Finding 401563 (2022-009)

Material Weakness Repeat Finding
Requirement
N
Questioned Costs
-
Year
2022
Accepted
2024-06-24
Audit: 309593
Organization: Martin University (IN)

AI Summary

  • Core Issue: The University failed to conduct a required risk assessment under the Gramm-Leach-Bliley Act, leaving student financial aid information vulnerable.
  • Impacted Requirements: Internal controls over compliance with federal regulations, specifically regarding employee training, information systems, and safeguarding sensitive data.
  • Recommended Follow-Up: Engage a third party to complete the risk assessment and document safeguards for identified risks to ensure compliance.

Finding Text

2022-009: Special Tests and Provisions – The Gramm-Leach-Bliley Act (GLBA) Federal Agency: Department of Education Federal Program Title: Student Financial Aid Cluster Assistance Listing Number: 84.007, 84.033, 84.063, 84.268 Award Number and Year: P007A215801 (March 25, 2021 - August 31, 2027), P033A215801(July 1, 2021 - August 31, 2027), P063P213807(March 23, 2021 - August 31, 2027), P268K223807(January 1, 2021 - July 31, 2043) Award Period: July 1, 2021 – June 30, 2022 Type of Finding: Material Weakness in Internal Control Over Compliance, Other Matters Criteria or Specific Requirement: Internal Control – Per 2 CFR section 200.303(a), a non-Federal entity must: Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Compliance- The Gramm-Leach-Bliley Act (Public Law 106-102) requires financial institutions to explain their information-sharing practices to their customers and to safeguard sensitive data. (16 CFR 314) The Federal Trade Commission considers Title IV-eligible institutions that participate in Title IV Educational Assistance Programs as “financial institutions” and subject to the Gramm-Leach-Bliley Act (16 CFR 313.3(k)(2)(vi). Condition: Under an institution’s Program Participation Agreement with the Department of Education and the Gramm-Leach-Bliley Act, schools must protect student financial aid information, with particular attention to information provided to institutions by the Department or otherwise obtained in support of the administration of the federal student financial aid programs. Questioned Costs: None Context: During our audit procedures, it was noted that the University did not conduct a risk assessment that addresses (2) and (3) of the 3 areas noted in 16 CFR 314.4 (b) which are (1) Employee training and management; (2) Information systems, including network and software design, as well as information processing, storage, transmission and disposal; and (3) Detecting, preventing and responding to attacks, intrusions, or other systems failures and document safeguards for identified risks. Cause: The University experienced turnover in the department responsible for this process and had a ransomware cyber-attack during the year ended June 30, 2022. Effect: The student personal information could be vulnerable. Repeat Finding: Yes – 2021-002. Recommendation: We recommend the University engage a third party or perform the risk assessment for the two areas required by the Gramm-Leach-Bliley Act that have not been completed and documented and ensure that there are documented safeguards for identified risks. Views of Responsible Officials: There is no disagreement with the audit finding.

Corrective Action Plan

2022-009 Special Tests and Provisions – The Gramm-Leach-Bliley Act (GLBA) Student Financial Aid Cluster – Assistance Listing No. 84.007, 84.033, 84.063, 84.268 Recommendation: We recommend the University engage a third party or perform the risk assessment for the two areas required by the Gramm-Leach-Bliley Act that have not been completed and documented and ensure that there are documented safeguards for identified risks. Explanation of disagreement with audit finding: There is no disagreement with the audit finding. Action taken in response to finding: The University began engagement with AIS, an IT Managed Service Provider in May 2022 and hired a Director of IT in November 2023. The University is working with AIS and Cowbell to develop and implement a Cybersecurity policy, as well as to provide training for all employees, the Board of Governors, and students. The University has also deployed Cloud Storage backup solutions for all data. Name(s) of the contact person(s) responsible for corrective action: Scharvin Wilson, Director of IT, AIS, IT Managed Services Provider, E. ZeNai Savage, CPA, CFO and Executive VP of Finance and Administration Planned completion date for corrective action plan: June 30, 2024

Categories

Special Tests & Provisions Student Financial Aid Subrecipient Monitoring Material Weakness Matching / Level of Effort / Earmarking Internal Control / Segregation of Duties

Other Findings in this Audit

  • 401556 2022-001
    Material Weakness Repeat
  • 401557 2022-002
    Material Weakness
  • 401558 2022-003
    Significant Deficiency
  • 401559 2022-004
    Significant Deficiency
  • 401560 2022-005
    - Repeat
  • 401561 2022-006
    Significant Deficiency Repeat
  • 401562 2022-007
    Significant Deficiency
  • 401564 2022-001
    Material Weakness Repeat
  • 401565 2022-002
    Material Weakness
  • 401566 2022-003
    Significant Deficiency
  • 401567 2022-004
    Significant Deficiency
  • 401568 2022-005
    - Repeat
  • 401569 2022-006
    Significant Deficiency Repeat
  • 401570 2022-007
    Significant Deficiency
  • 401571 2022-009
    Material Weakness Repeat
  • 401572 2022-001
    Material Weakness Repeat
  • 401573 2022-002
    Material Weakness
  • 401574 2022-003
    Significant Deficiency
  • 401575 2022-004
    Significant Deficiency
  • 401576 2022-005
    - Repeat
  • 401577 2022-006
    Significant Deficiency Repeat
  • 401578 2022-007
    Significant Deficiency
  • 401579 2022-008
    Significant Deficiency
  • 401580 2022-009
    Material Weakness Repeat
  • 401581 2022-001
    Material Weakness Repeat
  • 401582 2022-002
    Material Weakness
  • 401583 2022-003
    Significant Deficiency
  • 401584 2022-004
    Significant Deficiency
  • 401585 2022-005
    - Repeat
  • 401586 2022-006
    Significant Deficiency Repeat
  • 401587 2022-007
    Significant Deficiency
  • 401588 2022-009
    Material Weakness Repeat
  • 401589 2022-001
    Material Weakness Repeat
  • 401590 2022-002
    Material Weakness
  • 401591 2022-010
    Material Weakness Repeat
  • 401592 2022-001
    Material Weakness Repeat
  • 401593 2022-002
    Material Weakness
  • 401594 2022-010
    Material Weakness Repeat
  • 977998 2022-001
    Material Weakness Repeat
  • 977999 2022-002
    Material Weakness
  • 978000 2022-003
    Significant Deficiency
  • 978001 2022-004
    Significant Deficiency
  • 978002 2022-005
    - Repeat
  • 978003 2022-006
    Significant Deficiency Repeat
  • 978004 2022-007
    Significant Deficiency
  • 978005 2022-009
    Material Weakness Repeat
  • 978006 2022-001
    Material Weakness Repeat
  • 978007 2022-002
    Material Weakness
  • 978008 2022-003
    Significant Deficiency
  • 978009 2022-004
    Significant Deficiency
  • 978010 2022-005
    - Repeat
  • 978011 2022-006
    Significant Deficiency Repeat
  • 978012 2022-007
    Significant Deficiency
  • 978013 2022-009
    Material Weakness Repeat
  • 978014 2022-001
    Material Weakness Repeat
  • 978015 2022-002
    Material Weakness
  • 978016 2022-003
    Significant Deficiency
  • 978017 2022-004
    Significant Deficiency
  • 978018 2022-005
    - Repeat
  • 978019 2022-006
    Significant Deficiency Repeat
  • 978020 2022-007
    Significant Deficiency
  • 978021 2022-008
    Significant Deficiency
  • 978022 2022-009
    Material Weakness Repeat
  • 978023 2022-001
    Material Weakness Repeat
  • 978024 2022-002
    Material Weakness
  • 978025 2022-003
    Significant Deficiency
  • 978026 2022-004
    Significant Deficiency
  • 978027 2022-005
    - Repeat
  • 978028 2022-006
    Significant Deficiency Repeat
  • 978029 2022-007
    Significant Deficiency
  • 978030 2022-009
    Material Weakness Repeat
  • 978031 2022-001
    Material Weakness Repeat
  • 978032 2022-002
    Material Weakness
  • 978033 2022-010
    Material Weakness Repeat
  • 978034 2022-001
    Material Weakness Repeat
  • 978035 2022-002
    Material Weakness
  • 978036 2022-010
    Material Weakness Repeat

Programs in Audit

ALN Program Name Expenditures
84.268 Federal Direct Student Loans $1.68M
84.063 Federal Pell Grant Program $591,188
84.425 Education Stabilization Fund $518,388
84.033 Federal Work-Study Program $32,104
84.007 Federal Supplemental Educational Opportunity Grants $27,919