2 CFR 200 › § 200.303

Findings Citing § 200.303

Internal controls.

Total Findings
100,090
Across all audits in database
Showing Page
706 of 2002
50 findings per page
About this section
Section 200.303 requires recipients and subrecipients of Federal awards to establish and maintain effective internal controls to ensure compliance with Federal laws and award conditions. This section affects organizations receiving Federal funding, mandating them to monitor compliance, address noncompliance promptly, and protect sensitive information.
View full section details →
FY End: 2024-05-31
Minneapolis College of Art and Design
Compliance Requirement: ACELN
Federal Agency: Department of Education Federal Program Title: Student Financial Assistance Cluster ALN Numbers: Various Award Period: June 1, 2023 through May 31, 2024 Type of Finding: • Significant Deficiency in Internal Control Over Compliance • Other Matters Criteria or Specific Requirement: The 2 CFR Section 200.303 requires that nonfederal entities receiving federal awards establish and maintain internal controls designed to reasonably ensure compliance with Federal Statues, regulations, ...

Federal Agency: Department of Education Federal Program Title: Student Financial Assistance Cluster ALN Numbers: Various Award Period: June 1, 2023 through May 31, 2024 Type of Finding: • Significant Deficiency in Internal Control Over Compliance • Other Matters Criteria or Specific Requirement: The 2 CFR Section 200.303 requires that nonfederal entities receiving federal awards establish and maintain internal controls designed to reasonably ensure compliance with Federal Statues, regulations, and the term and conditions of the federal awards. Condition: During our testing of Return of Title IV Funds (R2T4), federal loan reconciliations, and award packaging, we noted there was not a review process implemented. Questioned Costs: None. Context: During our testing, it was noted the College does not have a process in place to ensure controls are being performed effectively. Cause: The College did not have a process in place to ensure controls implemented are being performed effectively Effect: There is no way to determine who was involved in the process should an error be present. Repeat Finding: No Recommendation: We recommend the College reevaluate its procedures and review policies surrounding controls implemented for Title IV Aid. Views of Responsible Officials: There is no disagreement with the audit finding.

FY End: 2024-05-31
Minneapolis College of Art and Design
Compliance Requirement: ACELN
Federal Agency: Department of Education Federal Program Title: Student Financial Assistance Cluster ALN Numbers: Various Award Period: June 1, 2023 through May 31, 2024 Type of Finding: • Significant Deficiency in Internal Control Over Compliance • Other Matters Criteria or Specific Requirement: The 2 CFR Section 200.303 requires that nonfederal entities receiving federal awards establish and maintain internal controls designed to reasonably ensure compliance with Federal Statues, regulations, ...

Federal Agency: Department of Education Federal Program Title: Student Financial Assistance Cluster ALN Numbers: Various Award Period: June 1, 2023 through May 31, 2024 Type of Finding: • Significant Deficiency in Internal Control Over Compliance • Other Matters Criteria or Specific Requirement: The 2 CFR Section 200.303 requires that nonfederal entities receiving federal awards establish and maintain internal controls designed to reasonably ensure compliance with Federal Statues, regulations, and the term and conditions of the federal awards. Condition: During our testing of Return of Title IV Funds (R2T4), federal loan reconciliations, and award packaging, we noted there was not a review process implemented. Questioned Costs: None. Context: During our testing, it was noted the College does not have a process in place to ensure controls are being performed effectively. Cause: The College did not have a process in place to ensure controls implemented are being performed effectively Effect: There is no way to determine who was involved in the process should an error be present. Repeat Finding: No Recommendation: We recommend the College reevaluate its procedures and review policies surrounding controls implemented for Title IV Aid. Views of Responsible Officials: There is no disagreement with the audit finding.

FY End: 2024-05-31
Minneapolis College of Art and Design
Compliance Requirement: ACELN
Federal Agency: Department of Education Federal Program Title: Student Financial Assistance Cluster ALN Numbers: Various Award Period: June 1, 2023 through May 31, 2024 Type of Finding: • Significant Deficiency in Internal Control Over Compliance • Other Matters Criteria or Specific Requirement: The 2 CFR Section 200.303 requires that nonfederal entities receiving federal awards establish and maintain internal controls designed to reasonably ensure compliance with Federal Statues, regulations, ...

Federal Agency: Department of Education Federal Program Title: Student Financial Assistance Cluster ALN Numbers: Various Award Period: June 1, 2023 through May 31, 2024 Type of Finding: • Significant Deficiency in Internal Control Over Compliance • Other Matters Criteria or Specific Requirement: The 2 CFR Section 200.303 requires that nonfederal entities receiving federal awards establish and maintain internal controls designed to reasonably ensure compliance with Federal Statues, regulations, and the term and conditions of the federal awards. Condition: During our testing of Return of Title IV Funds (R2T4), federal loan reconciliations, and award packaging, we noted there was not a review process implemented. Questioned Costs: None. Context: During our testing, it was noted the College does not have a process in place to ensure controls are being performed effectively. Cause: The College did not have a process in place to ensure controls implemented are being performed effectively Effect: There is no way to determine who was involved in the process should an error be present. Repeat Finding: No Recommendation: We recommend the College reevaluate its procedures and review policies surrounding controls implemented for Title IV Aid. Views of Responsible Officials: There is no disagreement with the audit finding.

FY End: 2024-05-31
Bothwell Regional Health Center
Compliance Requirement: I
U.S. Department of Health and Human Services, passed through the Curators of the University of Missouri ALN 93.680 - Medical Student Education PTE Federal Award No: C00084599-1 Criteria or Specific Requirement: Suspension and Debarment and Significant Deficiency In accordance with 2 CFR 200.214, non-federal entities are prohibited from contracting with or making subawards under covered transactions to parties that are suspended or debarred. “Covered transactions” include contracts for goods and...

U.S. Department of Health and Human Services, passed through the Curators of the University of Missouri ALN 93.680 - Medical Student Education PTE Federal Award No: C00084599-1 Criteria or Specific Requirement: Suspension and Debarment and Significant Deficiency In accordance with 2 CFR 200.214, non-federal entities are prohibited from contracting with or making subawards under covered transactions to parties that are suspended or debarred. “Covered transactions” include contracts for goods and services awarded under a non-procurement transaction (e.g., grant or cooperative agreement) that are expected to equal or exceed $25,000 or meet certain other criteria as specified in 2 CFR Section 180.220. All non-procurement transactions entered into by a pass-through entity (i.e., subawards to subrecipients), irrespective of award amount, are considered covered transactions, unless they are exempt as provided in 2 CFR Section 180.215. Per 2 CFR 200.303, the non-Federal entities receiving federal awards (i.e., auditee management) establish and maintain internal control design to reasonably ensure compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. Condition: Suspension and debarment checks were not completed for the vendors that received federal funds. Cause: Bothwell Regional Health Center did not have suspension and debarment controls in place prior to purchases with the vendors. Effect or Potential Effect: Federal funds could be paid to entities that are suspended or debarred. Questioned Costs: None noted. Context: Only one vendor was subject to the suspension and debarment requirement in 2024 and was selected for testing. The Health Center purchased $961,978 in goods/services from this vendor in 2024. During our testing, we noted the vendor utilized by the Health Center was not evaluated for suspension and debarment. Upon subsequent check, the vendor was not suspended or debarred. Identification of Prior Year Finding: N/A Recommendation: Policies and procedures should be modified to ensure that suspension and debarment checks are performed on vendors and subrecipients alike prior to making purchases with federal funds. When newly established programs include vendors, we also recommend the contracts include suspension and debarment language. View of Responsible Official and Planned Corrective Actions: Management agrees with the finding and management will implement a control process to ensure that suspension and debarment checks are performed on vendors/contracts funded with grants in 2025.

FY End: 2024-05-31
Webber International University, Inc.
Compliance Requirement: N
2024-007 – Preparation of the Schedule of Expenditures of Federal Awards (SEFA) (Significant Deficiency) Department of Education, SFA Cluster, Special Tests and Provisions Criteria: According to 2 CFR 200.210(b), a recipient of Federal awards is required to prepare a SEFA for the period covered by the entity’s financial statement which must include the total Federal awards expended. In addition, 2 CFR 200.303 requires non-Federal entities to, among other things, establish, document, and maintain...

2024-007 – Preparation of the Schedule of Expenditures of Federal Awards (SEFA) (Significant Deficiency) Department of Education, SFA Cluster, Special Tests and Provisions Criteria: According to 2 CFR 200.210(b), a recipient of Federal awards is required to prepare a SEFA for the period covered by the entity’s financial statement which must include the total Federal awards expended. In addition, 2 CFR 200.303 requires non-Federal entities to, among other things, establish, document, and maintain effective internal control over Federal awards that provides reasonable assurance that the non-Federal entity is managing the Federal awards in compliance with Federal statutes, regulations, and the terms and conditions of the Federal awards. Effective internal controls should include procedures to ensure expenditures are properly reported on the SEFA. In addition to providing an accurate SEFA, an organization must also be able to demonstrate that it has a system of internal control that supports the preparation of the SEFA. Condition: The University did not have an adequate process in place to prepare and review its SEFA. Cause: The University’s internal control process for preparing the SEFA did not include review and approval of the SEFA prior to providing it to the auditor. Effect: Failure to accurately report federal expenditures on the SEFA could result in noncompliance with federal regulations. Repeat Finding from a Prior Year: Not a repeat finding. Recommendation: We recommend the University establish, document, and maintain effective internal controls over the preparation of the SEFA. At a minimum, an organization should be able to show documentation that the SEFA was reviewed and approved by an individual who was not directly involved with the initial preparation of the SEFA. The review process should include checking both the reported expenditures of federal awards and the assistance listing numbers reported for each grant program. Management Response: The University acknowledges the identified deficiency in the internal control process related to the preparation and review of the Schedule of Expenditures of Federal Awards (SEFA). In response, the University has implemented a formalized and documented process to ensure the SEFA is accurately prepared, thoroughly reviewed, and approved in compliance with 2 CFR 200.210(b) and 2 CFR 200.303. The corrective actions taken include: 1) Independent Review and Approval: The SEFA is now subject to a formal review and approval process by an individual who is independent of the initial preparation. This review involves verifying the accuracy of reported expenditures, confirming the proper listing of assistance numbers (CFDA numbers), and ensuring that all program titles match the federal award documentation. 2) Internal Control Documentation: The University has documented its SEFA preparation and review procedures as part of its internal control framework. This documentation includes roles, responsibilities, timelines, and sign-off requirements to provide an audit trail for compliance verification. 3) Staff Training and Cross-Departmental Coordination: Staff involved in grants accounting and financial reporting will receive targeted training on SEFA requirements. Additionally, coordination among the Financial Aid Office and Finance Office has been strengthened to ensure the complete and accurate sharing of data related to federal award expenditures.

FY End: 2024-05-31
College of the Ozarks
Compliance Requirement: L
US Department of the Treasury Passed through Missouri Department of Higher Education and Workforce Development Program Name: Coronavirus State and Local Fiscal Recovery Fund / American Rescue Plan Act / MoExcels Grant Assistance Listing #: 21.027 Finding: 2024 – 001 SIGNIFICANT DEFICIENCY Reporting Condition: During our original audit, the College initially failed to include $768,053 of Coronavirus State and Local Fiscal Recovery Fund (ARPA) funding received from the State of Missouri o...

US Department of the Treasury Passed through Missouri Department of Higher Education and Workforce Development Program Name: Coronavirus State and Local Fiscal Recovery Fund / American Rescue Plan Act / MoExcels Grant Assistance Listing #: 21.027 Finding: 2024 – 001 SIGNIFICANT DEFICIENCY Reporting Condition: During our original audit, the College initially failed to include $768,053 of Coronavirus State and Local Fiscal Recovery Fund (ARPA) funding received from the State of Missouri on the Schedule of Expenditures of Federal Awards. Additionally, the College incorrectly included $78,539 of 2024-25 SEOG funding that was drawn but not expended in the 2023-24 SEFA, resulting in an overstatement of SEOG expenditures. These errors were identified subsequent to the issuance of the report and require a re-issuance of the related audit reports. The internal control system did not prevent or detect these errors during the SEFA preparation process. Cause: The College's procedures for identifying and reporting federal expenditures were insufficient. The MoExcels grant application was submitted outside of the finance office without early communication to finance personnel regarding the federal funding source. Since the College rarely receives federal funding beyond routine Student Financial Aid programs, finance personnel were initially unaware that the MoExcels funding originated from a federal source and therefore required inclusion on the SEFA. Additionally, the College lacked adequate cutoff procedures to ensure federal expenditures were reported in the correct period based on when costs were incurred rather than when funds were drawn down from federal systems. The absence of formal communication protocols between program staff and the finance staff who prepared the SEFA, combined with insufficient review procedures for year-end federal drawdown cutoff, contributed to these oversights. Effect: The initial errors resulted in an understatement of federal expenditures on the originally issued SEFA by $768,053 for ARPA funds and an overstatement by $78,539 for SEOG funds, for a net understatement of $689,514. While these errors have been corrected, the control deficiency increases the risk that future federal awards could be incorrectly reported on the SEFA, potentially resulting in noncompliance with federal reporting requirements and incomplete or inaccurate identification of major programs subject to audit. Questioned Costs: $0 Criteria: 2 CFR 200.510(b) requires that the auditee prepare a Schedule of Expenditures of Federal Awards (SEFA) for the period covered by the auditee's financial statements which must include the total Federal awards expended as determined in accordance with 2 CFR 200.502. Additionally, 2 CFR 200.303 requires that non-federal entities establish and maintain effective internal control over Federal awards that provides reasonable assurance that the non-federal entity is managing the awards in compliance with Federal statutes, regulations, and the terms and conditions of the related awards. Recommendation: We recommend the College implement written procedures for SEFA preparation that include: (1) obtaining and reviewing all grant agreements to identify federal funding sources; (2) establishing regular communication between program and finance departments to identify all federal awards received; (3) maintaining a master listing of all grants that identifies the funding source (federal/state/local) and applicable Assistance Listing Numbers; (4) implementing cutoff procedures to ensure federal expenditures are reported in the correct period based on when eligible costs are incurred, not when funds are drawn down from federal systems; and (5) requiring independent review of the SEFA by someone knowledgeable about federal compliance requirements who verifies completeness against grant documentation and proper period reporting. We note that the College's finance office maintains good communication practices with auditors regarding federal funding when they are aware of such awards; therefore, strengthening the internal identification and cutoff processes will enhance the College's ability to provide complete, accurate, and timely information to auditors about all federal funding sources. Views of responsible personnel and planned corrective actions: Management concurs with this finding. The College has implemented immediate corrective actions including development of a comprehensive grant tracking spreadsheet and establishment of regular meetings between program and finance staff. Additionally, effective immediately, all grant applications must be reviewed and approved by the Controller prior to submission to ensure proper identification of funding sources and compliance requirements. The College will also implement cutoff procedures to ensure federal expenditures are reported in the correct period based on when eligible costs are incurred. The Controller will review all G5 drawdowns near year-end to verify proper period reporting. Formal written procedures for SEFA preparation will be implemented by October 15, 2025. The Controller will maintain the master grant listing and review all grant agreements to determine federal funding sources. Beginning with fiscal year 2026 SEFA preparation, the CFO will perform an independent review for completeness and accuracy, including verification of proper period reporting for all federal expenditures.

FY End: 2024-05-31
University of Dubuque
Compliance Requirement: N
U.S. Department of Education Student Financial Assistance Programs Cluster (Direct) Federal Direct Loan Program (84.268) Federal Award Year: 2023-2024 Finding: The University did not timely or accurately report enrollment changes to the National Student Loan Data System (NSLDS). Criteria: Per 34 CFR 685.309(b), a school shall - (1) Upon receipt of an enrollment report from the Secretary, update all information included in the report and return the report to the Secretary in the manner and form...

U.S. Department of Education Student Financial Assistance Programs Cluster (Direct) Federal Direct Loan Program (84.268) Federal Award Year: 2023-2024 Finding: The University did not timely or accurately report enrollment changes to the National Student Loan Data System (NSLDS). Criteria: Per 34 CFR 685.309(b), a school shall - (1) Upon receipt of an enrollment report from the Secretary, update all information included in the report and return the report to the Secretary in the manner and format prescribed by the Secretary; and within the timeframe prescribed by the Secretary; and (2) Unless it expects to submit its next student updated enrollment report to the Secretary within the next 60 days, a school must notify the Secretary within 30 days if it discovers that a loan under Title IV of the Act was made to, or on behalf of, a student who was enrolled on at least a half-time basis or failed to enroll on at least a half-time basis for the period for which the loan was intended. Per 34 CFR 668.22(c)(ii), the withdrawal date is the date, as determined by the institution, that the student otherwise provided official notification to the institution, in writing or orally, of his or her intent to withdraw. Uniform Grant Guidance (2 CFR 200.303) requires nonfederal entities receiving Federal awards establish and maintain internal controls designed to reasonably ensure compliance with Federal laws, regulations and program compliance requirements. Effective internal controls should include procedures to ensure enrollment reporting is completed properly. Condition: 12 students were not reported as withdrawn within the 60 day timeframe for University’s reporting on the roster file submissions and the internal controls in place did not identify the errors. Cause: Student reporting was not within the 60 day roster submission timeframe. Effect: Noncompliance with federal regulations for enrollment reporting. Questioned costs: None. Context: 12 of the 25 students selected haphazardly and tested were not reported in accordance with NSLDS enrollment reporting and were within a range of five to six days late. Repeat finding: Yes. Recommendation: The University should accurately report all student status changes to the NSLDS. In addition, the University should review its policies and procedures to ensure withdrawal dates are accurately reflected in the enrollment management system and enrollment changes are reported timely. Views of responsible officials: Management agrees with this finding. See corrective action plan.

FY End: 2024-05-31
University of Dubuque
Compliance Requirement: N
U.S. Department of Education Student Financial Assistance Programs Cluster (Direct) Federal Direct Loan Program (84.268) Federal Award Year: 2023-2024 Finding: The University’s R2T4 calculation was improper for one student, as the student had not signed a promissory note for the direct loans and the direct loans should have not been included in the calculation. Criteria: Per 34 CFR 668.164, Any undisbursed Title IV aid for the period that the school uses as the basis for the R2T4 calculation i...

U.S. Department of Education Student Financial Assistance Programs Cluster (Direct) Federal Direct Loan Program (84.268) Federal Award Year: 2023-2024 Finding: The University’s R2T4 calculation was improper for one student, as the student had not signed a promissory note for the direct loans and the direct loans should have not been included in the calculation. Criteria: Per 34 CFR 668.164, Any undisbursed Title IV aid for the period that the school uses as the basis for the R2T4 calculation is counted as aid that could have been disbursed as long as the following conditions were met before the date the student became ineligible: For all programs, the Department processed a Student Aid Report (SAR) or Institutional Student Information Record (ISIR) with an official expected family contribution (EFC) for the student. (An official EFC is one calculated by the Department and provided on a SAR or ISIR. It may or may not be a valid EFC, which is one based on complete and correct information.) In all Title IV loan programs, a promissory note must be signed for a loan to be included as aid that could have been disbursed in an R2T4 calculation. The signature may be obtained after the student withdraws but must be signed before the school performs the R2T4 calculation. In addition, if a school has an affirmative confirmation process set up to actively determine if a student wants a Direct Loan, if the student declines or fails to respond to the request, the Direct Loan would not be included as aid that could have been disbursed. Uniform Grant Guidance (2 CFR 200.303) requires nonfederal entities receiving Federal awards establish and maintain internal controls designed to reasonably ensure compliance with Federal laws, regulations and program compliance requirements. Effective internal controls should include procedures to ensure enrollment reporting is completed properly. Condition: One student did not sign a promissory note for direct loans that were included in the R2T4 calculation; therefore, the University’s R2T4 calculation was improperly calculated and the internal controls in place did not identify the errors. Cause: Student did not sign a promissory note for direct loans. Effect: Noncompliance with federal regulations for R2T4 Questioned costs: Amount refunded was underpaid by $79. Context: One of the eight students selected randomly and tested did not sign a promissory note for direct loans that were included in the R2T4 calculation; therefore, the University’s R2T4 calculation was improperly calculated. Repeat finding: This is not a repeat finding. Recommendation: The University should review the controls and procedures in place to verify that only aid with signed promissory notes are being included in R2T4 calculations. Views of responsible officials: Management agrees with this finding. See corrective action plan.

FY End: 2024-05-31
University of Dubuque
Compliance Requirement: N
U.S. Department of Education Student Financial Assistance Programs Cluster Gramm-Leach Bliley Act – Student Information Security (84.007, 84.268, 84.038, 84.063, 84.378) Federal Award Year: 2023-2024 Finding: The University created and implemented a comprehensive information security policy, but did not have it done in a timely manner. Criteria: 2 CFR 200.303(a) requires that the non-Federal entity must establish and maintain effective internal control over the Federal award that provides reas...

U.S. Department of Education Student Financial Assistance Programs Cluster Gramm-Leach Bliley Act – Student Information Security (84.007, 84.268, 84.038, 84.063, 84.378) Federal Award Year: 2023-2024 Finding: The University created and implemented a comprehensive information security policy, but did not have it done in a timely manner. Criteria: 2 CFR 200.303(a) requires that the non-Federal entity must establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in Standards for Internal Control in the Federal Government issued by the Comptroller General of the United States or the Internal Control Integrated Framework, issued by the Committee of Sponsoring Organizations of the Treadway Commission. The Program Participation Agreement (PPA) with the U.S. Department of Education requires the institution to comply with the Standards for Safeguarding Customer Information as described in 16 CFR Part 314 which includes the development of a comprehensive written security program that includes the following parts: 16 CFR 314.4(a) requires institutions to designate a qualified individual responsible for overseeing and implementing the institution’s information security program and enforcing the information security program. 16 CFR 314.4(b) requires institutions to provide for the information security program to be based on a risk assessment that identifies reasonably foreseeable internal and external risks to the security, confidentiality and integrity of customer information (as the term customer information applies to the institution) that could result in the unauthorized disclosure, misuse, alteration, destruction or other compromise of such information, and assesses the sufficiency of any safeguards in place to control these risks. 16 CFR 314.4(c) requires institutions to provide for the design and implementation of safeguards to control the risks the institution provides through its risk assessment. 16 CFR 314.4(d) requires institutions to regularly test or otherwise monitor the effectiveness of the safeguards it has implemented 16 CFR 314.4(e) requires institutions to develop policies and procedures to ensure that personnel are able to enact the information security program. 16 CFR 314.4(f) requires institutions to develop policies and procedures to oversee its information system service providers. Condition: The institution’s written information security program was not done in a timely manner to include the following elements required by regulation as agreed to in the PPA: The written information security program does not designate an individual responsible for overseeing and implementing the institution’s information security program or enforcing the information security program. The institution has performed a risk assessment utilizing internal resources but has not based the information security program on the results of this assessment, nor has the institution included all required elements of internal and external risks to the security, confidentiality or integrity of customer information. The institution’s risk assessment is missing an inventory of IT systems that process and store customer information and the compliance with information security elements related to multifactor authentication, access control, change management, logging and alerting and encryption. The institution has not identified, designed or implemented safeguards for all of the risks identified in the risk assessment. The safeguards do not include the identification of security events or detection and response capabilities to support incident response. The institution has not been able to test safeguards because safeguards have not been designed or implemented in response to the risk assessment. The institution has not developed written policies and procedures to ensure that personnel are able to enact the information security program. There is a lack of evidence of leadership being required to report to the board or an appropriate supervisory council to ensure those charged with governance are informed on the current state of the information security program. The institution has not developed policies and procedures to oversee information service providers. Cause: The institution did not create and implement a comprehensive information security policy in a timely manner. Effect: The institution did not create and implement a comprehensive information security policy in a timely manner. The absence of internal controls and policies and procedures could result in the unauthorized disclosure, misuse, alteration, destruction or other compromise of student account information. Questioned costs: None. Context: Under an institution’s PPA with the U.S. Department of Education, schools must protect student financial aid information, with particular attention to information provided to institutions by the U.S. Department of Education or otherwise obtained in support of the administration of federal student financial aid programs. Repeat finding: This is not a repeat finding. Recommendation: We recommend that the University completes these requirements in a timely manner in the future. Views of responsible officials: Management agrees with this finding. See corrective action plan.

FY End: 2024-05-31
University of Dubuque
Compliance Requirement: N
U.S. Department of Education Student Financial Assistance Programs Cluster Gramm-Leach Bliley Act – Student Information Security (84.007, 84.268, 84.038, 84.063, 84.378) Federal Award Year: 2023-2024 Finding: The University created and implemented a comprehensive information security policy, but did not have it done in a timely manner. Criteria: 2 CFR 200.303(a) requires that the non-Federal entity must establish and maintain effective internal control over the Federal award that provides reas...

U.S. Department of Education Student Financial Assistance Programs Cluster Gramm-Leach Bliley Act – Student Information Security (84.007, 84.268, 84.038, 84.063, 84.378) Federal Award Year: 2023-2024 Finding: The University created and implemented a comprehensive information security policy, but did not have it done in a timely manner. Criteria: 2 CFR 200.303(a) requires that the non-Federal entity must establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in Standards for Internal Control in the Federal Government issued by the Comptroller General of the United States or the Internal Control Integrated Framework, issued by the Committee of Sponsoring Organizations of the Treadway Commission. The Program Participation Agreement (PPA) with the U.S. Department of Education requires the institution to comply with the Standards for Safeguarding Customer Information as described in 16 CFR Part 314 which includes the development of a comprehensive written security program that includes the following parts: 16 CFR 314.4(a) requires institutions to designate a qualified individual responsible for overseeing and implementing the institution’s information security program and enforcing the information security program. 16 CFR 314.4(b) requires institutions to provide for the information security program to be based on a risk assessment that identifies reasonably foreseeable internal and external risks to the security, confidentiality and integrity of customer information (as the term customer information applies to the institution) that could result in the unauthorized disclosure, misuse, alteration, destruction or other compromise of such information, and assesses the sufficiency of any safeguards in place to control these risks. 16 CFR 314.4(c) requires institutions to provide for the design and implementation of safeguards to control the risks the institution provides through its risk assessment. 16 CFR 314.4(d) requires institutions to regularly test or otherwise monitor the effectiveness of the safeguards it has implemented 16 CFR 314.4(e) requires institutions to develop policies and procedures to ensure that personnel are able to enact the information security program. 16 CFR 314.4(f) requires institutions to develop policies and procedures to oversee its information system service providers. Condition: The institution’s written information security program was not done in a timely manner to include the following elements required by regulation as agreed to in the PPA: The written information security program does not designate an individual responsible for overseeing and implementing the institution’s information security program or enforcing the information security program. The institution has performed a risk assessment utilizing internal resources but has not based the information security program on the results of this assessment, nor has the institution included all required elements of internal and external risks to the security, confidentiality or integrity of customer information. The institution’s risk assessment is missing an inventory of IT systems that process and store customer information and the compliance with information security elements related to multifactor authentication, access control, change management, logging and alerting and encryption. The institution has not identified, designed or implemented safeguards for all of the risks identified in the risk assessment. The safeguards do not include the identification of security events or detection and response capabilities to support incident response. The institution has not been able to test safeguards because safeguards have not been designed or implemented in response to the risk assessment. The institution has not developed written policies and procedures to ensure that personnel are able to enact the information security program. There is a lack of evidence of leadership being required to report to the board or an appropriate supervisory council to ensure those charged with governance are informed on the current state of the information security program. The institution has not developed policies and procedures to oversee information service providers. Cause: The institution did not create and implement a comprehensive information security policy in a timely manner. Effect: The institution did not create and implement a comprehensive information security policy in a timely manner. The absence of internal controls and policies and procedures could result in the unauthorized disclosure, misuse, alteration, destruction or other compromise of student account information. Questioned costs: None. Context: Under an institution’s PPA with the U.S. Department of Education, schools must protect student financial aid information, with particular attention to information provided to institutions by the U.S. Department of Education or otherwise obtained in support of the administration of federal student financial aid programs. Repeat finding: This is not a repeat finding. Recommendation: We recommend that the University completes these requirements in a timely manner in the future. Views of responsible officials: Management agrees with this finding. See corrective action plan.

FY End: 2024-05-31
University of Dubuque
Compliance Requirement: N
U.S. Department of Education Student Financial Assistance Programs Cluster Gramm-Leach Bliley Act – Student Information Security (84.007, 84.268, 84.038, 84.063, 84.378) Federal Award Year: 2023-2024 Finding: The University created and implemented a comprehensive information security policy, but did not have it done in a timely manner. Criteria: 2 CFR 200.303(a) requires that the non-Federal entity must establish and maintain effective internal control over the Federal award that provides reas...

U.S. Department of Education Student Financial Assistance Programs Cluster Gramm-Leach Bliley Act – Student Information Security (84.007, 84.268, 84.038, 84.063, 84.378) Federal Award Year: 2023-2024 Finding: The University created and implemented a comprehensive information security policy, but did not have it done in a timely manner. Criteria: 2 CFR 200.303(a) requires that the non-Federal entity must establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in Standards for Internal Control in the Federal Government issued by the Comptroller General of the United States or the Internal Control Integrated Framework, issued by the Committee of Sponsoring Organizations of the Treadway Commission. The Program Participation Agreement (PPA) with the U.S. Department of Education requires the institution to comply with the Standards for Safeguarding Customer Information as described in 16 CFR Part 314 which includes the development of a comprehensive written security program that includes the following parts: 16 CFR 314.4(a) requires institutions to designate a qualified individual responsible for overseeing and implementing the institution’s information security program and enforcing the information security program. 16 CFR 314.4(b) requires institutions to provide for the information security program to be based on a risk assessment that identifies reasonably foreseeable internal and external risks to the security, confidentiality and integrity of customer information (as the term customer information applies to the institution) that could result in the unauthorized disclosure, misuse, alteration, destruction or other compromise of such information, and assesses the sufficiency of any safeguards in place to control these risks. 16 CFR 314.4(c) requires institutions to provide for the design and implementation of safeguards to control the risks the institution provides through its risk assessment. 16 CFR 314.4(d) requires institutions to regularly test or otherwise monitor the effectiveness of the safeguards it has implemented 16 CFR 314.4(e) requires institutions to develop policies and procedures to ensure that personnel are able to enact the information security program. 16 CFR 314.4(f) requires institutions to develop policies and procedures to oversee its information system service providers. Condition: The institution’s written information security program was not done in a timely manner to include the following elements required by regulation as agreed to in the PPA: The written information security program does not designate an individual responsible for overseeing and implementing the institution’s information security program or enforcing the information security program. The institution has performed a risk assessment utilizing internal resources but has not based the information security program on the results of this assessment, nor has the institution included all required elements of internal and external risks to the security, confidentiality or integrity of customer information. The institution’s risk assessment is missing an inventory of IT systems that process and store customer information and the compliance with information security elements related to multifactor authentication, access control, change management, logging and alerting and encryption. The institution has not identified, designed or implemented safeguards for all of the risks identified in the risk assessment. The safeguards do not include the identification of security events or detection and response capabilities to support incident response. The institution has not been able to test safeguards because safeguards have not been designed or implemented in response to the risk assessment. The institution has not developed written policies and procedures to ensure that personnel are able to enact the information security program. There is a lack of evidence of leadership being required to report to the board or an appropriate supervisory council to ensure those charged with governance are informed on the current state of the information security program. The institution has not developed policies and procedures to oversee information service providers. Cause: The institution did not create and implement a comprehensive information security policy in a timely manner. Effect: The institution did not create and implement a comprehensive information security policy in a timely manner. The absence of internal controls and policies and procedures could result in the unauthorized disclosure, misuse, alteration, destruction or other compromise of student account information. Questioned costs: None. Context: Under an institution’s PPA with the U.S. Department of Education, schools must protect student financial aid information, with particular attention to information provided to institutions by the U.S. Department of Education or otherwise obtained in support of the administration of federal student financial aid programs. Repeat finding: This is not a repeat finding. Recommendation: We recommend that the University completes these requirements in a timely manner in the future. Views of responsible officials: Management agrees with this finding. See corrective action plan.

FY End: 2024-05-31
University of Dubuque
Compliance Requirement: N
U.S. Department of Education Student Financial Assistance Programs Cluster Gramm-Leach Bliley Act – Student Information Security (84.007, 84.268, 84.038, 84.063, 84.378) Federal Award Year: 2023-2024 Finding: The University created and implemented a comprehensive information security policy, but did not have it done in a timely manner. Criteria: 2 CFR 200.303(a) requires that the non-Federal entity must establish and maintain effective internal control over the Federal award that provides reas...

U.S. Department of Education Student Financial Assistance Programs Cluster Gramm-Leach Bliley Act – Student Information Security (84.007, 84.268, 84.038, 84.063, 84.378) Federal Award Year: 2023-2024 Finding: The University created and implemented a comprehensive information security policy, but did not have it done in a timely manner. Criteria: 2 CFR 200.303(a) requires that the non-Federal entity must establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in Standards for Internal Control in the Federal Government issued by the Comptroller General of the United States or the Internal Control Integrated Framework, issued by the Committee of Sponsoring Organizations of the Treadway Commission. The Program Participation Agreement (PPA) with the U.S. Department of Education requires the institution to comply with the Standards for Safeguarding Customer Information as described in 16 CFR Part 314 which includes the development of a comprehensive written security program that includes the following parts: 16 CFR 314.4(a) requires institutions to designate a qualified individual responsible for overseeing and implementing the institution’s information security program and enforcing the information security program. 16 CFR 314.4(b) requires institutions to provide for the information security program to be based on a risk assessment that identifies reasonably foreseeable internal and external risks to the security, confidentiality and integrity of customer information (as the term customer information applies to the institution) that could result in the unauthorized disclosure, misuse, alteration, destruction or other compromise of such information, and assesses the sufficiency of any safeguards in place to control these risks. 16 CFR 314.4(c) requires institutions to provide for the design and implementation of safeguards to control the risks the institution provides through its risk assessment. 16 CFR 314.4(d) requires institutions to regularly test or otherwise monitor the effectiveness of the safeguards it has implemented 16 CFR 314.4(e) requires institutions to develop policies and procedures to ensure that personnel are able to enact the information security program. 16 CFR 314.4(f) requires institutions to develop policies and procedures to oversee its information system service providers. Condition: The institution’s written information security program was not done in a timely manner to include the following elements required by regulation as agreed to in the PPA: The written information security program does not designate an individual responsible for overseeing and implementing the institution’s information security program or enforcing the information security program. The institution has performed a risk assessment utilizing internal resources but has not based the information security program on the results of this assessment, nor has the institution included all required elements of internal and external risks to the security, confidentiality or integrity of customer information. The institution’s risk assessment is missing an inventory of IT systems that process and store customer information and the compliance with information security elements related to multifactor authentication, access control, change management, logging and alerting and encryption. The institution has not identified, designed or implemented safeguards for all of the risks identified in the risk assessment. The safeguards do not include the identification of security events or detection and response capabilities to support incident response. The institution has not been able to test safeguards because safeguards have not been designed or implemented in response to the risk assessment. The institution has not developed written policies and procedures to ensure that personnel are able to enact the information security program. There is a lack of evidence of leadership being required to report to the board or an appropriate supervisory council to ensure those charged with governance are informed on the current state of the information security program. The institution has not developed policies and procedures to oversee information service providers. Cause: The institution did not create and implement a comprehensive information security policy in a timely manner. Effect: The institution did not create and implement a comprehensive information security policy in a timely manner. The absence of internal controls and policies and procedures could result in the unauthorized disclosure, misuse, alteration, destruction or other compromise of student account information. Questioned costs: None. Context: Under an institution’s PPA with the U.S. Department of Education, schools must protect student financial aid information, with particular attention to information provided to institutions by the U.S. Department of Education or otherwise obtained in support of the administration of federal student financial aid programs. Repeat finding: This is not a repeat finding. Recommendation: We recommend that the University completes these requirements in a timely manner in the future. Views of responsible officials: Management agrees with this finding. See corrective action plan.

FY End: 2024-05-31
University of Dubuque
Compliance Requirement: N
U.S. Department of Education Student Financial Assistance Programs Cluster Gramm-Leach Bliley Act – Student Information Security (84.007, 84.268, 84.038, 84.063, 84.378) Federal Award Year: 2023-2024 Finding: The University created and implemented a comprehensive information security policy, but did not have it done in a timely manner. Criteria: 2 CFR 200.303(a) requires that the non-Federal entity must establish and maintain effective internal control over the Federal award that provides reas...

U.S. Department of Education Student Financial Assistance Programs Cluster Gramm-Leach Bliley Act – Student Information Security (84.007, 84.268, 84.038, 84.063, 84.378) Federal Award Year: 2023-2024 Finding: The University created and implemented a comprehensive information security policy, but did not have it done in a timely manner. Criteria: 2 CFR 200.303(a) requires that the non-Federal entity must establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in Standards for Internal Control in the Federal Government issued by the Comptroller General of the United States or the Internal Control Integrated Framework, issued by the Committee of Sponsoring Organizations of the Treadway Commission. The Program Participation Agreement (PPA) with the U.S. Department of Education requires the institution to comply with the Standards for Safeguarding Customer Information as described in 16 CFR Part 314 which includes the development of a comprehensive written security program that includes the following parts: 16 CFR 314.4(a) requires institutions to designate a qualified individual responsible for overseeing and implementing the institution’s information security program and enforcing the information security program. 16 CFR 314.4(b) requires institutions to provide for the information security program to be based on a risk assessment that identifies reasonably foreseeable internal and external risks to the security, confidentiality and integrity of customer information (as the term customer information applies to the institution) that could result in the unauthorized disclosure, misuse, alteration, destruction or other compromise of such information, and assesses the sufficiency of any safeguards in place to control these risks. 16 CFR 314.4(c) requires institutions to provide for the design and implementation of safeguards to control the risks the institution provides through its risk assessment. 16 CFR 314.4(d) requires institutions to regularly test or otherwise monitor the effectiveness of the safeguards it has implemented 16 CFR 314.4(e) requires institutions to develop policies and procedures to ensure that personnel are able to enact the information security program. 16 CFR 314.4(f) requires institutions to develop policies and procedures to oversee its information system service providers. Condition: The institution’s written information security program was not done in a timely manner to include the following elements required by regulation as agreed to in the PPA: The written information security program does not designate an individual responsible for overseeing and implementing the institution’s information security program or enforcing the information security program. The institution has performed a risk assessment utilizing internal resources but has not based the information security program on the results of this assessment, nor has the institution included all required elements of internal and external risks to the security, confidentiality or integrity of customer information. The institution’s risk assessment is missing an inventory of IT systems that process and store customer information and the compliance with information security elements related to multifactor authentication, access control, change management, logging and alerting and encryption. The institution has not identified, designed or implemented safeguards for all of the risks identified in the risk assessment. The safeguards do not include the identification of security events or detection and response capabilities to support incident response. The institution has not been able to test safeguards because safeguards have not been designed or implemented in response to the risk assessment. The institution has not developed written policies and procedures to ensure that personnel are able to enact the information security program. There is a lack of evidence of leadership being required to report to the board or an appropriate supervisory council to ensure those charged with governance are informed on the current state of the information security program. The institution has not developed policies and procedures to oversee information service providers. Cause: The institution did not create and implement a comprehensive information security policy in a timely manner. Effect: The institution did not create and implement a comprehensive information security policy in a timely manner. The absence of internal controls and policies and procedures could result in the unauthorized disclosure, misuse, alteration, destruction or other compromise of student account information. Questioned costs: None. Context: Under an institution’s PPA with the U.S. Department of Education, schools must protect student financial aid information, with particular attention to information provided to institutions by the U.S. Department of Education or otherwise obtained in support of the administration of federal student financial aid programs. Repeat finding: This is not a repeat finding. Recommendation: We recommend that the University completes these requirements in a timely manner in the future. Views of responsible officials: Management agrees with this finding. See corrective action plan.

FY End: 2024-05-31
University of Dubuque
Compliance Requirement: N
U.S. Department of Education Student Financial Assistance Programs Cluster Gramm-Leach Bliley Act – Student Information Security (84.007, 84.268, 84.038, 84.063, 84.378) Federal Award Year: 2023-2024 Finding: The University created and implemented a comprehensive information security policy, but did not have it done in a timely manner. Criteria: 2 CFR 200.303(a) requires that the non-Federal entity must establish and maintain effective internal control over the Federal award that provides reas...

U.S. Department of Education Student Financial Assistance Programs Cluster Gramm-Leach Bliley Act – Student Information Security (84.007, 84.268, 84.038, 84.063, 84.378) Federal Award Year: 2023-2024 Finding: The University created and implemented a comprehensive information security policy, but did not have it done in a timely manner. Criteria: 2 CFR 200.303(a) requires that the non-Federal entity must establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in Standards for Internal Control in the Federal Government issued by the Comptroller General of the United States or the Internal Control Integrated Framework, issued by the Committee of Sponsoring Organizations of the Treadway Commission. The Program Participation Agreement (PPA) with the U.S. Department of Education requires the institution to comply with the Standards for Safeguarding Customer Information as described in 16 CFR Part 314 which includes the development of a comprehensive written security program that includes the following parts: 16 CFR 314.4(a) requires institutions to designate a qualified individual responsible for overseeing and implementing the institution’s information security program and enforcing the information security program. 16 CFR 314.4(b) requires institutions to provide for the information security program to be based on a risk assessment that identifies reasonably foreseeable internal and external risks to the security, confidentiality and integrity of customer information (as the term customer information applies to the institution) that could result in the unauthorized disclosure, misuse, alteration, destruction or other compromise of such information, and assesses the sufficiency of any safeguards in place to control these risks. 16 CFR 314.4(c) requires institutions to provide for the design and implementation of safeguards to control the risks the institution provides through its risk assessment. 16 CFR 314.4(d) requires institutions to regularly test or otherwise monitor the effectiveness of the safeguards it has implemented 16 CFR 314.4(e) requires institutions to develop policies and procedures to ensure that personnel are able to enact the information security program. 16 CFR 314.4(f) requires institutions to develop policies and procedures to oversee its information system service providers. Condition: The institution’s written information security program was not done in a timely manner to include the following elements required by regulation as agreed to in the PPA: The written information security program does not designate an individual responsible for overseeing and implementing the institution’s information security program or enforcing the information security program. The institution has performed a risk assessment utilizing internal resources but has not based the information security program on the results of this assessment, nor has the institution included all required elements of internal and external risks to the security, confidentiality or integrity of customer information. The institution’s risk assessment is missing an inventory of IT systems that process and store customer information and the compliance with information security elements related to multifactor authentication, access control, change management, logging and alerting and encryption. The institution has not identified, designed or implemented safeguards for all of the risks identified in the risk assessment. The safeguards do not include the identification of security events or detection and response capabilities to support incident response. The institution has not been able to test safeguards because safeguards have not been designed or implemented in response to the risk assessment. The institution has not developed written policies and procedures to ensure that personnel are able to enact the information security program. There is a lack of evidence of leadership being required to report to the board or an appropriate supervisory council to ensure those charged with governance are informed on the current state of the information security program. The institution has not developed policies and procedures to oversee information service providers. Cause: The institution did not create and implement a comprehensive information security policy in a timely manner. Effect: The institution did not create and implement a comprehensive information security policy in a timely manner. The absence of internal controls and policies and procedures could result in the unauthorized disclosure, misuse, alteration, destruction or other compromise of student account information. Questioned costs: None. Context: Under an institution’s PPA with the U.S. Department of Education, schools must protect student financial aid information, with particular attention to information provided to institutions by the U.S. Department of Education or otherwise obtained in support of the administration of federal student financial aid programs. Repeat finding: This is not a repeat finding. Recommendation: We recommend that the University completes these requirements in a timely manner in the future. Views of responsible officials: Management agrees with this finding. See corrective action plan.

FY End: 2024-05-31
Bradley University
Compliance Requirement: L
Federal Agency: U.S. Department of Education Federal Program Name: Student Financial Assistance Cluster Assistance Listing Number: 84.007 (Federal Supplemental Educational Opportunity Grants Program), 84.033 (Federal Work Study Program), 84.063 (Federal Pell Grant Program), 84.268 (Federal Direct Student Loans Program) Pass-Through Agency: N/A Pass-Through Number(s): N/A Award Period: June 1, 2023 – May 31, 2024 Type of Finding: • Significant Deficiency in Internal Control over Compliance • O...

Federal Agency: U.S. Department of Education Federal Program Name: Student Financial Assistance Cluster Assistance Listing Number: 84.007 (Federal Supplemental Educational Opportunity Grants Program), 84.033 (Federal Work Study Program), 84.063 (Federal Pell Grant Program), 84.268 (Federal Direct Student Loans Program) Pass-Through Agency: N/A Pass-Through Number(s): N/A Award Period: June 1, 2023 – May 31, 2024 Type of Finding: • Significant Deficiency in Internal Control over Compliance • Other Matters Criteria or specific requirement: The Gramm-Leach-Bliley Act (Public Law 106-102) requires financial institutions to explain their information-sharing practices to their customers and to safeguard sensitive data. (16 CFR 314) The Federal Trade Commission considers Title IV-eligible institutions that participate in Title IV Educational Assistance Programs as “financial institutions” and subject to the Gramm-Leach-Bliley Act (16 CFR 313.3(k)(2)(vi)). The Code of Federal Regulations 2 CFR 200.303 requires the University to establish and maintain effective internal controls over Federal awards. Condition: During our testing of the University’s information technology, we noted the University did not maintain a comprehensive written security program that included the minimum required elements. The University does perform all procedures required by the Gramm-Leach-Bliley Act, however, these procedures are not formally documented. Questioned costs: None Context: Under an institution’s Program Participation Agreement with the Department of Education and the Gramm-Leach-Bliley Act, schools must protect student financial aid information, with particular attention to information provided to institutions by the Department or otherwise obtained in support of the administration of the federal student financial aid programs. Cause: The University has continued to make progress in updating the University’s written security program to become in compliance with all requirements; however, due to capacity and demands on the information technology individuals, this is still a work in process. Effect: The student personal information could be vulnerable. Repeat finding: No Recommendation: We recommend the University work to update the written security program to ensure compliance with all the standards. Views of responsible officials: There is no disagreement with the audit finding.

FY End: 2024-05-31
Bradley University
Compliance Requirement: L
Federal Agency: U.S. Department of Education Federal Program Name: Student Financial Assistance Cluster Assistance Listing Number: 84.007 (Federal Supplemental Educational Opportunity Grants Program), 84.033 (Federal Work Study Program), 84.063 (Federal Pell Grant Program), 84.268 (Federal Direct Student Loans Program) Pass-Through Agency: N/A Pass-Through Number(s): N/A Award Period: June 1, 2023 – May 31, 2024 Type of Finding: • Significant Deficiency in Internal Control over Compliance • O...

Federal Agency: U.S. Department of Education Federal Program Name: Student Financial Assistance Cluster Assistance Listing Number: 84.007 (Federal Supplemental Educational Opportunity Grants Program), 84.033 (Federal Work Study Program), 84.063 (Federal Pell Grant Program), 84.268 (Federal Direct Student Loans Program) Pass-Through Agency: N/A Pass-Through Number(s): N/A Award Period: June 1, 2023 – May 31, 2024 Type of Finding: • Significant Deficiency in Internal Control over Compliance • Other Matters Criteria or specific requirement: The Gramm-Leach-Bliley Act (Public Law 106-102) requires financial institutions to explain their information-sharing practices to their customers and to safeguard sensitive data. (16 CFR 314) The Federal Trade Commission considers Title IV-eligible institutions that participate in Title IV Educational Assistance Programs as “financial institutions” and subject to the Gramm-Leach-Bliley Act (16 CFR 313.3(k)(2)(vi)). The Code of Federal Regulations 2 CFR 200.303 requires the University to establish and maintain effective internal controls over Federal awards. Condition: During our testing of the University’s information technology, we noted the University did not maintain a comprehensive written security program that included the minimum required elements. The University does perform all procedures required by the Gramm-Leach-Bliley Act, however, these procedures are not formally documented. Questioned costs: None Context: Under an institution’s Program Participation Agreement with the Department of Education and the Gramm-Leach-Bliley Act, schools must protect student financial aid information, with particular attention to information provided to institutions by the Department or otherwise obtained in support of the administration of the federal student financial aid programs. Cause: The University has continued to make progress in updating the University’s written security program to become in compliance with all requirements; however, due to capacity and demands on the information technology individuals, this is still a work in process. Effect: The student personal information could be vulnerable. Repeat finding: No Recommendation: We recommend the University work to update the written security program to ensure compliance with all the standards. Views of responsible officials: There is no disagreement with the audit finding.

FY End: 2024-05-31
Bradley University
Compliance Requirement: L
Federal Agency: U.S. Department of Education Federal Program Name: Student Financial Assistance Cluster Assistance Listing Number: 84.007 (Federal Supplemental Educational Opportunity Grants Program), 84.033 (Federal Work Study Program), 84.063 (Federal Pell Grant Program), 84.268 (Federal Direct Student Loans Program) Pass-Through Agency: N/A Pass-Through Number(s): N/A Award Period: June 1, 2023 – May 31, 2024 Type of Finding: • Significant Deficiency in Internal Control over Compliance • O...

Federal Agency: U.S. Department of Education Federal Program Name: Student Financial Assistance Cluster Assistance Listing Number: 84.007 (Federal Supplemental Educational Opportunity Grants Program), 84.033 (Federal Work Study Program), 84.063 (Federal Pell Grant Program), 84.268 (Federal Direct Student Loans Program) Pass-Through Agency: N/A Pass-Through Number(s): N/A Award Period: June 1, 2023 – May 31, 2024 Type of Finding: • Significant Deficiency in Internal Control over Compliance • Other Matters Criteria or specific requirement: The Gramm-Leach-Bliley Act (Public Law 106-102) requires financial institutions to explain their information-sharing practices to their customers and to safeguard sensitive data. (16 CFR 314) The Federal Trade Commission considers Title IV-eligible institutions that participate in Title IV Educational Assistance Programs as “financial institutions” and subject to the Gramm-Leach-Bliley Act (16 CFR 313.3(k)(2)(vi)). The Code of Federal Regulations 2 CFR 200.303 requires the University to establish and maintain effective internal controls over Federal awards. Condition: During our testing of the University’s information technology, we noted the University did not maintain a comprehensive written security program that included the minimum required elements. The University does perform all procedures required by the Gramm-Leach-Bliley Act, however, these procedures are not formally documented. Questioned costs: None Context: Under an institution’s Program Participation Agreement with the Department of Education and the Gramm-Leach-Bliley Act, schools must protect student financial aid information, with particular attention to information provided to institutions by the Department or otherwise obtained in support of the administration of the federal student financial aid programs. Cause: The University has continued to make progress in updating the University’s written security program to become in compliance with all requirements; however, due to capacity and demands on the information technology individuals, this is still a work in process. Effect: The student personal information could be vulnerable. Repeat finding: No Recommendation: We recommend the University work to update the written security program to ensure compliance with all the standards. Views of responsible officials: There is no disagreement with the audit finding.

FY End: 2024-05-31
Bradley University
Compliance Requirement: L
Federal Agency: U.S. Department of Education Federal Program Name: Student Financial Assistance Cluster Assistance Listing Number: 84.007 (Federal Supplemental Educational Opportunity Grants Program), 84.033 (Federal Work Study Program), 84.063 (Federal Pell Grant Program), 84.268 (Federal Direct Student Loans Program) Pass-Through Agency: N/A Pass-Through Number(s): N/A Award Period: June 1, 2023 – May 31, 2024 Type of Finding: • Significant Deficiency in Internal Control over Compliance • O...

Federal Agency: U.S. Department of Education Federal Program Name: Student Financial Assistance Cluster Assistance Listing Number: 84.007 (Federal Supplemental Educational Opportunity Grants Program), 84.033 (Federal Work Study Program), 84.063 (Federal Pell Grant Program), 84.268 (Federal Direct Student Loans Program) Pass-Through Agency: N/A Pass-Through Number(s): N/A Award Period: June 1, 2023 – May 31, 2024 Type of Finding: • Significant Deficiency in Internal Control over Compliance • Other Matters Criteria or specific requirement: The Gramm-Leach-Bliley Act (Public Law 106-102) requires financial institutions to explain their information-sharing practices to their customers and to safeguard sensitive data. (16 CFR 314) The Federal Trade Commission considers Title IV-eligible institutions that participate in Title IV Educational Assistance Programs as “financial institutions” and subject to the Gramm-Leach-Bliley Act (16 CFR 313.3(k)(2)(vi)). The Code of Federal Regulations 2 CFR 200.303 requires the University to establish and maintain effective internal controls over Federal awards. Condition: During our testing of the University’s information technology, we noted the University did not maintain a comprehensive written security program that included the minimum required elements. The University does perform all procedures required by the Gramm-Leach-Bliley Act, however, these procedures are not formally documented. Questioned costs: None Context: Under an institution’s Program Participation Agreement with the Department of Education and the Gramm-Leach-Bliley Act, schools must protect student financial aid information, with particular attention to information provided to institutions by the Department or otherwise obtained in support of the administration of the federal student financial aid programs. Cause: The University has continued to make progress in updating the University’s written security program to become in compliance with all requirements; however, due to capacity and demands on the information technology individuals, this is still a work in process. Effect: The student personal information could be vulnerable. Repeat finding: No Recommendation: We recommend the University work to update the written security program to ensure compliance with all the standards. Views of responsible officials: There is no disagreement with the audit finding.

FY End: 2024-05-31
Kansas Health Science Center, Inc.
Compliance Requirement: C
Finding 2024-001: Excess Cash – Student Financial Aid Federal Agency: U.S. Department of Education Program Name: Student Financial Assistance Cluster, Federal Direct Student Loans Assistance Listing Number: 84.268 Award Year: June 1, 2023 – May 31, 2024 Program Expenditures: $14,342,246 Questioned Costs: None Criteria: Uniform Grant Guidance (34 CFR 668.166) states the Secretary considers excess cash to be any amount of Title IV, Higher Education Act (HEA) program funds, other than Federal...

Finding 2024-001: Excess Cash – Student Financial Aid Federal Agency: U.S. Department of Education Program Name: Student Financial Assistance Cluster, Federal Direct Student Loans Assistance Listing Number: 84.268 Award Year: June 1, 2023 – May 31, 2024 Program Expenditures: $14,342,246 Questioned Costs: None Criteria: Uniform Grant Guidance (34 CFR 668.166) states the Secretary considers excess cash to be any amount of Title IV, Higher Education Act (HEA) program funds, other than Federal Perkins Loan program funds, that an institution does not disburse to students by the end of the third business day following the date the institution (1) received those funds from the Secretary; or (2) deposited or transferred to its depository account previously disbursed Title IV, HEA program funds, such as those resulting from awards adjustments, recoveries, or cancellations. An institution may maintain for up to seven days an amount of excess cash that does not exceed one percent of the total amount of funds the institution drew down in the prior award year. The institution must return immediately to the Secretary any amount of excess cash over the one-percent tolerance and any amount of excess cash remaining in its account after the seven-day tolerance period. Uniform Grant Guidance (2 CFR 200.303) requires nonfederal entities receiving Federal awards establish and maintain internal controls designed to reasonably ensure compliance with Federal laws, regulations, and program compliance requirements. Effective internal controls should include procedures to ensure excess cash is properly handled. Condition: The Kansas Health Science University (KHSU) had two instances of excess cash for the Federal Direct Student Loan program. During our cash management testing, we identified KHSU had excess cash for the Direct Loan program of $268,278 for the period from July 12, 2023 to July 19, 2023 and ranging from $2,204 to $13,385 for the period from April 8, 2024 to April 23, 2024. For the period of July 12, 2023 to July 19, 2023, the excess cash exceeded one percent of total prior year drawdowns and amounts were not returned within the three business-day period. For the period of April 8, 2024 to April 23, 2024, the excess cash did not exceed one percent of total prior year drawdowns, however, amounts were not returned with a seven-day period. Cause: University officials stated the excess cash issues were due to oversight regarding refunds issued to students. Effect: Excess cash is noncompliance with Federal regulations and could result in heightened monitoring by the U.S. Department of Education. Questioned Costs: None Finding 2024-001: Excess Cash – Student Financial Aid (Continued) Context: For the periods of July 12, 2023 to July 19, 2023 and April 8, 2024 to April 23, 2024, KHSU had excess cash in the amount of $268,278 and ranging from $2,204 to $13,385, respectively. KHSU held excess cash for a period of 5 business days and 17 calendar days, respectively. Repeat Finding: No. Recommendation: We recommend KHSU strengthen internal controls around the determination of amounts to be drawn and refunded to the Secretary during the fiscal year. Views of Responsible Officials: Management agrees with the finding. Please see corrective action plan attached.

FY End: 2024-05-31
Kansas Health Science Center, Inc.
Compliance Requirement: B
Finding 2024-002: Improper Controls over Personnel Expenses Federal Agency: U.S. Department of Treasury Program Name: COVID-19: Coronavirus State and Local Fiscal Recovery Funds Assistance Listing Number: 21.027 Award Year: June 1, 2023 – May 31, 2024 Program Expenditures: $1,119,206 Questioned Costs: None Criteria: Uniform Grant Guidance (2 CFR 200.430(g)(1)(i)) states charges to Federal awards for salaries and wages must be based on records that accurately reflect the work performed. The...

Finding 2024-002: Improper Controls over Personnel Expenses Federal Agency: U.S. Department of Treasury Program Name: COVID-19: Coronavirus State and Local Fiscal Recovery Funds Assistance Listing Number: 21.027 Award Year: June 1, 2023 – May 31, 2024 Program Expenditures: $1,119,206 Questioned Costs: None Criteria: Uniform Grant Guidance (2 CFR 200.430(g)(1)(i)) states charges to Federal awards for salaries and wages must be based on records that accurately reflect the work performed. These records must be supported by a system of internal control that provides reasonable assurance that the charges are accurate, allowable, and properly allocated. Uniform Grant Guidance (2 CFR 200.303) requires nonfederal entities receiving Federal awards establish and maintain internal controls designed to reasonably ensure compliance with Federal laws, regulations, and program compliance requirements. Effective internal controls should include procedures to ensure personnel activity reports are approved. Condition: A KHSU supervisor did not properly document approval for one employee’s personnel activity reports. Cause: KHSU officials stated that this issue was an isolated incident resulting from an unintentional oversight at multiple levels of approval. While established procedures generally ensure proper documentation of personnel activity reports, in this case, the required documentation was inadvertently missed during the review and approval process. Effect: If employee’s personnel activity reports are not properly reviewed and approved, KHSU could submit unallowable costs for the program. Questioned Costs: None Context: Of the 8 employee personnel activity reports sampled, one report did not contain the proper approval by a KHSU supervisor. Repeat Finding: No. Recommendation: We recommend KHSU strengthen internal controls around the approval of personnel activity reports to confirm that a reasonable person can confirm the control occurred. Views of Responsible Officials: Management agrees with the finding. Please see corrective action plan attached.

FY End: 2024-05-31
Kansas Health Science Center, Inc.
Compliance Requirement: I
Finding 2024-003: Lack of Control Documentation over Review of Suspended/Debarred Vendors Federal Agency: U.S. Department of Treasury Program Name: COVID-19: Coronavirus State and Local Fiscal Recovery Funds Assistance Listing Number: 21.027 Award Year: June 1, 2023 – May 31, 2024 Program Expenditures: $1,119,206 Questioned Costs: None Criteria: Uniform Grant Guidance (2 CFR 180.300) states that when entering into a covered transaction with another person at the next lower tier, the nonfed...

Finding 2024-003: Lack of Control Documentation over Review of Suspended/Debarred Vendors Federal Agency: U.S. Department of Treasury Program Name: COVID-19: Coronavirus State and Local Fiscal Recovery Funds Assistance Listing Number: 21.027 Award Year: June 1, 2023 – May 31, 2024 Program Expenditures: $1,119,206 Questioned Costs: None Criteria: Uniform Grant Guidance (2 CFR 180.300) states that when entering into a covered transaction with another person at the next lower tier, the nonfederal entity must verify the person with whom the nonfederal entity intends to do business is not excluded or disqualified by: (a) checking Sam.gov Exclusions; or (b) collecting a certification from that person; or (c) adding a clause or condition to the covered transaction with that person. Uniform Grant Guidance (2 CFR 200.303) requires nonfederal entities receiving Federal awards establish and maintain internal controls designed to reasonably ensure compliance with Federal laws, regulations, and program compliance requirements. Effective internal controls should include procedures to ensure vendors are not suspended or debarred. Condition: KHSU was not able to provide support showing that a check had been performed on vendors with whom KHSU entered into covered transactions to verify the vendor were not suspended or debarred. Cause: KHSU officials stated while the organization had a policy in place requiring the review of vendors to ensure compliance with federal requirements, the policy did not include proper documentation requirements. Effect: If KHSU does not maintain documentation confirming a vendor under a covered transaction was not suspended or debarred, KHSU could enter into a transaction with a suspended or debarred vendor and as a result represent noncompliance and improper use of federal funds. Questioned Costs: None Context: KHSU had covered transactions with five vendors for the program totaling expenditures of $440,610. KHSU confirmed it performed the check but did not maintain documentation showing the check was performed. Our testing of all five vendors did not indicate that any were suspended or debarred. Repeat Finding: No. Recommendation: We recommend KHSU update its policy over suspended and debarred vendors to affirm documentation of review of SAM.gov is maintained or certification is obtained from the vendor ensuring they are not suspended or debarred. Views of Responsible Officials: Management agrees with the finding. Please see corrective action plan attached.

FY End: 2024-05-31
The Colleges of Law
Compliance Requirement: C
Finding 2024-001: Excess Cash – Student Financial Aid Federal Agency: U.S. Department of Education Program Name: Student Financial Assistance Cluster, Federal Direct Student Loans Assistance Listing Number: 84.268 Award Year: June 1, 2023 – May 31, 2024 Program Expenditures: $14,342,246 Questioned Costs: None Criteria: Uniform Grant Guidance (34 CFR 668.166) states the Secretary considers excess cash to be any amount of title IV, HEA program funds, other than Federal Perkins Loan program ...

Finding 2024-001: Excess Cash – Student Financial Aid Federal Agency: U.S. Department of Education Program Name: Student Financial Assistance Cluster, Federal Direct Student Loans Assistance Listing Number: 84.268 Award Year: June 1, 2023 – May 31, 2024 Program Expenditures: $14,342,246 Questioned Costs: None Criteria: Uniform Grant Guidance (34 CFR 668.166) states the Secretary considers excess cash to be any amount of title IV, HEA program funds, other than Federal Perkins Loan program funds, that an institution does not disburse to students by the end of the third business day following the date the institution (1) received those funds from the Secretary; or (2) deposited or transferred to its depository account previously disbursed title IV, HEA program funds, such as those resulting from awards adjustments, recoveries, or cancellations. An institution may maintain for up to seven days an amount of excess cash that does not exceed one percent of the total amount of funds the institution drew down in the prior award year. The institution must return immediately to the Secretary any amount of excess cash over the one-percent tolerance and any amount of excess cash remaining in its account after the seven-day tolerance period. Uniform Grant Guidance (2 CFR 200.303) requires nonfederal entities receiving Federal awards establish and maintain internal controls designed to reasonably ensure compliance with Federal laws, regulations, and program compliance requirements. Effective internal controls should include procedures to ensure excess cash is properly handled. Condition: The Colleges of Law (COL) had one instance of excess cash for the Federal Direct Student Loan program. During our cash management testing, we identified COL had excess cash for the Direct Loan program ranging from $172 to $10,314 for the period from March 25, 2024 to April 5, 2024. For that period, the excess cash did not exceed one percent of total prior year drawdowns, however, amounts were not returned within the seven-day period. Cause: University officials stated the excess cash issues were due to oversight regarding refunds issued to students. Effect: Excess cash is noncompliance with Federal regulations and could result in heightened monitoring by the U.S. Department of Education. Questioned Costs: None   Context: For the period of March 25, 2024 to April 5, 2024, COL had excess cash in the amount ranging from $172 to $10,314. COL had excess cash for a period of 11 calendar days. Repeat Finding: No. Recommendation: We recommend COL strengthen internal controls around the determination of amounts to be drawn and refunded to the Secretary during the fiscal year. Views of Responsible Officials: Management agrees with the finding. Please see corrective action plan attached.

FY End: 2024-05-31
Pacific Oaks Education Corporation
Compliance Requirement: C
Finding 2024-001: Excess Cash – Student Financial Aid Federal Agency: U.S. Department of Education Program Name: Student Financial Assistance Cluster, Federal Direct Student Loans Assistance Listing Number: 84.268 Award Year: June 1, 2023 – May 31, 2024 Program Expenditures: $22,734,225 Questioned Costs: None Criteria: Uniform Guidance for the Department of Education (34 CFR 668.166) states the Secretary considers excess cash to be any amount of title IV, HEA program funds, other than Fed...

Finding 2024-001: Excess Cash – Student Financial Aid Federal Agency: U.S. Department of Education Program Name: Student Financial Assistance Cluster, Federal Direct Student Loans Assistance Listing Number: 84.268 Award Year: June 1, 2023 – May 31, 2024 Program Expenditures: $22,734,225 Questioned Costs: None Criteria: Uniform Guidance for the Department of Education (34 CFR 668.166) states the Secretary considers excess cash to be any amount of title IV, HEA program funds, other than Federal Perkins Loan program funds, that an institution does not disburse to students by the end of the third business day following the date the institution: (1) received those funds from the Secretary; or (2) deposited or transferred to its depository account previously disbursed title IV, HEA program funds, such as those resulting from awards adjustments, recoveries, or cancellations. An institution may maintain for up to seven days an amount of excess cash that does not exceed one percent of the total amount of funds the institution drew down in the prior award year. The institution must return immediately to the Secretary any amount of excess cash over the one-percent tolerance and any amount of excess cash remaining in its account after the seven-day tolerance period. Uniform Guidance (2 CFR 200.303) requires nonfederal entities receiving Federal awards establish and maintain internal controls designed to reasonably ensure compliance with Federal laws, regulations, and program compliance requirements. Effective internal controls should include procedures to ensure excess cash is properly handled. Condition: Pacific Oaks Education Corporation (the College) had one instance of excess cash for the Federal Direct Student Loan program. During our cash management testing, we identified the College had excess cash for the Direct Loan program ranging from $1,335,590 to $4,774,182 for the period from September 6, 2023 to September 13, 2023. For that period, the excess cash exceeded one percent of total prior year drawdowns and amounts were not returned within the three business-day period. Cause: College officials explained that the excess cash resulted from the College’s practice of drawing funds early to ensure timely disbursement of stipends to students. The drawdown occurred prior to completing the reconciliation of the award amounts. As a result, while the funds were drawn, they were not posted to the students' ledgers within the required three-day period, leading to the excess cash being held for a longer duration than allowed. Effect: Excess cash is noncompliance with Federal regulations and could result in heightened monitoring by the U.S. Department of Education. Questioned Costs: None Context: For the period of September 6, 2023 to September 13, 2023, the College had excess cash in the amount ranging from $1,335,590 to $4,774,182. The College held excess cash for a period of 5 business days. Repeat Finding: No. Recommendation: We recommend the College strengthen internal controls around cash management to prevent or timely correct excess cash instances. Views of Responsible Officials: Management agrees with the finding. Please see corrective action plan attached.

FY End: 2024-05-31
The Chicago School-Cal INC Dba the Chicago Sch of Pro Psychology
Compliance Requirement: C
Finding 2024-001: Excess Cash – Student Financial Aid Federal Agency: U.S. Department of Education Program Name: Student Financial Assistance Cluster, Federal Direct Student Loans Assistance Listing Number: 84.268 Award Year: June 1, 2023 – May 31, 2024 Program Expenditures: $202,369,164 Questioned Costs: None Criteria: Uniform Grant Guidance (34 CFR 668.166) states the Secretary considers excess cash to be any amount of title IV, HEA program funds, other than Federal Perkins Loan program...

Finding 2024-001: Excess Cash – Student Financial Aid Federal Agency: U.S. Department of Education Program Name: Student Financial Assistance Cluster, Federal Direct Student Loans Assistance Listing Number: 84.268 Award Year: June 1, 2023 – May 31, 2024 Program Expenditures: $202,369,164 Questioned Costs: None Criteria: Uniform Grant Guidance (34 CFR 668.166) states the Secretary considers excess cash to be any amount of title IV, HEA program funds, other than Federal Perkins Loan program funds, that an institution does not disburse to students by the end of the third business day following the date the institution (1) received those funds from the Secretary; or (2) deposited or transferred to its depository account previously disbursed title IV, HEA program funds, such as those resulting from awards adjustments, recoveries, or cancellations. An institution may maintain for up to seven days an amount of excess cash that does not exceed one percent of the total amount of funds the institution drew down in the prior award year. The institution must return immediately to the Secretary any amount of excess cash over the one-percent tolerance and any amount of excess cash remaining in its account after the seven-day tolerance period. Uniform Grant Guidance (2 CFR 200.303) requires nonfederal entities receiving Federal awards establish and maintain internal controls designed to reasonably ensure compliance with Federal laws, regulations, and program compliance requirements. Effective internal controls should include procedures to ensure excess cash is properly handled. Condition: The Chicago School (the College) had one instance of excess cash for the Federal Direct Student Loan program. During our cash management testing, we identified the College had excess cash for the Direct Loan program ranging from $528,450 to $1,238,306 for the period from November 13, 2023 to December 18, 2023. For that period, the excess cash did not exceed one percent of total prior year drawdowns; however, amounts were not returned with a seven-day period. Cause: College officials stated the excess cash resulted from the College’s practice of drawing a portion of funds to ensure timely disbursement of stipend payments to students while the reconciliation of awards was still in progress. While this approach aligns with the College’s commitment to promptly provide financial support, an administrative oversight occurred during the reconciliation process. Specifically, the College did not net out the prior drawdown for stipends when calculating subsequent fund requests. Effect: Excess cash is noncompliance with Federal regulations and could result in heightened monitoring by the U.S. Department of Education. Questioned Costs: None Context: For the period of November 13, 2023 to December 18, 2023, the College had excess cash in the amount ranging from $528,450 to $1,238,306. The College held excess cash for a period of 24 business days. Repeat Finding: No. Recommendation: We recommend the College strengthen internal controls around cash management to prevent or timely correct excess cash instances. Views of Responsible Officials: Management agrees with the finding. Please see corrective action plan attached.

FY End: 2024-05-31
Norwich University
Compliance Requirement: N
Condition: The University did not properly report student enrollment changes for students who received federal student aid to the National Student Loan Data System (NSLDS). Criteria or specific requirement: Per 2 CFR 200.303, nonfederal entities receiving federal awards are required to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations, and program compliance requirements. Additionally, 34 CFR 685.309, requires that enrollment status...

Condition: The University did not properly report student enrollment changes for students who received federal student aid to the National Student Loan Data System (NSLDS). Criteria or specific requirement: Per 2 CFR 200.303, nonfederal entities receiving federal awards are required to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations, and program compliance requirements. Additionally, 34 CFR 685.309, requires that enrollment status changes for students be reported to NSLDS within 30 days of becoming aware of the status change or in its next scheduled enrollment submission if the scheduled submission is within 60 days. Regulations require the status include an accurate effective date. In addition, regulations require that an institution make necessary corrections and return the records within 10 days for any roster files that don’t pass the NSLDS enrollment reporting edits. Context: During our testing of 40 students, we identified 2 students tested whose enrollment status was either not timely reported, not updated to graduate from withdrawn, not reported with correct enrollment status, not reported with correct effective date, or a combination of the above to NSLDS. Questioned costs: N/A Cause: The University didn't have proper procedures in place to verify the students’ status in NSLDS matched the institutions records in a timely manner. Effect: The University was not in compliance with the requirements to properly report student enrollment data correctly. Incorrect dates submitted to NSLDS may be used to determine the grace period for the repayment of interest of outstanding Title IV student loans. Repeat finding: No Recommendation: We recommend the University review current processes for reporting to NSLDS and implement procedures to ensure submissions are reported timely and accurately. Views of responsible officials: Management agrees with the finding and has developed a plan to correct the finding.

FY End: 2024-05-31
Norwich University
Compliance Requirement: N
Condition: The University did not properly report student enrollment changes for students who received federal student aid to the National Student Loan Data System (NSLDS). Criteria or specific requirement: Per 2 CFR 200.303, nonfederal entities receiving federal awards are required to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations, and program compliance requirements. Additionally, 34 CFR 685.309, requires that enrollment status...

Condition: The University did not properly report student enrollment changes for students who received federal student aid to the National Student Loan Data System (NSLDS). Criteria or specific requirement: Per 2 CFR 200.303, nonfederal entities receiving federal awards are required to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations, and program compliance requirements. Additionally, 34 CFR 685.309, requires that enrollment status changes for students be reported to NSLDS within 30 days of becoming aware of the status change or in its next scheduled enrollment submission if the scheduled submission is within 60 days. Regulations require the status include an accurate effective date. In addition, regulations require that an institution make necessary corrections and return the records within 10 days for any roster files that don’t pass the NSLDS enrollment reporting edits. Context: During our testing of 40 students, we identified 2 students tested whose enrollment status was either not timely reported, not updated to graduate from withdrawn, not reported with correct enrollment status, not reported with correct effective date, or a combination of the above to NSLDS. Questioned costs: N/A Cause: The University didn't have proper procedures in place to verify the students’ status in NSLDS matched the institutions records in a timely manner. Effect: The University was not in compliance with the requirements to properly report student enrollment data correctly. Incorrect dates submitted to NSLDS may be used to determine the grace period for the repayment of interest of outstanding Title IV student loans. Repeat finding: No Recommendation: We recommend the University review current processes for reporting to NSLDS and implement procedures to ensure submissions are reported timely and accurately. Views of responsible officials: Management agrees with the finding and has developed a plan to correct the finding.

FY End: 2024-05-31
Norwich University
Compliance Requirement: N
Condition: The University did not properly report student enrollment changes for students who received federal student aid to the National Student Loan Data System (NSLDS). Criteria or specific requirement: Per 2 CFR 200.303, nonfederal entities receiving federal awards are required to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations, and program compliance requirements. Additionally, 34 CFR 685.309, requires that enrollment status...

Condition: The University did not properly report student enrollment changes for students who received federal student aid to the National Student Loan Data System (NSLDS). Criteria or specific requirement: Per 2 CFR 200.303, nonfederal entities receiving federal awards are required to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations, and program compliance requirements. Additionally, 34 CFR 685.309, requires that enrollment status changes for students be reported to NSLDS within 30 days of becoming aware of the status change or in its next scheduled enrollment submission if the scheduled submission is within 60 days. Regulations require the status include an accurate effective date. In addition, regulations require that an institution make necessary corrections and return the records within 10 days for any roster files that don’t pass the NSLDS enrollment reporting edits. Context: During our testing of 40 students, we identified 2 students tested whose enrollment status was either not timely reported, not updated to graduate from withdrawn, not reported with correct enrollment status, not reported with correct effective date, or a combination of the above to NSLDS. Questioned costs: N/A Cause: The University didn't have proper procedures in place to verify the students’ status in NSLDS matched the institutions records in a timely manner. Effect: The University was not in compliance with the requirements to properly report student enrollment data correctly. Incorrect dates submitted to NSLDS may be used to determine the grace period for the repayment of interest of outstanding Title IV student loans. Repeat finding: No Recommendation: We recommend the University review current processes for reporting to NSLDS and implement procedures to ensure submissions are reported timely and accurately. Views of responsible officials: Management agrees with the finding and has developed a plan to correct the finding.

FY End: 2024-05-31
Norwich University
Compliance Requirement: N
Condition: The University did not properly report student enrollment changes for students who received federal student aid to the National Student Loan Data System (NSLDS). Criteria or specific requirement: Per 2 CFR 200.303, nonfederal entities receiving federal awards are required to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations, and program compliance requirements. Additionally, 34 CFR 685.309, requires that enrollment status...

Condition: The University did not properly report student enrollment changes for students who received federal student aid to the National Student Loan Data System (NSLDS). Criteria or specific requirement: Per 2 CFR 200.303, nonfederal entities receiving federal awards are required to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations, and program compliance requirements. Additionally, 34 CFR 685.309, requires that enrollment status changes for students be reported to NSLDS within 30 days of becoming aware of the status change or in its next scheduled enrollment submission if the scheduled submission is within 60 days. Regulations require the status include an accurate effective date. In addition, regulations require that an institution make necessary corrections and return the records within 10 days for any roster files that don’t pass the NSLDS enrollment reporting edits. Context: During our testing of 40 students, we identified 2 students tested whose enrollment status was either not timely reported, not updated to graduate from withdrawn, not reported with correct enrollment status, not reported with correct effective date, or a combination of the above to NSLDS. Questioned costs: N/A Cause: The University didn't have proper procedures in place to verify the students’ status in NSLDS matched the institutions records in a timely manner. Effect: The University was not in compliance with the requirements to properly report student enrollment data correctly. Incorrect dates submitted to NSLDS may be used to determine the grace period for the repayment of interest of outstanding Title IV student loans. Repeat finding: No Recommendation: We recommend the University review current processes for reporting to NSLDS and implement procedures to ensure submissions are reported timely and accurately. Views of responsible officials: Management agrees with the finding and has developed a plan to correct the finding.

FY End: 2024-05-31
University of Dubuque
Compliance Requirement: N
U.S. Department of Education Student Financial Assistance Programs Cluster (Direct) Federal Direct Loan Program (84.268) Federal Award Year: 2023-2024 Finding: The University did not timely or accurately report enrollment changes to the National Student Loan Data System (NSLDS). Criteria: Per 34 CFR 685.309(b), a school shall - (1) Upon receipt of an enrollment report from the Secretary, update all information included in the report and return the report to the Secretary in the manner and form...

U.S. Department of Education Student Financial Assistance Programs Cluster (Direct) Federal Direct Loan Program (84.268) Federal Award Year: 2023-2024 Finding: The University did not timely or accurately report enrollment changes to the National Student Loan Data System (NSLDS). Criteria: Per 34 CFR 685.309(b), a school shall - (1) Upon receipt of an enrollment report from the Secretary, update all information included in the report and return the report to the Secretary in the manner and format prescribed by the Secretary; and within the timeframe prescribed by the Secretary; and (2) Unless it expects to submit its next student updated enrollment report to the Secretary within the next 60 days, a school must notify the Secretary within 30 days if it discovers that a loan under Title IV of the Act was made to, or on behalf of, a student who was enrolled on at least a half-time basis or failed to enroll on at least a half-time basis for the period for which the loan was intended. Per 34 CFR 668.22(c)(ii), the withdrawal date is the date, as determined by the institution, that the student otherwise provided official notification to the institution, in writing or orally, of his or her intent to withdraw. Uniform Grant Guidance (2 CFR 200.303) requires nonfederal entities receiving Federal awards establish and maintain internal controls designed to reasonably ensure compliance with Federal laws, regulations and program compliance requirements. Effective internal controls should include procedures to ensure enrollment reporting is completed properly. Condition: 12 students were not reported as withdrawn within the 60 day timeframe for University’s reporting on the roster file submissions and the internal controls in place did not identify the errors. Cause: Student reporting was not within the 60 day roster submission timeframe. Effect: Noncompliance with federal regulations for enrollment reporting. Questioned costs: None. Context: 12 of the 25 students selected haphazardly and tested were not reported in accordance with NSLDS enrollment reporting and were within a range of five to six days late. Repeat finding: Yes. Recommendation: The University should accurately report all student status changes to the NSLDS. In addition, the University should review its policies and procedures to ensure withdrawal dates are accurately reflected in the enrollment management system and enrollment changes are reported timely. Views of responsible officials: Management agrees with this finding. See corrective action plan.

FY End: 2024-05-31
University of Dubuque
Compliance Requirement: N
U.S. Department of Education Student Financial Assistance Programs Cluster (Direct) Federal Direct Loan Program (84.268) Federal Award Year: 2023-2024 Finding: The University’s R2T4 calculation was improper for one student, as the student had not signed a promissory note for the direct loans and the direct loans should have not been included in the calculation. Criteria: Per 34 CFR 668.164, Any undisbursed Title IV aid for the period that the school uses as the basis for the R2T4 calculation i...

U.S. Department of Education Student Financial Assistance Programs Cluster (Direct) Federal Direct Loan Program (84.268) Federal Award Year: 2023-2024 Finding: The University’s R2T4 calculation was improper for one student, as the student had not signed a promissory note for the direct loans and the direct loans should have not been included in the calculation. Criteria: Per 34 CFR 668.164, Any undisbursed Title IV aid for the period that the school uses as the basis for the R2T4 calculation is counted as aid that could have been disbursed as long as the following conditions were met before the date the student became ineligible: For all programs, the Department processed a Student Aid Report (SAR) or Institutional Student Information Record (ISIR) with an official expected family contribution (EFC) for the student. (An official EFC is one calculated by the Department and provided on a SAR or ISIR. It may or may not be a valid EFC, which is one based on complete and correct information.) In all Title IV loan programs, a promissory note must be signed for a loan to be included as aid that could have been disbursed in an R2T4 calculation. The signature may be obtained after the student withdraws but must be signed before the school performs the R2T4 calculation. In addition, if a school has an affirmative confirmation process set up to actively determine if a student wants a Direct Loan, if the student declines or fails to respond to the request, the Direct Loan would not be included as aid that could have been disbursed. Uniform Grant Guidance (2 CFR 200.303) requires nonfederal entities receiving Federal awards establish and maintain internal controls designed to reasonably ensure compliance with Federal laws, regulations and program compliance requirements. Effective internal controls should include procedures to ensure enrollment reporting is completed properly. Condition: One student did not sign a promissory note for direct loans that were included in the R2T4 calculation; therefore, the University’s R2T4 calculation was improperly calculated and the internal controls in place did not identify the errors. Cause: Student did not sign a promissory note for direct loans. Effect: Noncompliance with federal regulations for R2T4 Questioned costs: Amount refunded was underpaid by $79. Context: One of the eight students selected randomly and tested did not sign a promissory note for direct loans that were included in the R2T4 calculation; therefore, the University’s R2T4 calculation was improperly calculated. Repeat finding: This is not a repeat finding. Recommendation: The University should review the controls and procedures in place to verify that only aid with signed promissory notes are being included in R2T4 calculations. Views of responsible officials: Management agrees with this finding. See corrective action plan.

FY End: 2024-05-31
University of Dubuque
Compliance Requirement: N
U.S. Department of Education Student Financial Assistance Programs Cluster Gramm-Leach Bliley Act – Student Information Security (84.007, 84.268, 84.038, 84.063, 84.378) Federal Award Year: 2023-2024 Finding: The University created and implemented a comprehensive information security policy, but did not have it done in a timely manner. Criteria: 2 CFR 200.303(a) requires that the non-Federal entity must establish and maintain effective internal control over the Federal award that provides reas...

U.S. Department of Education Student Financial Assistance Programs Cluster Gramm-Leach Bliley Act – Student Information Security (84.007, 84.268, 84.038, 84.063, 84.378) Federal Award Year: 2023-2024 Finding: The University created and implemented a comprehensive information security policy, but did not have it done in a timely manner. Criteria: 2 CFR 200.303(a) requires that the non-Federal entity must establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in Standards for Internal Control in the Federal Government issued by the Comptroller General of the United States or the Internal Control Integrated Framework, issued by the Committee of Sponsoring Organizations of the Treadway Commission. The Program Participation Agreement (PPA) with the U.S. Department of Education requires the institution to comply with the Standards for Safeguarding Customer Information as described in 16 CFR Part 314 which includes the development of a comprehensive written security program that includes the following parts: 16 CFR 314.4(a) requires institutions to designate a qualified individual responsible for overseeing and implementing the institution’s information security program and enforcing the information security program. 16 CFR 314.4(b) requires institutions to provide for the information security program to be based on a risk assessment that identifies reasonably foreseeable internal and external risks to the security, confidentiality and integrity of customer information (as the term customer information applies to the institution) that could result in the unauthorized disclosure, misuse, alteration, destruction or other compromise of such information, and assesses the sufficiency of any safeguards in place to control these risks. 16 CFR 314.4(c) requires institutions to provide for the design and implementation of safeguards to control the risks the institution provides through its risk assessment. 16 CFR 314.4(d) requires institutions to regularly test or otherwise monitor the effectiveness of the safeguards it has implemented 16 CFR 314.4(e) requires institutions to develop policies and procedures to ensure that personnel are able to enact the information security program. 16 CFR 314.4(f) requires institutions to develop policies and procedures to oversee its information system service providers. Condition: The institution’s written information security program was not done in a timely manner to include the following elements required by regulation as agreed to in the PPA: The written information security program does not designate an individual responsible for overseeing and implementing the institution’s information security program or enforcing the information security program. The institution has performed a risk assessment utilizing internal resources but has not based the information security program on the results of this assessment, nor has the institution included all required elements of internal and external risks to the security, confidentiality or integrity of customer information. The institution’s risk assessment is missing an inventory of IT systems that process and store customer information and the compliance with information security elements related to multifactor authentication, access control, change management, logging and alerting and encryption. The institution has not identified, designed or implemented safeguards for all of the risks identified in the risk assessment. The safeguards do not include the identification of security events or detection and response capabilities to support incident response. The institution has not been able to test safeguards because safeguards have not been designed or implemented in response to the risk assessment. The institution has not developed written policies and procedures to ensure that personnel are able to enact the information security program. There is a lack of evidence of leadership being required to report to the board or an appropriate supervisory council to ensure those charged with governance are informed on the current state of the information security program. The institution has not developed policies and procedures to oversee information service providers. Cause: The institution did not create and implement a comprehensive information security policy in a timely manner. Effect: The institution did not create and implement a comprehensive information security policy in a timely manner. The absence of internal controls and policies and procedures could result in the unauthorized disclosure, misuse, alteration, destruction or other compromise of student account information. Questioned costs: None. Context: Under an institution’s PPA with the U.S. Department of Education, schools must protect student financial aid information, with particular attention to information provided to institutions by the U.S. Department of Education or otherwise obtained in support of the administration of federal student financial aid programs. Repeat finding: This is not a repeat finding. Recommendation: We recommend that the University completes these requirements in a timely manner in the future. Views of responsible officials: Management agrees with this finding. See corrective action plan.

FY End: 2024-05-31
University of Dubuque
Compliance Requirement: N
U.S. Department of Education Student Financial Assistance Programs Cluster Gramm-Leach Bliley Act – Student Information Security (84.007, 84.268, 84.038, 84.063, 84.378) Federal Award Year: 2023-2024 Finding: The University created and implemented a comprehensive information security policy, but did not have it done in a timely manner. Criteria: 2 CFR 200.303(a) requires that the non-Federal entity must establish and maintain effective internal control over the Federal award that provides reas...

U.S. Department of Education Student Financial Assistance Programs Cluster Gramm-Leach Bliley Act – Student Information Security (84.007, 84.268, 84.038, 84.063, 84.378) Federal Award Year: 2023-2024 Finding: The University created and implemented a comprehensive information security policy, but did not have it done in a timely manner. Criteria: 2 CFR 200.303(a) requires that the non-Federal entity must establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in Standards for Internal Control in the Federal Government issued by the Comptroller General of the United States or the Internal Control Integrated Framework, issued by the Committee of Sponsoring Organizations of the Treadway Commission. The Program Participation Agreement (PPA) with the U.S. Department of Education requires the institution to comply with the Standards for Safeguarding Customer Information as described in 16 CFR Part 314 which includes the development of a comprehensive written security program that includes the following parts: 16 CFR 314.4(a) requires institutions to designate a qualified individual responsible for overseeing and implementing the institution’s information security program and enforcing the information security program. 16 CFR 314.4(b) requires institutions to provide for the information security program to be based on a risk assessment that identifies reasonably foreseeable internal and external risks to the security, confidentiality and integrity of customer information (as the term customer information applies to the institution) that could result in the unauthorized disclosure, misuse, alteration, destruction or other compromise of such information, and assesses the sufficiency of any safeguards in place to control these risks. 16 CFR 314.4(c) requires institutions to provide for the design and implementation of safeguards to control the risks the institution provides through its risk assessment. 16 CFR 314.4(d) requires institutions to regularly test or otherwise monitor the effectiveness of the safeguards it has implemented 16 CFR 314.4(e) requires institutions to develop policies and procedures to ensure that personnel are able to enact the information security program. 16 CFR 314.4(f) requires institutions to develop policies and procedures to oversee its information system service providers. Condition: The institution’s written information security program was not done in a timely manner to include the following elements required by regulation as agreed to in the PPA: The written information security program does not designate an individual responsible for overseeing and implementing the institution’s information security program or enforcing the information security program. The institution has performed a risk assessment utilizing internal resources but has not based the information security program on the results of this assessment, nor has the institution included all required elements of internal and external risks to the security, confidentiality or integrity of customer information. The institution’s risk assessment is missing an inventory of IT systems that process and store customer information and the compliance with information security elements related to multifactor authentication, access control, change management, logging and alerting and encryption. The institution has not identified, designed or implemented safeguards for all of the risks identified in the risk assessment. The safeguards do not include the identification of security events or detection and response capabilities to support incident response. The institution has not been able to test safeguards because safeguards have not been designed or implemented in response to the risk assessment. The institution has not developed written policies and procedures to ensure that personnel are able to enact the information security program. There is a lack of evidence of leadership being required to report to the board or an appropriate supervisory council to ensure those charged with governance are informed on the current state of the information security program. The institution has not developed policies and procedures to oversee information service providers. Cause: The institution did not create and implement a comprehensive information security policy in a timely manner. Effect: The institution did not create and implement a comprehensive information security policy in a timely manner. The absence of internal controls and policies and procedures could result in the unauthorized disclosure, misuse, alteration, destruction or other compromise of student account information. Questioned costs: None. Context: Under an institution’s PPA with the U.S. Department of Education, schools must protect student financial aid information, with particular attention to information provided to institutions by the U.S. Department of Education or otherwise obtained in support of the administration of federal student financial aid programs. Repeat finding: This is not a repeat finding. Recommendation: We recommend that the University completes these requirements in a timely manner in the future. Views of responsible officials: Management agrees with this finding. See corrective action plan.

FY End: 2024-05-31
University of Dubuque
Compliance Requirement: N
U.S. Department of Education Student Financial Assistance Programs Cluster Gramm-Leach Bliley Act – Student Information Security (84.007, 84.268, 84.038, 84.063, 84.378) Federal Award Year: 2023-2024 Finding: The University created and implemented a comprehensive information security policy, but did not have it done in a timely manner. Criteria: 2 CFR 200.303(a) requires that the non-Federal entity must establish and maintain effective internal control over the Federal award that provides reas...

U.S. Department of Education Student Financial Assistance Programs Cluster Gramm-Leach Bliley Act – Student Information Security (84.007, 84.268, 84.038, 84.063, 84.378) Federal Award Year: 2023-2024 Finding: The University created and implemented a comprehensive information security policy, but did not have it done in a timely manner. Criteria: 2 CFR 200.303(a) requires that the non-Federal entity must establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in Standards for Internal Control in the Federal Government issued by the Comptroller General of the United States or the Internal Control Integrated Framework, issued by the Committee of Sponsoring Organizations of the Treadway Commission. The Program Participation Agreement (PPA) with the U.S. Department of Education requires the institution to comply with the Standards for Safeguarding Customer Information as described in 16 CFR Part 314 which includes the development of a comprehensive written security program that includes the following parts: 16 CFR 314.4(a) requires institutions to designate a qualified individual responsible for overseeing and implementing the institution’s information security program and enforcing the information security program. 16 CFR 314.4(b) requires institutions to provide for the information security program to be based on a risk assessment that identifies reasonably foreseeable internal and external risks to the security, confidentiality and integrity of customer information (as the term customer information applies to the institution) that could result in the unauthorized disclosure, misuse, alteration, destruction or other compromise of such information, and assesses the sufficiency of any safeguards in place to control these risks. 16 CFR 314.4(c) requires institutions to provide for the design and implementation of safeguards to control the risks the institution provides through its risk assessment. 16 CFR 314.4(d) requires institutions to regularly test or otherwise monitor the effectiveness of the safeguards it has implemented 16 CFR 314.4(e) requires institutions to develop policies and procedures to ensure that personnel are able to enact the information security program. 16 CFR 314.4(f) requires institutions to develop policies and procedures to oversee its information system service providers. Condition: The institution’s written information security program was not done in a timely manner to include the following elements required by regulation as agreed to in the PPA: The written information security program does not designate an individual responsible for overseeing and implementing the institution’s information security program or enforcing the information security program. The institution has performed a risk assessment utilizing internal resources but has not based the information security program on the results of this assessment, nor has the institution included all required elements of internal and external risks to the security, confidentiality or integrity of customer information. The institution’s risk assessment is missing an inventory of IT systems that process and store customer information and the compliance with information security elements related to multifactor authentication, access control, change management, logging and alerting and encryption. The institution has not identified, designed or implemented safeguards for all of the risks identified in the risk assessment. The safeguards do not include the identification of security events or detection and response capabilities to support incident response. The institution has not been able to test safeguards because safeguards have not been designed or implemented in response to the risk assessment. The institution has not developed written policies and procedures to ensure that personnel are able to enact the information security program. There is a lack of evidence of leadership being required to report to the board or an appropriate supervisory council to ensure those charged with governance are informed on the current state of the information security program. The institution has not developed policies and procedures to oversee information service providers. Cause: The institution did not create and implement a comprehensive information security policy in a timely manner. Effect: The institution did not create and implement a comprehensive information security policy in a timely manner. The absence of internal controls and policies and procedures could result in the unauthorized disclosure, misuse, alteration, destruction or other compromise of student account information. Questioned costs: None. Context: Under an institution’s PPA with the U.S. Department of Education, schools must protect student financial aid information, with particular attention to information provided to institutions by the U.S. Department of Education or otherwise obtained in support of the administration of federal student financial aid programs. Repeat finding: This is not a repeat finding. Recommendation: We recommend that the University completes these requirements in a timely manner in the future. Views of responsible officials: Management agrees with this finding. See corrective action plan.

FY End: 2024-05-31
University of Dubuque
Compliance Requirement: N
U.S. Department of Education Student Financial Assistance Programs Cluster Gramm-Leach Bliley Act – Student Information Security (84.007, 84.268, 84.038, 84.063, 84.378) Federal Award Year: 2023-2024 Finding: The University created and implemented a comprehensive information security policy, but did not have it done in a timely manner. Criteria: 2 CFR 200.303(a) requires that the non-Federal entity must establish and maintain effective internal control over the Federal award that provides reas...

U.S. Department of Education Student Financial Assistance Programs Cluster Gramm-Leach Bliley Act – Student Information Security (84.007, 84.268, 84.038, 84.063, 84.378) Federal Award Year: 2023-2024 Finding: The University created and implemented a comprehensive information security policy, but did not have it done in a timely manner. Criteria: 2 CFR 200.303(a) requires that the non-Federal entity must establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in Standards for Internal Control in the Federal Government issued by the Comptroller General of the United States or the Internal Control Integrated Framework, issued by the Committee of Sponsoring Organizations of the Treadway Commission. The Program Participation Agreement (PPA) with the U.S. Department of Education requires the institution to comply with the Standards for Safeguarding Customer Information as described in 16 CFR Part 314 which includes the development of a comprehensive written security program that includes the following parts: 16 CFR 314.4(a) requires institutions to designate a qualified individual responsible for overseeing and implementing the institution’s information security program and enforcing the information security program. 16 CFR 314.4(b) requires institutions to provide for the information security program to be based on a risk assessment that identifies reasonably foreseeable internal and external risks to the security, confidentiality and integrity of customer information (as the term customer information applies to the institution) that could result in the unauthorized disclosure, misuse, alteration, destruction or other compromise of such information, and assesses the sufficiency of any safeguards in place to control these risks. 16 CFR 314.4(c) requires institutions to provide for the design and implementation of safeguards to control the risks the institution provides through its risk assessment. 16 CFR 314.4(d) requires institutions to regularly test or otherwise monitor the effectiveness of the safeguards it has implemented 16 CFR 314.4(e) requires institutions to develop policies and procedures to ensure that personnel are able to enact the information security program. 16 CFR 314.4(f) requires institutions to develop policies and procedures to oversee its information system service providers. Condition: The institution’s written information security program was not done in a timely manner to include the following elements required by regulation as agreed to in the PPA: The written information security program does not designate an individual responsible for overseeing and implementing the institution’s information security program or enforcing the information security program. The institution has performed a risk assessment utilizing internal resources but has not based the information security program on the results of this assessment, nor has the institution included all required elements of internal and external risks to the security, confidentiality or integrity of customer information. The institution’s risk assessment is missing an inventory of IT systems that process and store customer information and the compliance with information security elements related to multifactor authentication, access control, change management, logging and alerting and encryption. The institution has not identified, designed or implemented safeguards for all of the risks identified in the risk assessment. The safeguards do not include the identification of security events or detection and response capabilities to support incident response. The institution has not been able to test safeguards because safeguards have not been designed or implemented in response to the risk assessment. The institution has not developed written policies and procedures to ensure that personnel are able to enact the information security program. There is a lack of evidence of leadership being required to report to the board or an appropriate supervisory council to ensure those charged with governance are informed on the current state of the information security program. The institution has not developed policies and procedures to oversee information service providers. Cause: The institution did not create and implement a comprehensive information security policy in a timely manner. Effect: The institution did not create and implement a comprehensive information security policy in a timely manner. The absence of internal controls and policies and procedures could result in the unauthorized disclosure, misuse, alteration, destruction or other compromise of student account information. Questioned costs: None. Context: Under an institution’s PPA with the U.S. Department of Education, schools must protect student financial aid information, with particular attention to information provided to institutions by the U.S. Department of Education or otherwise obtained in support of the administration of federal student financial aid programs. Repeat finding: This is not a repeat finding. Recommendation: We recommend that the University completes these requirements in a timely manner in the future. Views of responsible officials: Management agrees with this finding. See corrective action plan.

FY End: 2024-05-31
University of Dubuque
Compliance Requirement: N
U.S. Department of Education Student Financial Assistance Programs Cluster Gramm-Leach Bliley Act – Student Information Security (84.007, 84.268, 84.038, 84.063, 84.378) Federal Award Year: 2023-2024 Finding: The University created and implemented a comprehensive information security policy, but did not have it done in a timely manner. Criteria: 2 CFR 200.303(a) requires that the non-Federal entity must establish and maintain effective internal control over the Federal award that provides reas...

U.S. Department of Education Student Financial Assistance Programs Cluster Gramm-Leach Bliley Act – Student Information Security (84.007, 84.268, 84.038, 84.063, 84.378) Federal Award Year: 2023-2024 Finding: The University created and implemented a comprehensive information security policy, but did not have it done in a timely manner. Criteria: 2 CFR 200.303(a) requires that the non-Federal entity must establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in Standards for Internal Control in the Federal Government issued by the Comptroller General of the United States or the Internal Control Integrated Framework, issued by the Committee of Sponsoring Organizations of the Treadway Commission. The Program Participation Agreement (PPA) with the U.S. Department of Education requires the institution to comply with the Standards for Safeguarding Customer Information as described in 16 CFR Part 314 which includes the development of a comprehensive written security program that includes the following parts: 16 CFR 314.4(a) requires institutions to designate a qualified individual responsible for overseeing and implementing the institution’s information security program and enforcing the information security program. 16 CFR 314.4(b) requires institutions to provide for the information security program to be based on a risk assessment that identifies reasonably foreseeable internal and external risks to the security, confidentiality and integrity of customer information (as the term customer information applies to the institution) that could result in the unauthorized disclosure, misuse, alteration, destruction or other compromise of such information, and assesses the sufficiency of any safeguards in place to control these risks. 16 CFR 314.4(c) requires institutions to provide for the design and implementation of safeguards to control the risks the institution provides through its risk assessment. 16 CFR 314.4(d) requires institutions to regularly test or otherwise monitor the effectiveness of the safeguards it has implemented 16 CFR 314.4(e) requires institutions to develop policies and procedures to ensure that personnel are able to enact the information security program. 16 CFR 314.4(f) requires institutions to develop policies and procedures to oversee its information system service providers. Condition: The institution’s written information security program was not done in a timely manner to include the following elements required by regulation as agreed to in the PPA: The written information security program does not designate an individual responsible for overseeing and implementing the institution’s information security program or enforcing the information security program. The institution has performed a risk assessment utilizing internal resources but has not based the information security program on the results of this assessment, nor has the institution included all required elements of internal and external risks to the security, confidentiality or integrity of customer information. The institution’s risk assessment is missing an inventory of IT systems that process and store customer information and the compliance with information security elements related to multifactor authentication, access control, change management, logging and alerting and encryption. The institution has not identified, designed or implemented safeguards for all of the risks identified in the risk assessment. The safeguards do not include the identification of security events or detection and response capabilities to support incident response. The institution has not been able to test safeguards because safeguards have not been designed or implemented in response to the risk assessment. The institution has not developed written policies and procedures to ensure that personnel are able to enact the information security program. There is a lack of evidence of leadership being required to report to the board or an appropriate supervisory council to ensure those charged with governance are informed on the current state of the information security program. The institution has not developed policies and procedures to oversee information service providers. Cause: The institution did not create and implement a comprehensive information security policy in a timely manner. Effect: The institution did not create and implement a comprehensive information security policy in a timely manner. The absence of internal controls and policies and procedures could result in the unauthorized disclosure, misuse, alteration, destruction or other compromise of student account information. Questioned costs: None. Context: Under an institution’s PPA with the U.S. Department of Education, schools must protect student financial aid information, with particular attention to information provided to institutions by the U.S. Department of Education or otherwise obtained in support of the administration of federal student financial aid programs. Repeat finding: This is not a repeat finding. Recommendation: We recommend that the University completes these requirements in a timely manner in the future. Views of responsible officials: Management agrees with this finding. See corrective action plan.

FY End: 2024-05-31
University of Dubuque
Compliance Requirement: N
U.S. Department of Education Student Financial Assistance Programs Cluster Gramm-Leach Bliley Act – Student Information Security (84.007, 84.268, 84.038, 84.063, 84.378) Federal Award Year: 2023-2024 Finding: The University created and implemented a comprehensive information security policy, but did not have it done in a timely manner. Criteria: 2 CFR 200.303(a) requires that the non-Federal entity must establish and maintain effective internal control over the Federal award that provides reas...

U.S. Department of Education Student Financial Assistance Programs Cluster Gramm-Leach Bliley Act – Student Information Security (84.007, 84.268, 84.038, 84.063, 84.378) Federal Award Year: 2023-2024 Finding: The University created and implemented a comprehensive information security policy, but did not have it done in a timely manner. Criteria: 2 CFR 200.303(a) requires that the non-Federal entity must establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in Standards for Internal Control in the Federal Government issued by the Comptroller General of the United States or the Internal Control Integrated Framework, issued by the Committee of Sponsoring Organizations of the Treadway Commission. The Program Participation Agreement (PPA) with the U.S. Department of Education requires the institution to comply with the Standards for Safeguarding Customer Information as described in 16 CFR Part 314 which includes the development of a comprehensive written security program that includes the following parts: 16 CFR 314.4(a) requires institutions to designate a qualified individual responsible for overseeing and implementing the institution’s information security program and enforcing the information security program. 16 CFR 314.4(b) requires institutions to provide for the information security program to be based on a risk assessment that identifies reasonably foreseeable internal and external risks to the security, confidentiality and integrity of customer information (as the term customer information applies to the institution) that could result in the unauthorized disclosure, misuse, alteration, destruction or other compromise of such information, and assesses the sufficiency of any safeguards in place to control these risks. 16 CFR 314.4(c) requires institutions to provide for the design and implementation of safeguards to control the risks the institution provides through its risk assessment. 16 CFR 314.4(d) requires institutions to regularly test or otherwise monitor the effectiveness of the safeguards it has implemented 16 CFR 314.4(e) requires institutions to develop policies and procedures to ensure that personnel are able to enact the information security program. 16 CFR 314.4(f) requires institutions to develop policies and procedures to oversee its information system service providers. Condition: The institution’s written information security program was not done in a timely manner to include the following elements required by regulation as agreed to in the PPA: The written information security program does not designate an individual responsible for overseeing and implementing the institution’s information security program or enforcing the information security program. The institution has performed a risk assessment utilizing internal resources but has not based the information security program on the results of this assessment, nor has the institution included all required elements of internal and external risks to the security, confidentiality or integrity of customer information. The institution’s risk assessment is missing an inventory of IT systems that process and store customer information and the compliance with information security elements related to multifactor authentication, access control, change management, logging and alerting and encryption. The institution has not identified, designed or implemented safeguards for all of the risks identified in the risk assessment. The safeguards do not include the identification of security events or detection and response capabilities to support incident response. The institution has not been able to test safeguards because safeguards have not been designed or implemented in response to the risk assessment. The institution has not developed written policies and procedures to ensure that personnel are able to enact the information security program. There is a lack of evidence of leadership being required to report to the board or an appropriate supervisory council to ensure those charged with governance are informed on the current state of the information security program. The institution has not developed policies and procedures to oversee information service providers. Cause: The institution did not create and implement a comprehensive information security policy in a timely manner. Effect: The institution did not create and implement a comprehensive information security policy in a timely manner. The absence of internal controls and policies and procedures could result in the unauthorized disclosure, misuse, alteration, destruction or other compromise of student account information. Questioned costs: None. Context: Under an institution’s PPA with the U.S. Department of Education, schools must protect student financial aid information, with particular attention to information provided to institutions by the U.S. Department of Education or otherwise obtained in support of the administration of federal student financial aid programs. Repeat finding: This is not a repeat finding. Recommendation: We recommend that the University completes these requirements in a timely manner in the future. Views of responsible officials: Management agrees with this finding. See corrective action plan.

FY End: 2024-05-31
Minneapolis College of Art and Design
Compliance Requirement: ACELN
Federal Agency: Department of Education Federal Program Title: Student Financial Assistance Cluster ALN Numbers: Various Award Period: June 1, 2023 through May 31, 2024 Type of Finding: • Significant Deficiency in Internal Control Over Compliance • Other Matters Criteria or Specific Requirement: The 2 CFR Section 200.303 requires that nonfederal entities receiving federal awards establish and maintain internal controls designed to reasonably ensure compliance with Federal Statues, regulations, ...

Federal Agency: Department of Education Federal Program Title: Student Financial Assistance Cluster ALN Numbers: Various Award Period: June 1, 2023 through May 31, 2024 Type of Finding: • Significant Deficiency in Internal Control Over Compliance • Other Matters Criteria or Specific Requirement: The 2 CFR Section 200.303 requires that nonfederal entities receiving federal awards establish and maintain internal controls designed to reasonably ensure compliance with Federal Statues, regulations, and the term and conditions of the federal awards. Condition: During our testing of Return of Title IV Funds (R2T4), federal loan reconciliations, and award packaging, we noted there was not a review process implemented. Questioned Costs: None. Context: During our testing, it was noted the College does not have a process in place to ensure controls are being performed effectively. Cause: The College did not have a process in place to ensure controls implemented are being performed effectively Effect: There is no way to determine who was involved in the process should an error be present. Repeat Finding: No Recommendation: We recommend the College reevaluate its procedures and review policies surrounding controls implemented for Title IV Aid. Views of Responsible Officials: There is no disagreement with the audit finding.

FY End: 2024-05-31
Minneapolis College of Art and Design
Compliance Requirement: ACELN
Federal Agency: Department of Education Federal Program Title: Student Financial Assistance Cluster ALN Numbers: Various Award Period: June 1, 2023 through May 31, 2024 Type of Finding: • Significant Deficiency in Internal Control Over Compliance • Other Matters Criteria or Specific Requirement: The 2 CFR Section 200.303 requires that nonfederal entities receiving federal awards establish and maintain internal controls designed to reasonably ensure compliance with Federal Statues, regulations, ...

Federal Agency: Department of Education Federal Program Title: Student Financial Assistance Cluster ALN Numbers: Various Award Period: June 1, 2023 through May 31, 2024 Type of Finding: • Significant Deficiency in Internal Control Over Compliance • Other Matters Criteria or Specific Requirement: The 2 CFR Section 200.303 requires that nonfederal entities receiving federal awards establish and maintain internal controls designed to reasonably ensure compliance with Federal Statues, regulations, and the term and conditions of the federal awards. Condition: During our testing of Return of Title IV Funds (R2T4), federal loan reconciliations, and award packaging, we noted there was not a review process implemented. Questioned Costs: None. Context: During our testing, it was noted the College does not have a process in place to ensure controls are being performed effectively. Cause: The College did not have a process in place to ensure controls implemented are being performed effectively Effect: There is no way to determine who was involved in the process should an error be present. Repeat Finding: No Recommendation: We recommend the College reevaluate its procedures and review policies surrounding controls implemented for Title IV Aid. Views of Responsible Officials: There is no disagreement with the audit finding.

FY End: 2024-05-31
Minneapolis College of Art and Design
Compliance Requirement: ACELN
Federal Agency: Department of Education Federal Program Title: Student Financial Assistance Cluster ALN Numbers: Various Award Period: June 1, 2023 through May 31, 2024 Type of Finding: • Significant Deficiency in Internal Control Over Compliance • Other Matters Criteria or Specific Requirement: The 2 CFR Section 200.303 requires that nonfederal entities receiving federal awards establish and maintain internal controls designed to reasonably ensure compliance with Federal Statues, regulations, ...

Federal Agency: Department of Education Federal Program Title: Student Financial Assistance Cluster ALN Numbers: Various Award Period: June 1, 2023 through May 31, 2024 Type of Finding: • Significant Deficiency in Internal Control Over Compliance • Other Matters Criteria or Specific Requirement: The 2 CFR Section 200.303 requires that nonfederal entities receiving federal awards establish and maintain internal controls designed to reasonably ensure compliance with Federal Statues, regulations, and the term and conditions of the federal awards. Condition: During our testing of Return of Title IV Funds (R2T4), federal loan reconciliations, and award packaging, we noted there was not a review process implemented. Questioned Costs: None. Context: During our testing, it was noted the College does not have a process in place to ensure controls are being performed effectively. Cause: The College did not have a process in place to ensure controls implemented are being performed effectively Effect: There is no way to determine who was involved in the process should an error be present. Repeat Finding: No Recommendation: We recommend the College reevaluate its procedures and review policies surrounding controls implemented for Title IV Aid. Views of Responsible Officials: There is no disagreement with the audit finding.

FY End: 2024-05-31
Minneapolis College of Art and Design
Compliance Requirement: ACELN
Federal Agency: Department of Education Federal Program Title: Student Financial Assistance Cluster ALN Numbers: Various Award Period: June 1, 2023 through May 31, 2024 Type of Finding: • Significant Deficiency in Internal Control Over Compliance • Other Matters Criteria or Specific Requirement: The 2 CFR Section 200.303 requires that nonfederal entities receiving federal awards establish and maintain internal controls designed to reasonably ensure compliance with Federal Statues, regulations, ...

Federal Agency: Department of Education Federal Program Title: Student Financial Assistance Cluster ALN Numbers: Various Award Period: June 1, 2023 through May 31, 2024 Type of Finding: • Significant Deficiency in Internal Control Over Compliance • Other Matters Criteria or Specific Requirement: The 2 CFR Section 200.303 requires that nonfederal entities receiving federal awards establish and maintain internal controls designed to reasonably ensure compliance with Federal Statues, regulations, and the term and conditions of the federal awards. Condition: During our testing of Return of Title IV Funds (R2T4), federal loan reconciliations, and award packaging, we noted there was not a review process implemented. Questioned Costs: None. Context: During our testing, it was noted the College does not have a process in place to ensure controls are being performed effectively. Cause: The College did not have a process in place to ensure controls implemented are being performed effectively Effect: There is no way to determine who was involved in the process should an error be present. Repeat Finding: No Recommendation: We recommend the College reevaluate its procedures and review policies surrounding controls implemented for Title IV Aid. Views of Responsible Officials: There is no disagreement with the audit finding.

FY End: 2024-05-31
Minneapolis College of Art and Design
Compliance Requirement: ACELN
Federal Agency: Department of Education Federal Program Title: Student Financial Assistance Cluster ALN Numbers: Various Award Period: June 1, 2023 through May 31, 2024 Type of Finding: • Significant Deficiency in Internal Control Over Compliance • Other Matters Criteria or Specific Requirement: The 2 CFR Section 200.303 requires that nonfederal entities receiving federal awards establish and maintain internal controls designed to reasonably ensure compliance with Federal Statues, regulations, ...

Federal Agency: Department of Education Federal Program Title: Student Financial Assistance Cluster ALN Numbers: Various Award Period: June 1, 2023 through May 31, 2024 Type of Finding: • Significant Deficiency in Internal Control Over Compliance • Other Matters Criteria or Specific Requirement: The 2 CFR Section 200.303 requires that nonfederal entities receiving federal awards establish and maintain internal controls designed to reasonably ensure compliance with Federal Statues, regulations, and the term and conditions of the federal awards. Condition: During our testing of Return of Title IV Funds (R2T4), federal loan reconciliations, and award packaging, we noted there was not a review process implemented. Questioned Costs: None. Context: During our testing, it was noted the College does not have a process in place to ensure controls are being performed effectively. Cause: The College did not have a process in place to ensure controls implemented are being performed effectively Effect: There is no way to determine who was involved in the process should an error be present. Repeat Finding: No Recommendation: We recommend the College reevaluate its procedures and review policies surrounding controls implemented for Title IV Aid. Views of Responsible Officials: There is no disagreement with the audit finding.

FY End: 2024-05-31
Bothwell Regional Health Center
Compliance Requirement: I
U.S. Department of Health and Human Services, passed through the Curators of the University of Missouri ALN 93.680 - Medical Student Education PTE Federal Award No: C00084599-1 Criteria or Specific Requirement: Suspension and Debarment and Significant Deficiency In accordance with 2 CFR 200.214, non-federal entities are prohibited from contracting with or making subawards under covered transactions to parties that are suspended or debarred. “Covered transactions” include contracts for goods and...

U.S. Department of Health and Human Services, passed through the Curators of the University of Missouri ALN 93.680 - Medical Student Education PTE Federal Award No: C00084599-1 Criteria or Specific Requirement: Suspension and Debarment and Significant Deficiency In accordance with 2 CFR 200.214, non-federal entities are prohibited from contracting with or making subawards under covered transactions to parties that are suspended or debarred. “Covered transactions” include contracts for goods and services awarded under a non-procurement transaction (e.g., grant or cooperative agreement) that are expected to equal or exceed $25,000 or meet certain other criteria as specified in 2 CFR Section 180.220. All non-procurement transactions entered into by a pass-through entity (i.e., subawards to subrecipients), irrespective of award amount, are considered covered transactions, unless they are exempt as provided in 2 CFR Section 180.215. Per 2 CFR 200.303, the non-Federal entities receiving federal awards (i.e., auditee management) establish and maintain internal control design to reasonably ensure compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. Condition: Suspension and debarment checks were not completed for the vendors that received federal funds. Cause: Bothwell Regional Health Center did not have suspension and debarment controls in place prior to purchases with the vendors. Effect or Potential Effect: Federal funds could be paid to entities that are suspended or debarred. Questioned Costs: None noted. Context: Only one vendor was subject to the suspension and debarment requirement in 2024 and was selected for testing. The Health Center purchased $961,978 in goods/services from this vendor in 2024. During our testing, we noted the vendor utilized by the Health Center was not evaluated for suspension and debarment. Upon subsequent check, the vendor was not suspended or debarred. Identification of Prior Year Finding: N/A Recommendation: Policies and procedures should be modified to ensure that suspension and debarment checks are performed on vendors and subrecipients alike prior to making purchases with federal funds. When newly established programs include vendors, we also recommend the contracts include suspension and debarment language. View of Responsible Official and Planned Corrective Actions: Management agrees with the finding and management will implement a control process to ensure that suspension and debarment checks are performed on vendors/contracts funded with grants in 2025.

FY End: 2024-05-31
Webber International University, Inc.
Compliance Requirement: N
2024-007 – Preparation of the Schedule of Expenditures of Federal Awards (SEFA) (Significant Deficiency) Department of Education, SFA Cluster, Special Tests and Provisions Criteria: According to 2 CFR 200.210(b), a recipient of Federal awards is required to prepare a SEFA for the period covered by the entity’s financial statement which must include the total Federal awards expended. In addition, 2 CFR 200.303 requires non-Federal entities to, among other things, establish, document, and maintain...

2024-007 – Preparation of the Schedule of Expenditures of Federal Awards (SEFA) (Significant Deficiency) Department of Education, SFA Cluster, Special Tests and Provisions Criteria: According to 2 CFR 200.210(b), a recipient of Federal awards is required to prepare a SEFA for the period covered by the entity’s financial statement which must include the total Federal awards expended. In addition, 2 CFR 200.303 requires non-Federal entities to, among other things, establish, document, and maintain effective internal control over Federal awards that provides reasonable assurance that the non-Federal entity is managing the Federal awards in compliance with Federal statutes, regulations, and the terms and conditions of the Federal awards. Effective internal controls should include procedures to ensure expenditures are properly reported on the SEFA. In addition to providing an accurate SEFA, an organization must also be able to demonstrate that it has a system of internal control that supports the preparation of the SEFA. Condition: The University did not have an adequate process in place to prepare and review its SEFA. Cause: The University’s internal control process for preparing the SEFA did not include review and approval of the SEFA prior to providing it to the auditor. Effect: Failure to accurately report federal expenditures on the SEFA could result in noncompliance with federal regulations. Repeat Finding from a Prior Year: Not a repeat finding. Recommendation: We recommend the University establish, document, and maintain effective internal controls over the preparation of the SEFA. At a minimum, an organization should be able to show documentation that the SEFA was reviewed and approved by an individual who was not directly involved with the initial preparation of the SEFA. The review process should include checking both the reported expenditures of federal awards and the assistance listing numbers reported for each grant program. Management Response: The University acknowledges the identified deficiency in the internal control process related to the preparation and review of the Schedule of Expenditures of Federal Awards (SEFA). In response, the University has implemented a formalized and documented process to ensure the SEFA is accurately prepared, thoroughly reviewed, and approved in compliance with 2 CFR 200.210(b) and 2 CFR 200.303. The corrective actions taken include: 1) Independent Review and Approval: The SEFA is now subject to a formal review and approval process by an individual who is independent of the initial preparation. This review involves verifying the accuracy of reported expenditures, confirming the proper listing of assistance numbers (CFDA numbers), and ensuring that all program titles match the federal award documentation. 2) Internal Control Documentation: The University has documented its SEFA preparation and review procedures as part of its internal control framework. This documentation includes roles, responsibilities, timelines, and sign-off requirements to provide an audit trail for compliance verification. 3) Staff Training and Cross-Departmental Coordination: Staff involved in grants accounting and financial reporting will receive targeted training on SEFA requirements. Additionally, coordination among the Financial Aid Office and Finance Office has been strengthened to ensure the complete and accurate sharing of data related to federal award expenditures.

FY End: 2024-05-31
College of the Ozarks
Compliance Requirement: L
US Department of the Treasury Passed through Missouri Department of Higher Education and Workforce Development Program Name: Coronavirus State and Local Fiscal Recovery Fund / American Rescue Plan Act / MoExcels Grant Assistance Listing #: 21.027 Finding: 2024 – 001 SIGNIFICANT DEFICIENCY Reporting Condition: During our original audit, the College initially failed to include $768,053 of Coronavirus State and Local Fiscal Recovery Fund (ARPA) funding received from the State of Missouri o...

US Department of the Treasury Passed through Missouri Department of Higher Education and Workforce Development Program Name: Coronavirus State and Local Fiscal Recovery Fund / American Rescue Plan Act / MoExcels Grant Assistance Listing #: 21.027 Finding: 2024 – 001 SIGNIFICANT DEFICIENCY Reporting Condition: During our original audit, the College initially failed to include $768,053 of Coronavirus State and Local Fiscal Recovery Fund (ARPA) funding received from the State of Missouri on the Schedule of Expenditures of Federal Awards. Additionally, the College incorrectly included $78,539 of 2024-25 SEOG funding that was drawn but not expended in the 2023-24 SEFA, resulting in an overstatement of SEOG expenditures. These errors were identified subsequent to the issuance of the report and require a re-issuance of the related audit reports. The internal control system did not prevent or detect these errors during the SEFA preparation process. Cause: The College's procedures for identifying and reporting federal expenditures were insufficient. The MoExcels grant application was submitted outside of the finance office without early communication to finance personnel regarding the federal funding source. Since the College rarely receives federal funding beyond routine Student Financial Aid programs, finance personnel were initially unaware that the MoExcels funding originated from a federal source and therefore required inclusion on the SEFA. Additionally, the College lacked adequate cutoff procedures to ensure federal expenditures were reported in the correct period based on when costs were incurred rather than when funds were drawn down from federal systems. The absence of formal communication protocols between program staff and the finance staff who prepared the SEFA, combined with insufficient review procedures for year-end federal drawdown cutoff, contributed to these oversights. Effect: The initial errors resulted in an understatement of federal expenditures on the originally issued SEFA by $768,053 for ARPA funds and an overstatement by $78,539 for SEOG funds, for a net understatement of $689,514. While these errors have been corrected, the control deficiency increases the risk that future federal awards could be incorrectly reported on the SEFA, potentially resulting in noncompliance with federal reporting requirements and incomplete or inaccurate identification of major programs subject to audit. Questioned Costs: $0 Criteria: 2 CFR 200.510(b) requires that the auditee prepare a Schedule of Expenditures of Federal Awards (SEFA) for the period covered by the auditee's financial statements which must include the total Federal awards expended as determined in accordance with 2 CFR 200.502. Additionally, 2 CFR 200.303 requires that non-federal entities establish and maintain effective internal control over Federal awards that provides reasonable assurance that the non-federal entity is managing the awards in compliance with Federal statutes, regulations, and the terms and conditions of the related awards. Recommendation: We recommend the College implement written procedures for SEFA preparation that include: (1) obtaining and reviewing all grant agreements to identify federal funding sources; (2) establishing regular communication between program and finance departments to identify all federal awards received; (3) maintaining a master listing of all grants that identifies the funding source (federal/state/local) and applicable Assistance Listing Numbers; (4) implementing cutoff procedures to ensure federal expenditures are reported in the correct period based on when eligible costs are incurred, not when funds are drawn down from federal systems; and (5) requiring independent review of the SEFA by someone knowledgeable about federal compliance requirements who verifies completeness against grant documentation and proper period reporting. We note that the College's finance office maintains good communication practices with auditors regarding federal funding when they are aware of such awards; therefore, strengthening the internal identification and cutoff processes will enhance the College's ability to provide complete, accurate, and timely information to auditors about all federal funding sources. Views of responsible personnel and planned corrective actions: Management concurs with this finding. The College has implemented immediate corrective actions including development of a comprehensive grant tracking spreadsheet and establishment of regular meetings between program and finance staff. Additionally, effective immediately, all grant applications must be reviewed and approved by the Controller prior to submission to ensure proper identification of funding sources and compliance requirements. The College will also implement cutoff procedures to ensure federal expenditures are reported in the correct period based on when eligible costs are incurred. The Controller will review all G5 drawdowns near year-end to verify proper period reporting. Formal written procedures for SEFA preparation will be implemented by October 15, 2025. The Controller will maintain the master grant listing and review all grant agreements to determine federal funding sources. Beginning with fiscal year 2026 SEFA preparation, the CFO will perform an independent review for completeness and accuracy, including verification of proper period reporting for all federal expenditures.

FY End: 2024-05-31
College of the Ozarks
Compliance Requirement: L
III – Findings and questioned costs for Federal awards US Department of the Treasury Passed through Missouri Department of Higher Education and Workforce Development Program Name: Coronavirus State and Local Fiscal Recovery Fund / American Rescue Plan Act / MoExcels Grant Assistance Listing #: 21.027 Finding: 2024 – 001 SIGNIFICANT DEFICIENCY Reporting Condition: During our original audit, the College initially failed to include $768,053 of Coronavirus State and Local Fiscal Recovery Fund (ARPA)...

III – Findings and questioned costs for Federal awards US Department of the Treasury Passed through Missouri Department of Higher Education and Workforce Development Program Name: Coronavirus State and Local Fiscal Recovery Fund / American Rescue Plan Act / MoExcels Grant Assistance Listing #: 21.027 Finding: 2024 – 001 SIGNIFICANT DEFICIENCY Reporting Condition: During our original audit, the College initially failed to include $768,053 of Coronavirus State and Local Fiscal Recovery Fund (ARPA) funding received from the State of Missouri on the Schedule of Expenditures of Federal Awards. Additionally, the College incorrectly included $78,539 of 2024-25 SEOG funding that was drawn but not expended in the 2023-24 SEFA, resulting in an overstatement of SEOG expenditures. These errors were identified subsequent to the issuance of the report and require a re-issuance of the related audit reports. The internal control system did not prevent or detect these errors during the SEFA preparation process. Cause: The College's procedures for identifying and reporting federal expenditures were insufficient. The MoExcels grant application was submitted outside of the finance office without early communication to finance personnel regarding the federal funding source. Since the College rarely receives federal funding beyond routine Student Financial Aid programs, finance personnel were initially unaware that the MoExcels funding originated from a federal source and therefore required inclusion on the SEFA. Additionally, the College lacked adequate cutoff procedures to ensure federal expenditures were reported in the correct period based on when costs were incurred rather than when funds were drawn down from federal systems. The absence of formal communication protocols between program staff and the finance staff who prepared the SEFA, combined with insufficient review procedures for year-end federal drawdown cutoff, contributed to these oversights. Effect: The initial errors resulted in an understatement of federal expenditures on the originally issued SEFA by $768,053 for ARPA funds and an overstatement by $78,539 for SEOG funds, for a net understatement of $689,514. While these errors have been corrected, the control deficiency increases the risk that future federal awards could be incorrectly reported on the SEFA, potentially resulting in noncompliance with federal reporting requirements and incomplete or inaccurate identification of major programs subject to audit. Questioned Costs: $0 Criteria: 2 CFR 200.510(b) requires that the auditee prepare a Schedule of Expenditures of Federal Awards (SEFA) for the period covered by the auditee's financial statements which must include the total Federal awards expended as determined in accordance with 2 CFR 200.502. Additionally, 2 CFR 200.303 requires that non-federal entities establish and maintain effective internal control over Federal awards that provides reasonable assurance that the non-federal entity is managing the awards in compliance with Federal statutes, regulations, and the terms and conditions of the related awards. Recommendation: We recommend the College implement written procedures for SEFA preparation that include: (1) obtaining and reviewing all grant agreements to identify federal funding sources; (2) establishing regular communication between program and finance departments to identify all federal awards received; (3) maintaining a master listing of all grants that identifies the funding source (federal/state/local) and applicable Assistance Listing Numbers; (4) implementing cutoff procedures to ensure federal expenditures are reported in the correct period based on when eligible costs are incurred, not when funds are drawn down from federal systems; and (5) requiring independent review of the SEFA by someone knowledgeable about federal compliance requirements who verifies completeness against grant documentation and proper period reporting. We note that the College's finance office maintains good communication practices with auditors regarding federal funding when they are aware of such awards; therefore, strengthening the internal identification and cutoff processes will enhance the College's ability to provide complete, accurate, and timely information to auditors about all federal funding sources. Views of responsible personnel and planned corrective actions: Management concurs with this finding. The College has implemented immediate corrective actions including development of a comprehensive grant tracking spreadsheet and establishment of regular meetings between program and finance staff. Additionally, effective immediately, all grant applications must be reviewed and approved by the Controller prior to submission to ensure proper identification of funding sources and compliance requirements. The College will also implement cutoff procedures to ensure federal expenditures are reported in the correct period based on when eligible costs are incurred. The Controller will review all G5 drawdowns near year-end to verify proper period reporting. Formal written procedures for SEFA preparation will be implemented by October 15, 2025. The Controller will maintain the master grant listing and review all grant agreements to determine federal funding sources. Beginning with fiscal year 2026 SEFA preparation, the CFO will perform an independent review for completeness and accuracy, including verification of proper period reporting for all federal expenditures.

FY End: 2024-05-31
Montana Cancer Consortium
Compliance Requirement: B
#2024-002: Grant Program: Department of Health and Human Services – National Institutes for Health Research and Development Cluster – Cancer Control – Assistance Listing #93.599 – Lack Inadequate Documentation and Lack of Independent Review of Expenditures Condition: During the audit for the fiscal year ended May 31, 2024, transactions lacked sufficient supporting documentation or evidence of review and approval by the director. Additionally, some of the expenditures were incurred by the directo...

#2024-002: Grant Program: Department of Health and Human Services – National Institutes for Health Research and Development Cluster – Cancer Control – Assistance Listing #93.599 – Lack Inadequate Documentation and Lack of Independent Review of Expenditures Condition: During the audit for the fiscal year ended May 31, 2024, transactions lacked sufficient supporting documentation or evidence of review and approval by the director. Additionally, some of the expenditures were incurred by the director and were self-reviewed without any independent oversight or secondary approval. Criteria: Per 2 CFR § 200.303, nonfederal entities must establish and maintain effective internal control over federal awards that provide reasonable assurance that the organization is managing the awards in compliance with federal statutes, regulations, and the terms and conditions of the award. Effective internal controls include proper documentation and independent review of expenditures to ensure allowability, reasonableness, and compliance. Context: Out of 61 expenditures tested, 28 lacked sufficient supporting documentation or evidence of review. 21 of the 28 were expenditures incurred by the director and self-reviewed. Cause: The Consortium has not implemented adequate internal control procedures to ensure that all expenditures are properly documented and independently reviewed. The lack of segregation of duties, particularly in the review of expenditures made by the director, contributed to the deficiency. Effect: The absence of sufficient documentation and independent review increases the risk of unauthorized, unsupported, or unallowable expenditures. Recommendation: We recommend that the Consortium strengthen its internal control procedures by: • Requiring complete supporting documentation for all expenditures; • Implementing a formal review and approval process for all transactions, including those made by executive leadership; and • Ensuring that expenditures made by the director are reviewed and approved by an independent party, such as a board member or designated individual. Management Response: See Corrective Action Plan.

FY End: 2024-05-31
Incorporated Village of Ocean Beach
Compliance Requirement: I
United States Environmental Protection Agency Capitalization Grants for Clean Water Revolving FundsALN: 66.458 Criteria: 2 CFR §200.303 of the Uniform Guidance requires non-federal entities receiving federal awards to establish and maintain internal control over the federal award that provides reasonable assurance that the non-federal entity is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award. Under the Uniform Guidanc...

United States Environmental Protection Agency Capitalization Grants for Clean Water Revolving FundsALN: 66.458 Criteria: 2 CFR §200.303 of the Uniform Guidance requires non-federal entities receiving federal awards to establish and maintain internal control over the federal award that provides reasonable assurance that the non-federal entity is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award. Under the Uniform Guidance, federal awards recipients must maintain written documentation of internal control policies and procedures, such as procurement policies that adhere to state and local law, as well as federal regulations and statutes; procedures for documenting how costs are to be allocated to federal awards, documenting actual time and effort for payroll costs charged to federal awards; cash management procedures to minimize the time elapsed between the receipts and disbursements of federal funds; and, how to safeguard personally identifiable information. Condition: The Village has not updated its existing policies and written procedures to conform to Uniform Guidance requirements. Cause: Staffing constraints have limited the Village’s ability to perform a timely review of its existing policies and written procedures. Effect: Having insufficient or non-compliant written policies and procedures weakens internal controls over the federal awards received, increasing the risk of noncompliance with federal statutes and regulations. Questioned Costs: The dollar amount is undetermined as adequate documentation was not available. Identification of a Repeat Finding: This is not a repeat finding. Recommendation: The Village must review its existing written policies and procedures and update them as needed in order to comply with requirements of Uniform Guidance. Views of Responsible Officials of Auditee: The Village’s Treasurer will work on updating all policies and procedures relating to U.S. Office of Management and Budget Uniform Guidance to ensure policies are in compliance with these guidelines.

FY End: 2024-05-31
Washington County Negro Business and Professional Women's Club, Inc.
Compliance Requirement: F
Item 2024-003 Property and Equipment Management (Repeat 2023-003 and Significant Deficiency in Internal Control) Assistance Listing Number 93.600 Head Start Cluster U.S. Department of Health and Human Services Grant No. 04CH010931-05-01 Condition – The Inventory tracking sheet did not contain all required asset information and was not properly reconciled to property records. Criteria – 2 CFR 200.303(a) of the Uniform Guidance requires non-Federal entities to establish and maintain effective inte...

Item 2024-003 Property and Equipment Management (Repeat 2023-003 and Significant Deficiency in Internal Control) Assistance Listing Number 93.600 Head Start Cluster U.S. Department of Health and Human Services Grant No. 04CH010931-05-01 Condition – The Inventory tracking sheet did not contain all required asset information and was not properly reconciled to property records. Criteria – 2 CFR 200.303(a) of the Uniform Guidance requires non-Federal entities to establish and maintain effective internal control over compliance with federal statutes, regulations, and the terms and conditions of federal awards. 2 CFR Part 200.313(d)(1) of the Uniform Guidance requires that property records must be maintained for equipment acquired under a federal award that include a description of the property, a serial number or other identification number, the source of funding for the property (including the FAIN), who holds title, the acquisition date, and cost of the property, percentage of federal participation in the project costs for the federal award under which the property was acquired, the location, use and condition of the property, and any ultimate disposition data including the date of disposal and sale price of the property. The Club’s financial policies and procedures indicate a physical inventory of federal property will be taken annually. It also states that it will be reconciled by the purchasing and accounts payable bookkeeper. Cause – The Club did not include all required property information on the inventory tracking sheet and information was not properly reconciled to property records due to staff turnover. Questioned Costs – Not determinable. Effect – Failure to comply with equipment management requirements could result in noncompliance with the grant agreements. Recommendation – CRI recommends the Club follow the requirements of 2 CFR Part 200.313(d)(1). CRI also recommends the Club include all of the information required by the Uniform Guidance in one central tracking spreadsheet and include the following fields in addition to the items previously being tracked: • the source of funding for the property (including the Federal award identification number), • who holds title, • the acquisition date, • cost of the property, • percentage of Federal participation in the project costs for the Federal award under which the property was acquired, • use and • condition of the property, • and any ultimate disposition data including the date of disposal and sales price of the property (2 CFR section 200.313(d)(1)). This spreadsheet should also be used to conduct a physical observation which is reconciled with the property records. This inventory should be taken at least once every two years. Management’s Response – Management has reviewed and accepted the finding. See “Corrective Action Plan”.

FY End: 2024-05-31
Washington County Negro Business and Professional Women's Club, Inc.
Compliance Requirement: L
Item 2024-004 Financial Reporting (Significant Deficiency in Internal Control) Assistance Listing Number 93.600 Head Start Cluster U.S. Department of Health and Human Services Grant No. 04CH010931-05-01 Condition – The Club did not maintain proper documentation in support of financial reporting requirements for the two SF-425 reports that were tested. Criteria – 2 CFR section 200.303 requires that nonfederal entities receiving federal awards establish and maintain internal control over the feder...

Item 2024-004 Financial Reporting (Significant Deficiency in Internal Control) Assistance Listing Number 93.600 Head Start Cluster U.S. Department of Health and Human Services Grant No. 04CH010931-05-01 Condition – The Club did not maintain proper documentation in support of financial reporting requirements for the two SF-425 reports that were tested. Criteria – 2 CFR section 200.303 requires that nonfederal entities receiving federal awards establish and maintain internal control over the federal awards that provides reasonable assurance that the nonfederal entity is managing the federal awards in compliance with federal statutes, regulations, and the terms and conditions of the federal awards. 2 CFR section 200.302(b))3) requires that nonfederal entities keep records that include information pertaining to Federal awards, authorizations, financial obligations, unobligated balances, assets, expenditures, income and interest and be supported by source documentation. Cause – Supporting records used to populate the required financial reporting were not retained by the Club. Effect – The Club could submit incorrect information. Questioned Costs – Not determinable. Recommendation – Documentation should be prepared, reviewed, and retained to support the required reporting. The documentation should clearly document who prepared the information, who reviewed the information, and that the reviewer considered whether the information was complete and accurate. Management’s Response – Management has reviewed and accepted the finding. See “Corrective Action Plan”.

FY End: 2024-05-31
Washington County Negro Business and Professional Women's Club, Inc.
Compliance Requirement: B
Item 2024-005 Allowable Costs/Cost Principles (Noncompliance and Material Weakness in Internal Control) Assistance Listing Number 93.600 Head Start Cluster US Department of Health & Human Services Federal Grant/Contract Number: 04CH010931 Grant period – 2023-2024 Condition – Three instances were identified where payments were made in which a current lease agreement could not be obtained to substantiate the costs invoiced. Further review indicated that payments were being made for leased copiers ...

Item 2024-005 Allowable Costs/Cost Principles (Noncompliance and Material Weakness in Internal Control) Assistance Listing Number 93.600 Head Start Cluster US Department of Health & Human Services Federal Grant/Contract Number: 04CH010931 Grant period – 2023-2024 Condition – Three instances were identified where payments were made in which a current lease agreement could not be obtained to substantiate the costs invoiced. Further review indicated that payments were being made for leased copiers that had previously been returned. The payments were charged to the Head Start program. Criteria – Per 2 CFR 200.303, the non-federal entity must establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should follow guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Per 2 CFR section 200.403 – Factors affecting allowability of costs – Except where otherwise authorized by statute, costs must meet the following general criteria in order to be allowable under Federal awards: paragraph (a) Be necessary and reasonable for the performance of the Federal award and be allocable thereto under these principles; and paragraph (g) Be adequately documented. Cause – Lack of proper review of underlying lease agreement for invoices. Effect – Inadequate or inconsistent documentation of expenses may result in improper payments or fraudulent transactions occurring, loss of funding, or disallowed costs. Management identified improper payments in fiscal year March/April 2025 and took steps to determine total amount of improper payments. As a result, the vendor returned those funds totaling $158,135 on May 22, 2025. $158,135 was returned by the Agency to the Department of Health and Human Services on May 29, 2025. Questioned Costs – $131,852 related to items expanding across fiscal years 2019 – 2024. Recommendation – Management should review internal controls and ensure all expenditures are reviewed, approved and supported by appropriate documentation. Management’s Response – Management has reviewed and accepted the finding. See “Corrective Action Plan”.

« 1 704 705 707 708 2002 »