with 2 CFR 200.313(d)(1), property records must be maintained that included a description of the property, a serial number or other identification number, the source of funding for the property (including the federal award identification number), who holds title, the acquisition date, cost of the property, percentage of federal participation in the project costs for the federal award under which the property was acquired, the location, use and condition of the property, and any ultimate disposition data including the date of disposal and sales price of the property. In accordance with 2 CFR 200.313(d)(2), a physical inventory of equipment and property must be taken, and the results reconciled with property records at least once every two years. Condition: The University’s controls were not operating effectively to reasonably ensure the University maintained property records with the above required information and performed the required physical inventory of equipment within the two previous years. As a result, the University did not comply with the compliance requirements for equipment and real property management. Cause: The University does not have processes and procedures in place related to equipment management, tracking and required physical inventories. Effect or potential effect: The University is not in compliance with federal grant requirements over the tracking and physical inventory of equipment. Improper equipment management procedures could result in actions taken by oversight agencies which could impact future funding. Questioned costs: None Context: The University has five pieces of qualified equipment with an aggregate cost of approximately $119,000. For all sample selections tested in the major program, there was no process of tagging and tracking equipment purchased with federal funding, nor was there any evidence that physical inventories had been performed. Identification as a repeat finding, if applicable: Not applicable. Recommendation: We recommend the University develop processes and procedures to tag and track the equipment purchased with federal funding, and maintain support that physical inventories were performed as required. View of responsible officials: Management agrees with this finding. See corrective action plan.
Finding 2024-002 – Procurement and Suspension and Debarment — Material Weakness Department of Health and Human Services Research and Development Cluster Department of Health and Human Services, National Institutes of Health, Assistance Listing No. 93.859 (Biomedical Research and Research Training) Federal award year 2023-2024 Criteria: The Uniform Guidance (2 CFR 200.303) requires nonfederal entities receiving federal awards to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations, and program compliance requirements. Effective internal controls should include procedures to ensure procurement methods outline by the University are properly followed. In accordance with 2 CFR 200.320, price quotations should be obtained from an adequate number of qualified sources for procurements that meet the small purchase procurement threshold. Condition: The University’s controls were not operating effectively to reasonably ensure the University obtained the proper number of price quotations as required using the small purchase procurement method. The University’s procurement policy requires price quotations be obtained from at least two sources when using the small purchase procurement method. The University only obtained one price quotation and no written documentation as the rational for selection was maintained. As a result, the University did not comply with the compliance requirements for procurement. Cause: The University does not have processes and procedures in place to ensure all procurements of goods and services are in accordance with Uniform Guidance and in accordance with it’s own procurement policy. Effect or potential effect: The University is not in compliance with federal grant requirements over small purchase procurements. Improper procurement procedures could result in actions taken by oversight agencies which could impact future funding. Questioned costs: None Context: For all sample selections tested in the major program, one price quotation was obtained and no documentation was maintained as to the rationale for selection of the underlying vendor. Identification as a repeat finding, if applicable: Not applicable. Recommendation: We recommend the University develop processes and procedures to obtain the required number of price quotations required under the small purchase procurement method, and maintain support for the required number of price quotations received under the small purchase procurement method. View of responsible officials: Management agrees with this finding. See corrective action plan.
Finding 2024-003 – Procurement and Suspension and Debarment — Material Weakness Department of Health and Human Services Research and Development Cluster Department of Health and Human Services, National Institutes of Health, Assistance Listing No. 93.859 (Biomedical Research and Research Training) Federal award year 2023-2024 Criteria: The Uniform Guidance (2 CFR 200.303) requires nonfederal entities receiving federal awards to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations, and program compliance requirements. Effective internal controls should include procedures to ensure vendors are not suspended or debarred. In accordance with 2 CFR 200.212 and 200.318(h)), when a nonfederal entity enters into a contract or purchase with an entity (vendor or subrecipient), the nonfederal entity must verify the entity is not suspended or debarred from participation in federal programs/grants when expending $25,000 or more in a year (or any amount in the case of a subrecipient). Condition: The University’s controls were not operating effectively to reasonably ensure the University verified the vendor was not suspended or debarred from participation in federal programs/grants prior to entering into a contract with the vendor. The University’s procurement policy requires vendor transactions equal to or greater than $25,000 undergo verification to ensure the vendor is not suspended or debarred, prior to entering into a contract with the vendor. Cause: A lack of controls to reasonably ensure this verification was performed. Effect or potential effect: The University did not have controls in place to reasonably ensure compliance with suspension and debarment requirements of the Uniform Guidance. The potential effect is submitting unallowable costs, or loss of federal funding. Questioned costs: $0 Context: For all sample selections tested in the major program, documentation was not maintained that could provide evidence that the University had performed the required verification. None of the samples tested were identified as suspended or debarred entities. Identification as a repeat finding, if applicable: Not applicable. Recommendation: We recommend the University develop proper controls and procedures to determine whether vendors have been suspended or debarred prior to entering into contracts or purchase orders for all transactions, and maintain documentation supporting this verification. View of responsible officials: Management agrees with this finding. See corrective action plan.
Finding 2024-004 – Subrecipient Monitoring — Material Weakness Department of Health and Human Services Research and Development Cluster National Science Foundation, Assistance Listing No. 47.076 (STEM Education) Federal award year 2023-2024 Criteria: The Uniform Guidance (2 CFR 200.303) requires nonfederal entities receiving federal awards to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations, and program compliance requirements. Effective internal controls should include procedures to ensure that risk assessment and monitoring are formally documented over subrecipient monitoring. In accordance with 2 CFR 200.332(b) and 2 CFR 200.332(e), a pass-through entity is required to evaluate each subrecipient’s risk of noncompliance with federal statutes, regulations, and the terms and conditions of each sub-award for purposes of determining appropriate subrecipient monitoring requirements. Depending on the risk assessment, the pass-through entity should identify monitoring procedures to be performed in order to ensure proper accountability and compliance with program requirements and achievements of performance goals. Condition: The University’s controls were not operating effectively to reasonably ensure the University performed risk assessment and monitoring procedures for its subrecipients. As a result, the University did not comply with the compliance requirements for subrecipient monitoring. Cause: The University does not have processes and procedures in place related to risk assessment and subrecipient monitoring. Effect or potential effect: The University is not in compliance with federal grant requirements over subrecipient monitoring. Lack of properly documented evidence of subrecipient monitoring policies and procedures performed, including required risk assessments, could result in actions taken by oversight agencies which could impact future funding. Questioned costs: None Context: The University has two active awards under the program with subrecipients with an aggregate award value of approximately $71,000. The University has two subrecipients and for both subrecipients tested in the major program, there was no evidence that a risk assessment or monitoring of those subrecipients was performed. Identification as a repeat finding, if applicable: Not applicable. Recommendation: We recommend the University develop processes and procedures to perform the required risk assessments and related monitoring, and maintain support that the risk assessments and related monitoring were performed as required. View of responsible officials: Management agrees with this finding. See corrective action plan.
Finding 2024-001 – Equipment and Real Property Management — Material Weakness Department of Health and Human Services Research and Development Cluster Department of Health and Human Services, National Institutes of Health, Assistance Listing No. 93.859 (Biomedical Research and Research Training) Federal award year 2023-2024 Criteria: Uniform Guidance (2 CFR 200.303) requires nonfederal entities receiving federal awards to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations, and program compliance requirements. Also, in accordance with 2 CFR 200.313(d)(1), property records must be maintained that included a description of the property, a serial number or other identification number, the source of funding for the property (including the federal award identification number), who holds title, the acquisition date, cost of the property, percentage of federal participation in the project costs for the federal award under which the property was acquired, the location, use and condition of the property, and any ultimate disposition data including the date of disposal and sales price of the property. In accordance with 2 CFR 200.313(d)(2), a physical inventory of equipment and property must be taken, and the results reconciled with property records at least once every two years. Condition: The University’s controls were not operating effectively to reasonably ensure the University maintained property records with the above required information and performed the required physical inventory of equipment within the two previous years. As a result, the University did not comply with the compliance requirements for equipment and real property management. Cause: The University does not have processes and procedures in place related to equipment management, tracking and required physical inventories. Effect or potential effect: The University is not in compliance with federal grant requirements over the tracking and physical inventory of equipment. Improper equipment management procedures could result in actions taken by oversight agencies which could impact future funding. Questioned costs: None Context: The University has five pieces of qualified equipment with an aggregate cost of approximately $119,000. For all sample selections tested in the major program, there was no process of tagging and tracking equipment purchased with federal funding, nor was there any evidence that physical inventories had been performed. Identification as a repeat finding, if applicable: Not applicable. Recommendation: We recommend the University develop processes and procedures to tag and track the equipment purchased with federal funding, and maintain support that physical inventories were performed as required. View of responsible officials: Management agrees with this finding. See corrective action plan.
Finding 2024-002 – Procurement and Suspension and Debarment — Material Weakness Department of Health and Human Services Research and Development Cluster Department of Health and Human Services, National Institutes of Health, Assistance Listing No. 93.859 (Biomedical Research and Research Training) Federal award year 2023-2024 Criteria: The Uniform Guidance (2 CFR 200.303) requires nonfederal entities receiving federal awards to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations, and program compliance requirements. Effective internal controls should include procedures to ensure procurement methods outline by the University are properly followed. In accordance with 2 CFR 200.320, price quotations should be obtained from an adequate number of qualified sources for procurements that meet the small purchase procurement threshold. Condition: The University’s controls were not operating effectively to reasonably ensure the University obtained the proper number of price quotations as required using the small purchase procurement method. The University’s procurement policy requires price quotations be obtained from at least two sources when using the small purchase procurement method. The University only obtained one price quotation and no written documentation as the rational for selection was maintained. As a result, the University did not comply with the compliance requirements for procurement. Cause: The University does not have processes and procedures in place to ensure all procurements of goods and services are in accordance with Uniform Guidance and in accordance with it’s own procurement policy. Effect or potential effect: The University is not in compliance with federal grant requirements over small purchase procurements. Improper procurement procedures could result in actions taken by oversight agencies which could impact future funding. Questioned costs: None Context: For all sample selections tested in the major program, one price quotation was obtained and no documentation was maintained as to the rationale for selection of the underlying vendor. Identification as a repeat finding, if applicable: Not applicable. Recommendation: We recommend the University develop processes and procedures to obtain the required number of price quotations required under the small purchase procurement method, and maintain support for the required number of price quotations received under the small purchase procurement method. View of responsible officials: Management agrees with this finding. See corrective action plan.
Finding 2024-003 – Procurement and Suspension and Debarment — Material Weakness Department of Health and Human Services Research and Development Cluster Department of Health and Human Services, National Institutes of Health, Assistance Listing No. 93.859 (Biomedical Research and Research Training) Federal award year 2023-2024 Criteria: The Uniform Guidance (2 CFR 200.303) requires nonfederal entities receiving federal awards to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations, and program compliance requirements. Effective internal controls should include procedures to ensure vendors are not suspended or debarred. In accordance with 2 CFR 200.212 and 200.318(h)), when a nonfederal entity enters into a contract or purchase with an entity (vendor or subrecipient), the nonfederal entity must verify the entity is not suspended or debarred from participation in federal programs/grants when expending $25,000 or more in a year (or any amount in the case of a subrecipient). Condition: The University’s controls were not operating effectively to reasonably ensure the University verified the vendor was not suspended or debarred from participation in federal programs/grants prior to entering into a contract with the vendor. The University’s procurement policy requires vendor transactions equal to or greater than $25,000 undergo verification to ensure the vendor is not suspended or debarred, prior to entering into a contract with the vendor. Cause: A lack of controls to reasonably ensure this verification was performed. Effect or potential effect: The University did not have controls in place to reasonably ensure compliance with suspension and debarment requirements of the Uniform Guidance. The potential effect is submitting unallowable costs, or loss of federal funding. Questioned costs: $0 Context: For all sample selections tested in the major program, documentation was not maintained that could provide evidence that the University had performed the required verification. None of the samples tested were identified as suspended or debarred entities. Identification as a repeat finding, if applicable: Not applicable. Recommendation: We recommend the University develop proper controls and procedures to determine whether vendors have been suspended or debarred prior to entering into contracts or purchase orders for all transactions, and maintain documentation supporting this verification. View of responsible officials: Management agrees with this finding. See corrective action plan.
Finding 2024-004 – Subrecipient Monitoring — Material Weakness Department of Health and Human Services Research and Development Cluster National Science Foundation, Assistance Listing No. 47.076 (STEM Education) Federal award year 2023-2024 Criteria: The Uniform Guidance (2 CFR 200.303) requires nonfederal entities receiving federal awards to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations, and program compliance requirements. Effective internal controls should include procedures to ensure that risk assessment and monitoring are formally documented over subrecipient monitoring. In accordance with 2 CFR 200.332(b) and 2 CFR 200.332(e), a pass-through entity is required to evaluate each subrecipient’s risk of noncompliance with federal statutes, regulations, and the terms and conditions of each sub-award for purposes of determining appropriate subrecipient monitoring requirements. Depending on the risk assessment, the pass-through entity should identify monitoring procedures to be performed in order to ensure proper accountability and compliance with program requirements and achievements of performance goals. Condition: The University’s controls were not operating effectively to reasonably ensure the University performed risk assessment and monitoring procedures for its subrecipients. As a result, the University did not comply with the compliance requirements for subrecipient monitoring. Cause: The University does not have processes and procedures in place related to risk assessment and subrecipient monitoring. Effect or potential effect: The University is not in compliance with federal grant requirements over subrecipient monitoring. Lack of properly documented evidence of subrecipient monitoring policies and procedures performed, including required risk assessments, could result in actions taken by oversight agencies which could impact future funding. Questioned costs: None Context: The University has two active awards under the program with subrecipients with an aggregate award value of approximately $71,000. The University has two subrecipients and for both subrecipients tested in the major program, there was no evidence that a risk assessment or monitoring of those subrecipients was performed. Identification as a repeat finding, if applicable: Not applicable. Recommendation: We recommend the University develop processes and procedures to perform the required risk assessments and related monitoring, and maintain support that the risk assessments and related monitoring were performed as required. View of responsible officials: Management agrees with this finding. See corrective action plan.
Finding 2024-001 Internal Controls over Compliance – Eligibility (Significant Deficiency) Assistance Listing Number 93.778 – Medical Assistance Program Criteria: 2 CFR 200.303 requires that a federal award recipient must “(a) establish, document, and maintain effective internal control over the Federal award that provides reasonable assurance that the recipient is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award.” Condition: During our review of compliance over eligibility, we identified one individual who was terminated from the program in November 2022, but continued to receive benefits through September 2024. Cause: Internal controls over eligibility compliance requirements were not properly designed and were not placed in operation. Management is responsible for compliance with requirements over eligibility and for the design, implementation, and maintenance of effective internal controls over compliance with the requirements of laws, statutes, regulations, rules, and provisions of grant agreements applicable to its federal program. Effect: As a result of this condition, an individual who was no longer eligible for benefits through the program continued to receive benefits. Recommendation: We recommend that FMAAA establish a process to ensure that terminated participants are properly disenrolled from the program and are no longer receiving benefits after their final date of eligibility. This process should include a secondary review of participant files by someone other than the preparer. Management’s response: See corrective action plan.
Reference Number: 2024-002 Prior Year Finding: 2023-007 Federal Agency: U.S. Department of Treasury Federal Program: COVID-19 – Coronavirus State and Local Fiscal Recovery Funds Assistance Listing Number: 21.027 Award Number and Year: 2021 Compliance Requirement: Subrecipient Monitoring Type of Finding: Significant Deficiency in Internal Controls over Compliance, Other Matters Criteria or Specific Requirement: Compliance - 2 CFR Section 200.332 – Requirements for Pass-Through Entities states in part, that all pass-through entities must: (a) Verify that every subrecipient is audited as required by Subpart F – Audit Requirements of this part when it is expected that the subrecipient’s Federal award expended during the respective fiscal year equaled or exceeded the threshold set forth in section 200.501 Audit requirements. Control - Per 2 CDF 200.303(a), a non-Federal entity must: Establish a maintain effective internal control over the federal award that provides reasonable assurance that the non-Federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal awards. These internal controls should comply with guidance in "Standards for Internal Control in the Federal Government" issued by the Comptroller General of the United States or the "Internal Control Integrated Framework", issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition: The County was not able to provide documentation to show it ensured its subrecipients were audited as required by 2 CFR Part 200 Subpart F – Audit Requirements (Subpart F). Context: Exceptions were noted for 7 of 7 subrecipients selected for testing: • The County was unable to provide support that it ensured the subrecipient was audited as required by Subpart F. The County could not produce evidence of verification that the subrecipient’s Federal awards expended during the fiscal year were below the threshold set forth in section 200.501 Audit Requirements. Cause: The County did not establish effective internal controls and procedures over subrecipient monitoring. Effect: Without ensuring subrecipients have obtained audits as required by Subpart F, there is an increased risk that subrecipients could be inappropriately spending and/or inaccurately tracking and reporting federal funds over multiple years, and these discrepancies may not be properly monitored, detected, and corrected by the County personnel on a timely basis. Questioned Costs: Undetermined. Recommendation: The County should review and enhance internal controls and procedures to ensure that evaluation of independent audits is performed. Views of Responsible Officials: The County agrees with this finding. See separate Correction Action Plan related to this finding.
Reference Number: 2024-002 Prior Year Finding: 2023-007 Federal Agency: U.S. Department of Treasury Federal Program: COVID-19 – Coronavirus State and Local Fiscal Recovery Funds Assistance Listing Number: 21.027 Award Number and Year: 2021 Compliance Requirement: Subrecipient Monitoring Type of Finding: Significant Deficiency in Internal Controls over Compliance, Other Matters Criteria or Specific Requirement: Compliance - 2 CFR Section 200.332 – Requirements for Pass-Through Entities states in part, that all pass-through entities must: (a) Verify that every subrecipient is audited as required by Subpart F – Audit Requirements of this part when it is expected that the subrecipient’s Federal award expended during the respective fiscal year equaled or exceeded the threshold set forth in section 200.501 Audit requirements. Control - Per 2 CDF 200.303(a), a non-Federal entity must: Establish a maintain effective internal control over the federal award that provides reasonable assurance that the non-Federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal awards. These internal controls should comply with guidance in "Standards for Internal Control in the Federal Government" issued by the Comptroller General of the United States or the "Internal Control Integrated Framework", issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition: The County was not able to provide documentation to show it ensured its subrecipients were audited as required by 2 CFR Part 200 Subpart F – Audit Requirements (Subpart F). Context: Exceptions were noted for 7 of 7 subrecipients selected for testing: • The County was unable to provide support that it ensured the subrecipient was audited as required by Subpart F. The County could not produce evidence of verification that the subrecipient’s Federal awards expended during the fiscal year were below the threshold set forth in section 200.501 Audit Requirements. Cause: The County did not establish effective internal controls and procedures over subrecipient monitoring. Effect: Without ensuring subrecipients have obtained audits as required by Subpart F, there is an increased risk that subrecipients could be inappropriately spending and/or inaccurately tracking and reporting federal funds over multiple years, and these discrepancies may not be properly monitored, detected, and corrected by the County personnel on a timely basis. Questioned Costs: Undetermined. Recommendation: The County should review and enhance internal controls and procedures to ensure that evaluation of independent audits is performed. Views of Responsible Officials: The County agrees with this finding. See separate Correction Action Plan related to this finding.
Finding No. 2024-003 – Special Tests and Provisions - Gramm-Leach-Bliley Act–Student Information Security Federal Program ALN 84.007 Federal Supplemental Educational Opportunity Grant Program ALN 84.033 Federal Work-Study Program ALN 84.063 Federal Pell Grant Program ALN 84.268 Federal Direct Student Loan Program Name of Federal Agency Teacher Education Assistance for College and Higher Education Grants (TEACH Grants) U.S. Department of Education (USDE) Type of Finding Internal Control/Compliance Category Significant deficiency Compliance Requirement Special Tests and Provisions Criteria Under an institution’s Program Participation Agreement with the Department of Education and the Gramm-Leach-Bliley Act, schools must protect student financial aid information, with particular attention to information provided to institutions by the Department or otherwise obtained in support of the administration of the federal student financial aid programs. The Gramm-Leach-Bliley Act (GLBA) (Pub. L. No. 106-102) requires financial institutions to explain their information-sharing practices to their customers and to safeguard sensitive data (16 CFR 314). The Federal Trade Commission considers Title IV-eligible institutions that participate in Title IV Educational Assistance Programs as “financial institutions” and subject to the Gramm-Leach-Bliley Act (16 CFR 313.3(k)(2)(vi)). The Standards for Safeguarding Customer Information, required by the GLBA (16 CFR §314.4) requires the University to: a) Designate a qualified individual responsible for overseeing and implementing the institution’s information security program and enforcing the information security program in compliance (16 CFR 314.4(a)). b) Provide for the information security program to be based on a risk assessment that identifies reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of customer information (as the term customer information applies to the institution) that could result in the unauthorized disclosure, misuse, alteration, destruction, or other compromise of such information, and assesses the sufficiency of any safeguards in place to control these risks (16 CFR 314.4(b)). c) Provide for the design and implementation of safeguards to control the risks the institution identifies through its risk assessment (16 CFR 314.4(c)). At a minimum, the institution’s written information security program must address the implementation of the minimum safeguards identified in 16 CFR 314.4(c)(1) through (8). The eight minimum safeguards that the written information security program must address are summarized as follows: 1. Implement and periodically review access controls. 2. Conduct a periodic inventory of data, noting where it’s collected, stored, or transmitted. 3. Encrypt customer information on the institution’s system and when it’s in transit. 4. Assess apps developed by the institution. 5. Implement multi-factor authentication for anyone accessing customer information on the institution’s system. 6. Dispose of customer information securely. 7. Anticipate and evaluate changes to the information system or network. 8. Maintain a log of authorized users’ activity and keep an eye out for unauthorized access. d) Provide for the institution to regularly test or otherwise monitor the effectiveness of the safeguards it has implemented (16 CFR 314.4(d)). e) Provide for the implementation of policies and procedures to ensure that personnel are able to enact the information security program (16 CFR 314.4(e)(1)). f) Address how the institution will oversee its information system service providers (16 CFR 314.4(f)). g) Provide for the evaluation and adjustment of its information security program in light of the results of the required testing and monitoring; any material changes to its operations or business arrangements; the results of the required risk assessments; or any other circumstances that it knows or has reason to know may have a material impact the institution’s information security program (16 CFR 314.4(g)). Additionally, the Uniform Guidance (2 CFR 200.303(a)) requires nonfederal entities receiving federal awards to establish and maintain effective internal controls designed to reasonably ensure compliance with Federal laws, statutes, regulations, and the terms and conditions of the Federal award. Furthermore, generally accepted information technology guidance endorses the implementation of a process to identify risk and ensure appropriate safeguards are in place to protect information technology systems and data. Condition During our audit procedures, we noted that the University risk assessment did not fully addressed all the elements required by (16 CFR 314.4). Accordingly, the following elements were missing: 1. Vulnerability test 2. Penetration test 3. No backup test was performed during year ended June 30, 2024. Cause In the past years there’s been a high turnover in the position of the qualified individual responsible for overseeing and implementing the University’s information cyber-security program. As a result, some of the procedures and policies established in the information cyber-security program risk assessment have not been consistently or continuously maintained, accordingly, the student personal information could be at risk. In addition, the USDE has informed through electronic announcements (EA), that “when an audit report that includes a GLBA audit finding is received, they will refer the audit to the Federal Trade Commission (FTC). Effect Once the finding is referred to the FTC, that finding will be considered closed for the USDE audit tracking purposes. The FTC will determine what action may be needed as a result of the GLBA audit finding. Identification of a repeat finding This is not a repeat finding from the immediate previous audit. Questioned cost N/A Context The Gramm-Leach-Bliley Act (GLBA) created a requirement that financial institutions must have certain information privacy protections and safeguards in place. The Federal Trade Commission (FTC) has enforcement authority for the requirements and has determined that institutions of higher education (institutions) are financial institutions under GLBA. Each institution has agreed to comply with GLBA in its Program Participation Agreement with the Department. In addition, as a condition of accessing the Department’s systems, each institution and servicer must sign the Student Aid Internet Gateway (SAIG) Enrollment Agreement, which states that the institution must ensure that all federal student aid applicant information is protected from access by or disclosure to unauthorized personnel. Institutions and third-party servicers are also required to demonstrate administrative capability in accordance with 34 C.F.R. § 668.16, including the maintenance of adequate checks and balances in their systems of internal control. An institution or servicer that does not maintain adequate internal controls over the security of student information may not be considered administratively capable. Recommendation We recommend that the University addresses the cause for the high turnover in the position of the qualified individual responsible for overseeing the implementation of policies and procedures, including internal controls, to ensure that they are in compliance with 16 CFR 314.4(b) and (c). Views of Responsible Officials and Planned Corrective Actions Management of the University agrees with this finding. Please refer to the corrective action plan on pages 61-63.
Finding No. 2024-003 – Special Tests and Provisions - Gramm-Leach-Bliley Act–Student Information Security Federal Program ALN 84.007 Federal Supplemental Educational Opportunity Grant Program ALN 84.033 Federal Work-Study Program ALN 84.063 Federal Pell Grant Program ALN 84.268 Federal Direct Student Loan Program Name of Federal Agency Teacher Education Assistance for College and Higher Education Grants (TEACH Grants) U.S. Department of Education (USDE) Type of Finding Internal Control/Compliance Category Significant deficiency Compliance Requirement Special Tests and Provisions Criteria Under an institution’s Program Participation Agreement with the Department of Education and the Gramm-Leach-Bliley Act, schools must protect student financial aid information, with particular attention to information provided to institutions by the Department or otherwise obtained in support of the administration of the federal student financial aid programs. The Gramm-Leach-Bliley Act (GLBA) (Pub. L. No. 106-102) requires financial institutions to explain their information-sharing practices to their customers and to safeguard sensitive data (16 CFR 314). The Federal Trade Commission considers Title IV-eligible institutions that participate in Title IV Educational Assistance Programs as “financial institutions” and subject to the Gramm-Leach-Bliley Act (16 CFR 313.3(k)(2)(vi)). The Standards for Safeguarding Customer Information, required by the GLBA (16 CFR §314.4) requires the University to: a) Designate a qualified individual responsible for overseeing and implementing the institution’s information security program and enforcing the information security program in compliance (16 CFR 314.4(a)). b) Provide for the information security program to be based on a risk assessment that identifies reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of customer information (as the term customer information applies to the institution) that could result in the unauthorized disclosure, misuse, alteration, destruction, or other compromise of such information, and assesses the sufficiency of any safeguards in place to control these risks (16 CFR 314.4(b)). c) Provide for the design and implementation of safeguards to control the risks the institution identifies through its risk assessment (16 CFR 314.4(c)). At a minimum, the institution’s written information security program must address the implementation of the minimum safeguards identified in 16 CFR 314.4(c)(1) through (8). The eight minimum safeguards that the written information security program must address are summarized as follows: 1. Implement and periodically review access controls. 2. Conduct a periodic inventory of data, noting where it’s collected, stored, or transmitted. 3. Encrypt customer information on the institution’s system and when it’s in transit. 4. Assess apps developed by the institution. 5. Implement multi-factor authentication for anyone accessing customer information on the institution’s system. 6. Dispose of customer information securely. 7. Anticipate and evaluate changes to the information system or network. 8. Maintain a log of authorized users’ activity and keep an eye out for unauthorized access. d) Provide for the institution to regularly test or otherwise monitor the effectiveness of the safeguards it has implemented (16 CFR 314.4(d)). e) Provide for the implementation of policies and procedures to ensure that personnel are able to enact the information security program (16 CFR 314.4(e)(1)). f) Address how the institution will oversee its information system service providers (16 CFR 314.4(f)). g) Provide for the evaluation and adjustment of its information security program in light of the results of the required testing and monitoring; any material changes to its operations or business arrangements; the results of the required risk assessments; or any other circumstances that it knows or has reason to know may have a material impact the institution’s information security program (16 CFR 314.4(g)). Additionally, the Uniform Guidance (2 CFR 200.303(a)) requires nonfederal entities receiving federal awards to establish and maintain effective internal controls designed to reasonably ensure compliance with Federal laws, statutes, regulations, and the terms and conditions of the Federal award. Furthermore, generally accepted information technology guidance endorses the implementation of a process to identify risk and ensure appropriate safeguards are in place to protect information technology systems and data. Condition During our audit procedures, we noted that the University risk assessment did not fully addressed all the elements required by (16 CFR 314.4). Accordingly, the following elements were missing: 1. Vulnerability test 2. Penetration test 3. No backup test was performed during year ended June 30, 2024. Cause In the past years there’s been a high turnover in the position of the qualified individual responsible for overseeing and implementing the University’s information cyber-security program. As a result, some of the procedures and policies established in the information cyber-security program risk assessment have not been consistently or continuously maintained, accordingly, the student personal information could be at risk. In addition, the USDE has informed through electronic announcements (EA), that “when an audit report that includes a GLBA audit finding is received, they will refer the audit to the Federal Trade Commission (FTC). Effect Once the finding is referred to the FTC, that finding will be considered closed for the USDE audit tracking purposes. The FTC will determine what action may be needed as a result of the GLBA audit finding. Identification of a repeat finding This is not a repeat finding from the immediate previous audit. Questioned cost N/A Context The Gramm-Leach-Bliley Act (GLBA) created a requirement that financial institutions must have certain information privacy protections and safeguards in place. The Federal Trade Commission (FTC) has enforcement authority for the requirements and has determined that institutions of higher education (institutions) are financial institutions under GLBA. Each institution has agreed to comply with GLBA in its Program Participation Agreement with the Department. In addition, as a condition of accessing the Department’s systems, each institution and servicer must sign the Student Aid Internet Gateway (SAIG) Enrollment Agreement, which states that the institution must ensure that all federal student aid applicant information is protected from access by or disclosure to unauthorized personnel. Institutions and third-party servicers are also required to demonstrate administrative capability in accordance with 34 C.F.R. § 668.16, including the maintenance of adequate checks and balances in their systems of internal control. An institution or servicer that does not maintain adequate internal controls over the security of student information may not be considered administratively capable. Recommendation We recommend that the University addresses the cause for the high turnover in the position of the qualified individual responsible for overseeing the implementation of policies and procedures, including internal controls, to ensure that they are in compliance with 16 CFR 314.4(b) and (c). Views of Responsible Officials and Planned Corrective Actions Management of the University agrees with this finding. Please refer to the corrective action plan on pages 61-63.
Finding No. 2024-003 – Special Tests and Provisions - Gramm-Leach-Bliley Act–Student Information Security Federal Program ALN 84.007 Federal Supplemental Educational Opportunity Grant Program ALN 84.033 Federal Work-Study Program ALN 84.063 Federal Pell Grant Program ALN 84.268 Federal Direct Student Loan Program Name of Federal Agency Teacher Education Assistance for College and Higher Education Grants (TEACH Grants) U.S. Department of Education (USDE) Type of Finding Internal Control/Compliance Category Significant deficiency Compliance Requirement Special Tests and Provisions Criteria Under an institution’s Program Participation Agreement with the Department of Education and the Gramm-Leach-Bliley Act, schools must protect student financial aid information, with particular attention to information provided to institutions by the Department or otherwise obtained in support of the administration of the federal student financial aid programs. The Gramm-Leach-Bliley Act (GLBA) (Pub. L. No. 106-102) requires financial institutions to explain their information-sharing practices to their customers and to safeguard sensitive data (16 CFR 314). The Federal Trade Commission considers Title IV-eligible institutions that participate in Title IV Educational Assistance Programs as “financial institutions” and subject to the Gramm-Leach-Bliley Act (16 CFR 313.3(k)(2)(vi)). The Standards for Safeguarding Customer Information, required by the GLBA (16 CFR §314.4) requires the University to: a) Designate a qualified individual responsible for overseeing and implementing the institution’s information security program and enforcing the information security program in compliance (16 CFR 314.4(a)). b) Provide for the information security program to be based on a risk assessment that identifies reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of customer information (as the term customer information applies to the institution) that could result in the unauthorized disclosure, misuse, alteration, destruction, or other compromise of such information, and assesses the sufficiency of any safeguards in place to control these risks (16 CFR 314.4(b)). c) Provide for the design and implementation of safeguards to control the risks the institution identifies through its risk assessment (16 CFR 314.4(c)). At a minimum, the institution’s written information security program must address the implementation of the minimum safeguards identified in 16 CFR 314.4(c)(1) through (8). The eight minimum safeguards that the written information security program must address are summarized as follows: 1. Implement and periodically review access controls. 2. Conduct a periodic inventory of data, noting where it’s collected, stored, or transmitted. 3. Encrypt customer information on the institution’s system and when it’s in transit. 4. Assess apps developed by the institution. 5. Implement multi-factor authentication for anyone accessing customer information on the institution’s system. 6. Dispose of customer information securely. 7. Anticipate and evaluate changes to the information system or network. 8. Maintain a log of authorized users’ activity and keep an eye out for unauthorized access. d) Provide for the institution to regularly test or otherwise monitor the effectiveness of the safeguards it has implemented (16 CFR 314.4(d)). e) Provide for the implementation of policies and procedures to ensure that personnel are able to enact the information security program (16 CFR 314.4(e)(1)). f) Address how the institution will oversee its information system service providers (16 CFR 314.4(f)). g) Provide for the evaluation and adjustment of its information security program in light of the results of the required testing and monitoring; any material changes to its operations or business arrangements; the results of the required risk assessments; or any other circumstances that it knows or has reason to know may have a material impact the institution’s information security program (16 CFR 314.4(g)). Additionally, the Uniform Guidance (2 CFR 200.303(a)) requires nonfederal entities receiving federal awards to establish and maintain effective internal controls designed to reasonably ensure compliance with Federal laws, statutes, regulations, and the terms and conditions of the Federal award. Furthermore, generally accepted information technology guidance endorses the implementation of a process to identify risk and ensure appropriate safeguards are in place to protect information technology systems and data. Condition During our audit procedures, we noted that the University risk assessment did not fully addressed all the elements required by (16 CFR 314.4). Accordingly, the following elements were missing: 1. Vulnerability test 2. Penetration test 3. No backup test was performed during year ended June 30, 2024. Cause In the past years there’s been a high turnover in the position of the qualified individual responsible for overseeing and implementing the University’s information cyber-security program. As a result, some of the procedures and policies established in the information cyber-security program risk assessment have not been consistently or continuously maintained, accordingly, the student personal information could be at risk. In addition, the USDE has informed through electronic announcements (EA), that “when an audit report that includes a GLBA audit finding is received, they will refer the audit to the Federal Trade Commission (FTC). Effect Once the finding is referred to the FTC, that finding will be considered closed for the USDE audit tracking purposes. The FTC will determine what action may be needed as a result of the GLBA audit finding. Identification of a repeat finding This is not a repeat finding from the immediate previous audit. Questioned cost N/A Context The Gramm-Leach-Bliley Act (GLBA) created a requirement that financial institutions must have certain information privacy protections and safeguards in place. The Federal Trade Commission (FTC) has enforcement authority for the requirements and has determined that institutions of higher education (institutions) are financial institutions under GLBA. Each institution has agreed to comply with GLBA in its Program Participation Agreement with the Department. In addition, as a condition of accessing the Department’s systems, each institution and servicer must sign the Student Aid Internet Gateway (SAIG) Enrollment Agreement, which states that the institution must ensure that all federal student aid applicant information is protected from access by or disclosure to unauthorized personnel. Institutions and third-party servicers are also required to demonstrate administrative capability in accordance with 34 C.F.R. § 668.16, including the maintenance of adequate checks and balances in their systems of internal control. An institution or servicer that does not maintain adequate internal controls over the security of student information may not be considered administratively capable. Recommendation We recommend that the University addresses the cause for the high turnover in the position of the qualified individual responsible for overseeing the implementation of policies and procedures, including internal controls, to ensure that they are in compliance with 16 CFR 314.4(b) and (c). Views of Responsible Officials and Planned Corrective Actions Management of the University agrees with this finding. Please refer to the corrective action plan on pages 61-63.
Finding No. 2024-003 – Special Tests and Provisions - Gramm-Leach-Bliley Act–Student Information Security Federal Program ALN 84.007 Federal Supplemental Educational Opportunity Grant Program ALN 84.033 Federal Work-Study Program ALN 84.063 Federal Pell Grant Program ALN 84.268 Federal Direct Student Loan Program Name of Federal Agency Teacher Education Assistance for College and Higher Education Grants (TEACH Grants) U.S. Department of Education (USDE) Type of Finding Internal Control/Compliance Category Significant deficiency Compliance Requirement Special Tests and Provisions Criteria Under an institution’s Program Participation Agreement with the Department of Education and the Gramm-Leach-Bliley Act, schools must protect student financial aid information, with particular attention to information provided to institutions by the Department or otherwise obtained in support of the administration of the federal student financial aid programs. The Gramm-Leach-Bliley Act (GLBA) (Pub. L. No. 106-102) requires financial institutions to explain their information-sharing practices to their customers and to safeguard sensitive data (16 CFR 314). The Federal Trade Commission considers Title IV-eligible institutions that participate in Title IV Educational Assistance Programs as “financial institutions” and subject to the Gramm-Leach-Bliley Act (16 CFR 313.3(k)(2)(vi)). The Standards for Safeguarding Customer Information, required by the GLBA (16 CFR §314.4) requires the University to: a) Designate a qualified individual responsible for overseeing and implementing the institution’s information security program and enforcing the information security program in compliance (16 CFR 314.4(a)). b) Provide for the information security program to be based on a risk assessment that identifies reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of customer information (as the term customer information applies to the institution) that could result in the unauthorized disclosure, misuse, alteration, destruction, or other compromise of such information, and assesses the sufficiency of any safeguards in place to control these risks (16 CFR 314.4(b)). c) Provide for the design and implementation of safeguards to control the risks the institution identifies through its risk assessment (16 CFR 314.4(c)). At a minimum, the institution’s written information security program must address the implementation of the minimum safeguards identified in 16 CFR 314.4(c)(1) through (8). The eight minimum safeguards that the written information security program must address are summarized as follows: 1. Implement and periodically review access controls. 2. Conduct a periodic inventory of data, noting where it’s collected, stored, or transmitted. 3. Encrypt customer information on the institution’s system and when it’s in transit. 4. Assess apps developed by the institution. 5. Implement multi-factor authentication for anyone accessing customer information on the institution’s system. 6. Dispose of customer information securely. 7. Anticipate and evaluate changes to the information system or network. 8. Maintain a log of authorized users’ activity and keep an eye out for unauthorized access. d) Provide for the institution to regularly test or otherwise monitor the effectiveness of the safeguards it has implemented (16 CFR 314.4(d)). e) Provide for the implementation of policies and procedures to ensure that personnel are able to enact the information security program (16 CFR 314.4(e)(1)). f) Address how the institution will oversee its information system service providers (16 CFR 314.4(f)). g) Provide for the evaluation and adjustment of its information security program in light of the results of the required testing and monitoring; any material changes to its operations or business arrangements; the results of the required risk assessments; or any other circumstances that it knows or has reason to know may have a material impact the institution’s information security program (16 CFR 314.4(g)). Additionally, the Uniform Guidance (2 CFR 200.303(a)) requires nonfederal entities receiving federal awards to establish and maintain effective internal controls designed to reasonably ensure compliance with Federal laws, statutes, regulations, and the terms and conditions of the Federal award. Furthermore, generally accepted information technology guidance endorses the implementation of a process to identify risk and ensure appropriate safeguards are in place to protect information technology systems and data. Condition During our audit procedures, we noted that the University risk assessment did not fully addressed all the elements required by (16 CFR 314.4). Accordingly, the following elements were missing: 1. Vulnerability test 2. Penetration test 3. No backup test was performed during year ended June 30, 2024. Cause In the past years there’s been a high turnover in the position of the qualified individual responsible for overseeing and implementing the University’s information cyber-security program. As a result, some of the procedures and policies established in the information cyber-security program risk assessment have not been consistently or continuously maintained, accordingly, the student personal information could be at risk. In addition, the USDE has informed through electronic announcements (EA), that “when an audit report that includes a GLBA audit finding is received, they will refer the audit to the Federal Trade Commission (FTC). Effect Once the finding is referred to the FTC, that finding will be considered closed for the USDE audit tracking purposes. The FTC will determine what action may be needed as a result of the GLBA audit finding. Identification of a repeat finding This is not a repeat finding from the immediate previous audit. Questioned cost N/A Context The Gramm-Leach-Bliley Act (GLBA) created a requirement that financial institutions must have certain information privacy protections and safeguards in place. The Federal Trade Commission (FTC) has enforcement authority for the requirements and has determined that institutions of higher education (institutions) are financial institutions under GLBA. Each institution has agreed to comply with GLBA in its Program Participation Agreement with the Department. In addition, as a condition of accessing the Department’s systems, each institution and servicer must sign the Student Aid Internet Gateway (SAIG) Enrollment Agreement, which states that the institution must ensure that all federal student aid applicant information is protected from access by or disclosure to unauthorized personnel. Institutions and third-party servicers are also required to demonstrate administrative capability in accordance with 34 C.F.R. § 668.16, including the maintenance of adequate checks and balances in their systems of internal control. An institution or servicer that does not maintain adequate internal controls over the security of student information may not be considered administratively capable. Recommendation We recommend that the University addresses the cause for the high turnover in the position of the qualified individual responsible for overseeing the implementation of policies and procedures, including internal controls, to ensure that they are in compliance with 16 CFR 314.4(b) and (c). Views of Responsible Officials and Planned Corrective Actions Management of the University agrees with this finding. Please refer to the corrective action plan on pages 61-63.
Finding No. 2024-003 – Special Tests and Provisions - Gramm-Leach-Bliley Act–Student Information Security Federal Program ALN 84.007 Federal Supplemental Educational Opportunity Grant Program ALN 84.033 Federal Work-Study Program ALN 84.063 Federal Pell Grant Program ALN 84.268 Federal Direct Student Loan Program Name of Federal Agency Teacher Education Assistance for College and Higher Education Grants (TEACH Grants) U.S. Department of Education (USDE) Type of Finding Internal Control/Compliance Category Significant deficiency Compliance Requirement Special Tests and Provisions Criteria Under an institution’s Program Participation Agreement with the Department of Education and the Gramm-Leach-Bliley Act, schools must protect student financial aid information, with particular attention to information provided to institutions by the Department or otherwise obtained in support of the administration of the federal student financial aid programs. The Gramm-Leach-Bliley Act (GLBA) (Pub. L. No. 106-102) requires financial institutions to explain their information-sharing practices to their customers and to safeguard sensitive data (16 CFR 314). The Federal Trade Commission considers Title IV-eligible institutions that participate in Title IV Educational Assistance Programs as “financial institutions” and subject to the Gramm-Leach-Bliley Act (16 CFR 313.3(k)(2)(vi)). The Standards for Safeguarding Customer Information, required by the GLBA (16 CFR §314.4) requires the University to: a) Designate a qualified individual responsible for overseeing and implementing the institution’s information security program and enforcing the information security program in compliance (16 CFR 314.4(a)). b) Provide for the information security program to be based on a risk assessment that identifies reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of customer information (as the term customer information applies to the institution) that could result in the unauthorized disclosure, misuse, alteration, destruction, or other compromise of such information, and assesses the sufficiency of any safeguards in place to control these risks (16 CFR 314.4(b)). c) Provide for the design and implementation of safeguards to control the risks the institution identifies through its risk assessment (16 CFR 314.4(c)). At a minimum, the institution’s written information security program must address the implementation of the minimum safeguards identified in 16 CFR 314.4(c)(1) through (8). The eight minimum safeguards that the written information security program must address are summarized as follows: 1. Implement and periodically review access controls. 2. Conduct a periodic inventory of data, noting where it’s collected, stored, or transmitted. 3. Encrypt customer information on the institution’s system and when it’s in transit. 4. Assess apps developed by the institution. 5. Implement multi-factor authentication for anyone accessing customer information on the institution’s system. 6. Dispose of customer information securely. 7. Anticipate and evaluate changes to the information system or network. 8. Maintain a log of authorized users’ activity and keep an eye out for unauthorized access. d) Provide for the institution to regularly test or otherwise monitor the effectiveness of the safeguards it has implemented (16 CFR 314.4(d)). e) Provide for the implementation of policies and procedures to ensure that personnel are able to enact the information security program (16 CFR 314.4(e)(1)). f) Address how the institution will oversee its information system service providers (16 CFR 314.4(f)). g) Provide for the evaluation and adjustment of its information security program in light of the results of the required testing and monitoring; any material changes to its operations or business arrangements; the results of the required risk assessments; or any other circumstances that it knows or has reason to know may have a material impact the institution’s information security program (16 CFR 314.4(g)). Additionally, the Uniform Guidance (2 CFR 200.303(a)) requires nonfederal entities receiving federal awards to establish and maintain effective internal controls designed to reasonably ensure compliance with Federal laws, statutes, regulations, and the terms and conditions of the Federal award. Furthermore, generally accepted information technology guidance endorses the implementation of a process to identify risk and ensure appropriate safeguards are in place to protect information technology systems and data. Condition During our audit procedures, we noted that the University risk assessment did not fully addressed all the elements required by (16 CFR 314.4). Accordingly, the following elements were missing: 1. Vulnerability test 2. Penetration test 3. No backup test was performed during year ended June 30, 2024. Cause In the past years there’s been a high turnover in the position of the qualified individual responsible for overseeing and implementing the University’s information cyber-security program. As a result, some of the procedures and policies established in the information cyber-security program risk assessment have not been consistently or continuously maintained, accordingly, the student personal information could be at risk. In addition, the USDE has informed through electronic announcements (EA), that “when an audit report that includes a GLBA audit finding is received, they will refer the audit to the Federal Trade Commission (FTC). Effect Once the finding is referred to the FTC, that finding will be considered closed for the USDE audit tracking purposes. The FTC will determine what action may be needed as a result of the GLBA audit finding. Identification of a repeat finding This is not a repeat finding from the immediate previous audit. Questioned cost N/A Context The Gramm-Leach-Bliley Act (GLBA) created a requirement that financial institutions must have certain information privacy protections and safeguards in place. The Federal Trade Commission (FTC) has enforcement authority for the requirements and has determined that institutions of higher education (institutions) are financial institutions under GLBA. Each institution has agreed to comply with GLBA in its Program Participation Agreement with the Department. In addition, as a condition of accessing the Department’s systems, each institution and servicer must sign the Student Aid Internet Gateway (SAIG) Enrollment Agreement, which states that the institution must ensure that all federal student aid applicant information is protected from access by or disclosure to unauthorized personnel. Institutions and third-party servicers are also required to demonstrate administrative capability in accordance with 34 C.F.R. § 668.16, including the maintenance of adequate checks and balances in their systems of internal control. An institution or servicer that does not maintain adequate internal controls over the security of student information may not be considered administratively capable. Recommendation We recommend that the University addresses the cause for the high turnover in the position of the qualified individual responsible for overseeing the implementation of policies and procedures, including internal controls, to ensure that they are in compliance with 16 CFR 314.4(b) and (c). Views of Responsible Officials and Planned Corrective Actions Management of the University agrees with this finding. Please refer to the corrective action plan on pages 61-63.