Finding 1171926 (2024-012)

Material Weakness Repeat Finding
Requirement
P
Questioned Costs
-
Year
2024
Accepted
2026-02-02
Audit: 384963
Organization: Community Benefit Solutions (PA)

AI Summary

  • Core Issue: The CBS Food Program lacks sufficient internal controls over its QuickBooks accounting system, leading to a material weakness in compliance.
  • Impacted Requirements: Key areas affected include user access management, input management, change control management, and backup and recovery procedures.
  • Recommended Follow-Up: Develop comprehensive written policies for internal controls, including an Accounting Manual, access control measures, a change management policy, and a disaster recovery plan.

Finding Text

2024-012 Federal Agencies: U.S. Department of Agriculture Federal Program Names: The Child Nutrition Cluster: National School Lunch Program Summer Food Service Program Child and Adult Care Food Program Assistance Listing Numbers: 10.555 10.559 10.558 Pass-Through Agency: Commonwealth of Pennsylvania, Department of Education Pass-Through Number: 359-46-477-8 Award Period: July 1, 2023 through June 30, 2024 Type of Finding: • Material Weakness in Internal Control over Compliance Criteria: The United States Government Accountability Office's Standards for Internal Control in the Federal Government, commonly known as the "Green Book," sets standards for an effective internal control system and concepts of the Green Book can be applied to non-profit entities. Green Book Principle 11 - Design Activities for the Information System, section 11.01 states, in part: Management should design the entity's information system and related control activities to achieve objectives and respond to risks. The following attributes contribute to the design, implementation, and operating effectiveness of this principle: • Design of the Entity's Information System • Design of Appropriate Types of Control Activities • Design of Information Technology Infrastructure • Design of Security Management • Design of Information Technology Acquisition, Development, and Maintenance Condition: Based on the Commonwealth of Pennsylvania, Office of the Budget, Bureau of Audits (Commonwealth) review of CBS Food Program's financial accounting system, it was noted that the Food Program utilizes QuickBooks software for their accounting system. Based on inquiry with CBS Food Program management, we determined internal controls connected with their QuickBooks accounting software were insufficient in the following areas: • User Access Management: Formal written policies or procedures have not been developed and implemented related to access authorization, access monitoring, and removal of system access. Additionally, certain functions are not properly segregated as users have access to perform both input and authorization of transactions. • Input Management: Formal written policies or procedures to ensure information input into QuickBooks is appropriate and accurate have not been developed and implemented. • Change Control Management: A formal written change management policy for QuickBooks Accounting System has not been developed and implemented including requirements that system security updates are implemented timely. • Backup and Recovery: A formal written policy for regular backup and recovery testing has not been developed and implemented. Questioned Costs: None Cause: The CBS Food Program's lack of policies and procedures over QuickBooks may be due to inadequate resources, insufficient information technology governance, and/or a lack of awareness of information technology control requirements. Additionally, the CBS Food Program management may not place adequate focus on enforcing information technology control measures as part of the overall control environment. Effect: The lack of established and documented controls over QuickBooks increases the risk of unauthorized access, system disruption, and data loss. Additionally, without a written disaster recovery plan the Food Program is exposed to increased risks of prolonged downtime in the event of a disaster or system failure. These weaknesses may compromise the confidentiality, integrity, and availability of critical data. Recommendation: We recommend that CBS Food Program develop and implement comprehensive written internal control policies and procedures connected with their QuickBooks Accounting System. This should include: • Development and utilization of an Accounting Manual which includes an outline of CBS Food Program's accounting rules, procedures, and guidelines. • Access control policies and procedures to ensure that user access to QuickBooks is appropriate, regularly reviewed and promptly revoked upon termination or when otherwise merited. • A formal written change management policy for QuickBooks should be developed and implemented including requirements that systems security updates are implemented timely. • A disaster recovery plan and procedures to perform periodic testing to ensure that plans are functional and mitigate the risk of extended downtime. This process should also include regular review of backup records to ensure they are appropriately created and maintained. Views of Responsible Officers and Corrective Action Plan: Please refer to Community Benefit Solutions dba CBS Food Program’s Corrective Action Plan.

Corrective Action Plan

2024-012 Material Weakness in Internal Control over Compliance The Child Nutrition Cluster: 10.555 – National School Lunch Program and 10.559 – Summer Food Service Program 10.558 – Child and Adult Care Food Program Commonwealth of Pennsylvania, Department of Education Contract Number: 359-46-477-8 Condition: Based on the Commonwealth of Pennsylvania, Office of the Budget, Bureau of Audits (Commonwealth) review of CBS Food Program's financial accounting system, it was noted that the Food Program utilizes QuickBooks software for their accounting system. Based on inquiry with CBS Food Program management, we determined internal controls connected with their QuickBooks accounting software were insufficient in the following areas: • User Access Management: Formal written policies or procedures have not been developed and implemented related to access authorization, access monitoring, and removal of system access. Additionally, certain functions are not properly segregated as users have access to perform both input and authorization of transactions. • Input Management: Formal written policies or procedures to ensure information input into QuickBooks is appropriate and accurate have not been developed and implemented. • Change Control Management: A formal written change management policy for QuickBooks Accounting System has not been developed and implemented including requirements that system security updates are implemented timely. • Backup and Recovery: A formal written policy for regular backup and recovery testing has not been developed and implemented. Recommendation: We recommend that CBS Food Program develop and implement comprehensive written internal control policies and procedures connected with their QuickBooks Accounting System. This should include: • Development and utilization of an Accounting Manual which includes an outline of CBS Food Program's accounting rules, procedures, and guidelines. • Access control policies and procedures to ensure that user access to QuickBooks is appropriate, regularly reviewed and promptly revoked upon termination or when otherwise merited. Recommendation (Continued) • A formal written change management policy for QuickBooks should be developed and implemented including requirements that systems security updates are implemented timely. • A disaster recovery plan and procedures to perform periodic testing to ensure that plans are functional and mitigate the risk of extended downtime. This process should also include regular review of backup records to ensure they are appropriately created and maintained. Repeat Finding: No Explanation of Disagreement with Audit Finding There is no disagreement with the audit finding. Action taken in response to finding: Community Benefit Solutions does not dispute this finding. Community Benefit Solutions will migrate from Quickbooks Desktop to Quickbooks Online, which will provide a perfect transitional opportunity to re-evaluate processes, and to develop and implement necessary controls over its systems. Community Benefit Solutions will work with independent auditors, internal information technology team, and, if necessary, legal counsel to plan, draft, and implement the relevant internal controls. Planned completion date for corrective action plan: June 30, 2025

Categories

School Nutrition Programs Internal Control / Segregation of Duties Subrecipient Monitoring Material Weakness

Other Findings in this Audit

  • 1171903 2024-004
    Material Weakness Repeat
  • 1171904 2024-006
    Material Weakness Repeat
  • 1171905 2024-007
    Material Weakness Repeat
  • 1171906 2024-008
    Material Weakness Repeat
  • 1171907 2024-009
    Material Weakness Repeat
  • 1171908 2024-010
    Material Weakness Repeat
  • 1171909 2024-011
    Material Weakness Repeat
  • 1171910 2024-012
    Material Weakness Repeat
  • 1171911 2024-004
    Material Weakness Repeat
  • 1171912 2024-006
    Material Weakness Repeat
  • 1171913 2024-007
    Material Weakness Repeat
  • 1171914 2024-008
    Material Weakness Repeat
  • 1171915 2024-009
    Material Weakness Repeat
  • 1171916 2024-010
    Material Weakness Repeat
  • 1171917 2024-011
    Material Weakness Repeat
  • 1171918 2024-012
    Material Weakness Repeat
  • 1171919 2024-004
    Material Weakness Repeat
  • 1171920 2024-005
    Material Weakness Repeat
  • 1171921 2024-006
    Material Weakness Repeat
  • 1171922 2024-007
    Material Weakness Repeat
  • 1171923 2024-009
    Material Weakness Repeat
  • 1171924 2024-010
    Material Weakness Repeat
  • 1171925 2024-011
    Material Weakness Repeat

Programs in Audit

ALN Program Name Expenditures
10.558 CHILD AND ADULT CARE FOOD PROGRAM $5.69M
10.555 NATIONAL SCHOOL LUNCH PROGRAM $780,169
10.559 SUMMER FOOD SERVICE PROGRAM FOR CHILDREN $16,260