2 CFR 200 › § 200.303

Findings Citing § 200.303

Internal controls.

Total Findings
100,090
Across all audits in database
Showing Page
705 of 2002
50 findings per page
About this section
Section 200.303 requires recipients and subrecipients of Federal awards to establish and maintain effective internal controls to ensure compliance with Federal laws and award conditions. This section affects organizations receiving Federal funding, mandating them to monitor compliance, address noncompliance promptly, and protect sensitive information.
View full section details →
FY End: 2024-06-30
Twin Oaks Juvenile Development, Inc.
Compliance Requirement: C
CASH MANAGEMENT – CASH DRAWS Repeat of finding 2022-003, 2023-006 Finding Type: Material Weakness in Internal Controls over Compliance, Material Noncompliance ALN Program Title: 93.676 – Unaccompanied Alien Children Program Federal Agency: U.S. Department of Health and Human Services Pass-Through Entity: Liberty Wilderness Crossroads Camp Contract Number: 90ZU0501 Criteria: Under 2 CFR 200.305(b) of the Uniform Guidance, non-federal entities “must minimize the time elapsing between the transfer ...

CASH MANAGEMENT – CASH DRAWS Repeat of finding 2022-003, 2023-006 Finding Type: Material Weakness in Internal Controls over Compliance, Material Noncompliance ALN Program Title: 93.676 – Unaccompanied Alien Children Program Federal Agency: U.S. Department of Health and Human Services Pass-Through Entity: Liberty Wilderness Crossroads Camp Contract Number: 90ZU0501 Criteria: Under 2 CFR 200.305(b) of the Uniform Guidance, non-federal entities “must minimize the time elapsing between the transfer of funds from the United States Treasury or the pass-through entity and the disbursement by the non-federal entity whether the payment is made by electronic funds transfer, or issuance or redemption of checks, warrants, or payment by other means.” Under 2 CFR 200.305(b)(5) of the Uniform Guidance, “To the extent available, the non-federal entity must disburse funds available from program income (including repayments to a revolving fund), rebates, refunds, contract settlements, audit recoveries, and interest earned on such funds before requesting additional cash payments.” Under 2 CFR 200.302(b)(6) of the Uniform Guidance, the Organization’s financial management system must provide for “written procedures to implement the requirements of 2 CFR 200.305.” Additionally, 2 CFR 200.303(a) of the Uniform Guidance requires non-federal entities to establish and maintain effective internal control over federal awards that provides reasonable assurance that the non-federal entity is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award. Condition: While the Organization did not draw cash in excess of program disbursements for the grant that was in effect during the current year, the Organization had previously drawn cash in excess of program disbursements under a grant that ended in the prior year so the Organization started and ended the year with a material balance of unspent grant funds for the program. Additionally, the Organization did not have written cash management policies and there was no process established for reviewing the pay requests prepared prior to submission. Cause: Policies and procedures were not in place to ensure that the time elapsing between the transfer of federal funds to the Organization and the disbursement of such funds for program purposes was minimized. In addition, policies and procedures were not in place to ensure that additional cash draws were not requested prior to disbursing all available funds for program related purposes. Effect: Overall program funds were drawn in excess of disbursements. The Organization could be required to return the excess funds to the grantor along with any associated earned interest. Questioned Costs: None Recommendation: We recommend that written policies and procedures be established to implement the requirements of 2 CFR 200.305, and recommend procedures be established for review of the cash draw requests prior to submission and that the review be documented. Views of Responsible Officials and Planned Corrective Actions: See management’s response and Corrective Action Plan on page 55.

FY End: 2024-06-30
Twin Oaks Juvenile Development, Inc.
Compliance Requirement: L
REPORTING – VARIOUS Repeat of finding 2023-007 Finding Type: Material Weakness in Internal Controls over Compliance, Material Noncompliance ALN and Program Title: 93.676 – Unaccompanied Alien Children Program Federal Agency: U.S. Department of Health and Human Services Pass-Through Entity: Liberty Wilderness Crossroads Camp Contract Number: 90ZU0501 Criteria: The program compliance supplement and grant agreements outline the reports required to be submitted and their due dates. Additionally, 2 C...

REPORTING – VARIOUS Repeat of finding 2023-007 Finding Type: Material Weakness in Internal Controls over Compliance, Material Noncompliance ALN and Program Title: 93.676 – Unaccompanied Alien Children Program Federal Agency: U.S. Department of Health and Human Services Pass-Through Entity: Liberty Wilderness Crossroads Camp Contract Number: 90ZU0501 Criteria: The program compliance supplement and grant agreements outline the reports required to be submitted and their due dates. Additionally, 2 CFR 200.303(a) of the Uniform Guidance requires non-federal entities to establish and maintain effective internal control over federal awards that provides reasonable assurance that the non-federal entity is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award. Condition: The auditor tested 1 quarterly and 1 annual Federal Financial Report (this was not a statistically valid sample) and noted the following: 1. There was no process for reviewing the reports that were prepared prior to submission. 2. The reports were submitted later than the due dates. 3. For all tested reports, the reported amounts did not agree with the Organization’s accounting records, the reported amounts did not agree within the reports, and/or the reported numbers were not cumulative as required by the reporting guidance. Cause: Procedures have not been established for reviewing the program reports, and management was unaware that the amounts reported should be cumulative. Additionally, the expenditures reported appear to be based on cash draws rather than actual program expenditures. Effect: Reports were not submitted timely and were inaccurate. Questioned Costs: None Recommendation: We recommend procedures be established for review of the program reports prior to submission to the grantors and that the review be documented, procedures be established to ensure reports are submitted timely, and a reconciliation of reported amounts to the accounting records be performed. Views of Responsible Officials and Planned Corrective Actions: See management’s response and Corrective Action Plan on page 55.

FY End: 2024-06-30
Twin Oaks Juvenile Development, Inc.
Compliance Requirement: AB
ACTIVITIES ALLOWED OR UNALLOWED, ALLOWABLE COSTS/COST PRINCIPLES – VARIOUS Repeat of finding 2022-005, 2023-005 Finding Type: Significant Deficiency in Internal Controls over Compliance, Noncompliance ALN and Program Title: 93.676 – Unaccompanied Alien Children Program Federal Agency: U.S. Department of Health and Human Services Pass-Through Entity: Liberty Wilderness Crossroads Camp Contract Number: 90ZU0501 Criteria: Under 2 CFR 200.405(d), “If a cost benefits two or more projects or activitie...

ACTIVITIES ALLOWED OR UNALLOWED, ALLOWABLE COSTS/COST PRINCIPLES – VARIOUS Repeat of finding 2022-005, 2023-005 Finding Type: Significant Deficiency in Internal Controls over Compliance, Noncompliance ALN and Program Title: 93.676 – Unaccompanied Alien Children Program Federal Agency: U.S. Department of Health and Human Services Pass-Through Entity: Liberty Wilderness Crossroads Camp Contract Number: 90ZU0501 Criteria: Under 2 CFR 200.405(d), “If a cost benefits two or more projects or activities in proportions that can be determined without undue effort or cost, the cost must be allocated to the projects based on the proportional benefit. However, when those proportions cannot be determined because of the interrelationship of the work involved, then… the costs may be allocated or transferred to benefitted projects on any reasonable documented basis.” Per the Organization’s policies and procedures, certain costs that benefit all programs should be allocated using allocation percentages that are calculated semi-annually. Under 2 CFR 200.438 of the Uniform Guidance, “Costs of entertainment, including amusement, diversion, and social activities and any associated costs (such as gifts), are unallowable unless they have a specific and direct programmatic purpose and are included in a federal award.” Per the program compliance supplement and 45 CFR 75.465, rental costs under “less-than-arm's-length” leases are allowable only up to the amount that would be allowed had the non-federal entity continued to own the property. This amount would include expenses such as depreciation, maintenance, taxes, and insurance. Additionally, 2 CFR 200.303(a) of the Uniform Guidance requires non-federal entities to establish and maintain effective internal control over federal awards that provides reasonable assurance that the nonfederal entity is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award. Condition: The auditor tested 70 program expenses (this was not a statistically valid sample) and noted the following: 1. For 4 expenses, the wrong allocation percentages were used to allocate costs for the period. 2. For 6 credit card expenses, the Organization did not have adequate supporting documentation. 3. For 2 credit card expenses, the total of the charges identified by the Organization do not agree to the expense recorded. 4. For 2 expenses, the costs are considered to be unallowable entertainment costs. 5. For 5 related party vehicle lease expenses, the portion paid over the amount allowed under 45 CFR 75.465 is considered to be unallowable. Cause: 1. Inadequate management review of allocations used for the costs and/or inadequate support for the allocation of the costs. 2. Management approval of credit card charges that are not supported by receipts or other documentation, or the Organization not maintaining the supporting documentation. 3. Difficulties with the credit card company where the Organization could not reconcile the costs in the statement to those that the employees were coding, and differences were typically coded to travel expenses. 4. Inadequate management review of costs that are allowable vs. unallowable for the program. Effect: Incorrectly allocated, unsupported, and unallowable costs were charged to the program, which could result in the grantor requiring repayment. Questioned Costs: Known questioned costs total $9,539, determined by calculating the difference between the costs allocated to the program and the costs that should have been allocated to the program using the allocation percentages in effect at the time the expenses occurred, and by totaling unsupported and unallowable costs. Likely questioned costs total $29,713, determined by dividing the known questioned costs by the total of the sample and applying the error rate to the population of expenditures. Recommendation: We recommend management more specifically review the allocations used when reviewing costs that are allocated among programs, that management ensure all credit card charges are adequately supported and not charge unsupported costs to federal awards, and that management gain a better understanding of allowable and unallowable costs for the program and ensure unallowable costs are not charged to the program. Views of Responsible Officials and Planned Corrective Actions: See management’s response and Corrective Action Plan on page 55.

FY End: 2024-06-30
Twin Oaks Juvenile Development, Inc.
Compliance Requirement: B
ALLOWABLE COSTS/COST PRINCIPLES – PAYROLL ALLOCATIONS Repeat of finding 2023-009 Finding Type: Significant Deficiency in Internal Controls over Compliance ALN/CSFA and Program Title: 93.558 – Temporary Assistance for Needy Families, 93.658 – Foster Care - Title IV-E, 93.676- Unaccompanied Alien Children Program, 60.074 – Out-of-Home Supports Federal/State Agency: U.S. Department of Health and Human Services, Florida Department of Children and Families Pass-Through Entity: Big Bend Community Base...

ALLOWABLE COSTS/COST PRINCIPLES – PAYROLL ALLOCATIONS Repeat of finding 2023-009 Finding Type: Significant Deficiency in Internal Controls over Compliance ALN/CSFA and Program Title: 93.558 – Temporary Assistance for Needy Families, 93.658 – Foster Care - Title IV-E, 93.676- Unaccompanied Alien Children Program, 60.074 – Out-of-Home Supports Federal/State Agency: U.S. Department of Health and Human Services, Florida Department of Children and Families Pass-Through Entity: Big Bend Community Based Care, Inc. dba NWF Health Network; Brevard Family Partnership; Children’s Network of Hillsborough; Children’s Network of Southwest Florida Social Services; Communities Connected for Kids; Community Partnership for Children; Embrace Families, Inc.; Family Support Services of North Florida, Inc.; Family Support Services of Suncoast; Heartland for Children; Kids Central, Inc.; Partnership for Strong Families; Safe Children Coalition, Inc., Liberty Wilderness Crossroads Camp Contract Number: 0299-22, C0900, PCM783, PCM788, 90ZU0501 Criteria: Under 2 CFR 200.430(g) of the Uniform Guidance, "Charges to federal awards for salaries and wages must be based on records that accurately reflect the work performed", and "Budget estimates (meaning, estimates determined before the services are performed) alone do not qualify as support for charges to federal awards...". Per the Reference Guide for State Expenditures of the Florida Department of Financial Services, "Timesheets that support the hours worked on the project or activity must be kept." Additionally, 2 CFR 200.303(a) of the Uniform Guidance requires non-federal entities to establish and maintain effective internal control over federal awards that provides reasonable assurance that the non-federal entity is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award, and Section 215.97(10), Florida Statutes, requires nonstate entities to have internal controls in place to provide reasonable assurance of compliance with the provisions of laws, regulations, and other rules, pertaining to state awards that have a material effect on each major state project. Condition: Time and pay for certain employees who perform work for multiple programs is allocated among these programs. The allocations are based on program budgets or other budgeted expectations of the employees’ activity. The Organization's internal control structure does not address adjusting these allocations to reflect actual time and effort expended. Cause: These employees do not record their time to each program, and management was unaware of federal and state requirements for documentation of personnel costs and charged to federal programs and state projects. Effect: Time and pay being allocated charged to the programs may not accurately reflect their actual time spent on each program. Questioned Costs: None Recommendation: We recommend all employees record their time to each program that they work on, or that time studies be completed at least annually by the employees whose time needs to be allocated and those time studies be used to determine how the employes’ time and pay should be allocated. Views of Responsible Officials and Planned Corrective Actions: See management’s response and Corrective Action Plan on page 55.

FY End: 2024-06-30
Twin Oaks Juvenile Development, Inc.
Compliance Requirement: B
ALLOWABLE COSTS/COST PRINCIPLES – INDIRECT COSTS Repeat of finding 2023-010 Finding Type: Significant Deficiency in Internal Controls over Compliance ALN/CSFA and Program Title: 93.558 – Temporary Assistance for Needy Families, 93.658 – Foster Care - Title IV-E, 93.676- Unaccompanied Alien Children Program Federal/State Agency: U.S. Department of Health and Human Services Pass-Through Entity: Big Bend Community Based Care, Inc. dba NWF Health Network; Brevard Family Partnership; Children’s Netwo...

ALLOWABLE COSTS/COST PRINCIPLES – INDIRECT COSTS Repeat of finding 2023-010 Finding Type: Significant Deficiency in Internal Controls over Compliance ALN/CSFA and Program Title: 93.558 – Temporary Assistance for Needy Families, 93.658 – Foster Care - Title IV-E, 93.676- Unaccompanied Alien Children Program Federal/State Agency: U.S. Department of Health and Human Services Pass-Through Entity: Big Bend Community Based Care, Inc. dba NWF Health Network; Brevard Family Partnership; Children’s Network of Hillsborough; Children’s Network of Southwest Florida Social Services; Communities Connected for Kids; Community Partnership for Children; Embrace Families, Inc.; Family Support Services of North Florida, Inc.; Family Support Services of Suncoast; Heartland for Children; Kids Central, Inc.; Partnership for Strong Families; Safe Children Coalition, Inc., Liberty Wilderness Crossroads Camp Contract Number: 0299-22, C0900, PCM783, PCM788, 90ZU0501 Criteria: The Organization has elected to charge the de minimis rate of 10% of modified total direct costs (MTDC). 2 CFR 200.1 of the Uniform Guidance defines MTDC as all direct salaries and wages, applicable fringe benefits, materials and supplies, services, travel, and up to the first $25,000 of each subaward (regardless of the period of performance of the subawards under the award). MTDC excludes equipment, capital expenditures, charges for patient care, rental costs, tuition remission, scholarships and fellowships, participant support costs and the portion of each subaward in excess of $25,000. Other items may only be excluded when necessary to avoid a serious inequity in the distribution of indirect costs, and with the approval of the cognizant agency for indirect costs. Additionally, 2 CFR 200.303(a) of the Uniform Guidance requires non-federal entities to establish and maintain effective internal control over federal awards that provides reasonable assurance that the non-federal entity is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award, and Section 215.97(10), Florida Statutes, requires nonstate entities to have internal controls in place to provide reasonable assurance of compliance with the provisions of laws, regulations, and other rules, pertaining to state awards that have a material effect on each major state project. Condition: The Organization used total program expenses as the MTDC base for calculating the 10% de minimis indirect costs and did not exclude certain items that are required to be excluded, such as rental costs, equipment, and charges for patient care. Additionally, the Organization's internal controls do not require review of the indirect costs charged to programs. Cause: Management was unaware of the requirements for calculating the MTDC and procedures have not been established for reviewing the indirect cost allocations. Effect: While indirect costs charged to programs in the current year did not exceed the allowable amount, the use of direct costs excluded from MTDC in the calculation and lack of review may result in excess indirect costs charged. Questioned Costs: None Recommendation: We recommend management calculate the MTDC in accordance with Uniform Guidance and apply the indirect cost rate consistently for all programs. We also recommend a procedure be established for review of the indirect cost allocations performed. Views of Responsible Officials and Planned Corrective Actions: See management’s response and Corrective Action Plan on page 55.

FY End: 2024-06-30
Twin Oaks Juvenile Development, Inc.
Compliance Requirement: I
PROCUREMENT AND SUSPENSION AND DEBARMENT – SMALL, FORMAL, AND NONCOMPETITIVE PROCUREMENTS Finding Type: Significant Deficiency in Internal Controls over Compliance ALN and Program Title: 93.676 – Unaccompanied Alien Children Program Federal Agency: U.S. Department of Health and Human Services Pass-Through Entity: Liberty Wilderness Crossroads Camp Contract Number: 90ZU0501 Criteria: 2 CFR 200 Subpart D of the Uniform Guidance outlines standards for procurement transactions made with federal fund...

PROCUREMENT AND SUSPENSION AND DEBARMENT – SMALL, FORMAL, AND NONCOMPETITIVE PROCUREMENTS Finding Type: Significant Deficiency in Internal Controls over Compliance ALN and Program Title: 93.676 – Unaccompanied Alien Children Program Federal Agency: U.S. Department of Health and Human Services Pass-Through Entity: Liberty Wilderness Crossroads Camp Contract Number: 90ZU0501 Criteria: 2 CFR 200 Subpart D of the Uniform Guidance outlines standards for procurement transactions made with federal funds. Additionally, 2 CFR 200.303(a) of the Uniform Guidance requires non-federal entities to establish and maintain effective internal control over federal awards that provides reasonable assurance that the non-federal entity is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award. Condition: The auditor tested 4 small, formal, and noncompetitive procurements which were also covered transactions (this was not a statistically valid sample). For all procurements tested, all necessary documentation of the procurement process was not maintained, the procurement method used was incorrect or there was no documented justification for the procurement to be noncompetitive, and there was no evidence the Organization verified that vendor was not suspended or debarred. For 3 procurements, the original procurement was done many years ago and management has not changed vendors and has not documented a reasoning for this. Cause: The Organization’s policies and procedures for purchasing do not align with Uniform Guidance. Additionally, the existing procurement policies were not followed. Effect: Procurements were potentially not made in compliance with Uniform Guidance. Questioned Costs: None Recommendation: We recommend the Organization update its policies and procedures for purchasing and suspension and debarment to align with Uniform Guidance or other requirements, whichever are more restrictive, and maintain all necessary documentation of the procurement process for purchases. We also recommend management re-evaluate vendors periodically and document any reasoning for not performing a new procurement for the goods or services. Views of Responsible Officials and Planned Corrective Actions: See management’s response and Corrective Action Plan on page 55.

FY End: 2024-06-30
Twin Oaks Juvenile Development, Inc.
Compliance Requirement: L
REPORTING – VARIOUS Repeat of finding 2023-013 Finding Type: Significant Deficiency in Internal Controls over Compliance ALN/CSFA and Program Title: 93.558 – Temporary Assistance for Needy Families, 93.658 – Foster Care - Title IV-E, 60.074 – Out-of-Home Supports Federal/State Agency: U.S. Department of Health and Human Services, Florida Department of Children and Families Pass-Through Entity: Big Bend Community Based Care, Inc. dba NWF Health Network; Brevard Family Partnership; Children’s Netw...

REPORTING – VARIOUS Repeat of finding 2023-013 Finding Type: Significant Deficiency in Internal Controls over Compliance ALN/CSFA and Program Title: 93.558 – Temporary Assistance for Needy Families, 93.658 – Foster Care - Title IV-E, 60.074 – Out-of-Home Supports Federal/State Agency: U.S. Department of Health and Human Services, Florida Department of Children and Families Pass-Through Entity: Big Bend Community Based Care, Inc. dba NWF Health Network; Brevard Family Partnership; Children’s Network of Hillsborough; Children’s Network of Southwest Florida Social Services; Communities Connected for Kids; Community Partnership for Children; Embrace Families, Inc.; Family Support Services of North Florida, Inc.; Family Support Services of Suncoast; Heartland for Children; Kids Central, Inc.; Partnership for Strong Families; Safe Children Coalition, Inc. Contract Number: 0299-22, C0900, PCM783, PCM788 Criteria: The grant agreements outline the reports required to be submitted and their due dates. Additionally, 2 CFR 200.303(a) of the Uniform Guidance requires non-federal entities to establish and maintain effective internal control over federal awards that provides reasonable assurance that the non-federal entity is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award, and Section 215.97(10), Florida Statutes, requires nonstate entities to have internal controls in place to provide reasonable assurance of compliance with the provisions of laws, regulations, and other rules, pertaining to state awards that have a material effect on each major state project. Condition: Certain grants and reports for these programs overlap. The auditor tested a total of 69 reports between these programs (this was not a statistically valid sample) and noted the following: 1. For 17 reports, the reports were submitted later than the due date. 2. For 61 reports, there was either no process for reviewing the reports that were prepared prior to submission or there was a review process but no documented evidence that the review occurred. 3. For 1 report, the Organization could not provide evidence that the report was submitted to the grantor. 4. For 3 reports, the reported amounts did not agree with the Organization’s accounting records. Cause: Management has not established procedures for reviewing certain program reports and/or the reviews failed to catch reporting errors and ensure reports were submitted timely. Effect: Certain reports were not submitted timely or may not have been submitted to the grantor, and certain reports were inaccurate. Questioned Costs: None Recommendation: We recommend procedures be established for review of all program reports prior to submission to the grantors and that the review be documented, procedures be established to ensure reports are submitted timely, and reconciliations of reported amounts to the accounting records be performed. Views of Responsible Officials and Planned Corrective Actions: See management’s response and Corrective Action Plan on page 55.

FY End: 2024-06-30
State of Nevada
Compliance Requirement: G
2024-031: U.S. Department of Education Special Education (IDEA) Cluster Special Education Grants to States, 84.027 COVID-19 Special Education Grants to States, 84.027 Special Education Preschool Grants, 84.173 Matching, Level of Effort, and Earmarking Material Weakness in Internal Control over Compliance and Material Noncompliance Grant Award Number: Affects all grant awards included under assistance listing 84.027 on the Schedule of Expenditures of Federal Awards. Criteria: Title 2 U.S. Code of...

2024-031: U.S. Department of Education Special Education (IDEA) Cluster Special Education Grants to States, 84.027 COVID-19 Special Education Grants to States, 84.027 Special Education Preschool Grants, 84.173 Matching, Level of Effort, and Earmarking Material Weakness in Internal Control over Compliance and Material Noncompliance Grant Award Number: Affects all grant awards included under assistance listing 84.027 on the Schedule of Expenditures of Federal Awards. Criteria: Title 2 U.S. Code of Federal Regulations (CFR) Part 200 Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards (Uniform Guidance) section 200.303 provides that non-federal entities must establish and maintain effective internal control that provides reasonable assurance that the non-federal entity is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award. Local Educational Agencies (LEA) must meet a local maintenance of effort. IDEA, Part B funds received by an LEA cannot be used, except under certain limited circumstances, to reduce the level of expenditures for the education of children with disabilities made by the LEA from local funds, or a combination of state and local funds, below the level of those expenditures for the preceding fiscal year. To meet this requirement, LEAs must meet (1) the eligibility standard and (2) the compliance standard. The eligibility standard is budgeted expenditures and the compliance standard is actual expenditures. For purposes of establishing the LEA’s eligibility for an award for a fiscal year, the State Educational Agencies (SEA) must determine that the LEA is meeting the eligibility standard (34 CFR section 300.203(a)). Condition: The Nevada Department of Education (NDE) monitors the LEA’s maintenance of effort with regards to the compliance standard (actual expenditures) rather than to the eligibility standard (by budget). In addition, the actual expenditures used in the monitoring did not agree to the underlying supporting documentation. Cause: NDE did not have adequate internal controls to ensure the amounts used in monitoring the LEA maintenance of effort were accurate. Effect: LEA’s may not be in compliance with the maintenance of effort requirement and it may not be detected. Questioned Costs: None Context/Sampling: A non-statistical sample of four school districts out of a population of 18 was selected for testing. In addition, the State Public Charter School Authority (SPCSA) is a LEA and aggregates 43 underlying charter schools. A nonstatistical sample of five out of 43 charter schools was also selected for testing. For one school district, we noted the amounts did not agree to the underlying supporting records. However, when using the underlying supporting records, the school district still met the maintenance of effort. In addition, we could not verify the amounts reported for all five charter schools selected for testing. Although financial statements were maintained, the amounts used to monitor the maintenance of effort were not reconciled or maintained. Repeat Finding from Prior Year: No Recommendation: We recommend NDE enhance internal controls to ensure the amounts used in monitoring the LEA maintenance of effort is accurate. In addition, we recommend documentation sounding in the eligibility standard be maintained in accordance with 34 CFR section 300.230(a). Views of Responsible Officials: The Nevada Department of Education agrees with this finding.

FY End: 2024-06-30
State of Nevada
Compliance Requirement: G
2024-030: U.S. Department of Education Title I Grants to Local Educational Agencies, 84.010 Matching, Level of Effort, and Earmarking Significant Deficiency in Internal Control over Compliance Grant Award Number: Affects all grant awards included under assistance listing 84.010 on the Schedule of Expenditures of Federal Awards. Criteria: Title 2 U.S. Code of Federal Regulations (CFR) Part 200 Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards (Uniform...

2024-030: U.S. Department of Education Title I Grants to Local Educational Agencies, 84.010 Matching, Level of Effort, and Earmarking Significant Deficiency in Internal Control over Compliance Grant Award Number: Affects all grant awards included under assistance listing 84.010 on the Schedule of Expenditures of Federal Awards. Criteria: Title 2 U.S. Code of Federal Regulations (CFR) Part 200 Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards (Uniform Guidance) section 200.303 provides that non-federal entities must establish and maintain effective internal control that provides reasonable assurance that the non-federal entity is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award. A Local Educational Agency (LEA) may receive funds under Title I only if the State Educational Agency (SEA) finds that the combined fiscal effort per student or the aggregate expenditures of the LEA from State and local funds for free public education for the preceding year was not less than 90 percent of the combined fiscal effort or aggregate expenditures for the second preceding year, unless specifically waived by the U.S. Department of Education (34 CFR section 299.5). Condition: The Nevada Department of Education (NDE) monitors the LEA fiscal effort; however, there was no documentation retained to evidence that two individuals (segregation of duties) were involved in the review of the LEA information. Cause: NDE did not have adequate internal controls to ensure maintenance of effort monitoring was reviewed by a party other than the preparer for accuracy and appropriate review of compliance. Effect: Noncompliance with maintenance of effort requirements may not be detected and NDE may not make required funding adjustments. Questioned Costs: None Context/Sampling: No sampling was performed, the maintenance of effort is monitored in an excel workbook as a whole. Repeat Finding from Prior Year: Yes – prior year finding 2023-034. Recommendation: We recommend NDE enhance internal controls to ensure maintenance of effort monitoring is reviewed by a party other than the preparer for accuracy and appropriate review of compliance. Views of Responsible Officials: The Nevada Department of Education agrees with this finding.

FY End: 2024-06-30
State of Nevada
Compliance Requirement: L
2024-034: U.S. Department of Education COVID-19 Education Stabilization Fund, 84.425 Reporting Material Weakness in Internal Control over Compliance and Material Noncompliance Grant Award Number: Affects all grant awards included under assistance listing 84.425 on the Schedule of Expenditures of Federal Awards. Criteria: The OMB Compliance Supplement provides that State Educational Agencies submit annual reports over Governor’s Emergency Education Relief (GEER), Elementary and Secondary School E...

2024-034: U.S. Department of Education COVID-19 Education Stabilization Fund, 84.425 Reporting Material Weakness in Internal Control over Compliance and Material Noncompliance Grant Award Number: Affects all grant awards included under assistance listing 84.425 on the Schedule of Expenditures of Federal Awards. Criteria: The OMB Compliance Supplement provides that State Educational Agencies submit annual reports over Governor’s Emergency Education Relief (GEER), Elementary and Secondary School Emergency Relief (ESSER) Grants and Emergency Assistance to Non-Public Schools (EANS). Each report contains data on expenditures, planned expenditures, subrecipients, and use of funds, including mandatory reservations. Title 2 U.S. Code of Federal Regulations (CFR) Part 200 Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards (Uniform Guidance) section 200.303 provides that non-federal entities must establish and maintain effective internal control that provides reasonable assurance that the non-federal entity is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award. Condition: Certain amounts included in the annual reports submitted did not agree to underlying support or underlying support for amounts reported were not maintained. In addition, there was no evidence of review and approval (segregation of duties) between the preparer and reviewer of the reports. Cause: The Nevada Department of Education (NDE) did not have internal controls to identify required information to be reported, ensure accuracy, or maintain adequate document retention to support compliance. Effect: Inaccurate or incomplete information was reported to the federal awarding agency or was not reported timely. Questioned Costs: None Context/Sampling: All six annual reports required to be filed in the fiscal year were selected for testing; three reports for ESSER, two for GEER and one for EANS. Variances were noted as follows: ESSER I Year 4 Annual Report • Amounts reported for key line 3b.1 – LEA expenditures by ESSER subgrant fund, expenditure category, and object code o Support for two schools reported was not maintained o Three schools did not agree to the underlying support, with variances ranging from variances of $367 to $746,160 • Amounts reported for key line 3c – allocation of ESSER funds to schools and criteria used to allocate funds to schools o Support for three schools reported was not maintained o Seven schools were improperly excluded from the report ESSER II Year 3 Annual Report • Amounts reported for key line 3b.1 – LEA expenditures by ESSER subgrant fund, expenditure category, and object code o One school was improperly excluded from the report o 22 schools did not agree to underlying support, with variances ranging from $64 to $113,620,036. ESSER III Year 3 Annual Report • Amounts reported for key line 3b.1 – LEA expenditures by ESSER subgrant fund, expenditure category, and object code o Support for one school reported was not maintained o Seven schools were improperly excluded from the report o Ten schools did not agree to underlying support, with variances ranging from $6 to $150,869,445 All ESSER Reports • Amounts reported for key line 5a – full time equivalent positions o Support for three schools reported was not maintained o Nine schools did not agree to the underlying support, with variances ranging from 3.98 FTE to 252 FTE • Amounts reported for key line 3b.10 – Number of specific positions supported with ESSER funds o Support for three schools reported was not maintained o Six schools were improperly excluded from the report o Eight schools did not agree to the underlying support, with variances ranging from 0.5 FTE to 175 FTE GEER I Year 4 Report • Amounts reported for Key Line 2.c and 2.d – administrative and nonadministrative expenditures by Governors o Support was not maintained • Amounts reported for key line 9.a – reporting on LEA expenditures by GEER subgrant fund and expenditure category o Three schools did not agree to the underlying support, with variances ranging from $6,419 to $60,495 • Amounts reported for key line 10.a and 11.a – reporting IHE expenditures by GEER subgrant and expenditure category o One school did not agree to the underlying support, with a variance of $4,000,237 GEER II Year 3 Report • Amounts reported for Key Line 2.c and 2.d – administrative and nonadministrative expenditures by Governors o Support was not maintained • Amounts reported for key line 9.a – reporting on LEA expenditures by GEER subgrant fund and expenditure category o Support was not maintained for two schools o Two schools did not agree to the underlying support, with variances ranging from $676 to $63,578 EANS Year 3 Annual Report • Amounts reported for Key Line 13 – reporting on SEA obligations by allowable activity for CRRSA EANS o Support was not maintained • Amounts reported for key line 15 – reporting on non-public schools receiving services or assistance under CCRSA EANS o Support for four schools was not maintained o Two schools did not agree to the underlying support, with variances ranging from 7 to 12 students Lastly, there was no evidence of review and approval (segregation of duties) for all reports tested. Repeat Finding from Prior Year: Yes – prior year finding 2023-037. Recommendation: We recommend NDE implement internal controls to identify required information to be reported, ensure accuracy, and maintain adequate document retention to support compliance. Views of Responsible Officials: The Nevada Department of Education agrees with this finding.

FY End: 2024-06-30
State of Nevada
Compliance Requirement: G
2024-045: U.S. Department of Health and Human Services CCDF Cluster: Child Care and Development Block Grant, 93.575 COVID-19 Child Care and Development Block Grant, 93.575 Child Care Mandatory and Matching Funds of the Child Care and Development Fund, 93.596 Matching, Level of Effort, and Earmarking Significant Deficiency in Internal Control over Compliance Grant Award Number: Affects all grant awards included under assistance listing 93.596 on the Schedule of Expenditures of Federal Awards. Cri...

2024-045: U.S. Department of Health and Human Services CCDF Cluster: Child Care and Development Block Grant, 93.575 COVID-19 Child Care and Development Block Grant, 93.575 Child Care Mandatory and Matching Funds of the Child Care and Development Fund, 93.596 Matching, Level of Effort, and Earmarking Significant Deficiency in Internal Control over Compliance Grant Award Number: Affects all grant awards included under assistance listing 93.596 on the Schedule of Expenditures of Federal Awards. Criteria: Title 2 U.S. Code of Federal Regulations (CFR) Part 200 Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards (Uniform Guidance) section 200.303 provides that non-federal entities must establish and maintain effective internal control that provides reasonable assurance that the non-federal entity is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award. Applicable to the matching fund (assistance listing 93.596), state expenditures will be matched at the Federal Medical Assistance Percentage (FMAP) rate for the applicable fiscal year. Private or public donated funds may be counted as state expenditures for this purpose subject to the limitations in 45 CFR section 98.53. Condition: The Nevada Division of Social Services (DSS) utilizes donated in-kind services from partner agencies and subrecipients to satisfy the match requirement for the matching fund. The in-kind services are cumulatively tracked and applied against the required match. During our audit procedures, we noted instances where the amount reported for matching expenditures did not agree to the in-kind cumulative tracker and instances where the underlying support (certified match letters received from partner agencies and subrecipients) did not agree to the tracker. Cause: DSS did not have adequate internal controls to ensure the in-kind service match amounts are reconciled and reported accurately. Effect: Inaccurate amounts available for match may be maintained and may impact whether the matching requirement is met. Questioned Costs: None Context/Sampling: The matching fund was tested for the federal fiscal year 2021 matching grant, which had a period performance end of September 30, 2023. The match required was $9,070,648. The match reconciled in the cumulative balance tracker was $10,087,427. The match contributed from partner agencies and subrecipients from support maintained was noted as $8,731,155; however, the cumulative available match available from prior years exceeded $45 million and was adequate for the required current year match of $9,070,648. Repeat Finding from Prior Year: Yes – prior year finding 2023-047. Recommendation: We recommend DSS enhance internal controls to ensure in-kind service match amounts are reconciled and reported accurately. Views of Responsible Officials: The Nevada Division of Social Services agrees with this finding.

FY End: 2024-06-30
State of Nevada
Compliance Requirement: L
2024-037: U.S. Department of Health and Human Services Epidemiology and Laboratory Capacity for Infectious Diseases, 93.323 COVID-19 Epidemiology and Laboratory Capacity for Infectious Diseases, 93.323 Reporting Significant Deficiency in Internal Control over Compliance Grant Award Number: Affects all grant awards included under assistance listing 93.323 on the Schedule of Expenditures of Federal Awards. Criteria: The OMB Compliance Supplement requires that reports submitted to the federal award...

2024-037: U.S. Department of Health and Human Services Epidemiology and Laboratory Capacity for Infectious Diseases, 93.323 COVID-19 Epidemiology and Laboratory Capacity for Infectious Diseases, 93.323 Reporting Significant Deficiency in Internal Control over Compliance Grant Award Number: Affects all grant awards included under assistance listing 93.323 on the Schedule of Expenditures of Federal Awards. Criteria: The OMB Compliance Supplement requires that reports submitted to the federal awarding agency include all activity of the reporting period, are supported by applicable accounting or performance records, and are fairly presented in accordance with governing requirements. The Nevada Division of Public and Behavioral Health (DPBH) must submit certain quarterly fiscal reports in accordance with the grant agreements. Title 2 U.S. Code of Federal Regulations (CFR) Part 200 Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards (Uniform Guidance) section 200.303 provides that non-federal entities must establish and maintain effective internal control that provides reasonable assurance that the non-federal entity is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award. Condition: Certain amounts included in the reports submitted did not agree to underlying support. Additionally, DPBH did not have internal controls in place to document the review by an individual independent of the preparation of the reports (segregation of duties). Cause: DPBH did not have adequate internal controls to ensure quarterly fiscal reports were reviewed by a person other than the preparer and that certain information reconciled to underlying supporting documentation. Effect: Inaccurate information was reported to the federal awarding agency. Questioned Costs: None Context/Sampling: A nonstatistical sample of six Quarterly Fiscal Reports out of a population of 40 was selected for testing. Variances were noted as follows: Reporting Period Ended March 31, 2024 (6 NU50CK000560-01-06): Amount Reported Amount Supported Contractual Expenditures $3 $385 Total Expenditures $2,319 $2,701 In addition, there was no evidence of segregation of duties for all six reports tested. Repeat Finding from Prior Year: No Recommendation: We recommend the DPBH enhance internal controls to ensure Quarterly Fiscal Reports are reconciled to underlying supporting documentation and are reviewed by an individual independent of the preparation of the reports. Views of Responsible Officials: The Nevada Division of Public and Behavioral Health agrees with this finding.

FY End: 2024-06-30
State of Nevada
Compliance Requirement: G
2024-040: U.S. Department of Health and Human Services Temporary Assistance for Needy Families, 93.558 COVID-19 Temporary Assistance for Needy Families, 93.558 Matching, Level of Effort, and Earmarking Significant Deficiency in Internal Control over Compliance Grant Award Number: Affects all grant awards included under assistance listing 93.558 on the Schedule of Expenditures of Federal Awards. Criteria: Title 2 U.S. Code of Federal Regulations (CFR) Part 200 Uniform Administrative Requirements,...

2024-040: U.S. Department of Health and Human Services Temporary Assistance for Needy Families, 93.558 COVID-19 Temporary Assistance for Needy Families, 93.558 Matching, Level of Effort, and Earmarking Significant Deficiency in Internal Control over Compliance Grant Award Number: Affects all grant awards included under assistance listing 93.558 on the Schedule of Expenditures of Federal Awards. Criteria: Title 2 U.S. Code of Federal Regulations (CFR) Part 200 Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards (Uniform Guidance) section 200.303 provides that non-federal entities must establish and maintain effective internal control that provides reasonable assurance that the non-federal entity is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award. As provided by 45 CFR section 264.1, the average monthly number of families that include an adult or minor child head of household, or the spouse of the head of household, who has received assistance under any state program funded by federal TANF funds for more than 60 countable months (whether or not consecutive) may not exceed 20 percent of the average monthly number of all families to which the state provided assistance during the fiscal year or the immediately preceding fiscal year (but not both), as the state may elect. Condition: The Nevada Division of Social Services (DSS) compiles the caseload criteria above in a TANF NEON Cash Cases Hardship Report. There was no evidence that this report was approved, reviewed, or otherwise monitored. Cause: DSS did not have internal controls to ensure caseload earmarking requirements are monitored. Effect: Noncompliance with earmarking requirements may not be detected. Questioned Costs: None Context/Sampling: The caseload report was generated for the entire state fiscal year. The average cases with more than 60 countable months were 0.21% of the total cases for the state fiscal year, which is below the 20% maximum allowed. However, this report is generated internally by DWSS on a quarterly basis (and aggregated to be summarized annually), and there was no evidence of a review being performed. Repeat Finding from Prior Year: Yes – prior year finding 2023-038. Recommendation: We recommend DSS enhance internal controls to ensure caseload earmarking requirements are monitored. Views of Responsible Officials: The Nevada Division Social Services agrees with this finding.

FY End: 2024-06-30
State of Nevada
Compliance Requirement: N
2024-052: Social Security Administration Disability Insurance/SSI Cluster Social Security – Disability Insurance, 96.001 Special Tests and Provisions – Qualified Providers Significant Deficiency in Internal Control over Compliance Grant Award Number: Affects all grant awards included under assistance listing 96.001 on the Schedule of Expenditures of Federal Awards. Criteria: Title 2 U.S. Code of Federal Regulations (CFR) Part 200 Uniform Administrative Requirements, Cost Principles, and Audit Re...

2024-052: Social Security Administration Disability Insurance/SSI Cluster Social Security – Disability Insurance, 96.001 Special Tests and Provisions – Qualified Providers Significant Deficiency in Internal Control over Compliance Grant Award Number: Affects all grant awards included under assistance listing 96.001 on the Schedule of Expenditures of Federal Awards. Criteria: Title 2 U.S. Code of Federal Regulations (CFR) Part 200 Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards (Uniform Guidance) section 200.303 provides that non-federal entities must establish and maintain effective internal control that provides reasonable assurance that the non-federal entity is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award. Title 20 U.S Code of Federal Regulations (CFR) Part 404 Federal Old-Age, Survivors and Disability Insurance states that each State agency is responsible for comprehensive oversight management of its process and for ensuring accuracy, integrity, and economy of its process. As part of these duties, disability determination services must have, and follow, procedures for performing medical license verifications to ensure that only qualified providers perform disability determination services’ task. Condition: The Nevada Division of Employment, Training and Rehabilitation (DETR) does not have written procedures for verifying, before engaging the services of a provider and at least annually thereafter, whether provides have valid medical licenses and are not currently excluded, suspended, or barred from participation in federal or federally assisted programs; and whose license to provide health care is not currently lawfully revoked or suspended by any state licensing authority for reasons of fraud, abuse, or professional misconduct. In addition, DETR has an individual assigned to this task as part of the position’s job duties. However, there is no evidence of monitoring by someone other than the individual (segregation of duties and oversight) that this procedure was followed and the results were appropriate. Cause: DETR does not have written procedures in place for this process. Effect: Providers may not have valid medical licenses or be suspended or debarred and not detected. Questioned Costs: None Context/Sampling: DETR does not have written policies and procedures. A nonstatistical sample of ten out of a population of 41 providers (i.e., medical staff, consultative examination providers, medical consultants, and psychological consultants). All were appropriately verified but the results were not monitored or reviewed by an individual other than the individual performing the verification. Repeat Finding from Prior Year: No Recommendation: We recommend DETR develop written policies and procedures over this process and implement a review and monitoring procedure to ensure the task has been completed accurately and timely. Views of Responsible Officials: The Nevada Division of Employment, Training, and Rehabilitation agrees with this finding.

FY End: 2024-06-30
State of Nevada
Compliance Requirement: G
2024-054: U.S. Department of Homeland Security Homeland Security Grant Program, 97.067 Matching, Level of Effort, and Earmarking Material Weakness in Internal Control over Compliance and Material Noncompliance Grant Award Number: Affects all grant awards included under assistance listing 97.067 on the Schedule of Expenditures of Federal Awards. Criteria: Title 2 U.S. Code of Federal Regulations (CFR) Part 200 Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federa...

2024-054: U.S. Department of Homeland Security Homeland Security Grant Program, 97.067 Matching, Level of Effort, and Earmarking Material Weakness in Internal Control over Compliance and Material Noncompliance Grant Award Number: Affects all grant awards included under assistance listing 97.067 on the Schedule of Expenditures of Federal Awards. Criteria: Title 2 U.S. Code of Federal Regulations (CFR) Part 200 Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards (Uniform Guidance) section 200.303 provides that non-federal entities must establish and maintain effective internal control that provides reasonable assurance that the non-federal entity is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award. As directed by section 2008(b)(2) of the Homeland Security Act of 2002 (codified as amended at 6 USC 609(b)(2)), all personnel and personnel-related costs, including those of intelligence analysts and operational overtime, are allowed up to 50 percent of HSGP funding without time limitation placed on the period of time that such personnel can serve. Condition: Support that demonstrated this requirement was monitored and evaluated was not provided. Cause: The Nevada Division of Emergency Management (DEM) did not have adequate internal controls to ensure personnel and personnel-related costs funded by HSGP were tracked, accumulated, and monitored for compliance with the earmarking requirement. Effect: Noncompliance with earmarking requirements may not be detected by DEM. Questioned Costs: None Context/Sampling: Personnel and personnel-related costs occur at both DEM and its subrecipients. At least 80% of the HSGP funding is provided to subrecipients where budgets are developed by program area. However, the personnel and personnel-related costs within the program areas are not accumulated, combined with DEM’s own costs, and evaluated for compliance with the 50% earmarking requirement. Therefore, this information was not provided for us to conclude the requirement was met. Repeat Finding from Prior Year: No Recommendation: We recommend DEM enhance internal controls to ensure personnel and personnel-related costs funded by HSGP are tracked, accumulated, and monitored for compliance with the earmarking requirement. Views of Responsible Officials: The Nevada Division of Emergency Management disagrees with this finding as specified in the corrective action plan. Auditor’s Comments to Views of Responsible Officials: The Uniform Guidance requires entities to demonstrate compliance. While we appreciate all the activities that DEM performs as described in their corrective action plan, ultimately DEM was unable to demonstrate that it complied with the requirement. There was no documentation made available for audit that would indicate DEM either met or did not meet the requirement as it was not monitored or compiled at an aggregate level.

FY End: 2024-06-30
State of Nevada
Compliance Requirement: L
2024-055: U.S. Department of Homeland Security Homeland Security Grant Program, 97.067 Reporting Material Weakness in Internal Control over Compliance Grant Award Number: Affects all grant awards included under assistance listings 97.067 on the Schedule of Expenditures of Federal Awards. Criteria: The OMB Compliance Supplement requires that reports submitted to the federal awarding agency include all activity of the reporting period, are supported by applicable accounting or performance records,...

2024-055: U.S. Department of Homeland Security Homeland Security Grant Program, 97.067 Reporting Material Weakness in Internal Control over Compliance Grant Award Number: Affects all grant awards included under assistance listings 97.067 on the Schedule of Expenditures of Federal Awards. Criteria: The OMB Compliance Supplement requires that reports submitted to the federal awarding agency include all activity of the reporting period, are supported by applicable accounting or performance records, and are fairly presented in accordance with governing requirements. The Nevada Division of Emergency Management (DEM) is required to submit the SF-425, Federal Financial Report on a quarterly basis. Title 2 U.S. Code of Federal Regulations (CFR) Part 200 Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards (Uniform Guidance) section 200.303 provides that non-federal entities must establish and maintain effective internal control that provides reasonable assurance that the non-federal entity is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award. Condition: Certain amounts included in the reports submitted did not agree to underlying support. Additionally, DEM did not have internal controls in place to document the review by an individual independent of the preparation of the reports (segregation of duties). Cause: DEM did not have adequate internal controls to ensure SF-425 reports were reviewed by a person other than the preparer and that reported information reconciled to underlying supporting documentation. Effect: Inaccurate information was reported to the federal awarding agency. Questioned Costs: None Context/Sampling: A nonstatistical sample nine out of a population of 17 SF-425 reports was selected for testing. A variance was noted as follows: Quarter End 9/30/2023 Grant Award EMW-2023-SS-00044 Amount Reported Amount Supported d. Total Federal Funds Authorized $0 $10,097,500 In addition, there was no evidence of segregation of duties for all nine reports tested. Repeat Finding from Prior Year: No Recommendation: We recommend DEM enhance internal controls to ensure SF-425 reports are reviewed by a person other than the preparer and that reported information reconciles to the underlying supporting documentation. Views of Responsible Officials: The Nevada Division of Emergency Management agrees with this finding.

FY End: 2024-06-30
State of Nevada
Compliance Requirement: L
2024-056: U.S. Department of Homeland Security Homeland Security Grant Program, 97.067 Reporting Significant Deficiency in Internal Control over Compliance Grant Award Number: Affects all grant awards with pass-through payments included under assistance listing 97.067 on the Schedule of Expenditures of Federal Awards. Criteria: The Federal Funding Accountability and Transparency Act (FFATA) requires direct recipients of certain federal awards to report subaward information by the end of the mont...

2024-056: U.S. Department of Homeland Security Homeland Security Grant Program, 97.067 Reporting Significant Deficiency in Internal Control over Compliance Grant Award Number: Affects all grant awards with pass-through payments included under assistance listing 97.067 on the Schedule of Expenditures of Federal Awards. Criteria: The Federal Funding Accountability and Transparency Act (FFATA) requires direct recipients of certain federal awards to report subaward information by the end of the month following the month in which the prime awardee obligates a subgrant award equal to or greater than $30,000. Title 2 U.S. Code of Federal Regulations (CFR) Part 200 Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards (Uniform Guidance) section 200.303 provides that non-federal entities must establish and maintain effective internal control that provides reasonable assurance that the non-federal entity is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award. Condition: Required subaward information reported in the FFATA Subaward Reporting System (FSRS) did not have evidence of review and approval by an individual independent of the submission of the information. Cause: The Nevada Division of Emergency Management (DEM) did not have internal controls to evidence review (segregation of duties) of subaward information submitted in accordance with the FFATA. Effect: Subaward obligations may not be accurately reported in the FSRS, and, therefore, the public information on FFATA’s website may be in error. Questioned Costs: None Context/Sampling: A nonstatistical sample of six out of a population of 39 applicable subaward obligations was selected for testing. There was no evidence of review for all six subaward obligations tested. Subawards Obligations Total Tested 6 $2,314,263 Not Reported 0 $0 Not Timely 0 $0 Obligation Incorrect 0 $0 Missing Key Elements 0 $0 Repeat Finding from Prior Year: No Recommendation: We recommend DEM implement internal controls to evidence review (segregation of duties) of subaward information submitted in accordance with the FFATA. Views of Responsible Officials: The Nevada Division of Emergency Management agrees with this finding.

FY End: 2024-06-30
Regional Office of Education #47
Compliance Requirement: M
FINDING 2024-002 – Subrecipient Monitoring (Partially Repeated from Prior Year Findings 23-002, 22-002, 21-003, 20-004, 19-005, 18-004, and 17-003) Federal Program: COVID-19 ARP – McKinney Education for Homeless Children Project No: 22-4998-HM and 24-4998-HM Federal Assistance Listing Number: 84.425W Passed Through: Illinois State Board of Education Federal Agency: U.S. Department of Education Criteria/Specific Requirement: A. The Uniform Administrative Requirements, Cost Principles, and Audit R...

FINDING 2024-002 – Subrecipient Monitoring (Partially Repeated from Prior Year Findings 23-002, 22-002, 21-003, 20-004, 19-005, 18-004, and 17-003) Federal Program: COVID-19 ARP – McKinney Education for Homeless Children Project No: 22-4998-HM and 24-4998-HM Federal Assistance Listing Number: 84.425W Passed Through: Illinois State Board of Education Federal Agency: U.S. Department of Education Criteria/Specific Requirement: A. The Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards (Uniform Guidance) require the Regional Office to ensure the process to monitor subrecipients of federal funds be consistent with the standards set forth in the Uniform Guidance at 2 CFR 200.332. B. The Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards (Uniform Guidance) section 200.303 Internal Controls states the following: “The non-Federal entity must: Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award.” Condition: The Regional Office of Education #47 did not perform subrecipient monitoring procedures including the preparation and retention of monitoring documentation. During audit testing procedures it was determined that: For one (1) of two (2) subrecipients tested, ROE #47: • Did not identify the subaward and applicable requirements in the agreements. • Did not conduct subrecipient monitoring procedures during the year ended June 30, 2024. For two (2) of two (2) subrecipients tested, ROE #47: • Did not evaluate the risk of noncompliance with Federal statutes, regulations, and the terms and conditions of the subaward. • Did not determine whether the subrecipient met the 2 CFR 200 Subpart F Audit requirements criteria for a single audit. Questioned Costs: None Context: The Regional Office of Education #47 expended a total of $917,485 of federal awards in fiscal year 2024. The Regional Office of Education #47 passed-through to subrecipients a total of $191,630 of federal awards in fiscal year 2024 of which $52,029 was funded by COVID-19 ARP – McKinney Education for Homeless Children grant. Effect: The Regional Office of Education #47 is not in compliance with Title 2 of the Code of Federal Regulations (CFR) Part 200.332 as it relates to subrecipient monitoring requirements. Additionally, the effect of noncompliance can result in questioned costs. Cause: Regional Office Management indicated the ROE is not adhering to established subrecipient monitoring policies and procedures to properly detect and prevent noncompliance with subrecipient monitoring requirements. Recommendation: We recommend that the Regional Office of Education #47 adhere to set subrecipient monitoring policies and procedures and maintain effective internal control over federal awards to ensure subrecipients are properly monitored as required by 2 CFR 200.332. This includes: a. Identifying the subaward and applicable requirements in the agreements; b. Evaluating the risk of noncompliance with Federal statutes, regulations, and the terms and conditions of the subaward; c. Utilizing risk assessment results to develop and implement necessary subrecipient monitoring procedures for the fiscal year; d. Conducting subrecipient monitoring procedures; e. Determining whether the subrecipient met the requirement criteria of 2 CFR 200 Subpart F Audit requirements for a single audit; and f. Retaining supporting monitoring documentation. Management’s Response: Effective with the FY25 School Year, the Regional Office will formally identify the subaward and the applicable requirements in our agreements. We will conduct and document subrecipient monitoring procedures. We will determine if the subrecipient met the requirement criteria of 2 CFR 22 Subpart F Audit requirements for a single audit.

FY End: 2024-05-31
University of Dubuque
Compliance Requirement: N
U.S. Department of Education Student Financial Assistance Programs Cluster (Direct) Federal Direct Loan Program (84.268) Federal Award Year: 2023-2024 Finding: The University did not timely or accurately report enrollment changes to the National Student Loan Data System (NSLDS). Criteria: Per 34 CFR 685.309(b), a school shall - (1) Upon receipt of an enrollment report from the Secretary, update all information included in the report and return the report to the Secretary in the manner and form...

U.S. Department of Education Student Financial Assistance Programs Cluster (Direct) Federal Direct Loan Program (84.268) Federal Award Year: 2023-2024 Finding: The University did not timely or accurately report enrollment changes to the National Student Loan Data System (NSLDS). Criteria: Per 34 CFR 685.309(b), a school shall - (1) Upon receipt of an enrollment report from the Secretary, update all information included in the report and return the report to the Secretary in the manner and format prescribed by the Secretary; and within the timeframe prescribed by the Secretary; and (2) Unless it expects to submit its next student updated enrollment report to the Secretary within the next 60 days, a school must notify the Secretary within 30 days if it discovers that a loan under Title IV of the Act was made to, or on behalf of, a student who was enrolled on at least a half-time basis or failed to enroll on at least a half-time basis for the period for which the loan was intended. Per 34 CFR 668.22(c)(ii), the withdrawal date is the date, as determined by the institution, that the student otherwise provided official notification to the institution, in writing or orally, of his or her intent to withdraw. Uniform Grant Guidance (2 CFR 200.303) requires nonfederal entities receiving Federal awards establish and maintain internal controls designed to reasonably ensure compliance with Federal laws, regulations and program compliance requirements. Effective internal controls should include procedures to ensure enrollment reporting is completed properly. Condition: 12 students were not reported as withdrawn within the 60 day timeframe for University’s reporting on the roster file submissions and the internal controls in place did not identify the errors. Cause: Student reporting was not within the 60 day roster submission timeframe. Effect: Noncompliance with federal regulations for enrollment reporting. Questioned costs: None. Context: 12 of the 25 students selected haphazardly and tested were not reported in accordance with NSLDS enrollment reporting and were within a range of five to six days late. Repeat finding: Yes. Recommendation: The University should accurately report all student status changes to the NSLDS. In addition, the University should review its policies and procedures to ensure withdrawal dates are accurately reflected in the enrollment management system and enrollment changes are reported timely. Views of responsible officials: Management agrees with this finding. See corrective action plan.

FY End: 2024-05-31
University of Dubuque
Compliance Requirement: N
U.S. Department of Education Student Financial Assistance Programs Cluster (Direct) Federal Direct Loan Program (84.268) Federal Award Year: 2023-2024 Finding: The University’s R2T4 calculation was improper for one student, as the student had not signed a promissory note for the direct loans and the direct loans should have not been included in the calculation. Criteria: Per 34 CFR 668.164, Any undisbursed Title IV aid for the period that the school uses as the basis for the R2T4 calculation i...

U.S. Department of Education Student Financial Assistance Programs Cluster (Direct) Federal Direct Loan Program (84.268) Federal Award Year: 2023-2024 Finding: The University’s R2T4 calculation was improper for one student, as the student had not signed a promissory note for the direct loans and the direct loans should have not been included in the calculation. Criteria: Per 34 CFR 668.164, Any undisbursed Title IV aid for the period that the school uses as the basis for the R2T4 calculation is counted as aid that could have been disbursed as long as the following conditions were met before the date the student became ineligible: For all programs, the Department processed a Student Aid Report (SAR) or Institutional Student Information Record (ISIR) with an official expected family contribution (EFC) for the student. (An official EFC is one calculated by the Department and provided on a SAR or ISIR. It may or may not be a valid EFC, which is one based on complete and correct information.) In all Title IV loan programs, a promissory note must be signed for a loan to be included as aid that could have been disbursed in an R2T4 calculation. The signature may be obtained after the student withdraws but must be signed before the school performs the R2T4 calculation. In addition, if a school has an affirmative confirmation process set up to actively determine if a student wants a Direct Loan, if the student declines or fails to respond to the request, the Direct Loan would not be included as aid that could have been disbursed. Uniform Grant Guidance (2 CFR 200.303) requires nonfederal entities receiving Federal awards establish and maintain internal controls designed to reasonably ensure compliance with Federal laws, regulations and program compliance requirements. Effective internal controls should include procedures to ensure enrollment reporting is completed properly. Condition: One student did not sign a promissory note for direct loans that were included in the R2T4 calculation; therefore, the University’s R2T4 calculation was improperly calculated and the internal controls in place did not identify the errors. Cause: Student did not sign a promissory note for direct loans. Effect: Noncompliance with federal regulations for R2T4 Questioned costs: Amount refunded was underpaid by $79. Context: One of the eight students selected randomly and tested did not sign a promissory note for direct loans that were included in the R2T4 calculation; therefore, the University’s R2T4 calculation was improperly calculated. Repeat finding: This is not a repeat finding. Recommendation: The University should review the controls and procedures in place to verify that only aid with signed promissory notes are being included in R2T4 calculations. Views of responsible officials: Management agrees with this finding. See corrective action plan.

FY End: 2024-05-31
University of Dubuque
Compliance Requirement: N
U.S. Department of Education Student Financial Assistance Programs Cluster Gramm-Leach Bliley Act – Student Information Security (84.007, 84.268, 84.038, 84.063, 84.378) Federal Award Year: 2023-2024 Finding: The University created and implemented a comprehensive information security policy, but did not have it done in a timely manner. Criteria: 2 CFR 200.303(a) requires that the non-Federal entity must establish and maintain effective internal control over the Federal award that provides reas...

U.S. Department of Education Student Financial Assistance Programs Cluster Gramm-Leach Bliley Act – Student Information Security (84.007, 84.268, 84.038, 84.063, 84.378) Federal Award Year: 2023-2024 Finding: The University created and implemented a comprehensive information security policy, but did not have it done in a timely manner. Criteria: 2 CFR 200.303(a) requires that the non-Federal entity must establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in Standards for Internal Control in the Federal Government issued by the Comptroller General of the United States or the Internal Control Integrated Framework, issued by the Committee of Sponsoring Organizations of the Treadway Commission. The Program Participation Agreement (PPA) with the U.S. Department of Education requires the institution to comply with the Standards for Safeguarding Customer Information as described in 16 CFR Part 314 which includes the development of a comprehensive written security program that includes the following parts: 16 CFR 314.4(a) requires institutions to designate a qualified individual responsible for overseeing and implementing the institution’s information security program and enforcing the information security program. 16 CFR 314.4(b) requires institutions to provide for the information security program to be based on a risk assessment that identifies reasonably foreseeable internal and external risks to the security, confidentiality and integrity of customer information (as the term customer information applies to the institution) that could result in the unauthorized disclosure, misuse, alteration, destruction or other compromise of such information, and assesses the sufficiency of any safeguards in place to control these risks. 16 CFR 314.4(c) requires institutions to provide for the design and implementation of safeguards to control the risks the institution provides through its risk assessment. 16 CFR 314.4(d) requires institutions to regularly test or otherwise monitor the effectiveness of the safeguards it has implemented 16 CFR 314.4(e) requires institutions to develop policies and procedures to ensure that personnel are able to enact the information security program. 16 CFR 314.4(f) requires institutions to develop policies and procedures to oversee its information system service providers. Condition: The institution’s written information security program was not done in a timely manner to include the following elements required by regulation as agreed to in the PPA: The written information security program does not designate an individual responsible for overseeing and implementing the institution’s information security program or enforcing the information security program. The institution has performed a risk assessment utilizing internal resources but has not based the information security program on the results of this assessment, nor has the institution included all required elements of internal and external risks to the security, confidentiality or integrity of customer information. The institution’s risk assessment is missing an inventory of IT systems that process and store customer information and the compliance with information security elements related to multifactor authentication, access control, change management, logging and alerting and encryption. The institution has not identified, designed or implemented safeguards for all of the risks identified in the risk assessment. The safeguards do not include the identification of security events or detection and response capabilities to support incident response. The institution has not been able to test safeguards because safeguards have not been designed or implemented in response to the risk assessment. The institution has not developed written policies and procedures to ensure that personnel are able to enact the information security program. There is a lack of evidence of leadership being required to report to the board or an appropriate supervisory council to ensure those charged with governance are informed on the current state of the information security program. The institution has not developed policies and procedures to oversee information service providers. Cause: The institution did not create and implement a comprehensive information security policy in a timely manner. Effect: The institution did not create and implement a comprehensive information security policy in a timely manner. The absence of internal controls and policies and procedures could result in the unauthorized disclosure, misuse, alteration, destruction or other compromise of student account information. Questioned costs: None. Context: Under an institution’s PPA with the U.S. Department of Education, schools must protect student financial aid information, with particular attention to information provided to institutions by the U.S. Department of Education or otherwise obtained in support of the administration of federal student financial aid programs. Repeat finding: This is not a repeat finding. Recommendation: We recommend that the University completes these requirements in a timely manner in the future. Views of responsible officials: Management agrees with this finding. See corrective action plan.

FY End: 2024-05-31
University of Dubuque
Compliance Requirement: N
U.S. Department of Education Student Financial Assistance Programs Cluster Gramm-Leach Bliley Act – Student Information Security (84.007, 84.268, 84.038, 84.063, 84.378) Federal Award Year: 2023-2024 Finding: The University created and implemented a comprehensive information security policy, but did not have it done in a timely manner. Criteria: 2 CFR 200.303(a) requires that the non-Federal entity must establish and maintain effective internal control over the Federal award that provides reas...

U.S. Department of Education Student Financial Assistance Programs Cluster Gramm-Leach Bliley Act – Student Information Security (84.007, 84.268, 84.038, 84.063, 84.378) Federal Award Year: 2023-2024 Finding: The University created and implemented a comprehensive information security policy, but did not have it done in a timely manner. Criteria: 2 CFR 200.303(a) requires that the non-Federal entity must establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in Standards for Internal Control in the Federal Government issued by the Comptroller General of the United States or the Internal Control Integrated Framework, issued by the Committee of Sponsoring Organizations of the Treadway Commission. The Program Participation Agreement (PPA) with the U.S. Department of Education requires the institution to comply with the Standards for Safeguarding Customer Information as described in 16 CFR Part 314 which includes the development of a comprehensive written security program that includes the following parts: 16 CFR 314.4(a) requires institutions to designate a qualified individual responsible for overseeing and implementing the institution’s information security program and enforcing the information security program. 16 CFR 314.4(b) requires institutions to provide for the information security program to be based on a risk assessment that identifies reasonably foreseeable internal and external risks to the security, confidentiality and integrity of customer information (as the term customer information applies to the institution) that could result in the unauthorized disclosure, misuse, alteration, destruction or other compromise of such information, and assesses the sufficiency of any safeguards in place to control these risks. 16 CFR 314.4(c) requires institutions to provide for the design and implementation of safeguards to control the risks the institution provides through its risk assessment. 16 CFR 314.4(d) requires institutions to regularly test or otherwise monitor the effectiveness of the safeguards it has implemented 16 CFR 314.4(e) requires institutions to develop policies and procedures to ensure that personnel are able to enact the information security program. 16 CFR 314.4(f) requires institutions to develop policies and procedures to oversee its information system service providers. Condition: The institution’s written information security program was not done in a timely manner to include the following elements required by regulation as agreed to in the PPA: The written information security program does not designate an individual responsible for overseeing and implementing the institution’s information security program or enforcing the information security program. The institution has performed a risk assessment utilizing internal resources but has not based the information security program on the results of this assessment, nor has the institution included all required elements of internal and external risks to the security, confidentiality or integrity of customer information. The institution’s risk assessment is missing an inventory of IT systems that process and store customer information and the compliance with information security elements related to multifactor authentication, access control, change management, logging and alerting and encryption. The institution has not identified, designed or implemented safeguards for all of the risks identified in the risk assessment. The safeguards do not include the identification of security events or detection and response capabilities to support incident response. The institution has not been able to test safeguards because safeguards have not been designed or implemented in response to the risk assessment. The institution has not developed written policies and procedures to ensure that personnel are able to enact the information security program. There is a lack of evidence of leadership being required to report to the board or an appropriate supervisory council to ensure those charged with governance are informed on the current state of the information security program. The institution has not developed policies and procedures to oversee information service providers. Cause: The institution did not create and implement a comprehensive information security policy in a timely manner. Effect: The institution did not create and implement a comprehensive information security policy in a timely manner. The absence of internal controls and policies and procedures could result in the unauthorized disclosure, misuse, alteration, destruction or other compromise of student account information. Questioned costs: None. Context: Under an institution’s PPA with the U.S. Department of Education, schools must protect student financial aid information, with particular attention to information provided to institutions by the U.S. Department of Education or otherwise obtained in support of the administration of federal student financial aid programs. Repeat finding: This is not a repeat finding. Recommendation: We recommend that the University completes these requirements in a timely manner in the future. Views of responsible officials: Management agrees with this finding. See corrective action plan.

FY End: 2024-05-31
University of Dubuque
Compliance Requirement: N
U.S. Department of Education Student Financial Assistance Programs Cluster Gramm-Leach Bliley Act – Student Information Security (84.007, 84.268, 84.038, 84.063, 84.378) Federal Award Year: 2023-2024 Finding: The University created and implemented a comprehensive information security policy, but did not have it done in a timely manner. Criteria: 2 CFR 200.303(a) requires that the non-Federal entity must establish and maintain effective internal control over the Federal award that provides reas...

U.S. Department of Education Student Financial Assistance Programs Cluster Gramm-Leach Bliley Act – Student Information Security (84.007, 84.268, 84.038, 84.063, 84.378) Federal Award Year: 2023-2024 Finding: The University created and implemented a comprehensive information security policy, but did not have it done in a timely manner. Criteria: 2 CFR 200.303(a) requires that the non-Federal entity must establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in Standards for Internal Control in the Federal Government issued by the Comptroller General of the United States or the Internal Control Integrated Framework, issued by the Committee of Sponsoring Organizations of the Treadway Commission. The Program Participation Agreement (PPA) with the U.S. Department of Education requires the institution to comply with the Standards for Safeguarding Customer Information as described in 16 CFR Part 314 which includes the development of a comprehensive written security program that includes the following parts: 16 CFR 314.4(a) requires institutions to designate a qualified individual responsible for overseeing and implementing the institution’s information security program and enforcing the information security program. 16 CFR 314.4(b) requires institutions to provide for the information security program to be based on a risk assessment that identifies reasonably foreseeable internal and external risks to the security, confidentiality and integrity of customer information (as the term customer information applies to the institution) that could result in the unauthorized disclosure, misuse, alteration, destruction or other compromise of such information, and assesses the sufficiency of any safeguards in place to control these risks. 16 CFR 314.4(c) requires institutions to provide for the design and implementation of safeguards to control the risks the institution provides through its risk assessment. 16 CFR 314.4(d) requires institutions to regularly test or otherwise monitor the effectiveness of the safeguards it has implemented 16 CFR 314.4(e) requires institutions to develop policies and procedures to ensure that personnel are able to enact the information security program. 16 CFR 314.4(f) requires institutions to develop policies and procedures to oversee its information system service providers. Condition: The institution’s written information security program was not done in a timely manner to include the following elements required by regulation as agreed to in the PPA: The written information security program does not designate an individual responsible for overseeing and implementing the institution’s information security program or enforcing the information security program. The institution has performed a risk assessment utilizing internal resources but has not based the information security program on the results of this assessment, nor has the institution included all required elements of internal and external risks to the security, confidentiality or integrity of customer information. The institution’s risk assessment is missing an inventory of IT systems that process and store customer information and the compliance with information security elements related to multifactor authentication, access control, change management, logging and alerting and encryption. The institution has not identified, designed or implemented safeguards for all of the risks identified in the risk assessment. The safeguards do not include the identification of security events or detection and response capabilities to support incident response. The institution has not been able to test safeguards because safeguards have not been designed or implemented in response to the risk assessment. The institution has not developed written policies and procedures to ensure that personnel are able to enact the information security program. There is a lack of evidence of leadership being required to report to the board or an appropriate supervisory council to ensure those charged with governance are informed on the current state of the information security program. The institution has not developed policies and procedures to oversee information service providers. Cause: The institution did not create and implement a comprehensive information security policy in a timely manner. Effect: The institution did not create and implement a comprehensive information security policy in a timely manner. The absence of internal controls and policies and procedures could result in the unauthorized disclosure, misuse, alteration, destruction or other compromise of student account information. Questioned costs: None. Context: Under an institution’s PPA with the U.S. Department of Education, schools must protect student financial aid information, with particular attention to information provided to institutions by the U.S. Department of Education or otherwise obtained in support of the administration of federal student financial aid programs. Repeat finding: This is not a repeat finding. Recommendation: We recommend that the University completes these requirements in a timely manner in the future. Views of responsible officials: Management agrees with this finding. See corrective action plan.

FY End: 2024-05-31
University of Dubuque
Compliance Requirement: N
U.S. Department of Education Student Financial Assistance Programs Cluster Gramm-Leach Bliley Act – Student Information Security (84.007, 84.268, 84.038, 84.063, 84.378) Federal Award Year: 2023-2024 Finding: The University created and implemented a comprehensive information security policy, but did not have it done in a timely manner. Criteria: 2 CFR 200.303(a) requires that the non-Federal entity must establish and maintain effective internal control over the Federal award that provides reas...

U.S. Department of Education Student Financial Assistance Programs Cluster Gramm-Leach Bliley Act – Student Information Security (84.007, 84.268, 84.038, 84.063, 84.378) Federal Award Year: 2023-2024 Finding: The University created and implemented a comprehensive information security policy, but did not have it done in a timely manner. Criteria: 2 CFR 200.303(a) requires that the non-Federal entity must establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in Standards for Internal Control in the Federal Government issued by the Comptroller General of the United States or the Internal Control Integrated Framework, issued by the Committee of Sponsoring Organizations of the Treadway Commission. The Program Participation Agreement (PPA) with the U.S. Department of Education requires the institution to comply with the Standards for Safeguarding Customer Information as described in 16 CFR Part 314 which includes the development of a comprehensive written security program that includes the following parts: 16 CFR 314.4(a) requires institutions to designate a qualified individual responsible for overseeing and implementing the institution’s information security program and enforcing the information security program. 16 CFR 314.4(b) requires institutions to provide for the information security program to be based on a risk assessment that identifies reasonably foreseeable internal and external risks to the security, confidentiality and integrity of customer information (as the term customer information applies to the institution) that could result in the unauthorized disclosure, misuse, alteration, destruction or other compromise of such information, and assesses the sufficiency of any safeguards in place to control these risks. 16 CFR 314.4(c) requires institutions to provide for the design and implementation of safeguards to control the risks the institution provides through its risk assessment. 16 CFR 314.4(d) requires institutions to regularly test or otherwise monitor the effectiveness of the safeguards it has implemented 16 CFR 314.4(e) requires institutions to develop policies and procedures to ensure that personnel are able to enact the information security program. 16 CFR 314.4(f) requires institutions to develop policies and procedures to oversee its information system service providers. Condition: The institution’s written information security program was not done in a timely manner to include the following elements required by regulation as agreed to in the PPA: The written information security program does not designate an individual responsible for overseeing and implementing the institution’s information security program or enforcing the information security program. The institution has performed a risk assessment utilizing internal resources but has not based the information security program on the results of this assessment, nor has the institution included all required elements of internal and external risks to the security, confidentiality or integrity of customer information. The institution’s risk assessment is missing an inventory of IT systems that process and store customer information and the compliance with information security elements related to multifactor authentication, access control, change management, logging and alerting and encryption. The institution has not identified, designed or implemented safeguards for all of the risks identified in the risk assessment. The safeguards do not include the identification of security events or detection and response capabilities to support incident response. The institution has not been able to test safeguards because safeguards have not been designed or implemented in response to the risk assessment. The institution has not developed written policies and procedures to ensure that personnel are able to enact the information security program. There is a lack of evidence of leadership being required to report to the board or an appropriate supervisory council to ensure those charged with governance are informed on the current state of the information security program. The institution has not developed policies and procedures to oversee information service providers. Cause: The institution did not create and implement a comprehensive information security policy in a timely manner. Effect: The institution did not create and implement a comprehensive information security policy in a timely manner. The absence of internal controls and policies and procedures could result in the unauthorized disclosure, misuse, alteration, destruction or other compromise of student account information. Questioned costs: None. Context: Under an institution’s PPA with the U.S. Department of Education, schools must protect student financial aid information, with particular attention to information provided to institutions by the U.S. Department of Education or otherwise obtained in support of the administration of federal student financial aid programs. Repeat finding: This is not a repeat finding. Recommendation: We recommend that the University completes these requirements in a timely manner in the future. Views of responsible officials: Management agrees with this finding. See corrective action plan.

FY End: 2024-05-31
University of Dubuque
Compliance Requirement: N
U.S. Department of Education Student Financial Assistance Programs Cluster Gramm-Leach Bliley Act – Student Information Security (84.007, 84.268, 84.038, 84.063, 84.378) Federal Award Year: 2023-2024 Finding: The University created and implemented a comprehensive information security policy, but did not have it done in a timely manner. Criteria: 2 CFR 200.303(a) requires that the non-Federal entity must establish and maintain effective internal control over the Federal award that provides reas...

U.S. Department of Education Student Financial Assistance Programs Cluster Gramm-Leach Bliley Act – Student Information Security (84.007, 84.268, 84.038, 84.063, 84.378) Federal Award Year: 2023-2024 Finding: The University created and implemented a comprehensive information security policy, but did not have it done in a timely manner. Criteria: 2 CFR 200.303(a) requires that the non-Federal entity must establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in Standards for Internal Control in the Federal Government issued by the Comptroller General of the United States or the Internal Control Integrated Framework, issued by the Committee of Sponsoring Organizations of the Treadway Commission. The Program Participation Agreement (PPA) with the U.S. Department of Education requires the institution to comply with the Standards for Safeguarding Customer Information as described in 16 CFR Part 314 which includes the development of a comprehensive written security program that includes the following parts: 16 CFR 314.4(a) requires institutions to designate a qualified individual responsible for overseeing and implementing the institution’s information security program and enforcing the information security program. 16 CFR 314.4(b) requires institutions to provide for the information security program to be based on a risk assessment that identifies reasonably foreseeable internal and external risks to the security, confidentiality and integrity of customer information (as the term customer information applies to the institution) that could result in the unauthorized disclosure, misuse, alteration, destruction or other compromise of such information, and assesses the sufficiency of any safeguards in place to control these risks. 16 CFR 314.4(c) requires institutions to provide for the design and implementation of safeguards to control the risks the institution provides through its risk assessment. 16 CFR 314.4(d) requires institutions to regularly test or otherwise monitor the effectiveness of the safeguards it has implemented 16 CFR 314.4(e) requires institutions to develop policies and procedures to ensure that personnel are able to enact the information security program. 16 CFR 314.4(f) requires institutions to develop policies and procedures to oversee its information system service providers. Condition: The institution’s written information security program was not done in a timely manner to include the following elements required by regulation as agreed to in the PPA: The written information security program does not designate an individual responsible for overseeing and implementing the institution’s information security program or enforcing the information security program. The institution has performed a risk assessment utilizing internal resources but has not based the information security program on the results of this assessment, nor has the institution included all required elements of internal and external risks to the security, confidentiality or integrity of customer information. The institution’s risk assessment is missing an inventory of IT systems that process and store customer information and the compliance with information security elements related to multifactor authentication, access control, change management, logging and alerting and encryption. The institution has not identified, designed or implemented safeguards for all of the risks identified in the risk assessment. The safeguards do not include the identification of security events or detection and response capabilities to support incident response. The institution has not been able to test safeguards because safeguards have not been designed or implemented in response to the risk assessment. The institution has not developed written policies and procedures to ensure that personnel are able to enact the information security program. There is a lack of evidence of leadership being required to report to the board or an appropriate supervisory council to ensure those charged with governance are informed on the current state of the information security program. The institution has not developed policies and procedures to oversee information service providers. Cause: The institution did not create and implement a comprehensive information security policy in a timely manner. Effect: The institution did not create and implement a comprehensive information security policy in a timely manner. The absence of internal controls and policies and procedures could result in the unauthorized disclosure, misuse, alteration, destruction or other compromise of student account information. Questioned costs: None. Context: Under an institution’s PPA with the U.S. Department of Education, schools must protect student financial aid information, with particular attention to information provided to institutions by the U.S. Department of Education or otherwise obtained in support of the administration of federal student financial aid programs. Repeat finding: This is not a repeat finding. Recommendation: We recommend that the University completes these requirements in a timely manner in the future. Views of responsible officials: Management agrees with this finding. See corrective action plan.

FY End: 2024-05-31
University of Dubuque
Compliance Requirement: N
U.S. Department of Education Student Financial Assistance Programs Cluster Gramm-Leach Bliley Act – Student Information Security (84.007, 84.268, 84.038, 84.063, 84.378) Federal Award Year: 2023-2024 Finding: The University created and implemented a comprehensive information security policy, but did not have it done in a timely manner. Criteria: 2 CFR 200.303(a) requires that the non-Federal entity must establish and maintain effective internal control over the Federal award that provides reas...

U.S. Department of Education Student Financial Assistance Programs Cluster Gramm-Leach Bliley Act – Student Information Security (84.007, 84.268, 84.038, 84.063, 84.378) Federal Award Year: 2023-2024 Finding: The University created and implemented a comprehensive information security policy, but did not have it done in a timely manner. Criteria: 2 CFR 200.303(a) requires that the non-Federal entity must establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in Standards for Internal Control in the Federal Government issued by the Comptroller General of the United States or the Internal Control Integrated Framework, issued by the Committee of Sponsoring Organizations of the Treadway Commission. The Program Participation Agreement (PPA) with the U.S. Department of Education requires the institution to comply with the Standards for Safeguarding Customer Information as described in 16 CFR Part 314 which includes the development of a comprehensive written security program that includes the following parts: 16 CFR 314.4(a) requires institutions to designate a qualified individual responsible for overseeing and implementing the institution’s information security program and enforcing the information security program. 16 CFR 314.4(b) requires institutions to provide for the information security program to be based on a risk assessment that identifies reasonably foreseeable internal and external risks to the security, confidentiality and integrity of customer information (as the term customer information applies to the institution) that could result in the unauthorized disclosure, misuse, alteration, destruction or other compromise of such information, and assesses the sufficiency of any safeguards in place to control these risks. 16 CFR 314.4(c) requires institutions to provide for the design and implementation of safeguards to control the risks the institution provides through its risk assessment. 16 CFR 314.4(d) requires institutions to regularly test or otherwise monitor the effectiveness of the safeguards it has implemented 16 CFR 314.4(e) requires institutions to develop policies and procedures to ensure that personnel are able to enact the information security program. 16 CFR 314.4(f) requires institutions to develop policies and procedures to oversee its information system service providers. Condition: The institution’s written information security program was not done in a timely manner to include the following elements required by regulation as agreed to in the PPA: The written information security program does not designate an individual responsible for overseeing and implementing the institution’s information security program or enforcing the information security program. The institution has performed a risk assessment utilizing internal resources but has not based the information security program on the results of this assessment, nor has the institution included all required elements of internal and external risks to the security, confidentiality or integrity of customer information. The institution’s risk assessment is missing an inventory of IT systems that process and store customer information and the compliance with information security elements related to multifactor authentication, access control, change management, logging and alerting and encryption. The institution has not identified, designed or implemented safeguards for all of the risks identified in the risk assessment. The safeguards do not include the identification of security events or detection and response capabilities to support incident response. The institution has not been able to test safeguards because safeguards have not been designed or implemented in response to the risk assessment. The institution has not developed written policies and procedures to ensure that personnel are able to enact the information security program. There is a lack of evidence of leadership being required to report to the board or an appropriate supervisory council to ensure those charged with governance are informed on the current state of the information security program. The institution has not developed policies and procedures to oversee information service providers. Cause: The institution did not create and implement a comprehensive information security policy in a timely manner. Effect: The institution did not create and implement a comprehensive information security policy in a timely manner. The absence of internal controls and policies and procedures could result in the unauthorized disclosure, misuse, alteration, destruction or other compromise of student account information. Questioned costs: None. Context: Under an institution’s PPA with the U.S. Department of Education, schools must protect student financial aid information, with particular attention to information provided to institutions by the U.S. Department of Education or otherwise obtained in support of the administration of federal student financial aid programs. Repeat finding: This is not a repeat finding. Recommendation: We recommend that the University completes these requirements in a timely manner in the future. Views of responsible officials: Management agrees with this finding. See corrective action plan.

FY End: 2024-05-31
Bradley University
Compliance Requirement: L
Federal Agency: U.S. Department of Education Federal Program Name: Student Financial Assistance Cluster Assistance Listing Number: 84.007 (Federal Supplemental Educational Opportunity Grants Program), 84.033 (Federal Work Study Program), 84.063 (Federal Pell Grant Program), 84.268 (Federal Direct Student Loans Program) Pass-Through Agency: N/A Pass-Through Number(s): N/A Award Period: June 1, 2023 – May 31, 2024 Type of Finding: • Significant Deficiency in Internal Control over Compliance • O...

Federal Agency: U.S. Department of Education Federal Program Name: Student Financial Assistance Cluster Assistance Listing Number: 84.007 (Federal Supplemental Educational Opportunity Grants Program), 84.033 (Federal Work Study Program), 84.063 (Federal Pell Grant Program), 84.268 (Federal Direct Student Loans Program) Pass-Through Agency: N/A Pass-Through Number(s): N/A Award Period: June 1, 2023 – May 31, 2024 Type of Finding: • Significant Deficiency in Internal Control over Compliance • Other Matters Criteria or specific requirement: The Gramm-Leach-Bliley Act (Public Law 106-102) requires financial institutions to explain their information-sharing practices to their customers and to safeguard sensitive data. (16 CFR 314) The Federal Trade Commission considers Title IV-eligible institutions that participate in Title IV Educational Assistance Programs as “financial institutions” and subject to the Gramm-Leach-Bliley Act (16 CFR 313.3(k)(2)(vi)). The Code of Federal Regulations 2 CFR 200.303 requires the University to establish and maintain effective internal controls over Federal awards. Condition: During our testing of the University’s information technology, we noted the University did not maintain a comprehensive written security program that included the minimum required elements. The University does perform all procedures required by the Gramm-Leach-Bliley Act, however, these procedures are not formally documented. Questioned costs: None Context: Under an institution’s Program Participation Agreement with the Department of Education and the Gramm-Leach-Bliley Act, schools must protect student financial aid information, with particular attention to information provided to institutions by the Department or otherwise obtained in support of the administration of the federal student financial aid programs. Cause: The University has continued to make progress in updating the University’s written security program to become in compliance with all requirements; however, due to capacity and demands on the information technology individuals, this is still a work in process. Effect: The student personal information could be vulnerable. Repeat finding: No Recommendation: We recommend the University work to update the written security program to ensure compliance with all the standards. Views of responsible officials: There is no disagreement with the audit finding.

FY End: 2024-05-31
Bradley University
Compliance Requirement: L
Federal Agency: U.S. Department of Education Federal Program Name: Student Financial Assistance Cluster Assistance Listing Number: 84.007 (Federal Supplemental Educational Opportunity Grants Program), 84.033 (Federal Work Study Program), 84.063 (Federal Pell Grant Program), 84.268 (Federal Direct Student Loans Program) Pass-Through Agency: N/A Pass-Through Number(s): N/A Award Period: June 1, 2023 – May 31, 2024 Type of Finding: • Significant Deficiency in Internal Control over Compliance • O...

Federal Agency: U.S. Department of Education Federal Program Name: Student Financial Assistance Cluster Assistance Listing Number: 84.007 (Federal Supplemental Educational Opportunity Grants Program), 84.033 (Federal Work Study Program), 84.063 (Federal Pell Grant Program), 84.268 (Federal Direct Student Loans Program) Pass-Through Agency: N/A Pass-Through Number(s): N/A Award Period: June 1, 2023 – May 31, 2024 Type of Finding: • Significant Deficiency in Internal Control over Compliance • Other Matters Criteria or specific requirement: The Gramm-Leach-Bliley Act (Public Law 106-102) requires financial institutions to explain their information-sharing practices to their customers and to safeguard sensitive data. (16 CFR 314) The Federal Trade Commission considers Title IV-eligible institutions that participate in Title IV Educational Assistance Programs as “financial institutions” and subject to the Gramm-Leach-Bliley Act (16 CFR 313.3(k)(2)(vi)). The Code of Federal Regulations 2 CFR 200.303 requires the University to establish and maintain effective internal controls over Federal awards. Condition: During our testing of the University’s information technology, we noted the University did not maintain a comprehensive written security program that included the minimum required elements. The University does perform all procedures required by the Gramm-Leach-Bliley Act, however, these procedures are not formally documented. Questioned costs: None Context: Under an institution’s Program Participation Agreement with the Department of Education and the Gramm-Leach-Bliley Act, schools must protect student financial aid information, with particular attention to information provided to institutions by the Department or otherwise obtained in support of the administration of the federal student financial aid programs. Cause: The University has continued to make progress in updating the University’s written security program to become in compliance with all requirements; however, due to capacity and demands on the information technology individuals, this is still a work in process. Effect: The student personal information could be vulnerable. Repeat finding: No Recommendation: We recommend the University work to update the written security program to ensure compliance with all the standards. Views of responsible officials: There is no disagreement with the audit finding.

FY End: 2024-05-31
Bradley University
Compliance Requirement: L
Federal Agency: U.S. Department of Education Federal Program Name: Student Financial Assistance Cluster Assistance Listing Number: 84.007 (Federal Supplemental Educational Opportunity Grants Program), 84.033 (Federal Work Study Program), 84.063 (Federal Pell Grant Program), 84.268 (Federal Direct Student Loans Program) Pass-Through Agency: N/A Pass-Through Number(s): N/A Award Period: June 1, 2023 – May 31, 2024 Type of Finding: • Significant Deficiency in Internal Control over Compliance • O...

Federal Agency: U.S. Department of Education Federal Program Name: Student Financial Assistance Cluster Assistance Listing Number: 84.007 (Federal Supplemental Educational Opportunity Grants Program), 84.033 (Federal Work Study Program), 84.063 (Federal Pell Grant Program), 84.268 (Federal Direct Student Loans Program) Pass-Through Agency: N/A Pass-Through Number(s): N/A Award Period: June 1, 2023 – May 31, 2024 Type of Finding: • Significant Deficiency in Internal Control over Compliance • Other Matters Criteria or specific requirement: The Gramm-Leach-Bliley Act (Public Law 106-102) requires financial institutions to explain their information-sharing practices to their customers and to safeguard sensitive data. (16 CFR 314) The Federal Trade Commission considers Title IV-eligible institutions that participate in Title IV Educational Assistance Programs as “financial institutions” and subject to the Gramm-Leach-Bliley Act (16 CFR 313.3(k)(2)(vi)). The Code of Federal Regulations 2 CFR 200.303 requires the University to establish and maintain effective internal controls over Federal awards. Condition: During our testing of the University’s information technology, we noted the University did not maintain a comprehensive written security program that included the minimum required elements. The University does perform all procedures required by the Gramm-Leach-Bliley Act, however, these procedures are not formally documented. Questioned costs: None Context: Under an institution’s Program Participation Agreement with the Department of Education and the Gramm-Leach-Bliley Act, schools must protect student financial aid information, with particular attention to information provided to institutions by the Department or otherwise obtained in support of the administration of the federal student financial aid programs. Cause: The University has continued to make progress in updating the University’s written security program to become in compliance with all requirements; however, due to capacity and demands on the information technology individuals, this is still a work in process. Effect: The student personal information could be vulnerable. Repeat finding: No Recommendation: We recommend the University work to update the written security program to ensure compliance with all the standards. Views of responsible officials: There is no disagreement with the audit finding.

FY End: 2024-05-31
Bradley University
Compliance Requirement: L
Federal Agency: U.S. Department of Education Federal Program Name: Student Financial Assistance Cluster Assistance Listing Number: 84.007 (Federal Supplemental Educational Opportunity Grants Program), 84.033 (Federal Work Study Program), 84.063 (Federal Pell Grant Program), 84.268 (Federal Direct Student Loans Program) Pass-Through Agency: N/A Pass-Through Number(s): N/A Award Period: June 1, 2023 – May 31, 2024 Type of Finding: • Significant Deficiency in Internal Control over Compliance • O...

Federal Agency: U.S. Department of Education Federal Program Name: Student Financial Assistance Cluster Assistance Listing Number: 84.007 (Federal Supplemental Educational Opportunity Grants Program), 84.033 (Federal Work Study Program), 84.063 (Federal Pell Grant Program), 84.268 (Federal Direct Student Loans Program) Pass-Through Agency: N/A Pass-Through Number(s): N/A Award Period: June 1, 2023 – May 31, 2024 Type of Finding: • Significant Deficiency in Internal Control over Compliance • Other Matters Criteria or specific requirement: The Gramm-Leach-Bliley Act (Public Law 106-102) requires financial institutions to explain their information-sharing practices to their customers and to safeguard sensitive data. (16 CFR 314) The Federal Trade Commission considers Title IV-eligible institutions that participate in Title IV Educational Assistance Programs as “financial institutions” and subject to the Gramm-Leach-Bliley Act (16 CFR 313.3(k)(2)(vi)). The Code of Federal Regulations 2 CFR 200.303 requires the University to establish and maintain effective internal controls over Federal awards. Condition: During our testing of the University’s information technology, we noted the University did not maintain a comprehensive written security program that included the minimum required elements. The University does perform all procedures required by the Gramm-Leach-Bliley Act, however, these procedures are not formally documented. Questioned costs: None Context: Under an institution’s Program Participation Agreement with the Department of Education and the Gramm-Leach-Bliley Act, schools must protect student financial aid information, with particular attention to information provided to institutions by the Department or otherwise obtained in support of the administration of the federal student financial aid programs. Cause: The University has continued to make progress in updating the University’s written security program to become in compliance with all requirements; however, due to capacity and demands on the information technology individuals, this is still a work in process. Effect: The student personal information could be vulnerable. Repeat finding: No Recommendation: We recommend the University work to update the written security program to ensure compliance with all the standards. Views of responsible officials: There is no disagreement with the audit finding.

FY End: 2024-05-31
Kansas Health Science Center, Inc.
Compliance Requirement: C
Finding 2024-001: Excess Cash – Student Financial Aid Federal Agency: U.S. Department of Education Program Name: Student Financial Assistance Cluster, Federal Direct Student Loans Assistance Listing Number: 84.268 Award Year: June 1, 2023 – May 31, 2024 Program Expenditures: $14,342,246 Questioned Costs: None Criteria: Uniform Grant Guidance (34 CFR 668.166) states the Secretary considers excess cash to be any amount of Title IV, Higher Education Act (HEA) program funds, other than Federal...

Finding 2024-001: Excess Cash – Student Financial Aid Federal Agency: U.S. Department of Education Program Name: Student Financial Assistance Cluster, Federal Direct Student Loans Assistance Listing Number: 84.268 Award Year: June 1, 2023 – May 31, 2024 Program Expenditures: $14,342,246 Questioned Costs: None Criteria: Uniform Grant Guidance (34 CFR 668.166) states the Secretary considers excess cash to be any amount of Title IV, Higher Education Act (HEA) program funds, other than Federal Perkins Loan program funds, that an institution does not disburse to students by the end of the third business day following the date the institution (1) received those funds from the Secretary; or (2) deposited or transferred to its depository account previously disbursed Title IV, HEA program funds, such as those resulting from awards adjustments, recoveries, or cancellations. An institution may maintain for up to seven days an amount of excess cash that does not exceed one percent of the total amount of funds the institution drew down in the prior award year. The institution must return immediately to the Secretary any amount of excess cash over the one-percent tolerance and any amount of excess cash remaining in its account after the seven-day tolerance period. Uniform Grant Guidance (2 CFR 200.303) requires nonfederal entities receiving Federal awards establish and maintain internal controls designed to reasonably ensure compliance with Federal laws, regulations, and program compliance requirements. Effective internal controls should include procedures to ensure excess cash is properly handled. Condition: The Kansas Health Science University (KHSU) had two instances of excess cash for the Federal Direct Student Loan program. During our cash management testing, we identified KHSU had excess cash for the Direct Loan program of $268,278 for the period from July 12, 2023 to July 19, 2023 and ranging from $2,204 to $13,385 for the period from April 8, 2024 to April 23, 2024. For the period of July 12, 2023 to July 19, 2023, the excess cash exceeded one percent of total prior year drawdowns and amounts were not returned within the three business-day period. For the period of April 8, 2024 to April 23, 2024, the excess cash did not exceed one percent of total prior year drawdowns, however, amounts were not returned with a seven-day period. Cause: University officials stated the excess cash issues were due to oversight regarding refunds issued to students. Effect: Excess cash is noncompliance with Federal regulations and could result in heightened monitoring by the U.S. Department of Education. Questioned Costs: None Finding 2024-001: Excess Cash – Student Financial Aid (Continued) Context: For the periods of July 12, 2023 to July 19, 2023 and April 8, 2024 to April 23, 2024, KHSU had excess cash in the amount of $268,278 and ranging from $2,204 to $13,385, respectively. KHSU held excess cash for a period of 5 business days and 17 calendar days, respectively. Repeat Finding: No. Recommendation: We recommend KHSU strengthen internal controls around the determination of amounts to be drawn and refunded to the Secretary during the fiscal year. Views of Responsible Officials: Management agrees with the finding. Please see corrective action plan attached.

FY End: 2024-05-31
Kansas Health Science Center, Inc.
Compliance Requirement: B
Finding 2024-002: Improper Controls over Personnel Expenses Federal Agency: U.S. Department of Treasury Program Name: COVID-19: Coronavirus State and Local Fiscal Recovery Funds Assistance Listing Number: 21.027 Award Year: June 1, 2023 – May 31, 2024 Program Expenditures: $1,119,206 Questioned Costs: None Criteria: Uniform Grant Guidance (2 CFR 200.430(g)(1)(i)) states charges to Federal awards for salaries and wages must be based on records that accurately reflect the work performed. The...

Finding 2024-002: Improper Controls over Personnel Expenses Federal Agency: U.S. Department of Treasury Program Name: COVID-19: Coronavirus State and Local Fiscal Recovery Funds Assistance Listing Number: 21.027 Award Year: June 1, 2023 – May 31, 2024 Program Expenditures: $1,119,206 Questioned Costs: None Criteria: Uniform Grant Guidance (2 CFR 200.430(g)(1)(i)) states charges to Federal awards for salaries and wages must be based on records that accurately reflect the work performed. These records must be supported by a system of internal control that provides reasonable assurance that the charges are accurate, allowable, and properly allocated. Uniform Grant Guidance (2 CFR 200.303) requires nonfederal entities receiving Federal awards establish and maintain internal controls designed to reasonably ensure compliance with Federal laws, regulations, and program compliance requirements. Effective internal controls should include procedures to ensure personnel activity reports are approved. Condition: A KHSU supervisor did not properly document approval for one employee’s personnel activity reports. Cause: KHSU officials stated that this issue was an isolated incident resulting from an unintentional oversight at multiple levels of approval. While established procedures generally ensure proper documentation of personnel activity reports, in this case, the required documentation was inadvertently missed during the review and approval process. Effect: If employee’s personnel activity reports are not properly reviewed and approved, KHSU could submit unallowable costs for the program. Questioned Costs: None Context: Of the 8 employee personnel activity reports sampled, one report did not contain the proper approval by a KHSU supervisor. Repeat Finding: No. Recommendation: We recommend KHSU strengthen internal controls around the approval of personnel activity reports to confirm that a reasonable person can confirm the control occurred. Views of Responsible Officials: Management agrees with the finding. Please see corrective action plan attached.

FY End: 2024-05-31
Kansas Health Science Center, Inc.
Compliance Requirement: I
Finding 2024-003: Lack of Control Documentation over Review of Suspended/Debarred Vendors Federal Agency: U.S. Department of Treasury Program Name: COVID-19: Coronavirus State and Local Fiscal Recovery Funds Assistance Listing Number: 21.027 Award Year: June 1, 2023 – May 31, 2024 Program Expenditures: $1,119,206 Questioned Costs: None Criteria: Uniform Grant Guidance (2 CFR 180.300) states that when entering into a covered transaction with another person at the next lower tier, the nonfed...

Finding 2024-003: Lack of Control Documentation over Review of Suspended/Debarred Vendors Federal Agency: U.S. Department of Treasury Program Name: COVID-19: Coronavirus State and Local Fiscal Recovery Funds Assistance Listing Number: 21.027 Award Year: June 1, 2023 – May 31, 2024 Program Expenditures: $1,119,206 Questioned Costs: None Criteria: Uniform Grant Guidance (2 CFR 180.300) states that when entering into a covered transaction with another person at the next lower tier, the nonfederal entity must verify the person with whom the nonfederal entity intends to do business is not excluded or disqualified by: (a) checking Sam.gov Exclusions; or (b) collecting a certification from that person; or (c) adding a clause or condition to the covered transaction with that person. Uniform Grant Guidance (2 CFR 200.303) requires nonfederal entities receiving Federal awards establish and maintain internal controls designed to reasonably ensure compliance with Federal laws, regulations, and program compliance requirements. Effective internal controls should include procedures to ensure vendors are not suspended or debarred. Condition: KHSU was not able to provide support showing that a check had been performed on vendors with whom KHSU entered into covered transactions to verify the vendor were not suspended or debarred. Cause: KHSU officials stated while the organization had a policy in place requiring the review of vendors to ensure compliance with federal requirements, the policy did not include proper documentation requirements. Effect: If KHSU does not maintain documentation confirming a vendor under a covered transaction was not suspended or debarred, KHSU could enter into a transaction with a suspended or debarred vendor and as a result represent noncompliance and improper use of federal funds. Questioned Costs: None Context: KHSU had covered transactions with five vendors for the program totaling expenditures of $440,610. KHSU confirmed it performed the check but did not maintain documentation showing the check was performed. Our testing of all five vendors did not indicate that any were suspended or debarred. Repeat Finding: No. Recommendation: We recommend KHSU update its policy over suspended and debarred vendors to affirm documentation of review of SAM.gov is maintained or certification is obtained from the vendor ensuring they are not suspended or debarred. Views of Responsible Officials: Management agrees with the finding. Please see corrective action plan attached.

FY End: 2024-05-31
The Colleges of Law
Compliance Requirement: C
Finding 2024-001: Excess Cash – Student Financial Aid Federal Agency: U.S. Department of Education Program Name: Student Financial Assistance Cluster, Federal Direct Student Loans Assistance Listing Number: 84.268 Award Year: June 1, 2023 – May 31, 2024 Program Expenditures: $14,342,246 Questioned Costs: None Criteria: Uniform Grant Guidance (34 CFR 668.166) states the Secretary considers excess cash to be any amount of title IV, HEA program funds, other than Federal Perkins Loan program ...

Finding 2024-001: Excess Cash – Student Financial Aid Federal Agency: U.S. Department of Education Program Name: Student Financial Assistance Cluster, Federal Direct Student Loans Assistance Listing Number: 84.268 Award Year: June 1, 2023 – May 31, 2024 Program Expenditures: $14,342,246 Questioned Costs: None Criteria: Uniform Grant Guidance (34 CFR 668.166) states the Secretary considers excess cash to be any amount of title IV, HEA program funds, other than Federal Perkins Loan program funds, that an institution does not disburse to students by the end of the third business day following the date the institution (1) received those funds from the Secretary; or (2) deposited or transferred to its depository account previously disbursed title IV, HEA program funds, such as those resulting from awards adjustments, recoveries, or cancellations. An institution may maintain for up to seven days an amount of excess cash that does not exceed one percent of the total amount of funds the institution drew down in the prior award year. The institution must return immediately to the Secretary any amount of excess cash over the one-percent tolerance and any amount of excess cash remaining in its account after the seven-day tolerance period. Uniform Grant Guidance (2 CFR 200.303) requires nonfederal entities receiving Federal awards establish and maintain internal controls designed to reasonably ensure compliance with Federal laws, regulations, and program compliance requirements. Effective internal controls should include procedures to ensure excess cash is properly handled. Condition: The Colleges of Law (COL) had one instance of excess cash for the Federal Direct Student Loan program. During our cash management testing, we identified COL had excess cash for the Direct Loan program ranging from $172 to $10,314 for the period from March 25, 2024 to April 5, 2024. For that period, the excess cash did not exceed one percent of total prior year drawdowns, however, amounts were not returned within the seven-day period. Cause: University officials stated the excess cash issues were due to oversight regarding refunds issued to students. Effect: Excess cash is noncompliance with Federal regulations and could result in heightened monitoring by the U.S. Department of Education. Questioned Costs: None   Context: For the period of March 25, 2024 to April 5, 2024, COL had excess cash in the amount ranging from $172 to $10,314. COL had excess cash for a period of 11 calendar days. Repeat Finding: No. Recommendation: We recommend COL strengthen internal controls around the determination of amounts to be drawn and refunded to the Secretary during the fiscal year. Views of Responsible Officials: Management agrees with the finding. Please see corrective action plan attached.

FY End: 2024-05-31
Pacific Oaks Education Corporation
Compliance Requirement: C
Finding 2024-001: Excess Cash – Student Financial Aid Federal Agency: U.S. Department of Education Program Name: Student Financial Assistance Cluster, Federal Direct Student Loans Assistance Listing Number: 84.268 Award Year: June 1, 2023 – May 31, 2024 Program Expenditures: $22,734,225 Questioned Costs: None Criteria: Uniform Guidance for the Department of Education (34 CFR 668.166) states the Secretary considers excess cash to be any amount of title IV, HEA program funds, other than Fed...

Finding 2024-001: Excess Cash – Student Financial Aid Federal Agency: U.S. Department of Education Program Name: Student Financial Assistance Cluster, Federal Direct Student Loans Assistance Listing Number: 84.268 Award Year: June 1, 2023 – May 31, 2024 Program Expenditures: $22,734,225 Questioned Costs: None Criteria: Uniform Guidance for the Department of Education (34 CFR 668.166) states the Secretary considers excess cash to be any amount of title IV, HEA program funds, other than Federal Perkins Loan program funds, that an institution does not disburse to students by the end of the third business day following the date the institution: (1) received those funds from the Secretary; or (2) deposited or transferred to its depository account previously disbursed title IV, HEA program funds, such as those resulting from awards adjustments, recoveries, or cancellations. An institution may maintain for up to seven days an amount of excess cash that does not exceed one percent of the total amount of funds the institution drew down in the prior award year. The institution must return immediately to the Secretary any amount of excess cash over the one-percent tolerance and any amount of excess cash remaining in its account after the seven-day tolerance period. Uniform Guidance (2 CFR 200.303) requires nonfederal entities receiving Federal awards establish and maintain internal controls designed to reasonably ensure compliance with Federal laws, regulations, and program compliance requirements. Effective internal controls should include procedures to ensure excess cash is properly handled. Condition: Pacific Oaks Education Corporation (the College) had one instance of excess cash for the Federal Direct Student Loan program. During our cash management testing, we identified the College had excess cash for the Direct Loan program ranging from $1,335,590 to $4,774,182 for the period from September 6, 2023 to September 13, 2023. For that period, the excess cash exceeded one percent of total prior year drawdowns and amounts were not returned within the three business-day period. Cause: College officials explained that the excess cash resulted from the College’s practice of drawing funds early to ensure timely disbursement of stipends to students. The drawdown occurred prior to completing the reconciliation of the award amounts. As a result, while the funds were drawn, they were not posted to the students' ledgers within the required three-day period, leading to the excess cash being held for a longer duration than allowed. Effect: Excess cash is noncompliance with Federal regulations and could result in heightened monitoring by the U.S. Department of Education. Questioned Costs: None Context: For the period of September 6, 2023 to September 13, 2023, the College had excess cash in the amount ranging from $1,335,590 to $4,774,182. The College held excess cash for a period of 5 business days. Repeat Finding: No. Recommendation: We recommend the College strengthen internal controls around cash management to prevent or timely correct excess cash instances. Views of Responsible Officials: Management agrees with the finding. Please see corrective action plan attached.

FY End: 2024-05-31
The Chicago School-Cal INC Dba the Chicago Sch of Pro Psychology
Compliance Requirement: C
Finding 2024-001: Excess Cash – Student Financial Aid Federal Agency: U.S. Department of Education Program Name: Student Financial Assistance Cluster, Federal Direct Student Loans Assistance Listing Number: 84.268 Award Year: June 1, 2023 – May 31, 2024 Program Expenditures: $202,369,164 Questioned Costs: None Criteria: Uniform Grant Guidance (34 CFR 668.166) states the Secretary considers excess cash to be any amount of title IV, HEA program funds, other than Federal Perkins Loan program...

Finding 2024-001: Excess Cash – Student Financial Aid Federal Agency: U.S. Department of Education Program Name: Student Financial Assistance Cluster, Federal Direct Student Loans Assistance Listing Number: 84.268 Award Year: June 1, 2023 – May 31, 2024 Program Expenditures: $202,369,164 Questioned Costs: None Criteria: Uniform Grant Guidance (34 CFR 668.166) states the Secretary considers excess cash to be any amount of title IV, HEA program funds, other than Federal Perkins Loan program funds, that an institution does not disburse to students by the end of the third business day following the date the institution (1) received those funds from the Secretary; or (2) deposited or transferred to its depository account previously disbursed title IV, HEA program funds, such as those resulting from awards adjustments, recoveries, or cancellations. An institution may maintain for up to seven days an amount of excess cash that does not exceed one percent of the total amount of funds the institution drew down in the prior award year. The institution must return immediately to the Secretary any amount of excess cash over the one-percent tolerance and any amount of excess cash remaining in its account after the seven-day tolerance period. Uniform Grant Guidance (2 CFR 200.303) requires nonfederal entities receiving Federal awards establish and maintain internal controls designed to reasonably ensure compliance with Federal laws, regulations, and program compliance requirements. Effective internal controls should include procedures to ensure excess cash is properly handled. Condition: The Chicago School (the College) had one instance of excess cash for the Federal Direct Student Loan program. During our cash management testing, we identified the College had excess cash for the Direct Loan program ranging from $528,450 to $1,238,306 for the period from November 13, 2023 to December 18, 2023. For that period, the excess cash did not exceed one percent of total prior year drawdowns; however, amounts were not returned with a seven-day period. Cause: College officials stated the excess cash resulted from the College’s practice of drawing a portion of funds to ensure timely disbursement of stipend payments to students while the reconciliation of awards was still in progress. While this approach aligns with the College’s commitment to promptly provide financial support, an administrative oversight occurred during the reconciliation process. Specifically, the College did not net out the prior drawdown for stipends when calculating subsequent fund requests. Effect: Excess cash is noncompliance with Federal regulations and could result in heightened monitoring by the U.S. Department of Education. Questioned Costs: None Context: For the period of November 13, 2023 to December 18, 2023, the College had excess cash in the amount ranging from $528,450 to $1,238,306. The College held excess cash for a period of 24 business days. Repeat Finding: No. Recommendation: We recommend the College strengthen internal controls around cash management to prevent or timely correct excess cash instances. Views of Responsible Officials: Management agrees with the finding. Please see corrective action plan attached.

FY End: 2024-05-31
Norwich University
Compliance Requirement: N
Condition: The University did not properly report student enrollment changes for students who received federal student aid to the National Student Loan Data System (NSLDS). Criteria or specific requirement: Per 2 CFR 200.303, nonfederal entities receiving federal awards are required to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations, and program compliance requirements. Additionally, 34 CFR 685.309, requires that enrollment status...

Condition: The University did not properly report student enrollment changes for students who received federal student aid to the National Student Loan Data System (NSLDS). Criteria or specific requirement: Per 2 CFR 200.303, nonfederal entities receiving federal awards are required to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations, and program compliance requirements. Additionally, 34 CFR 685.309, requires that enrollment status changes for students be reported to NSLDS within 30 days of becoming aware of the status change or in its next scheduled enrollment submission if the scheduled submission is within 60 days. Regulations require the status include an accurate effective date. In addition, regulations require that an institution make necessary corrections and return the records within 10 days for any roster files that don’t pass the NSLDS enrollment reporting edits. Context: During our testing of 40 students, we identified 2 students tested whose enrollment status was either not timely reported, not updated to graduate from withdrawn, not reported with correct enrollment status, not reported with correct effective date, or a combination of the above to NSLDS. Questioned costs: N/A Cause: The University didn't have proper procedures in place to verify the students’ status in NSLDS matched the institutions records in a timely manner. Effect: The University was not in compliance with the requirements to properly report student enrollment data correctly. Incorrect dates submitted to NSLDS may be used to determine the grace period for the repayment of interest of outstanding Title IV student loans. Repeat finding: No Recommendation: We recommend the University review current processes for reporting to NSLDS and implement procedures to ensure submissions are reported timely and accurately. Views of responsible officials: Management agrees with the finding and has developed a plan to correct the finding.

FY End: 2024-05-31
Norwich University
Compliance Requirement: N
Condition: The University did not properly report student enrollment changes for students who received federal student aid to the National Student Loan Data System (NSLDS). Criteria or specific requirement: Per 2 CFR 200.303, nonfederal entities receiving federal awards are required to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations, and program compliance requirements. Additionally, 34 CFR 685.309, requires that enrollment status...

Condition: The University did not properly report student enrollment changes for students who received federal student aid to the National Student Loan Data System (NSLDS). Criteria or specific requirement: Per 2 CFR 200.303, nonfederal entities receiving federal awards are required to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations, and program compliance requirements. Additionally, 34 CFR 685.309, requires that enrollment status changes for students be reported to NSLDS within 30 days of becoming aware of the status change or in its next scheduled enrollment submission if the scheduled submission is within 60 days. Regulations require the status include an accurate effective date. In addition, regulations require that an institution make necessary corrections and return the records within 10 days for any roster files that don’t pass the NSLDS enrollment reporting edits. Context: During our testing of 40 students, we identified 2 students tested whose enrollment status was either not timely reported, not updated to graduate from withdrawn, not reported with correct enrollment status, not reported with correct effective date, or a combination of the above to NSLDS. Questioned costs: N/A Cause: The University didn't have proper procedures in place to verify the students’ status in NSLDS matched the institutions records in a timely manner. Effect: The University was not in compliance with the requirements to properly report student enrollment data correctly. Incorrect dates submitted to NSLDS may be used to determine the grace period for the repayment of interest of outstanding Title IV student loans. Repeat finding: No Recommendation: We recommend the University review current processes for reporting to NSLDS and implement procedures to ensure submissions are reported timely and accurately. Views of responsible officials: Management agrees with the finding and has developed a plan to correct the finding.

FY End: 2024-05-31
Norwich University
Compliance Requirement: N
Condition: The University did not properly report student enrollment changes for students who received federal student aid to the National Student Loan Data System (NSLDS). Criteria or specific requirement: Per 2 CFR 200.303, nonfederal entities receiving federal awards are required to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations, and program compliance requirements. Additionally, 34 CFR 685.309, requires that enrollment status...

Condition: The University did not properly report student enrollment changes for students who received federal student aid to the National Student Loan Data System (NSLDS). Criteria or specific requirement: Per 2 CFR 200.303, nonfederal entities receiving federal awards are required to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations, and program compliance requirements. Additionally, 34 CFR 685.309, requires that enrollment status changes for students be reported to NSLDS within 30 days of becoming aware of the status change or in its next scheduled enrollment submission if the scheduled submission is within 60 days. Regulations require the status include an accurate effective date. In addition, regulations require that an institution make necessary corrections and return the records within 10 days for any roster files that don’t pass the NSLDS enrollment reporting edits. Context: During our testing of 40 students, we identified 2 students tested whose enrollment status was either not timely reported, not updated to graduate from withdrawn, not reported with correct enrollment status, not reported with correct effective date, or a combination of the above to NSLDS. Questioned costs: N/A Cause: The University didn't have proper procedures in place to verify the students’ status in NSLDS matched the institutions records in a timely manner. Effect: The University was not in compliance with the requirements to properly report student enrollment data correctly. Incorrect dates submitted to NSLDS may be used to determine the grace period for the repayment of interest of outstanding Title IV student loans. Repeat finding: No Recommendation: We recommend the University review current processes for reporting to NSLDS and implement procedures to ensure submissions are reported timely and accurately. Views of responsible officials: Management agrees with the finding and has developed a plan to correct the finding.

FY End: 2024-05-31
Norwich University
Compliance Requirement: N
Condition: The University did not properly report student enrollment changes for students who received federal student aid to the National Student Loan Data System (NSLDS). Criteria or specific requirement: Per 2 CFR 200.303, nonfederal entities receiving federal awards are required to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations, and program compliance requirements. Additionally, 34 CFR 685.309, requires that enrollment status...

Condition: The University did not properly report student enrollment changes for students who received federal student aid to the National Student Loan Data System (NSLDS). Criteria or specific requirement: Per 2 CFR 200.303, nonfederal entities receiving federal awards are required to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations, and program compliance requirements. Additionally, 34 CFR 685.309, requires that enrollment status changes for students be reported to NSLDS within 30 days of becoming aware of the status change or in its next scheduled enrollment submission if the scheduled submission is within 60 days. Regulations require the status include an accurate effective date. In addition, regulations require that an institution make necessary corrections and return the records within 10 days for any roster files that don’t pass the NSLDS enrollment reporting edits. Context: During our testing of 40 students, we identified 2 students tested whose enrollment status was either not timely reported, not updated to graduate from withdrawn, not reported with correct enrollment status, not reported with correct effective date, or a combination of the above to NSLDS. Questioned costs: N/A Cause: The University didn't have proper procedures in place to verify the students’ status in NSLDS matched the institutions records in a timely manner. Effect: The University was not in compliance with the requirements to properly report student enrollment data correctly. Incorrect dates submitted to NSLDS may be used to determine the grace period for the repayment of interest of outstanding Title IV student loans. Repeat finding: No Recommendation: We recommend the University review current processes for reporting to NSLDS and implement procedures to ensure submissions are reported timely and accurately. Views of responsible officials: Management agrees with the finding and has developed a plan to correct the finding.

FY End: 2024-05-31
University of Dubuque
Compliance Requirement: N
U.S. Department of Education Student Financial Assistance Programs Cluster (Direct) Federal Direct Loan Program (84.268) Federal Award Year: 2023-2024 Finding: The University did not timely or accurately report enrollment changes to the National Student Loan Data System (NSLDS). Criteria: Per 34 CFR 685.309(b), a school shall - (1) Upon receipt of an enrollment report from the Secretary, update all information included in the report and return the report to the Secretary in the manner and form...

U.S. Department of Education Student Financial Assistance Programs Cluster (Direct) Federal Direct Loan Program (84.268) Federal Award Year: 2023-2024 Finding: The University did not timely or accurately report enrollment changes to the National Student Loan Data System (NSLDS). Criteria: Per 34 CFR 685.309(b), a school shall - (1) Upon receipt of an enrollment report from the Secretary, update all information included in the report and return the report to the Secretary in the manner and format prescribed by the Secretary; and within the timeframe prescribed by the Secretary; and (2) Unless it expects to submit its next student updated enrollment report to the Secretary within the next 60 days, a school must notify the Secretary within 30 days if it discovers that a loan under Title IV of the Act was made to, or on behalf of, a student who was enrolled on at least a half-time basis or failed to enroll on at least a half-time basis for the period for which the loan was intended. Per 34 CFR 668.22(c)(ii), the withdrawal date is the date, as determined by the institution, that the student otherwise provided official notification to the institution, in writing or orally, of his or her intent to withdraw. Uniform Grant Guidance (2 CFR 200.303) requires nonfederal entities receiving Federal awards establish and maintain internal controls designed to reasonably ensure compliance with Federal laws, regulations and program compliance requirements. Effective internal controls should include procedures to ensure enrollment reporting is completed properly. Condition: 12 students were not reported as withdrawn within the 60 day timeframe for University’s reporting on the roster file submissions and the internal controls in place did not identify the errors. Cause: Student reporting was not within the 60 day roster submission timeframe. Effect: Noncompliance with federal regulations for enrollment reporting. Questioned costs: None. Context: 12 of the 25 students selected haphazardly and tested were not reported in accordance with NSLDS enrollment reporting and were within a range of five to six days late. Repeat finding: Yes. Recommendation: The University should accurately report all student status changes to the NSLDS. In addition, the University should review its policies and procedures to ensure withdrawal dates are accurately reflected in the enrollment management system and enrollment changes are reported timely. Views of responsible officials: Management agrees with this finding. See corrective action plan.

FY End: 2024-05-31
University of Dubuque
Compliance Requirement: N
U.S. Department of Education Student Financial Assistance Programs Cluster (Direct) Federal Direct Loan Program (84.268) Federal Award Year: 2023-2024 Finding: The University’s R2T4 calculation was improper for one student, as the student had not signed a promissory note for the direct loans and the direct loans should have not been included in the calculation. Criteria: Per 34 CFR 668.164, Any undisbursed Title IV aid for the period that the school uses as the basis for the R2T4 calculation i...

U.S. Department of Education Student Financial Assistance Programs Cluster (Direct) Federal Direct Loan Program (84.268) Federal Award Year: 2023-2024 Finding: The University’s R2T4 calculation was improper for one student, as the student had not signed a promissory note for the direct loans and the direct loans should have not been included in the calculation. Criteria: Per 34 CFR 668.164, Any undisbursed Title IV aid for the period that the school uses as the basis for the R2T4 calculation is counted as aid that could have been disbursed as long as the following conditions were met before the date the student became ineligible: For all programs, the Department processed a Student Aid Report (SAR) or Institutional Student Information Record (ISIR) with an official expected family contribution (EFC) for the student. (An official EFC is one calculated by the Department and provided on a SAR or ISIR. It may or may not be a valid EFC, which is one based on complete and correct information.) In all Title IV loan programs, a promissory note must be signed for a loan to be included as aid that could have been disbursed in an R2T4 calculation. The signature may be obtained after the student withdraws but must be signed before the school performs the R2T4 calculation. In addition, if a school has an affirmative confirmation process set up to actively determine if a student wants a Direct Loan, if the student declines or fails to respond to the request, the Direct Loan would not be included as aid that could have been disbursed. Uniform Grant Guidance (2 CFR 200.303) requires nonfederal entities receiving Federal awards establish and maintain internal controls designed to reasonably ensure compliance with Federal laws, regulations and program compliance requirements. Effective internal controls should include procedures to ensure enrollment reporting is completed properly. Condition: One student did not sign a promissory note for direct loans that were included in the R2T4 calculation; therefore, the University’s R2T4 calculation was improperly calculated and the internal controls in place did not identify the errors. Cause: Student did not sign a promissory note for direct loans. Effect: Noncompliance with federal regulations for R2T4 Questioned costs: Amount refunded was underpaid by $79. Context: One of the eight students selected randomly and tested did not sign a promissory note for direct loans that were included in the R2T4 calculation; therefore, the University’s R2T4 calculation was improperly calculated. Repeat finding: This is not a repeat finding. Recommendation: The University should review the controls and procedures in place to verify that only aid with signed promissory notes are being included in R2T4 calculations. Views of responsible officials: Management agrees with this finding. See corrective action plan.

FY End: 2024-05-31
University of Dubuque
Compliance Requirement: N
U.S. Department of Education Student Financial Assistance Programs Cluster Gramm-Leach Bliley Act – Student Information Security (84.007, 84.268, 84.038, 84.063, 84.378) Federal Award Year: 2023-2024 Finding: The University created and implemented a comprehensive information security policy, but did not have it done in a timely manner. Criteria: 2 CFR 200.303(a) requires that the non-Federal entity must establish and maintain effective internal control over the Federal award that provides reas...

U.S. Department of Education Student Financial Assistance Programs Cluster Gramm-Leach Bliley Act – Student Information Security (84.007, 84.268, 84.038, 84.063, 84.378) Federal Award Year: 2023-2024 Finding: The University created and implemented a comprehensive information security policy, but did not have it done in a timely manner. Criteria: 2 CFR 200.303(a) requires that the non-Federal entity must establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in Standards for Internal Control in the Federal Government issued by the Comptroller General of the United States or the Internal Control Integrated Framework, issued by the Committee of Sponsoring Organizations of the Treadway Commission. The Program Participation Agreement (PPA) with the U.S. Department of Education requires the institution to comply with the Standards for Safeguarding Customer Information as described in 16 CFR Part 314 which includes the development of a comprehensive written security program that includes the following parts: 16 CFR 314.4(a) requires institutions to designate a qualified individual responsible for overseeing and implementing the institution’s information security program and enforcing the information security program. 16 CFR 314.4(b) requires institutions to provide for the information security program to be based on a risk assessment that identifies reasonably foreseeable internal and external risks to the security, confidentiality and integrity of customer information (as the term customer information applies to the institution) that could result in the unauthorized disclosure, misuse, alteration, destruction or other compromise of such information, and assesses the sufficiency of any safeguards in place to control these risks. 16 CFR 314.4(c) requires institutions to provide for the design and implementation of safeguards to control the risks the institution provides through its risk assessment. 16 CFR 314.4(d) requires institutions to regularly test or otherwise monitor the effectiveness of the safeguards it has implemented 16 CFR 314.4(e) requires institutions to develop policies and procedures to ensure that personnel are able to enact the information security program. 16 CFR 314.4(f) requires institutions to develop policies and procedures to oversee its information system service providers. Condition: The institution’s written information security program was not done in a timely manner to include the following elements required by regulation as agreed to in the PPA: The written information security program does not designate an individual responsible for overseeing and implementing the institution’s information security program or enforcing the information security program. The institution has performed a risk assessment utilizing internal resources but has not based the information security program on the results of this assessment, nor has the institution included all required elements of internal and external risks to the security, confidentiality or integrity of customer information. The institution’s risk assessment is missing an inventory of IT systems that process and store customer information and the compliance with information security elements related to multifactor authentication, access control, change management, logging and alerting and encryption. The institution has not identified, designed or implemented safeguards for all of the risks identified in the risk assessment. The safeguards do not include the identification of security events or detection and response capabilities to support incident response. The institution has not been able to test safeguards because safeguards have not been designed or implemented in response to the risk assessment. The institution has not developed written policies and procedures to ensure that personnel are able to enact the information security program. There is a lack of evidence of leadership being required to report to the board or an appropriate supervisory council to ensure those charged with governance are informed on the current state of the information security program. The institution has not developed policies and procedures to oversee information service providers. Cause: The institution did not create and implement a comprehensive information security policy in a timely manner. Effect: The institution did not create and implement a comprehensive information security policy in a timely manner. The absence of internal controls and policies and procedures could result in the unauthorized disclosure, misuse, alteration, destruction or other compromise of student account information. Questioned costs: None. Context: Under an institution’s PPA with the U.S. Department of Education, schools must protect student financial aid information, with particular attention to information provided to institutions by the U.S. Department of Education or otherwise obtained in support of the administration of federal student financial aid programs. Repeat finding: This is not a repeat finding. Recommendation: We recommend that the University completes these requirements in a timely manner in the future. Views of responsible officials: Management agrees with this finding. See corrective action plan.

FY End: 2024-05-31
University of Dubuque
Compliance Requirement: N
U.S. Department of Education Student Financial Assistance Programs Cluster Gramm-Leach Bliley Act – Student Information Security (84.007, 84.268, 84.038, 84.063, 84.378) Federal Award Year: 2023-2024 Finding: The University created and implemented a comprehensive information security policy, but did not have it done in a timely manner. Criteria: 2 CFR 200.303(a) requires that the non-Federal entity must establish and maintain effective internal control over the Federal award that provides reas...

U.S. Department of Education Student Financial Assistance Programs Cluster Gramm-Leach Bliley Act – Student Information Security (84.007, 84.268, 84.038, 84.063, 84.378) Federal Award Year: 2023-2024 Finding: The University created and implemented a comprehensive information security policy, but did not have it done in a timely manner. Criteria: 2 CFR 200.303(a) requires that the non-Federal entity must establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in Standards for Internal Control in the Federal Government issued by the Comptroller General of the United States or the Internal Control Integrated Framework, issued by the Committee of Sponsoring Organizations of the Treadway Commission. The Program Participation Agreement (PPA) with the U.S. Department of Education requires the institution to comply with the Standards for Safeguarding Customer Information as described in 16 CFR Part 314 which includes the development of a comprehensive written security program that includes the following parts: 16 CFR 314.4(a) requires institutions to designate a qualified individual responsible for overseeing and implementing the institution’s information security program and enforcing the information security program. 16 CFR 314.4(b) requires institutions to provide for the information security program to be based on a risk assessment that identifies reasonably foreseeable internal and external risks to the security, confidentiality and integrity of customer information (as the term customer information applies to the institution) that could result in the unauthorized disclosure, misuse, alteration, destruction or other compromise of such information, and assesses the sufficiency of any safeguards in place to control these risks. 16 CFR 314.4(c) requires institutions to provide for the design and implementation of safeguards to control the risks the institution provides through its risk assessment. 16 CFR 314.4(d) requires institutions to regularly test or otherwise monitor the effectiveness of the safeguards it has implemented 16 CFR 314.4(e) requires institutions to develop policies and procedures to ensure that personnel are able to enact the information security program. 16 CFR 314.4(f) requires institutions to develop policies and procedures to oversee its information system service providers. Condition: The institution’s written information security program was not done in a timely manner to include the following elements required by regulation as agreed to in the PPA: The written information security program does not designate an individual responsible for overseeing and implementing the institution’s information security program or enforcing the information security program. The institution has performed a risk assessment utilizing internal resources but has not based the information security program on the results of this assessment, nor has the institution included all required elements of internal and external risks to the security, confidentiality or integrity of customer information. The institution’s risk assessment is missing an inventory of IT systems that process and store customer information and the compliance with information security elements related to multifactor authentication, access control, change management, logging and alerting and encryption. The institution has not identified, designed or implemented safeguards for all of the risks identified in the risk assessment. The safeguards do not include the identification of security events or detection and response capabilities to support incident response. The institution has not been able to test safeguards because safeguards have not been designed or implemented in response to the risk assessment. The institution has not developed written policies and procedures to ensure that personnel are able to enact the information security program. There is a lack of evidence of leadership being required to report to the board or an appropriate supervisory council to ensure those charged with governance are informed on the current state of the information security program. The institution has not developed policies and procedures to oversee information service providers. Cause: The institution did not create and implement a comprehensive information security policy in a timely manner. Effect: The institution did not create and implement a comprehensive information security policy in a timely manner. The absence of internal controls and policies and procedures could result in the unauthorized disclosure, misuse, alteration, destruction or other compromise of student account information. Questioned costs: None. Context: Under an institution’s PPA with the U.S. Department of Education, schools must protect student financial aid information, with particular attention to information provided to institutions by the U.S. Department of Education or otherwise obtained in support of the administration of federal student financial aid programs. Repeat finding: This is not a repeat finding. Recommendation: We recommend that the University completes these requirements in a timely manner in the future. Views of responsible officials: Management agrees with this finding. See corrective action plan.

FY End: 2024-05-31
University of Dubuque
Compliance Requirement: N
U.S. Department of Education Student Financial Assistance Programs Cluster Gramm-Leach Bliley Act – Student Information Security (84.007, 84.268, 84.038, 84.063, 84.378) Federal Award Year: 2023-2024 Finding: The University created and implemented a comprehensive information security policy, but did not have it done in a timely manner. Criteria: 2 CFR 200.303(a) requires that the non-Federal entity must establish and maintain effective internal control over the Federal award that provides reas...

U.S. Department of Education Student Financial Assistance Programs Cluster Gramm-Leach Bliley Act – Student Information Security (84.007, 84.268, 84.038, 84.063, 84.378) Federal Award Year: 2023-2024 Finding: The University created and implemented a comprehensive information security policy, but did not have it done in a timely manner. Criteria: 2 CFR 200.303(a) requires that the non-Federal entity must establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in Standards for Internal Control in the Federal Government issued by the Comptroller General of the United States or the Internal Control Integrated Framework, issued by the Committee of Sponsoring Organizations of the Treadway Commission. The Program Participation Agreement (PPA) with the U.S. Department of Education requires the institution to comply with the Standards for Safeguarding Customer Information as described in 16 CFR Part 314 which includes the development of a comprehensive written security program that includes the following parts: 16 CFR 314.4(a) requires institutions to designate a qualified individual responsible for overseeing and implementing the institution’s information security program and enforcing the information security program. 16 CFR 314.4(b) requires institutions to provide for the information security program to be based on a risk assessment that identifies reasonably foreseeable internal and external risks to the security, confidentiality and integrity of customer information (as the term customer information applies to the institution) that could result in the unauthorized disclosure, misuse, alteration, destruction or other compromise of such information, and assesses the sufficiency of any safeguards in place to control these risks. 16 CFR 314.4(c) requires institutions to provide for the design and implementation of safeguards to control the risks the institution provides through its risk assessment. 16 CFR 314.4(d) requires institutions to regularly test or otherwise monitor the effectiveness of the safeguards it has implemented 16 CFR 314.4(e) requires institutions to develop policies and procedures to ensure that personnel are able to enact the information security program. 16 CFR 314.4(f) requires institutions to develop policies and procedures to oversee its information system service providers. Condition: The institution’s written information security program was not done in a timely manner to include the following elements required by regulation as agreed to in the PPA: The written information security program does not designate an individual responsible for overseeing and implementing the institution’s information security program or enforcing the information security program. The institution has performed a risk assessment utilizing internal resources but has not based the information security program on the results of this assessment, nor has the institution included all required elements of internal and external risks to the security, confidentiality or integrity of customer information. The institution’s risk assessment is missing an inventory of IT systems that process and store customer information and the compliance with information security elements related to multifactor authentication, access control, change management, logging and alerting and encryption. The institution has not identified, designed or implemented safeguards for all of the risks identified in the risk assessment. The safeguards do not include the identification of security events or detection and response capabilities to support incident response. The institution has not been able to test safeguards because safeguards have not been designed or implemented in response to the risk assessment. The institution has not developed written policies and procedures to ensure that personnel are able to enact the information security program. There is a lack of evidence of leadership being required to report to the board or an appropriate supervisory council to ensure those charged with governance are informed on the current state of the information security program. The institution has not developed policies and procedures to oversee information service providers. Cause: The institution did not create and implement a comprehensive information security policy in a timely manner. Effect: The institution did not create and implement a comprehensive information security policy in a timely manner. The absence of internal controls and policies and procedures could result in the unauthorized disclosure, misuse, alteration, destruction or other compromise of student account information. Questioned costs: None. Context: Under an institution’s PPA with the U.S. Department of Education, schools must protect student financial aid information, with particular attention to information provided to institutions by the U.S. Department of Education or otherwise obtained in support of the administration of federal student financial aid programs. Repeat finding: This is not a repeat finding. Recommendation: We recommend that the University completes these requirements in a timely manner in the future. Views of responsible officials: Management agrees with this finding. See corrective action plan.

FY End: 2024-05-31
University of Dubuque
Compliance Requirement: N
U.S. Department of Education Student Financial Assistance Programs Cluster Gramm-Leach Bliley Act – Student Information Security (84.007, 84.268, 84.038, 84.063, 84.378) Federal Award Year: 2023-2024 Finding: The University created and implemented a comprehensive information security policy, but did not have it done in a timely manner. Criteria: 2 CFR 200.303(a) requires that the non-Federal entity must establish and maintain effective internal control over the Federal award that provides reas...

U.S. Department of Education Student Financial Assistance Programs Cluster Gramm-Leach Bliley Act – Student Information Security (84.007, 84.268, 84.038, 84.063, 84.378) Federal Award Year: 2023-2024 Finding: The University created and implemented a comprehensive information security policy, but did not have it done in a timely manner. Criteria: 2 CFR 200.303(a) requires that the non-Federal entity must establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in Standards for Internal Control in the Federal Government issued by the Comptroller General of the United States or the Internal Control Integrated Framework, issued by the Committee of Sponsoring Organizations of the Treadway Commission. The Program Participation Agreement (PPA) with the U.S. Department of Education requires the institution to comply with the Standards for Safeguarding Customer Information as described in 16 CFR Part 314 which includes the development of a comprehensive written security program that includes the following parts: 16 CFR 314.4(a) requires institutions to designate a qualified individual responsible for overseeing and implementing the institution’s information security program and enforcing the information security program. 16 CFR 314.4(b) requires institutions to provide for the information security program to be based on a risk assessment that identifies reasonably foreseeable internal and external risks to the security, confidentiality and integrity of customer information (as the term customer information applies to the institution) that could result in the unauthorized disclosure, misuse, alteration, destruction or other compromise of such information, and assesses the sufficiency of any safeguards in place to control these risks. 16 CFR 314.4(c) requires institutions to provide for the design and implementation of safeguards to control the risks the institution provides through its risk assessment. 16 CFR 314.4(d) requires institutions to regularly test or otherwise monitor the effectiveness of the safeguards it has implemented 16 CFR 314.4(e) requires institutions to develop policies and procedures to ensure that personnel are able to enact the information security program. 16 CFR 314.4(f) requires institutions to develop policies and procedures to oversee its information system service providers. Condition: The institution’s written information security program was not done in a timely manner to include the following elements required by regulation as agreed to in the PPA: The written information security program does not designate an individual responsible for overseeing and implementing the institution’s information security program or enforcing the information security program. The institution has performed a risk assessment utilizing internal resources but has not based the information security program on the results of this assessment, nor has the institution included all required elements of internal and external risks to the security, confidentiality or integrity of customer information. The institution’s risk assessment is missing an inventory of IT systems that process and store customer information and the compliance with information security elements related to multifactor authentication, access control, change management, logging and alerting and encryption. The institution has not identified, designed or implemented safeguards for all of the risks identified in the risk assessment. The safeguards do not include the identification of security events or detection and response capabilities to support incident response. The institution has not been able to test safeguards because safeguards have not been designed or implemented in response to the risk assessment. The institution has not developed written policies and procedures to ensure that personnel are able to enact the information security program. There is a lack of evidence of leadership being required to report to the board or an appropriate supervisory council to ensure those charged with governance are informed on the current state of the information security program. The institution has not developed policies and procedures to oversee information service providers. Cause: The institution did not create and implement a comprehensive information security policy in a timely manner. Effect: The institution did not create and implement a comprehensive information security policy in a timely manner. The absence of internal controls and policies and procedures could result in the unauthorized disclosure, misuse, alteration, destruction or other compromise of student account information. Questioned costs: None. Context: Under an institution’s PPA with the U.S. Department of Education, schools must protect student financial aid information, with particular attention to information provided to institutions by the U.S. Department of Education or otherwise obtained in support of the administration of federal student financial aid programs. Repeat finding: This is not a repeat finding. Recommendation: We recommend that the University completes these requirements in a timely manner in the future. Views of responsible officials: Management agrees with this finding. See corrective action plan.

FY End: 2024-05-31
University of Dubuque
Compliance Requirement: N
U.S. Department of Education Student Financial Assistance Programs Cluster Gramm-Leach Bliley Act – Student Information Security (84.007, 84.268, 84.038, 84.063, 84.378) Federal Award Year: 2023-2024 Finding: The University created and implemented a comprehensive information security policy, but did not have it done in a timely manner. Criteria: 2 CFR 200.303(a) requires that the non-Federal entity must establish and maintain effective internal control over the Federal award that provides reas...

U.S. Department of Education Student Financial Assistance Programs Cluster Gramm-Leach Bliley Act – Student Information Security (84.007, 84.268, 84.038, 84.063, 84.378) Federal Award Year: 2023-2024 Finding: The University created and implemented a comprehensive information security policy, but did not have it done in a timely manner. Criteria: 2 CFR 200.303(a) requires that the non-Federal entity must establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in Standards for Internal Control in the Federal Government issued by the Comptroller General of the United States or the Internal Control Integrated Framework, issued by the Committee of Sponsoring Organizations of the Treadway Commission. The Program Participation Agreement (PPA) with the U.S. Department of Education requires the institution to comply with the Standards for Safeguarding Customer Information as described in 16 CFR Part 314 which includes the development of a comprehensive written security program that includes the following parts: 16 CFR 314.4(a) requires institutions to designate a qualified individual responsible for overseeing and implementing the institution’s information security program and enforcing the information security program. 16 CFR 314.4(b) requires institutions to provide for the information security program to be based on a risk assessment that identifies reasonably foreseeable internal and external risks to the security, confidentiality and integrity of customer information (as the term customer information applies to the institution) that could result in the unauthorized disclosure, misuse, alteration, destruction or other compromise of such information, and assesses the sufficiency of any safeguards in place to control these risks. 16 CFR 314.4(c) requires institutions to provide for the design and implementation of safeguards to control the risks the institution provides through its risk assessment. 16 CFR 314.4(d) requires institutions to regularly test or otherwise monitor the effectiveness of the safeguards it has implemented 16 CFR 314.4(e) requires institutions to develop policies and procedures to ensure that personnel are able to enact the information security program. 16 CFR 314.4(f) requires institutions to develop policies and procedures to oversee its information system service providers. Condition: The institution’s written information security program was not done in a timely manner to include the following elements required by regulation as agreed to in the PPA: The written information security program does not designate an individual responsible for overseeing and implementing the institution’s information security program or enforcing the information security program. The institution has performed a risk assessment utilizing internal resources but has not based the information security program on the results of this assessment, nor has the institution included all required elements of internal and external risks to the security, confidentiality or integrity of customer information. The institution’s risk assessment is missing an inventory of IT systems that process and store customer information and the compliance with information security elements related to multifactor authentication, access control, change management, logging and alerting and encryption. The institution has not identified, designed or implemented safeguards for all of the risks identified in the risk assessment. The safeguards do not include the identification of security events or detection and response capabilities to support incident response. The institution has not been able to test safeguards because safeguards have not been designed or implemented in response to the risk assessment. The institution has not developed written policies and procedures to ensure that personnel are able to enact the information security program. There is a lack of evidence of leadership being required to report to the board or an appropriate supervisory council to ensure those charged with governance are informed on the current state of the information security program. The institution has not developed policies and procedures to oversee information service providers. Cause: The institution did not create and implement a comprehensive information security policy in a timely manner. Effect: The institution did not create and implement a comprehensive information security policy in a timely manner. The absence of internal controls and policies and procedures could result in the unauthorized disclosure, misuse, alteration, destruction or other compromise of student account information. Questioned costs: None. Context: Under an institution’s PPA with the U.S. Department of Education, schools must protect student financial aid information, with particular attention to information provided to institutions by the U.S. Department of Education or otherwise obtained in support of the administration of federal student financial aid programs. Repeat finding: This is not a repeat finding. Recommendation: We recommend that the University completes these requirements in a timely manner in the future. Views of responsible officials: Management agrees with this finding. See corrective action plan.

FY End: 2024-05-31
University of Dubuque
Compliance Requirement: N
U.S. Department of Education Student Financial Assistance Programs Cluster Gramm-Leach Bliley Act – Student Information Security (84.007, 84.268, 84.038, 84.063, 84.378) Federal Award Year: 2023-2024 Finding: The University created and implemented a comprehensive information security policy, but did not have it done in a timely manner. Criteria: 2 CFR 200.303(a) requires that the non-Federal entity must establish and maintain effective internal control over the Federal award that provides reas...

U.S. Department of Education Student Financial Assistance Programs Cluster Gramm-Leach Bliley Act – Student Information Security (84.007, 84.268, 84.038, 84.063, 84.378) Federal Award Year: 2023-2024 Finding: The University created and implemented a comprehensive information security policy, but did not have it done in a timely manner. Criteria: 2 CFR 200.303(a) requires that the non-Federal entity must establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in Standards for Internal Control in the Federal Government issued by the Comptroller General of the United States or the Internal Control Integrated Framework, issued by the Committee of Sponsoring Organizations of the Treadway Commission. The Program Participation Agreement (PPA) with the U.S. Department of Education requires the institution to comply with the Standards for Safeguarding Customer Information as described in 16 CFR Part 314 which includes the development of a comprehensive written security program that includes the following parts: 16 CFR 314.4(a) requires institutions to designate a qualified individual responsible for overseeing and implementing the institution’s information security program and enforcing the information security program. 16 CFR 314.4(b) requires institutions to provide for the information security program to be based on a risk assessment that identifies reasonably foreseeable internal and external risks to the security, confidentiality and integrity of customer information (as the term customer information applies to the institution) that could result in the unauthorized disclosure, misuse, alteration, destruction or other compromise of such information, and assesses the sufficiency of any safeguards in place to control these risks. 16 CFR 314.4(c) requires institutions to provide for the design and implementation of safeguards to control the risks the institution provides through its risk assessment. 16 CFR 314.4(d) requires institutions to regularly test or otherwise monitor the effectiveness of the safeguards it has implemented 16 CFR 314.4(e) requires institutions to develop policies and procedures to ensure that personnel are able to enact the information security program. 16 CFR 314.4(f) requires institutions to develop policies and procedures to oversee its information system service providers. Condition: The institution’s written information security program was not done in a timely manner to include the following elements required by regulation as agreed to in the PPA: The written information security program does not designate an individual responsible for overseeing and implementing the institution’s information security program or enforcing the information security program. The institution has performed a risk assessment utilizing internal resources but has not based the information security program on the results of this assessment, nor has the institution included all required elements of internal and external risks to the security, confidentiality or integrity of customer information. The institution’s risk assessment is missing an inventory of IT systems that process and store customer information and the compliance with information security elements related to multifactor authentication, access control, change management, logging and alerting and encryption. The institution has not identified, designed or implemented safeguards for all of the risks identified in the risk assessment. The safeguards do not include the identification of security events or detection and response capabilities to support incident response. The institution has not been able to test safeguards because safeguards have not been designed or implemented in response to the risk assessment. The institution has not developed written policies and procedures to ensure that personnel are able to enact the information security program. There is a lack of evidence of leadership being required to report to the board or an appropriate supervisory council to ensure those charged with governance are informed on the current state of the information security program. The institution has not developed policies and procedures to oversee information service providers. Cause: The institution did not create and implement a comprehensive information security policy in a timely manner. Effect: The institution did not create and implement a comprehensive information security policy in a timely manner. The absence of internal controls and policies and procedures could result in the unauthorized disclosure, misuse, alteration, destruction or other compromise of student account information. Questioned costs: None. Context: Under an institution’s PPA with the U.S. Department of Education, schools must protect student financial aid information, with particular attention to information provided to institutions by the U.S. Department of Education or otherwise obtained in support of the administration of federal student financial aid programs. Repeat finding: This is not a repeat finding. Recommendation: We recommend that the University completes these requirements in a timely manner in the future. Views of responsible officials: Management agrees with this finding. See corrective action plan.

FY End: 2024-05-31
Minneapolis College of Art and Design
Compliance Requirement: ACELN
Federal Agency: Department of Education Federal Program Title: Student Financial Assistance Cluster ALN Numbers: Various Award Period: June 1, 2023 through May 31, 2024 Type of Finding: • Significant Deficiency in Internal Control Over Compliance • Other Matters Criteria or Specific Requirement: The 2 CFR Section 200.303 requires that nonfederal entities receiving federal awards establish and maintain internal controls designed to reasonably ensure compliance with Federal Statues, regulations, ...

Federal Agency: Department of Education Federal Program Title: Student Financial Assistance Cluster ALN Numbers: Various Award Period: June 1, 2023 through May 31, 2024 Type of Finding: • Significant Deficiency in Internal Control Over Compliance • Other Matters Criteria or Specific Requirement: The 2 CFR Section 200.303 requires that nonfederal entities receiving federal awards establish and maintain internal controls designed to reasonably ensure compliance with Federal Statues, regulations, and the term and conditions of the federal awards. Condition: During our testing of Return of Title IV Funds (R2T4), federal loan reconciliations, and award packaging, we noted there was not a review process implemented. Questioned Costs: None. Context: During our testing, it was noted the College does not have a process in place to ensure controls are being performed effectively. Cause: The College did not have a process in place to ensure controls implemented are being performed effectively Effect: There is no way to determine who was involved in the process should an error be present. Repeat Finding: No Recommendation: We recommend the College reevaluate its procedures and review policies surrounding controls implemented for Title IV Aid. Views of Responsible Officials: There is no disagreement with the audit finding.

FY End: 2024-05-31
Minneapolis College of Art and Design
Compliance Requirement: ACELN
Federal Agency: Department of Education Federal Program Title: Student Financial Assistance Cluster ALN Numbers: Various Award Period: June 1, 2023 through May 31, 2024 Type of Finding: • Significant Deficiency in Internal Control Over Compliance • Other Matters Criteria or Specific Requirement: The 2 CFR Section 200.303 requires that nonfederal entities receiving federal awards establish and maintain internal controls designed to reasonably ensure compliance with Federal Statues, regulations, ...

Federal Agency: Department of Education Federal Program Title: Student Financial Assistance Cluster ALN Numbers: Various Award Period: June 1, 2023 through May 31, 2024 Type of Finding: • Significant Deficiency in Internal Control Over Compliance • Other Matters Criteria or Specific Requirement: The 2 CFR Section 200.303 requires that nonfederal entities receiving federal awards establish and maintain internal controls designed to reasonably ensure compliance with Federal Statues, regulations, and the term and conditions of the federal awards. Condition: During our testing of Return of Title IV Funds (R2T4), federal loan reconciliations, and award packaging, we noted there was not a review process implemented. Questioned Costs: None. Context: During our testing, it was noted the College does not have a process in place to ensure controls are being performed effectively. Cause: The College did not have a process in place to ensure controls implemented are being performed effectively Effect: There is no way to determine who was involved in the process should an error be present. Repeat Finding: No Recommendation: We recommend the College reevaluate its procedures and review policies surrounding controls implemented for Title IV Aid. Views of Responsible Officials: There is no disagreement with the audit finding.

« 1 703 704 706 707 2002 »