EIN: 010275130
UEI: CKWYMFNCG798
Audited by: BDMP Assurance, LLP
Cognizant agency: 84 [Department of Education]
View federal awards & risk assessment →
Data as of August 28, 2026
Management decision deadline — for entities that funded this organization
The FAC accepted this audit on February 18, 2026. Under 2 CFR 200.521(d), a pass-through entity that provided federal funds to this organization for this audit period must issue a management decision on these findings by August 18, 2026 (11 days ago).
What is a management decision? →FAC accepted this audit on February 28, 2025 — management decision was due August 28, 2025.
FAC accepted this audit on December 14, 2023 — management decision was due June 14, 2024.
Programs Affected U.S. Department of Education—Student Financial Assistance Cluster, AL 84.063, 84.007, 84.033, and 84.268—Award Year July 1, 2022—June 30, 2023. Criteria According to 34 CFR section 668.22, a school is required to determine the earned and unearned portions of Title IV aid as of the date the student ceased attendance based on the amount of time the student is in attendance or, in the case of a clock-hour program, was scheduled to be in attendance. 34 CFR Section 668.2 (f)(2)(i) further states the total number of calendar days in a payment period or period of enrollment includes all days within the period that the student was scheduled to complete. Condition While testing the return of Title IV funds, a nonstatistical sample of 25 students was tested for proper return calculations. During the testing, we noted 1 of 25 calculations were incorrectly calculated. We noted this did not result in additional funds to be returned. Cause This occurred during a time of low staffing in the student financial aid office and high volume of activity. While the calculation was performed by one individual and reviewed by a second individual, the review did not identify the miscalculation. While, the calculation of total days was miscalculated, the percentage earned and unearned by Title IV student that withdrew did not significantly change. As a result, there was no financial impact. Questioned Costs None. Effect Without effective review, students withdrawing could have improper calculations of aid earned and unearned due to the miscalculated total number of days. Recommendation We recommend additional emphasis be placed on the reviewer function within the return of title funds process, to timely identify errors, even in times of staffing shortages. Views of Responsible Officials and Corrective Action Plan Management agrees with the finding. See attached Corrective Action Plan.
Show full finding ▾Hide full finding ▴Programs Affected U.S. Department of Education—Student Financial Assistance Cluster, AL 84.063, 84.007, 84.033, and 84.268—Award Year July 1, 2022—June 30, 2023. Criteria According to 34 CFR section 668.22, a school is required to determine the earned and unearned portions of Title IV aid as of the date the student ceased attendance based on the amount of time the student is in attendance or, in the case of a clock-hour program, was scheduled to be in attendance. 34 CFR Section 668.2 (f)(2)(i) further states the total number of calendar days in a payment period or period of enrollment includes all days within the period that the student was scheduled to complete. Condition While testing the return of Title IV funds, a nonstatistical sample of 25 students was tested for proper return calculations. During the testing, we noted 1 of 25 calculations were incorrectly calculated. We noted this did not result in additional funds to be returned. Cause This occurred during a time of low staffing in the student financial aid office and high volume of activity. While the calculation was performed by one individual and reviewed by a second individual, the review did not identify the miscalculation. While, the calculation of total days was miscalculated, the percentage earned and unearned by Title IV student that withdrew did not significantly change. As a result, there was no financial impact. Questioned Costs None. Effect Without effective review, students withdrawing could have improper calculations of aid earned and unearned due to the miscalculated total number of days. Recommendation We recommend additional emphasis be placed on the reviewer function within the return of title funds process, to timely identify errors, even in times of staffing shortages. Views of Responsible Officials and Corrective Action Plan Management agrees with the finding. See attached Corrective Action Plan.
Finding 2023-001 Correcve Acon Plan This is a response to Finding 2023-001 listed in the Schedule of Findings and Quesoned Costs for Federal Awards. Unity Environmental University agrees with this finding and has taken the following correcve acons to prevent recurrence of such findings. While tesng the return of Title IV funds, a nonstascal sample of 25 students was tested for proper return calculaons. During the tesng, 1 of 25 calculaons were incorrectly calculated. The error did not result in addional funds to be returned. The student in queson had aended one module of two in the graduate program payment period. When the recalculaon was performed, the full payment period was used. The student had earned 100% of aid due to compleng 60% of the period. The error was not caught by the second reviewer. This occurred during a me of low staffing in the financial aid office and a high volume of acvity. The calculaon was corrected but no addional funds needed to be returned as the student sll earned 100% of aid due to compleng 60% of the module. In an abundance of cauon, the financial aid staff reviewed R2T4 calculaons completed for all graduate students. No addional errors were found. The financial aid staff met to discuss the finding and management emphasized the impact to the student and instuon when these errors occur. We believe this was an isolated incident and the staff understands the importance of the second reviewer role to avoid such errors. Responsible Person: Sherry Watson Correction Date: 06/27/23
FAC accepted this audit on March 5, 2023 — management decision was due September 5, 2023.
Program(s) Affected Student Financial Assistance Cluster-Award Year, AL 84.063, 84.007, 84.033, and 84.268, July 1, 2021 ? June 30, 2022 Criteria Federal regulations 34 CFR 685.309 and 34 CFR 682.610 require institutions to report to National Students Loan Data System (NSLDS) changes to a student?s enrollment status to less than half-time within 60 days of the date the school discovered that a student has ceased to be enrolled, or has failed to enroll, at least half-time. This date is also commonly referred to as the ?date of determination.? This date may be the same as the status effective date, which is the date the enrollment status became effective. Condition and Context During our testing of reporting to NSLDS for change in enrollment status, of our nonstatistical sample of 28 students, we noted that 2 student status changes were not reported timely. Questioned Costs None noted. Cause and Effect The College?s process for updating student status changes requires that an Integrated Enrollment Service staff run a report of students to be reported. This report is provided to the Registrar?s Office for review. There was a breakdown in this process during the year that resulted in a delay of notification of status changes to the NSLDS. Identification as a Repeat Finding, if Applicable Yes, 2021-003 Recommendation We recommend modifying the business office procedures and adding a level of review on a monthly basis to confirm accurate and timely submissions. Views of Responsible Officials and Planned Corrective Actions Management agrees with the finding. See attached Corrective Action Plan.
Show full finding ▾Hide full finding ▴Program(s) Affected Student Financial Assistance Cluster-Award Year, AL 84.063, 84.007, 84.033, and 84.268, July 1, 2021 ? June 30, 2022 Criteria Federal regulations 34 CFR 685.309 and 34 CFR 682.610 require institutions to report to National Students Loan Data System (NSLDS) changes to a student?s enrollment status to less than half-time within 60 days of the date the school discovered that a student has ceased to be enrolled, or has failed to enroll, at least half-time. This date is also commonly referred to as the ?date of determination.? This date may be the same as the status effective date, which is the date the enrollment status became effective. Condition and Context During our testing of reporting to NSLDS for change in enrollment status, of our nonstatistical sample of 28 students, we noted that 2 student status changes were not reported timely. Questioned Costs None noted. Cause and Effect The College?s process for updating student status changes requires that an Integrated Enrollment Service staff run a report of students to be reported. This report is provided to the Registrar?s Office for review. There was a breakdown in this process during the year that resulted in a delay of notification of status changes to the NSLDS. Identification as a Repeat Finding, if Applicable Yes, 2021-003 Recommendation We recommend modifying the business office procedures and adding a level of review on a monthly basis to confirm accurate and timely submissions. Views of Responsible Officials and Planned Corrective Actions Management agrees with the finding. See attached Corrective Action Plan.
Finding 2022-001 Corrective Action Plan The Business Office has hired a Director of Internal Controls to ensure this task is done timely and a Bookkeeper to assist in the reconciliation process. Drawdowns were made and posted to students accounts in a timely manner and in accordance with all laws and regulations. The Business Office, Bursars Office, and Student Financial Services will meet monthly to reconcile the drawdowns. Drawdown reconciliations are current. Anticipated Date of Correction 10/1/22 Responsible Person: Tom Dressler Finding 2022-002 Corrective Action Plan This is a response to finding 2022-002 listed in the Schedule of Findings and Questioned Costs for Federal Awards. Unity College agrees with this finding and has made the following corrective actions to prevent recurrence of such findings. Due to staff openings and implementation of a new student information system (SIS), the internal NSC audit from Registrar's Office was delayed. Students were missed in the CAMS report for the initial Grads Only submission to NSC. The delay in reporting was further compounded with degree conferral at only three times per year and the May conferral date being several weeks after the last day of the most recent term in May. While the last day of term is May 8, 2022, for the affected students, conferral of degrees was not until May 21, 2022, inflating the days between effective date and the reporting date. Moving forward, a new policy was created by which degrees will be conferred to students (given that they have applied) within two weeks of the end of their final term. This will then be reported to NSC within the 60-day window following the students' final term. Anticipated Date of Correction 7/1/22 Responsible Person: Kerry Hafford
2021-003
FAC accepted this audit on March 3, 2022 — management decision was due September 3, 2022.
Program(s) Affected Student Financial Assistance Cluster-Award Year, AL 84.063, 84.007, 84.033, and 84.268, July 1, 2020 ? June 30, 2021 Criteria Federal regulations 34 CFR 685.309 and 34 CFR 682.610 require institutions to report to National Students Loan Data System (NSLDS) changes to a student?s enrollment status to less than half-time within 60 days of the date the school discovered that a student has ceased to be enrolled, or has failed to enroll, at least half-time. This date is also commonly referred to as the ?date of determination.? This date may be the same as the status effective date, which is the date the enrollment status became effective. Condition and Context During our testing of reporting to NSLDS for change in enrollment status of 25 students selected from a statistically valid sample, we noted that 4 students who had a change in status had not yet been reported, while 10 were not reported timely. Questioned Costs None. Cause and Effect The College?s process for updating student status changes requires that an Integrated Enrollment Service staff run a report of students to be reported. This report is provided to the Registrar?s Office for review. During the 2020-2021 school year, the Registrar?s Office identified 30 students that were missed in the report. The Integrated Enrollment Service staff were notified, however, the data file had been returned to NSLDS before these status changes were added. This results in a delay in notification of status changes to the NSLDS. Identification as a Repeat Finding, if Applicable None. Recommendation We recommend modifying the business procedures and add a level of review on a monthly basis to confirm accurate and timely submissions. Views of Responsible Officials and Planned Corrective Actions Management agrees with the finding. See attached Corrective Action Plan.
Show full finding ▾Hide full finding ▴Program(s) Affected Student Financial Assistance Cluster-Award Year, AL 84.063, 84.007, 84.033, and 84.268, July 1, 2020 ? June 30, 2021 Criteria Federal regulations 34 CFR 685.309 and 34 CFR 682.610 require institutions to report to National Students Loan Data System (NSLDS) changes to a student?s enrollment status to less than half-time within 60 days of the date the school discovered that a student has ceased to be enrolled, or has failed to enroll, at least half-time. This date is also commonly referred to as the ?date of determination.? This date may be the same as the status effective date, which is the date the enrollment status became effective. Condition and Context During our testing of reporting to NSLDS for change in enrollment status of 25 students selected from a statistically valid sample, we noted that 4 students who had a change in status had not yet been reported, while 10 were not reported timely. Questioned Costs None. Cause and Effect The College?s process for updating student status changes requires that an Integrated Enrollment Service staff run a report of students to be reported. This report is provided to the Registrar?s Office for review. During the 2020-2021 school year, the Registrar?s Office identified 30 students that were missed in the report. The Integrated Enrollment Service staff were notified, however, the data file had been returned to NSLDS before these status changes were added. This results in a delay in notification of status changes to the NSLDS. Identification as a Repeat Finding, if Applicable None. Recommendation We recommend modifying the business procedures and add a level of review on a monthly basis to confirm accurate and timely submissions. Views of Responsible Officials and Planned Corrective Actions Management agrees with the finding. See attached Corrective Action Plan.
Of the 25 students reviewed 2 were missed in graduation reporting. From a thorough review of the students, we determined that several students were not picked up by our software report. The process requires that an Integrated Enrollment Service staff person runs the report of students required to be reported. This list is provided to the Registrar?s Office for review. The Registrar?s Office identified 30 students that were missed in the report. The Integrated Enrollment Service staff person was notified. Unfortunately, the staff person sent the file before adding the students. We are in the process of updating these students. In future, Unity College will train the Integrated Enrollment Services staff person on how to add students to the report. The final Graduation report will be reviewed by the Registrar?s Office prior to submission to ensure all students are included. Anticipated Date of Correction: 7/1/21 Responsible Person: Kerry Hafford
Program(s) Affected Student Financial Assistance Cluster-Award Year, AL 84.063, 84.007, 84.033, and 84.268, July 1, 2020 ? June 30, 2021 Criteria 34 CFR 668.22 ? (1) an institution must return the amount of title IV funds for which it is responsible under paragraph (g) of this section as soon as possible, but no later than 45 days after the date of the institution?s determination that the student withdrew as defined in paragraph (I)(3) of this section. Condition and Context During our testing of refund calculations, we noted one of 25 students from a statistically valid sample who did not have funds appropriately refunded. Questioned Costs None. Cause and Effect The College has a process to perform the calculation, review it, and send a letter and invoice to the student following the calculation. In this instance, the invoice was omitted from the package. This appears to be an isolated incident caused by human error or oversight. Identification as a Repeat Finding, if Applicable None. Recommendation We recommend the College include a step of review following the calculation and prior to sending the new letter and invoice to the student. Views of Responsible Officials and Planned Corrective Actions Management agrees with the finding. See attached Corrective Action Plan
Show full finding ▾Hide full finding ▴Program(s) Affected Student Financial Assistance Cluster-Award Year, AL 84.063, 84.007, 84.033, and 84.268, July 1, 2020 ? June 30, 2021 Criteria 34 CFR 668.22 ? (1) an institution must return the amount of title IV funds for which it is responsible under paragraph (g) of this section as soon as possible, but no later than 45 days after the date of the institution?s determination that the student withdrew as defined in paragraph (I)(3) of this section. Condition and Context During our testing of refund calculations, we noted one of 25 students from a statistically valid sample who did not have funds appropriately refunded. Questioned Costs None. Cause and Effect The College has a process to perform the calculation, review it, and send a letter and invoice to the student following the calculation. In this instance, the invoice was omitted from the package. This appears to be an isolated incident caused by human error or oversight. Identification as a Repeat Finding, if Applicable None. Recommendation We recommend the College include a step of review following the calculation and prior to sending the new letter and invoice to the student. Views of Responsible Officials and Planned Corrective Actions Management agrees with the finding. See attached Corrective Action Plan
As part of Unity College?s Return to Title IV process, we have one staff person complete the R2T4. Once completed, the staff person who completed the R2T4 gives the completed calculations and documentation to another staff person for secondary review. Unfortunately, a new staff person missed a recalculation amount of Pell Grant to return. Despite the review of the second staff person, the Pell Grant retraction of the student portion was missed. To ensure this issue does not occur in the future, the Student Financial Services team met to discuss the error. We preformed additional training regarding the return of the student?s portion of the Pell Grant that needed to be returned. We are confident that this additional training will eliminate any chance of this finding occurring in the future. Anticipated Date of Correction: 7/1/21 Responsible Person: Sherry L. Watson
Program(s) Affected Student Financial Assistance Cluster-Award Year, AL 84.063, 84.007, 84.033, and 84.268, July 1, 2020 ? June 30, 2021 Criteria The Gramm-Leach-Bliley Act (Public Law 106-102) (GLBA) requires financial institutions to explain their information-sharing practices with their customers to safeguard sensitive data (16 CFR 314). Higher education institutions are subject to GLBA. Schools must protect student financial information, with particular attention to information provided to institutions by the Department of Education or otherwise obtained in support of the administration of student financial aid programs. Under the Uniform Guidance, the College is required to designate an individual to coordinate the information security program and perform a risk assessment that addresses the required areas noted in 16 CFR 314.4(b) which are 1) employee training and management; 2) information systems, including network and software design, as well as information processing, storage, transmission, and disposal; and 3) detecting, preventing, and responding to attacks, intrusions, or other system failures. Further, the College must document safeguards for each of the identified risks. Condition and Context We noted that, as of June 30, 2021, while an individual had been tasked with coordinating the information security program, the internal policy had not been updated to reflect GLBA requirements. In addition, the College has not yet formally documented a risk assessment that addresses the required areas noted in 16 CFR 314.4(b) 1) and 3). Questioned Costs None. Cause and Effect While the College is aware of the GLBA requirements, and undertook risk assessment work during the year, there was turnover in key positions involved in the risk assessment process leading to a delay in its completion. Without a completed risk assessment, the College may not maintain adequate safeguards to protect student financial information in compliance with GLBA. Identification as a Repeat Finding, if Applicable Yes, Finding 2020-008. Recommendation We recommend the College complete the required risk assessment and documentation of steps taken in compliance with GLBA. Views of Responsible Officials and Planned Corrective Actions Management agrees with the finding. See attached Corrective Action Plan
Show full finding ▾Hide full finding ▴Program(s) Affected Student Financial Assistance Cluster-Award Year, AL 84.063, 84.007, 84.033, and 84.268, July 1, 2020 ? June 30, 2021 Criteria The Gramm-Leach-Bliley Act (Public Law 106-102) (GLBA) requires financial institutions to explain their information-sharing practices with their customers to safeguard sensitive data (16 CFR 314). Higher education institutions are subject to GLBA. Schools must protect student financial information, with particular attention to information provided to institutions by the Department of Education or otherwise obtained in support of the administration of student financial aid programs. Under the Uniform Guidance, the College is required to designate an individual to coordinate the information security program and perform a risk assessment that addresses the required areas noted in 16 CFR 314.4(b) which are 1) employee training and management; 2) information systems, including network and software design, as well as information processing, storage, transmission, and disposal; and 3) detecting, preventing, and responding to attacks, intrusions, or other system failures. Further, the College must document safeguards for each of the identified risks. Condition and Context We noted that, as of June 30, 2021, while an individual had been tasked with coordinating the information security program, the internal policy had not been updated to reflect GLBA requirements. In addition, the College has not yet formally documented a risk assessment that addresses the required areas noted in 16 CFR 314.4(b) 1) and 3). Questioned Costs None. Cause and Effect While the College is aware of the GLBA requirements, and undertook risk assessment work during the year, there was turnover in key positions involved in the risk assessment process leading to a delay in its completion. Without a completed risk assessment, the College may not maintain adequate safeguards to protect student financial information in compliance with GLBA. Identification as a Repeat Finding, if Applicable Yes, Finding 2020-008. Recommendation We recommend the College complete the required risk assessment and documentation of steps taken in compliance with GLBA. Views of Responsible Officials and Planned Corrective Actions Management agrees with the finding. See attached Corrective Action Plan
The Director of IT, under the President of the Enterprise, will be responsible for conducting risk assessment related to information systems, network, software design, info processing, info storage, and info transmission and proper disposal. The Director of IT will likewise be tasked with safeguarding Unity College proprietary data and student financial information from intrusion, attack, and system failure. Documents related to these safeguards will be kept on file and meet GLBA requirements. Anticipated Date of Correction: 6/30/22 Responsible Person: Charles Bellantoni
2020-008
FAC accepted this audit on May 12, 2021 — management decision was due November 12, 2021.
Program(s) Affected Student Financial Assistance Cluster, CFDA 84.063, 84.007, 84.033, 84.038, and 84.268, Award Year July 1, 2019 ? June 30, 2020. Criteria 2CFR 200.303 provides that ?The non-Federal entity must: ... establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award? as well as ?evaluate and monitor the non-Federal entity's compliance with statutes, regulations, and the terms and conditions of Federal awards.? Condition and Context During testing, we noted that, while management indicated a review process is in place for return of Title IV refund calculations (R2T4), documentation is not available to provide evidence the secondary review of the R2T4 calculations took place. Questioned Costs None. Cause and Effect Due to a transition in roles within the Financial Aid office, this procedure was not occurring in line with the review policy. Without a documented secondary review, errors may be made in the calculation, resulting in improper return of Title IV funds. Recommendation We recommend that the College update its processes to include a documented secondary review of each R2T4 calculation. Views of Responsible Officials and Planned Corrective Actions Management agrees with the finding. See attached Corrective Action Plan.
Show full finding ▾Hide full finding ▴Program(s) Affected Student Financial Assistance Cluster, CFDA 84.063, 84.007, 84.033, 84.038, and 84.268, Award Year July 1, 2019 ? June 30, 2020. Criteria 2CFR 200.303 provides that ?The non-Federal entity must: ... establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award? as well as ?evaluate and monitor the non-Federal entity's compliance with statutes, regulations, and the terms and conditions of Federal awards.? Condition and Context During testing, we noted that, while management indicated a review process is in place for return of Title IV refund calculations (R2T4), documentation is not available to provide evidence the secondary review of the R2T4 calculations took place. Questioned Costs None. Cause and Effect Due to a transition in roles within the Financial Aid office, this procedure was not occurring in line with the review policy. Without a documented secondary review, errors may be made in the calculation, resulting in improper return of Title IV funds. Recommendation We recommend that the College update its processes to include a documented secondary review of each R2T4 calculation. Views of Responsible Officials and Planned Corrective Actions Management agrees with the finding. See attached Corrective Action Plan.
Finding #2020-007 2CFR 200.303 provides that ?The non-Federal entity must: ... establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award? as well as ?evaluate and monitor the non-Federal entity's compliance with statutes, regulations, and the terms and conditions of Federal awards.? While management indicated a review process is in place for the return of Title IV refund calculations (R2T4), documentation is not available to provide evidence the secondary review of the R2T4 calculations took place. Response provided by Student Financial Services: As part of Unity College?s Return to Title IV process, we have one staff person complete the R2T4. Once completed, the staff person who completed the R2T4 gives the completed calculations and documentation to another staff person for secondary review. Although the review was complete, we could not show evidence of a secondary review. To ensure this issue does not occur in the future, we have created a process that requires the person who completes the second review to document this review in the PowerFAIDS system and on the printed R2T4 documents. As this finding was discussed at the site visit, Unity College immediately instituted the new procedure with the next R2T4 calculations processed. Corrective action completion date: August 1, 2020 Responsible Parties: Sherry Watson, Student Financial Services
Program(s) Affected Student Financial Assistance Cluster-Award Year, CFDA 84.063, 84.007, 84.033, 84.038, and 84.268, July 1, 2019 ? June 30, 2020 Criteria The Gramm-Leach-Bliley Act (Public Law 106-102) (GLBA) requires financial institutions to explain their information-sharing practices with their customers to safeguard sensitive data (16 CFR 314). Higher education institutions are subject to GLBA. Schools must protect student financial information, with particular attention to information provided to institutions by the Department of Education or otherwise obtained in support of the administration of student financial aid programs. Under the Uniform Guidance, the College is required to designate an individual to coordinate the information security program and perform a risk assessment that addresses the required areas noted in 16 CFR 314.4(b) which are 1) employee training and management; 2) information systems, including network and software design, as well as information processing, storage, transmission and disposal; and 3) detecting, preventing and responding to attacks, intrusions or other system failures. Further, the College must document safeguards for each of the identified risks. Condition and Context We noted that, as of June 30, 2020, an individual had not been tasked with coordinating the information security program and the internal policy has been updated to reflect GLBA requirements. In addition, the College has not yet formally documented a risk assessment that addresses the required areas noted in 16 CFR 314.4(b) 1) and 3). Questioned Costs None. Cause and Effect While the College is aware of the GLBA requirements, and undertook risk assessment work during the year, there was turnover in key positions involved in the risk assessment process leading to a delay in its completion. Without a completed risk assessment, the College may not maintain adequate safeguards to protect student financial information in compliance with GLBA. Identification as a Repeat Finding, if Applicable Yes, Finding 2019-004 Recommendation We recommend the College complete the required risk assessment and documentation of steps taken in compliance with GLBA. Views of Responsible Officials and Planned Corrective Actions Management agrees with the finding. See attached Corrective Action Plan.
Show full finding ▾Hide full finding ▴Program(s) Affected Student Financial Assistance Cluster-Award Year, CFDA 84.063, 84.007, 84.033, 84.038, and 84.268, July 1, 2019 ? June 30, 2020 Criteria The Gramm-Leach-Bliley Act (Public Law 106-102) (GLBA) requires financial institutions to explain their information-sharing practices with their customers to safeguard sensitive data (16 CFR 314). Higher education institutions are subject to GLBA. Schools must protect student financial information, with particular attention to information provided to institutions by the Department of Education or otherwise obtained in support of the administration of student financial aid programs. Under the Uniform Guidance, the College is required to designate an individual to coordinate the information security program and perform a risk assessment that addresses the required areas noted in 16 CFR 314.4(b) which are 1) employee training and management; 2) information systems, including network and software design, as well as information processing, storage, transmission and disposal; and 3) detecting, preventing and responding to attacks, intrusions or other system failures. Further, the College must document safeguards for each of the identified risks. Condition and Context We noted that, as of June 30, 2020, an individual had not been tasked with coordinating the information security program and the internal policy has been updated to reflect GLBA requirements. In addition, the College has not yet formally documented a risk assessment that addresses the required areas noted in 16 CFR 314.4(b) 1) and 3). Questioned Costs None. Cause and Effect While the College is aware of the GLBA requirements, and undertook risk assessment work during the year, there was turnover in key positions involved in the risk assessment process leading to a delay in its completion. Without a completed risk assessment, the College may not maintain adequate safeguards to protect student financial information in compliance with GLBA. Identification as a Repeat Finding, if Applicable Yes, Finding 2019-004 Recommendation We recommend the College complete the required risk assessment and documentation of steps taken in compliance with GLBA. Views of Responsible Officials and Planned Corrective Actions Management agrees with the finding. See attached Corrective Action Plan.
Finding #2020-008 The Gramm-Leach-Bliley Act (Public Law 106-102) (GLBA) requires financial institutions to explain their information-sharing practices with their customers to safeguard sensitive data (16 CFR 314). Higher education institutions are subject to GLBA. Schools must protect student financial information, with particular attention to information provided to institutions by the Department of Education or otherwise obtained in support of the administration of student financial aid programs. Under the Uniform Guidance, the College is required to designate an individual to coordinate the information security program and perform a risk assessment that addresses the required areas noted in 16 CFR 314.4(b) which are 1) employee training and management; 2) information systems, including network and software design, as well as information processing, storage, transmission and disposal; and 3) detecting, preventing and responding to attacks, intrusions or other system failures. Further, the College must document safeguards for each of the identified risks. As of June 30, 2020, an individual had not been tasked with coordinating the information security program and the internal policy has been updated to reflect GLBA requirements. In addition, the College has not yet formally documented a risk assessment that addresses the required areas noted in 16 CFR 314.4(b) 1) and 3). Unity College agrees with this finding and plans to correct with the following: The Director of IT, under the director of the CSO, will be responsible for conducting risk assessment related to information systems, network, software design, info processing, info storage, and info transmission and proper disposal. The Director of IT will likewise be tasked with safeguarding Unity College proprietary data and student financial information from intrusion, attack, and system failure. Documents related to these safeguards will be kept on file and meet GLBA requirements. Anticipated Date of Correction 12/31/21 Responsible Parties: Melissa Couture, Chief Sustainability Officer
2019-004
FAC accepted this audit on March 15, 2020 — management decision was due September 15, 2020.
Finding 2019-002 Program(s) Affected The Student Financial Assistance Cluster - Award Year July 1, 2018 ? June 30, 2019 Criteria 34 CFR section 668.165 ? The institution must notify the student in writing of the student?s right to cancel all or a portion of a loan and to have the loan proceeds returned to the holder, no later than 30 days after crediting the student?s account with the Direct Loan. Condition and Context During testing, we noted 4 out of 32 selections tested for Federal Direct Student Loan disbursements were not notified of the date, amount, and right to cancel the loan timely. Further, of the 1,122 transactions within this disbursement, 430 of these did not include a notification to the students. Questioned Costs None. Cause and Effect The notification process is automated and there appears to have been a system error during an electronic mass distribution notification. As a result, students may not have been aware of their right to cancel the loan timely. Identification as a Repeat Finding, if Applicable Not a repeat finding. Recommendation We recommend the College implement a documented process to review the student account correspondence logs, within Powerfaids, following the email notifications, to determine accuracy and completion. Views of Responsible Officials and Planned Corrective Actions Management agrees with the finding. See attached Corrective Action Plan.
Show full finding ▾Hide full finding ▴Finding 2019-002 Program(s) Affected The Student Financial Assistance Cluster - Award Year July 1, 2018 ? June 30, 2019 Criteria 34 CFR section 668.165 ? The institution must notify the student in writing of the student?s right to cancel all or a portion of a loan and to have the loan proceeds returned to the holder, no later than 30 days after crediting the student?s account with the Direct Loan. Condition and Context During testing, we noted 4 out of 32 selections tested for Federal Direct Student Loan disbursements were not notified of the date, amount, and right to cancel the loan timely. Further, of the 1,122 transactions within this disbursement, 430 of these did not include a notification to the students. Questioned Costs None. Cause and Effect The notification process is automated and there appears to have been a system error during an electronic mass distribution notification. As a result, students may not have been aware of their right to cancel the loan timely. Identification as a Repeat Finding, if Applicable Not a repeat finding. Recommendation We recommend the College implement a documented process to review the student account correspondence logs, within Powerfaids, following the email notifications, to determine accuracy and completion. Views of Responsible Officials and Planned Corrective Actions Management agrees with the finding. See attached Corrective Action Plan.
Finding 2019-002 Corrective Action Plan This is a response to Finding 2019-002 listed in the Schedule of Findings and Questioned Costs for Federal Awards. Unity College agrees with this finding and has made the following corrective actions to prevent recurrence of such findings. During testing for Direct Loan Disbursement Notifications, we identified an issue with our first spring 2019 disbursement notification process. Once the audit firm identified that 4 students from their selection did not appear to receive Disbursement Notification via our internal email process, we began to research the issue. Through this review, we determined that a batch job had not posted a confirmation in the software system that a notification was sent for all 1122 borrowers. As the finding was determined six months after the disbursement, we were not able to recreate what caused the system glitch and we are unable to show proof that the notifications were sent to 430 Direct Loan borrowers for the first spring 2019 disbursement. To ensure this issue is resolved immediately, we reached out to the College Board to see if they could assist us in determining what would have caused this issue. The College Board was unable to assist with determining what lead to the issue due to the period that had elapsed since the issue, they were able to provide a query to identify any disbursement notifications that were not posted. We have updated our disbursement process to include a second check of disbursement notifications. After each large disbursement, the query will be run to ensure all Direct Loan borrowers received the disbursement notification. As a secondary precaution, the financial aid office will also run a check on all Direct Loan borrowers periodically to confirm there are no further incidents. We are confident that adding these additional steps will guarantee that disbursement notifications are sent to all Direct Loan borrowers. The corrective action plan completion date: November 1, 2019 Contact person: Sherry L McCollett Cordially, Sherry L. McCollett Unity College Director of Student Financial Services
Finding 2019-003 Program(s) Affected The Student Financial Assistance Cluster - Award Year July 1, 2018 ? June 30, 2019 Criteria According to the Uniform Guidance (34CFR 685.300(b)(5)), the College must agree to, on a monthly basis, reconcile institutional records with Direct Loan funds received from the Secretary and Direct Loan disbursement records submitted to and accepted by the Secretary. Condition and Context We noted 1 of 4 direct loan reconciliations selected, using a nonstatistical sample, did not have auditable evidence of secondary review of the reconciliation by management. Questioned Costs None. Cause and Effect The College had a period of transition in management roles within the student financial aid office which, coupled with the lack of procedural guidelines, resulted in an inability to show proof of the review of the direct loan reconciliation. We were thus unable to verify this review was complete. The lack of review could lead to undetected discrepancies between funds received or disbursed from the Department?s systems and College?s records. Identification as a Repeat Finding, if Applicable Not a repeat finding. Recommendation We recommend that the College update its internal policy and procedures to require secondary review of the direct loan reconciliations. Views of Responsible Officials and Planned Corrective Actions Management agrees with the finding. See attached Corrective Action Plan.
Show full finding ▾Hide full finding ▴Finding 2019-003 Program(s) Affected The Student Financial Assistance Cluster - Award Year July 1, 2018 ? June 30, 2019 Criteria According to the Uniform Guidance (34CFR 685.300(b)(5)), the College must agree to, on a monthly basis, reconcile institutional records with Direct Loan funds received from the Secretary and Direct Loan disbursement records submitted to and accepted by the Secretary. Condition and Context We noted 1 of 4 direct loan reconciliations selected, using a nonstatistical sample, did not have auditable evidence of secondary review of the reconciliation by management. Questioned Costs None. Cause and Effect The College had a period of transition in management roles within the student financial aid office which, coupled with the lack of procedural guidelines, resulted in an inability to show proof of the review of the direct loan reconciliation. We were thus unable to verify this review was complete. The lack of review could lead to undetected discrepancies between funds received or disbursed from the Department?s systems and College?s records. Identification as a Repeat Finding, if Applicable Not a repeat finding. Recommendation We recommend that the College update its internal policy and procedures to require secondary review of the direct loan reconciliations. Views of Responsible Officials and Planned Corrective Actions Management agrees with the finding. See attached Corrective Action Plan.
Finding 2019-003 Corrective Action Plan This is a response to Finding 2019-003 listed in the Schedule of Findings and Questioned Costs for Federal Awards. Unity College agrees with this finding and has made the following corrective actions to prevent recurrence of such findings. As part of Unity College's reconciliation process, we have one staff person complete the reconciliation. Once completed, an email notification is sent to a second staff person that reconciliation is complete and ready for the secondary review. The audit team found one reconciliation where we did not have email proof that a review occurred. Although the review was complete, we could not show the email proof that a review had been completed. For the month in question, we had a staff change and the reviewer worked directly with the person assigned to complete reconciliation. Once reconciliation was complete, the secondary review request was handled verbally and there was no auditable evidence of the secondary review. To ensure this issue does not occur in the future, we have created a reconciliation sheet that will be signed and dated by the person completing reconciliation for both Pell and Direct Loans. Once the second review is complete, the reviewer will also sign and date the sheet. This reconciliation confirmation sheet will be scanned with all reconciliation documents for each month. We are confident that this procedure will eliminate any chance of this finding occurring in the future. Corrective action completion date: December 1, 2019 Contact Person: Sherry L. McCollett Cordially, Sherry L. McCollett Unity College Director of Student Financial Services
Finding 2019-004 Program(s) Affected The Student Financial Assistance Cluster-Award Year July 1, 2018 ? June 30, 2019 Criteria The Gramm-Leach-Bliley Act (Public Law 106-102) (GLBA) requires financial institutions to explain their information-sharing practices with their customers to safeguard sensitive data (16 CFR 314). Higher education institutions are subject to GLBA. Schools must protect student financial information, with particular attention to information provided to institutions by the Department or otherwise obtained in support of the administration of student financial aid programs. Under the Uniform Guidance, the College is required to perform a risk assessment that addresses the required areas noted in 16 CFR 314.4(b) which are 1) employee training and management; 2) information systems, including network and software design, as well as information processing, storage, transmission and disposal; and 3) detecting, preventing and responding to attacks, intrusions or other system failures. Further, the risk assessment should include documented safeguards for each of the identified risks. Condition and Context We noted an individual has been tasked with coordinating the information security program and the internal policy has been updated to reflect GLBA requirements. The College has not yet formally documented a risk assessment that addresses the required areas noted in 16 CFR 314.4(b). Questioned Costs None. Cause and Effect While the College is aware of the GLBA requirements, the risk assessment process has taken longer than anticipated to perform and document, resulting in the noncompliance with GLBA requirements. Without such a risk assessment, the College may not maintain current safeguards to ensure compliance with GLBA over time. Identification as a Repeat Finding, if Applicable Not a repeat finding. Recommendation We recommend the College perform risk assessments and document steps taken to gain GLBA compliance. Views of Responsible Officials and Planned Corrective Actions Management agrees with the finding. See attached Corrective Action Plan.
Show full finding ▾Hide full finding ▴Finding 2019-004 Program(s) Affected The Student Financial Assistance Cluster-Award Year July 1, 2018 ? June 30, 2019 Criteria The Gramm-Leach-Bliley Act (Public Law 106-102) (GLBA) requires financial institutions to explain their information-sharing practices with their customers to safeguard sensitive data (16 CFR 314). Higher education institutions are subject to GLBA. Schools must protect student financial information, with particular attention to information provided to institutions by the Department or otherwise obtained in support of the administration of student financial aid programs. Under the Uniform Guidance, the College is required to perform a risk assessment that addresses the required areas noted in 16 CFR 314.4(b) which are 1) employee training and management; 2) information systems, including network and software design, as well as information processing, storage, transmission and disposal; and 3) detecting, preventing and responding to attacks, intrusions or other system failures. Further, the risk assessment should include documented safeguards for each of the identified risks. Condition and Context We noted an individual has been tasked with coordinating the information security program and the internal policy has been updated to reflect GLBA requirements. The College has not yet formally documented a risk assessment that addresses the required areas noted in 16 CFR 314.4(b). Questioned Costs None. Cause and Effect While the College is aware of the GLBA requirements, the risk assessment process has taken longer than anticipated to perform and document, resulting in the noncompliance with GLBA requirements. Without such a risk assessment, the College may not maintain current safeguards to ensure compliance with GLBA over time. Identification as a Repeat Finding, if Applicable Not a repeat finding. Recommendation We recommend the College perform risk assessments and document steps taken to gain GLBA compliance. Views of Responsible Officials and Planned Corrective Actions Management agrees with the finding. See attached Corrective Action Plan.
Finding 2019-004 Corrective Action Plan This is a response to Finding 2019-004 listed in the Schedule of Findings and Questioned Costs for Federal Awards. Unity College agrees with this finding and has made the following corrective actions to prevent recurrence of such findings. Unity College has taken steps to update our internal policy to reflect GLBA requirements. At this time Unity College's Information Technology Department is working with a third-party company, OPT Solutions, to complete the risk assessments and document steps taken to gain GLBA compliance. The Risk assessment will address all areas noted in 16 CFR 314.4(b) and will be completed by 3/15/2020. A Risk Assessment will be performed annually. We are confident that this procedure will eliminate any chance of this finding occurring in the future, Contact Person: Jennifer DeHart Cordially, Sherry L. McCollett Unity College Director of Student Financial Services
FAC accepted this audit on December 3, 2018 — management decision was due June 3, 2019.
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
2017-001
FAC accepted this audit on January 3, 2018 — management decision was due July 3, 2018.
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
FAC accepted this audit on December 18, 2016 — management decision was due June 18, 2017.
Data source: This information comes from the Federal Audit Clearinghouse, the official repository of Single Audit data. All data is public domain. Verify this organization's audit history at fac.gov.
Track your findings and corrective action plans across audit cycles.
Start tracking findings →Monitor subrecipient audit findings and filing records.
Start monitoring →© 2026 Single Audit Intelligence. All data is public domain.