Criteria (A)Per 16 CFR 314.3 the institutions with 5,000 or more customers must stablish written information securityprogram to include nine elements. The elements that an institution must address in its written informationsecurity program are at 16 CFR 314.4. At a minimum, an institution’s written information security programshould include: 1.Designates a qualified individual responsible for overseeing and implementing the institutions or servicer’sinformation security program and enforcing the information security program (16 C.F.R. 314.4(a)). 2.Provides for the information security program to be based on a risk assessment that identifies reasonablyforeseeable internal and external risks to the security, confidentiality, and integrity of customer information(as the term customer information applies to the institution or servicer) that could result in the unauthorizeddisclosure, misuse, alteration, destruction, or other compromise of such information, and assesses thesufficiency of any safeguards in place to control these risks (16 C.F.R. 314.4(b)). 3.Provides for the design and implementation of safeguards to control the risks the institution or serviceridentifies through its risk assessment (16 C.F.R. 314.4(c)). At a minimum, the written information securityprogram must address the implementation of the minimum safeguards identified in 16 C.F.R. 314.4(c)(1)through (8). 4.Provides for the institution to regularly test or otherwise monitor the effectiveness of the safeguards it hasimplemented (16 CFR 314.4(d)). 5.Provides for the implementation of policies and procedures to ensure that personnel are able to enact theinformation security program (16 C.F.R. 314.4(e)). 6.Addresses how the institution will oversee its information system service providers (16 C.F.R. 314.4(f)). 7.Provides for the evaluation and adjustment of its information security program in light of the results of therequired testing and monitoring; any material changes to its operations or business arrangements; theresults of the required risk assessments; or any other circumstances that it knows or has reason to knowmay have a material impact the information security program (16 C.F.R. 314.4(g)). 8.For an institution or servicer maintaining student information on 5,000 or more consumers, addresses theestablishment of an incident response plan (16 C.F.R. 314.4(h)). 9.For an institution or servicer maintaining student information on 5,000 or more consumers, addresses therequirement for its Qualified Individual to report regularly and at least annually to those with control over theinstitution on the institution’s information security program (16 C.F.R. 314.4(i)). (B)Per 2 CFR 200.303, a non-federal entity mush establish and maintain internal control over the federal award that provides reasonable assurance that the non-federal entity is managing the federal award in compliance with federal statutes, regulations and the terms and conditions of the federal award.Condition and ContextDuring our audit of the internal controls over compliance and compliance requirements, we noted that the University did not have written procedures or formal policies to ensure compliance with all the elements included in the criteria. We were no able to identify formal written procedures for the elements: 4,5,7 and 9.
Criteria (A)Per 16 CFR 314.3 the institutions with 5,000 or more customers must stablish written information securityprogram to include nine elements. The elements that an institution must address in its written informationsecurity program are at 16 CFR 314.4. At a minimum, an institution’s written information security programshould include: 1.Designates a qualified individual responsible for overseeing and implementing the institutions or servicer’sinformation security program and enforcing the information security program (16 C.F.R. 314.4(a)). 2.Provides for the information security program to be based on a risk assessment that identifies reasonablyforeseeable internal and external risks to the security, confidentiality, and integrity of customer information(as the term customer information applies to the institution or servicer) that could result in the unauthorizeddisclosure, misuse, alteration, destruction, or other compromise of such information, and assesses thesufficiency of any safeguards in place to control these risks (16 C.F.R. 314.4(b)). 3.Provides for the design and implementation of safeguards to control the risks the institution or serviceridentifies through its risk assessment (16 C.F.R. 314.4(c)). At a minimum, the written information securityprogram must address the implementation of the minimum safeguards identified in 16 C.F.R. 314.4(c)(1)through (8). 4.Provides for the institution to regularly test or otherwise monitor the effectiveness of the safeguards it hasimplemented (16 CFR 314.4(d)). 5.Provides for the implementation of policies and procedures to ensure that personnel are able to enact theinformation security program (16 C.F.R. 314.4(e)). 6.Addresses how the institution will oversee its information system service providers (16 C.F.R. 314.4(f)). 7.Provides for the evaluation and adjustment of its information security program in light of the results of therequired testing and monitoring; any material changes to its operations or business arrangements; theresults of the required risk assessments; or any other circumstances that it knows or has reason to knowmay have a material impact the information security program (16 C.F.R. 314.4(g)). 8.For an institution or servicer maintaining student information on 5,000 or more consumers, addresses theestablishment of an incident response plan (16 C.F.R. 314.4(h)). 9.For an institution or servicer maintaining student information on 5,000 or more consumers, addresses therequirement for its Qualified Individual to report regularly and at least annually to those with control over theinstitution on the institution’s information security program (16 C.F.R. 314.4(i)). (B)Per 2 CFR 200.303, a non-federal entity mush establish and maintain internal control over the federal award that provides reasonable assurance that the non-federal entity is managing the federal award in compliance with federal statutes, regulations and the terms and conditions of the federal award.Condition and ContextDuring our audit of the internal controls over compliance and compliance requirements, we noted that the University did not have written procedures or formal policies to ensure compliance with all the elements included in the criteria. We were no able to identify formal written procedures for the elements: 4,5,7 and 9.
Criteria (A)Per 16 CFR 314.3 the institutions with 5,000 or more customers must stablish written information securityprogram to include nine elements. The elements that an institution must address in its written informationsecurity program are at 16 CFR 314.4. At a minimum, an institution’s written information security programshould include: 1.Designates a qualified individual responsible for overseeing and implementing the institutions or servicer’sinformation security program and enforcing the information security program (16 C.F.R. 314.4(a)). 2.Provides for the information security program to be based on a risk assessment that identifies reasonablyforeseeable internal and external risks to the security, confidentiality, and integrity of customer information(as the term customer information applies to the institution or servicer) that could result in the unauthorizeddisclosure, misuse, alteration, destruction, or other compromise of such information, and assesses thesufficiency of any safeguards in place to control these risks (16 C.F.R. 314.4(b)). 3.Provides for the design and implementation of safeguards to control the risks the institution or serviceridentifies through its risk assessment (16 C.F.R. 314.4(c)). At a minimum, the written information securityprogram must address the implementation of the minimum safeguards identified in 16 C.F.R. 314.4(c)(1)through (8). 4.Provides for the institution to regularly test or otherwise monitor the effectiveness of the safeguards it hasimplemented (16 CFR 314.4(d)). 5.Provides for the implementation of policies and procedures to ensure that personnel are able to enact theinformation security program (16 C.F.R. 314.4(e)). 6.Addresses how the institution will oversee its information system service providers (16 C.F.R. 314.4(f)). 7.Provides for the evaluation and adjustment of its information security program in light of the results of therequired testing and monitoring; any material changes to its operations or business arrangements; theresults of the required risk assessments; or any other circumstances that it knows or has reason to knowmay have a material impact the information security program (16 C.F.R. 314.4(g)). 8.For an institution or servicer maintaining student information on 5,000 or more consumers, addresses theestablishment of an incident response plan (16 C.F.R. 314.4(h)). 9.For an institution or servicer maintaining student information on 5,000 or more consumers, addresses therequirement for its Qualified Individual to report regularly and at least annually to those with control over theinstitution on the institution’s information security program (16 C.F.R. 314.4(i)). (B)Per 2 CFR 200.303, a non-federal entity mush establish and maintain internal control over the federal award that provides reasonable assurance that the non-federal entity is managing the federal award in compliance with federal statutes, regulations and the terms and conditions of the federal award.Condition and ContextDuring our audit of the internal controls over compliance and compliance requirements, we noted that the University did not have written procedures or formal policies to ensure compliance with all the elements included in the criteria. We were no able to identify formal written procedures for the elements: 4,5,7 and 9.
Criteria (A)Per 16 CFR 314.3 the institutions with 5,000 or more customers must stablish written information securityprogram to include nine elements. The elements that an institution must address in its written informationsecurity program are at 16 CFR 314.4. At a minimum, an institution’s written information security programshould include: 1.Designates a qualified individual responsible for overseeing and implementing the institutions or servicer’sinformation security program and enforcing the information security program (16 C.F.R. 314.4(a)). 2.Provides for the information security program to be based on a risk assessment that identifies reasonablyforeseeable internal and external risks to the security, confidentiality, and integrity of customer information(as the term customer information applies to the institution or servicer) that could result in the unauthorizeddisclosure, misuse, alteration, destruction, or other compromise of such information, and assesses thesufficiency of any safeguards in place to control these risks (16 C.F.R. 314.4(b)). 3.Provides for the design and implementation of safeguards to control the risks the institution or serviceridentifies through its risk assessment (16 C.F.R. 314.4(c)). At a minimum, the written information securityprogram must address the implementation of the minimum safeguards identified in 16 C.F.R. 314.4(c)(1)through (8). 4.Provides for the institution to regularly test or otherwise monitor the effectiveness of the safeguards it hasimplemented (16 CFR 314.4(d)). 5.Provides for the implementation of policies and procedures to ensure that personnel are able to enact theinformation security program (16 C.F.R. 314.4(e)). 6.Addresses how the institution will oversee its information system service providers (16 C.F.R. 314.4(f)). 7.Provides for the evaluation and adjustment of its information security program in light of the results of therequired testing and monitoring; any material changes to its operations or business arrangements; theresults of the required risk assessments; or any other circumstances that it knows or has reason to knowmay have a material impact the information security program (16 C.F.R. 314.4(g)). 8.For an institution or servicer maintaining student information on 5,000 or more consumers, addresses theestablishment of an incident response plan (16 C.F.R. 314.4(h)). 9.For an institution or servicer maintaining student information on 5,000 or more consumers, addresses therequirement for its Qualified Individual to report regularly and at least annually to those with control over theinstitution on the institution’s information security program (16 C.F.R. 314.4(i)). (B)Per 2 CFR 200.303, a non-federal entity mush establish and maintain internal control over the federal award that provides reasonable assurance that the non-federal entity is managing the federal award in compliance with federal statutes, regulations and the terms and conditions of the federal award.Condition and ContextDuring our audit of the internal controls over compliance and compliance requirements, we noted that the University did not have written procedures or formal policies to ensure compliance with all the elements included in the criteria. We were no able to identify formal written procedures for the elements: 4,5,7 and 9.
Criteria (A)Per 16 CFR 314.3 the institutions with 5,000 or more customers must stablish written information securityprogram to include nine elements. The elements that an institution must address in its written informationsecurity program are at 16 CFR 314.4. At a minimum, an institution’s written information security programshould include: 1.Designates a qualified individual responsible for overseeing and implementing the institutions or servicer’sinformation security program and enforcing the information security program (16 C.F.R. 314.4(a)). 2.Provides for the information security program to be based on a risk assessment that identifies reasonablyforeseeable internal and external risks to the security, confidentiality, and integrity of customer information(as the term customer information applies to the institution or servicer) that could result in the unauthorizeddisclosure, misuse, alteration, destruction, or other compromise of such information, and assesses thesufficiency of any safeguards in place to control these risks (16 C.F.R. 314.4(b)). 3.Provides for the design and implementation of safeguards to control the risks the institution or serviceridentifies through its risk assessment (16 C.F.R. 314.4(c)). At a minimum, the written information securityprogram must address the implementation of the minimum safeguards identified in 16 C.F.R. 314.4(c)(1)through (8). 4.Provides for the institution to regularly test or otherwise monitor the effectiveness of the safeguards it hasimplemented (16 CFR 314.4(d)). 5.Provides for the implementation of policies and procedures to ensure that personnel are able to enact theinformation security program (16 C.F.R. 314.4(e)). 6.Addresses how the institution will oversee its information system service providers (16 C.F.R. 314.4(f)). 7.Provides for the evaluation and adjustment of its information security program in light of the results of therequired testing and monitoring; any material changes to its operations or business arrangements; theresults of the required risk assessments; or any other circumstances that it knows or has reason to knowmay have a material impact the information security program (16 C.F.R. 314.4(g)). 8.For an institution or servicer maintaining student information on 5,000 or more consumers, addresses theestablishment of an incident response plan (16 C.F.R. 314.4(h)). 9.For an institution or servicer maintaining student information on 5,000 or more consumers, addresses therequirement for its Qualified Individual to report regularly and at least annually to those with control over theinstitution on the institution’s information security program (16 C.F.R. 314.4(i)). (B)Per 2 CFR 200.303, a non-federal entity mush establish and maintain internal control over the federal award that provides reasonable assurance that the non-federal entity is managing the federal award in compliance with federal statutes, regulations and the terms and conditions of the federal award.Condition and ContextDuring our audit of the internal controls over compliance and compliance requirements, we noted that the University did not have written procedures or formal policies to ensure compliance with all the elements included in the criteria. We were no able to identify formal written procedures for the elements: 4,5,7 and 9.
2023-001 Special Tests and Provisions Federal agency: U.S Department of Education Federal program title: Student Financial Assistance Cluster Assistant Listing Number: 84.007/84.033/84.063/84.268 Federal Award Identification Number: P007A221105 - P033A221105 - P063P221336 - P268K231336 Award Period: July 1, 2022 to June 30, 2023 Type of Finding: • Compliance, Other Matters • Significant Deficiency in Internal Control over Compliance Criteria or specific requirement: The Gramm-Leach Bliley Act (GLBA) requires financial institutions to explain their information-sharing practices to their customers and to safeguard sensitive data (16 CFR 314). The regulation states that the college must designate a qualified individual responsible for overseeing and implementing your information security program and enforcing your information security program. (16 CFR 314.4(a)). The entity shall have a Written Information Security Program (WISP) that outlines the design and implementation of the risk assessment procedures. (16 CFR 314.4(b)). At a minimum, the institution’s written information security program must address the implementation of the minimum safeguards identified in 16 CFR 314.4(c)(1) through (8) including: Assess apps developed by the institution. In addition, the written security program provides for the institution to regularly test or otherwise monitor the effectiveness of the safeguards it has implemented (16 CFR 314.4(d)). Per 2 CFR 200.303, nonfederal entities receiving federal awards are required to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations, and program compliance requirements. Condition: The University has a Written information Security Program; however, the University did not meet the minimum requirements stated in the Gramm-Leach-Bliley Act. Context: These new GLBA requirements were applicable beginning on June 9, 2023, and there were certain required elements missing from the institution’s Written Information Security Program (WISP). Questioned costs: None. Cause: There was not a formal process in place to review against all the new GLBA requirements to ensure compliance. Effect: The University was not in Gramm-Leach-Bliley compliance standards. Repeat Finding: No. Recommendation: We recommend that the College review the updated GLBA requirements and ensure their WISP includes all required elements. Views of responsible officials: Management agrees with the finding.
2023-001 Special Tests and Provisions Federal agency: U.S Department of Education Federal program title: Student Financial Assistance Cluster Assistant Listing Number: 84.007/84.033/84.063/84.268 Federal Award Identification Number: P007A221105 - P033A221105 - P063P221336 - P268K231336 Award Period: July 1, 2022 to June 30, 2023 Type of Finding: • Compliance, Other Matters • Significant Deficiency in Internal Control over Compliance Criteria or specific requirement: The Gramm-Leach Bliley Act (GLBA) requires financial institutions to explain their information-sharing practices to their customers and to safeguard sensitive data (16 CFR 314). The regulation states that the college must designate a qualified individual responsible for overseeing and implementing your information security program and enforcing your information security program. (16 CFR 314.4(a)). The entity shall have a Written Information Security Program (WISP) that outlines the design and implementation of the risk assessment procedures. (16 CFR 314.4(b)). At a minimum, the institution’s written information security program must address the implementation of the minimum safeguards identified in 16 CFR 314.4(c)(1) through (8) including: Assess apps developed by the institution. In addition, the written security program provides for the institution to regularly test or otherwise monitor the effectiveness of the safeguards it has implemented (16 CFR 314.4(d)). Per 2 CFR 200.303, nonfederal entities receiving federal awards are required to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations, and program compliance requirements. Condition: The University has a Written information Security Program; however, the University did not meet the minimum requirements stated in the Gramm-Leach-Bliley Act. Context: These new GLBA requirements were applicable beginning on June 9, 2023, and there were certain required elements missing from the institution’s Written Information Security Program (WISP). Questioned costs: None. Cause: There was not a formal process in place to review against all the new GLBA requirements to ensure compliance. Effect: The University was not in Gramm-Leach-Bliley compliance standards. Repeat Finding: No. Recommendation: We recommend that the College review the updated GLBA requirements and ensure their WISP includes all required elements. Views of responsible officials: Management agrees with the finding.
2023-001 Special Tests and Provisions Federal agency: U.S Department of Education Federal program title: Student Financial Assistance Cluster Assistant Listing Number: 84.007/84.033/84.063/84.268 Federal Award Identification Number: P007A221105 - P033A221105 - P063P221336 - P268K231336 Award Period: July 1, 2022 to June 30, 2023 Type of Finding: • Compliance, Other Matters • Significant Deficiency in Internal Control over Compliance Criteria or specific requirement: The Gramm-Leach Bliley Act (GLBA) requires financial institutions to explain their information-sharing practices to their customers and to safeguard sensitive data (16 CFR 314). The regulation states that the college must designate a qualified individual responsible for overseeing and implementing your information security program and enforcing your information security program. (16 CFR 314.4(a)). The entity shall have a Written Information Security Program (WISP) that outlines the design and implementation of the risk assessment procedures. (16 CFR 314.4(b)). At a minimum, the institution’s written information security program must address the implementation of the minimum safeguards identified in 16 CFR 314.4(c)(1) through (8) including: Assess apps developed by the institution. In addition, the written security program provides for the institution to regularly test or otherwise monitor the effectiveness of the safeguards it has implemented (16 CFR 314.4(d)). Per 2 CFR 200.303, nonfederal entities receiving federal awards are required to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations, and program compliance requirements. Condition: The University has a Written information Security Program; however, the University did not meet the minimum requirements stated in the Gramm-Leach-Bliley Act. Context: These new GLBA requirements were applicable beginning on June 9, 2023, and there were certain required elements missing from the institution’s Written Information Security Program (WISP). Questioned costs: None. Cause: There was not a formal process in place to review against all the new GLBA requirements to ensure compliance. Effect: The University was not in Gramm-Leach-Bliley compliance standards. Repeat Finding: No. Recommendation: We recommend that the College review the updated GLBA requirements and ensure their WISP includes all required elements. Views of responsible officials: Management agrees with the finding.
2023-001 Special Tests and Provisions Federal agency: U.S Department of Education Federal program title: Student Financial Assistance Cluster Assistant Listing Number: 84.007/84.033/84.063/84.268 Federal Award Identification Number: P007A221105 - P033A221105 - P063P221336 - P268K231336 Award Period: July 1, 2022 to June 30, 2023 Type of Finding: • Compliance, Other Matters • Significant Deficiency in Internal Control over Compliance Criteria or specific requirement: The Gramm-Leach Bliley Act (GLBA) requires financial institutions to explain their information-sharing practices to their customers and to safeguard sensitive data (16 CFR 314). The regulation states that the college must designate a qualified individual responsible for overseeing and implementing your information security program and enforcing your information security program. (16 CFR 314.4(a)). The entity shall have a Written Information Security Program (WISP) that outlines the design and implementation of the risk assessment procedures. (16 CFR 314.4(b)). At a minimum, the institution’s written information security program must address the implementation of the minimum safeguards identified in 16 CFR 314.4(c)(1) through (8) including: Assess apps developed by the institution. In addition, the written security program provides for the institution to regularly test or otherwise monitor the effectiveness of the safeguards it has implemented (16 CFR 314.4(d)). Per 2 CFR 200.303, nonfederal entities receiving federal awards are required to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations, and program compliance requirements. Condition: The University has a Written information Security Program; however, the University did not meet the minimum requirements stated in the Gramm-Leach-Bliley Act. Context: These new GLBA requirements were applicable beginning on June 9, 2023, and there were certain required elements missing from the institution’s Written Information Security Program (WISP). Questioned costs: None. Cause: There was not a formal process in place to review against all the new GLBA requirements to ensure compliance. Effect: The University was not in Gramm-Leach-Bliley compliance standards. Repeat Finding: No. Recommendation: We recommend that the College review the updated GLBA requirements and ensure their WISP includes all required elements. Views of responsible officials: Management agrees with the finding.
2023-001 Special Tests and Provisions Federal agency: U.S Department of Education Federal program title: Student Financial Assistance Cluster Assistant Listing Number: 84.007/84.033/84.063/84.268 Federal Award Identification Number: P007A221105 - P033A221105 - P063P221336 - P268K231336 Award Period: July 1, 2022 to June 30, 2023 Type of Finding: • Compliance, Other Matters • Significant Deficiency in Internal Control over Compliance Criteria or specific requirement: The Gramm-Leach Bliley Act (GLBA) requires financial institutions to explain their information-sharing practices to their customers and to safeguard sensitive data (16 CFR 314). The regulation states that the college must designate a qualified individual responsible for overseeing and implementing your information security program and enforcing your information security program. (16 CFR 314.4(a)). The entity shall have a Written Information Security Program (WISP) that outlines the design and implementation of the risk assessment procedures. (16 CFR 314.4(b)). At a minimum, the institution’s written information security program must address the implementation of the minimum safeguards identified in 16 CFR 314.4(c)(1) through (8) including: Assess apps developed by the institution. In addition, the written security program provides for the institution to regularly test or otherwise monitor the effectiveness of the safeguards it has implemented (16 CFR 314.4(d)). Per 2 CFR 200.303, nonfederal entities receiving federal awards are required to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations, and program compliance requirements. Condition: The University has a Written information Security Program; however, the University did not meet the minimum requirements stated in the Gramm-Leach-Bliley Act. Context: These new GLBA requirements were applicable beginning on June 9, 2023, and there were certain required elements missing from the institution’s Written Information Security Program (WISP). Questioned costs: None. Cause: There was not a formal process in place to review against all the new GLBA requirements to ensure compliance. Effect: The University was not in Gramm-Leach-Bliley compliance standards. Repeat Finding: No. Recommendation: We recommend that the College review the updated GLBA requirements and ensure their WISP includes all required elements. Views of responsible officials: Management agrees with the finding.
2023-001 Special Tests and Provisions Federal agency: U.S Department of Education Federal program title: Student Financial Assistance Cluster Assistant Listing Number: 84.007/84.033/84.063/84.268 Federal Award Identification Number: P007A221105 - P033A221105 - P063P221336 - P268K231336 Award Period: July 1, 2022 to June 30, 2023 Type of Finding: • Compliance, Other Matters • Significant Deficiency in Internal Control over Compliance Criteria or specific requirement: The Gramm-Leach Bliley Act (GLBA) requires financial institutions to explain their information-sharing practices to their customers and to safeguard sensitive data (16 CFR 314). The regulation states that the college must designate a qualified individual responsible for overseeing and implementing your information security program and enforcing your information security program. (16 CFR 314.4(a)). The entity shall have a Written Information Security Program (WISP) that outlines the design and implementation of the risk assessment procedures. (16 CFR 314.4(b)). At a minimum, the institution’s written information security program must address the implementation of the minimum safeguards identified in 16 CFR 314.4(c)(1) through (8) including: Assess apps developed by the institution. In addition, the written security program provides for the institution to regularly test or otherwise monitor the effectiveness of the safeguards it has implemented (16 CFR 314.4(d)). Per 2 CFR 200.303, nonfederal entities receiving federal awards are required to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations, and program compliance requirements. Condition: The University has a Written information Security Program; however, the University did not meet the minimum requirements stated in the Gramm-Leach-Bliley Act. Context: These new GLBA requirements were applicable beginning on June 9, 2023, and there were certain required elements missing from the institution’s Written Information Security Program (WISP). Questioned costs: None. Cause: There was not a formal process in place to review against all the new GLBA requirements to ensure compliance. Effect: The University was not in Gramm-Leach-Bliley compliance standards. Repeat Finding: No. Recommendation: We recommend that the College review the updated GLBA requirements and ensure their WISP includes all required elements. Views of responsible officials: Management agrees with the finding.
2023-002 Special Tests and Provisions Federal agency: U.S Department of Education Federal program title: Student Financial Assistance Cluster Assistant Listing Number: 84.007/84.033/84.063/84.268 Federal Award Identification Number: P007A221105 - P033A221105 - P063P221336 - P268K231336 Award Period: July 1, 2022 to June 30, 2023 Type of Finding: • Compliance, Other Matters • Significant Deficiency in Internal Control over Compliance Criteria or specific requirement: The Department of Education requires institutions to report the disbursement dates and amounts to the Common Origination and Disbursement (COD) system within 15 days of disbursing Pell (34 CFR 690.83(b)(2) and Direct Loan (34 CFR 685.309) funds to a student. Per 2 CFR 200.303, nonfederal entities receiving federal awards are required to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations, and program compliance requirements. Condition: The College did not timely report all disbursement dates and amounts to the COD system. Context: We identified 2 out of 40 COD disbursements tested that were not reported within the required 15 days to COD, these two instances were reported 7 days late. Questioned costs: None. Cause: The Student Financial Aid Office does not have a process in place to ensure all disbursements are reported within 15 days to COD. Effect: Student interest accrues based on disbursement date reported to COD, thus interest calculation could be misstated due to the discrepancy in disbursement dates reported. Repeat Finding: No. Recommendation: We recommend that the student financial aid department work to ensure disbursements are reported to COD within 15 days of the disbursement date. Views of responsible officials: Management agrees with the finding.
2023-002 Special Tests and Provisions Federal agency: U.S Department of Education Federal program title: Student Financial Assistance Cluster Assistant Listing Number: 84.007/84.033/84.063/84.268 Federal Award Identification Number: P007A221105 - P033A221105 - P063P221336 - P268K231336 Award Period: July 1, 2022 to June 30, 2023 Type of Finding: • Compliance, Other Matters • Significant Deficiency in Internal Control over Compliance Criteria or specific requirement: The Department of Education requires institutions to report the disbursement dates and amounts to the Common Origination and Disbursement (COD) system within 15 days of disbursing Pell (34 CFR 690.83(b)(2) and Direct Loan (34 CFR 685.309) funds to a student. Per 2 CFR 200.303, nonfederal entities receiving federal awards are required to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations, and program compliance requirements. Condition: The College did not timely report all disbursement dates and amounts to the COD system. Context: We identified 2 out of 40 COD disbursements tested that were not reported within the required 15 days to COD, these two instances were reported 7 days late. Questioned costs: None. Cause: The Student Financial Aid Office does not have a process in place to ensure all disbursements are reported within 15 days to COD. Effect: Student interest accrues based on disbursement date reported to COD, thus interest calculation could be misstated due to the discrepancy in disbursement dates reported. Repeat Finding: No. Recommendation: We recommend that the student financial aid department work to ensure disbursements are reported to COD within 15 days of the disbursement date. Views of responsible officials: Management agrees with the finding.
2023-002 Special Tests and Provisions Federal agency: U.S Department of Education Federal program title: Student Financial Assistance Cluster Assistant Listing Number: 84.007/84.033/84.063/84.268 Federal Award Identification Number: P007A221105 - P033A221105 - P063P221336 - P268K231336 Award Period: July 1, 2022 to June 30, 2023 Type of Finding: • Compliance, Other Matters • Significant Deficiency in Internal Control over Compliance Criteria or specific requirement: The Department of Education requires institutions to report the disbursement dates and amounts to the Common Origination and Disbursement (COD) system within 15 days of disbursing Pell (34 CFR 690.83(b)(2) and Direct Loan (34 CFR 685.309) funds to a student. Per 2 CFR 200.303, nonfederal entities receiving federal awards are required to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations, and program compliance requirements. Condition: The College did not timely report all disbursement dates and amounts to the COD system. Context: We identified 2 out of 40 COD disbursements tested that were not reported within the required 15 days to COD, these two instances were reported 7 days late. Questioned costs: None. Cause: The Student Financial Aid Office does not have a process in place to ensure all disbursements are reported within 15 days to COD. Effect: Student interest accrues based on disbursement date reported to COD, thus interest calculation could be misstated due to the discrepancy in disbursement dates reported. Repeat Finding: No. Recommendation: We recommend that the student financial aid department work to ensure disbursements are reported to COD within 15 days of the disbursement date. Views of responsible officials: Management agrees with the finding.
2023-002 Special Tests and Provisions Federal agency: U.S Department of Education Federal program title: Student Financial Assistance Cluster Assistant Listing Number: 84.007/84.033/84.063/84.268 Federal Award Identification Number: P007A221105 - P033A221105 - P063P221336 - P268K231336 Award Period: July 1, 2022 to June 30, 2023 Type of Finding: • Compliance, Other Matters • Significant Deficiency in Internal Control over Compliance Criteria or specific requirement: The Department of Education requires institutions to report the disbursement dates and amounts to the Common Origination and Disbursement (COD) system within 15 days of disbursing Pell (34 CFR 690.83(b)(2) and Direct Loan (34 CFR 685.309) funds to a student. Per 2 CFR 200.303, nonfederal entities receiving federal awards are required to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations, and program compliance requirements. Condition: The College did not timely report all disbursement dates and amounts to the COD system. Context: We identified 2 out of 40 COD disbursements tested that were not reported within the required 15 days to COD, these two instances were reported 7 days late. Questioned costs: None. Cause: The Student Financial Aid Office does not have a process in place to ensure all disbursements are reported within 15 days to COD. Effect: Student interest accrues based on disbursement date reported to COD, thus interest calculation could be misstated due to the discrepancy in disbursement dates reported. Repeat Finding: No. Recommendation: We recommend that the student financial aid department work to ensure disbursements are reported to COD within 15 days of the disbursement date. Views of responsible officials: Management agrees with the finding.
2023-002 Special Tests and Provisions Federal agency: U.S Department of Education Federal program title: Student Financial Assistance Cluster Assistant Listing Number: 84.007/84.033/84.063/84.268 Federal Award Identification Number: P007A221105 - P033A221105 - P063P221336 - P268K231336 Award Period: July 1, 2022 to June 30, 2023 Type of Finding: • Compliance, Other Matters • Significant Deficiency in Internal Control over Compliance Criteria or specific requirement: The Department of Education requires institutions to report the disbursement dates and amounts to the Common Origination and Disbursement (COD) system within 15 days of disbursing Pell (34 CFR 690.83(b)(2) and Direct Loan (34 CFR 685.309) funds to a student. Per 2 CFR 200.303, nonfederal entities receiving federal awards are required to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations, and program compliance requirements. Condition: The College did not timely report all disbursement dates and amounts to the COD system. Context: We identified 2 out of 40 COD disbursements tested that were not reported within the required 15 days to COD, these two instances were reported 7 days late. Questioned costs: None. Cause: The Student Financial Aid Office does not have a process in place to ensure all disbursements are reported within 15 days to COD. Effect: Student interest accrues based on disbursement date reported to COD, thus interest calculation could be misstated due to the discrepancy in disbursement dates reported. Repeat Finding: No. Recommendation: We recommend that the student financial aid department work to ensure disbursements are reported to COD within 15 days of the disbursement date. Views of responsible officials: Management agrees with the finding.
2023-002 Special Tests and Provisions Federal agency: U.S Department of Education Federal program title: Student Financial Assistance Cluster Assistant Listing Number: 84.007/84.033/84.063/84.268 Federal Award Identification Number: P007A221105 - P033A221105 - P063P221336 - P268K231336 Award Period: July 1, 2022 to June 30, 2023 Type of Finding: • Compliance, Other Matters • Significant Deficiency in Internal Control over Compliance Criteria or specific requirement: The Department of Education requires institutions to report the disbursement dates and amounts to the Common Origination and Disbursement (COD) system within 15 days of disbursing Pell (34 CFR 690.83(b)(2) and Direct Loan (34 CFR 685.309) funds to a student. Per 2 CFR 200.303, nonfederal entities receiving federal awards are required to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations, and program compliance requirements. Condition: The College did not timely report all disbursement dates and amounts to the COD system. Context: We identified 2 out of 40 COD disbursements tested that were not reported within the required 15 days to COD, these two instances were reported 7 days late. Questioned costs: None. Cause: The Student Financial Aid Office does not have a process in place to ensure all disbursements are reported within 15 days to COD. Effect: Student interest accrues based on disbursement date reported to COD, thus interest calculation could be misstated due to the discrepancy in disbursement dates reported. Repeat Finding: No. Recommendation: We recommend that the student financial aid department work to ensure disbursements are reported to COD within 15 days of the disbursement date. Views of responsible officials: Management agrees with the finding.
2023-003 Special Tests and Provisions Federal agency: U.S Department of Education Federal program title: Student Financial Assistance Cluster Assistant Listing Number: 84.007/84.033/84.063/84.268 Federal Award Identification Number: P007A221105 - P033A221105 - P063P221336 - P268K231336 Award Period: July 1, 2022 to June 30, 2023 Type of Finding: • Compliance, Other Matters • Significant Deficiency in Internal Control over Compliance Criteria or specific requirement: The Department of Education requires that Title IV credit balances must be paid to the student or parent no later than 14 days after the credit balance occurred. (34 CFR 164(h)(2)). Per 2 CFR 200.303, nonfederal entities receiving federal awards are required to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations, and program compliance requirements. Condition: The College did not timely refund credit balances to the student or parent. Context: We identified 1 out of 40 students tested that was not refunded within the required 14 days, the credit balance was refunded 7 days late. Questioned costs: None. Cause: The Student Financial Aid office had an automated process to ensure all refunds were issued in 14 days failed to recognize a credit balance in a student's account. Effect: The student did not have access to Title IV funds timely after disbursement. Repeat Finding: No. Recommendation: We recommend that the student financial aid department develop a process to identify all credit balances are paid timely. Views of responsible officials: Management agrees with the finding.
2023-003 Special Tests and Provisions Federal agency: U.S Department of Education Federal program title: Student Financial Assistance Cluster Assistant Listing Number: 84.007/84.033/84.063/84.268 Federal Award Identification Number: P007A221105 - P033A221105 - P063P221336 - P268K231336 Award Period: July 1, 2022 to June 30, 2023 Type of Finding: • Compliance, Other Matters • Significant Deficiency in Internal Control over Compliance Criteria or specific requirement: The Department of Education requires that Title IV credit balances must be paid to the student or parent no later than 14 days after the credit balance occurred. (34 CFR 164(h)(2)). Per 2 CFR 200.303, nonfederal entities receiving federal awards are required to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations, and program compliance requirements. Condition: The College did not timely refund credit balances to the student or parent. Context: We identified 1 out of 40 students tested that was not refunded within the required 14 days, the credit balance was refunded 7 days late. Questioned costs: None. Cause: The Student Financial Aid office had an automated process to ensure all refunds were issued in 14 days failed to recognize a credit balance in a student's account. Effect: The student did not have access to Title IV funds timely after disbursement. Repeat Finding: No. Recommendation: We recommend that the student financial aid department develop a process to identify all credit balances are paid timely. Views of responsible officials: Management agrees with the finding.
2023-003 Special Tests and Provisions Federal agency: U.S Department of Education Federal program title: Student Financial Assistance Cluster Assistant Listing Number: 84.007/84.033/84.063/84.268 Federal Award Identification Number: P007A221105 - P033A221105 - P063P221336 - P268K231336 Award Period: July 1, 2022 to June 30, 2023 Type of Finding: • Compliance, Other Matters • Significant Deficiency in Internal Control over Compliance Criteria or specific requirement: The Department of Education requires that Title IV credit balances must be paid to the student or parent no later than 14 days after the credit balance occurred. (34 CFR 164(h)(2)). Per 2 CFR 200.303, nonfederal entities receiving federal awards are required to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations, and program compliance requirements. Condition: The College did not timely refund credit balances to the student or parent. Context: We identified 1 out of 40 students tested that was not refunded within the required 14 days, the credit balance was refunded 7 days late. Questioned costs: None. Cause: The Student Financial Aid office had an automated process to ensure all refunds were issued in 14 days failed to recognize a credit balance in a student's account. Effect: The student did not have access to Title IV funds timely after disbursement. Repeat Finding: No. Recommendation: We recommend that the student financial aid department develop a process to identify all credit balances are paid timely. Views of responsible officials: Management agrees with the finding.
2023-003 Special Tests and Provisions Federal agency: U.S Department of Education Federal program title: Student Financial Assistance Cluster Assistant Listing Number: 84.007/84.033/84.063/84.268 Federal Award Identification Number: P007A221105 - P033A221105 - P063P221336 - P268K231336 Award Period: July 1, 2022 to June 30, 2023 Type of Finding: • Compliance, Other Matters • Significant Deficiency in Internal Control over Compliance Criteria or specific requirement: The Department of Education requires that Title IV credit balances must be paid to the student or parent no later than 14 days after the credit balance occurred. (34 CFR 164(h)(2)). Per 2 CFR 200.303, nonfederal entities receiving federal awards are required to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations, and program compliance requirements. Condition: The College did not timely refund credit balances to the student or parent. Context: We identified 1 out of 40 students tested that was not refunded within the required 14 days, the credit balance was refunded 7 days late. Questioned costs: None. Cause: The Student Financial Aid office had an automated process to ensure all refunds were issued in 14 days failed to recognize a credit balance in a student's account. Effect: The student did not have access to Title IV funds timely after disbursement. Repeat Finding: No. Recommendation: We recommend that the student financial aid department develop a process to identify all credit balances are paid timely. Views of responsible officials: Management agrees with the finding.
2023-003 Special Tests and Provisions Federal agency: U.S Department of Education Federal program title: Student Financial Assistance Cluster Assistant Listing Number: 84.007/84.033/84.063/84.268 Federal Award Identification Number: P007A221105 - P033A221105 - P063P221336 - P268K231336 Award Period: July 1, 2022 to June 30, 2023 Type of Finding: • Compliance, Other Matters • Significant Deficiency in Internal Control over Compliance Criteria or specific requirement: The Department of Education requires that Title IV credit balances must be paid to the student or parent no later than 14 days after the credit balance occurred. (34 CFR 164(h)(2)). Per 2 CFR 200.303, nonfederal entities receiving federal awards are required to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations, and program compliance requirements. Condition: The College did not timely refund credit balances to the student or parent. Context: We identified 1 out of 40 students tested that was not refunded within the required 14 days, the credit balance was refunded 7 days late. Questioned costs: None. Cause: The Student Financial Aid office had an automated process to ensure all refunds were issued in 14 days failed to recognize a credit balance in a student's account. Effect: The student did not have access to Title IV funds timely after disbursement. Repeat Finding: No. Recommendation: We recommend that the student financial aid department develop a process to identify all credit balances are paid timely. Views of responsible officials: Management agrees with the finding.
2023-003 Special Tests and Provisions Federal agency: U.S Department of Education Federal program title: Student Financial Assistance Cluster Assistant Listing Number: 84.007/84.033/84.063/84.268 Federal Award Identification Number: P007A221105 - P033A221105 - P063P221336 - P268K231336 Award Period: July 1, 2022 to June 30, 2023 Type of Finding: • Compliance, Other Matters • Significant Deficiency in Internal Control over Compliance Criteria or specific requirement: The Department of Education requires that Title IV credit balances must be paid to the student or parent no later than 14 days after the credit balance occurred. (34 CFR 164(h)(2)). Per 2 CFR 200.303, nonfederal entities receiving federal awards are required to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations, and program compliance requirements. Condition: The College did not timely refund credit balances to the student or parent. Context: We identified 1 out of 40 students tested that was not refunded within the required 14 days, the credit balance was refunded 7 days late. Questioned costs: None. Cause: The Student Financial Aid office had an automated process to ensure all refunds were issued in 14 days failed to recognize a credit balance in a student's account. Effect: The student did not have access to Title IV funds timely after disbursement. Repeat Finding: No. Recommendation: We recommend that the student financial aid department develop a process to identify all credit balances are paid timely. Views of responsible officials: Management agrees with the finding.
2023-004 Special Tests and Provisions Federal agency: U.S Department of Education Federal program title: Student Financial Assistance Cluster Assistant Listing Number: 84.007/84.033/84.063/84.268 Federal Award Identification Number: P007A221105 - P033A221105 - P063P221336 - P268K231336 Award Period: July 1, 2022 to June 30, 2023 Type of Finding: • Compliance, Other Matters • Significant Deficiency in Internal Control over Compliance Criteria or specific requirement: The Department of Education requires that the college provide to the Secretary an up-to-date Uniform Resource Locator (URL) for the contract for publication in a centralized database to the public. (34 CFR 668.164(f)(4)(iii)(B)). Per 2 CFR 200.303, nonfederal entities receiving federal awards are required to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations, and program compliance requirements. Condition: The college had the required information on their website but had not disclosed the URL to the Department of Education. Context: The college published the contract, assessed fees, and terms and conditions, however, they did not properly report the URL to Department of Education. Questioned costs: None. Cause: The contract is in its first year of operations, and the URL was not submitted within 60 days after award year. Effect: The college was not in compliance with Title IV third-party servicer compliance. Repeat Finding: No. Recommendation: We recommend the College implement policies and procedures to identify these requirements and timely report to the appropriate regulators. Views of responsible officials: Management agrees with the finding.
2023-004 Special Tests and Provisions Federal agency: U.S Department of Education Federal program title: Student Financial Assistance Cluster Assistant Listing Number: 84.007/84.033/84.063/84.268 Federal Award Identification Number: P007A221105 - P033A221105 - P063P221336 - P268K231336 Award Period: July 1, 2022 to June 30, 2023 Type of Finding: • Compliance, Other Matters • Significant Deficiency in Internal Control over Compliance Criteria or specific requirement: The Department of Education requires that the college provide to the Secretary an up-to-date Uniform Resource Locator (URL) for the contract for publication in a centralized database to the public. (34 CFR 668.164(f)(4)(iii)(B)). Per 2 CFR 200.303, nonfederal entities receiving federal awards are required to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations, and program compliance requirements. Condition: The college had the required information on their website but had not disclosed the URL to the Department of Education. Context: The college published the contract, assessed fees, and terms and conditions, however, they did not properly report the URL to Department of Education. Questioned costs: None. Cause: The contract is in its first year of operations, and the URL was not submitted within 60 days after award year. Effect: The college was not in compliance with Title IV third-party servicer compliance. Repeat Finding: No. Recommendation: We recommend the College implement policies and procedures to identify these requirements and timely report to the appropriate regulators. Views of responsible officials: Management agrees with the finding.
2023-004 Special Tests and Provisions Federal agency: U.S Department of Education Federal program title: Student Financial Assistance Cluster Assistant Listing Number: 84.007/84.033/84.063/84.268 Federal Award Identification Number: P007A221105 - P033A221105 - P063P221336 - P268K231336 Award Period: July 1, 2022 to June 30, 2023 Type of Finding: • Compliance, Other Matters • Significant Deficiency in Internal Control over Compliance Criteria or specific requirement: The Department of Education requires that the college provide to the Secretary an up-to-date Uniform Resource Locator (URL) for the contract for publication in a centralized database to the public. (34 CFR 668.164(f)(4)(iii)(B)). Per 2 CFR 200.303, nonfederal entities receiving federal awards are required to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations, and program compliance requirements. Condition: The college had the required information on their website but had not disclosed the URL to the Department of Education. Context: The college published the contract, assessed fees, and terms and conditions, however, they did not properly report the URL to Department of Education. Questioned costs: None. Cause: The contract is in its first year of operations, and the URL was not submitted within 60 days after award year. Effect: The college was not in compliance with Title IV third-party servicer compliance. Repeat Finding: No. Recommendation: We recommend the College implement policies and procedures to identify these requirements and timely report to the appropriate regulators. Views of responsible officials: Management agrees with the finding.
2023-004 Special Tests and Provisions Federal agency: U.S Department of Education Federal program title: Student Financial Assistance Cluster Assistant Listing Number: 84.007/84.033/84.063/84.268 Federal Award Identification Number: P007A221105 - P033A221105 - P063P221336 - P268K231336 Award Period: July 1, 2022 to June 30, 2023 Type of Finding: • Compliance, Other Matters • Significant Deficiency in Internal Control over Compliance Criteria or specific requirement: The Department of Education requires that the college provide to the Secretary an up-to-date Uniform Resource Locator (URL) for the contract for publication in a centralized database to the public. (34 CFR 668.164(f)(4)(iii)(B)). Per 2 CFR 200.303, nonfederal entities receiving federal awards are required to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations, and program compliance requirements. Condition: The college had the required information on their website but had not disclosed the URL to the Department of Education. Context: The college published the contract, assessed fees, and terms and conditions, however, they did not properly report the URL to Department of Education. Questioned costs: None. Cause: The contract is in its first year of operations, and the URL was not submitted within 60 days after award year. Effect: The college was not in compliance with Title IV third-party servicer compliance. Repeat Finding: No. Recommendation: We recommend the College implement policies and procedures to identify these requirements and timely report to the appropriate regulators. Views of responsible officials: Management agrees with the finding.
2023-004 Special Tests and Provisions Federal agency: U.S Department of Education Federal program title: Student Financial Assistance Cluster Assistant Listing Number: 84.007/84.033/84.063/84.268 Federal Award Identification Number: P007A221105 - P033A221105 - P063P221336 - P268K231336 Award Period: July 1, 2022 to June 30, 2023 Type of Finding: • Compliance, Other Matters • Significant Deficiency in Internal Control over Compliance Criteria or specific requirement: The Department of Education requires that the college provide to the Secretary an up-to-date Uniform Resource Locator (URL) for the contract for publication in a centralized database to the public. (34 CFR 668.164(f)(4)(iii)(B)). Per 2 CFR 200.303, nonfederal entities receiving federal awards are required to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations, and program compliance requirements. Condition: The college had the required information on their website but had not disclosed the URL to the Department of Education. Context: The college published the contract, assessed fees, and terms and conditions, however, they did not properly report the URL to Department of Education. Questioned costs: None. Cause: The contract is in its first year of operations, and the URL was not submitted within 60 days after award year. Effect: The college was not in compliance with Title IV third-party servicer compliance. Repeat Finding: No. Recommendation: We recommend the College implement policies and procedures to identify these requirements and timely report to the appropriate regulators. Views of responsible officials: Management agrees with the finding.
2023-004 Special Tests and Provisions Federal agency: U.S Department of Education Federal program title: Student Financial Assistance Cluster Assistant Listing Number: 84.007/84.033/84.063/84.268 Federal Award Identification Number: P007A221105 - P033A221105 - P063P221336 - P268K231336 Award Period: July 1, 2022 to June 30, 2023 Type of Finding: • Compliance, Other Matters • Significant Deficiency in Internal Control over Compliance Criteria or specific requirement: The Department of Education requires that the college provide to the Secretary an up-to-date Uniform Resource Locator (URL) for the contract for publication in a centralized database to the public. (34 CFR 668.164(f)(4)(iii)(B)). Per 2 CFR 200.303, nonfederal entities receiving federal awards are required to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations, and program compliance requirements. Condition: The college had the required information on their website but had not disclosed the URL to the Department of Education. Context: The college published the contract, assessed fees, and terms and conditions, however, they did not properly report the URL to Department of Education. Questioned costs: None. Cause: The contract is in its first year of operations, and the URL was not submitted within 60 days after award year. Effect: The college was not in compliance with Title IV third-party servicer compliance. Repeat Finding: No. Recommendation: We recommend the College implement policies and procedures to identify these requirements and timely report to the appropriate regulators. Views of responsible officials: Management agrees with the finding.
2023-005 Special Tests and Provisions Federal agency: U.S Department of Education Federal program title: Student Financial Assistance Cluster Assistant Listing Number: 84.007/84.033/84.063/84.268 Federal Award Identification Number: P007A221105 - P033A221105 - P063P221336 - P268K231336 Award Period: July 1, 2022 to June 30, 2023 Type of Finding: • Compliance, Other Matters • Significant Deficiency in Internal Control over Compliance Criteria or specific requirement: The Code of Federal Regulations, 34 CFR 682.610, states that institutions must report accurately the enrollment status of all students regardless of if they receive aid from the institution or not. Changes to said status are required to be reported within 30 days of becoming aware of the status change, or with the next scheduled transmission of statuses if the scheduled transmission is within 60 days. The Code of Federal Regulations, 34 CFR 685.309(b), states the school is required to report changes in the student’s enrollment status, the effective date of the status, and an anticipated completion date Per 2 CFR 200.303, nonfederal entities receiving federal awards are required to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations, and program compliance requirements. Condition: The College did not properly report student enrollment changes for students who received federal student aid to the National Student Loan Data System (NSLDS). Context: During our testing of 40 students, we identified 5 students that were reported past the 60-day reporting timeframe to NSLDS. These student enrollment dates were reported 12 days late. Questioned costs: None. Cause: The College didn't have proper procedures in place to verify students' status in NSLDS matched the institutions records in a timely manner. Effect: Incorrect dates submitted to NSLDS may be used to determine the grace period for the repayment and interest of outstanding Title IV student loans. Repeat Finding: No. Recommendation: We recommend the College review current processes for reporting to NSLDS and implement procedures to ensure submissions are reported timely. Views of responsible officials: Management agrees with the finding.
2023-005 Special Tests and Provisions Federal agency: U.S Department of Education Federal program title: Student Financial Assistance Cluster Assistant Listing Number: 84.007/84.033/84.063/84.268 Federal Award Identification Number: P007A221105 - P033A221105 - P063P221336 - P268K231336 Award Period: July 1, 2022 to June 30, 2023 Type of Finding: • Compliance, Other Matters • Significant Deficiency in Internal Control over Compliance Criteria or specific requirement: The Code of Federal Regulations, 34 CFR 682.610, states that institutions must report accurately the enrollment status of all students regardless of if they receive aid from the institution or not. Changes to said status are required to be reported within 30 days of becoming aware of the status change, or with the next scheduled transmission of statuses if the scheduled transmission is within 60 days. The Code of Federal Regulations, 34 CFR 685.309(b), states the school is required to report changes in the student’s enrollment status, the effective date of the status, and an anticipated completion date Per 2 CFR 200.303, nonfederal entities receiving federal awards are required to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations, and program compliance requirements. Condition: The College did not properly report student enrollment changes for students who received federal student aid to the National Student Loan Data System (NSLDS). Context: During our testing of 40 students, we identified 5 students that were reported past the 60-day reporting timeframe to NSLDS. These student enrollment dates were reported 12 days late. Questioned costs: None. Cause: The College didn't have proper procedures in place to verify students' status in NSLDS matched the institutions records in a timely manner. Effect: Incorrect dates submitted to NSLDS may be used to determine the grace period for the repayment and interest of outstanding Title IV student loans. Repeat Finding: No. Recommendation: We recommend the College review current processes for reporting to NSLDS and implement procedures to ensure submissions are reported timely. Views of responsible officials: Management agrees with the finding.
2023-005 Special Tests and Provisions Federal agency: U.S Department of Education Federal program title: Student Financial Assistance Cluster Assistant Listing Number: 84.007/84.033/84.063/84.268 Federal Award Identification Number: P007A221105 - P033A221105 - P063P221336 - P268K231336 Award Period: July 1, 2022 to June 30, 2023 Type of Finding: • Compliance, Other Matters • Significant Deficiency in Internal Control over Compliance Criteria or specific requirement: The Code of Federal Regulations, 34 CFR 682.610, states that institutions must report accurately the enrollment status of all students regardless of if they receive aid from the institution or not. Changes to said status are required to be reported within 30 days of becoming aware of the status change, or with the next scheduled transmission of statuses if the scheduled transmission is within 60 days. The Code of Federal Regulations, 34 CFR 685.309(b), states the school is required to report changes in the student’s enrollment status, the effective date of the status, and an anticipated completion date Per 2 CFR 200.303, nonfederal entities receiving federal awards are required to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations, and program compliance requirements. Condition: The College did not properly report student enrollment changes for students who received federal student aid to the National Student Loan Data System (NSLDS). Context: During our testing of 40 students, we identified 5 students that were reported past the 60-day reporting timeframe to NSLDS. These student enrollment dates were reported 12 days late. Questioned costs: None. Cause: The College didn't have proper procedures in place to verify students' status in NSLDS matched the institutions records in a timely manner. Effect: Incorrect dates submitted to NSLDS may be used to determine the grace period for the repayment and interest of outstanding Title IV student loans. Repeat Finding: No. Recommendation: We recommend the College review current processes for reporting to NSLDS and implement procedures to ensure submissions are reported timely. Views of responsible officials: Management agrees with the finding.
2023-005 Special Tests and Provisions Federal agency: U.S Department of Education Federal program title: Student Financial Assistance Cluster Assistant Listing Number: 84.007/84.033/84.063/84.268 Federal Award Identification Number: P007A221105 - P033A221105 - P063P221336 - P268K231336 Award Period: July 1, 2022 to June 30, 2023 Type of Finding: • Compliance, Other Matters • Significant Deficiency in Internal Control over Compliance Criteria or specific requirement: The Code of Federal Regulations, 34 CFR 682.610, states that institutions must report accurately the enrollment status of all students regardless of if they receive aid from the institution or not. Changes to said status are required to be reported within 30 days of becoming aware of the status change, or with the next scheduled transmission of statuses if the scheduled transmission is within 60 days. The Code of Federal Regulations, 34 CFR 685.309(b), states the school is required to report changes in the student’s enrollment status, the effective date of the status, and an anticipated completion date Per 2 CFR 200.303, nonfederal entities receiving federal awards are required to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations, and program compliance requirements. Condition: The College did not properly report student enrollment changes for students who received federal student aid to the National Student Loan Data System (NSLDS). Context: During our testing of 40 students, we identified 5 students that were reported past the 60-day reporting timeframe to NSLDS. These student enrollment dates were reported 12 days late. Questioned costs: None. Cause: The College didn't have proper procedures in place to verify students' status in NSLDS matched the institutions records in a timely manner. Effect: Incorrect dates submitted to NSLDS may be used to determine the grace period for the repayment and interest of outstanding Title IV student loans. Repeat Finding: No. Recommendation: We recommend the College review current processes for reporting to NSLDS and implement procedures to ensure submissions are reported timely. Views of responsible officials: Management agrees with the finding.
2023-005 Special Tests and Provisions Federal agency: U.S Department of Education Federal program title: Student Financial Assistance Cluster Assistant Listing Number: 84.007/84.033/84.063/84.268 Federal Award Identification Number: P007A221105 - P033A221105 - P063P221336 - P268K231336 Award Period: July 1, 2022 to June 30, 2023 Type of Finding: • Compliance, Other Matters • Significant Deficiency in Internal Control over Compliance Criteria or specific requirement: The Code of Federal Regulations, 34 CFR 682.610, states that institutions must report accurately the enrollment status of all students regardless of if they receive aid from the institution or not. Changes to said status are required to be reported within 30 days of becoming aware of the status change, or with the next scheduled transmission of statuses if the scheduled transmission is within 60 days. The Code of Federal Regulations, 34 CFR 685.309(b), states the school is required to report changes in the student’s enrollment status, the effective date of the status, and an anticipated completion date Per 2 CFR 200.303, nonfederal entities receiving federal awards are required to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations, and program compliance requirements. Condition: The College did not properly report student enrollment changes for students who received federal student aid to the National Student Loan Data System (NSLDS). Context: During our testing of 40 students, we identified 5 students that were reported past the 60-day reporting timeframe to NSLDS. These student enrollment dates were reported 12 days late. Questioned costs: None. Cause: The College didn't have proper procedures in place to verify students' status in NSLDS matched the institutions records in a timely manner. Effect: Incorrect dates submitted to NSLDS may be used to determine the grace period for the repayment and interest of outstanding Title IV student loans. Repeat Finding: No. Recommendation: We recommend the College review current processes for reporting to NSLDS and implement procedures to ensure submissions are reported timely. Views of responsible officials: Management agrees with the finding.
2023-005 Special Tests and Provisions Federal agency: U.S Department of Education Federal program title: Student Financial Assistance Cluster Assistant Listing Number: 84.007/84.033/84.063/84.268 Federal Award Identification Number: P007A221105 - P033A221105 - P063P221336 - P268K231336 Award Period: July 1, 2022 to June 30, 2023 Type of Finding: • Compliance, Other Matters • Significant Deficiency in Internal Control over Compliance Criteria or specific requirement: The Code of Federal Regulations, 34 CFR 682.610, states that institutions must report accurately the enrollment status of all students regardless of if they receive aid from the institution or not. Changes to said status are required to be reported within 30 days of becoming aware of the status change, or with the next scheduled transmission of statuses if the scheduled transmission is within 60 days. The Code of Federal Regulations, 34 CFR 685.309(b), states the school is required to report changes in the student’s enrollment status, the effective date of the status, and an anticipated completion date Per 2 CFR 200.303, nonfederal entities receiving federal awards are required to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations, and program compliance requirements. Condition: The College did not properly report student enrollment changes for students who received federal student aid to the National Student Loan Data System (NSLDS). Context: During our testing of 40 students, we identified 5 students that were reported past the 60-day reporting timeframe to NSLDS. These student enrollment dates were reported 12 days late. Questioned costs: None. Cause: The College didn't have proper procedures in place to verify students' status in NSLDS matched the institutions records in a timely manner. Effect: Incorrect dates submitted to NSLDS may be used to determine the grace period for the repayment and interest of outstanding Title IV student loans. Repeat Finding: No. Recommendation: We recommend the College review current processes for reporting to NSLDS and implement procedures to ensure submissions are reported timely. Views of responsible officials: Management agrees with the finding.
Findings And Questioned Costs For Federal Awards Reference Number: 2023-001 Prior year Finding: No Federal Agency: U.S. Department of the Treasury Federal Program: COVID-19 - Coronavirus State and Local Fiscal Recovery Funds Assistance Listing Number: 21.027 Compliance Requirement: Procurement, Suspension and Debarment Type of Finding: Significant Deficiency in Internal control, Noncompliance Criteria: Compliance - Per 2 CFR section 200.318, when procuring property, the non- Federal entity must have and use documented procurement procedures, consistent with States, for the acquisition of property or services required under a Federal award or subaward. Compliance - Per 2 CFR 200.214, restricts awards, subawards and contracts with certain parties that are debarred, suspended or otherwise excluded from or ineligible for participation in Federal assistance programs or activities. 2 CFR 180.300 states that an entity may determine suspension and debarment status by: (a) Checking SAM (System for Award Management) Exclusions; or (b) Collecting a certification from that person (c) Adding a clause or condition to the covered transaction with that person. Control - Per 2 CFR 200.303(a), a non-Federal entity must: Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations and the terms and conditions of the Federal award. These internal controls should comply with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition: The Town was unable to provide documentation to support compliance with the required State procurement processes for acquiring property or services. In addition, the Town did not provide support that the suspension and debarment status of the vendor was checked before the contract was awarded. Context: For all contracts selected for testing, no support was provided for how the contract was procured. Further, the suspension and debarment status of the vendor was not documented for that contract. Questioned Costs: Undetermined. Cause: The Town’s internal controls were not sufficient to ensure that applicable procurement policies and Federal suspension and debarment regulations were followed for purchased made for the program. Effect: The Town is not compliant with federal and state procurement and suspension and debarment requirements. Failure to adhere to procurement and suspension and debarment policies and procedures may result in obtaining goods and services under terms that are not in the best interest of the Federal program. Recommendation: The Town should review and enhance controls and procedures to ensure that it follows the applicable procurement policy and Federal suspension and debarment regulations for all goods and services charged to the program. Views of responsible officials: We agree with the auditor’s recommendation. The Town of Camden, Delaware will review the State’s procurement process to satisfy the compliance requirements for the program. The Town of Camden, Delaware will also put procedures in place to check and review each bidder as part of the Federal suspension and debarment policies.
Information on the federal program: Subject: Education Stabilization Fund – Activities Allowed or Unallowed, Allowable Costs/Cost Principles Federal Agency: Department of Education Federal Program: COVID-19 – Education Stabilization Fund Assistance Listing Number: 84.425C, 84.425D, 84.425U Federal Award Numbers: S425C200018, S425D200013, S425D210013 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Activities Allowed or Unallowed, Allowable Costs/Cost Principles Audit Findings: Material Weakness, Qualified Opinion Criteria: 2 CFR 200.303 states in part: "The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal awards in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in 'Standards for Internal Control in the Federal Government' issued by the Comptroller General of the United States or the 'Internal Control Integrated Framework', issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO)...." Condition: The School Corporation did not have internal controls in place to ensure that the School Corporation complied with the Activities Allowed or Unallowed, Allowable Costs/Cost Principles compliance requirements. Cause: A proper system of internal controls was not designed by management of the School Corporation. Embedded within a properly designed and implemented internal control system should be internal controls consisting of policies and procedures. Policies reflect the School Corporation's management statements of what should be done to effect internal controls, and procedures should consist of actions that would implement these policies. Effect: Without the proper design or implementation of the components of a system of internal control, including policies and procedures that provide segregation of duties and additional oversight as needed, the control system cannot be capable of effectively preventing, or detecting and correcting, material noncompliance. Questioned Costs: There were $82,276 of questioned costs identified. There were $78,462 of ESSER II funds that were drawn down in advance of the disbursement taking place, $3,013 of GEER funds drawn down in advance of the disbursement taking place, and $801 of questioned costs pertaining to payroll charges to the grant that were not supported by contracts and/or timecards. Context: In our testing of disbursements charged to the Education Stabilization Fund grants, we noted the ESSER II grant award, tracked in Fund 7931 has a positive cash balance at June 30, 2023. We were able to tie out the disbursements reported on the Annual Financial Report to underlying detail. We noted the School Corporation had drawn down $78,462 of ESSER II funds in advance of the expenditures taking place. The GEER grant award, which is tracked in Fund 7940, had a positive cash balance of $36,013 at June 30, 2023. This was a result of $33,000 of expenditures pertaining to the GEER fund being incorrectly recorded in the Operating fund during the year, rather than the applicable GEER fund. The remaining $3,013 is due to drawing down funds in advance of the expenditures taking place. During our testing payroll disbursements, we noted three selections in a sample of 60 payroll disbursements for which management was unable to provide adequate documentation to support the amounts disbursed to the employees. The employee in question went on medical leave during the school year, but continued to receive payments over the remaining months. Management was unable to provide an adjusted contract that agreed to the amounts being paid to the employee. These issues resulted in questioned costs of $801. Identification as a repeat finding: No Recommendation: We recommended that management of the School Corporation design and implement a proper system of internal control, including policies and procedures, that are documented that would provide segregation of duties to ensure appropriate reviews, approvals and oversight are taking place to support disbursements that are charged to the respective grants as well as amounts being requested for draw downs. Views of Responsible Officials and Planned Corrective Actions: Management agrees with the finding and has prepared a corrective action plan.
Information on the federal program: Subject: Education Stabilization Fund – Activities Allowed or Unallowed, Allowable Costs/Cost Principles Federal Agency: Department of Education Federal Program: COVID-19 – Education Stabilization Fund Assistance Listing Number: 84.425C, 84.425D, 84.425U Federal Award Numbers: S425C200018, S425D200013, S425D210013 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Activities Allowed or Unallowed, Allowable Costs/Cost Principles Audit Findings: Material Weakness, Qualified Opinion Criteria: 2 CFR 200.303 states in part: "The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal awards in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in 'Standards for Internal Control in the Federal Government' issued by the Comptroller General of the United States or the 'Internal Control Integrated Framework', issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO)...." Condition: The School Corporation did not have internal controls in place to ensure that the School Corporation complied with the Activities Allowed or Unallowed, Allowable Costs/Cost Principles compliance requirements. Cause: A proper system of internal controls was not designed by management of the School Corporation. Embedded within a properly designed and implemented internal control system should be internal controls consisting of policies and procedures. Policies reflect the School Corporation's management statements of what should be done to effect internal controls, and procedures should consist of actions that would implement these policies. Effect: Without the proper design or implementation of the components of a system of internal control, including policies and procedures that provide segregation of duties and additional oversight as needed, the control system cannot be capable of effectively preventing, or detecting and correcting, material noncompliance. Questioned Costs: There were $82,276 of questioned costs identified. There were $78,462 of ESSER II funds that were drawn down in advance of the disbursement taking place, $3,013 of GEER funds drawn down in advance of the disbursement taking place, and $801 of questioned costs pertaining to payroll charges to the grant that were not supported by contracts and/or timecards. Context: In our testing of disbursements charged to the Education Stabilization Fund grants, we noted the ESSER II grant award, tracked in Fund 7931 has a positive cash balance at June 30, 2023. We were able to tie out the disbursements reported on the Annual Financial Report to underlying detail. We noted the School Corporation had drawn down $78,462 of ESSER II funds in advance of the expenditures taking place. The GEER grant award, which is tracked in Fund 7940, had a positive cash balance of $36,013 at June 30, 2023. This was a result of $33,000 of expenditures pertaining to the GEER fund being incorrectly recorded in the Operating fund during the year, rather than the applicable GEER fund. The remaining $3,013 is due to drawing down funds in advance of the expenditures taking place. During our testing payroll disbursements, we noted three selections in a sample of 60 payroll disbursements for which management was unable to provide adequate documentation to support the amounts disbursed to the employees. The employee in question went on medical leave during the school year, but continued to receive payments over the remaining months. Management was unable to provide an adjusted contract that agreed to the amounts being paid to the employee. These issues resulted in questioned costs of $801. Identification as a repeat finding: No Recommendation: We recommended that management of the School Corporation design and implement a proper system of internal control, including policies and procedures, that are documented that would provide segregation of duties to ensure appropriate reviews, approvals and oversight are taking place to support disbursements that are charged to the respective grants as well as amounts being requested for draw downs. Views of Responsible Officials and Planned Corrective Actions: Management agrees with the finding and has prepared a corrective action plan.
Information on the federal program: Subject: Education Stabilization Fund – Activities Allowed or Unallowed, Allowable Costs/Cost Principles Federal Agency: Department of Education Federal Program: COVID-19 – Education Stabilization Fund Assistance Listing Number: 84.425C, 84.425D, 84.425U Federal Award Numbers: S425C200018, S425D200013, S425D210013 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Activities Allowed or Unallowed, Allowable Costs/Cost Principles Audit Findings: Material Weakness, Qualified Opinion Criteria: 2 CFR 200.303 states in part: "The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal awards in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in 'Standards for Internal Control in the Federal Government' issued by the Comptroller General of the United States or the 'Internal Control Integrated Framework', issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO)...." Condition: The School Corporation did not have internal controls in place to ensure that the School Corporation complied with the Activities Allowed or Unallowed, Allowable Costs/Cost Principles compliance requirements. Cause: A proper system of internal controls was not designed by management of the School Corporation. Embedded within a properly designed and implemented internal control system should be internal controls consisting of policies and procedures. Policies reflect the School Corporation's management statements of what should be done to effect internal controls, and procedures should consist of actions that would implement these policies. Effect: Without the proper design or implementation of the components of a system of internal control, including policies and procedures that provide segregation of duties and additional oversight as needed, the control system cannot be capable of effectively preventing, or detecting and correcting, material noncompliance. Questioned Costs: There were $82,276 of questioned costs identified. There were $78,462 of ESSER II funds that were drawn down in advance of the disbursement taking place, $3,013 of GEER funds drawn down in advance of the disbursement taking place, and $801 of questioned costs pertaining to payroll charges to the grant that were not supported by contracts and/or timecards. Context: In our testing of disbursements charged to the Education Stabilization Fund grants, we noted the ESSER II grant award, tracked in Fund 7931 has a positive cash balance at June 30, 2023. We were able to tie out the disbursements reported on the Annual Financial Report to underlying detail. We noted the School Corporation had drawn down $78,462 of ESSER II funds in advance of the expenditures taking place. The GEER grant award, which is tracked in Fund 7940, had a positive cash balance of $36,013 at June 30, 2023. This was a result of $33,000 of expenditures pertaining to the GEER fund being incorrectly recorded in the Operating fund during the year, rather than the applicable GEER fund. The remaining $3,013 is due to drawing down funds in advance of the expenditures taking place. During our testing payroll disbursements, we noted three selections in a sample of 60 payroll disbursements for which management was unable to provide adequate documentation to support the amounts disbursed to the employees. The employee in question went on medical leave during the school year, but continued to receive payments over the remaining months. Management was unable to provide an adjusted contract that agreed to the amounts being paid to the employee. These issues resulted in questioned costs of $801. Identification as a repeat finding: No Recommendation: We recommended that management of the School Corporation design and implement a proper system of internal control, including policies and procedures, that are documented that would provide segregation of duties to ensure appropriate reviews, approvals and oversight are taking place to support disbursements that are charged to the respective grants as well as amounts being requested for draw downs. Views of Responsible Officials and Planned Corrective Actions: Management agrees with the finding and has prepared a corrective action plan.
Information on the federal program: Subject: Education Stabilization Fund – Activities Allowed or Unallowed, Allowable Costs/Cost Principles Federal Agency: Department of Education Federal Program: COVID-19 – Education Stabilization Fund Assistance Listing Number: 84.425C, 84.425D, 84.425U Federal Award Numbers: S425C200018, S425D200013, S425D210013 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Activities Allowed or Unallowed, Allowable Costs/Cost Principles Audit Findings: Material Weakness, Qualified Opinion Criteria: 2 CFR 200.303 states in part: "The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal awards in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in 'Standards for Internal Control in the Federal Government' issued by the Comptroller General of the United States or the 'Internal Control Integrated Framework', issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO)...." Condition: The School Corporation did not have internal controls in place to ensure that the School Corporation complied with the Activities Allowed or Unallowed, Allowable Costs/Cost Principles compliance requirements. Cause: A proper system of internal controls was not designed by management of the School Corporation. Embedded within a properly designed and implemented internal control system should be internal controls consisting of policies and procedures. Policies reflect the School Corporation's management statements of what should be done to effect internal controls, and procedures should consist of actions that would implement these policies. Effect: Without the proper design or implementation of the components of a system of internal control, including policies and procedures that provide segregation of duties and additional oversight as needed, the control system cannot be capable of effectively preventing, or detecting and correcting, material noncompliance. Questioned Costs: There were $82,276 of questioned costs identified. There were $78,462 of ESSER II funds that were drawn down in advance of the disbursement taking place, $3,013 of GEER funds drawn down in advance of the disbursement taking place, and $801 of questioned costs pertaining to payroll charges to the grant that were not supported by contracts and/or timecards. Context: In our testing of disbursements charged to the Education Stabilization Fund grants, we noted the ESSER II grant award, tracked in Fund 7931 has a positive cash balance at June 30, 2023. We were able to tie out the disbursements reported on the Annual Financial Report to underlying detail. We noted the School Corporation had drawn down $78,462 of ESSER II funds in advance of the expenditures taking place. The GEER grant award, which is tracked in Fund 7940, had a positive cash balance of $36,013 at June 30, 2023. This was a result of $33,000 of expenditures pertaining to the GEER fund being incorrectly recorded in the Operating fund during the year, rather than the applicable GEER fund. The remaining $3,013 is due to drawing down funds in advance of the expenditures taking place. During our testing payroll disbursements, we noted three selections in a sample of 60 payroll disbursements for which management was unable to provide adequate documentation to support the amounts disbursed to the employees. The employee in question went on medical leave during the school year, but continued to receive payments over the remaining months. Management was unable to provide an adjusted contract that agreed to the amounts being paid to the employee. These issues resulted in questioned costs of $801. Identification as a repeat finding: No Recommendation: We recommended that management of the School Corporation design and implement a proper system of internal control, including policies and procedures, that are documented that would provide segregation of duties to ensure appropriate reviews, approvals and oversight are taking place to support disbursements that are charged to the respective grants as well as amounts being requested for draw downs. Views of Responsible Officials and Planned Corrective Actions: Management agrees with the finding and has prepared a corrective action plan.
2023-001 Significant Deficiency in Internal Controls over Compliance - Activities Allowed or Unallowed and Allowable Costs/Cost Principles. IDENTIFICATION OF MAJOR PROGRAM - 93.592 Family Violence Prevention and Services/Discretionary. CRITIERA or SPECIFIC REQUIREMENT - Uniform Guidance 2 C.F.R § 200.303 The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non- Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). (b) Comply with the U.S. Constitution, Federal statutes, regulations, and the terms and conditions of the Federal awards. (c) Evaluate and monitor the non-Federal entity's compliance th statutes, regulations and the terms and conditions of Federal awards. (d) Take prompt action when instances of noncompliance are identified including noncompliance identified in audit findings. (e) Take reasonable measures to safeguard protected personally identifiable information and other information the Federal awarding agency or pass-through entity designates as sensitive or the non-Federal entity considers sensitive consistent with applicable Federal, State, local, and tribal laws regarding privacy and responsibility over confidentiality. CONDITION - WISH did not maintain expenditure support and/or evidence of expenditure approvals in accordance with its own policies and procedures. CAUSE - Management was heavily involved in daily operations and receive a significant volume of requisitions so they were often discussed and approved verbally in order to process a check timely within the next check run. EFFECT OR POTENTIAL EFFECT - Lack of substantiation that internal controls are operating effectively in order to allow management, in the normal course of performing their assigned functions, to prevent, or detect and correct, noncompliance with a type of compliance requirement of a federal program on a timely basis. QUESTIONED COSTS - None known and likely were below program materiality and questioned costs threshold. CONTEXT - Three credit card expenditures did not have a receipt or invoice to support the charge. For nonpayroll expenditures, a Requisition Form is to be used and contains a line for initiator's signature, supervisor's, and Executive Director's. Auditor noted six instances where the form was either not signed by the Executive Director, or not signed at all. IDENTIFICATION OF REPEAT FINDING - Not Applicable. RECOMMENDATIONS - We recommend that all relevant documentation is retained in order to support approved expenditures and which follow WISH policy and procedures as well as the Uniform Guidance. VIEWS OF RESPONSIBLE OFFICIALS - See corrective action plan
FINDING 2023-003 Subject: Child Nutrition Cluster - Internal Controls Federal Agency: Department of Agriculture Federal Programs: School Breakfast Program, National School Lunch Program, Summer Food Service Program for Children Assistance Listings Numbers: 10.553, 10.555, 10.559 Federal Award Numbers and Years (or Other Identifying Numbers): FY 21-22, FY 22-23, 7182022IN890342, 7182023IN890342 Pass-Through Entity: Indiana Department of Education Compliance Requirements: Activities Allowed or Unallowed, Allowable Costs/Cost Principles Audit Finding: Material Weakness Condition and Context The School Corporation did not have effective internal controls in place to ensure costs charged to the food service program were allowable and in conformance with the cost principles. The School Corporation designed and implemented a process to ensure that costs charged for vendor claims to the food service program were allowable and in conformance with the cost principles. The process was for vendor claims to be reviewed and approved by the department head or Food Service Director and the Treasurer. However, during our test of 40 vendor claims, there were 5 claims that were not approved by the department head or the Food Service Director and 1 claim not approved by the department head or Food Service Director and the Treasurer. The lack of internal controls was a systemic issue that occurred throughout the audit period. Criteria 2 CFR 200.303 states in part: "The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in 'Standards for Internal Control in the Federal Government' issued by the Comptroller General of the United States or the 'Internal Control Integrated Framework', issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). . . ." Cause A proper system of internal controls was not designed by management of the School Corporation, which would include segregation of key functions. Embedded within a properly designed and implemented internal control system should be internal controls consisting of policies and procedures. Policies reflect the School Corporation's management statements of what should be done to effect internal controls, and procedures should consist of actions that would implement these policies. Effect Without the proper design or implementation of the components of a system of internal controls, including policies and procedures that provide segregation of duties and additional oversight as needed, the internal control system cannot be capable of effectively preventing, or detecting and correcting, material noncompliance. Questioned Costs There were no questioned costs identified. Recommendation We recommended that management of the School Corporation design and implement a proper system of internal controls, including policies and procedures that would provide segregation of duties to ensure appropriate reviews, approvals, and oversight regarding vendor claims. Views of Responsible Officials For the views of responsible officials, refer to the Corrective Action Plan that is part of this report.
FINDING 2023-003 Subject: Child Nutrition Cluster - Internal Controls Federal Agency: Department of Agriculture Federal Programs: School Breakfast Program, National School Lunch Program, Summer Food Service Program for Children Assistance Listings Numbers: 10.553, 10.555, 10.559 Federal Award Numbers and Years (or Other Identifying Numbers): FY 21-22, FY 22-23, 7182022IN890342, 7182023IN890342 Pass-Through Entity: Indiana Department of Education Compliance Requirements: Activities Allowed or Unallowed, Allowable Costs/Cost Principles Audit Finding: Material Weakness Condition and Context The School Corporation did not have effective internal controls in place to ensure costs charged to the food service program were allowable and in conformance with the cost principles. The School Corporation designed and implemented a process to ensure that costs charged for vendor claims to the food service program were allowable and in conformance with the cost principles. The process was for vendor claims to be reviewed and approved by the department head or Food Service Director and the Treasurer. However, during our test of 40 vendor claims, there were 5 claims that were not approved by the department head or the Food Service Director and 1 claim not approved by the department head or Food Service Director and the Treasurer. The lack of internal controls was a systemic issue that occurred throughout the audit period. Criteria 2 CFR 200.303 states in part: "The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in 'Standards for Internal Control in the Federal Government' issued by the Comptroller General of the United States or the 'Internal Control Integrated Framework', issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). . . ." Cause A proper system of internal controls was not designed by management of the School Corporation, which would include segregation of key functions. Embedded within a properly designed and implemented internal control system should be internal controls consisting of policies and procedures. Policies reflect the School Corporation's management statements of what should be done to effect internal controls, and procedures should consist of actions that would implement these policies. Effect Without the proper design or implementation of the components of a system of internal controls, including policies and procedures that provide segregation of duties and additional oversight as needed, the internal control system cannot be capable of effectively preventing, or detecting and correcting, material noncompliance. Questioned Costs There were no questioned costs identified. Recommendation We recommended that management of the School Corporation design and implement a proper system of internal controls, including policies and procedures that would provide segregation of duties to ensure appropriate reviews, approvals, and oversight regarding vendor claims. Views of Responsible Officials For the views of responsible officials, refer to the Corrective Action Plan that is part of this report.
FINDING 2023-003 Subject: Child Nutrition Cluster - Internal Controls Federal Agency: Department of Agriculture Federal Programs: School Breakfast Program, National School Lunch Program, Summer Food Service Program for Children Assistance Listings Numbers: 10.553, 10.555, 10.559 Federal Award Numbers and Years (or Other Identifying Numbers): FY 21-22, FY 22-23, 7182022IN890342, 7182023IN890342 Pass-Through Entity: Indiana Department of Education Compliance Requirements: Activities Allowed or Unallowed, Allowable Costs/Cost Principles Audit Finding: Material Weakness Condition and Context The School Corporation did not have effective internal controls in place to ensure costs charged to the food service program were allowable and in conformance with the cost principles. The School Corporation designed and implemented a process to ensure that costs charged for vendor claims to the food service program were allowable and in conformance with the cost principles. The process was for vendor claims to be reviewed and approved by the department head or Food Service Director and the Treasurer. However, during our test of 40 vendor claims, there were 5 claims that were not approved by the department head or the Food Service Director and 1 claim not approved by the department head or Food Service Director and the Treasurer. The lack of internal controls was a systemic issue that occurred throughout the audit period. Criteria 2 CFR 200.303 states in part: "The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in 'Standards for Internal Control in the Federal Government' issued by the Comptroller General of the United States or the 'Internal Control Integrated Framework', issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). . . ." Cause A proper system of internal controls was not designed by management of the School Corporation, which would include segregation of key functions. Embedded within a properly designed and implemented internal control system should be internal controls consisting of policies and procedures. Policies reflect the School Corporation's management statements of what should be done to effect internal controls, and procedures should consist of actions that would implement these policies. Effect Without the proper design or implementation of the components of a system of internal controls, including policies and procedures that provide segregation of duties and additional oversight as needed, the internal control system cannot be capable of effectively preventing, or detecting and correcting, material noncompliance. Questioned Costs There were no questioned costs identified. Recommendation We recommended that management of the School Corporation design and implement a proper system of internal controls, including policies and procedures that would provide segregation of duties to ensure appropriate reviews, approvals, and oversight regarding vendor claims. Views of Responsible Officials For the views of responsible officials, refer to the Corrective Action Plan that is part of this report.
FINDING 2023-003 Subject: Child Nutrition Cluster - Internal Controls Federal Agency: Department of Agriculture Federal Programs: School Breakfast Program, National School Lunch Program, Summer Food Service Program for Children Assistance Listings Numbers: 10.553, 10.555, 10.559 Federal Award Numbers and Years (or Other Identifying Numbers): FY 21-22, FY 22-23, 7182022IN890342, 7182023IN890342 Pass-Through Entity: Indiana Department of Education Compliance Requirements: Activities Allowed or Unallowed, Allowable Costs/Cost Principles Audit Finding: Material Weakness Condition and Context The School Corporation did not have effective internal controls in place to ensure costs charged to the food service program were allowable and in conformance with the cost principles. The School Corporation designed and implemented a process to ensure that costs charged for vendor claims to the food service program were allowable and in conformance with the cost principles. The process was for vendor claims to be reviewed and approved by the department head or Food Service Director and the Treasurer. However, during our test of 40 vendor claims, there were 5 claims that were not approved by the department head or the Food Service Director and 1 claim not approved by the department head or Food Service Director and the Treasurer. The lack of internal controls was a systemic issue that occurred throughout the audit period. Criteria 2 CFR 200.303 states in part: "The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in 'Standards for Internal Control in the Federal Government' issued by the Comptroller General of the United States or the 'Internal Control Integrated Framework', issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). . . ." Cause A proper system of internal controls was not designed by management of the School Corporation, which would include segregation of key functions. Embedded within a properly designed and implemented internal control system should be internal controls consisting of policies and procedures. Policies reflect the School Corporation's management statements of what should be done to effect internal controls, and procedures should consist of actions that would implement these policies. Effect Without the proper design or implementation of the components of a system of internal controls, including policies and procedures that provide segregation of duties and additional oversight as needed, the internal control system cannot be capable of effectively preventing, or detecting and correcting, material noncompliance. Questioned Costs There were no questioned costs identified. Recommendation We recommended that management of the School Corporation design and implement a proper system of internal controls, including policies and procedures that would provide segregation of duties to ensure appropriate reviews, approvals, and oversight regarding vendor claims. Views of Responsible Officials For the views of responsible officials, refer to the Corrective Action Plan that is part of this report.
FINDING 2023-003 Subject: Child Nutrition Cluster - Internal Controls Federal Agency: Department of Agriculture Federal Programs: School Breakfast Program, National School Lunch Program, Summer Food Service Program for Children Assistance Listings Numbers: 10.553, 10.555, 10.559 Federal Award Numbers and Years (or Other Identifying Numbers): FY 21-22, FY 22-23, 7182022IN890342, 7182023IN890342 Pass-Through Entity: Indiana Department of Education Compliance Requirements: Activities Allowed or Unallowed, Allowable Costs/Cost Principles Audit Finding: Material Weakness Condition and Context The School Corporation did not have effective internal controls in place to ensure costs charged to the food service program were allowable and in conformance with the cost principles. The School Corporation designed and implemented a process to ensure that costs charged for vendor claims to the food service program were allowable and in conformance with the cost principles. The process was for vendor claims to be reviewed and approved by the department head or Food Service Director and the Treasurer. However, during our test of 40 vendor claims, there were 5 claims that were not approved by the department head or the Food Service Director and 1 claim not approved by the department head or Food Service Director and the Treasurer. The lack of internal controls was a systemic issue that occurred throughout the audit period. Criteria 2 CFR 200.303 states in part: "The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in 'Standards for Internal Control in the Federal Government' issued by the Comptroller General of the United States or the 'Internal Control Integrated Framework', issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). . . ." Cause A proper system of internal controls was not designed by management of the School Corporation, which would include segregation of key functions. Embedded within a properly designed and implemented internal control system should be internal controls consisting of policies and procedures. Policies reflect the School Corporation's management statements of what should be done to effect internal controls, and procedures should consist of actions that would implement these policies. Effect Without the proper design or implementation of the components of a system of internal controls, including policies and procedures that provide segregation of duties and additional oversight as needed, the internal control system cannot be capable of effectively preventing, or detecting and correcting, material noncompliance. Questioned Costs There were no questioned costs identified. Recommendation We recommended that management of the School Corporation design and implement a proper system of internal controls, including policies and procedures that would provide segregation of duties to ensure appropriate reviews, approvals, and oversight regarding vendor claims. Views of Responsible Officials For the views of responsible officials, refer to the Corrective Action Plan that is part of this report.
FINDING 2023-003 Subject: Child Nutrition Cluster - Internal Controls Federal Agency: Department of Agriculture Federal Programs: School Breakfast Program, National School Lunch Program, Summer Food Service Program for Children Assistance Listings Numbers: 10.553, 10.555, 10.559 Federal Award Numbers and Years (or Other Identifying Numbers): FY 21-22, FY 22-23, 7182022IN890342, 7182023IN890342 Pass-Through Entity: Indiana Department of Education Compliance Requirements: Activities Allowed or Unallowed, Allowable Costs/Cost Principles Audit Finding: Material Weakness Condition and Context The School Corporation did not have effective internal controls in place to ensure costs charged to the food service program were allowable and in conformance with the cost principles. The School Corporation designed and implemented a process to ensure that costs charged for vendor claims to the food service program were allowable and in conformance with the cost principles. The process was for vendor claims to be reviewed and approved by the department head or Food Service Director and the Treasurer. However, during our test of 40 vendor claims, there were 5 claims that were not approved by the department head or the Food Service Director and 1 claim not approved by the department head or Food Service Director and the Treasurer. The lack of internal controls was a systemic issue that occurred throughout the audit period. Criteria 2 CFR 200.303 states in part: "The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in 'Standards for Internal Control in the Federal Government' issued by the Comptroller General of the United States or the 'Internal Control Integrated Framework', issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). . . ." Cause A proper system of internal controls was not designed by management of the School Corporation, which would include segregation of key functions. Embedded within a properly designed and implemented internal control system should be internal controls consisting of policies and procedures. Policies reflect the School Corporation's management statements of what should be done to effect internal controls, and procedures should consist of actions that would implement these policies. Effect Without the proper design or implementation of the components of a system of internal controls, including policies and procedures that provide segregation of duties and additional oversight as needed, the internal control system cannot be capable of effectively preventing, or detecting and correcting, material noncompliance. Questioned Costs There were no questioned costs identified. Recommendation We recommended that management of the School Corporation design and implement a proper system of internal controls, including policies and procedures that would provide segregation of duties to ensure appropriate reviews, approvals, and oversight regarding vendor claims. Views of Responsible Officials For the views of responsible officials, refer to the Corrective Action Plan that is part of this report.
FINDING 2023-004 Subject: Child Nutrition Cluster - Procurement and Suspension and Debarment Federal Agency: Department of Agriculture Federal Programs: School Breakfast Program, National School Lunch Program, Summer Food Service Program for Children Assistance Listings Numbers: 10.553, 10.555, 10.559 Federal Award Numbers and Years (or Other Identifying Numbers): FY 21-22, FY 22-23, 7182022IN890342, 7182023IN890342 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Procurement and Suspension and Debarment Audit Findings: Material Weakness, Modified Opinion Condition and Context Procurement The School Corporation did not have effective internal controls in place to ensure costs charged for goods and services to the food service program were properly procured. The School Corporation designed and implemented a process to ensure that costs charged for goods and services to the food service program were properly procured. The process was for vendor claims to be reviewed and approved by the department head or Food Service Director and the Treasurer. However, during our test of 11 vendor claims that fell within the micropurchase threshold, there were 5 claims that were not approved by the department head or the Food Service Director. The lack of internal controls was isolated to 2022-2023. Suspension and Debarment The School Corporation had not properly designed or implemented a system of internal controls which would include segregation of duties, that would likely be effective in preventing, or detecting and correcting noncompliance. Prior to entering into subawards and covered transactions with federal award funds, recipients are required to verify that such contractors and subrecipients are not suspended, debarred, or otherwise excluded. "Covered transactions" include, but are not limited to, contracts for goods and services awarded under a nonprocurement transaction (i.e., grant agreement) that are expected to equal or exceed $25,000. The verification is to be done by checking the SAMs exclusions, collecting a certification from that vendor, or adding a clause or condition to the covered transaction with that vendor. Upon inquiry of the School Corporation in order to review the procedures in place for verifying that a vendor with which it plans to enter into a covered transaction is not suspended, debarred, or otherwise excluded, the School Corporation disclosed procedures had not been performed that ensured all vendors were not suspended or debarred prior to entering into covered transaction. There were five covered transactions that equaled or exceeded $25,000 that were identified, totaling $254,729. All five covered transactions were selected for testing. For two of the transactions, totaling $85,616, the School Corporation had not performed procedures that ensured vendors were not suspended or debarred, or otherwise excluded or disqualified from participating in federal assistance programs. The lack of internal controls and noncompliance were systemic issues throughout the audit period. Criteria 2 CFR 200.303 states in part: "The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in 'Standards for Internal Control in the Federal Government' issued by the Comptroller General of the United States or the 'Internal Control Integrated Framework', issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). . . ." 2 CFR 180.300 states: "When you enter into a covered transaction with another person at the next lower tier, you must verify that the person with whom you intend to do business is not excluded or disqualified. You do this by: (a) Checking the SAM Exclusions; or (b) Collecting a certification from that person; or (c) Adding a clause or condition to the covered transaction with that person." Cause A proper system of internal controls was not designed by management of the School Corporation. Embedded within a properly designed and implemented internal control system should be internal controls consisting of policies and procedures. Policies reflect the School Corporation's managements statements of what should be done to effect internal controls, and procedures should consist of actions that would implement these policies. Effect Without the proper implementation of an effectively designed system of internal controls, the internal control system cannot be capable of effectively preventing, or detecting and correcting, material noncompliance. As a result, vendors to whom payments equal to or in excess of $25,000 were not verified to be not suspended, debarred, or otherwise excluded. Noncompliance with the provisions of federal statutes, regulations, and the terms and conditions or the federal award could result in the loss of future federal funding to the School Corporation. Questioned Costs There were no questioned costs identified. Recommendation We recommended that management of the School Corporation establish a proper system of internal controls and develop policies and procedures to ensure that contractors are not suspended, debarred, or otherwise excluded prior to entering into any contracts or subawards. Views of Responsible Officials For the views of responsible officials, refer to the Corrective Action Plan that is part of this report.
FINDING 2023-004 Subject: Child Nutrition Cluster - Procurement and Suspension and Debarment Federal Agency: Department of Agriculture Federal Programs: School Breakfast Program, National School Lunch Program, Summer Food Service Program for Children Assistance Listings Numbers: 10.553, 10.555, 10.559 Federal Award Numbers and Years (or Other Identifying Numbers): FY 21-22, FY 22-23, 7182022IN890342, 7182023IN890342 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Procurement and Suspension and Debarment Audit Findings: Material Weakness, Modified Opinion Condition and Context Procurement The School Corporation did not have effective internal controls in place to ensure costs charged for goods and services to the food service program were properly procured. The School Corporation designed and implemented a process to ensure that costs charged for goods and services to the food service program were properly procured. The process was for vendor claims to be reviewed and approved by the department head or Food Service Director and the Treasurer. However, during our test of 11 vendor claims that fell within the micropurchase threshold, there were 5 claims that were not approved by the department head or the Food Service Director. The lack of internal controls was isolated to 2022-2023. Suspension and Debarment The School Corporation had not properly designed or implemented a system of internal controls which would include segregation of duties, that would likely be effective in preventing, or detecting and correcting noncompliance. Prior to entering into subawards and covered transactions with federal award funds, recipients are required to verify that such contractors and subrecipients are not suspended, debarred, or otherwise excluded. "Covered transactions" include, but are not limited to, contracts for goods and services awarded under a nonprocurement transaction (i.e., grant agreement) that are expected to equal or exceed $25,000. The verification is to be done by checking the SAMs exclusions, collecting a certification from that vendor, or adding a clause or condition to the covered transaction with that vendor. Upon inquiry of the School Corporation in order to review the procedures in place for verifying that a vendor with which it plans to enter into a covered transaction is not suspended, debarred, or otherwise excluded, the School Corporation disclosed procedures had not been performed that ensured all vendors were not suspended or debarred prior to entering into covered transaction. There were five covered transactions that equaled or exceeded $25,000 that were identified, totaling $254,729. All five covered transactions were selected for testing. For two of the transactions, totaling $85,616, the School Corporation had not performed procedures that ensured vendors were not suspended or debarred, or otherwise excluded or disqualified from participating in federal assistance programs. The lack of internal controls and noncompliance were systemic issues throughout the audit period. Criteria 2 CFR 200.303 states in part: "The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in 'Standards for Internal Control in the Federal Government' issued by the Comptroller General of the United States or the 'Internal Control Integrated Framework', issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). . . ." 2 CFR 180.300 states: "When you enter into a covered transaction with another person at the next lower tier, you must verify that the person with whom you intend to do business is not excluded or disqualified. You do this by: (a) Checking the SAM Exclusions; or (b) Collecting a certification from that person; or (c) Adding a clause or condition to the covered transaction with that person." Cause A proper system of internal controls was not designed by management of the School Corporation. Embedded within a properly designed and implemented internal control system should be internal controls consisting of policies and procedures. Policies reflect the School Corporation's managements statements of what should be done to effect internal controls, and procedures should consist of actions that would implement these policies. Effect Without the proper implementation of an effectively designed system of internal controls, the internal control system cannot be capable of effectively preventing, or detecting and correcting, material noncompliance. As a result, vendors to whom payments equal to or in excess of $25,000 were not verified to be not suspended, debarred, or otherwise excluded. Noncompliance with the provisions of federal statutes, regulations, and the terms and conditions or the federal award could result in the loss of future federal funding to the School Corporation. Questioned Costs There were no questioned costs identified. Recommendation We recommended that management of the School Corporation establish a proper system of internal controls and develop policies and procedures to ensure that contractors are not suspended, debarred, or otherwise excluded prior to entering into any contracts or subawards. Views of Responsible Officials For the views of responsible officials, refer to the Corrective Action Plan that is part of this report.
FINDING 2023-004 Subject: Child Nutrition Cluster - Procurement and Suspension and Debarment Federal Agency: Department of Agriculture Federal Programs: School Breakfast Program, National School Lunch Program, Summer Food Service Program for Children Assistance Listings Numbers: 10.553, 10.555, 10.559 Federal Award Numbers and Years (or Other Identifying Numbers): FY 21-22, FY 22-23, 7182022IN890342, 7182023IN890342 Pass-Through Entity: Indiana Department of Education Compliance Requirement: Procurement and Suspension and Debarment Audit Findings: Material Weakness, Modified Opinion Condition and Context Procurement The School Corporation did not have effective internal controls in place to ensure costs charged for goods and services to the food service program were properly procured. The School Corporation designed and implemented a process to ensure that costs charged for goods and services to the food service program were properly procured. The process was for vendor claims to be reviewed and approved by the department head or Food Service Director and the Treasurer. However, during our test of 11 vendor claims that fell within the micropurchase threshold, there were 5 claims that were not approved by the department head or the Food Service Director. The lack of internal controls was isolated to 2022-2023. Suspension and Debarment The School Corporation had not properly designed or implemented a system of internal controls which would include segregation of duties, that would likely be effective in preventing, or detecting and correcting noncompliance. Prior to entering into subawards and covered transactions with federal award funds, recipients are required to verify that such contractors and subrecipients are not suspended, debarred, or otherwise excluded. "Covered transactions" include, but are not limited to, contracts for goods and services awarded under a nonprocurement transaction (i.e., grant agreement) that are expected to equal or exceed $25,000. The verification is to be done by checking the SAMs exclusions, collecting a certification from that vendor, or adding a clause or condition to the covered transaction with that vendor. Upon inquiry of the School Corporation in order to review the procedures in place for verifying that a vendor with which it plans to enter into a covered transaction is not suspended, debarred, or otherwise excluded, the School Corporation disclosed procedures had not been performed that ensured all vendors were not suspended or debarred prior to entering into covered transaction. There were five covered transactions that equaled or exceeded $25,000 that were identified, totaling $254,729. All five covered transactions were selected for testing. For two of the transactions, totaling $85,616, the School Corporation had not performed procedures that ensured vendors were not suspended or debarred, or otherwise excluded or disqualified from participating in federal assistance programs. The lack of internal controls and noncompliance were systemic issues throughout the audit period. Criteria 2 CFR 200.303 states in part: "The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in 'Standards for Internal Control in the Federal Government' issued by the Comptroller General of the United States or the 'Internal Control Integrated Framework', issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). . . ." 2 CFR 180.300 states: "When you enter into a covered transaction with another person at the next lower tier, you must verify that the person with whom you intend to do business is not excluded or disqualified. You do this by: (a) Checking the SAM Exclusions; or (b) Collecting a certification from that person; or (c) Adding a clause or condition to the covered transaction with that person." Cause A proper system of internal controls was not designed by management of the School Corporation. Embedded within a properly designed and implemented internal control system should be internal controls consisting of policies and procedures. Policies reflect the School Corporation's managements statements of what should be done to effect internal controls, and procedures should consist of actions that would implement these policies. Effect Without the proper implementation of an effectively designed system of internal controls, the internal control system cannot be capable of effectively preventing, or detecting and correcting, material noncompliance. As a result, vendors to whom payments equal to or in excess of $25,000 were not verified to be not suspended, debarred, or otherwise excluded. Noncompliance with the provisions of federal statutes, regulations, and the terms and conditions or the federal award could result in the loss of future federal funding to the School Corporation. Questioned Costs There were no questioned costs identified. Recommendation We recommended that management of the School Corporation establish a proper system of internal controls and develop policies and procedures to ensure that contractors are not suspended, debarred, or otherwise excluded prior to entering into any contracts or subawards. Views of Responsible Officials For the views of responsible officials, refer to the Corrective Action Plan that is part of this report.