FINDING 2023-002 Bridges Security Management and Access Controls* See Schedule of Findings and Questioned Costs for chart/table. Condition MDHHS had not established effective security management and access controls over Bridges users. We noted: a. MDHHS did not maintain documentation for 30 (75%) of the 40 sampled Bridges incompatible role exception requests. Of the 10 forms received, we noted MDHHS did not properly approve 6 forms prior to granting the exception requests. b. MDHHS did not maintain documentation for 21 (26%) of 80 sampled local office security monitoring reports. Also, MDHHS did not complete timely reviews for 2 (3%) of 59 sampled security monitoring reports. c. MDHHS did not maintain documentation for 1 (3%) of the 40 sampled Bridges application security agreements. Of the 39 forms received, we noted MDHHS did not properly approve 10 (26%) forms prior to granting access to Bridges. d. MDHHS did not monitor non-local office Bridges user accounts for compliance with account management requirements semiannually for privileged users or annually for all other users. e. MDHHS did not maintain documentation for 9 (45%) of the 20 sampled local office high risk Bridges transaction monitoring reports. Of the 11 reports received, MDHHS did not complete the review timely or did not document its review date for 3 (27%) of the reports. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. According to State of Michigan Administrative Guide to State Government policy 1340.00, security controls must be implemented to protect State of Michigan information from unauthorized access, use, disclosure, modification, destruction, or denial and to ensure confidentiality, integrity, and availability of State of Michigan information. State of Michigan (SOM) Technical Standard 1340.00.020.01 requires agencies to implement and document baseline controls ensuring users are only granted access which is necessary to accomplish assigned tasks in accordance with roles and responsibilities of their job functions. The Standard also requires separation of duties must be implemented through assigned information system access authorizations and accounts should be reviewed for compliance with account management requirements semiannually for privileged accounts* and annually for all other accounts. In addition, the GAO's FISCAM recommends compensating controls, such as additional monitoring and supervision, should be in place where segregation of duties'* conflicts exist. Cause For parts a., c., and d., MDHHS's internal control and monitoring activities were not sufficient to ensure all appropriate parties adhered to established policies and procedures. For parts b. and e., MDHHS's internal control and monitoring activities need improvement to ensure all appropriate parties maintain and timely complete their review of the local office security monitoring reports and high-risk Bridges transaction monitoring reports. Effect We consider these issues to be a material weakness because, without effective security management and access controls, individuals may obtain unauthorized or inappropriate access to Bridges. As a result, an increased risk exists that MDHHS cannot ensure the security of the Bridges application and data used to help determine eligibility and benefit levels for the SNAP Cluster, Pandemic Electronic Benefits Transfer (P-EBT) Food Benefits, CCDF Cluster, Medicaid Cluster, Temporary Assistance for Needy Families (TANF), Refugee and Entrant Assistance State/Replacement Designee Administered Programs (REAP), Low-Income Home Energy Assistance Program (LIHEAP), and Children's Health Insurance Program (CHIP). Known Questioned Costs None. Recommendation We recommend MDHHS establish effective security management and access controls over Bridges users. Management Views MDHHS agrees with the finding.
FINDING 2023-003 Bridges Change Management Process See Schedule of Findings and Questioned Costs for chart/table. Condition MDHHS did not fully implement an effective change management process over Bridges. Our review disclosed MDHHS did not document post-implementation approvals for 3 (12%) of 25 sampled Bridges change records. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. SOM Technical Standard 1340.00.060.04 requires the business owner perform post-implementation validation. SOM Technical Procedure 1340.00.060.04.01 requires each test type to have its own set of documentation. State of Michigan Administrative Guide to State Government policy 1340.00 requires approved personnel to adequately manage the configuration* of the State's systems, such as retaining previous system configurations, configuring approved devices for high-risk areas, and tracking and documenting system changes. Cause MDHHS informed us it did not always follow established processes for documenting testing and business owner approvals. Effect Without an effective change management process, individuals may make unauthorized or inappropriate changes to Bridges. As a result, an increased risk exists that MDHHS cannot ensure Bridges is configured and operating securely and as intended. Known Questioned Costs None. Recommendation We recommend MDHHS fully implement an effective change management process over Bridges. Management Views MDHHS agrees with the finding.
FINDING 2023-006 MDE, Security Management and Access Controls See Schedule of Findings and Questioned Costs for chart/table. Condition The Michigan Department of Education (MDE) did not fully establish effective security management and access controls over Michigan Electronic Grants System Plus (MEGS+); Grant Electronic Monitoring System/Michigan Administrative Review System (GEMS/MARS); Michigan Nutrition Data (MiND); and Next Generation Grant, Application and Cash Management System (NexSys). We noted: a. MDE did not consistently follow its established policies and procedures over the granting of access to MiND and NexSys: (1) MDE did not maintain documentation to support the appropriate individual approved the system role for 6 (24%) of 25 sampled MiND users. (2) Of the 47 sampled NexSys forms reviewed, 19 forms related to replacing an existing user and we noted for 1 (5%) of these users MDE did not deactivate the existing users' accounts. Also, MDE did not obtain proper approval prior to granting access for 1 of 6 sampled NexSys grant unit users. In addition, MDE did not properly authorize 2 of 9 sampled NexSys users with incompatible roles. b. MDE did not review all privileged accounts on a semiannual basis for MEGS+ and NexSys. c. MDE did not fully implement an effective annual recertification process of non-privileged accounts: (1) MDE did not review all non-privileged internal accounts on an annual basis for MEGS+, GEMS/MARS, and NexSys. (2) MDE did not always ensure the subrecipients* certified their non-privileged external accounts on an annual basis. Our results are summarized in the following table: See Schedule of Findings and Questioned Costs for chart/table. d. MDE did not disable inactive MiND and NexSys users who had not accessed the applications in over 18 months as of September 30, 2023 as noted below: See Schedule of Findings and Questioned Costs for chart/table. e. MDE did not timely review 2 of the 4 quarterly MEGS+ high-risk transactionsʹ review sheets. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. According to State of Michigan Administrative Guide to State Government policy 1340.00, security controls must be implemented to protect State of Michigan information from unauthorized access, use, disclosure, modification, destruction, or denial and to ensure confidentiality, integrity, and availability of State of Michigan information. SOM Technical Standard 1340.00.020.01 requires agencies to implement and document baseline controls ensuring users are only granted access which is necessary to accomplish assigned tasks in accordance with roles and responsibilities of their job functions. The Standard also requires separation of duties must be implemented through assigned information system access authorizations, accounts should be reviewed for compliance with account management requirements semiannually for privileged accounts and annually for all other accounts, and the information system to automatically disable inactive user accounts after 60 days. However, MDE requested and received an approved exception, which allows user accounts to not be disabled until after 18 months. MDE is responsible for granting access to certain user roles within each system. MDE's process required a security access form to be completed and signed by an authorized official prior to access being granted. MDE's process also requires quarterly reviews of MEGS+ high risk transactions. Cause MDE's internal control and monitoring activities were not sufficient to ensure all appropriate parties adhered to established policies. Effect Without effective user access controls, individuals may obtain unauthorized or inappropriate access to MDE's systems. Known Questioned Costs None. Recommendation We recommend MDE fully establish effective security management and access controls over MEGS+, GEMS/MARS, MiND, and NexSys. Management Views MDE agrees with the finding.
FINDING 2023-007 MDE, Change Management Process See Schedule of Findings and Questioned Costs for chart/table. Condition MDE did not fully implement an effective change management process over MiND and NexSys. We sampled 24 MiND and 10 NexSys change deployments and noted: See Schedule of Findings and Questioned Costs for chart/table. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. SOM Technical Standard 1340.00.060.04 requires the business owner to authorize the change to be developed and perform post-implementation validation. SOM Technical Procedure 1340.00.060.04.01 requires each test type to have its own set of documentation. State of Michigan Administrative Guide to State Government policy 1340.00 requires approved personnel to adequately manage the configuration of the State's systems, such as retaining previous system configurations, configuring approved devices for high-risk areas, and tracking and documenting system changes. Cause MDE informed us that because of an oversight, it did not document the testing results and close the work items. Effect Without an effective change management process, individuals may make unauthorized or inappropriate changes to MiND and NexSys. As a result, an increased risk exists that MDE cannot ensure MiND and NexSys are configured and operating securely and as intended. Known Questioned Costs None. Recommendation We recommend MDE fully implement an effective change management process over MiND and NexSys. Management Views MDE agrees with the finding.
FINDING 2023-002 Bridges Security Management and Access Controls* See Schedule of Findings and Questioned Costs for chart/table. Condition MDHHS had not established effective security management and access controls over Bridges users. We noted: a. MDHHS did not maintain documentation for 30 (75%) of the 40 sampled Bridges incompatible role exception requests. Of the 10 forms received, we noted MDHHS did not properly approve 6 forms prior to granting the exception requests. b. MDHHS did not maintain documentation for 21 (26%) of 80 sampled local office security monitoring reports. Also, MDHHS did not complete timely reviews for 2 (3%) of 59 sampled security monitoring reports. c. MDHHS did not maintain documentation for 1 (3%) of the 40 sampled Bridges application security agreements. Of the 39 forms received, we noted MDHHS did not properly approve 10 (26%) forms prior to granting access to Bridges. d. MDHHS did not monitor non-local office Bridges user accounts for compliance with account management requirements semiannually for privileged users or annually for all other users. e. MDHHS did not maintain documentation for 9 (45%) of the 20 sampled local office high risk Bridges transaction monitoring reports. Of the 11 reports received, MDHHS did not complete the review timely or did not document its review date for 3 (27%) of the reports. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. According to State of Michigan Administrative Guide to State Government policy 1340.00, security controls must be implemented to protect State of Michigan information from unauthorized access, use, disclosure, modification, destruction, or denial and to ensure confidentiality, integrity, and availability of State of Michigan information. State of Michigan (SOM) Technical Standard 1340.00.020.01 requires agencies to implement and document baseline controls ensuring users are only granted access which is necessary to accomplish assigned tasks in accordance with roles and responsibilities of their job functions. The Standard also requires separation of duties must be implemented through assigned information system access authorizations and accounts should be reviewed for compliance with account management requirements semiannually for privileged accounts* and annually for all other accounts. In addition, the GAO's FISCAM recommends compensating controls, such as additional monitoring and supervision, should be in place where segregation of duties'* conflicts exist. Cause For parts a., c., and d., MDHHS's internal control and monitoring activities were not sufficient to ensure all appropriate parties adhered to established policies and procedures. For parts b. and e., MDHHS's internal control and monitoring activities need improvement to ensure all appropriate parties maintain and timely complete their review of the local office security monitoring reports and high-risk Bridges transaction monitoring reports. Effect We consider these issues to be a material weakness because, without effective security management and access controls, individuals may obtain unauthorized or inappropriate access to Bridges. As a result, an increased risk exists that MDHHS cannot ensure the security of the Bridges application and data used to help determine eligibility and benefit levels for the SNAP Cluster, Pandemic Electronic Benefits Transfer (P-EBT) Food Benefits, CCDF Cluster, Medicaid Cluster, Temporary Assistance for Needy Families (TANF), Refugee and Entrant Assistance State/Replacement Designee Administered Programs (REAP), Low-Income Home Energy Assistance Program (LIHEAP), and Children's Health Insurance Program (CHIP). Known Questioned Costs None. Recommendation We recommend MDHHS establish effective security management and access controls over Bridges users. Management Views MDHHS agrees with the finding.
FINDING 2023-003 Bridges Change Management Process See Schedule of Findings and Questioned Costs for chart/table. Condition MDHHS did not fully implement an effective change management process over Bridges. Our review disclosed MDHHS did not document post-implementation approvals for 3 (12%) of 25 sampled Bridges change records. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. SOM Technical Standard 1340.00.060.04 requires the business owner perform post-implementation validation. SOM Technical Procedure 1340.00.060.04.01 requires each test type to have its own set of documentation. State of Michigan Administrative Guide to State Government policy 1340.00 requires approved personnel to adequately manage the configuration* of the State's systems, such as retaining previous system configurations, configuring approved devices for high-risk areas, and tracking and documenting system changes. Cause MDHHS informed us it did not always follow established processes for documenting testing and business owner approvals. Effect Without an effective change management process, individuals may make unauthorized or inappropriate changes to Bridges. As a result, an increased risk exists that MDHHS cannot ensure Bridges is configured and operating securely and as intended. Known Questioned Costs None. Recommendation We recommend MDHHS fully implement an effective change management process over Bridges. Management Views MDHHS agrees with the finding.
FINDING 2023-002 Bridges Security Management and Access Controls* See Schedule of Findings and Questioned Costs for chart/table. Condition MDHHS had not established effective security management and access controls over Bridges users. We noted: a. MDHHS did not maintain documentation for 30 (75%) of the 40 sampled Bridges incompatible role exception requests. Of the 10 forms received, we noted MDHHS did not properly approve 6 forms prior to granting the exception requests. b. MDHHS did not maintain documentation for 21 (26%) of 80 sampled local office security monitoring reports. Also, MDHHS did not complete timely reviews for 2 (3%) of 59 sampled security monitoring reports. c. MDHHS did not maintain documentation for 1 (3%) of the 40 sampled Bridges application security agreements. Of the 39 forms received, we noted MDHHS did not properly approve 10 (26%) forms prior to granting access to Bridges. d. MDHHS did not monitor non-local office Bridges user accounts for compliance with account management requirements semiannually for privileged users or annually for all other users. e. MDHHS did not maintain documentation for 9 (45%) of the 20 sampled local office high risk Bridges transaction monitoring reports. Of the 11 reports received, MDHHS did not complete the review timely or did not document its review date for 3 (27%) of the reports. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. According to State of Michigan Administrative Guide to State Government policy 1340.00, security controls must be implemented to protect State of Michigan information from unauthorized access, use, disclosure, modification, destruction, or denial and to ensure confidentiality, integrity, and availability of State of Michigan information. State of Michigan (SOM) Technical Standard 1340.00.020.01 requires agencies to implement and document baseline controls ensuring users are only granted access which is necessary to accomplish assigned tasks in accordance with roles and responsibilities of their job functions. The Standard also requires separation of duties must be implemented through assigned information system access authorizations and accounts should be reviewed for compliance with account management requirements semiannually for privileged accounts* and annually for all other accounts. In addition, the GAO's FISCAM recommends compensating controls, such as additional monitoring and supervision, should be in place where segregation of duties'* conflicts exist. Cause For parts a., c., and d., MDHHS's internal control and monitoring activities were not sufficient to ensure all appropriate parties adhered to established policies and procedures. For parts b. and e., MDHHS's internal control and monitoring activities need improvement to ensure all appropriate parties maintain and timely complete their review of the local office security monitoring reports and high-risk Bridges transaction monitoring reports. Effect We consider these issues to be a material weakness because, without effective security management and access controls, individuals may obtain unauthorized or inappropriate access to Bridges. As a result, an increased risk exists that MDHHS cannot ensure the security of the Bridges application and data used to help determine eligibility and benefit levels for the SNAP Cluster, Pandemic Electronic Benefits Transfer (P-EBT) Food Benefits, CCDF Cluster, Medicaid Cluster, Temporary Assistance for Needy Families (TANF), Refugee and Entrant Assistance State/Replacement Designee Administered Programs (REAP), Low-Income Home Energy Assistance Program (LIHEAP), and Children's Health Insurance Program (CHIP). Known Questioned Costs None. Recommendation We recommend MDHHS establish effective security management and access controls over Bridges users. Management Views MDHHS agrees with the finding.
FINDING 2023-003 Bridges Change Management Process See Schedule of Findings and Questioned Costs for chart/table. Condition MDHHS did not fully implement an effective change management process over Bridges. Our review disclosed MDHHS did not document post-implementation approvals for 3 (12%) of 25 sampled Bridges change records. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. SOM Technical Standard 1340.00.060.04 requires the business owner perform post-implementation validation. SOM Technical Procedure 1340.00.060.04.01 requires each test type to have its own set of documentation. State of Michigan Administrative Guide to State Government policy 1340.00 requires approved personnel to adequately manage the configuration* of the State's systems, such as retaining previous system configurations, configuring approved devices for high-risk areas, and tracking and documenting system changes. Cause MDHHS informed us it did not always follow established processes for documenting testing and business owner approvals. Effect Without an effective change management process, individuals may make unauthorized or inappropriate changes to Bridges. As a result, an increased risk exists that MDHHS cannot ensure Bridges is configured and operating securely and as intended. Known Questioned Costs None. Recommendation We recommend MDHHS fully implement an effective change management process over Bridges. Management Views MDHHS agrees with the finding.
FINDING 2023-002 Bridges Security Management and Access Controls* See Schedule of Findings and Questioned Costs for chart/table. Condition MDHHS had not established effective security management and access controls over Bridges users. We noted: a. MDHHS did not maintain documentation for 30 (75%) of the 40 sampled Bridges incompatible role exception requests. Of the 10 forms received, we noted MDHHS did not properly approve 6 forms prior to granting the exception requests. b. MDHHS did not maintain documentation for 21 (26%) of 80 sampled local office security monitoring reports. Also, MDHHS did not complete timely reviews for 2 (3%) of 59 sampled security monitoring reports. c. MDHHS did not maintain documentation for 1 (3%) of the 40 sampled Bridges application security agreements. Of the 39 forms received, we noted MDHHS did not properly approve 10 (26%) forms prior to granting access to Bridges. d. MDHHS did not monitor non-local office Bridges user accounts for compliance with account management requirements semiannually for privileged users or annually for all other users. e. MDHHS did not maintain documentation for 9 (45%) of the 20 sampled local office high risk Bridges transaction monitoring reports. Of the 11 reports received, MDHHS did not complete the review timely or did not document its review date for 3 (27%) of the reports. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. According to State of Michigan Administrative Guide to State Government policy 1340.00, security controls must be implemented to protect State of Michigan information from unauthorized access, use, disclosure, modification, destruction, or denial and to ensure confidentiality, integrity, and availability of State of Michigan information. State of Michigan (SOM) Technical Standard 1340.00.020.01 requires agencies to implement and document baseline controls ensuring users are only granted access which is necessary to accomplish assigned tasks in accordance with roles and responsibilities of their job functions. The Standard also requires separation of duties must be implemented through assigned information system access authorizations and accounts should be reviewed for compliance with account management requirements semiannually for privileged accounts* and annually for all other accounts. In addition, the GAO's FISCAM recommends compensating controls, such as additional monitoring and supervision, should be in place where segregation of duties'* conflicts exist. Cause For parts a., c., and d., MDHHS's internal control and monitoring activities were not sufficient to ensure all appropriate parties adhered to established policies and procedures. For parts b. and e., MDHHS's internal control and monitoring activities need improvement to ensure all appropriate parties maintain and timely complete their review of the local office security monitoring reports and high-risk Bridges transaction monitoring reports. Effect We consider these issues to be a material weakness because, without effective security management and access controls, individuals may obtain unauthorized or inappropriate access to Bridges. As a result, an increased risk exists that MDHHS cannot ensure the security of the Bridges application and data used to help determine eligibility and benefit levels for the SNAP Cluster, Pandemic Electronic Benefits Transfer (P-EBT) Food Benefits, CCDF Cluster, Medicaid Cluster, Temporary Assistance for Needy Families (TANF), Refugee and Entrant Assistance State/Replacement Designee Administered Programs (REAP), Low-Income Home Energy Assistance Program (LIHEAP), and Children's Health Insurance Program (CHIP). Known Questioned Costs None. Recommendation We recommend MDHHS establish effective security management and access controls over Bridges users. Management Views MDHHS agrees with the finding.
FINDING 2023-003 Bridges Change Management Process See Schedule of Findings and Questioned Costs for chart/table. Condition MDHHS did not fully implement an effective change management process over Bridges. Our review disclosed MDHHS did not document post-implementation approvals for 3 (12%) of 25 sampled Bridges change records. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. SOM Technical Standard 1340.00.060.04 requires the business owner perform post-implementation validation. SOM Technical Procedure 1340.00.060.04.01 requires each test type to have its own set of documentation. State of Michigan Administrative Guide to State Government policy 1340.00 requires approved personnel to adequately manage the configuration* of the State's systems, such as retaining previous system configurations, configuring approved devices for high-risk areas, and tracking and documenting system changes. Cause MDHHS informed us it did not always follow established processes for documenting testing and business owner approvals. Effect Without an effective change management process, individuals may make unauthorized or inappropriate changes to Bridges. As a result, an increased risk exists that MDHHS cannot ensure Bridges is configured and operating securely and as intended. Known Questioned Costs None. Recommendation We recommend MDHHS fully implement an effective change management process over Bridges. Management Views MDHHS agrees with the finding.
FINDING 2023-002 Bridges Security Management and Access Controls* See Schedule of Findings and Questioned Costs for chart/table. Condition MDHHS had not established effective security management and access controls over Bridges users. We noted: a. MDHHS did not maintain documentation for 30 (75%) of the 40 sampled Bridges incompatible role exception requests. Of the 10 forms received, we noted MDHHS did not properly approve 6 forms prior to granting the exception requests. b. MDHHS did not maintain documentation for 21 (26%) of 80 sampled local office security monitoring reports. Also, MDHHS did not complete timely reviews for 2 (3%) of 59 sampled security monitoring reports. c. MDHHS did not maintain documentation for 1 (3%) of the 40 sampled Bridges application security agreements. Of the 39 forms received, we noted MDHHS did not properly approve 10 (26%) forms prior to granting access to Bridges. d. MDHHS did not monitor non-local office Bridges user accounts for compliance with account management requirements semiannually for privileged users or annually for all other users. e. MDHHS did not maintain documentation for 9 (45%) of the 20 sampled local office high risk Bridges transaction monitoring reports. Of the 11 reports received, MDHHS did not complete the review timely or did not document its review date for 3 (27%) of the reports. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. According to State of Michigan Administrative Guide to State Government policy 1340.00, security controls must be implemented to protect State of Michigan information from unauthorized access, use, disclosure, modification, destruction, or denial and to ensure confidentiality, integrity, and availability of State of Michigan information. State of Michigan (SOM) Technical Standard 1340.00.020.01 requires agencies to implement and document baseline controls ensuring users are only granted access which is necessary to accomplish assigned tasks in accordance with roles and responsibilities of their job functions. The Standard also requires separation of duties must be implemented through assigned information system access authorizations and accounts should be reviewed for compliance with account management requirements semiannually for privileged accounts* and annually for all other accounts. In addition, the GAO's FISCAM recommends compensating controls, such as additional monitoring and supervision, should be in place where segregation of duties'* conflicts exist. Cause For parts a., c., and d., MDHHS's internal control and monitoring activities were not sufficient to ensure all appropriate parties adhered to established policies and procedures. For parts b. and e., MDHHS's internal control and monitoring activities need improvement to ensure all appropriate parties maintain and timely complete their review of the local office security monitoring reports and high-risk Bridges transaction monitoring reports. Effect We consider these issues to be a material weakness because, without effective security management and access controls, individuals may obtain unauthorized or inappropriate access to Bridges. As a result, an increased risk exists that MDHHS cannot ensure the security of the Bridges application and data used to help determine eligibility and benefit levels for the SNAP Cluster, Pandemic Electronic Benefits Transfer (P-EBT) Food Benefits, CCDF Cluster, Medicaid Cluster, Temporary Assistance for Needy Families (TANF), Refugee and Entrant Assistance State/Replacement Designee Administered Programs (REAP), Low-Income Home Energy Assistance Program (LIHEAP), and Children's Health Insurance Program (CHIP). Known Questioned Costs None. Recommendation We recommend MDHHS establish effective security management and access controls over Bridges users. Management Views MDHHS agrees with the finding.
FINDING 2023-003 Bridges Change Management Process See Schedule of Findings and Questioned Costs for chart/table. Condition MDHHS did not fully implement an effective change management process over Bridges. Our review disclosed MDHHS did not document post-implementation approvals for 3 (12%) of 25 sampled Bridges change records. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. SOM Technical Standard 1340.00.060.04 requires the business owner perform post-implementation validation. SOM Technical Procedure 1340.00.060.04.01 requires each test type to have its own set of documentation. State of Michigan Administrative Guide to State Government policy 1340.00 requires approved personnel to adequately manage the configuration* of the State's systems, such as retaining previous system configurations, configuring approved devices for high-risk areas, and tracking and documenting system changes. Cause MDHHS informed us it did not always follow established processes for documenting testing and business owner approvals. Effect Without an effective change management process, individuals may make unauthorized or inappropriate changes to Bridges. As a result, an increased risk exists that MDHHS cannot ensure Bridges is configured and operating securely and as intended. Known Questioned Costs None. Recommendation We recommend MDHHS fully implement an effective change management process over Bridges. Management Views MDHHS agrees with the finding.
FINDING 2023-002 Bridges Security Management and Access Controls* See Schedule of Findings and Questioned Costs for chart/table. Condition MDHHS had not established effective security management and access controls over Bridges users. We noted: a. MDHHS did not maintain documentation for 30 (75%) of the 40 sampled Bridges incompatible role exception requests. Of the 10 forms received, we noted MDHHS did not properly approve 6 forms prior to granting the exception requests. b. MDHHS did not maintain documentation for 21 (26%) of 80 sampled local office security monitoring reports. Also, MDHHS did not complete timely reviews for 2 (3%) of 59 sampled security monitoring reports. c. MDHHS did not maintain documentation for 1 (3%) of the 40 sampled Bridges application security agreements. Of the 39 forms received, we noted MDHHS did not properly approve 10 (26%) forms prior to granting access to Bridges. d. MDHHS did not monitor non-local office Bridges user accounts for compliance with account management requirements semiannually for privileged users or annually for all other users. e. MDHHS did not maintain documentation for 9 (45%) of the 20 sampled local office high risk Bridges transaction monitoring reports. Of the 11 reports received, MDHHS did not complete the review timely or did not document its review date for 3 (27%) of the reports. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. According to State of Michigan Administrative Guide to State Government policy 1340.00, security controls must be implemented to protect State of Michigan information from unauthorized access, use, disclosure, modification, destruction, or denial and to ensure confidentiality, integrity, and availability of State of Michigan information. State of Michigan (SOM) Technical Standard 1340.00.020.01 requires agencies to implement and document baseline controls ensuring users are only granted access which is necessary to accomplish assigned tasks in accordance with roles and responsibilities of their job functions. The Standard also requires separation of duties must be implemented through assigned information system access authorizations and accounts should be reviewed for compliance with account management requirements semiannually for privileged accounts* and annually for all other accounts. In addition, the GAO's FISCAM recommends compensating controls, such as additional monitoring and supervision, should be in place where segregation of duties'* conflicts exist. Cause For parts a., c., and d., MDHHS's internal control and monitoring activities were not sufficient to ensure all appropriate parties adhered to established policies and procedures. For parts b. and e., MDHHS's internal control and monitoring activities need improvement to ensure all appropriate parties maintain and timely complete their review of the local office security monitoring reports and high-risk Bridges transaction monitoring reports. Effect We consider these issues to be a material weakness because, without effective security management and access controls, individuals may obtain unauthorized or inappropriate access to Bridges. As a result, an increased risk exists that MDHHS cannot ensure the security of the Bridges application and data used to help determine eligibility and benefit levels for the SNAP Cluster, Pandemic Electronic Benefits Transfer (P-EBT) Food Benefits, CCDF Cluster, Medicaid Cluster, Temporary Assistance for Needy Families (TANF), Refugee and Entrant Assistance State/Replacement Designee Administered Programs (REAP), Low-Income Home Energy Assistance Program (LIHEAP), and Children's Health Insurance Program (CHIP). Known Questioned Costs None. Recommendation We recommend MDHHS establish effective security management and access controls over Bridges users. Management Views MDHHS agrees with the finding.
FINDING 2023-003 Bridges Change Management Process See Schedule of Findings and Questioned Costs for chart/table. Condition MDHHS did not fully implement an effective change management process over Bridges. Our review disclosed MDHHS did not document post-implementation approvals for 3 (12%) of 25 sampled Bridges change records. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. SOM Technical Standard 1340.00.060.04 requires the business owner perform post-implementation validation. SOM Technical Procedure 1340.00.060.04.01 requires each test type to have its own set of documentation. State of Michigan Administrative Guide to State Government policy 1340.00 requires approved personnel to adequately manage the configuration* of the State's systems, such as retaining previous system configurations, configuring approved devices for high-risk areas, and tracking and documenting system changes. Cause MDHHS informed us it did not always follow established processes for documenting testing and business owner approvals. Effect Without an effective change management process, individuals may make unauthorized or inappropriate changes to Bridges. As a result, an increased risk exists that MDHHS cannot ensure Bridges is configured and operating securely and as intended. Known Questioned Costs None. Recommendation We recommend MDHHS fully implement an effective change management process over Bridges. Management Views MDHHS agrees with the finding.
FINDING 2023-002 Bridges Security Management and Access Controls* See Schedule of Findings and Questioned Costs for chart/table. Condition MDHHS had not established effective security management and access controls over Bridges users. We noted: a. MDHHS did not maintain documentation for 30 (75%) of the 40 sampled Bridges incompatible role exception requests. Of the 10 forms received, we noted MDHHS did not properly approve 6 forms prior to granting the exception requests. b. MDHHS did not maintain documentation for 21 (26%) of 80 sampled local office security monitoring reports. Also, MDHHS did not complete timely reviews for 2 (3%) of 59 sampled security monitoring reports. c. MDHHS did not maintain documentation for 1 (3%) of the 40 sampled Bridges application security agreements. Of the 39 forms received, we noted MDHHS did not properly approve 10 (26%) forms prior to granting access to Bridges. d. MDHHS did not monitor non-local office Bridges user accounts for compliance with account management requirements semiannually for privileged users or annually for all other users. e. MDHHS did not maintain documentation for 9 (45%) of the 20 sampled local office high risk Bridges transaction monitoring reports. Of the 11 reports received, MDHHS did not complete the review timely or did not document its review date for 3 (27%) of the reports. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. According to State of Michigan Administrative Guide to State Government policy 1340.00, security controls must be implemented to protect State of Michigan information from unauthorized access, use, disclosure, modification, destruction, or denial and to ensure confidentiality, integrity, and availability of State of Michigan information. State of Michigan (SOM) Technical Standard 1340.00.020.01 requires agencies to implement and document baseline controls ensuring users are only granted access which is necessary to accomplish assigned tasks in accordance with roles and responsibilities of their job functions. The Standard also requires separation of duties must be implemented through assigned information system access authorizations and accounts should be reviewed for compliance with account management requirements semiannually for privileged accounts* and annually for all other accounts. In addition, the GAO's FISCAM recommends compensating controls, such as additional monitoring and supervision, should be in place where segregation of duties'* conflicts exist. Cause For parts a., c., and d., MDHHS's internal control and monitoring activities were not sufficient to ensure all appropriate parties adhered to established policies and procedures. For parts b. and e., MDHHS's internal control and monitoring activities need improvement to ensure all appropriate parties maintain and timely complete their review of the local office security monitoring reports and high-risk Bridges transaction monitoring reports. Effect We consider these issues to be a material weakness because, without effective security management and access controls, individuals may obtain unauthorized or inappropriate access to Bridges. As a result, an increased risk exists that MDHHS cannot ensure the security of the Bridges application and data used to help determine eligibility and benefit levels for the SNAP Cluster, Pandemic Electronic Benefits Transfer (P-EBT) Food Benefits, CCDF Cluster, Medicaid Cluster, Temporary Assistance for Needy Families (TANF), Refugee and Entrant Assistance State/Replacement Designee Administered Programs (REAP), Low-Income Home Energy Assistance Program (LIHEAP), and Children's Health Insurance Program (CHIP). Known Questioned Costs None. Recommendation We recommend MDHHS establish effective security management and access controls over Bridges users. Management Views MDHHS agrees with the finding.
FINDING 2023-003 Bridges Change Management Process See Schedule of Findings and Questioned Costs for chart/table. Condition MDHHS did not fully implement an effective change management process over Bridges. Our review disclosed MDHHS did not document post-implementation approvals for 3 (12%) of 25 sampled Bridges change records. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. SOM Technical Standard 1340.00.060.04 requires the business owner perform post-implementation validation. SOM Technical Procedure 1340.00.060.04.01 requires each test type to have its own set of documentation. State of Michigan Administrative Guide to State Government policy 1340.00 requires approved personnel to adequately manage the configuration* of the State's systems, such as retaining previous system configurations, configuring approved devices for high-risk areas, and tracking and documenting system changes. Cause MDHHS informed us it did not always follow established processes for documenting testing and business owner approvals. Effect Without an effective change management process, individuals may make unauthorized or inappropriate changes to Bridges. As a result, an increased risk exists that MDHHS cannot ensure Bridges is configured and operating securely and as intended. Known Questioned Costs None. Recommendation We recommend MDHHS fully implement an effective change management process over Bridges. Management Views MDHHS agrees with the finding.
FINDING 2023-002 Bridges Security Management and Access Controls* See Schedule of Findings and Questioned Costs for chart/table. Condition MDHHS had not established effective security management and access controls over Bridges users. We noted: a. MDHHS did not maintain documentation for 30 (75%) of the 40 sampled Bridges incompatible role exception requests. Of the 10 forms received, we noted MDHHS did not properly approve 6 forms prior to granting the exception requests. b. MDHHS did not maintain documentation for 21 (26%) of 80 sampled local office security monitoring reports. Also, MDHHS did not complete timely reviews for 2 (3%) of 59 sampled security monitoring reports. c. MDHHS did not maintain documentation for 1 (3%) of the 40 sampled Bridges application security agreements. Of the 39 forms received, we noted MDHHS did not properly approve 10 (26%) forms prior to granting access to Bridges. d. MDHHS did not monitor non-local office Bridges user accounts for compliance with account management requirements semiannually for privileged users or annually for all other users. e. MDHHS did not maintain documentation for 9 (45%) of the 20 sampled local office high risk Bridges transaction monitoring reports. Of the 11 reports received, MDHHS did not complete the review timely or did not document its review date for 3 (27%) of the reports. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. According to State of Michigan Administrative Guide to State Government policy 1340.00, security controls must be implemented to protect State of Michigan information from unauthorized access, use, disclosure, modification, destruction, or denial and to ensure confidentiality, integrity, and availability of State of Michigan information. State of Michigan (SOM) Technical Standard 1340.00.020.01 requires agencies to implement and document baseline controls ensuring users are only granted access which is necessary to accomplish assigned tasks in accordance with roles and responsibilities of their job functions. The Standard also requires separation of duties must be implemented through assigned information system access authorizations and accounts should be reviewed for compliance with account management requirements semiannually for privileged accounts* and annually for all other accounts. In addition, the GAO's FISCAM recommends compensating controls, such as additional monitoring and supervision, should be in place where segregation of duties'* conflicts exist. Cause For parts a., c., and d., MDHHS's internal control and monitoring activities were not sufficient to ensure all appropriate parties adhered to established policies and procedures. For parts b. and e., MDHHS's internal control and monitoring activities need improvement to ensure all appropriate parties maintain and timely complete their review of the local office security monitoring reports and high-risk Bridges transaction monitoring reports. Effect We consider these issues to be a material weakness because, without effective security management and access controls, individuals may obtain unauthorized or inappropriate access to Bridges. As a result, an increased risk exists that MDHHS cannot ensure the security of the Bridges application and data used to help determine eligibility and benefit levels for the SNAP Cluster, Pandemic Electronic Benefits Transfer (P-EBT) Food Benefits, CCDF Cluster, Medicaid Cluster, Temporary Assistance for Needy Families (TANF), Refugee and Entrant Assistance State/Replacement Designee Administered Programs (REAP), Low-Income Home Energy Assistance Program (LIHEAP), and Children's Health Insurance Program (CHIP). Known Questioned Costs None. Recommendation We recommend MDHHS establish effective security management and access controls over Bridges users. Management Views MDHHS agrees with the finding.
FINDING 2023-003 Bridges Change Management Process See Schedule of Findings and Questioned Costs for chart/table. Condition MDHHS did not fully implement an effective change management process over Bridges. Our review disclosed MDHHS did not document post-implementation approvals for 3 (12%) of 25 sampled Bridges change records. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. SOM Technical Standard 1340.00.060.04 requires the business owner perform post-implementation validation. SOM Technical Procedure 1340.00.060.04.01 requires each test type to have its own set of documentation. State of Michigan Administrative Guide to State Government policy 1340.00 requires approved personnel to adequately manage the configuration* of the State's systems, such as retaining previous system configurations, configuring approved devices for high-risk areas, and tracking and documenting system changes. Cause MDHHS informed us it did not always follow established processes for documenting testing and business owner approvals. Effect Without an effective change management process, individuals may make unauthorized or inappropriate changes to Bridges. As a result, an increased risk exists that MDHHS cannot ensure Bridges is configured and operating securely and as intended. Known Questioned Costs None. Recommendation We recommend MDHHS fully implement an effective change management process over Bridges. Management Views MDHHS agrees with the finding.
FINDING 2023-002 Bridges Security Management and Access Controls* See Schedule of Findings and Questioned Costs for chart/table. Condition MDHHS had not established effective security management and access controls over Bridges users. We noted: a. MDHHS did not maintain documentation for 30 (75%) of the 40 sampled Bridges incompatible role exception requests. Of the 10 forms received, we noted MDHHS did not properly approve 6 forms prior to granting the exception requests. b. MDHHS did not maintain documentation for 21 (26%) of 80 sampled local office security monitoring reports. Also, MDHHS did not complete timely reviews for 2 (3%) of 59 sampled security monitoring reports. c. MDHHS did not maintain documentation for 1 (3%) of the 40 sampled Bridges application security agreements. Of the 39 forms received, we noted MDHHS did not properly approve 10 (26%) forms prior to granting access to Bridges. d. MDHHS did not monitor non-local office Bridges user accounts for compliance with account management requirements semiannually for privileged users or annually for all other users. e. MDHHS did not maintain documentation for 9 (45%) of the 20 sampled local office high risk Bridges transaction monitoring reports. Of the 11 reports received, MDHHS did not complete the review timely or did not document its review date for 3 (27%) of the reports. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. According to State of Michigan Administrative Guide to State Government policy 1340.00, security controls must be implemented to protect State of Michigan information from unauthorized access, use, disclosure, modification, destruction, or denial and to ensure confidentiality, integrity, and availability of State of Michigan information. State of Michigan (SOM) Technical Standard 1340.00.020.01 requires agencies to implement and document baseline controls ensuring users are only granted access which is necessary to accomplish assigned tasks in accordance with roles and responsibilities of their job functions. The Standard also requires separation of duties must be implemented through assigned information system access authorizations and accounts should be reviewed for compliance with account management requirements semiannually for privileged accounts* and annually for all other accounts. In addition, the GAO's FISCAM recommends compensating controls, such as additional monitoring and supervision, should be in place where segregation of duties'* conflicts exist. Cause For parts a., c., and d., MDHHS's internal control and monitoring activities were not sufficient to ensure all appropriate parties adhered to established policies and procedures. For parts b. and e., MDHHS's internal control and monitoring activities need improvement to ensure all appropriate parties maintain and timely complete their review of the local office security monitoring reports and high-risk Bridges transaction monitoring reports. Effect We consider these issues to be a material weakness because, without effective security management and access controls, individuals may obtain unauthorized or inappropriate access to Bridges. As a result, an increased risk exists that MDHHS cannot ensure the security of the Bridges application and data used to help determine eligibility and benefit levels for the SNAP Cluster, Pandemic Electronic Benefits Transfer (P-EBT) Food Benefits, CCDF Cluster, Medicaid Cluster, Temporary Assistance for Needy Families (TANF), Refugee and Entrant Assistance State/Replacement Designee Administered Programs (REAP), Low-Income Home Energy Assistance Program (LIHEAP), and Children's Health Insurance Program (CHIP). Known Questioned Costs None. Recommendation We recommend MDHHS establish effective security management and access controls over Bridges users. Management Views MDHHS agrees with the finding.
FINDING 2023-003 Bridges Change Management Process See Schedule of Findings and Questioned Costs for chart/table. Condition MDHHS did not fully implement an effective change management process over Bridges. Our review disclosed MDHHS did not document post-implementation approvals for 3 (12%) of 25 sampled Bridges change records. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. SOM Technical Standard 1340.00.060.04 requires the business owner perform post-implementation validation. SOM Technical Procedure 1340.00.060.04.01 requires each test type to have its own set of documentation. State of Michigan Administrative Guide to State Government policy 1340.00 requires approved personnel to adequately manage the configuration* of the State's systems, such as retaining previous system configurations, configuring approved devices for high-risk areas, and tracking and documenting system changes. Cause MDHHS informed us it did not always follow established processes for documenting testing and business owner approvals. Effect Without an effective change management process, individuals may make unauthorized or inappropriate changes to Bridges. As a result, an increased risk exists that MDHHS cannot ensure Bridges is configured and operating securely and as intended. Known Questioned Costs None. Recommendation We recommend MDHHS fully implement an effective change management process over Bridges. Management Views MDHHS agrees with the finding.
FINDING 2023-002 Bridges Security Management and Access Controls* See Schedule of Findings and Questioned Costs for chart/table. Condition MDHHS had not established effective security management and access controls over Bridges users. We noted: a. MDHHS did not maintain documentation for 30 (75%) of the 40 sampled Bridges incompatible role exception requests. Of the 10 forms received, we noted MDHHS did not properly approve 6 forms prior to granting the exception requests. b. MDHHS did not maintain documentation for 21 (26%) of 80 sampled local office security monitoring reports. Also, MDHHS did not complete timely reviews for 2 (3%) of 59 sampled security monitoring reports. c. MDHHS did not maintain documentation for 1 (3%) of the 40 sampled Bridges application security agreements. Of the 39 forms received, we noted MDHHS did not properly approve 10 (26%) forms prior to granting access to Bridges. d. MDHHS did not monitor non-local office Bridges user accounts for compliance with account management requirements semiannually for privileged users or annually for all other users. e. MDHHS did not maintain documentation for 9 (45%) of the 20 sampled local office high risk Bridges transaction monitoring reports. Of the 11 reports received, MDHHS did not complete the review timely or did not document its review date for 3 (27%) of the reports. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. According to State of Michigan Administrative Guide to State Government policy 1340.00, security controls must be implemented to protect State of Michigan information from unauthorized access, use, disclosure, modification, destruction, or denial and to ensure confidentiality, integrity, and availability of State of Michigan information. State of Michigan (SOM) Technical Standard 1340.00.020.01 requires agencies to implement and document baseline controls ensuring users are only granted access which is necessary to accomplish assigned tasks in accordance with roles and responsibilities of their job functions. The Standard also requires separation of duties must be implemented through assigned information system access authorizations and accounts should be reviewed for compliance with account management requirements semiannually for privileged accounts* and annually for all other accounts. In addition, the GAO's FISCAM recommends compensating controls, such as additional monitoring and supervision, should be in place where segregation of duties'* conflicts exist. Cause For parts a., c., and d., MDHHS's internal control and monitoring activities were not sufficient to ensure all appropriate parties adhered to established policies and procedures. For parts b. and e., MDHHS's internal control and monitoring activities need improvement to ensure all appropriate parties maintain and timely complete their review of the local office security monitoring reports and high-risk Bridges transaction monitoring reports. Effect We consider these issues to be a material weakness because, without effective security management and access controls, individuals may obtain unauthorized or inappropriate access to Bridges. As a result, an increased risk exists that MDHHS cannot ensure the security of the Bridges application and data used to help determine eligibility and benefit levels for the SNAP Cluster, Pandemic Electronic Benefits Transfer (P-EBT) Food Benefits, CCDF Cluster, Medicaid Cluster, Temporary Assistance for Needy Families (TANF), Refugee and Entrant Assistance State/Replacement Designee Administered Programs (REAP), Low-Income Home Energy Assistance Program (LIHEAP), and Children's Health Insurance Program (CHIP). Known Questioned Costs None. Recommendation We recommend MDHHS establish effective security management and access controls over Bridges users. Management Views MDHHS agrees with the finding.
FINDING 2023-003 Bridges Change Management Process See Schedule of Findings and Questioned Costs for chart/table. Condition MDHHS did not fully implement an effective change management process over Bridges. Our review disclosed MDHHS did not document post-implementation approvals for 3 (12%) of 25 sampled Bridges change records. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. SOM Technical Standard 1340.00.060.04 requires the business owner perform post-implementation validation. SOM Technical Procedure 1340.00.060.04.01 requires each test type to have its own set of documentation. State of Michigan Administrative Guide to State Government policy 1340.00 requires approved personnel to adequately manage the configuration* of the State's systems, such as retaining previous system configurations, configuring approved devices for high-risk areas, and tracking and documenting system changes. Cause MDHHS informed us it did not always follow established processes for documenting testing and business owner approvals. Effect Without an effective change management process, individuals may make unauthorized or inappropriate changes to Bridges. As a result, an increased risk exists that MDHHS cannot ensure Bridges is configured and operating securely and as intended. Known Questioned Costs None. Recommendation We recommend MDHHS fully implement an effective change management process over Bridges. Management Views MDHHS agrees with the finding.
FINDING 2023-002 Bridges Security Management and Access Controls* See Schedule of Findings and Questioned Costs for chart/table. Condition MDHHS had not established effective security management and access controls over Bridges users. We noted: a. MDHHS did not maintain documentation for 30 (75%) of the 40 sampled Bridges incompatible role exception requests. Of the 10 forms received, we noted MDHHS did not properly approve 6 forms prior to granting the exception requests. b. MDHHS did not maintain documentation for 21 (26%) of 80 sampled local office security monitoring reports. Also, MDHHS did not complete timely reviews for 2 (3%) of 59 sampled security monitoring reports. c. MDHHS did not maintain documentation for 1 (3%) of the 40 sampled Bridges application security agreements. Of the 39 forms received, we noted MDHHS did not properly approve 10 (26%) forms prior to granting access to Bridges. d. MDHHS did not monitor non-local office Bridges user accounts for compliance with account management requirements semiannually for privileged users or annually for all other users. e. MDHHS did not maintain documentation for 9 (45%) of the 20 sampled local office high risk Bridges transaction monitoring reports. Of the 11 reports received, MDHHS did not complete the review timely or did not document its review date for 3 (27%) of the reports. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. According to State of Michigan Administrative Guide to State Government policy 1340.00, security controls must be implemented to protect State of Michigan information from unauthorized access, use, disclosure, modification, destruction, or denial and to ensure confidentiality, integrity, and availability of State of Michigan information. State of Michigan (SOM) Technical Standard 1340.00.020.01 requires agencies to implement and document baseline controls ensuring users are only granted access which is necessary to accomplish assigned tasks in accordance with roles and responsibilities of their job functions. The Standard also requires separation of duties must be implemented through assigned information system access authorizations and accounts should be reviewed for compliance with account management requirements semiannually for privileged accounts* and annually for all other accounts. In addition, the GAO's FISCAM recommends compensating controls, such as additional monitoring and supervision, should be in place where segregation of duties'* conflicts exist. Cause For parts a., c., and d., MDHHS's internal control and monitoring activities were not sufficient to ensure all appropriate parties adhered to established policies and procedures. For parts b. and e., MDHHS's internal control and monitoring activities need improvement to ensure all appropriate parties maintain and timely complete their review of the local office security monitoring reports and high-risk Bridges transaction monitoring reports. Effect We consider these issues to be a material weakness because, without effective security management and access controls, individuals may obtain unauthorized or inappropriate access to Bridges. As a result, an increased risk exists that MDHHS cannot ensure the security of the Bridges application and data used to help determine eligibility and benefit levels for the SNAP Cluster, Pandemic Electronic Benefits Transfer (P-EBT) Food Benefits, CCDF Cluster, Medicaid Cluster, Temporary Assistance for Needy Families (TANF), Refugee and Entrant Assistance State/Replacement Designee Administered Programs (REAP), Low-Income Home Energy Assistance Program (LIHEAP), and Children's Health Insurance Program (CHIP). Known Questioned Costs None. Recommendation We recommend MDHHS establish effective security management and access controls over Bridges users. Management Views MDHHS agrees with the finding.
FINDING 2023-003 Bridges Change Management Process See Schedule of Findings and Questioned Costs for chart/table. Condition MDHHS did not fully implement an effective change management process over Bridges. Our review disclosed MDHHS did not document post-implementation approvals for 3 (12%) of 25 sampled Bridges change records. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. SOM Technical Standard 1340.00.060.04 requires the business owner perform post-implementation validation. SOM Technical Procedure 1340.00.060.04.01 requires each test type to have its own set of documentation. State of Michigan Administrative Guide to State Government policy 1340.00 requires approved personnel to adequately manage the configuration* of the State's systems, such as retaining previous system configurations, configuring approved devices for high-risk areas, and tracking and documenting system changes. Cause MDHHS informed us it did not always follow established processes for documenting testing and business owner approvals. Effect Without an effective change management process, individuals may make unauthorized or inappropriate changes to Bridges. As a result, an increased risk exists that MDHHS cannot ensure Bridges is configured and operating securely and as intended. Known Questioned Costs None. Recommendation We recommend MDHHS fully implement an effective change management process over Bridges. Management Views MDHHS agrees with the finding.
FINDING 2023-002 Bridges Security Management and Access Controls* See Schedule of Findings and Questioned Costs for chart/table. Condition MDHHS had not established effective security management and access controls over Bridges users. We noted: a. MDHHS did not maintain documentation for 30 (75%) of the 40 sampled Bridges incompatible role exception requests. Of the 10 forms received, we noted MDHHS did not properly approve 6 forms prior to granting the exception requests. b. MDHHS did not maintain documentation for 21 (26%) of 80 sampled local office security monitoring reports. Also, MDHHS did not complete timely reviews for 2 (3%) of 59 sampled security monitoring reports. c. MDHHS did not maintain documentation for 1 (3%) of the 40 sampled Bridges application security agreements. Of the 39 forms received, we noted MDHHS did not properly approve 10 (26%) forms prior to granting access to Bridges. d. MDHHS did not monitor non-local office Bridges user accounts for compliance with account management requirements semiannually for privileged users or annually for all other users. e. MDHHS did not maintain documentation for 9 (45%) of the 20 sampled local office high risk Bridges transaction monitoring reports. Of the 11 reports received, MDHHS did not complete the review timely or did not document its review date for 3 (27%) of the reports. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. According to State of Michigan Administrative Guide to State Government policy 1340.00, security controls must be implemented to protect State of Michigan information from unauthorized access, use, disclosure, modification, destruction, or denial and to ensure confidentiality, integrity, and availability of State of Michigan information. State of Michigan (SOM) Technical Standard 1340.00.020.01 requires agencies to implement and document baseline controls ensuring users are only granted access which is necessary to accomplish assigned tasks in accordance with roles and responsibilities of their job functions. The Standard also requires separation of duties must be implemented through assigned information system access authorizations and accounts should be reviewed for compliance with account management requirements semiannually for privileged accounts* and annually for all other accounts. In addition, the GAO's FISCAM recommends compensating controls, such as additional monitoring and supervision, should be in place where segregation of duties'* conflicts exist. Cause For parts a., c., and d., MDHHS's internal control and monitoring activities were not sufficient to ensure all appropriate parties adhered to established policies and procedures. For parts b. and e., MDHHS's internal control and monitoring activities need improvement to ensure all appropriate parties maintain and timely complete their review of the local office security monitoring reports and high-risk Bridges transaction monitoring reports. Effect We consider these issues to be a material weakness because, without effective security management and access controls, individuals may obtain unauthorized or inappropriate access to Bridges. As a result, an increased risk exists that MDHHS cannot ensure the security of the Bridges application and data used to help determine eligibility and benefit levels for the SNAP Cluster, Pandemic Electronic Benefits Transfer (P-EBT) Food Benefits, CCDF Cluster, Medicaid Cluster, Temporary Assistance for Needy Families (TANF), Refugee and Entrant Assistance State/Replacement Designee Administered Programs (REAP), Low-Income Home Energy Assistance Program (LIHEAP), and Children's Health Insurance Program (CHIP). Known Questioned Costs None. Recommendation We recommend MDHHS establish effective security management and access controls over Bridges users. Management Views MDHHS agrees with the finding.
FINDING 2023-003 Bridges Change Management Process See Schedule of Findings and Questioned Costs for chart/table. Condition MDHHS did not fully implement an effective change management process over Bridges. Our review disclosed MDHHS did not document post-implementation approvals for 3 (12%) of 25 sampled Bridges change records. Criteria Federal regulations 2 CFR 200.303 and 45 CFR 75.303 require the auditee to establish and maintain effective internal control over federal awards that provides reasonable assurance the auditee is managing federal awards in compliance with federal statutes, regulations, and the terms and conditions of federal awards. SOM Technical Standard 1340.00.060.04 requires the business owner perform post-implementation validation. SOM Technical Procedure 1340.00.060.04.01 requires each test type to have its own set of documentation. State of Michigan Administrative Guide to State Government policy 1340.00 requires approved personnel to adequately manage the configuration* of the State's systems, such as retaining previous system configurations, configuring approved devices for high-risk areas, and tracking and documenting system changes. Cause MDHHS informed us it did not always follow established processes for documenting testing and business owner approvals. Effect Without an effective change management process, individuals may make unauthorized or inappropriate changes to Bridges. As a result, an increased risk exists that MDHHS cannot ensure Bridges is configured and operating securely and as intended. Known Questioned Costs None. Recommendation We recommend MDHHS fully implement an effective change management process over Bridges. Management Views MDHHS agrees with the finding.
Finding 2023-003: Suspension and Debarment Information About the Program: All Programs Criteria: As stated in 2 CFR §200.303, the non-Federal entity (i.e. NFHA) must establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations and terms and conditions of the Federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or in the “Internal Control Integrated Framework” issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). According to 2 CFR §200.214, the non-Federal entity is subject to the non-procurement debarment and suspension regulations implementing Executive Orders 12549 and 12689, 2 CFR part 180. The regulations in 2 CFR part 180 restrict awards, subawards, and contracts with certain parties that are debarred, suspended, or otherwise excluded from or ineligible for participation in Federal assistance programs or activities. Condition: During our audit, we noted NFHA did not perform checks via SAM.gov to ensure that potential vendors, contractors, or consultants are suspended or debarred. The failure to screen such parties increases the possibility that U.S. Government funds may inadvertently be provided to individuals or organizations deemed to be excluded by the U.S. Government. Cause: Management did not have effective internal controls in place to ensure that suspension and debarment checks were being performed prior to entering into contracts with vendors or contractors/ consultants.Potential Effect: NFHA is exposed to an increased risk that future noncompliance could occur by entering into transactions with vendors, contractors, or consultants that are suspended, debarred, or otherwise excluded from contracting with the U.S. Federal Government. If a non-Federal entity knowingly does business with an excluded person, the agency responsible for NFHA's funding may disallow costs, annul or terminate the transaction, issue a stop work order, debar or suspend NFHA, or take other remedies as appropriate. Questioned Costs: None. Context: NFHA failed to perform its due diligence with respect to these requirements. The issue is considered systemic in nature. Identification as a Repeat Finding: Not applicable. Recommendation: We recommend NFHA implement internal controls to ensure that all vendors, contractors, and consultants are screened for suspension and debarment prior to entering into any executed contract. We further recommend that a policy be formalized and implemented that requires an annual screening, at a minimum, of any current vendors, contractors, or consultants as well.
Finding 2023-004: Procurement Information About the Program: All Programs Criteria: According to 2 CFR §200.303, the non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non- Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in Standards for Internal Control in the Federal Government issued by the Comptroller General of the United States or the internal Control Integrated Framework, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Additionally, according to 2 CFR §200.318 Procurement standards, the non-Federal entity must maintain records sufficient to detail the history of procurement. These records will include, but are not necessarily limited to, the following: Rationale for the method of procurement, selection of contract type, contractor selection or rejection, and the basis for the contract price. Title 2, Subtitle A Chapter II Part 200 Subpart D 200.319 Procurement Standards. All procurement transactions for the acquisition of property or services required under a Federal award must be conducted in a manner providing full and open competition consistent with the standards of this section and §200.320. The non-Federal entity must have written procedures for procurement transactions. These procedures must ensure that all solicitations: (1) Incorporate a clear and accurate description of the technical requirements for the material, product, or service to be procured. Such description must not, in competitive procurements, contain features which unduly restrict competition. The description may include a statement of the qualitative nature of the material, product or service to be procured and, when necessary, must set forth those minimum essential characteristics and standards to which it must conform if it is to satisfy its intended use. Noncompetitive procurements can only be awarded in accordance with §200.320(c). According to 2 CFR §200.320 Procurement Standards, there are specific circumstances in which noncompetitive procurement can be used. Noncompetitive procurement can only be awarded if one or more of the following circumstances apply: 1. The acquisition of property or services, the aggregate dollar amount of which does not exceed the micro-purchase threshold (see paragraph (a)(1) of this section); 2. The item is available only from a single source; 3. The public exigency or emergency for the requirement will not permit a delay resulting from publicizing a competitive solicitation; 4. The Federal awarding agency or pass-through entity expressly authorizes a noncompetitive procurement in response to a written request from the non-Federal entity; or 5. After solicitation of a number of sources, competition is determined inadequate. Condition: During our testing over procurement, we determined NFHA did not clearly document the rationale for the method of procurement, selection of contract type, contractor selection or rejection, and the basis for the contract price. In addition, for noncompetitive procurements, there was no documentation to support which of the five criteria was met to allow for the noncompetitive procurement. Cause: Management did not have effective internal controls in place to ensure that procurement requirements were adequately documented and retained. Effect: Procurement records were insufficient to meet the requirements noted in the Criteria section above, as well as NFHA's internal procurement policy. Questioned Costs: None. Context: We noted that several items selected for testing did not document the rationale for the method of procurement, selection of contract type, contractor selection or rejection, and the basis for the contract price. In addition, we noted that several items selected for testing for noncompetitive procurements did not maintain documentation of which of the five criteria were met to allow for the noncompetitive procurement. Identification as a Repeat Finding: Not applicable. Recommendation: We recommend NFHA update its policies to treat Federal and non-Federal procurement the same and ensure compliance with Uniform Guidance. NFHA should retain sufficient procurement documentation to meet the requirements noted in the Criteria section above.
Finding 2023-003: Suspension and Debarment Information About the Program: All Programs Criteria: As stated in 2 CFR §200.303, the non-Federal entity (i.e. NFHA) must establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations and terms and conditions of the Federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or in the “Internal Control Integrated Framework” issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). According to 2 CFR §200.214, the non-Federal entity is subject to the non-procurement debarment and suspension regulations implementing Executive Orders 12549 and 12689, 2 CFR part 180. The regulations in 2 CFR part 180 restrict awards, subawards, and contracts with certain parties that are debarred, suspended, or otherwise excluded from or ineligible for participation in Federal assistance programs or activities. Condition: During our audit, we noted NFHA did not perform checks via SAM.gov to ensure that potential vendors, contractors, or consultants are suspended or debarred. The failure to screen such parties increases the possibility that U.S. Government funds may inadvertently be provided to individuals or organizations deemed to be excluded by the U.S. Government. Cause: Management did not have effective internal controls in place to ensure that suspension and debarment checks were being performed prior to entering into contracts with vendors or contractors/ consultants.Potential Effect: NFHA is exposed to an increased risk that future noncompliance could occur by entering into transactions with vendors, contractors, or consultants that are suspended, debarred, or otherwise excluded from contracting with the U.S. Federal Government. If a non-Federal entity knowingly does business with an excluded person, the agency responsible for NFHA's funding may disallow costs, annul or terminate the transaction, issue a stop work order, debar or suspend NFHA, or take other remedies as appropriate. Questioned Costs: None. Context: NFHA failed to perform its due diligence with respect to these requirements. The issue is considered systemic in nature. Identification as a Repeat Finding: Not applicable. Recommendation: We recommend NFHA implement internal controls to ensure that all vendors, contractors, and consultants are screened for suspension and debarment prior to entering into any executed contract. We further recommend that a policy be formalized and implemented that requires an annual screening, at a minimum, of any current vendors, contractors, or consultants as well.
Finding 2023-004: Procurement Information About the Program: All Programs Criteria: According to 2 CFR §200.303, the non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non- Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in Standards for Internal Control in the Federal Government issued by the Comptroller General of the United States or the internal Control Integrated Framework, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Additionally, according to 2 CFR §200.318 Procurement standards, the non-Federal entity must maintain records sufficient to detail the history of procurement. These records will include, but are not necessarily limited to, the following: Rationale for the method of procurement, selection of contract type, contractor selection or rejection, and the basis for the contract price. Title 2, Subtitle A Chapter II Part 200 Subpart D 200.319 Procurement Standards. All procurement transactions for the acquisition of property or services required under a Federal award must be conducted in a manner providing full and open competition consistent with the standards of this section and §200.320. The non-Federal entity must have written procedures for procurement transactions. These procedures must ensure that all solicitations: (1) Incorporate a clear and accurate description of the technical requirements for the material, product, or service to be procured. Such description must not, in competitive procurements, contain features which unduly restrict competition. The description may include a statement of the qualitative nature of the material, product or service to be procured and, when necessary, must set forth those minimum essential characteristics and standards to which it must conform if it is to satisfy its intended use. Noncompetitive procurements can only be awarded in accordance with §200.320(c). According to 2 CFR §200.320 Procurement Standards, there are specific circumstances in which noncompetitive procurement can be used. Noncompetitive procurement can only be awarded if one or more of the following circumstances apply: 1. The acquisition of property or services, the aggregate dollar amount of which does not exceed the micro-purchase threshold (see paragraph (a)(1) of this section); 2. The item is available only from a single source; 3. The public exigency or emergency for the requirement will not permit a delay resulting from publicizing a competitive solicitation; 4. The Federal awarding agency or pass-through entity expressly authorizes a noncompetitive procurement in response to a written request from the non-Federal entity; or 5. After solicitation of a number of sources, competition is determined inadequate. Condition: During our testing over procurement, we determined NFHA did not clearly document the rationale for the method of procurement, selection of contract type, contractor selection or rejection, and the basis for the contract price. In addition, for noncompetitive procurements, there was no documentation to support which of the five criteria was met to allow for the noncompetitive procurement. Cause: Management did not have effective internal controls in place to ensure that procurement requirements were adequately documented and retained. Effect: Procurement records were insufficient to meet the requirements noted in the Criteria section above, as well as NFHA's internal procurement policy. Questioned Costs: None. Context: We noted that several items selected for testing did not document the rationale for the method of procurement, selection of contract type, contractor selection or rejection, and the basis for the contract price. In addition, we noted that several items selected for testing for noncompetitive procurements did not maintain documentation of which of the five criteria were met to allow for the noncompetitive procurement. Identification as a Repeat Finding: Not applicable. Recommendation: We recommend NFHA update its policies to treat Federal and non-Federal procurement the same and ensure compliance with Uniform Guidance. NFHA should retain sufficient procurement documentation to meet the requirements noted in the Criteria section above.
Finding 2023-003: Suspension and Debarment Information About the Program: All Programs Criteria: As stated in 2 CFR §200.303, the non-Federal entity (i.e. NFHA) must establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations and terms and conditions of the Federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or in the “Internal Control Integrated Framework” issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). According to 2 CFR §200.214, the non-Federal entity is subject to the non-procurement debarment and suspension regulations implementing Executive Orders 12549 and 12689, 2 CFR part 180. The regulations in 2 CFR part 180 restrict awards, subawards, and contracts with certain parties that are debarred, suspended, or otherwise excluded from or ineligible for participation in Federal assistance programs or activities. Condition: During our audit, we noted NFHA did not perform checks via SAM.gov to ensure that potential vendors, contractors, or consultants are suspended or debarred. The failure to screen such parties increases the possibility that U.S. Government funds may inadvertently be provided to individuals or organizations deemed to be excluded by the U.S. Government. Cause: Management did not have effective internal controls in place to ensure that suspension and debarment checks were being performed prior to entering into contracts with vendors or contractors/ consultants.Potential Effect: NFHA is exposed to an increased risk that future noncompliance could occur by entering into transactions with vendors, contractors, or consultants that are suspended, debarred, or otherwise excluded from contracting with the U.S. Federal Government. If a non-Federal entity knowingly does business with an excluded person, the agency responsible for NFHA's funding may disallow costs, annul or terminate the transaction, issue a stop work order, debar or suspend NFHA, or take other remedies as appropriate. Questioned Costs: None. Context: NFHA failed to perform its due diligence with respect to these requirements. The issue is considered systemic in nature. Identification as a Repeat Finding: Not applicable. Recommendation: We recommend NFHA implement internal controls to ensure that all vendors, contractors, and consultants are screened for suspension and debarment prior to entering into any executed contract. We further recommend that a policy be formalized and implemented that requires an annual screening, at a minimum, of any current vendors, contractors, or consultants as well.
Finding 2023-004: Procurement Information About the Program: All Programs Criteria: According to 2 CFR §200.303, the non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non- Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in Standards for Internal Control in the Federal Government issued by the Comptroller General of the United States or the internal Control Integrated Framework, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Additionally, according to 2 CFR §200.318 Procurement standards, the non-Federal entity must maintain records sufficient to detail the history of procurement. These records will include, but are not necessarily limited to, the following: Rationale for the method of procurement, selection of contract type, contractor selection or rejection, and the basis for the contract price. Title 2, Subtitle A Chapter II Part 200 Subpart D 200.319 Procurement Standards. All procurement transactions for the acquisition of property or services required under a Federal award must be conducted in a manner providing full and open competition consistent with the standards of this section and §200.320. The non-Federal entity must have written procedures for procurement transactions. These procedures must ensure that all solicitations: (1) Incorporate a clear and accurate description of the technical requirements for the material, product, or service to be procured. Such description must not, in competitive procurements, contain features which unduly restrict competition. The description may include a statement of the qualitative nature of the material, product or service to be procured and, when necessary, must set forth those minimum essential characteristics and standards to which it must conform if it is to satisfy its intended use. Noncompetitive procurements can only be awarded in accordance with §200.320(c). According to 2 CFR §200.320 Procurement Standards, there are specific circumstances in which noncompetitive procurement can be used. Noncompetitive procurement can only be awarded if one or more of the following circumstances apply: 1. The acquisition of property or services, the aggregate dollar amount of which does not exceed the micro-purchase threshold (see paragraph (a)(1) of this section); 2. The item is available only from a single source; 3. The public exigency or emergency for the requirement will not permit a delay resulting from publicizing a competitive solicitation; 4. The Federal awarding agency or pass-through entity expressly authorizes a noncompetitive procurement in response to a written request from the non-Federal entity; or 5. After solicitation of a number of sources, competition is determined inadequate. Condition: During our testing over procurement, we determined NFHA did not clearly document the rationale for the method of procurement, selection of contract type, contractor selection or rejection, and the basis for the contract price. In addition, for noncompetitive procurements, there was no documentation to support which of the five criteria was met to allow for the noncompetitive procurement. Cause: Management did not have effective internal controls in place to ensure that procurement requirements were adequately documented and retained. Effect: Procurement records were insufficient to meet the requirements noted in the Criteria section above, as well as NFHA's internal procurement policy. Questioned Costs: None. Context: We noted that several items selected for testing did not document the rationale for the method of procurement, selection of contract type, contractor selection or rejection, and the basis for the contract price. In addition, we noted that several items selected for testing for noncompetitive procurements did not maintain documentation of which of the five criteria were met to allow for the noncompetitive procurement. Identification as a Repeat Finding: Not applicable. Recommendation: We recommend NFHA update its policies to treat Federal and non-Federal procurement the same and ensure compliance with Uniform Guidance. NFHA should retain sufficient procurement documentation to meet the requirements noted in the Criteria section above.
Item 2023-001 (Originally of 2022-001) Special Tests and Provisions – Wage Rate Requirements Education Stabilization Fund (ESF) ALN# 84.425 (Repeated) U.S. Department of Education Passed through the State Department of Education Grant period – Years ended September 30, 2022 and September 30, 2023 (84.425D) Criteria – Grantees should have controls in place to ensure that contractors and subcontractors are notified of the requirement to pay prevailing wage rates to all laborers and mechanics employed on construction contracts in excess of $2,000 financed by federal assistance funds and to submit weekly certified payrolls for each week in which contract work is performed. 2 CFR 200.303 requires the non‐Federal entity to “(a) establish and maintain effective internal controls over the Federal award that provides reasonable assurance that the non‐Federal entity is managing the Federal statutes, regulations, and the terms and conditions of the Federal award.” 2 CFR 200.326 and 29 CFR Part 5, Labor Standards Provisions Applicable to Contracts Governing Federally Financed and Assisted Construction (DOL Regulations) require the contractor or subcontractor to submit to the nonfederal entity weekly, for each week in which any contract work is performed, a copy of the payroll and a statement of compliance (certified payrolls). Condition – Adequate controls were not in place to ensure that contractors and subcontractors were notified of the requirements to comply with the wage rate requirements and provided timely certified payrolls throughout the construction projects. Cause – A clause describing the Wage Rate Requirements was not added to the construction contracts. There was a lack of sufficient controls over the communication of this requirement to ensure that accurate and complete certified payrolls were provided to the Board. Effect – Lack of notification of the wage rate requirements to the contractors and subcontractors could lead to disallowed costs. We noted that payments to contractors did not have supporting documentation of certified payrolls. However, our audit disclosed no instances of unallowable costs. Questioned Costs – $1,521,784.16 Recommendation – We recommend the strengthening of controls to ensure the prevailing wage rate clauses are included in the contracts and that certified payrolls are received for each week in which construction work is performed. Management’s Response – The Board will strengthen the controls in place to provide assurance that proper prevailing wage rate clauses are added to construction contracts and certified payrolls are received from each week in which construction work is performed.
Finding Number: 2023-001 Prior Year Finding Number: N/A Compliance Requirement: Activities Allowed or Unallowed and Allowable Costs/Cost Principles Program: Government Department/Agency: U.S. Department of Agriculture Supplemental Nutrition Assistance Program Cluster (SNAP) ALN: 10.551, 10.561 Award #: Various Award Year: 10/01/2022 – 09/30/2023 Department of Human Services (DHS)/ Economic Security Administration (ESA) Criteria - The Uniform Guidance in 2 CFR Section 200.303 requires that non-Federal entities receiving Federal awards (i.e., auditee management) establish and maintain internal control designed to reasonably ensure compliance with Federal statues, regulations, and the terms and conditions of the Federal award. Per 2 CFR Section 200.430 Compensation – Personal Services: “Costs of compensation are allowable to the extent that they satisfy the specific requirements of this part, and that the total compensation for individual employees: (1) Is reasonable for the services rendered and conforms to the establish written policy of the non-Federal entity consistently applied to both Federal and non-Federal activities; (2) Follows an appointment made in accordance with a non-Federal entity’s laws and/or rules or written policies and meets the requirements of Federal statute, where applicable; and (3) Is determined and supported as provided in paragraph (i) of this section, Standards for Documentation of Personnel Expenses, when applicable.” 2 CFR Section 200.430(i): “Standards for Documentation of Personnel Expenses (1) Charges to Federal awards for salaries and wages must be based on records that accurately reflect the work performed. These records must: (i) Be supported by a system of internal control which provides reasonable assurance that the charges are accurate, allowable, and properly allocated; (ii) Be incorporated into the official records of the non-Federal entity; (iii) Reasonably reflect the total activity for which the employee is compensated by the non-Federal entity, not exceeding 100% of compensated activities; (iv) Encompass both federally assisted and all other activities compensated by the non-Federal entity on an integrated basis, but may include the use of subsidiary records as defined in the non-Federal entity’s written policy; (v) Comply with the established accounting policies and practices of the non-Federal entity; (vi) [Reserved] (vii) Support the distribution of the employee’s salary or wages among specific activities or cost objectives if the employee works on more than one Federal award; a Federal award and non-Federal award; an indirect cost activity and a direct cost activity; two or more indirect activities which are allocated using different allocation bases; or an unallowable activity and a direct or indirect cost activity. (viii) Budget estimates (i.e., estimates determined before the services are performed) alone do not qualify as support for charges to Federal awards.” Per District Personnel Issuance No. 2021-10 (Approval Required) - "Overtime work must be officially ordered and approved in advance. Agency heads and their designees are authorized to order and approve overtime work provided the agency has sufficient funding available. Employees may submit overtime requests in PeopleSoft. To submit a request, go to the main employee self-service page and access the navigator. Click “Self Service,” next “Time Reporting,” then “Report Time,” and finally “Overtime Requests.” Once an employee submits an overtime request, the employee’s supervisor and, if required by PeopleSoft any additional designated agency personnel, must review and approve the request in PeopleSoft for the employee to be authorized to receive overtime pay.” Per District Personnel Issuance No. 2018-00 (Annual Leave) effective April 21, 2018 “Using Annual Leave” - An employee may use accrued annual leave at any time during the leave year if they receive approval from their immediate supervisor or the agency head responsible for the employee’s timesheet. If an employee wishes to use their accrued annual leave, they must: 1. Submit a request in advance to use annual leave to their manager or supervisor. 2. Receive approval from the manager or supervisor; and 3. Record the approved leave taken on their timesheet in PeopleSoft. Condition – We noted that for six (6) out of a sample of seven (7) employees tested of total costs sampled of $30,993, although the employee's timesheet was approved by the supervisor, DHS/ESA was unable to provide documentation to show the preapproval of the scheduled leave and overtime approved on the timesheet. Questioned Costs – Known amount is $28,093. Context – This is a condition identified per review of DHS/ESA’s compliance with specified requirements using a statistically valid sample. Payroll costs including fringe benefits, for the SNAP program in fiscal year 2023 were $16,063,809. Effect – Without adequate internal controls in place to ensure costs are properly reviewed for allowability, DHS/ESA could be noncompliant with the allowability requirement and could request funds for costs that are unallowed. Cause – DHS/ESA did not follow its own internal controls and policies and procedures to ensure that documentation to show the preapproval of the scheduled leave and overtime approved on the timesheet is obtained and maintained. Recommendation – We recommend that DHS/ESA follow its own policies, procedures and controls to ensure that pre-authorization of scheduled leave or overtime is obtained and maintained. Related Noncompliance – Noncompliance. Views of Responsible Officials and Planned Corrective Actions – DHS concurs with the finding. The District’s corrective action is described in the Management’s Corrective Action Plan included as Appendix B of the attached Management’s Section.
Finding Number: 2023-002 Prior Year Finding Number: N/A Compliance Requirement: Matching, Level of Effort, Earmarking Program: Government Department/Agency: U.S. Department of Agriculture Supplemental Nutrition Assistance Program Cluster (SNAP) ALN: 10.551, 10.561 Award #: Various Award Year: 10/01/2022 – 09/30/2023 Department of Human Services (DHS)/ Economic Security Administration (ESA) Criteria - The Uniform Guidance in 2 CFR Section 200.303 requires that non-Federal entities receiving Federal awards (i.e., auditee management) establish and maintain internal control designed to reasonably ensure compliance with Federal statues, regulations, and the terms and conditions of the Federal award. Per 2 CFR Section 277.4(b), Federal reimbursement rate, states that the base percentage for Federal payment shall be 50 percent of State agencies’ allowable SNAP administrative costs. Condition – During the testing of the SNAP Matching, Level of Effort, Earmarking compliance requirement, we noted that the quarterly SF-425 reports were approved and certified, and DHS/ESA exceeded the required SNAP Matching amount of $34,983,777. However, OCFO for DHS/ESA was unable to provide supporting documentation that would allow us to agree specific amounts reported as the match for fiscal year 2023. OCFO for DHS/ESA was unable to provide support to enable recalculation of the exact amounts reported for (1) Certification for the 4th quarter, (2) Education and Training (E&T) 50% Grant for each of the four quarters, and (3) for New Investment for the 4th quarter, which is not allowed to be included as a match but must be spent by the agency. The total calculated amount by OCFO for DHS/ESA to be reported as the required match on the SF-425 report, excluding New investment, was $36,603,773. However, the total recalculated amount by auditors to be reported as the required match was $37,315,738. Variance between these two amounts was $711,965. Questioned Costs – None. Context – This is a condition identified per review of DHS/ESA’s compliance through the OCFO team with specified requirements using a statistically valid sample. Effect – OCFO for DHS/ESA is not in compliance with the stated provisions. Without adequate internal controls to ensure reconciliation of the amounts reported for the matching requirements, there is an increased risk that matching will not be properly reported. Cause – OCFO for DHS/ESA does not have appear to have adequate policies and procedures in place to ensure that the amounts reported for the matching requirement agreed to the support. Recommendation – We recommend that OCFO for DHS/ESA strengthen its policies and procedures to ensure that amounts reported for SNAP matching requirements are properly reported. Related Noncompliance – Noncompliance. Views of Responsible Officials and Planned Corrective Actions – DHS concurs with the finding. The District’s corrective action is described in the Management’s Corrective Action Plan included as Appendix B of the attached Management’s Section.
Finding Number: 2023-003 Prior Year Finding Number: 2022-001 Compliance Requirement: Special Tests and Provisions – ADP System for SNAP Program: Government Department/Agency: U.S. Department of Agriculture Supplemental Nutrition Assistance Program Cluster (SNAP) ALN: 10.551, 10.561 Award #: Various Award Year: 10/01/2022 – 09/30/2023 Department of Human Services (DHS)/ Department of Health Care Finance (DHCF) DC Access System (DCAS) Program Management Administration Criteria - The Uniform Guidance in 2 CFR Section 200.303 requires that non-Federal entities receiving Federal awards (i.e., auditee management) establish and maintain internal control designed to reasonably ensure compliance with Federal statues, regulations, and the terms and conditions of the Federal award. Per 2 CFR Section 272.10(a), “All State agencies are required to sufficiently automate their SNAP operations and computerize their systems for obtaining, maintaining, utilizing, and transmitting information concerning SNAP.” Per 2 CFR Section 272.10(b), “In order to meet the requirements of the Act and ensure the efficient and effective administration of the program, a SNAP system, at a minimum, shall be automated in each of the following program areas (1) Certification and (2) Issuance Reconciliation and Reporting. Under Certification – States agencies must determine eligibility and calculate benefits or validate the eligibility worker’s calculations by processing and storing all casefile information necessary for the eligibility determination and benefit computation (including but not limited to all household members’ names, addresses, dates of birth, social security numbers, individual household members’ earned and unearned income by source, deductions, resources and household size). Also, State agencies must redetermine or revalidate eligibility and benefits based on notices of change in households’ circumstances.” Condition – The District is self-reporting findings it noted from its ongoing efforts to resolve issues with the ADP system for SNAP. The issues identified and the estimated impact follows: 1. Failure to Send Correct and Timely Notices to SNAP Households - Notices pertaining to SNAP eligibility contain incorrect information, and/or SNAP applicants and recipients fail to receive proper notices. For example, in the Federal Fiscal Year (FFY) 2018 Local Program Access Review (PAR), Food and Nutrition Service (FNS) cited that SNAP applicants did not receive a Notice of Eligibility or notice contained incorrect information, no notice of required verification, and the notice of adverse action was incorrect. 2. Untimely Processing of SNAP Applications and Periodic Reports - On October 23, 2017, FNS advised DHS that its application processing timeliness (APT) rate between October 2016 and March 2017 was 88.45%, which triggered corrective action per FNS policy. Moreover, between that last APT report and now, DHS has disclosed that it has experienced processing backlogs of varying severity and persistence to FNS via ongoing communications and as part of waiver requests. DHS also provided a report to FNS in August 2022 that indicated significant application processing backlogs. 3. Establishment of Duplicate Accounts - DHS discovered that duplicate Product Delivery Cases (PDC) were being created in DCAS. One PDC was active and the other closed, but the closed PDC was still receiving benefits. 4. Issuance of Duplicate Payment - As a result of duplicate accounts in Deficiency 3, duplicate payments may have been issued to the same household when a caseworker reactivated a closed case. There is also a possibility that customers who received duplicate EBT cards from different EBT vendors may have received duplicate payments. 5. Failure to Implement Computer Matching System - Based on the FFY18 Program Integrity Management Evaluation (ME) review, DHS failed to process Prisoner Verification System (PVS) matches, deceased matches, and National Directory of New Hires (NDNH) matches in accordance with federal requirements. 6. Failure to Produce System Computations to Support Recipient Claims - DCAS does not have the ability to calculate overpayments or send a demand letter. FNS correspondence letters dated October 18, 2017, and September 20, 2018, advised DHS to suspend the establishment of DCAS claims but allowed DHS to continue servicing ACEDS claims. 7. Recipient Fraud Investigations, Hearings and Tracking System Unvalidated - As reported by DHS in the Advance Warning Letter (AWL) CAP, DHS has been using manual and other electronic systems, such as QuickBase, to meet federal recipient fraud requirements and related notices. Since then, DHS has been working on creating a fraud management system called Thomas Reuters (formerly Pondera), which went live on October 11, 2022. This finding remains open until FNS validates the system, including viewing a demo. 8. Treasury Offset Program (TOP) Reporting and Maintenance Decertified - FNS conducted a TOP Technical Review in June 2021 and DHS was decertified from TOP due to the following: • Referral of customers to TOP that are undergoing recoupment. • Incorrect determination of the date of delinquency. • Incorrect debt balance and debt status in TOP. 9. Failure to Initiate Recoupment on Active Households - When DCAS launched in October 2016, more than 3,000 claim cases with outstanding balances originating from SNAP overpayments were converted from ACEDS to DCAS. Some claims were not properly converted or activated in DCAS. As a result, DHS failed to take the required recovery actions, including TOP recovery or activation of the recoupment process through EBT cards. 10. Recipient and Benefit Integrity Report Update Required - DHS must provide an update on the target completion dates for system generation of all SNAP-related reports currently being created through manual intervention. The plan must include the procedures for reviewing and ensuring the accuracy of the data being submitted to Food Programs Reporting System (FPRS) with particular emphasis on the FNS-209 and the FNS-366B reports. DHS experienced some technical challenges in processing and retrieving claim and recoupment information accurately since the launch of DCAS in October 2016, which affected the FNS-209 quarterly reports. The Payment and Collections Division (PCD) and the DCAS report development team have made concerted efforts to improve the ability to generate data for the reports but continue to have difficulties in verifying the accuracy of data due in part to the laborious manual processes involved. Based on the FFY 2018 Program Integrity ME review, lines 3b, 10, and 14 of the FNS-209 failed to reconcile with the detailed documentation. 11. Work Requirements Have Not Been Properly Implemented - DHS is not in compliance with the requirement to accurately report on the FNS 583. DHS is unprepared to implement the work requirement and time limit for able-bodied adults without dependents when the current suspension mandated by the Families First Coronavirus Response Act ends and/or its waiver ends. Additionally, the District is not prepared to apply the Able-Bodied Adults Without Dependents (ABAWD) time limits when their ABAWD waiver expires. 12. Minimum Benefit for Non-Categorically Eligible One/Two Person Households Not Issued to Eligible Households - As reported by DHS, the Federal minimum SNAP benefit is not issued to eligible one or two-person households unless those households are categorically eligible. As a result, one or two-person households that are not categorically eligible will not receive benefits to which they are entitled. 13. Medical Expense Deduction for Elderly and Disabled Households Not Configured in DCAS - As reported by DHS, certain allowable medical expense evidence is not configured in DCAS to allow a medical expense deduction. Certain allowable disability statuses selected in DCAS are not configured to allow a medical expense deduction. As a result, certain households with elderly or disabled members are not receiving a medical expense deduction. 14. Failure to Analyze Client Complaints and Include in the State’s Corrective Action Plans (CAP) Where Appropriate - DHS is failing to analyze client complaints and include in the State’s CAP where appropriate, per 7 CFR 271.6(a)(3) and 275.16. 15. The SNAP Application Does Not Clearly Explain Which Questions Are Required for SNAP - FNS reviewers found that the District’s SNAP application does not provide clear directions about which questions are required for SNAP, versus Cash or Medical Assistance. For example, Step 5 of the application asks “Does anyone in your household (including non-applicants) have any income? Yes – complete below; No – skip to step 6 (Complete if you are applying for Food, Medical, or Cash Assistance).” The directions are confusing and may be difficult to understand. Questioned Costs – Not determinable. Context – This is a condition identified per review of DHS’ compliance with specified requirements resulting from a system implementation. Effect – Without an effectively designed and operated system in place, ineligible beneficiaries may receive benefits under the SNAP grant and DHS may make payments on behalf of those beneficiaries resulting in noncompliance with the eligibility requirements. Inaccurate beneficiary allotment payments could result in participants receiving benefits that they are not entitled to receive under the program. Cause – DHS did not effectively design and operate the ADP system for SNAP which resulted to inaccurate benefit payments. Recommendation – We recommend that DHS continue to evaluate and improve the new ADP system for SNAP to ensure that it addresses all the administration requirements of the SNAP program. Related Noncompliance – Material noncompliance. Views of Responsible Officials and Planned Corrective Actions – The DHS and DHCF DCAS team agree with the findings noted in this report. DHS self-reported these findings as part of the agency’s ongoing effort to maintain integrity with all eligibility determinations. The root cause of each of the fifteen (15) case issues with the ADP system for SNAP varied. The District’s corrective action is described in the Management’s Corrective Action Plan included as Appendix B of the attached Management’s Section.
Finding Number: 2023-004 Prior Year Finding Number: 2022-002 Compliance Requirement: Special Tests and Provisions – EBT Card Security Program: Government Department/Agency: U.S. Department of Agriculture Supplemental Nutrition Assistance Program Cluster (SNAP) ALN: 10.551, 10.561 Award #: Various Award Year: 10/01/2022 – 09/30/2023 Department of Human Services (DHS)/ Office of the Chief Financial Officer/Office of Finance and Treasury (OCFO/OFT) Criteria - The Uniform Guidance in 2 CFR Section 200.303 requires that non-Federal entities receiving Federal awards (i.e., auditee management) establish and maintain internal control designed to reasonably ensure compliance with Federal statues, regulations, and the terms and conditions of the Federal award. Per 7 CFR Section 274.8(b)(3), As an addition to or component of the Security Program required of Automated Data Processing (ADP) systems, the State agency shall ensure that the following electronic benefits transfer (EBT) security requirements are established: (i) Storage and control measures to control blank unissued EBT cards and PINs, and unused or spare POS devices; (ii) Measures to ensure communication access control. Communication controls shall include the transmission of transaction data and issuance information from POS terminals to work-stations and terminals at the data processing center; (iii) Message validation; (iv) Administrative and operational procedures; (v) A separate EBT security component shall be incorporated into the State agency Security Program for ADP systems. The periodic risk analyses required by the Security Program shall address the following items specific to an EBT system – (B) Completeness and timeliness of the reconciliation system; and (vi) The State agency shall incorporate the contingency plan approved by FNS into the Security Program. Condition – OCFO/OFT for DHS are required to maintain adequate security over, and documentation/records for EBT cards, to prevent their theft, embezzlement, loss damage, destruction, unauthorized transfer, negotiation, or use. OCFO/OFT have contracted with Fidelity National Information Service (FIS) for the issuance and security of the EBT cards; however, it is OCFO/OFT’s ultimate responsibility to ensure the contractor has controls in place to maintain adequate security over, and documentation/records of EBT cards. During our tests of the design and implementation of internal controls, we noted the following issues: • For nine (9) out of the 60 samples, although both EBT Balance Sheets reconciled with the EBT Card Issuance Logs included in the package, we noted the following deficiencies: o For one (1) out of the samples, we noted that for at least one (1) customer, the client’s name was missing from the EBT Intake Form. o For two (2) out of the samples, we noted that for at least one (1) customer on the United Planning Organization (UPO) Intake Form, the ID type for identification purposes was missing. o For two (2) out of the samples, we noted that for at least one (1) customer the case number was cancelled but no new/correct case number indicated on the EBT Intake Form. o For two (2) out of the samples, we noted that for at least one (1) customer the identification type was noted as referral on the EBT Intake Form, but no referral form was attached. o For one (1) out of the samples, we noted that for at least one (1) customer the DHS Photo ID Program Referral Form was missing the supervisor's signature and only had the eligibility staff’s signature. o For one (1) out of the samples, we noted that for at least one (1) customer, the name of the beneficiary in the intake forms does not agree with the EBT Issuance Log. Questioned Costs – None. Context – This is a condition identified per review of DHS’ compliance with specified requirements using a statistically valid sample. Effect – Without adequate internal controls to ensure compliance with EBT Card Security requirements, there is an increased risk that the inventory of EBT cards will not be properly maintained and accounted for. Cause – OCFO/OFT for DHS does not have adequate policies and procedures in place to ensure adequate safeguarding, documentation over issuance and monitoring of EBT cards. Recommendation - We recommend that OCFO/OFT for DHS strengthen formal policies and procedures to maintain adequate security over, and documentation/records for EBT Cards. Related Noncompliance – Noncompliance. Views of Responsible Officials and Planned Corrective Actions – The OCFO/OFT for DHS concurs with this finding. The District’s corrective action is described in the Management’s Corrective Action Plan included as Appendix B of the attached Management’s Section.
Finding Number: 2023-001 Prior Year Finding Number: N/A Compliance Requirement: Activities Allowed or Unallowed and Allowable Costs/Cost Principles Program: Government Department/Agency: U.S. Department of Agriculture Supplemental Nutrition Assistance Program Cluster (SNAP) ALN: 10.551, 10.561 Award #: Various Award Year: 10/01/2022 – 09/30/2023 Department of Human Services (DHS)/ Economic Security Administration (ESA) Criteria - The Uniform Guidance in 2 CFR Section 200.303 requires that non-Federal entities receiving Federal awards (i.e., auditee management) establish and maintain internal control designed to reasonably ensure compliance with Federal statues, regulations, and the terms and conditions of the Federal award. Per 2 CFR Section 200.430 Compensation – Personal Services: “Costs of compensation are allowable to the extent that they satisfy the specific requirements of this part, and that the total compensation for individual employees: (1) Is reasonable for the services rendered and conforms to the establish written policy of the non-Federal entity consistently applied to both Federal and non-Federal activities; (2) Follows an appointment made in accordance with a non-Federal entity’s laws and/or rules or written policies and meets the requirements of Federal statute, where applicable; and (3) Is determined and supported as provided in paragraph (i) of this section, Standards for Documentation of Personnel Expenses, when applicable.” 2 CFR Section 200.430(i): “Standards for Documentation of Personnel Expenses (1) Charges to Federal awards for salaries and wages must be based on records that accurately reflect the work performed. These records must: (i) Be supported by a system of internal control which provides reasonable assurance that the charges are accurate, allowable, and properly allocated; (ii) Be incorporated into the official records of the non-Federal entity; (iii) Reasonably reflect the total activity for which the employee is compensated by the non-Federal entity, not exceeding 100% of compensated activities; (iv) Encompass both federally assisted and all other activities compensated by the non-Federal entity on an integrated basis, but may include the use of subsidiary records as defined in the non-Federal entity’s written policy; (v) Comply with the established accounting policies and practices of the non-Federal entity; (vi) [Reserved] (vii) Support the distribution of the employee’s salary or wages among specific activities or cost objectives if the employee works on more than one Federal award; a Federal award and non-Federal award; an indirect cost activity and a direct cost activity; two or more indirect activities which are allocated using different allocation bases; or an unallowable activity and a direct or indirect cost activity. (viii) Budget estimates (i.e., estimates determined before the services are performed) alone do not qualify as support for charges to Federal awards.” Per District Personnel Issuance No. 2021-10 (Approval Required) - "Overtime work must be officially ordered and approved in advance. Agency heads and their designees are authorized to order and approve overtime work provided the agency has sufficient funding available. Employees may submit overtime requests in PeopleSoft. To submit a request, go to the main employee self-service page and access the navigator. Click “Self Service,” next “Time Reporting,” then “Report Time,” and finally “Overtime Requests.” Once an employee submits an overtime request, the employee’s supervisor and, if required by PeopleSoft any additional designated agency personnel, must review and approve the request in PeopleSoft for the employee to be authorized to receive overtime pay.” Per District Personnel Issuance No. 2018-00 (Annual Leave) effective April 21, 2018 “Using Annual Leave” - An employee may use accrued annual leave at any time during the leave year if they receive approval from their immediate supervisor or the agency head responsible for the employee’s timesheet. If an employee wishes to use their accrued annual leave, they must: 1. Submit a request in advance to use annual leave to their manager or supervisor. 2. Receive approval from the manager or supervisor; and 3. Record the approved leave taken on their timesheet in PeopleSoft. Condition – We noted that for six (6) out of a sample of seven (7) employees tested of total costs sampled of $30,993, although the employee's timesheet was approved by the supervisor, DHS/ESA was unable to provide documentation to show the preapproval of the scheduled leave and overtime approved on the timesheet. Questioned Costs – Known amount is $28,093. Context – This is a condition identified per review of DHS/ESA’s compliance with specified requirements using a statistically valid sample. Payroll costs including fringe benefits, for the SNAP program in fiscal year 2023 were $16,063,809. Effect – Without adequate internal controls in place to ensure costs are properly reviewed for allowability, DHS/ESA could be noncompliant with the allowability requirement and could request funds for costs that are unallowed. Cause – DHS/ESA did not follow its own internal controls and policies and procedures to ensure that documentation to show the preapproval of the scheduled leave and overtime approved on the timesheet is obtained and maintained. Recommendation – We recommend that DHS/ESA follow its own policies, procedures and controls to ensure that pre-authorization of scheduled leave or overtime is obtained and maintained. Related Noncompliance – Noncompliance. Views of Responsible Officials and Planned Corrective Actions – DHS concurs with the finding. The District’s corrective action is described in the Management’s Corrective Action Plan included as Appendix B of the attached Management’s Section.
Finding Number: 2023-002 Prior Year Finding Number: N/A Compliance Requirement: Matching, Level of Effort, Earmarking Program: Government Department/Agency: U.S. Department of Agriculture Supplemental Nutrition Assistance Program Cluster (SNAP) ALN: 10.551, 10.561 Award #: Various Award Year: 10/01/2022 – 09/30/2023 Department of Human Services (DHS)/ Economic Security Administration (ESA) Criteria - The Uniform Guidance in 2 CFR Section 200.303 requires that non-Federal entities receiving Federal awards (i.e., auditee management) establish and maintain internal control designed to reasonably ensure compliance with Federal statues, regulations, and the terms and conditions of the Federal award. Per 2 CFR Section 277.4(b), Federal reimbursement rate, states that the base percentage for Federal payment shall be 50 percent of State agencies’ allowable SNAP administrative costs. Condition – During the testing of the SNAP Matching, Level of Effort, Earmarking compliance requirement, we noted that the quarterly SF-425 reports were approved and certified, and DHS/ESA exceeded the required SNAP Matching amount of $34,983,777. However, OCFO for DHS/ESA was unable to provide supporting documentation that would allow us to agree specific amounts reported as the match for fiscal year 2023. OCFO for DHS/ESA was unable to provide support to enable recalculation of the exact amounts reported for (1) Certification for the 4th quarter, (2) Education and Training (E&T) 50% Grant for each of the four quarters, and (3) for New Investment for the 4th quarter, which is not allowed to be included as a match but must be spent by the agency. The total calculated amount by OCFO for DHS/ESA to be reported as the required match on the SF-425 report, excluding New investment, was $36,603,773. However, the total recalculated amount by auditors to be reported as the required match was $37,315,738. Variance between these two amounts was $711,965. Questioned Costs – None. Context – This is a condition identified per review of DHS/ESA’s compliance through the OCFO team with specified requirements using a statistically valid sample. Effect – OCFO for DHS/ESA is not in compliance with the stated provisions. Without adequate internal controls to ensure reconciliation of the amounts reported for the matching requirements, there is an increased risk that matching will not be properly reported. Cause – OCFO for DHS/ESA does not have appear to have adequate policies and procedures in place to ensure that the amounts reported for the matching requirement agreed to the support. Recommendation – We recommend that OCFO for DHS/ESA strengthen its policies and procedures to ensure that amounts reported for SNAP matching requirements are properly reported. Related Noncompliance – Noncompliance. Views of Responsible Officials and Planned Corrective Actions – DHS concurs with the finding. The District’s corrective action is described in the Management’s Corrective Action Plan included as Appendix B of the attached Management’s Section.
Finding Number: 2023-003 Prior Year Finding Number: 2022-001 Compliance Requirement: Special Tests and Provisions – ADP System for SNAP Program: Government Department/Agency: U.S. Department of Agriculture Supplemental Nutrition Assistance Program Cluster (SNAP) ALN: 10.551, 10.561 Award #: Various Award Year: 10/01/2022 – 09/30/2023 Department of Human Services (DHS)/ Department of Health Care Finance (DHCF) DC Access System (DCAS) Program Management Administration Criteria - The Uniform Guidance in 2 CFR Section 200.303 requires that non-Federal entities receiving Federal awards (i.e., auditee management) establish and maintain internal control designed to reasonably ensure compliance with Federal statues, regulations, and the terms and conditions of the Federal award. Per 2 CFR Section 272.10(a), “All State agencies are required to sufficiently automate their SNAP operations and computerize their systems for obtaining, maintaining, utilizing, and transmitting information concerning SNAP.” Per 2 CFR Section 272.10(b), “In order to meet the requirements of the Act and ensure the efficient and effective administration of the program, a SNAP system, at a minimum, shall be automated in each of the following program areas (1) Certification and (2) Issuance Reconciliation and Reporting. Under Certification – States agencies must determine eligibility and calculate benefits or validate the eligibility worker’s calculations by processing and storing all casefile information necessary for the eligibility determination and benefit computation (including but not limited to all household members’ names, addresses, dates of birth, social security numbers, individual household members’ earned and unearned income by source, deductions, resources and household size). Also, State agencies must redetermine or revalidate eligibility and benefits based on notices of change in households’ circumstances.” Condition – The District is self-reporting findings it noted from its ongoing efforts to resolve issues with the ADP system for SNAP. The issues identified and the estimated impact follows: 1. Failure to Send Correct and Timely Notices to SNAP Households - Notices pertaining to SNAP eligibility contain incorrect information, and/or SNAP applicants and recipients fail to receive proper notices. For example, in the Federal Fiscal Year (FFY) 2018 Local Program Access Review (PAR), Food and Nutrition Service (FNS) cited that SNAP applicants did not receive a Notice of Eligibility or notice contained incorrect information, no notice of required verification, and the notice of adverse action was incorrect. 2. Untimely Processing of SNAP Applications and Periodic Reports - On October 23, 2017, FNS advised DHS that its application processing timeliness (APT) rate between October 2016 and March 2017 was 88.45%, which triggered corrective action per FNS policy. Moreover, between that last APT report and now, DHS has disclosed that it has experienced processing backlogs of varying severity and persistence to FNS via ongoing communications and as part of waiver requests. DHS also provided a report to FNS in August 2022 that indicated significant application processing backlogs. 3. Establishment of Duplicate Accounts - DHS discovered that duplicate Product Delivery Cases (PDC) were being created in DCAS. One PDC was active and the other closed, but the closed PDC was still receiving benefits. 4. Issuance of Duplicate Payment - As a result of duplicate accounts in Deficiency 3, duplicate payments may have been issued to the same household when a caseworker reactivated a closed case. There is also a possibility that customers who received duplicate EBT cards from different EBT vendors may have received duplicate payments. 5. Failure to Implement Computer Matching System - Based on the FFY18 Program Integrity Management Evaluation (ME) review, DHS failed to process Prisoner Verification System (PVS) matches, deceased matches, and National Directory of New Hires (NDNH) matches in accordance with federal requirements. 6. Failure to Produce System Computations to Support Recipient Claims - DCAS does not have the ability to calculate overpayments or send a demand letter. FNS correspondence letters dated October 18, 2017, and September 20, 2018, advised DHS to suspend the establishment of DCAS claims but allowed DHS to continue servicing ACEDS claims. 7. Recipient Fraud Investigations, Hearings and Tracking System Unvalidated - As reported by DHS in the Advance Warning Letter (AWL) CAP, DHS has been using manual and other electronic systems, such as QuickBase, to meet federal recipient fraud requirements and related notices. Since then, DHS has been working on creating a fraud management system called Thomas Reuters (formerly Pondera), which went live on October 11, 2022. This finding remains open until FNS validates the system, including viewing a demo. 8. Treasury Offset Program (TOP) Reporting and Maintenance Decertified - FNS conducted a TOP Technical Review in June 2021 and DHS was decertified from TOP due to the following: • Referral of customers to TOP that are undergoing recoupment. • Incorrect determination of the date of delinquency. • Incorrect debt balance and debt status in TOP. 9. Failure to Initiate Recoupment on Active Households - When DCAS launched in October 2016, more than 3,000 claim cases with outstanding balances originating from SNAP overpayments were converted from ACEDS to DCAS. Some claims were not properly converted or activated in DCAS. As a result, DHS failed to take the required recovery actions, including TOP recovery or activation of the recoupment process through EBT cards. 10. Recipient and Benefit Integrity Report Update Required - DHS must provide an update on the target completion dates for system generation of all SNAP-related reports currently being created through manual intervention. The plan must include the procedures for reviewing and ensuring the accuracy of the data being submitted to Food Programs Reporting System (FPRS) with particular emphasis on the FNS-209 and the FNS-366B reports. DHS experienced some technical challenges in processing and retrieving claim and recoupment information accurately since the launch of DCAS in October 2016, which affected the FNS-209 quarterly reports. The Payment and Collections Division (PCD) and the DCAS report development team have made concerted efforts to improve the ability to generate data for the reports but continue to have difficulties in verifying the accuracy of data due in part to the laborious manual processes involved. Based on the FFY 2018 Program Integrity ME review, lines 3b, 10, and 14 of the FNS-209 failed to reconcile with the detailed documentation. 11. Work Requirements Have Not Been Properly Implemented - DHS is not in compliance with the requirement to accurately report on the FNS 583. DHS is unprepared to implement the work requirement and time limit for able-bodied adults without dependents when the current suspension mandated by the Families First Coronavirus Response Act ends and/or its waiver ends. Additionally, the District is not prepared to apply the Able-Bodied Adults Without Dependents (ABAWD) time limits when their ABAWD waiver expires. 12. Minimum Benefit for Non-Categorically Eligible One/Two Person Households Not Issued to Eligible Households - As reported by DHS, the Federal minimum SNAP benefit is not issued to eligible one or two-person households unless those households are categorically eligible. As a result, one or two-person households that are not categorically eligible will not receive benefits to which they are entitled. 13. Medical Expense Deduction for Elderly and Disabled Households Not Configured in DCAS - As reported by DHS, certain allowable medical expense evidence is not configured in DCAS to allow a medical expense deduction. Certain allowable disability statuses selected in DCAS are not configured to allow a medical expense deduction. As a result, certain households with elderly or disabled members are not receiving a medical expense deduction. 14. Failure to Analyze Client Complaints and Include in the State’s Corrective Action Plans (CAP) Where Appropriate - DHS is failing to analyze client complaints and include in the State’s CAP where appropriate, per 7 CFR 271.6(a)(3) and 275.16. 15. The SNAP Application Does Not Clearly Explain Which Questions Are Required for SNAP - FNS reviewers found that the District’s SNAP application does not provide clear directions about which questions are required for SNAP, versus Cash or Medical Assistance. For example, Step 5 of the application asks “Does anyone in your household (including non-applicants) have any income? Yes – complete below; No – skip to step 6 (Complete if you are applying for Food, Medical, or Cash Assistance).” The directions are confusing and may be difficult to understand. Questioned Costs – Not determinable. Context – This is a condition identified per review of DHS’ compliance with specified requirements resulting from a system implementation. Effect – Without an effectively designed and operated system in place, ineligible beneficiaries may receive benefits under the SNAP grant and DHS may make payments on behalf of those beneficiaries resulting in noncompliance with the eligibility requirements. Inaccurate beneficiary allotment payments could result in participants receiving benefits that they are not entitled to receive under the program. Cause – DHS did not effectively design and operate the ADP system for SNAP which resulted to inaccurate benefit payments. Recommendation – We recommend that DHS continue to evaluate and improve the new ADP system for SNAP to ensure that it addresses all the administration requirements of the SNAP program. Related Noncompliance – Material noncompliance. Views of Responsible Officials and Planned Corrective Actions – The DHS and DHCF DCAS team agree with the findings noted in this report. DHS self-reported these findings as part of the agency’s ongoing effort to maintain integrity with all eligibility determinations. The root cause of each of the fifteen (15) case issues with the ADP system for SNAP varied. The District’s corrective action is described in the Management’s Corrective Action Plan included as Appendix B of the attached Management’s Section.
Finding Number: 2023-004 Prior Year Finding Number: 2022-002 Compliance Requirement: Special Tests and Provisions – EBT Card Security Program: Government Department/Agency: U.S. Department of Agriculture Supplemental Nutrition Assistance Program Cluster (SNAP) ALN: 10.551, 10.561 Award #: Various Award Year: 10/01/2022 – 09/30/2023 Department of Human Services (DHS)/ Office of the Chief Financial Officer/Office of Finance and Treasury (OCFO/OFT) Criteria - The Uniform Guidance in 2 CFR Section 200.303 requires that non-Federal entities receiving Federal awards (i.e., auditee management) establish and maintain internal control designed to reasonably ensure compliance with Federal statues, regulations, and the terms and conditions of the Federal award. Per 7 CFR Section 274.8(b)(3), As an addition to or component of the Security Program required of Automated Data Processing (ADP) systems, the State agency shall ensure that the following electronic benefits transfer (EBT) security requirements are established: (i) Storage and control measures to control blank unissued EBT cards and PINs, and unused or spare POS devices; (ii) Measures to ensure communication access control. Communication controls shall include the transmission of transaction data and issuance information from POS terminals to work-stations and terminals at the data processing center; (iii) Message validation; (iv) Administrative and operational procedures; (v) A separate EBT security component shall be incorporated into the State agency Security Program for ADP systems. The periodic risk analyses required by the Security Program shall address the following items specific to an EBT system – (B) Completeness and timeliness of the reconciliation system; and (vi) The State agency shall incorporate the contingency plan approved by FNS into the Security Program. Condition – OCFO/OFT for DHS are required to maintain adequate security over, and documentation/records for EBT cards, to prevent their theft, embezzlement, loss damage, destruction, unauthorized transfer, negotiation, or use. OCFO/OFT have contracted with Fidelity National Information Service (FIS) for the issuance and security of the EBT cards; however, it is OCFO/OFT’s ultimate responsibility to ensure the contractor has controls in place to maintain adequate security over, and documentation/records of EBT cards. During our tests of the design and implementation of internal controls, we noted the following issues: • For nine (9) out of the 60 samples, although both EBT Balance Sheets reconciled with the EBT Card Issuance Logs included in the package, we noted the following deficiencies: o For one (1) out of the samples, we noted that for at least one (1) customer, the client’s name was missing from the EBT Intake Form. o For two (2) out of the samples, we noted that for at least one (1) customer on the United Planning Organization (UPO) Intake Form, the ID type for identification purposes was missing. o For two (2) out of the samples, we noted that for at least one (1) customer the case number was cancelled but no new/correct case number indicated on the EBT Intake Form. o For two (2) out of the samples, we noted that for at least one (1) customer the identification type was noted as referral on the EBT Intake Form, but no referral form was attached. o For one (1) out of the samples, we noted that for at least one (1) customer the DHS Photo ID Program Referral Form was missing the supervisor's signature and only had the eligibility staff’s signature. o For one (1) out of the samples, we noted that for at least one (1) customer, the name of the beneficiary in the intake forms does not agree with the EBT Issuance Log. Questioned Costs – None. Context – This is a condition identified per review of DHS’ compliance with specified requirements using a statistically valid sample. Effect – Without adequate internal controls to ensure compliance with EBT Card Security requirements, there is an increased risk that the inventory of EBT cards will not be properly maintained and accounted for. Cause – OCFO/OFT for DHS does not have adequate policies and procedures in place to ensure adequate safeguarding, documentation over issuance and monitoring of EBT cards. Recommendation - We recommend that OCFO/OFT for DHS strengthen formal policies and procedures to maintain adequate security over, and documentation/records for EBT Cards. Related Noncompliance – Noncompliance. Views of Responsible Officials and Planned Corrective Actions – The OCFO/OFT for DHS concurs with this finding. The District’s corrective action is described in the Management’s Corrective Action Plan included as Appendix B of the attached Management’s Section.
Finding Number: 2023-001 Prior Year Finding Number: N/A Compliance Requirement: Activities Allowed or Unallowed and Allowable Costs/Cost Principles Program: Government Department/Agency: U.S. Department of Agriculture Supplemental Nutrition Assistance Program Cluster (SNAP) ALN: 10.551, 10.561 Award #: Various Award Year: 10/01/2022 – 09/30/2023 Department of Human Services (DHS)/ Economic Security Administration (ESA) Criteria - The Uniform Guidance in 2 CFR Section 200.303 requires that non-Federal entities receiving Federal awards (i.e., auditee management) establish and maintain internal control designed to reasonably ensure compliance with Federal statues, regulations, and the terms and conditions of the Federal award. Per 2 CFR Section 200.430 Compensation – Personal Services: “Costs of compensation are allowable to the extent that they satisfy the specific requirements of this part, and that the total compensation for individual employees: (1) Is reasonable for the services rendered and conforms to the establish written policy of the non-Federal entity consistently applied to both Federal and non-Federal activities; (2) Follows an appointment made in accordance with a non-Federal entity’s laws and/or rules or written policies and meets the requirements of Federal statute, where applicable; and (3) Is determined and supported as provided in paragraph (i) of this section, Standards for Documentation of Personnel Expenses, when applicable.” 2 CFR Section 200.430(i): “Standards for Documentation of Personnel Expenses (1) Charges to Federal awards for salaries and wages must be based on records that accurately reflect the work performed. These records must: (i) Be supported by a system of internal control which provides reasonable assurance that the charges are accurate, allowable, and properly allocated; (ii) Be incorporated into the official records of the non-Federal entity; (iii) Reasonably reflect the total activity for which the employee is compensated by the non-Federal entity, not exceeding 100% of compensated activities; (iv) Encompass both federally assisted and all other activities compensated by the non-Federal entity on an integrated basis, but may include the use of subsidiary records as defined in the non-Federal entity’s written policy; (v) Comply with the established accounting policies and practices of the non-Federal entity; (vi) [Reserved] (vii) Support the distribution of the employee’s salary or wages among specific activities or cost objectives if the employee works on more than one Federal award; a Federal award and non-Federal award; an indirect cost activity and a direct cost activity; two or more indirect activities which are allocated using different allocation bases; or an unallowable activity and a direct or indirect cost activity. (viii) Budget estimates (i.e., estimates determined before the services are performed) alone do not qualify as support for charges to Federal awards.” Per District Personnel Issuance No. 2021-10 (Approval Required) - "Overtime work must be officially ordered and approved in advance. Agency heads and their designees are authorized to order and approve overtime work provided the agency has sufficient funding available. Employees may submit overtime requests in PeopleSoft. To submit a request, go to the main employee self-service page and access the navigator. Click “Self Service,” next “Time Reporting,” then “Report Time,” and finally “Overtime Requests.” Once an employee submits an overtime request, the employee’s supervisor and, if required by PeopleSoft any additional designated agency personnel, must review and approve the request in PeopleSoft for the employee to be authorized to receive overtime pay.” Per District Personnel Issuance No. 2018-00 (Annual Leave) effective April 21, 2018 “Using Annual Leave” - An employee may use accrued annual leave at any time during the leave year if they receive approval from their immediate supervisor or the agency head responsible for the employee’s timesheet. If an employee wishes to use their accrued annual leave, they must: 1. Submit a request in advance to use annual leave to their manager or supervisor. 2. Receive approval from the manager or supervisor; and 3. Record the approved leave taken on their timesheet in PeopleSoft. Condition – We noted that for six (6) out of a sample of seven (7) employees tested of total costs sampled of $30,993, although the employee's timesheet was approved by the supervisor, DHS/ESA was unable to provide documentation to show the preapproval of the scheduled leave and overtime approved on the timesheet. Questioned Costs – Known amount is $28,093. Context – This is a condition identified per review of DHS/ESA’s compliance with specified requirements using a statistically valid sample. Payroll costs including fringe benefits, for the SNAP program in fiscal year 2023 were $16,063,809. Effect – Without adequate internal controls in place to ensure costs are properly reviewed for allowability, DHS/ESA could be noncompliant with the allowability requirement and could request funds for costs that are unallowed. Cause – DHS/ESA did not follow its own internal controls and policies and procedures to ensure that documentation to show the preapproval of the scheduled leave and overtime approved on the timesheet is obtained and maintained. Recommendation – We recommend that DHS/ESA follow its own policies, procedures and controls to ensure that pre-authorization of scheduled leave or overtime is obtained and maintained. Related Noncompliance – Noncompliance. Views of Responsible Officials and Planned Corrective Actions – DHS concurs with the finding. The District’s corrective action is described in the Management’s Corrective Action Plan included as Appendix B of the attached Management’s Section.
Finding Number: 2023-002 Prior Year Finding Number: N/A Compliance Requirement: Matching, Level of Effort, Earmarking Program: Government Department/Agency: U.S. Department of Agriculture Supplemental Nutrition Assistance Program Cluster (SNAP) ALN: 10.551, 10.561 Award #: Various Award Year: 10/01/2022 – 09/30/2023 Department of Human Services (DHS)/ Economic Security Administration (ESA) Criteria - The Uniform Guidance in 2 CFR Section 200.303 requires that non-Federal entities receiving Federal awards (i.e., auditee management) establish and maintain internal control designed to reasonably ensure compliance with Federal statues, regulations, and the terms and conditions of the Federal award. Per 2 CFR Section 277.4(b), Federal reimbursement rate, states that the base percentage for Federal payment shall be 50 percent of State agencies’ allowable SNAP administrative costs. Condition – During the testing of the SNAP Matching, Level of Effort, Earmarking compliance requirement, we noted that the quarterly SF-425 reports were approved and certified, and DHS/ESA exceeded the required SNAP Matching amount of $34,983,777. However, OCFO for DHS/ESA was unable to provide supporting documentation that would allow us to agree specific amounts reported as the match for fiscal year 2023. OCFO for DHS/ESA was unable to provide support to enable recalculation of the exact amounts reported for (1) Certification for the 4th quarter, (2) Education and Training (E&T) 50% Grant for each of the four quarters, and (3) for New Investment for the 4th quarter, which is not allowed to be included as a match but must be spent by the agency. The total calculated amount by OCFO for DHS/ESA to be reported as the required match on the SF-425 report, excluding New investment, was $36,603,773. However, the total recalculated amount by auditors to be reported as the required match was $37,315,738. Variance between these two amounts was $711,965. Questioned Costs – None. Context – This is a condition identified per review of DHS/ESA’s compliance through the OCFO team with specified requirements using a statistically valid sample. Effect – OCFO for DHS/ESA is not in compliance with the stated provisions. Without adequate internal controls to ensure reconciliation of the amounts reported for the matching requirements, there is an increased risk that matching will not be properly reported. Cause – OCFO for DHS/ESA does not have appear to have adequate policies and procedures in place to ensure that the amounts reported for the matching requirement agreed to the support. Recommendation – We recommend that OCFO for DHS/ESA strengthen its policies and procedures to ensure that amounts reported for SNAP matching requirements are properly reported. Related Noncompliance – Noncompliance. Views of Responsible Officials and Planned Corrective Actions – DHS concurs with the finding. The District’s corrective action is described in the Management’s Corrective Action Plan included as Appendix B of the attached Management’s Section.
Finding Number: 2023-003 Prior Year Finding Number: 2022-001 Compliance Requirement: Special Tests and Provisions – ADP System for SNAP Program: Government Department/Agency: U.S. Department of Agriculture Supplemental Nutrition Assistance Program Cluster (SNAP) ALN: 10.551, 10.561 Award #: Various Award Year: 10/01/2022 – 09/30/2023 Department of Human Services (DHS)/ Department of Health Care Finance (DHCF) DC Access System (DCAS) Program Management Administration Criteria - The Uniform Guidance in 2 CFR Section 200.303 requires that non-Federal entities receiving Federal awards (i.e., auditee management) establish and maintain internal control designed to reasonably ensure compliance with Federal statues, regulations, and the terms and conditions of the Federal award. Per 2 CFR Section 272.10(a), “All State agencies are required to sufficiently automate their SNAP operations and computerize their systems for obtaining, maintaining, utilizing, and transmitting information concerning SNAP.” Per 2 CFR Section 272.10(b), “In order to meet the requirements of the Act and ensure the efficient and effective administration of the program, a SNAP system, at a minimum, shall be automated in each of the following program areas (1) Certification and (2) Issuance Reconciliation and Reporting. Under Certification – States agencies must determine eligibility and calculate benefits or validate the eligibility worker’s calculations by processing and storing all casefile information necessary for the eligibility determination and benefit computation (including but not limited to all household members’ names, addresses, dates of birth, social security numbers, individual household members’ earned and unearned income by source, deductions, resources and household size). Also, State agencies must redetermine or revalidate eligibility and benefits based on notices of change in households’ circumstances.” Condition – The District is self-reporting findings it noted from its ongoing efforts to resolve issues with the ADP system for SNAP. The issues identified and the estimated impact follows: 1. Failure to Send Correct and Timely Notices to SNAP Households - Notices pertaining to SNAP eligibility contain incorrect information, and/or SNAP applicants and recipients fail to receive proper notices. For example, in the Federal Fiscal Year (FFY) 2018 Local Program Access Review (PAR), Food and Nutrition Service (FNS) cited that SNAP applicants did not receive a Notice of Eligibility or notice contained incorrect information, no notice of required verification, and the notice of adverse action was incorrect. 2. Untimely Processing of SNAP Applications and Periodic Reports - On October 23, 2017, FNS advised DHS that its application processing timeliness (APT) rate between October 2016 and March 2017 was 88.45%, which triggered corrective action per FNS policy. Moreover, between that last APT report and now, DHS has disclosed that it has experienced processing backlogs of varying severity and persistence to FNS via ongoing communications and as part of waiver requests. DHS also provided a report to FNS in August 2022 that indicated significant application processing backlogs. 3. Establishment of Duplicate Accounts - DHS discovered that duplicate Product Delivery Cases (PDC) were being created in DCAS. One PDC was active and the other closed, but the closed PDC was still receiving benefits. 4. Issuance of Duplicate Payment - As a result of duplicate accounts in Deficiency 3, duplicate payments may have been issued to the same household when a caseworker reactivated a closed case. There is also a possibility that customers who received duplicate EBT cards from different EBT vendors may have received duplicate payments. 5. Failure to Implement Computer Matching System - Based on the FFY18 Program Integrity Management Evaluation (ME) review, DHS failed to process Prisoner Verification System (PVS) matches, deceased matches, and National Directory of New Hires (NDNH) matches in accordance with federal requirements. 6. Failure to Produce System Computations to Support Recipient Claims - DCAS does not have the ability to calculate overpayments or send a demand letter. FNS correspondence letters dated October 18, 2017, and September 20, 2018, advised DHS to suspend the establishment of DCAS claims but allowed DHS to continue servicing ACEDS claims. 7. Recipient Fraud Investigations, Hearings and Tracking System Unvalidated - As reported by DHS in the Advance Warning Letter (AWL) CAP, DHS has been using manual and other electronic systems, such as QuickBase, to meet federal recipient fraud requirements and related notices. Since then, DHS has been working on creating a fraud management system called Thomas Reuters (formerly Pondera), which went live on October 11, 2022. This finding remains open until FNS validates the system, including viewing a demo. 8. Treasury Offset Program (TOP) Reporting and Maintenance Decertified - FNS conducted a TOP Technical Review in June 2021 and DHS was decertified from TOP due to the following: • Referral of customers to TOP that are undergoing recoupment. • Incorrect determination of the date of delinquency. • Incorrect debt balance and debt status in TOP. 9. Failure to Initiate Recoupment on Active Households - When DCAS launched in October 2016, more than 3,000 claim cases with outstanding balances originating from SNAP overpayments were converted from ACEDS to DCAS. Some claims were not properly converted or activated in DCAS. As a result, DHS failed to take the required recovery actions, including TOP recovery or activation of the recoupment process through EBT cards. 10. Recipient and Benefit Integrity Report Update Required - DHS must provide an update on the target completion dates for system generation of all SNAP-related reports currently being created through manual intervention. The plan must include the procedures for reviewing and ensuring the accuracy of the data being submitted to Food Programs Reporting System (FPRS) with particular emphasis on the FNS-209 and the FNS-366B reports. DHS experienced some technical challenges in processing and retrieving claim and recoupment information accurately since the launch of DCAS in October 2016, which affected the FNS-209 quarterly reports. The Payment and Collections Division (PCD) and the DCAS report development team have made concerted efforts to improve the ability to generate data for the reports but continue to have difficulties in verifying the accuracy of data due in part to the laborious manual processes involved. Based on the FFY 2018 Program Integrity ME review, lines 3b, 10, and 14 of the FNS-209 failed to reconcile with the detailed documentation. 11. Work Requirements Have Not Been Properly Implemented - DHS is not in compliance with the requirement to accurately report on the FNS 583. DHS is unprepared to implement the work requirement and time limit for able-bodied adults without dependents when the current suspension mandated by the Families First Coronavirus Response Act ends and/or its waiver ends. Additionally, the District is not prepared to apply the Able-Bodied Adults Without Dependents (ABAWD) time limits when their ABAWD waiver expires. 12. Minimum Benefit for Non-Categorically Eligible One/Two Person Households Not Issued to Eligible Households - As reported by DHS, the Federal minimum SNAP benefit is not issued to eligible one or two-person households unless those households are categorically eligible. As a result, one or two-person households that are not categorically eligible will not receive benefits to which they are entitled. 13. Medical Expense Deduction for Elderly and Disabled Households Not Configured in DCAS - As reported by DHS, certain allowable medical expense evidence is not configured in DCAS to allow a medical expense deduction. Certain allowable disability statuses selected in DCAS are not configured to allow a medical expense deduction. As a result, certain households with elderly or disabled members are not receiving a medical expense deduction. 14. Failure to Analyze Client Complaints and Include in the State’s Corrective Action Plans (CAP) Where Appropriate - DHS is failing to analyze client complaints and include in the State’s CAP where appropriate, per 7 CFR 271.6(a)(3) and 275.16. 15. The SNAP Application Does Not Clearly Explain Which Questions Are Required for SNAP - FNS reviewers found that the District’s SNAP application does not provide clear directions about which questions are required for SNAP, versus Cash or Medical Assistance. For example, Step 5 of the application asks “Does anyone in your household (including non-applicants) have any income? Yes – complete below; No – skip to step 6 (Complete if you are applying for Food, Medical, or Cash Assistance).” The directions are confusing and may be difficult to understand. Questioned Costs – Not determinable. Context – This is a condition identified per review of DHS’ compliance with specified requirements resulting from a system implementation. Effect – Without an effectively designed and operated system in place, ineligible beneficiaries may receive benefits under the SNAP grant and DHS may make payments on behalf of those beneficiaries resulting in noncompliance with the eligibility requirements. Inaccurate beneficiary allotment payments could result in participants receiving benefits that they are not entitled to receive under the program. Cause – DHS did not effectively design and operate the ADP system for SNAP which resulted to inaccurate benefit payments. Recommendation – We recommend that DHS continue to evaluate and improve the new ADP system for SNAP to ensure that it addresses all the administration requirements of the SNAP program. Related Noncompliance – Material noncompliance. Views of Responsible Officials and Planned Corrective Actions – The DHS and DHCF DCAS team agree with the findings noted in this report. DHS self-reported these findings as part of the agency’s ongoing effort to maintain integrity with all eligibility determinations. The root cause of each of the fifteen (15) case issues with the ADP system for SNAP varied. The District’s corrective action is described in the Management’s Corrective Action Plan included as Appendix B of the attached Management’s Section.
Finding Number: 2023-004 Prior Year Finding Number: 2022-002 Compliance Requirement: Special Tests and Provisions – EBT Card Security Program: Government Department/Agency: U.S. Department of Agriculture Supplemental Nutrition Assistance Program Cluster (SNAP) ALN: 10.551, 10.561 Award #: Various Award Year: 10/01/2022 – 09/30/2023 Department of Human Services (DHS)/ Office of the Chief Financial Officer/Office of Finance and Treasury (OCFO/OFT) Criteria - The Uniform Guidance in 2 CFR Section 200.303 requires that non-Federal entities receiving Federal awards (i.e., auditee management) establish and maintain internal control designed to reasonably ensure compliance with Federal statues, regulations, and the terms and conditions of the Federal award. Per 7 CFR Section 274.8(b)(3), As an addition to or component of the Security Program required of Automated Data Processing (ADP) systems, the State agency shall ensure that the following electronic benefits transfer (EBT) security requirements are established: (i) Storage and control measures to control blank unissued EBT cards and PINs, and unused or spare POS devices; (ii) Measures to ensure communication access control. Communication controls shall include the transmission of transaction data and issuance information from POS terminals to work-stations and terminals at the data processing center; (iii) Message validation; (iv) Administrative and operational procedures; (v) A separate EBT security component shall be incorporated into the State agency Security Program for ADP systems. The periodic risk analyses required by the Security Program shall address the following items specific to an EBT system – (B) Completeness and timeliness of the reconciliation system; and (vi) The State agency shall incorporate the contingency plan approved by FNS into the Security Program. Condition – OCFO/OFT for DHS are required to maintain adequate security over, and documentation/records for EBT cards, to prevent their theft, embezzlement, loss damage, destruction, unauthorized transfer, negotiation, or use. OCFO/OFT have contracted with Fidelity National Information Service (FIS) for the issuance and security of the EBT cards; however, it is OCFO/OFT’s ultimate responsibility to ensure the contractor has controls in place to maintain adequate security over, and documentation/records of EBT cards. During our tests of the design and implementation of internal controls, we noted the following issues: • For nine (9) out of the 60 samples, although both EBT Balance Sheets reconciled with the EBT Card Issuance Logs included in the package, we noted the following deficiencies: o For one (1) out of the samples, we noted that for at least one (1) customer, the client’s name was missing from the EBT Intake Form. o For two (2) out of the samples, we noted that for at least one (1) customer on the United Planning Organization (UPO) Intake Form, the ID type for identification purposes was missing. o For two (2) out of the samples, we noted that for at least one (1) customer the case number was cancelled but no new/correct case number indicated on the EBT Intake Form. o For two (2) out of the samples, we noted that for at least one (1) customer the identification type was noted as referral on the EBT Intake Form, but no referral form was attached. o For one (1) out of the samples, we noted that for at least one (1) customer the DHS Photo ID Program Referral Form was missing the supervisor's signature and only had the eligibility staff’s signature. o For one (1) out of the samples, we noted that for at least one (1) customer, the name of the beneficiary in the intake forms does not agree with the EBT Issuance Log. Questioned Costs – None. Context – This is a condition identified per review of DHS’ compliance with specified requirements using a statistically valid sample. Effect – Without adequate internal controls to ensure compliance with EBT Card Security requirements, there is an increased risk that the inventory of EBT cards will not be properly maintained and accounted for. Cause – OCFO/OFT for DHS does not have adequate policies and procedures in place to ensure adequate safeguarding, documentation over issuance and monitoring of EBT cards. Recommendation - We recommend that OCFO/OFT for DHS strengthen formal policies and procedures to maintain adequate security over, and documentation/records for EBT Cards. Related Noncompliance – Noncompliance. Views of Responsible Officials and Planned Corrective Actions – The OCFO/OFT for DHS concurs with this finding. The District’s corrective action is described in the Management’s Corrective Action Plan included as Appendix B of the attached Management’s Section.
Finding Number: 2023-005 Prior Year Finding Number: N/A Compliance Requirement: Activities Allowed or Unallowed and Allowable Costs/Cost Principles Program: Government Department/Agency: U.S. Department of Agriculture Special Supplemental Nutrition Program for Women, Infants and Children (WIC) ALN: 10.557 Award #: Various Award Year: 10/01/2022 – 09/30/2023 Department of Health (DC Health) Criteria - The Uniform Guidance in 2 CFR Section 200.303 requires that non-Federal entities receiving Federal awards (i.e., auditee management) establish and maintain internal control designed to reasonably ensure compliance with Federal statues, regulations, and the terms and conditions of the Federal award. Per 2 CFR Section 200.430 Compensation – Personal Services: “Costs of compensation are allowable to the extent that they satisfy the specific requirements of this part, and that the total compensation for individual employees: (1) Is reasonable for the services rendered and conforms to the establish written policy of the non-Federal entity consistently applied to both Federal and non-Federal activities; (2) Follows an appointment made in accordance with a non-Federal entity’s laws and/or rules or written policies and meets the requirements of Federal statute, where applicable; and (3) Is determined and supported as provided in paragraph (i) of this section, Standards for Documentation of Personnel Expenses, when applicable.” 2 CFR Section 200.430(i): “Standards for Documentation of Personnel Expenses (1) Charges to Federal awards for salaries and wages must be based on records that accurately reflect the work performed. These records must: (i) Be supported by a system of internal control which provides reasonable assurance that the charges are accurate, allowable, and properly allocated; (ii) Be incorporated into the official records of the non-Federal entity; (iii) Reasonably reflect the total activity for which the employee is compensated by the non-Federal entity, not exceeding 100% of compensated activities; (iv) Encompass both federally assisted and all other activities compensated by the non-Federal entity on an integrated basis, but may include the use of subsidiary records as defined in the non-Federal entity’s written policy; (v) Comply with the established accounting policies and practices of the non-Federal entity; (vi) [Reserved] (vii) Support the distribution of the employee’s salary or wages among specific activities or cost objectives if the employee works on more than one Federal award; a Federal award and non-Federal award; an indirect cost activity and a direct cost activity; two or more indirect activities which are allocated using different allocation bases; or an unallowable activity and a direct or indirect cost activity. (viii) Budget estimates (i.e., estimates determined before the services are performed) alone do not qualify as support for charges to Federal awards.” Condition – From a sample of 40 payroll transactions, we noted five (5) transactions for one employee that did not work on the program, thus, there should be no hours charged to the program during the year. Per review of the total payroll charged to the program for the year for this employee, we noted $32,290 that should not have been charged to the program. Questioned Costs – Known amount is $32,290. Context – This is a condition identified per review of DC Health’s compliance with specified requirements using a statistically valid sample. Payroll costs including fringe benefits, for the WIC program in fiscal year 2023 were $1,073,965. Effect – DC Health was unable to demonstrate that the payroll expenditures charged to the WIC program were allowable expenses in accordance with 2 CFR Part 200.430. Cause – DC Health did not adhere to its internal control policies and procedures for reviewing the eligibility and allowability of payroll expenditures charged to the WIC program. Recommendation – We recommend that DC Health strengthen its policies and procedures to ensure that only allowable expenses are charged to the program as required by 2 CFR 200.430. Related Noncompliance – Noncompliance. Views of Responsible Officials and Planned Corrective Actions – DC Health concurs with the finding. DC Health complies with local and federal requirements for regular and routine review of budgeted employee time and alignment with allowable costs and hours worked. Staff duties are documented in performance plans, SMART goals, logs/calendars and reports revised by supervisors. The exception found in the sample was corrected in January 2024 when the employee was found to be budgeted partly on the WIC grant. The District’s corrective action is described in the Management’s Corrective Action Plan included as Appendix B of the attached Management’s Section.
Finding Number: 2023-006 Prior Year Finding Number: N/A Compliance Requirement: Activities Allowed or Unallowed and Allowable Costs/Cost Principles Program: Government Department/Agency: U.S. Department of Agriculture Special Supplemental Nutrition Program for Women, Infants and Children (WIC) ALN: 10.557 Award #: Various Award Year: 10/01/2022 – 09/30/2023 Department of Health (DC Health) Criteria - The Uniform Guidance in 2 CFR Section 200.303 requires that non-Federal entities receiving Federal awards (i.e., auditee management) establish and maintain internal control designed to reasonably ensure compliance with Federal statues, regulations, and the terms and conditions of the Federal award. Per 7 CFR 246.16a (c) Rebate contracts with infant formula manufacturers are authorized as a cost containment measure. Rebates represent a reduction of expenditures previously incurred for WIC food benefit costs. Applying the rebates received to such costs enabled the DC Health to extend program benefits to more participants than could have been serviced this fiscal year in the absence of the rebate contract. Condition – During our review of five (5) rebate samples, we found that for one (1) rebate amounting to $4,639, DC Health was unable to provide the invoice to support the rebate credit received in October 2022. Questioned Costs – Not determinable. Context – This is a condition identified per review of DC Health’s compliance with specified requirements using a statistically valid sample. We sampled $1,085,404 of the population of $3,351,591. Effect – Without strict adherence to policies and procedures, there is no assurance that food rebates are accurately reviewed and approved before being claimed for credit. Cause – DC Health did not follow its own internal control policies and procedures for reviewing rebates submitted for credit. Recommendation – We recommend that DC Health strictly adhere to its policies and procedures to ensure that rebates are reviewed and approved before claiming for credit. Related Noncompliance – Noncompliance. Views of Responsible Officials and Planned Corrective Actions – DC Health concurs with the finding. Contributing factors include absence of an internal policy and procedure outlining the annual process for the service provider, to submit supporting documentation to DC WIC for review and approval prior to receipt of the annual rebate. This internal control would have alerted WIC staff to contact the service provider last year, when they did not email a cover letter to DC WIC as supporting documentation for the annual vendor’s rebate. The District’s corrective action is described in the Management’s Corrective Action Plan included as Appendix B of the attached Management’s Section.
Finding Number: 2023-007 Prior Year Finding Number: N/A Compliance Requirement: Eligibility Program: Government Department/Agency: U.S. Department of Agriculture Special Supplemental Nutrition Program for Women, Infants and Children (WIC) ALN: 10.557 Award #: Various Award Year: 10/01/2022 – 09/30/2023 Department of Health (DC Health) Criteria - The Uniform Guidance in 2 CFR Section 200.303 requires that non-Federal entities receiving Federal awards (i.e., auditee management) establish and maintain internal control designed to reasonably ensure compliance with Federal statues, regulations, and the terms and conditions of the Federal award. Per 7 CFR § 246.7 - Certification of participants: “246.7 (d)(v) - (v) Are applicants required to document income eligibility? (A) Adjunctively/automatically income eligible applicants. The State or local agency must require applicants determined to be adjunctively or automatically income eligible to document their eligibility for the program that makes them income eligible as set forth in paragraph (d)(2)(vi) of this section. (B) Other applicants. The State or local agency must require all other applicants to provide documentation of family income at certification.” Condition – During testing over individual eligibility for the WIC program benefits, we noted the following exception: • BDO identified one (1) instance out of forty (40) samples where "COVID Self-declared" was accepted as proof of income for determining eligibility under the WIC program, which is no longer valid for income determination. Questioned Costs – Not determinable. Context – This is a condition identified per review of DC Health’s compliance with specified requirements using a statistically valid sample. Effect – Due to lack of operating effectiveness of controls and non-compliance with program requirements, there is no assurance over income eligibility under the WIC program for individual participants. Cause – DC Health did not adhere to the required internal control procedures over income eligibility determinations to ensure that certifications are issued to eligible individuals. Recommendation – We recommend that DC Health implement internal control procedures to ensure income eligibility determinations are made accurately in compliance with the program requirements. Related Noncompliance – Noncompliance. Views of Responsible Officials and Planned Corrective Actions – DC Health concurs with the finding. The internal control deficiencies identified are a result of a combination of grantee staff turnover, change in federal WIC policy after the end of the public health emergency and the continued existence of pandemic era terminology in DC WIC’s management information system. In fiscal year 2024, The DC WIC Program implemented several quality assurance activities that are aimed at resetting the program back to normal operations pre-pandemic. The District’s corrective action is described in the Management’s Corrective Action Plan included as Appendix B of the attached Management’s Section.
Finding Number: 2023-005 Prior Year Finding Number: N/A Compliance Requirement: Activities Allowed or Unallowed and Allowable Costs/Cost Principles Program: Government Department/Agency: U.S. Department of Agriculture Special Supplemental Nutrition Program for Women, Infants and Children (WIC) ALN: 10.557 Award #: Various Award Year: 10/01/2022 – 09/30/2023 Department of Health (DC Health) Criteria - The Uniform Guidance in 2 CFR Section 200.303 requires that non-Federal entities receiving Federal awards (i.e., auditee management) establish and maintain internal control designed to reasonably ensure compliance with Federal statues, regulations, and the terms and conditions of the Federal award. Per 2 CFR Section 200.430 Compensation – Personal Services: “Costs of compensation are allowable to the extent that they satisfy the specific requirements of this part, and that the total compensation for individual employees: (1) Is reasonable for the services rendered and conforms to the establish written policy of the non-Federal entity consistently applied to both Federal and non-Federal activities; (2) Follows an appointment made in accordance with a non-Federal entity’s laws and/or rules or written policies and meets the requirements of Federal statute, where applicable; and (3) Is determined and supported as provided in paragraph (i) of this section, Standards for Documentation of Personnel Expenses, when applicable.” 2 CFR Section 200.430(i): “Standards for Documentation of Personnel Expenses (1) Charges to Federal awards for salaries and wages must be based on records that accurately reflect the work performed. These records must: (i) Be supported by a system of internal control which provides reasonable assurance that the charges are accurate, allowable, and properly allocated; (ii) Be incorporated into the official records of the non-Federal entity; (iii) Reasonably reflect the total activity for which the employee is compensated by the non-Federal entity, not exceeding 100% of compensated activities; (iv) Encompass both federally assisted and all other activities compensated by the non-Federal entity on an integrated basis, but may include the use of subsidiary records as defined in the non-Federal entity’s written policy; (v) Comply with the established accounting policies and practices of the non-Federal entity; (vi) [Reserved] (vii) Support the distribution of the employee’s salary or wages among specific activities or cost objectives if the employee works on more than one Federal award; a Federal award and non-Federal award; an indirect cost activity and a direct cost activity; two or more indirect activities which are allocated using different allocation bases; or an unallowable activity and a direct or indirect cost activity. (viii) Budget estimates (i.e., estimates determined before the services are performed) alone do not qualify as support for charges to Federal awards.” Condition – From a sample of 40 payroll transactions, we noted five (5) transactions for one employee that did not work on the program, thus, there should be no hours charged to the program during the year. Per review of the total payroll charged to the program for the year for this employee, we noted $32,290 that should not have been charged to the program. Questioned Costs – Known amount is $32,290. Context – This is a condition identified per review of DC Health’s compliance with specified requirements using a statistically valid sample. Payroll costs including fringe benefits, for the WIC program in fiscal year 2023 were $1,073,965. Effect – DC Health was unable to demonstrate that the payroll expenditures charged to the WIC program were allowable expenses in accordance with 2 CFR Part 200.430. Cause – DC Health did not adhere to its internal control policies and procedures for reviewing the eligibility and allowability of payroll expenditures charged to the WIC program. Recommendation – We recommend that DC Health strengthen its policies and procedures to ensure that only allowable expenses are charged to the program as required by 2 CFR 200.430. Related Noncompliance – Noncompliance. Views of Responsible Officials and Planned Corrective Actions – DC Health concurs with the finding. DC Health complies with local and federal requirements for regular and routine review of budgeted employee time and alignment with allowable costs and hours worked. Staff duties are documented in performance plans, SMART goals, logs/calendars and reports revised by supervisors. The exception found in the sample was corrected in January 2024 when the employee was found to be budgeted partly on the WIC grant. The District’s corrective action is described in the Management’s Corrective Action Plan included as Appendix B of the attached Management’s Section.
Finding Number: 2023-006 Prior Year Finding Number: N/A Compliance Requirement: Activities Allowed or Unallowed and Allowable Costs/Cost Principles Program: Government Department/Agency: U.S. Department of Agriculture Special Supplemental Nutrition Program for Women, Infants and Children (WIC) ALN: 10.557 Award #: Various Award Year: 10/01/2022 – 09/30/2023 Department of Health (DC Health) Criteria - The Uniform Guidance in 2 CFR Section 200.303 requires that non-Federal entities receiving Federal awards (i.e., auditee management) establish and maintain internal control designed to reasonably ensure compliance with Federal statues, regulations, and the terms and conditions of the Federal award. Per 7 CFR 246.16a (c) Rebate contracts with infant formula manufacturers are authorized as a cost containment measure. Rebates represent a reduction of expenditures previously incurred for WIC food benefit costs. Applying the rebates received to such costs enabled the DC Health to extend program benefits to more participants than could have been serviced this fiscal year in the absence of the rebate contract. Condition – During our review of five (5) rebate samples, we found that for one (1) rebate amounting to $4,639, DC Health was unable to provide the invoice to support the rebate credit received in October 2022. Questioned Costs – Not determinable. Context – This is a condition identified per review of DC Health’s compliance with specified requirements using a statistically valid sample. We sampled $1,085,404 of the population of $3,351,591. Effect – Without strict adherence to policies and procedures, there is no assurance that food rebates are accurately reviewed and approved before being claimed for credit. Cause – DC Health did not follow its own internal control policies and procedures for reviewing rebates submitted for credit. Recommendation – We recommend that DC Health strictly adhere to its policies and procedures to ensure that rebates are reviewed and approved before claiming for credit. Related Noncompliance – Noncompliance. Views of Responsible Officials and Planned Corrective Actions – DC Health concurs with the finding. Contributing factors include absence of an internal policy and procedure outlining the annual process for the service provider, to submit supporting documentation to DC WIC for review and approval prior to receipt of the annual rebate. This internal control would have alerted WIC staff to contact the service provider last year, when they did not email a cover letter to DC WIC as supporting documentation for the annual vendor’s rebate. The District’s corrective action is described in the Management’s Corrective Action Plan included as Appendix B of the attached Management’s Section.