2 CFR 200 › § 200.303

Findings Citing § 200.303

Internal controls.

Total Findings
100,090
Across all audits in database
Showing Page
767 of 2002
50 findings per page
About this section
Section 200.303 requires recipients and subrecipients of Federal awards to establish and maintain effective internal controls to ensure compliance with Federal laws and award conditions. This section affects organizations receiving Federal funding, mandating them to monitor compliance, address noncompliance promptly, and protect sensitive information.
View full section details →
FY End: 2023-09-30
Seattle Indian Health Board
Compliance Requirement: L
Criteria – Federal regulations and grant terms and conditions of the programs require annual fiscal reports be submitted to the awarding agencies. In accordance with Uniform Guidance 2 CFR 200.303 the Health Board should have internal controls established to ensure accuracy of information reported and ensure compliance with reporting requirements. Additionally, good internal controls require that an individual who did not prepare the report should review the report for accuracy prior to submissi...

Criteria – Federal regulations and grant terms and conditions of the programs require annual fiscal reports be submitted to the awarding agencies. In accordance with Uniform Guidance 2 CFR 200.303 the Health Board should have internal controls established to ensure accuracy of information reported and ensure compliance with reporting requirements. Additionally, good internal controls require that an individual who did not prepare the report should review the report for accuracy prior to submission. Condition and Context – The annual SF-425 reports required under each program were submitted, but we noted no evidence of secondary review by an individual other than the preparer. As a result, the submitted SF-425 reports misreported total program expenditures for the period and the reports were ultimately rejected by the funding agencies causing the Health Board’s accounting department to correct and re-submit SF-425 reports subsequent to the period under audit. Cause – The Health Board does not have sufficient internal controls over their grant reporting process to ensure proper review of report prior to submission to ensure all reported information is accurate. Effect – There is an increased likelihood of errors in the information reported to federal agencies and ultimately an increased likelihood of noncompliance over reporting requirements. Questioned Costs – There were no questioned costs associated with this finding. Repeat Finding – This is not a repeat finding. Recommendation – We recommend the Health Board improve the controls over the reporting function, which includes the documentation, review, and approval of all required reports. Views of responsible officials – Management agrees with the auditors' findings and will implement the corrective action plan to address the issue identified.

FY End: 2023-09-30
Seattle Indian Health Board
Compliance Requirement: L
Criteria – Federal regulations and grant terms and conditions of the programs require annual fiscal reports be submitted to the awarding agencies. In accordance with Uniform Guidance 2 CFR 200.303 the Health Board should have internal controls established to ensure accuracy of information reported and ensure compliance with reporting requirements. Additionally, good internal controls require that an individual who did not prepare the report should review the report for accuracy prior to submissi...

Criteria – Federal regulations and grant terms and conditions of the programs require annual fiscal reports be submitted to the awarding agencies. In accordance with Uniform Guidance 2 CFR 200.303 the Health Board should have internal controls established to ensure accuracy of information reported and ensure compliance with reporting requirements. Additionally, good internal controls require that an individual who did not prepare the report should review the report for accuracy prior to submission. Condition and Context – The annual SF-425 reports required under each program were submitted, but we noted no evidence of secondary review by an individual other than the preparer. As a result, the submitted SF-425 reports misreported total program expenditures for the period and the reports were ultimately rejected by the funding agencies causing the Health Board’s accounting department to correct and re-submit SF-425 reports subsequent to the period under audit. Cause – The Health Board does not have sufficient internal controls over their grant reporting process to ensure proper review of report prior to submission to ensure all reported information is accurate. Effect – There is an increased likelihood of errors in the information reported to federal agencies and ultimately an increased likelihood of noncompliance over reporting requirements. Questioned Costs – There were no questioned costs associated with this finding. Repeat Finding – This is not a repeat finding. Recommendation – We recommend the Health Board improve the controls over the reporting function, which includes the documentation, review, and approval of all required reports. Views of responsible officials – Management agrees with the auditors' findings and will implement the corrective action plan to address the issue identified.

FY End: 2023-09-30
Seattle Indian Health Board
Compliance Requirement: L
Criteria – Federal regulations and grant terms and conditions of the programs require annual fiscal reports be submitted to the awarding agencies. In accordance with Uniform Guidance 2 CFR 200.303 the Health Board should have internal controls established to ensure accuracy of information reported and ensure compliance with reporting requirements. Additionally, good internal controls require that an individual who did not prepare the report should review the report for accuracy prior to submissi...

Criteria – Federal regulations and grant terms and conditions of the programs require annual fiscal reports be submitted to the awarding agencies. In accordance with Uniform Guidance 2 CFR 200.303 the Health Board should have internal controls established to ensure accuracy of information reported and ensure compliance with reporting requirements. Additionally, good internal controls require that an individual who did not prepare the report should review the report for accuracy prior to submission. Condition and Context – The annual SF-425 reports required under each program were submitted, but we noted no evidence of secondary review by an individual other than the preparer. As a result, the submitted SF-425 reports misreported total program expenditures for the period and the reports were ultimately rejected by the funding agencies causing the Health Board’s accounting department to correct and re-submit SF-425 reports subsequent to the period under audit. Cause – The Health Board does not have sufficient internal controls over their grant reporting process to ensure proper review of report prior to submission to ensure all reported information is accurate. Effect – There is an increased likelihood of errors in the information reported to federal agencies and ultimately an increased likelihood of noncompliance over reporting requirements. Questioned Costs – There were no questioned costs associated with this finding. Repeat Finding – This is not a repeat finding. Recommendation – We recommend the Health Board improve the controls over the reporting function, which includes the documentation, review, and approval of all required reports. Views of responsible officials – Management agrees with the auditors' findings and will implement the corrective action plan to address the issue identified.

FY End: 2023-09-30
Seattle Indian Health Board
Compliance Requirement: L
Criteria – Federal regulations and grant terms and conditions of the programs require annual fiscal reports be submitted to the awarding agencies. In accordance with Uniform Guidance 2 CFR 200.303 the Health Board should have internal controls established to ensure accuracy of information reported and ensure compliance with reporting requirements. Additionally, good internal controls require that an individual who did not prepare the report should review the report for accuracy prior to submissi...

Criteria – Federal regulations and grant terms and conditions of the programs require annual fiscal reports be submitted to the awarding agencies. In accordance with Uniform Guidance 2 CFR 200.303 the Health Board should have internal controls established to ensure accuracy of information reported and ensure compliance with reporting requirements. Additionally, good internal controls require that an individual who did not prepare the report should review the report for accuracy prior to submission. Condition and Context – The annual SF-425 reports required under each program were submitted, but we noted no evidence of secondary review by an individual other than the preparer. As a result, the submitted SF-425 reports misreported total program expenditures for the period and the reports were ultimately rejected by the funding agencies causing the Health Board’s accounting department to correct and re-submit SF-425 reports subsequent to the period under audit. Cause – The Health Board does not have sufficient internal controls over their grant reporting process to ensure proper review of report prior to submission to ensure all reported information is accurate. Effect – There is an increased likelihood of errors in the information reported to federal agencies and ultimately an increased likelihood of noncompliance over reporting requirements. Questioned Costs – There were no questioned costs associated with this finding. Repeat Finding – This is not a repeat finding. Recommendation – We recommend the Health Board improve the controls over the reporting function, which includes the documentation, review, and approval of all required reports. Views of responsible officials – Management agrees with the auditors' findings and will implement the corrective action plan to address the issue identified.

FY End: 2023-09-30
National Park Foundation
Compliance Requirement: L
2023-003 – Internal Control over Compliance and Compliance with Reporting Information on the Major Federal Program: Federal Agency: Department of Interior Program Name: National Park Service Second Century Endowment and Appropriation Assistance Listing Number: 15.U01 Award Number: H.R. 4680/P.L. 114-289 Award Period: October 1, 2022 to September 30, 2023 Criteria – The Uniform Guidance in 2 CFR Section 200.303 requires that non-Federal entities receiving Federal awards (i.e., au...

2023-003 – Internal Control over Compliance and Compliance with Reporting Information on the Major Federal Program: Federal Agency: Department of Interior Program Name: National Park Service Second Century Endowment and Appropriation Assistance Listing Number: 15.U01 Award Number: H.R. 4680/P.L. 114-289 Award Period: October 1, 2022 to September 30, 2023 Criteria – The Uniform Guidance in 2 CFR Section 200.303 requires that non-Federal entities receiving Federal awards (i.e., auditee management) establish and maintain internal control designed to reasonably ensure compliance with Federal statues, regulations, and the terms and conditions of the Federal award. In accordance with the requirements 2 CFR §1402.300(b), a non-Federal entity is responsible for complying with all requirements of the Federal award. For all Federal awards, this includes the provisions of the Federal Funding and Accountability Act (FFATA), which includes requirements on executive compensation, and also requirements implementing the Act for the non-Federal entity at 2 CFR part 25, Financial Assistance Use of Universal Identifier and System for Award Management and 2 CFR part 170, Reporting Subaward and Executive Compensation Information. In accordance with 2 CFR Part 170, Appendix A, under FFATA, the Foundation is required to collect and report information on each subaward or amendment of $30,000 or more in federal funds in the FFATA Subaward Reporting System. Condition – During our testing of reporting, we selected seven subrecipient awards. For all samples tested, the Foundation did not comply with the mandatory FFATA report filing requirements. Transactions Tested Subaward not reported Report not timely Subaward amount incorrect Subaward missing key elements 7 7 7 Not applicable – no report was submitted Not applicable – no report was submitted Dollar Amount of Tested 2023 Subawards Subaward not reported Report not timely Subaward amount incorrect Subaward missing key elements $ 843,636 $ 843,636 $ 843,636 Not applicable – no report was submitted Not applicable – no report was submitted Cause - The Foundation did not have adequate policies and procedures in place to ensure compliance with the FFATA filing requirements. Effect or Potential Effect - Failure to comply with the reporting requirements of the Uniform Guidance could result in noncompliance and awarding agency taking administrative action. Questioned Costs – None. Context - This is a condition identified based upon our review of the Foundation’s compliance with specified requirements. The sample was selected based on a non-statistical basis. The prevalence of these finding is detailed in the condition section above. Repeat Finding – This is a repeat finding from prior year. This was reported as finding 2022-001 in the 2022 report. Recommendation – BDO noted management’s actions to address prior year finding, however, due to certain FFATA requirements to file, management is still unable to file the required FFATA reporting. BDO recommends that the Foundation continue to work with federal grantor/agencies to determine the required information and immediately file the required requirements. Views of Responsible Officials – The Foundation’s management agrees with the finding and recommendation. The planned corrective actions are presented in the Foundation’s management’s corrective action plan attached as Appendix C.

FY End: 2023-09-30
National Park Foundation
Compliance Requirement: L
2023-003 – Internal Control over Compliance and Compliance with Reporting Information on the Major Federal Program: Federal Agency: Department of Interior Program Name: National Park Service Second Century Endowment and Appropriation Assistance Listing Number: 15.U01 Award Number: H.R. 4680/P.L. 114-289 Award Period: October 1, 2022 to September 30, 2023 Criteria – The Uniform Guidance in 2 CFR Section 200.303 requires that non-Federal entities receiving Federal awards (i.e., au...

2023-003 – Internal Control over Compliance and Compliance with Reporting Information on the Major Federal Program: Federal Agency: Department of Interior Program Name: National Park Service Second Century Endowment and Appropriation Assistance Listing Number: 15.U01 Award Number: H.R. 4680/P.L. 114-289 Award Period: October 1, 2022 to September 30, 2023 Criteria – The Uniform Guidance in 2 CFR Section 200.303 requires that non-Federal entities receiving Federal awards (i.e., auditee management) establish and maintain internal control designed to reasonably ensure compliance with Federal statues, regulations, and the terms and conditions of the Federal award. In accordance with the requirements 2 CFR §1402.300(b), a non-Federal entity is responsible for complying with all requirements of the Federal award. For all Federal awards, this includes the provisions of the Federal Funding and Accountability Act (FFATA), which includes requirements on executive compensation, and also requirements implementing the Act for the non-Federal entity at 2 CFR part 25, Financial Assistance Use of Universal Identifier and System for Award Management and 2 CFR part 170, Reporting Subaward and Executive Compensation Information. In accordance with 2 CFR Part 170, Appendix A, under FFATA, the Foundation is required to collect and report information on each subaward or amendment of $30,000 or more in federal funds in the FFATA Subaward Reporting System. Condition – During our testing of reporting, we selected seven subrecipient awards. For all samples tested, the Foundation did not comply with the mandatory FFATA report filing requirements. Transactions Tested Subaward not reported Report not timely Subaward amount incorrect Subaward missing key elements 7 7 7 Not applicable – no report was submitted Not applicable – no report was submitted Dollar Amount of Tested 2023 Subawards Subaward not reported Report not timely Subaward amount incorrect Subaward missing key elements $ 843,636 $ 843,636 $ 843,636 Not applicable – no report was submitted Not applicable – no report was submitted Cause - The Foundation did not have adequate policies and procedures in place to ensure compliance with the FFATA filing requirements. Effect or Potential Effect - Failure to comply with the reporting requirements of the Uniform Guidance could result in noncompliance and awarding agency taking administrative action. Questioned Costs – None. Context - This is a condition identified based upon our review of the Foundation’s compliance with specified requirements. The sample was selected based on a non-statistical basis. The prevalence of these finding is detailed in the condition section above. Repeat Finding – This is a repeat finding from prior year. This was reported as finding 2022-001 in the 2022 report. Recommendation – BDO noted management’s actions to address prior year finding, however, due to certain FFATA requirements to file, management is still unable to file the required FFATA reporting. BDO recommends that the Foundation continue to work with federal grantor/agencies to determine the required information and immediately file the required requirements. Views of Responsible Officials – The Foundation’s management agrees with the finding and recommendation. The planned corrective actions are presented in the Foundation’s management’s corrective action plan attached as Appendix C.

FY End: 2023-09-30
Kid Power, Inc.
Compliance Requirement: ABCGHL
Assistance Listing Number: 21.027 Name of Federal Program or Cluster: COVID-19—Coronavirus State and Local Fiscal Recovery Funds Name of Federal Agency: Department of the Treasury Name of Pass-through Entity: Office of the State Superintendent of Education Award Period: May 25, 2022 – September 30, 2024 Criteria: 2 CFR Section 200.303 of the Uniform Grant Guidance requires a non-federal entity to establish and maintain effective internal controls to ensure compliance with federal statues, r...

Assistance Listing Number: 21.027 Name of Federal Program or Cluster: COVID-19—Coronavirus State and Local Fiscal Recovery Funds Name of Federal Agency: Department of the Treasury Name of Pass-through Entity: Office of the State Superintendent of Education Award Period: May 25, 2022 – September 30, 2024 Criteria: 2 CFR Section 200.303 of the Uniform Grant Guidance requires a non-federal entity to establish and maintain effective internal controls to ensure compliance with federal statues, regulations, and the terms and conditions of federal awards. Condition: Kid Power, Inc.'s internal controls over review of cost allocation journal entries, allowable costs and activities, period of performance, cash management, matching, and reporting were not documented. Cause: Written procedures were not established for the documentation of internal controls over compliance requirements. Effect or Potential Effect: This could result in noncompliance, disallowed costs, or discontinuance of federal funding. Recommendation: We recommend documenting the controls over each compliance requirement and providing training on documentation and forms to provide evidence of review. Views of Responsible Officials: Kid Power, Inc. agrees with the finding and will establish written procedures, train individuals, and document the review of cost allocation journal entries, allowable costs and activities, period of performance, cash management, matching, and reporting.

FY End: 2023-09-30
Corus International, Inc. and Affiliates
Compliance Requirement: H
2023-002 – Internal Control over Compliance and Compliance with Period of Performance Information on the Major Federal Program - Federal Agency: United States Agency for International Development (USAID) Program Name: USAID Foreign Assistance for Program Overseas Assistance Listing Number: 98.001 Award Number: Various Award Period: Various Criteria – A non-Federal entity may charge to the Federal award only allowable costs incurred during the period of performance and any costs i...

2023-002 – Internal Control over Compliance and Compliance with Period of Performance Information on the Major Federal Program - Federal Agency: United States Agency for International Development (USAID) Program Name: USAID Foreign Assistance for Program Overseas Assistance Listing Number: 98.001 Award Number: Various Award Period: Various Criteria – A non-Federal entity may charge to the Federal award only allowable costs incurred during the period of performance and any costs incurred before the Federal awarding agency or pass-through entity made the Federal award, only to the extent that they would have been allowable if incurred after the date of the Federal award and only with the written approval of the Federal awarding agency. Additionally, the Uniform Guidance in 2 CFR Section 200.344(b), states that unless the federal awarding agency or pass-through entity authorized an extension, a non-Federal entity must liquidate all financial obligations incurred under the Federal award not later than 120 calendar days after the end date of the period of performance as specified in the terms and conditions of the Federal award. Further, the Uniform Guidance in 2 CFR Section 200.303, Internal Controls, requires the non-federal entities receiving Federal awards (i.e., auditee management) establish and maintain internal control designed to reasonable ensure compliance with Federal statutes, regulations, and other terms and conditions of the Federal Award. The Uniform Guidance in 2 CFR Section 200.510 (b) states in part: “The auditee must also prepare a schedule of expenditures of Federal awards (SEFA) for the period covered by the auditee’s financial statements which must include the total Federal awards expended as determined in accordance with 2 CFR Section 200.502 Basis for determining Federal awards expended.” The SEFA must provide total Federal awards expended for each individual Federal program. Condition – During our testing, we identified one (1) out of 40 sampled transactions was incurred outside the period of performance. Corus did not obtain written approval from the federal awarding agency for the specific project. As a result, total expenditure totaling $106,400 was improperly included in the SEFA. Cause - The internal controls established for the review and reconciliation of the SEFA to the underlying accounting records were not consistently followed to ensure accurate charging of expenditures to the SEFA in the correct period. Questioned Costs - None. Context – This is a condition identified per review of Corus’ compliance with the specified requirements. Total expenditures of the specific project charged to the program was $106,400. These charges were removed from the SEFA presented for the year ended September 30, 2023. Effect - Failure to properly review and support expenditures reported in the SEFA can result in inaccurate reporting and non-compliance with laws and regulations. Repeat Finding - This is not a repeat finding. Recommendation - Internal controls should be designed to prevent, detect and correct errors and/or omissions in a timely manner. Without adequate controls, Corus cannot provide reasonable assurance that the SEFA is fairly presented. We recommend management to strengthen its internal control to ensure complete and accurate SEFA. Views of Responsible Officials - Corus management agrees with the findings and recommendations. The planned corrective actions are presented in Corus management’s corrective action plan attached as Appendix B to the Single Audit Report.

FY End: 2023-09-30
Corus International, Inc. and Affiliates
Compliance Requirement: H
2023-002 – Internal Control over Compliance and Compliance with Period of Performance Information on the Major Federal Program - Federal Agency: United States Agency for International Development (USAID) Program Name: USAID Foreign Assistance for Program Overseas Assistance Listing Number: 98.001 Award Number: Various Award Period: Various Criteria – A non-Federal entity may charge to the Federal award only allowable costs incurred during the period of performance and any costs i...

2023-002 – Internal Control over Compliance and Compliance with Period of Performance Information on the Major Federal Program - Federal Agency: United States Agency for International Development (USAID) Program Name: USAID Foreign Assistance for Program Overseas Assistance Listing Number: 98.001 Award Number: Various Award Period: Various Criteria – A non-Federal entity may charge to the Federal award only allowable costs incurred during the period of performance and any costs incurred before the Federal awarding agency or pass-through entity made the Federal award, only to the extent that they would have been allowable if incurred after the date of the Federal award and only with the written approval of the Federal awarding agency. Additionally, the Uniform Guidance in 2 CFR Section 200.344(b), states that unless the federal awarding agency or pass-through entity authorized an extension, a non-Federal entity must liquidate all financial obligations incurred under the Federal award not later than 120 calendar days after the end date of the period of performance as specified in the terms and conditions of the Federal award. Further, the Uniform Guidance in 2 CFR Section 200.303, Internal Controls, requires the non-federal entities receiving Federal awards (i.e., auditee management) establish and maintain internal control designed to reasonable ensure compliance with Federal statutes, regulations, and other terms and conditions of the Federal Award. The Uniform Guidance in 2 CFR Section 200.510 (b) states in part: “The auditee must also prepare a schedule of expenditures of Federal awards (SEFA) for the period covered by the auditee’s financial statements which must include the total Federal awards expended as determined in accordance with 2 CFR Section 200.502 Basis for determining Federal awards expended.” The SEFA must provide total Federal awards expended for each individual Federal program. Condition – During our testing, we identified one (1) out of 40 sampled transactions was incurred outside the period of performance. Corus did not obtain written approval from the federal awarding agency for the specific project. As a result, total expenditure totaling $106,400 was improperly included in the SEFA. Cause - The internal controls established for the review and reconciliation of the SEFA to the underlying accounting records were not consistently followed to ensure accurate charging of expenditures to the SEFA in the correct period. Questioned Costs - None. Context – This is a condition identified per review of Corus’ compliance with the specified requirements. Total expenditures of the specific project charged to the program was $106,400. These charges were removed from the SEFA presented for the year ended September 30, 2023. Effect - Failure to properly review and support expenditures reported in the SEFA can result in inaccurate reporting and non-compliance with laws and regulations. Repeat Finding - This is not a repeat finding. Recommendation - Internal controls should be designed to prevent, detect and correct errors and/or omissions in a timely manner. Without adequate controls, Corus cannot provide reasonable assurance that the SEFA is fairly presented. We recommend management to strengthen its internal control to ensure complete and accurate SEFA. Views of Responsible Officials - Corus management agrees with the findings and recommendations. The planned corrective actions are presented in Corus management’s corrective action plan attached as Appendix B to the Single Audit Report.

FY End: 2023-09-30
Corus International, Inc. and Affiliates
Compliance Requirement: H
2023-002 – Internal Control over Compliance and Compliance with Period of Performance Information on the Major Federal Program - Federal Agency: United States Agency for International Development (USAID) Program Name: USAID Foreign Assistance for Program Overseas Assistance Listing Number: 98.001 Award Number: Various Award Period: Various Criteria – A non-Federal entity may charge to the Federal award only allowable costs incurred during the period of performance and any costs i...

2023-002 – Internal Control over Compliance and Compliance with Period of Performance Information on the Major Federal Program - Federal Agency: United States Agency for International Development (USAID) Program Name: USAID Foreign Assistance for Program Overseas Assistance Listing Number: 98.001 Award Number: Various Award Period: Various Criteria – A non-Federal entity may charge to the Federal award only allowable costs incurred during the period of performance and any costs incurred before the Federal awarding agency or pass-through entity made the Federal award, only to the extent that they would have been allowable if incurred after the date of the Federal award and only with the written approval of the Federal awarding agency. Additionally, the Uniform Guidance in 2 CFR Section 200.344(b), states that unless the federal awarding agency or pass-through entity authorized an extension, a non-Federal entity must liquidate all financial obligations incurred under the Federal award not later than 120 calendar days after the end date of the period of performance as specified in the terms and conditions of the Federal award. Further, the Uniform Guidance in 2 CFR Section 200.303, Internal Controls, requires the non-federal entities receiving Federal awards (i.e., auditee management) establish and maintain internal control designed to reasonable ensure compliance with Federal statutes, regulations, and other terms and conditions of the Federal Award. The Uniform Guidance in 2 CFR Section 200.510 (b) states in part: “The auditee must also prepare a schedule of expenditures of Federal awards (SEFA) for the period covered by the auditee’s financial statements which must include the total Federal awards expended as determined in accordance with 2 CFR Section 200.502 Basis for determining Federal awards expended.” The SEFA must provide total Federal awards expended for each individual Federal program. Condition – During our testing, we identified one (1) out of 40 sampled transactions was incurred outside the period of performance. Corus did not obtain written approval from the federal awarding agency for the specific project. As a result, total expenditure totaling $106,400 was improperly included in the SEFA. Cause - The internal controls established for the review and reconciliation of the SEFA to the underlying accounting records were not consistently followed to ensure accurate charging of expenditures to the SEFA in the correct period. Questioned Costs - None. Context – This is a condition identified per review of Corus’ compliance with the specified requirements. Total expenditures of the specific project charged to the program was $106,400. These charges were removed from the SEFA presented for the year ended September 30, 2023. Effect - Failure to properly review and support expenditures reported in the SEFA can result in inaccurate reporting and non-compliance with laws and regulations. Repeat Finding - This is not a repeat finding. Recommendation - Internal controls should be designed to prevent, detect and correct errors and/or omissions in a timely manner. Without adequate controls, Corus cannot provide reasonable assurance that the SEFA is fairly presented. We recommend management to strengthen its internal control to ensure complete and accurate SEFA. Views of Responsible Officials - Corus management agrees with the findings and recommendations. The planned corrective actions are presented in Corus management’s corrective action plan attached as Appendix B to the Single Audit Report.

FY End: 2023-09-30
Corus International, Inc. and Affiliates
Compliance Requirement: H
2023-002 – Internal Control over Compliance and Compliance with Period of Performance Information on the Major Federal Program - Federal Agency: United States Agency for International Development (USAID) Program Name: USAID Foreign Assistance for Program Overseas Assistance Listing Number: 98.001 Award Number: Various Award Period: Various Criteria – A non-Federal entity may charge to the Federal award only allowable costs incurred during the period of performance and any costs i...

2023-002 – Internal Control over Compliance and Compliance with Period of Performance Information on the Major Federal Program - Federal Agency: United States Agency for International Development (USAID) Program Name: USAID Foreign Assistance for Program Overseas Assistance Listing Number: 98.001 Award Number: Various Award Period: Various Criteria – A non-Federal entity may charge to the Federal award only allowable costs incurred during the period of performance and any costs incurred before the Federal awarding agency or pass-through entity made the Federal award, only to the extent that they would have been allowable if incurred after the date of the Federal award and only with the written approval of the Federal awarding agency. Additionally, the Uniform Guidance in 2 CFR Section 200.344(b), states that unless the federal awarding agency or pass-through entity authorized an extension, a non-Federal entity must liquidate all financial obligations incurred under the Federal award not later than 120 calendar days after the end date of the period of performance as specified in the terms and conditions of the Federal award. Further, the Uniform Guidance in 2 CFR Section 200.303, Internal Controls, requires the non-federal entities receiving Federal awards (i.e., auditee management) establish and maintain internal control designed to reasonable ensure compliance with Federal statutes, regulations, and other terms and conditions of the Federal Award. The Uniform Guidance in 2 CFR Section 200.510 (b) states in part: “The auditee must also prepare a schedule of expenditures of Federal awards (SEFA) for the period covered by the auditee’s financial statements which must include the total Federal awards expended as determined in accordance with 2 CFR Section 200.502 Basis for determining Federal awards expended.” The SEFA must provide total Federal awards expended for each individual Federal program. Condition – During our testing, we identified one (1) out of 40 sampled transactions was incurred outside the period of performance. Corus did not obtain written approval from the federal awarding agency for the specific project. As a result, total expenditure totaling $106,400 was improperly included in the SEFA. Cause - The internal controls established for the review and reconciliation of the SEFA to the underlying accounting records were not consistently followed to ensure accurate charging of expenditures to the SEFA in the correct period. Questioned Costs - None. Context – This is a condition identified per review of Corus’ compliance with the specified requirements. Total expenditures of the specific project charged to the program was $106,400. These charges were removed from the SEFA presented for the year ended September 30, 2023. Effect - Failure to properly review and support expenditures reported in the SEFA can result in inaccurate reporting and non-compliance with laws and regulations. Repeat Finding - This is not a repeat finding. Recommendation - Internal controls should be designed to prevent, detect and correct errors and/or omissions in a timely manner. Without adequate controls, Corus cannot provide reasonable assurance that the SEFA is fairly presented. We recommend management to strengthen its internal control to ensure complete and accurate SEFA. Views of Responsible Officials - Corus management agrees with the findings and recommendations. The planned corrective actions are presented in Corus management’s corrective action plan attached as Appendix B to the Single Audit Report.

FY End: 2023-09-30
Corus International, Inc. and Affiliates
Compliance Requirement: H
2023-002 – Internal Control over Compliance and Compliance with Period of Performance Information on the Major Federal Program - Federal Agency: United States Agency for International Development (USAID) Program Name: USAID Foreign Assistance for Program Overseas Assistance Listing Number: 98.001 Award Number: Various Award Period: Various Criteria – A non-Federal entity may charge to the Federal award only allowable costs incurred during the period of performance and any costs i...

2023-002 – Internal Control over Compliance and Compliance with Period of Performance Information on the Major Federal Program - Federal Agency: United States Agency for International Development (USAID) Program Name: USAID Foreign Assistance for Program Overseas Assistance Listing Number: 98.001 Award Number: Various Award Period: Various Criteria – A non-Federal entity may charge to the Federal award only allowable costs incurred during the period of performance and any costs incurred before the Federal awarding agency or pass-through entity made the Federal award, only to the extent that they would have been allowable if incurred after the date of the Federal award and only with the written approval of the Federal awarding agency. Additionally, the Uniform Guidance in 2 CFR Section 200.344(b), states that unless the federal awarding agency or pass-through entity authorized an extension, a non-Federal entity must liquidate all financial obligations incurred under the Federal award not later than 120 calendar days after the end date of the period of performance as specified in the terms and conditions of the Federal award. Further, the Uniform Guidance in 2 CFR Section 200.303, Internal Controls, requires the non-federal entities receiving Federal awards (i.e., auditee management) establish and maintain internal control designed to reasonable ensure compliance with Federal statutes, regulations, and other terms and conditions of the Federal Award. The Uniform Guidance in 2 CFR Section 200.510 (b) states in part: “The auditee must also prepare a schedule of expenditures of Federal awards (SEFA) for the period covered by the auditee’s financial statements which must include the total Federal awards expended as determined in accordance with 2 CFR Section 200.502 Basis for determining Federal awards expended.” The SEFA must provide total Federal awards expended for each individual Federal program. Condition – During our testing, we identified one (1) out of 40 sampled transactions was incurred outside the period of performance. Corus did not obtain written approval from the federal awarding agency for the specific project. As a result, total expenditure totaling $106,400 was improperly included in the SEFA. Cause - The internal controls established for the review and reconciliation of the SEFA to the underlying accounting records were not consistently followed to ensure accurate charging of expenditures to the SEFA in the correct period. Questioned Costs - None. Context – This is a condition identified per review of Corus’ compliance with the specified requirements. Total expenditures of the specific project charged to the program was $106,400. These charges were removed from the SEFA presented for the year ended September 30, 2023. Effect - Failure to properly review and support expenditures reported in the SEFA can result in inaccurate reporting and non-compliance with laws and regulations. Repeat Finding - This is not a repeat finding. Recommendation - Internal controls should be designed to prevent, detect and correct errors and/or omissions in a timely manner. Without adequate controls, Corus cannot provide reasonable assurance that the SEFA is fairly presented. We recommend management to strengthen its internal control to ensure complete and accurate SEFA. Views of Responsible Officials - Corus management agrees with the findings and recommendations. The planned corrective actions are presented in Corus management’s corrective action plan attached as Appendix B to the Single Audit Report.

FY End: 2023-09-30
Corus International, Inc. and Affiliates
Compliance Requirement: H
2023-002 – Internal Control over Compliance and Compliance with Period of Performance Information on the Major Federal Program - Federal Agency: United States Agency for International Development (USAID) Program Name: USAID Foreign Assistance for Program Overseas Assistance Listing Number: 98.001 Award Number: Various Award Period: Various Criteria – A non-Federal entity may charge to the Federal award only allowable costs incurred during the period of performance and any costs i...

2023-002 – Internal Control over Compliance and Compliance with Period of Performance Information on the Major Federal Program - Federal Agency: United States Agency for International Development (USAID) Program Name: USAID Foreign Assistance for Program Overseas Assistance Listing Number: 98.001 Award Number: Various Award Period: Various Criteria – A non-Federal entity may charge to the Federal award only allowable costs incurred during the period of performance and any costs incurred before the Federal awarding agency or pass-through entity made the Federal award, only to the extent that they would have been allowable if incurred after the date of the Federal award and only with the written approval of the Federal awarding agency. Additionally, the Uniform Guidance in 2 CFR Section 200.344(b), states that unless the federal awarding agency or pass-through entity authorized an extension, a non-Federal entity must liquidate all financial obligations incurred under the Federal award not later than 120 calendar days after the end date of the period of performance as specified in the terms and conditions of the Federal award. Further, the Uniform Guidance in 2 CFR Section 200.303, Internal Controls, requires the non-federal entities receiving Federal awards (i.e., auditee management) establish and maintain internal control designed to reasonable ensure compliance with Federal statutes, regulations, and other terms and conditions of the Federal Award. The Uniform Guidance in 2 CFR Section 200.510 (b) states in part: “The auditee must also prepare a schedule of expenditures of Federal awards (SEFA) for the period covered by the auditee’s financial statements which must include the total Federal awards expended as determined in accordance with 2 CFR Section 200.502 Basis for determining Federal awards expended.” The SEFA must provide total Federal awards expended for each individual Federal program. Condition – During our testing, we identified one (1) out of 40 sampled transactions was incurred outside the period of performance. Corus did not obtain written approval from the federal awarding agency for the specific project. As a result, total expenditure totaling $106,400 was improperly included in the SEFA. Cause - The internal controls established for the review and reconciliation of the SEFA to the underlying accounting records were not consistently followed to ensure accurate charging of expenditures to the SEFA in the correct period. Questioned Costs - None. Context – This is a condition identified per review of Corus’ compliance with the specified requirements. Total expenditures of the specific project charged to the program was $106,400. These charges were removed from the SEFA presented for the year ended September 30, 2023. Effect - Failure to properly review and support expenditures reported in the SEFA can result in inaccurate reporting and non-compliance with laws and regulations. Repeat Finding - This is not a repeat finding. Recommendation - Internal controls should be designed to prevent, detect and correct errors and/or omissions in a timely manner. Without adequate controls, Corus cannot provide reasonable assurance that the SEFA is fairly presented. We recommend management to strengthen its internal control to ensure complete and accurate SEFA. Views of Responsible Officials - Corus management agrees with the findings and recommendations. The planned corrective actions are presented in Corus management’s corrective action plan attached as Appendix B to the Single Audit Report.

FY End: 2023-09-30
Corus International, Inc. and Affiliates
Compliance Requirement: H
2023-002 – Internal Control over Compliance and Compliance with Period of Performance Information on the Major Federal Program - Federal Agency: United States Agency for International Development (USAID) Program Name: USAID Foreign Assistance for Program Overseas Assistance Listing Number: 98.001 Award Number: Various Award Period: Various Criteria – A non-Federal entity may charge to the Federal award only allowable costs incurred during the period of performance and any costs i...

2023-002 – Internal Control over Compliance and Compliance with Period of Performance Information on the Major Federal Program - Federal Agency: United States Agency for International Development (USAID) Program Name: USAID Foreign Assistance for Program Overseas Assistance Listing Number: 98.001 Award Number: Various Award Period: Various Criteria – A non-Federal entity may charge to the Federal award only allowable costs incurred during the period of performance and any costs incurred before the Federal awarding agency or pass-through entity made the Federal award, only to the extent that they would have been allowable if incurred after the date of the Federal award and only with the written approval of the Federal awarding agency. Additionally, the Uniform Guidance in 2 CFR Section 200.344(b), states that unless the federal awarding agency or pass-through entity authorized an extension, a non-Federal entity must liquidate all financial obligations incurred under the Federal award not later than 120 calendar days after the end date of the period of performance as specified in the terms and conditions of the Federal award. Further, the Uniform Guidance in 2 CFR Section 200.303, Internal Controls, requires the non-federal entities receiving Federal awards (i.e., auditee management) establish and maintain internal control designed to reasonable ensure compliance with Federal statutes, regulations, and other terms and conditions of the Federal Award. The Uniform Guidance in 2 CFR Section 200.510 (b) states in part: “The auditee must also prepare a schedule of expenditures of Federal awards (SEFA) for the period covered by the auditee’s financial statements which must include the total Federal awards expended as determined in accordance with 2 CFR Section 200.502 Basis for determining Federal awards expended.” The SEFA must provide total Federal awards expended for each individual Federal program. Condition – During our testing, we identified one (1) out of 40 sampled transactions was incurred outside the period of performance. Corus did not obtain written approval from the federal awarding agency for the specific project. As a result, total expenditure totaling $106,400 was improperly included in the SEFA. Cause - The internal controls established for the review and reconciliation of the SEFA to the underlying accounting records were not consistently followed to ensure accurate charging of expenditures to the SEFA in the correct period. Questioned Costs - None. Context – This is a condition identified per review of Corus’ compliance with the specified requirements. Total expenditures of the specific project charged to the program was $106,400. These charges were removed from the SEFA presented for the year ended September 30, 2023. Effect - Failure to properly review and support expenditures reported in the SEFA can result in inaccurate reporting and non-compliance with laws and regulations. Repeat Finding - This is not a repeat finding. Recommendation - Internal controls should be designed to prevent, detect and correct errors and/or omissions in a timely manner. Without adequate controls, Corus cannot provide reasonable assurance that the SEFA is fairly presented. We recommend management to strengthen its internal control to ensure complete and accurate SEFA. Views of Responsible Officials - Corus management agrees with the findings and recommendations. The planned corrective actions are presented in Corus management’s corrective action plan attached as Appendix B to the Single Audit Report.

FY End: 2023-09-30
Corus International, Inc. and Affiliates
Compliance Requirement: H
2023-002 – Internal Control over Compliance and Compliance with Period of Performance Information on the Major Federal Program - Federal Agency: United States Agency for International Development (USAID) Program Name: USAID Foreign Assistance for Program Overseas Assistance Listing Number: 98.001 Award Number: Various Award Period: Various Criteria – A non-Federal entity may charge to the Federal award only allowable costs incurred during the period of performance and any costs i...

2023-002 – Internal Control over Compliance and Compliance with Period of Performance Information on the Major Federal Program - Federal Agency: United States Agency for International Development (USAID) Program Name: USAID Foreign Assistance for Program Overseas Assistance Listing Number: 98.001 Award Number: Various Award Period: Various Criteria – A non-Federal entity may charge to the Federal award only allowable costs incurred during the period of performance and any costs incurred before the Federal awarding agency or pass-through entity made the Federal award, only to the extent that they would have been allowable if incurred after the date of the Federal award and only with the written approval of the Federal awarding agency. Additionally, the Uniform Guidance in 2 CFR Section 200.344(b), states that unless the federal awarding agency or pass-through entity authorized an extension, a non-Federal entity must liquidate all financial obligations incurred under the Federal award not later than 120 calendar days after the end date of the period of performance as specified in the terms and conditions of the Federal award. Further, the Uniform Guidance in 2 CFR Section 200.303, Internal Controls, requires the non-federal entities receiving Federal awards (i.e., auditee management) establish and maintain internal control designed to reasonable ensure compliance with Federal statutes, regulations, and other terms and conditions of the Federal Award. The Uniform Guidance in 2 CFR Section 200.510 (b) states in part: “The auditee must also prepare a schedule of expenditures of Federal awards (SEFA) for the period covered by the auditee’s financial statements which must include the total Federal awards expended as determined in accordance with 2 CFR Section 200.502 Basis for determining Federal awards expended.” The SEFA must provide total Federal awards expended for each individual Federal program. Condition – During our testing, we identified one (1) out of 40 sampled transactions was incurred outside the period of performance. Corus did not obtain written approval from the federal awarding agency for the specific project. As a result, total expenditure totaling $106,400 was improperly included in the SEFA. Cause - The internal controls established for the review and reconciliation of the SEFA to the underlying accounting records were not consistently followed to ensure accurate charging of expenditures to the SEFA in the correct period. Questioned Costs - None. Context – This is a condition identified per review of Corus’ compliance with the specified requirements. Total expenditures of the specific project charged to the program was $106,400. These charges were removed from the SEFA presented for the year ended September 30, 2023. Effect - Failure to properly review and support expenditures reported in the SEFA can result in inaccurate reporting and non-compliance with laws and regulations. Repeat Finding - This is not a repeat finding. Recommendation - Internal controls should be designed to prevent, detect and correct errors and/or omissions in a timely manner. Without adequate controls, Corus cannot provide reasonable assurance that the SEFA is fairly presented. We recommend management to strengthen its internal control to ensure complete and accurate SEFA. Views of Responsible Officials - Corus management agrees with the findings and recommendations. The planned corrective actions are presented in Corus management’s corrective action plan attached as Appendix B to the Single Audit Report.

FY End: 2023-09-30
Corus International, Inc. and Affiliates
Compliance Requirement: H
2023-002 – Internal Control over Compliance and Compliance with Period of Performance Information on the Major Federal Program - Federal Agency: United States Agency for International Development (USAID) Program Name: USAID Foreign Assistance for Program Overseas Assistance Listing Number: 98.001 Award Number: Various Award Period: Various Criteria – A non-Federal entity may charge to the Federal award only allowable costs incurred during the period of performance and any costs i...

2023-002 – Internal Control over Compliance and Compliance with Period of Performance Information on the Major Federal Program - Federal Agency: United States Agency for International Development (USAID) Program Name: USAID Foreign Assistance for Program Overseas Assistance Listing Number: 98.001 Award Number: Various Award Period: Various Criteria – A non-Federal entity may charge to the Federal award only allowable costs incurred during the period of performance and any costs incurred before the Federal awarding agency or pass-through entity made the Federal award, only to the extent that they would have been allowable if incurred after the date of the Federal award and only with the written approval of the Federal awarding agency. Additionally, the Uniform Guidance in 2 CFR Section 200.344(b), states that unless the federal awarding agency or pass-through entity authorized an extension, a non-Federal entity must liquidate all financial obligations incurred under the Federal award not later than 120 calendar days after the end date of the period of performance as specified in the terms and conditions of the Federal award. Further, the Uniform Guidance in 2 CFR Section 200.303, Internal Controls, requires the non-federal entities receiving Federal awards (i.e., auditee management) establish and maintain internal control designed to reasonable ensure compliance with Federal statutes, regulations, and other terms and conditions of the Federal Award. The Uniform Guidance in 2 CFR Section 200.510 (b) states in part: “The auditee must also prepare a schedule of expenditures of Federal awards (SEFA) for the period covered by the auditee’s financial statements which must include the total Federal awards expended as determined in accordance with 2 CFR Section 200.502 Basis for determining Federal awards expended.” The SEFA must provide total Federal awards expended for each individual Federal program. Condition – During our testing, we identified one (1) out of 40 sampled transactions was incurred outside the period of performance. Corus did not obtain written approval from the federal awarding agency for the specific project. As a result, total expenditure totaling $106,400 was improperly included in the SEFA. Cause - The internal controls established for the review and reconciliation of the SEFA to the underlying accounting records were not consistently followed to ensure accurate charging of expenditures to the SEFA in the correct period. Questioned Costs - None. Context – This is a condition identified per review of Corus’ compliance with the specified requirements. Total expenditures of the specific project charged to the program was $106,400. These charges were removed from the SEFA presented for the year ended September 30, 2023. Effect - Failure to properly review and support expenditures reported in the SEFA can result in inaccurate reporting and non-compliance with laws and regulations. Repeat Finding - This is not a repeat finding. Recommendation - Internal controls should be designed to prevent, detect and correct errors and/or omissions in a timely manner. Without adequate controls, Corus cannot provide reasonable assurance that the SEFA is fairly presented. We recommend management to strengthen its internal control to ensure complete and accurate SEFA. Views of Responsible Officials - Corus management agrees with the findings and recommendations. The planned corrective actions are presented in Corus management’s corrective action plan attached as Appendix B to the Single Audit Report.

FY End: 2023-09-30
Corus International, Inc. and Affiliates
Compliance Requirement: H
2023-002 – Internal Control over Compliance and Compliance with Period of Performance Information on the Major Federal Program - Federal Agency: United States Agency for International Development (USAID) Program Name: USAID Foreign Assistance for Program Overseas Assistance Listing Number: 98.001 Award Number: Various Award Period: Various Criteria – A non-Federal entity may charge to the Federal award only allowable costs incurred during the period of performance and any costs i...

2023-002 – Internal Control over Compliance and Compliance with Period of Performance Information on the Major Federal Program - Federal Agency: United States Agency for International Development (USAID) Program Name: USAID Foreign Assistance for Program Overseas Assistance Listing Number: 98.001 Award Number: Various Award Period: Various Criteria – A non-Federal entity may charge to the Federal award only allowable costs incurred during the period of performance and any costs incurred before the Federal awarding agency or pass-through entity made the Federal award, only to the extent that they would have been allowable if incurred after the date of the Federal award and only with the written approval of the Federal awarding agency. Additionally, the Uniform Guidance in 2 CFR Section 200.344(b), states that unless the federal awarding agency or pass-through entity authorized an extension, a non-Federal entity must liquidate all financial obligations incurred under the Federal award not later than 120 calendar days after the end date of the period of performance as specified in the terms and conditions of the Federal award. Further, the Uniform Guidance in 2 CFR Section 200.303, Internal Controls, requires the non-federal entities receiving Federal awards (i.e., auditee management) establish and maintain internal control designed to reasonable ensure compliance with Federal statutes, regulations, and other terms and conditions of the Federal Award. The Uniform Guidance in 2 CFR Section 200.510 (b) states in part: “The auditee must also prepare a schedule of expenditures of Federal awards (SEFA) for the period covered by the auditee’s financial statements which must include the total Federal awards expended as determined in accordance with 2 CFR Section 200.502 Basis for determining Federal awards expended.” The SEFA must provide total Federal awards expended for each individual Federal program. Condition – During our testing, we identified one (1) out of 40 sampled transactions was incurred outside the period of performance. Corus did not obtain written approval from the federal awarding agency for the specific project. As a result, total expenditure totaling $106,400 was improperly included in the SEFA. Cause - The internal controls established for the review and reconciliation of the SEFA to the underlying accounting records were not consistently followed to ensure accurate charging of expenditures to the SEFA in the correct period. Questioned Costs - None. Context – This is a condition identified per review of Corus’ compliance with the specified requirements. Total expenditures of the specific project charged to the program was $106,400. These charges were removed from the SEFA presented for the year ended September 30, 2023. Effect - Failure to properly review and support expenditures reported in the SEFA can result in inaccurate reporting and non-compliance with laws and regulations. Repeat Finding - This is not a repeat finding. Recommendation - Internal controls should be designed to prevent, detect and correct errors and/or omissions in a timely manner. Without adequate controls, Corus cannot provide reasonable assurance that the SEFA is fairly presented. We recommend management to strengthen its internal control to ensure complete and accurate SEFA. Views of Responsible Officials - Corus management agrees with the findings and recommendations. The planned corrective actions are presented in Corus management’s corrective action plan attached as Appendix B to the Single Audit Report.

FY End: 2023-09-30
Corus International, Inc. and Affiliates
Compliance Requirement: H
2023-002 – Internal Control over Compliance and Compliance with Period of Performance Information on the Major Federal Program - Federal Agency: United States Agency for International Development (USAID) Program Name: USAID Foreign Assistance for Program Overseas Assistance Listing Number: 98.001 Award Number: Various Award Period: Various Criteria – A non-Federal entity may charge to the Federal award only allowable costs incurred during the period of performance and any costs i...

2023-002 – Internal Control over Compliance and Compliance with Period of Performance Information on the Major Federal Program - Federal Agency: United States Agency for International Development (USAID) Program Name: USAID Foreign Assistance for Program Overseas Assistance Listing Number: 98.001 Award Number: Various Award Period: Various Criteria – A non-Federal entity may charge to the Federal award only allowable costs incurred during the period of performance and any costs incurred before the Federal awarding agency or pass-through entity made the Federal award, only to the extent that they would have been allowable if incurred after the date of the Federal award and only with the written approval of the Federal awarding agency. Additionally, the Uniform Guidance in 2 CFR Section 200.344(b), states that unless the federal awarding agency or pass-through entity authorized an extension, a non-Federal entity must liquidate all financial obligations incurred under the Federal award not later than 120 calendar days after the end date of the period of performance as specified in the terms and conditions of the Federal award. Further, the Uniform Guidance in 2 CFR Section 200.303, Internal Controls, requires the non-federal entities receiving Federal awards (i.e., auditee management) establish and maintain internal control designed to reasonable ensure compliance with Federal statutes, regulations, and other terms and conditions of the Federal Award. The Uniform Guidance in 2 CFR Section 200.510 (b) states in part: “The auditee must also prepare a schedule of expenditures of Federal awards (SEFA) for the period covered by the auditee’s financial statements which must include the total Federal awards expended as determined in accordance with 2 CFR Section 200.502 Basis for determining Federal awards expended.” The SEFA must provide total Federal awards expended for each individual Federal program. Condition – During our testing, we identified one (1) out of 40 sampled transactions was incurred outside the period of performance. Corus did not obtain written approval from the federal awarding agency for the specific project. As a result, total expenditure totaling $106,400 was improperly included in the SEFA. Cause - The internal controls established for the review and reconciliation of the SEFA to the underlying accounting records were not consistently followed to ensure accurate charging of expenditures to the SEFA in the correct period. Questioned Costs - None. Context – This is a condition identified per review of Corus’ compliance with the specified requirements. Total expenditures of the specific project charged to the program was $106,400. These charges were removed from the SEFA presented for the year ended September 30, 2023. Effect - Failure to properly review and support expenditures reported in the SEFA can result in inaccurate reporting and non-compliance with laws and regulations. Repeat Finding - This is not a repeat finding. Recommendation - Internal controls should be designed to prevent, detect and correct errors and/or omissions in a timely manner. Without adequate controls, Corus cannot provide reasonable assurance that the SEFA is fairly presented. We recommend management to strengthen its internal control to ensure complete and accurate SEFA. Views of Responsible Officials - Corus management agrees with the findings and recommendations. The planned corrective actions are presented in Corus management’s corrective action plan attached as Appendix B to the Single Audit Report.

FY End: 2023-09-30
Corus International, Inc. and Affiliates
Compliance Requirement: H
2023-002 – Internal Control over Compliance and Compliance with Period of Performance Information on the Major Federal Program - Federal Agency: United States Agency for International Development (USAID) Program Name: USAID Foreign Assistance for Program Overseas Assistance Listing Number: 98.001 Award Number: Various Award Period: Various Criteria – A non-Federal entity may charge to the Federal award only allowable costs incurred during the period of performance and any costs i...

2023-002 – Internal Control over Compliance and Compliance with Period of Performance Information on the Major Federal Program - Federal Agency: United States Agency for International Development (USAID) Program Name: USAID Foreign Assistance for Program Overseas Assistance Listing Number: 98.001 Award Number: Various Award Period: Various Criteria – A non-Federal entity may charge to the Federal award only allowable costs incurred during the period of performance and any costs incurred before the Federal awarding agency or pass-through entity made the Federal award, only to the extent that they would have been allowable if incurred after the date of the Federal award and only with the written approval of the Federal awarding agency. Additionally, the Uniform Guidance in 2 CFR Section 200.344(b), states that unless the federal awarding agency or pass-through entity authorized an extension, a non-Federal entity must liquidate all financial obligations incurred under the Federal award not later than 120 calendar days after the end date of the period of performance as specified in the terms and conditions of the Federal award. Further, the Uniform Guidance in 2 CFR Section 200.303, Internal Controls, requires the non-federal entities receiving Federal awards (i.e., auditee management) establish and maintain internal control designed to reasonable ensure compliance with Federal statutes, regulations, and other terms and conditions of the Federal Award. The Uniform Guidance in 2 CFR Section 200.510 (b) states in part: “The auditee must also prepare a schedule of expenditures of Federal awards (SEFA) for the period covered by the auditee’s financial statements which must include the total Federal awards expended as determined in accordance with 2 CFR Section 200.502 Basis for determining Federal awards expended.” The SEFA must provide total Federal awards expended for each individual Federal program. Condition – During our testing, we identified one (1) out of 40 sampled transactions was incurred outside the period of performance. Corus did not obtain written approval from the federal awarding agency for the specific project. As a result, total expenditure totaling $106,400 was improperly included in the SEFA. Cause - The internal controls established for the review and reconciliation of the SEFA to the underlying accounting records were not consistently followed to ensure accurate charging of expenditures to the SEFA in the correct period. Questioned Costs - None. Context – This is a condition identified per review of Corus’ compliance with the specified requirements. Total expenditures of the specific project charged to the program was $106,400. These charges were removed from the SEFA presented for the year ended September 30, 2023. Effect - Failure to properly review and support expenditures reported in the SEFA can result in inaccurate reporting and non-compliance with laws and regulations. Repeat Finding - This is not a repeat finding. Recommendation - Internal controls should be designed to prevent, detect and correct errors and/or omissions in a timely manner. Without adequate controls, Corus cannot provide reasonable assurance that the SEFA is fairly presented. We recommend management to strengthen its internal control to ensure complete and accurate SEFA. Views of Responsible Officials - Corus management agrees with the findings and recommendations. The planned corrective actions are presented in Corus management’s corrective action plan attached as Appendix B to the Single Audit Report.

FY End: 2023-09-30
Corus International, Inc. and Affiliates
Compliance Requirement: H
2023-002 – Internal Control over Compliance and Compliance with Period of Performance Information on the Major Federal Program - Federal Agency: United States Agency for International Development (USAID) Program Name: USAID Foreign Assistance for Program Overseas Assistance Listing Number: 98.001 Award Number: Various Award Period: Various Criteria – A non-Federal entity may charge to the Federal award only allowable costs incurred during the period of performance and any costs i...

2023-002 – Internal Control over Compliance and Compliance with Period of Performance Information on the Major Federal Program - Federal Agency: United States Agency for International Development (USAID) Program Name: USAID Foreign Assistance for Program Overseas Assistance Listing Number: 98.001 Award Number: Various Award Period: Various Criteria – A non-Federal entity may charge to the Federal award only allowable costs incurred during the period of performance and any costs incurred before the Federal awarding agency or pass-through entity made the Federal award, only to the extent that they would have been allowable if incurred after the date of the Federal award and only with the written approval of the Federal awarding agency. Additionally, the Uniform Guidance in 2 CFR Section 200.344(b), states that unless the federal awarding agency or pass-through entity authorized an extension, a non-Federal entity must liquidate all financial obligations incurred under the Federal award not later than 120 calendar days after the end date of the period of performance as specified in the terms and conditions of the Federal award. Further, the Uniform Guidance in 2 CFR Section 200.303, Internal Controls, requires the non-federal entities receiving Federal awards (i.e., auditee management) establish and maintain internal control designed to reasonable ensure compliance with Federal statutes, regulations, and other terms and conditions of the Federal Award. The Uniform Guidance in 2 CFR Section 200.510 (b) states in part: “The auditee must also prepare a schedule of expenditures of Federal awards (SEFA) for the period covered by the auditee’s financial statements which must include the total Federal awards expended as determined in accordance with 2 CFR Section 200.502 Basis for determining Federal awards expended.” The SEFA must provide total Federal awards expended for each individual Federal program. Condition – During our testing, we identified one (1) out of 40 sampled transactions was incurred outside the period of performance. Corus did not obtain written approval from the federal awarding agency for the specific project. As a result, total expenditure totaling $106,400 was improperly included in the SEFA. Cause - The internal controls established for the review and reconciliation of the SEFA to the underlying accounting records were not consistently followed to ensure accurate charging of expenditures to the SEFA in the correct period. Questioned Costs - None. Context – This is a condition identified per review of Corus’ compliance with the specified requirements. Total expenditures of the specific project charged to the program was $106,400. These charges were removed from the SEFA presented for the year ended September 30, 2023. Effect - Failure to properly review and support expenditures reported in the SEFA can result in inaccurate reporting and non-compliance with laws and regulations. Repeat Finding - This is not a repeat finding. Recommendation - Internal controls should be designed to prevent, detect and correct errors and/or omissions in a timely manner. Without adequate controls, Corus cannot provide reasonable assurance that the SEFA is fairly presented. We recommend management to strengthen its internal control to ensure complete and accurate SEFA. Views of Responsible Officials - Corus management agrees with the findings and recommendations. The planned corrective actions are presented in Corus management’s corrective action plan attached as Appendix B to the Single Audit Report.

FY End: 2023-09-30
Corus International, Inc. and Affiliates
Compliance Requirement: H
2023-002 – Internal Control over Compliance and Compliance with Period of Performance Information on the Major Federal Program - Federal Agency: United States Agency for International Development (USAID) Program Name: USAID Foreign Assistance for Program Overseas Assistance Listing Number: 98.001 Award Number: Various Award Period: Various Criteria – A non-Federal entity may charge to the Federal award only allowable costs incurred during the period of performance and any costs i...

2023-002 – Internal Control over Compliance and Compliance with Period of Performance Information on the Major Federal Program - Federal Agency: United States Agency for International Development (USAID) Program Name: USAID Foreign Assistance for Program Overseas Assistance Listing Number: 98.001 Award Number: Various Award Period: Various Criteria – A non-Federal entity may charge to the Federal award only allowable costs incurred during the period of performance and any costs incurred before the Federal awarding agency or pass-through entity made the Federal award, only to the extent that they would have been allowable if incurred after the date of the Federal award and only with the written approval of the Federal awarding agency. Additionally, the Uniform Guidance in 2 CFR Section 200.344(b), states that unless the federal awarding agency or pass-through entity authorized an extension, a non-Federal entity must liquidate all financial obligations incurred under the Federal award not later than 120 calendar days after the end date of the period of performance as specified in the terms and conditions of the Federal award. Further, the Uniform Guidance in 2 CFR Section 200.303, Internal Controls, requires the non-federal entities receiving Federal awards (i.e., auditee management) establish and maintain internal control designed to reasonable ensure compliance with Federal statutes, regulations, and other terms and conditions of the Federal Award. The Uniform Guidance in 2 CFR Section 200.510 (b) states in part: “The auditee must also prepare a schedule of expenditures of Federal awards (SEFA) for the period covered by the auditee’s financial statements which must include the total Federal awards expended as determined in accordance with 2 CFR Section 200.502 Basis for determining Federal awards expended.” The SEFA must provide total Federal awards expended for each individual Federal program. Condition – During our testing, we identified one (1) out of 40 sampled transactions was incurred outside the period of performance. Corus did not obtain written approval from the federal awarding agency for the specific project. As a result, total expenditure totaling $106,400 was improperly included in the SEFA. Cause - The internal controls established for the review and reconciliation of the SEFA to the underlying accounting records were not consistently followed to ensure accurate charging of expenditures to the SEFA in the correct period. Questioned Costs - None. Context – This is a condition identified per review of Corus’ compliance with the specified requirements. Total expenditures of the specific project charged to the program was $106,400. These charges were removed from the SEFA presented for the year ended September 30, 2023. Effect - Failure to properly review and support expenditures reported in the SEFA can result in inaccurate reporting and non-compliance with laws and regulations. Repeat Finding - This is not a repeat finding. Recommendation - Internal controls should be designed to prevent, detect and correct errors and/or omissions in a timely manner. Without adequate controls, Corus cannot provide reasonable assurance that the SEFA is fairly presented. We recommend management to strengthen its internal control to ensure complete and accurate SEFA. Views of Responsible Officials - Corus management agrees with the findings and recommendations. The planned corrective actions are presented in Corus management’s corrective action plan attached as Appendix B to the Single Audit Report.

FY End: 2023-09-30
Corus International, Inc. and Affiliates
Compliance Requirement: H
2023-002 – Internal Control over Compliance and Compliance with Period of Performance Information on the Major Federal Program - Federal Agency: United States Agency for International Development (USAID) Program Name: USAID Foreign Assistance for Program Overseas Assistance Listing Number: 98.001 Award Number: Various Award Period: Various Criteria – A non-Federal entity may charge to the Federal award only allowable costs incurred during the period of performance and any costs i...

2023-002 – Internal Control over Compliance and Compliance with Period of Performance Information on the Major Federal Program - Federal Agency: United States Agency for International Development (USAID) Program Name: USAID Foreign Assistance for Program Overseas Assistance Listing Number: 98.001 Award Number: Various Award Period: Various Criteria – A non-Federal entity may charge to the Federal award only allowable costs incurred during the period of performance and any costs incurred before the Federal awarding agency or pass-through entity made the Federal award, only to the extent that they would have been allowable if incurred after the date of the Federal award and only with the written approval of the Federal awarding agency. Additionally, the Uniform Guidance in 2 CFR Section 200.344(b), states that unless the federal awarding agency or pass-through entity authorized an extension, a non-Federal entity must liquidate all financial obligations incurred under the Federal award not later than 120 calendar days after the end date of the period of performance as specified in the terms and conditions of the Federal award. Further, the Uniform Guidance in 2 CFR Section 200.303, Internal Controls, requires the non-federal entities receiving Federal awards (i.e., auditee management) establish and maintain internal control designed to reasonable ensure compliance with Federal statutes, regulations, and other terms and conditions of the Federal Award. The Uniform Guidance in 2 CFR Section 200.510 (b) states in part: “The auditee must also prepare a schedule of expenditures of Federal awards (SEFA) for the period covered by the auditee’s financial statements which must include the total Federal awards expended as determined in accordance with 2 CFR Section 200.502 Basis for determining Federal awards expended.” The SEFA must provide total Federal awards expended for each individual Federal program. Condition – During our testing, we identified one (1) out of 40 sampled transactions was incurred outside the period of performance. Corus did not obtain written approval from the federal awarding agency for the specific project. As a result, total expenditure totaling $106,400 was improperly included in the SEFA. Cause - The internal controls established for the review and reconciliation of the SEFA to the underlying accounting records were not consistently followed to ensure accurate charging of expenditures to the SEFA in the correct period. Questioned Costs - None. Context – This is a condition identified per review of Corus’ compliance with the specified requirements. Total expenditures of the specific project charged to the program was $106,400. These charges were removed from the SEFA presented for the year ended September 30, 2023. Effect - Failure to properly review and support expenditures reported in the SEFA can result in inaccurate reporting and non-compliance with laws and regulations. Repeat Finding - This is not a repeat finding. Recommendation - Internal controls should be designed to prevent, detect and correct errors and/or omissions in a timely manner. Without adequate controls, Corus cannot provide reasonable assurance that the SEFA is fairly presented. We recommend management to strengthen its internal control to ensure complete and accurate SEFA. Views of Responsible Officials - Corus management agrees with the findings and recommendations. The planned corrective actions are presented in Corus management’s corrective action plan attached as Appendix B to the Single Audit Report.

FY End: 2023-09-30
Memorial Health and Subsidiaries
Compliance Requirement: ABN
Finding 2023-001 Identification of the federal program: COVID-19 Disaster Grants – Public Assistance (Presidentially Declared Disasters) (FEMA) Federal Agency: Department of Homeland Security Pass-Through Entity: Illinois Emergency Management Agency Award ID: COVID-19 PA-05-IL-4489-PW-00786 Assistance Listing Number: 97.036 Criteria or specific requirement (including statutory, regulatory or other citation): 2 CFR Section 200.303 of the Uniform Guidance states the following regarding internal co...

Finding 2023-001 Identification of the federal program: COVID-19 Disaster Grants – Public Assistance (Presidentially Declared Disasters) (FEMA) Federal Agency: Department of Homeland Security Pass-Through Entity: Illinois Emergency Management Agency Award ID: COVID-19 PA-05-IL-4489-PW-00786 Assistance Listing Number: 97.036 Criteria or specific requirement (including statutory, regulatory or other citation): 2 CFR Section 200.303 of the Uniform Guidance states the following regarding internal control: “The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO).” Condition: Per inquiry of management, Memorial Health has processes and internal controls in place to ensure personnel expenses submitted to FEMA were allowable COVID-19-related expenses. These internal controls include ensuring completeness and accuracy of the expenses to ensure the expenses comply with the terms and conditions of the award. However, management did not retain documentation evidencing the performance of the internal controls. Cause: Management did not retain supporting documentation to evidence the performance of internal controls over the allowability of expenses charged to FEMA. Effect or potential effect: A lack of internal controls over the review and approval of FEMA expenditures could result in unallowable expenses being charged. Questioned costs: None Context: There was one project worksheet in 2023 and management did not maintain documentation over the review and approval over the expenses submitted to FEMA. We tested 40 transactions charged to the FEMA grant ($56,621). Management did not maintain documentation over the review and approval for all the 40 transactions submitted to FEMA. Total FEMA expenditures reported on the Schedule of Expenditures of Federal Awards for the year ended September 30, 2023 were $4,093,663. Identification as a repeat finding, if applicable: The finding is a repeat finding, finding 2022-004. Recommendation: Memorial Health should refine its internal control procedures and retain documentation evidencing that management reviewed expenses charged to FEMA to ensure the expenses are allowable. Views of responsible officials: Management agrees with the finding. The FEMA submission request was submitted by management in 2021, which occurred prior to management’s implementation of its corrective action plan to address finding 2022-004. Management performed an independent review of the expenditure for FEMA eligibility as part of an iterative review process with its FEMA consultants and FEMA representatives. This review was also documented in management’s representation on the FEMA online portal when the submission was made. However, management’s process did not include internal documentation to evidence an independent review had occurred prior to submission. The process has been corrected for any future FEMA submissions.

FY End: 2023-09-30
Memorial Health and Subsidiaries
Compliance Requirement: AB
Finding 2023-002 Identification of the federal program: Research and Development (R&D) Cluster Federal Agency: U.S. Department of Health and Human Services Assistance Listing: 93.399 Award Numbers: 5UG1CA189830-09, 5UG1CA189830-10 Criteria or specific requirement (including statutory, regulatory or other citation): 2 CFR Section 200.303 of the Uniform Guidance states the following regarding internal control: “The non-Federal entity must: (a) Establish and maintain effective internal control over...

Finding 2023-002 Identification of the federal program: Research and Development (R&D) Cluster Federal Agency: U.S. Department of Health and Human Services Assistance Listing: 93.399 Award Numbers: 5UG1CA189830-09, 5UG1CA189830-10 Criteria or specific requirement (including statutory, regulatory or other citation): 2 CFR Section 200.303 of the Uniform Guidance states the following regarding internal control: “The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO).” 2 CFR Section 200.431 of the Uniform Guidance states: “Compensation—fringe benefits. (a) Fringe benefits are allowances and services provided by employers to their employees as compensation in addition to regular salaries and wages. Fringe benefits include, but are not limited to, the costs of leave (vacation, family-related, sick or military), employee insurance, pensions, and unemployment benefit plans. Except as provided elsewhere in these principles, the costs of fringe benefits are allowable provided that the benefits are reasonable and are required by law, non-Federal entity-employee agreement, or an established policy of the non-Federal entity.” Condition: Management calculated fringe expense charged to the R&D Cluster using the incorrect fringe cost rate. Cause: Management’s internal controls over the review and approval of fringe expense charged to the federal awards within the R&D Cluster were not sufficiently precise to identify that the incorrect fringe cost rate was used to calculate benefits charged. Effect or potential effect: Fringe expense charged to the R&D Cluster federal awards was overstated. Questioned costs: Questioned costs represent the difference between fringe expense calculated at the approved fringe rate versus the fringe rate used by management. Correct Amount to Be Recorded Original Amount Recorded Questioned Costs Correct Rate: 30% Incorrect Rate: 33% Fringe: $303,201 Fringe: $333,521 $ 30,320 AL # 93.399 NIH Award 5UG1CA189830-09: $25,688 AL # 93.399 NIH Award 5UG1CA189830-10: $4,632 Context: Management calculated and approved a fringe rate for 2023 of 30%; however, the fringe expense calculation used a fringe rate of 33%. We selected 13 fringe transactions to test compliance, and we identified that 100% of our selections were exceptions as the incorrect rate was used to calculate fringe. The total R&D Cluster expenditures reported on the Schedule of Expenditures of Federal Awards are $3,960,439 for the year ended September 30, 2023, which includes fringe costs of $303,201, which represents 7.7% of total R&D Cluster expenditures. Identification as a repeat finding, if applicable: Not a repeat finding. Recommendation: Management should design and implement effective internal controls over the review and approval of the monthly fringe calculation. Views of responsible officials: Management agrees with the finding. Management calculated and approved an annual fringe benefit rate to be used for its fiscal year 2023, but failed to update the rate on its internal calculation during fiscal year 2023 from the prior year rate. It was ultimately identified by management in early fiscal year 2024. Management has confirmed the $30,320 of questioned cost arising from the overstatement of fringe benefits would easily be replaced by unreimbursed grant-eligible direct labor costs. Therefore, management contends it still earned the grant awarded funds, despite the questioned costs. Additionally, management has provided re-education to grant personnel preparing and reviewing calculations to ensure an adequate understanding of the key calculation elements are identified and validated for the grant year.

FY End: 2023-09-30
Memorial Health and Subsidiaries
Compliance Requirement: AB
Finding 2023-002 Identification of the federal program: Research and Development (R&D) Cluster Federal Agency: U.S. Department of Health and Human Services Assistance Listing: 93.399 Award Numbers: 5UG1CA189830-09, 5UG1CA189830-10 Criteria or specific requirement (including statutory, regulatory or other citation): 2 CFR Section 200.303 of the Uniform Guidance states the following regarding internal control: “The non-Federal entity must: (a) Establish and maintain effective internal control over...

Finding 2023-002 Identification of the federal program: Research and Development (R&D) Cluster Federal Agency: U.S. Department of Health and Human Services Assistance Listing: 93.399 Award Numbers: 5UG1CA189830-09, 5UG1CA189830-10 Criteria or specific requirement (including statutory, regulatory or other citation): 2 CFR Section 200.303 of the Uniform Guidance states the following regarding internal control: “The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO).” 2 CFR Section 200.431 of the Uniform Guidance states: “Compensation—fringe benefits. (a) Fringe benefits are allowances and services provided by employers to their employees as compensation in addition to regular salaries and wages. Fringe benefits include, but are not limited to, the costs of leave (vacation, family-related, sick or military), employee insurance, pensions, and unemployment benefit plans. Except as provided elsewhere in these principles, the costs of fringe benefits are allowable provided that the benefits are reasonable and are required by law, non-Federal entity-employee agreement, or an established policy of the non-Federal entity.” Condition: Management calculated fringe expense charged to the R&D Cluster using the incorrect fringe cost rate. Cause: Management’s internal controls over the review and approval of fringe expense charged to the federal awards within the R&D Cluster were not sufficiently precise to identify that the incorrect fringe cost rate was used to calculate benefits charged. Effect or potential effect: Fringe expense charged to the R&D Cluster federal awards was overstated. Questioned costs: Questioned costs represent the difference between fringe expense calculated at the approved fringe rate versus the fringe rate used by management. Correct Amount to Be Recorded Original Amount Recorded Questioned Costs Correct Rate: 30% Incorrect Rate: 33% Fringe: $303,201 Fringe: $333,521 $ 30,320 AL # 93.399 NIH Award 5UG1CA189830-09: $25,688 AL # 93.399 NIH Award 5UG1CA189830-10: $4,632 Context: Management calculated and approved a fringe rate for 2023 of 30%; however, the fringe expense calculation used a fringe rate of 33%. We selected 13 fringe transactions to test compliance, and we identified that 100% of our selections were exceptions as the incorrect rate was used to calculate fringe. The total R&D Cluster expenditures reported on the Schedule of Expenditures of Federal Awards are $3,960,439 for the year ended September 30, 2023, which includes fringe costs of $303,201, which represents 7.7% of total R&D Cluster expenditures. Identification as a repeat finding, if applicable: Not a repeat finding. Recommendation: Management should design and implement effective internal controls over the review and approval of the monthly fringe calculation. Views of responsible officials: Management agrees with the finding. Management calculated and approved an annual fringe benefit rate to be used for its fiscal year 2023, but failed to update the rate on its internal calculation during fiscal year 2023 from the prior year rate. It was ultimately identified by management in early fiscal year 2024. Management has confirmed the $30,320 of questioned cost arising from the overstatement of fringe benefits would easily be replaced by unreimbursed grant-eligible direct labor costs. Therefore, management contends it still earned the grant awarded funds, despite the questioned costs. Additionally, management has provided re-education to grant personnel preparing and reviewing calculations to ensure an adequate understanding of the key calculation elements are identified and validated for the grant year.

FY End: 2023-09-30
North Mississippi Health Services, Inc.
Compliance Requirement: AB
(a) Criteria or Requirement 2 CFR 200.303 requires non-federal entities receiving federal awards to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations, and program compliance requirements. Effective internal control should include procedures to ensure federal expenditures are accurately and completely reported on the SEFA. (b) Condition Found The System did not have adequate controls related to determining allowability of expenditures...

(a) Criteria or Requirement 2 CFR 200.303 requires non-federal entities receiving federal awards to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations, and program compliance requirements. Effective internal control should include procedures to ensure federal expenditures are accurately and completely reported on the SEFA. (b) Condition Found The System did not have adequate controls related to determining allowability of expenditures for the Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution Grant. Our testing identified one charge within the population that had been charged incorrectly to the federal program. This charge was for government contract labor totaling $126,313 that was determined to be an unallowable expenditure that should have been removed prior to submission to the federal agency. In addition, during our testwork over expenses, we selected for testing a sample of 40 expenses charged to the program. One of our samples related to COVID lab tests was identified with a cost that should have been zero as the tests were voided and the vendor invoice reflected a zero balance; however, a standard test was inappropriately charged to the federal program in excess of the vendor invoice. Further, one sample was identified as having the incorrect price applied to the cost due to the drug being purchased from a different vendor, which had a lower price. This resulted in a higher price being charged to the federal program. The resulting impact of the above two items was $508 inappropriately charged to the federal program. In addition, the System was unable to provide evidence of management review and approval for three of the 40 expenses sampled. These three disbursements were for allowable costs under the terms and conditions of the program. (c) Cause The System’s review process in place over the recording of these costs did not operate effectively to prevent unallowable charges and inaccurate amounts from being submitted for reimbursement by the federal agency. The System was unable to provide evidence of certain management reviews and approvals due to system limitations that only maintain electronic approvals (via email) for 365 days. (d) Effect Federal funds were expended for unallowable purposes or for inaccurate amounts and evidence of the effective operation of management review controls was not maintained in accordance with Federal requirements. (e) Questioned Cost Expenditures related to contract labor and other costs of $126,821. (f) Statistical Sample The sample was not intended to be, and was not, a statistically valid sample. (g) Repeat Finding in the Prior Year Not a repeat finding (h) Recommendation We recommend that the System strengthen controls over the management review process to prevent unallowable costs and inaccurate amounts from being charged to Federal programs. (i) View of Responsible Officials The Monthly Cost Capture detail for the Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (ALN No. 93.498) reporting was developed to appropriately track expenditures that qualified under the grant. A wide variety of costs from across the company were charged to a COVID cost department. These costs originated in a variety of ways. While the overall amounts were tracked and reviewed, a comprehensive 100% review was not conducted. As a result, the government labor expenditure and the cost for a COVID lab specimen that was never billed were inappropriately included. The price per unit from a vendor we did not buy the specific drug from was also used when the cost for that drug was allocated to the COVID department. Furthermore, there were three Morris and Dickson invoices that were submitted to AP electronically approving payment via email, but the emails automatically delete after 365 days.

FY End: 2023-09-30
Wagoner Hospital Authority, An Oklahoma Trust, D/b/a Wagoner Community Hospital
Compliance Requirement: ABL
Department of Health and Human Services Federal Assistance Listing #93.498 COVID-19 Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution Applicable Federal Award Number and Year – Period 1 TIN #352276246 Activities Allowed or Unallowed, Allowable Costs/Cost Principles, and Reporting Material Weakness in Internal Control Over Compliance and Material Noncompliance Criteria: 2 CFR 200.303(a) establishes that the auditee must establish and maintain effective internal control over t...

Department of Health and Human Services Federal Assistance Listing #93.498 COVID-19 Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution Applicable Federal Award Number and Year – Period 1 TIN #352276246 Activities Allowed or Unallowed, Allowable Costs/Cost Principles, and Reporting Material Weakness in Internal Control Over Compliance and Material Noncompliance Criteria: 2 CFR 200.303(a) establishes that the auditee must establish and maintain effective internal control over the federal award that provides assurance that the entity is managing the federal award in compliance with federal statutes, regulations, and conditions of the federal award. Condition: The Authority claimed expenses that were previously claimed and reported on the Period 1 report to the Department of Health and Human Services (HHS). Cause: The Authority misunderstood the reporting requirements on the Period 4 report to HHS and believed the section related to expenses incurred required all expenses for the program from inception, including those claimed on previous reports, be included. Effect: The Authority claimed and reported expenses that were previously claimed and reported in Period 1 report to HHS. Accordingly, the Authority technically claimed expenses already reimbursed by the program and the Period 4 report to HHS contained material errors. Questioned Costs: None reported. While $502,982 of expenses were claimed on the Period 1 report to HHS, the Authority reported excess lost revenues totaling $4,674,489. The Authority intended to utilize available lost revenues when reporting. Context: All key line items were tested on the Period 4 report to HHS. The total error was identified when reconciling the expense details to the Period 4 report to HHS. No sampling was utilized related to this finding. Repeat Finding from Prior Years: No Recommendation: We recommend the Authority modify internal control policies to ensure there is an understanding of reporting requirements to ensure that reports are accurate and amounts are not inadvertently claimed that are considered unallowable. Views of Responsible Officials: Management agrees with the finding.

FY End: 2023-09-30
Community Loan Fund of New Jersey, Inc.
Compliance Requirement: I
2023 001 Procurement – Suspension and Debarment U.S. Department of Treasury Community Development Financial Institutions Bond Guarantee Program (ALN 21.014) Statistically Valid Sample: No, and it was not intended to be. Prior Year Finding: Not a repeat finding. Finding Type: Significant deficiency and noncompliance Criteria Prior to entering into subawards and contracts with award funds, recipients must verify that such contractors and subrecipients are not suspended, debarred, or otherwise ...

2023 001 Procurement – Suspension and Debarment U.S. Department of Treasury Community Development Financial Institutions Bond Guarantee Program (ALN 21.014) Statistically Valid Sample: No, and it was not intended to be. Prior Year Finding: Not a repeat finding. Finding Type: Significant deficiency and noncompliance Criteria Prior to entering into subawards and contracts with award funds, recipients must verify that such contractors and subrecipients are not suspended, debarred, or otherwise excluded pursuant to 31 CFR section 19.300. Additionally, 2 CFR 200.303 (a) states that non federal entities must establish and maintain effective internal control over federal awards that provide reasonable assurance that the non federal entity is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award. Condition and Context During our testwork over suspension and debarment, we noted the following as of the year ended September 30, 2023, for 1 of 10 items selected for testwork, we found no evidence that a suspension and debarment independent status search of SAM.gov was performed. However, the entity was able to obtain certification from the recipient through the signed loan agreement that the entity was registered in SAM.gov and in good standing. Cause The Organization did not perform an independent status search of the recipient to ensure that it was not suspended or debarred. Effect The funds could be paid to an entity that has been suspended or debarred and costs paid to the entity would be unallowable. Questioned Costs Cannot be determined Recommendation We recommend that the Organization strengthen its process to ensure that all recipients have independent status search whether they are suspended or debarred prior to entering into a loan agreement. Views of Responsible Officials A process and checklist will be put in place to ensure the independent status search is performed on recipients when a payment is made. The process and checklist will include a verification by someone other than the person preparing the request.

FY End: 2023-09-30
State of Michigan
Compliance Requirement: ABN
FINDING 2023-002 Bridges Security Management and Access Controls* See Schedule of Findings and Questioned Costs for chart/table. Condition MDHHS had not established effective security management and access controls over Bridges users. We noted: a. MDHHS did not maintain documentation for 30 (75%) of the 40 sampled Bridges incompatible role exception requests. Of the 10 forms received, we noted MDHHS did not properly approve 6 forms prior to granting the exception requests. b. MDHHS did not m...

FINDING 2023-002 Bridges Security Management and Access Controls* See Schedule of Findings and Questioned Costs for chart/table. Condition MDHHS had not established effective security management and access controls over Bridges users. We noted: a. MDHHS did not maintain documentation for 30 (75%) of the 40 sampled Bridges incompatible role exception requests. Of the 10 forms received, we noted MDHHS did not properly approve 6 forms prior to granting the exception requests. b. MDHHS did not maintain documentation for 21 (26%) of 80 sampled local office security monitoring reports. Also, MDHHS did not complete timely reviews for 2 (3%) of 59 sampled security monitoring reports. c. MDHHS did not maintain documentation for 1 (3%) of the 40 sampled Bridges application security agreements. Of the 39 forms received, we noted MDHHS did not properly approve 10 (26%) forms prior to granting access to Bridges. d. MDHHS did not monitor non-local office Bridges user accounts for compliance with account management requirements semiannually for privileged users or annually for all other users. e. MDHHS did not maintain documentation for 9 (45%) of the 20 sampled local office high risk Bridges transaction monitoring reports. Of the 11 reports received, MDHHS did not complete the review timely or did not document its review date for 3 (27%) of the reports. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards.   According to State of Michigan Administrative Guide to State Government policy 1340.00, security controls must be implemented to protect State of Michigan information from unauthorized access, use, disclosure, modification, destruction, or denial and to ensure confidentiality, integrity, and availability of State of Michigan information. State of Michigan (SOM) Technical Standard 1340.00.020.01 requires agencies to implement and document baseline controls ensuring users are only granted access which is necessary to accomplish assigned tasks in accordance with roles and responsibilities of their job functions. The Standard also requires separation of duties must be implemented through assigned information system access authorizations and accounts should be reviewed for compliance with account management requirements semiannually for privileged accounts* and annually for all other accounts. In addition, the GAO's FISCAM recommends compensating controls, such as additional monitoring and supervision, should be in place where segregation of duties'* conflicts exist. Cause For parts a., c., and d., MDHHS's internal control and monitoring activities were not sufficient to ensure all appropriate parties adhered to established policies and procedures. For parts b. and e., MDHHS's internal control and monitoring activities need improvement to ensure all appropriate parties maintain and timely complete their review of the local office security monitoring reports and high-risk Bridges transaction monitoring reports. Effect We consider these issues to be a material weakness because, without effective security management and access controls, individuals may obtain unauthorized or inappropriate access to Bridges. As a result, an increased risk exists that MDHHS cannot ensure the security of the Bridges application and data used to help determine eligibility and benefit levels for the SNAP Cluster, Pandemic Electronic Benefits Transfer (P-EBT) Food Benefits, CCDF Cluster, Medicaid Cluster, Temporary Assistance for Needy Families (TANF), Refugee and Entrant Assistance State/Replacement Designee Administered Programs (REAP), Low-Income Home Energy Assistance Program (LIHEAP), and Children's Health Insurance Program (CHIP). Known Questioned Costs None. Recommendation We recommend MDHHS establish effective security management and access controls over Bridges users. Management Views MDHHS agrees with the finding.

FY End: 2023-09-30
State of Michigan
Compliance Requirement: ABN
FINDING 2023-003 Bridges Change Management Process See Schedule of Findings and Questioned Costs for chart/table. Condition MDHHS did not fully implement an effective change management process over Bridges. Our review disclosed MDHHS did not document post-implementation approvals for 3 (12%) of 25 sampled Bridges change records.   Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provide...

FINDING 2023-003 Bridges Change Management Process See Schedule of Findings and Questioned Costs for chart/table. Condition MDHHS did not fully implement an effective change management process over Bridges. Our review disclosed MDHHS did not document post-implementation approvals for 3 (12%) of 25 sampled Bridges change records.   Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. SOM Technical Standard 1340.00.060.04 requires the business owner perform post-implementation validation. SOM Technical Procedure 1340.00.060.04.01 requires each test type to have its own set of documentation. State of Michigan Administrative Guide to State Government policy 1340.00 requires approved personnel to adequately manage the configuration* of the State's systems, such as retaining previous system configurations, configuring approved devices for high-risk areas, and tracking and documenting system changes. Cause MDHHS informed us it did not always follow established processes for documenting testing and business owner approvals. Effect Without an effective change management process, individuals may make unauthorized or inappropriate changes to Bridges. As a result, an increased risk exists that MDHHS cannot ensure Bridges is configured and operating securely and as intended. Known Questioned Costs None. Recommendation We recommend MDHHS fully implement an effective change management process over Bridges. Management Views MDHHS agrees with the finding.

FY End: 2023-09-30
State of Michigan
Compliance Requirement: ABN
FINDING 2023-002 Bridges Security Management and Access Controls* See Schedule of Findings and Questioned Costs for chart/table. Condition MDHHS had not established effective security management and access controls over Bridges users. We noted: a. MDHHS did not maintain documentation for 30 (75%) of the 40 sampled Bridges incompatible role exception requests. Of the 10 forms received, we noted MDHHS did not properly approve 6 forms prior to granting the exception requests. b. MDHHS did not m...

FINDING 2023-002 Bridges Security Management and Access Controls* See Schedule of Findings and Questioned Costs for chart/table. Condition MDHHS had not established effective security management and access controls over Bridges users. We noted: a. MDHHS did not maintain documentation for 30 (75%) of the 40 sampled Bridges incompatible role exception requests. Of the 10 forms received, we noted MDHHS did not properly approve 6 forms prior to granting the exception requests. b. MDHHS did not maintain documentation for 21 (26%) of 80 sampled local office security monitoring reports. Also, MDHHS did not complete timely reviews for 2 (3%) of 59 sampled security monitoring reports. c. MDHHS did not maintain documentation for 1 (3%) of the 40 sampled Bridges application security agreements. Of the 39 forms received, we noted MDHHS did not properly approve 10 (26%) forms prior to granting access to Bridges. d. MDHHS did not monitor non-local office Bridges user accounts for compliance with account management requirements semiannually for privileged users or annually for all other users. e. MDHHS did not maintain documentation for 9 (45%) of the 20 sampled local office high risk Bridges transaction monitoring reports. Of the 11 reports received, MDHHS did not complete the review timely or did not document its review date for 3 (27%) of the reports. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards.   According to State of Michigan Administrative Guide to State Government policy 1340.00, security controls must be implemented to protect State of Michigan information from unauthorized access, use, disclosure, modification, destruction, or denial and to ensure confidentiality, integrity, and availability of State of Michigan information. State of Michigan (SOM) Technical Standard 1340.00.020.01 requires agencies to implement and document baseline controls ensuring users are only granted access which is necessary to accomplish assigned tasks in accordance with roles and responsibilities of their job functions. The Standard also requires separation of duties must be implemented through assigned information system access authorizations and accounts should be reviewed for compliance with account management requirements semiannually for privileged accounts* and annually for all other accounts. In addition, the GAO's FISCAM recommends compensating controls, such as additional monitoring and supervision, should be in place where segregation of duties'* conflicts exist. Cause For parts a., c., and d., MDHHS's internal control and monitoring activities were not sufficient to ensure all appropriate parties adhered to established policies and procedures. For parts b. and e., MDHHS's internal control and monitoring activities need improvement to ensure all appropriate parties maintain and timely complete their review of the local office security monitoring reports and high-risk Bridges transaction monitoring reports. Effect We consider these issues to be a material weakness because, without effective security management and access controls, individuals may obtain unauthorized or inappropriate access to Bridges. As a result, an increased risk exists that MDHHS cannot ensure the security of the Bridges application and data used to help determine eligibility and benefit levels for the SNAP Cluster, Pandemic Electronic Benefits Transfer (P-EBT) Food Benefits, CCDF Cluster, Medicaid Cluster, Temporary Assistance for Needy Families (TANF), Refugee and Entrant Assistance State/Replacement Designee Administered Programs (REAP), Low-Income Home Energy Assistance Program (LIHEAP), and Children's Health Insurance Program (CHIP). Known Questioned Costs None. Recommendation We recommend MDHHS establish effective security management and access controls over Bridges users. Management Views MDHHS agrees with the finding.

FY End: 2023-09-30
State of Michigan
Compliance Requirement: ABN
FINDING 2023-003 Bridges Change Management Process See Schedule of Findings and Questioned Costs for chart/table. Condition MDHHS did not fully implement an effective change management process over Bridges. Our review disclosed MDHHS did not document post-implementation approvals for 3 (12%) of 25 sampled Bridges change records.   Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provide...

FINDING 2023-003 Bridges Change Management Process See Schedule of Findings and Questioned Costs for chart/table. Condition MDHHS did not fully implement an effective change management process over Bridges. Our review disclosed MDHHS did not document post-implementation approvals for 3 (12%) of 25 sampled Bridges change records.   Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. SOM Technical Standard 1340.00.060.04 requires the business owner perform post-implementation validation. SOM Technical Procedure 1340.00.060.04.01 requires each test type to have its own set of documentation. State of Michigan Administrative Guide to State Government policy 1340.00 requires approved personnel to adequately manage the configuration* of the State's systems, such as retaining previous system configurations, configuring approved devices for high-risk areas, and tracking and documenting system changes. Cause MDHHS informed us it did not always follow established processes for documenting testing and business owner approvals. Effect Without an effective change management process, individuals may make unauthorized or inappropriate changes to Bridges. As a result, an increased risk exists that MDHHS cannot ensure Bridges is configured and operating securely and as intended. Known Questioned Costs None. Recommendation We recommend MDHHS fully implement an effective change management process over Bridges. Management Views MDHHS agrees with the finding.

FY End: 2023-09-30
State of Michigan
Compliance Requirement: ABN
FINDING 2023-002 Bridges Security Management and Access Controls* See Schedule of Findings and Questioned Costs for chart/table. Condition MDHHS had not established effective security management and access controls over Bridges users. We noted: a. MDHHS did not maintain documentation for 30 (75%) of the 40 sampled Bridges incompatible role exception requests. Of the 10 forms received, we noted MDHHS did not properly approve 6 forms prior to granting the exception requests. b. MDHHS did not m...

FINDING 2023-002 Bridges Security Management and Access Controls* See Schedule of Findings and Questioned Costs for chart/table. Condition MDHHS had not established effective security management and access controls over Bridges users. We noted: a. MDHHS did not maintain documentation for 30 (75%) of the 40 sampled Bridges incompatible role exception requests. Of the 10 forms received, we noted MDHHS did not properly approve 6 forms prior to granting the exception requests. b. MDHHS did not maintain documentation for 21 (26%) of 80 sampled local office security monitoring reports. Also, MDHHS did not complete timely reviews for 2 (3%) of 59 sampled security monitoring reports. c. MDHHS did not maintain documentation for 1 (3%) of the 40 sampled Bridges application security agreements. Of the 39 forms received, we noted MDHHS did not properly approve 10 (26%) forms prior to granting access to Bridges. d. MDHHS did not monitor non-local office Bridges user accounts for compliance with account management requirements semiannually for privileged users or annually for all other users. e. MDHHS did not maintain documentation for 9 (45%) of the 20 sampled local office high risk Bridges transaction monitoring reports. Of the 11 reports received, MDHHS did not complete the review timely or did not document its review date for 3 (27%) of the reports. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards.   According to State of Michigan Administrative Guide to State Government policy 1340.00, security controls must be implemented to protect State of Michigan information from unauthorized access, use, disclosure, modification, destruction, or denial and to ensure confidentiality, integrity, and availability of State of Michigan information. State of Michigan (SOM) Technical Standard 1340.00.020.01 requires agencies to implement and document baseline controls ensuring users are only granted access which is necessary to accomplish assigned tasks in accordance with roles and responsibilities of their job functions. The Standard also requires separation of duties must be implemented through assigned information system access authorizations and accounts should be reviewed for compliance with account management requirements semiannually for privileged accounts* and annually for all other accounts. In addition, the GAO's FISCAM recommends compensating controls, such as additional monitoring and supervision, should be in place where segregation of duties'* conflicts exist. Cause For parts a., c., and d., MDHHS's internal control and monitoring activities were not sufficient to ensure all appropriate parties adhered to established policies and procedures. For parts b. and e., MDHHS's internal control and monitoring activities need improvement to ensure all appropriate parties maintain and timely complete their review of the local office security monitoring reports and high-risk Bridges transaction monitoring reports. Effect We consider these issues to be a material weakness because, without effective security management and access controls, individuals may obtain unauthorized or inappropriate access to Bridges. As a result, an increased risk exists that MDHHS cannot ensure the security of the Bridges application and data used to help determine eligibility and benefit levels for the SNAP Cluster, Pandemic Electronic Benefits Transfer (P-EBT) Food Benefits, CCDF Cluster, Medicaid Cluster, Temporary Assistance for Needy Families (TANF), Refugee and Entrant Assistance State/Replacement Designee Administered Programs (REAP), Low-Income Home Energy Assistance Program (LIHEAP), and Children's Health Insurance Program (CHIP). Known Questioned Costs None. Recommendation We recommend MDHHS establish effective security management and access controls over Bridges users. Management Views MDHHS agrees with the finding.

FY End: 2023-09-30
State of Michigan
Compliance Requirement: ABN
FINDING 2023-003 Bridges Change Management Process See Schedule of Findings and Questioned Costs for chart/table. Condition MDHHS did not fully implement an effective change management process over Bridges. Our review disclosed MDHHS did not document post-implementation approvals for 3 (12%) of 25 sampled Bridges change records.   Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provide...

FINDING 2023-003 Bridges Change Management Process See Schedule of Findings and Questioned Costs for chart/table. Condition MDHHS did not fully implement an effective change management process over Bridges. Our review disclosed MDHHS did not document post-implementation approvals for 3 (12%) of 25 sampled Bridges change records.   Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. SOM Technical Standard 1340.00.060.04 requires the business owner perform post-implementation validation. SOM Technical Procedure 1340.00.060.04.01 requires each test type to have its own set of documentation. State of Michigan Administrative Guide to State Government policy 1340.00 requires approved personnel to adequately manage the configuration* of the State's systems, such as retaining previous system configurations, configuring approved devices for high-risk areas, and tracking and documenting system changes. Cause MDHHS informed us it did not always follow established processes for documenting testing and business owner approvals. Effect Without an effective change management process, individuals may make unauthorized or inappropriate changes to Bridges. As a result, an increased risk exists that MDHHS cannot ensure Bridges is configured and operating securely and as intended. Known Questioned Costs None. Recommendation We recommend MDHHS fully implement an effective change management process over Bridges. Management Views MDHHS agrees with the finding.

FY End: 2023-09-30
State of Michigan
Compliance Requirement: ABELN
FINDING 2023-006 MDE, Security Management and Access Controls See Schedule of Findings and Questioned Costs for chart/table. Condition The Michigan Department of Education (MDE) did not fully establish effective security management and access controls over Michigan Electronic Grants System Plus (MEGS+); Grant Electronic Monitoring System/Michigan Administrative Review System (GEMS/MARS); Michigan Nutrition Data (MiND); and Next Generation Grant, Application and Cash Management System (NexSys). ...

FINDING 2023-006 MDE, Security Management and Access Controls See Schedule of Findings and Questioned Costs for chart/table. Condition The Michigan Department of Education (MDE) did not fully establish effective security management and access controls over Michigan Electronic Grants System Plus (MEGS+); Grant Electronic Monitoring System/Michigan Administrative Review System (GEMS/MARS); Michigan Nutrition Data (MiND); and Next Generation Grant, Application and Cash Management System (NexSys). We noted: a. MDE did not consistently follow its established policies and procedures over the granting of access to MiND and NexSys: (1) MDE did not maintain documentation to support the appropriate individual approved the system role for 6 (24%) of 25 sampled MiND users. (2) Of the 47 sampled NexSys forms reviewed, 19 forms related to replacing an existing user and we noted for 1 (5%) of these users MDE did not deactivate the existing users' accounts. Also, MDE did not obtain proper approval prior to granting access for 1 of 6 sampled NexSys grant unit users. In addition, MDE did not properly authorize 2 of 9 sampled NexSys users with incompatible roles. b. MDE did not review all privileged accounts on a semiannual basis for MEGS+ and NexSys. c. MDE did not fully implement an effective annual recertification process of non-privileged accounts: (1) MDE did not review all non-privileged internal accounts on an annual basis for MEGS+, GEMS/MARS, and NexSys. (2) MDE did not always ensure the subrecipients* certified their non-privileged external accounts on an annual basis. Our results are summarized in the following table: See Schedule of Findings and Questioned Costs for chart/table. d. MDE did not disable inactive MiND and NexSys users who had not accessed the applications in over 18 months as of September 30, 2023 as noted below: See Schedule of Findings and Questioned Costs for chart/table. e. MDE did not timely review 2 of the 4 quarterly MEGS+ high-risk transactionsʹ review sheets. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. According to State of Michigan Administrative Guide to State Government policy 1340.00, security controls must be implemented to protect State of Michigan information from unauthorized access, use, disclosure, modification, destruction, or denial and to ensure confidentiality, integrity, and availability of State of Michigan information. SOM Technical Standard 1340.00.020.01 requires agencies to implement and document baseline controls ensuring users are only granted access which is necessary to accomplish assigned tasks in accordance with roles and responsibilities of their job functions. The Standard also requires separation of duties must be implemented through assigned information system access authorizations, accounts should be reviewed for compliance with account management requirements semiannually for privileged accounts and annually for all other accounts, and the information system to automatically disable inactive user accounts after 60 days. However, MDE requested and received an approved exception, which allows user accounts to not be disabled until after 18 months. MDE is responsible for granting access to certain user roles within each system. MDE's process required a security access form to be completed and signed by an authorized official prior to access being granted. MDE's process also requires quarterly reviews of MEGS+ high risk transactions. Cause MDE's internal control and monitoring activities were not sufficient to ensure all appropriate parties adhered to established policies. Effect Without effective user access controls, individuals may obtain unauthorized or inappropriate access to MDE's systems. Known Questioned Costs None.   Recommendation We recommend MDE fully establish effective security management and access controls over MEGS+, GEMS/MARS, MiND, and NexSys. Management Views MDE agrees with the finding.

FY End: 2023-09-30
State of Michigan
Compliance Requirement: ABELN
FINDING 2023-007 MDE, Change Management Process See Schedule of Findings and Questioned Costs for chart/table. Condition MDE did not fully implement an effective change management process over MiND and NexSys. We sampled 24 MiND and 10 NexSys change deployments and noted: See Schedule of Findings and Questioned Costs for chart/table. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that pro...

FINDING 2023-007 MDE, Change Management Process See Schedule of Findings and Questioned Costs for chart/table. Condition MDE did not fully implement an effective change management process over MiND and NexSys. We sampled 24 MiND and 10 NexSys change deployments and noted: See Schedule of Findings and Questioned Costs for chart/table. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. SOM Technical Standard 1340.00.060.04 requires the business owner to authorize the change to be developed and perform post-implementation validation. SOM Technical Procedure 1340.00.060.04.01 requires each test type to have its own set of documentation. State of Michigan Administrative Guide to State Government policy 1340.00 requires approved personnel to adequately manage the configuration of the State's systems, such as retaining previous system configurations, configuring approved devices for high-risk areas, and tracking and documenting system changes. Cause MDE informed us that because of an oversight, it did not document the testing results and close the work items. Effect Without an effective change management process, individuals may make unauthorized or inappropriate changes to MiND and NexSys. As a result, an increased risk exists that MDE cannot ensure MiND and NexSys are configured and operating securely and as intended. Known Questioned Costs None. Recommendation We recommend MDE fully implement an effective change management process over MiND and NexSys. Management Views MDE agrees with the finding.

FY End: 2023-09-30
State of Michigan
Compliance Requirement: ABELN
FINDING 2023-006 MDE, Security Management and Access Controls See Schedule of Findings and Questioned Costs for chart/table. Condition The Michigan Department of Education (MDE) did not fully establish effective security management and access controls over Michigan Electronic Grants System Plus (MEGS+); Grant Electronic Monitoring System/Michigan Administrative Review System (GEMS/MARS); Michigan Nutrition Data (MiND); and Next Generation Grant, Application and Cash Management System (NexSys). ...

FINDING 2023-006 MDE, Security Management and Access Controls See Schedule of Findings and Questioned Costs for chart/table. Condition The Michigan Department of Education (MDE) did not fully establish effective security management and access controls over Michigan Electronic Grants System Plus (MEGS+); Grant Electronic Monitoring System/Michigan Administrative Review System (GEMS/MARS); Michigan Nutrition Data (MiND); and Next Generation Grant, Application and Cash Management System (NexSys). We noted: a. MDE did not consistently follow its established policies and procedures over the granting of access to MiND and NexSys: (1) MDE did not maintain documentation to support the appropriate individual approved the system role for 6 (24%) of 25 sampled MiND users. (2) Of the 47 sampled NexSys forms reviewed, 19 forms related to replacing an existing user and we noted for 1 (5%) of these users MDE did not deactivate the existing users' accounts. Also, MDE did not obtain proper approval prior to granting access for 1 of 6 sampled NexSys grant unit users. In addition, MDE did not properly authorize 2 of 9 sampled NexSys users with incompatible roles. b. MDE did not review all privileged accounts on a semiannual basis for MEGS+ and NexSys. c. MDE did not fully implement an effective annual recertification process of non-privileged accounts: (1) MDE did not review all non-privileged internal accounts on an annual basis for MEGS+, GEMS/MARS, and NexSys. (2) MDE did not always ensure the subrecipients* certified their non-privileged external accounts on an annual basis. Our results are summarized in the following table: See Schedule of Findings and Questioned Costs for chart/table. d. MDE did not disable inactive MiND and NexSys users who had not accessed the applications in over 18 months as of September 30, 2023 as noted below: See Schedule of Findings and Questioned Costs for chart/table. e. MDE did not timely review 2 of the 4 quarterly MEGS+ high-risk transactionsʹ review sheets. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. According to State of Michigan Administrative Guide to State Government policy 1340.00, security controls must be implemented to protect State of Michigan information from unauthorized access, use, disclosure, modification, destruction, or denial and to ensure confidentiality, integrity, and availability of State of Michigan information. SOM Technical Standard 1340.00.020.01 requires agencies to implement and document baseline controls ensuring users are only granted access which is necessary to accomplish assigned tasks in accordance with roles and responsibilities of their job functions. The Standard also requires separation of duties must be implemented through assigned information system access authorizations, accounts should be reviewed for compliance with account management requirements semiannually for privileged accounts and annually for all other accounts, and the information system to automatically disable inactive user accounts after 60 days. However, MDE requested and received an approved exception, which allows user accounts to not be disabled until after 18 months. MDE is responsible for granting access to certain user roles within each system. MDE's process required a security access form to be completed and signed by an authorized official prior to access being granted. MDE's process also requires quarterly reviews of MEGS+ high risk transactions. Cause MDE's internal control and monitoring activities were not sufficient to ensure all appropriate parties adhered to established policies. Effect Without effective user access controls, individuals may obtain unauthorized or inappropriate access to MDE's systems. Known Questioned Costs None.   Recommendation We recommend MDE fully establish effective security management and access controls over MEGS+, GEMS/MARS, MiND, and NexSys. Management Views MDE agrees with the finding.

FY End: 2023-09-30
State of Michigan
Compliance Requirement: ABELN
FINDING 2023-007 MDE, Change Management Process See Schedule of Findings and Questioned Costs for chart/table. Condition MDE did not fully implement an effective change management process over MiND and NexSys. We sampled 24 MiND and 10 NexSys change deployments and noted: See Schedule of Findings and Questioned Costs for chart/table. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that pro...

FINDING 2023-007 MDE, Change Management Process See Schedule of Findings and Questioned Costs for chart/table. Condition MDE did not fully implement an effective change management process over MiND and NexSys. We sampled 24 MiND and 10 NexSys change deployments and noted: See Schedule of Findings and Questioned Costs for chart/table. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. SOM Technical Standard 1340.00.060.04 requires the business owner to authorize the change to be developed and perform post-implementation validation. SOM Technical Procedure 1340.00.060.04.01 requires each test type to have its own set of documentation. State of Michigan Administrative Guide to State Government policy 1340.00 requires approved personnel to adequately manage the configuration of the State's systems, such as retaining previous system configurations, configuring approved devices for high-risk areas, and tracking and documenting system changes. Cause MDE informed us that because of an oversight, it did not document the testing results and close the work items. Effect Without an effective change management process, individuals may make unauthorized or inappropriate changes to MiND and NexSys. As a result, an increased risk exists that MDE cannot ensure MiND and NexSys are configured and operating securely and as intended. Known Questioned Costs None. Recommendation We recommend MDE fully implement an effective change management process over MiND and NexSys. Management Views MDE agrees with the finding.

FY End: 2023-09-30
State of Michigan
Compliance Requirement: ABELN
FINDING 2023-006 MDE, Security Management and Access Controls See Schedule of Findings and Questioned Costs for chart/table. Condition The Michigan Department of Education (MDE) did not fully establish effective security management and access controls over Michigan Electronic Grants System Plus (MEGS+); Grant Electronic Monitoring System/Michigan Administrative Review System (GEMS/MARS); Michigan Nutrition Data (MiND); and Next Generation Grant, Application and Cash Management System (NexSys). ...

FINDING 2023-006 MDE, Security Management and Access Controls See Schedule of Findings and Questioned Costs for chart/table. Condition The Michigan Department of Education (MDE) did not fully establish effective security management and access controls over Michigan Electronic Grants System Plus (MEGS+); Grant Electronic Monitoring System/Michigan Administrative Review System (GEMS/MARS); Michigan Nutrition Data (MiND); and Next Generation Grant, Application and Cash Management System (NexSys). We noted: a. MDE did not consistently follow its established policies and procedures over the granting of access to MiND and NexSys: (1) MDE did not maintain documentation to support the appropriate individual approved the system role for 6 (24%) of 25 sampled MiND users. (2) Of the 47 sampled NexSys forms reviewed, 19 forms related to replacing an existing user and we noted for 1 (5%) of these users MDE did not deactivate the existing users' accounts. Also, MDE did not obtain proper approval prior to granting access for 1 of 6 sampled NexSys grant unit users. In addition, MDE did not properly authorize 2 of 9 sampled NexSys users with incompatible roles. b. MDE did not review all privileged accounts on a semiannual basis for MEGS+ and NexSys. c. MDE did not fully implement an effective annual recertification process of non-privileged accounts: (1) MDE did not review all non-privileged internal accounts on an annual basis for MEGS+, GEMS/MARS, and NexSys. (2) MDE did not always ensure the subrecipients* certified their non-privileged external accounts on an annual basis. Our results are summarized in the following table: See Schedule of Findings and Questioned Costs for chart/table. d. MDE did not disable inactive MiND and NexSys users who had not accessed the applications in over 18 months as of September 30, 2023 as noted below: See Schedule of Findings and Questioned Costs for chart/table. e. MDE did not timely review 2 of the 4 quarterly MEGS+ high-risk transactionsʹ review sheets. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. According to State of Michigan Administrative Guide to State Government policy 1340.00, security controls must be implemented to protect State of Michigan information from unauthorized access, use, disclosure, modification, destruction, or denial and to ensure confidentiality, integrity, and availability of State of Michigan information. SOM Technical Standard 1340.00.020.01 requires agencies to implement and document baseline controls ensuring users are only granted access which is necessary to accomplish assigned tasks in accordance with roles and responsibilities of their job functions. The Standard also requires separation of duties must be implemented through assigned information system access authorizations, accounts should be reviewed for compliance with account management requirements semiannually for privileged accounts and annually for all other accounts, and the information system to automatically disable inactive user accounts after 60 days. However, MDE requested and received an approved exception, which allows user accounts to not be disabled until after 18 months. MDE is responsible for granting access to certain user roles within each system. MDE's process required a security access form to be completed and signed by an authorized official prior to access being granted. MDE's process also requires quarterly reviews of MEGS+ high risk transactions. Cause MDE's internal control and monitoring activities were not sufficient to ensure all appropriate parties adhered to established policies. Effect Without effective user access controls, individuals may obtain unauthorized or inappropriate access to MDE's systems. Known Questioned Costs None.   Recommendation We recommend MDE fully establish effective security management and access controls over MEGS+, GEMS/MARS, MiND, and NexSys. Management Views MDE agrees with the finding.

FY End: 2023-09-30
State of Michigan
Compliance Requirement: ABELN
FINDING 2023-007 MDE, Change Management Process See Schedule of Findings and Questioned Costs for chart/table. Condition MDE did not fully implement an effective change management process over MiND and NexSys. We sampled 24 MiND and 10 NexSys change deployments and noted: See Schedule of Findings and Questioned Costs for chart/table. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that pro...

FINDING 2023-007 MDE, Change Management Process See Schedule of Findings and Questioned Costs for chart/table. Condition MDE did not fully implement an effective change management process over MiND and NexSys. We sampled 24 MiND and 10 NexSys change deployments and noted: See Schedule of Findings and Questioned Costs for chart/table. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. SOM Technical Standard 1340.00.060.04 requires the business owner to authorize the change to be developed and perform post-implementation validation. SOM Technical Procedure 1340.00.060.04.01 requires each test type to have its own set of documentation. State of Michigan Administrative Guide to State Government policy 1340.00 requires approved personnel to adequately manage the configuration of the State's systems, such as retaining previous system configurations, configuring approved devices for high-risk areas, and tracking and documenting system changes. Cause MDE informed us that because of an oversight, it did not document the testing results and close the work items. Effect Without an effective change management process, individuals may make unauthorized or inappropriate changes to MiND and NexSys. As a result, an increased risk exists that MDE cannot ensure MiND and NexSys are configured and operating securely and as intended. Known Questioned Costs None. Recommendation We recommend MDE fully implement an effective change management process over MiND and NexSys. Management Views MDE agrees with the finding.

FY End: 2023-09-30
State of Michigan
Compliance Requirement: ABELN
FINDING 2023-006 MDE, Security Management and Access Controls See Schedule of Findings and Questioned Costs for chart/table. Condition The Michigan Department of Education (MDE) did not fully establish effective security management and access controls over Michigan Electronic Grants System Plus (MEGS+); Grant Electronic Monitoring System/Michigan Administrative Review System (GEMS/MARS); Michigan Nutrition Data (MiND); and Next Generation Grant, Application and Cash Management System (NexSys). ...

FINDING 2023-006 MDE, Security Management and Access Controls See Schedule of Findings and Questioned Costs for chart/table. Condition The Michigan Department of Education (MDE) did not fully establish effective security management and access controls over Michigan Electronic Grants System Plus (MEGS+); Grant Electronic Monitoring System/Michigan Administrative Review System (GEMS/MARS); Michigan Nutrition Data (MiND); and Next Generation Grant, Application and Cash Management System (NexSys). We noted: a. MDE did not consistently follow its established policies and procedures over the granting of access to MiND and NexSys: (1) MDE did not maintain documentation to support the appropriate individual approved the system role for 6 (24%) of 25 sampled MiND users. (2) Of the 47 sampled NexSys forms reviewed, 19 forms related to replacing an existing user and we noted for 1 (5%) of these users MDE did not deactivate the existing users' accounts. Also, MDE did not obtain proper approval prior to granting access for 1 of 6 sampled NexSys grant unit users. In addition, MDE did not properly authorize 2 of 9 sampled NexSys users with incompatible roles. b. MDE did not review all privileged accounts on a semiannual basis for MEGS+ and NexSys. c. MDE did not fully implement an effective annual recertification process of non-privileged accounts: (1) MDE did not review all non-privileged internal accounts on an annual basis for MEGS+, GEMS/MARS, and NexSys. (2) MDE did not always ensure the subrecipients* certified their non-privileged external accounts on an annual basis. Our results are summarized in the following table: See Schedule of Findings and Questioned Costs for chart/table. d. MDE did not disable inactive MiND and NexSys users who had not accessed the applications in over 18 months as of September 30, 2023 as noted below: See Schedule of Findings and Questioned Costs for chart/table. e. MDE did not timely review 2 of the 4 quarterly MEGS+ high-risk transactionsʹ review sheets. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. According to State of Michigan Administrative Guide to State Government policy 1340.00, security controls must be implemented to protect State of Michigan information from unauthorized access, use, disclosure, modification, destruction, or denial and to ensure confidentiality, integrity, and availability of State of Michigan information. SOM Technical Standard 1340.00.020.01 requires agencies to implement and document baseline controls ensuring users are only granted access which is necessary to accomplish assigned tasks in accordance with roles and responsibilities of their job functions. The Standard also requires separation of duties must be implemented through assigned information system access authorizations, accounts should be reviewed for compliance with account management requirements semiannually for privileged accounts and annually for all other accounts, and the information system to automatically disable inactive user accounts after 60 days. However, MDE requested and received an approved exception, which allows user accounts to not be disabled until after 18 months. MDE is responsible for granting access to certain user roles within each system. MDE's process required a security access form to be completed and signed by an authorized official prior to access being granted. MDE's process also requires quarterly reviews of MEGS+ high risk transactions. Cause MDE's internal control and monitoring activities were not sufficient to ensure all appropriate parties adhered to established policies. Effect Without effective user access controls, individuals may obtain unauthorized or inappropriate access to MDE's systems. Known Questioned Costs None.   Recommendation We recommend MDE fully establish effective security management and access controls over MEGS+, GEMS/MARS, MiND, and NexSys. Management Views MDE agrees with the finding.

FY End: 2023-09-30
State of Michigan
Compliance Requirement: ABELN
FINDING 2023-007 MDE, Change Management Process See Schedule of Findings and Questioned Costs for chart/table. Condition MDE did not fully implement an effective change management process over MiND and NexSys. We sampled 24 MiND and 10 NexSys change deployments and noted: See Schedule of Findings and Questioned Costs for chart/table. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that pro...

FINDING 2023-007 MDE, Change Management Process See Schedule of Findings and Questioned Costs for chart/table. Condition MDE did not fully implement an effective change management process over MiND and NexSys. We sampled 24 MiND and 10 NexSys change deployments and noted: See Schedule of Findings and Questioned Costs for chart/table. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. SOM Technical Standard 1340.00.060.04 requires the business owner to authorize the change to be developed and perform post-implementation validation. SOM Technical Procedure 1340.00.060.04.01 requires each test type to have its own set of documentation. State of Michigan Administrative Guide to State Government policy 1340.00 requires approved personnel to adequately manage the configuration of the State's systems, such as retaining previous system configurations, configuring approved devices for high-risk areas, and tracking and documenting system changes. Cause MDE informed us that because of an oversight, it did not document the testing results and close the work items. Effect Without an effective change management process, individuals may make unauthorized or inappropriate changes to MiND and NexSys. As a result, an increased risk exists that MDE cannot ensure MiND and NexSys are configured and operating securely and as intended. Known Questioned Costs None. Recommendation We recommend MDE fully implement an effective change management process over MiND and NexSys. Management Views MDE agrees with the finding.

FY End: 2023-09-30
State of Michigan
Compliance Requirement: ABELN
FINDING 2023-006 MDE, Security Management and Access Controls See Schedule of Findings and Questioned Costs for chart/table. Condition The Michigan Department of Education (MDE) did not fully establish effective security management and access controls over Michigan Electronic Grants System Plus (MEGS+); Grant Electronic Monitoring System/Michigan Administrative Review System (GEMS/MARS); Michigan Nutrition Data (MiND); and Next Generation Grant, Application and Cash Management System (NexSys). ...

FINDING 2023-006 MDE, Security Management and Access Controls See Schedule of Findings and Questioned Costs for chart/table. Condition The Michigan Department of Education (MDE) did not fully establish effective security management and access controls over Michigan Electronic Grants System Plus (MEGS+); Grant Electronic Monitoring System/Michigan Administrative Review System (GEMS/MARS); Michigan Nutrition Data (MiND); and Next Generation Grant, Application and Cash Management System (NexSys). We noted: a. MDE did not consistently follow its established policies and procedures over the granting of access to MiND and NexSys: (1) MDE did not maintain documentation to support the appropriate individual approved the system role for 6 (24%) of 25 sampled MiND users. (2) Of the 47 sampled NexSys forms reviewed, 19 forms related to replacing an existing user and we noted for 1 (5%) of these users MDE did not deactivate the existing users' accounts. Also, MDE did not obtain proper approval prior to granting access for 1 of 6 sampled NexSys grant unit users. In addition, MDE did not properly authorize 2 of 9 sampled NexSys users with incompatible roles. b. MDE did not review all privileged accounts on a semiannual basis for MEGS+ and NexSys. c. MDE did not fully implement an effective annual recertification process of non-privileged accounts: (1) MDE did not review all non-privileged internal accounts on an annual basis for MEGS+, GEMS/MARS, and NexSys. (2) MDE did not always ensure the subrecipients* certified their non-privileged external accounts on an annual basis. Our results are summarized in the following table: See Schedule of Findings and Questioned Costs for chart/table. d. MDE did not disable inactive MiND and NexSys users who had not accessed the applications in over 18 months as of September 30, 2023 as noted below: See Schedule of Findings and Questioned Costs for chart/table. e. MDE did not timely review 2 of the 4 quarterly MEGS+ high-risk transactionsʹ review sheets. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. According to State of Michigan Administrative Guide to State Government policy 1340.00, security controls must be implemented to protect State of Michigan information from unauthorized access, use, disclosure, modification, destruction, or denial and to ensure confidentiality, integrity, and availability of State of Michigan information. SOM Technical Standard 1340.00.020.01 requires agencies to implement and document baseline controls ensuring users are only granted access which is necessary to accomplish assigned tasks in accordance with roles and responsibilities of their job functions. The Standard also requires separation of duties must be implemented through assigned information system access authorizations, accounts should be reviewed for compliance with account management requirements semiannually for privileged accounts and annually for all other accounts, and the information system to automatically disable inactive user accounts after 60 days. However, MDE requested and received an approved exception, which allows user accounts to not be disabled until after 18 months. MDE is responsible for granting access to certain user roles within each system. MDE's process required a security access form to be completed and signed by an authorized official prior to access being granted. MDE's process also requires quarterly reviews of MEGS+ high risk transactions. Cause MDE's internal control and monitoring activities were not sufficient to ensure all appropriate parties adhered to established policies. Effect Without effective user access controls, individuals may obtain unauthorized or inappropriate access to MDE's systems. Known Questioned Costs None.   Recommendation We recommend MDE fully establish effective security management and access controls over MEGS+, GEMS/MARS, MiND, and NexSys. Management Views MDE agrees with the finding.

FY End: 2023-09-30
State of Michigan
Compliance Requirement: ABELN
FINDING 2023-007 MDE, Change Management Process See Schedule of Findings and Questioned Costs for chart/table. Condition MDE did not fully implement an effective change management process over MiND and NexSys. We sampled 24 MiND and 10 NexSys change deployments and noted: See Schedule of Findings and Questioned Costs for chart/table. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that pro...

FINDING 2023-007 MDE, Change Management Process See Schedule of Findings and Questioned Costs for chart/table. Condition MDE did not fully implement an effective change management process over MiND and NexSys. We sampled 24 MiND and 10 NexSys change deployments and noted: See Schedule of Findings and Questioned Costs for chart/table. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. SOM Technical Standard 1340.00.060.04 requires the business owner to authorize the change to be developed and perform post-implementation validation. SOM Technical Procedure 1340.00.060.04.01 requires each test type to have its own set of documentation. State of Michigan Administrative Guide to State Government policy 1340.00 requires approved personnel to adequately manage the configuration of the State's systems, such as retaining previous system configurations, configuring approved devices for high-risk areas, and tracking and documenting system changes. Cause MDE informed us that because of an oversight, it did not document the testing results and close the work items. Effect Without an effective change management process, individuals may make unauthorized or inappropriate changes to MiND and NexSys. As a result, an increased risk exists that MDE cannot ensure MiND and NexSys are configured and operating securely and as intended. Known Questioned Costs None. Recommendation We recommend MDE fully implement an effective change management process over MiND and NexSys. Management Views MDE agrees with the finding.

FY End: 2023-09-30
State of Michigan
Compliance Requirement: ABELN
FINDING 2023-006 MDE, Security Management and Access Controls See Schedule of Findings and Questioned Costs for chart/table. Condition The Michigan Department of Education (MDE) did not fully establish effective security management and access controls over Michigan Electronic Grants System Plus (MEGS+); Grant Electronic Monitoring System/Michigan Administrative Review System (GEMS/MARS); Michigan Nutrition Data (MiND); and Next Generation Grant, Application and Cash Management System (NexSys). ...

FINDING 2023-006 MDE, Security Management and Access Controls See Schedule of Findings and Questioned Costs for chart/table. Condition The Michigan Department of Education (MDE) did not fully establish effective security management and access controls over Michigan Electronic Grants System Plus (MEGS+); Grant Electronic Monitoring System/Michigan Administrative Review System (GEMS/MARS); Michigan Nutrition Data (MiND); and Next Generation Grant, Application and Cash Management System (NexSys). We noted: a. MDE did not consistently follow its established policies and procedures over the granting of access to MiND and NexSys: (1) MDE did not maintain documentation to support the appropriate individual approved the system role for 6 (24%) of 25 sampled MiND users. (2) Of the 47 sampled NexSys forms reviewed, 19 forms related to replacing an existing user and we noted for 1 (5%) of these users MDE did not deactivate the existing users' accounts. Also, MDE did not obtain proper approval prior to granting access for 1 of 6 sampled NexSys grant unit users. In addition, MDE did not properly authorize 2 of 9 sampled NexSys users with incompatible roles. b. MDE did not review all privileged accounts on a semiannual basis for MEGS+ and NexSys. c. MDE did not fully implement an effective annual recertification process of non-privileged accounts: (1) MDE did not review all non-privileged internal accounts on an annual basis for MEGS+, GEMS/MARS, and NexSys. (2) MDE did not always ensure the subrecipients* certified their non-privileged external accounts on an annual basis. Our results are summarized in the following table: See Schedule of Findings and Questioned Costs for chart/table. d. MDE did not disable inactive MiND and NexSys users who had not accessed the applications in over 18 months as of September 30, 2023 as noted below: See Schedule of Findings and Questioned Costs for chart/table. e. MDE did not timely review 2 of the 4 quarterly MEGS+ high-risk transactionsʹ review sheets. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. According to State of Michigan Administrative Guide to State Government policy 1340.00, security controls must be implemented to protect State of Michigan information from unauthorized access, use, disclosure, modification, destruction, or denial and to ensure confidentiality, integrity, and availability of State of Michigan information. SOM Technical Standard 1340.00.020.01 requires agencies to implement and document baseline controls ensuring users are only granted access which is necessary to accomplish assigned tasks in accordance with roles and responsibilities of their job functions. The Standard also requires separation of duties must be implemented through assigned information system access authorizations, accounts should be reviewed for compliance with account management requirements semiannually for privileged accounts and annually for all other accounts, and the information system to automatically disable inactive user accounts after 60 days. However, MDE requested and received an approved exception, which allows user accounts to not be disabled until after 18 months. MDE is responsible for granting access to certain user roles within each system. MDE's process required a security access form to be completed and signed by an authorized official prior to access being granted. MDE's process also requires quarterly reviews of MEGS+ high risk transactions. Cause MDE's internal control and monitoring activities were not sufficient to ensure all appropriate parties adhered to established policies. Effect Without effective user access controls, individuals may obtain unauthorized or inappropriate access to MDE's systems. Known Questioned Costs None.   Recommendation We recommend MDE fully establish effective security management and access controls over MEGS+, GEMS/MARS, MiND, and NexSys. Management Views MDE agrees with the finding.

FY End: 2023-09-30
State of Michigan
Compliance Requirement: ABELN
FINDING 2023-007 MDE, Change Management Process See Schedule of Findings and Questioned Costs for chart/table. Condition MDE did not fully implement an effective change management process over MiND and NexSys. We sampled 24 MiND and 10 NexSys change deployments and noted: See Schedule of Findings and Questioned Costs for chart/table. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that pro...

FINDING 2023-007 MDE, Change Management Process See Schedule of Findings and Questioned Costs for chart/table. Condition MDE did not fully implement an effective change management process over MiND and NexSys. We sampled 24 MiND and 10 NexSys change deployments and noted: See Schedule of Findings and Questioned Costs for chart/table. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. SOM Technical Standard 1340.00.060.04 requires the business owner to authorize the change to be developed and perform post-implementation validation. SOM Technical Procedure 1340.00.060.04.01 requires each test type to have its own set of documentation. State of Michigan Administrative Guide to State Government policy 1340.00 requires approved personnel to adequately manage the configuration of the State's systems, such as retaining previous system configurations, configuring approved devices for high-risk areas, and tracking and documenting system changes. Cause MDE informed us that because of an oversight, it did not document the testing results and close the work items. Effect Without an effective change management process, individuals may make unauthorized or inappropriate changes to MiND and NexSys. As a result, an increased risk exists that MDE cannot ensure MiND and NexSys are configured and operating securely and as intended. Known Questioned Costs None. Recommendation We recommend MDE fully implement an effective change management process over MiND and NexSys. Management Views MDE agrees with the finding.

FY End: 2023-09-30
State of Michigan
Compliance Requirement: ABELN
FINDING 2023-006 MDE, Security Management and Access Controls See Schedule of Findings and Questioned Costs for chart/table. Condition The Michigan Department of Education (MDE) did not fully establish effective security management and access controls over Michigan Electronic Grants System Plus (MEGS+); Grant Electronic Monitoring System/Michigan Administrative Review System (GEMS/MARS); Michigan Nutrition Data (MiND); and Next Generation Grant, Application and Cash Management System (NexSys). ...

FINDING 2023-006 MDE, Security Management and Access Controls See Schedule of Findings and Questioned Costs for chart/table. Condition The Michigan Department of Education (MDE) did not fully establish effective security management and access controls over Michigan Electronic Grants System Plus (MEGS+); Grant Electronic Monitoring System/Michigan Administrative Review System (GEMS/MARS); Michigan Nutrition Data (MiND); and Next Generation Grant, Application and Cash Management System (NexSys). We noted: a. MDE did not consistently follow its established policies and procedures over the granting of access to MiND and NexSys: (1) MDE did not maintain documentation to support the appropriate individual approved the system role for 6 (24%) of 25 sampled MiND users. (2) Of the 47 sampled NexSys forms reviewed, 19 forms related to replacing an existing user and we noted for 1 (5%) of these users MDE did not deactivate the existing users' accounts. Also, MDE did not obtain proper approval prior to granting access for 1 of 6 sampled NexSys grant unit users. In addition, MDE did not properly authorize 2 of 9 sampled NexSys users with incompatible roles. b. MDE did not review all privileged accounts on a semiannual basis for MEGS+ and NexSys. c. MDE did not fully implement an effective annual recertification process of non-privileged accounts: (1) MDE did not review all non-privileged internal accounts on an annual basis for MEGS+, GEMS/MARS, and NexSys. (2) MDE did not always ensure the subrecipients* certified their non-privileged external accounts on an annual basis. Our results are summarized in the following table: See Schedule of Findings and Questioned Costs for chart/table. d. MDE did not disable inactive MiND and NexSys users who had not accessed the applications in over 18 months as of September 30, 2023 as noted below: See Schedule of Findings and Questioned Costs for chart/table. e. MDE did not timely review 2 of the 4 quarterly MEGS+ high-risk transactionsʹ review sheets. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. According to State of Michigan Administrative Guide to State Government policy 1340.00, security controls must be implemented to protect State of Michigan information from unauthorized access, use, disclosure, modification, destruction, or denial and to ensure confidentiality, integrity, and availability of State of Michigan information. SOM Technical Standard 1340.00.020.01 requires agencies to implement and document baseline controls ensuring users are only granted access which is necessary to accomplish assigned tasks in accordance with roles and responsibilities of their job functions. The Standard also requires separation of duties must be implemented through assigned information system access authorizations, accounts should be reviewed for compliance with account management requirements semiannually for privileged accounts and annually for all other accounts, and the information system to automatically disable inactive user accounts after 60 days. However, MDE requested and received an approved exception, which allows user accounts to not be disabled until after 18 months. MDE is responsible for granting access to certain user roles within each system. MDE's process required a security access form to be completed and signed by an authorized official prior to access being granted. MDE's process also requires quarterly reviews of MEGS+ high risk transactions. Cause MDE's internal control and monitoring activities were not sufficient to ensure all appropriate parties adhered to established policies. Effect Without effective user access controls, individuals may obtain unauthorized or inappropriate access to MDE's systems. Known Questioned Costs None.   Recommendation We recommend MDE fully establish effective security management and access controls over MEGS+, GEMS/MARS, MiND, and NexSys. Management Views MDE agrees with the finding.

FY End: 2023-09-30
State of Michigan
Compliance Requirement: ABELN
FINDING 2023-007 MDE, Change Management Process See Schedule of Findings and Questioned Costs for chart/table. Condition MDE did not fully implement an effective change management process over MiND and NexSys. We sampled 24 MiND and 10 NexSys change deployments and noted: See Schedule of Findings and Questioned Costs for chart/table. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that pro...

FINDING 2023-007 MDE, Change Management Process See Schedule of Findings and Questioned Costs for chart/table. Condition MDE did not fully implement an effective change management process over MiND and NexSys. We sampled 24 MiND and 10 NexSys change deployments and noted: See Schedule of Findings and Questioned Costs for chart/table. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. SOM Technical Standard 1340.00.060.04 requires the business owner to authorize the change to be developed and perform post-implementation validation. SOM Technical Procedure 1340.00.060.04.01 requires each test type to have its own set of documentation. State of Michigan Administrative Guide to State Government policy 1340.00 requires approved personnel to adequately manage the configuration of the State's systems, such as retaining previous system configurations, configuring approved devices for high-risk areas, and tracking and documenting system changes. Cause MDE informed us that because of an oversight, it did not document the testing results and close the work items. Effect Without an effective change management process, individuals may make unauthorized or inappropriate changes to MiND and NexSys. As a result, an increased risk exists that MDE cannot ensure MiND and NexSys are configured and operating securely and as intended. Known Questioned Costs None. Recommendation We recommend MDE fully implement an effective change management process over MiND and NexSys. Management Views MDE agrees with the finding.

FY End: 2023-09-30
State of Michigan
Compliance Requirement: ABCEIN
FINDING 2023-006 MDE, Security Management and Access Controls See Schedule of Findings and Questioned Costs for chart/table. Condition The Michigan Department of Education (MDE) did not fully establish effective security management and access controls over Michigan Electronic Grants System Plus (MEGS+); Grant Electronic Monitoring System/Michigan Administrative Review System (GEMS/MARS); Michigan Nutrition Data (MiND); and Next Generation Grant, Application and Cash Management System (NexSys). ...

FINDING 2023-006 MDE, Security Management and Access Controls See Schedule of Findings and Questioned Costs for chart/table. Condition The Michigan Department of Education (MDE) did not fully establish effective security management and access controls over Michigan Electronic Grants System Plus (MEGS+); Grant Electronic Monitoring System/Michigan Administrative Review System (GEMS/MARS); Michigan Nutrition Data (MiND); and Next Generation Grant, Application and Cash Management System (NexSys). We noted: a. MDE did not consistently follow its established policies and procedures over the granting of access to MiND and NexSys: (1) MDE did not maintain documentation to support the appropriate individual approved the system role for 6 (24%) of 25 sampled MiND users. (2) Of the 47 sampled NexSys forms reviewed, 19 forms related to replacing an existing user and we noted for 1 (5%) of these users MDE did not deactivate the existing users' accounts. Also, MDE did not obtain proper approval prior to granting access for 1 of 6 sampled NexSys grant unit users. In addition, MDE did not properly authorize 2 of 9 sampled NexSys users with incompatible roles. b. MDE did not review all privileged accounts on a semiannual basis for MEGS+ and NexSys. c. MDE did not fully implement an effective annual recertification process of non-privileged accounts: (1) MDE did not review all non-privileged internal accounts on an annual basis for MEGS+, GEMS/MARS, and NexSys. (2) MDE did not always ensure the subrecipients* certified their non-privileged external accounts on an annual basis. Our results are summarized in the following table: See Schedule of Findings and Questioned Costs for chart/table. d. MDE did not disable inactive MiND and NexSys users who had not accessed the applications in over 18 months as of September 30, 2023 as noted below: See Schedule of Findings and Questioned Costs for chart/table. e. MDE did not timely review 2 of the 4 quarterly MEGS+ high-risk transactionsʹ review sheets. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. According to State of Michigan Administrative Guide to State Government policy 1340.00, security controls must be implemented to protect State of Michigan information from unauthorized access, use, disclosure, modification, destruction, or denial and to ensure confidentiality, integrity, and availability of State of Michigan information. SOM Technical Standard 1340.00.020.01 requires agencies to implement and document baseline controls ensuring users are only granted access which is necessary to accomplish assigned tasks in accordance with roles and responsibilities of their job functions. The Standard also requires separation of duties must be implemented through assigned information system access authorizations, accounts should be reviewed for compliance with account management requirements semiannually for privileged accounts and annually for all other accounts, and the information system to automatically disable inactive user accounts after 60 days. However, MDE requested and received an approved exception, which allows user accounts to not be disabled until after 18 months. MDE is responsible for granting access to certain user roles within each system. MDE's process required a security access form to be completed and signed by an authorized official prior to access being granted. MDE's process also requires quarterly reviews of MEGS+ high risk transactions. Cause MDE's internal control and monitoring activities were not sufficient to ensure all appropriate parties adhered to established policies. Effect Without effective user access controls, individuals may obtain unauthorized or inappropriate access to MDE's systems. Known Questioned Costs None.   Recommendation We recommend MDE fully establish effective security management and access controls over MEGS+, GEMS/MARS, MiND, and NexSys. Management Views MDE agrees with the finding.

FY End: 2023-09-30
State of Michigan
Compliance Requirement: ABCE
FINDING 2023-007 MDE, Change Management Process See Schedule of Findings and Questioned Costs for chart/table. Condition MDE did not fully implement an effective change management process over MiND and NexSys. We sampled 24 MiND and 10 NexSys change deployments and noted: See Schedule of Findings and Questioned Costs for chart/table. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that pro...

FINDING 2023-007 MDE, Change Management Process See Schedule of Findings and Questioned Costs for chart/table. Condition MDE did not fully implement an effective change management process over MiND and NexSys. We sampled 24 MiND and 10 NexSys change deployments and noted: See Schedule of Findings and Questioned Costs for chart/table. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. SOM Technical Standard 1340.00.060.04 requires the business owner to authorize the change to be developed and perform post-implementation validation. SOM Technical Procedure 1340.00.060.04.01 requires each test type to have its own set of documentation. State of Michigan Administrative Guide to State Government policy 1340.00 requires approved personnel to adequately manage the configuration of the State's systems, such as retaining previous system configurations, configuring approved devices for high-risk areas, and tracking and documenting system changes. Cause MDE informed us that because of an oversight, it did not document the testing results and close the work items. Effect Without an effective change management process, individuals may make unauthorized or inappropriate changes to MiND and NexSys. As a result, an increased risk exists that MDE cannot ensure MiND and NexSys are configured and operating securely and as intended. Known Questioned Costs None. Recommendation We recommend MDE fully implement an effective change management process over MiND and NexSys. Management Views MDE agrees with the finding.

« 1 765 766 768 769 2002 »