CORRECTIVE ACTION PLAN U.S. Department of Education | Arizona Department of Education Tuba City Unified School District No. 15 respectfully submits the following corrective action plan for the year ended June 30, 2025. Audit period: July 1, 2024 – June 30, 2025 The findings from the schedule of findings and questioned costs are discussed below. The findings are numbered consistently with the numbers assigned in the schedule. FINANCIAL STATEMENT FINDINGS 2025-001 INFORMATION TECHNOLOGY Type of Finding: Material Weakness in Internal Control Over Financial Reporting Condition/Context: The District did not establish internal control procedures over information technology systems to ensure proper protection of District and student data. The following control deficiencies were noted regarding the District’s information technology policies and procedures: • The District did not limit access within the District’s accounting software to only those areas in each employee’s job function. Several employees had full administrative access to the accounting software, including third-party consultants, without compensating manual controls. • The District did not have a formal written policy regarding system or software changes. • Data-sharing agreements with third party provides that had access to the District’s data were not provided. • Documentation was not provided to support that the IT systems generated electronic audit trail reports or change logs were being reviewed or analyzed. This would include systemgenerated incident or error reports. • Disaster recovery and contingency plans were not provided. Recommendation: To strengthen internal controls, the District should evaluate its procedures regarding information technology security. The District should review and establish IT policies and procedures to protect the District’s data, train employees, establish backup plans, disaster recover or contingency plans, and 3rd party security and data confidentiality agreements. System general irregularity reports, including incident or error reports should be reviewed on an ongoing basis. Corrective Action: The District will evaluate its procedures regarding information technology security. The District will review and establish IT policies and procedures to protect the District’s data, disaster recovery or contingency plans, and 3rd party security and data confidentiality agreements. Additionally, the District will review system generated irregularity reports, including incident or error reports on an ongoing basis. Planned completion date for corrective action plan: For the period ending June 30, 2026. Name of the contact person responsible for corrective action: Leah Begay, Business Manager