2023-007: Special Tests and Provisions: Outstanding Checks over 240 Days Federal agency: U.S. Department of Education Federal program title: Student Financial Assistance ALN Number: 84.007, 84.033, 84.063, 84.268, 84.379 Pass-Through Agency: N/A Pass-Through Number(s): N/A Award Period: July 1, 2022 through June 30, 2023 Type of Finding: • Significant Deficiency in Internal Control over Compliance • Other Matters Criteria or specific requirement: The Code of Federal Regulations, 34 CFR 668.164(h)(2) states that an institution that attempts to disburse funds by check and the check is not cashed, the institution must return the funds to the Secretary no later than 240 days after the date it issued that check. Per 2 CFR 200.303, nonfederal entities receiving federal awards are required to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations, and program compliance requirements. Condition: The University had 3 instances of Title IV refund checks to students that were outstanding longer than 240 days as of June 30, 2023 Questioned costs: None. Context: During the testing of the outstanding Title IV student check listing CLA observed three instances of stale checks that were aged greater than 240 days. Cause: Due to staff turnover, stale checks were not being monitored. Effect: Funds are not returned to the Department of Education in a timely manner Repeat finding: No. Recommendation: We recommend that the University review processes to track Title IV refund checks Views of responsible officials: There is no disagreement with the audit finding.
2023-007: Special Tests and Provisions: Outstanding Checks over 240 Days Federal agency: U.S. Department of Education Federal program title: Student Financial Assistance ALN Number: 84.007, 84.033, 84.063, 84.268, 84.379 Pass-Through Agency: N/A Pass-Through Number(s): N/A Award Period: July 1, 2022 through June 30, 2023 Type of Finding: • Significant Deficiency in Internal Control over Compliance • Other Matters Criteria or specific requirement: The Code of Federal Regulations, 34 CFR 668.164(h)(2) states that an institution that attempts to disburse funds by check and the check is not cashed, the institution must return the funds to the Secretary no later than 240 days after the date it issued that check. Per 2 CFR 200.303, nonfederal entities receiving federal awards are required to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations, and program compliance requirements. Condition: The University had 3 instances of Title IV refund checks to students that were outstanding longer than 240 days as of June 30, 2023 Questioned costs: None. Context: During the testing of the outstanding Title IV student check listing CLA observed three instances of stale checks that were aged greater than 240 days. Cause: Due to staff turnover, stale checks were not being monitored. Effect: Funds are not returned to the Department of Education in a timely manner Repeat finding: No. Recommendation: We recommend that the University review processes to track Title IV refund checks Views of responsible officials: There is no disagreement with the audit finding.
2023-007: Special Tests and Provisions: Outstanding Checks over 240 Days Federal agency: U.S. Department of Education Federal program title: Student Financial Assistance ALN Number: 84.007, 84.033, 84.063, 84.268, 84.379 Pass-Through Agency: N/A Pass-Through Number(s): N/A Award Period: July 1, 2022 through June 30, 2023 Type of Finding: • Significant Deficiency in Internal Control over Compliance • Other Matters Criteria or specific requirement: The Code of Federal Regulations, 34 CFR 668.164(h)(2) states that an institution that attempts to disburse funds by check and the check is not cashed, the institution must return the funds to the Secretary no later than 240 days after the date it issued that check. Per 2 CFR 200.303, nonfederal entities receiving federal awards are required to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations, and program compliance requirements. Condition: The University had 3 instances of Title IV refund checks to students that were outstanding longer than 240 days as of June 30, 2023 Questioned costs: None. Context: During the testing of the outstanding Title IV student check listing CLA observed three instances of stale checks that were aged greater than 240 days. Cause: Due to staff turnover, stale checks were not being monitored. Effect: Funds are not returned to the Department of Education in a timely manner Repeat finding: No. Recommendation: We recommend that the University review processes to track Title IV refund checks Views of responsible officials: There is no disagreement with the audit finding.
2023-007: Special Tests and Provisions: Outstanding Checks over 240 Days Federal agency: U.S. Department of Education Federal program title: Student Financial Assistance ALN Number: 84.007, 84.033, 84.063, 84.268, 84.379 Pass-Through Agency: N/A Pass-Through Number(s): N/A Award Period: July 1, 2022 through June 30, 2023 Type of Finding: • Significant Deficiency in Internal Control over Compliance • Other Matters Criteria or specific requirement: The Code of Federal Regulations, 34 CFR 668.164(h)(2) states that an institution that attempts to disburse funds by check and the check is not cashed, the institution must return the funds to the Secretary no later than 240 days after the date it issued that check. Per 2 CFR 200.303, nonfederal entities receiving federal awards are required to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations, and program compliance requirements. Condition: The University had 3 instances of Title IV refund checks to students that were outstanding longer than 240 days as of June 30, 2023 Questioned costs: None. Context: During the testing of the outstanding Title IV student check listing CLA observed three instances of stale checks that were aged greater than 240 days. Cause: Due to staff turnover, stale checks were not being monitored. Effect: Funds are not returned to the Department of Education in a timely manner Repeat finding: No. Recommendation: We recommend that the University review processes to track Title IV refund checks Views of responsible officials: There is no disagreement with the audit finding.
2023-008: Eligibility: Student Timesheets Federal agency: U.S. Department of Education Federal program title: Student Financial Assistance ALN Number: 84.007, 84.033, 84.063, 84.268, 84.379 Pass-Through Agency: N/A Pass-Through Number(s): N/A Award Period: July 1, 2022 through June 30, 2023 Type of Finding: • Significant Deficiency in Internal Control over Compliance • Other Matters Criteria or specific requirement: Per FSA Handbook, you must maintain adequate timesheets or records of hours worked for FWS students. These timesheets must show, separately for each day worked, the hours a student worked, and the total hours worked during the job’s payment cycle. These amounts and hours recorded must match the hours for which the student is paid. Per 2 CFR 200.303, nonfederal entities receiving federal awards are required to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations, and program compliance requirements. Condition: The University did not accurately pay Federal Work Study (FWS) funds based on hours reported on timesheet. Questioned costs: None. Context: During our testing of FWS, we identified one instance where a students hours reported did not match the hours the student was paid causing an overpayment. Cause: Due to human error, hours were not removed properly before submitted to payroll. Effect: If timesheets are not properly reported then inaccurate FWS funds could be disbursed. Repeat finding: No. Recommendation: We recommend the University review processes to complete and review timesheets for FWS students. Views of responsible officials: There is no disagreement with the audit finding.
2023-008: Eligibility: Student Timesheets Federal agency: U.S. Department of Education Federal program title: Student Financial Assistance ALN Number: 84.007, 84.033, 84.063, 84.268, 84.379 Pass-Through Agency: N/A Pass-Through Number(s): N/A Award Period: July 1, 2022 through June 30, 2023 Type of Finding: • Significant Deficiency in Internal Control over Compliance • Other Matters Criteria or specific requirement: Per FSA Handbook, you must maintain adequate timesheets or records of hours worked for FWS students. These timesheets must show, separately for each day worked, the hours a student worked, and the total hours worked during the job’s payment cycle. These amounts and hours recorded must match the hours for which the student is paid. Per 2 CFR 200.303, nonfederal entities receiving federal awards are required to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations, and program compliance requirements. Condition: The University did not accurately pay Federal Work Study (FWS) funds based on hours reported on timesheet. Questioned costs: None. Context: During our testing of FWS, we identified one instance where a students hours reported did not match the hours the student was paid causing an overpayment. Cause: Due to human error, hours were not removed properly before submitted to payroll. Effect: If timesheets are not properly reported then inaccurate FWS funds could be disbursed. Repeat finding: No. Recommendation: We recommend the University review processes to complete and review timesheets for FWS students. Views of responsible officials: There is no disagreement with the audit finding.
2023-008: Eligibility: Student Timesheets Federal agency: U.S. Department of Education Federal program title: Student Financial Assistance ALN Number: 84.007, 84.033, 84.063, 84.268, 84.379 Pass-Through Agency: N/A Pass-Through Number(s): N/A Award Period: July 1, 2022 through June 30, 2023 Type of Finding: • Significant Deficiency in Internal Control over Compliance • Other Matters Criteria or specific requirement: Per FSA Handbook, you must maintain adequate timesheets or records of hours worked for FWS students. These timesheets must show, separately for each day worked, the hours a student worked, and the total hours worked during the job’s payment cycle. These amounts and hours recorded must match the hours for which the student is paid. Per 2 CFR 200.303, nonfederal entities receiving federal awards are required to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations, and program compliance requirements. Condition: The University did not accurately pay Federal Work Study (FWS) funds based on hours reported on timesheet. Questioned costs: None. Context: During our testing of FWS, we identified one instance where a students hours reported did not match the hours the student was paid causing an overpayment. Cause: Due to human error, hours were not removed properly before submitted to payroll. Effect: If timesheets are not properly reported then inaccurate FWS funds could be disbursed. Repeat finding: No. Recommendation: We recommend the University review processes to complete and review timesheets for FWS students. Views of responsible officials: There is no disagreement with the audit finding.
2023-008: Eligibility: Student Timesheets Federal agency: U.S. Department of Education Federal program title: Student Financial Assistance ALN Number: 84.007, 84.033, 84.063, 84.268, 84.379 Pass-Through Agency: N/A Pass-Through Number(s): N/A Award Period: July 1, 2022 through June 30, 2023 Type of Finding: • Significant Deficiency in Internal Control over Compliance • Other Matters Criteria or specific requirement: Per FSA Handbook, you must maintain adequate timesheets or records of hours worked for FWS students. These timesheets must show, separately for each day worked, the hours a student worked, and the total hours worked during the job’s payment cycle. These amounts and hours recorded must match the hours for which the student is paid. Per 2 CFR 200.303, nonfederal entities receiving federal awards are required to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations, and program compliance requirements. Condition: The University did not accurately pay Federal Work Study (FWS) funds based on hours reported on timesheet. Questioned costs: None. Context: During our testing of FWS, we identified one instance where a students hours reported did not match the hours the student was paid causing an overpayment. Cause: Due to human error, hours were not removed properly before submitted to payroll. Effect: If timesheets are not properly reported then inaccurate FWS funds could be disbursed. Repeat finding: No. Recommendation: We recommend the University review processes to complete and review timesheets for FWS students. Views of responsible officials: There is no disagreement with the audit finding.
2023-008: Eligibility: Student Timesheets Federal agency: U.S. Department of Education Federal program title: Student Financial Assistance ALN Number: 84.007, 84.033, 84.063, 84.268, 84.379 Pass-Through Agency: N/A Pass-Through Number(s): N/A Award Period: July 1, 2022 through June 30, 2023 Type of Finding: • Significant Deficiency in Internal Control over Compliance • Other Matters Criteria or specific requirement: Per FSA Handbook, you must maintain adequate timesheets or records of hours worked for FWS students. These timesheets must show, separately for each day worked, the hours a student worked, and the total hours worked during the job’s payment cycle. These amounts and hours recorded must match the hours for which the student is paid. Per 2 CFR 200.303, nonfederal entities receiving federal awards are required to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations, and program compliance requirements. Condition: The University did not accurately pay Federal Work Study (FWS) funds based on hours reported on timesheet. Questioned costs: None. Context: During our testing of FWS, we identified one instance where a students hours reported did not match the hours the student was paid causing an overpayment. Cause: Due to human error, hours were not removed properly before submitted to payroll. Effect: If timesheets are not properly reported then inaccurate FWS funds could be disbursed. Repeat finding: No. Recommendation: We recommend the University review processes to complete and review timesheets for FWS students. Views of responsible officials: There is no disagreement with the audit finding.
2023-008: Eligibility: Student Timesheets Federal agency: U.S. Department of Education Federal program title: Student Financial Assistance ALN Number: 84.007, 84.033, 84.063, 84.268, 84.379 Pass-Through Agency: N/A Pass-Through Number(s): N/A Award Period: July 1, 2022 through June 30, 2023 Type of Finding: • Significant Deficiency in Internal Control over Compliance • Other Matters Criteria or specific requirement: Per FSA Handbook, you must maintain adequate timesheets or records of hours worked for FWS students. These timesheets must show, separately for each day worked, the hours a student worked, and the total hours worked during the job’s payment cycle. These amounts and hours recorded must match the hours for which the student is paid. Per 2 CFR 200.303, nonfederal entities receiving federal awards are required to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations, and program compliance requirements. Condition: The University did not accurately pay Federal Work Study (FWS) funds based on hours reported on timesheet. Questioned costs: None. Context: During our testing of FWS, we identified one instance where a students hours reported did not match the hours the student was paid causing an overpayment. Cause: Due to human error, hours were not removed properly before submitted to payroll. Effect: If timesheets are not properly reported then inaccurate FWS funds could be disbursed. Repeat finding: No. Recommendation: We recommend the University review processes to complete and review timesheets for FWS students. Views of responsible officials: There is no disagreement with the audit finding.
2023-009: Special Tests and Provisions: Enrollment Reporting Federal agency: U.S. Department of Education Federal program title: Student Financial Assistance ALN Number: 84.007, 84.033, 84.063, 84.268, 84.379 Pass-Through Agency: N/A Pass-Through Number(s): N/A Award Period: July 1, 2022 through June 30, 2023 Type of Finding: • Significant Deficiency in Internal Control over Compliance • Other Matters Criteria or specific requirement: The Code of Federal Regulations, 34 CFR 682.610, states that institutions must report accurately the enrollment status of all students regardless of if they receive aid from the institution or not. Changes to said status are required to be reported within 30 days of becoming aware of the status change, or with the next scheduled transmission of statuses if the scheduled transmission is within 60 days. Per Uniform Guidance 2 CFR 200.303, nonfederal entities receiving federal awards are required to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations, and program compliance requirements. Condition: The University did not properly report student enrollment changes for one student who received federal student aid to the National Student Loan Data System (NSLDS). Questioned costs: None. Context: During our testing of 28 students, we identified 1 student had the incorrect effective date and was reported past the 60-day reporting timeframe. Cause: The University did not have the appropriate resources and staffing in place to verify they were in compliance with all requirements. Effect: Student could have inaccurate loan status if their enrollment status is not changed timely. Repeat finding: No. Recommendation: We recommend the University review current processes for reporting to NSLDS and implement procedures to ensure submissions are reported timely and accurately. Views of responsible officials: There is no disagreement with the audit finding.
2023-009: Special Tests and Provisions: Enrollment Reporting Federal agency: U.S. Department of Education Federal program title: Student Financial Assistance ALN Number: 84.007, 84.033, 84.063, 84.268, 84.379 Pass-Through Agency: N/A Pass-Through Number(s): N/A Award Period: July 1, 2022 through June 30, 2023 Type of Finding: • Significant Deficiency in Internal Control over Compliance • Other Matters Criteria or specific requirement: The Code of Federal Regulations, 34 CFR 682.610, states that institutions must report accurately the enrollment status of all students regardless of if they receive aid from the institution or not. Changes to said status are required to be reported within 30 days of becoming aware of the status change, or with the next scheduled transmission of statuses if the scheduled transmission is within 60 days. Per Uniform Guidance 2 CFR 200.303, nonfederal entities receiving federal awards are required to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations, and program compliance requirements. Condition: The University did not properly report student enrollment changes for one student who received federal student aid to the National Student Loan Data System (NSLDS). Questioned costs: None. Context: During our testing of 28 students, we identified 1 student had the incorrect effective date and was reported past the 60-day reporting timeframe. Cause: The University did not have the appropriate resources and staffing in place to verify they were in compliance with all requirements. Effect: Student could have inaccurate loan status if their enrollment status is not changed timely. Repeat finding: No. Recommendation: We recommend the University review current processes for reporting to NSLDS and implement procedures to ensure submissions are reported timely and accurately. Views of responsible officials: There is no disagreement with the audit finding.
2023-009: Special Tests and Provisions: Enrollment Reporting Federal agency: U.S. Department of Education Federal program title: Student Financial Assistance ALN Number: 84.007, 84.033, 84.063, 84.268, 84.379 Pass-Through Agency: N/A Pass-Through Number(s): N/A Award Period: July 1, 2022 through June 30, 2023 Type of Finding: • Significant Deficiency in Internal Control over Compliance • Other Matters Criteria or specific requirement: The Code of Federal Regulations, 34 CFR 682.610, states that institutions must report accurately the enrollment status of all students regardless of if they receive aid from the institution or not. Changes to said status are required to be reported within 30 days of becoming aware of the status change, or with the next scheduled transmission of statuses if the scheduled transmission is within 60 days. Per Uniform Guidance 2 CFR 200.303, nonfederal entities receiving federal awards are required to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations, and program compliance requirements. Condition: The University did not properly report student enrollment changes for one student who received federal student aid to the National Student Loan Data System (NSLDS). Questioned costs: None. Context: During our testing of 28 students, we identified 1 student had the incorrect effective date and was reported past the 60-day reporting timeframe. Cause: The University did not have the appropriate resources and staffing in place to verify they were in compliance with all requirements. Effect: Student could have inaccurate loan status if their enrollment status is not changed timely. Repeat finding: No. Recommendation: We recommend the University review current processes for reporting to NSLDS and implement procedures to ensure submissions are reported timely and accurately. Views of responsible officials: There is no disagreement with the audit finding.
2023-009: Special Tests and Provisions: Enrollment Reporting Federal agency: U.S. Department of Education Federal program title: Student Financial Assistance ALN Number: 84.007, 84.033, 84.063, 84.268, 84.379 Pass-Through Agency: N/A Pass-Through Number(s): N/A Award Period: July 1, 2022 through June 30, 2023 Type of Finding: • Significant Deficiency in Internal Control over Compliance • Other Matters Criteria or specific requirement: The Code of Federal Regulations, 34 CFR 682.610, states that institutions must report accurately the enrollment status of all students regardless of if they receive aid from the institution or not. Changes to said status are required to be reported within 30 days of becoming aware of the status change, or with the next scheduled transmission of statuses if the scheduled transmission is within 60 days. Per Uniform Guidance 2 CFR 200.303, nonfederal entities receiving federal awards are required to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations, and program compliance requirements. Condition: The University did not properly report student enrollment changes for one student who received federal student aid to the National Student Loan Data System (NSLDS). Questioned costs: None. Context: During our testing of 28 students, we identified 1 student had the incorrect effective date and was reported past the 60-day reporting timeframe. Cause: The University did not have the appropriate resources and staffing in place to verify they were in compliance with all requirements. Effect: Student could have inaccurate loan status if their enrollment status is not changed timely. Repeat finding: No. Recommendation: We recommend the University review current processes for reporting to NSLDS and implement procedures to ensure submissions are reported timely and accurately. Views of responsible officials: There is no disagreement with the audit finding.
2023-009: Special Tests and Provisions: Enrollment Reporting Federal agency: U.S. Department of Education Federal program title: Student Financial Assistance ALN Number: 84.007, 84.033, 84.063, 84.268, 84.379 Pass-Through Agency: N/A Pass-Through Number(s): N/A Award Period: July 1, 2022 through June 30, 2023 Type of Finding: • Significant Deficiency in Internal Control over Compliance • Other Matters Criteria or specific requirement: The Code of Federal Regulations, 34 CFR 682.610, states that institutions must report accurately the enrollment status of all students regardless of if they receive aid from the institution or not. Changes to said status are required to be reported within 30 days of becoming aware of the status change, or with the next scheduled transmission of statuses if the scheduled transmission is within 60 days. Per Uniform Guidance 2 CFR 200.303, nonfederal entities receiving federal awards are required to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations, and program compliance requirements. Condition: The University did not properly report student enrollment changes for one student who received federal student aid to the National Student Loan Data System (NSLDS). Questioned costs: None. Context: During our testing of 28 students, we identified 1 student had the incorrect effective date and was reported past the 60-day reporting timeframe. Cause: The University did not have the appropriate resources and staffing in place to verify they were in compliance with all requirements. Effect: Student could have inaccurate loan status if their enrollment status is not changed timely. Repeat finding: No. Recommendation: We recommend the University review current processes for reporting to NSLDS and implement procedures to ensure submissions are reported timely and accurately. Views of responsible officials: There is no disagreement with the audit finding.
2023-009: Special Tests and Provisions: Enrollment Reporting Federal agency: U.S. Department of Education Federal program title: Student Financial Assistance ALN Number: 84.007, 84.033, 84.063, 84.268, 84.379 Pass-Through Agency: N/A Pass-Through Number(s): N/A Award Period: July 1, 2022 through June 30, 2023 Type of Finding: • Significant Deficiency in Internal Control over Compliance • Other Matters Criteria or specific requirement: The Code of Federal Regulations, 34 CFR 682.610, states that institutions must report accurately the enrollment status of all students regardless of if they receive aid from the institution or not. Changes to said status are required to be reported within 30 days of becoming aware of the status change, or with the next scheduled transmission of statuses if the scheduled transmission is within 60 days. Per Uniform Guidance 2 CFR 200.303, nonfederal entities receiving federal awards are required to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations, and program compliance requirements. Condition: The University did not properly report student enrollment changes for one student who received federal student aid to the National Student Loan Data System (NSLDS). Questioned costs: None. Context: During our testing of 28 students, we identified 1 student had the incorrect effective date and was reported past the 60-day reporting timeframe. Cause: The University did not have the appropriate resources and staffing in place to verify they were in compliance with all requirements. Effect: Student could have inaccurate loan status if their enrollment status is not changed timely. Repeat finding: No. Recommendation: We recommend the University review current processes for reporting to NSLDS and implement procedures to ensure submissions are reported timely and accurately. Views of responsible officials: There is no disagreement with the audit finding.
2023-010: Special Tests and Provisions: Return of Title IV Funds Federal agency: U.S. Department of Education Federal program title: Student Financial Assistance ALN Number: 84.007, 84.033, 84.063, 84.268, 84.379 Pass-Through Agency: N/A Pass-Through Number(s): N/A Award Period: July 1, 2022 through June 30, 2023 Type of Finding: • Significant Deficiency in Internal Control over Compliance • Other Matters Criteria or specific requirement: The Code of Federal Regulations, 34 CFR 668.22(j)(1), states that an institution must return the amount of title IV funds for which it is responsible as soon as possible but no later than 45 days after the date of the institution's determination that the student withdrew. Per Uniform Guidance 2 CFR 200.303, nonfederal entities receiving federal awards are required to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations, and program compliance requirements. Condition: The University did not properly evaluate unofficial withdrawals for the 2022-2023 aid year, correctly calculate returns or disburse return timely for Return to Title IV (R2T4) calculations. Additionally, the University did not have formal documentation of review for R2T4 calculations. Questioned costs: $46,735 Context: During our testing of 8 R2T4s, we identified 1 instance of payment returned later than 45 days after the withdrawal was determined and 2 instances of award amounts being used instead of the net disbursed amount. Also during our testing we identified that unofficial withdrawals were not evaluated for the 2022-2023 aid year which resulted in 27 calculations to not be performed. Additionally, there was no documentation of review for R2T4 calculations. Cause: Due to staff turnover, R2T4 calculations were not completed correctly or timely. Effect: The University could return incorrect amounts based off of their calculations and incorrect calculations could affect student repayment amounts based off of amount earned. Repeat finding: No. Recommendation: We recommend the University review current processes for determining unofficial withdrawals and ensure calculations are performed correctly and returns disbursed timely. We also recommend the University document review of Return of Title IV calculations by an employee that did not prepare the calculations. Views of responsible officials: There is no disagreement with the audit finding.
2023-010: Special Tests and Provisions: Return of Title IV Funds Federal agency: U.S. Department of Education Federal program title: Student Financial Assistance ALN Number: 84.007, 84.033, 84.063, 84.268, 84.379 Pass-Through Agency: N/A Pass-Through Number(s): N/A Award Period: July 1, 2022 through June 30, 2023 Type of Finding: • Significant Deficiency in Internal Control over Compliance • Other Matters Criteria or specific requirement: The Code of Federal Regulations, 34 CFR 668.22(j)(1), states that an institution must return the amount of title IV funds for which it is responsible as soon as possible but no later than 45 days after the date of the institution's determination that the student withdrew. Per Uniform Guidance 2 CFR 200.303, nonfederal entities receiving federal awards are required to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations, and program compliance requirements. Condition: The University did not properly evaluate unofficial withdrawals for the 2022-2023 aid year, correctly calculate returns or disburse return timely for Return to Title IV (R2T4) calculations. Additionally, the University did not have formal documentation of review for R2T4 calculations. Questioned costs: $46,735 Context: During our testing of 8 R2T4s, we identified 1 instance of payment returned later than 45 days after the withdrawal was determined and 2 instances of award amounts being used instead of the net disbursed amount. Also during our testing we identified that unofficial withdrawals were not evaluated for the 2022-2023 aid year which resulted in 27 calculations to not be performed. Additionally, there was no documentation of review for R2T4 calculations. Cause: Due to staff turnover, R2T4 calculations were not completed correctly or timely. Effect: The University could return incorrect amounts based off of their calculations and incorrect calculations could affect student repayment amounts based off of amount earned. Repeat finding: No. Recommendation: We recommend the University review current processes for determining unofficial withdrawals and ensure calculations are performed correctly and returns disbursed timely. We also recommend the University document review of Return of Title IV calculations by an employee that did not prepare the calculations. Views of responsible officials: There is no disagreement with the audit finding.
2023-010: Special Tests and Provisions: Return of Title IV Funds Federal agency: U.S. Department of Education Federal program title: Student Financial Assistance ALN Number: 84.007, 84.033, 84.063, 84.268, 84.379 Pass-Through Agency: N/A Pass-Through Number(s): N/A Award Period: July 1, 2022 through June 30, 2023 Type of Finding: • Significant Deficiency in Internal Control over Compliance • Other Matters Criteria or specific requirement: The Code of Federal Regulations, 34 CFR 668.22(j)(1), states that an institution must return the amount of title IV funds for which it is responsible as soon as possible but no later than 45 days after the date of the institution's determination that the student withdrew. Per Uniform Guidance 2 CFR 200.303, nonfederal entities receiving federal awards are required to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations, and program compliance requirements. Condition: The University did not properly evaluate unofficial withdrawals for the 2022-2023 aid year, correctly calculate returns or disburse return timely for Return to Title IV (R2T4) calculations. Additionally, the University did not have formal documentation of review for R2T4 calculations. Questioned costs: $46,735 Context: During our testing of 8 R2T4s, we identified 1 instance of payment returned later than 45 days after the withdrawal was determined and 2 instances of award amounts being used instead of the net disbursed amount. Also during our testing we identified that unofficial withdrawals were not evaluated for the 2022-2023 aid year which resulted in 27 calculations to not be performed. Additionally, there was no documentation of review for R2T4 calculations. Cause: Due to staff turnover, R2T4 calculations were not completed correctly or timely. Effect: The University could return incorrect amounts based off of their calculations and incorrect calculations could affect student repayment amounts based off of amount earned. Repeat finding: No. Recommendation: We recommend the University review current processes for determining unofficial withdrawals and ensure calculations are performed correctly and returns disbursed timely. We also recommend the University document review of Return of Title IV calculations by an employee that did not prepare the calculations. Views of responsible officials: There is no disagreement with the audit finding.
2023-010: Special Tests and Provisions: Return of Title IV Funds Federal agency: U.S. Department of Education Federal program title: Student Financial Assistance ALN Number: 84.007, 84.033, 84.063, 84.268, 84.379 Pass-Through Agency: N/A Pass-Through Number(s): N/A Award Period: July 1, 2022 through June 30, 2023 Type of Finding: • Significant Deficiency in Internal Control over Compliance • Other Matters Criteria or specific requirement: The Code of Federal Regulations, 34 CFR 668.22(j)(1), states that an institution must return the amount of title IV funds for which it is responsible as soon as possible but no later than 45 days after the date of the institution's determination that the student withdrew. Per Uniform Guidance 2 CFR 200.303, nonfederal entities receiving federal awards are required to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations, and program compliance requirements. Condition: The University did not properly evaluate unofficial withdrawals for the 2022-2023 aid year, correctly calculate returns or disburse return timely for Return to Title IV (R2T4) calculations. Additionally, the University did not have formal documentation of review for R2T4 calculations. Questioned costs: $46,735 Context: During our testing of 8 R2T4s, we identified 1 instance of payment returned later than 45 days after the withdrawal was determined and 2 instances of award amounts being used instead of the net disbursed amount. Also during our testing we identified that unofficial withdrawals were not evaluated for the 2022-2023 aid year which resulted in 27 calculations to not be performed. Additionally, there was no documentation of review for R2T4 calculations. Cause: Due to staff turnover, R2T4 calculations were not completed correctly or timely. Effect: The University could return incorrect amounts based off of their calculations and incorrect calculations could affect student repayment amounts based off of amount earned. Repeat finding: No. Recommendation: We recommend the University review current processes for determining unofficial withdrawals and ensure calculations are performed correctly and returns disbursed timely. We also recommend the University document review of Return of Title IV calculations by an employee that did not prepare the calculations. Views of responsible officials: There is no disagreement with the audit finding.
2023-010: Special Tests and Provisions: Return of Title IV Funds Federal agency: U.S. Department of Education Federal program title: Student Financial Assistance ALN Number: 84.007, 84.033, 84.063, 84.268, 84.379 Pass-Through Agency: N/A Pass-Through Number(s): N/A Award Period: July 1, 2022 through June 30, 2023 Type of Finding: • Significant Deficiency in Internal Control over Compliance • Other Matters Criteria or specific requirement: The Code of Federal Regulations, 34 CFR 668.22(j)(1), states that an institution must return the amount of title IV funds for which it is responsible as soon as possible but no later than 45 days after the date of the institution's determination that the student withdrew. Per Uniform Guidance 2 CFR 200.303, nonfederal entities receiving federal awards are required to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations, and program compliance requirements. Condition: The University did not properly evaluate unofficial withdrawals for the 2022-2023 aid year, correctly calculate returns or disburse return timely for Return to Title IV (R2T4) calculations. Additionally, the University did not have formal documentation of review for R2T4 calculations. Questioned costs: $46,735 Context: During our testing of 8 R2T4s, we identified 1 instance of payment returned later than 45 days after the withdrawal was determined and 2 instances of award amounts being used instead of the net disbursed amount. Also during our testing we identified that unofficial withdrawals were not evaluated for the 2022-2023 aid year which resulted in 27 calculations to not be performed. Additionally, there was no documentation of review for R2T4 calculations. Cause: Due to staff turnover, R2T4 calculations were not completed correctly or timely. Effect: The University could return incorrect amounts based off of their calculations and incorrect calculations could affect student repayment amounts based off of amount earned. Repeat finding: No. Recommendation: We recommend the University review current processes for determining unofficial withdrawals and ensure calculations are performed correctly and returns disbursed timely. We also recommend the University document review of Return of Title IV calculations by an employee that did not prepare the calculations. Views of responsible officials: There is no disagreement with the audit finding.
2023-010: Special Tests and Provisions: Return of Title IV Funds Federal agency: U.S. Department of Education Federal program title: Student Financial Assistance ALN Number: 84.007, 84.033, 84.063, 84.268, 84.379 Pass-Through Agency: N/A Pass-Through Number(s): N/A Award Period: July 1, 2022 through June 30, 2023 Type of Finding: • Significant Deficiency in Internal Control over Compliance • Other Matters Criteria or specific requirement: The Code of Federal Regulations, 34 CFR 668.22(j)(1), states that an institution must return the amount of title IV funds for which it is responsible as soon as possible but no later than 45 days after the date of the institution's determination that the student withdrew. Per Uniform Guidance 2 CFR 200.303, nonfederal entities receiving federal awards are required to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations, and program compliance requirements. Condition: The University did not properly evaluate unofficial withdrawals for the 2022-2023 aid year, correctly calculate returns or disburse return timely for Return to Title IV (R2T4) calculations. Additionally, the University did not have formal documentation of review for R2T4 calculations. Questioned costs: $46,735 Context: During our testing of 8 R2T4s, we identified 1 instance of payment returned later than 45 days after the withdrawal was determined and 2 instances of award amounts being used instead of the net disbursed amount. Also during our testing we identified that unofficial withdrawals were not evaluated for the 2022-2023 aid year which resulted in 27 calculations to not be performed. Additionally, there was no documentation of review for R2T4 calculations. Cause: Due to staff turnover, R2T4 calculations were not completed correctly or timely. Effect: The University could return incorrect amounts based off of their calculations and incorrect calculations could affect student repayment amounts based off of amount earned. Repeat finding: No. Recommendation: We recommend the University review current processes for determining unofficial withdrawals and ensure calculations are performed correctly and returns disbursed timely. We also recommend the University document review of Return of Title IV calculations by an employee that did not prepare the calculations. Views of responsible officials: There is no disagreement with the audit finding.
2023-011: Special Tests and Provisions: Third Party Servicers Federal agency: U.S. Department of Education Federal program title: Student Financial Assistance ALN Number: 84.007, 84.033, 84.063, 84.268, 84.379 Pass-Through Agency: N/A Pass-Through Number(s): N/A Award Period: July 1, 2022 through June 30, 2023 Type of Finding: • Significant Deficiency in Internal Control over Compliance • Other Matters Criteria or specific requirement: Per FSA handbook, when a school uses a third party servicer under a Tier One Agreement with processing direct payments of Title IV funds on behalf of the school, then a school must conduct reasonable due diligence reviews every two years to ascertain whether the fees imposed under the T1 arrangement are, considered as a whole, consistent with or below prevailing market rates. Per Uniform Guidance 2 CFR 200.303, nonfederal entities receiving federal awards are required to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations, and program compliance requirements. Condition: The University did not meet the minimum requirements when in a Tier One Agreement with a third party servicer to perform one or more of the functions associated with processing direct payments of Title IV funds on behalf of the University. Questioned costs: None. Context: During our testing of the third party agreement with Bank Mobile, we identified that the University did not conduct a due diligence review in the 2 year required timeframe. Cause: Due to staff turnover, compliance requirements were not timely monitored. Effect: The University was not in compliance with the using a servicer to deliver Title IV credit balances standards. Repeat finding: No. Recommendation: We recommend the University review current processes to ensure all compliance requirements are being met when using a third party servicer to deliver Title IV credit balances. Views of responsible officials: There is no disagreement with the audit finding.
2023-011: Special Tests and Provisions: Third Party Servicers Federal agency: U.S. Department of Education Federal program title: Student Financial Assistance ALN Number: 84.007, 84.033, 84.063, 84.268, 84.379 Pass-Through Agency: N/A Pass-Through Number(s): N/A Award Period: July 1, 2022 through June 30, 2023 Type of Finding: • Significant Deficiency in Internal Control over Compliance • Other Matters Criteria or specific requirement: Per FSA handbook, when a school uses a third party servicer under a Tier One Agreement with processing direct payments of Title IV funds on behalf of the school, then a school must conduct reasonable due diligence reviews every two years to ascertain whether the fees imposed under the T1 arrangement are, considered as a whole, consistent with or below prevailing market rates. Per Uniform Guidance 2 CFR 200.303, nonfederal entities receiving federal awards are required to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations, and program compliance requirements. Condition: The University did not meet the minimum requirements when in a Tier One Agreement with a third party servicer to perform one or more of the functions associated with processing direct payments of Title IV funds on behalf of the University. Questioned costs: None. Context: During our testing of the third party agreement with Bank Mobile, we identified that the University did not conduct a due diligence review in the 2 year required timeframe. Cause: Due to staff turnover, compliance requirements were not timely monitored. Effect: The University was not in compliance with the using a servicer to deliver Title IV credit balances standards. Repeat finding: No. Recommendation: We recommend the University review current processes to ensure all compliance requirements are being met when using a third party servicer to deliver Title IV credit balances. Views of responsible officials: There is no disagreement with the audit finding.
2023-011: Special Tests and Provisions: Third Party Servicers Federal agency: U.S. Department of Education Federal program title: Student Financial Assistance ALN Number: 84.007, 84.033, 84.063, 84.268, 84.379 Pass-Through Agency: N/A Pass-Through Number(s): N/A Award Period: July 1, 2022 through June 30, 2023 Type of Finding: • Significant Deficiency in Internal Control over Compliance • Other Matters Criteria or specific requirement: Per FSA handbook, when a school uses a third party servicer under a Tier One Agreement with processing direct payments of Title IV funds on behalf of the school, then a school must conduct reasonable due diligence reviews every two years to ascertain whether the fees imposed under the T1 arrangement are, considered as a whole, consistent with or below prevailing market rates. Per Uniform Guidance 2 CFR 200.303, nonfederal entities receiving federal awards are required to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations, and program compliance requirements. Condition: The University did not meet the minimum requirements when in a Tier One Agreement with a third party servicer to perform one or more of the functions associated with processing direct payments of Title IV funds on behalf of the University. Questioned costs: None. Context: During our testing of the third party agreement with Bank Mobile, we identified that the University did not conduct a due diligence review in the 2 year required timeframe. Cause: Due to staff turnover, compliance requirements were not timely monitored. Effect: The University was not in compliance with the using a servicer to deliver Title IV credit balances standards. Repeat finding: No. Recommendation: We recommend the University review current processes to ensure all compliance requirements are being met when using a third party servicer to deliver Title IV credit balances. Views of responsible officials: There is no disagreement with the audit finding.
2023-011: Special Tests and Provisions: Third Party Servicers Federal agency: U.S. Department of Education Federal program title: Student Financial Assistance ALN Number: 84.007, 84.033, 84.063, 84.268, 84.379 Pass-Through Agency: N/A Pass-Through Number(s): N/A Award Period: July 1, 2022 through June 30, 2023 Type of Finding: • Significant Deficiency in Internal Control over Compliance • Other Matters Criteria or specific requirement: Per FSA handbook, when a school uses a third party servicer under a Tier One Agreement with processing direct payments of Title IV funds on behalf of the school, then a school must conduct reasonable due diligence reviews every two years to ascertain whether the fees imposed under the T1 arrangement are, considered as a whole, consistent with or below prevailing market rates. Per Uniform Guidance 2 CFR 200.303, nonfederal entities receiving federal awards are required to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations, and program compliance requirements. Condition: The University did not meet the minimum requirements when in a Tier One Agreement with a third party servicer to perform one or more of the functions associated with processing direct payments of Title IV funds on behalf of the University. Questioned costs: None. Context: During our testing of the third party agreement with Bank Mobile, we identified that the University did not conduct a due diligence review in the 2 year required timeframe. Cause: Due to staff turnover, compliance requirements were not timely monitored. Effect: The University was not in compliance with the using a servicer to deliver Title IV credit balances standards. Repeat finding: No. Recommendation: We recommend the University review current processes to ensure all compliance requirements are being met when using a third party servicer to deliver Title IV credit balances. Views of responsible officials: There is no disagreement with the audit finding.
2023-011: Special Tests and Provisions: Third Party Servicers Federal agency: U.S. Department of Education Federal program title: Student Financial Assistance ALN Number: 84.007, 84.033, 84.063, 84.268, 84.379 Pass-Through Agency: N/A Pass-Through Number(s): N/A Award Period: July 1, 2022 through June 30, 2023 Type of Finding: • Significant Deficiency in Internal Control over Compliance • Other Matters Criteria or specific requirement: Per FSA handbook, when a school uses a third party servicer under a Tier One Agreement with processing direct payments of Title IV funds on behalf of the school, then a school must conduct reasonable due diligence reviews every two years to ascertain whether the fees imposed under the T1 arrangement are, considered as a whole, consistent with or below prevailing market rates. Per Uniform Guidance 2 CFR 200.303, nonfederal entities receiving federal awards are required to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations, and program compliance requirements. Condition: The University did not meet the minimum requirements when in a Tier One Agreement with a third party servicer to perform one or more of the functions associated with processing direct payments of Title IV funds on behalf of the University. Questioned costs: None. Context: During our testing of the third party agreement with Bank Mobile, we identified that the University did not conduct a due diligence review in the 2 year required timeframe. Cause: Due to staff turnover, compliance requirements were not timely monitored. Effect: The University was not in compliance with the using a servicer to deliver Title IV credit balances standards. Repeat finding: No. Recommendation: We recommend the University review current processes to ensure all compliance requirements are being met when using a third party servicer to deliver Title IV credit balances. Views of responsible officials: There is no disagreement with the audit finding.
2023-011: Special Tests and Provisions: Third Party Servicers Federal agency: U.S. Department of Education Federal program title: Student Financial Assistance ALN Number: 84.007, 84.033, 84.063, 84.268, 84.379 Pass-Through Agency: N/A Pass-Through Number(s): N/A Award Period: July 1, 2022 through June 30, 2023 Type of Finding: • Significant Deficiency in Internal Control over Compliance • Other Matters Criteria or specific requirement: Per FSA handbook, when a school uses a third party servicer under a Tier One Agreement with processing direct payments of Title IV funds on behalf of the school, then a school must conduct reasonable due diligence reviews every two years to ascertain whether the fees imposed under the T1 arrangement are, considered as a whole, consistent with or below prevailing market rates. Per Uniform Guidance 2 CFR 200.303, nonfederal entities receiving federal awards are required to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations, and program compliance requirements. Condition: The University did not meet the minimum requirements when in a Tier One Agreement with a third party servicer to perform one or more of the functions associated with processing direct payments of Title IV funds on behalf of the University. Questioned costs: None. Context: During our testing of the third party agreement with Bank Mobile, we identified that the University did not conduct a due diligence review in the 2 year required timeframe. Cause: Due to staff turnover, compliance requirements were not timely monitored. Effect: The University was not in compliance with the using a servicer to deliver Title IV credit balances standards. Repeat finding: No. Recommendation: We recommend the University review current processes to ensure all compliance requirements are being met when using a third party servicer to deliver Title IV credit balances. Views of responsible officials: There is no disagreement with the audit finding.
Finding No. 2023-001 Gramm-Leach-Bliley Act–Student Information Security Federal Program ALN 84.007 Federal Supplemental Educational Opportunity Grant Program ALN 84.033 Federal Work-Study Program ALN 84.063 Federal Pell Grant Program ALN 84.268 Federal Direct Student Loan Program Name of Federal Agency U.S. Department of Education Pass-through Entity N/A Type of Finding Compliance Internal of Control Category Significant deficiency Compliance Requirement N. Special Tests and Provisions Criteria Under an institution’s Program Participation Agreement with the Department of Education and the Gramm-Leach-Bliley Act, schools must protect student financial aid information, with particular attention to information provided to institutions by the Department or otherwise obtained in support of the administration of the federal student financial aid programs.The Gramm-Leach-Bliley Act (GLBA) (Pub. L. No. 106-102) requires financial institutions to explain their information-sharing practices to their customers and to safeguard sensitive data (16 CFR 314). The Federal Trade Commission considers Title IV-eligible institutions that participate in Title IV Educational Assistance Programs as “financial institutions” and subject to the Gramm-Leach-Bliley Act (16 CFR 313.3(k)(2)(vi)). The Standards for Safeguarding Customer Information, required by the GLBA (16 CFR §314.4) requires the University to: a) Designates a qualified individual responsible for overseeing and implementing the institution’s information security program and enforcing the information security program in compliance (16 CFR 314.4(a)). b) Provides for the information security program to be based on a risk assessment that identifies reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of customer information (as the term customer information applies to the institution) that could result in the unauthorized disclosure, misuse, alteration, destruction, or other compromise of such information, and assesses the sufficiency of any safeguards in place to control these risks (16 CFR 314.4(b)). c) Provides for the design and implementation of safeguards to control the risks the institution identifies through its risk assessment (16 CFR 314.4(c)). At a minimum, the institution’s written information security program must address the implementation of the minimum safeguards identified in 16 CFR 314.4(c)(1) through (8). The eight minimum safeguards that the written information security program must address are summarized as follows: 1. Implement and periodically review access controls. 2. Conduct a periodic inventory of data, noting where it’s collected, stored, or transmitted. 3. Encrypt customer information on the institution’s system and when it’s in transit. 4. Assess apps developed by the institution. 5. Implement multi-factor authentication for anyone accessing customer information on the institution’s system. 6. Dispose of customer information securely. 7. Anticipate and evaluate changes to the information system or network. 8. Maintain a log of authorized users’ activity and keep an eye out for unauthorized access. d) Provides for the institution to regularly test or otherwise monitor the effectiveness of the safeguards it has implemented (16 CFR 314.4(d)).Criteria – (continued) e) Provides for the implementation of policies and procedures to ensure that personnel are able to enact the information security program (16 CFR 314.4(e)(1)). f) Addresses how the institution will oversee its information system service providers (16 CFR 314.4(f)). g) Provides for the evaluation and adjustment of its information security program in light of the results of the required testing and monitoring; any material changes to its operations or business arrangements; the results of the required risk assessments; or any other circumstances that it knows or has reason to know may have a material impact the institution’s information security program (16 CFR 314.4(g)). Additionally, the Uniform Guidance (2 CFR 200.303(a)) requires nonfederal entities receiving federal awards to establish and maintain effective internal controls designed to reasonably ensure compliance with Federal laws, statutes, regulations, and the terms and conditions of the Federal award. Furthermore, generally accepted information technology guidance endorses the implementation of a process to identify risk and ensure appropriate safeguards are in place to protect information technology systems and data. Condition During our audit procedures, we noted that the University risk assessment did not fully addressed all the elements required by (16 CFR 314.4). Accordingly, the following elements were missing: 1. Evidence of annual security report to those charge with governance 2. Vulnerability test 3. Disaster recovery plan 4. No backup test was performed during year ended June 30, 2023. Cause In the past years there’s been a high turnover in the position of the qualified individual responsible for overseeing and implementing the institution’s information security program. As a result, some of the procedures and policies established in the information security program risk assessment have not been consistently or continuously maintained. Effect The student personal information could be vulnerable. In addition, the Department of Education (DE) has informed through electronic announcements (EA), that “when an audit report that includes a GLBA audit finding is received by the Department, they will refer the audit to the Federal Trade Commission (FTC). Once the finding is referred to the FTC, that finding will be considered closed for the Department’s audit tracking purposes. The FTC will determine what action may be needed as a result of the GLBA audit finding.” Questioned cost N/A Context The Gramm-Leach-Bliley Act (GLBA) created a requirement that financial institutions must have certain information privacy protections and safeguards in place. The Federal Trade Commission (FTC) has enforcement authority for the requirements and has determined that institutions of higher education (institutions) are financial institutions under GLBA. Each institution has agreed to comply with GLBA in its Program Participation Agreement with the Department. In addition, as a condition of accessing the Department’s systems, each institution and servicer must sign the Student Aid Internet Gateway (SAIG) Enrollment Agreement, which states that the institution must ensure that all federal student aid applicant information is protected from access by or disclosure to unauthorized personnel. Institutions and third-party servicers are also required to demonstrate administrative capability in accordance with 34 C.F.R. § 668.16, including the maintenance of adequate checks and balances in their systems of internal control. An institution or servicer that does not maintain adequate internal controls over the security of student information may not be considered administratively capable. Identification of a repeat finding This is not a repeat finding. Recommendation We recommend that management implement policies and procedures, including internal controls, to ensure that they are in compliance with 16 CFR 314.4(b) and (c). Views of responsible officials and planned corrective actions The University’s management agrees with this finding. Please refer to the corrective action plan on pages 47-48.
Finding No. 2023-001 Gramm-Leach-Bliley Act–Student Information Security Federal Program ALN 84.007 Federal Supplemental Educational Opportunity Grant Program ALN 84.033 Federal Work-Study Program ALN 84.063 Federal Pell Grant Program ALN 84.268 Federal Direct Student Loan Program Name of Federal Agency U.S. Department of Education Pass-through Entity N/A Type of Finding Compliance Internal of Control Category Significant deficiency Compliance Requirement N. Special Tests and Provisions Criteria Under an institution’s Program Participation Agreement with the Department of Education and the Gramm-Leach-Bliley Act, schools must protect student financial aid information, with particular attention to information provided to institutions by the Department or otherwise obtained in support of the administration of the federal student financial aid programs.The Gramm-Leach-Bliley Act (GLBA) (Pub. L. No. 106-102) requires financial institutions to explain their information-sharing practices to their customers and to safeguard sensitive data (16 CFR 314). The Federal Trade Commission considers Title IV-eligible institutions that participate in Title IV Educational Assistance Programs as “financial institutions” and subject to the Gramm-Leach-Bliley Act (16 CFR 313.3(k)(2)(vi)). The Standards for Safeguarding Customer Information, required by the GLBA (16 CFR §314.4) requires the University to: a) Designates a qualified individual responsible for overseeing and implementing the institution’s information security program and enforcing the information security program in compliance (16 CFR 314.4(a)). b) Provides for the information security program to be based on a risk assessment that identifies reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of customer information (as the term customer information applies to the institution) that could result in the unauthorized disclosure, misuse, alteration, destruction, or other compromise of such information, and assesses the sufficiency of any safeguards in place to control these risks (16 CFR 314.4(b)). c) Provides for the design and implementation of safeguards to control the risks the institution identifies through its risk assessment (16 CFR 314.4(c)). At a minimum, the institution’s written information security program must address the implementation of the minimum safeguards identified in 16 CFR 314.4(c)(1) through (8). The eight minimum safeguards that the written information security program must address are summarized as follows: 1. Implement and periodically review access controls. 2. Conduct a periodic inventory of data, noting where it’s collected, stored, or transmitted. 3. Encrypt customer information on the institution’s system and when it’s in transit. 4. Assess apps developed by the institution. 5. Implement multi-factor authentication for anyone accessing customer information on the institution’s system. 6. Dispose of customer information securely. 7. Anticipate and evaluate changes to the information system or network. 8. Maintain a log of authorized users’ activity and keep an eye out for unauthorized access. d) Provides for the institution to regularly test or otherwise monitor the effectiveness of the safeguards it has implemented (16 CFR 314.4(d)).Criteria – (continued) e) Provides for the implementation of policies and procedures to ensure that personnel are able to enact the information security program (16 CFR 314.4(e)(1)). f) Addresses how the institution will oversee its information system service providers (16 CFR 314.4(f)). g) Provides for the evaluation and adjustment of its information security program in light of the results of the required testing and monitoring; any material changes to its operations or business arrangements; the results of the required risk assessments; or any other circumstances that it knows or has reason to know may have a material impact the institution’s information security program (16 CFR 314.4(g)). Additionally, the Uniform Guidance (2 CFR 200.303(a)) requires nonfederal entities receiving federal awards to establish and maintain effective internal controls designed to reasonably ensure compliance with Federal laws, statutes, regulations, and the terms and conditions of the Federal award. Furthermore, generally accepted information technology guidance endorses the implementation of a process to identify risk and ensure appropriate safeguards are in place to protect information technology systems and data. Condition During our audit procedures, we noted that the University risk assessment did not fully addressed all the elements required by (16 CFR 314.4). Accordingly, the following elements were missing: 1. Evidence of annual security report to those charge with governance 2. Vulnerability test 3. Disaster recovery plan 4. No backup test was performed during year ended June 30, 2023. Cause In the past years there’s been a high turnover in the position of the qualified individual responsible for overseeing and implementing the institution’s information security program. As a result, some of the procedures and policies established in the information security program risk assessment have not been consistently or continuously maintained. Effect The student personal information could be vulnerable. In addition, the Department of Education (DE) has informed through electronic announcements (EA), that “when an audit report that includes a GLBA audit finding is received by the Department, they will refer the audit to the Federal Trade Commission (FTC). Once the finding is referred to the FTC, that finding will be considered closed for the Department’s audit tracking purposes. The FTC will determine what action may be needed as a result of the GLBA audit finding.” Questioned cost N/A Context The Gramm-Leach-Bliley Act (GLBA) created a requirement that financial institutions must have certain information privacy protections and safeguards in place. The Federal Trade Commission (FTC) has enforcement authority for the requirements and has determined that institutions of higher education (institutions) are financial institutions under GLBA. Each institution has agreed to comply with GLBA in its Program Participation Agreement with the Department. In addition, as a condition of accessing the Department’s systems, each institution and servicer must sign the Student Aid Internet Gateway (SAIG) Enrollment Agreement, which states that the institution must ensure that all federal student aid applicant information is protected from access by or disclosure to unauthorized personnel. Institutions and third-party servicers are also required to demonstrate administrative capability in accordance with 34 C.F.R. § 668.16, including the maintenance of adequate checks and balances in their systems of internal control. An institution or servicer that does not maintain adequate internal controls over the security of student information may not be considered administratively capable. Identification of a repeat finding This is not a repeat finding. Recommendation We recommend that management implement policies and procedures, including internal controls, to ensure that they are in compliance with 16 CFR 314.4(b) and (c). Views of responsible officials and planned corrective actions The University’s management agrees with this finding. Please refer to the corrective action plan on pages 47-48.
Finding No. 2023-001 Gramm-Leach-Bliley Act–Student Information Security Federal Program ALN 84.007 Federal Supplemental Educational Opportunity Grant Program ALN 84.033 Federal Work-Study Program ALN 84.063 Federal Pell Grant Program ALN 84.268 Federal Direct Student Loan Program Name of Federal Agency U.S. Department of Education Pass-through Entity N/A Type of Finding Compliance Internal of Control Category Significant deficiency Compliance Requirement N. Special Tests and Provisions Criteria Under an institution’s Program Participation Agreement with the Department of Education and the Gramm-Leach-Bliley Act, schools must protect student financial aid information, with particular attention to information provided to institutions by the Department or otherwise obtained in support of the administration of the federal student financial aid programs.The Gramm-Leach-Bliley Act (GLBA) (Pub. L. No. 106-102) requires financial institutions to explain their information-sharing practices to their customers and to safeguard sensitive data (16 CFR 314). The Federal Trade Commission considers Title IV-eligible institutions that participate in Title IV Educational Assistance Programs as “financial institutions” and subject to the Gramm-Leach-Bliley Act (16 CFR 313.3(k)(2)(vi)). The Standards for Safeguarding Customer Information, required by the GLBA (16 CFR §314.4) requires the University to: a) Designates a qualified individual responsible for overseeing and implementing the institution’s information security program and enforcing the information security program in compliance (16 CFR 314.4(a)). b) Provides for the information security program to be based on a risk assessment that identifies reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of customer information (as the term customer information applies to the institution) that could result in the unauthorized disclosure, misuse, alteration, destruction, or other compromise of such information, and assesses the sufficiency of any safeguards in place to control these risks (16 CFR 314.4(b)). c) Provides for the design and implementation of safeguards to control the risks the institution identifies through its risk assessment (16 CFR 314.4(c)). At a minimum, the institution’s written information security program must address the implementation of the minimum safeguards identified in 16 CFR 314.4(c)(1) through (8). The eight minimum safeguards that the written information security program must address are summarized as follows: 1. Implement and periodically review access controls. 2. Conduct a periodic inventory of data, noting where it’s collected, stored, or transmitted. 3. Encrypt customer information on the institution’s system and when it’s in transit. 4. Assess apps developed by the institution. 5. Implement multi-factor authentication for anyone accessing customer information on the institution’s system. 6. Dispose of customer information securely. 7. Anticipate and evaluate changes to the information system or network. 8. Maintain a log of authorized users’ activity and keep an eye out for unauthorized access. d) Provides for the institution to regularly test or otherwise monitor the effectiveness of the safeguards it has implemented (16 CFR 314.4(d)).Criteria – (continued) e) Provides for the implementation of policies and procedures to ensure that personnel are able to enact the information security program (16 CFR 314.4(e)(1)). f) Addresses how the institution will oversee its information system service providers (16 CFR 314.4(f)). g) Provides for the evaluation and adjustment of its information security program in light of the results of the required testing and monitoring; any material changes to its operations or business arrangements; the results of the required risk assessments; or any other circumstances that it knows or has reason to know may have a material impact the institution’s information security program (16 CFR 314.4(g)). Additionally, the Uniform Guidance (2 CFR 200.303(a)) requires nonfederal entities receiving federal awards to establish and maintain effective internal controls designed to reasonably ensure compliance with Federal laws, statutes, regulations, and the terms and conditions of the Federal award. Furthermore, generally accepted information technology guidance endorses the implementation of a process to identify risk and ensure appropriate safeguards are in place to protect information technology systems and data. Condition During our audit procedures, we noted that the University risk assessment did not fully addressed all the elements required by (16 CFR 314.4). Accordingly, the following elements were missing: 1. Evidence of annual security report to those charge with governance 2. Vulnerability test 3. Disaster recovery plan 4. No backup test was performed during year ended June 30, 2023. Cause In the past years there’s been a high turnover in the position of the qualified individual responsible for overseeing and implementing the institution’s information security program. As a result, some of the procedures and policies established in the information security program risk assessment have not been consistently or continuously maintained. Effect The student personal information could be vulnerable. In addition, the Department of Education (DE) has informed through electronic announcements (EA), that “when an audit report that includes a GLBA audit finding is received by the Department, they will refer the audit to the Federal Trade Commission (FTC). Once the finding is referred to the FTC, that finding will be considered closed for the Department’s audit tracking purposes. The FTC will determine what action may be needed as a result of the GLBA audit finding.” Questioned cost N/A Context The Gramm-Leach-Bliley Act (GLBA) created a requirement that financial institutions must have certain information privacy protections and safeguards in place. The Federal Trade Commission (FTC) has enforcement authority for the requirements and has determined that institutions of higher education (institutions) are financial institutions under GLBA. Each institution has agreed to comply with GLBA in its Program Participation Agreement with the Department. In addition, as a condition of accessing the Department’s systems, each institution and servicer must sign the Student Aid Internet Gateway (SAIG) Enrollment Agreement, which states that the institution must ensure that all federal student aid applicant information is protected from access by or disclosure to unauthorized personnel. Institutions and third-party servicers are also required to demonstrate administrative capability in accordance with 34 C.F.R. § 668.16, including the maintenance of adequate checks and balances in their systems of internal control. An institution or servicer that does not maintain adequate internal controls over the security of student information may not be considered administratively capable. Identification of a repeat finding This is not a repeat finding. Recommendation We recommend that management implement policies and procedures, including internal controls, to ensure that they are in compliance with 16 CFR 314.4(b) and (c). Views of responsible officials and planned corrective actions The University’s management agrees with this finding. Please refer to the corrective action plan on pages 47-48.
Finding No. 2023-001 Gramm-Leach-Bliley Act–Student Information Security Federal Program ALN 84.007 Federal Supplemental Educational Opportunity Grant Program ALN 84.033 Federal Work-Study Program ALN 84.063 Federal Pell Grant Program ALN 84.268 Federal Direct Student Loan Program Name of Federal Agency U.S. Department of Education Pass-through Entity N/A Type of Finding Compliance Internal of Control Category Significant deficiency Compliance Requirement N. Special Tests and Provisions Criteria Under an institution’s Program Participation Agreement with the Department of Education and the Gramm-Leach-Bliley Act, schools must protect student financial aid information, with particular attention to information provided to institutions by the Department or otherwise obtained in support of the administration of the federal student financial aid programs.The Gramm-Leach-Bliley Act (GLBA) (Pub. L. No. 106-102) requires financial institutions to explain their information-sharing practices to their customers and to safeguard sensitive data (16 CFR 314). The Federal Trade Commission considers Title IV-eligible institutions that participate in Title IV Educational Assistance Programs as “financial institutions” and subject to the Gramm-Leach-Bliley Act (16 CFR 313.3(k)(2)(vi)). The Standards for Safeguarding Customer Information, required by the GLBA (16 CFR §314.4) requires the University to: a) Designates a qualified individual responsible for overseeing and implementing the institution’s information security program and enforcing the information security program in compliance (16 CFR 314.4(a)). b) Provides for the information security program to be based on a risk assessment that identifies reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of customer information (as the term customer information applies to the institution) that could result in the unauthorized disclosure, misuse, alteration, destruction, or other compromise of such information, and assesses the sufficiency of any safeguards in place to control these risks (16 CFR 314.4(b)). c) Provides for the design and implementation of safeguards to control the risks the institution identifies through its risk assessment (16 CFR 314.4(c)). At a minimum, the institution’s written information security program must address the implementation of the minimum safeguards identified in 16 CFR 314.4(c)(1) through (8). The eight minimum safeguards that the written information security program must address are summarized as follows: 1. Implement and periodically review access controls. 2. Conduct a periodic inventory of data, noting where it’s collected, stored, or transmitted. 3. Encrypt customer information on the institution’s system and when it’s in transit. 4. Assess apps developed by the institution. 5. Implement multi-factor authentication for anyone accessing customer information on the institution’s system. 6. Dispose of customer information securely. 7. Anticipate and evaluate changes to the information system or network. 8. Maintain a log of authorized users’ activity and keep an eye out for unauthorized access. d) Provides for the institution to regularly test or otherwise monitor the effectiveness of the safeguards it has implemented (16 CFR 314.4(d)).Criteria – (continued) e) Provides for the implementation of policies and procedures to ensure that personnel are able to enact the information security program (16 CFR 314.4(e)(1)). f) Addresses how the institution will oversee its information system service providers (16 CFR 314.4(f)). g) Provides for the evaluation and adjustment of its information security program in light of the results of the required testing and monitoring; any material changes to its operations or business arrangements; the results of the required risk assessments; or any other circumstances that it knows or has reason to know may have a material impact the institution’s information security program (16 CFR 314.4(g)). Additionally, the Uniform Guidance (2 CFR 200.303(a)) requires nonfederal entities receiving federal awards to establish and maintain effective internal controls designed to reasonably ensure compliance with Federal laws, statutes, regulations, and the terms and conditions of the Federal award. Furthermore, generally accepted information technology guidance endorses the implementation of a process to identify risk and ensure appropriate safeguards are in place to protect information technology systems and data. Condition During our audit procedures, we noted that the University risk assessment did not fully addressed all the elements required by (16 CFR 314.4). Accordingly, the following elements were missing: 1. Evidence of annual security report to those charge with governance 2. Vulnerability test 3. Disaster recovery plan 4. No backup test was performed during year ended June 30, 2023. Cause In the past years there’s been a high turnover in the position of the qualified individual responsible for overseeing and implementing the institution’s information security program. As a result, some of the procedures and policies established in the information security program risk assessment have not been consistently or continuously maintained. Effect The student personal information could be vulnerable. In addition, the Department of Education (DE) has informed through electronic announcements (EA), that “when an audit report that includes a GLBA audit finding is received by the Department, they will refer the audit to the Federal Trade Commission (FTC). Once the finding is referred to the FTC, that finding will be considered closed for the Department’s audit tracking purposes. The FTC will determine what action may be needed as a result of the GLBA audit finding.” Questioned cost N/A Context The Gramm-Leach-Bliley Act (GLBA) created a requirement that financial institutions must have certain information privacy protections and safeguards in place. The Federal Trade Commission (FTC) has enforcement authority for the requirements and has determined that institutions of higher education (institutions) are financial institutions under GLBA. Each institution has agreed to comply with GLBA in its Program Participation Agreement with the Department. In addition, as a condition of accessing the Department’s systems, each institution and servicer must sign the Student Aid Internet Gateway (SAIG) Enrollment Agreement, which states that the institution must ensure that all federal student aid applicant information is protected from access by or disclosure to unauthorized personnel. Institutions and third-party servicers are also required to demonstrate administrative capability in accordance with 34 C.F.R. § 668.16, including the maintenance of adequate checks and balances in their systems of internal control. An institution or servicer that does not maintain adequate internal controls over the security of student information may not be considered administratively capable. Identification of a repeat finding This is not a repeat finding. Recommendation We recommend that management implement policies and procedures, including internal controls, to ensure that they are in compliance with 16 CFR 314.4(b) and (c). Views of responsible officials and planned corrective actions The University’s management agrees with this finding. Please refer to the corrective action plan on pages 47-48.
Criteria There are three components to reporting for HEERF: 1) public reporting on the (a)(1) Student Aid Portion; 2) public reporting on the (a)(1) Institutional Portion (a)(2) and (a)(3) subprograms (Quarterly Reporting Form), as applicable; and 3) the annual report. The CARES Act 18004(e) and the CRRSAA 314(e) require an institution receiving funds under HEERF I and HEERF II to submit a report to the secretary, at such time in such a manner as the secretary may require. While ARP does not explicitly identify procedures by which institutions must report on their uses of HEERF grant funds, ED exercises this reporting authority under 2 CFR section 200.328 and 2 CFR section 200.329. ED required an annual report from HEERF grantees to be filed in March 2023 that included reporting uses of HEERF I CARES Act funds, HEERF II CRRSAA funds, and HEERF III ARP funds for the 2022 calendar year. Additionally, beginning with the second quarter of 2022 quarterly report, institutions were required to complete and post on their websites a combined institutional and student reporting form. This form was required to be conspicuously posted on the institutions’ website no later than 10 days after the calendar quarter (January 10, April 10, July 10, October 10) as long as the institution’s HEERF grant was active. Further, in accordance with 2 CFR 200.303(a), non-federal entities must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non-federal entity is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award. Condition During the year ended June 30, 2023, the College did not publish its quarterly reporting on the College's website within the 10-day compliance requirement for the quarters ending, March 31, 2023 and June 30, 2023. Cause The College’s HEERF reporting process did not include a control designed to monitor the timeliness and accuracy of the required reporting in either of the two prior years (2021 and 2022). This was noted as a finding in both 2022 (2022-002) and 2021 (2021-001). Although the College drafted a corrective action plan in March 2023 that included implementation of a control designed to monitor the timeliness and accuracy of the required reporting, due to employee turnover, the control was not implemented prior to June 30, 2023. Effect If appropriate controls are not designed and operating effectively over the HEERF reporting process, HEERF expenditures reported on the College’s website may be incomplete, inaccurate, or not posted within the timeframe required. Questioned Costs None noted. Statistical Sampling The sample was not intended to be and was not a statistically valid sample. Prior Year Finding Yes – 2022-002 Recommendation We recommend that the College implement a more thorough and detailed process and related internal controls to ensure timely and accurate reporting required under its Federal programs. Management’s Views Subsequent to June 30, 2023, management has reviewed its reporting requirements under its Federal programs and implemented controls to ensure accuracy and timeliness of required reporting. In prior years, there has been high employee turnover in the business office, now that staffing has stabilized, the College has implemented new general controls over all federal funding received. For future funds, the Senior Accountant will be responsible for the receipt and disbursement of federal funds, and for monitoring reporting requirements. Additionally, the Associate Vice President for Finance and Controller will oversee the process and ensure that spending guidelines are followed and that all deadlines for reporting are met. Anticipated Completion Date Completed – December 15, 2023 Responsible Person Heather Martinez, Associate Vice President for Finance and Controller
2023-002. FINDING (Enrollment Reporting) Federal Department: U.S. Department of Education Assistance Listing Number: 84.268 Cluster Name: Student Financial Assistance Cluster Program Name: Federal Direct Student Loans Award Numbers: P268K230567, P268K220567 Questioned Cost: None Program Expenditures: $21,864,079 Cluster Expenditures: $33,549,307 Governors State University (University) did not timely report student enrollment information to the U.S. Department of Education’s National Student Loan Data System (NSLDS). During our audit, we tested 33 students who experienced a change in enrollment status during the fiscal year. Our testing identified two students (6%) whose enrollment status change was not reported timely to the NSLDS. The student enrollment status changes were reported 236 and 353 days late after the date of occurrence. The sample was not intended to be, and was not, a statistically valid sample. The Code of Federal Regulations (34 CFR 685.309) requires the University, upon the receipt of an enrollment report from the Secretary, to update all information included in the report and return the report to the Secretary within the timeframe prescribed by the Secretary. It further requires the University to report enrollment changes within 30 days unless a roster file is expected within 60 days, in which case the enrollment data may be updated on that roster file. The Uniform Guidance (2 CFR 200.303) requires nonfederal entities receiving federal awards establish and maintain internal controls designed to reasonably ensure compliance with federal statutes, regulations, and terms and conditions of the federal award. Effective internal controls should include procedures to ensure timely student enrollment status reports are submitted to NSLDS. University officials stated the students noted were granted administrative withdrawal for a single course after the semester (the students registered for) ended, which resulted in a change of enrollment from Full-time to Three-Quarters of a Time. The University reports enrollment status changes to NSLDS through the National Student Clearinghouse (NSC), a third-party servicer. Changes to enrollment that occur after the term has been reported will not be updated in NSLDS by changes made by the University in NSC. Those enrollment changes need to be updated directly in the NSLDS enrollment history update function. Enrollment reporting in a timely manner is critical for effective management of the student financial aid programs. Noncompliance with enrollment reporting regulations may result in a loss of future federal funding. (Finding Code No. 2023-002, 2022-002, 2021-003) RECOMMENDATION We recommend the University improve its procedures to ensure timely reporting of student enrollment status to the NSLDS. UNIVERSITY RESPONSE The University agrees with this finding and accepts the recommendation. The University has already identified a method to report directly to NSLDS all enrollment changes occurring after the end of the term. The University will continue to update timely the NSLDS enrollment history as needed when the situation of late withdrawals occurs beyond the reporting dates.
2023-003. FINDING (Noncompliance with Gramm-Leach-Bliley Act) Federal Department: U.S. Department of Education, U.S. Department of Health and Human Services Assistance Listing Number: 84.038, 84.033, 84.007, 84.063, 84.268, 84.379, 93.925,93.264 Cluster Name: Student Financial Assistance Cluster Program Name: Federal Perkins Loan Program, Federal Work-Study Program, Federal Supplemental Educational Opportunity Grants, Federal Pell Grant Program, Federal Direct Student Loans, Teacher Education Assistance for College and Higher Education Grants, Scholarships for Health Professions Students from Disadvantaged Backgrounds, and Nurse Faculty Loan Program Award Numbers: P033A221156, P033A211156, P033A171156, P007A221156, P007A211156, P063P220567, P063P210567, P268K230567, P268K220567, P379T230567, P379T220567, 5T08HP39308‐03‐00, and E01HP27019 Questioned Cost: None Program Expenditures: $2,474,974; $503,715; $265,650; 7,216,654, $21,864,079; $25,930; $576,000; $622,305 Cluster Expenditures: $33,549,307 Governors State University (University) did not establish a written incident response plan designed to promptly respond to, and recover from, any security event materially affecting the confidentiality, integrity, or availability of customer information in their control. During our audit, we noted the University was unable to complete the development of the written incident response plan as of the end of the audit period. On December 9, 2021, the Federal Trade Commission issued final regulations to amend the Standards for Safeguarding Customer Information (Safeguards Rule), an important component of the Gramm-Leach-Bliley Act’s (GLBA) requirements for protecting the privacy and personal information of consumers. The Code of Federal Regulations (16 CFR 314.4 (h)) requires the University to develop, implement and maintain an information security program which includes establishing a written incident response plan designed to promptly respond to, and recover from, any security event materially affecting the confidentiality, integrity, or availability of customer information in its control. At a minimum, such incident response plan shall address the following areas: • the goals of the incident response plan; • the internal processes for responding to a security event; • the definition of clear roles, responsibilities, and levels of decision-making authority; • external and internal communications and information sharing; • identification of requirements for the remediation of any identified weaknesses in information systems and associated controls; • documentation and reporting regarding security events and related incident response activities; and • the evaluation and revision as necessary of the incident response plan following a security event. Additionally, the Uniform Guidance (2 CFR 200.303(a)) requires nonfederal entities receiving federal awards establish and maintain effective internal control designed to reasonably ensure compliance with federal laws, statutes, regulations, and the terms and conditions of the federal award. University officials stated the University has started the process of developing the written incident response plan but has not been completed to date due to resource constraints and competing priorities. The intent of the GLBA Safeguards Rule is to enhance security over confidential information. Without a documented response to all applicable requirements, the University is more susceptible to vulnerabilities as it relates to protecting the privacy and personal information of students than it will be following full implementation. (Finding Code No. 2023-003) RECOMMENDATION We recommend the University continue towards completion and full implementation of the written incident response plan. UNIVERSITY RESPONSE The University agrees with this finding and accepts the recommendation. The University is currently drafting the incident response plan and is working to secure a contract with an incident response firm. Additionally, the University recently hired an Information Security Analyst, a newly created position designed to address smaller-scale alerts and incidents.
2023-003. FINDING (Noncompliance with Gramm-Leach-Bliley Act) Federal Department: U.S. Department of Education, U.S. Department of Health and Human Services Assistance Listing Number: 84.038, 84.033, 84.007, 84.063, 84.268, 84.379, 93.925,93.264 Cluster Name: Student Financial Assistance Cluster Program Name: Federal Perkins Loan Program, Federal Work-Study Program, Federal Supplemental Educational Opportunity Grants, Federal Pell Grant Program, Federal Direct Student Loans, Teacher Education Assistance for College and Higher Education Grants, Scholarships for Health Professions Students from Disadvantaged Backgrounds, and Nurse Faculty Loan Program Award Numbers: P033A221156, P033A211156, P033A171156, P007A221156, P007A211156, P063P220567, P063P210567, P268K230567, P268K220567, P379T230567, P379T220567, 5T08HP39308‐03‐00, and E01HP27019 Questioned Cost: None Program Expenditures: $2,474,974; $503,715; $265,650; 7,216,654, $21,864,079; $25,930; $576,000; $622,305 Cluster Expenditures: $33,549,307 Governors State University (University) did not establish a written incident response plan designed to promptly respond to, and recover from, any security event materially affecting the confidentiality, integrity, or availability of customer information in their control. During our audit, we noted the University was unable to complete the development of the written incident response plan as of the end of the audit period. On December 9, 2021, the Federal Trade Commission issued final regulations to amend the Standards for Safeguarding Customer Information (Safeguards Rule), an important component of the Gramm-Leach-Bliley Act’s (GLBA) requirements for protecting the privacy and personal information of consumers. The Code of Federal Regulations (16 CFR 314.4 (h)) requires the University to develop, implement and maintain an information security program which includes establishing a written incident response plan designed to promptly respond to, and recover from, any security event materially affecting the confidentiality, integrity, or availability of customer information in its control. At a minimum, such incident response plan shall address the following areas: • the goals of the incident response plan; • the internal processes for responding to a security event; • the definition of clear roles, responsibilities, and levels of decision-making authority; • external and internal communications and information sharing; • identification of requirements for the remediation of any identified weaknesses in information systems and associated controls; • documentation and reporting regarding security events and related incident response activities; and • the evaluation and revision as necessary of the incident response plan following a security event. Additionally, the Uniform Guidance (2 CFR 200.303(a)) requires nonfederal entities receiving federal awards establish and maintain effective internal control designed to reasonably ensure compliance with federal laws, statutes, regulations, and the terms and conditions of the federal award. University officials stated the University has started the process of developing the written incident response plan but has not been completed to date due to resource constraints and competing priorities. The intent of the GLBA Safeguards Rule is to enhance security over confidential information. Without a documented response to all applicable requirements, the University is more susceptible to vulnerabilities as it relates to protecting the privacy and personal information of students than it will be following full implementation. (Finding Code No. 2023-003) RECOMMENDATION We recommend the University continue towards completion and full implementation of the written incident response plan. UNIVERSITY RESPONSE The University agrees with this finding and accepts the recommendation. The University is currently drafting the incident response plan and is working to secure a contract with an incident response firm. Additionally, the University recently hired an Information Security Analyst, a newly created position designed to address smaller-scale alerts and incidents.
2023-003. FINDING (Noncompliance with Gramm-Leach-Bliley Act) Federal Department: U.S. Department of Education, U.S. Department of Health and Human Services Assistance Listing Number: 84.038, 84.033, 84.007, 84.063, 84.268, 84.379, 93.925,93.264 Cluster Name: Student Financial Assistance Cluster Program Name: Federal Perkins Loan Program, Federal Work-Study Program, Federal Supplemental Educational Opportunity Grants, Federal Pell Grant Program, Federal Direct Student Loans, Teacher Education Assistance for College and Higher Education Grants, Scholarships for Health Professions Students from Disadvantaged Backgrounds, and Nurse Faculty Loan Program Award Numbers: P033A221156, P033A211156, P033A171156, P007A221156, P007A211156, P063P220567, P063P210567, P268K230567, P268K220567, P379T230567, P379T220567, 5T08HP39308‐03‐00, and E01HP27019 Questioned Cost: None Program Expenditures: $2,474,974; $503,715; $265,650; 7,216,654, $21,864,079; $25,930; $576,000; $622,305 Cluster Expenditures: $33,549,307 Governors State University (University) did not establish a written incident response plan designed to promptly respond to, and recover from, any security event materially affecting the confidentiality, integrity, or availability of customer information in their control. During our audit, we noted the University was unable to complete the development of the written incident response plan as of the end of the audit period. On December 9, 2021, the Federal Trade Commission issued final regulations to amend the Standards for Safeguarding Customer Information (Safeguards Rule), an important component of the Gramm-Leach-Bliley Act’s (GLBA) requirements for protecting the privacy and personal information of consumers. The Code of Federal Regulations (16 CFR 314.4 (h)) requires the University to develop, implement and maintain an information security program which includes establishing a written incident response plan designed to promptly respond to, and recover from, any security event materially affecting the confidentiality, integrity, or availability of customer information in its control. At a minimum, such incident response plan shall address the following areas: • the goals of the incident response plan; • the internal processes for responding to a security event; • the definition of clear roles, responsibilities, and levels of decision-making authority; • external and internal communications and information sharing; • identification of requirements for the remediation of any identified weaknesses in information systems and associated controls; • documentation and reporting regarding security events and related incident response activities; and • the evaluation and revision as necessary of the incident response plan following a security event. Additionally, the Uniform Guidance (2 CFR 200.303(a)) requires nonfederal entities receiving federal awards establish and maintain effective internal control designed to reasonably ensure compliance with federal laws, statutes, regulations, and the terms and conditions of the federal award. University officials stated the University has started the process of developing the written incident response plan but has not been completed to date due to resource constraints and competing priorities. The intent of the GLBA Safeguards Rule is to enhance security over confidential information. Without a documented response to all applicable requirements, the University is more susceptible to vulnerabilities as it relates to protecting the privacy and personal information of students than it will be following full implementation. (Finding Code No. 2023-003) RECOMMENDATION We recommend the University continue towards completion and full implementation of the written incident response plan. UNIVERSITY RESPONSE The University agrees with this finding and accepts the recommendation. The University is currently drafting the incident response plan and is working to secure a contract with an incident response firm. Additionally, the University recently hired an Information Security Analyst, a newly created position designed to address smaller-scale alerts and incidents.
2023-003. FINDING (Noncompliance with Gramm-Leach-Bliley Act) Federal Department: U.S. Department of Education, U.S. Department of Health and Human Services Assistance Listing Number: 84.038, 84.033, 84.007, 84.063, 84.268, 84.379, 93.925,93.264 Cluster Name: Student Financial Assistance Cluster Program Name: Federal Perkins Loan Program, Federal Work-Study Program, Federal Supplemental Educational Opportunity Grants, Federal Pell Grant Program, Federal Direct Student Loans, Teacher Education Assistance for College and Higher Education Grants, Scholarships for Health Professions Students from Disadvantaged Backgrounds, and Nurse Faculty Loan Program Award Numbers: P033A221156, P033A211156, P033A171156, P007A221156, P007A211156, P063P220567, P063P210567, P268K230567, P268K220567, P379T230567, P379T220567, 5T08HP39308‐03‐00, and E01HP27019 Questioned Cost: None Program Expenditures: $2,474,974; $503,715; $265,650; 7,216,654, $21,864,079; $25,930; $576,000; $622,305 Cluster Expenditures: $33,549,307 Governors State University (University) did not establish a written incident response plan designed to promptly respond to, and recover from, any security event materially affecting the confidentiality, integrity, or availability of customer information in their control. During our audit, we noted the University was unable to complete the development of the written incident response plan as of the end of the audit period. On December 9, 2021, the Federal Trade Commission issued final regulations to amend the Standards for Safeguarding Customer Information (Safeguards Rule), an important component of the Gramm-Leach-Bliley Act’s (GLBA) requirements for protecting the privacy and personal information of consumers. The Code of Federal Regulations (16 CFR 314.4 (h)) requires the University to develop, implement and maintain an information security program which includes establishing a written incident response plan designed to promptly respond to, and recover from, any security event materially affecting the confidentiality, integrity, or availability of customer information in its control. At a minimum, such incident response plan shall address the following areas: • the goals of the incident response plan; • the internal processes for responding to a security event; • the definition of clear roles, responsibilities, and levels of decision-making authority; • external and internal communications and information sharing; • identification of requirements for the remediation of any identified weaknesses in information systems and associated controls; • documentation and reporting regarding security events and related incident response activities; and • the evaluation and revision as necessary of the incident response plan following a security event. Additionally, the Uniform Guidance (2 CFR 200.303(a)) requires nonfederal entities receiving federal awards establish and maintain effective internal control designed to reasonably ensure compliance with federal laws, statutes, regulations, and the terms and conditions of the federal award. University officials stated the University has started the process of developing the written incident response plan but has not been completed to date due to resource constraints and competing priorities. The intent of the GLBA Safeguards Rule is to enhance security over confidential information. Without a documented response to all applicable requirements, the University is more susceptible to vulnerabilities as it relates to protecting the privacy and personal information of students than it will be following full implementation. (Finding Code No. 2023-003) RECOMMENDATION We recommend the University continue towards completion and full implementation of the written incident response plan. UNIVERSITY RESPONSE The University agrees with this finding and accepts the recommendation. The University is currently drafting the incident response plan and is working to secure a contract with an incident response firm. Additionally, the University recently hired an Information Security Analyst, a newly created position designed to address smaller-scale alerts and incidents.
2023-003. FINDING (Noncompliance with Gramm-Leach-Bliley Act) Federal Department: U.S. Department of Education, U.S. Department of Health and Human Services Assistance Listing Number: 84.038, 84.033, 84.007, 84.063, 84.268, 84.379, 93.925,93.264 Cluster Name: Student Financial Assistance Cluster Program Name: Federal Perkins Loan Program, Federal Work-Study Program, Federal Supplemental Educational Opportunity Grants, Federal Pell Grant Program, Federal Direct Student Loans, Teacher Education Assistance for College and Higher Education Grants, Scholarships for Health Professions Students from Disadvantaged Backgrounds, and Nurse Faculty Loan Program Award Numbers: P033A221156, P033A211156, P033A171156, P007A221156, P007A211156, P063P220567, P063P210567, P268K230567, P268K220567, P379T230567, P379T220567, 5T08HP39308‐03‐00, and E01HP27019 Questioned Cost: None Program Expenditures: $2,474,974; $503,715; $265,650; 7,216,654, $21,864,079; $25,930; $576,000; $622,305 Cluster Expenditures: $33,549,307 Governors State University (University) did not establish a written incident response plan designed to promptly respond to, and recover from, any security event materially affecting the confidentiality, integrity, or availability of customer information in their control. During our audit, we noted the University was unable to complete the development of the written incident response plan as of the end of the audit period. On December 9, 2021, the Federal Trade Commission issued final regulations to amend the Standards for Safeguarding Customer Information (Safeguards Rule), an important component of the Gramm-Leach-Bliley Act’s (GLBA) requirements for protecting the privacy and personal information of consumers. The Code of Federal Regulations (16 CFR 314.4 (h)) requires the University to develop, implement and maintain an information security program which includes establishing a written incident response plan designed to promptly respond to, and recover from, any security event materially affecting the confidentiality, integrity, or availability of customer information in its control. At a minimum, such incident response plan shall address the following areas: • the goals of the incident response plan; • the internal processes for responding to a security event; • the definition of clear roles, responsibilities, and levels of decision-making authority; • external and internal communications and information sharing; • identification of requirements for the remediation of any identified weaknesses in information systems and associated controls; • documentation and reporting regarding security events and related incident response activities; and • the evaluation and revision as necessary of the incident response plan following a security event. Additionally, the Uniform Guidance (2 CFR 200.303(a)) requires nonfederal entities receiving federal awards establish and maintain effective internal control designed to reasonably ensure compliance with federal laws, statutes, regulations, and the terms and conditions of the federal award. University officials stated the University has started the process of developing the written incident response plan but has not been completed to date due to resource constraints and competing priorities. The intent of the GLBA Safeguards Rule is to enhance security over confidential information. Without a documented response to all applicable requirements, the University is more susceptible to vulnerabilities as it relates to protecting the privacy and personal information of students than it will be following full implementation. (Finding Code No. 2023-003) RECOMMENDATION We recommend the University continue towards completion and full implementation of the written incident response plan. UNIVERSITY RESPONSE The University agrees with this finding and accepts the recommendation. The University is currently drafting the incident response plan and is working to secure a contract with an incident response firm. Additionally, the University recently hired an Information Security Analyst, a newly created position designed to address smaller-scale alerts and incidents.
2023-003. FINDING (Noncompliance with Gramm-Leach-Bliley Act) Federal Department: U.S. Department of Education, U.S. Department of Health and Human Services Assistance Listing Number: 84.038, 84.033, 84.007, 84.063, 84.268, 84.379, 93.925,93.264 Cluster Name: Student Financial Assistance Cluster Program Name: Federal Perkins Loan Program, Federal Work-Study Program, Federal Supplemental Educational Opportunity Grants, Federal Pell Grant Program, Federal Direct Student Loans, Teacher Education Assistance for College and Higher Education Grants, Scholarships for Health Professions Students from Disadvantaged Backgrounds, and Nurse Faculty Loan Program Award Numbers: P033A221156, P033A211156, P033A171156, P007A221156, P007A211156, P063P220567, P063P210567, P268K230567, P268K220567, P379T230567, P379T220567, 5T08HP39308‐03‐00, and E01HP27019 Questioned Cost: None Program Expenditures: $2,474,974; $503,715; $265,650; 7,216,654, $21,864,079; $25,930; $576,000; $622,305 Cluster Expenditures: $33,549,307 Governors State University (University) did not establish a written incident response plan designed to promptly respond to, and recover from, any security event materially affecting the confidentiality, integrity, or availability of customer information in their control. During our audit, we noted the University was unable to complete the development of the written incident response plan as of the end of the audit period. On December 9, 2021, the Federal Trade Commission issued final regulations to amend the Standards for Safeguarding Customer Information (Safeguards Rule), an important component of the Gramm-Leach-Bliley Act’s (GLBA) requirements for protecting the privacy and personal information of consumers. The Code of Federal Regulations (16 CFR 314.4 (h)) requires the University to develop, implement and maintain an information security program which includes establishing a written incident response plan designed to promptly respond to, and recover from, any security event materially affecting the confidentiality, integrity, or availability of customer information in its control. At a minimum, such incident response plan shall address the following areas: • the goals of the incident response plan; • the internal processes for responding to a security event; • the definition of clear roles, responsibilities, and levels of decision-making authority; • external and internal communications and information sharing; • identification of requirements for the remediation of any identified weaknesses in information systems and associated controls; • documentation and reporting regarding security events and related incident response activities; and • the evaluation and revision as necessary of the incident response plan following a security event. Additionally, the Uniform Guidance (2 CFR 200.303(a)) requires nonfederal entities receiving federal awards establish and maintain effective internal control designed to reasonably ensure compliance with federal laws, statutes, regulations, and the terms and conditions of the federal award. University officials stated the University has started the process of developing the written incident response plan but has not been completed to date due to resource constraints and competing priorities. The intent of the GLBA Safeguards Rule is to enhance security over confidential information. Without a documented response to all applicable requirements, the University is more susceptible to vulnerabilities as it relates to protecting the privacy and personal information of students than it will be following full implementation. (Finding Code No. 2023-003) RECOMMENDATION We recommend the University continue towards completion and full implementation of the written incident response plan. UNIVERSITY RESPONSE The University agrees with this finding and accepts the recommendation. The University is currently drafting the incident response plan and is working to secure a contract with an incident response firm. Additionally, the University recently hired an Information Security Analyst, a newly created position designed to address smaller-scale alerts and incidents.
2023-003. FINDING (Noncompliance with Gramm-Leach-Bliley Act) Federal Department: U.S. Department of Education, U.S. Department of Health and Human Services Assistance Listing Number: 84.038, 84.033, 84.007, 84.063, 84.268, 84.379, 93.925,93.264 Cluster Name: Student Financial Assistance Cluster Program Name: Federal Perkins Loan Program, Federal Work-Study Program, Federal Supplemental Educational Opportunity Grants, Federal Pell Grant Program, Federal Direct Student Loans, Teacher Education Assistance for College and Higher Education Grants, Scholarships for Health Professions Students from Disadvantaged Backgrounds, and Nurse Faculty Loan Program Award Numbers: P033A221156, P033A211156, P033A171156, P007A221156, P007A211156, P063P220567, P063P210567, P268K230567, P268K220567, P379T230567, P379T220567, 5T08HP39308‐03‐00, and E01HP27019 Questioned Cost: None Program Expenditures: $2,474,974; $503,715; $265,650; 7,216,654, $21,864,079; $25,930; $576,000; $622,305 Cluster Expenditures: $33,549,307 Governors State University (University) did not establish a written incident response plan designed to promptly respond to, and recover from, any security event materially affecting the confidentiality, integrity, or availability of customer information in their control. During our audit, we noted the University was unable to complete the development of the written incident response plan as of the end of the audit period. On December 9, 2021, the Federal Trade Commission issued final regulations to amend the Standards for Safeguarding Customer Information (Safeguards Rule), an important component of the Gramm-Leach-Bliley Act’s (GLBA) requirements for protecting the privacy and personal information of consumers. The Code of Federal Regulations (16 CFR 314.4 (h)) requires the University to develop, implement and maintain an information security program which includes establishing a written incident response plan designed to promptly respond to, and recover from, any security event materially affecting the confidentiality, integrity, or availability of customer information in its control. At a minimum, such incident response plan shall address the following areas: • the goals of the incident response plan; • the internal processes for responding to a security event; • the definition of clear roles, responsibilities, and levels of decision-making authority; • external and internal communications and information sharing; • identification of requirements for the remediation of any identified weaknesses in information systems and associated controls; • documentation and reporting regarding security events and related incident response activities; and • the evaluation and revision as necessary of the incident response plan following a security event. Additionally, the Uniform Guidance (2 CFR 200.303(a)) requires nonfederal entities receiving federal awards establish and maintain effective internal control designed to reasonably ensure compliance with federal laws, statutes, regulations, and the terms and conditions of the federal award. University officials stated the University has started the process of developing the written incident response plan but has not been completed to date due to resource constraints and competing priorities. The intent of the GLBA Safeguards Rule is to enhance security over confidential information. Without a documented response to all applicable requirements, the University is more susceptible to vulnerabilities as it relates to protecting the privacy and personal information of students than it will be following full implementation. (Finding Code No. 2023-003) RECOMMENDATION We recommend the University continue towards completion and full implementation of the written incident response plan. UNIVERSITY RESPONSE The University agrees with this finding and accepts the recommendation. The University is currently drafting the incident response plan and is working to secure a contract with an incident response firm. Additionally, the University recently hired an Information Security Analyst, a newly created position designed to address smaller-scale alerts and incidents.
2023-003. FINDING (Noncompliance with Gramm-Leach-Bliley Act) Federal Department: U.S. Department of Education, U.S. Department of Health and Human Services Assistance Listing Number: 84.038, 84.033, 84.007, 84.063, 84.268, 84.379, 93.925,93.264 Cluster Name: Student Financial Assistance Cluster Program Name: Federal Perkins Loan Program, Federal Work-Study Program, Federal Supplemental Educational Opportunity Grants, Federal Pell Grant Program, Federal Direct Student Loans, Teacher Education Assistance for College and Higher Education Grants, Scholarships for Health Professions Students from Disadvantaged Backgrounds, and Nurse Faculty Loan Program Award Numbers: P033A221156, P033A211156, P033A171156, P007A221156, P007A211156, P063P220567, P063P210567, P268K230567, P268K220567, P379T230567, P379T220567, 5T08HP39308‐03‐00, and E01HP27019 Questioned Cost: None Program Expenditures: $2,474,974; $503,715; $265,650; 7,216,654, $21,864,079; $25,930; $576,000; $622,305 Cluster Expenditures: $33,549,307 Governors State University (University) did not establish a written incident response plan designed to promptly respond to, and recover from, any security event materially affecting the confidentiality, integrity, or availability of customer information in their control. During our audit, we noted the University was unable to complete the development of the written incident response plan as of the end of the audit period. On December 9, 2021, the Federal Trade Commission issued final regulations to amend the Standards for Safeguarding Customer Information (Safeguards Rule), an important component of the Gramm-Leach-Bliley Act’s (GLBA) requirements for protecting the privacy and personal information of consumers. The Code of Federal Regulations (16 CFR 314.4 (h)) requires the University to develop, implement and maintain an information security program which includes establishing a written incident response plan designed to promptly respond to, and recover from, any security event materially affecting the confidentiality, integrity, or availability of customer information in its control. At a minimum, such incident response plan shall address the following areas: • the goals of the incident response plan; • the internal processes for responding to a security event; • the definition of clear roles, responsibilities, and levels of decision-making authority; • external and internal communications and information sharing; • identification of requirements for the remediation of any identified weaknesses in information systems and associated controls; • documentation and reporting regarding security events and related incident response activities; and • the evaluation and revision as necessary of the incident response plan following a security event. Additionally, the Uniform Guidance (2 CFR 200.303(a)) requires nonfederal entities receiving federal awards establish and maintain effective internal control designed to reasonably ensure compliance with federal laws, statutes, regulations, and the terms and conditions of the federal award. University officials stated the University has started the process of developing the written incident response plan but has not been completed to date due to resource constraints and competing priorities. The intent of the GLBA Safeguards Rule is to enhance security over confidential information. Without a documented response to all applicable requirements, the University is more susceptible to vulnerabilities as it relates to protecting the privacy and personal information of students than it will be following full implementation. (Finding Code No. 2023-003) RECOMMENDATION We recommend the University continue towards completion and full implementation of the written incident response plan. UNIVERSITY RESPONSE The University agrees with this finding and accepts the recommendation. The University is currently drafting the incident response plan and is working to secure a contract with an incident response firm. Additionally, the University recently hired an Information Security Analyst, a newly created position designed to address smaller-scale alerts and incidents.
2023-004. FINDING (Inadequate Controls over Payroll Expenditures and Noncompliance with Allowable Cost & Cost Principles Requirements Applicable to the Head Start Cluster) Federal Department: U.S. Department of Health and Human Services Assistance Listing Number: 93.600 Cluster Name: Head Start Cluster Program Name: Early Head Start Award Numbers: 05CH011351-03-02, 05CH011351-04-03 Questioned Cost: Known ($37,377) Program Expenditures: $985,732 Cluster Expenditures: $1,026,985 The Governors State University (University) did not have adequate controls over payroll expenditures and did not comply with the allowable cost and cost principles requirements applicable to the Head Start Cluster. During our testing of Head Start Cluster payroll expenditures amounting to $555,569, we noted the following: • There was no periodic reconciliation performed between the amount actually worked on the grant (i.e. certified time and effort reports) against payroll expenditures to ensure the amount charged to the grant was accurate. Payroll expenditures for five (5) of twelve (12) employees tested were charged to the Early Head Start program using incorrect time and effort rates. The actual amounts charged to the grant were less than computed payroll expenditures using the certified time and effort rates. These differences were not adjusted at year-end to ensure the accuracy of the accounting records and schedule of expenditures of federal awards. The questioned costs were ($37,377). The sample was not intended to be, and was not, a statistically valid sample. • Our testing of payroll expenditures identified 12 instances out of 12 employees tested who worked on multiple federal awards and/or nonfederal awards lacked appropriate supporting documentation to account for 100% actual time and effort certification of the employees for each reporting period to provide a basis to reconcile with payroll distribution used in charging these awards. The University’s time and effort certification shows only the percentage of effort for each employee on a specific grant. As a result, we were unable to ascertain the accuracy of the payroll expenditure charged as a whole. The sample was not intended to be, and was not, a statistically valid sample. The Code of Federal Regulations (Code) (2 CFR 200.303) requires the University establish and maintain effective internal control over the federal award that provides reasonable assurance the University is managing the federal award in compliance with federal statutes, regulations, and the terms and conditions of the federal award. Effective internal controls should include procedures to ensure that there is reconciliation between the compensation for personal services charged to the agreement and the amount actually worked on the agreement. The Code (2 CFR 200.430) states charges to federal awards for salaries and wages must be based on records that accurately reflect the work performed and must support the distribution of the employee's salary or wages among specific activities or cost objectives if the employee works on more than one federal award; a federal award and nonfederal award; an indirect cost activity and a direct cost activity; two or more indirect activities which are allocated using different allocation bases; or an unallowable activity and a direct or indirect cost activity. These records must be supported by a system of internal control which provides reasonable assurance that the charges are accurate, allowable, and properly allocated. The University’s effort reporting guidelines requires the University to have a periodic review of the salary distribution system to confirm the reasonableness of the charges to the federal projects. In addition, the University is required to review, update, and prepare salary reallocations, and if necessary, make appropriate changes to the effort reports and certify reports on a quarterly basis to ensure that the salaries charged to federally sponsored projects are reasonable and consistent with the portion of activity committed to projects. The effort report must represent, in percentages totaling 100%, a reasonable estimate of an employee’s University compensated effort for the period. University officials stated the reconciliation process for time and effort reports is in place; however, staffing constraints resulted in some delays in the reconciliation process. The Early Head Start program is a calendar year grant that runs from January through December. The necessary adjustments to correct the differences noted for 2023 were made by the University after fiscal year end, but within the grant’s budget period. University officials stated 100% of work is captured on Human Resource and workflow records but not on the certification forms. Failure to accurately charge sponsored agreements for the equitable distribution of employee compensation may result in federal expenditures being disallowed and could jeopardize future federal funding. (Finding Code No. 2023-004) RECOMMENDATION We recommend the University timely reconcile payroll and ensure employees certify 100% of time worked to allow for adequate application of allowable cost and cost principles requirements for the Head Start Cluster. UNIVERSITY RESPONSE The University agrees with this finding and accepts the recommendation. The University has updated its process to collect time and effort information on a semi-annual basis rather than quarterly, which relieves some burden from staff, but still complies with federal regulations. By collecting time and effort information on a semi-annual basis, staff will have more time to reconcile time and effort against actual payroll expenditures. The University has also redesigned the time and effort collection form to show the 100% distribution of work. Further, the University now has a full-time financial research administrator who will help ensure that payroll- related adjustments are done timely. The financial research administrator will work with the Early Head Start program management to ensure that the related payroll reports are reviewed and reconciled timely, in accordance with existing University procedures.
2023-005. FINDING (Failure to File Real Property Status Report) Federal Department: U.S. Department of Health and Human Services Assistance Listing Number: 93.600 Cluster Name: Head Start Cluster Program Name: Early Head Start Award Numbers: 05CH011351-03-02, 05CH011351-04-03 Questioned Cost: None Program Expenditures: $985,732 Cluster Expenditures: $1,026,985 Governors State University (University) failed to submit the required annual real property status report (SF-429). During our audit, we identified the University did not submit the calendar year 2022 SF-429 report. The SF-429 report must be submitted by all grantees on the same date the grantee’s SF- 425 Final Federal Financial Report for the budget period is due. Grantees must act in compliance with the requirements of this grant and applicable federal statutes, regulations, and policies as included in the Compendium of Program Instructions and Information Memoranda. The Office of Head Start has issued Program Instruction Log Number ACF-PI-HS-17-03 which requires all grantees, including those with no covered real property, to prepare and submit SF-429 with Attachment A on an annual basis at the same time as their annual SF-425 Federal Financial Report. The Program Instruction Log Number ACF-PI-HS-17- 03 is required in accordance with the Code of Federal Regulations (Code) (45 CFR 75.343). The Code (45 CFR 75.343) requires nonfederal entities to submit reports periodically dependent on time frame on the status of real property in which the federal government retains an interest. Additionally, the Code (2 CFR 200.303) requires nonfederal entities receiving federal awards to establish and maintain internal controls designed to reasonably ensure compliance with federal laws, regulations, and program compliance requirements. Effective internal controls should include procedures to ensure reports are submitted timely. University officials stated the SF-429 report was inadvertently not submitted as there was no real property acquired from the grant funds. Failure to meet grant reporting requirements is a noncompliance with the related grant request for proposal and application agreement and could result in loss of grant funding in future years. (Finding Code No. 2023-005) RECOMMENDATION We recommend the University improve its procedures to ensure timely submission of required reports. UNIVERSITY RESPONSE The University agrees with this finding and accepts the recommendation. Existing procedures are already in place to ensure that required reports are submitted. As indicated in the finding above, this was just a misunderstanding on the part of the employee submitting the report as there was no real property acquired from the Early Head Start grant funds. The University believes that this matter did not have a direct and material effect on the University’s compliance with federal requirements.
Federal Agency: U.S. Department of Education Federal Program Title: Student Financial Assistance Cluster Assistance Listing Number: 84.007, 84.033, 84.063 and 84.268 Award Period: July 1, 2022 to June 30, 2023 Type of Finding: Significant Deficiency in Internal Control over Compliance and Noncompliance Criteria or Specific Requirement: In accordance with 2 CFR 200.303, nonfederal entities must establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. Condition / Context: During our audit procedures, we noted that a formal documented review process was not available for the following areas at two of the District’s four colleges: R2T4 calculations (two colleges) Student award packaging (one college) Students selected for verification by the Department of Education (one college) Questioned Costs: None. Cause: The Colleges' Financial Aid Director positions were vacant in early 2022-23, resulting in an oversight. Effect: A lack of internal controls can result in noncompliance with provisions of the various programs within the Student Financial Assistance Cluster. Repeat Finding: See prior year finding 2022-002. Recommendation: We recommend the Colleges reinforce their review processes, monitor proper follow-up on audit findings, and review all activity level controls to ensure compliance with the various requirements of the Student Financial Assistance Cluster. Action taken in response to finding: The District continues to enlist the assistance of Huron and other vendors to assess our internal controls over financial aid federal awards. The district collaborates with external entities to engage in comprehensive training to district-wide staff involved in student financial aid processing. College FA staff are sent regular reminders to reconcile and perform R2T4 calculations. Management is actively recruiting to fill vacant positions in this area across the district. Planned completion date for corrective action plan: June 30, 2024.
Department of Treasury Passed through Equal Justice Wyoming and Wyoming Department of Family Services Federal Financial Assistance Listing #21.023 Emergency Rental Assistance Program Reporting Significant Deficiency in Internal Control Over Compliance Criteria: 2 CFR 200.303(a) establishes that the auditee must establish and maintain effective internal control over the federal award that provides assurance that the entity is managing the federal award in compliance with federal statutes, regulations, and conditions of the federal award. Condition: There was no evidence retained that the Medical Center’s compliance reports submitted to Equal Justice and Wyoming Department of Family Services (WDFS) were reviewed and approved prior to submission. Cause: The Medical Center did not have an internal control policy in place to ensure documented review and approval of the compliance and financial reports. Effect: The lack of adequate policies governing review and approval increases the risk that employees participating in the federal awards administration may not be able to detect and correct noncompliance in a timely manner. Questioned Costs: None reported. Context: A nonstatistical sample of 12 out of 32 reports were selected for detail testing and did not include evidence of a review by someone other than the preparer. Repeat Finding from Prior Years: No Recommendation: We recommend that the Medical Center enhance internal control policies to ensure that formal documentation of review and approval is obtained and retained. Views of Responsible Officials: Management agrees with the finding.
Department of Treasury Passed through Equal Justice Wyoming and Wyoming Department of Family Services Federal Financial Assistance Listing #21.023 Emergency Rental Assistance Program Activities Allowed or Unallowed and Allowable Costs/Costs Principles and Period of Performance Significant Deficiency in Internal Control Over Compliance Criteria: 2 CFR 200.303(a) establishes that the auditee must establish and maintain effective internal control over the federal award that provides assurance that the entity is managing the federal award in compliance with federal statutes, regulations, and conditions of the federal award. Condition: The Medical Center was not able to provide supporting invoices for two of the testing selections. An additional selection contained a keying error. Cause: The Medical Center did have an internal control policy in place to ensure proper review and approval of the supporting invoices but controls did not appear to be functioning properly. Effect: The lack of adequate policies governing review and approval of the specific invoices increase the risk that employees participating in the federal award administration may not be able to detect and correct noncompliance in a timely manner. Without this documentation, ineligible expenditures may be claimed under the program. Questioned Costs: None reported. Context: A nonstatistical sample of 62 was selected for detail testing. The Medical Center was not able to provide supporting invoices for two of the testing selections. An additional selection contained a keying error. Repeat Finding from Prior Years: No Recommendation: We recommend that the Medical Center enhance internal control policies to ensure that all support utilized for the program is retained within accounting records. We also recommend that the Medical Center enhance internal control policies to ensure future keying errors are identified during the review process. Views of Responsible Officials: Management agrees with the finding.
Criteria: The federal award program noted above is not subject to the Treasury-State Cash Management Improvement Act agreement and, as such, is subject to 2 CFR 200.305(b), which states: “The timing and amount of advance payments must be as close as is administratively feasible to the actual disbursements by the non-Federal entity for direct program or project costs and the proportionate share of any allowable indirect costs. The non-Federal entity must make timely payment to contractors in accordance with the contract provisions.” 2 CFR section 200.303 requires that non-federal entities receiving federal awards establish and maintain internal control over the federal awards that provides reasonable assurance that the non-federal entity is managing the federal awards in compliance with federal statutes, regulations, and the terms and conditions of the federal awards. The State of Hawaii, Department of Budget and Finance has determined and communicated in Finance Memorandum 20-02 that their standard for an “administratively feasible time period” was 21 calendar days. Condition: During the testing of the Department’s cash management procedures, it was determined that two out of sixty payments tested were not distributed within 21 days of the draw down of funds. For the items tested, the time elapsed between draw down and payment ranged to 28 to 57 days. Context: During the fiscal year ended June 30, 2023, the Department expended $8,398,791 (excluding food expenditures). Cause: The Department draws down federal funds that will be needed based on the expenditures that must be paid. However, since deposits must be posted prior to the processing of payments or disbursing of the funds, it is difficult for the Department to disburse federal funds in accordance with 2 CFR 200.305 (b). Also, the State’s payment process requires all State departments to process payments through DAGS resulting in processing delays. Effect: Noncompliance with federal regulations could result in a loss of funding that may jeopardize the operations of the Department’s federally funded programs. Questioned Costs: None Identification as a Repeat Finding, if applicable: See finding 2022-005 included in the Summary Schedule of Prior Audit Findings. Recommendation: We recommend that the Department work with DAGS and the Department of Budget and Finance to ensure compliance with established standard and timely disbursement of federal funds in accordance with 2 CFR 200.305(b). Views of Responsible Officials and Planned Corrective Action: See Part VI Correction Action Plan.
Reference Number: 2023-005 Federal Program Title: HIV Prevention Activities Health Department Based Federal Assistance Listing Number: 93.940 Federal Agency: U.S. Department of Health and Human Services Pass-Through Entity: N/A Federal Award Number and Year: 5 NU62PS924619-02-00, 5 NU62SP924619-03-00, 6 NU62PS924569-05-03; 6 NU62PS924569-05-04; 6 NU62PS924569-05-05; Fiscal Year 2022-23 Name of Department: Department of Public Health Category of Finding: Reporting Type of Finding: Material Weakness in Internal Control Over Compliance; Instance of Noncompliance Criteria In accordance with Title 2 U.S. Code of Federal Regulations (CFR) Part 170 – Reporting Subaward and Executive Compensation Information, Appendix A to Part 170 – Award Term, prime awardees awarded a Federal grant are required to file a Federal Funding Accountability and Transparency Act (FFATA) report by the end of the month following the month in which the prime awardee awards any sub-grant equal to or greater than $30,000. 2 CFR § 200.303 states that the non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition During our audit of the DPH’s compliance with the reporting requirement for the HIV Prevention Activities Health Department Based program, we noted that DPH submitted the FFATA reports for seven (7) subawards after the due date. See the Notes to the SEFA for chart/table. This is a repeat finding of 2022-010. Cause The program reported subaward agreements and modifications in December 2022 and at fiscal year-end in June 2023, rather than 30 days after when the subaward agreements or modifications occurred. Effect Failure to submit the FFATA reports results in noncompliance with the reporting requirements with 2 CFR Part 170. Questioned Costs Questioned costs were not identified. Context Ten (10) subawards requiring the submission of a FFATA report were selected for testing from a total population of 38 subrecipient awards, and FFATA reports were not submitted timely for seven (7) subawards. The sample was not a statistically valid sample. Recommendation We recommend that the DPH develop and document a process to identify, track and report all subaward agreements and modifications executed throughout the fiscal year and subject to FFATA reporting requirements.
Reference Number: 2023-005 Federal Program Title: HIV Prevention Activities Health Department Based Federal Assistance Listing Number: 93.940 Federal Agency: U.S. Department of Health and Human Services Pass-Through Entity: N/A Federal Award Number and Year: 5 NU62PS924619-02-00, 5 NU62SP924619-03-00, 6 NU62PS924569-05-03; 6 NU62PS924569-05-04; 6 NU62PS924569-05-05; Fiscal Year 2022-23 Name of Department: Department of Public Health Category of Finding: Reporting Type of Finding: Material Weakness in Internal Control Over Compliance; Instance of Noncompliance Criteria In accordance with Title 2 U.S. Code of Federal Regulations (CFR) Part 170 – Reporting Subaward and Executive Compensation Information, Appendix A to Part 170 – Award Term, prime awardees awarded a Federal grant are required to file a Federal Funding Accountability and Transparency Act (FFATA) report by the end of the month following the month in which the prime awardee awards any sub-grant equal to or greater than $30,000. 2 CFR § 200.303 states that the non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition During our audit of the DPH’s compliance with the reporting requirement for the HIV Prevention Activities Health Department Based program, we noted that DPH submitted the FFATA reports for seven (7) subawards after the due date. See the Notes to the SEFA for chart/table. This is a repeat finding of 2022-010. Cause The program reported subaward agreements and modifications in December 2022 and at fiscal year-end in June 2023, rather than 30 days after when the subaward agreements or modifications occurred. Effect Failure to submit the FFATA reports results in noncompliance with the reporting requirements with 2 CFR Part 170. Questioned Costs Questioned costs were not identified. Context Ten (10) subawards requiring the submission of a FFATA report were selected for testing from a total population of 38 subrecipient awards, and FFATA reports were not submitted timely for seven (7) subawards. The sample was not a statistically valid sample. Recommendation We recommend that the DPH develop and document a process to identify, track and report all subaward agreements and modifications executed throughout the fiscal year and subject to FFATA reporting requirements.