2 CFR 200 › § 200.303

Findings Citing § 200.303

Internal controls.

Total Findings
100,090
Across all audits in database
Showing Page
842 of 2002
50 findings per page
About this section
Section 200.303 requires recipients and subrecipients of Federal awards to establish and maintain effective internal controls to ensure compliance with Federal laws and award conditions. This section affects organizations receiving Federal funding, mandating them to monitor compliance, address noncompliance promptly, and protect sensitive information.
View full section details →
FY End: 2023-06-30
Solano Community College District
Compliance Requirement: N
2023-005: Gramm-Leach-Bliley Act Compliance Federal Agency: Department of Education Federal Program Name: Student Financial Assistance Cluster Assistance Listing Number: Various Federal Award Identification Number and Year: Various Award Period: July 1, 2022 through June 30, 2023 Type of Finding: Material Weakness in Internal Control over Compliance and Other Matters Criteria: In accordance with 16 CFR 314.3(a) and 2 CFR 200.303, Institutions are required to develop, implement and maintain a com...

2023-005: Gramm-Leach-Bliley Act Compliance Federal Agency: Department of Education Federal Program Name: Student Financial Assistance Cluster Assistance Listing Number: Various Federal Award Identification Number and Year: Various Award Period: July 1, 2022 through June 30, 2023 Type of Finding: Material Weakness in Internal Control over Compliance and Other Matters Criteria: In accordance with 16 CFR 314.3(a) and 2 CFR 200.303, Institutions are required to develop, implement and maintain a comprehensive information security program that is written in one or more readily accessible parts. The regulations require the written information security program to include seven elements for institutions with fewer than 5,000 customers. Condition: During our testing, we noted the District's information security policy is in draft form and does not include all of the required seven elements. Questioned Costs: None. Context: The District's information security policy does not contain all seven elements required by the Gramm-Leach-Bliley Act. Cause: The District's information security policy is still in draft form. Effect: The District's information security policy is not in compliance with the Gramm-Leach- Bliley Act. Repeat Finding: This was not a finding in the prior year. Recommendation: We recommend the District review and finalize its information security policy and ensure it contains all seven elements required for compliance with Gramm-Leach-Bliley. Views of responsible officials: Management concurs with the finding and plans to correct the finding.

FY End: 2023-06-30
Solano Community College District
Compliance Requirement: A
2023-006: Unallowable Costs Federal Agency: Department of Education Federal Program: COVID-19 Higher Education Emergency Relief Funds (HEERF)/Coronavirus Aid, Relief and Economic Security (CARES) Act – Institutional Portion Assistance Listing Number: 84.425F Federal Award Identification Number and Year: P425E205093 Award Period: July 1, 2022 to June 30, 2023 Type of Finding: Significant Deficiency in Internal Control over Compliance and Other Matters Criteria: The Uniform Guidance Cost Principle...

2023-006: Unallowable Costs Federal Agency: Department of Education Federal Program: COVID-19 Higher Education Emergency Relief Funds (HEERF)/Coronavirus Aid, Relief and Economic Security (CARES) Act – Institutional Portion Assistance Listing Number: 84.425F Federal Award Identification Number and Year: P425E205093 Award Period: July 1, 2022 to June 30, 2023 Type of Finding: Significant Deficiency in Internal Control over Compliance and Other Matters Criteria: The Uniform Guidance Cost Principles described in 2 CFR Part 200, Compensation, states that costs of compensation are allowable to the extent that they satisfy the specific requirements of the grant and that total compensation for individual employees is reasonable for the services rendered. Salaries and benefits are allowable for this grant as long as the job duties are a result of responding to the pandemic. In addition, 2 CFR 200.303, nonfederal entities receiving federal awards are required to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations and program compliance requirements. Condition: The District charged unallowable costs to the grant related to an employee whose job duties were not related to the pandemic. Questioned Costs: $3,341 Context: The District expended $1,951,384 in HEERF – Institutional Portion funds for direct costs during the fiscal year. The value of the sample tested was $22,736. Cause: The District charged payroll costs for an employee in error. Effect: Noncompliance with allowable cost principles. Repeat Finding: This was not a finding in the prior year. Recommendation: Implement procedures to ensure all grant expenditures are reviewed by fiscal management for additional review. Views of responsible officials: Management concurs with the finding and plans to correct the finding.

FY End: 2023-06-30
Brewton-Parker College
Compliance Requirement: N
Finding 2023‐001: Special Tests and Provisions: Enrollment Reporting Program Name: Student Financial Assistance Cluster: Federal Direct Student Loans. Assistance Listing No. 84.268 Federal Pell Grant Program, Assistance Listing No. 84.063 Awarding Agency: U.S. Department of Education Finding Type: Significant Deficiency on Internal Controls over Compliance Questioned Costs: None Criteria: Per Title 2 US Code of Federal Regulations Part 200.303a, non‐federal entity must establish and maintai...

Finding 2023‐001: Special Tests and Provisions: Enrollment Reporting Program Name: Student Financial Assistance Cluster: Federal Direct Student Loans. Assistance Listing No. 84.268 Federal Pell Grant Program, Assistance Listing No. 84.063 Awarding Agency: U.S. Department of Education Finding Type: Significant Deficiency on Internal Controls over Compliance Questioned Costs: None Criteria: Per Title 2 US Code of Federal Regulations Part 200.303a, non‐federal entity must establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non‐Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). In addition, the Department of Education relies on institution’s enrollments reports to determine a student’s enrollment status based on reductions or increases in attendance levels, withdrawals, graduations or approved leaves of‐absence. According to 34 CFR 690.83(b)(2) and 685.309, the University is required to submit changes in student attendance to the National Student Loan Data System (NSLDS) at a minimum of every 60 days. Context/Condition: Of the 40 students selected for enrollment reporting testing, three students within the sample were reported to NSLDS outside the maximum 60‐day window. This was not a statistically valid sample. Cause: The University did not have effective controls in place to ensure timely reporting of all status changes. Effect: Without timely notification of withdrawals or graduation, the NSLDS is unable to accurately determine when a student enters repayment status. Recommendation: We recommend that the University review and update internal controls to ensure student enrollment status in the NSLDS is updated in a timely manner to ensure compliance with Federal requirements. Views of Responsible Officials: Management agrees with the finding. See accompanying Corrective Action Plan.

FY End: 2023-06-30
Brewton-Parker College
Compliance Requirement: N
Finding 2023‐001: Special Tests and Provisions: Enrollment Reporting Program Name: Student Financial Assistance Cluster: Federal Direct Student Loans. Assistance Listing No. 84.268 Federal Pell Grant Program, Assistance Listing No. 84.063 Awarding Agency: U.S. Department of Education Finding Type: Significant Deficiency on Internal Controls over Compliance Questioned Costs: None Criteria: Per Title 2 US Code of Federal Regulations Part 200.303a, non‐federal entity must establish and maintai...

Finding 2023‐001: Special Tests and Provisions: Enrollment Reporting Program Name: Student Financial Assistance Cluster: Federal Direct Student Loans. Assistance Listing No. 84.268 Federal Pell Grant Program, Assistance Listing No. 84.063 Awarding Agency: U.S. Department of Education Finding Type: Significant Deficiency on Internal Controls over Compliance Questioned Costs: None Criteria: Per Title 2 US Code of Federal Regulations Part 200.303a, non‐federal entity must establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non‐Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). In addition, the Department of Education relies on institution’s enrollments reports to determine a student’s enrollment status based on reductions or increases in attendance levels, withdrawals, graduations or approved leaves of‐absence. According to 34 CFR 690.83(b)(2) and 685.309, the University is required to submit changes in student attendance to the National Student Loan Data System (NSLDS) at a minimum of every 60 days. Context/Condition: Of the 40 students selected for enrollment reporting testing, three students within the sample were reported to NSLDS outside the maximum 60‐day window. This was not a statistically valid sample. Cause: The University did not have effective controls in place to ensure timely reporting of all status changes. Effect: Without timely notification of withdrawals or graduation, the NSLDS is unable to accurately determine when a student enters repayment status. Recommendation: We recommend that the University review and update internal controls to ensure student enrollment status in the NSLDS is updated in a timely manner to ensure compliance with Federal requirements. Views of Responsible Officials: Management agrees with the finding. See accompanying Corrective Action Plan.

FY End: 2023-06-30
Brewton-Parker College
Compliance Requirement: N
Finding 2023‐001: Special Tests and Provisions: Enrollment Reporting Program Name: Student Financial Assistance Cluster: Federal Direct Student Loans. Assistance Listing No. 84.268 Federal Pell Grant Program, Assistance Listing No. 84.063 Awarding Agency: U.S. Department of Education Finding Type: Significant Deficiency on Internal Controls over Compliance Questioned Costs: None Criteria: Per Title 2 US Code of Federal Regulations Part 200.303a, non‐federal entity must establish and maintai...

Finding 2023‐001: Special Tests and Provisions: Enrollment Reporting Program Name: Student Financial Assistance Cluster: Federal Direct Student Loans. Assistance Listing No. 84.268 Federal Pell Grant Program, Assistance Listing No. 84.063 Awarding Agency: U.S. Department of Education Finding Type: Significant Deficiency on Internal Controls over Compliance Questioned Costs: None Criteria: Per Title 2 US Code of Federal Regulations Part 200.303a, non‐federal entity must establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non‐Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). In addition, the Department of Education relies on institution’s enrollments reports to determine a student’s enrollment status based on reductions or increases in attendance levels, withdrawals, graduations or approved leaves of‐absence. According to 34 CFR 690.83(b)(2) and 685.309, the University is required to submit changes in student attendance to the National Student Loan Data System (NSLDS) at a minimum of every 60 days. Context/Condition: Of the 40 students selected for enrollment reporting testing, three students within the sample were reported to NSLDS outside the maximum 60‐day window. This was not a statistically valid sample. Cause: The University did not have effective controls in place to ensure timely reporting of all status changes. Effect: Without timely notification of withdrawals or graduation, the NSLDS is unable to accurately determine when a student enters repayment status. Recommendation: We recommend that the University review and update internal controls to ensure student enrollment status in the NSLDS is updated in a timely manner to ensure compliance with Federal requirements. Views of Responsible Officials: Management agrees with the finding. See accompanying Corrective Action Plan.

FY End: 2023-06-30
Brewton-Parker College
Compliance Requirement: N
Finding 2023‐001: Special Tests and Provisions: Enrollment Reporting Program Name: Student Financial Assistance Cluster: Federal Direct Student Loans. Assistance Listing No. 84.268 Federal Pell Grant Program, Assistance Listing No. 84.063 Awarding Agency: U.S. Department of Education Finding Type: Significant Deficiency on Internal Controls over Compliance Questioned Costs: None Criteria: Per Title 2 US Code of Federal Regulations Part 200.303a, non‐federal entity must establish and maintai...

Finding 2023‐001: Special Tests and Provisions: Enrollment Reporting Program Name: Student Financial Assistance Cluster: Federal Direct Student Loans. Assistance Listing No. 84.268 Federal Pell Grant Program, Assistance Listing No. 84.063 Awarding Agency: U.S. Department of Education Finding Type: Significant Deficiency on Internal Controls over Compliance Questioned Costs: None Criteria: Per Title 2 US Code of Federal Regulations Part 200.303a, non‐federal entity must establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non‐Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). In addition, the Department of Education relies on institution’s enrollments reports to determine a student’s enrollment status based on reductions or increases in attendance levels, withdrawals, graduations or approved leaves of‐absence. According to 34 CFR 690.83(b)(2) and 685.309, the University is required to submit changes in student attendance to the National Student Loan Data System (NSLDS) at a minimum of every 60 days. Context/Condition: Of the 40 students selected for enrollment reporting testing, three students within the sample were reported to NSLDS outside the maximum 60‐day window. This was not a statistically valid sample. Cause: The University did not have effective controls in place to ensure timely reporting of all status changes. Effect: Without timely notification of withdrawals or graduation, the NSLDS is unable to accurately determine when a student enters repayment status. Recommendation: We recommend that the University review and update internal controls to ensure student enrollment status in the NSLDS is updated in a timely manner to ensure compliance with Federal requirements. Views of Responsible Officials: Management agrees with the finding. See accompanying Corrective Action Plan.

FY End: 2023-06-30
Brewton-Parker College
Compliance Requirement: N
Finding 2023‐001: Special Tests and Provisions: Enrollment Reporting Program Name: Student Financial Assistance Cluster: Federal Direct Student Loans. Assistance Listing No. 84.268 Federal Pell Grant Program, Assistance Listing No. 84.063 Awarding Agency: U.S. Department of Education Finding Type: Significant Deficiency on Internal Controls over Compliance Questioned Costs: None Criteria: Per Title 2 US Code of Federal Regulations Part 200.303a, non‐federal entity must establish and maintai...

Finding 2023‐001: Special Tests and Provisions: Enrollment Reporting Program Name: Student Financial Assistance Cluster: Federal Direct Student Loans. Assistance Listing No. 84.268 Federal Pell Grant Program, Assistance Listing No. 84.063 Awarding Agency: U.S. Department of Education Finding Type: Significant Deficiency on Internal Controls over Compliance Questioned Costs: None Criteria: Per Title 2 US Code of Federal Regulations Part 200.303a, non‐federal entity must establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non‐Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). In addition, the Department of Education relies on institution’s enrollments reports to determine a student’s enrollment status based on reductions or increases in attendance levels, withdrawals, graduations or approved leaves of‐absence. According to 34 CFR 690.83(b)(2) and 685.309, the University is required to submit changes in student attendance to the National Student Loan Data System (NSLDS) at a minimum of every 60 days. Context/Condition: Of the 40 students selected for enrollment reporting testing, three students within the sample were reported to NSLDS outside the maximum 60‐day window. This was not a statistically valid sample. Cause: The University did not have effective controls in place to ensure timely reporting of all status changes. Effect: Without timely notification of withdrawals or graduation, the NSLDS is unable to accurately determine when a student enters repayment status. Recommendation: We recommend that the University review and update internal controls to ensure student enrollment status in the NSLDS is updated in a timely manner to ensure compliance with Federal requirements. Views of Responsible Officials: Management agrees with the finding. See accompanying Corrective Action Plan.

FY End: 2023-06-30
University of New Mexico
Compliance Requirement: N
Finding Reference Number: 2023-001 Federal Agency: U.S. Department of Education (USDE) Program Name: Student Financial Assistance Cluster ALN: 84.268 Award Numbers: NA Federal Award Year: 2022-23 Questioned Costs: None Compliance Requirement: Special Tests and Provisions – Disbursements to or on Behalf of Students Type of Finding: Significant Deficiency and Material Non-Compliance Condition: The University of New Mexico (UNM) has opted-in to the federal direct loan (FDL) disbursement notificatio...

Finding Reference Number: 2023-001 Federal Agency: U.S. Department of Education (USDE) Program Name: Student Financial Assistance Cluster ALN: 84.268 Award Numbers: NA Federal Award Year: 2022-23 Questioned Costs: None Compliance Requirement: Special Tests and Provisions – Disbursements to or on Behalf of Students Type of Finding: Significant Deficiency and Material Non-Compliance Condition: The University of New Mexico (UNM) has opted-in to the federal direct loan (FDL) disbursement notifications Common Originations and Disbursement online (COD) service and the majority of the spring notifications were not sent within the required timeframe. UNM was unaware the spring notifications were not sent timely. For 40 FDL disbursements during the 2022-23 federal award year, 12 spring disbursements included in our sample were sent outside the 30-day required timeframe. All 12 of these spring notifications were sent with the correct content. Criteria: Per 34 CFR 668.165, when FDL are being credited to a student’s account, the institution must notify the student, or parent, in writing of (1) the date and amount of the disbursement; (2) the student’s right, or parent’s right, to cancel all or a portion of that loan or loan disbursement and have the loan proceeds returned to the holder of that loan; and (3) the procedure and time by which the student or parent must notify the institution that he or she wishes to cancel the loan. Institutions that implement an affirmative confirmation process (as described in 34 CFR 668.165 (a)(6)(i)) must make this notification to the student or parent no earlier than 30 days before, and no later than 30 days after, crediting the student’s account at the institution with FDL. 2 CFR 200.303 requires non-Federal entities receiving Federal awards to establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. Effective internal controls should include procedures to ensure that FDL notification are sent timely. Effect: UNM is not complying with the 30 day before/after the actual disbursement requirement for the FDL notification. Cause: UNM did not monitor the FDL notifications at a sufficient level to determine the spring notifications were not sent timely. During the audit, UNM noted that when the university sends a COD record for one student with both fall and spring FDL amounts and fall and spring dates of disbursement, COD sends the letter within 30 days of the fall disbursement date. The notification letter includes the required content including the date and amount for both the fall and spring disbursement. The notification is not resent within 30 days of the spring disbursement date. Spring disbursements notification that are updated or are singular (there is no associated fall award) are being sent within the 30 days of the spring disbursement date. Questioned Costs: None Repeat Finding: A similar finding was not reported in the prior year audit. Statistical Sampling: The sample was not intended to be, and was not, a statistically valid sample. Auditors’ Recommendation: UNM should continue discussions with COD on how to correct or implement an internal solution. Management Response: UNM agrees with this recommendation. UNM will implement an internal loan disbursement notification process. UNM’s Financial Aid Director, is responsible for the corrective action plan, with an anticipated completion date of January 15, 2024.

FY End: 2023-06-30
Kent County, De Government (kent County Levy Court)
Compliance Requirement: I
Reference Number: 2023-001 Prior Year Finding: Yes Federal Agency: U.S. Department of the Treasury & U.S. Environmental Protection Agency Federal Program: Coronavirus State and Local Fiscal Recovery Funds (American Rescue Plan Act) & Clean Water State Revolving Funds Assistance Listing Number: 21.027 & 66.458 Compliance Requirement: Suspension and Debarment Type of Finding: Significant Deficiency in Internal Control Over Compliance Criteria or specific requirement: Compliance: 2 CFR 200.213 Sus...

Reference Number: 2023-001 Prior Year Finding: Yes Federal Agency: U.S. Department of the Treasury & U.S. Environmental Protection Agency Federal Program: Coronavirus State and Local Fiscal Recovery Funds (American Rescue Plan Act) & Clean Water State Revolving Funds Assistance Listing Number: 21.027 & 66.458 Compliance Requirement: Suspension and Debarment Type of Finding: Significant Deficiency in Internal Control Over Compliance Criteria or specific requirement: Compliance: 2 CFR 200.213 Suspension and Debarment restricts awards, subawards, and contracts with certain parties that are debarred, suspended, or otherwise excluded from or ineligible for participation in Federal assistance programs or activities. 2 CFR 180.300 states that an entity may determine suspension and debarment status by: (a) Checking SAM (System for Award Management) Exclusions; or (b) Collecting a certification from that person; or (c) Adding a clause or condition to the covered transaction with that person (7) Distribution of work to individuals and firms or economic considerations. Control: Per 2 CFR Section 200.303(a), a non-Federal entity must: Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should comply with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition: The County could not provide supporting documentation that suspension and debarment status was determined prior to award. Context: The suspension and debarment status for three out of eight vendors was not documented related to the Coronavirus State and Local Fiscal Recovery Funds program. The suspension and debarment status for four out of five vendors was not documented related to the Clean Water State Revolving Funds program. Questioned costs: There are no questioned costs related to this finding as the vendors were not federally suspended or debarred. Cause: The County did not establish effective internal controls over suspension and debarment transactions. Effect: The County is not in compliance with federal suspension and debarment regulations. Recommendation: The County should ensure they maintain audit documentation to support their review of suspension and debarment status. Views of responsible officials: The County does check Sam.gov for suspension and debarment transactions. Documentation was retained, but was lost due to a network intrusion. We will remain diligent in documenting our reviews.

FY End: 2023-06-30
Kent County, De Government (kent County Levy Court)
Compliance Requirement: I
Reference Number: 2023-001 Prior Year Finding: Yes Federal Agency: U.S. Department of the Treasury & U.S. Environmental Protection Agency Federal Program: Coronavirus State and Local Fiscal Recovery Funds (American Rescue Plan Act) & Clean Water State Revolving Funds Assistance Listing Number: 21.027 & 66.458 Compliance Requirement: Suspension and Debarment Type of Finding: Significant Deficiency in Internal Control Over Compliance Criteria or specific requirement: Compliance: 2 CFR 200.213 Sus...

Reference Number: 2023-001 Prior Year Finding: Yes Federal Agency: U.S. Department of the Treasury & U.S. Environmental Protection Agency Federal Program: Coronavirus State and Local Fiscal Recovery Funds (American Rescue Plan Act) & Clean Water State Revolving Funds Assistance Listing Number: 21.027 & 66.458 Compliance Requirement: Suspension and Debarment Type of Finding: Significant Deficiency in Internal Control Over Compliance Criteria or specific requirement: Compliance: 2 CFR 200.213 Suspension and Debarment restricts awards, subawards, and contracts with certain parties that are debarred, suspended, or otherwise excluded from or ineligible for participation in Federal assistance programs or activities. 2 CFR 180.300 states that an entity may determine suspension and debarment status by: (a) Checking SAM (System for Award Management) Exclusions; or (b) Collecting a certification from that person; or (c) Adding a clause or condition to the covered transaction with that person (7) Distribution of work to individuals and firms or economic considerations. Control: Per 2 CFR Section 200.303(a), a non-Federal entity must: Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should comply with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition: The County could not provide supporting documentation that suspension and debarment status was determined prior to award. Context: The suspension and debarment status for three out of eight vendors was not documented related to the Coronavirus State and Local Fiscal Recovery Funds program. The suspension and debarment status for four out of five vendors was not documented related to the Clean Water State Revolving Funds program. Questioned costs: There are no questioned costs related to this finding as the vendors were not federally suspended or debarred. Cause: The County did not establish effective internal controls over suspension and debarment transactions. Effect: The County is not in compliance with federal suspension and debarment regulations. Recommendation: The County should ensure they maintain audit documentation to support their review of suspension and debarment status. Views of responsible officials: The County does check Sam.gov for suspension and debarment transactions. Documentation was retained, but was lost due to a network intrusion. We will remain diligent in documenting our reviews.

FY End: 2023-06-30
Kent County, De Government (kent County Levy Court)
Compliance Requirement: I
Reference Number: 2023-001 Prior Year Finding: Yes Federal Agency: U.S. Department of the Treasury & U.S. Environmental Protection Agency Federal Program: Coronavirus State and Local Fiscal Recovery Funds (American Rescue Plan Act) & Clean Water State Revolving Funds Assistance Listing Number: 21.027 & 66.458 Compliance Requirement: Suspension and Debarment Type of Finding: Significant Deficiency in Internal Control Over Compliance Criteria or specific requirement: Compliance: 2 CFR 200.213 Sus...

Reference Number: 2023-001 Prior Year Finding: Yes Federal Agency: U.S. Department of the Treasury & U.S. Environmental Protection Agency Federal Program: Coronavirus State and Local Fiscal Recovery Funds (American Rescue Plan Act) & Clean Water State Revolving Funds Assistance Listing Number: 21.027 & 66.458 Compliance Requirement: Suspension and Debarment Type of Finding: Significant Deficiency in Internal Control Over Compliance Criteria or specific requirement: Compliance: 2 CFR 200.213 Suspension and Debarment restricts awards, subawards, and contracts with certain parties that are debarred, suspended, or otherwise excluded from or ineligible for participation in Federal assistance programs or activities. 2 CFR 180.300 states that an entity may determine suspension and debarment status by: (a) Checking SAM (System for Award Management) Exclusions; or (b) Collecting a certification from that person; or (c) Adding a clause or condition to the covered transaction with that person (7) Distribution of work to individuals and firms or economic considerations. Control: Per 2 CFR Section 200.303(a), a non-Federal entity must: Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should comply with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition: The County could not provide supporting documentation that suspension and debarment status was determined prior to award. Context: The suspension and debarment status for three out of eight vendors was not documented related to the Coronavirus State and Local Fiscal Recovery Funds program. The suspension and debarment status for four out of five vendors was not documented related to the Clean Water State Revolving Funds program. Questioned costs: There are no questioned costs related to this finding as the vendors were not federally suspended or debarred. Cause: The County did not establish effective internal controls over suspension and debarment transactions. Effect: The County is not in compliance with federal suspension and debarment regulations. Recommendation: The County should ensure they maintain audit documentation to support their review of suspension and debarment status. Views of responsible officials: The County does check Sam.gov for suspension and debarment transactions. Documentation was retained, but was lost due to a network intrusion. We will remain diligent in documenting our reviews.

FY End: 2023-06-30
Kent County, De Government (kent County Levy Court)
Compliance Requirement: I
Reference Number: 2023-001 Prior Year Finding: Yes Federal Agency: U.S. Department of the Treasury & U.S. Environmental Protection Agency Federal Program: Coronavirus State and Local Fiscal Recovery Funds (American Rescue Plan Act) & Clean Water State Revolving Funds Assistance Listing Number: 21.027 & 66.458 Compliance Requirement: Suspension and Debarment Type of Finding: Significant Deficiency in Internal Control Over Compliance Criteria or specific requirement: Compliance: 2 CFR 200.213 Sus...

Reference Number: 2023-001 Prior Year Finding: Yes Federal Agency: U.S. Department of the Treasury & U.S. Environmental Protection Agency Federal Program: Coronavirus State and Local Fiscal Recovery Funds (American Rescue Plan Act) & Clean Water State Revolving Funds Assistance Listing Number: 21.027 & 66.458 Compliance Requirement: Suspension and Debarment Type of Finding: Significant Deficiency in Internal Control Over Compliance Criteria or specific requirement: Compliance: 2 CFR 200.213 Suspension and Debarment restricts awards, subawards, and contracts with certain parties that are debarred, suspended, or otherwise excluded from or ineligible for participation in Federal assistance programs or activities. 2 CFR 180.300 states that an entity may determine suspension and debarment status by: (a) Checking SAM (System for Award Management) Exclusions; or (b) Collecting a certification from that person; or (c) Adding a clause or condition to the covered transaction with that person (7) Distribution of work to individuals and firms or economic considerations. Control: Per 2 CFR Section 200.303(a), a non-Federal entity must: Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should comply with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition: The County could not provide supporting documentation that suspension and debarment status was determined prior to award. Context: The suspension and debarment status for three out of eight vendors was not documented related to the Coronavirus State and Local Fiscal Recovery Funds program. The suspension and debarment status for four out of five vendors was not documented related to the Clean Water State Revolving Funds program. Questioned costs: There are no questioned costs related to this finding as the vendors were not federally suspended or debarred. Cause: The County did not establish effective internal controls over suspension and debarment transactions. Effect: The County is not in compliance with federal suspension and debarment regulations. Recommendation: The County should ensure they maintain audit documentation to support their review of suspension and debarment status. Views of responsible officials: The County does check Sam.gov for suspension and debarment transactions. Documentation was retained, but was lost due to a network intrusion. We will remain diligent in documenting our reviews.

FY End: 2023-06-30
College of Lake County
Compliance Requirement: L
Finding 2023-002 – COVID-19 Education Stabilization Fund: Higher Education Emergency Relief Fund Reporting Repeat Finding: No Federal Program Title – U.S. Department of Education Pass-Through Entity: Illinois Community College Board COVID-19 Education Stabilization Fund Higher Education Emergency Relief Fund (HEERF) COVID-19: HEERF Institutional Portion: 84.425F COVID-19: HEERF Minority Serving Institutions (MSI): 84.425L ...

Finding 2023-002 – COVID-19 Education Stabilization Fund: Higher Education Emergency Relief Fund Reporting Repeat Finding: No Federal Program Title – U.S. Department of Education Pass-Through Entity: Illinois Community College Board COVID-19 Education Stabilization Fund Higher Education Emergency Relief Fund (HEERF) COVID-19: HEERF Institutional Portion: 84.425F COVID-19: HEERF Minority Serving Institutions (MSI): 84.425L Federal Award Year 2022-2023 Condition The College did not publicly post a certain required report timely. The following instance of noncompliance was identified: • HEERF Institutional Portion and MSI: The College posted a report to their website on October 23, 2023, for the period of April 1, 2023 – June 30, 2023, which was 110 days after the required deadline of July 10, 2023. Criteria There are three components to reporting for HEERF: (1) public reporting on the (a)(1) Student Aid Portion; (2) public reporting on the (a)(1) Institutional Portion, (a)(2), and (a)(3) subprograms, as applicable; and (3) the annual report. The institutional quarterly portion reporting requirements involve publicly posting completed forms on the College’s website. The forms must be conspicuously posted on the College’s primary website on the same page the reports of the College’s activities as to the emergency financial aid grants to students (Student Aid Portion) are posted. A new, separate form must be posted covering aggregate amounts spent for HEERF I, HEERF II, and HEERF III funds each quarterly reporting period (September 30, December 31, March 31, June 30), concluding after an institution has expended and liquidated all (a)(1) Institutional Portion, (a)(2), and (a)(3) funds and checks the “final report” box. The College must post this quarterly report form no later than 10 days after the end of each calendar quarter (October 10, January 10, April 10, July 10). 2 CFR Section 200.303 requires entities receiving Federal awards establish and maintain internal controls deigned to reasonably ensure compliance with Federal laws, regulations, and program compliance requirements. Effective internal controls should include procedures in place to ensure the timely and accurate posting of reports. Questioned Costs There were no questioned costs with respect to this finding. Cause The College mistakenly overlooked the timely submission of the last quarterly report as this was the end of the grant period. Prevalence Infrequent. 4 quarterly reports and 1 annual report were required to be submitted in fiscal year 2023 relative to HEERF Institutional and MSI. 1 quarterly report was not published timely. Effect The untimely submission of reports is noncompliance with the requirements of the grant award and could result in loss of funding or other penalties. Recommendation We recommend the College implement monitor their internal controls to ensure reports are posted timely. Views of responsible officials We agree with this finding. See corrective action plan.

FY End: 2023-06-30
College of Lake County
Compliance Requirement: B
Finding 2023-003 – COVID-19 Education Stabilization Fund: Higher Education Emergency Relief Fund Period of Performance Repeat Finding: No Federal Program Title – U.S. Department of Education Pass-Through Entity: Illinois Community College Board COVID-19 Education Stabilization Fund Higher Education Emergency Relief Fund (HEERF) COVID-19: HEERF Institutional Portion: 84.425F COVID-19: HEERF Minority Serving Institutions (MSI): 84.425L ...

Finding 2023-003 – COVID-19 Education Stabilization Fund: Higher Education Emergency Relief Fund Period of Performance Repeat Finding: No Federal Program Title – U.S. Department of Education Pass-Through Entity: Illinois Community College Board COVID-19 Education Stabilization Fund Higher Education Emergency Relief Fund (HEERF) COVID-19: HEERF Institutional Portion: 84.425F COVID-19: HEERF Minority Serving Institutions (MSI): 84.425L Federal Award Year 2022-2023 Condition For 2 out of 17 (11.7%) expenditures tested, portions of the expenditures had service periods that extended beyond the grant’s period of performance and were charged to the grant for reimbursement. Criteria The period of performance for HEERF / MSI ended on June 30, 2023. Uniform Grant Guidance (2 CFR 200.303) requires nonfederal entities receiving Federal awards establish and maintain internal controls deigned to reasonably ensure compliance with Federal laws, regulations, and program compliance requirements. Effective internal controls should include procedures to ensure that expenditures are recorded properly. Questioned Costs The questioned costs amount to $16,001. Cause The College did not have proper controls in place to ensure that expenditures with service periods that extended beyond the grant’s period of performance were not charged to the grant. Prevalence Infrequent. Two out seventeen invoices selected for testing. Effect Failure to properly account for expenditures is noncompliance with Federal regulation. Recommendation We recommend the College implement a review process to ensure all expenditures are properly recorded and prior to applying to the grants. Views of responsible officials We agree with this finding. See corrective action plan.

FY End: 2023-06-30
College of Lake County
Compliance Requirement: L
Finding 2023-002 – COVID-19 Education Stabilization Fund: Higher Education Emergency Relief Fund Reporting Repeat Finding: No Federal Program Title – U.S. Department of Education Pass-Through Entity: Illinois Community College Board COVID-19 Education Stabilization Fund Higher Education Emergency Relief Fund (HEERF) COVID-19: HEERF Institutional Portion: 84.425F COVID-19: HEERF Minority Serving Institutions (MSI): 84.425L ...

Finding 2023-002 – COVID-19 Education Stabilization Fund: Higher Education Emergency Relief Fund Reporting Repeat Finding: No Federal Program Title – U.S. Department of Education Pass-Through Entity: Illinois Community College Board COVID-19 Education Stabilization Fund Higher Education Emergency Relief Fund (HEERF) COVID-19: HEERF Institutional Portion: 84.425F COVID-19: HEERF Minority Serving Institutions (MSI): 84.425L Federal Award Year 2022-2023 Condition The College did not publicly post a certain required report timely. The following instance of noncompliance was identified: • HEERF Institutional Portion and MSI: The College posted a report to their website on October 23, 2023, for the period of April 1, 2023 – June 30, 2023, which was 110 days after the required deadline of July 10, 2023. Criteria There are three components to reporting for HEERF: (1) public reporting on the (a)(1) Student Aid Portion; (2) public reporting on the (a)(1) Institutional Portion, (a)(2), and (a)(3) subprograms, as applicable; and (3) the annual report. The institutional quarterly portion reporting requirements involve publicly posting completed forms on the College’s website. The forms must be conspicuously posted on the College’s primary website on the same page the reports of the College’s activities as to the emergency financial aid grants to students (Student Aid Portion) are posted. A new, separate form must be posted covering aggregate amounts spent for HEERF I, HEERF II, and HEERF III funds each quarterly reporting period (September 30, December 31, March 31, June 30), concluding after an institution has expended and liquidated all (a)(1) Institutional Portion, (a)(2), and (a)(3) funds and checks the “final report” box. The College must post this quarterly report form no later than 10 days after the end of each calendar quarter (October 10, January 10, April 10, July 10). 2 CFR Section 200.303 requires entities receiving Federal awards establish and maintain internal controls deigned to reasonably ensure compliance with Federal laws, regulations, and program compliance requirements. Effective internal controls should include procedures in place to ensure the timely and accurate posting of reports. Questioned Costs There were no questioned costs with respect to this finding. Cause The College mistakenly overlooked the timely submission of the last quarterly report as this was the end of the grant period. Prevalence Infrequent. 4 quarterly reports and 1 annual report were required to be submitted in fiscal year 2023 relative to HEERF Institutional and MSI. 1 quarterly report was not published timely. Effect The untimely submission of reports is noncompliance with the requirements of the grant award and could result in loss of funding or other penalties. Recommendation We recommend the College implement monitor their internal controls to ensure reports are posted timely. Views of responsible officials We agree with this finding. See corrective action plan.

FY End: 2023-06-30
College of Lake County
Compliance Requirement: B
Finding 2023-003 – COVID-19 Education Stabilization Fund: Higher Education Emergency Relief Fund Period of Performance Repeat Finding: No Federal Program Title – U.S. Department of Education Pass-Through Entity: Illinois Community College Board COVID-19 Education Stabilization Fund Higher Education Emergency Relief Fund (HEERF) COVID-19: HEERF Institutional Portion: 84.425F COVID-19: HEERF Minority Serving Institutions (MSI): 84.425L ...

Finding 2023-003 – COVID-19 Education Stabilization Fund: Higher Education Emergency Relief Fund Period of Performance Repeat Finding: No Federal Program Title – U.S. Department of Education Pass-Through Entity: Illinois Community College Board COVID-19 Education Stabilization Fund Higher Education Emergency Relief Fund (HEERF) COVID-19: HEERF Institutional Portion: 84.425F COVID-19: HEERF Minority Serving Institutions (MSI): 84.425L Federal Award Year 2022-2023 Condition For 2 out of 17 (11.7%) expenditures tested, portions of the expenditures had service periods that extended beyond the grant’s period of performance and were charged to the grant for reimbursement. Criteria The period of performance for HEERF / MSI ended on June 30, 2023. Uniform Grant Guidance (2 CFR 200.303) requires nonfederal entities receiving Federal awards establish and maintain internal controls deigned to reasonably ensure compliance with Federal laws, regulations, and program compliance requirements. Effective internal controls should include procedures to ensure that expenditures are recorded properly. Questioned Costs The questioned costs amount to $16,001. Cause The College did not have proper controls in place to ensure that expenditures with service periods that extended beyond the grant’s period of performance were not charged to the grant. Prevalence Infrequent. Two out seventeen invoices selected for testing. Effect Failure to properly account for expenditures is noncompliance with Federal regulation. Recommendation We recommend the College implement a review process to ensure all expenditures are properly recorded and prior to applying to the grants. Views of responsible officials We agree with this finding. See corrective action plan.

FY End: 2023-06-30
College of Lake County
Compliance Requirement: N
Finding 2023-004 – Gramm-Leach Bliley Act—Student Information Security Repeat Finding: No Federal Program Title – U.S. Department of Education Student Financial Assistance Cluster Federal Direct Student Loans: 84.268 Federal Pell Grant Program: 84.063 Federal Work-Study Program: 84.033 Federal Supplemental Educational Opportunity Grants: 84.007 Federal Award Year 2022-2023 Condition While the College does have a program that addresses information sec...

Finding 2023-004 – Gramm-Leach Bliley Act—Student Information Security Repeat Finding: No Federal Program Title – U.S. Department of Education Student Financial Assistance Cluster Federal Direct Student Loans: 84.268 Federal Pell Grant Program: 84.063 Federal Work-Study Program: 84.033 Federal Supplemental Educational Opportunity Grants: 84.007 Federal Award Year 2022-2023 Condition While the College does have a program that addresses information security, the College did not have a readily accessible program document to address the required safeguards for the nine required elements under the implementing regulations of the Gramm-Leach Bliley Act (GLBA) known as the “Safeguards Rule” by June 9, 2023. Criteria In accordance with 16 CFR 314.4(c), an institution’s written information security program must address the implementation of the minimum safeguards identified in 16 CFR 314.4(c)(1) through (8). This includes the following: (1) implement and periodically review access controls, (2) conduct a periodic inventory of data, noting where it’s collected, stored or transmitted, (3) encrypt customer information on the institution’s system and when it’s in transit, (4) assess apps developed by the institution, (5) implement multi-factor authentication for anyone accessing customer information on the institution’s system, (6) dispose of customer information securely, (7) anticipate and evaluate changes to the information system or network, and (8) maintain a log of authorized users’ activity and keep an eye out for unauthorized users. 2 CFR Section 200.303 requires entities receiving Federal awards establish and maintain internal controls deigned to reasonably ensure compliance with Federal laws, regulations, and program compliance requirements. Effective internal controls should include procedures in place to ensure that reviews are being completed over information security policies and that they are in compliance with GLBA requirements. Questioned Costs There were no questioned costs. Cause Due to conflicting priorities, the College’s Information Security Program was not fully documented by June 9, 2023. The formal document is under development with an expected completion date by June 30, 2024. Prevalence Frequent. The required elements were not combined into a single program document that is available upon request by appropriate entities. Effect While substantive work has been completed through the College’s Information Security program in implementing the nine elements of the GLBA Safeguards Rule and eight standards identified above, failure to have a formal program document outlining all of the standards of GLBA, results in the failure to meet the requirements outlined in the Act and is deemed as noncompliance. Recommendation We recommend that the College create a formal Information Security Program document outlining the standards that are in place to address the GLBA requirements. Additionally, we recommend the College place the document in a readily accessible location for distribution to appropriate entities by approved individuals. Views of responsible officials We agree with this finding. See corrective action plan.

FY End: 2023-06-30
College of Lake County
Compliance Requirement: N
Finding 2023-004 – Gramm-Leach Bliley Act—Student Information Security Repeat Finding: No Federal Program Title – U.S. Department of Education Student Financial Assistance Cluster Federal Direct Student Loans: 84.268 Federal Pell Grant Program: 84.063 Federal Work-Study Program: 84.033 Federal Supplemental Educational Opportunity Grants: 84.007 Federal Award Year 2022-2023 Condition While the College does have a program that addresses information sec...

Finding 2023-004 – Gramm-Leach Bliley Act—Student Information Security Repeat Finding: No Federal Program Title – U.S. Department of Education Student Financial Assistance Cluster Federal Direct Student Loans: 84.268 Federal Pell Grant Program: 84.063 Federal Work-Study Program: 84.033 Federal Supplemental Educational Opportunity Grants: 84.007 Federal Award Year 2022-2023 Condition While the College does have a program that addresses information security, the College did not have a readily accessible program document to address the required safeguards for the nine required elements under the implementing regulations of the Gramm-Leach Bliley Act (GLBA) known as the “Safeguards Rule” by June 9, 2023. Criteria In accordance with 16 CFR 314.4(c), an institution’s written information security program must address the implementation of the minimum safeguards identified in 16 CFR 314.4(c)(1) through (8). This includes the following: (1) implement and periodically review access controls, (2) conduct a periodic inventory of data, noting where it’s collected, stored or transmitted, (3) encrypt customer information on the institution’s system and when it’s in transit, (4) assess apps developed by the institution, (5) implement multi-factor authentication for anyone accessing customer information on the institution’s system, (6) dispose of customer information securely, (7) anticipate and evaluate changes to the information system or network, and (8) maintain a log of authorized users’ activity and keep an eye out for unauthorized users. 2 CFR Section 200.303 requires entities receiving Federal awards establish and maintain internal controls deigned to reasonably ensure compliance with Federal laws, regulations, and program compliance requirements. Effective internal controls should include procedures in place to ensure that reviews are being completed over information security policies and that they are in compliance with GLBA requirements. Questioned Costs There were no questioned costs. Cause Due to conflicting priorities, the College’s Information Security Program was not fully documented by June 9, 2023. The formal document is under development with an expected completion date by June 30, 2024. Prevalence Frequent. The required elements were not combined into a single program document that is available upon request by appropriate entities. Effect While substantive work has been completed through the College’s Information Security program in implementing the nine elements of the GLBA Safeguards Rule and eight standards identified above, failure to have a formal program document outlining all of the standards of GLBA, results in the failure to meet the requirements outlined in the Act and is deemed as noncompliance. Recommendation We recommend that the College create a formal Information Security Program document outlining the standards that are in place to address the GLBA requirements. Additionally, we recommend the College place the document in a readily accessible location for distribution to appropriate entities by approved individuals. Views of responsible officials We agree with this finding. See corrective action plan.

FY End: 2023-06-30
College of Lake County
Compliance Requirement: N
Finding 2023-004 – Gramm-Leach Bliley Act—Student Information Security Repeat Finding: No Federal Program Title – U.S. Department of Education Student Financial Assistance Cluster Federal Direct Student Loans: 84.268 Federal Pell Grant Program: 84.063 Federal Work-Study Program: 84.033 Federal Supplemental Educational Opportunity Grants: 84.007 Federal Award Year 2022-2023 Condition While the College does have a program that addresses information sec...

Finding 2023-004 – Gramm-Leach Bliley Act—Student Information Security Repeat Finding: No Federal Program Title – U.S. Department of Education Student Financial Assistance Cluster Federal Direct Student Loans: 84.268 Federal Pell Grant Program: 84.063 Federal Work-Study Program: 84.033 Federal Supplemental Educational Opportunity Grants: 84.007 Federal Award Year 2022-2023 Condition While the College does have a program that addresses information security, the College did not have a readily accessible program document to address the required safeguards for the nine required elements under the implementing regulations of the Gramm-Leach Bliley Act (GLBA) known as the “Safeguards Rule” by June 9, 2023. Criteria In accordance with 16 CFR 314.4(c), an institution’s written information security program must address the implementation of the minimum safeguards identified in 16 CFR 314.4(c)(1) through (8). This includes the following: (1) implement and periodically review access controls, (2) conduct a periodic inventory of data, noting where it’s collected, stored or transmitted, (3) encrypt customer information on the institution’s system and when it’s in transit, (4) assess apps developed by the institution, (5) implement multi-factor authentication for anyone accessing customer information on the institution’s system, (6) dispose of customer information securely, (7) anticipate and evaluate changes to the information system or network, and (8) maintain a log of authorized users’ activity and keep an eye out for unauthorized users. 2 CFR Section 200.303 requires entities receiving Federal awards establish and maintain internal controls deigned to reasonably ensure compliance with Federal laws, regulations, and program compliance requirements. Effective internal controls should include procedures in place to ensure that reviews are being completed over information security policies and that they are in compliance with GLBA requirements. Questioned Costs There were no questioned costs. Cause Due to conflicting priorities, the College’s Information Security Program was not fully documented by June 9, 2023. The formal document is under development with an expected completion date by June 30, 2024. Prevalence Frequent. The required elements were not combined into a single program document that is available upon request by appropriate entities. Effect While substantive work has been completed through the College’s Information Security program in implementing the nine elements of the GLBA Safeguards Rule and eight standards identified above, failure to have a formal program document outlining all of the standards of GLBA, results in the failure to meet the requirements outlined in the Act and is deemed as noncompliance. Recommendation We recommend that the College create a formal Information Security Program document outlining the standards that are in place to address the GLBA requirements. Additionally, we recommend the College place the document in a readily accessible location for distribution to appropriate entities by approved individuals. Views of responsible officials We agree with this finding. See corrective action plan.

FY End: 2023-06-30
College of Lake County
Compliance Requirement: N
Finding 2023-004 – Gramm-Leach Bliley Act—Student Information Security Repeat Finding: No Federal Program Title – U.S. Department of Education Student Financial Assistance Cluster Federal Direct Student Loans: 84.268 Federal Pell Grant Program: 84.063 Federal Work-Study Program: 84.033 Federal Supplemental Educational Opportunity Grants: 84.007 Federal Award Year 2022-2023 Condition While the College does have a program that addresses information sec...

Finding 2023-004 – Gramm-Leach Bliley Act—Student Information Security Repeat Finding: No Federal Program Title – U.S. Department of Education Student Financial Assistance Cluster Federal Direct Student Loans: 84.268 Federal Pell Grant Program: 84.063 Federal Work-Study Program: 84.033 Federal Supplemental Educational Opportunity Grants: 84.007 Federal Award Year 2022-2023 Condition While the College does have a program that addresses information security, the College did not have a readily accessible program document to address the required safeguards for the nine required elements under the implementing regulations of the Gramm-Leach Bliley Act (GLBA) known as the “Safeguards Rule” by June 9, 2023. Criteria In accordance with 16 CFR 314.4(c), an institution’s written information security program must address the implementation of the minimum safeguards identified in 16 CFR 314.4(c)(1) through (8). This includes the following: (1) implement and periodically review access controls, (2) conduct a periodic inventory of data, noting where it’s collected, stored or transmitted, (3) encrypt customer information on the institution’s system and when it’s in transit, (4) assess apps developed by the institution, (5) implement multi-factor authentication for anyone accessing customer information on the institution’s system, (6) dispose of customer information securely, (7) anticipate and evaluate changes to the information system or network, and (8) maintain a log of authorized users’ activity and keep an eye out for unauthorized users. 2 CFR Section 200.303 requires entities receiving Federal awards establish and maintain internal controls deigned to reasonably ensure compliance with Federal laws, regulations, and program compliance requirements. Effective internal controls should include procedures in place to ensure that reviews are being completed over information security policies and that they are in compliance with GLBA requirements. Questioned Costs There were no questioned costs. Cause Due to conflicting priorities, the College’s Information Security Program was not fully documented by June 9, 2023. The formal document is under development with an expected completion date by June 30, 2024. Prevalence Frequent. The required elements were not combined into a single program document that is available upon request by appropriate entities. Effect While substantive work has been completed through the College’s Information Security program in implementing the nine elements of the GLBA Safeguards Rule and eight standards identified above, failure to have a formal program document outlining all of the standards of GLBA, results in the failure to meet the requirements outlined in the Act and is deemed as noncompliance. Recommendation We recommend that the College create a formal Information Security Program document outlining the standards that are in place to address the GLBA requirements. Additionally, we recommend the College place the document in a readily accessible location for distribution to appropriate entities by approved individuals. Views of responsible officials We agree with this finding. See corrective action plan.

FY End: 2023-06-30
Horizons for Homeless Children
Compliance Requirement: E
2023-001 - Eligibility Federal Agency: U.S. Department of Health and Human Services Federal Program: 93.596 and 93.575 Child Care Development Fund (CCDF) Cluster Condition: As part of our testing of Horizons for Homeless Children’s (the Organization) internal control over compliance for eligibility, we noted that the Organization did not follow their internal controls regarding review and approval of the Child Care Subsidy Application and Fee Agreement for one out of twenty-five applications rev...

2023-001 - Eligibility Federal Agency: U.S. Department of Health and Human Services Federal Program: 93.596 and 93.575 Child Care Development Fund (CCDF) Cluster Condition: As part of our testing of Horizons for Homeless Children’s (the Organization) internal control over compliance for eligibility, we noted that the Organization did not follow their internal controls regarding review and approval of the Child Care Subsidy Application and Fee Agreement for one out of twenty-five applications reviewed. Criteria: 2 CFR 200.303 indicates that non-Federal entities receiving Federal awards must establish and maintain effective internal controls over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations and the terms and conditions of the Federal award. Cause: The Organization did not properly follow its internal controls. Effect: The Child Care Subsidy Application and Fee Agreement was not properly reviewed and approved. Context: One out of twenty-five applications sampled. Our sample was not a statistically valid sample. This was not a repeat finding from a prior period. Questioned Costs: None Recommendations: Management should ensure that the Organization’s internal controls in place are properly followed. Management Response: Management agrees with the finding and will implement additional review procedures during fiscal year 2024 to ensure the Child Care Subsidy Application and Fee Agreements are properly reviewed and approved.

FY End: 2023-06-30
Horizons for Homeless Children
Compliance Requirement: E
2023-001 - Eligibility Federal Agency: U.S. Department of Health and Human Services Federal Program: 93.596 and 93.575 Child Care Development Fund (CCDF) Cluster Condition: As part of our testing of Horizons for Homeless Children’s (the Organization) internal control over compliance for eligibility, we noted that the Organization did not follow their internal controls regarding review and approval of the Child Care Subsidy Application and Fee Agreement for one out of twenty-five applications rev...

2023-001 - Eligibility Federal Agency: U.S. Department of Health and Human Services Federal Program: 93.596 and 93.575 Child Care Development Fund (CCDF) Cluster Condition: As part of our testing of Horizons for Homeless Children’s (the Organization) internal control over compliance for eligibility, we noted that the Organization did not follow their internal controls regarding review and approval of the Child Care Subsidy Application and Fee Agreement for one out of twenty-five applications reviewed. Criteria: 2 CFR 200.303 indicates that non-Federal entities receiving Federal awards must establish and maintain effective internal controls over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations and the terms and conditions of the Federal award. Cause: The Organization did not properly follow its internal controls. Effect: The Child Care Subsidy Application and Fee Agreement was not properly reviewed and approved. Context: One out of twenty-five applications sampled. Our sample was not a statistically valid sample. This was not a repeat finding from a prior period. Questioned Costs: None Recommendations: Management should ensure that the Organization’s internal controls in place are properly followed. Management Response: Management agrees with the finding and will implement additional review procedures during fiscal year 2024 to ensure the Child Care Subsidy Application and Fee Agreements are properly reviewed and approved.

FY End: 2023-06-30
Unified School District Number 494
Compliance Requirement: L
Finding 2023-001 SIGNIFICANT DEFICENCY Internal Controls Criteria: Pursuant to the Code of Federal Regulations (CFR), Title 2 Grants and Agreements, Subpart D Post Federal Award Requirements, Section 200.303 “the non-federal entity must establish and maintain effective internal control over the Federal aware that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal a...

Finding 2023-001 SIGNIFICANT DEFICENCY Internal Controls Criteria: Pursuant to the Code of Federal Regulations (CFR), Title 2 Grants and Agreements, Subpart D Post Federal Award Requirements, Section 200.303 “the non-federal entity must establish and maintain effective internal control over the Federal aware that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award.” Condition: When investigating the controls related to Education Stabilization Fund reporting to the State of Kanas, we became aware that the same individual compiling the information is the same submitting the reports with no secondary review. Cause: The controls related to reporting for Education Stabilization Fund are non-existent. Effect: There is no internal control related to reporting for Education Stabilization Fund. Recommendations: The District should have an employee compare the Board Clerk’s supporting documentation and the Education Stabilization Fund spreadsheet report before its submission to the State of Kansas for its accuracy. After the approval by the secondary review employee, the report submitted should be printed, initialed by the secondary reviewer, stapled with the information used to compile the report and combined with all financial records for the fiscal year. Views of Responsible Officials and Planned Corrective Actions: The District agrees with the finding. See separate document for planned corrective actions.

FY End: 2023-06-30
Unified School District Number 494
Compliance Requirement: F
Finding 2023-002 SIGNIFICANT DEFICENCY Internal Controls Criteria: Pursuant to the Code of Federal Regulations (CFR), Title 2 Grants and Agreements, Subpart D Post Federal Award Requirements, Section 200.303 “the non-federal entity must establish and maintain effective internal control over the Federal aware that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal a...

Finding 2023-002 SIGNIFICANT DEFICENCY Internal Controls Criteria: Pursuant to the Code of Federal Regulations (CFR), Title 2 Grants and Agreements, Subpart D Post Federal Award Requirements, Section 200.303 “the non-federal entity must establish and maintain effective internal control over the Federal aware that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award.” Condition: When investigating the controls related to equipment management, we became aware that the District relies on a third party to maintain records without any secondary review of its completeness. The current maintenance records does not include non-technology records and its related funding source. Cause: The controls related to equipment maintenance for Education Stabilization Fund are non-existent. Effect: There is no internal control related to equipment maintenance for the Education Stabilization Fund. Recommendations: The District should have an employee compare the third party’s equipment inventory records with the financial records for completeness. An employee should also be present during the physical equipment inventory each year and maintain records of proof for its occurrence. Lastly, the current inventory records should also be altered in order to be maintained with information required by 2 CFR section 200.313(d)(2) that include a description of the property, a serial number or other identification number, the source of funding for the property (including the Federal award identification number), who holds title, the acquisition date, cost of the property, percentage of Federal participation in the project costs for the Federal award under which the property was acquired, the location, use and condition of the property, and any ultimate disposition data of disposal and sales price of the property. Views of Responsible Officials and Planned Corrective Actions: The District agrees with the finding. See separate document for planned corrective actions.

FY End: 2023-06-30
Rural Health Redesign Center Organization
Compliance Requirement: I
Federal Agency: U.S. Department of Health and Human Services Federal Program Title: Rural Health Care Services Outreach and Rural Emergency Hospital Technical Assistance Assistance Listing Number: 93.912 and 93.241 Federal Award Program Year: July 1, 2022 – June 30, 2023 Pass-Through Agency: None Pass-Through Number: None Type of Finding: • Significant deficiency in internal control over compliance • Other matter finding Criteria or Specific Requirement – Procurement, Suspension and Debarment: P...

Federal Agency: U.S. Department of Health and Human Services Federal Program Title: Rural Health Care Services Outreach and Rural Emergency Hospital Technical Assistance Assistance Listing Number: 93.912 and 93.241 Federal Award Program Year: July 1, 2022 – June 30, 2023 Pass-Through Agency: None Pass-Through Number: None Type of Finding: • Significant deficiency in internal control over compliance • Other matter finding Criteria or Specific Requirement – Procurement, Suspension and Debarment: Pursuant to 31 CFR § 19.300, non-Federal entities are prohibited from contracting with or making subawards under covered transactions to parties that are suspended and debarred or whose principals are suspended or debarred. The non-Federal entity must verify that the contracted entity is not suspended or debarred or otherwise excluded. In addition, pursuant to 2 CFR 200.303, which states in part, the non-Federal entity must establish and maintain an effective internal control over the Federal awards that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission. Condition: The Organization could not provide support that it had reviewed the “List of Parties Excluded from Federal Procurement and Nonprocurement Programs” during their procurement procedures on a consistent basis. The Organization had not properly designed or implemented a system of internal controls, which would include appropriate segregation of duties that would likely be effective in preventing, detecting, and correcting, noncompliance. Questioned Costs: None Context: It was noted that the files selected for testing did not have documented evidence supporting that the Organization had determined that the contracted parties were not suspended or debarred. From a population of two files, one was selected for testing. Our sample was not intended to be statistically valid. Effect: The Organization was unable to support vendors were not suspended or debarred. Cause: Failure to maintain sufficient procurement records. Identification as a Repeat Finding: No Recommendation: We recommend that the Organization maintain adequate documentation to ensure compliance with the suspension and debarment requirement. This documentation could include a print out from the Excluded Parties List System maintained by the General Services Administration, collection of a certification from the contracted party, or adding a clause or condition to the covered transaction with the contracted party. Views of Responsible Officials and Planned Corrective Action: The Organization is aware of the compliance requirement and has implemented additional procedures, including certain of those identified in the recommendation above, to be able to support suspension and debarment processes are in place. Persons responsible for implementing: Gerry Egan, Finance Manager Anticipated completion date: Completed.

FY End: 2023-06-30
Rural Health Redesign Center Organization
Compliance Requirement: I
Federal Agency: U.S. Department of Health and Human Services Federal Program Title: Rural Health Care Services Outreach and Rural Emergency Hospital Technical Assistance Assistance Listing Number: 93.912 and 93.241 Federal Award Program Year: July 1, 2022 – June 30, 2023 Pass-Through Agency: None Pass-Through Number: None Type of Finding: • Significant deficiency in internal control over compliance • Other matter finding Criteria or Specific Requirement – Procurement, Suspension and Debarment: P...

Federal Agency: U.S. Department of Health and Human Services Federal Program Title: Rural Health Care Services Outreach and Rural Emergency Hospital Technical Assistance Assistance Listing Number: 93.912 and 93.241 Federal Award Program Year: July 1, 2022 – June 30, 2023 Pass-Through Agency: None Pass-Through Number: None Type of Finding: • Significant deficiency in internal control over compliance • Other matter finding Criteria or Specific Requirement – Procurement, Suspension and Debarment: Pursuant to 31 CFR § 19.300, non-Federal entities are prohibited from contracting with or making subawards under covered transactions to parties that are suspended and debarred or whose principals are suspended or debarred. The non-Federal entity must verify that the contracted entity is not suspended or debarred or otherwise excluded. In addition, pursuant to 2 CFR 200.303, which states in part, the non-Federal entity must establish and maintain an effective internal control over the Federal awards that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission. Condition: The Organization could not provide support that it had reviewed the “List of Parties Excluded from Federal Procurement and Nonprocurement Programs” during their procurement procedures on a consistent basis. The Organization had not properly designed or implemented a system of internal controls, which would include appropriate segregation of duties that would likely be effective in preventing, detecting, and correcting, noncompliance. Questioned Costs: None Context: It was noted that the files selected for testing did not have documented evidence supporting that the Organization had determined that the contracted parties were not suspended or debarred. From a population of two files, one was selected for testing. Our sample was not intended to be statistically valid. Effect: The Organization was unable to support vendors were not suspended or debarred. Cause: Failure to maintain sufficient procurement records. Identification as a Repeat Finding: No Recommendation: We recommend that the Organization maintain adequate documentation to ensure compliance with the suspension and debarment requirement. This documentation could include a print out from the Excluded Parties List System maintained by the General Services Administration, collection of a certification from the contracted party, or adding a clause or condition to the covered transaction with the contracted party. Views of Responsible Officials and Planned Corrective Action: The Organization is aware of the compliance requirement and has implemented additional procedures, including certain of those identified in the recommendation above, to be able to support suspension and debarment processes are in place. Persons responsible for implementing: Gerry Egan, Finance Manager Anticipated completion date: Completed.

FY End: 2023-06-30
Southwestern Oregon Community College
Compliance Requirement: L
Criteria or specific requirement: Per Uniform Guidance 2 CFR 200.303, non-federal entities receiving federal awards are required to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations and program compliance requirements. The initial reporting for this grant requires the report to be submitted to the Institution’s website within 30 days of the signed Certification Agreement or 30 days after the electronic announcement dated May 6, which...

Criteria or specific requirement: Per Uniform Guidance 2 CFR 200.303, non-federal entities receiving federal awards are required to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations and program compliance requirements. The initial reporting for this grant requires the report to be submitted to the Institution’s website within 30 days of the signed Certification Agreement or 30 days after the electronic announcement dated May 6, whichever is later. Institutions were then required to update their websites every 45 days after initial upload. This was changed to quarterly on August 31, 2020. In addition, an annual report is required. Condition: The College did not report the correct amount for total quarterly expenditures for one of the quarterly reports tested. Questioned costs: None Context: One of two HEERF quarterly reports tested included data that did not agree to supporting documentation. Cause: The control system put in place for review of these reports is not operating effectively. Effect: The College reported an incorrect amount for total quarterly expenditures. Repeat Finding: No Recommendation: CLA recommends SOCC reviews its review process for these reports and implements a reconciling process between the report and the supporting documentation to make sure these things match before being signed off as reviewed. CLA also recommends a second reviewer of these reports. Views of responsible officials: There is no disagreement with the audit finding.

FY End: 2023-06-30
Southwestern Oregon Community College
Compliance Requirement: L
Criteria or specific requirement: Per Uniform Guidance 2 CFR 200.303, non-federal entities receiving federal awards are required to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations and program compliance requirements. The initial reporting for this grant requires the report to be submitted to the Institution’s website within 30 days of the signed Certification Agreement or 30 days after the electronic announcement dated May 6, which...

Criteria or specific requirement: Per Uniform Guidance 2 CFR 200.303, non-federal entities receiving federal awards are required to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations and program compliance requirements. The initial reporting for this grant requires the report to be submitted to the Institution’s website within 30 days of the signed Certification Agreement or 30 days after the electronic announcement dated May 6, whichever is later. Institutions were then required to update their websites every 45 days after initial upload. This was changed to quarterly on August 31, 2020. In addition, an annual report is required. Condition: The College did not report the correct amount for total quarterly expenditures for one of the quarterly reports tested. Questioned costs: None Context: One of two HEERF quarterly reports tested included data that did not agree to supporting documentation. Cause: The control system put in place for review of these reports is not operating effectively. Effect: The College reported an incorrect amount for total quarterly expenditures. Repeat Finding: No Recommendation: CLA recommends SOCC reviews its review process for these reports and implements a reconciling process between the report and the supporting documentation to make sure these things match before being signed off as reviewed. CLA also recommends a second reviewer of these reports. Views of responsible officials: There is no disagreement with the audit finding.

FY End: 2023-06-30
Murphy Elementary School District No. 21
Compliance Requirement: LN
Finding Number: 2023‐001 Repeat Finding: No Program Name/Assistance Listing Title: Child Nutrition Cluster Assistance Listing Number: 10.553, 10.555, 10.559 Federal Agency: U.S. Department of Education Federal Award Number: 7AZ300AZ3 Pass‐Through Agency: Arizona Department of Education Questioned Costs: N/A Type of Finding: Noncompliance, Significant Deficiency Compliance Requirement: Reporting, Special Tests and Provisions Criteria In accordance with 2 CFR 200.303, management is responsible for...

Finding Number: 2023‐001 Repeat Finding: No Program Name/Assistance Listing Title: Child Nutrition Cluster Assistance Listing Number: 10.553, 10.555, 10.559 Federal Agency: U.S. Department of Education Federal Award Number: 7AZ300AZ3 Pass‐Through Agency: Arizona Department of Education Questioned Costs: N/A Type of Finding: Noncompliance, Significant Deficiency Compliance Requirement: Reporting, Special Tests and Provisions Criteria In accordance with 2 CFR 200.303, management is responsible for establishing and maintaining internal controls over federal programs. This includes the development of a system to ensure documentation is maintained to support all reported figures and counts as it relates to federal programs, including the Child Nutrition Cluster. Condition The District lacked proper internal controls over supporting documentation. Cause The director of the program left in August 2023 and there was not an adequate filing system in place to ensure all files would be retained. Effect The District could not support the figures reported on the meal reimbursement claim and may not have been reimbursed for the proper number of meals served. The District may not have filed the verification report on time. Context During our review of the child nutrition cluster we noted the following:  Breakfast meals claimed on the January 2023 reimbursement claim could not be agreed to supporting documentation. Meals reported on the claim were less than the support.  It could not be determined if the Verification Summary Report was submitted by February 1. The sample was not intended to be, and was not, a statistically valid sample. Recommendation The District should ensure all supporting documentation is retained. Views of Responsible Officials See Corrective Action Plan.

FY End: 2023-06-30
Murphy Elementary School District No. 21
Compliance Requirement: LN
Finding Number: 2023‐001 Repeat Finding: No Program Name/Assistance Listing Title: Child Nutrition Cluster Assistance Listing Number: 10.553, 10.555, 10.559 Federal Agency: U.S. Department of Education Federal Award Number: 7AZ300AZ3 Pass‐Through Agency: Arizona Department of Education Questioned Costs: N/A Type of Finding: Noncompliance, Significant Deficiency Compliance Requirement: Reporting, Special Tests and Provisions Criteria In accordance with 2 CFR 200.303, management is responsible for...

Finding Number: 2023‐001 Repeat Finding: No Program Name/Assistance Listing Title: Child Nutrition Cluster Assistance Listing Number: 10.553, 10.555, 10.559 Federal Agency: U.S. Department of Education Federal Award Number: 7AZ300AZ3 Pass‐Through Agency: Arizona Department of Education Questioned Costs: N/A Type of Finding: Noncompliance, Significant Deficiency Compliance Requirement: Reporting, Special Tests and Provisions Criteria In accordance with 2 CFR 200.303, management is responsible for establishing and maintaining internal controls over federal programs. This includes the development of a system to ensure documentation is maintained to support all reported figures and counts as it relates to federal programs, including the Child Nutrition Cluster. Condition The District lacked proper internal controls over supporting documentation. Cause The director of the program left in August 2023 and there was not an adequate filing system in place to ensure all files would be retained. Effect The District could not support the figures reported on the meal reimbursement claim and may not have been reimbursed for the proper number of meals served. The District may not have filed the verification report on time. Context During our review of the child nutrition cluster we noted the following:  Breakfast meals claimed on the January 2023 reimbursement claim could not be agreed to supporting documentation. Meals reported on the claim were less than the support.  It could not be determined if the Verification Summary Report was submitted by February 1. The sample was not intended to be, and was not, a statistically valid sample. Recommendation The District should ensure all supporting documentation is retained. Views of Responsible Officials See Corrective Action Plan.

FY End: 2023-06-30
Murphy Elementary School District No. 21
Compliance Requirement: LN
Finding Number: 2023‐001 Repeat Finding: No Program Name/Assistance Listing Title: Child Nutrition Cluster Assistance Listing Number: 10.553, 10.555, 10.559 Federal Agency: U.S. Department of Education Federal Award Number: 7AZ300AZ3 Pass‐Through Agency: Arizona Department of Education Questioned Costs: N/A Type of Finding: Noncompliance, Significant Deficiency Compliance Requirement: Reporting, Special Tests and Provisions Criteria In accordance with 2 CFR 200.303, management is responsible for...

Finding Number: 2023‐001 Repeat Finding: No Program Name/Assistance Listing Title: Child Nutrition Cluster Assistance Listing Number: 10.553, 10.555, 10.559 Federal Agency: U.S. Department of Education Federal Award Number: 7AZ300AZ3 Pass‐Through Agency: Arizona Department of Education Questioned Costs: N/A Type of Finding: Noncompliance, Significant Deficiency Compliance Requirement: Reporting, Special Tests and Provisions Criteria In accordance with 2 CFR 200.303, management is responsible for establishing and maintaining internal controls over federal programs. This includes the development of a system to ensure documentation is maintained to support all reported figures and counts as it relates to federal programs, including the Child Nutrition Cluster. Condition The District lacked proper internal controls over supporting documentation. Cause The director of the program left in August 2023 and there was not an adequate filing system in place to ensure all files would be retained. Effect The District could not support the figures reported on the meal reimbursement claim and may not have been reimbursed for the proper number of meals served. The District may not have filed the verification report on time. Context During our review of the child nutrition cluster we noted the following:  Breakfast meals claimed on the January 2023 reimbursement claim could not be agreed to supporting documentation. Meals reported on the claim were less than the support.  It could not be determined if the Verification Summary Report was submitted by February 1. The sample was not intended to be, and was not, a statistically valid sample. Recommendation The District should ensure all supporting documentation is retained. Views of Responsible Officials See Corrective Action Plan.

FY End: 2023-06-30
New Mexico Highlands University
Compliance Requirement: I
2023‐009 (2022‐005) Procurement, Small Purchase (Significant Deficiency in Internal Controls over Compliance, Noncompliance, and Questioned Costs greater than $25k) Funding Agency: United States Department of Education Federal Award Agreement Number: N/A Award Year: 2023 Title: Education Stabilization Fund, HEERF Assistance Listing Number: 84.425C, 84.425F Pass‐through Agency: Not Applicable Pass‐through Identification Number: Not Applicable Questioned Costs: $76,109 Condition: The University di...

2023‐009 (2022‐005) Procurement, Small Purchase (Significant Deficiency in Internal Controls over Compliance, Noncompliance, and Questioned Costs greater than $25k) Funding Agency: United States Department of Education Federal Award Agreement Number: N/A Award Year: 2023 Title: Education Stabilization Fund, HEERF Assistance Listing Number: 84.425C, 84.425F Pass‐through Agency: Not Applicable Pass‐through Identification Number: Not Applicable Questioned Costs: $76,109 Condition: The University did not apply the correct small purchase threshold for identifying purchases that need to obtain quotes in their policy. Population $10k‐$20k not included in small purchase policy included transactions totaling $76,109. Progress on resolution of prior year finding: No progress was made. Criteria: Per 2 CFR 200.303(a) requires non‐Federal entities to establish and maintain effective internal controls over compliance with Federal statutes, regulations, and the terms and conditions of grant agreements. 2 CFR 200.320(a) sets the micro‐purchase threshold at $10,000 and requires purchases over the micro‐purchase threshold to use small purchase procedures, whereby price or rate quotations must be obtained. Cause: Policies are not adequate to meet federal guidelines and need to be updated. Effect: The University may unintentionally use a higher‐cost vendor when failing to obtain price or rate quotations for items over the micro‐purchase threshold.

FY End: 2023-06-30
New Mexico Highlands University
Compliance Requirement: I
2023‐009 (2022‐005) Procurement, Small Purchase (Significant Deficiency in Internal Controls over Compliance, Noncompliance, and Questioned Costs greater than $25k) Funding Agency: United States Department of Education Federal Award Agreement Number: N/A Award Year: 2023 Title: Education Stabilization Fund, HEERF Assistance Listing Number: 84.425C, 84.425F Pass‐through Agency: Not Applicable Pass‐through Identification Number: Not Applicable Questioned Costs: $76,109 Condition: The University di...

2023‐009 (2022‐005) Procurement, Small Purchase (Significant Deficiency in Internal Controls over Compliance, Noncompliance, and Questioned Costs greater than $25k) Funding Agency: United States Department of Education Federal Award Agreement Number: N/A Award Year: 2023 Title: Education Stabilization Fund, HEERF Assistance Listing Number: 84.425C, 84.425F Pass‐through Agency: Not Applicable Pass‐through Identification Number: Not Applicable Questioned Costs: $76,109 Condition: The University did not apply the correct small purchase threshold for identifying purchases that need to obtain quotes in their policy. Population $10k‐$20k not included in small purchase policy included transactions totaling $76,109. Progress on resolution of prior year finding: No progress was made. Criteria: Per 2 CFR 200.303(a) requires non‐Federal entities to establish and maintain effective internal controls over compliance with Federal statutes, regulations, and the terms and conditions of grant agreements. 2 CFR 200.320(a) sets the micro‐purchase threshold at $10,000 and requires purchases over the micro‐purchase threshold to use small purchase procedures, whereby price or rate quotations must be obtained. Cause: Policies are not adequate to meet federal guidelines and need to be updated. Effect: The University may unintentionally use a higher‐cost vendor when failing to obtain price or rate quotations for items over the micro‐purchase threshold.

FY End: 2023-06-30
New Mexico Highlands University
Compliance Requirement: I
2023‐009 (2022‐005) Procurement, Small Purchase (Significant Deficiency in Internal Controls over Compliance, Noncompliance, and Questioned Costs greater than $25k) Funding Agency: United States Department of Education Federal Award Agreement Number: N/A Award Year: 2023 Title: Education Stabilization Fund, HEERF Assistance Listing Number: 84.425C, 84.425F Pass‐through Agency: Not Applicable Pass‐through Identification Number: Not Applicable Questioned Costs: $76,109 Condition: The University di...

2023‐009 (2022‐005) Procurement, Small Purchase (Significant Deficiency in Internal Controls over Compliance, Noncompliance, and Questioned Costs greater than $25k) Funding Agency: United States Department of Education Federal Award Agreement Number: N/A Award Year: 2023 Title: Education Stabilization Fund, HEERF Assistance Listing Number: 84.425C, 84.425F Pass‐through Agency: Not Applicable Pass‐through Identification Number: Not Applicable Questioned Costs: $76,109 Condition: The University did not apply the correct small purchase threshold for identifying purchases that need to obtain quotes in their policy. Population $10k‐$20k not included in small purchase policy included transactions totaling $76,109. Progress on resolution of prior year finding: No progress was made. Criteria: Per 2 CFR 200.303(a) requires non‐Federal entities to establish and maintain effective internal controls over compliance with Federal statutes, regulations, and the terms and conditions of grant agreements. 2 CFR 200.320(a) sets the micro‐purchase threshold at $10,000 and requires purchases over the micro‐purchase threshold to use small purchase procedures, whereby price or rate quotations must be obtained. Cause: Policies are not adequate to meet federal guidelines and need to be updated. Effect: The University may unintentionally use a higher‐cost vendor when failing to obtain price or rate quotations for items over the micro‐purchase threshold.

FY End: 2023-06-30
Womenventure
Compliance Requirement: L
Finding - Reporting: Microloan Program, #59.046, Technical Assistance Grant. June 2023 Award Year, U.S. Small Business Administration Criteria or Specific Requirement Non-federal entities receiving federal awards must establish and maintain internal controls over the federal awards that provides reasonable assurance that the non-federal entity is managing the federal awards in compliance with the federal statutes, regulations, and the terms and conditions of the federal awards (2 CFR Section 200...

Finding - Reporting: Microloan Program, #59.046, Technical Assistance Grant. June 2023 Award Year, U.S. Small Business Administration Criteria or Specific Requirement Non-federal entities receiving federal awards must establish and maintain internal controls over the federal awards that provides reasonable assurance that the non-federal entity is managing the federal awards in compliance with the federal statutes, regulations, and the terms and conditions of the federal awards (2 CFR Section 200.303) Condition and Context Two quarterly reports and SF-425 reports were tested for the Microloan Technical Assistance grant. We noted that the CFO was preparing and signing the reports, but supervisory review of the completed reports was not performed prior to submission to the Small Business Administration. We did note that the underlying general ledger data that is used for preparing these reports is recorded by accounting staff and the data is reviewed by the CFO. Cause Staff turnover and shortages caused difficulty in segregating the preparation and review of the reports. Effect or Potential Effect Misstatements in the reports could go undetected. Questioned Costs None noted. Identification as a Repeat Finding Not a repeat finding. Recommendation We recommend procedures be implemented to include a supervisory review of reports to assure accuracy and completeness of the data and information included in the reports. Views of Responsible Officials and Planned Corrective Actions See corrective action plan.

FY End: 2023-06-30
Eastern Oregon University
Compliance Requirement: E
Criteria or specific requirement: The amount of a student's Pell Grant for an academic year is based upon the payment and disbursement schedules published by the Secretary for each award year (34 CFR 690.62). The Code of Federal Regulations (34 CFR 690.80(b)(1)) states if the student’s enrollment status changes from one academic term to another within the same award year, the institution shall recalculate the Federal Pell Grant award for the new payment period taking into account any changes in ...

Criteria or specific requirement: The amount of a student's Pell Grant for an academic year is based upon the payment and disbursement schedules published by the Secretary for each award year (34 CFR 690.62). The Code of Federal Regulations (34 CFR 690.80(b)(1)) states if the student’s enrollment status changes from one academic term to another within the same award year, the institution shall recalculate the Federal Pell Grant award for the new payment period taking into account any changes in the cost of attendance. Uniform Grant Guidance (2 CFR 200.303) requires nonfederal entities receiving Federal awards establish and maintain internal controls designed to reasonably ensure compliance with Federal laws, regulations, and program compliance requirements. Effective internal controls should include procedures to ensure students are awarded and disbursed the proper federal fund amounts. Condition: During our testing of disbursements to eligible students, we noted one instance of a Pell award not being properly disbursed. Questioned costs: None reported. Context: In our eligibility sample of 40, one student was not properly disbursed their Pell award. Student was enrolled half-time for fall and winter, and less-than-half time for spring. Student only received a disbursement in fall. Cause: The students award was based on full-time enrollment level, but the student was only enrolled half-time in fall and winter. Pell recalculation was not performed for this student, and remaining aid was not paid. Effect: A student did not receive all their Pell Grant Aid. Repeat Finding: No. Recommendation: We recommend the University review the current procedures for awarding Title IV funds and implement changes necessary to ensure federal funds are awarded and disbursed in accordance with federal regulations. View of Responsible Official: The University agrees with the finding.

FY End: 2023-06-30
Eastern Oregon University
Compliance Requirement: N
Criteria or specific requirement: The Code of Federal Regulations, 34 CFR 682.610, states that institutions must report accurately the enrollment status of all students regardless of if they receive aid from the institution or not. Changes to said status are required to be reported within 30 days of becoming aware of the status change, or with the next scheduled transmission of statuses if the scheduled transmission is within 60 days. In addition, per the Uniform Guidance 2 CRF 200.303, nonfeder...

Criteria or specific requirement: The Code of Federal Regulations, 34 CFR 682.610, states that institutions must report accurately the enrollment status of all students regardless of if they receive aid from the institution or not. Changes to said status are required to be reported within 30 days of becoming aware of the status change, or with the next scheduled transmission of statuses if the scheduled transmission is within 60 days. In addition, per the Uniform Guidance 2 CRF 200.303, nonfederal entities receiving federal awards are required to establish and maintain internal controls designed to reasonable ensure compliance with federal laws, regulations, and program compliance requirements. Condition: During our enrollment reporting testing, we noted the University did not update student enrollment data correctly or timely. Questioned costs: None reported. Context: During our testing, we noted that the University did not accurately report to National Student Loan Data System (NSLDS) the enrollment status for 2 of the 40 students tested. The enrollment effective date of 6 of the 40 students tested was not reported correctly to NSLDS. The status change of 28 of the 40 students tested was not reported timely to NSLDS. The enrollment was not certified every 60 days for 1 of the 40 students tested. The program enrollment effective date of 3 of 40 students tested did not match the institutions records. The program enrollment status of 2 of 40 students tested did not match the status per the institution. Cause: The University did accurately report student status changes to NSLDS through their third-party servicer, National Student Clearinghouse (NSC). Additionally, NSC did not report all status changes timely which caused the University to not meet the requirements. Effect: Failure to properly report enrollment status changes on NSLDS could affect the timing of the grace period for repayment of Title IV loans. Additionally, the University was not in compliance with the requirements to properly report student enrollment data correctly or timely to NSLDS. Repeat Finding: No. Recommendation: We recommend that the University implement procedures to ensure that enrollment data, changes in status and effective dates within NSLDS match the records of the institution and are reported timely. View of Responsible Official: The University agrees with the finding.

FY End: 2023-06-30
Eastern Oregon University
Compliance Requirement: N
Criteria or specific requirement: The Code of Federal Regulations, 34 CFR 682.610, states that institutions must report accurately the enrollment status of all students regardless of if they receive aid from the institution or not. Changes to said status are required to be reported within 30 days of becoming aware of the status change, or with the next scheduled transmission of statuses if the scheduled transmission is within 60 days. In addition, per the Uniform Guidance 2 CRF 200.303, nonfeder...

Criteria or specific requirement: The Code of Federal Regulations, 34 CFR 682.610, states that institutions must report accurately the enrollment status of all students regardless of if they receive aid from the institution or not. Changes to said status are required to be reported within 30 days of becoming aware of the status change, or with the next scheduled transmission of statuses if the scheduled transmission is within 60 days. In addition, per the Uniform Guidance 2 CRF 200.303, nonfederal entities receiving federal awards are required to establish and maintain internal controls designed to reasonable ensure compliance with federal laws, regulations, and program compliance requirements. Condition: During our enrollment reporting testing, we noted the University did not update student enrollment data correctly or timely. Questioned costs: None reported. Context: During our testing, we noted that the University did not accurately report to National Student Loan Data System (NSLDS) the enrollment status for 2 of the 40 students tested. The enrollment effective date of 6 of the 40 students tested was not reported correctly to NSLDS. The status change of 28 of the 40 students tested was not reported timely to NSLDS. The enrollment was not certified every 60 days for 1 of the 40 students tested. The program enrollment effective date of 3 of 40 students tested did not match the institutions records. The program enrollment status of 2 of 40 students tested did not match the status per the institution. Cause: The University did accurately report student status changes to NSLDS through their third-party servicer, National Student Clearinghouse (NSC). Additionally, NSC did not report all status changes timely which caused the University to not meet the requirements. Effect: Failure to properly report enrollment status changes on NSLDS could affect the timing of the grace period for repayment of Title IV loans. Additionally, the University was not in compliance with the requirements to properly report student enrollment data correctly or timely to NSLDS. Repeat Finding: No. Recommendation: We recommend that the University implement procedures to ensure that enrollment data, changes in status and effective dates within NSLDS match the records of the institution and are reported timely. View of Responsible Official: The University agrees with the finding.

FY End: 2023-06-30
Eastern Oregon University
Compliance Requirement: N
Criteria or specific requirement: The Code of Federal Regulations, 34 CFR 682.610, states that institutions must report accurately the enrollment status of all students regardless of if they receive aid from the institution or not. Changes to said status are required to be reported within 30 days of becoming aware of the status change, or with the next scheduled transmission of statuses if the scheduled transmission is within 60 days. In addition, per the Uniform Guidance 2 CRF 200.303, nonfeder...

Criteria or specific requirement: The Code of Federal Regulations, 34 CFR 682.610, states that institutions must report accurately the enrollment status of all students regardless of if they receive aid from the institution or not. Changes to said status are required to be reported within 30 days of becoming aware of the status change, or with the next scheduled transmission of statuses if the scheduled transmission is within 60 days. In addition, per the Uniform Guidance 2 CRF 200.303, nonfederal entities receiving federal awards are required to establish and maintain internal controls designed to reasonable ensure compliance with federal laws, regulations, and program compliance requirements. Condition: During our enrollment reporting testing, we noted the University did not update student enrollment data correctly or timely. Questioned costs: None reported. Context: During our testing, we noted that the University did not accurately report to National Student Loan Data System (NSLDS) the enrollment status for 2 of the 40 students tested. The enrollment effective date of 6 of the 40 students tested was not reported correctly to NSLDS. The status change of 28 of the 40 students tested was not reported timely to NSLDS. The enrollment was not certified every 60 days for 1 of the 40 students tested. The program enrollment effective date of 3 of 40 students tested did not match the institutions records. The program enrollment status of 2 of 40 students tested did not match the status per the institution. Cause: The University did accurately report student status changes to NSLDS through their third-party servicer, National Student Clearinghouse (NSC). Additionally, NSC did not report all status changes timely which caused the University to not meet the requirements. Effect: Failure to properly report enrollment status changes on NSLDS could affect the timing of the grace period for repayment of Title IV loans. Additionally, the University was not in compliance with the requirements to properly report student enrollment data correctly or timely to NSLDS. Repeat Finding: No. Recommendation: We recommend that the University implement procedures to ensure that enrollment data, changes in status and effective dates within NSLDS match the records of the institution and are reported timely. View of Responsible Official: The University agrees with the finding.

FY End: 2023-06-30
Eastern Oregon University
Compliance Requirement: N
Criteria or specific requirement: The Code of Federal Regulations, 34 CFR 682.610, states that institutions must report accurately the enrollment status of all students regardless of if they receive aid from the institution or not. Changes to said status are required to be reported within 30 days of becoming aware of the status change, or with the next scheduled transmission of statuses if the scheduled transmission is within 60 days. In addition, per the Uniform Guidance 2 CRF 200.303, nonfeder...

Criteria or specific requirement: The Code of Federal Regulations, 34 CFR 682.610, states that institutions must report accurately the enrollment status of all students regardless of if they receive aid from the institution or not. Changes to said status are required to be reported within 30 days of becoming aware of the status change, or with the next scheduled transmission of statuses if the scheduled transmission is within 60 days. In addition, per the Uniform Guidance 2 CRF 200.303, nonfederal entities receiving federal awards are required to establish and maintain internal controls designed to reasonable ensure compliance with federal laws, regulations, and program compliance requirements. Condition: During our enrollment reporting testing, we noted the University did not update student enrollment data correctly or timely. Questioned costs: None reported. Context: During our testing, we noted that the University did not accurately report to National Student Loan Data System (NSLDS) the enrollment status for 2 of the 40 students tested. The enrollment effective date of 6 of the 40 students tested was not reported correctly to NSLDS. The status change of 28 of the 40 students tested was not reported timely to NSLDS. The enrollment was not certified every 60 days for 1 of the 40 students tested. The program enrollment effective date of 3 of 40 students tested did not match the institutions records. The program enrollment status of 2 of 40 students tested did not match the status per the institution. Cause: The University did accurately report student status changes to NSLDS through their third-party servicer, National Student Clearinghouse (NSC). Additionally, NSC did not report all status changes timely which caused the University to not meet the requirements. Effect: Failure to properly report enrollment status changes on NSLDS could affect the timing of the grace period for repayment of Title IV loans. Additionally, the University was not in compliance with the requirements to properly report student enrollment data correctly or timely to NSLDS. Repeat Finding: No. Recommendation: We recommend that the University implement procedures to ensure that enrollment data, changes in status and effective dates within NSLDS match the records of the institution and are reported timely. View of Responsible Official: The University agrees with the finding.

FY End: 2023-06-30
Eastern Oregon University
Compliance Requirement: N
Criteria or specific requirement: The Code of Federal Regulations, 34 CFR 682.610, states that institutions must report accurately the enrollment status of all students regardless of if they receive aid from the institution or not. Changes to said status are required to be reported within 30 days of becoming aware of the status change, or with the next scheduled transmission of statuses if the scheduled transmission is within 60 days. In addition, per the Uniform Guidance 2 CRF 200.303, nonfeder...

Criteria or specific requirement: The Code of Federal Regulations, 34 CFR 682.610, states that institutions must report accurately the enrollment status of all students regardless of if they receive aid from the institution or not. Changes to said status are required to be reported within 30 days of becoming aware of the status change, or with the next scheduled transmission of statuses if the scheduled transmission is within 60 days. In addition, per the Uniform Guidance 2 CRF 200.303, nonfederal entities receiving federal awards are required to establish and maintain internal controls designed to reasonable ensure compliance with federal laws, regulations, and program compliance requirements. Condition: During our enrollment reporting testing, we noted the University did not update student enrollment data correctly or timely. Questioned costs: None reported. Context: During our testing, we noted that the University did not accurately report to National Student Loan Data System (NSLDS) the enrollment status for 2 of the 40 students tested. The enrollment effective date of 6 of the 40 students tested was not reported correctly to NSLDS. The status change of 28 of the 40 students tested was not reported timely to NSLDS. The enrollment was not certified every 60 days for 1 of the 40 students tested. The program enrollment effective date of 3 of 40 students tested did not match the institutions records. The program enrollment status of 2 of 40 students tested did not match the status per the institution. Cause: The University did accurately report student status changes to NSLDS through their third-party servicer, National Student Clearinghouse (NSC). Additionally, NSC did not report all status changes timely which caused the University to not meet the requirements. Effect: Failure to properly report enrollment status changes on NSLDS could affect the timing of the grace period for repayment of Title IV loans. Additionally, the University was not in compliance with the requirements to properly report student enrollment data correctly or timely to NSLDS. Repeat Finding: No. Recommendation: We recommend that the University implement procedures to ensure that enrollment data, changes in status and effective dates within NSLDS match the records of the institution and are reported timely. View of Responsible Official: The University agrees with the finding.

FY End: 2023-06-30
Los Angeles Community College District
Compliance Requirement: E
Finding FA 2023-001: Eligibility: Incorrect Federal Pell Grant Amounts Awarded (Repeat Finding) Federal Program Information Assistance Listing Number: ALN 84.063 Federal Program Name: Student Financial Assistance Cluster. Federal Pell Grant Program Federal Agency: U.S. Department of Education Passed Through Entity: N/A Federal Award Number: P063P200033 (Steve to Confirm) Federal Award Year: July 1, 2022, to June 30, 2023 Campus: West Los Angeles College Compliance Requirement: Eligibility Cri...

Finding FA 2023-001: Eligibility: Incorrect Federal Pell Grant Amounts Awarded (Repeat Finding) Federal Program Information Assistance Listing Number: ALN 84.063 Federal Program Name: Student Financial Assistance Cluster. Federal Pell Grant Program Federal Agency: U.S. Department of Education Passed Through Entity: N/A Federal Award Number: P063P200033 (Steve to Confirm) Federal Award Year: July 1, 2022, to June 30, 2023 Campus: West Los Angeles College Compliance Requirement: Eligibility Criteria or Specific Requirement: Per 34 Code of Federal Regulations (CFR) 690.62 Calculation of a Federal Pell Grant, the amount of a student’s Pell Grant for an academic year is based upon the payment and disbursement schedules published by the Secretary for each award year. The Uniform Guidance Compliance Supplement states that the Department of Education provides institutions with Payment and Disbursement Schedules for determining Pell awards each year. The Payment or Disbursement Schedule provides the maximum annual amount a student would receive for a full academic year for a given enrollment status, Expected Family Contribution (EFC), and Cost of Attendance (COA). The Payment Schedule is used to determine the annual award for full-time, three-quarter-time, half-time, and less-than-half-time students. 2 CFR section 200.303 requires that non-Federal entities receiving Federal awards establish and maintain internal control over the Federal awards that provide reasonable assurance that the non-Federal entity is managing the Federal awards in compliance with Federal statutes, regulations, and the terms and conditions of the Federal awards. Identified Condition: Of the twenty (20) students selected for eligibility test work at West Los Angeles College, we noted the following: • 1 student had an incorrectly calculated Federal Pell Grant award, which resulted in an understatement of the disbursement to the student by $773. The student was eligible to receive $1,273 yet received $500 in Winter 2023. Cause and Effect: The institution has reviewed the student’s award and determined that the student was inadvertently disbursed $500 instead of $1,273 which is considered to be an underpayment. Once identified by the auditors, the award has since been corrected and refunded to the student. The Central Financial Aid Systems Unit and the District’s Student Information System (SIS) Information Technology department have reviewed both system controls and manual intervention, but the cause remains undetermined. Questioned Costs: See schedule of findings and questioned costs The District has a known net understatement of Pell Grant award disbursements of ($773). The projected total net understatement of the Pell Grant award disbursements is $186,345 as follows: See schedule of findings and questioned costs This is computed by dividing the error found in the samples per term (Fall/Winter term – net underpayment ($773) and Spring/Summer terms – $0) over the total Pell awards disbursed in the sample size per term (Winter term – $64,577, and Spring/Summer terms – $81,046) multiplied by the total Pell awards disbursed for the identified colleges per term (Fall/Winter term – $15,567,394 and Spring/Summer terms – $14,958,472). The computation is made on a per-term basis on a campus level and not on a district-wide level. Recommendation: We recommend that the District make the necessary system modifications to the PeopleSoft SIS to ensure student awards are properly calculated. This will help ensure that Federal Pell grants are properly awarded to students who meet the eligibility requirements. Views of Responsible Officials and Planned Corrective Actions: The District believes this error was an isolated incident and the effect is minimal as we performed an extensive review of all nine campuses’ Pell grant award disbursements for the term and found that this was the only similar award. The District will monitor disbursements and will perform reconciliation on a monthly basis. Personnel Responsible for Implementation: FA Office and the Central Financial Aid Unit. Position of Responsible Personnel: FA Managers Expected Date of Implementation: Already Implemented

FY End: 2023-06-30
Calumet College of St. Joseph
Compliance Requirement: N
Criteria: 2 CFR 200.303(a) requires that “the non-Federal entity must establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of th...

Criteria: 2 CFR 200.303(a) requires that “the non-Federal entity must establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework,” issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO).” The Program Participation Agreement (PPA) with the United States Department of Education requires the institution to comply with the Standards for Safeguarding Customer Information as described in 16 CFR Part 314 which includes the development of a comprehensive written security program that includes the following parts: • 16 CFR 314.4(a) requires institutions to designate a qualified individual responsible for overseeing and implementing the institution’s information security program and enforcing the information security program. • 16 CFR 314.4(b) requires institutions to provide for the information security program to be based on a risk assessment that identifies reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of customer information (as the term customer information applies to the institution) that could result in the unauthorized disclosure, misuse, alteration, destruction, or other compromise of such information, and assesses the sufficiency of any safeguards in place to control these risks. • 16 CFR 314.4(c) requires institutions to provide for the design and implementation of safeguards to control the risks the institution provides through its risk assessment. • 16 CFR 314.4(d) requires institutions to regularly test or otherwise monitor the effectiveness of the safeguards it has implemented. • 16 CFR 314.4(e) requires institutions to develop policies and procedures to ensure that personnel are able to enact the information security program. • 16 CFR 314.4(f) requires institutions to develop policies and procedures to oversee its information system service providers. Condition: The institution’s written information security program did not include the following elements required by regulation as agreed to in the Program Participation Agreement: • The written information security program does not designate an individual responsible for overseeing and implementing the institution’s information security program or enforcing the information security program. • The institution has performed a risk assessment utilizing internal resources but has not based the information security program on the results of this assessment, nor has the institution included all required elements of internal and external risks to the security, confidentiality, or integrity of customer information. The institution’s risk assessment is missing an inventory of IT systems that process and store customer information and the compliance with information security elements related to multifactor authentication, access control, change management, logging and alerting and encryption. • The institution has not identified, designed or implemented safeguards for all of the risks identified in the risk assessment. The safeguards do not include the identification of security events or detection and response capabilities to support incident response. • The institution has not been able to test safeguards because safeguards have not been designed or implemented in response to the risk assessment. • The institution has not developed written policies and procedures to ensure that personnel are able to enact the information security program. There is a lack of evidence of leadership being required to report to the board or an appropriate supervisory council to ensure those charged with governance are informed on the current state of the information security program. • The institution has not developed policies and procedures to oversee information service providers. Cause: The institution has not created or implemented a comprehensive information security policy. Effect: The absence of internal controls and policies and procedures could result in the unauthorized disclosure, misuse, alteration, destruction, or other compromise of student account information. Context: Under an institution’s Program Participation Agreement with the US Department of Education, schools must protect student financial aid information, with particular attention to information provided to institutions by the US Department of Education or otherwise obtained in support of the administration of federal student financial aid programs. Questioned Costs: There were no questioned costs identified. Repeat Finding: This is not a repeat finding. Recommendation: We recommend that the institution complete a comprehensive risk assessment, create a comprehensive information security policy based on that assessment, and implement those policies through the use of safeguards and other policies and procedures. Views of responsible officials: Management agrees with this finding. See corrective action plan.

FY End: 2023-06-30
Calumet College of St. Joseph
Compliance Requirement: N
Criteria: 2 CFR 200.303(a) requires that “the non-Federal entity must establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of th...

Criteria: 2 CFR 200.303(a) requires that “the non-Federal entity must establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework,” issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO).” The Program Participation Agreement (PPA) with the United States Department of Education requires the institution to comply with the Standards for Safeguarding Customer Information as described in 16 CFR Part 314 which includes the development of a comprehensive written security program that includes the following parts: • 16 CFR 314.4(a) requires institutions to designate a qualified individual responsible for overseeing and implementing the institution’s information security program and enforcing the information security program. • 16 CFR 314.4(b) requires institutions to provide for the information security program to be based on a risk assessment that identifies reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of customer information (as the term customer information applies to the institution) that could result in the unauthorized disclosure, misuse, alteration, destruction, or other compromise of such information, and assesses the sufficiency of any safeguards in place to control these risks. • 16 CFR 314.4(c) requires institutions to provide for the design and implementation of safeguards to control the risks the institution provides through its risk assessment. • 16 CFR 314.4(d) requires institutions to regularly test or otherwise monitor the effectiveness of the safeguards it has implemented. • 16 CFR 314.4(e) requires institutions to develop policies and procedures to ensure that personnel are able to enact the information security program. • 16 CFR 314.4(f) requires institutions to develop policies and procedures to oversee its information system service providers. Condition: The institution’s written information security program did not include the following elements required by regulation as agreed to in the Program Participation Agreement: • The written information security program does not designate an individual responsible for overseeing and implementing the institution’s information security program or enforcing the information security program. • The institution has performed a risk assessment utilizing internal resources but has not based the information security program on the results of this assessment, nor has the institution included all required elements of internal and external risks to the security, confidentiality, or integrity of customer information. The institution’s risk assessment is missing an inventory of IT systems that process and store customer information and the compliance with information security elements related to multifactor authentication, access control, change management, logging and alerting and encryption. • The institution has not identified, designed or implemented safeguards for all of the risks identified in the risk assessment. The safeguards do not include the identification of security events or detection and response capabilities to support incident response. • The institution has not been able to test safeguards because safeguards have not been designed or implemented in response to the risk assessment. • The institution has not developed written policies and procedures to ensure that personnel are able to enact the information security program. There is a lack of evidence of leadership being required to report to the board or an appropriate supervisory council to ensure those charged with governance are informed on the current state of the information security program. • The institution has not developed policies and procedures to oversee information service providers. Cause: The institution has not created or implemented a comprehensive information security policy. Effect: The absence of internal controls and policies and procedures could result in the unauthorized disclosure, misuse, alteration, destruction, or other compromise of student account information. Context: Under an institution’s Program Participation Agreement with the US Department of Education, schools must protect student financial aid information, with particular attention to information provided to institutions by the US Department of Education or otherwise obtained in support of the administration of federal student financial aid programs. Questioned Costs: There were no questioned costs identified. Repeat Finding: This is not a repeat finding. Recommendation: We recommend that the institution complete a comprehensive risk assessment, create a comprehensive information security policy based on that assessment, and implement those policies through the use of safeguards and other policies and procedures. Views of responsible officials: Management agrees with this finding. See corrective action plan.

FY End: 2023-06-30
Calumet College of St. Joseph
Compliance Requirement: N
Criteria: 2 CFR 200.303(a) requires that “the non-Federal entity must establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of th...

Criteria: 2 CFR 200.303(a) requires that “the non-Federal entity must establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework,” issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO).” The Program Participation Agreement (PPA) with the United States Department of Education requires the institution to comply with the Standards for Safeguarding Customer Information as described in 16 CFR Part 314 which includes the development of a comprehensive written security program that includes the following parts: • 16 CFR 314.4(a) requires institutions to designate a qualified individual responsible for overseeing and implementing the institution’s information security program and enforcing the information security program. • 16 CFR 314.4(b) requires institutions to provide for the information security program to be based on a risk assessment that identifies reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of customer information (as the term customer information applies to the institution) that could result in the unauthorized disclosure, misuse, alteration, destruction, or other compromise of such information, and assesses the sufficiency of any safeguards in place to control these risks. • 16 CFR 314.4(c) requires institutions to provide for the design and implementation of safeguards to control the risks the institution provides through its risk assessment. • 16 CFR 314.4(d) requires institutions to regularly test or otherwise monitor the effectiveness of the safeguards it has implemented. • 16 CFR 314.4(e) requires institutions to develop policies and procedures to ensure that personnel are able to enact the information security program. • 16 CFR 314.4(f) requires institutions to develop policies and procedures to oversee its information system service providers. Condition: The institution’s written information security program did not include the following elements required by regulation as agreed to in the Program Participation Agreement: • The written information security program does not designate an individual responsible for overseeing and implementing the institution’s information security program or enforcing the information security program. • The institution has performed a risk assessment utilizing internal resources but has not based the information security program on the results of this assessment, nor has the institution included all required elements of internal and external risks to the security, confidentiality, or integrity of customer information. The institution’s risk assessment is missing an inventory of IT systems that process and store customer information and the compliance with information security elements related to multifactor authentication, access control, change management, logging and alerting and encryption. • The institution has not identified, designed or implemented safeguards for all of the risks identified in the risk assessment. The safeguards do not include the identification of security events or detection and response capabilities to support incident response. • The institution has not been able to test safeguards because safeguards have not been designed or implemented in response to the risk assessment. • The institution has not developed written policies and procedures to ensure that personnel are able to enact the information security program. There is a lack of evidence of leadership being required to report to the board or an appropriate supervisory council to ensure those charged with governance are informed on the current state of the information security program. • The institution has not developed policies and procedures to oversee information service providers. Cause: The institution has not created or implemented a comprehensive information security policy. Effect: The absence of internal controls and policies and procedures could result in the unauthorized disclosure, misuse, alteration, destruction, or other compromise of student account information. Context: Under an institution’s Program Participation Agreement with the US Department of Education, schools must protect student financial aid information, with particular attention to information provided to institutions by the US Department of Education or otherwise obtained in support of the administration of federal student financial aid programs. Questioned Costs: There were no questioned costs identified. Repeat Finding: This is not a repeat finding. Recommendation: We recommend that the institution complete a comprehensive risk assessment, create a comprehensive information security policy based on that assessment, and implement those policies through the use of safeguards and other policies and procedures. Views of responsible officials: Management agrees with this finding. See corrective action plan.

FY End: 2023-06-30
Calumet College of St. Joseph
Compliance Requirement: N
Criteria: 2 CFR 200.303(a) requires that “the non-Federal entity must establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of th...

Criteria: 2 CFR 200.303(a) requires that “the non-Federal entity must establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework,” issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO).” The Program Participation Agreement (PPA) with the United States Department of Education requires the institution to comply with the Standards for Safeguarding Customer Information as described in 16 CFR Part 314 which includes the development of a comprehensive written security program that includes the following parts: • 16 CFR 314.4(a) requires institutions to designate a qualified individual responsible for overseeing and implementing the institution’s information security program and enforcing the information security program. • 16 CFR 314.4(b) requires institutions to provide for the information security program to be based on a risk assessment that identifies reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of customer information (as the term customer information applies to the institution) that could result in the unauthorized disclosure, misuse, alteration, destruction, or other compromise of such information, and assesses the sufficiency of any safeguards in place to control these risks. • 16 CFR 314.4(c) requires institutions to provide for the design and implementation of safeguards to control the risks the institution provides through its risk assessment. • 16 CFR 314.4(d) requires institutions to regularly test or otherwise monitor the effectiveness of the safeguards it has implemented. • 16 CFR 314.4(e) requires institutions to develop policies and procedures to ensure that personnel are able to enact the information security program. • 16 CFR 314.4(f) requires institutions to develop policies and procedures to oversee its information system service providers. Condition: The institution’s written information security program did not include the following elements required by regulation as agreed to in the Program Participation Agreement: • The written information security program does not designate an individual responsible for overseeing and implementing the institution’s information security program or enforcing the information security program. • The institution has performed a risk assessment utilizing internal resources but has not based the information security program on the results of this assessment, nor has the institution included all required elements of internal and external risks to the security, confidentiality, or integrity of customer information. The institution’s risk assessment is missing an inventory of IT systems that process and store customer information and the compliance with information security elements related to multifactor authentication, access control, change management, logging and alerting and encryption. • The institution has not identified, designed or implemented safeguards for all of the risks identified in the risk assessment. The safeguards do not include the identification of security events or detection and response capabilities to support incident response. • The institution has not been able to test safeguards because safeguards have not been designed or implemented in response to the risk assessment. • The institution has not developed written policies and procedures to ensure that personnel are able to enact the information security program. There is a lack of evidence of leadership being required to report to the board or an appropriate supervisory council to ensure those charged with governance are informed on the current state of the information security program. • The institution has not developed policies and procedures to oversee information service providers. Cause: The institution has not created or implemented a comprehensive information security policy. Effect: The absence of internal controls and policies and procedures could result in the unauthorized disclosure, misuse, alteration, destruction, or other compromise of student account information. Context: Under an institution’s Program Participation Agreement with the US Department of Education, schools must protect student financial aid information, with particular attention to information provided to institutions by the US Department of Education or otherwise obtained in support of the administration of federal student financial aid programs. Questioned Costs: There were no questioned costs identified. Repeat Finding: This is not a repeat finding. Recommendation: We recommend that the institution complete a comprehensive risk assessment, create a comprehensive information security policy based on that assessment, and implement those policies through the use of safeguards and other policies and procedures. Views of responsible officials: Management agrees with this finding. See corrective action plan.

FY End: 2023-06-30
Calumet College of St. Joseph
Compliance Requirement: N
Criteria: Per 34 CFR 685.309, Schools are required to accurately report enrollment information under the Direct Loan program via the NSLDS. Enrollment status changes for students should be reported to NSLDS within 30 days, or within 60 days if the student with the status change will be reported on a scheduled transmission within 60 days of the effective change in status, or the date of determination if the date of determination was determined after the withdrawal date. At a minimum, schools a...

Criteria: Per 34 CFR 685.309, Schools are required to accurately report enrollment information under the Direct Loan program via the NSLDS. Enrollment status changes for students should be reported to NSLDS within 30 days, or within 60 days if the student with the status change will be reported on a scheduled transmission within 60 days of the effective change in status, or the date of determination if the date of determination was determined after the withdrawal date. At a minimum, schools are required to certify enrollment every 60 days. The NSLDS Enrollment Reporting Guide further states that the information that is reported to the Department of Education should be accurate and timely. Per the NSLDS Enrollment Reporting Guide section 4.4.3, when a student withdraws during a term, the effective date for the withdrawn status is the withdrawal date used by the institution. In the case of a student who completes a term does not return for the next term, leaving the course of study uncompleted, the effective date of the withdrawn status is the final day of the term in which the student was last enrolled. The effective date for graduation status is the date that the school assigns to the completion/graduation. Uniform Guidance (2 CFR 200.303) requires nonfederal entities receiving Federal awards to establish and maintain internal controls designed to reasonably ensure compliance with Federal laws, regulations, and program compliance requirements. Effective internal controls should include procedures to ensure enrollment reporting is completed properly. Condition: During our testing of students that were disbursed financial aid during the 2022-2023 school year, there were 13 instances of students that withdrew or graduated during and after the Spring 2023 semester that were not reflected in the NSLDS within 60 days. RSM observed through Empower (student portal) and other internal reports (including transcripts) that these students should have shown statuses of graduated/withdrawn on their NSLDS reports as of the audit period. Additionally, we noted that the NSLDS report showed three students who withdrew from the College but the NSLDS reflected an incorrect Enrollment Effective date for both campus-level and program-level, as the students withdrew during March and April of the Spring 2023 semester but the campus-level enrollment effective date listed on the NSLDS report was May 5, 2023 (the last day of the Spring 2023 semester) while the program-level enrollment effective date listed was December 16, 2022. Cause: The institution did not properly report the Spring 2023 students with enrollment status changes to the Clearinghouse/NSLDS by leaving out the program level information, which created error codes that were not properly addressed by the institution. The dates reported for the three student withdraws was not correctly documented. Effect: The administration of the Title IV program depends heavily on the accuracy and timeliness of the enrollment information reported by institutions. Without accurate and timely NSLDS reporting there is a diminished ability for the Department of Education to properly administer the program. Context: 13 of the 13 status changes tested. In accordance with the OMB Compliance Supplement, our sample did not include any enrollment reporting data due from July 19, 2022 through February 28, 2023 in our evaluation of the enrollment reporting requirements due to the NSLDS system modernization. Our sample was not statistically valid. Questioned Costs: None. Repeat Finding: No. Recommendation: Management should review the controls and procedures in place to verify that accurate, timely, and complete data is being submitted to NSLDS. This should include separation of the preparation of data and review and completion of the submission, as well as additional methods to help identify errors. Views of responsible officials: Management agrees with this finding. See corrective action plan.

FY End: 2023-06-30
Catholic Community Services of the Mid-Willamette Valley, INC
Compliance Requirement: E
2023-003 Assistance Listing No. 14.239 HOME Investment Partnerships Program Criteria: 2 CFR Part 200.303 establishes internal control requirements over federal awards that provides reasonable assurance the entity is managing the federal award in compliance with Federal Statutes. Condition: The Organization contracted with a third party to determine eligibility of tenants. During the year, the third party failed to complete annual recertifications timely. Internal controls should be present t...

2023-003 Assistance Listing No. 14.239 HOME Investment Partnerships Program Criteria: 2 CFR Part 200.303 establishes internal control requirements over federal awards that provides reasonable assurance the entity is managing the federal award in compliance with Federal Statutes. Condition: The Organization contracted with a third party to determine eligibility of tenants. During the year, the third party failed to complete annual recertifications timely. Internal controls should be present to monitor the activities of the third party to ensure timely completion of recertifications. Cause: The Organization relied on a third-party provider to perform the work they were contracted to perform and did not implement internal controls to monitor the services provided to ensure they complied with Federal Statutes. Effect: Annual recertifications were not performed timely. Questioned Costs: None Recommendations: The Organization should implement internal controls to monitor the activities of third-party providers to ensure the services being provided are in compliance with Federal Statutes. Views of Responsible Officials and Planned Corrective Actions: See corrective action plan included in report.

FY End: 2023-06-30
Catholic Community Services of the Mid-Willamette Valley, INC
Compliance Requirement: E
2023-003 Assistance Listing No. 14.239 HOME Investment Partnerships Program Criteria: 2 CFR Part 200.303 establishes internal control requirements over federal awards that provides reasonable assurance the entity is managing the federal award in compliance with Federal Statutes. Condition: The Organization contracted with a third party to determine eligibility of tenants. During the year, the third party failed to complete annual recertifications timely. Internal controls should be present t...

2023-003 Assistance Listing No. 14.239 HOME Investment Partnerships Program Criteria: 2 CFR Part 200.303 establishes internal control requirements over federal awards that provides reasonable assurance the entity is managing the federal award in compliance with Federal Statutes. Condition: The Organization contracted with a third party to determine eligibility of tenants. During the year, the third party failed to complete annual recertifications timely. Internal controls should be present to monitor the activities of the third party to ensure timely completion of recertifications. Cause: The Organization relied on a third-party provider to perform the work they were contracted to perform and did not implement internal controls to monitor the services provided to ensure they complied with Federal Statutes. Effect: Annual recertifications were not performed timely. Questioned Costs: None Recommendations: The Organization should implement internal controls to monitor the activities of third-party providers to ensure the services being provided are in compliance with Federal Statutes. Views of Responsible Officials and Planned Corrective Actions: See corrective action plan included in report.

FY End: 2023-06-30
Catholic Community Services of the Mid-Willamette Valley, INC
Compliance Requirement: E
2023-003 Assistance Listing No. 14.239 HOME Investment Partnerships Program Criteria: 2 CFR Part 200.303 establishes internal control requirements over federal awards that provides reasonable assurance the entity is managing the federal award in compliance with Federal Statutes. Condition: The Organization contracted with a third party to determine eligibility of tenants. During the year, the third party failed to complete annual recertifications timely. Internal controls should be present t...

2023-003 Assistance Listing No. 14.239 HOME Investment Partnerships Program Criteria: 2 CFR Part 200.303 establishes internal control requirements over federal awards that provides reasonable assurance the entity is managing the federal award in compliance with Federal Statutes. Condition: The Organization contracted with a third party to determine eligibility of tenants. During the year, the third party failed to complete annual recertifications timely. Internal controls should be present to monitor the activities of the third party to ensure timely completion of recertifications. Cause: The Organization relied on a third-party provider to perform the work they were contracted to perform and did not implement internal controls to monitor the services provided to ensure they complied with Federal Statutes. Effect: Annual recertifications were not performed timely. Questioned Costs: None Recommendations: The Organization should implement internal controls to monitor the activities of third-party providers to ensure the services being provided are in compliance with Federal Statutes. Views of Responsible Officials and Planned Corrective Actions: See corrective action plan included in report.

« 1 840 841 843 844 2002 »