Finding 621620 (2022-007)

Significant Deficiency
Requirement
N
Questioned Costs
-
Year
2022
Accepted
2023-03-29
Audit: 44253
Organization: Tabor College, Inc. (KS)

AI Summary

  • Core Issue: The College failed to conduct a required IT risk assessment under the Gramm-Leach-Bliley Act, leaving student financial aid information potentially vulnerable.
  • Impacted Requirements: The College did not address key areas such as employee training, information systems security, and response to security threats as mandated by the Act.
  • Recommended Follow-Up: Engage a third party or conduct an internal risk assessment to identify and document safeguards for the required areas of risk.

Finding Text

2022-007 Gramm-Leach-Bliley Act Federal Agency: U.S. Department of Education Federal Program Title: Student Financial Aid Cluster Assistance Listing Number: Various Award Period: July 1, 2021 to June 30, 2022 Type of Finding: - Significant Deficiency in Internal Control Over Compliance - Other Matters Criteria or specific requirement: The Gramm-Leach-Bliley Act (Public Law 106-102) requires financial institutions to explain their information-sharing practices to their customers and to safeguard sensitive data. (16 CFR 314) The Federal Trade Commission considers Title IV-eligible institutions that participate in Title IV Educational Assistance Programs as ?financial institutions? and subject to the Gramm-Leach-Bliley Act (16 CFR 313.3(k)(2)(vi). Condition: Under an institution?s Program Participation Agreement with the Department of Education and the Gramm-Leach-Bliley Act, schools must protect student financial aid information, with particular attention to information provided to institutions by the Department or otherwise obtained in support of the administration of the federal student financial aid programs. Questioned costs: None Context: During our audit procedures, it was noted that the College did not perform a risk assessment that addresses the three areas noted in 16 CFR 314.4 (b) which are (1) Employee training and management; (2) Information systems, including network and software design, as well as information processing, storage, transmission and disposal; and (3) Detecting, preventing and responding to attacks, intrusions, or other systems failures and document safeguards for identified risks. Cause: The organization did not perform an IT risk assessment tailored specifically to the organization, identify risks or address risks identified as required by the Gramm-Leach-Bliley Act. Effect: The student personal information could be vulnerable. Repeat Finding: No Recommendation: We recommend that the College engage a third party or perform the risk assessment for the three areas required by the Gramm-Leach-Bliley Act and ensure that there are documented safeguards for identified risks. Views of responsible officials: There is no disagreement with the audit finding.

Categories

Student Financial Aid Subrecipient Monitoring Significant Deficiency Internal Control / Segregation of Duties

Other Findings in this Audit

  • 45175 2022-002
    Significant Deficiency
  • 45176 2022-003
    Significant Deficiency
  • 45177 2022-004
    Significant Deficiency
  • 45178 2022-007
    Significant Deficiency
  • 45179 2022-002
    Significant Deficiency
  • 45180 2022-003
    Significant Deficiency
  • 45181 2022-004
    Significant Deficiency
  • 45182 2022-007
    Significant Deficiency
  • 45183 2022-002
    Significant Deficiency
  • 45184 2022-003
    Significant Deficiency
  • 45185 2022-004
    Significant Deficiency
  • 45186 2022-007
    Significant Deficiency
  • 45187 2022-002
    Significant Deficiency
  • 45188 2022-003
    Significant Deficiency
  • 45189 2022-004
    Significant Deficiency
  • 45190 2022-007
    Significant Deficiency
  • 45191 2022-002
    Significant Deficiency
  • 45192 2022-003
    Significant Deficiency
  • 45193 2022-004
    Significant Deficiency
  • 45194 2022-007
    Significant Deficiency
  • 45195 2022-005
    Significant Deficiency
  • 45196 2022-006
    Significant Deficiency
  • 45197 2022-005
    Significant Deficiency
  • 45198 2022-006
    Significant Deficiency
  • 621617 2022-002
    Significant Deficiency
  • 621618 2022-003
    Significant Deficiency
  • 621619 2022-004
    Significant Deficiency
  • 621621 2022-002
    Significant Deficiency
  • 621622 2022-003
    Significant Deficiency
  • 621623 2022-004
    Significant Deficiency
  • 621624 2022-007
    Significant Deficiency
  • 621625 2022-002
    Significant Deficiency
  • 621626 2022-003
    Significant Deficiency
  • 621627 2022-004
    Significant Deficiency
  • 621628 2022-007
    Significant Deficiency
  • 621629 2022-002
    Significant Deficiency
  • 621630 2022-003
    Significant Deficiency
  • 621631 2022-004
    Significant Deficiency
  • 621632 2022-007
    Significant Deficiency
  • 621633 2022-002
    Significant Deficiency
  • 621634 2022-003
    Significant Deficiency
  • 621635 2022-004
    Significant Deficiency
  • 621636 2022-007
    Significant Deficiency
  • 621637 2022-005
    Significant Deficiency
  • 621638 2022-006
    Significant Deficiency
  • 621639 2022-005
    Significant Deficiency
  • 621640 2022-006
    Significant Deficiency

Programs in Audit

ALN Program Name Expenditures
84.063 Federal Pell Grant Program $3.72M
84.268 Federal Direct Student Loans $1.10M
84.425E Heerf Student Aid Portion $882,282
84.038 Federal Perkins Loan Program $405,899
84.425F Heerf Institutional Portion $364,751
84.033 Federal Work-Study Program $104,379
84.007 Federal Supplemental Educational Opportunity Grants $85,765