2023-006 Department of Health and Human Services Federal Financial Assistance Listing #93.498 COVID-19 Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution Applicable Federal Award Number and Year – Period 4 TIN #460255944 Activities Allowed or Unallowed and Allowable Costs/Cost Principles Material Weakness in Internal Control over Compliance and Noncompliance Reporting Material Weakness in Internal Control over Compliance and Material Noncompliance Criteria: 2 CFR 200.303(a) establishes that the auditee must establish and maintain effective internal control over the federal award that provides assurance that the entity is managing the federal award in compliance with federal statutes, regulations, and conditions of the federal award. The Hospital selected option 1 to calculate lost revenue which consists of a comparison of 2019 actual results to 2020, 2021, and 2022 actual results by quarter. Patient care-related revenue should be reported net of adjustments for all third-party payers, charity care adjustments, bad debt, and any other discounts or adjustments, as applicable when reporting patient carerelated revenue sources. Condition: The Hospital’s lost revenue calculation was not reviewed and approved by a separate individual outside of the preparer. The Hospital’s lost revenue calculation was based upon actual revenue billed and reported within the Hospital’s electronic medical records (EMR) system which does not consider monthly or quarterly adjustments. The Hospital’s special report submitted to the Department of Health and Human Services for Period 4 TIN#460255944 was not reviewed and approved by a separate individual outside of the individual who inputted and submitted the report. Cause: The Hospital did not have an internal control process in place to ensure a secondary review and approval of the lost revenue calculation. The Hospital used the EMR system to calculate lost revenue due to the categories required to be input into the Hospital’s special report as the categories could not be identified within the general ledger system. The Hospital did not have an internal control process in place to ensure review and approval of the report submitted to the Department of Health and Human Services for Period 4 was performed and documented. Effect: The lost revenue reported within the special report submitted to the Department of Health and Human Services for Period 4 was $204,862 for 2020 and $57,757 for 2021. Had the Hospital considered monthly or quarterly adjustments in the lost revenue calculation during the period of availability, the lost revenue would have been $248,664 in 2020 and $86,392 in 2021. No lost revenue was utilized during Period 4. Questioned Costs: Lost revenue reported would increase after consideration of monthly or quarterly adjustments. As a result, there are no questioned costs for activities allowed or unallowed and allowable costs/cost principles. Context/Sampling: Key line items were tested on the Period 4 Department of Health and Human Services special report. Repeat Finding from Prior Years: No Recommendation: We recommend the Hospital implement a control process which verifies that lost revenue is calculated correctly and includes a secondary review and approval of the calculation. We recommend Hospital implement a control process to ensure the special report is reviewed and approved prior to submission. Views of Responsible Officials: Management agrees with the finding.
2023-007 Department of Health and Human Services Federal Financial Assistance Listing #93.498 COVID-19 Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution Applicable Federal Award Number and Year – Period 4 TIN #460255944 Activities Allowed or Unallowed and Allowable Costs/Cost Principles Material Weakness in Internal Control over Compliance and Material Noncompliance Reporting Material Weakness in Internal Control over Compliance and Material Noncompliance Criteria: 2 CFR 200.303(a) establishes that the auditee must establish and maintain effective internal control over the federal award that provides assurance that the entity is managing the federal award in compliance with federal statutes, regulations, and conditions of the federal award. Condition: The Hospital’s final expenditure listing identified as eligible and claimed under the Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution program (the program) was not reviewed and approved by a separate individual outside of the preparer. Additionally, the Hospital claimed mortgage reimbursements as expenditures under the program. Cause: The Hospital did not have an internal control process in place to ensure a secondary review and approval of the final expenditure listing and to ensure the expenditures claimed on the report were for expenditures incurred. Some amounts claimed under the program were mortgage reimbursements. Effect: Without a secondary review and approval, there is a possibility that ineligible expenditures are claimed under the program and included within the special report. Expenses included within the special report submitted to the Department of Health and Human Services for Period 4 TIN#460255944 relating to the mortgage reimbursements were overstated by $66,094. Questioned Costs: $66,094. Context/Sampling: Summary level testing was performed over mortgage and insurance expenses. In addition, a nonstatistical sample of 8 ($185,866) out of a population of 31 transactions ($302,202) relating to general and administrative and healthcare related expenses, including personnel, lease payments, supplies, equipment and other healthcare expenses were tested. Repeat Finding from Prior Years: No Recommendation: We recommend the Hospital implement a control process which includes a secondary review and approval of the final expenditure listing used to claim the allowable costs under the program. Views of Responsible Officials: Management agrees with the finding.
Finding 2023-003 Inadequate Tracking of Federal Expenses (Allowable Costs) Federal Programs: All Criteria: In accordance with CFR 200.302 organizations receiving Federal awards must maintain accurate records that adequately identify the source and application of Federal funds. This includes tracking Federal expenditures separately and distinctly within their accounting system. Additionally, in accordance with CFR 200.303, the non-Federal entity must: Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework” issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition: The Organization's use of class codes in QuickBooks to track Federal expenses was found to be inadequate. Although the Organization uses QuickBooks to record financial transactions, there is no systematic method in place to ensure that Federal expenditures are properly classified and tracked using distinct class codes. Cause: The deficiency in tracking Federal expenses within QuickBooks using class codes appears to stem from a lack of understanding or awareness of the requirements outlined in Uniform Guidance. Additionally, there may be insufficient training provided to staff responsible for financial management and accounting practices. Effect or Potential Effect: Without proper tracking of Federal expenses using class codes, the Organization risks commingling Federal funds with other sources of revenue, which could lead to inaccurate reporting and potential non-compliance with Uniform Guidance requirements. This deficiency increases the likelihood of errors in financial reporting and raises concerns about the Organization's ability to demonstrate proper stewardship of Federal funds. Questioned Costs: Indeterminable. Context: The Organization does not currently use its financial management system to leverage the tracking of Federal funds between programs; the tracking is currently manual, based on Excel spreadsheets, and difficult to track/audit. Recommendation: It is recommended that the Organization establish and implement procedures to effectively track Federal expenses within QuickBooks using distinct class codes in accordance with 2 CFR 200.302. This may involve providing training to staff on the proper use of class codes and ensuring that all Federal expenditures are consistently and accurately classified in the accounting system.
Finding 2023-003 Inadequate Tracking of Federal Expenses (Allowable Costs) Federal Programs: All Criteria: In accordance with CFR 200.302 organizations receiving Federal awards must maintain accurate records that adequately identify the source and application of Federal funds. This includes tracking Federal expenditures separately and distinctly within their accounting system. Additionally, in accordance with CFR 200.303, the non-Federal entity must: Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework” issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition: The Organization's use of class codes in QuickBooks to track Federal expenses was found to be inadequate. Although the Organization uses QuickBooks to record financial transactions, there is no systematic method in place to ensure that Federal expenditures are properly classified and tracked using distinct class codes. Cause: The deficiency in tracking Federal expenses within QuickBooks using class codes appears to stem from a lack of understanding or awareness of the requirements outlined in Uniform Guidance. Additionally, there may be insufficient training provided to staff responsible for financial management and accounting practices. Effect or Potential Effect: Without proper tracking of Federal expenses using class codes, the Organization risks commingling Federal funds with other sources of revenue, which could lead to inaccurate reporting and potential non-compliance with Uniform Guidance requirements. This deficiency increases the likelihood of errors in financial reporting and raises concerns about the Organization's ability to demonstrate proper stewardship of Federal funds. Questioned Costs: Indeterminable. Context: The Organization does not currently use its financial management system to leverage the tracking of Federal funds between programs; the tracking is currently manual, based on Excel spreadsheets, and difficult to track/audit. Recommendation: It is recommended that the Organization establish and implement procedures to effectively track Federal expenses within QuickBooks using distinct class codes in accordance with 2 CFR 200.302. This may involve providing training to staff on the proper use of class codes and ensuring that all Federal expenditures are consistently and accurately classified in the accounting system.
Finding 2023-003 Inadequate Tracking of Federal Expenses (Allowable Costs) Federal Programs: All Criteria: In accordance with CFR 200.302 organizations receiving Federal awards must maintain accurate records that adequately identify the source and application of Federal funds. This includes tracking Federal expenditures separately and distinctly within their accounting system. Additionally, in accordance with CFR 200.303, the non-Federal entity must: Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework” issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition: The Organization's use of class codes in QuickBooks to track Federal expenses was found to be inadequate. Although the Organization uses QuickBooks to record financial transactions, there is no systematic method in place to ensure that Federal expenditures are properly classified and tracked using distinct class codes. Cause: The deficiency in tracking Federal expenses within QuickBooks using class codes appears to stem from a lack of understanding or awareness of the requirements outlined in Uniform Guidance. Additionally, there may be insufficient training provided to staff responsible for financial management and accounting practices. Effect or Potential Effect: Without proper tracking of Federal expenses using class codes, the Organization risks commingling Federal funds with other sources of revenue, which could lead to inaccurate reporting and potential non-compliance with Uniform Guidance requirements. This deficiency increases the likelihood of errors in financial reporting and raises concerns about the Organization's ability to demonstrate proper stewardship of Federal funds. Questioned Costs: Indeterminable. Context: The Organization does not currently use its financial management system to leverage the tracking of Federal funds between programs; the tracking is currently manual, based on Excel spreadsheets, and difficult to track/audit. Recommendation: It is recommended that the Organization establish and implement procedures to effectively track Federal expenses within QuickBooks using distinct class codes in accordance with 2 CFR 200.302. This may involve providing training to staff on the proper use of class codes and ensuring that all Federal expenditures are consistently and accurately classified in the accounting system.
Federal Agency: U.S. Department of Health and Human Services Federal Program: 93.568 Low Income Home Energy Assistance Condition: As part of our testing of Action Inc’s (the Organization) internal control over compliance for eligibility, we noted that the Organization did not follow their internal controls regarding income recalculation for one out of forty applications reviewed. The issue did not result in disqualification of the individual to receive benefits nor did the issue impact the participant’s benefits being provided. Criteria: 2 CFR 200.303 indicates that non-Federal entities receiving Federal awards must establish and maintain effective internal controls over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations and the terms and conditions of the Federal award. Cause: The Organization did not properly follow its internal controls. Effect: The Organization did not properly calculate the income level for a participant in accordance with its internal controls Context: One out of forty applications sampled. Our sample was not a statistically valid sample. This was not a repeat finding from a prior period. Questioned Costs: None Recommendations: Management should ensure that the Organization’s internal controls in place are properly followed. Management Response: Management agrees with the finding and will provide additional training during fiscal year 2024 to its program staff to ensure that the Organization’s internal controls are properly followed.
Federal Agency: U.S. Department of Health and Human Services Federal Program: 93.568 Low Income Home Energy Assistance Condition: As part of our testing of Action Inc’s (the Organization) internal control over compliance for eligibility, we noted that the Organization did not follow their internal controls regarding income recalculation for one out of forty applications reviewed. The issue did not result in disqualification of the individual to receive benefits nor did the issue impact the participant’s benefits being provided. Criteria: 2 CFR 200.303 indicates that non-Federal entities receiving Federal awards must establish and maintain effective internal controls over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations and the terms and conditions of the Federal award. Cause: The Organization did not properly follow its internal controls. Effect: The Organization did not properly calculate the income level for a participant in accordance with its internal controls Context: One out of forty applications sampled. Our sample was not a statistically valid sample. This was not a repeat finding from a prior period. Questioned Costs: None Recommendations: Management should ensure that the Organization’s internal controls in place are properly followed. Management Response: Management agrees with the finding and will provide additional training during fiscal year 2024 to its program staff to ensure that the Organization’s internal controls are properly followed.
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Workday, a cloud based system, to provide human resources and payroll applications. BMC’s management of Workday includes maintaining the application system layer of the information technology (IT)control environment and relies on the Workday vendor to support infrastructure layers through Service Organization Control (SOC) Type 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Workday IT application controls. During our testing, we noted the following deficiencies operating effectiveness of the Workday general IT controls: 1) BMC did not perform and document a Workday change review during the fiscal year, such a control would enable management to detect inappropriate changes to the Workday application. Such a report detailing changes to Workday was generated as part of the Uniform Guidance audit, however management did not formally perform and document its review over the report. Upon audit inquiry, the review was subsequently performed by management and we observed no inappropriate changes were made during the year that would impact the IT application controls relied upon. 2) For 1 of 13 employee new or modified Workday access provisioning samples, BMC did not maintain adequate documentation of the access request and approval. Upon audit inquiry, it was determined that access was provided as part of a promotion and was appropriate; however, was not formally documented. Cause The conditions above related to the following: 1) Management did not formally perform and document their review over the report due to a lack of knowledge of performance and documentation requirements by the control operators. 2) The exception occurred due to delays in supervisors’ timely reporting of terminations in Infor which delayed the de provisioning process performed by IT. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access and change management may result in unauthorized changes being made to Workday, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the change management policies and procedures with key personnel to help ensure that the Workday change Review is performed to address change management risks for the system. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for requesting and provisioning access to help ensure that requests for both new and modified access are appropriately obtained and documented for approval of access needed for job responsibilities. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Workday, a cloud based system, to provide human resources and payroll applications. BMC’s management of Workday includes maintaining the application system layer of the information technology (IT)control environment and relies on the Workday vendor to support infrastructure layers through Service Organization Control (SOC) Type 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Workday IT application controls. During our testing, we noted the following deficiencies operating effectiveness of the Workday general IT controls: 1) BMC did not perform and document a Workday change review during the fiscal year, such a control would enable management to detect inappropriate changes to the Workday application. Such a report detailing changes to Workday was generated as part of the Uniform Guidance audit, however management did not formally perform and document its review over the report. Upon audit inquiry, the review was subsequently performed by management and we observed no inappropriate changes were made during the year that would impact the IT application controls relied upon. 2) For 1 of 13 employee new or modified Workday access provisioning samples, BMC did not maintain adequate documentation of the access request and approval. Upon audit inquiry, it was determined that access was provided as part of a promotion and was appropriate; however, was not formally documented. Cause The conditions above related to the following: 1) Management did not formally perform and document their review over the report due to a lack of knowledge of performance and documentation requirements by the control operators. 2) The exception occurred due to delays in supervisors’ timely reporting of terminations in Infor which delayed the de provisioning process performed by IT. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access and change management may result in unauthorized changes being made to Workday, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the change management policies and procedures with key personnel to help ensure that the Workday change Review is performed to address change management risks for the system. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for requesting and provisioning access to help ensure that requests for both new and modified access are appropriately obtained and documented for approval of access needed for job responsibilities. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Workday, a cloud based system, to provide human resources and payroll applications. BMC’s management of Workday includes maintaining the application system layer of the information technology (IT)control environment and relies on the Workday vendor to support infrastructure layers through Service Organization Control (SOC) Type 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Workday IT application controls. During our testing, we noted the following deficiencies operating effectiveness of the Workday general IT controls: 1) BMC did not perform and document a Workday change review during the fiscal year, such a control would enable management to detect inappropriate changes to the Workday application. Such a report detailing changes to Workday was generated as part of the Uniform Guidance audit, however management did not formally perform and document its review over the report. Upon audit inquiry, the review was subsequently performed by management and we observed no inappropriate changes were made during the year that would impact the IT application controls relied upon. 2) For 1 of 13 employee new or modified Workday access provisioning samples, BMC did not maintain adequate documentation of the access request and approval. Upon audit inquiry, it was determined that access was provided as part of a promotion and was appropriate; however, was not formally documented. Cause The conditions above related to the following: 1) Management did not formally perform and document their review over the report due to a lack of knowledge of performance and documentation requirements by the control operators. 2) The exception occurred due to delays in supervisors’ timely reporting of terminations in Infor which delayed the de provisioning process performed by IT. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access and change management may result in unauthorized changes being made to Workday, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the change management policies and procedures with key personnel to help ensure that the Workday change Review is performed to address change management risks for the system. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for requesting and provisioning access to help ensure that requests for both new and modified access are appropriately obtained and documented for approval of access needed for job responsibilities. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Workday, a cloud based system, to provide human resources and payroll applications. BMC’s management of Workday includes maintaining the application system layer of the information technology (IT)control environment and relies on the Workday vendor to support infrastructure layers through Service Organization Control (SOC) Type 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Workday IT application controls. During our testing, we noted the following deficiencies operating effectiveness of the Workday general IT controls: 1) BMC did not perform and document a Workday change review during the fiscal year, such a control would enable management to detect inappropriate changes to the Workday application. Such a report detailing changes to Workday was generated as part of the Uniform Guidance audit, however management did not formally perform and document its review over the report. Upon audit inquiry, the review was subsequently performed by management and we observed no inappropriate changes were made during the year that would impact the IT application controls relied upon. 2) For 1 of 13 employee new or modified Workday access provisioning samples, BMC did not maintain adequate documentation of the access request and approval. Upon audit inquiry, it was determined that access was provided as part of a promotion and was appropriate; however, was not formally documented. Cause The conditions above related to the following: 1) Management did not formally perform and document their review over the report due to a lack of knowledge of performance and documentation requirements by the control operators. 2) The exception occurred due to delays in supervisors’ timely reporting of terminations in Infor which delayed the de provisioning process performed by IT. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access and change management may result in unauthorized changes being made to Workday, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the change management policies and procedures with key personnel to help ensure that the Workday change Review is performed to address change management risks for the system. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for requesting and provisioning access to help ensure that requests for both new and modified access are appropriately obtained and documented for approval of access needed for job responsibilities. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Workday, a cloud based system, to provide human resources and payroll applications. BMC’s management of Workday includes maintaining the application system layer of the information technology (IT)control environment and relies on the Workday vendor to support infrastructure layers through Service Organization Control (SOC) Type 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Workday IT application controls. During our testing, we noted the following deficiencies operating effectiveness of the Workday general IT controls: 1) BMC did not perform and document a Workday change review during the fiscal year, such a control would enable management to detect inappropriate changes to the Workday application. Such a report detailing changes to Workday was generated as part of the Uniform Guidance audit, however management did not formally perform and document its review over the report. Upon audit inquiry, the review was subsequently performed by management and we observed no inappropriate changes were made during the year that would impact the IT application controls relied upon. 2) For 1 of 13 employee new or modified Workday access provisioning samples, BMC did not maintain adequate documentation of the access request and approval. Upon audit inquiry, it was determined that access was provided as part of a promotion and was appropriate; however, was not formally documented. Cause The conditions above related to the following: 1) Management did not formally perform and document their review over the report due to a lack of knowledge of performance and documentation requirements by the control operators. 2) The exception occurred due to delays in supervisors’ timely reporting of terminations in Infor which delayed the de provisioning process performed by IT. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access and change management may result in unauthorized changes being made to Workday, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the change management policies and procedures with key personnel to help ensure that the Workday change Review is performed to address change management risks for the system. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for requesting and provisioning access to help ensure that requests for both new and modified access are appropriately obtained and documented for approval of access needed for job responsibilities. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Workday, a cloud based system, to provide human resources and payroll applications. BMC’s management of Workday includes maintaining the application system layer of the information technology (IT)control environment and relies on the Workday vendor to support infrastructure layers through Service Organization Control (SOC) Type 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Workday IT application controls. During our testing, we noted the following deficiencies operating effectiveness of the Workday general IT controls: 1) BMC did not perform and document a Workday change review during the fiscal year, such a control would enable management to detect inappropriate changes to the Workday application. Such a report detailing changes to Workday was generated as part of the Uniform Guidance audit, however management did not formally perform and document its review over the report. Upon audit inquiry, the review was subsequently performed by management and we observed no inappropriate changes were made during the year that would impact the IT application controls relied upon. 2) For 1 of 13 employee new or modified Workday access provisioning samples, BMC did not maintain adequate documentation of the access request and approval. Upon audit inquiry, it was determined that access was provided as part of a promotion and was appropriate; however, was not formally documented. Cause The conditions above related to the following: 1) Management did not formally perform and document their review over the report due to a lack of knowledge of performance and documentation requirements by the control operators. 2) The exception occurred due to delays in supervisors’ timely reporting of terminations in Infor which delayed the de provisioning process performed by IT. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access and change management may result in unauthorized changes being made to Workday, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the change management policies and procedures with key personnel to help ensure that the Workday change Review is performed to address change management risks for the system. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for requesting and provisioning access to help ensure that requests for both new and modified access are appropriately obtained and documented for approval of access needed for job responsibilities. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Workday, a cloud based system, to provide human resources and payroll applications. BMC’s management of Workday includes maintaining the application system layer of the information technology (IT)control environment and relies on the Workday vendor to support infrastructure layers through Service Organization Control (SOC) Type 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Workday IT application controls. During our testing, we noted the following deficiencies operating effectiveness of the Workday general IT controls: 1) BMC did not perform and document a Workday change review during the fiscal year, such a control would enable management to detect inappropriate changes to the Workday application. Such a report detailing changes to Workday was generated as part of the Uniform Guidance audit, however management did not formally perform and document its review over the report. Upon audit inquiry, the review was subsequently performed by management and we observed no inappropriate changes were made during the year that would impact the IT application controls relied upon. 2) For 1 of 13 employee new or modified Workday access provisioning samples, BMC did not maintain adequate documentation of the access request and approval. Upon audit inquiry, it was determined that access was provided as part of a promotion and was appropriate; however, was not formally documented. Cause The conditions above related to the following: 1) Management did not formally perform and document their review over the report due to a lack of knowledge of performance and documentation requirements by the control operators. 2) The exception occurred due to delays in supervisors’ timely reporting of terminations in Infor which delayed the de provisioning process performed by IT. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access and change management may result in unauthorized changes being made to Workday, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the change management policies and procedures with key personnel to help ensure that the Workday change Review is performed to address change management risks for the system. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for requesting and provisioning access to help ensure that requests for both new and modified access are appropriately obtained and documented for approval of access needed for job responsibilities. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Workday, a cloud based system, to provide human resources and payroll applications. BMC’s management of Workday includes maintaining the application system layer of the information technology (IT)control environment and relies on the Workday vendor to support infrastructure layers through Service Organization Control (SOC) Type 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Workday IT application controls. During our testing, we noted the following deficiencies operating effectiveness of the Workday general IT controls: 1) BMC did not perform and document a Workday change review during the fiscal year, such a control would enable management to detect inappropriate changes to the Workday application. Such a report detailing changes to Workday was generated as part of the Uniform Guidance audit, however management did not formally perform and document its review over the report. Upon audit inquiry, the review was subsequently performed by management and we observed no inappropriate changes were made during the year that would impact the IT application controls relied upon. 2) For 1 of 13 employee new or modified Workday access provisioning samples, BMC did not maintain adequate documentation of the access request and approval. Upon audit inquiry, it was determined that access was provided as part of a promotion and was appropriate; however, was not formally documented. Cause The conditions above related to the following: 1) Management did not formally perform and document their review over the report due to a lack of knowledge of performance and documentation requirements by the control operators. 2) The exception occurred due to delays in supervisors’ timely reporting of terminations in Infor which delayed the de provisioning process performed by IT. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access and change management may result in unauthorized changes being made to Workday, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the change management policies and procedures with key personnel to help ensure that the Workday change Review is performed to address change management risks for the system. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for requesting and provisioning access to help ensure that requests for both new and modified access are appropriately obtained and documented for approval of access needed for job responsibilities. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Workday, a cloud based system, to provide human resources and payroll applications. BMC’s management of Workday includes maintaining the application system layer of the information technology (IT)control environment and relies on the Workday vendor to support infrastructure layers through Service Organization Control (SOC) Type 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Workday IT application controls. During our testing, we noted the following deficiencies operating effectiveness of the Workday general IT controls: 1) BMC did not perform and document a Workday change review during the fiscal year, such a control would enable management to detect inappropriate changes to the Workday application. Such a report detailing changes to Workday was generated as part of the Uniform Guidance audit, however management did not formally perform and document its review over the report. Upon audit inquiry, the review was subsequently performed by management and we observed no inappropriate changes were made during the year that would impact the IT application controls relied upon. 2) For 1 of 13 employee new or modified Workday access provisioning samples, BMC did not maintain adequate documentation of the access request and approval. Upon audit inquiry, it was determined that access was provided as part of a promotion and was appropriate; however, was not formally documented. Cause The conditions above related to the following: 1) Management did not formally perform and document their review over the report due to a lack of knowledge of performance and documentation requirements by the control operators. 2) The exception occurred due to delays in supervisors’ timely reporting of terminations in Infor which delayed the de provisioning process performed by IT. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access and change management may result in unauthorized changes being made to Workday, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the change management policies and procedures with key personnel to help ensure that the Workday change Review is performed to address change management risks for the system. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for requesting and provisioning access to help ensure that requests for both new and modified access are appropriately obtained and documented for approval of access needed for job responsibilities. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Workday, a cloud based system, to provide human resources and payroll applications. BMC’s management of Workday includes maintaining the application system layer of the information technology (IT)control environment and relies on the Workday vendor to support infrastructure layers through Service Organization Control (SOC) Type 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Workday IT application controls. During our testing, we noted the following deficiencies operating effectiveness of the Workday general IT controls: 1) BMC did not perform and document a Workday change review during the fiscal year, such a control would enable management to detect inappropriate changes to the Workday application. Such a report detailing changes to Workday was generated as part of the Uniform Guidance audit, however management did not formally perform and document its review over the report. Upon audit inquiry, the review was subsequently performed by management and we observed no inappropriate changes were made during the year that would impact the IT application controls relied upon. 2) For 1 of 13 employee new or modified Workday access provisioning samples, BMC did not maintain adequate documentation of the access request and approval. Upon audit inquiry, it was determined that access was provided as part of a promotion and was appropriate; however, was not formally documented. Cause The conditions above related to the following: 1) Management did not formally perform and document their review over the report due to a lack of knowledge of performance and documentation requirements by the control operators. 2) The exception occurred due to delays in supervisors’ timely reporting of terminations in Infor which delayed the de provisioning process performed by IT. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access and change management may result in unauthorized changes being made to Workday, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the change management policies and procedures with key personnel to help ensure that the Workday change Review is performed to address change management risks for the system. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for requesting and provisioning access to help ensure that requests for both new and modified access are appropriately obtained and documented for approval of access needed for job responsibilities. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Workday, a cloud based system, to provide human resources and payroll applications. BMC’s management of Workday includes maintaining the application system layer of the information technology (IT)control environment and relies on the Workday vendor to support infrastructure layers through Service Organization Control (SOC) Type 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Workday IT application controls. During our testing, we noted the following deficiencies operating effectiveness of the Workday general IT controls: 1) BMC did not perform and document a Workday change review during the fiscal year, such a control would enable management to detect inappropriate changes to the Workday application. Such a report detailing changes to Workday was generated as part of the Uniform Guidance audit, however management did not formally perform and document its review over the report. Upon audit inquiry, the review was subsequently performed by management and we observed no inappropriate changes were made during the year that would impact the IT application controls relied upon. 2) For 1 of 13 employee new or modified Workday access provisioning samples, BMC did not maintain adequate documentation of the access request and approval. Upon audit inquiry, it was determined that access was provided as part of a promotion and was appropriate; however, was not formally documented. Cause The conditions above related to the following: 1) Management did not formally perform and document their review over the report due to a lack of knowledge of performance and documentation requirements by the control operators. 2) The exception occurred due to delays in supervisors’ timely reporting of terminations in Infor which delayed the de provisioning process performed by IT. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access and change management may result in unauthorized changes being made to Workday, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the change management policies and procedures with key personnel to help ensure that the Workday change Review is performed to address change management risks for the system. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for requesting and provisioning access to help ensure that requests for both new and modified access are appropriately obtained and documented for approval of access needed for job responsibilities. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Workday, a cloud based system, to provide human resources and payroll applications. BMC’s management of Workday includes maintaining the application system layer of the information technology (IT)control environment and relies on the Workday vendor to support infrastructure layers through Service Organization Control (SOC) Type 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Workday IT application controls. During our testing, we noted the following deficiencies operating effectiveness of the Workday general IT controls: 1) BMC did not perform and document a Workday change review during the fiscal year, such a control would enable management to detect inappropriate changes to the Workday application. Such a report detailing changes to Workday was generated as part of the Uniform Guidance audit, however management did not formally perform and document its review over the report. Upon audit inquiry, the review was subsequently performed by management and we observed no inappropriate changes were made during the year that would impact the IT application controls relied upon. 2) For 1 of 13 employee new or modified Workday access provisioning samples, BMC did not maintain adequate documentation of the access request and approval. Upon audit inquiry, it was determined that access was provided as part of a promotion and was appropriate; however, was not formally documented. Cause The conditions above related to the following: 1) Management did not formally perform and document their review over the report due to a lack of knowledge of performance and documentation requirements by the control operators. 2) The exception occurred due to delays in supervisors’ timely reporting of terminations in Infor which delayed the de provisioning process performed by IT. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access and change management may result in unauthorized changes being made to Workday, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the change management policies and procedures with key personnel to help ensure that the Workday change Review is performed to address change management risks for the system. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for requesting and provisioning access to help ensure that requests for both new and modified access are appropriately obtained and documented for approval of access needed for job responsibilities. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Workday, a cloud based system, to provide human resources and payroll applications. BMC’s management of Workday includes maintaining the application system layer of the information technology (IT)control environment and relies on the Workday vendor to support infrastructure layers through Service Organization Control (SOC) Type 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Workday IT application controls. During our testing, we noted the following deficiencies operating effectiveness of the Workday general IT controls: 1) BMC did not perform and document a Workday change review during the fiscal year, such a control would enable management to detect inappropriate changes to the Workday application. Such a report detailing changes to Workday was generated as part of the Uniform Guidance audit, however management did not formally perform and document its review over the report. Upon audit inquiry, the review was subsequently performed by management and we observed no inappropriate changes were made during the year that would impact the IT application controls relied upon. 2) For 1 of 13 employee new or modified Workday access provisioning samples, BMC did not maintain adequate documentation of the access request and approval. Upon audit inquiry, it was determined that access was provided as part of a promotion and was appropriate; however, was not formally documented. Cause The conditions above related to the following: 1) Management did not formally perform and document their review over the report due to a lack of knowledge of performance and documentation requirements by the control operators. 2) The exception occurred due to delays in supervisors’ timely reporting of terminations in Infor which delayed the de provisioning process performed by IT. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access and change management may result in unauthorized changes being made to Workday, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the change management policies and procedures with key personnel to help ensure that the Workday change Review is performed to address change management risks for the system. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for requesting and provisioning access to help ensure that requests for both new and modified access are appropriately obtained and documented for approval of access needed for job responsibilities. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Workday, a cloud based system, to provide human resources and payroll applications. BMC’s management of Workday includes maintaining the application system layer of the information technology (IT)control environment and relies on the Workday vendor to support infrastructure layers through Service Organization Control (SOC) Type 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Workday IT application controls. During our testing, we noted the following deficiencies operating effectiveness of the Workday general IT controls: 1) BMC did not perform and document a Workday change review during the fiscal year, such a control would enable management to detect inappropriate changes to the Workday application. Such a report detailing changes to Workday was generated as part of the Uniform Guidance audit, however management did not formally perform and document its review over the report. Upon audit inquiry, the review was subsequently performed by management and we observed no inappropriate changes were made during the year that would impact the IT application controls relied upon. 2) For 1 of 13 employee new or modified Workday access provisioning samples, BMC did not maintain adequate documentation of the access request and approval. Upon audit inquiry, it was determined that access was provided as part of a promotion and was appropriate; however, was not formally documented. Cause The conditions above related to the following: 1) Management did not formally perform and document their review over the report due to a lack of knowledge of performance and documentation requirements by the control operators. 2) The exception occurred due to delays in supervisors’ timely reporting of terminations in Infor which delayed the de provisioning process performed by IT. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access and change management may result in unauthorized changes being made to Workday, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the change management policies and procedures with key personnel to help ensure that the Workday change Review is performed to address change management risks for the system. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for requesting and provisioning access to help ensure that requests for both new and modified access are appropriately obtained and documented for approval of access needed for job responsibilities. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Workday, a cloud based system, to provide human resources and payroll applications. BMC’s management of Workday includes maintaining the application system layer of the information technology (IT)control environment and relies on the Workday vendor to support infrastructure layers through Service Organization Control (SOC) Type 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Workday IT application controls. During our testing, we noted the following deficiencies operating effectiveness of the Workday general IT controls: 1) BMC did not perform and document a Workday change review during the fiscal year, such a control would enable management to detect inappropriate changes to the Workday application. Such a report detailing changes to Workday was generated as part of the Uniform Guidance audit, however management did not formally perform and document its review over the report. Upon audit inquiry, the review was subsequently performed by management and we observed no inappropriate changes were made during the year that would impact the IT application controls relied upon. 2) For 1 of 13 employee new or modified Workday access provisioning samples, BMC did not maintain adequate documentation of the access request and approval. Upon audit inquiry, it was determined that access was provided as part of a promotion and was appropriate; however, was not formally documented. Cause The conditions above related to the following: 1) Management did not formally perform and document their review over the report due to a lack of knowledge of performance and documentation requirements by the control operators. 2) The exception occurred due to delays in supervisors’ timely reporting of terminations in Infor which delayed the de provisioning process performed by IT. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access and change management may result in unauthorized changes being made to Workday, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the change management policies and procedures with key personnel to help ensure that the Workday change Review is performed to address change management risks for the system. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for requesting and provisioning access to help ensure that requests for both new and modified access are appropriately obtained and documented for approval of access needed for job responsibilities. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Workday, a cloud based system, to provide human resources and payroll applications. BMC’s management of Workday includes maintaining the application system layer of the information technology (IT)control environment and relies on the Workday vendor to support infrastructure layers through Service Organization Control (SOC) Type 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Workday IT application controls. During our testing, we noted the following deficiencies operating effectiveness of the Workday general IT controls: 1) BMC did not perform and document a Workday change review during the fiscal year, such a control would enable management to detect inappropriate changes to the Workday application. Such a report detailing changes to Workday was generated as part of the Uniform Guidance audit, however management did not formally perform and document its review over the report. Upon audit inquiry, the review was subsequently performed by management and we observed no inappropriate changes were made during the year that would impact the IT application controls relied upon. 2) For 1 of 13 employee new or modified Workday access provisioning samples, BMC did not maintain adequate documentation of the access request and approval. Upon audit inquiry, it was determined that access was provided as part of a promotion and was appropriate; however, was not formally documented. Cause The conditions above related to the following: 1) Management did not formally perform and document their review over the report due to a lack of knowledge of performance and documentation requirements by the control operators. 2) The exception occurred due to delays in supervisors’ timely reporting of terminations in Infor which delayed the de provisioning process performed by IT. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access and change management may result in unauthorized changes being made to Workday, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the change management policies and procedures with key personnel to help ensure that the Workday change Review is performed to address change management risks for the system. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for requesting and provisioning access to help ensure that requests for both new and modified access are appropriately obtained and documented for approval of access needed for job responsibilities. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Workday, a cloud based system, to provide human resources and payroll applications. BMC’s management of Workday includes maintaining the application system layer of the information technology (IT)control environment and relies on the Workday vendor to support infrastructure layers through Service Organization Control (SOC) Type 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Workday IT application controls. During our testing, we noted the following deficiencies operating effectiveness of the Workday general IT controls: 1) BMC did not perform and document a Workday change review during the fiscal year, such a control would enable management to detect inappropriate changes to the Workday application. Such a report detailing changes to Workday was generated as part of the Uniform Guidance audit, however management did not formally perform and document its review over the report. Upon audit inquiry, the review was subsequently performed by management and we observed no inappropriate changes were made during the year that would impact the IT application controls relied upon. 2) For 1 of 13 employee new or modified Workday access provisioning samples, BMC did not maintain adequate documentation of the access request and approval. Upon audit inquiry, it was determined that access was provided as part of a promotion and was appropriate; however, was not formally documented. Cause The conditions above related to the following: 1) Management did not formally perform and document their review over the report due to a lack of knowledge of performance and documentation requirements by the control operators. 2) The exception occurred due to delays in supervisors’ timely reporting of terminations in Infor which delayed the de provisioning process performed by IT. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access and change management may result in unauthorized changes being made to Workday, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the change management policies and procedures with key personnel to help ensure that the Workday change Review is performed to address change management risks for the system. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for requesting and provisioning access to help ensure that requests for both new and modified access are appropriately obtained and documented for approval of access needed for job responsibilities. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Workday, a cloud based system, to provide human resources and payroll applications. BMC’s management of Workday includes maintaining the application system layer of the information technology (IT)control environment and relies on the Workday vendor to support infrastructure layers through Service Organization Control (SOC) Type 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Workday IT application controls. During our testing, we noted the following deficiencies operating effectiveness of the Workday general IT controls: 1) BMC did not perform and document a Workday change review during the fiscal year, such a control would enable management to detect inappropriate changes to the Workday application. Such a report detailing changes to Workday was generated as part of the Uniform Guidance audit, however management did not formally perform and document its review over the report. Upon audit inquiry, the review was subsequently performed by management and we observed no inappropriate changes were made during the year that would impact the IT application controls relied upon. 2) For 1 of 13 employee new or modified Workday access provisioning samples, BMC did not maintain adequate documentation of the access request and approval. Upon audit inquiry, it was determined that access was provided as part of a promotion and was appropriate; however, was not formally documented. Cause The conditions above related to the following: 1) Management did not formally perform and document their review over the report due to a lack of knowledge of performance and documentation requirements by the control operators. 2) The exception occurred due to delays in supervisors’ timely reporting of terminations in Infor which delayed the de provisioning process performed by IT. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access and change management may result in unauthorized changes being made to Workday, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the change management policies and procedures with key personnel to help ensure that the Workday change Review is performed to address change management risks for the system. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for requesting and provisioning access to help ensure that requests for both new and modified access are appropriately obtained and documented for approval of access needed for job responsibilities. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Workday, a cloud based system, to provide human resources and payroll applications. BMC’s management of Workday includes maintaining the application system layer of the information technology (IT)control environment and relies on the Workday vendor to support infrastructure layers through Service Organization Control (SOC) Type 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Workday IT application controls. During our testing, we noted the following deficiencies operating effectiveness of the Workday general IT controls: 1) BMC did not perform and document a Workday change review during the fiscal year, such a control would enable management to detect inappropriate changes to the Workday application. Such a report detailing changes to Workday was generated as part of the Uniform Guidance audit, however management did not formally perform and document its review over the report. Upon audit inquiry, the review was subsequently performed by management and we observed no inappropriate changes were made during the year that would impact the IT application controls relied upon. 2) For 1 of 13 employee new or modified Workday access provisioning samples, BMC did not maintain adequate documentation of the access request and approval. Upon audit inquiry, it was determined that access was provided as part of a promotion and was appropriate; however, was not formally documented. Cause The conditions above related to the following: 1) Management did not formally perform and document their review over the report due to a lack of knowledge of performance and documentation requirements by the control operators. 2) The exception occurred due to delays in supervisors’ timely reporting of terminations in Infor which delayed the de provisioning process performed by IT. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access and change management may result in unauthorized changes being made to Workday, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the change management policies and procedures with key personnel to help ensure that the Workday change Review is performed to address change management risks for the system. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for requesting and provisioning access to help ensure that requests for both new and modified access are appropriately obtained and documented for approval of access needed for job responsibilities. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Workday, a cloud based system, to provide human resources and payroll applications. BMC’s management of Workday includes maintaining the application system layer of the information technology (IT)control environment and relies on the Workday vendor to support infrastructure layers through Service Organization Control (SOC) Type 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Workday IT application controls. During our testing, we noted the following deficiencies operating effectiveness of the Workday general IT controls: 1) BMC did not perform and document a Workday change review during the fiscal year, such a control would enable management to detect inappropriate changes to the Workday application. Such a report detailing changes to Workday was generated as part of the Uniform Guidance audit, however management did not formally perform and document its review over the report. Upon audit inquiry, the review was subsequently performed by management and we observed no inappropriate changes were made during the year that would impact the IT application controls relied upon. 2) For 1 of 13 employee new or modified Workday access provisioning samples, BMC did not maintain adequate documentation of the access request and approval. Upon audit inquiry, it was determined that access was provided as part of a promotion and was appropriate; however, was not formally documented. Cause The conditions above related to the following: 1) Management did not formally perform and document their review over the report due to a lack of knowledge of performance and documentation requirements by the control operators. 2) The exception occurred due to delays in supervisors’ timely reporting of terminations in Infor which delayed the de provisioning process performed by IT. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access and change management may result in unauthorized changes being made to Workday, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the change management policies and procedures with key personnel to help ensure that the Workday change Review is performed to address change management risks for the system. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for requesting and provisioning access to help ensure that requests for both new and modified access are appropriately obtained and documented for approval of access needed for job responsibilities. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Workday, a cloud based system, to provide human resources and payroll applications. BMC’s management of Workday includes maintaining the application system layer of the information technology (IT)control environment and relies on the Workday vendor to support infrastructure layers through Service Organization Control (SOC) Type 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Workday IT application controls. During our testing, we noted the following deficiencies operating effectiveness of the Workday general IT controls: 1) BMC did not perform and document a Workday change review during the fiscal year, such a control would enable management to detect inappropriate changes to the Workday application. Such a report detailing changes to Workday was generated as part of the Uniform Guidance audit, however management did not formally perform and document its review over the report. Upon audit inquiry, the review was subsequently performed by management and we observed no inappropriate changes were made during the year that would impact the IT application controls relied upon. 2) For 1 of 13 employee new or modified Workday access provisioning samples, BMC did not maintain adequate documentation of the access request and approval. Upon audit inquiry, it was determined that access was provided as part of a promotion and was appropriate; however, was not formally documented. Cause The conditions above related to the following: 1) Management did not formally perform and document their review over the report due to a lack of knowledge of performance and documentation requirements by the control operators. 2) The exception occurred due to delays in supervisors’ timely reporting of terminations in Infor which delayed the de provisioning process performed by IT. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access and change management may result in unauthorized changes being made to Workday, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the change management policies and procedures with key personnel to help ensure that the Workday change Review is performed to address change management risks for the system. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for requesting and provisioning access to help ensure that requests for both new and modified access are appropriately obtained and documented for approval of access needed for job responsibilities. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Workday, a cloud based system, to provide human resources and payroll applications. BMC’s management of Workday includes maintaining the application system layer of the information technology (IT)control environment and relies on the Workday vendor to support infrastructure layers through Service Organization Control (SOC) Type 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Workday IT application controls. During our testing, we noted the following deficiencies operating effectiveness of the Workday general IT controls: 1) BMC did not perform and document a Workday change review during the fiscal year, such a control would enable management to detect inappropriate changes to the Workday application. Such a report detailing changes to Workday was generated as part of the Uniform Guidance audit, however management did not formally perform and document its review over the report. Upon audit inquiry, the review was subsequently performed by management and we observed no inappropriate changes were made during the year that would impact the IT application controls relied upon. 2) For 1 of 13 employee new or modified Workday access provisioning samples, BMC did not maintain adequate documentation of the access request and approval. Upon audit inquiry, it was determined that access was provided as part of a promotion and was appropriate; however, was not formally documented. Cause The conditions above related to the following: 1) Management did not formally perform and document their review over the report due to a lack of knowledge of performance and documentation requirements by the control operators. 2) The exception occurred due to delays in supervisors’ timely reporting of terminations in Infor which delayed the de provisioning process performed by IT. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access and change management may result in unauthorized changes being made to Workday, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the change management policies and procedures with key personnel to help ensure that the Workday change Review is performed to address change management risks for the system. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for requesting and provisioning access to help ensure that requests for both new and modified access are appropriately obtained and documented for approval of access needed for job responsibilities. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Workday, a cloud based system, to provide human resources and payroll applications. BMC’s management of Workday includes maintaining the application system layer of the information technology (IT)control environment and relies on the Workday vendor to support infrastructure layers through Service Organization Control (SOC) Type 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Workday IT application controls. During our testing, we noted the following deficiencies operating effectiveness of the Workday general IT controls: 1) BMC did not perform and document a Workday change review during the fiscal year, such a control would enable management to detect inappropriate changes to the Workday application. Such a report detailing changes to Workday was generated as part of the Uniform Guidance audit, however management did not formally perform and document its review over the report. Upon audit inquiry, the review was subsequently performed by management and we observed no inappropriate changes were made during the year that would impact the IT application controls relied upon. 2) For 1 of 13 employee new or modified Workday access provisioning samples, BMC did not maintain adequate documentation of the access request and approval. Upon audit inquiry, it was determined that access was provided as part of a promotion and was appropriate; however, was not formally documented. Cause The conditions above related to the following: 1) Management did not formally perform and document their review over the report due to a lack of knowledge of performance and documentation requirements by the control operators. 2) The exception occurred due to delays in supervisors’ timely reporting of terminations in Infor which delayed the de provisioning process performed by IT. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access and change management may result in unauthorized changes being made to Workday, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the change management policies and procedures with key personnel to help ensure that the Workday change Review is performed to address change management risks for the system. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for requesting and provisioning access to help ensure that requests for both new and modified access are appropriately obtained and documented for approval of access needed for job responsibilities. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Workday, a cloud based system, to provide human resources and payroll applications. BMC’s management of Workday includes maintaining the application system layer of the information technology (IT)control environment and relies on the Workday vendor to support infrastructure layers through Service Organization Control (SOC) Type 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Workday IT application controls. During our testing, we noted the following deficiencies operating effectiveness of the Workday general IT controls: 1) BMC did not perform and document a Workday change review during the fiscal year, such a control would enable management to detect inappropriate changes to the Workday application. Such a report detailing changes to Workday was generated as part of the Uniform Guidance audit, however management did not formally perform and document its review over the report. Upon audit inquiry, the review was subsequently performed by management and we observed no inappropriate changes were made during the year that would impact the IT application controls relied upon. 2) For 1 of 13 employee new or modified Workday access provisioning samples, BMC did not maintain adequate documentation of the access request and approval. Upon audit inquiry, it was determined that access was provided as part of a promotion and was appropriate; however, was not formally documented. Cause The conditions above related to the following: 1) Management did not formally perform and document their review over the report due to a lack of knowledge of performance and documentation requirements by the control operators. 2) The exception occurred due to delays in supervisors’ timely reporting of terminations in Infor which delayed the de provisioning process performed by IT. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access and change management may result in unauthorized changes being made to Workday, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the change management policies and procedures with key personnel to help ensure that the Workday change Review is performed to address change management risks for the system. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for requesting and provisioning access to help ensure that requests for both new and modified access are appropriately obtained and documented for approval of access needed for job responsibilities. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Workday, a cloud based system, to provide human resources and payroll applications. BMC’s management of Workday includes maintaining the application system layer of the information technology (IT)control environment and relies on the Workday vendor to support infrastructure layers through Service Organization Control (SOC) Type 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Workday IT application controls. During our testing, we noted the following deficiencies operating effectiveness of the Workday general IT controls: 1) BMC did not perform and document a Workday change review during the fiscal year, such a control would enable management to detect inappropriate changes to the Workday application. Such a report detailing changes to Workday was generated as part of the Uniform Guidance audit, however management did not formally perform and document its review over the report. Upon audit inquiry, the review was subsequently performed by management and we observed no inappropriate changes were made during the year that would impact the IT application controls relied upon. 2) For 1 of 13 employee new or modified Workday access provisioning samples, BMC did not maintain adequate documentation of the access request and approval. Upon audit inquiry, it was determined that access was provided as part of a promotion and was appropriate; however, was not formally documented. Cause The conditions above related to the following: 1) Management did not formally perform and document their review over the report due to a lack of knowledge of performance and documentation requirements by the control operators. 2) The exception occurred due to delays in supervisors’ timely reporting of terminations in Infor which delayed the de provisioning process performed by IT. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access and change management may result in unauthorized changes being made to Workday, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the change management policies and procedures with key personnel to help ensure that the Workday change Review is performed to address change management risks for the system. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for requesting and provisioning access to help ensure that requests for both new and modified access are appropriately obtained and documented for approval of access needed for job responsibilities. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Workday, a cloud based system, to provide human resources and payroll applications. BMC’s management of Workday includes maintaining the application system layer of the information technology (IT)control environment and relies on the Workday vendor to support infrastructure layers through Service Organization Control (SOC) Type 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Workday IT application controls. During our testing, we noted the following deficiencies operating effectiveness of the Workday general IT controls: 1) BMC did not perform and document a Workday change review during the fiscal year, such a control would enable management to detect inappropriate changes to the Workday application. Such a report detailing changes to Workday was generated as part of the Uniform Guidance audit, however management did not formally perform and document its review over the report. Upon audit inquiry, the review was subsequently performed by management and we observed no inappropriate changes were made during the year that would impact the IT application controls relied upon. 2) For 1 of 13 employee new or modified Workday access provisioning samples, BMC did not maintain adequate documentation of the access request and approval. Upon audit inquiry, it was determined that access was provided as part of a promotion and was appropriate; however, was not formally documented. Cause The conditions above related to the following: 1) Management did not formally perform and document their review over the report due to a lack of knowledge of performance and documentation requirements by the control operators. 2) The exception occurred due to delays in supervisors’ timely reporting of terminations in Infor which delayed the de provisioning process performed by IT. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access and change management may result in unauthorized changes being made to Workday, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the change management policies and procedures with key personnel to help ensure that the Workday change Review is performed to address change management risks for the system. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for requesting and provisioning access to help ensure that requests for both new and modified access are appropriately obtained and documented for approval of access needed for job responsibilities. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Workday, a cloud based system, to provide human resources and payroll applications. BMC’s management of Workday includes maintaining the application system layer of the information technology (IT)control environment and relies on the Workday vendor to support infrastructure layers through Service Organization Control (SOC) Type 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Workday IT application controls. During our testing, we noted the following deficiencies operating effectiveness of the Workday general IT controls: 1) BMC did not perform and document a Workday change review during the fiscal year, such a control would enable management to detect inappropriate changes to the Workday application. Such a report detailing changes to Workday was generated as part of the Uniform Guidance audit, however management did not formally perform and document its review over the report. Upon audit inquiry, the review was subsequently performed by management and we observed no inappropriate changes were made during the year that would impact the IT application controls relied upon. 2) For 1 of 13 employee new or modified Workday access provisioning samples, BMC did not maintain adequate documentation of the access request and approval. Upon audit inquiry, it was determined that access was provided as part of a promotion and was appropriate; however, was not formally documented. Cause The conditions above related to the following: 1) Management did not formally perform and document their review over the report due to a lack of knowledge of performance and documentation requirements by the control operators. 2) The exception occurred due to delays in supervisors’ timely reporting of terminations in Infor which delayed the de provisioning process performed by IT. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access and change management may result in unauthorized changes being made to Workday, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the change management policies and procedures with key personnel to help ensure that the Workday change Review is performed to address change management risks for the system. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for requesting and provisioning access to help ensure that requests for both new and modified access are appropriately obtained and documented for approval of access needed for job responsibilities. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Workday, a cloud based system, to provide human resources and payroll applications. BMC’s management of Workday includes maintaining the application system layer of the information technology (IT)control environment and relies on the Workday vendor to support infrastructure layers through Service Organization Control (SOC) Type 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Workday IT application controls. During our testing, we noted the following deficiencies operating effectiveness of the Workday general IT controls: 1) BMC did not perform and document a Workday change review during the fiscal year, such a control would enable management to detect inappropriate changes to the Workday application. Such a report detailing changes to Workday was generated as part of the Uniform Guidance audit, however management did not formally perform and document its review over the report. Upon audit inquiry, the review was subsequently performed by management and we observed no inappropriate changes were made during the year that would impact the IT application controls relied upon. 2) For 1 of 13 employee new or modified Workday access provisioning samples, BMC did not maintain adequate documentation of the access request and approval. Upon audit inquiry, it was determined that access was provided as part of a promotion and was appropriate; however, was not formally documented. Cause The conditions above related to the following: 1) Management did not formally perform and document their review over the report due to a lack of knowledge of performance and documentation requirements by the control operators. 2) The exception occurred due to delays in supervisors’ timely reporting of terminations in Infor which delayed the de provisioning process performed by IT. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access and change management may result in unauthorized changes being made to Workday, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the change management policies and procedures with key personnel to help ensure that the Workday change Review is performed to address change management risks for the system. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for requesting and provisioning access to help ensure that requests for both new and modified access are appropriately obtained and documented for approval of access needed for job responsibilities. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Workday, a cloud based system, to provide human resources and payroll applications. BMC’s management of Workday includes maintaining the application system layer of the information technology (IT)control environment and relies on the Workday vendor to support infrastructure layers through Service Organization Control (SOC) Type 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Workday IT application controls. During our testing, we noted the following deficiencies operating effectiveness of the Workday general IT controls: 1) BMC did not perform and document a Workday change review during the fiscal year, such a control would enable management to detect inappropriate changes to the Workday application. Such a report detailing changes to Workday was generated as part of the Uniform Guidance audit, however management did not formally perform and document its review over the report. Upon audit inquiry, the review was subsequently performed by management and we observed no inappropriate changes were made during the year that would impact the IT application controls relied upon. 2) For 1 of 13 employee new or modified Workday access provisioning samples, BMC did not maintain adequate documentation of the access request and approval. Upon audit inquiry, it was determined that access was provided as part of a promotion and was appropriate; however, was not formally documented. Cause The conditions above related to the following: 1) Management did not formally perform and document their review over the report due to a lack of knowledge of performance and documentation requirements by the control operators. 2) The exception occurred due to delays in supervisors’ timely reporting of terminations in Infor which delayed the de provisioning process performed by IT. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access and change management may result in unauthorized changes being made to Workday, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the change management policies and procedures with key personnel to help ensure that the Workday change Review is performed to address change management risks for the system. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for requesting and provisioning access to help ensure that requests for both new and modified access are appropriately obtained and documented for approval of access needed for job responsibilities. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Workday, a cloud based system, to provide human resources and payroll applications. BMC’s management of Workday includes maintaining the application system layer of the information technology (IT)control environment and relies on the Workday vendor to support infrastructure layers through Service Organization Control (SOC) Type 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Workday IT application controls. During our testing, we noted the following deficiencies operating effectiveness of the Workday general IT controls: 1) BMC did not perform and document a Workday change review during the fiscal year, such a control would enable management to detect inappropriate changes to the Workday application. Such a report detailing changes to Workday was generated as part of the Uniform Guidance audit, however management did not formally perform and document its review over the report. Upon audit inquiry, the review was subsequently performed by management and we observed no inappropriate changes were made during the year that would impact the IT application controls relied upon. 2) For 1 of 13 employee new or modified Workday access provisioning samples, BMC did not maintain adequate documentation of the access request and approval. Upon audit inquiry, it was determined that access was provided as part of a promotion and was appropriate; however, was not formally documented. Cause The conditions above related to the following: 1) Management did not formally perform and document their review over the report due to a lack of knowledge of performance and documentation requirements by the control operators. 2) The exception occurred due to delays in supervisors’ timely reporting of terminations in Infor which delayed the de provisioning process performed by IT. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access and change management may result in unauthorized changes being made to Workday, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the change management policies and procedures with key personnel to help ensure that the Workday change Review is performed to address change management risks for the system. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for requesting and provisioning access to help ensure that requests for both new and modified access are appropriately obtained and documented for approval of access needed for job responsibilities. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Workday, a cloud based system, to provide human resources and payroll applications. BMC’s management of Workday includes maintaining the application system layer of the information technology (IT)control environment and relies on the Workday vendor to support infrastructure layers through Service Organization Control (SOC) Type 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Workday IT application controls. During our testing, we noted the following deficiencies operating effectiveness of the Workday general IT controls: 1) BMC did not perform and document a Workday change review during the fiscal year, such a control would enable management to detect inappropriate changes to the Workday application. Such a report detailing changes to Workday was generated as part of the Uniform Guidance audit, however management did not formally perform and document its review over the report. Upon audit inquiry, the review was subsequently performed by management and we observed no inappropriate changes were made during the year that would impact the IT application controls relied upon. 2) For 1 of 13 employee new or modified Workday access provisioning samples, BMC did not maintain adequate documentation of the access request and approval. Upon audit inquiry, it was determined that access was provided as part of a promotion and was appropriate; however, was not formally documented. Cause The conditions above related to the following: 1) Management did not formally perform and document their review over the report due to a lack of knowledge of performance and documentation requirements by the control operators. 2) The exception occurred due to delays in supervisors’ timely reporting of terminations in Infor which delayed the de provisioning process performed by IT. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access and change management may result in unauthorized changes being made to Workday, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the change management policies and procedures with key personnel to help ensure that the Workday change Review is performed to address change management risks for the system. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for requesting and provisioning access to help ensure that requests for both new and modified access are appropriately obtained and documented for approval of access needed for job responsibilities. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Workday, a cloud based system, to provide human resources and payroll applications. BMC’s management of Workday includes maintaining the application system layer of the information technology (IT)control environment and relies on the Workday vendor to support infrastructure layers through Service Organization Control (SOC) Type 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Workday IT application controls. During our testing, we noted the following deficiencies operating effectiveness of the Workday general IT controls: 1) BMC did not perform and document a Workday change review during the fiscal year, such a control would enable management to detect inappropriate changes to the Workday application. Such a report detailing changes to Workday was generated as part of the Uniform Guidance audit, however management did not formally perform and document its review over the report. Upon audit inquiry, the review was subsequently performed by management and we observed no inappropriate changes were made during the year that would impact the IT application controls relied upon. 2) For 1 of 13 employee new or modified Workday access provisioning samples, BMC did not maintain adequate documentation of the access request and approval. Upon audit inquiry, it was determined that access was provided as part of a promotion and was appropriate; however, was not formally documented. Cause The conditions above related to the following: 1) Management did not formally perform and document their review over the report due to a lack of knowledge of performance and documentation requirements by the control operators. 2) The exception occurred due to delays in supervisors’ timely reporting of terminations in Infor which delayed the de provisioning process performed by IT. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access and change management may result in unauthorized changes being made to Workday, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the change management policies and procedures with key personnel to help ensure that the Workday change Review is performed to address change management risks for the system. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for requesting and provisioning access to help ensure that requests for both new and modified access are appropriately obtained and documented for approval of access needed for job responsibilities. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Workday, a cloud based system, to provide human resources and payroll applications. BMC’s management of Workday includes maintaining the application system layer of the information technology (IT)control environment and relies on the Workday vendor to support infrastructure layers through Service Organization Control (SOC) Type 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Workday IT application controls. During our testing, we noted the following deficiencies operating effectiveness of the Workday general IT controls: 1) BMC did not perform and document a Workday change review during the fiscal year, such a control would enable management to detect inappropriate changes to the Workday application. Such a report detailing changes to Workday was generated as part of the Uniform Guidance audit, however management did not formally perform and document its review over the report. Upon audit inquiry, the review was subsequently performed by management and we observed no inappropriate changes were made during the year that would impact the IT application controls relied upon. 2) For 1 of 13 employee new or modified Workday access provisioning samples, BMC did not maintain adequate documentation of the access request and approval. Upon audit inquiry, it was determined that access was provided as part of a promotion and was appropriate; however, was not formally documented. Cause The conditions above related to the following: 1) Management did not formally perform and document their review over the report due to a lack of knowledge of performance and documentation requirements by the control operators. 2) The exception occurred due to delays in supervisors’ timely reporting of terminations in Infor which delayed the de provisioning process performed by IT. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access and change management may result in unauthorized changes being made to Workday, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the change management policies and procedures with key personnel to help ensure that the Workday change Review is performed to address change management risks for the system. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for requesting and provisioning access to help ensure that requests for both new and modified access are appropriately obtained and documented for approval of access needed for job responsibilities. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Workday, a cloud based system, to provide human resources and payroll applications. BMC’s management of Workday includes maintaining the application system layer of the information technology (IT)control environment and relies on the Workday vendor to support infrastructure layers through Service Organization Control (SOC) Type 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Workday IT application controls. During our testing, we noted the following deficiencies operating effectiveness of the Workday general IT controls: 1) BMC did not perform and document a Workday change review during the fiscal year, such a control would enable management to detect inappropriate changes to the Workday application. Such a report detailing changes to Workday was generated as part of the Uniform Guidance audit, however management did not formally perform and document its review over the report. Upon audit inquiry, the review was subsequently performed by management and we observed no inappropriate changes were made during the year that would impact the IT application controls relied upon. 2) For 1 of 13 employee new or modified Workday access provisioning samples, BMC did not maintain adequate documentation of the access request and approval. Upon audit inquiry, it was determined that access was provided as part of a promotion and was appropriate; however, was not formally documented. Cause The conditions above related to the following: 1) Management did not formally perform and document their review over the report due to a lack of knowledge of performance and documentation requirements by the control operators. 2) The exception occurred due to delays in supervisors’ timely reporting of terminations in Infor which delayed the de provisioning process performed by IT. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access and change management may result in unauthorized changes being made to Workday, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the change management policies and procedures with key personnel to help ensure that the Workday change Review is performed to address change management risks for the system. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for requesting and provisioning access to help ensure that requests for both new and modified access are appropriately obtained and documented for approval of access needed for job responsibilities. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Workday, a cloud based system, to provide human resources and payroll applications. BMC’s management of Workday includes maintaining the application system layer of the information technology (IT)control environment and relies on the Workday vendor to support infrastructure layers through Service Organization Control (SOC) Type 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Workday IT application controls. During our testing, we noted the following deficiencies operating effectiveness of the Workday general IT controls: 1) BMC did not perform and document a Workday change review during the fiscal year, such a control would enable management to detect inappropriate changes to the Workday application. Such a report detailing changes to Workday was generated as part of the Uniform Guidance audit, however management did not formally perform and document its review over the report. Upon audit inquiry, the review was subsequently performed by management and we observed no inappropriate changes were made during the year that would impact the IT application controls relied upon. 2) For 1 of 13 employee new or modified Workday access provisioning samples, BMC did not maintain adequate documentation of the access request and approval. Upon audit inquiry, it was determined that access was provided as part of a promotion and was appropriate; however, was not formally documented. Cause The conditions above related to the following: 1) Management did not formally perform and document their review over the report due to a lack of knowledge of performance and documentation requirements by the control operators. 2) The exception occurred due to delays in supervisors’ timely reporting of terminations in Infor which delayed the de provisioning process performed by IT. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access and change management may result in unauthorized changes being made to Workday, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the change management policies and procedures with key personnel to help ensure that the Workday change Review is performed to address change management risks for the system. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for requesting and provisioning access to help ensure that requests for both new and modified access are appropriately obtained and documented for approval of access needed for job responsibilities. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Workday, a cloud based system, to provide human resources and payroll applications. BMC’s management of Workday includes maintaining the application system layer of the information technology (IT)control environment and relies on the Workday vendor to support infrastructure layers through Service Organization Control (SOC) Type 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Workday IT application controls. During our testing, we noted the following deficiencies operating effectiveness of the Workday general IT controls: 1) BMC did not perform and document a Workday change review during the fiscal year, such a control would enable management to detect inappropriate changes to the Workday application. Such a report detailing changes to Workday was generated as part of the Uniform Guidance audit, however management did not formally perform and document its review over the report. Upon audit inquiry, the review was subsequently performed by management and we observed no inappropriate changes were made during the year that would impact the IT application controls relied upon. 2) For 1 of 13 employee new or modified Workday access provisioning samples, BMC did not maintain adequate documentation of the access request and approval. Upon audit inquiry, it was determined that access was provided as part of a promotion and was appropriate; however, was not formally documented. Cause The conditions above related to the following: 1) Management did not formally perform and document their review over the report due to a lack of knowledge of performance and documentation requirements by the control operators. 2) The exception occurred due to delays in supervisors’ timely reporting of terminations in Infor which delayed the de provisioning process performed by IT. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access and change management may result in unauthorized changes being made to Workday, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the change management policies and procedures with key personnel to help ensure that the Workday change Review is performed to address change management risks for the system. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for requesting and provisioning access to help ensure that requests for both new and modified access are appropriately obtained and documented for approval of access needed for job responsibilities. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Workday, a cloud based system, to provide human resources and payroll applications. BMC’s management of Workday includes maintaining the application system layer of the information technology (IT)control environment and relies on the Workday vendor to support infrastructure layers through Service Organization Control (SOC) Type 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Workday IT application controls. During our testing, we noted the following deficiencies operating effectiveness of the Workday general IT controls: 1) BMC did not perform and document a Workday change review during the fiscal year, such a control would enable management to detect inappropriate changes to the Workday application. Such a report detailing changes to Workday was generated as part of the Uniform Guidance audit, however management did not formally perform and document its review over the report. Upon audit inquiry, the review was subsequently performed by management and we observed no inappropriate changes were made during the year that would impact the IT application controls relied upon. 2) For 1 of 13 employee new or modified Workday access provisioning samples, BMC did not maintain adequate documentation of the access request and approval. Upon audit inquiry, it was determined that access was provided as part of a promotion and was appropriate; however, was not formally documented. Cause The conditions above related to the following: 1) Management did not formally perform and document their review over the report due to a lack of knowledge of performance and documentation requirements by the control operators. 2) The exception occurred due to delays in supervisors’ timely reporting of terminations in Infor which delayed the de provisioning process performed by IT. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access and change management may result in unauthorized changes being made to Workday, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the change management policies and procedures with key personnel to help ensure that the Workday change Review is performed to address change management risks for the system. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for requesting and provisioning access to help ensure that requests for both new and modified access are appropriately obtained and documented for approval of access needed for job responsibilities. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Workday, a cloud based system, to provide human resources and payroll applications. BMC’s management of Workday includes maintaining the application system layer of the information technology (IT)control environment and relies on the Workday vendor to support infrastructure layers through Service Organization Control (SOC) Type 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Workday IT application controls. During our testing, we noted the following deficiencies operating effectiveness of the Workday general IT controls: 1) BMC did not perform and document a Workday change review during the fiscal year, such a control would enable management to detect inappropriate changes to the Workday application. Such a report detailing changes to Workday was generated as part of the Uniform Guidance audit, however management did not formally perform and document its review over the report. Upon audit inquiry, the review was subsequently performed by management and we observed no inappropriate changes were made during the year that would impact the IT application controls relied upon. 2) For 1 of 13 employee new or modified Workday access provisioning samples, BMC did not maintain adequate documentation of the access request and approval. Upon audit inquiry, it was determined that access was provided as part of a promotion and was appropriate; however, was not formally documented. Cause The conditions above related to the following: 1) Management did not formally perform and document their review over the report due to a lack of knowledge of performance and documentation requirements by the control operators. 2) The exception occurred due to delays in supervisors’ timely reporting of terminations in Infor which delayed the de provisioning process performed by IT. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access and change management may result in unauthorized changes being made to Workday, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the change management policies and procedures with key personnel to help ensure that the Workday change Review is performed to address change management risks for the system. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for requesting and provisioning access to help ensure that requests for both new and modified access are appropriately obtained and documented for approval of access needed for job responsibilities. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Workday, a cloud based system, to provide human resources and payroll applications. BMC’s management of Workday includes maintaining the application system layer of the information technology (IT)control environment and relies on the Workday vendor to support infrastructure layers through Service Organization Control (SOC) Type 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Workday IT application controls. During our testing, we noted the following deficiencies operating effectiveness of the Workday general IT controls: 1) BMC did not perform and document a Workday change review during the fiscal year, such a control would enable management to detect inappropriate changes to the Workday application. Such a report detailing changes to Workday was generated as part of the Uniform Guidance audit, however management did not formally perform and document its review over the report. Upon audit inquiry, the review was subsequently performed by management and we observed no inappropriate changes were made during the year that would impact the IT application controls relied upon. 2) For 1 of 13 employee new or modified Workday access provisioning samples, BMC did not maintain adequate documentation of the access request and approval. Upon audit inquiry, it was determined that access was provided as part of a promotion and was appropriate; however, was not formally documented. Cause The conditions above related to the following: 1) Management did not formally perform and document their review over the report due to a lack of knowledge of performance and documentation requirements by the control operators. 2) The exception occurred due to delays in supervisors’ timely reporting of terminations in Infor which delayed the de provisioning process performed by IT. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access and change management may result in unauthorized changes being made to Workday, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the change management policies and procedures with key personnel to help ensure that the Workday change Review is performed to address change management risks for the system. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for requesting and provisioning access to help ensure that requests for both new and modified access are appropriately obtained and documented for approval of access needed for job responsibilities. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Workday, a cloud based system, to provide human resources and payroll applications. BMC’s management of Workday includes maintaining the application system layer of the information technology (IT)control environment and relies on the Workday vendor to support infrastructure layers through Service Organization Control (SOC) Type 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Workday IT application controls. During our testing, we noted the following deficiencies operating effectiveness of the Workday general IT controls: 1) BMC did not perform and document a Workday change review during the fiscal year, such a control would enable management to detect inappropriate changes to the Workday application. Such a report detailing changes to Workday was generated as part of the Uniform Guidance audit, however management did not formally perform and document its review over the report. Upon audit inquiry, the review was subsequently performed by management and we observed no inappropriate changes were made during the year that would impact the IT application controls relied upon. 2) For 1 of 13 employee new or modified Workday access provisioning samples, BMC did not maintain adequate documentation of the access request and approval. Upon audit inquiry, it was determined that access was provided as part of a promotion and was appropriate; however, was not formally documented. Cause The conditions above related to the following: 1) Management did not formally perform and document their review over the report due to a lack of knowledge of performance and documentation requirements by the control operators. 2) The exception occurred due to delays in supervisors’ timely reporting of terminations in Infor which delayed the de provisioning process performed by IT. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access and change management may result in unauthorized changes being made to Workday, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the change management policies and procedures with key personnel to help ensure that the Workday change Review is performed to address change management risks for the system. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for requesting and provisioning access to help ensure that requests for both new and modified access are appropriately obtained and documented for approval of access needed for job responsibilities. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Workday, a cloud based system, to provide human resources and payroll applications. BMC’s management of Workday includes maintaining the application system layer of the information technology (IT)control environment and relies on the Workday vendor to support infrastructure layers through Service Organization Control (SOC) Type 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Workday IT application controls. During our testing, we noted the following deficiencies operating effectiveness of the Workday general IT controls: 1) BMC did not perform and document a Workday change review during the fiscal year, such a control would enable management to detect inappropriate changes to the Workday application. Such a report detailing changes to Workday was generated as part of the Uniform Guidance audit, however management did not formally perform and document its review over the report. Upon audit inquiry, the review was subsequently performed by management and we observed no inappropriate changes were made during the year that would impact the IT application controls relied upon. 2) For 1 of 13 employee new or modified Workday access provisioning samples, BMC did not maintain adequate documentation of the access request and approval. Upon audit inquiry, it was determined that access was provided as part of a promotion and was appropriate; however, was not formally documented. Cause The conditions above related to the following: 1) Management did not formally perform and document their review over the report due to a lack of knowledge of performance and documentation requirements by the control operators. 2) The exception occurred due to delays in supervisors’ timely reporting of terminations in Infor which delayed the de provisioning process performed by IT. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access and change management may result in unauthorized changes being made to Workday, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the change management policies and procedures with key personnel to help ensure that the Workday change Review is performed to address change management risks for the system. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for requesting and provisioning access to help ensure that requests for both new and modified access are appropriately obtained and documented for approval of access needed for job responsibilities. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Workday, a cloud based system, to provide human resources and payroll applications. BMC’s management of Workday includes maintaining the application system layer of the information technology (IT)control environment and relies on the Workday vendor to support infrastructure layers through Service Organization Control (SOC) Type 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Workday IT application controls. During our testing, we noted the following deficiencies operating effectiveness of the Workday general IT controls: 1) BMC did not perform and document a Workday change review during the fiscal year, such a control would enable management to detect inappropriate changes to the Workday application. Such a report detailing changes to Workday was generated as part of the Uniform Guidance audit, however management did not formally perform and document its review over the report. Upon audit inquiry, the review was subsequently performed by management and we observed no inappropriate changes were made during the year that would impact the IT application controls relied upon. 2) For 1 of 13 employee new or modified Workday access provisioning samples, BMC did not maintain adequate documentation of the access request and approval. Upon audit inquiry, it was determined that access was provided as part of a promotion and was appropriate; however, was not formally documented. Cause The conditions above related to the following: 1) Management did not formally perform and document their review over the report due to a lack of knowledge of performance and documentation requirements by the control operators. 2) The exception occurred due to delays in supervisors’ timely reporting of terminations in Infor which delayed the de provisioning process performed by IT. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access and change management may result in unauthorized changes being made to Workday, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the change management policies and procedures with key personnel to help ensure that the Workday change Review is performed to address change management risks for the system. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for requesting and provisioning access to help ensure that requests for both new and modified access are appropriately obtained and documented for approval of access needed for job responsibilities. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.
Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Workday, a cloud based system, to provide human resources and payroll applications. BMC’s management of Workday includes maintaining the application system layer of the information technology (IT)control environment and relies on the Workday vendor to support infrastructure layers through Service Organization Control (SOC) Type 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Workday IT application controls. During our testing, we noted the following deficiencies operating effectiveness of the Workday general IT controls: 1) BMC did not perform and document a Workday change review during the fiscal year, such a control would enable management to detect inappropriate changes to the Workday application. Such a report detailing changes to Workday was generated as part of the Uniform Guidance audit, however management did not formally perform and document its review over the report. Upon audit inquiry, the review was subsequently performed by management and we observed no inappropriate changes were made during the year that would impact the IT application controls relied upon. 2) For 1 of 13 employee new or modified Workday access provisioning samples, BMC did not maintain adequate documentation of the access request and approval. Upon audit inquiry, it was determined that access was provided as part of a promotion and was appropriate; however, was not formally documented. Cause The conditions above related to the following: 1) Management did not formally perform and document their review over the report due to a lack of knowledge of performance and documentation requirements by the control operators. 2) The exception occurred due to delays in supervisors’ timely reporting of terminations in Infor which delayed the de provisioning process performed by IT. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access and change management may result in unauthorized changes being made to Workday, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the change management policies and procedures with key personnel to help ensure that the Workday change Review is performed to address change management risks for the system. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for requesting and provisioning access to help ensure that requests for both new and modified access are appropriately obtained and documented for approval of access needed for job responsibilities. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.