2023-066: Continue Developing Record Retention Requirements and Processes for Electronic Records Applicable to: Department of Social Services Prior Year Finding Number: 2022-064; 2021-047; 2020-041; 2019-049; 2018-054 Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: Contingency Planning ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 Federal Award Number and Year: 2305VA5MAP - 2023 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Social Services continues to operate without an adequate data retention process that ensures consistent compliance with retention requirements for its case management system and adherence to federal regulations and the Code of Virginia. Specifically, Social Services does not have data retention policies and procedures that define its requirements and processes to consistently ensure data retention compliance and destruction. Social Services’ case management system stores several types of federal benefit program records with varying retention requirements supporting ten programs and services, such as Medicaid, TANF, and the Supplemental Nutrition Assistance Program (SNAP). Social Services’ case management system authorized over $17 billion in public assistance payments to beneficiaries from these federal programs during fiscal year 2023. Since fiscal year 2019, Social Services gathered retention requirements from the business divisions that support the federal programs and services. In fiscal year 2022, Social Services finalized and documented policies with retention requirements for the data sets handled by each of the ten programs and services supported by its case management system. However, Social Services has not developed, documented, and implemented procedures and processes to operationalize the records retention policies for each of the programs and services to ensure consistent retention and destruction of records in compliance with regulations and laws. Title 45 CFR § 155.1210, governs record retention for Medicaid and requires state agencies to maintain records for ten years. Additionally, the Virginia Public Records Act outlined in § 42.1-91 of the Code of Virginia makes an agency responsible for ensuring that it preserves, maintains, and makes accessible public records throughout their lifecycle, including converting and migrating electronic records as often as necessary so that information is not lost due to hardware, software, or media obsolescence or deterioration. Furthermore, the Virginia Public Records Act in § 42.1-86.1 of the Code of Virginia details requirements for the disposition of records including that records created after July 1, 2006, and authorized to be destroyed or discarded, must be discarded in a timely manner and in accordance with the provisions of Chapter 7 of the Virginia Public Records Act. Records that contain identifying information as defined by subsection C of § 18.2-186.3 of the Code of Virginia shall be destroyed within six months of the expiration of the records retention period. Finally, the Security Standard requires agencies to implement backup and restoration plans that address the retention of the data in accordance with the records retention policy for every IT system identified as sensitive relative to availability (Security Standard, Section CP-9-COV Information System Backup). Without implementing records retention requirements, Social Services increases the risk of a data or privacy breach. Additionally, destroying documents that should be available for business processes or audit, or keeping data longer than stated, could expose Social Services to fines, penalties, or other legal consequences. Further, Social Services may not be able to ensure that backup and restoration efforts will provide mission essential information according to recovery times. Finally, Social Services spends additional resources to maintain, back up, and protect information that no longer serves a business purpose. Social Services determined that the retention requirements for all ten programs and services supported by its case management system are not feasible as a single release due to the risk and complexity of the project, as well as changes to federal requirements, since its initial analysis. Therefore, Social Services plans to use a phased delivery approach including multiple releases, beginning with Release 1 in February 2024. Further, Social Services is working on a revised timeline to complete each additional phase for the remaining releases. Social Services should continue to develop and implement records retention procedures that define its requirements and processes to ensure that consistent records retention processes can be operationalized across business divisions to comply with applicable with laws and regulations. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2023-072: Continue to Ensure ITISP Suppliers Meet all Contractual Requirements Applicable to: Virginia Information Technologies Agency Prior Year Finding Number: 2022-100; 2021-023; 2020-070 Type of Finding: Internal Control Severity of Deficiency: Significant Deficiency Information System Security Control Family: N/A ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 Federal Award Number and Year: 2305VA5MAP - 2023 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Although VITA is monitoring and enforcing the contractual requirements each month, as of June 2023, there were still cases of Information Technology Infrastructure Services Program (ITISP) suppliers not meeting the minimum requirements. When ITISP suppliers do not meet all contractual requirements (e.g., key measures, critical service levels, deliverables, etc.), it impacts the ability of Commonwealth agencies that rely on the ITISP services to comply with the Commonwealth’s Information Security Standard, SEC 501 (Security Standard). The Security Standard is a baseline for information security and risk management activities for Commonwealth agencies. Many agencies rely on services provided through ITISP suppliers to ensure compliance with the Security Standard. For example, the Security Standard requires the installation of security-relevant software updates within 90 days of release (Security Standard, Section SI-2 Flaw Remediation). Commonwealth agencies rely on the ITISP suppliers for the installation of security patches in systems that support agencies’ operations. Our audits at various agencies for fiscal year 2023 found critical and highly important security patches not installed within the 90-day Security Standard requirement. The systems missing critical security updates are at an increased risk of cyberattack, exploitation, and data breach by malicious parties. During fiscal year 2023, VITA and the Multisource Service Integrator (MSI) continued to evaluate the current service level measurements to ensure they align with the Commonwealth’s needs. VITA and the MSI implemented changes to the service level related to security and vulnerability patching. The changes to this service level included establishing a Common Vulnerabilities and Exposures (CVE) threshold, which required that ITISP suppliers must install any patch with a CVE score above the threshold within 60 days. VITA excluded the revised service level related to security and vulnerability patching from the monthly monitoring process until June 2023 to allow the agency, the MSI, and the ITISP suppliers time to develop procedures and data standardizations to accurately monitor compliance with the service level. VITA should ensure that the CVE score threshold is sufficient to meet the Security Standard requirements and to mitigate the risk associated with the Commonwealth’s information, data, and security. The Security Standard also requires agencies to review and analyze audit records at least every 30 days for indications of inappropriate or unusual activity (Security Standard, Section AU-6 Audit Review, Analysis, and Reporting). Our audits of various agencies for fiscal year 2023 found that agencies rely on ITISP suppliers to provide access to a centralized monitoring tool that collects audit log information about activities in the IT environment. Although the supplier was performing audit logging and monitoring, most agencies were unable to obtain access to the audit log information during fiscal year 2023, and thus, were not able to comply with the Security Standard requirements related to audit log monitoring. An inability for all agencies to review and monitor their individual audit logs, increases the risk associated with the Commonwealth’s data confidentiality, integrity and availability. During fiscal year 2023, VITA continued to work with the managed security supplier to address the agencies’ inability to access the audit log information. The supplier continued to implement the managed detection and response platform with a small number of agencies piloting the platform in 2023. As of October 2023, the supplier has opened the platform to all Commonwealth agencies. VITA should continue to work with the supplier to ensure all agencies have access to the platform, and all necessary audit logs are available for agency review. To ensure all agencies that rely on the ITISP services comply with the Security Standard, VITA should ensure suppliers meet all contractual requirements (e.g., key measures, critical service levels, deliverables, etc.). To aid in determining which requirements have Security Standard implications, VITA should crosswalk contractual requirements to the Security Standard. A crosswalk will help in identifying which requirements, if not met, could put an agency at risk, per the Security Standard. If VITA determines suppliers are not meeting any of these requirements, VITA should communicate with the affected agencies and provide guidance on what the agencies can do to comply with the Security Standard while the suppliers work to meet the requirements of the contract. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2023-072: Continue to Ensure ITISP Suppliers Meet all Contractual Requirements Applicable to: Virginia Information Technologies Agency Prior Year Finding Number: 2022-100; 2021-023; 2020-070 Type of Finding: Internal Control Severity of Deficiency: Significant Deficiency Information System Security Control Family: N/A ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 Federal Award Number and Year: 2305VA5MAP - 2023 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Although VITA is monitoring and enforcing the contractual requirements each month, as of June 2023, there were still cases of Information Technology Infrastructure Services Program (ITISP) suppliers not meeting the minimum requirements. When ITISP suppliers do not meet all contractual requirements (e.g., key measures, critical service levels, deliverables, etc.), it impacts the ability of Commonwealth agencies that rely on the ITISP services to comply with the Commonwealth’s Information Security Standard, SEC 501 (Security Standard). The Security Standard is a baseline for information security and risk management activities for Commonwealth agencies. Many agencies rely on services provided through ITISP suppliers to ensure compliance with the Security Standard. For example, the Security Standard requires the installation of security-relevant software updates within 90 days of release (Security Standard, Section SI-2 Flaw Remediation). Commonwealth agencies rely on the ITISP suppliers for the installation of security patches in systems that support agencies’ operations. Our audits at various agencies for fiscal year 2023 found critical and highly important security patches not installed within the 90-day Security Standard requirement. The systems missing critical security updates are at an increased risk of cyberattack, exploitation, and data breach by malicious parties. During fiscal year 2023, VITA and the Multisource Service Integrator (MSI) continued to evaluate the current service level measurements to ensure they align with the Commonwealth’s needs. VITA and the MSI implemented changes to the service level related to security and vulnerability patching. The changes to this service level included establishing a Common Vulnerabilities and Exposures (CVE) threshold, which required that ITISP suppliers must install any patch with a CVE score above the threshold within 60 days. VITA excluded the revised service level related to security and vulnerability patching from the monthly monitoring process until June 2023 to allow the agency, the MSI, and the ITISP suppliers time to develop procedures and data standardizations to accurately monitor compliance with the service level. VITA should ensure that the CVE score threshold is sufficient to meet the Security Standard requirements and to mitigate the risk associated with the Commonwealth’s information, data, and security. The Security Standard also requires agencies to review and analyze audit records at least every 30 days for indications of inappropriate or unusual activity (Security Standard, Section AU-6 Audit Review, Analysis, and Reporting). Our audits of various agencies for fiscal year 2023 found that agencies rely on ITISP suppliers to provide access to a centralized monitoring tool that collects audit log information about activities in the IT environment. Although the supplier was performing audit logging and monitoring, most agencies were unable to obtain access to the audit log information during fiscal year 2023, and thus, were not able to comply with the Security Standard requirements related to audit log monitoring. An inability for all agencies to review and monitor their individual audit logs, increases the risk associated with the Commonwealth’s data confidentiality, integrity and availability. During fiscal year 2023, VITA continued to work with the managed security supplier to address the agencies’ inability to access the audit log information. The supplier continued to implement the managed detection and response platform with a small number of agencies piloting the platform in 2023. As of October 2023, the supplier has opened the platform to all Commonwealth agencies. VITA should continue to work with the supplier to ensure all agencies have access to the platform, and all necessary audit logs are available for agency review. To ensure all agencies that rely on the ITISP services comply with the Security Standard, VITA should ensure suppliers meet all contractual requirements (e.g., key measures, critical service levels, deliverables, etc.). To aid in determining which requirements have Security Standard implications, VITA should crosswalk contractual requirements to the Security Standard. A crosswalk will help in identifying which requirements, if not met, could put an agency at risk, per the Security Standard. If VITA determines suppliers are not meeting any of these requirements, VITA should communicate with the affected agencies and provide guidance on what the agencies can do to comply with the Security Standard while the suppliers work to meet the requirements of the contract. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2023-072: Continue to Ensure ITISP Suppliers Meet all Contractual Requirements Applicable to: Virginia Information Technologies Agency Prior Year Finding Number: 2022-100; 2021-023; 2020-070 Type of Finding: Internal Control Severity of Deficiency: Significant Deficiency Information System Security Control Family: N/A ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 Federal Award Number and Year: 2305VA5MAP - 2023 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Although VITA is monitoring and enforcing the contractual requirements each month, as of June 2023, there were still cases of Information Technology Infrastructure Services Program (ITISP) suppliers not meeting the minimum requirements. When ITISP suppliers do not meet all contractual requirements (e.g., key measures, critical service levels, deliverables, etc.), it impacts the ability of Commonwealth agencies that rely on the ITISP services to comply with the Commonwealth’s Information Security Standard, SEC 501 (Security Standard). The Security Standard is a baseline for information security and risk management activities for Commonwealth agencies. Many agencies rely on services provided through ITISP suppliers to ensure compliance with the Security Standard. For example, the Security Standard requires the installation of security-relevant software updates within 90 days of release (Security Standard, Section SI-2 Flaw Remediation). Commonwealth agencies rely on the ITISP suppliers for the installation of security patches in systems that support agencies’ operations. Our audits at various agencies for fiscal year 2023 found critical and highly important security patches not installed within the 90-day Security Standard requirement. The systems missing critical security updates are at an increased risk of cyberattack, exploitation, and data breach by malicious parties. During fiscal year 2023, VITA and the Multisource Service Integrator (MSI) continued to evaluate the current service level measurements to ensure they align with the Commonwealth’s needs. VITA and the MSI implemented changes to the service level related to security and vulnerability patching. The changes to this service level included establishing a Common Vulnerabilities and Exposures (CVE) threshold, which required that ITISP suppliers must install any patch with a CVE score above the threshold within 60 days. VITA excluded the revised service level related to security and vulnerability patching from the monthly monitoring process until June 2023 to allow the agency, the MSI, and the ITISP suppliers time to develop procedures and data standardizations to accurately monitor compliance with the service level. VITA should ensure that the CVE score threshold is sufficient to meet the Security Standard requirements and to mitigate the risk associated with the Commonwealth’s information, data, and security. The Security Standard also requires agencies to review and analyze audit records at least every 30 days for indications of inappropriate or unusual activity (Security Standard, Section AU-6 Audit Review, Analysis, and Reporting). Our audits of various agencies for fiscal year 2023 found that agencies rely on ITISP suppliers to provide access to a centralized monitoring tool that collects audit log information about activities in the IT environment. Although the supplier was performing audit logging and monitoring, most agencies were unable to obtain access to the audit log information during fiscal year 2023, and thus, were not able to comply with the Security Standard requirements related to audit log monitoring. An inability for all agencies to review and monitor their individual audit logs, increases the risk associated with the Commonwealth’s data confidentiality, integrity and availability. During fiscal year 2023, VITA continued to work with the managed security supplier to address the agencies’ inability to access the audit log information. The supplier continued to implement the managed detection and response platform with a small number of agencies piloting the platform in 2023. As of October 2023, the supplier has opened the platform to all Commonwealth agencies. VITA should continue to work with the supplier to ensure all agencies have access to the platform, and all necessary audit logs are available for agency review. To ensure all agencies that rely on the ITISP services comply with the Security Standard, VITA should ensure suppliers meet all contractual requirements (e.g., key measures, critical service levels, deliverables, etc.). To aid in determining which requirements have Security Standard implications, VITA should crosswalk contractual requirements to the Security Standard. A crosswalk will help in identifying which requirements, if not met, could put an agency at risk, per the Security Standard. If VITA determines suppliers are not meeting any of these requirements, VITA should communicate with the affected agencies and provide guidance on what the agencies can do to comply with the Security Standard while the suppliers work to meet the requirements of the contract. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2023-085: Obtain, Review, and Document System and Organization Control Reports of Third-Party Service Providers Applicable to: Department of Social Services Prior Year Finding Number: 2022-089; 2021-019 Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: N/A ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 Federal Award Number and Year: 2305VA5MAP - 2023 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(a) Known Questioned Costs: $0 Social Services continues to not have sufficient internal controls over System and Organization Controls (SOC) reports of service providers. Social Services uses service providers to perform functions such as administering the Electronic Benefit Transfer (EBT) process for public assistance programs, processing public assistance program applications, and performing call center functions. SOC reports, specifically SOC 1, Type 2 reports, provide an independent description and evaluation of the operating effectiveness of service providers’ internal controls over financial processes and are a key tool in gaining an understanding of a service provider’s internal control environment and maintaining oversight over outsourced operations. Social Services did not obtain, review, or document its review of service provider SOC reports to identify deficiencies or determine whether the reports provided adequate coverage over operations during state fiscal year 2023. The CAPP Manual Topic 10305 requires agencies to have adequate interaction with service providers to appropriately understand the service provider’s internal control environment. Agencies must also maintain oversight over service providers to gain assurance over outsourced operations. Additionally, Section 1.1 of the Security Standard states that agency heads remain accountable for maintaining compliance with the Security Standard for information technology equipment, systems, and services procured from service providers, and that agencies must enforce the compliance requirements through documented agreements and oversight of the services provided. Finally, 2 CFR § 200.303(a) requires non-federal entities to establish and maintain effective internal control over the federal award that provides reasonable assurance that the non-federal entity is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award. Social Services shares responsibilities for reviewing SOC reports with VITA’s ECOS based on the type of SOC report. VITA obtains and reviews SOC 2 reports, which provide information on controls at service providers relevant to information system security, availability, processing integrity, and confidentiality or privacy. SOC 1 reports provide information on controls at the service providers relevant to Social Services’ internal control over financial reporting. Designated staff in Social Services programmatic areas, who the service provider’s services affect, should obtain and review SOC 1, Type 2 reports. Designated staff should communicate any complementary user entity controls to the Agency Risk Management and Internal Controls Standards (ARMICS) coordinator to ensure Social Services has properly designed and implemented the relevant controls. Additionally, designated staff should document their review of the SOC 1, Type 2 reports, noting if there were any deviations in controls, perform a review of the service provider management’s response to any exceptions noted, and document Social Services’ consideration of the significance of any deviations and their impact on Social Services’ operations. Social Services did not assign responsibility to a resource within the agency, knowledgeable of SOC reporting requirements, to develop an agency-wide policy to communicate expectations related to obtaining, reviewing, and documenting SOC 1, Type 2 reports for agency personnel to use when carrying out their programmatic responsibilities. As a result, the individuals responsible for obtaining and reviewing SOC 1, Type 2 reports misunderstood the services provided by ECOS, as ECOS does not obtain or review SOC 1, Type 2 reports, and did not have clear expectations as to what should be considered during their review of SOC 1, Type 2 reports. Without adequate policies and procedures over service providers’ operations, Social Services is unable to ensure its complementary user entity controls are sufficient to support their reliance on the service providers’ control design, implementation, and operating effectiveness. Additionally, Social Services is unable to address any internal control deficiencies and/or exceptions identified in the SOC reports. Social Services is increasing the risk that it will not detect a weakness in a service provider’s environment by not obtaining the necessary SOC reports timely or properly documenting its review of the reports. Social Services should obtain, review, and document SOC 1, Type 2 reports for its service providers that significantly affect its financial activity. As part of its corrective action, Social Services should assign responsibility to a knowledgeable resource within the agency to develop an office-wide policy that other divisions can use when reviewing and documenting SOC reports. Policies and procedures should comply with the requirements outlined in the CAPP Manual and Security Standard and include, but not be limited to, the timeframes for obtaining SOC reports from the service provider, documentation requirements for user entity complementary controls, the steps needed to address internal control deficiencies and/or exceptions found in reviews, and the responsible staff for any corrective actions necessary to mitigate the risk to the Commonwealth until the service provider corrects the deficiency. After developing an agency-wide policy, Social Services should communicate it to all individuals responsible for overseeing service provider operations to ensure compliance with federal and state regulations. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2023-085: Obtain, Review, and Document System and Organization Control Reports of Third-Party Service Providers Applicable to: Department of Social Services Prior Year Finding Number: 2022-089; 2021-019 Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: N/A ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 Federal Award Number and Year: 2305VA5MAP - 2023 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(a) Known Questioned Costs: $0 Social Services continues to not have sufficient internal controls over System and Organization Controls (SOC) reports of service providers. Social Services uses service providers to perform functions such as administering the Electronic Benefit Transfer (EBT) process for public assistance programs, processing public assistance program applications, and performing call center functions. SOC reports, specifically SOC 1, Type 2 reports, provide an independent description and evaluation of the operating effectiveness of service providers’ internal controls over financial processes and are a key tool in gaining an understanding of a service provider’s internal control environment and maintaining oversight over outsourced operations. Social Services did not obtain, review, or document its review of service provider SOC reports to identify deficiencies or determine whether the reports provided adequate coverage over operations during state fiscal year 2023. The CAPP Manual Topic 10305 requires agencies to have adequate interaction with service providers to appropriately understand the service provider’s internal control environment. Agencies must also maintain oversight over service providers to gain assurance over outsourced operations. Additionally, Section 1.1 of the Security Standard states that agency heads remain accountable for maintaining compliance with the Security Standard for information technology equipment, systems, and services procured from service providers, and that agencies must enforce the compliance requirements through documented agreements and oversight of the services provided. Finally, 2 CFR § 200.303(a) requires non-federal entities to establish and maintain effective internal control over the federal award that provides reasonable assurance that the non-federal entity is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award. Social Services shares responsibilities for reviewing SOC reports with VITA’s ECOS based on the type of SOC report. VITA obtains and reviews SOC 2 reports, which provide information on controls at service providers relevant to information system security, availability, processing integrity, and confidentiality or privacy. SOC 1 reports provide information on controls at the service providers relevant to Social Services’ internal control over financial reporting. Designated staff in Social Services programmatic areas, who the service provider’s services affect, should obtain and review SOC 1, Type 2 reports. Designated staff should communicate any complementary user entity controls to the Agency Risk Management and Internal Controls Standards (ARMICS) coordinator to ensure Social Services has properly designed and implemented the relevant controls. Additionally, designated staff should document their review of the SOC 1, Type 2 reports, noting if there were any deviations in controls, perform a review of the service provider management’s response to any exceptions noted, and document Social Services’ consideration of the significance of any deviations and their impact on Social Services’ operations. Social Services did not assign responsibility to a resource within the agency, knowledgeable of SOC reporting requirements, to develop an agency-wide policy to communicate expectations related to obtaining, reviewing, and documenting SOC 1, Type 2 reports for agency personnel to use when carrying out their programmatic responsibilities. As a result, the individuals responsible for obtaining and reviewing SOC 1, Type 2 reports misunderstood the services provided by ECOS, as ECOS does not obtain or review SOC 1, Type 2 reports, and did not have clear expectations as to what should be considered during their review of SOC 1, Type 2 reports. Without adequate policies and procedures over service providers’ operations, Social Services is unable to ensure its complementary user entity controls are sufficient to support their reliance on the service providers’ control design, implementation, and operating effectiveness. Additionally, Social Services is unable to address any internal control deficiencies and/or exceptions identified in the SOC reports. Social Services is increasing the risk that it will not detect a weakness in a service provider’s environment by not obtaining the necessary SOC reports timely or properly documenting its review of the reports. Social Services should obtain, review, and document SOC 1, Type 2 reports for its service providers that significantly affect its financial activity. As part of its corrective action, Social Services should assign responsibility to a knowledgeable resource within the agency to develop an office-wide policy that other divisions can use when reviewing and documenting SOC reports. Policies and procedures should comply with the requirements outlined in the CAPP Manual and Security Standard and include, but not be limited to, the timeframes for obtaining SOC reports from the service provider, documentation requirements for user entity complementary controls, the steps needed to address internal control deficiencies and/or exceptions found in reviews, and the responsible staff for any corrective actions necessary to mitigate the risk to the Commonwealth until the service provider corrects the deficiency. After developing an agency-wide policy, Social Services should communicate it to all individuals responsible for overseeing service provider operations to ensure compliance with federal and state regulations. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2023-085: Obtain, Review, and Document System and Organization Control Reports of Third-Party Service Providers Applicable to: Department of Social Services Prior Year Finding Number: 2022-089; 2021-019 Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: N/A ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 Federal Award Number and Year: 2305VA5MAP - 2023 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(a) Known Questioned Costs: $0 Social Services continues to not have sufficient internal controls over System and Organization Controls (SOC) reports of service providers. Social Services uses service providers to perform functions such as administering the Electronic Benefit Transfer (EBT) process for public assistance programs, processing public assistance program applications, and performing call center functions. SOC reports, specifically SOC 1, Type 2 reports, provide an independent description and evaluation of the operating effectiveness of service providers’ internal controls over financial processes and are a key tool in gaining an understanding of a service provider’s internal control environment and maintaining oversight over outsourced operations. Social Services did not obtain, review, or document its review of service provider SOC reports to identify deficiencies or determine whether the reports provided adequate coverage over operations during state fiscal year 2023. The CAPP Manual Topic 10305 requires agencies to have adequate interaction with service providers to appropriately understand the service provider’s internal control environment. Agencies must also maintain oversight over service providers to gain assurance over outsourced operations. Additionally, Section 1.1 of the Security Standard states that agency heads remain accountable for maintaining compliance with the Security Standard for information technology equipment, systems, and services procured from service providers, and that agencies must enforce the compliance requirements through documented agreements and oversight of the services provided. Finally, 2 CFR § 200.303(a) requires non-federal entities to establish and maintain effective internal control over the federal award that provides reasonable assurance that the non-federal entity is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award. Social Services shares responsibilities for reviewing SOC reports with VITA’s ECOS based on the type of SOC report. VITA obtains and reviews SOC 2 reports, which provide information on controls at service providers relevant to information system security, availability, processing integrity, and confidentiality or privacy. SOC 1 reports provide information on controls at the service providers relevant to Social Services’ internal control over financial reporting. Designated staff in Social Services programmatic areas, who the service provider’s services affect, should obtain and review SOC 1, Type 2 reports. Designated staff should communicate any complementary user entity controls to the Agency Risk Management and Internal Controls Standards (ARMICS) coordinator to ensure Social Services has properly designed and implemented the relevant controls. Additionally, designated staff should document their review of the SOC 1, Type 2 reports, noting if there were any deviations in controls, perform a review of the service provider management’s response to any exceptions noted, and document Social Services’ consideration of the significance of any deviations and their impact on Social Services’ operations. Social Services did not assign responsibility to a resource within the agency, knowledgeable of SOC reporting requirements, to develop an agency-wide policy to communicate expectations related to obtaining, reviewing, and documenting SOC 1, Type 2 reports for agency personnel to use when carrying out their programmatic responsibilities. As a result, the individuals responsible for obtaining and reviewing SOC 1, Type 2 reports misunderstood the services provided by ECOS, as ECOS does not obtain or review SOC 1, Type 2 reports, and did not have clear expectations as to what should be considered during their review of SOC 1, Type 2 reports. Without adequate policies and procedures over service providers’ operations, Social Services is unable to ensure its complementary user entity controls are sufficient to support their reliance on the service providers’ control design, implementation, and operating effectiveness. Additionally, Social Services is unable to address any internal control deficiencies and/or exceptions identified in the SOC reports. Social Services is increasing the risk that it will not detect a weakness in a service provider’s environment by not obtaining the necessary SOC reports timely or properly documenting its review of the reports. Social Services should obtain, review, and document SOC 1, Type 2 reports for its service providers that significantly affect its financial activity. As part of its corrective action, Social Services should assign responsibility to a knowledgeable resource within the agency to develop an office-wide policy that other divisions can use when reviewing and documenting SOC reports. Policies and procedures should comply with the requirements outlined in the CAPP Manual and Security Standard and include, but not be limited to, the timeframes for obtaining SOC reports from the service provider, documentation requirements for user entity complementary controls, the steps needed to address internal control deficiencies and/or exceptions found in reviews, and the responsible staff for any corrective actions necessary to mitigate the risk to the Commonwealth until the service provider corrects the deficiency. After developing an agency-wide policy, Social Services should communicate it to all individuals responsible for overseeing service provider operations to ensure compliance with federal and state regulations. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2023-086: Improve Third-Party Oversight Process Applicable to: Department of Medical Assistance Services Prior Year Finding Number: 2022-090 Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: N/A ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 Federal Award Number and Year: 2305VA5MAP - 2023 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Medical Assistance Services has made progress to document and implement a formal process for maintaining oversight for three of its IT third-party service providers that manage and support the Medicaid management system. However, Medical Assistance Services continues to not verify that one of its three service providers performs two controls as required by the Hosted Environment Security Standard. We communicated the two weaknesses to management in a separate document marked FOIAE under § 2.2-3705.2 of the Code of Virginia due to it containing descriptions of security mechanisms. VITA’s Enterprise Cloud Oversight Service (ECOS) confirms the two controls as part of its service for two of the three service providers; however, ECOS does not review the third service provider, and it is Medical Assistance Services’ responsibility to verify the provider performs the required controls. Medical Assistance Services did not ensure the individuals responsible for monitoring the service providers are confirming these specific controls and processes within the required timeframe. Without maintaining appropriate oversight of its service providers, Medical Assistance Services cannot validate whether its service providers implement the required security controls to protect the agency’s sensitive and mission-critical data. Medical Assistance Services should improve its process by ensuring individuals tasked with monitoring service providers confirm the controls per the Hosted Environment Security Standard. Medical Assistance Services should ensure the individuals responsible for monitoring service providers implement and consistently perform formal oversight processes in a timely manner, which will help maintain the confidentiality, integrity, and availability of sensitive and mission-critical data. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2023-086: Improve Third-Party Oversight Process Applicable to: Department of Medical Assistance Services Prior Year Finding Number: 2022-090 Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: N/A ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 Federal Award Number and Year: 2305VA5MAP - 2023 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Medical Assistance Services has made progress to document and implement a formal process for maintaining oversight for three of its IT third-party service providers that manage and support the Medicaid management system. However, Medical Assistance Services continues to not verify that one of its three service providers performs two controls as required by the Hosted Environment Security Standard. We communicated the two weaknesses to management in a separate document marked FOIAE under § 2.2-3705.2 of the Code of Virginia due to it containing descriptions of security mechanisms. VITA’s Enterprise Cloud Oversight Service (ECOS) confirms the two controls as part of its service for two of the three service providers; however, ECOS does not review the third service provider, and it is Medical Assistance Services’ responsibility to verify the provider performs the required controls. Medical Assistance Services did not ensure the individuals responsible for monitoring the service providers are confirming these specific controls and processes within the required timeframe. Without maintaining appropriate oversight of its service providers, Medical Assistance Services cannot validate whether its service providers implement the required security controls to protect the agency’s sensitive and mission-critical data. Medical Assistance Services should improve its process by ensuring individuals tasked with monitoring service providers confirm the controls per the Hosted Environment Security Standard. Medical Assistance Services should ensure the individuals responsible for monitoring service providers implement and consistently perform formal oversight processes in a timely manner, which will help maintain the confidentiality, integrity, and availability of sensitive and mission-critical data. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2023-086: Improve Third-Party Oversight Process Applicable to: Department of Medical Assistance Services Prior Year Finding Number: 2022-090 Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: N/A ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 Federal Award Number and Year: 2305VA5MAP - 2023 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Other - 2 CFR § 200.303(e) Known Questioned Costs: $0 Medical Assistance Services has made progress to document and implement a formal process for maintaining oversight for three of its IT third-party service providers that manage and support the Medicaid management system. However, Medical Assistance Services continues to not verify that one of its three service providers performs two controls as required by the Hosted Environment Security Standard. We communicated the two weaknesses to management in a separate document marked FOIAE under § 2.2-3705.2 of the Code of Virginia due to it containing descriptions of security mechanisms. VITA’s Enterprise Cloud Oversight Service (ECOS) confirms the two controls as part of its service for two of the three service providers; however, ECOS does not review the third service provider, and it is Medical Assistance Services’ responsibility to verify the provider performs the required controls. Medical Assistance Services did not ensure the individuals responsible for monitoring the service providers are confirming these specific controls and processes within the required timeframe. Without maintaining appropriate oversight of its service providers, Medical Assistance Services cannot validate whether its service providers implement the required security controls to protect the agency’s sensitive and mission-critical data. Medical Assistance Services should improve its process by ensuring individuals tasked with monitoring service providers confirm the controls per the Hosted Environment Security Standard. Medical Assistance Services should ensure the individuals responsible for monitoring service providers implement and consistently perform formal oversight processes in a timely manner, which will help maintain the confidentiality, integrity, and availability of sensitive and mission-critical data. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2023-097: Perform Responsibilities Outlined in the Agency Monitoring Plan Applicable to: Department of Social Services Prior Year Finding Number: 2022-011; 2021-070; 2020-074; 2019-090; 2018-093 Type of Finding: Internal Control and Compliance Severity of Deficiency: Material Weakness Information System Security Control Family: N/A ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 Federal Award Number and Year: 2305VA5MAP - 2023 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Subrecipient Monitoring - 2 CFR § 200.303(a); 2 CFR § 200.332 Known Questioned Costs: $0 Social Services’ Compliance Division (Compliance) continues to not adhere to its established approach to oversee the agency’s subrecipient monitoring activities, as outlined in its Agency Monitoring Plan. According to Social Services’ Organizational Structure Report, Compliance is responsible for agency-wide compliance and risk mitigation that helps to ensure adherence to state and federal legal and regulatory standards, including subrecipient monitoring. During fiscal year 2023, Social Services disbursed approximately $619 million in federal funds through roughly 5,400 subawards from 35 federal grant programs. During the audit, we noted the following deviations from the Agency Monitoring Plan: While Compliance has updated and finalized the Agency Monitoring Plan, it has not communicated it to Subrecipient Monitoring Coordinators in divisions with subrecipient monitoring responsibilities. Because of the lack of communication, there were deviations from the Agency Monitoring Plan at the division level. For example, the Agency Monitoring Plan requires each division to monitor subrecipients once every three years. However, the Local Review Team did not consider this requirement because Compliance did not communicate the Agency Monitoring Plan to Subrecipient Monitoring Coordinators. The Local Review Team did, however, implement a risk-based approach to monitoring subrecipients as required by the Agency Monitoring Plan. Compliance continues to not review division monitoring plans to ensure the divisions implement a risk-based approach for monitoring subrecipients. The Agency Monitoring Plan states that Compliance will use a Monitoring Plan Checklist to evaluate and determine if all the required elements for subrecipient monitoring are present in each division’s plan. Because of the lack of review, the Division of Benefit Programs’ (Benefit Programs) fiscal year 2023 monitoring plan did not meet all the requirements outlined in the Agency Monitoring Plan because it did not include a risk-based approach for subrecipient monitoring and did not consider all subrecipients who receive funding from the Temporary Assistance for Needy Families (TANF) federal grant program. Additionally, while the Office of New Americans has adequate subrecipient monitoring processes, it does not have a written monitoring plan as required by the Agency Monitoring Plan. Compliance continues to not analyze each division’s subrecipient monitoring activities. As a result, Compliance has not produced quarterly reports of variances and noncompliance to brief Social Services’ Executive Team on the agency’s subrecipient monitoring activities. Because of Compliance’s lack of analysis and communication, the Executive Team was unaware of the deviations noted above. Title 2 CFR § 200.303(a) requires pass-through entities to establish and maintain effective internal control over the federal award that provides reasonable assurance that the non-federal entity is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award. Without performing the responsibilities in the Agency Monitoring Plan, Social Services cannot provide reasonable assurance that the agency has complied with pass-through entity federal requirements at 2 CFR § 200.332. Because of the scope of this matter and the magnitude of Social Services’ subrecipient monitoring responsibilities, we consider these weaknesses collectively to create a material weakness in internal control over compliance. Since the prior audit, Compliance and Social Services’ Executive Team have worked together to discuss solutions to address this audit finding. Social Services is considering procuring a grants management system and Compliance has worked with the agency’s Division of Information Technology to determine whether it can utilize this system to fulfil its subrecipient monitoring responsibilities. Compliance has also discussed the need for additional staff to assist with subrecipient monitoring oversight with the Executive Team. However, Compliance has not implemented these corrective actions as of the end of fiscal year 2023 because of the level of effort and considerations involved with these corrective actions. Therefore, Compliance should continue to work with the Executive Team to make sure that it has the appropriate level of resources to fulfil its responsibilities in the Agency Monitoring Plan. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2023-097: Perform Responsibilities Outlined in the Agency Monitoring Plan Applicable to: Department of Social Services Prior Year Finding Number: 2022-011; 2021-070; 2020-074; 2019-090; 2018-093 Type of Finding: Internal Control and Compliance Severity of Deficiency: Material Weakness Information System Security Control Family: N/A ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 Federal Award Number and Year: 2305VA5MAP - 2023 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Subrecipient Monitoring - 2 CFR § 200.303(a); 2 CFR § 200.332 Known Questioned Costs: $0 Social Services’ Compliance Division (Compliance) continues to not adhere to its established approach to oversee the agency’s subrecipient monitoring activities, as outlined in its Agency Monitoring Plan. According to Social Services’ Organizational Structure Report, Compliance is responsible for agency-wide compliance and risk mitigation that helps to ensure adherence to state and federal legal and regulatory standards, including subrecipient monitoring. During fiscal year 2023, Social Services disbursed approximately $619 million in federal funds through roughly 5,400 subawards from 35 federal grant programs. During the audit, we noted the following deviations from the Agency Monitoring Plan: While Compliance has updated and finalized the Agency Monitoring Plan, it has not communicated it to Subrecipient Monitoring Coordinators in divisions with subrecipient monitoring responsibilities. Because of the lack of communication, there were deviations from the Agency Monitoring Plan at the division level. For example, the Agency Monitoring Plan requires each division to monitor subrecipients once every three years. However, the Local Review Team did not consider this requirement because Compliance did not communicate the Agency Monitoring Plan to Subrecipient Monitoring Coordinators. The Local Review Team did, however, implement a risk-based approach to monitoring subrecipients as required by the Agency Monitoring Plan. Compliance continues to not review division monitoring plans to ensure the divisions implement a risk-based approach for monitoring subrecipients. The Agency Monitoring Plan states that Compliance will use a Monitoring Plan Checklist to evaluate and determine if all the required elements for subrecipient monitoring are present in each division’s plan. Because of the lack of review, the Division of Benefit Programs’ (Benefit Programs) fiscal year 2023 monitoring plan did not meet all the requirements outlined in the Agency Monitoring Plan because it did not include a risk-based approach for subrecipient monitoring and did not consider all subrecipients who receive funding from the Temporary Assistance for Needy Families (TANF) federal grant program. Additionally, while the Office of New Americans has adequate subrecipient monitoring processes, it does not have a written monitoring plan as required by the Agency Monitoring Plan. Compliance continues to not analyze each division’s subrecipient monitoring activities. As a result, Compliance has not produced quarterly reports of variances and noncompliance to brief Social Services’ Executive Team on the agency’s subrecipient monitoring activities. Because of Compliance’s lack of analysis and communication, the Executive Team was unaware of the deviations noted above. Title 2 CFR § 200.303(a) requires pass-through entities to establish and maintain effective internal control over the federal award that provides reasonable assurance that the non-federal entity is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award. Without performing the responsibilities in the Agency Monitoring Plan, Social Services cannot provide reasonable assurance that the agency has complied with pass-through entity federal requirements at 2 CFR § 200.332. Because of the scope of this matter and the magnitude of Social Services’ subrecipient monitoring responsibilities, we consider these weaknesses collectively to create a material weakness in internal control over compliance. Since the prior audit, Compliance and Social Services’ Executive Team have worked together to discuss solutions to address this audit finding. Social Services is considering procuring a grants management system and Compliance has worked with the agency’s Division of Information Technology to determine whether it can utilize this system to fulfil its subrecipient monitoring responsibilities. Compliance has also discussed the need for additional staff to assist with subrecipient monitoring oversight with the Executive Team. However, Compliance has not implemented these corrective actions as of the end of fiscal year 2023 because of the level of effort and considerations involved with these corrective actions. Therefore, Compliance should continue to work with the Executive Team to make sure that it has the appropriate level of resources to fulfil its responsibilities in the Agency Monitoring Plan. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2023-097: Perform Responsibilities Outlined in the Agency Monitoring Plan Applicable to: Department of Social Services Prior Year Finding Number: 2022-011; 2021-070; 2020-074; 2019-090; 2018-093 Type of Finding: Internal Control and Compliance Severity of Deficiency: Material Weakness Information System Security Control Family: N/A ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 Federal Award Number and Year: 2305VA5MAP - 2023 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Subrecipient Monitoring - 2 CFR § 200.303(a); 2 CFR § 200.332 Known Questioned Costs: $0 Social Services’ Compliance Division (Compliance) continues to not adhere to its established approach to oversee the agency’s subrecipient monitoring activities, as outlined in its Agency Monitoring Plan. According to Social Services’ Organizational Structure Report, Compliance is responsible for agency-wide compliance and risk mitigation that helps to ensure adherence to state and federal legal and regulatory standards, including subrecipient monitoring. During fiscal year 2023, Social Services disbursed approximately $619 million in federal funds through roughly 5,400 subawards from 35 federal grant programs. During the audit, we noted the following deviations from the Agency Monitoring Plan: While Compliance has updated and finalized the Agency Monitoring Plan, it has not communicated it to Subrecipient Monitoring Coordinators in divisions with subrecipient monitoring responsibilities. Because of the lack of communication, there were deviations from the Agency Monitoring Plan at the division level. For example, the Agency Monitoring Plan requires each division to monitor subrecipients once every three years. However, the Local Review Team did not consider this requirement because Compliance did not communicate the Agency Monitoring Plan to Subrecipient Monitoring Coordinators. The Local Review Team did, however, implement a risk-based approach to monitoring subrecipients as required by the Agency Monitoring Plan. Compliance continues to not review division monitoring plans to ensure the divisions implement a risk-based approach for monitoring subrecipients. The Agency Monitoring Plan states that Compliance will use a Monitoring Plan Checklist to evaluate and determine if all the required elements for subrecipient monitoring are present in each division’s plan. Because of the lack of review, the Division of Benefit Programs’ (Benefit Programs) fiscal year 2023 monitoring plan did not meet all the requirements outlined in the Agency Monitoring Plan because it did not include a risk-based approach for subrecipient monitoring and did not consider all subrecipients who receive funding from the Temporary Assistance for Needy Families (TANF) federal grant program. Additionally, while the Office of New Americans has adequate subrecipient monitoring processes, it does not have a written monitoring plan as required by the Agency Monitoring Plan. Compliance continues to not analyze each division’s subrecipient monitoring activities. As a result, Compliance has not produced quarterly reports of variances and noncompliance to brief Social Services’ Executive Team on the agency’s subrecipient monitoring activities. Because of Compliance’s lack of analysis and communication, the Executive Team was unaware of the deviations noted above. Title 2 CFR § 200.303(a) requires pass-through entities to establish and maintain effective internal control over the federal award that provides reasonable assurance that the non-federal entity is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award. Without performing the responsibilities in the Agency Monitoring Plan, Social Services cannot provide reasonable assurance that the agency has complied with pass-through entity federal requirements at 2 CFR § 200.332. Because of the scope of this matter and the magnitude of Social Services’ subrecipient monitoring responsibilities, we consider these weaknesses collectively to create a material weakness in internal control over compliance. Since the prior audit, Compliance and Social Services’ Executive Team have worked together to discuss solutions to address this audit finding. Social Services is considering procuring a grants management system and Compliance has worked with the agency’s Division of Information Technology to determine whether it can utilize this system to fulfil its subrecipient monitoring responsibilities. Compliance has also discussed the need for additional staff to assist with subrecipient monitoring oversight with the Executive Team. However, Compliance has not implemented these corrective actions as of the end of fiscal year 2023 because of the level of effort and considerations involved with these corrective actions. Therefore, Compliance should continue to work with the Executive Team to make sure that it has the appropriate level of resources to fulfil its responsibilities in the Agency Monitoring Plan. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2023-099: Communicate Responsibilities to Subrecipient Monitoring Coordinators Applicable to: Department of Social Services Prior Year Finding Number: 2022-012; 2021-069; 2020-076 Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: N/A ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 Federal Award Number and Year: 2305VA5MAP - 2023 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Subrecipient Monitoring - 2 CFR § 200.332(d) Known Questioned Costs: $0 Compliance has not communicated responsibilities to subrecipient monitoring coordinators, as required by the Agency Monitoring Plan. Compliance’s Agency Monitoring Plan serves as a guide in the development, implementation, and coordination of division monitoring plans and aims to address accountability and provide consistency in monitoring activities across all Social Services’ divisions and offices. During fiscal year 2023, Social Services disbursed approximately $619 million in federal funds from roughly 5,400 subawards. Title 2 CFR § 200.332(d) requires pass-through entities to monitor the activities of subrecipients as necessary to ensure that the subaward is used for authorized purposes, in compliance with federal statutes, regulations, and the terms and conditions of the subaward. Further, 2 CFR § 200.303(a) requires pass-through entities to establish and maintain effective internal control over the federal award that provides reasonable assurance that the non-federal entity is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award. Since the prior audit, Compliance has updated and finalized the Agency Monitoring Plan but has been unable to communicate it to the subrecipient monitoring coordinators because of a lack of available resources. Without communicating responsibilities to subrecipient monitoring coordinators, Compliance cannot provide assurance that Social Services adequately monitors all its subrecipients to ensure they are achieving program objectives or complying with federal requirements. Compliance should continue to work with Social Services’ Executive Team to obtain the appropriate resources so that it can communicate responsibilities to subrecipient monitoring coordinators. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2023-099: Communicate Responsibilities to Subrecipient Monitoring Coordinators Applicable to: Department of Social Services Prior Year Finding Number: 2022-012; 2021-069; 2020-076 Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: N/A ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 Federal Award Number and Year: 2305VA5MAP - 2023 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Subrecipient Monitoring - 2 CFR § 200.332(d) Known Questioned Costs: $0 Compliance has not communicated responsibilities to subrecipient monitoring coordinators, as required by the Agency Monitoring Plan. Compliance’s Agency Monitoring Plan serves as a guide in the development, implementation, and coordination of division monitoring plans and aims to address accountability and provide consistency in monitoring activities across all Social Services’ divisions and offices. During fiscal year 2023, Social Services disbursed approximately $619 million in federal funds from roughly 5,400 subawards. Title 2 CFR § 200.332(d) requires pass-through entities to monitor the activities of subrecipients as necessary to ensure that the subaward is used for authorized purposes, in compliance with federal statutes, regulations, and the terms and conditions of the subaward. Further, 2 CFR § 200.303(a) requires pass-through entities to establish and maintain effective internal control over the federal award that provides reasonable assurance that the non-federal entity is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award. Since the prior audit, Compliance has updated and finalized the Agency Monitoring Plan but has been unable to communicate it to the subrecipient monitoring coordinators because of a lack of available resources. Without communicating responsibilities to subrecipient monitoring coordinators, Compliance cannot provide assurance that Social Services adequately monitors all its subrecipients to ensure they are achieving program objectives or complying with federal requirements. Compliance should continue to work with Social Services’ Executive Team to obtain the appropriate resources so that it can communicate responsibilities to subrecipient monitoring coordinators. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2023-099: Communicate Responsibilities to Subrecipient Monitoring Coordinators Applicable to: Department of Social Services Prior Year Finding Number: 2022-012; 2021-069; 2020-076 Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: N/A ALPT or Cluster Name and ALN: Medicaid Cluster - 93.775, 93.777, 93.778 Federal Award Number and Year: 2305VA5MAP - 2023 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Subrecipient Monitoring - 2 CFR § 200.332(d) Known Questioned Costs: $0 Compliance has not communicated responsibilities to subrecipient monitoring coordinators, as required by the Agency Monitoring Plan. Compliance’s Agency Monitoring Plan serves as a guide in the development, implementation, and coordination of division monitoring plans and aims to address accountability and provide consistency in monitoring activities across all Social Services’ divisions and offices. During fiscal year 2023, Social Services disbursed approximately $619 million in federal funds from roughly 5,400 subawards. Title 2 CFR § 200.332(d) requires pass-through entities to monitor the activities of subrecipients as necessary to ensure that the subaward is used for authorized purposes, in compliance with federal statutes, regulations, and the terms and conditions of the subaward. Further, 2 CFR § 200.303(a) requires pass-through entities to establish and maintain effective internal control over the federal award that provides reasonable assurance that the non-federal entity is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award. Since the prior audit, Compliance has updated and finalized the Agency Monitoring Plan but has been unable to communicate it to the subrecipient monitoring coordinators because of a lack of available resources. Without communicating responsibilities to subrecipient monitoring coordinators, Compliance cannot provide assurance that Social Services adequately monitors all its subrecipients to ensure they are achieving program objectives or complying with federal requirements. Compliance should continue to work with Social Services’ Executive Team to obtain the appropriate resources so that it can communicate responsibilities to subrecipient monitoring coordinators. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2023-103: Monitor Case Management System Records to Ensure Compliance with TANF Eligibility Requirements Applicable to: Department of Social Services Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: N/A ALPT or Cluster Name and ALN: Temporary Assistance for Needy Families (TANF) - 93.558 Federal Award Number and Year: 2301VATANF - 2023 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Eligibility - 2 CFR § 200.303(a) Known Questioned Costs: $12,275 Social Services did not comply with certain federal eligibility requirements for the TANF federal grant program, resulting in known questioned costs of $12,275. The TANF federal grant program provided over $120 million in assistance to approximately 28,000 needy families during fiscal year 2023. During the audit, we reperformed the eligibility determinations for all needy families that received assistance during the fiscal year and identified 30 instances (<1%) where the facts in the recipient’s case record did not support the eligibility determination. Specifically: For sixteen payments, staff did not properly assign to the state the rights the family member may have for child support. In 12 instances, Social Services underpaid benefit amounts to recipients, and in two instances, Social Services improperly denied benefits to the recipient due to manually entering child support payments beyond the acceptable timeframe. Staff incorrectly keyed the remaining two instances into the system but did not result in an adverse financial effect to the recipient or Social Services. Title 42 United States Code (USC) 608(a)(3) mandates that the State shall require that, as a condition of providing assistance, a member of the family assigned to the state the rights the family member may have for support from any other person and this assignment may not exceed the amount of assistance provided by the State. For eight payments, staff did not properly evaluate the income eligibility. Title 45 CFR § 263.2(b)(2) defines financially “needy” as financially eligible according to the state’s quantified income and resource criteria, which Social Services quantifies through its TANF Manual as maximum income charts in Section 305, Appendix 1. For two payments, staff did not properly evaluate the extended absence of a child or adult to determine the effect on household eligibility. Title 42 USC 608(a)(10) mandates that a state may not provide assistance to an individual who is a parent (or other caretaker relative) of a minor child who fails to notify the state agency of the absence of the minor child from the home within five days of the date that it becomes clear to that individual that the child will be absent for the specified period of time. Staff did not properly reduce or terminate two payments for individuals not complying with the Commonwealth’s work requirements for TANF recipients. Title 45 CFR §261.13 mandates that if an individual in a family receiving assistance refuses to engage in required work without good cause, a state must reduce assistance to the family, at least pro rata, with respect to any period during the month in which the individual refuses or may terminate assistance. Staff did not properly evaluate the qualified alien status for one payment as required by 8 USC § 1611. One recipient had a failed eligibility determination yet received a payment from the case management system. Title 45 CFR § 206.10(a)(8) requires that each decision regarding eligibility or ineligibility to be supported by facts in the applicant's or recipient's case record. Social Services relies on its case management system to properly determine eligibility, correctly calculate benefits payments, and achieve the federal requirements of the TANF federal grant program. Of the exceptions noted above, 16 of the 30 (53%) were the result of local agency eligibility workers mistakenly reporting child support payments as unearned revenue beyond the acceptable timeframe instead of assigning these payments to the Commonwealth for referral to the Division of Child Support Enforcement, as required by the CFR. The remaining 14 exceptions (47%) resulted from local agency eligibility workers manually overriding the eligibility determination made by the case management system and not including sufficient documentation to justify the rationale for the override. Social Services provides local agency eligibility workers with elevated access to the case management system so they can exercise their judgement during the applicant intake process. However, Social Services does not appear to monitor the use of manual overrides to ensure they are documented appropriately and that local agency eligibility workers are not using them excessively. In effect, Social Services places itself at risk of having to repay grant funds to the federal government if it does not comply with federal laws and regulations. Social Services should provide additional training to local agency eligibility workers on how to properly determine and document eligibility determinations in the case management system. Additionally, Social Services should consider monitoring local agency eligibility worker’s use of manual overrides to confirm that they properly document eligibility determinations in the case management system. By providing additional training and implementing additional internal controls, Social Services will be able to ensure that sufficient documentation supports each eligibility decision in its case management system in the applicant’s or recipient’s case record. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2023-103: Monitor Case Management System Records to Ensure Compliance with TANF Eligibility Requirements Applicable to: Department of Social Services Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: N/A ALPT or Cluster Name and ALN: Temporary Assistance for Needy Families (TANF) - 93.558 Federal Award Number and Year: 2301VATANF - 2023 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Eligibility - 2 CFR § 200.303(a) Known Questioned Costs: $12,275 Social Services did not comply with certain federal eligibility requirements for the TANF federal grant program, resulting in known questioned costs of $12,275. The TANF federal grant program provided over $120 million in assistance to approximately 28,000 needy families during fiscal year 2023. During the audit, we reperformed the eligibility determinations for all needy families that received assistance during the fiscal year and identified 30 instances (<1%) where the facts in the recipient’s case record did not support the eligibility determination. Specifically: For sixteen payments, staff did not properly assign to the state the rights the family member may have for child support. In 12 instances, Social Services underpaid benefit amounts to recipients, and in two instances, Social Services improperly denied benefits to the recipient due to manually entering child support payments beyond the acceptable timeframe. Staff incorrectly keyed the remaining two instances into the system but did not result in an adverse financial effect to the recipient or Social Services. Title 42 United States Code (USC) 608(a)(3) mandates that the State shall require that, as a condition of providing assistance, a member of the family assigned to the state the rights the family member may have for support from any other person and this assignment may not exceed the amount of assistance provided by the State. For eight payments, staff did not properly evaluate the income eligibility. Title 45 CFR § 263.2(b)(2) defines financially “needy” as financially eligible according to the state’s quantified income and resource criteria, which Social Services quantifies through its TANF Manual as maximum income charts in Section 305, Appendix 1. For two payments, staff did not properly evaluate the extended absence of a child or adult to determine the effect on household eligibility. Title 42 USC 608(a)(10) mandates that a state may not provide assistance to an individual who is a parent (or other caretaker relative) of a minor child who fails to notify the state agency of the absence of the minor child from the home within five days of the date that it becomes clear to that individual that the child will be absent for the specified period of time. Staff did not properly reduce or terminate two payments for individuals not complying with the Commonwealth’s work requirements for TANF recipients. Title 45 CFR §261.13 mandates that if an individual in a family receiving assistance refuses to engage in required work without good cause, a state must reduce assistance to the family, at least pro rata, with respect to any period during the month in which the individual refuses or may terminate assistance. Staff did not properly evaluate the qualified alien status for one payment as required by 8 USC § 1611. One recipient had a failed eligibility determination yet received a payment from the case management system. Title 45 CFR § 206.10(a)(8) requires that each decision regarding eligibility or ineligibility to be supported by facts in the applicant's or recipient's case record. Social Services relies on its case management system to properly determine eligibility, correctly calculate benefits payments, and achieve the federal requirements of the TANF federal grant program. Of the exceptions noted above, 16 of the 30 (53%) were the result of local agency eligibility workers mistakenly reporting child support payments as unearned revenue beyond the acceptable timeframe instead of assigning these payments to the Commonwealth for referral to the Division of Child Support Enforcement, as required by the CFR. The remaining 14 exceptions (47%) resulted from local agency eligibility workers manually overriding the eligibility determination made by the case management system and not including sufficient documentation to justify the rationale for the override. Social Services provides local agency eligibility workers with elevated access to the case management system so they can exercise their judgement during the applicant intake process. However, Social Services does not appear to monitor the use of manual overrides to ensure they are documented appropriately and that local agency eligibility workers are not using them excessively. In effect, Social Services places itself at risk of having to repay grant funds to the federal government if it does not comply with federal laws and regulations. Social Services should provide additional training to local agency eligibility workers on how to properly determine and document eligibility determinations in the case management system. Additionally, Social Services should consider monitoring local agency eligibility worker’s use of manual overrides to confirm that they properly document eligibility determinations in the case management system. By providing additional training and implementing additional internal controls, Social Services will be able to ensure that sufficient documentation supports each eligibility decision in its case management system in the applicant’s or recipient’s case record. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2023-103: Monitor Case Management System Records to Ensure Compliance with TANF Eligibility Requirements Applicable to: Department of Social Services Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: N/A ALPT or Cluster Name and ALN: Temporary Assistance for Needy Families (TANF) - 93.558 Federal Award Number and Year: 2301VATANF - 2023 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Eligibility - 2 CFR § 200.303(a) Known Questioned Costs: $12,275 Social Services did not comply with certain federal eligibility requirements for the TANF federal grant program, resulting in known questioned costs of $12,275. The TANF federal grant program provided over $120 million in assistance to approximately 28,000 needy families during fiscal year 2023. During the audit, we reperformed the eligibility determinations for all needy families that received assistance during the fiscal year and identified 30 instances (<1%) where the facts in the recipient’s case record did not support the eligibility determination. Specifically: For sixteen payments, staff did not properly assign to the state the rights the family member may have for child support. In 12 instances, Social Services underpaid benefit amounts to recipients, and in two instances, Social Services improperly denied benefits to the recipient due to manually entering child support payments beyond the acceptable timeframe. Staff incorrectly keyed the remaining two instances into the system but did not result in an adverse financial effect to the recipient or Social Services. Title 42 United States Code (USC) 608(a)(3) mandates that the State shall require that, as a condition of providing assistance, a member of the family assigned to the state the rights the family member may have for support from any other person and this assignment may not exceed the amount of assistance provided by the State. For eight payments, staff did not properly evaluate the income eligibility. Title 45 CFR § 263.2(b)(2) defines financially “needy” as financially eligible according to the state’s quantified income and resource criteria, which Social Services quantifies through its TANF Manual as maximum income charts in Section 305, Appendix 1. For two payments, staff did not properly evaluate the extended absence of a child or adult to determine the effect on household eligibility. Title 42 USC 608(a)(10) mandates that a state may not provide assistance to an individual who is a parent (or other caretaker relative) of a minor child who fails to notify the state agency of the absence of the minor child from the home within five days of the date that it becomes clear to that individual that the child will be absent for the specified period of time. Staff did not properly reduce or terminate two payments for individuals not complying with the Commonwealth’s work requirements for TANF recipients. Title 45 CFR §261.13 mandates that if an individual in a family receiving assistance refuses to engage in required work without good cause, a state must reduce assistance to the family, at least pro rata, with respect to any period during the month in which the individual refuses or may terminate assistance. Staff did not properly evaluate the qualified alien status for one payment as required by 8 USC § 1611. One recipient had a failed eligibility determination yet received a payment from the case management system. Title 45 CFR § 206.10(a)(8) requires that each decision regarding eligibility or ineligibility to be supported by facts in the applicant's or recipient's case record. Social Services relies on its case management system to properly determine eligibility, correctly calculate benefits payments, and achieve the federal requirements of the TANF federal grant program. Of the exceptions noted above, 16 of the 30 (53%) were the result of local agency eligibility workers mistakenly reporting child support payments as unearned revenue beyond the acceptable timeframe instead of assigning these payments to the Commonwealth for referral to the Division of Child Support Enforcement, as required by the CFR. The remaining 14 exceptions (47%) resulted from local agency eligibility workers manually overriding the eligibility determination made by the case management system and not including sufficient documentation to justify the rationale for the override. Social Services provides local agency eligibility workers with elevated access to the case management system so they can exercise their judgement during the applicant intake process. However, Social Services does not appear to monitor the use of manual overrides to ensure they are documented appropriately and that local agency eligibility workers are not using them excessively. In effect, Social Services places itself at risk of having to repay grant funds to the federal government if it does not comply with federal laws and regulations. Social Services should provide additional training to local agency eligibility workers on how to properly determine and document eligibility determinations in the case management system. Additionally, Social Services should consider monitoring local agency eligibility worker’s use of manual overrides to confirm that they properly document eligibility determinations in the case management system. By providing additional training and implementing additional internal controls, Social Services will be able to ensure that sufficient documentation supports each eligibility decision in its case management system in the applicant’s or recipient’s case record. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2023-104: Obtain Reasonable Assurance over Contractor Compliance with Program Regulations Applicable to: Department of Social Services Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Material Weakness Information System Security Control Family: N/A ALPT or Cluster Name and ALN: Low-Income Household Water Assistance Program (LIHWAP) - 93.499 Federal Award Number and Year: 2101VALWC1 - 2023 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Eligibility - 2 CFR § 200.303(a); 2 CFR § 200.501(g) Known Questioned Costs: $0 Social Services cannot provide reasonable assurance that its contractor administered the Low-Income Household Water Assistance Program (LIHWAP) in compliance with federal statutes, regulations, and the terms and conditions of the federal award. Reasonable assurance is a high, but not absolute, level of assurance that the entity and its contractors have complied with federal laws and regulations. The United States Department of Health and Human Services awarded approximately $25 million to Social Services to administer the LIHWAP federal grant program. The objective of the LIHWAP federal grant program is to meet unprecedented water services needs that arose during the COVID-19 pandemic and provide quick intervention to help the people facing high water or wastewater costs compared to their income in resuming and/or maintaining their home water or wastewater services. Social Services partnered with a for-profit contractor to administer the program on its behalf due to resource limitations and the need to provide this assistance to individuals as quickly as possible. Through its contractual agreement, Social Services assumed ultimate responsibility for program compliance and incorporated certain measures into its contractual agreement to maintain compliance with federal laws and regulations. Specifically, Social Services was to agree on performance self-assessment criteria with the contractor within 30 calendar days of the execution of the project start date, then have the contractor prepare a monthly self-assessment to report on such criteria. Social Services then had ten business days, after the receipt of the contractor’s self-assessment, to audit the results of the contractor’s service level obligations and performance requirements and discuss any discrepancies with the contractor to determine if invoice or payment adjustments were necessary. Because of the fast-paced nature of the program and the need to provide the assistance to individuals as quickly as possible, Social Services was unable to agree on the performance criteria with the contractor. As a result, Social Services did not receive the monthly self-assessments from the contractor and audit them in accordance with the contractual agreement. While Social Services did have on-going discussions with the contractor about program compliance and did perform periodic reviews of applicant records, these reviews did not follow a systematic process that provides reasonable assurance over the contractor’s compliance with program regulations. Title 2 CFR § 200.501(g) states that the auditee is responsible for reviewing the contractor’s records to determine program compliance. Additionally, 2 CFR § 200.303(a) states that non-federal entities must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non-federal entity is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award. Since Social Services has not implemented the contractual provisions related to the vendor’s self-assessment reporting and performance auditing, we are unable to audit Social Services' compliance for the LIHWAP federal grant program and must disclaim an opinion on compliance for the program in the Commonwealth's Single Audit report. We also believe this matter represents a material weakness in internal control over compliance because there is a reasonable possibility that material noncompliance with a compliance requirement will not be prevented, or detected and corrected, on a timely basis. The contract between Social Services and the contractor ends on December 31, 2023. Thereafter, the contractor will transfer program records to Social Services within the subsequent months. Social Services has until June 2024 to close out the LIHWAP federal grant program and should fulfill its responsibilities for auditing the contractor’s records for compliance before it closes the LIHWAP grant with the United States Department of Health and Human Services. Therefore, Social Services should implement an audit process that provides reasonable assurance that the contractor administered the LIHWAP federal grant program in accordance with federal statutes, regulations, and the terms and conditions of the federal award before it closes the grant award. Additionally, Social Services’ Executive Team should oversee the implementation of the audit process. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2023-106: Implement Internal Controls over TANF Federal Special Reporting Applicable to: Department of Social Services Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: N/A ALPT or Cluster Name and ALN: Temporary Assistance for Needy Families (TANF) - 93.558 Federal Award Number and Year: 2301VATANF - 2023 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Reporting - 2 CFR § 200.303(a); 45 CFR § 75.361 Known Questioned Costs: $0 Benefit Programs does not have adequate internal controls in place to ensure reasonably accurate reporting in the ACF Annual Report on State Maintenance-of-Effort (MOE) Programs (ACF-204) for the TANF federal grant program. ACF requires Social Services to submit this data to ACF annually and ACF uses this information in reports to Congress about how TANF programs are evolving, in assessing State and Territory MOE expenditures, and in assessing the need for legislative changes. During our review, we identified the following: Benefit Programs could not produce evidence to support a reasonable estimate for four out of six (66%) of the “Total number of families served under the program with MOE funds” key line items. Benefit Programs appeared to use an estimation process that did not have a sound basis for two out of six (33%) of the “Total number of families served under the program with MOE funds” key line items. Title 2 CFR § 200.303(a) requires the non-federal entity to establish and maintain effective internal control over the federal award that provides reasonable assurance that the non-federal entity is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award. Further, 45 CFR § 75.361 requires that financial records, supporting documents, statistical records, and all other non-federal entity records pertinent to a federal award must be retained for a period of three years from the date of submission. The ACF-204 Reporting Instructions allow states the flexibility to use reasonable estimates with a sound basis when actual numbers are not available. However, Benefit Programs has not dedicated the resources to implement appropriate internal controls and document its estimation and retention processes to demonstrate that it uses reasonable estimates with a sound basis to support the amounts reported in the ACF-204 report. Reporting potentially inaccurate information prevents the ACF from adequately monitoring Social Services’ MOE programs and the overall performance for the TANF federal grant program. Therefore, Benefit Programs should dedicate the necessary resources to implement internal controls over the TANF special reporting process and include documented estimation and retention processes to ensure reasonably accurate reporting of TANF MOE Programs to ACF in accordance with the ACF-204 reporting instructions. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2023-106: Implement Internal Controls over TANF Federal Special Reporting Applicable to: Department of Social Services Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: N/A ALPT or Cluster Name and ALN: Temporary Assistance for Needy Families (TANF) - 93.558 Federal Award Number and Year: 2301VATANF - 2023 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Reporting - 2 CFR § 200.303(a); 45 CFR § 75.361 Known Questioned Costs: $0 Benefit Programs does not have adequate internal controls in place to ensure reasonably accurate reporting in the ACF Annual Report on State Maintenance-of-Effort (MOE) Programs (ACF-204) for the TANF federal grant program. ACF requires Social Services to submit this data to ACF annually and ACF uses this information in reports to Congress about how TANF programs are evolving, in assessing State and Territory MOE expenditures, and in assessing the need for legislative changes. During our review, we identified the following: Benefit Programs could not produce evidence to support a reasonable estimate for four out of six (66%) of the “Total number of families served under the program with MOE funds” key line items. Benefit Programs appeared to use an estimation process that did not have a sound basis for two out of six (33%) of the “Total number of families served under the program with MOE funds” key line items. Title 2 CFR § 200.303(a) requires the non-federal entity to establish and maintain effective internal control over the federal award that provides reasonable assurance that the non-federal entity is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award. Further, 45 CFR § 75.361 requires that financial records, supporting documents, statistical records, and all other non-federal entity records pertinent to a federal award must be retained for a period of three years from the date of submission. The ACF-204 Reporting Instructions allow states the flexibility to use reasonable estimates with a sound basis when actual numbers are not available. However, Benefit Programs has not dedicated the resources to implement appropriate internal controls and document its estimation and retention processes to demonstrate that it uses reasonable estimates with a sound basis to support the amounts reported in the ACF-204 report. Reporting potentially inaccurate information prevents the ACF from adequately monitoring Social Services’ MOE programs and the overall performance for the TANF federal grant program. Therefore, Benefit Programs should dedicate the necessary resources to implement internal controls over the TANF special reporting process and include documented estimation and retention processes to ensure reasonably accurate reporting of TANF MOE Programs to ACF in accordance with the ACF-204 reporting instructions. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2023-106: Implement Internal Controls over TANF Federal Special Reporting Applicable to: Department of Social Services Prior Year Finding Number: N/A Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: N/A ALPT or Cluster Name and ALN: Temporary Assistance for Needy Families (TANF) - 93.558 Federal Award Number and Year: 2301VATANF - 2023 Name of Federal Agency: U.S. Department of Health and Human Services Type of Compliance Requirement - Criteria: Reporting - 2 CFR § 200.303(a); 45 CFR § 75.361 Known Questioned Costs: $0 Benefit Programs does not have adequate internal controls in place to ensure reasonably accurate reporting in the ACF Annual Report on State Maintenance-of-Effort (MOE) Programs (ACF-204) for the TANF federal grant program. ACF requires Social Services to submit this data to ACF annually and ACF uses this information in reports to Congress about how TANF programs are evolving, in assessing State and Territory MOE expenditures, and in assessing the need for legislative changes. During our review, we identified the following: Benefit Programs could not produce evidence to support a reasonable estimate for four out of six (66%) of the “Total number of families served under the program with MOE funds” key line items. Benefit Programs appeared to use an estimation process that did not have a sound basis for two out of six (33%) of the “Total number of families served under the program with MOE funds” key line items. Title 2 CFR § 200.303(a) requires the non-federal entity to establish and maintain effective internal control over the federal award that provides reasonable assurance that the non-federal entity is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award. Further, 45 CFR § 75.361 requires that financial records, supporting documents, statistical records, and all other non-federal entity records pertinent to a federal award must be retained for a period of three years from the date of submission. The ACF-204 Reporting Instructions allow states the flexibility to use reasonable estimates with a sound basis when actual numbers are not available. However, Benefit Programs has not dedicated the resources to implement appropriate internal controls and document its estimation and retention processes to demonstrate that it uses reasonable estimates with a sound basis to support the amounts reported in the ACF-204 report. Reporting potentially inaccurate information prevents the ACF from adequately monitoring Social Services’ MOE programs and the overall performance for the TANF federal grant program. Therefore, Benefit Programs should dedicate the necessary resources to implement internal controls over the TANF special reporting process and include documented estimation and retention processes to ensure reasonably accurate reporting of TANF MOE Programs to ACF in accordance with the ACF-204 reporting instructions. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2023-107: Strengthen Internal Controls over FFATA Reporting Applicable to: Department of Social Services Prior Year Finding Number: 2022-106 Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: N/A ALPT or Cluster Name and ALN: Crime Victim Assistance - 16.575; Temporary Assistance for Needy Families (TANF) - 93.558; Refugee and Entrant Assistance State/Replacement Designee Administered Programs - 93.566 Federal Award Number and Year: 2301VATANF; 2019-V2-GX-0054; 2020-V2-GX-0048; 15POVC-21-GG-00602-ASSI; 2301VARSSS; 2301VARCMA - 2023 Name of Federal Agency: U.S. Department of Health and Human Services; U.S. Department of Justice Type of Compliance Requirement - Criteria: Reporting - 2 CFR Part 170 Appendix A Known Questioned Costs: $0 Finance does not maintain adequate internal control over Federal Funding Accountability and Transparency Act (FFATA) reporting. FFATA reporting is intended to provide full disclosure of how entities and organizations are obligating federal funding. During fiscal year 2023, Social Services disbursed approximately $619 million in federal funds from roughly 5,400 subawards. During our audit of the TANF, Refugee and Entrant Assistance State/Replacement Designee Administered Programs (Refugee Assistance), and Victims of Crime Act (VOCA) federal grant programs, we noted the following deviations from Finance’s policy: Finance did not complete FFATA reporting submissions for 106 of 205 (52%) of the grant year 2023 TANF subawards that spent $30,000 or more during fiscal year 2023. Social Services disbursed approximately $7.9 million from these subawards during the fiscal year. Finance did not report TANF subawards to FFATA Subaward Reporting System (FSRS) because program personnel did not submit the required information to Finance to report in FSRS. Finance did not complete FFATA reporting submissions for three of 17 (18%) of the grant year 2023 Refugee Assistance subawards that spent $30,000 or more during fiscal year 2023. Social Services disbursed approximately $126,000 from these subawards during the fiscal year. Finance did not report Refugee Assistance subawards to FSRS for these three subawards because the initial subaward amount was less than $30,000 and program personnel did not inform Finance that subsequent subaward modifications increased the subaward value to over $30,000. Finance did not complete FFATA reporting submissions for grant year 2023 VOCA subawards during fiscal year 2023. Social Services disbursed approximately $3.5 million from 129 subawards during the fiscal year. Social Services did not report this information to FSRS because it inadvertently assumed that it was a subrecipient of the Department of Criminal Justice Services and did not need to complete FFATA reporting as required by the VOCA Grant Special Conditions document. Title 2 CFR Part 170 Appendix A requires the non-federal entity to report each obligating action exceeding $30,000 to the FSRS. Further, Title 2 CFR Part 170 Appendix A requires the non-federal entity to submit subaward information no later than the end of the month following the month in which it made the obligation. Finally, 2 CFR §200.303(a) states that the non-federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non-federal entity is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award. The decentralized nature of Social Services’ grants management practices and the volume of subawards elevates the risk that Finance will not report all subaward information to FSRS. Although Finance sent periodic email reminders to program staff responsible for submitting FFATA data to Finance for submission to FSRS, program personnel overlooked a significant percentage of these submissions because of turnover and a lack of familiarity with FFATA reporting requirements. Additionally, Finance did not have a compensating internal control in place to detect subawards that it did not report to FSRS. When Social Services does not upload all obligating actions meeting the reporting threshold to FSRS as required, a citizen or federal official may have a distorted view as to how Social Services is obligating federal funds. Therefore, Finance should continue to remind program personnel to submit required FFATA subaward reporting information to them and revise its policy to reflect any changes in its processes. Additionally, Finance should consider periodically checking Social Services’ financial records to determine if there are instances where program personnel are not submitting the required FFATA subaward reporting information. If so, Finance should collect this information from them promptly to comply with the FFATA reporting requirements. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2023-107: Strengthen Internal Controls over FFATA Reporting Applicable to: Department of Social Services Prior Year Finding Number: 2022-106 Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: N/A ALPT or Cluster Name and ALN: Crime Victim Assistance - 16.575; Temporary Assistance for Needy Families (TANF) - 93.558; Refugee and Entrant Assistance State/Replacement Designee Administered Programs - 93.566 Federal Award Number and Year: 2301VATANF; 2019-V2-GX-0054; 2020-V2-GX-0048; 15POVC-21-GG-00602-ASSI; 2301VARSSS; 2301VARCMA - 2023 Name of Federal Agency: U.S. Department of Health and Human Services; U.S. Department of Justice Type of Compliance Requirement - Criteria: Reporting - 2 CFR Part 170 Appendix A Known Questioned Costs: $0 Finance does not maintain adequate internal control over Federal Funding Accountability and Transparency Act (FFATA) reporting. FFATA reporting is intended to provide full disclosure of how entities and organizations are obligating federal funding. During fiscal year 2023, Social Services disbursed approximately $619 million in federal funds from roughly 5,400 subawards. During our audit of the TANF, Refugee and Entrant Assistance State/Replacement Designee Administered Programs (Refugee Assistance), and Victims of Crime Act (VOCA) federal grant programs, we noted the following deviations from Finance’s policy: Finance did not complete FFATA reporting submissions for 106 of 205 (52%) of the grant year 2023 TANF subawards that spent $30,000 or more during fiscal year 2023. Social Services disbursed approximately $7.9 million from these subawards during the fiscal year. Finance did not report TANF subawards to FFATA Subaward Reporting System (FSRS) because program personnel did not submit the required information to Finance to report in FSRS. Finance did not complete FFATA reporting submissions for three of 17 (18%) of the grant year 2023 Refugee Assistance subawards that spent $30,000 or more during fiscal year 2023. Social Services disbursed approximately $126,000 from these subawards during the fiscal year. Finance did not report Refugee Assistance subawards to FSRS for these three subawards because the initial subaward amount was less than $30,000 and program personnel did not inform Finance that subsequent subaward modifications increased the subaward value to over $30,000. Finance did not complete FFATA reporting submissions for grant year 2023 VOCA subawards during fiscal year 2023. Social Services disbursed approximately $3.5 million from 129 subawards during the fiscal year. Social Services did not report this information to FSRS because it inadvertently assumed that it was a subrecipient of the Department of Criminal Justice Services and did not need to complete FFATA reporting as required by the VOCA Grant Special Conditions document. Title 2 CFR Part 170 Appendix A requires the non-federal entity to report each obligating action exceeding $30,000 to the FSRS. Further, Title 2 CFR Part 170 Appendix A requires the non-federal entity to submit subaward information no later than the end of the month following the month in which it made the obligation. Finally, 2 CFR §200.303(a) states that the non-federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non-federal entity is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award. The decentralized nature of Social Services’ grants management practices and the volume of subawards elevates the risk that Finance will not report all subaward information to FSRS. Although Finance sent periodic email reminders to program staff responsible for submitting FFATA data to Finance for submission to FSRS, program personnel overlooked a significant percentage of these submissions because of turnover and a lack of familiarity with FFATA reporting requirements. Additionally, Finance did not have a compensating internal control in place to detect subawards that it did not report to FSRS. When Social Services does not upload all obligating actions meeting the reporting threshold to FSRS as required, a citizen or federal official may have a distorted view as to how Social Services is obligating federal funds. Therefore, Finance should continue to remind program personnel to submit required FFATA subaward reporting information to them and revise its policy to reflect any changes in its processes. Additionally, Finance should consider periodically checking Social Services’ financial records to determine if there are instances where program personnel are not submitting the required FFATA subaward reporting information. If so, Finance should collect this information from them promptly to comply with the FFATA reporting requirements. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2023-107: Strengthen Internal Controls over FFATA Reporting Applicable to: Department of Social Services Prior Year Finding Number: 2022-106 Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: N/A ALPT or Cluster Name and ALN: Crime Victim Assistance - 16.575; Temporary Assistance for Needy Families (TANF) - 93.558; Refugee and Entrant Assistance State/Replacement Designee Administered Programs - 93.566 Federal Award Number and Year: 2301VATANF; 2019-V2-GX-0054; 2020-V2-GX-0048; 15POVC-21-GG-00602-ASSI; 2301VARSSS; 2301VARCMA - 2023 Name of Federal Agency: U.S. Department of Health and Human Services; U.S. Department of Justice Type of Compliance Requirement - Criteria: Reporting - 2 CFR Part 170 Appendix A Known Questioned Costs: $0 Finance does not maintain adequate internal control over Federal Funding Accountability and Transparency Act (FFATA) reporting. FFATA reporting is intended to provide full disclosure of how entities and organizations are obligating federal funding. During fiscal year 2023, Social Services disbursed approximately $619 million in federal funds from roughly 5,400 subawards. During our audit of the TANF, Refugee and Entrant Assistance State/Replacement Designee Administered Programs (Refugee Assistance), and Victims of Crime Act (VOCA) federal grant programs, we noted the following deviations from Finance’s policy: Finance did not complete FFATA reporting submissions for 106 of 205 (52%) of the grant year 2023 TANF subawards that spent $30,000 or more during fiscal year 2023. Social Services disbursed approximately $7.9 million from these subawards during the fiscal year. Finance did not report TANF subawards to FFATA Subaward Reporting System (FSRS) because program personnel did not submit the required information to Finance to report in FSRS. Finance did not complete FFATA reporting submissions for three of 17 (18%) of the grant year 2023 Refugee Assistance subawards that spent $30,000 or more during fiscal year 2023. Social Services disbursed approximately $126,000 from these subawards during the fiscal year. Finance did not report Refugee Assistance subawards to FSRS for these three subawards because the initial subaward amount was less than $30,000 and program personnel did not inform Finance that subsequent subaward modifications increased the subaward value to over $30,000. Finance did not complete FFATA reporting submissions for grant year 2023 VOCA subawards during fiscal year 2023. Social Services disbursed approximately $3.5 million from 129 subawards during the fiscal year. Social Services did not report this information to FSRS because it inadvertently assumed that it was a subrecipient of the Department of Criminal Justice Services and did not need to complete FFATA reporting as required by the VOCA Grant Special Conditions document. Title 2 CFR Part 170 Appendix A requires the non-federal entity to report each obligating action exceeding $30,000 to the FSRS. Further, Title 2 CFR Part 170 Appendix A requires the non-federal entity to submit subaward information no later than the end of the month following the month in which it made the obligation. Finally, 2 CFR §200.303(a) states that the non-federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non-federal entity is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award. The decentralized nature of Social Services’ grants management practices and the volume of subawards elevates the risk that Finance will not report all subaward information to FSRS. Although Finance sent periodic email reminders to program staff responsible for submitting FFATA data to Finance for submission to FSRS, program personnel overlooked a significant percentage of these submissions because of turnover and a lack of familiarity with FFATA reporting requirements. Additionally, Finance did not have a compensating internal control in place to detect subawards that it did not report to FSRS. When Social Services does not upload all obligating actions meeting the reporting threshold to FSRS as required, a citizen or federal official may have a distorted view as to how Social Services is obligating federal funds. Therefore, Finance should continue to remind program personnel to submit required FFATA subaward reporting information to them and revise its policy to reflect any changes in its processes. Additionally, Finance should consider periodically checking Social Services’ financial records to determine if there are instances where program personnel are not submitting the required FFATA subaward reporting information. If so, Finance should collect this information from them promptly to comply with the FFATA reporting requirements. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2023-107: Strengthen Internal Controls over FFATA Reporting Applicable to: Department of Social Services Prior Year Finding Number: 2022-106 Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: N/A ALPT or Cluster Name and ALN: Crime Victim Assistance - 16.575; Temporary Assistance for Needy Families (TANF) - 93.558; Refugee and Entrant Assistance State/Replacement Designee Administered Programs - 93.566 Federal Award Number and Year: 2301VATANF; 2019-V2-GX-0054; 2020-V2-GX-0048; 15POVC-21-GG-00602-ASSI; 2301VARSSS; 2301VARCMA - 2023 Name of Federal Agency: U.S. Department of Health and Human Services; U.S. Department of Justice Type of Compliance Requirement - Criteria: Reporting - 2 CFR Part 170 Appendix A Known Questioned Costs: $0 Finance does not maintain adequate internal control over Federal Funding Accountability and Transparency Act (FFATA) reporting. FFATA reporting is intended to provide full disclosure of how entities and organizations are obligating federal funding. During fiscal year 2023, Social Services disbursed approximately $619 million in federal funds from roughly 5,400 subawards. During our audit of the TANF, Refugee and Entrant Assistance State/Replacement Designee Administered Programs (Refugee Assistance), and Victims of Crime Act (VOCA) federal grant programs, we noted the following deviations from Finance’s policy: Finance did not complete FFATA reporting submissions for 106 of 205 (52%) of the grant year 2023 TANF subawards that spent $30,000 or more during fiscal year 2023. Social Services disbursed approximately $7.9 million from these subawards during the fiscal year. Finance did not report TANF subawards to FFATA Subaward Reporting System (FSRS) because program personnel did not submit the required information to Finance to report in FSRS. Finance did not complete FFATA reporting submissions for three of 17 (18%) of the grant year 2023 Refugee Assistance subawards that spent $30,000 or more during fiscal year 2023. Social Services disbursed approximately $126,000 from these subawards during the fiscal year. Finance did not report Refugee Assistance subawards to FSRS for these three subawards because the initial subaward amount was less than $30,000 and program personnel did not inform Finance that subsequent subaward modifications increased the subaward value to over $30,000. Finance did not complete FFATA reporting submissions for grant year 2023 VOCA subawards during fiscal year 2023. Social Services disbursed approximately $3.5 million from 129 subawards during the fiscal year. Social Services did not report this information to FSRS because it inadvertently assumed that it was a subrecipient of the Department of Criminal Justice Services and did not need to complete FFATA reporting as required by the VOCA Grant Special Conditions document. Title 2 CFR Part 170 Appendix A requires the non-federal entity to report each obligating action exceeding $30,000 to the FSRS. Further, Title 2 CFR Part 170 Appendix A requires the non-federal entity to submit subaward information no later than the end of the month following the month in which it made the obligation. Finally, 2 CFR §200.303(a) states that the non-federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non-federal entity is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award. The decentralized nature of Social Services’ grants management practices and the volume of subawards elevates the risk that Finance will not report all subaward information to FSRS. Although Finance sent periodic email reminders to program staff responsible for submitting FFATA data to Finance for submission to FSRS, program personnel overlooked a significant percentage of these submissions because of turnover and a lack of familiarity with FFATA reporting requirements. Additionally, Finance did not have a compensating internal control in place to detect subawards that it did not report to FSRS. When Social Services does not upload all obligating actions meeting the reporting threshold to FSRS as required, a citizen or federal official may have a distorted view as to how Social Services is obligating federal funds. Therefore, Finance should continue to remind program personnel to submit required FFATA subaward reporting information to them and revise its policy to reflect any changes in its processes. Additionally, Finance should consider periodically checking Social Services’ financial records to determine if there are instances where program personnel are not submitting the required FFATA subaward reporting information. If so, Finance should collect this information from them promptly to comply with the FFATA reporting requirements. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2023-107: Strengthen Internal Controls over FFATA Reporting Applicable to: Department of Social Services Prior Year Finding Number: 2022-106 Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: N/A ALPT or Cluster Name and ALN: Crime Victim Assistance - 16.575; Temporary Assistance for Needy Families (TANF) - 93.558; Refugee and Entrant Assistance State/Replacement Designee Administered Programs - 93.566 Federal Award Number and Year: 2301VATANF; 2019-V2-GX-0054; 2020-V2-GX-0048; 15POVC-21-GG-00602-ASSI; 2301VARSSS; 2301VARCMA - 2023 Name of Federal Agency: U.S. Department of Health and Human Services; U.S. Department of Justice Type of Compliance Requirement - Criteria: Reporting - 2 CFR Part 170 Appendix A Known Questioned Costs: $0 Finance does not maintain adequate internal control over Federal Funding Accountability and Transparency Act (FFATA) reporting. FFATA reporting is intended to provide full disclosure of how entities and organizations are obligating federal funding. During fiscal year 2023, Social Services disbursed approximately $619 million in federal funds from roughly 5,400 subawards. During our audit of the TANF, Refugee and Entrant Assistance State/Replacement Designee Administered Programs (Refugee Assistance), and Victims of Crime Act (VOCA) federal grant programs, we noted the following deviations from Finance’s policy: Finance did not complete FFATA reporting submissions for 106 of 205 (52%) of the grant year 2023 TANF subawards that spent $30,000 or more during fiscal year 2023. Social Services disbursed approximately $7.9 million from these subawards during the fiscal year. Finance did not report TANF subawards to FFATA Subaward Reporting System (FSRS) because program personnel did not submit the required information to Finance to report in FSRS. Finance did not complete FFATA reporting submissions for three of 17 (18%) of the grant year 2023 Refugee Assistance subawards that spent $30,000 or more during fiscal year 2023. Social Services disbursed approximately $126,000 from these subawards during the fiscal year. Finance did not report Refugee Assistance subawards to FSRS for these three subawards because the initial subaward amount was less than $30,000 and program personnel did not inform Finance that subsequent subaward modifications increased the subaward value to over $30,000. Finance did not complete FFATA reporting submissions for grant year 2023 VOCA subawards during fiscal year 2023. Social Services disbursed approximately $3.5 million from 129 subawards during the fiscal year. Social Services did not report this information to FSRS because it inadvertently assumed that it was a subrecipient of the Department of Criminal Justice Services and did not need to complete FFATA reporting as required by the VOCA Grant Special Conditions document. Title 2 CFR Part 170 Appendix A requires the non-federal entity to report each obligating action exceeding $30,000 to the FSRS. Further, Title 2 CFR Part 170 Appendix A requires the non-federal entity to submit subaward information no later than the end of the month following the month in which it made the obligation. Finally, 2 CFR §200.303(a) states that the non-federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non-federal entity is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award. The decentralized nature of Social Services’ grants management practices and the volume of subawards elevates the risk that Finance will not report all subaward information to FSRS. Although Finance sent periodic email reminders to program staff responsible for submitting FFATA data to Finance for submission to FSRS, program personnel overlooked a significant percentage of these submissions because of turnover and a lack of familiarity with FFATA reporting requirements. Additionally, Finance did not have a compensating internal control in place to detect subawards that it did not report to FSRS. When Social Services does not upload all obligating actions meeting the reporting threshold to FSRS as required, a citizen or federal official may have a distorted view as to how Social Services is obligating federal funds. Therefore, Finance should continue to remind program personnel to submit required FFATA subaward reporting information to them and revise its policy to reflect any changes in its processes. Additionally, Finance should consider periodically checking Social Services’ financial records to determine if there are instances where program personnel are not submitting the required FFATA subaward reporting information. If so, Finance should collect this information from them promptly to comply with the FFATA reporting requirements. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
2023-107: Strengthen Internal Controls over FFATA Reporting Applicable to: Department of Social Services Prior Year Finding Number: 2022-106 Type of Finding: Internal Control and Compliance Severity of Deficiency: Significant Deficiency Information System Security Control Family: N/A ALPT or Cluster Name and ALN: Crime Victim Assistance - 16.575; Temporary Assistance for Needy Families (TANF) - 93.558; Refugee and Entrant Assistance State/Replacement Designee Administered Programs - 93.566 Federal Award Number and Year: 2301VATANF; 2019-V2-GX-0054; 2020-V2-GX-0048; 15POVC-21-GG-00602-ASSI; 2301VARSSS; 2301VARCMA - 2023 Name of Federal Agency: U.S. Department of Health and Human Services; U.S. Department of Justice Type of Compliance Requirement - Criteria: Reporting - 2 CFR Part 170 Appendix A Known Questioned Costs: $0 Finance does not maintain adequate internal control over Federal Funding Accountability and Transparency Act (FFATA) reporting. FFATA reporting is intended to provide full disclosure of how entities and organizations are obligating federal funding. During fiscal year 2023, Social Services disbursed approximately $619 million in federal funds from roughly 5,400 subawards. During our audit of the TANF, Refugee and Entrant Assistance State/Replacement Designee Administered Programs (Refugee Assistance), and Victims of Crime Act (VOCA) federal grant programs, we noted the following deviations from Finance’s policy: Finance did not complete FFATA reporting submissions for 106 of 205 (52%) of the grant year 2023 TANF subawards that spent $30,000 or more during fiscal year 2023. Social Services disbursed approximately $7.9 million from these subawards during the fiscal year. Finance did not report TANF subawards to FFATA Subaward Reporting System (FSRS) because program personnel did not submit the required information to Finance to report in FSRS. Finance did not complete FFATA reporting submissions for three of 17 (18%) of the grant year 2023 Refugee Assistance subawards that spent $30,000 or more during fiscal year 2023. Social Services disbursed approximately $126,000 from these subawards during the fiscal year. Finance did not report Refugee Assistance subawards to FSRS for these three subawards because the initial subaward amount was less than $30,000 and program personnel did not inform Finance that subsequent subaward modifications increased the subaward value to over $30,000. Finance did not complete FFATA reporting submissions for grant year 2023 VOCA subawards during fiscal year 2023. Social Services disbursed approximately $3.5 million from 129 subawards during the fiscal year. Social Services did not report this information to FSRS because it inadvertently assumed that it was a subrecipient of the Department of Criminal Justice Services and did not need to complete FFATA reporting as required by the VOCA Grant Special Conditions document. Title 2 CFR Part 170 Appendix A requires the non-federal entity to report each obligating action exceeding $30,000 to the FSRS. Further, Title 2 CFR Part 170 Appendix A requires the non-federal entity to submit subaward information no later than the end of the month following the month in which it made the obligation. Finally, 2 CFR §200.303(a) states that the non-federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non-federal entity is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award. The decentralized nature of Social Services’ grants management practices and the volume of subawards elevates the risk that Finance will not report all subaward information to FSRS. Although Finance sent periodic email reminders to program staff responsible for submitting FFATA data to Finance for submission to FSRS, program personnel overlooked a significant percentage of these submissions because of turnover and a lack of familiarity with FFATA reporting requirements. Additionally, Finance did not have a compensating internal control in place to detect subawards that it did not report to FSRS. When Social Services does not upload all obligating actions meeting the reporting threshold to FSRS as required, a citizen or federal official may have a distorted view as to how Social Services is obligating federal funds. Therefore, Finance should continue to remind program personnel to submit required FFATA subaward reporting information to them and revise its policy to reflect any changes in its processes. Additionally, Finance should consider periodically checking Social Services’ financial records to determine if there are instances where program personnel are not submitting the required FFATA subaward reporting information. If so, Finance should collect this information from them promptly to comply with the FFATA reporting requirements. Views of Responsible Officials: Views of responsible officials are in the report related to their agency, which can be found at www.apa.virginia.gov. In summary, the views of responsible officials in the agency report do not express a disagreement with the finding.
Department of Health and Human Services Federal Financial Assistance Listing #93.498 COVID‐19 Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution Applicable Federal Award Number and Year – Period 4 TIN #420868216 Activities Allowed or Unallowed and Allowable Costs/Cost Principles Significant Deficiency in Internal Control Over Compliance Criteria: 2 CFR 200.303(a) establishes that the auditee must establish and maintain effective internal control over the federal award that provides assurance that the entity is managing the federal award in compliance with federal statutes, regulations, and conditions of the federal award. Condition: The Hospital claimed expenses in the HHS special report for Period 4 that were related to services to be performed after the period of availability. Cause: The Hospital did not have an internal control process in place to ensure that all expenditures claimed met the terms and conditions of the federal award. Effect: Without an improved internal control process there is a possibility that ineligible expenditures may be claimed under the program. Questioned Costs: None over the $25,000 threshold. Context: A nonstatistical sample of 65 items ($592,145) from a total population exceeding 250 items ($1,708,935) were tested. Repeat Finding from Prior Years: No Recommendation: We recommend the Hospital enhance internal control policies to ensure that the federal expenditures meet the terms and conditions of the grant. Views of Responsible Officials: Management agrees with the finding.
Department of Health and Human Services Federal Financial Assistance Listing #93.498 COVID‐19 Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution Applicable Federal Award Number and Year – Period 4 TIN #420868216 Reporting Significant Deficiency in Internal Control Over Compliance Criteria: 2 CFR 200.303(a) establishes that the auditee must establish and maintain effective internal control over the federal award that provides assurance that the entity is managing the federal award in compliance with federal statutes, regulations, and conditions of the federal award. Condition: There was no evidence retained that the Hospital’s special report submitted to the Department of Health and Human Services for Period 4 TIN #420868216 was reviewed or approved by an individual separate from the preparer prior to submission. Cause: The Hospital did not have an internal control process in place to ensure documented review of the report submitted to the Department of Health and Human Services for Period 4. Effect: The lack of adequate policies governing review and approval increases the risk that employees participating in the federal awards administration may not be able to detect and correct noncompliance in a timely manner. Questioned Costs: None reported. Context: Key line items were tested on the Period 4 Department of Health and Human Services special report. Repeat Finding from Prior Years: Yes Recommendation: We recommend the Hospital enhance internal control policies to ensure that formal documentation of review and approval is obtained and retained. Views of Responsible Officials: Management agrees with the finding.
FINDING 2023-001 Subject: Child Nutrition Cluster - Special Tests and Provisions - Verification of Free and Reduced Price Applications (NSLP) Federal Agency: Department of Agriculture Federal Programs: School Breakfast Program, National School Lunch Program Assistance Listings Numbers: 10.553, 10.555 Federal Award Number and Year (or Other Identifying Number): FY2023 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Special Tests and Provisions - Verification of Free and Reduced Price Applications (NSLP) Audit Findings: Material Weakness, Other Matters Repeat Finding This is a repeat finding from the prior audit report. The prior audit finding number was 2021-003. Condition and Context By November 15th of each school year, the Local Educational Agencies (LEA) must verify the current free and reduced price eligibility of households selected from a sample of applications that it has approved for free and reduced price meals, unless the LEA is otherwise exempt from the verification requirement. The verification sample size is based on the total number of approved applications on file on October 1st. If the LEA performs the verification function it must be in accordance with instructions provided by the state agency. The LEA must follow up on children whose eligibility status has changed as the result of verification activities to put them in the correct category. As instructed, LEAs must select a sample of applications to be verified utilizing one of the following methods: a. Standard sample size - The lesser of 3 percent or 3,000 of the approved applications on file as of October 1, selected from error-prone applications. For this purpose, error prone applications are those showing household incomes within $100 monthly or $1,200 annually of the income eligibility guidelines for free and reduced price meals. b. Alternative sample sizes - 1) The lesser of 3 percent or 3,000 applications selected at random from approved applications on file as of October 1 of the school year, or (2) The sum of (a) the lesser of 1 percent of all applications identified as error-prone or 1,000 error-prone applications, and (b) the lesser of 1/2 of 1 percent of, or 500, approved applications in which the household provided, in lieu of income information, a case number showing participation in the SNAP, TANF, or FDPIR. In accordance with the above guidance, the School Corporation selected a sample of applications based on the alternative sample size. As such, the School Corporation was required to review the lesser of 3 percent or 3,000 applications selected at random from approved applications on file as of October 1 of the 2022-2023 school year. On October 1, the School Corporation had 69 applications on file and determined that 3 applications were required to be verified. INDIANA STATE BOARD OF ACCOUNTS 14 SOUTH RIPLEY COMMUNITY SCHOOL CORPORATION SCHEDULE OF FINDINGS AND QUESTIONED COSTS (Continued) There was one employee that was responsible for performing the required verification of the 3 free and reduced price applications. There was no documentation of an oversight, review, or approval process to ensure that the verifications were properly performed. All 3 of the required verifications were selected for testing. For each verification, the School Corporation requested income documentation from the applicant to perform the verification as required. As a response was not received from any of the applicants, each student should have had a change in status from free or reduced to paid. Although, 2 of the students were flagged in the system as no response; the students' statuses were not appropriately updated to reflect that they were no longer eligible for free or reduced price meals. The remaining student was appropriately verified. The lack of internal controls and noncompliance were isolated to fiscal year 2022-2023. Criteria 2 CFR 200.303 states in part: "The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in 'Standards for Internal Control in the Federal Government' issued by the Comptroller General of the United States or the 'Internal Control Integrated Framework', issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). . . ." 7 CFR 245.6a states in part: "(f) Verification procedures and assistance for households – . . . (7) Eligibility changes. Based on the verification activities, the local educational agency shall make appropriate modifications to the eligibility determinations made initially. The local educational agency must notify the household of any change. Households must be notified of any reduction in benefits in accordance with paragraph (j) of this section. Households with reduced benefits or that are longer eligible for free or reduced price meals must be notified of their right to reapply at any time with documentation of income or participation in one of the eligible programs in paragraph (a)(1) of this section. . . . (j) Adverse action. If verification activities fail to confirm eligibility for free or reduced price benefits or should the household fail to cooperate with verification efforts, the school or local educational agency shall reduce or terminate benefits, as applicable, as follows: Ten days advance notification shall be provided to households that are to receive a reduction or termination of benefits, prior to the actual reduction or termination. The first day of the 10 day advance notice period shall be the day the notice is sent. The notice shall advise the household of: (1) The change; (2) The reasons for the change; INDIANA STATE BOARD OF ACCOUNTS 15 SOUTH RIPLEY COMMUNITY SCHOOL CORPORATION SCHEDULE OF FINDINGS AND QUESTIONED COSTS (Continued) (3) Notification of the right to appeal and when the appeal must be filed to ensure continued benefits while awaiting a hearing and decision; (4) Instructions on how to appeal; and (5) The right to reapply at any time during the school year. The reasons for ineligibility shall be properly documented and retained on file at the local educational agency." Cause A proper system of internal controls was not implemented by management of the School Corporation, which would include segregation of key functions. Embedded within a properly designed and implemented internal control system should be internal controls consisting of policies and procedures. Policies reflect the School Corporation's management statements of what should be done to effect internal controls, and procedures should consist of actions that would implement these policies. Effect Without the proper implementation of an effectively designed system of internal controls, the internal control system cannot be capable of effectively preventing, or detecting and correcting, material noncompliance. As a result, verifications for free and reduced price applications were not appropriately changed. Noncompliance with the provisions of federal statutes, regulations, and the terms and conditions of the federal award could result in the loss of future federal funding to the School Corporation. Questioned Costs There were no questioned costs identified. Recommendation We recommended that management of the School Corporation establish a proper system of internal controls and develop policies and procedures to ensure verifications for free and reduced price applications are appropriately changed. Views of Responsible Officials For the views of responsible officials, refer to the Corrective Action Plan that is part of this report.
FINDING 2023-001 Subject: Child Nutrition Cluster - Special Tests and Provisions - Verification of Free and Reduced Price Applications (NSLP) Federal Agency: Department of Agriculture Federal Programs: School Breakfast Program, National School Lunch Program Assistance Listings Numbers: 10.553, 10.555 Federal Award Number and Year (or Other Identifying Number): FY2023 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Special Tests and Provisions - Verification of Free and Reduced Price Applications (NSLP) Audit Findings: Material Weakness, Other Matters Repeat Finding This is a repeat finding from the prior audit report. The prior audit finding number was 2021-003. Condition and Context By November 15th of each school year, the Local Educational Agencies (LEA) must verify the current free and reduced price eligibility of households selected from a sample of applications that it has approved for free and reduced price meals, unless the LEA is otherwise exempt from the verification requirement. The verification sample size is based on the total number of approved applications on file on October 1st. If the LEA performs the verification function it must be in accordance with instructions provided by the state agency. The LEA must follow up on children whose eligibility status has changed as the result of verification activities to put them in the correct category. As instructed, LEAs must select a sample of applications to be verified utilizing one of the following methods: a. Standard sample size - The lesser of 3 percent or 3,000 of the approved applications on file as of October 1, selected from error-prone applications. For this purpose, error prone applications are those showing household incomes within $100 monthly or $1,200 annually of the income eligibility guidelines for free and reduced price meals. b. Alternative sample sizes - 1) The lesser of 3 percent or 3,000 applications selected at random from approved applications on file as of October 1 of the school year, or (2) The sum of (a) the lesser of 1 percent of all applications identified as error-prone or 1,000 error-prone applications, and (b) the lesser of 1/2 of 1 percent of, or 500, approved applications in which the household provided, in lieu of income information, a case number showing participation in the SNAP, TANF, or FDPIR. In accordance with the above guidance, the School Corporation selected a sample of applications based on the alternative sample size. As such, the School Corporation was required to review the lesser of 3 percent or 3,000 applications selected at random from approved applications on file as of October 1 of the 2022-2023 school year. On October 1, the School Corporation had 69 applications on file and determined that 3 applications were required to be verified. INDIANA STATE BOARD OF ACCOUNTS 14 SOUTH RIPLEY COMMUNITY SCHOOL CORPORATION SCHEDULE OF FINDINGS AND QUESTIONED COSTS (Continued) There was one employee that was responsible for performing the required verification of the 3 free and reduced price applications. There was no documentation of an oversight, review, or approval process to ensure that the verifications were properly performed. All 3 of the required verifications were selected for testing. For each verification, the School Corporation requested income documentation from the applicant to perform the verification as required. As a response was not received from any of the applicants, each student should have had a change in status from free or reduced to paid. Although, 2 of the students were flagged in the system as no response; the students' statuses were not appropriately updated to reflect that they were no longer eligible for free or reduced price meals. The remaining student was appropriately verified. The lack of internal controls and noncompliance were isolated to fiscal year 2022-2023. Criteria 2 CFR 200.303 states in part: "The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in 'Standards for Internal Control in the Federal Government' issued by the Comptroller General of the United States or the 'Internal Control Integrated Framework', issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). . . ." 7 CFR 245.6a states in part: "(f) Verification procedures and assistance for households – . . . (7) Eligibility changes. Based on the verification activities, the local educational agency shall make appropriate modifications to the eligibility determinations made initially. The local educational agency must notify the household of any change. Households must be notified of any reduction in benefits in accordance with paragraph (j) of this section. Households with reduced benefits or that are longer eligible for free or reduced price meals must be notified of their right to reapply at any time with documentation of income or participation in one of the eligible programs in paragraph (a)(1) of this section. . . . (j) Adverse action. If verification activities fail to confirm eligibility for free or reduced price benefits or should the household fail to cooperate with verification efforts, the school or local educational agency shall reduce or terminate benefits, as applicable, as follows: Ten days advance notification shall be provided to households that are to receive a reduction or termination of benefits, prior to the actual reduction or termination. The first day of the 10 day advance notice period shall be the day the notice is sent. The notice shall advise the household of: (1) The change; (2) The reasons for the change; INDIANA STATE BOARD OF ACCOUNTS 15 SOUTH RIPLEY COMMUNITY SCHOOL CORPORATION SCHEDULE OF FINDINGS AND QUESTIONED COSTS (Continued) (3) Notification of the right to appeal and when the appeal must be filed to ensure continued benefits while awaiting a hearing and decision; (4) Instructions on how to appeal; and (5) The right to reapply at any time during the school year. The reasons for ineligibility shall be properly documented and retained on file at the local educational agency." Cause A proper system of internal controls was not implemented by management of the School Corporation, which would include segregation of key functions. Embedded within a properly designed and implemented internal control system should be internal controls consisting of policies and procedures. Policies reflect the School Corporation's management statements of what should be done to effect internal controls, and procedures should consist of actions that would implement these policies. Effect Without the proper implementation of an effectively designed system of internal controls, the internal control system cannot be capable of effectively preventing, or detecting and correcting, material noncompliance. As a result, verifications for free and reduced price applications were not appropriately changed. Noncompliance with the provisions of federal statutes, regulations, and the terms and conditions of the federal award could result in the loss of future federal funding to the School Corporation. Questioned Costs There were no questioned costs identified. Recommendation We recommended that management of the School Corporation establish a proper system of internal controls and develop policies and procedures to ensure verifications for free and reduced price applications are appropriately changed. Views of Responsible Officials For the views of responsible officials, refer to the Corrective Action Plan that is part of this report.
FINDING 2023-002 Subject: Child Nutrition Cluster - Procurement and Suspension and Debarment Federal Agency: Department of Agriculture Federal Programs: School Breakfast Program, National School Lunch Program Assistance Listings Numbers: 10.553, 10.555 Federal Award Numbers and Years (or Other Identifying Numbers): FY2022, FY2023 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Procurement and Suspension and Debarment Audit Findings: Material Weakness, Other Matters INDIANA STATE BOARD OF ACCOUNTS 16 SOUTH RIPLEY COMMUNITY SCHOOL CORPORATION SCHEDULE OF FINDINGS AND QUESTIONED COSTS (Continued) Condition and Context Prior to entering into subawards and covered transactions with program funds, recipients are required to verify that such contractors and subrecipients are not suspended, debarred, or otherwise excluded. "Covered transactions" include, but are not limited to, contracts for goods and services awarded under a non-procurement transaction (i.e., grant agreement) that are expected to equal or exceed $25,000. The verification is to be done by checking the SAM exclusions, collecting a certification from that person, or adding a clause or condition to the covered transaction with that person. Upon inquiry of the School Corporation, in order to review the procedures in place for verifying that an entity with which it plans to enter into a covered transaction is not suspended, debarred, or otherwise excluded, the School Corporation disclosed there were not adequate procedures in place. The School Corporation verified that contractors were not suspended or debarred on a yearly basis, in June; however, this did not ensure the verification was performed of all required contractors, prior to entering into a covered transaction. One covered transaction that equaled or exceeded $25,000, paid from Child Nutrition Cluster funds, was identified. The one transaction, totaling $43,599, was selected for testing. The School Corporation did not verify the vendor's suspension and debarment status prior to payment. The lack of internal controls was a systemic issue throughout the audit period, the noncompliance was an issue in fiscal year 2022-2023. Criteria 2 CFR 200.303 states in part: "The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in 'Standards for Internal Control in the Federal Government' issued by the Comptroller General of the United States or the 'Internal Control Integrated Framework', issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). . . ." 2 CFR 180.300 states: "When you enter into a covered transaction with another person at the next lower tier, you must verify that the person with whom you intend to do business is not excluded or disqualified. You do this by: (a) Checking SAM Exclusions; or (b) Collecting a certification from that person; or (c) Adding a clause or condition to the covered transaction with that person." INDIANA STATE BOARD OF ACCOUNTS 17 SOUTH RIPLEY COMMUNITY SCHOOL CORPORATION SCHEDULE OF FINDINGS AND QUESTIONED COSTS (Continued) Cause A proper system of internal controls was not implemented by management of the School Corporation, which would include segregation of key functions. Embedded within a properly designed and implemented internal control system should be internal controls consisting of policies and procedures. Policies reflect the School Corporation's management statements of what should be done to effect internal controls, and procedures should consist of actions that would implement these policies. Effect Without the proper implementation of an effectively designed system of internal controls, the internal control system cannot be capable of effectively preventing, or detecting and correcting, material noncompliance. As a result, vendors to whom payments equal to or in excess of $25,000 were not verified to be not suspended, debarred, or otherwise excluded. Noncompliance with the provisions of federal statutes, regulations, and the terms and conditions of the federal award could result in the loss of future federal funding to the School Corporation. Questioned Costs There were no questioned costs identified. Recommendation We recommended that management of the School Corporation establish a proper system of internal controls and develop policies and procedures to ensure contractors and subrecipients, as appropriate, are not suspended, debarred, or otherwise excluded prior to entering into any covered transactions. Views of Responsible Officials For the views of responsible officials, refer to the Corrective Action Plan that is part of this report.
FINDING 2023-002 Subject: Child Nutrition Cluster - Procurement and Suspension and Debarment Federal Agency: Department of Agriculture Federal Programs: School Breakfast Program, National School Lunch Program Assistance Listings Numbers: 10.553, 10.555 Federal Award Numbers and Years (or Other Identifying Numbers): FY2022, FY2023 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Procurement and Suspension and Debarment Audit Findings: Material Weakness, Other Matters INDIANA STATE BOARD OF ACCOUNTS 16 SOUTH RIPLEY COMMUNITY SCHOOL CORPORATION SCHEDULE OF FINDINGS AND QUESTIONED COSTS (Continued) Condition and Context Prior to entering into subawards and covered transactions with program funds, recipients are required to verify that such contractors and subrecipients are not suspended, debarred, or otherwise excluded. "Covered transactions" include, but are not limited to, contracts for goods and services awarded under a non-procurement transaction (i.e., grant agreement) that are expected to equal or exceed $25,000. The verification is to be done by checking the SAM exclusions, collecting a certification from that person, or adding a clause or condition to the covered transaction with that person. Upon inquiry of the School Corporation, in order to review the procedures in place for verifying that an entity with which it plans to enter into a covered transaction is not suspended, debarred, or otherwise excluded, the School Corporation disclosed there were not adequate procedures in place. The School Corporation verified that contractors were not suspended or debarred on a yearly basis, in June; however, this did not ensure the verification was performed of all required contractors, prior to entering into a covered transaction. One covered transaction that equaled or exceeded $25,000, paid from Child Nutrition Cluster funds, was identified. The one transaction, totaling $43,599, was selected for testing. The School Corporation did not verify the vendor's suspension and debarment status prior to payment. The lack of internal controls was a systemic issue throughout the audit period, the noncompliance was an issue in fiscal year 2022-2023. Criteria 2 CFR 200.303 states in part: "The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in 'Standards for Internal Control in the Federal Government' issued by the Comptroller General of the United States or the 'Internal Control Integrated Framework', issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). . . ." 2 CFR 180.300 states: "When you enter into a covered transaction with another person at the next lower tier, you must verify that the person with whom you intend to do business is not excluded or disqualified. You do this by: (a) Checking SAM Exclusions; or (b) Collecting a certification from that person; or (c) Adding a clause or condition to the covered transaction with that person." INDIANA STATE BOARD OF ACCOUNTS 17 SOUTH RIPLEY COMMUNITY SCHOOL CORPORATION SCHEDULE OF FINDINGS AND QUESTIONED COSTS (Continued) Cause A proper system of internal controls was not implemented by management of the School Corporation, which would include segregation of key functions. Embedded within a properly designed and implemented internal control system should be internal controls consisting of policies and procedures. Policies reflect the School Corporation's management statements of what should be done to effect internal controls, and procedures should consist of actions that would implement these policies. Effect Without the proper implementation of an effectively designed system of internal controls, the internal control system cannot be capable of effectively preventing, or detecting and correcting, material noncompliance. As a result, vendors to whom payments equal to or in excess of $25,000 were not verified to be not suspended, debarred, or otherwise excluded. Noncompliance with the provisions of federal statutes, regulations, and the terms and conditions of the federal award could result in the loss of future federal funding to the School Corporation. Questioned Costs There were no questioned costs identified. Recommendation We recommended that management of the School Corporation establish a proper system of internal controls and develop policies and procedures to ensure contractors and subrecipients, as appropriate, are not suspended, debarred, or otherwise excluded prior to entering into any covered transactions. Views of Responsible Officials For the views of responsible officials, refer to the Corrective Action Plan that is part of this report.
FINDING 2023-002 Subject: Child Nutrition Cluster - Procurement and Suspension and Debarment Federal Agency: Department of Agriculture Federal Programs: School Breakfast Program, National School Lunch Program Assistance Listings Numbers: 10.553, 10.555 Federal Award Numbers and Years (or Other Identifying Numbers): FY2022, FY2023 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Procurement and Suspension and Debarment Audit Findings: Material Weakness, Other Matters INDIANA STATE BOARD OF ACCOUNTS 16 SOUTH RIPLEY COMMUNITY SCHOOL CORPORATION SCHEDULE OF FINDINGS AND QUESTIONED COSTS (Continued) Condition and Context Prior to entering into subawards and covered transactions with program funds, recipients are required to verify that such contractors and subrecipients are not suspended, debarred, or otherwise excluded. "Covered transactions" include, but are not limited to, contracts for goods and services awarded under a non-procurement transaction (i.e., grant agreement) that are expected to equal or exceed $25,000. The verification is to be done by checking the SAM exclusions, collecting a certification from that person, or adding a clause or condition to the covered transaction with that person. Upon inquiry of the School Corporation, in order to review the procedures in place for verifying that an entity with which it plans to enter into a covered transaction is not suspended, debarred, or otherwise excluded, the School Corporation disclosed there were not adequate procedures in place. The School Corporation verified that contractors were not suspended or debarred on a yearly basis, in June; however, this did not ensure the verification was performed of all required contractors, prior to entering into a covered transaction. One covered transaction that equaled or exceeded $25,000, paid from Child Nutrition Cluster funds, was identified. The one transaction, totaling $43,599, was selected for testing. The School Corporation did not verify the vendor's suspension and debarment status prior to payment. The lack of internal controls was a systemic issue throughout the audit period, the noncompliance was an issue in fiscal year 2022-2023. Criteria 2 CFR 200.303 states in part: "The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in 'Standards for Internal Control in the Federal Government' issued by the Comptroller General of the United States or the 'Internal Control Integrated Framework', issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). . . ." 2 CFR 180.300 states: "When you enter into a covered transaction with another person at the next lower tier, you must verify that the person with whom you intend to do business is not excluded or disqualified. You do this by: (a) Checking SAM Exclusions; or (b) Collecting a certification from that person; or (c) Adding a clause or condition to the covered transaction with that person." INDIANA STATE BOARD OF ACCOUNTS 17 SOUTH RIPLEY COMMUNITY SCHOOL CORPORATION SCHEDULE OF FINDINGS AND QUESTIONED COSTS (Continued) Cause A proper system of internal controls was not implemented by management of the School Corporation, which would include segregation of key functions. Embedded within a properly designed and implemented internal control system should be internal controls consisting of policies and procedures. Policies reflect the School Corporation's management statements of what should be done to effect internal controls, and procedures should consist of actions that would implement these policies. Effect Without the proper implementation of an effectively designed system of internal controls, the internal control system cannot be capable of effectively preventing, or detecting and correcting, material noncompliance. As a result, vendors to whom payments equal to or in excess of $25,000 were not verified to be not suspended, debarred, or otherwise excluded. Noncompliance with the provisions of federal statutes, regulations, and the terms and conditions of the federal award could result in the loss of future federal funding to the School Corporation. Questioned Costs There were no questioned costs identified. Recommendation We recommended that management of the School Corporation establish a proper system of internal controls and develop policies and procedures to ensure contractors and subrecipients, as appropriate, are not suspended, debarred, or otherwise excluded prior to entering into any covered transactions. Views of Responsible Officials For the views of responsible officials, refer to the Corrective Action Plan that is part of this report.
FINDING 2023-002 Subject: Child Nutrition Cluster - Procurement and Suspension and Debarment Federal Agency: Department of Agriculture Federal Programs: School Breakfast Program, National School Lunch Program Assistance Listings Numbers: 10.553, 10.555 Federal Award Numbers and Years (or Other Identifying Numbers): FY2022, FY2023 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Procurement and Suspension and Debarment Audit Findings: Material Weakness, Other Matters INDIANA STATE BOARD OF ACCOUNTS 16 SOUTH RIPLEY COMMUNITY SCHOOL CORPORATION SCHEDULE OF FINDINGS AND QUESTIONED COSTS (Continued) Condition and Context Prior to entering into subawards and covered transactions with program funds, recipients are required to verify that such contractors and subrecipients are not suspended, debarred, or otherwise excluded. "Covered transactions" include, but are not limited to, contracts for goods and services awarded under a non-procurement transaction (i.e., grant agreement) that are expected to equal or exceed $25,000. The verification is to be done by checking the SAM exclusions, collecting a certification from that person, or adding a clause or condition to the covered transaction with that person. Upon inquiry of the School Corporation, in order to review the procedures in place for verifying that an entity with which it plans to enter into a covered transaction is not suspended, debarred, or otherwise excluded, the School Corporation disclosed there were not adequate procedures in place. The School Corporation verified that contractors were not suspended or debarred on a yearly basis, in June; however, this did not ensure the verification was performed of all required contractors, prior to entering into a covered transaction. One covered transaction that equaled or exceeded $25,000, paid from Child Nutrition Cluster funds, was identified. The one transaction, totaling $43,599, was selected for testing. The School Corporation did not verify the vendor's suspension and debarment status prior to payment. The lack of internal controls was a systemic issue throughout the audit period, the noncompliance was an issue in fiscal year 2022-2023. Criteria 2 CFR 200.303 states in part: "The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in 'Standards for Internal Control in the Federal Government' issued by the Comptroller General of the United States or the 'Internal Control Integrated Framework', issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). . . ." 2 CFR 180.300 states: "When you enter into a covered transaction with another person at the next lower tier, you must verify that the person with whom you intend to do business is not excluded or disqualified. You do this by: (a) Checking SAM Exclusions; or (b) Collecting a certification from that person; or (c) Adding a clause or condition to the covered transaction with that person." INDIANA STATE BOARD OF ACCOUNTS 17 SOUTH RIPLEY COMMUNITY SCHOOL CORPORATION SCHEDULE OF FINDINGS AND QUESTIONED COSTS (Continued) Cause A proper system of internal controls was not implemented by management of the School Corporation, which would include segregation of key functions. Embedded within a properly designed and implemented internal control system should be internal controls consisting of policies and procedures. Policies reflect the School Corporation's management statements of what should be done to effect internal controls, and procedures should consist of actions that would implement these policies. Effect Without the proper implementation of an effectively designed system of internal controls, the internal control system cannot be capable of effectively preventing, or detecting and correcting, material noncompliance. As a result, vendors to whom payments equal to or in excess of $25,000 were not verified to be not suspended, debarred, or otherwise excluded. Noncompliance with the provisions of federal statutes, regulations, and the terms and conditions of the federal award could result in the loss of future federal funding to the School Corporation. Questioned Costs There were no questioned costs identified. Recommendation We recommended that management of the School Corporation establish a proper system of internal controls and develop policies and procedures to ensure contractors and subrecipients, as appropriate, are not suspended, debarred, or otherwise excluded prior to entering into any covered transactions. Views of Responsible Officials For the views of responsible officials, refer to the Corrective Action Plan that is part of this report.
FINDING 2023-003 Subject: Special Education Cluster (IDEA) - Procurement and Suspension and Debarment Federal Agency: Department of Education Federal Programs: Special Education Grants to States, COVID-19 - Individuals with Disabilities Education Act of 2021 (ARP) Assistance Listings Numbers: 84.027, 84.027X Federal Award Numbers and Years (or Other Identifying Numbers): 23611-048-PN01, 22611-048-ARP Pass-Through Entity: Indiana Department of Education Compliance Requirements: Procurement and Suspension and Debarment Audit Findings: Material Weakness, Modified Opinion Condition and Context The School Corporation is a member of the Ripley-Ohio-Dearborn Special Education Cooperative (Cooperative). As the grant agreements were between the Indiana Department of Education and each member school, the School Corporation was responsible for ensuring and providing oversight of the Cooperative. However, there was inadequate oversight performed by the School Corporation in order to ensure compliance with the Procurement and Suspension and Debarment compliance requirement. INDIANA STATE BOARD OF ACCOUNTS 18 SOUTH RIPLEY COMMUNITY SCHOOL CORPORATION SCHEDULE OF FINDINGS AND QUESTIONED COSTS (Continued) The School Corporation did not have internal controls in place to ensure that the Cooperative complied with the procurement and the suspension and debarment requirements. The Cooperative did not have adequate procedures in place to ensure that the requirements for small purchases were met for each applicable procured good or service or to ensure that vendors were not suspended or debarred prior to entering into a covered transaction. Procurement Federal regulations allow for informal procurement methods when the value of the procurement for goods or services does not exceed the simplified acquisition threshold, which is customarily set at $250,000. However, Indiana Code 5-22-8 has a more restrictive threshold of $150,000 or less for when small purchase procedures may be used. This informal process allows for methods other than the formal bid process. The informal process is divided between two methods based on thresholds. Micro-purchases, typically for those purchases $10,000 or under, and small purchase procedures for those purchases above the micro-purchase threshold, but below the simplified acquisition threshold. Micro-purchases may be awarded without soliciting competitive price rate quotations. If small purchase procedures are used, then price or rate quotations must be obtained from an adequate number of qualified sources. If it is determined a single source provider can be used for a small purchase, documentation must be retained supporting the determination. Two vendors exceeded the small purchase threshold during the audit period. Both vendors were selected for testing. In both cases, the Cooperative had determined the curriculum and materials that were purchased, totaling $109,322, were to be provided by a single source provider; however, they did not have a documented rationale or support for the decision. Documentation detailing the history of procurement, which must include the reason for the procurement method used, selection of the vendor, and the basis for the price, was not available for audit for either purchase. Suspension and Debarment Prior to entering into subawards and covered transactions with SPED award funds, recipients are required to verify that such contractors and subrecipients are not suspended, debarred, or otherwise excluded. "Covered transactions" include, but are not limited to, contracts for goods and services awarded under a nonprocurement transaction (i.e., grant agreement) that are expected to equal or exceed $25,000. The verification is to be done by checking the SAMS Exclusions, collecting a certification from that person, or adding a clause or condition to the covered transaction with that person. Two covered transactions were identified that equaled or exceeded $25,000. Both transactions, totaling $109,322 were selected for testing. For the noted transactions, the Cooperative did not verify the vendor's suspension and debarment status prior to payment due to the Cooperative not having any policies or procedures in place to verify that contractors were neither suspended nor debarred, or otherwise excluded or disqualified from participating in federal assistance programs or activities. The lack of internal controls and noncompliance were isolated to fiscal year 2022-2023 and the 23611-048-PN01 and 22611-048-ARP grants. INDIANA STATE BOARD OF ACCOUNTS 19 SOUTH RIPLEY COMMUNITY SCHOOL CORPORATION SCHEDULE OF FINDINGS AND QUESTIONED COSTS (Continued) Criteria 2 CFR 200.303 states in part: "The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in 'Standards for Internal Control in the Federal Government' issued by the Comptroller General of the United States or the 'Internal Control Integrated Framework', issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). . . ." 2 CFR 200.318(i) states: "The non-Federal entity must maintain records sufficient to detail the history of procurement. These records will include, but are not necessarily limited to the following: Rationale for the method of procurement, selection of contract type, contractor selection or rejection, and the basis for the contract price." 2 CFR 200.320 states in part: "The non-Federal entity must have and use documented procurement procedures , consistent with the standards of this section and §§ 200.317, 200.318, and 200.319 for any of the following methods of procurement used for the acquisition of property or services required under a Federal award or sub-award. (a) Informal procurement methods. When the value of the procurement for property or services under a Federal award does not exceed the simplified acquisition threshold (SAT), as defined in § 200.1, or a lower threshold established by a non-Federal entity, formal procurement methods are not required. The non-Federal entity may use informal procurement methods to expedite the completion of its transactions and minimize the associated administrative burden and cost. The informal methods used for procurement of property or services at or below the SAT include: . . . (1) Small purchases — (i) Small purchase procedures. The acquisition of property or services, the aggregate dollar amount of which is higher than the micro-purchase threshold but does not exceed the simplified acquisition threshold. If small purchase procedures are used, price or rate quotations must be obtained from an adequate number of qualified sources as determined appropriate by the non-Federal entity. . . . " 2 CFR 180.300 states: "When you enter into a covered transaction with another person at the next lower tier, you must verify that the person with whom you intend to do business is not excluded or disqualified. You do this by: (a) Checking SAM Exclusions; or INDIANA STATE BOARD OF ACCOUNTS 20 SOUTH RIPLEY COMMUNITY SCHOOL CORPORATION SCHEDULE OF FINDINGS AND QUESTIONED COSTS (Continued) (b) Collecting a certification from that person; or (c) Adding a clause or condition to the covered transaction with that person." Cause A proper system of internal controls was not implemented by management of the School Corporation, which would include segregation of key functions. Embedded within a properly designed and implemented internal control system should be internal controls consisting of policies and procedures. Policies reflect the School Corporation's management statements of what should be done to effect internal controls, and procedures should consist of actions that would implement these policies. Effect Without the proper implementation of an effectively designed system of internal controls, including policies and procedures that provide segregation of duties and additional oversight as needed, the internal control system cannot be capable of effectively preventing, or detecting and correcting, material noncompliance. As a result, adequate documentation was not retained for procurements that fell within the small purchase threshold and vendors to whom payments equal to or in excess of $25,000 were made, were not verified to be not suspended, debarred, or otherwise excluded. Noncompliance with the provisions of federal statutes, regulations, and the terms and conditions of the federal award could result in the loss of future federal funding to the School Corporation. Questioned Costs There were no questioned costs identified. Recommendation We recommended that management of the School Corporation establish a proper system of internal controls and develop policies and procedures to ensure all required documentation is retained and provided for small purchases and to ensure contractors and subrecipients, as appropriate are not suspended, debarred, or otherwise excluded prior to entering into any contracts or subawards. Views of Responsible Officials For the views of responsible officials, refer to the Corrective Action Plan that is part of this report.
FINDING 2023-003 Subject: Special Education Cluster (IDEA) - Procurement and Suspension and Debarment Federal Agency: Department of Education Federal Programs: Special Education Grants to States, COVID-19 - Individuals with Disabilities Education Act of 2021 (ARP) Assistance Listings Numbers: 84.027, 84.027X Federal Award Numbers and Years (or Other Identifying Numbers): 23611-048-PN01, 22611-048-ARP Pass-Through Entity: Indiana Department of Education Compliance Requirements: Procurement and Suspension and Debarment Audit Findings: Material Weakness, Modified Opinion Condition and Context The School Corporation is a member of the Ripley-Ohio-Dearborn Special Education Cooperative (Cooperative). As the grant agreements were between the Indiana Department of Education and each member school, the School Corporation was responsible for ensuring and providing oversight of the Cooperative. However, there was inadequate oversight performed by the School Corporation in order to ensure compliance with the Procurement and Suspension and Debarment compliance requirement. INDIANA STATE BOARD OF ACCOUNTS 18 SOUTH RIPLEY COMMUNITY SCHOOL CORPORATION SCHEDULE OF FINDINGS AND QUESTIONED COSTS (Continued) The School Corporation did not have internal controls in place to ensure that the Cooperative complied with the procurement and the suspension and debarment requirements. The Cooperative did not have adequate procedures in place to ensure that the requirements for small purchases were met for each applicable procured good or service or to ensure that vendors were not suspended or debarred prior to entering into a covered transaction. Procurement Federal regulations allow for informal procurement methods when the value of the procurement for goods or services does not exceed the simplified acquisition threshold, which is customarily set at $250,000. However, Indiana Code 5-22-8 has a more restrictive threshold of $150,000 or less for when small purchase procedures may be used. This informal process allows for methods other than the formal bid process. The informal process is divided between two methods based on thresholds. Micro-purchases, typically for those purchases $10,000 or under, and small purchase procedures for those purchases above the micro-purchase threshold, but below the simplified acquisition threshold. Micro-purchases may be awarded without soliciting competitive price rate quotations. If small purchase procedures are used, then price or rate quotations must be obtained from an adequate number of qualified sources. If it is determined a single source provider can be used for a small purchase, documentation must be retained supporting the determination. Two vendors exceeded the small purchase threshold during the audit period. Both vendors were selected for testing. In both cases, the Cooperative had determined the curriculum and materials that were purchased, totaling $109,322, were to be provided by a single source provider; however, they did not have a documented rationale or support for the decision. Documentation detailing the history of procurement, which must include the reason for the procurement method used, selection of the vendor, and the basis for the price, was not available for audit for either purchase. Suspension and Debarment Prior to entering into subawards and covered transactions with SPED award funds, recipients are required to verify that such contractors and subrecipients are not suspended, debarred, or otherwise excluded. "Covered transactions" include, but are not limited to, contracts for goods and services awarded under a nonprocurement transaction (i.e., grant agreement) that are expected to equal or exceed $25,000. The verification is to be done by checking the SAMS Exclusions, collecting a certification from that person, or adding a clause or condition to the covered transaction with that person. Two covered transactions were identified that equaled or exceeded $25,000. Both transactions, totaling $109,322 were selected for testing. For the noted transactions, the Cooperative did not verify the vendor's suspension and debarment status prior to payment due to the Cooperative not having any policies or procedures in place to verify that contractors were neither suspended nor debarred, or otherwise excluded or disqualified from participating in federal assistance programs or activities. The lack of internal controls and noncompliance were isolated to fiscal year 2022-2023 and the 23611-048-PN01 and 22611-048-ARP grants. INDIANA STATE BOARD OF ACCOUNTS 19 SOUTH RIPLEY COMMUNITY SCHOOL CORPORATION SCHEDULE OF FINDINGS AND QUESTIONED COSTS (Continued) Criteria 2 CFR 200.303 states in part: "The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in 'Standards for Internal Control in the Federal Government' issued by the Comptroller General of the United States or the 'Internal Control Integrated Framework', issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). . . ." 2 CFR 200.318(i) states: "The non-Federal entity must maintain records sufficient to detail the history of procurement. These records will include, but are not necessarily limited to the following: Rationale for the method of procurement, selection of contract type, contractor selection or rejection, and the basis for the contract price." 2 CFR 200.320 states in part: "The non-Federal entity must have and use documented procurement procedures , consistent with the standards of this section and §§ 200.317, 200.318, and 200.319 for any of the following methods of procurement used for the acquisition of property or services required under a Federal award or sub-award. (a) Informal procurement methods. When the value of the procurement for property or services under a Federal award does not exceed the simplified acquisition threshold (SAT), as defined in § 200.1, or a lower threshold established by a non-Federal entity, formal procurement methods are not required. The non-Federal entity may use informal procurement methods to expedite the completion of its transactions and minimize the associated administrative burden and cost. The informal methods used for procurement of property or services at or below the SAT include: . . . (1) Small purchases — (i) Small purchase procedures. The acquisition of property or services, the aggregate dollar amount of which is higher than the micro-purchase threshold but does not exceed the simplified acquisition threshold. If small purchase procedures are used, price or rate quotations must be obtained from an adequate number of qualified sources as determined appropriate by the non-Federal entity. . . . " 2 CFR 180.300 states: "When you enter into a covered transaction with another person at the next lower tier, you must verify that the person with whom you intend to do business is not excluded or disqualified. You do this by: (a) Checking SAM Exclusions; or INDIANA STATE BOARD OF ACCOUNTS 20 SOUTH RIPLEY COMMUNITY SCHOOL CORPORATION SCHEDULE OF FINDINGS AND QUESTIONED COSTS (Continued) (b) Collecting a certification from that person; or (c) Adding a clause or condition to the covered transaction with that person." Cause A proper system of internal controls was not implemented by management of the School Corporation, which would include segregation of key functions. Embedded within a properly designed and implemented internal control system should be internal controls consisting of policies and procedures. Policies reflect the School Corporation's management statements of what should be done to effect internal controls, and procedures should consist of actions that would implement these policies. Effect Without the proper implementation of an effectively designed system of internal controls, including policies and procedures that provide segregation of duties and additional oversight as needed, the internal control system cannot be capable of effectively preventing, or detecting and correcting, material noncompliance. As a result, adequate documentation was not retained for procurements that fell within the small purchase threshold and vendors to whom payments equal to or in excess of $25,000 were made, were not verified to be not suspended, debarred, or otherwise excluded. Noncompliance with the provisions of federal statutes, regulations, and the terms and conditions of the federal award could result in the loss of future federal funding to the School Corporation. Questioned Costs There were no questioned costs identified. Recommendation We recommended that management of the School Corporation establish a proper system of internal controls and develop policies and procedures to ensure all required documentation is retained and provided for small purchases and to ensure contractors and subrecipients, as appropriate are not suspended, debarred, or otherwise excluded prior to entering into any contracts or subawards. Views of Responsible Officials For the views of responsible officials, refer to the Corrective Action Plan that is part of this report.
FINDING 2023-004 Subject: Special Education Cluster (IDEA) - Earmarking Federal Agency: Department of Education Federal Program: Special Education Grants to States Assistance Listings Number: 84.027 Federal Award Numbers and Years (or Other Identifying Numbers): 21611-048-PN01, 22611-048-PN01 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Matching, Level of Effort, Earmarking Audit Findings: Material Weakness, Modified Opinion INDIANA STATE BOARD OF ACCOUNTS 21 SOUTH RIPLEY COMMUNITY SCHOOL CORPORATION SCHEDULE OF FINDINGS AND QUESTIONED COSTS (Continued) Repeat Finding This is a repeat finding from the prior audit report. The prior audit finding number was 2021-001. Condition and Context The School Corporation is a member of the Ripley-Ohio-Dearborn Special Education Cooperative (Cooperative). During fiscal years 2021-2022 and 2022-2023, the Cooperative operated the special education programs and spent the federal money for earmarked expenditures on behalf of 3 of the 6 member schools. As the grant agreement was between the Indiana Department of Education (IDOE) and the member school, the School Corporation was responsible for ensuring and providing oversight of the Cooperative. However, there was inadequate oversight performed by the School Corporation in order to ensure compliance with the Matching, Level of Effort, Earmarking compliance requirement. The School Corporation did not have internal controls in place to ensure that the Cooperative complied with the earmarking requirements. The Cooperative did not have adequate procedures in place to ensure that the required level of expenditures for nonpublic school students with disabilities was met for each member school. The Cooperative did not have effective internal controls to ensure nonpublic school expenditures were appropriately identified and reported. The Non-Public Proportionate Share expenditures for the 21611-048-PN01 and 22611-048-PN01 grant awards could not be verified for the individual member schools. The nonpublic school share funds for the participating member schools were allocated based on the yearly budget for certified staff instead of time charged to the nonpublic schools. These allocations were the amounts reported to the IDOE. As such, we were unable to identify which expenditures were for each school in order to verify the minimum amount per the grant award was expended and properly reported to the IDOE as required. The lack of internal controls and noncompliance was isolated to the 21611-048-PN01 and 22611-048-PN01 grant awards. Criteria 2 CFR 200.303 states in part: "The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in 'Standards for Internal Control in the Federal Government' issued by the Comptroller General of the United States or the 'Internal Control Integrated Framework', issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). . . ." 2 CFR 200.403 states in part: "Except where otherwise authorized by statute, costs must meet the following general criteria in order to be allowable under Federal awards: . . . (g) Be adequately documented. . . ." INDIANA STATE BOARD OF ACCOUNTS 22 SOUTH RIPLEY COMMUNITY SCHOOL CORPORATION SCHEDULE OF FINDINGS AND QUESTIONED COSTS (Continued) 2 CFR 200.208(b) states in part: "The Federal awarding agency or pass-through entity may adjust specific Federal award conditions as needed . . ." 511 IAC 7-34-7(b) states: "The public agency, in providing special education and related services to students in nonpublic schools must expend at least an amount that is the same proportion of the public agency total subgrant under 20 U.S.C. 1411(f) as the number of nonpublic school students with disabilities, who are enrolled by their parents in nonpublic schools within its boundaries, is to the total number of students with disabilities of the same age range." Cause A proper system of internal controls was not designed by management of the School Corporation. Embedded within a properly designed and implemented internal control system should be internal controls consisting of policies and procedures. Policies reflect the School Corporation's management statements of what should be done to effect internal controls, and procedures should consist of actions that would implement these policies. Effect Without the proper implementation of an effectively designed system of internal controls, the internal control system cannot be capable of effectively preventing, or detecting and correcting, material noncompliance. Noncompliance with the provisions of federal statutes, regulations, and the terms and conditions of the federal award could result in the loss of future federal funding to the School Corporation. Questioned Costs There were no questioned costs identified. Recommendation We recommended that management of the School Corporation establish a proper system of internal controls and develop policies and procedures to ensure non-public proportionate share funds are appropriately allocated to the member school based on expenses charged directly on behalf of the member school. Supporting documentation for these expenses should be retained for audit. Views of Responsible Officials For the views of responsible officials, refer to the Corrective Action Plan that is part of this report.
FINDING 2023-004 Subject: Special Education Cluster (IDEA) - Earmarking Federal Agency: Department of Education Federal Program: Special Education Grants to States Assistance Listings Number: 84.027 Federal Award Numbers and Years (or Other Identifying Numbers): 21611-048-PN01, 22611-048-PN01 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Matching, Level of Effort, Earmarking Audit Findings: Material Weakness, Modified Opinion INDIANA STATE BOARD OF ACCOUNTS 21 SOUTH RIPLEY COMMUNITY SCHOOL CORPORATION SCHEDULE OF FINDINGS AND QUESTIONED COSTS (Continued) Repeat Finding This is a repeat finding from the prior audit report. The prior audit finding number was 2021-001. Condition and Context The School Corporation is a member of the Ripley-Ohio-Dearborn Special Education Cooperative (Cooperative). During fiscal years 2021-2022 and 2022-2023, the Cooperative operated the special education programs and spent the federal money for earmarked expenditures on behalf of 3 of the 6 member schools. As the grant agreement was between the Indiana Department of Education (IDOE) and the member school, the School Corporation was responsible for ensuring and providing oversight of the Cooperative. However, there was inadequate oversight performed by the School Corporation in order to ensure compliance with the Matching, Level of Effort, Earmarking compliance requirement. The School Corporation did not have internal controls in place to ensure that the Cooperative complied with the earmarking requirements. The Cooperative did not have adequate procedures in place to ensure that the required level of expenditures for nonpublic school students with disabilities was met for each member school. The Cooperative did not have effective internal controls to ensure nonpublic school expenditures were appropriately identified and reported. The Non-Public Proportionate Share expenditures for the 21611-048-PN01 and 22611-048-PN01 grant awards could not be verified for the individual member schools. The nonpublic school share funds for the participating member schools were allocated based on the yearly budget for certified staff instead of time charged to the nonpublic schools. These allocations were the amounts reported to the IDOE. As such, we were unable to identify which expenditures were for each school in order to verify the minimum amount per the grant award was expended and properly reported to the IDOE as required. The lack of internal controls and noncompliance was isolated to the 21611-048-PN01 and 22611-048-PN01 grant awards. Criteria 2 CFR 200.303 states in part: "The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in 'Standards for Internal Control in the Federal Government' issued by the Comptroller General of the United States or the 'Internal Control Integrated Framework', issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). . . ." 2 CFR 200.403 states in part: "Except where otherwise authorized by statute, costs must meet the following general criteria in order to be allowable under Federal awards: . . . (g) Be adequately documented. . . ." INDIANA STATE BOARD OF ACCOUNTS 22 SOUTH RIPLEY COMMUNITY SCHOOL CORPORATION SCHEDULE OF FINDINGS AND QUESTIONED COSTS (Continued) 2 CFR 200.208(b) states in part: "The Federal awarding agency or pass-through entity may adjust specific Federal award conditions as needed . . ." 511 IAC 7-34-7(b) states: "The public agency, in providing special education and related services to students in nonpublic schools must expend at least an amount that is the same proportion of the public agency total subgrant under 20 U.S.C. 1411(f) as the number of nonpublic school students with disabilities, who are enrolled by their parents in nonpublic schools within its boundaries, is to the total number of students with disabilities of the same age range." Cause A proper system of internal controls was not designed by management of the School Corporation. Embedded within a properly designed and implemented internal control system should be internal controls consisting of policies and procedures. Policies reflect the School Corporation's management statements of what should be done to effect internal controls, and procedures should consist of actions that would implement these policies. Effect Without the proper implementation of an effectively designed system of internal controls, the internal control system cannot be capable of effectively preventing, or detecting and correcting, material noncompliance. Noncompliance with the provisions of federal statutes, regulations, and the terms and conditions of the federal award could result in the loss of future federal funding to the School Corporation. Questioned Costs There were no questioned costs identified. Recommendation We recommended that management of the School Corporation establish a proper system of internal controls and develop policies and procedures to ensure non-public proportionate share funds are appropriately allocated to the member school based on expenses charged directly on behalf of the member school. Supporting documentation for these expenses should be retained for audit. Views of Responsible Officials For the views of responsible officials, refer to the Corrective Action Plan that is part of this report.
FINDING 2023-001 Subject: Special Education Cluster (IDEA) - Earmarking Federal Agency: Department of Education Federal Programs: Special Education Grants to States, Special Education Preschool Grants Assistance Listings Numbers: 84.027, 84.173 Federal Award Numbers and Years (or Other Identifying Numbers): 20611-021-PN01, 21611-021-PN01, 22619-021-PN01 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Matching, Level of Effort, Earmarking Audit Findings: Material Weakness, Modified Opinion Condition and Context The School Corporation is a member of the Greater Lafayette Area Special Services Cooperative (Cooperative). During fiscal years 2021-2022 and 2022-2023, the Cooperative operated the special education programs and spent the federal money on behalf of all its members. As the grant agreements were between the Indiana Department of Education (IDOE) and each member school, the School Corporation was responsible for ensuring and providing oversight of the Cooperative. However, there was inadequate oversight performed by the School Corporation in order to ensure compliance with the Matching, Level of Effort, Earmarking compliance requirement. The School Corporation did not have internal controls in place to ensure that the Cooperative complied with the earmarking requirements. The Cooperative did not have adequate procedures in place to ensure that the required level of expenditures for nonpublic school students with disabilities was met for each member school. The Cooperative did not have effective internal controls to ensure nonpublic school expenditures were appropriately identified and reported. The Non-Public Proportionate Share expenditures for the 20611-021-PN01, 21611-021-PN01, and 22619-021-PN01 grant awards could not be verified for the individual member school corporations. Total grant expenditures were posted as expended. The Non-Public Proportionate Share expenditures were determined by applying a percentage to the nonpublic school budgeted expenditures. As such, we were unable to identify if the minimum amount per the grant awards was expended and properly reported to the IDOE as required. The lack of internal controls and noncompliance were isolated to the 20611-021-PN01, 21611-021-PN01, and 22619-021-PN01 grant awards. Criteria 2 CFR 200.303 states in part: "The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in 'Standards for Internal Control in the Federal Government' issued by the Comptroller General of the United States or the 'Internal Control Integrated Framework', issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). . . ." INDIANA STATE BOARD OF ACCOUNTS 16 WEST LAFAYETTE COMMUNITY SCHOOL CORPORATION SCHEDULE OF FINDINGS AND QUESTIONED COSTS (Continued) 2 CFR 200.403 states in part: "Except where otherwise authorized by statute, costs must meet the following general criteria in order to be allowable under Federal awards: . . . (g) Be adequately documented. . . ." 2 CFR 200.208(b) states in part: "The Federal awarding agency or pass-through entity may adjust specific Federal award conditions as needed, . . ." 511 IAC 7-34-7(b) states: "The public agency, in providing special education and related services to students in nonpublic schools must expend at least an amount that is the same proportion of the public agency total subgrant under 20 U.S.C. 1411(f) as the number of nonpublic school students with disabilities, who are enrolled by their parents in nonpublic schools within its boundaries, is to the total number of students with disabilities of the same age range." Cause A proper system of internal controls was not designed by management of the School Corporation. Embedded within a properly designed and implemented internal control system should be internal controls consisting of policies and procedures. Policies reflect the School Corporation's management statements of what should be done to effect internal control, and procedures should consist of actions that would implement these policies. Effect Without the proper implementation of an effectively designed system of internal controls, the internal control system cannot be capable of effectively preventing, or detecting and correcting, material noncompliance. As such, the School Corporation's Non-Public Proportionate Share expenditures could not be determined, and it could not be determined if the School Corporation met its minimum Non-Public Proportionate Share as required by the grant agreement. Noncompliance with the provisions of federal statutes, regulations, and the terms and conditions of the federal award could result in the loss of future federal funding to the School Corporation. Questioned Costs There were no questioned costs identified. Recommendation We recommended that management of the School Corporation establish a proper system of internal controls and develop policies and procedures to ensure Non-Public Proportionate Share funds are appropriately allocated to the member school corporation based on expenses charged directly on behalf of the member school corporation. Supporting documentation for these expenses should be retained for audit. Views of Responsible Officials For the views of responsible officials, refer to the Corrective Action Plan that is part of this report.
FINDING 2023-001 Subject: Special Education Cluster (IDEA) - Earmarking Federal Agency: Department of Education Federal Programs: Special Education Grants to States, Special Education Preschool Grants Assistance Listings Numbers: 84.027, 84.173 Federal Award Numbers and Years (or Other Identifying Numbers): 20611-021-PN01, 21611-021-PN01, 22619-021-PN01 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Matching, Level of Effort, Earmarking Audit Findings: Material Weakness, Modified Opinion Condition and Context The School Corporation is a member of the Greater Lafayette Area Special Services Cooperative (Cooperative). During fiscal years 2021-2022 and 2022-2023, the Cooperative operated the special education programs and spent the federal money on behalf of all its members. As the grant agreements were between the Indiana Department of Education (IDOE) and each member school, the School Corporation was responsible for ensuring and providing oversight of the Cooperative. However, there was inadequate oversight performed by the School Corporation in order to ensure compliance with the Matching, Level of Effort, Earmarking compliance requirement. The School Corporation did not have internal controls in place to ensure that the Cooperative complied with the earmarking requirements. The Cooperative did not have adequate procedures in place to ensure that the required level of expenditures for nonpublic school students with disabilities was met for each member school. The Cooperative did not have effective internal controls to ensure nonpublic school expenditures were appropriately identified and reported. The Non-Public Proportionate Share expenditures for the 20611-021-PN01, 21611-021-PN01, and 22619-021-PN01 grant awards could not be verified for the individual member school corporations. Total grant expenditures were posted as expended. The Non-Public Proportionate Share expenditures were determined by applying a percentage to the nonpublic school budgeted expenditures. As such, we were unable to identify if the minimum amount per the grant awards was expended and properly reported to the IDOE as required. The lack of internal controls and noncompliance were isolated to the 20611-021-PN01, 21611-021-PN01, and 22619-021-PN01 grant awards. Criteria 2 CFR 200.303 states in part: "The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in 'Standards for Internal Control in the Federal Government' issued by the Comptroller General of the United States or the 'Internal Control Integrated Framework', issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). . . ." INDIANA STATE BOARD OF ACCOUNTS 16 WEST LAFAYETTE COMMUNITY SCHOOL CORPORATION SCHEDULE OF FINDINGS AND QUESTIONED COSTS (Continued) 2 CFR 200.403 states in part: "Except where otherwise authorized by statute, costs must meet the following general criteria in order to be allowable under Federal awards: . . . (g) Be adequately documented. . . ." 2 CFR 200.208(b) states in part: "The Federal awarding agency or pass-through entity may adjust specific Federal award conditions as needed, . . ." 511 IAC 7-34-7(b) states: "The public agency, in providing special education and related services to students in nonpublic schools must expend at least an amount that is the same proportion of the public agency total subgrant under 20 U.S.C. 1411(f) as the number of nonpublic school students with disabilities, who are enrolled by their parents in nonpublic schools within its boundaries, is to the total number of students with disabilities of the same age range." Cause A proper system of internal controls was not designed by management of the School Corporation. Embedded within a properly designed and implemented internal control system should be internal controls consisting of policies and procedures. Policies reflect the School Corporation's management statements of what should be done to effect internal control, and procedures should consist of actions that would implement these policies. Effect Without the proper implementation of an effectively designed system of internal controls, the internal control system cannot be capable of effectively preventing, or detecting and correcting, material noncompliance. As such, the School Corporation's Non-Public Proportionate Share expenditures could not be determined, and it could not be determined if the School Corporation met its minimum Non-Public Proportionate Share as required by the grant agreement. Noncompliance with the provisions of federal statutes, regulations, and the terms and conditions of the federal award could result in the loss of future federal funding to the School Corporation. Questioned Costs There were no questioned costs identified. Recommendation We recommended that management of the School Corporation establish a proper system of internal controls and develop policies and procedures to ensure Non-Public Proportionate Share funds are appropriately allocated to the member school corporation based on expenses charged directly on behalf of the member school corporation. Supporting documentation for these expenses should be retained for audit. Views of Responsible Officials For the views of responsible officials, refer to the Corrective Action Plan that is part of this report.
FINDING 2023-001 Subject: Special Education Cluster (IDEA) - Earmarking Federal Agency: Department of Education Federal Programs: Special Education Grants to States, Special Education Preschool Grants Assistance Listings Numbers: 84.027, 84.173 Federal Award Numbers and Years (or Other Identifying Numbers): 20611-021-PN01, 21611-021-PN01, 22619-021-PN01 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Matching, Level of Effort, Earmarking Audit Findings: Material Weakness, Modified Opinion Condition and Context The School Corporation is a member of the Greater Lafayette Area Special Services Cooperative (Cooperative). During fiscal years 2021-2022 and 2022-2023, the Cooperative operated the special education programs and spent the federal money on behalf of all its members. As the grant agreements were between the Indiana Department of Education (IDOE) and each member school, the School Corporation was responsible for ensuring and providing oversight of the Cooperative. However, there was inadequate oversight performed by the School Corporation in order to ensure compliance with the Matching, Level of Effort, Earmarking compliance requirement. The School Corporation did not have internal controls in place to ensure that the Cooperative complied with the earmarking requirements. The Cooperative did not have adequate procedures in place to ensure that the required level of expenditures for nonpublic school students with disabilities was met for each member school. The Cooperative did not have effective internal controls to ensure nonpublic school expenditures were appropriately identified and reported. The Non-Public Proportionate Share expenditures for the 20611-021-PN01, 21611-021-PN01, and 22619-021-PN01 grant awards could not be verified for the individual member school corporations. Total grant expenditures were posted as expended. The Non-Public Proportionate Share expenditures were determined by applying a percentage to the nonpublic school budgeted expenditures. As such, we were unable to identify if the minimum amount per the grant awards was expended and properly reported to the IDOE as required. The lack of internal controls and noncompliance were isolated to the 20611-021-PN01, 21611-021-PN01, and 22619-021-PN01 grant awards. Criteria 2 CFR 200.303 states in part: "The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in 'Standards for Internal Control in the Federal Government' issued by the Comptroller General of the United States or the 'Internal Control Integrated Framework', issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). . . ." INDIANA STATE BOARD OF ACCOUNTS 16 WEST LAFAYETTE COMMUNITY SCHOOL CORPORATION SCHEDULE OF FINDINGS AND QUESTIONED COSTS (Continued) 2 CFR 200.403 states in part: "Except where otherwise authorized by statute, costs must meet the following general criteria in order to be allowable under Federal awards: . . . (g) Be adequately documented. . . ." 2 CFR 200.208(b) states in part: "The Federal awarding agency or pass-through entity may adjust specific Federal award conditions as needed, . . ." 511 IAC 7-34-7(b) states: "The public agency, in providing special education and related services to students in nonpublic schools must expend at least an amount that is the same proportion of the public agency total subgrant under 20 U.S.C. 1411(f) as the number of nonpublic school students with disabilities, who are enrolled by their parents in nonpublic schools within its boundaries, is to the total number of students with disabilities of the same age range." Cause A proper system of internal controls was not designed by management of the School Corporation. Embedded within a properly designed and implemented internal control system should be internal controls consisting of policies and procedures. Policies reflect the School Corporation's management statements of what should be done to effect internal control, and procedures should consist of actions that would implement these policies. Effect Without the proper implementation of an effectively designed system of internal controls, the internal control system cannot be capable of effectively preventing, or detecting and correcting, material noncompliance. As such, the School Corporation's Non-Public Proportionate Share expenditures could not be determined, and it could not be determined if the School Corporation met its minimum Non-Public Proportionate Share as required by the grant agreement. Noncompliance with the provisions of federal statutes, regulations, and the terms and conditions of the federal award could result in the loss of future federal funding to the School Corporation. Questioned Costs There were no questioned costs identified. Recommendation We recommended that management of the School Corporation establish a proper system of internal controls and develop policies and procedures to ensure Non-Public Proportionate Share funds are appropriately allocated to the member school corporation based on expenses charged directly on behalf of the member school corporation. Supporting documentation for these expenses should be retained for audit. Views of Responsible Officials For the views of responsible officials, refer to the Corrective Action Plan that is part of this report.
FINDING 2023-001 Subject: Special Education Cluster (IDEA) - Earmarking Federal Agency: Department of Education Federal Programs: Special Education Grants to States, Special Education Preschool Grants Assistance Listings Numbers: 84.027, 84.173 Federal Award Numbers and Years (or Other Identifying Numbers): 20611-021-PN01, 21611-021-PN01, 22619-021-PN01 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Matching, Level of Effort, Earmarking Audit Findings: Material Weakness, Modified Opinion Condition and Context The School Corporation is a member of the Greater Lafayette Area Special Services Cooperative (Cooperative). During fiscal years 2021-2022 and 2022-2023, the Cooperative operated the special education programs and spent the federal money on behalf of all its members. As the grant agreements were between the Indiana Department of Education (IDOE) and each member school, the School Corporation was responsible for ensuring and providing oversight of the Cooperative. However, there was inadequate oversight performed by the School Corporation in order to ensure compliance with the Matching, Level of Effort, Earmarking compliance requirement. The School Corporation did not have internal controls in place to ensure that the Cooperative complied with the earmarking requirements. The Cooperative did not have adequate procedures in place to ensure that the required level of expenditures for nonpublic school students with disabilities was met for each member school. The Cooperative did not have effective internal controls to ensure nonpublic school expenditures were appropriately identified and reported. The Non-Public Proportionate Share expenditures for the 20611-021-PN01, 21611-021-PN01, and 22619-021-PN01 grant awards could not be verified for the individual member school corporations. Total grant expenditures were posted as expended. The Non-Public Proportionate Share expenditures were determined by applying a percentage to the nonpublic school budgeted expenditures. As such, we were unable to identify if the minimum amount per the grant awards was expended and properly reported to the IDOE as required. The lack of internal controls and noncompliance were isolated to the 20611-021-PN01, 21611-021-PN01, and 22619-021-PN01 grant awards. Criteria 2 CFR 200.303 states in part: "The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in 'Standards for Internal Control in the Federal Government' issued by the Comptroller General of the United States or the 'Internal Control Integrated Framework', issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). . . ." INDIANA STATE BOARD OF ACCOUNTS 16 WEST LAFAYETTE COMMUNITY SCHOOL CORPORATION SCHEDULE OF FINDINGS AND QUESTIONED COSTS (Continued) 2 CFR 200.403 states in part: "Except where otherwise authorized by statute, costs must meet the following general criteria in order to be allowable under Federal awards: . . . (g) Be adequately documented. . . ." 2 CFR 200.208(b) states in part: "The Federal awarding agency or pass-through entity may adjust specific Federal award conditions as needed, . . ." 511 IAC 7-34-7(b) states: "The public agency, in providing special education and related services to students in nonpublic schools must expend at least an amount that is the same proportion of the public agency total subgrant under 20 U.S.C. 1411(f) as the number of nonpublic school students with disabilities, who are enrolled by their parents in nonpublic schools within its boundaries, is to the total number of students with disabilities of the same age range." Cause A proper system of internal controls was not designed by management of the School Corporation. Embedded within a properly designed and implemented internal control system should be internal controls consisting of policies and procedures. Policies reflect the School Corporation's management statements of what should be done to effect internal control, and procedures should consist of actions that would implement these policies. Effect Without the proper implementation of an effectively designed system of internal controls, the internal control system cannot be capable of effectively preventing, or detecting and correcting, material noncompliance. As such, the School Corporation's Non-Public Proportionate Share expenditures could not be determined, and it could not be determined if the School Corporation met its minimum Non-Public Proportionate Share as required by the grant agreement. Noncompliance with the provisions of federal statutes, regulations, and the terms and conditions of the federal award could result in the loss of future federal funding to the School Corporation. Questioned Costs There were no questioned costs identified. Recommendation We recommended that management of the School Corporation establish a proper system of internal controls and develop policies and procedures to ensure Non-Public Proportionate Share funds are appropriately allocated to the member school corporation based on expenses charged directly on behalf of the member school corporation. Supporting documentation for these expenses should be retained for audit. Views of Responsible Officials For the views of responsible officials, refer to the Corrective Action Plan that is part of this report.
FINDING 2023-002 Subject: COVID-19 - Education Stabilization Fund - Subrecipient Monitoring Federal Agency: Department of Education Federal Program: COVID-19 - Education Stabilization Fund Assistance Listings Number: 84.425U Federal Award Number and Year (or Other Identifying Number): S425U210013 Compliance Requirement: Subrecipient Monitoring Audit Findings: Material Weakness, Modified Opinion Condition and Context The School Corporation had not properly designed or implemented a system of internal controls, which would include appropriate segregation of duties, that would likely be effective in preventing, or detecting and correcting, material noncompliance related to the COVID-19 - Education Stabilization Fund (ESF) funds passed through to subrecipients. The School Corporation received and passed through to subrecipients $420,500 of ESF funds. The School Corporation is to clearly identify the award and applicable requirements to the subrecipients, evaluate the risk of noncompliance related to the subrecipients to determine appropriate monitoring of the subaward, and monitor the activities of the subrecipients to ensure that the subaward is used for authorized purposes, complies with the terms and conditions of the subaward, and achieves performance goals. The School Corporation did not enter into an agreement with the subrecipients. As such there is no agreement between the School Corporation and the subrecipients that clearly identifies the award as a subaward or includes all the required data elements. In addition, the School Corporation did not have any policies or procedures in place to evaluate the subrecipients' risk of noncompliance or to monitor the activity of the subrecipients. Per inquiry of the School Corporation, it was determined an evaluation of the risk of noncompliance for the subrecipients was not completed, nor did the subrecipients' files support any such evaluation. The lack of internal controls and noncompliance were systemic issues throughout the audit period. Criteria 2 CFR 200.303 states in part: "The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in 'Standards for Internal Control in the Federal Government' issued by the Comptroller General of the United States or the 'Internal Control Integrated Framework', issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). . . ." 2 CFR 200.332 states: "All pass-through entities must: INDIANA STATE BOARD OF ACCOUNTS 18 WEST LAFAYETTE COMMUNITY SCHOOL CORPORATION SCHEDULE OF FINDINGS AND QUESTIONED COSTS (Continued) (a) Ensure that every subaward is clearly identified to the subrecipient as a subaward and include the following information at the time of the subaward and if any of these data elements change, include the changes in subsequent subaward notification. When some of this information is not available, the pass-through entity must provide the best information available to describe the Federal award and subaward. Required information includes: (1) Federal award identification. (i) Subrecipient name (which must match the name associated with its unique entity identifier); (ii) Subrecipient's unique entity identifier; (iii) Federal Award Identification Number (FAIN); (iv) Federal Award Date (see the definition of Federal award date in § 200.1 of this part) of award to the recipient by the Federal agency; (v) Subaward Period of Performance Start and End Date; (vi) Subaward Budget Period Start and End Date; (vii) Amount of Federal Funds Obligated by this action by the pass-through entity to the subrecipient; (viii) Total Amount of Federal Funds Obligated to the subrecipient by the pass-through entity including the current financial obligation; (ix) Total Amount of the Federal Award committed to the subrecipient by the passthrough entity; (x) Federal award project description, as required to be responsive to the Federal Funding Accountability and Transparency Act (FFATA); (xi) Name of Federal awarding agency, pass-through entity, and contact information for awarding official of the Pass-through entity; (xii) Assistance Listings number and Title; the pass-through entity must identify the dollar amount made available under each Federal award and the Assistance Listings Number at time of disbursement; (xiii) Identification of whether the award is R&D; and (xiv) Indirect cost rate for the Federal award (including if the de minimis rate is charged) per § 200.414. (2) All requirements imposed by the pass-through entity on the subrecipient so that the Federal award is used in accordance with Federal statutes, regulations and the terms and conditions of the Federal award; INDIANA STATE BOARD OF ACCOUNTS 19 WEST LAFAYETTE COMMUNITY SCHOOL CORPORATION SCHEDULE OF FINDINGS AND QUESTIONED COSTS (Continued) (3) Any additional requirements that the pass-through entity imposes on the subrecipient in order for the pass-through entity to meet its own responsibility to the Federal awarding agency including identification of any required financial and performance reports; (4) (i) An approved federally recognized indirect cost rate negotiated between the subrecipient and the Federal Government. If no approved rate exists, the pass-through entity must determine the appropriate rate in collaboration with the subrecipient, which is either: (A) The negotiated indirect cost rate between the pass-through entity and the subrecipient; which can be based on a prior negotiated rate between a different PTE and the same subrecipient. If basing the rate on a previously negotiated rate, the passthrough entity is not required to collect information justifying this rate, but may elect to do so; (B) The de minimis indirect cost rate. (ii) The pass-through entity must not require use of a de minimis indirect cost rate if the subrecipient has a Federally approved rate. Subrecipients can elect to use the cost allocation method to account for indirect costs in accordance with § 200.405(d). (5) A requirement that the subrecipient permit the pass-through entity and auditors to have access to the subrecipient's records and financial statements as necessary for the pass-through entity to meet the requirements of this part; and (6) Appropriate terms and conditions concerning closeout of the subaward. . . . (b) Evaluate each subrecipient's risk of noncompliance with Federal statutes, regulations, and the terms and conditions of the subaward for purposes of determining the appropriate subrecipient monitoring described in paragraphs (d) and (e) of this section, which may include consideration of such factors as: (1) The subrecipient's prior experience with the same or similar subawards; (2) The results of previous audits including whether or not the subrecipient receives a Single Audit in accordance with Subpart F of this part, and the extent to which the same or similar subaward has been audited as a major program; (3) Whether the subrecipient has new personnel or new or substantially changed systems; and (4) The extent and results of Federal awarding agency monitoring (e.g., if the subrecipient also receives Federal awards directly from a Federal awarding agency). (c) Consider imposing specific subaward conditions upon a subrecipient if appropriate as described in § 200.208. INDIANA STATE BOARD OF ACCOUNTS 20 WEST LAFAYETTE COMMUNITY SCHOOL CORPORATION SCHEDULE OF FINDINGS AND QUESTIONED COSTS (Continued) (d) Monitor the activities of the subrecipient as necessary to ensure that the subaward is used for authorized purposes, in compliance with Federal statutes, regulations, and the terms and conditions of the subaward; and that subaward performance goals are achieved. Pass-through entity monitoring of the subrecipient must include: (1) Reviewing financial and performance reports required by the pass-through entity. (2) Following-up and ensuring that the subrecipient takes timely and appropriate action on all deficiencies pertaining to the Federal award provided to the subrecipient from the pass-through entity detected through audits, on-site reviews, and written confirmation from the subrecipient, highlighting the status of actions planned or taken to address Single Audit findings related to the particular subaward. (3) Issuing a management decision for applicable audit findings pertaining only to the Federal award provided to the subrecipient from the pass-through entity as required by § 200.521. (4) The pass-through entity is responsible for resolving audit findings specifically related to the subaward and not responsible for resolving crosscutting findings. If a subrecipient has a current Single Audit report posted in the Federal Audit Clearinghouse and has not otherwise been excluded from receipt of Federal funding (e.g., has been debarred or suspended), the pass-through entity may rely on the subrecipient's cognizant audit agency or cognizant oversight agency to perform audit follow-up and make management decisions related to cross-cutting findings in accordance with section § 200.513(a)(3)(vii). Such reliance does not eliminate the responsibility of the pass-through entity to issue subawards that conform to agency and award-specific requirements, to manage risk through ongoing subaward monitoring, and to monitor the status of the findings that are specifically related to the subaward. (e) Depending upon the pass-through entity's assessment of risk posed by the subrecipient (as described in paragraph (b) of this section), the following monitoring tools may be useful for the pass-through entity to ensure proper accountability and compliance with program requirements and achievement of performance goals: (1) Providing subrecipients with training and technical assistance on programrelated matters; and (2) Performing on-site reviews of the subrecipient's program operations; (3) Arranging for agreed-upon-procedures engagements as described in § 200.425. (f) Verify that every subrecipient is audited as required by Subpart F of this part when it is expected that the subrecipient's Federal awards expended during the respective fiscal year equaled or exceeded the threshold set forth in § 200.501. (g) Consider whether the results of the subrecipient's audits, on-site reviews, or other monitoring indicate conditions that necessitate adjustments to the pass-through entity's own records. INDIANA STATE BOARD OF ACCOUNTS 21 WEST LAFAYETTE COMMUNITY SCHOOL CORPORATION SCHEDULE OF FINDINGS AND QUESTIONED COSTS (Continued) (h) Consider taking enforcement action against noncompliant subrecipients as described in § 200.339 of this part and in program regulations." Cause A proper system of internal controls was not designed by management of the School Corporation. Embedded within a properly designed and implemented internal control system should be internal controls consisting of policies and procedures. Policies reflect the School Corporation's management statements of what should be done to effect internal controls, and procedures should consist of actions that would implement these policies. Effect Without the proper implementation of an effectively designed system of internal controls, the internal control system cannot be capable of effectively preventing, or detecting and correcting, material noncompliance. As a result, the School Corporation did not properly evaluate the subrecipients risk of noncompliance or adequately monitor the subrecipients. Noncompliance with the provisions of federal statutes, regulations, and the terms and conditions of the federal award could result in the loss of future federal funding to the School Corporation. Questioned Costs There were no questioned costs identified. Recommendation We recommended that management of the School Corporation establish a proper system of internal controls, including segregation of duties, to evaluate the subrecipients risk of noncompliance and adequately monitor the subrecipients. Additionally, policies and procedures should be implemented to ensure appropriate reviews, approvals, and oversight are taking place, as needed, to evaluate and monitor its subrecipients. Views of Responsible Officials For the views of responsible officials, refer to the Corrective Action Plan that is part of this report.
FINDING 2023-001 Subject: COVID-19 - Education Stabilization Fund - Internal Controls over Annual Data Report Federal Agency: Department of Education Federal Program: COVID-19 - Education Stabilization Fund Assistance Listings Numbers: 84.425D, 84.425U Federal Award Numbers and Years (or Other Identifying Numbers): S425D200013, S425U210013 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Reporting Audit Finding: Material Weakness INDIANA STATE BOARD OF ACCOUNTS 15 CLOVERDALE COMMUNITY SCHOOL CORPORATION SCHEDULE OF FINDINGS AND QUESTIONED COSTS (Continued) Condition and Context The School Corporation had not properly designed or implemented a system of internal controls, which would include appropriate segregation of duties, that would likely be effective in preventing, or detecting and correcting, noncompliance. The School Corporation was required to submit annual data reports to the Indiana Department of Education via JotForm, a form/report builder. Data to be submitted included, but was not limited to, current period expenditures, prior period expenditures, and expenditures per activity. During the audit period, the School Corporation submitted two ESSER I reports, two ESSER II reports, and two ESSER III reports, for a total of six reports. Although, the School Corporation's process for the annual data reports was for the Treasurer and the Director of Curriculum and Instruction to compile and prepare the reports, and the School Board to approve the reports prior to submission, there was no documented evidence of this review. As such, the reports were submitted by the Treasurer without an oversight or review process in place to prevent, or detect and correct, errors. Criteria 2 CFR 200.303 states in part: "The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in 'Standards for Internal Control in the Federal Government' issued by the Comptroller General of the United States or the 'Internal Control Integrated Framework', issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). . . ." Cause A proper system of internal controls was not designed and implemented by management of the School Corporation, which would include segregation of key functions. Embedded within a properly designed and implemented internal control system should be internal controls consisting of policies and procedures. Policies reflect the School Corporation's management statements of what should be done to effect internal controls, and procedures should consist of actions that would implement these policies. Effect Without the proper design or implementation of the components of a system of internal control, including policies and procedures that provide segregation of duties and additional oversight as needed, the internal control system cannot be capable of effectively preventing, or detecting and correcting, material noncompliance. Questioned Costs There were no questioned costs identified. INDIANA STATE BOARD OF ACCOUNTS 16 CLOVERDALE COMMUNITY SCHOOL CORPORATION SCHEDULE OF FINDINGS AND QUESTIONED COSTS (Continued) Recommendation We recommended that management of the School Corporation design and implement a proper system of internal controls, including policies and procedures, that are documented that would provide segregation of duties to ensure appropriate reviews, approvals, and oversight are taking place. Views of Responsible Officials For the views of responsible officials, refer to the Corrective Action Plan that is part of this report.
FINDING 2023-001 Subject: COVID-19 - Education Stabilization Fund - Internal Controls over Annual Data Report Federal Agency: Department of Education Federal Program: COVID-19 - Education Stabilization Fund Assistance Listings Numbers: 84.425D, 84.425U Federal Award Numbers and Years (or Other Identifying Numbers): S425D200013, S425U210013 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Reporting Audit Finding: Material Weakness INDIANA STATE BOARD OF ACCOUNTS 15 CLOVERDALE COMMUNITY SCHOOL CORPORATION SCHEDULE OF FINDINGS AND QUESTIONED COSTS (Continued) Condition and Context The School Corporation had not properly designed or implemented a system of internal controls, which would include appropriate segregation of duties, that would likely be effective in preventing, or detecting and correcting, noncompliance. The School Corporation was required to submit annual data reports to the Indiana Department of Education via JotForm, a form/report builder. Data to be submitted included, but was not limited to, current period expenditures, prior period expenditures, and expenditures per activity. During the audit period, the School Corporation submitted two ESSER I reports, two ESSER II reports, and two ESSER III reports, for a total of six reports. Although, the School Corporation's process for the annual data reports was for the Treasurer and the Director of Curriculum and Instruction to compile and prepare the reports, and the School Board to approve the reports prior to submission, there was no documented evidence of this review. As such, the reports were submitted by the Treasurer without an oversight or review process in place to prevent, or detect and correct, errors. Criteria 2 CFR 200.303 states in part: "The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in 'Standards for Internal Control in the Federal Government' issued by the Comptroller General of the United States or the 'Internal Control Integrated Framework', issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). . . ." Cause A proper system of internal controls was not designed and implemented by management of the School Corporation, which would include segregation of key functions. Embedded within a properly designed and implemented internal control system should be internal controls consisting of policies and procedures. Policies reflect the School Corporation's management statements of what should be done to effect internal controls, and procedures should consist of actions that would implement these policies. Effect Without the proper design or implementation of the components of a system of internal control, including policies and procedures that provide segregation of duties and additional oversight as needed, the internal control system cannot be capable of effectively preventing, or detecting and correcting, material noncompliance. Questioned Costs There were no questioned costs identified. INDIANA STATE BOARD OF ACCOUNTS 16 CLOVERDALE COMMUNITY SCHOOL CORPORATION SCHEDULE OF FINDINGS AND QUESTIONED COSTS (Continued) Recommendation We recommended that management of the School Corporation design and implement a proper system of internal controls, including policies and procedures, that are documented that would provide segregation of duties to ensure appropriate reviews, approvals, and oversight are taking place. Views of Responsible Officials For the views of responsible officials, refer to the Corrective Action Plan that is part of this report.
FINDING 2023-001 Subject: COVID-19 - Education Stabilization Fund - Internal Controls over Annual Data Report Federal Agency: Department of Education Federal Program: COVID-19 - Education Stabilization Fund Assistance Listings Numbers: 84.425D, 84.425U Federal Award Numbers and Years (or Other Identifying Numbers): S425D200013, S425U210013 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Reporting Audit Finding: Material Weakness INDIANA STATE BOARD OF ACCOUNTS 15 CLOVERDALE COMMUNITY SCHOOL CORPORATION SCHEDULE OF FINDINGS AND QUESTIONED COSTS (Continued) Condition and Context The School Corporation had not properly designed or implemented a system of internal controls, which would include appropriate segregation of duties, that would likely be effective in preventing, or detecting and correcting, noncompliance. The School Corporation was required to submit annual data reports to the Indiana Department of Education via JotForm, a form/report builder. Data to be submitted included, but was not limited to, current period expenditures, prior period expenditures, and expenditures per activity. During the audit period, the School Corporation submitted two ESSER I reports, two ESSER II reports, and two ESSER III reports, for a total of six reports. Although, the School Corporation's process for the annual data reports was for the Treasurer and the Director of Curriculum and Instruction to compile and prepare the reports, and the School Board to approve the reports prior to submission, there was no documented evidence of this review. As such, the reports were submitted by the Treasurer without an oversight or review process in place to prevent, or detect and correct, errors. Criteria 2 CFR 200.303 states in part: "The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in 'Standards for Internal Control in the Federal Government' issued by the Comptroller General of the United States or the 'Internal Control Integrated Framework', issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). . . ." Cause A proper system of internal controls was not designed and implemented by management of the School Corporation, which would include segregation of key functions. Embedded within a properly designed and implemented internal control system should be internal controls consisting of policies and procedures. Policies reflect the School Corporation's management statements of what should be done to effect internal controls, and procedures should consist of actions that would implement these policies. Effect Without the proper design or implementation of the components of a system of internal control, including policies and procedures that provide segregation of duties and additional oversight as needed, the internal control system cannot be capable of effectively preventing, or detecting and correcting, material noncompliance. Questioned Costs There were no questioned costs identified. INDIANA STATE BOARD OF ACCOUNTS 16 CLOVERDALE COMMUNITY SCHOOL CORPORATION SCHEDULE OF FINDINGS AND QUESTIONED COSTS (Continued) Recommendation We recommended that management of the School Corporation design and implement a proper system of internal controls, including policies and procedures, that are documented that would provide segregation of duties to ensure appropriate reviews, approvals, and oversight are taking place. Views of Responsible Officials For the views of responsible officials, refer to the Corrective Action Plan that is part of this report.
FINDING 2023-001 Subject: COVID-19 - Education Stabilization Fund - Internal Controls over Annual Data Report Federal Agency: Department of Education Federal Program: COVID-19 - Education Stabilization Fund Assistance Listings Numbers: 84.425D, 84.425U Federal Award Numbers and Years (or Other Identifying Numbers): S425D200013, S425U210013 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Reporting Audit Finding: Material Weakness INDIANA STATE BOARD OF ACCOUNTS 15 CLOVERDALE COMMUNITY SCHOOL CORPORATION SCHEDULE OF FINDINGS AND QUESTIONED COSTS (Continued) Condition and Context The School Corporation had not properly designed or implemented a system of internal controls, which would include appropriate segregation of duties, that would likely be effective in preventing, or detecting and correcting, noncompliance. The School Corporation was required to submit annual data reports to the Indiana Department of Education via JotForm, a form/report builder. Data to be submitted included, but was not limited to, current period expenditures, prior period expenditures, and expenditures per activity. During the audit period, the School Corporation submitted two ESSER I reports, two ESSER II reports, and two ESSER III reports, for a total of six reports. Although, the School Corporation's process for the annual data reports was for the Treasurer and the Director of Curriculum and Instruction to compile and prepare the reports, and the School Board to approve the reports prior to submission, there was no documented evidence of this review. As such, the reports were submitted by the Treasurer without an oversight or review process in place to prevent, or detect and correct, errors. Criteria 2 CFR 200.303 states in part: "The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in 'Standards for Internal Control in the Federal Government' issued by the Comptroller General of the United States or the 'Internal Control Integrated Framework', issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). . . ." Cause A proper system of internal controls was not designed and implemented by management of the School Corporation, which would include segregation of key functions. Embedded within a properly designed and implemented internal control system should be internal controls consisting of policies and procedures. Policies reflect the School Corporation's management statements of what should be done to effect internal controls, and procedures should consist of actions that would implement these policies. Effect Without the proper design or implementation of the components of a system of internal control, including policies and procedures that provide segregation of duties and additional oversight as needed, the internal control system cannot be capable of effectively preventing, or detecting and correcting, material noncompliance. Questioned Costs There were no questioned costs identified. INDIANA STATE BOARD OF ACCOUNTS 16 CLOVERDALE COMMUNITY SCHOOL CORPORATION SCHEDULE OF FINDINGS AND QUESTIONED COSTS (Continued) Recommendation We recommended that management of the School Corporation design and implement a proper system of internal controls, including policies and procedures, that are documented that would provide segregation of duties to ensure appropriate reviews, approvals, and oversight are taking place. Views of Responsible Officials For the views of responsible officials, refer to the Corrective Action Plan that is part of this report.