COMMONWEALTH OF PENNSYLVANIA

EIN: 010661737

UEI: TN75GJE1S7G3

Data as of August 26, 2026

COMMONWEALTH OF PENNSYLVANIA10 audit years169 findings108 repeat
10
Audit Years
169
Total Findings
108
Repeat Findings

FY 2025-06-30

Management decision deadline — for entities that funded this organization

The FAC accepted this audit on March 18, 2026. Under 2 CFR 200.521(d), a pass-through entity that provided federal funds to this organization for this audit period must issue a management decision on these findings by September 18, 2026 (23 days from today).

What is a management decision? →
2025-003
Subrecipient Monitoring
MATERIAL WEAKNESSREPEATQUESTIONED COSTS

Within the Aging Cluster, the Pennsylvania Department of Aging (PDOA) contracts with 52 Area Agency on Aging subrecipients to provide various services that include cares support, preventive health, and nutrition services, among others. Our audit testing disclosed that PDOA performed subrecipient monitoring on 18 of the 52 subrecipients during the fiscal year ended June 30, 2025. The review period for the 18 subrecipients monitored was 2019 through 2023, representing old grant years. The monitoring performed did not include grants in years 2024 and 2025 to ensure timely compliance. The Aging Cluster subrecipients received $66.3 million, or 97 percent, of Aging Cluster Program expenditures totaling $68.1 million reported on the Schedule of Expenditures of Federal Awards (SEFA). Criteria: 45 CFR Section 1321.9 State agency policies and procedures, states in part: (a) The State agency on aging shall develop policies and procedures governing all aspects of programs operated as set forth in this part… The State agency is responsible for implementing, monitoring, and enforcing policies and procedures, where: (1) The policies and procedures developed by the State agency shall address how the State agency will monitor the programmatic and fiscal performance of all programs and activities initiated under this part for compliance with all requirements, and for quality and effectiveness. 2 CFR Section 200.332, Requirements for pass-through entities, states: (e) Monitor the activities of the subrecipient as necessary to ensure that the subrecipient complies with Federal statutes, regulations, and the terms and conditions of the subaward. The pass-through entity is responsible for monitoring the overall performance of a subrecipient to ensure that the goals and objectives of the subaward are achieved. In monitoring a subrecipient, a pass-through entity must: (1) Review financial and performance reports. Finding 2025 – 003: (continued) (2) Ensure that the subrecipient takes corrective action on all significant developments that negatively affect the subaward. Significant developments include Single Audit findings related to the subaward, other audit findings, site visits, and written notifications from a subrecipient of adverse conditions which will impact their ability to meet the milestones or the objectives of a subaward. When significant developments negatively impact the subaward, a subrecipient must provide the pass-through entity with information on their plan for corrective action and any assistance needed to resolve the situation. (3) Issue a management decision for audit findings pertaining only to the Federal award provided to the subrecipient from the pass-through entity… (4) Resolve audit findings specifically related to the subaward. However, the pass-through entity is not responsible for resolving cross-cutting audit findings that apply to the subaward and other Federal awards or subawards. If a subrecipient has a current Single Audit report and has not been excluded from receiving Federal funding (meaning, has not been debarred or suspended), the pass-through entity may rely on the subrecipient's cognizant agency for audit or oversight agency for audit to perform audit follow-up and make management decisions related to cross-cutting audit findings in accordance with section § 200.513(a)(4)(viii). Such reliance does not eliminate the responsibility of the pass-through entity to issue subawards that conform to agency and award-specific requirements, to manage risk through ongoing subaward monitoring, and to monitor the status of the findings that are specifically related to the subaward. (f) Depending upon the pass-through entity's assessment of the risk posed by the subrecipient (as described in paragraph (c) of this section), the following monitoring tools may be useful for the pass-through entity to ensure proper accountability and compliance with program requirements and achievement of performance goals: (1) Providing subrecipients with training and technical assistance on program-related matters; (2) Performing site visits to review the subrecipient's program operations; and (3) Arranging for agreed-upon-procedures engagements as described in § 200.425. PDOA’s Policy and Procedures Manual, Section B. Roles and Responsibilities of the State Authority states: In accordance with the State’s administrative authority, the Department’s functions and responsibilities include the following: • The establishment and maintenance of policies and procedures for the fiscal and programmatic operation of the programs. • The establishment of minimum standards for the provision of services and benefits. • Enter into contracts or grants between the State and the Area Agencies on Aging (AAA) to set forth the responsibilities and performance requirements. • Provide oversight and monitoring of the AAAs for compliance with all program's standards. • Provide oversight and fiscal management of fund utilization based on funding source requirements. Management Directive 325.12, Amended – Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office’s Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Finding 2025 – 003: (continued) Cause: In response to the lack of monitoring procedures conducted in the prior year, PDOA has started monitoring subrecipients but continues to have a backlog. PDOA accelerated the monitoring schedule to include prior year review periods to bring the monitoring process current but did not monitor the current audit period. PDOA’s policy did not include a defined monitoring cycle of its subrecipients to ensure adequate monitoring was performed on a timely basis. We acknowledge that PDOA has implemented a new phase of their monitoring process. They enhanced the monitoring instrument used to monitor subrecipients and are working to eliminate the monitoring backlog. Effect: Without proper subrecipient monitoring, PDOA cannot ensure compliance with grant requirements and federal regulations, including allowable costs and other requirements. Recommendation: PDOA should perform adequate during-the-award monitoring procedures for all Aging Cluster subrecipients to ensure timely compliance with all applicable federal regulations. PDOA policy should include a defined monitoring cycle to ensure timely monitoring visits in addition to the compliance procedures. Monitoring by state officials should be supported by documentation to show the monitoring performed, areas examined, conclusions reached, and that the monitoring was performed in compliance with applicable regulations. Agency Response: PDOA agrees with the finding. Questioned Costs: The amount of questioned costs cannot be determined.

Show full finding ▾
Full finding narrative

Department of Aging Finding 2025 – 003: ALN 93.044, 93.045, and 93.053 – Aging Cluster (including COVID-19) A Material Weakness and Material Noncompliance Exist in the Department of Aging Related to Subrecipient Monitoring (A Similar Condition Was Noted in Prior Year Finding 2024-003) Federal Grant Number(s) and Year(s): 2101PACMC6 (4/01/2021 – 9/30/2024), 2101PAHDC6 (4/01/2021 – 9/30/2024), 2101PASSC6 (4/01/2021 – 9/30/2024), 2201PASTPH (1/01/2022 – 9/30/2025), 2301PAOACM (10/01/2022 – 9/30/2025), 2301PAOAHD (10/01/2022 – 9/30/2025), 2301PAOASS (10/01/2022 – 9/30/2025), 2401PAOACM (10/01/2023 – 9/30/2025), 2401PAOAHD (10/01/2023 – 9/30/2025), 2401PAOANS (10/01/2023 – 9/30/2025), 2401PAOASS (10/01/2023 – 9/30/2025), 2501PAOASS (10/01/2024 – 9/30/2026), 2501PAOACM (10/01/2024 – 9/30/2026), 2501PAOAHD (10/01/2024 – 9/30/2026), 2501PAOANS (10/01/2024 – 9/30/2026) Type of Finding: Material Weakness in Internal Control over Compliance, Material Noncompliance Compliance Requirement: Subrecipient Monitoring Condition: Within the Aging Cluster, the Pennsylvania Department of Aging (PDOA) contracts with 52 Area Agency on Aging subrecipients to provide various services that include cares support, preventive health, and nutrition services, among others. Our audit testing disclosed that PDOA performed subrecipient monitoring on 18 of the 52 subrecipients during the fiscal year ended June 30, 2025. The review period for the 18 subrecipients monitored was 2019 through 2023, representing old grant years. The monitoring performed did not include grants in years 2024 and 2025 to ensure timely compliance. The Aging Cluster subrecipients received $66.3 million, or 97 percent, of Aging Cluster Program expenditures totaling $68.1 million reported on the Schedule of Expenditures of Federal Awards (SEFA). Criteria: 45 CFR Section 1321.9 State agency policies and procedures, states in part: (a) The State agency on aging shall develop policies and procedures governing all aspects of programs operated as set forth in this part… The State agency is responsible for implementing, monitoring, and enforcing policies and procedures, where: (1) The policies and procedures developed by the State agency shall address how the State agency will monitor the programmatic and fiscal performance of all programs and activities initiated under this part for compliance with all requirements, and for quality and effectiveness. 2 CFR Section 200.332, Requirements for pass-through entities, states: (e) Monitor the activities of the subrecipient as necessary to ensure that the subrecipient complies with Federal statutes, regulations, and the terms and conditions of the subaward. The pass-through entity is responsible for monitoring the overall performance of a subrecipient to ensure that the goals and objectives of the subaward are achieved. In monitoring a subrecipient, a pass-through entity must: (1) Review financial and performance reports. Finding 2025 – 003: (continued) (2) Ensure that the subrecipient takes corrective action on all significant developments that negatively affect the subaward. Significant developments include Single Audit findings related to the subaward, other audit findings, site visits, and written notifications from a subrecipient of adverse conditions which will impact their ability to meet the milestones or the objectives of a subaward. When significant developments negatively impact the subaward, a subrecipient must provide the pass-through entity with information on their plan for corrective action and any assistance needed to resolve the situation. (3) Issue a management decision for audit findings pertaining only to the Federal award provided to the subrecipient from the pass-through entity… (4) Resolve audit findings specifically related to the subaward. However, the pass-through entity is not responsible for resolving cross-cutting audit findings that apply to the subaward and other Federal awards or subawards. If a subrecipient has a current Single Audit report and has not been excluded from receiving Federal funding (meaning, has not been debarred or suspended), the pass-through entity may rely on the subrecipient's cognizant agency for audit or oversight agency for audit to perform audit follow-up and make management decisions related to cross-cutting audit findings in accordance with section § 200.513(a)(4)(viii). Such reliance does not eliminate the responsibility of the pass-through entity to issue subawards that conform to agency and award-specific requirements, to manage risk through ongoing subaward monitoring, and to monitor the status of the findings that are specifically related to the subaward. (f) Depending upon the pass-through entity's assessment of the risk posed by the subrecipient (as described in paragraph (c) of this section), the following monitoring tools may be useful for the pass-through entity to ensure proper accountability and compliance with program requirements and achievement of performance goals: (1) Providing subrecipients with training and technical assistance on program-related matters; (2) Performing site visits to review the subrecipient's program operations; and (3) Arranging for agreed-upon-procedures engagements as described in § 200.425. PDOA’s Policy and Procedures Manual, Section B. Roles and Responsibilities of the State Authority states: In accordance with the State’s administrative authority, the Department’s functions and responsibilities include the following: • The establishment and maintenance of policies and procedures for the fiscal and programmatic operation of the programs. • The establishment of minimum standards for the provision of services and benefits. • Enter into contracts or grants between the State and the Area Agencies on Aging (AAA) to set forth the responsibilities and performance requirements. • Provide oversight and monitoring of the AAAs for compliance with all program's standards. • Provide oversight and fiscal management of fund utilization based on funding source requirements. Management Directive 325.12, Amended – Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office’s Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Finding 2025 – 003: (continued) Cause: In response to the lack of monitoring procedures conducted in the prior year, PDOA has started monitoring subrecipients but continues to have a backlog. PDOA accelerated the monitoring schedule to include prior year review periods to bring the monitoring process current but did not monitor the current audit period. PDOA’s policy did not include a defined monitoring cycle of its subrecipients to ensure adequate monitoring was performed on a timely basis. We acknowledge that PDOA has implemented a new phase of their monitoring process. They enhanced the monitoring instrument used to monitor subrecipients and are working to eliminate the monitoring backlog. Effect: Without proper subrecipient monitoring, PDOA cannot ensure compliance with grant requirements and federal regulations, including allowable costs and other requirements. Recommendation: PDOA should perform adequate during-the-award monitoring procedures for all Aging Cluster subrecipients to ensure timely compliance with all applicable federal regulations. PDOA policy should include a defined monitoring cycle to ensure timely monitoring visits in addition to the compliance procedures. Monitoring by state officials should be supported by documentation to show the monitoring performed, areas examined, conclusions reached, and that the monitoring was performed in compliance with applicable regulations. Agency Response: PDOA agrees with the finding. Questioned Costs: The amount of questioned costs cannot be determined.

Corrective Action Plan

1. Revise the written, risk-based subrecipient monitoring procedures in accordance with 2 CFR §200.332. 2. Conduct an annual risk assessment of all 52 AAAs and assign risk ratings. 3. Implement an annual monitoring schedule ensuring coverage of active grant years (FY2024 and forward). 4. Complete catch-up monitoring of all subrecipients not reviewed for FY2024 and FY2025 within 12 months. 5. Revise monitoring checklists to require review of current-year expenditures to verify compliance. 6. Improve centralized tracking system for monitoring activities and audit reviews. 7. Confirm supervisory approval following completion of monitoring reports. 8. Provide mandatory staff training on 45 CFR §1321.9 and 2 CFR Part 200 requirements. 9. Develop quarterly compliance reporting to leadership to ensure ongoing oversight. Anticipated Completion Date: 06/30/2026 Contact Names: Jason Kavulich, Secretary of Aging ; Jennifer Beck, Fiscal Management Specialist & PDOA Audit Liaison

Prior Finding References

2024-003

About Subrecipient Monitoring →
2025-004
Matching, Level of Effort, Earmarking / Reporting
MATERIAL WEAKNESS

The Pennsylvania Department of Aging (PDOA) is required to spend at least the average amount of state funds for aging services and administration that it reported as spent under the state plan for these activities for the three previous fiscal years. The amount of state funds expended is subsequently required to be reported to the U.S. Department of Health and Human Services (HHS) on the Certification of Maintenance of Effort (MOE). Our testing confirmed that PDOA submitted the MOE Certification for federal fiscal year (FFY) ending September 30, 2024, for Title III, Parts B and C applicable to the Aging Cluster; however, the amount certified was incorrect. In addition, using information provided by PDOA to support state funds expended, it was determined that FFY 2024 state expenditures were less than the average of the previous three years and therefore, PDOA did not meet the required level of effort for FFY ending September 30, 2024. Criteria: 45 CFR Section 1321.9(c)(2)(vi), Maintenance of effort, states: Maintenance of effort. The State agency will meet expectations regarding maintenance of effort, where: (A) The State agency must expend for both services and administration at least the average amount of State funds reported and certified as expended under the State plan for these activities for the three previous fiscal years for Title III; (B) The amount certified must at least meet minimum match requirements from State resources; (C) Any amount of State resources included in the Title III maintenance of effort certification that exceeds the minimum amount mandated becomes part of the permanent maintenance of effort; and (D) Excess State match reported on the Federal financial report does not become part of the maintenance of effort unless the State agency certifies the excess. The Instructions for Maintenance of Effort for Title III and Certification of Long-Term Care Ombudsman Program Expenditures states in part: This instruction requires the Authorized Official in each State/Territory Agency on Aging to submit a certification on maintenance of effort for Title III and certification of minimum expenditures for Long-Term Ombudsman Programs under Title III and Title VII of the Older Americans Act (OAA) for the prior fiscal year. As required in OAA, the State/Territory maintenance of effort level is to be determined annually. Finding 2025 – 004: (continued) In addition, Commonwealth Management Directive 325.12 Amended – Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office’s Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should design control activities to achieve objectives and respond to risk. Management should implement control activities through policies. Cause: PDOA changed their methodology for calculating the MOE, and the data used to calculate state expenditures for FFY 2024 was from a prior period representing FFY 2023. PDOA’s controls over meeting the required level of effort and calculating the required MOE were not effective in detecting noncompliance and errors on the Certification of Maintenance of Effort submitted to HHS. Effect: The MOE Certification submitted by PDOA was inaccurate. In addition, PDOA did not meet the required level of effort of state resources for FFY 2024. PDOA was not in compliance with the Level of Effort and reporting requirements. Recommendation: We recommend that PDOA implement procedures to monitor their level of effort to ensure state expenditures meet the required level for each FFY as required. In addition, procedures should be implemented to ensure the MOE Certification is calculated correctly using verifiable resources. Agency Response: PDOA agrees with the finding. Questioned Costs: None

Show full finding ▾
Full finding narrative

Department of Aging Finding 2025 – 004: ALN 93.044, 93.045, and 93.053 – Aging Cluster (including COVID-19) A Material Weakness and Material Noncompliance Exist in the Department of Aging’s Maintenance of Effort Certification Reporting Process Federal Grant Number(s) and Year(s): 2101PACMC6 (4/01/2021 – 9/30/2024), 2101PAHDC6 (4/01/2021 – 9/30/2024), 2101PASSC6 (4/01/2021 – 9/30/2024), 2201PASTPH (1/01/2022 – 9/30/2025), 2301PAOACM (10/01/2022 – 9/30/2025), 2301PAOAHD (10/01/2022 – 9/30/2025), 2301PAOASS (10/01/2022 – 9/30/2025), 2401PAOACM (10/01/2023 – 9/30/2025), 2401PAOAHD (10/01/2023 – 9/30/2025), 2401PAOASS (10/01/2023 – 9/30/2025), 2501PAOACM (10/01/2024 – 9/30/2026), 2501PAOAHD (10/01/2024 – 9/30/2026), 2501PAOASS (10/01/2024 – 9/30/2026) Type of Finding: Material Weakness in Internal Control over Compliance, Material Noncompliance Compliance Requirement: Matching, Level of Effort, Earmarking, Reporting Condition: The Pennsylvania Department of Aging (PDOA) is required to spend at least the average amount of state funds for aging services and administration that it reported as spent under the state plan for these activities for the three previous fiscal years. The amount of state funds expended is subsequently required to be reported to the U.S. Department of Health and Human Services (HHS) on the Certification of Maintenance of Effort (MOE). Our testing confirmed that PDOA submitted the MOE Certification for federal fiscal year (FFY) ending September 30, 2024, for Title III, Parts B and C applicable to the Aging Cluster; however, the amount certified was incorrect. In addition, using information provided by PDOA to support state funds expended, it was determined that FFY 2024 state expenditures were less than the average of the previous three years and therefore, PDOA did not meet the required level of effort for FFY ending September 30, 2024. Criteria: 45 CFR Section 1321.9(c)(2)(vi), Maintenance of effort, states: Maintenance of effort. The State agency will meet expectations regarding maintenance of effort, where: (A) The State agency must expend for both services and administration at least the average amount of State funds reported and certified as expended under the State plan for these activities for the three previous fiscal years for Title III; (B) The amount certified must at least meet minimum match requirements from State resources; (C) Any amount of State resources included in the Title III maintenance of effort certification that exceeds the minimum amount mandated becomes part of the permanent maintenance of effort; and (D) Excess State match reported on the Federal financial report does not become part of the maintenance of effort unless the State agency certifies the excess. The Instructions for Maintenance of Effort for Title III and Certification of Long-Term Care Ombudsman Program Expenditures states in part: This instruction requires the Authorized Official in each State/Territory Agency on Aging to submit a certification on maintenance of effort for Title III and certification of minimum expenditures for Long-Term Ombudsman Programs under Title III and Title VII of the Older Americans Act (OAA) for the prior fiscal year. As required in OAA, the State/Territory maintenance of effort level is to be determined annually. Finding 2025 – 004: (continued) In addition, Commonwealth Management Directive 325.12 Amended – Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office’s Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should design control activities to achieve objectives and respond to risk. Management should implement control activities through policies. Cause: PDOA changed their methodology for calculating the MOE, and the data used to calculate state expenditures for FFY 2024 was from a prior period representing FFY 2023. PDOA’s controls over meeting the required level of effort and calculating the required MOE were not effective in detecting noncompliance and errors on the Certification of Maintenance of Effort submitted to HHS. Effect: The MOE Certification submitted by PDOA was inaccurate. In addition, PDOA did not meet the required level of effort of state resources for FFY 2024. PDOA was not in compliance with the Level of Effort and reporting requirements. Recommendation: We recommend that PDOA implement procedures to monitor their level of effort to ensure state expenditures meet the required level for each FFY as required. In addition, procedures should be implemented to ensure the MOE Certification is calculated correctly using verifiable resources. Agency Response: PDOA agrees with the finding. Questioned Costs: None

Corrective Action Plan

1. Recalculate the three-year MOE average and FFY 2024 qualifying state expenditures and reconcile to the Commonwealth’s accounting records. 2. Submit a corrected MOE Certification to HHS/ACL and formally notify the federal awarding agency of the error. 3. Revisit the existing MOE procedure that defines qualifying expenditures, calculation methodology, documentation standards, and retention requirements. 4. Review current multi-level review process. 5. Implement quarterly MOE monitoring and variance analysis comparing projected state expenditures to required MOE levels, with reporting to leadership. 6. Provide mandatory training to fiscal staff on MOE requirements and 45 CFR §1321.9(c)(2)(vi). Anticipated Completion Date: 06/30/2026 Contact Names: Jason Kavulich, Secretary of Aging ; Jennifer Beck, Fiscal Management Specialist & PDOA Audit Liaison

About Matching, Level of Effort, Earmarking, Reporting →
2025-005
Program Income / Reporting
MATERIAL WEAKNESS

The Pennsylvania Department of Aging (PDOA) is required to submit a SF-425, Federal Financial Report to the United States Department of Health and Human Services (HHS) for the Aging Cluster of grants. The reports are due annually 90 days after the reporting period with a final submission due 120 days after the project period end date. The SF-425 report includes data related to federal cash receipts and disbursements, federal expenditures to date, the federal share of unliquidated obligations, the federal program income earned, the federal program income expended and unexpended, indirect charges to the grant, as well as other general information that is necessary to ensure compliance with program requirements. We selected two of 11 SF-425 reports submitted during the audit period for testing. Our testing disclosed that federal program income did not agree to supporting documentation and was incorrectly reported on the September 30, 2024 annual filing for the federal fiscal year (FFY) 2024 federal grant. Although the SF-425 report was certified by an authorized official, the overstatement of federal program income earned and expended went undetected by Commonwealth management until it was brought to their attention by the auditor. Our testing also disclosed that $2,983,034 of unexpended federal program income was reported on the September 30, 2024, final filing for the FFY 2021 federal grant. This amount agreed to supporting documentation; however, PDOA could not adequately explain what action was taken to ensure the balance was expended in the subsequent fiscal year, as required by federal regulations and Aging Program Directives. Our testing of federal program income included the review of cost sharing fees collected from services provided through Aging Cluster grants and PDOA provided reports from their accounting system used to track program income, but auditors were unable to determine the amount of federal cost sharing collections and if they were allowable. Criteria: The 2025 OMB Uniform Guidance Compliance Supplement, Part 4 – III. Compliance Requirements for Aging Cluster, L. Reporting states, in part: For State Agency- 1. Financial Reporting c. SF-425, Federal Financial Reports – Semi-Annual (OMB No. 4040-0014)- Applicable Finding 2025 – 005: (continued) 45 CFR Section 1321.9(c)(2)(xii), Use of program income, states: Program income is subject to the requirements in 2 CFR 200.307 and 45 CFR 75.307 and as follows: (A) Voluntary contributions and cost sharing payments are considered program income; (B) Program income collected must be used to expand a service funded under the Title III grant award pursuant to which the income was originally collected; (C) The State agency must use the addition alternative as set forth in 2 CFR 200.307(e)(2) and 45 CFR 75.307(e)(2) when reporting program income, and prior approval of the addition alternative from the Assistant Secretary for Aging is not required; (D) Program income must be expended or disbursed prior to requesting additional Federal funds; and (E) Program income may not be used to match grant awards funded by the Act without prior approval. 45 CFR Section 1321.9(c)(2)(xi), Cost Sharing states, in part: A State agency is permitted under section 315(a) of the Act (42 U.S.C. 3030c-2(a)), to implement cost sharing for services funded by the Act by recipients of the services, except as provided for in paragraph (c)(2)(xi)(D) of this section. (H) Collection of program income. All cost sharing contributions collected are considered program income and are subject to the requirements of 2 CFR 200.307, 45 CFR 75.307, and in § 1321.9(c)(2)(xii). 2 CFR Section 200.303(a), Internal controls, states: The recipient and subrecipient must: (a) Establish, document, and maintain effective internal control over the Federal award that provides reasonable assurance that the recipient or subrecipient is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should align with the guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control-Integrated Framework” issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Aging Program Directive (APD) #25-01-03, Program Income, states in part: Federal Program Income - All program income generated from services funded, in whole or in part, by federal OAA funds on hand as of June 30, 2024, is to be budgeted and expended during SFY 2024-25… Failure to comply with these policies may result in the reduction of Block Grant funding to the AAA [Area Agency on Aging]… AAAs will comply with the provisions of APD #05-01-11 concerning excessive balances of program income collections. AAAs are advised that payments of funds on SFY 2024-25 Aging Block Grant contracts will be contingent upon the compliance of AAAs with the federal and state requirements for program income and cost sharing fund balances… Finding 2025 – 005: (continued) When a AAA has excessive balances of Federal Program Income, Local Program Income or OPTIONS Cost Sharing Funds as of June 30, 2024 (Fourth Quarter FRR), its SFY2024-25 Block Grant monthly payment(s)may be reduced or withheld until the AAA achieves compliance with the established program income balance requirements. Aging Program Directive #05-01-11, Area Agency on Aging (AAAs) Program Income Policies, states in part: Federal Program Income - All Federal program income generated from services funded, in whole or in part, by federal Older Americans Act funds that is on hand as of June 30 must be budgeted and expended during the following fiscal year. Failure to comply with this policy could result in the reduction of Block Grant funding to the AAA… The AAA must also ensure that appropriate financial records for program income are maintained by service provider. The purpose of such records is to ensure compliance with standards established by the Department of Aging, i.e. that program income collections are expended on a timely basis and no excessive balances for program income collections are accumulated. Records must be available that properly reflect beginning balances, receipts, expenditures and ending balances. In addition, Commonwealth Management Directive 325.12 Amended – Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office’s Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should design control activities to achieve objectives and respond to risk. Management should implement control activities through policies. Cause: PDOA stated that management turnover, outdated policies, inconsistencies and timing of AAA reporting contributed to the incorrect reporting of program income. In addition, the accounting system, used by the AAAs to report program income to PDOA, reports federal program income as a single figure, commingling the reporting of program income of the various grant awards. As a result, the liquidation of program income by grant award could not be determined to ensure it was fully spent in compliance with federal requirements. Also, the report does not differentiate between voluntary contributions or cost sharing fees to determine compliance with federal program income requirements specific to cost sharing fees. Effect: Since PDOA’s controls over reporting program income and the preparation process for the SF-425 report were not effective, program income was incorrectly reported on the SF-425 report submitted to HHS. In addition, PDOA was not in compliance with federal regulations and their Aging Program Directives related to program income requirements. Recommendation: We recommend that PDOA update their written policies and procedures to ensure federal program income is accurately recorded, reported and in compliance with federal regulations. Program income should be monitored and reconciled to ensure that the balance on hand is budgeted and expended in accordance with federal regulations and PDOA’s policies. PDOA policy should allow for consistent accounting and reporting amongst the AAAs. PDOA and the Office of Comptroller Operations (OCO) should also develop a policy for the review, approval, and submission of the SF-425 reports to ensure the reports are prepared accurately and submitted timely in accordance with federal regulations. Finding 2025 – 005: (continued) PDOA Response: PDOA agrees with this finding. OCO Response: OCO agrees with this finding. Questioned Costs: None

Show full finding ▾
Full finding narrative

Department of Aging Office of the Budget - Office of Comptroller Operations Finding 2025 – 005: ALN 93.044, 93.045, and 93.053 – Aging Cluster (including COVID-19) A Material Weakness and Material Noncompliance Exist in the Department of Aging’s Program Income and Reporting Process Federal Grant Number(s) and Year(s): 2101PACMC6 (4/01/2021 – 9/30/2024), 2101PAHDC6 (4/01/2021 – 9/30/2024), 2101PASSC6 (4/01/2021 – 9/30/2024), 2201PASTPH (1/01/2022 – 9/30/2025), 2301PAOACM (10/01/2022 – 9/30/2025), 2301PAOAHD (10/01/2022 – 9/30/2025), 2301PAOASS (10/01/2022 – 9/30/2025), 2401PAOACM (10/01/2023 – 9/30/2025), 2401PAOAHD (10/01/2023 – 9/30/2025), 2401PAOASS (10/01/2023 – 9/30/2025), 2501PAOACM (10/01/2024 – 9/30/2026), 2501PAOAHD (10/01/2024 – 9/30/2026), 2501PAOASS (10/01/2024 – 9/30/2026) Type of Finding: Material Weakness in Internal Control over Compliance, Material Noncompliance Compliance Requirement: Program Income, Reporting Condition: The Pennsylvania Department of Aging (PDOA) is required to submit a SF-425, Federal Financial Report to the United States Department of Health and Human Services (HHS) for the Aging Cluster of grants. The reports are due annually 90 days after the reporting period with a final submission due 120 days after the project period end date. The SF-425 report includes data related to federal cash receipts and disbursements, federal expenditures to date, the federal share of unliquidated obligations, the federal program income earned, the federal program income expended and unexpended, indirect charges to the grant, as well as other general information that is necessary to ensure compliance with program requirements. We selected two of 11 SF-425 reports submitted during the audit period for testing. Our testing disclosed that federal program income did not agree to supporting documentation and was incorrectly reported on the September 30, 2024 annual filing for the federal fiscal year (FFY) 2024 federal grant. Although the SF-425 report was certified by an authorized official, the overstatement of federal program income earned and expended went undetected by Commonwealth management until it was brought to their attention by the auditor. Our testing also disclosed that $2,983,034 of unexpended federal program income was reported on the September 30, 2024, final filing for the FFY 2021 federal grant. This amount agreed to supporting documentation; however, PDOA could not adequately explain what action was taken to ensure the balance was expended in the subsequent fiscal year, as required by federal regulations and Aging Program Directives. Our testing of federal program income included the review of cost sharing fees collected from services provided through Aging Cluster grants and PDOA provided reports from their accounting system used to track program income, but auditors were unable to determine the amount of federal cost sharing collections and if they were allowable. Criteria: The 2025 OMB Uniform Guidance Compliance Supplement, Part 4 – III. Compliance Requirements for Aging Cluster, L. Reporting states, in part: For State Agency- 1. Financial Reporting c. SF-425, Federal Financial Reports – Semi-Annual (OMB No. 4040-0014)- Applicable Finding 2025 – 005: (continued) 45 CFR Section 1321.9(c)(2)(xii), Use of program income, states: Program income is subject to the requirements in 2 CFR 200.307 and 45 CFR 75.307 and as follows: (A) Voluntary contributions and cost sharing payments are considered program income; (B) Program income collected must be used to expand a service funded under the Title III grant award pursuant to which the income was originally collected; (C) The State agency must use the addition alternative as set forth in 2 CFR 200.307(e)(2) and 45 CFR 75.307(e)(2) when reporting program income, and prior approval of the addition alternative from the Assistant Secretary for Aging is not required; (D) Program income must be expended or disbursed prior to requesting additional Federal funds; and (E) Program income may not be used to match grant awards funded by the Act without prior approval. 45 CFR Section 1321.9(c)(2)(xi), Cost Sharing states, in part: A State agency is permitted under section 315(a) of the Act (42 U.S.C. 3030c-2(a)), to implement cost sharing for services funded by the Act by recipients of the services, except as provided for in paragraph (c)(2)(xi)(D) of this section. (H) Collection of program income. All cost sharing contributions collected are considered program income and are subject to the requirements of 2 CFR 200.307, 45 CFR 75.307, and in § 1321.9(c)(2)(xii). 2 CFR Section 200.303(a), Internal controls, states: The recipient and subrecipient must: (a) Establish, document, and maintain effective internal control over the Federal award that provides reasonable assurance that the recipient or subrecipient is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should align with the guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control-Integrated Framework” issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Aging Program Directive (APD) #25-01-03, Program Income, states in part: Federal Program Income - All program income generated from services funded, in whole or in part, by federal OAA funds on hand as of June 30, 2024, is to be budgeted and expended during SFY 2024-25… Failure to comply with these policies may result in the reduction of Block Grant funding to the AAA [Area Agency on Aging]… AAAs will comply with the provisions of APD #05-01-11 concerning excessive balances of program income collections. AAAs are advised that payments of funds on SFY 2024-25 Aging Block Grant contracts will be contingent upon the compliance of AAAs with the federal and state requirements for program income and cost sharing fund balances… Finding 2025 – 005: (continued) When a AAA has excessive balances of Federal Program Income, Local Program Income or OPTIONS Cost Sharing Funds as of June 30, 2024 (Fourth Quarter FRR), its SFY2024-25 Block Grant monthly payment(s)may be reduced or withheld until the AAA achieves compliance with the established program income balance requirements. Aging Program Directive #05-01-11, Area Agency on Aging (AAAs) Program Income Policies, states in part: Federal Program Income - All Federal program income generated from services funded, in whole or in part, by federal Older Americans Act funds that is on hand as of June 30 must be budgeted and expended during the following fiscal year. Failure to comply with this policy could result in the reduction of Block Grant funding to the AAA… The AAA must also ensure that appropriate financial records for program income are maintained by service provider. The purpose of such records is to ensure compliance with standards established by the Department of Aging, i.e. that program income collections are expended on a timely basis and no excessive balances for program income collections are accumulated. Records must be available that properly reflect beginning balances, receipts, expenditures and ending balances. In addition, Commonwealth Management Directive 325.12 Amended – Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office’s Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should design control activities to achieve objectives and respond to risk. Management should implement control activities through policies. Cause: PDOA stated that management turnover, outdated policies, inconsistencies and timing of AAA reporting contributed to the incorrect reporting of program income. In addition, the accounting system, used by the AAAs to report program income to PDOA, reports federal program income as a single figure, commingling the reporting of program income of the various grant awards. As a result, the liquidation of program income by grant award could not be determined to ensure it was fully spent in compliance with federal requirements. Also, the report does not differentiate between voluntary contributions or cost sharing fees to determine compliance with federal program income requirements specific to cost sharing fees. Effect: Since PDOA’s controls over reporting program income and the preparation process for the SF-425 report were not effective, program income was incorrectly reported on the SF-425 report submitted to HHS. In addition, PDOA was not in compliance with federal regulations and their Aging Program Directives related to program income requirements. Recommendation: We recommend that PDOA update their written policies and procedures to ensure federal program income is accurately recorded, reported and in compliance with federal regulations. Program income should be monitored and reconciled to ensure that the balance on hand is budgeted and expended in accordance with federal regulations and PDOA’s policies. PDOA policy should allow for consistent accounting and reporting amongst the AAAs. PDOA and the Office of Comptroller Operations (OCO) should also develop a policy for the review, approval, and submission of the SF-425 reports to ensure the reports are prepared accurately and submitted timely in accordance with federal regulations. Finding 2025 – 005: (continued) PDOA Response: PDOA agrees with this finding. OCO Response: OCO agrees with this finding. Questioned Costs: None

Corrective Action Plan

PDOA: 1. Strengthen internal controls over program income. 2. Recalculate FFY 2024 program income balances and submit amended report. 3. Implement a tracking log to actively monitor program income reporting levels. 4. Improve reporting of cost sharing and program income to ensure it is in compliance with federal regulations. 5. Provide training to PDA and AAA fiscal staff on program income. Anticipated Completion Date: 06/30/2026 Contact Names: Jason Kavulich, Secretary of Aging ; Jennifer Beck, Fiscal Management Specialist & PDOA Audit Liaison OB-OCO: As of 02/25/2026, the procedures for preparing the Federal Financial Report (SF‑425) were updated to include additional controls for reviewing and certifying the report prior to submission. These updates require the Pennsylvania Department of Aging to verify all program income forms to ensure they are relevant and applicable to the reporting period covered by the SF‑425. The updated procedures also require PDOA to conduct a full review of the SF‑425 and certify its accuracy via email before the Bureau of Accounting and Financial Management completes the submission in PMS. By June 30, 2026, OCO will further enhance the accuracy of financial reporting on the SF‑425 by updating the Title III working papers to incorporate linked data sources and formulas, reducing reliance on manually entered figures. Anticipated Completion Date: 06/30/2026 Contact Names: Jamie Jerosky, BAFM Assist. Director; Matt Stubb, BAFM Integrated Financial Service Mgr.; Carol Waite, BAFM Mgr.

About Program Income, Reporting →
2025-006
Subrecipient Monitoring
REPEATQUESTIONED COSTS

The Pennsylvania Department of Agriculture (PDA), Bureau of Food Assistance (BFA), administers the operations of the Food Distribution Cluster (FDC). During the fiscal year ended June 30, 2025, subrecipient expenditures accounted for $92.6 million or approximately 95.9 percent of total federal program expenditures of $96.6 million. PDA performs on-site monitoring of subrecipients to ensure compliance with federal program regulations. For The Emergency Food Assistance Program (TEFAP), PDA must submit a report of review findings to the eligible agency and ensure that corrective action is taken to eliminate deficiencies identified if deficiencies are disclosed through their review. As part of our testing of subrecipient monitoring, we selected 20 TEFAP subrecipients, 14 soup kitchens and six lead agencies, out of 114 reviews conducted during the audit period to test PDA’s monitoring procedures which includes the corrective action process. Our testing disclosed that PDA failed to submit a report of review findings and ensure that corrective action was taken by the eligible recipient agency for four of 14 soup kitchen subrecipients reviewed until after auditor inquiry. Criteria: 7 CFR Section 251.11 (e) regarding TEFAP state monitoring system states: If deficiencies are disclosed through the review of an eligible recipient agency, the State agency must submit a report of the review findings to the eligible recipient agency and ensure that corrective action is taken to eliminate the deficiencies identified. Management Directive 325.12, Amended – Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office’s Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: PDA management did not provide a response as to why the deficiencies noted during the review of the soup kitchens were not completed in a timely manner. PDA subsequently communicated the deficiencies to the subrecipients and corrective action was taken. Finding 2025 – 006: (continued) Effect: When PDA does not ensure corrective action for deficiencies disclosed in their review are corrected timely, subrecipients may continue to operate in noncompliance with program regulations. Recommendation: We recommend that PDA implement procedures to communicate deficiencies to subrecipients to ensure timely corrective action is taken by the subrecipients to eliminate the deficiencies identified. Agency Response: The Department of Agriculture agrees with this finding. Questioned Costs: The amount of questioned costs cannot be determined.

Show full finding ▾
Full finding narrative

Department of Agriculture Finding 2025 – 006: ALN 10.565, 10.568, and 10.569 – Food Distribution Cluster A Significant Deficiency and Noncompliance Exist in Pennsylvania Department of Agriculture Monitoring of Food Distribution Cluster Subrecipients (A Similar Condition Was Noted in Prior Year Finding 2024-005) Federal Grant Number(s) and Year(s): 228PA100I1003 (6/13/2022 – 6/30/2025), 241PA825Y8105 (10/01/2023 – 9/30/2024), 241PA445Q2204 (10/01/2023 – 9/30/2024), 238PA000I1003 (5/25/2023 – 6/30/2025), 251PA825Y8105 (10/01/2024 – 9/30/2025) Type of Finding: Significant Deficiency in Internal Control over Compliance, Other Matters Compliance Requirement: Subrecipient Monitoring Condition: The Pennsylvania Department of Agriculture (PDA), Bureau of Food Assistance (BFA), administers the operations of the Food Distribution Cluster (FDC). During the fiscal year ended June 30, 2025, subrecipient expenditures accounted for $92.6 million or approximately 95.9 percent of total federal program expenditures of $96.6 million. PDA performs on-site monitoring of subrecipients to ensure compliance with federal program regulations. For The Emergency Food Assistance Program (TEFAP), PDA must submit a report of review findings to the eligible agency and ensure that corrective action is taken to eliminate deficiencies identified if deficiencies are disclosed through their review. As part of our testing of subrecipient monitoring, we selected 20 TEFAP subrecipients, 14 soup kitchens and six lead agencies, out of 114 reviews conducted during the audit period to test PDA’s monitoring procedures which includes the corrective action process. Our testing disclosed that PDA failed to submit a report of review findings and ensure that corrective action was taken by the eligible recipient agency for four of 14 soup kitchen subrecipients reviewed until after auditor inquiry. Criteria: 7 CFR Section 251.11 (e) regarding TEFAP state monitoring system states: If deficiencies are disclosed through the review of an eligible recipient agency, the State agency must submit a report of the review findings to the eligible recipient agency and ensure that corrective action is taken to eliminate the deficiencies identified. Management Directive 325.12, Amended – Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office’s Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: PDA management did not provide a response as to why the deficiencies noted during the review of the soup kitchens were not completed in a timely manner. PDA subsequently communicated the deficiencies to the subrecipients and corrective action was taken. Finding 2025 – 006: (continued) Effect: When PDA does not ensure corrective action for deficiencies disclosed in their review are corrected timely, subrecipients may continue to operate in noncompliance with program regulations. Recommendation: We recommend that PDA implement procedures to communicate deficiencies to subrecipients to ensure timely corrective action is taken by the subrecipients to eliminate the deficiencies identified. Agency Response: The Department of Agriculture agrees with this finding. Questioned Costs: The amount of questioned costs cannot be determined.

Corrective Action Plan

The Pennsylvania Department of Agriculture, Bureau of Food Assistance is in the process of developing a procedure to ensure that a report of review findings is submitted to each eligible agency after their review. This procedure will also ensure that, if the review resulted in findings that require implementation of corrective actions, additional monitoring is conducted until the eligible agency has successfully taken actions to mitigate the deficiencies. Anticipated Completion Date: 09/30/2026 Contact Name: Caryn Long Earl, Director, Bureau of Food Assistance

Prior Finding References

2024-005

About Subrecipient Monitoring →
2025-007
Special Tests & Provisions
MATERIAL WEAKNESSREPEATQUESTIONED COSTS

During our audit of the Supplemental Nutrition Assistance Program (SNAP) administered by the Department of Human Services (DHS), we evaluated the security over Electronic Benefits Transfer (EBT) cards, which includes both the physical security of EBT cards during the issuance process at County Assistance Offices (CAO), as well as the handling of EBT cards returned from the United States Postal Service as undeliverable, or those that have been lost or stolen. EBT cards are the method by which SNAP benefit payments are made available to recipients. Also, EBT cards are the primary method by which cash and special allowance benefit payments are made available to Temporary Assistance for Needy Families (TANF) recipients. Total benefit expenditures for SNAP for the fiscal year ended June 30, 2025, totaled $4.3 billion. Total benefit expenditures for TANF for the fiscal year ended June 30, 2025, totaled $97.2 million. Fourteen of the 86 CAO and district locations that issued EBT cards were selected for site testing in the current audit period. During our testing of the physical security over EBT cards, we noted exceptions at ten CAO and district locations selected for testing. These exceptions included the following: 1) The Roles/Permissions Report from the EBT Card Tracking Database provided by the EBT Project Office and CAO/district offices did not reconcile (1 district office and 5 CAO locations); 2) EBT cards were created outside of the hours of operations (1 CAO location); 3) The Daily Log Summary and Weekly Log Report from the EBT Card Tracking Database did not reconcile (1 CAO location); 4) Failure to perform the following: • Completion of EBT Card Paper Logs only in circumstances deemed an emergency (1 district office and 1 CAO location); • Designate a manager or supervisor to the Alternate EBT Coordinator role (1 CAO location); • Ensure that upon receipt of each shipment of EBT cards and related supplies, the shipping manifest is date stamped (1 CAO location); • Mail locally created EBT cards directly to customers (1 district office); • Maintain adequate security of EBT cards (1 CAO location); • Maintain adequate security of card printer (1 CAO location); • Maintain EBT Card Paper Logs for four years (1 CAO location); • Proper completion of EPPIC EBT Systems Application forms (1 CAO location); • Timely completion and submission of the EPPIC EBT Systems Application forms to the Office of Income Maintenance (OIM) EBT Security (1 district office and 4 CAO locations); Finding 2025 – 007: (continued) • Timely deactivation of user access in the EBT Card Tracking Database (2 CAO locations); • Timely enter a shipment received into the EBT Card Tracking Database (1 CAO location); and • Timely mail locally created EBT cards on the same day as card creation (1 district office). Criteria: The 2025 OMB Uniform Guidance Compliance Supplement, Part 4 – Agency Program Requirements for the SNAP Cluster, Special Tests and Provisions – N.3 EBT Card Security, states: The state is required to maintain adequate security over, and documentation/records for, EBT cards to prevent their theft, embezzlement, loss, damage, destruction, unauthorized transfer, negotiation, or use (7 CFR Section 274.8(b)(3)). 7 CFR Section 274.5, Record retention and forms security, states: (c) Accountable Documents. (1) EBT cards shall be considered accountable documents. The State agency shall provide the following minimum security and control procedures for these documents: i. Secure storage; ii. Access limited to authorized personnel; iii. Bulk inventory control records; iv. Subsequent control records maintained through the point of issuance or use; and v. Periodic review and validation of inventory controls and records by parties not otherwise involved in maintaining control records. 45 CFR Section 75.302 applicable to TANF states: (b) The financial management system of each non-Federal entity must provide for the following (see also §75.361, 75.362, 75.363, 75.364, and 75.365): (4) Effective control over, and accountability for, all funds, property, and other assets. The non-Federal entity must adequately safeguard all assets and assure that they are used solely for authorized purposes. See §75.303. Management Directive 325.12, Amended – Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office’s Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Finding 2025 – 007: (continued) Cause: Established policies and procedures were not followed consistently across CAO and district locations, which resulted in ineffective internal controls over EBT card security. Effect: Without adequate security controls over EBT cards, there exists the possibility of misappropriation and/or abuse. Recommendation: We recommend that DHS monitor EBT card security at CAO and district locations on a regular basis to improve consistency in the execution of documented policies and procedures. Agency Response: DHS agrees with the finding. Questioned Costs: The amount of questioned costs cannot be determined.

Show full finding ▾
Full finding narrative

Department of Human Services Finding 2025 – 007: ALN 10.551 and 10.561 – Supplemental Nutrition Assistance Program (SNAP) Cluster (including COVID-19) ALN 93.558 – Temporary Assistance for Needy Families A Material Weakness and Material Noncompliance Exist at the Department of Human Services Related to Electronic Benefits Transfer Card Security (A Similar Condition Was Noted in Prior Year Finding 2024-007) Federal Grant Number(s) and Year(s): 241PA405S2514 (10/01/2023 – 9/30/2024), 251PA405S2514 (10/01/2024 – 9/30/2025), 2101PATANF (10/01/2020 – 9/30/2021), 2301PATANF (10/01/2022 – 9/30/2023), 2401PATANF (10/01/2023 – 9/30/2024), 2501PATANF (10/01/2024 – 9/30/2025) Type of Finding: Material Weakness in Internal Control over Compliance, Material Noncompliance Compliance Requirement: Special Tests and Provisions related to EBT Card Security Condition: During our audit of the Supplemental Nutrition Assistance Program (SNAP) administered by the Department of Human Services (DHS), we evaluated the security over Electronic Benefits Transfer (EBT) cards, which includes both the physical security of EBT cards during the issuance process at County Assistance Offices (CAO), as well as the handling of EBT cards returned from the United States Postal Service as undeliverable, or those that have been lost or stolen. EBT cards are the method by which SNAP benefit payments are made available to recipients. Also, EBT cards are the primary method by which cash and special allowance benefit payments are made available to Temporary Assistance for Needy Families (TANF) recipients. Total benefit expenditures for SNAP for the fiscal year ended June 30, 2025, totaled $4.3 billion. Total benefit expenditures for TANF for the fiscal year ended June 30, 2025, totaled $97.2 million. Fourteen of the 86 CAO and district locations that issued EBT cards were selected for site testing in the current audit period. During our testing of the physical security over EBT cards, we noted exceptions at ten CAO and district locations selected for testing. These exceptions included the following: 1) The Roles/Permissions Report from the EBT Card Tracking Database provided by the EBT Project Office and CAO/district offices did not reconcile (1 district office and 5 CAO locations); 2) EBT cards were created outside of the hours of operations (1 CAO location); 3) The Daily Log Summary and Weekly Log Report from the EBT Card Tracking Database did not reconcile (1 CAO location); 4) Failure to perform the following: • Completion of EBT Card Paper Logs only in circumstances deemed an emergency (1 district office and 1 CAO location); • Designate a manager or supervisor to the Alternate EBT Coordinator role (1 CAO location); • Ensure that upon receipt of each shipment of EBT cards and related supplies, the shipping manifest is date stamped (1 CAO location); • Mail locally created EBT cards directly to customers (1 district office); • Maintain adequate security of EBT cards (1 CAO location); • Maintain adequate security of card printer (1 CAO location); • Maintain EBT Card Paper Logs for four years (1 CAO location); • Proper completion of EPPIC EBT Systems Application forms (1 CAO location); • Timely completion and submission of the EPPIC EBT Systems Application forms to the Office of Income Maintenance (OIM) EBT Security (1 district office and 4 CAO locations); Finding 2025 – 007: (continued) • Timely deactivation of user access in the EBT Card Tracking Database (2 CAO locations); • Timely enter a shipment received into the EBT Card Tracking Database (1 CAO location); and • Timely mail locally created EBT cards on the same day as card creation (1 district office). Criteria: The 2025 OMB Uniform Guidance Compliance Supplement, Part 4 – Agency Program Requirements for the SNAP Cluster, Special Tests and Provisions – N.3 EBT Card Security, states: The state is required to maintain adequate security over, and documentation/records for, EBT cards to prevent their theft, embezzlement, loss, damage, destruction, unauthorized transfer, negotiation, or use (7 CFR Section 274.8(b)(3)). 7 CFR Section 274.5, Record retention and forms security, states: (c) Accountable Documents. (1) EBT cards shall be considered accountable documents. The State agency shall provide the following minimum security and control procedures for these documents: i. Secure storage; ii. Access limited to authorized personnel; iii. Bulk inventory control records; iv. Subsequent control records maintained through the point of issuance or use; and v. Periodic review and validation of inventory controls and records by parties not otherwise involved in maintaining control records. 45 CFR Section 75.302 applicable to TANF states: (b) The financial management system of each non-Federal entity must provide for the following (see also §75.361, 75.362, 75.363, 75.364, and 75.365): (4) Effective control over, and accountability for, all funds, property, and other assets. The non-Federal entity must adequately safeguard all assets and assure that they are used solely for authorized purposes. See §75.303. Management Directive 325.12, Amended – Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office’s Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Finding 2025 – 007: (continued) Cause: Established policies and procedures were not followed consistently across CAO and district locations, which resulted in ineffective internal controls over EBT card security. Effect: Without adequate security controls over EBT cards, there exists the possibility of misappropriation and/or abuse. Recommendation: We recommend that DHS monitor EBT card security at CAO and district locations on a regular basis to improve consistency in the execution of documented policies and procedures. Agency Response: DHS agrees with the finding. Questioned Costs: The amount of questioned costs cannot be determined.

Corrective Action Plan

DHS’ Office of Income Maintenance (OIM) Bureau of Operations (BOO): BOO will take the following actions to address the finding: The BOO will work with the EBT Project Office to create a dedicated section in the OIM EBT Procedure Manual to document the exceptions identified during the single audit each year. This addition will ensure that all offices are informed of the issues, can review their processes and procedures, and can make any necessary corrections. It will be added by April 1, 2026. The below items will be included: Knowing how to reconcile: • The Roles/Permissions Report from the EBT Card Tracking Database. • The Daily Log Summary and Weekly log report in the EBT Card Tracking Database. Reminders of the following concerns: • EBT card creation should end, and all cards should be logged in the EBT Card Tracking Database, by the close of business each day. No cards should be created after 5 PM. • When to use EBT Card Tracking Paper Logs, and how long to maintain them. • Ensuring that, upon receipt of each shipment of EBT cards and related supplies, the shipping manifest date is stamped. • Mailing locally created EBT cards directly to customers on the same day that the card is created. • Timeframes for completing and submitting the EPPIC EBT Systems Application forms to the OIM EBT Project Office. • Timeframe to deactivate user access in the EBT Card Tracking Database. • Timeframe for when to enter a shipment received into the EBT Card Tracking Database. The BOO, in conjunction with the EBT Project Office, distributes attestation forms to staff each year, typically during the first quarter. Employees are required to sign and return these forms to confirm that they have reviewed the procedure manual. The form for this cycle was sent out in February 2026. Anticipated Completion Date: 04/01/2026 Contact Name: Jeanette Coulston, Staff Assistant to BOO Director OIM Bureau of Program Evaluation (BPE) Division of Corrective Action (DCA): BPE will take the following actions to address the finding: The DCA conducts EBT Card Security reviews at every CAO and District Office that issues EBT cards. These reviews are conducted on a 3-year rotation to ensure compliance with documented policies and procedures. Annually, BPE/DCA EBT Headquarters staff provide training to DCA Income Maintenance Examiners in both field offices, to ensure awareness of any policy or procedure changes, prior to the start of EBT reviews. This training occurred on October 2, 2025. The current rotation schedule spans FFY 2025 through FFY 2027. Anticipated Completion Date: 04/01/2026 Contact Names: Amira Milikin, DCA Director; Bryan Bumpers, EBT Project Officer

Prior Finding References

2024-007

About Special Tests and Provisions →
2025-008
Cash Management / Subrecipient Monitoring
MATERIAL WEAKNESSREPEATQUESTIONED COSTS

Our examination of the Department of Human Services’ (DHS) procedures for monitoring Social Services Block Grant (SSBG) subrecipients revealed that DHS did not adequately risk assess and monitor the SSBG Mental Health, Homeless Assistance, and Child Welfare subrecipients to ensure that SSBG awards are used in compliance with laws and regulations, which include allowable costs, period of performance, and other requirements. Although DHS performed risk assessments of these subrecipients, the risk assessments did not include a consideration of all of the items outlined in 2 CFR Section 200.332 (c) (1)-(4). Further, the risk assessments did not define the course of action to be taken for each assigned risk level. DHS program personnel indicated that they performed on-site monitoring of eight subrecipients with seven final monitoring reports issued and one report in progress. The remaining 67 subrecipients were not monitored during the audit period. Expenditures for Mental Health, Homeless Assistance, and Child Welfare subrecipient programs not monitored totaled $21.7 million (or approximately 23.2 percent) of total SSBG program expenditures of $93.6 million reported on the Schedule of Expenditures of Federal Awards (SEFA). While we noted that DHS monitored eight of the 75 Mental Health County/County Joinder subrecipients which included Mental Health, Homeless Assistance and Child Welfare services, this coverage was not adequate. In addition, our review of the risk assessments completed for all of the aforementioned subrecipients identified several instances where subrecipient monitoring was warranted but was not conducted, including several subrecipients assessed as high risk for which no monitoring procedures were performed. In addition, for the compliance requirement related to cash management, we noted that DHS advanced funds to SSBG subrecipients in four of nine program areas, representing $34.0 million (or approximately 36.3 percent) of SSBG program expenditures, without adequately monitoring the reasonableness of the subrecipient cash balances. In particular, for the program areas related to Mental Health, Intellectual Disabilities, Homeless Assistance, and Child Welfare, DHS advanced funds to subrecipients on a quarterly basis. Our inquiries with applicable DHS program administrators disclosed that DHS did not adequately monitor the four program areas’ subrecipients for cash management compliance either at the time of payment or at any other time during the fiscal year ended June 30, 2025. Furthermore, while Single Audits of SSBG subrecipients may be conducted each year, this auditing activity does not compensate for the lack of during-the-award program monitoring, since the timing, focus, and scope of subrecipient auditing activities after year end are different than compliance monitoring to be performed by program officials during the year. Criteria: 2 CFR Section 200.332, Requirements for pass-through entities, states: (c) Evaluate each subrecipient's fraud risk and risk of noncompliance with a subaward to determine the appropriate subrecipient monitoring described in paragraph (f) of this section. When evaluating a subrecipient's risk, a pass-through entity should consider the following: Finding 2025 – 008: (continued) (1) The subrecipient's prior experience with the same or similar subawards; (2) The results of previous audits. This includes considering whether or not the subrecipient receives a Single Audit in accordance with subpart F and the extent to which the same or similar subawards have been audited as a major program; (3) Whether the subrecipient has new personnel or new or substantially changed systems; and (4) The extent and results of any Federal agency monitoring (for example, if the subrecipient also receives Federal awards directly from the Federal agency). (e) Monitor the activities of a subrecipient as necessary to ensure that the subrecipient complies with Federal statutes, regulations, and the terms and conditions of the subaward. The pass-through entity is responsible for monitoring the overall performance of a subrecipient to ensure that the goals and objectives of the subaward are achieved. In monitoring a subrecipient, a pass-through entity must: (1) Review financial and performance reports. (2) Ensure that the subrecipient takes corrective action on all significant developments that negatively affect the subaward. Significant developments include Single Audit findings related to the subaward, other audit findings, site visits, and written notifications from a subrecipient of adverse conditions which will impact their ability to meet the milestones or the objectives of a subaward. When significant developments negatively impact the subaward, a subrecipient must provide the pass-through entity with information on their plan for corrective action and any assistance needed to resolve the situation. (3) Issue a management decision for audit findings pertaining only to the Federal award provided to the subrecipient from the pass-through entity as required by § 200.521. (4) Resolve audit findings specifically related to the subaward. However, the pass-through entity is not responsible for resolving cross-cutting audit findings that apply to the subaward and other Federal awards or subawards. If a subrecipient has a current Single Audit report and has not been excluded from receiving Federal funding (meaning, has not been debarred or suspended), the pass-through entity may rely on the subrecipient's cognizant agency for audit or oversight agency for audit to perform audit follow-up and make management decisions related to cross-cutting audit findings in accordance with section § 200.513(a)(4)(viii). Such reliance does not eliminate the responsibility of the pass-through entity to issue subawards that conform to agency and award-specific requirements, to manage risk through ongoing subaward monitoring, and to monitor the status of the findings that are specifically related to the subaward. (f) Depending upon the pass-through entity's assessment of the risk posed by the subrecipient (as described in paragraph (c) of this section), the following monitoring tools may be useful for the pass-through entity to ensure proper accountability and compliance with program requirements and achievement of performance goals: (1) Providing subrecipients with training and technical assistance on program-related matters; (2) Performing site visits to review the subrecipient's program operations; and (3) Arranging for agreed-upon-procedures engagements as described in § 200.425. Finding 2025 – 008: (continued) 2 CFR Section 200.305 (b)(1), applicable for recipients and subrecipients, states in part: …Advance payments to a recipient or subrecipient must be limited to the minimum amounts needed and be timed with actual, immediate cash requirements of the recipient or subrecipient in carrying out the purpose of the approved program or project. The timing and amount of advance payments must be as close as is administratively feasible to the actual disbursements by the recipient or subrecipient for direct program or project costs and the proportionate share of any allowable indirect costs. The recipient or subrecipient must make timely payments to contractors in accordance with the contract provisions. Management Directive 325.12, Amended – Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office’s Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: DHS management indicated that risk assessment and monitoring documents were created for use during on-site monitoring of SSBG subrecipients. However, due to staffing issues, on-site monitoring was not performed for all SSBG subrecipients. Consistent with prior year audits, DHS management noted that there have been no changes to the payment methodology for the Homeless Assistance, Mental Health, Intellectual Disabilities, and Child Welfare components of SSBG. These programs provide subrecipients with advances to comply with Commonwealth law and also to ensure that adequate funds are available to provide services to participants on a timely basis. DHS officials believe that their in-house payment review procedures for the SSBG program are as efficient as administratively feasible and that controls exist in each of the program areas. Without on-site program monitoring visits by funding agency officials, we consider DHS’s limited in-house reviews of subrecipient status reports or other documents to be insufficient to detect potential subrecipient noncompliance, including excess cash violations. DHS does not adjust payments to the subrecipients based on in-house reviews. Effect: Since DHS does not adequately perform during-the-award monitoring of subrecipients, including the monitoring of subrecipient cash on hand, subrecipients may not be complying with applicable grant requirements and federal regulations, including cash management standards. Recommendation: DHS should perform risk based during-the-award monitoring procedures for all SSBG subrecipients to ensure timely compliance with all applicable federal regulations. On-site monitoring visits by state officials should be supported by documentation to show the monitoring performed, areas examined, conclusions reached, and that the monitoring was performed in compliance with applicable regulations. As recommended in previous Single Audits and supported by the United States Department of Health and Human Services, DHS should either consider changing their current subrecipient payment procedures from advancement basis to reimbursement basis or establish procedures to adequately monitor subrecipient cash on hand to ensure it is limited to immediate needs, but no longer than one month. The implementation and strengthening of these controls should provide DHS with reasonable assurance as to compliance with cash management requirements at the subrecipient level. Agency Response: DHS agrees with this finding. Questioned Costs: The amount of questioned costs cannot be determined.

Show full finding ▾
Full finding narrative

Department of Human Services Finding 2025 – 008: ALN 93.667 – Social Services Block Grant A Material Weakness and Material Noncompliance Exist in the Department of Human Services’ Program Monitoring of the Social Services Block Grant Subrecipients (A Similar Condition Was Noted in Prior Year Finding 2024-008) Federal Grant Number(s) and Year(s): 2501PASOSR (10/01/2024 – 9/30/2026), 2401PASOSR (10/01/2023 – 9/30/2025) Type of Finding: Material Weakness in Internal Control over Compliance, Material Noncompliance Compliance Requirements: Cash Management, Subrecipient Monitoring Condition: Our examination of the Department of Human Services’ (DHS) procedures for monitoring Social Services Block Grant (SSBG) subrecipients revealed that DHS did not adequately risk assess and monitor the SSBG Mental Health, Homeless Assistance, and Child Welfare subrecipients to ensure that SSBG awards are used in compliance with laws and regulations, which include allowable costs, period of performance, and other requirements. Although DHS performed risk assessments of these subrecipients, the risk assessments did not include a consideration of all of the items outlined in 2 CFR Section 200.332 (c) (1)-(4). Further, the risk assessments did not define the course of action to be taken for each assigned risk level. DHS program personnel indicated that they performed on-site monitoring of eight subrecipients with seven final monitoring reports issued and one report in progress. The remaining 67 subrecipients were not monitored during the audit period. Expenditures for Mental Health, Homeless Assistance, and Child Welfare subrecipient programs not monitored totaled $21.7 million (or approximately 23.2 percent) of total SSBG program expenditures of $93.6 million reported on the Schedule of Expenditures of Federal Awards (SEFA). While we noted that DHS monitored eight of the 75 Mental Health County/County Joinder subrecipients which included Mental Health, Homeless Assistance and Child Welfare services, this coverage was not adequate. In addition, our review of the risk assessments completed for all of the aforementioned subrecipients identified several instances where subrecipient monitoring was warranted but was not conducted, including several subrecipients assessed as high risk for which no monitoring procedures were performed. In addition, for the compliance requirement related to cash management, we noted that DHS advanced funds to SSBG subrecipients in four of nine program areas, representing $34.0 million (or approximately 36.3 percent) of SSBG program expenditures, without adequately monitoring the reasonableness of the subrecipient cash balances. In particular, for the program areas related to Mental Health, Intellectual Disabilities, Homeless Assistance, and Child Welfare, DHS advanced funds to subrecipients on a quarterly basis. Our inquiries with applicable DHS program administrators disclosed that DHS did not adequately monitor the four program areas’ subrecipients for cash management compliance either at the time of payment or at any other time during the fiscal year ended June 30, 2025. Furthermore, while Single Audits of SSBG subrecipients may be conducted each year, this auditing activity does not compensate for the lack of during-the-award program monitoring, since the timing, focus, and scope of subrecipient auditing activities after year end are different than compliance monitoring to be performed by program officials during the year. Criteria: 2 CFR Section 200.332, Requirements for pass-through entities, states: (c) Evaluate each subrecipient's fraud risk and risk of noncompliance with a subaward to determine the appropriate subrecipient monitoring described in paragraph (f) of this section. When evaluating a subrecipient's risk, a pass-through entity should consider the following: Finding 2025 – 008: (continued) (1) The subrecipient's prior experience with the same or similar subawards; (2) The results of previous audits. This includes considering whether or not the subrecipient receives a Single Audit in accordance with subpart F and the extent to which the same or similar subawards have been audited as a major program; (3) Whether the subrecipient has new personnel or new or substantially changed systems; and (4) The extent and results of any Federal agency monitoring (for example, if the subrecipient also receives Federal awards directly from the Federal agency). (e) Monitor the activities of a subrecipient as necessary to ensure that the subrecipient complies with Federal statutes, regulations, and the terms and conditions of the subaward. The pass-through entity is responsible for monitoring the overall performance of a subrecipient to ensure that the goals and objectives of the subaward are achieved. In monitoring a subrecipient, a pass-through entity must: (1) Review financial and performance reports. (2) Ensure that the subrecipient takes corrective action on all significant developments that negatively affect the subaward. Significant developments include Single Audit findings related to the subaward, other audit findings, site visits, and written notifications from a subrecipient of adverse conditions which will impact their ability to meet the milestones or the objectives of a subaward. When significant developments negatively impact the subaward, a subrecipient must provide the pass-through entity with information on their plan for corrective action and any assistance needed to resolve the situation. (3) Issue a management decision for audit findings pertaining only to the Federal award provided to the subrecipient from the pass-through entity as required by § 200.521. (4) Resolve audit findings specifically related to the subaward. However, the pass-through entity is not responsible for resolving cross-cutting audit findings that apply to the subaward and other Federal awards or subawards. If a subrecipient has a current Single Audit report and has not been excluded from receiving Federal funding (meaning, has not been debarred or suspended), the pass-through entity may rely on the subrecipient's cognizant agency for audit or oversight agency for audit to perform audit follow-up and make management decisions related to cross-cutting audit findings in accordance with section § 200.513(a)(4)(viii). Such reliance does not eliminate the responsibility of the pass-through entity to issue subawards that conform to agency and award-specific requirements, to manage risk through ongoing subaward monitoring, and to monitor the status of the findings that are specifically related to the subaward. (f) Depending upon the pass-through entity's assessment of the risk posed by the subrecipient (as described in paragraph (c) of this section), the following monitoring tools may be useful for the pass-through entity to ensure proper accountability and compliance with program requirements and achievement of performance goals: (1) Providing subrecipients with training and technical assistance on program-related matters; (2) Performing site visits to review the subrecipient's program operations; and (3) Arranging for agreed-upon-procedures engagements as described in § 200.425. Finding 2025 – 008: (continued) 2 CFR Section 200.305 (b)(1), applicable for recipients and subrecipients, states in part: …Advance payments to a recipient or subrecipient must be limited to the minimum amounts needed and be timed with actual, immediate cash requirements of the recipient or subrecipient in carrying out the purpose of the approved program or project. The timing and amount of advance payments must be as close as is administratively feasible to the actual disbursements by the recipient or subrecipient for direct program or project costs and the proportionate share of any allowable indirect costs. The recipient or subrecipient must make timely payments to contractors in accordance with the contract provisions. Management Directive 325.12, Amended – Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office’s Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: DHS management indicated that risk assessment and monitoring documents were created for use during on-site monitoring of SSBG subrecipients. However, due to staffing issues, on-site monitoring was not performed for all SSBG subrecipients. Consistent with prior year audits, DHS management noted that there have been no changes to the payment methodology for the Homeless Assistance, Mental Health, Intellectual Disabilities, and Child Welfare components of SSBG. These programs provide subrecipients with advances to comply with Commonwealth law and also to ensure that adequate funds are available to provide services to participants on a timely basis. DHS officials believe that their in-house payment review procedures for the SSBG program are as efficient as administratively feasible and that controls exist in each of the program areas. Without on-site program monitoring visits by funding agency officials, we consider DHS’s limited in-house reviews of subrecipient status reports or other documents to be insufficient to detect potential subrecipient noncompliance, including excess cash violations. DHS does not adjust payments to the subrecipients based on in-house reviews. Effect: Since DHS does not adequately perform during-the-award monitoring of subrecipients, including the monitoring of subrecipient cash on hand, subrecipients may not be complying with applicable grant requirements and federal regulations, including cash management standards. Recommendation: DHS should perform risk based during-the-award monitoring procedures for all SSBG subrecipients to ensure timely compliance with all applicable federal regulations. On-site monitoring visits by state officials should be supported by documentation to show the monitoring performed, areas examined, conclusions reached, and that the monitoring was performed in compliance with applicable regulations. As recommended in previous Single Audits and supported by the United States Department of Health and Human Services, DHS should either consider changing their current subrecipient payment procedures from advancement basis to reimbursement basis or establish procedures to adequately monitor subrecipient cash on hand to ensure it is limited to immediate needs, but no longer than one month. The implementation and strengthening of these controls should provide DHS with reasonable assurance as to compliance with cash management requirements at the subrecipient level. Agency Response: DHS agrees with this finding. Questioned Costs: The amount of questioned costs cannot be determined.

Corrective Action Plan

The Bureau of Financial Operations (BFO) will continue conducting during-the-award subrecipient monitoring for the SSBG based on the results of the documented risk assessment. As it relates to the cash management portion of the finding, given the relatively small amount of funds involved and the number of counties affected, DHS has determined that it is not economically feasible to change the payment methodology at this time. Anticipated Completion Date: 06/30/2026 Contact Name: Kelly Graham, Director, Division of Financial Reporting

Prior Finding References

2024-008

About Cash Management, Subrecipient Monitoring →
2025-009
Subrecipient Monitoring
REPEATQUESTIONED COSTS

During the fiscal year ended June 30, 2025, the Department of Labor and Industry (L&I) paid $26.9 million in Temporary Assistance for Needy Families (TANF) funding to 22 subrecipients within the Youth Employment and Training (E&T) appropriation (or 6.7 percent) out of total federal TANF expenditures of $403.4 million reported on the June 30, 2025 Schedule of Expenditures of Federal Awards (SEFA). Our testing of L&I’s during-the-award monitoring of subrecipients for the fiscal year ended June 30, 2025, disclosed that L&I did not conduct on-site monitoring or perform desk reviews of the TANF Youth Development Program (TANF YDP) for three out of five subrecipients selected for testing. Although L&I performed monitoring of these subrecipients specific to another federal program, the monitoring did not include a review of the performance of the subrecipients’ TANF YDP programs. The TANF YDP operations transitioned from the Bureau of Workforce Development Administration (BWDA) to the Bureau of Workforce Partnership and Operations (BWPO) in December 2023. During the fiscal year ended June 30, 2025, BWPO began onsite monitoring of the TANF YDP program on a limited basis by developing a pilot program that BWPO used to monitor the TANF YDP program for three subrecipients. BWPO developed a written TANF YDP Monitoring Plan that outlines plans to expand the monitoring to other TANF YDP subrecipients; however, the plan was not fully implemented as of June 30, 2025. Criteria: 2 CFR Section 200.332, Requirements for pass-through entities, states: A pass-through entity must: (e) Monitor the activities of a subrecipient as necessary to ensure that the subrecipient complies with Federal statutes, regulations, and the terms and conditions of the subaward. The pass-through entity is responsible for monitoring the overall performance of a subrecipient to ensure that the goals and objectives of the subaward are achieved. In monitoring a subrecipient, a pass-through entity must: (1) Review financial and performance reports. (2) Ensure that the subrecipient takes corrective action on all significant developments that negatively affect the subaward. Significant developments include Single Audit findings related to the subaward, other audit findings, site visits, and written notifications from a subrecipient of adverse conditions which will impact their ability to meet the milestones or the objectives of a subaward. When significant developments negatively impact the subaward, a subrecipient must provide the pass-through entity with information on their plan for corrective action and any assistance needed to resolve the situation. Finding 2025 – 009: (continued) (3) Issue a management decision for audit findings pertaining only to the Federal award provided to the subrecipient from the pass-through entity as required by § 200.521. (4) Resolve audit findings specifically related to the subaward. However, the pass-through entity is not responsible for resolving cross-cutting audit findings that apply to the subaward and other Federal awards or subawards. If a subrecipient has a current Single Audit report and has not been excluded from receiving Federal funding (meaning, has not been debarred or suspended), the pass-through entity may rely on the subrecipient’s cognizant agency for audit or oversight agency for audit to perform audit follow-up and make management decisions related to cross-cutting audit findings in accordance with section § 200.513(a)(4)(viii). Such reliance does not eliminate the responsibility of the pass-through entity to issue subawards that conform to agency and award-specific requirements, to manage risk through ongoing subaward monitoring, and to monitor the status of the findings that are specifically related to the subaward. (f) Depending upon the pass-through entity's assessment of risk posed by the subrecipient (as described in paragraph (c) of this section), the following monitoring tools may be useful for the pass-through entity to ensure proper accountability and compliance with program requirements and achievement of performance goals: (1) Providing subrecipients with training and technical assistance on program-related matters; (2) Performing site visits to review the subrecipient's program operations; and (3) Arranging for agreed-upon-procedures engagements as described in §200.425. Management Directive 325.12, Amended – Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office’s Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: L&I recognized the need to perform during-the-award monitoring procedures for TANF funds passed through for the Youth E&T program, but the updated monitoring procedures were not fully incorporated during the fiscal year ended June 30, 2025. Effect: TANF subrecipients could be operating in noncompliance with federal regulations without timely detection and correction by L&I management. Recommendation: L&I should continue to strengthen controls to ensure during-the-award monitoring is being performed for all TANF subrecipients and that the monitoring includes procedures to ensure that subrecipients are in compliance with applicable federal regulations. This should include examining subrecipients’ financial records and ensuring that all required Single Audits were obtained by L&I subrecipients. Agency Response: L&I agrees with this finding. TANF YDP operations transitioned from BWDA to BWPO in January 2023. Due to this transition, BWPO did not conduct on site monitoring of the TANF YDP program in Program Year (PY) 22. BWPO did begin monitoring in PY 23 on a limited basis as a pilot with 3 local areas in September of 2024. BWPO expanded monitoring efforts in 2025 by conducting PY 24 TANF YDP monitoring in alignment with the WIOA Common Measures Data Validation cycle. This enhanced desk review monitoring effort concluded by January 2026. PY is defined as July 1st to June 30th. BWPO will further expand annual monitoring of TANF YDP in alignment with the requirement to monitor all TANF YDP grant subrecipients for PY 25 and moving forward. L&I does ensure single audits are obtained from the TANF YDP sub-recipients as a part of our single audit review. Finding 2025 – 009: (continued) Questioned Costs: The amount of questioned costs cannot be determined.

Show full finding ▾
Full finding narrative

Department of Labor and Industry Finding 2025 – 009: ALN 93.558 – Temporary Assistance for Needy Families Department of Labor and Industry Did Not Perform Adequate Monitoring of Temporary Assistance for Needy Families Subrecipients (A Similar Condition Was Noted in Prior Year Finding 2024-009) Federal Grant Number(s) and Year(s): 2401PATANF (10/01/2023 – 9/30/2024), 2301PATANF (10/01/2022 – 9/30/2023), 2201PATANF (10/01/2021 – 9/30/2022), 2101PATANF (10/01/2020 – 9/30/2021) Type of Finding: Significant Deficiency in Internal Control over Compliance, Other Matters Compliance Requirement: Subrecipient Monitoring Condition: During the fiscal year ended June 30, 2025, the Department of Labor and Industry (L&I) paid $26.9 million in Temporary Assistance for Needy Families (TANF) funding to 22 subrecipients within the Youth Employment and Training (E&T) appropriation (or 6.7 percent) out of total federal TANF expenditures of $403.4 million reported on the June 30, 2025 Schedule of Expenditures of Federal Awards (SEFA). Our testing of L&I’s during-the-award monitoring of subrecipients for the fiscal year ended June 30, 2025, disclosed that L&I did not conduct on-site monitoring or perform desk reviews of the TANF Youth Development Program (TANF YDP) for three out of five subrecipients selected for testing. Although L&I performed monitoring of these subrecipients specific to another federal program, the monitoring did not include a review of the performance of the subrecipients’ TANF YDP programs. The TANF YDP operations transitioned from the Bureau of Workforce Development Administration (BWDA) to the Bureau of Workforce Partnership and Operations (BWPO) in December 2023. During the fiscal year ended June 30, 2025, BWPO began onsite monitoring of the TANF YDP program on a limited basis by developing a pilot program that BWPO used to monitor the TANF YDP program for three subrecipients. BWPO developed a written TANF YDP Monitoring Plan that outlines plans to expand the monitoring to other TANF YDP subrecipients; however, the plan was not fully implemented as of June 30, 2025. Criteria: 2 CFR Section 200.332, Requirements for pass-through entities, states: A pass-through entity must: (e) Monitor the activities of a subrecipient as necessary to ensure that the subrecipient complies with Federal statutes, regulations, and the terms and conditions of the subaward. The pass-through entity is responsible for monitoring the overall performance of a subrecipient to ensure that the goals and objectives of the subaward are achieved. In monitoring a subrecipient, a pass-through entity must: (1) Review financial and performance reports. (2) Ensure that the subrecipient takes corrective action on all significant developments that negatively affect the subaward. Significant developments include Single Audit findings related to the subaward, other audit findings, site visits, and written notifications from a subrecipient of adverse conditions which will impact their ability to meet the milestones or the objectives of a subaward. When significant developments negatively impact the subaward, a subrecipient must provide the pass-through entity with information on their plan for corrective action and any assistance needed to resolve the situation. Finding 2025 – 009: (continued) (3) Issue a management decision for audit findings pertaining only to the Federal award provided to the subrecipient from the pass-through entity as required by § 200.521. (4) Resolve audit findings specifically related to the subaward. However, the pass-through entity is not responsible for resolving cross-cutting audit findings that apply to the subaward and other Federal awards or subawards. If a subrecipient has a current Single Audit report and has not been excluded from receiving Federal funding (meaning, has not been debarred or suspended), the pass-through entity may rely on the subrecipient’s cognizant agency for audit or oversight agency for audit to perform audit follow-up and make management decisions related to cross-cutting audit findings in accordance with section § 200.513(a)(4)(viii). Such reliance does not eliminate the responsibility of the pass-through entity to issue subawards that conform to agency and award-specific requirements, to manage risk through ongoing subaward monitoring, and to monitor the status of the findings that are specifically related to the subaward. (f) Depending upon the pass-through entity's assessment of risk posed by the subrecipient (as described in paragraph (c) of this section), the following monitoring tools may be useful for the pass-through entity to ensure proper accountability and compliance with program requirements and achievement of performance goals: (1) Providing subrecipients with training and technical assistance on program-related matters; (2) Performing site visits to review the subrecipient's program operations; and (3) Arranging for agreed-upon-procedures engagements as described in §200.425. Management Directive 325.12, Amended – Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office’s Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: L&I recognized the need to perform during-the-award monitoring procedures for TANF funds passed through for the Youth E&T program, but the updated monitoring procedures were not fully incorporated during the fiscal year ended June 30, 2025. Effect: TANF subrecipients could be operating in noncompliance with federal regulations without timely detection and correction by L&I management. Recommendation: L&I should continue to strengthen controls to ensure during-the-award monitoring is being performed for all TANF subrecipients and that the monitoring includes procedures to ensure that subrecipients are in compliance with applicable federal regulations. This should include examining subrecipients’ financial records and ensuring that all required Single Audits were obtained by L&I subrecipients. Agency Response: L&I agrees with this finding. TANF YDP operations transitioned from BWDA to BWPO in January 2023. Due to this transition, BWPO did not conduct on site monitoring of the TANF YDP program in Program Year (PY) 22. BWPO did begin monitoring in PY 23 on a limited basis as a pilot with 3 local areas in September of 2024. BWPO expanded monitoring efforts in 2025 by conducting PY 24 TANF YDP monitoring in alignment with the WIOA Common Measures Data Validation cycle. This enhanced desk review monitoring effort concluded by January 2026. PY is defined as July 1st to June 30th. BWPO will further expand annual monitoring of TANF YDP in alignment with the requirement to monitor all TANF YDP grant subrecipients for PY 25 and moving forward. L&I does ensure single audits are obtained from the TANF YDP sub-recipients as a part of our single audit review. Finding 2025 – 009: (continued) Questioned Costs: The amount of questioned costs cannot be determined.

Corrective Action Plan

TANF Youth Development Program (TANF YDP) operations transitioned from the Bureau of Workforce Development Administration (BWDA) to the Bureau of Workforce Partnerships and Operations (BWPO) in January 2023. Due to this transition, BWPO did not conduct onsite monitoring of the TANF YDP program in program year (PY) 2022. BWPO did begin onsite monitoring in program year 2023 on a limited basis as a pilot with 3 local areas in September of 2024. BWPO conducted expanded monitoring efforts for PY 2024 by aligning TANF YDP monitoring with the WIOA Common Measures Data Validation cycle (larger areas are monitored annually with smaller areas monitored on a 3-year rotating schedule). PYs are July 1st to June 30th. TANF YDP PY 2024 monitoring concluded by January 2026. BWPO provided written communication to local areas within 45 days post monitoring to issue results, concerns, recommendations, and corrective actions as needed. During PY 2025, July 1, 2025 to June 30, 2026, L&I will monitor all 22 subrecipients for both program and fiscal compliance to ensure that the goals and objectives of the subaward are achieved. This will be done in coordination between BWPO and BWDA. Monitoring will then be completed annually. Currently, BWDA does reconcile the TANF Youth Development Partnership Statement of Expenditures of Financial Awards for each of the subrecipients’ single audits, reviews all TANF findings related to the TANF YDP funds and ensures all single audits are received - issuing audit management determinations. The overall goal of monitoring activities is to ensure that TANF YDF funding is used for authorized purposes by subrecipients, in compliance with Federal statutes and regulations, and that the TANF YDP program is being implemented in accordance with current PA Dept. of Labor & Industry’s policies and procedures. BWPO in collaboration with BWDA plans to begin monitoring TANF YDP activities via enhanced desk review monitoring in the spring of 2026 for PY 2025. This effort will be ongoing and moving forward for every subsequent program year either onsite or by enhanced desk review monitoring. PY 2025 monitoring will be completed by 6/30/26 with results issued as a written communication within 45 days of the monitoring completion date. Anticipated Completion Date: 06/30/2026 Contact Name: Dorraine Rauch, Division Chief

Prior Finding References

2024-009

About Subrecipient Monitoring →
2025-010
Other

The Department of Military and Veterans Affairs (DMVA) uses MatrixCare to track data regarding daily bed counts, moves, additions, and subtractions of nursing home residents needed to calculate the federal reimbursement amount on the monthly invoice. MatrixCare is hosted by the vendor and has a System and Organization Control (SOC) report available. During our audit of the information technology (IT) controls implemented by DMVA we noted the following: • A current SOC report was not obtained and reviewed; and • A review of user accounts and associated permissions is not routinely performed. Criteria: Management Directive 325.12, Amended – Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office’s Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Management Directive 325.13, Amended – Service Organization Controls states in part: Evaluate appropriate levels of oversight, as well as determine which monitoring requirements, independent audits, or assessments are needed to confirm the operating effectiveness of a Service Organization’s Internal Control system. Cause: Established policies and procedures were not followed consistently, which resulted in ineffective internal controls over MatrixCare. Effect: Inadequate oversight of the service organization increases the risk that residents’ records will not be accurate and complete for determining the monthly federal reimbursements. Recommendation: We recommend that DMVA implement procedures to complete the following: • Obtain and review the MatrixCare SOC report at least annually; and • Review all user accounts for appropriateness of access. Finding 2025 – 010: (continued) Agency Response: The agency concurs the SOC2 report was obtained in 2023, it was not obtained and reviewed during this audit period. The agency concurs no documented routine review of user accounts and associated permissions were performed. Questioned Costs: None

Show full finding ▾
Full finding narrative

Department of Military and Veterans Affairs Finding 2025 – 010: ALN 64.015 – Veterans State Nursing Home Care A Significant Deficiency Exists at the Department of Military and Veterans Affairs related to MatrixCare Application Federal Grant Number(s) and Year(s): D70314 (7/01/2024 – 6/30/2025), D75114 (7/01/2024 – 6/30/2025), D75214 (7/01/2024 – 6/30/2025), D75514 (7/01/2024 – 6/30/2025), D75814 (7/01/2024 – 6/30/2025), D77814 (7/01/2024 – 6/30/2025) Type of Finding: Significant Deficiency in Internal Control over Compliance Compliance Requirement: Other Condition: The Department of Military and Veterans Affairs (DMVA) uses MatrixCare to track data regarding daily bed counts, moves, additions, and subtractions of nursing home residents needed to calculate the federal reimbursement amount on the monthly invoice. MatrixCare is hosted by the vendor and has a System and Organization Control (SOC) report available. During our audit of the information technology (IT) controls implemented by DMVA we noted the following: • A current SOC report was not obtained and reviewed; and • A review of user accounts and associated permissions is not routinely performed. Criteria: Management Directive 325.12, Amended – Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office’s Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Management Directive 325.13, Amended – Service Organization Controls states in part: Evaluate appropriate levels of oversight, as well as determine which monitoring requirements, independent audits, or assessments are needed to confirm the operating effectiveness of a Service Organization’s Internal Control system. Cause: Established policies and procedures were not followed consistently, which resulted in ineffective internal controls over MatrixCare. Effect: Inadequate oversight of the service organization increases the risk that residents’ records will not be accurate and complete for determining the monthly federal reimbursements. Recommendation: We recommend that DMVA implement procedures to complete the following: • Obtain and review the MatrixCare SOC report at least annually; and • Review all user accounts for appropriateness of access. Finding 2025 – 010: (continued) Agency Response: The agency concurs the SOC2 report was obtained in 2023, it was not obtained and reviewed during this audit period. The agency concurs no documented routine review of user accounts and associated permissions were performed. Questioned Costs: None

Corrective Action Plan

The MatrixCare SOC2 report for 2025 was received on Friday February 6, 2026 and was reviewed by the Agency’s Information Technology (IT) Executive. The Agency’s Information Technology Executive/designee will educate the Information Technology Project Manager to request from Matrixcare on an annual basis the SOC2 report and will review compliance criteria such as data security and confidentiality. An Agency Information Technology Resource Account will be developed for the SOC2 report/s to be sent to for review. Future contracts will request the vendor to automatically send SOC2 reports to the established IT Resource Account. Matrixcare security templates for Healthcare Record access have been updated by the Change Management Committee and activated by the Nurse Administrator-Technical for all users to ensure appropriate access. The Agency’s Human Resources Field Operations Manager/designee will educate the State Veterans Home (SVH) Human Resources Assistants of their responsibilities for on-boarding and off-boarding documentation for employee hires, classification changes and separations and of the DMVA’s Onboarding and Offboarding User Guides. The SVH Human Resource Analyst/designee will provide to the SVH Privacy Officer/designee all employee actions monthly to review for appropriate Healthcare Record access, the Bureau of Veterans Homes (BVH) Healthcare Record Management protocol will be updated to reflect this audit. The Agency’s Privacy Officer/designee will review 25% of all employee actions annually during each State Veterans’ Homes’ Facility Performance Assessment (FPA) to verify appropriate Healthcare Record access, the BVH FPA Protocol will be updated to reflect this audit. Anticipated Completion Date: 04/15/2026 Contact Name: Barbara L. Raymond, Director, Bureau of Veterans Homes

About Other →
2025-011
Other

As part of testing internal controls over the AMLR program, we performed certain tests of information technology (IT) general controls over a computer application used by the Department of Environmental Protection, Bureau of Abandoned Mine Reclamation (BAMR) to record and process subrecipient expenditures. During our testing, we identified a lack of segregation of duties whereby 15 application developers had the ability to promote code to production on servers supported by Office of Administration – Office for Information Technology’s (OA-OIT’s) Enterprise Solutions Office and the Infrastructure and Economic Development (I&ED) Delivery Center. Details of this issue have been provided to OA-OIT’s Enterprise Solutions Office and I&ED Delivery Center for their information and corrective action. Criteria: Management Directive 325.12, Amended – Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office’s Standards for Internal Control in the Federal Government (Green Book). • Green Book Principle 10 – Design Control Activities, states in part: o 10.12 Management considers segregation of duties in designing control activity responsibilities so that incompatible duties are segregated and, where such segregation is not practical, designs alternative control activities to address the risk. • Green Book Principle 11 – Design Activities for the Information System, states in part: o 11.07 General controls facilitate the proper operation of information systems by creating the environment for proper operation of application controls. General controls include security management, logical and physical access, configuration management, segregation of duties, and contingency planning. o 11.09 Management designs control activities over the information technology infrastructure to support the completeness, accuracy, and validity of information processing by information technology. … Management evaluates the objectives of the entity and related risks in designing control activities for the information technology infrastructure. o 11.11 Management designs control activities for security management of the entity’s information system for appropriate access by internal and external sources to protect the entity’s information system. Finding 2025 – 011: (continued) o 11.12 Management designs control activities over access to protect an entity from inappropriate access and unauthorized use of the system. These control activities support appropriate segregation of duties. By preventing unauthorized use of and changes to the system, data and program integrity are protected from malicious intent (e.g., someone breaking into the technology to commit fraud, vandalism, or terrorism) or error. o 11.14 Management designs control activities to limit user access to information technology through authorization control activities…These control activities may restrict authorized users to the applications or functions commensurate with their assigned responsibilities, supporting an appropriate segregation of duties. A well-designed system of internal controls dictates effective IT general controls, which necessitates that adequate segregation of duties controls be established and functioning to ensure overall agency operations are conducted in accordance with management’s intent. Cause: The segregation of duties weakness occurred when IT support services for this application were being transitioned from an agency/delivery center-supported service to an OA-OIT Enterprise-supported service in July 2022. Prior to the transition, OA-OIT management was aware that developers had been accessing production servers to make deployments, and this process was retained temporarily until a new process with better segregation of duties could be put in place. In 2023, as outdated servers for the application were being replaced, all deployments became the responsibility of I&ED Delivery Center server and database administrators, and OA-OIT Enterprise management directed their application developers that they would no longer be able to log into production servers and perform direct deployments to production environments. However, due to an oversight when the servers were replaced, the Active Directory group containing 15 application developers remained on the servers with the ability to log into the servers and perform deployments. Effect: Lack of segregation of duties between development and production contributes to the risk that system actions can occur that are not in accordance with management’s intent, including unauthorized changes to the software and noncompliance with federal laws and regulations. Further, without properly functioning controls over segregation of duties, the auditors are precluded from reliance on computer controls in these agencies. Recommendation: We recommend that OA-OIT and I&ED Delivery Center management implement controls and procedures that segregate the responsibility for the development of programs from the promotion to production environment. Agency Response: The agency agrees with the facts of the finding. The details of the root cause have been provided in the Cause section above. Questioned Costs: None

Show full finding ▾
Full finding narrative

Office of Administration – Office for Information Technology Finding 2025 – 011: ALN 15.252 – Abandoned Mine Land Reclamation (AMLR) A Significant Deficiency Exists at the Department of Environmental Protection Related to Segregation of Duties Federal Grant Number(s) and Year(s): S18AF20004 (11/01/2017 – 10/31/2025), S19AF20004 (12/01/2018 – 11/30/2026), S22AF00017 (1/01/2022 – 12/31/2026), S23AF00002 (11/01/2022 – 10/31/2027), S23AF00022 (10/01/2022 – 9/30/2026), S23AF00028 (11/01/2022 – 10/31/2026), S24AF00026 (11/01/2023 – 10/31/2028) Type of Finding: Significant Deficiency in Internal Control over Compliance Compliance Requirement: Other Condition: As part of testing internal controls over the AMLR program, we performed certain tests of information technology (IT) general controls over a computer application used by the Department of Environmental Protection, Bureau of Abandoned Mine Reclamation (BAMR) to record and process subrecipient expenditures. During our testing, we identified a lack of segregation of duties whereby 15 application developers had the ability to promote code to production on servers supported by Office of Administration – Office for Information Technology’s (OA-OIT’s) Enterprise Solutions Office and the Infrastructure and Economic Development (I&ED) Delivery Center. Details of this issue have been provided to OA-OIT’s Enterprise Solutions Office and I&ED Delivery Center for their information and corrective action. Criteria: Management Directive 325.12, Amended – Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office’s Standards for Internal Control in the Federal Government (Green Book). • Green Book Principle 10 – Design Control Activities, states in part: o 10.12 Management considers segregation of duties in designing control activity responsibilities so that incompatible duties are segregated and, where such segregation is not practical, designs alternative control activities to address the risk. • Green Book Principle 11 – Design Activities for the Information System, states in part: o 11.07 General controls facilitate the proper operation of information systems by creating the environment for proper operation of application controls. General controls include security management, logical and physical access, configuration management, segregation of duties, and contingency planning. o 11.09 Management designs control activities over the information technology infrastructure to support the completeness, accuracy, and validity of information processing by information technology. … Management evaluates the objectives of the entity and related risks in designing control activities for the information technology infrastructure. o 11.11 Management designs control activities for security management of the entity’s information system for appropriate access by internal and external sources to protect the entity’s information system. Finding 2025 – 011: (continued) o 11.12 Management designs control activities over access to protect an entity from inappropriate access and unauthorized use of the system. These control activities support appropriate segregation of duties. By preventing unauthorized use of and changes to the system, data and program integrity are protected from malicious intent (e.g., someone breaking into the technology to commit fraud, vandalism, or terrorism) or error. o 11.14 Management designs control activities to limit user access to information technology through authorization control activities…These control activities may restrict authorized users to the applications or functions commensurate with their assigned responsibilities, supporting an appropriate segregation of duties. A well-designed system of internal controls dictates effective IT general controls, which necessitates that adequate segregation of duties controls be established and functioning to ensure overall agency operations are conducted in accordance with management’s intent. Cause: The segregation of duties weakness occurred when IT support services for this application were being transitioned from an agency/delivery center-supported service to an OA-OIT Enterprise-supported service in July 2022. Prior to the transition, OA-OIT management was aware that developers had been accessing production servers to make deployments, and this process was retained temporarily until a new process with better segregation of duties could be put in place. In 2023, as outdated servers for the application were being replaced, all deployments became the responsibility of I&ED Delivery Center server and database administrators, and OA-OIT Enterprise management directed their application developers that they would no longer be able to log into production servers and perform direct deployments to production environments. However, due to an oversight when the servers were replaced, the Active Directory group containing 15 application developers remained on the servers with the ability to log into the servers and perform deployments. Effect: Lack of segregation of duties between development and production contributes to the risk that system actions can occur that are not in accordance with management’s intent, including unauthorized changes to the software and noncompliance with federal laws and regulations. Further, without properly functioning controls over segregation of duties, the auditors are precluded from reliance on computer controls in these agencies. Recommendation: We recommend that OA-OIT and I&ED Delivery Center management implement controls and procedures that segregate the responsibility for the development of programs from the promotion to production environment. Agency Response: The agency agrees with the facts of the finding. The details of the root cause have been provided in the Cause section above. Questioned Costs: None

Corrective Action Plan

Alfred Yaney, Director, Enterprise e-Grants, opened a remedy ticket requesting to have the e-Grants group removed from the list of permitted groups. Screenshots were provided to the auditors as evidence of all the groups that have Admin access to validate the requested group had been removed. Anticipated Completion Date: Completed Contact Name: Carolyn McCarthy, Head of Governance, Risk and Compliance

About Other →
2025-012
Reporting
MATERIAL WEAKNESS

The Federal Funding Accountability and Transparency Act (FFATA) requires the Commonwealth of Pennsylvania to report first-tier subawards of $30,000 or more to the federal government’s FFATA reporting system. The federal government reporting system was replaced during the audit period. The FFATA Subaward Reporting System (FSRS) was replaced with the System for Award Management (SAM.gov) on March 8, 2025. Necessary FFATA reporting details including the contract amount, contract date, federal award identification number, internal order number, and other information are entered into the Commonwealth’s SAP accounting system when the Commonwealth agencies award subrecipient contracts in order to ensure compliance with the FFATA reporting requirements. Each month, Commonwealth information technology personnel run an extract in SAP to populate a FFATA database and generate a report that summarizes the contract information required for that month’s FFATA reporting. The Office of the Budget, Bureau of Accounting and Financial Management (BAFM), is responsible for overseeing FFATA reporting, including reviewing the summary report to ensure the contract data is complete. Once reviewed, the information is uploaded into the FFATA reporting system to meet reporting requirements. Due to complications with the upgrade to SAM.gov, the Commonwealth was unable to upload the data to the system from March 8 until October 1 when they were able to start filing catch-up submissions. As a result, the Commonwealth was unable to report subawards in compliance with the reporting requirement timeframe. Finding 2025 – 012: (continued) Our testing of the FFATA reporting requirements for 40 subaward transactions totaling $258.9 million from five major programs disclosed that 37 transactions totaling $227.9 million, or 93 percent of transactions tested, were not reported or reported untimely to SAM.gov as follows: SEE SCHEDULE OF FINDINGS AND QUESTIONED COSTS FOR CHART/TABLE Criteria: 2 CFR Section 170, Appendix A to Part 170, Award Term, states in part: I. Reporting Subawards and Executive Compensation (a) Reporting of first-tier subawards — (1) Applicability. Unless the recipient is exempt as provided in paragraph (d) of this award term, the recipient must report each subaward that equals or exceeds $30,000 in Federal funds for a subaward to an entity or Federal agency. The recipient must also report a subaward if a modification increases the Federal funding to an amount that equals or exceeds $30,000. All reported subawards should reflect the total amount of the subaward. (2) Reporting Requirements. (i) The recipient must report each subaward described in paragraph (a)(1) of this award term to the Federal Funding Accountability and Transparency Act Subaward Reporting System (FSRS) at http://www.fsrs.gov. (ii) For subaward information, report no later than the end of the month following the month in which the subaward was issued. (For example, if the subaward was made on November 7, 2025, the subaward must be reported by no later than December 31, 2025). Management Directive 325.12, Amended – Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office’s Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: As of March 8, 2025, the FSRS system was replaced with SAM.gov for reporting subaward data. BAFM indicated that with the transition to SAM.gov, the federal government encountered errors and complications that resulted in delay with reporting subaward data timely. As of February 2026, BAFM continues to refine the interface upload process and identify and file previously unfiled reports. Finding 2025 – 012: (continued) Effect: BAFM was unable to timely file subaward information in SAM.gov to satisfy FFATA Reporting requirements. Further, noncompliance with FFATA reporting requirements may recur in future periods if control deficiencies are not corrected to ensure completeness of the subaward information reported in SAM.gov. Recommendation: We recommend that BAFM continue to work with the federal government to ensure accurate reporting in SAM.gov. Also, BAFM should continue efforts to develop and implement procedures to ensure reporting in SAM.gov is accurate and complete in accordance with FFATA reporting requirements. Agency Response: BAFM agrees with this finding. Questioned Costs: None

Show full finding ▾
Full finding narrative

Office of the Budget – Office of Comptroller Operations Finding 2025 – 012: ALN 15.252 – Abandoned Mine Land Reclamation (AMLR) ALN 93.044, 93.045, and 93.053 – Aging Cluster (including COVID-19) ALN 93.558 – Temporary Assistance for Needy Families ALN 93.667 – Social Services Block Grant ALN 97.036 – Disaster Grants – Public Assistance (Presidentially Declared Disasters) (including COVID-19) A Material Weakness and Material Noncompliance Exist in the Commonwealth’s FFATA Reporting Process Federal Grant Number(s) and Year(s): S18AF20004 (11/01/2017 – 10/31/2025), S19AF20004 (12/01/2018 – 11/30/2026), S22AF00017 (1/01/2022 – 12/31/2026), S23AF00002 (11/01/2022 – 10/31/2027), S23AF00022 (10/01/2022 – 9/30/2026), S23AF00028 (11/01/2022 – 10/31/2026), S24AF00026 (11/01/2023 – 10/31/2028) 2101PACMC6 (4/01/2021 – 9/30/2024), 2101PAHDC6 (4/01/2021 – 9/30/2024), 2101PASSC6 (4/01/2021 – 9/30/2024), 2201PASTPH (1/01/2022 – 9/30/2025), 2301PAOACM (10/01/2022 – 9/30/2025), 2301PAOAHD (10/01/2022 – 9/30/2025), 2301PAOASS (10/01/2022 – 9/30/2025), 2401PAOACM (10/01/2023 – 9/30/2025), 2401PAOAHD (10/01/2023 – 9/30/2025), 2401PAOANS (10/01/2023 – 9/30/2025), 2401PAOASS (10/01/2023 – 9/30/2025), 2501PAOASS (10/01/2024 – 9/30/2026), 2501PAOACM (10/01/2024 – 9/30/2026), 2501PAOAHD (10/01/2024 – 9/30/2026), 2501PAOANS (10/01/2024 – 9/30/2026) 2501PATANF (10/01/2024 – 9/30/2025), 2401PATANF (10/01/2023 – 9/30/2024), 2301PATANF (10/01/2022 – 9/30/2023), 2201PATANF (10/01/2021 – 9/30/2022), 2101PATANF (10/01/2020 – 9/30/2021) 2501PASOSR (10/01/2024 – 9/30/2026), 2401PASOSR (10/01/2023 – 9/30/2025) 4408DRPAP00000001 (11/27/2018 – 10/31/2026), 4506DRPAP00000001 (1/20/2020 – 12/30/2025), 4618DRPAP00000001 (8/31/2021 – 9/30/2026), 4815DRPAP00000001 (9/11/2024 – 9/11/2028) Type of Finding: Material Weakness in Internal Control over Compliance, Material Noncompliance Compliance Requirement: Reporting – Federal Funding Accountability and Transparency Act Condition: The Federal Funding Accountability and Transparency Act (FFATA) requires the Commonwealth of Pennsylvania to report first-tier subawards of $30,000 or more to the federal government’s FFATA reporting system. The federal government reporting system was replaced during the audit period. The FFATA Subaward Reporting System (FSRS) was replaced with the System for Award Management (SAM.gov) on March 8, 2025. Necessary FFATA reporting details including the contract amount, contract date, federal award identification number, internal order number, and other information are entered into the Commonwealth’s SAP accounting system when the Commonwealth agencies award subrecipient contracts in order to ensure compliance with the FFATA reporting requirements. Each month, Commonwealth information technology personnel run an extract in SAP to populate a FFATA database and generate a report that summarizes the contract information required for that month’s FFATA reporting. The Office of the Budget, Bureau of Accounting and Financial Management (BAFM), is responsible for overseeing FFATA reporting, including reviewing the summary report to ensure the contract data is complete. Once reviewed, the information is uploaded into the FFATA reporting system to meet reporting requirements. Due to complications with the upgrade to SAM.gov, the Commonwealth was unable to upload the data to the system from March 8 until October 1 when they were able to start filing catch-up submissions. As a result, the Commonwealth was unable to report subawards in compliance with the reporting requirement timeframe. Finding 2025 – 012: (continued) Our testing of the FFATA reporting requirements for 40 subaward transactions totaling $258.9 million from five major programs disclosed that 37 transactions totaling $227.9 million, or 93 percent of transactions tested, were not reported or reported untimely to SAM.gov as follows: SEE SCHEDULE OF FINDINGS AND QUESTIONED COSTS FOR CHART/TABLE Criteria: 2 CFR Section 170, Appendix A to Part 170, Award Term, states in part: I. Reporting Subawards and Executive Compensation (a) Reporting of first-tier subawards — (1) Applicability. Unless the recipient is exempt as provided in paragraph (d) of this award term, the recipient must report each subaward that equals or exceeds $30,000 in Federal funds for a subaward to an entity or Federal agency. The recipient must also report a subaward if a modification increases the Federal funding to an amount that equals or exceeds $30,000. All reported subawards should reflect the total amount of the subaward. (2) Reporting Requirements. (i) The recipient must report each subaward described in paragraph (a)(1) of this award term to the Federal Funding Accountability and Transparency Act Subaward Reporting System (FSRS) at http://www.fsrs.gov. (ii) For subaward information, report no later than the end of the month following the month in which the subaward was issued. (For example, if the subaward was made on November 7, 2025, the subaward must be reported by no later than December 31, 2025). Management Directive 325.12, Amended – Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office’s Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: As of March 8, 2025, the FSRS system was replaced with SAM.gov for reporting subaward data. BAFM indicated that with the transition to SAM.gov, the federal government encountered errors and complications that resulted in delay with reporting subaward data timely. As of February 2026, BAFM continues to refine the interface upload process and identify and file previously unfiled reports. Finding 2025 – 012: (continued) Effect: BAFM was unable to timely file subaward information in SAM.gov to satisfy FFATA Reporting requirements. Further, noncompliance with FFATA reporting requirements may recur in future periods if control deficiencies are not corrected to ensure completeness of the subaward information reported in SAM.gov. Recommendation: We recommend that BAFM continue to work with the federal government to ensure accurate reporting in SAM.gov. Also, BAFM should continue efforts to develop and implement procedures to ensure reporting in SAM.gov is accurate and complete in accordance with FFATA reporting requirements. Agency Response: BAFM agrees with this finding. Questioned Costs: None

Corrective Action Plan

BAFM has collaborated with the U.S. General Services Administration (GSA) and the Commonwealth of Pennsylvania’s Office of Administration, Office of Information Technology (OA-IT) to develop a new API solution to centrally file FFATA subrecipient reports following the federal system change implemented in March 2025. As of December 2025, BAFM restored the monthly centralized FFATA filing process. BAFM currently performs review and validation of all monthly records, and OA-IT submits the reports on BAFM’s behalf. Within six months (by June 2026), BAFM will work with OA-IT to finalize and refine the API process to enable BAFM to independently submit reports without OA-IT assistance. Due to federal system limitations on daily API request volumes, reconciliation of statewide records not filed during the transition period has been challenging. Within six months (by June 2026), BAFM will evaluate available data retrieval options to complete reconciliation of records not filed during the changeover period. Any identified missed filings will be submitted as part of this reconciliation process. Anticipated Completion Date: 06/30/2026 Contact Names: Jamie Jerosky, BAFM Assistant Director; Matt Stubb, BAFM Integrated Financial Service Manager

About Reporting →
2025-013
Subrecipient Monitoring
REPEATQUESTIONED COSTS

The Uniform Guidance in 2 CFR Section 200 applies to the major programs listed above for the fiscal year ended June 30, 2025. Our testing disclosed that the Pennsylvania Department of Agriculture (PDA) did not identify the federal award information in subrecipient award documents. Additionally, PDA, and the Pennsylvania Department of Aging (PDOA) did not adequately evaluate each subrecipient’s risk of noncompliance for the purpose of determining the appropriate subrecipient monitoring related to the subaward. This represents an internal control weakness which could cause subrecipients to be improperly informed of federal award information and may result in inadequate monitoring by the state agencies. Also, it could cause the omission or improper identification of program expenditures on subrecipients’ Schedules of Expenditures of Federal Awards (SEFAs). The following chart shows which federal award information required by 2 CFR Section 200 was omitted (as indicated by “No”) from the subrecipient award documents at the time of the subaward and which major programs did not have a state agency evaluation of each subrecipient’s risk of noncompliance. SEE SCHEDULE OF FINDINGS AND QUESTIONED COSTS FOR CHART/TABLE Finding 2025 – 013: (continued) Criteria: 2 CFR Section 200.332, Requirements for pass-through entities, states in part: All pass-through entities must: (b) Ensure that every subaward is clearly identified to the subrecipient as a subaward and includes the information provided below. A pass-through entity must provide the best available information when some of the information below is unavailable. A pass-through entity must provide the unavailable information when it is obtained. Required information includes: (1) Federal award identification. (iii) Federal Award Identification Number (FAIN); (6) Appropriate terms and conditions concerning closeout of the subaward. (c) Evaluate each subrecipient's fraud risk and risk of noncompliance with a subaward to determine the appropriate subrecipient monitoring described in paragraph (f) of this section. When evaluating a subrecipient's risk, a pass-through entity should consider the following: (1) The subrecipient's prior experience with the same or similar subawards; (2) The results of previous audits. This includes considering whether or not the subrecipient receives a Single Audit in accordance with subpart F and the extent to which the same or similar subawards have been audited as a major program; (3) Whether the subrecipient has new personnel or new or substantially changed systems; and (4) The extent and results of any Federal agency monitoring (for example, if the subrecipient also receives Federal awards directly from the Federal agency). Management Directive 325.12, Amended – Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office’s Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should identify, analyze, and respond to risks related to achieving the defined objectives. Management should identify, analyze, and respond to significant changes that could impact the internal control system. Cause: In general, PDA’s (Commodity Supplemental Food Program) processes for subrecipient award monitoring did not identify the omission of required elements from the grant awards. In addition, the risk assessments performed by PDA and PDOA were not properly documented or not performed. Effect: Excluding the federal grant award information at the time of the subaward may cause subrecipients and their auditors to be uninformed about specific program and other regulations that apply to the funds they receive. There is also the potential for subrecipients to have incomplete SEFAs in their Single Audit reports submitted to the Commonwealth, and federal funds may not be properly audited at the subrecipient level in accordance with the Single Audit Act and Uniform Guidance. Not evaluating each subrecipient’s risk of noncompliance for purposes of determining the appropriate subrecipient monitoring related to the subaward may result in subrecipients using the subaward for unauthorized purposes or in violation of the terms and conditions of the subaward, and state agency monitoring would not detect this noncompliance and ensure it is corrected in a timely manner. Finding 2025 – 013: (continued) Recommendation: PDA should develop policies and reporting mechanisms to ensure all required federal award information is disseminated to all subrecipients at the time of the subaward to ensure subrecipient compliance with the Uniform Guidance in 2 CFR Section 200 and other applicable federal regulations. In addition, PDA should correspond with applicable subrecipients to ensure they are aware of the correct federal award information and review applicable subaward documents prior to issuance to ensure federal information is complete and accurate. PDA and PDOA should implement procedures to adequately document their evaluation of each subrecipient’s risk of noncompliance as cited in 2 CFR Section 200.332 for purposes of determining the appropriate subrecipient monitoring related to the subaward. PDA Response: PDA agrees with this finding. PDOA Response: PDOA agrees with this finding. Questioned Costs: The amount of questioned costs cannot be determined.

Show full finding ▾
Full finding narrative

Department of Agriculture Department of Aging Finding 2025 – 013: ALN 10.565, 10.568, and 10.569 – Food Distribution Cluster ALN 93.044, 93.045, and 93.053 – Aging Cluster (including COVID-19) State Agencies Did Not Identify the Federal Award Information and Applicable Requirements at the Time of the Subaward and Did Not Evaluate Each Subrecipient’s Risk of Noncompliance as Required by the Uniform Grant Guidance (A Similar Condition Was Noted in Prior Year Finding 2024-014) Federal Grant Number(s) and Year(s): 241PA825Y8005 (10/01/2023 – 9/30/2024), 241PA825Y8105 (10/01/2023 – 9/30/2024), 241PA445Q2204 (10/01/2023 – 9/30/2024), 251PA825Y8105 (10/01/2024 – 9/30/2025), 228PA100I1003 (6/13/2022 – 6/30/2025), 238PA000I1003 (5/25/2023 – 6/30/2025), 2101PACMC6 (4/01/2021 – 9/30/2024), 2101PAHDC6 (4/01/2021 – 9/30/2024), 2101PASSC6 (4/01/2021 – 9/30/2024), 2201PASTPH (1/01/2022 – 9/30/2025), 2301PAOACM (10/01/2022 – 9/30/2025), 2301PAOAHD (10/01/2022 – 9/30/2025), 2301PAOASS (10/01/2022 – 9/30/2025), 2401PAOACM (10/01/2023 – 9/30/2025), 2401PAOAHD (10/01/2023 – 9/30/2025), 2401PAOANS (10/01/2023 – 9/30/2025), 2401PAOASS (10/01/2023 – 9/30/2025), 2501PAOACM (10/01/2024 – 9/30/2026), 2501PAOAHD (10/01/2024 – 9/30/2026), 2501PAOANS (10/01/2024 – 9/30/2026), 2501PAOASS (10/01/2024 – 9/30/2026) Type of Finding: Significant Deficiency in Internal Control over Compliance, Other Matters Compliance Requirement: Subrecipient Monitoring Condition: The Uniform Guidance in 2 CFR Section 200 applies to the major programs listed above for the fiscal year ended June 30, 2025. Our testing disclosed that the Pennsylvania Department of Agriculture (PDA) did not identify the federal award information in subrecipient award documents. Additionally, PDA, and the Pennsylvania Department of Aging (PDOA) did not adequately evaluate each subrecipient’s risk of noncompliance for the purpose of determining the appropriate subrecipient monitoring related to the subaward. This represents an internal control weakness which could cause subrecipients to be improperly informed of federal award information and may result in inadequate monitoring by the state agencies. Also, it could cause the omission or improper identification of program expenditures on subrecipients’ Schedules of Expenditures of Federal Awards (SEFAs). The following chart shows which federal award information required by 2 CFR Section 200 was omitted (as indicated by “No”) from the subrecipient award documents at the time of the subaward and which major programs did not have a state agency evaluation of each subrecipient’s risk of noncompliance. SEE SCHEDULE OF FINDINGS AND QUESTIONED COSTS FOR CHART/TABLE Finding 2025 – 013: (continued) Criteria: 2 CFR Section 200.332, Requirements for pass-through entities, states in part: All pass-through entities must: (b) Ensure that every subaward is clearly identified to the subrecipient as a subaward and includes the information provided below. A pass-through entity must provide the best available information when some of the information below is unavailable. A pass-through entity must provide the unavailable information when it is obtained. Required information includes: (1) Federal award identification. (iii) Federal Award Identification Number (FAIN); (6) Appropriate terms and conditions concerning closeout of the subaward. (c) Evaluate each subrecipient's fraud risk and risk of noncompliance with a subaward to determine the appropriate subrecipient monitoring described in paragraph (f) of this section. When evaluating a subrecipient's risk, a pass-through entity should consider the following: (1) The subrecipient's prior experience with the same or similar subawards; (2) The results of previous audits. This includes considering whether or not the subrecipient receives a Single Audit in accordance with subpart F and the extent to which the same or similar subawards have been audited as a major program; (3) Whether the subrecipient has new personnel or new or substantially changed systems; and (4) The extent and results of any Federal agency monitoring (for example, if the subrecipient also receives Federal awards directly from the Federal agency). Management Directive 325.12, Amended – Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office’s Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should identify, analyze, and respond to risks related to achieving the defined objectives. Management should identify, analyze, and respond to significant changes that could impact the internal control system. Cause: In general, PDA’s (Commodity Supplemental Food Program) processes for subrecipient award monitoring did not identify the omission of required elements from the grant awards. In addition, the risk assessments performed by PDA and PDOA were not properly documented or not performed. Effect: Excluding the federal grant award information at the time of the subaward may cause subrecipients and their auditors to be uninformed about specific program and other regulations that apply to the funds they receive. There is also the potential for subrecipients to have incomplete SEFAs in their Single Audit reports submitted to the Commonwealth, and federal funds may not be properly audited at the subrecipient level in accordance with the Single Audit Act and Uniform Guidance. Not evaluating each subrecipient’s risk of noncompliance for purposes of determining the appropriate subrecipient monitoring related to the subaward may result in subrecipients using the subaward for unauthorized purposes or in violation of the terms and conditions of the subaward, and state agency monitoring would not detect this noncompliance and ensure it is corrected in a timely manner. Finding 2025 – 013: (continued) Recommendation: PDA should develop policies and reporting mechanisms to ensure all required federal award information is disseminated to all subrecipients at the time of the subaward to ensure subrecipient compliance with the Uniform Guidance in 2 CFR Section 200 and other applicable federal regulations. In addition, PDA should correspond with applicable subrecipients to ensure they are aware of the correct federal award information and review applicable subaward documents prior to issuance to ensure federal information is complete and accurate. PDA and PDOA should implement procedures to adequately document their evaluation of each subrecipient’s risk of noncompliance as cited in 2 CFR Section 200.332 for purposes of determining the appropriate subrecipient monitoring related to the subaward. PDA Response: PDA agrees with this finding. PDOA Response: PDOA agrees with this finding. Questioned Costs: The amount of questioned costs cannot be determined.

Corrective Action Plan

PDA: The Pennsylvania Department of Agriculture (PDA) Bureau of Food Assistance has already put the following steps in place to address this deficiency and noncompliance finding. 1. As of August 2025, PDA has a documented process to evaluate each subrecipient’s risk of noncompliance with federal statutes, regulations, and the term and conditions of the subaward for purposes of determining appropriate subrecipient monitoring. The evaluation process looks at Key Performance Indicators – such as leadership tenure, prior incidents of food spoilage, complaints, values of USDA Foods and USDA administrative funding – to determine the need for additional or more frequent monitoring. 2. As of October 2025, PDA has implemented a system to document the evaluation of each subrecipient’s risk of noncompliance. This system was used to determine if agencies would receive monitoring reviews throughout Federal Fiscal Year 2026 (October 1, 2025 - September 30, 2026). 3. PDA has been providing FAINs and providing information on applicable requirements at the time of subawards to all TEFAP counties and agencies. However, as the cited CSFP contract pre-dated this finding, the information had not been properly provided to our subrecipient. This has been rectified as of February 2026. Anticipated Completion Date: Completed Contact Name: Caryn Long Earl, Director, Bureau of Food Assistance PDOA: 1. Revise the risk-based subrecipient monitoring procedures. 2. Establish a formal risk-tiered monitoring framework requiring enhanced oversight for high-risk subrecipients. 3. Update written policies and procedures to meet standards. 4. Conduct annual internal compliance review of a sample of subawards. Anticipated Completion Date: 06/30/2026 Contact Names: Jason Kavulich, Secretary of Aging; Jennifer Beck, Fiscal Management Specialist & PDOA Audit Liaison

Prior Finding References

2024-014

About Subrecipient Monitoring →
2025-014
Subrecipient Monitoring
MATERIAL WEAKNESSREPEATQUESTIONED COSTS

Under the Commonwealth of Pennsylvania's (Commonwealth) implementation of the Single Audit Act, review and resolution of subrecipient Single Audit reports is split into two stages. The Office of the Budget’s Bureau of Accounting and Financial Management (OB-BAFM) ensures the reports meet technical standards through a centralized desk review process. The various funding agencies in the Commonwealth are responsible for making a management decision on each finding within six months of the Federal Audit Clearinghouse’s (FAC) acceptance date for audits subject to Uniform Guidance and to ensure appropriate corrective action is taken by the subrecipient (except for Uniform Guidance audits under U.S. Department of Labor programs which are permitted 12 months for management decisions in accordance with 2 CFR Section 2900.21). Each Commonwealth agency is also responsible for reviewing financial information in each audit report to determine whether the audit included all pass-through funding provided by the agency to ensure pass-through funds were subject to audit. Most agencies meet this requirement by performing Schedule of Expenditures of Federal Awards (SEFA) reconciliations. The agency is also required to adjust Commonwealth records, if necessary. Our fiscal year ended June 30, 2025 audit of the Commonwealth’s process for review and resolution of subrecipient Single Audits included an evaluation of the Commonwealth’s fiscal year ended June 30, 2024 subrecipient audit universe for audits due for submission to the FAC during the fiscal year ended June 30, 2025. We also evaluated the Commonwealth’s review of 47 subrecipient audit reports with findings in major programs/clusters which were identified on the Commonwealth agencies’ tracking lists during the fiscal year ended June 30, 2025 and required management decisions by Commonwealth agencies. Finding 2025 – 014: (continued) Our testing disclosed the following audit exceptions regarding the Commonwealth agencies’ review of subrecipient audit reports: • Pennsylvania Department of Aging (PDOA): Our testing disclosed that PDOA did not have adequate procedures in place for tracking and making management decisions on findings timely. The time period for making management decisions on findings was approximately 13.4 months to over 19 months after the FAC acceptance date for four out of four audit reports with findings. For the four items selected for testing, PDOA had not completed SEFA reconciliations or performed alternative procedures to ensure the subrecipient SEFAs were accurate so that major programs were properly determined and subjected to audit. • Department of Agriculture (PDA): The time period for making a management decision on findings was approximately eight months to over 15 months after the FAC acceptance date for four out of six audit reports with findings. There were also delays in PDA’s procedures to ensure the subrecipient SEFAs were accurate so that major programs were properly determined and subjected to audit. In addition, our testing disclosed that PDA subgranted federal funds of approximately $8.9 million to one subrecipient during fiscal year ended June 30, 2024, for which the Single Audit was not submitted to the FAC as of our February 2026 testing date. This was over 10 months after the March 31, 2025 due date. • Department of Education (PDE): The time period for making a management decision on findings was approximately 6.9 months to over 12 months after the FAC acceptance date for nine out of 30 audit reports with findings selected for testing. Three of the 30 audits reports were improperly classified on PDE’s audit tracking list as not having federal award findings. There were additional audit reports with findings listed on PDE’s audit tracking list where management decisions were not made timely. • Pennsylvania Infrastructure Investment Authority (PENNVEST): The time period for making a management decision on findings was over 15.9 months after the FAC acceptance date for one out of three audit reports with findings. For one out of three items selected for testing, PENNVEST had started but had not yet completed reconciling the SEFA to ensure the subrecipient SEFA was accurate so that major programs were properly determined and subject to audit. Criteria: 2 CFR Section 200.332, Requirements for pass-through entities, states in part: A pass-through entity must: (e) Monitor the activities of a subrecipient as necessary to ensure that the subrecipient complies with Federal statutes, regulations, and the terms and conditions of the subaward. The pass-through entity is responsible for monitoring the overall performance of a subrecipient to ensure that the goals and objectives of the subaward are achieved. In monitoring a subrecipient, a pass-through entity must: (2) Ensure that the subrecipient takes corrective action on all significant developments that negatively affect the subaward. Significant developments include Single Audit findings related to the subaward, other audit findings, site visits, and written notifications from a subrecipient of adverse conditions which will impact their ability to meet the milestones or the objectives of a subaward. When significant developments negatively impact the subaward, a subrecipient must provide the pass-through entity with information on their plan for corrective action and any assistance needed to resolve the situation. (3) Issue a management decision for audit findings pertaining only to the Federal award provided to the subrecipient from the pass-through entity as required by §200.521 [Management decision]. (g) Verify that a subrecipient is audited as required by Subpart F [Audit Requirements] of this part. (h) Consider whether the results of a subrecipient’s audit, site visits, or other monitoring necessitate adjustments to the pass-through entity’s records. Finding 2025 – 014: (continued) (i) Consider taking enforcement action against noncompliant subrecipients as described in §200.339 [Remedies for noncompliance] and in program regulations. In order to carry out these responsibilities properly, good internal control dictates that state pass-through agencies ensure subrecipient Single Audit SEFAs are representative of state payment records each year, and that the related federal programs have been properly subjected to Single Audit procedures. 2 CFR Section 200.512, Report submission, states in part: (a) General. (1) The audit, the data collection form, and the reporting package must be submitted within 30 calendar days after the auditee receives the auditor's report(s) or nine months after the end of the audit period (whichever is earlier). The cognizant agency for audit or oversight agency for audit (in the absence of a cognizant agency for audit) may authorize an extension when the nine-month timeframe would place an undue burden on the auditee. If the due date falls on a Saturday, Sunday, or Federal holiday, the reporting package is due the next business day. 2 CFR Section 200.521, Management decision, states in part: (a) General. The management decision must clearly state whether or not the finding is sustained, the reasons for the decision, and the expected auditee action to repay disallowed costs, make financial adjustments or take other action. (d) Time requirements. The Federal agency or pass-through entity responsible for issuing a management decision must do so within six months of the FAC’s acceptance of the audit report. The auditee must initiate and proceed with corrective action as rapidly as possible and corrective action should begin no later than upon receipt of the audit report. 2 CFR Section 200.505, Remedies for audit noncompliance, states: In cases of continued inability or unwillingness of a non-federal entity to have an audit conducted in accordance with this part, Federal agencies or pass-through entities must take appropriate action as provided in §200.339 [Remedies for noncompliance]. 2 CFR Section 200.339, Remedies for noncompliance, states in part: The Federal agency or pass-through entity may implement specific conditions if the recipient or subrecipient fails to comply with the U.S. Constitution, Federal statutes, regulations, or terms and conditions of the Federal award. See §200.208 for additional information on specific conditions. When the Federal agency or pass-through entity determines that noncompliance cannot be remedied by imposing specific conditions, the Federal agency or pass-through entity may take one or more of the following actions: (a) Temporarily withhold payments until the recipient or subrecipient takes corrective action. (b) Disallow costs for all or part of the activity associated with the noncompliance of the recipient or subrecipient. (c) Suspend or terminate the Federal award in part or in its entirety. (d) Initiate suspension or debarment proceedings as authorized in 2 CFR Part 180 and the Federal agency’s regulations, or for pass-through entities, recommend suspension or debarment proceedings be initiated by the Federal agency. (e) Withhold further Federal funds (new awards or continuation funding) for the project or program. (f) Pursue other legally available remedies. Finding 2025 – 014: (continued) To ensure Commonwealth enforcement of federal regulations for subrecipient noncompliance with audit requirements, Commonwealth Management Directive 325.08, Amended – Remedies for Recipient Noncompliance with Audit Requirements, Section 5 related to policy, states in part: (a) Agencies must develop and implement remedial action that reflects the unique requirements of each program… (b) The remedial action should be implemented within six months from the date the first remedial action is initiated. At the end of the six-month period, the recipient should take the appropriate corrective action or the final stage of remedial action should be imposed on the recipient. Examples of remedial action include, but are not limited to: (1) Meeting or calling the recipient to explain the importance and benefits of the audit and audit resolution processes, emphasizing the value of the audit as an administrative tool and the Commonwealth’s reliance on an acceptable audit and prompt resolution as evidence of the recipient’s ability to properly administer the program. (2) Encouraging the entity to establish an audit committee or designate an individual as the single point of contact to: (a) Communicate regarding the audit. (b) Arrange for and oversee the audit. (c) Direct and monitor audit resolution. (3) Providing technical assistance to the recipient in devising and implementing an appropriate plan to remedy the noncompliance. (4) Withholding a portion of assistance payments until the noncompliance is resolved. (5) Withholding or disallowing overhead costs until the noncompliance is resolved. (6) Suspending the assistance agreement until the noncompliance is resolved. (7) Terminating the assistance agreement with the recipient and, if necessary, seeking alternative entities to administer the program. Management Directive 325.09, Amended – Processing Subrecipient Single Audits of Federal Pass-Through Funds, Section 7 related to procedures, states in part: a. Agencies. (2) Evaluate single audit report submissions received from BAFM to determine program purpose acceptability by verifying, at a minimum, that all agency-funded programs are properly included on the applicable financial schedules; that findings affecting the agency contain sufficient information to facilitate a management decision; and that the subrecipient has submitted an adequate corrective action plan. (5) Issue management decisions relative to audit findings and crosscutting findings assigned to the agency for resolution, as required by 2 CFR §200.521. If responsible for the resolution of crosscutting findings, notify the affected agency or agencies upon resolution of such findings. (7) Impose or coordinate the imposition of remedial action in accordance with 2 CFR Part 200.339 and Management Directive 325.08 Amended, Remedies for Recipient Noncompliance with Audit Requirements, when subrecipients fail to comply with the provisions of Subpart F. Finding 2025 – 014: (continued) Management Directive 325.12, Amended – Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office’s, Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: One reason provided by Commonwealth management for untimely audit resolution in the various agencies, including making management decisions, approving corrective action, and performing procedures to ensure the accuracy of subrecipient SEFAs, was either a change in staff or a lack of staff to follow up and process subrecipient audit reports more timely. Regarding the late and outstanding audit report submission, PDA did not take timely remedial action steps in accordance with 2 CFR Section 200.339 and Commonwealth Management Directive 325.08 in order to ensure compliance with federal audit submission requirements. Effect: Since required management decisions were not made within six months to ensure appropriate corrective action was taken on audits received from subrecipients, the Commonwealth did not comply with federal regulations, and subrecipients were not made aware of acceptance or rejection of corrective action plans in a timely manner. Further, noncompliance may recur in future periods if control deficiencies are not corrected on a timely basis, and there is an increased risk of unallowable charges being made to federal programs if corrective action and recovery of questioned costs is not timely. Regarding the SEFA reviews or alternate procedures which are not being performed timely, there is an increased risk that subrecipients could be misspending and/or inappropriately tracking and reporting federal funds over multiple year periods, and these discrepancies may not be properly monitored, detected, and corrected by agency personnel on a timely basis as required. Finally, additional federal pass-through funds may be unaudited in the future without timely and effective remedial action from Commonwealth agencies to enforce compliance. Recommendation: We recommend that the above weaknesses that cause untimely subrecipient Single Audit resolution, including untimely management decisions on findings, and untimely review of the SEFA or alternate procedures be corrected to ensure compliance with federal requirements and Commonwealth Management Directives, and to better ensure timelier subrecipient compliance with program requirements. Commonwealth agencies should promptly pursue outstanding audits and implement remedial action steps on a timely basis in accordance with 2 CFR Section 200.339 and Commonwealth Management Directive 325.08. PDA Response: PDA agrees with the finding. PDOA Response: PDOA agrees with the finding. PDE Response: PDE agrees with the finding. PENNVEST Response: PENNVEST agrees with the finding. Questioned Costs: The amount of questioned costs cannot be determined.

Show full finding ▾
Full finding narrative

Various Agencies Finding 2025 – 014: ALN 10.565, 10.568, and 10.569 – Food Distribution Cluster ALN 66.458 – Clean Water State Revolving Fund ALN 84.425C – COVID-19 – Education Stabilization Fund – GEER Fund ALN 84.425D – COVID-19 – Education Stabilization Fund – ESSER Fund ALN 84.425R – COVID-19 – Education Stabilization Fund – CRRSA EANS Program ALN 84.425U – COVID-19 – Education Stabilization Fund – ARP ESSER ALN 84.425V – COVID-19 – Education Stabilization Fund – ARP EANS Program ALN 84.425W – COVID-19 – Education Stabilization Fund – ARP ESSER HCY ALN 93.044, 93.045, and 93.053 – Aging Cluster (including COVID-19) A Material Weakness and Material Noncompliance Exist in the Commonwealth’s Subrecipient Audit Resolution Process (A Similar Condition Was Noted in Prior Year Finding 2024-015) Federal Grant Number(s) and Year(s): 228PA100I1003 (6/13/2022 – 6/30/2025), 241PA825Y8005 (10/01/2023 – 9/30/2024), 241PA825Y8105 (10/01/2023 – 9/30/2024), 241PA445Q2204 (10/01/2023 – 9/30/2024), 238PA000I1003 (5/25/2023 – 6/30/2025), 251PA825Y8105 (10/01/2024 – 9/30/2025), 42000124-0-CS (7/01/2024 – 9/30/2026), 95324301-0-4C (7/01/2023 – 6/30/2023), 95325401-0-4X (7/01/2023 – 6/30/2030), S425W210039 (4/23/2021 – 9/30/2024), S425U210028 (3/24/2021 – 9/30/2024), S425D210028 (1/05/2021 – 9/30/2024), S425C200013 (5/18/2020 – 4/01/2024), S425R210037 (3/13/2020 – 9/30/2024), S425V210037 (11/16/2021 – 9/30/2024), S425C210013 (3/13/2020 – 9/30/2024), 2101PACMC6 (4/01/2021 – 9/30/2024), 2101PAHDC6 (4/01/2021 – 9/30/2024), 2101PASSC6 (4/01/2021 – 9/30/2024), 2201PASTPH (1/01/2022 – 9/30/2025), 2301PAOACM (10/01/2022 – 9/30/2025), 2301PAOAHD (10/01/2022 – 9/30/2025), 2301PAOASS (10/01/2022 – 9/30/2025), 2401PAOACM (10/01/2023 – 9/30/2025), 2401PAOAHD (10/01/2023 – 9/30/2025), 2401PAOANS (10/01/2023 – 9/30/2025), 2401PAOASS (10/01/2023 – 9/30/2025), 2501PAOASS (10/01/2024 – 9/30/2026), 2501PAOACM (10/01/2024 – 9/30/2026), 2501PAOAHD (10/01/2024 – 9/30/2026), 2501PAOANS (10/01/2024 – 9/30/2026) Type of Finding: Material Weakness in Internal Control over Compliance, Material Noncompliance Compliance Requirement: Subrecipient Monitoring Condition: Under the Commonwealth of Pennsylvania's (Commonwealth) implementation of the Single Audit Act, review and resolution of subrecipient Single Audit reports is split into two stages. The Office of the Budget’s Bureau of Accounting and Financial Management (OB-BAFM) ensures the reports meet technical standards through a centralized desk review process. The various funding agencies in the Commonwealth are responsible for making a management decision on each finding within six months of the Federal Audit Clearinghouse’s (FAC) acceptance date for audits subject to Uniform Guidance and to ensure appropriate corrective action is taken by the subrecipient (except for Uniform Guidance audits under U.S. Department of Labor programs which are permitted 12 months for management decisions in accordance with 2 CFR Section 2900.21). Each Commonwealth agency is also responsible for reviewing financial information in each audit report to determine whether the audit included all pass-through funding provided by the agency to ensure pass-through funds were subject to audit. Most agencies meet this requirement by performing Schedule of Expenditures of Federal Awards (SEFA) reconciliations. The agency is also required to adjust Commonwealth records, if necessary. Our fiscal year ended June 30, 2025 audit of the Commonwealth’s process for review and resolution of subrecipient Single Audits included an evaluation of the Commonwealth’s fiscal year ended June 30, 2024 subrecipient audit universe for audits due for submission to the FAC during the fiscal year ended June 30, 2025. We also evaluated the Commonwealth’s review of 47 subrecipient audit reports with findings in major programs/clusters which were identified on the Commonwealth agencies’ tracking lists during the fiscal year ended June 30, 2025 and required management decisions by Commonwealth agencies. Finding 2025 – 014: (continued) Our testing disclosed the following audit exceptions regarding the Commonwealth agencies’ review of subrecipient audit reports: • Pennsylvania Department of Aging (PDOA): Our testing disclosed that PDOA did not have adequate procedures in place for tracking and making management decisions on findings timely. The time period for making management decisions on findings was approximately 13.4 months to over 19 months after the FAC acceptance date for four out of four audit reports with findings. For the four items selected for testing, PDOA had not completed SEFA reconciliations or performed alternative procedures to ensure the subrecipient SEFAs were accurate so that major programs were properly determined and subjected to audit. • Department of Agriculture (PDA): The time period for making a management decision on findings was approximately eight months to over 15 months after the FAC acceptance date for four out of six audit reports with findings. There were also delays in PDA’s procedures to ensure the subrecipient SEFAs were accurate so that major programs were properly determined and subjected to audit. In addition, our testing disclosed that PDA subgranted federal funds of approximately $8.9 million to one subrecipient during fiscal year ended June 30, 2024, for which the Single Audit was not submitted to the FAC as of our February 2026 testing date. This was over 10 months after the March 31, 2025 due date. • Department of Education (PDE): The time period for making a management decision on findings was approximately 6.9 months to over 12 months after the FAC acceptance date for nine out of 30 audit reports with findings selected for testing. Three of the 30 audits reports were improperly classified on PDE’s audit tracking list as not having federal award findings. There were additional audit reports with findings listed on PDE’s audit tracking list where management decisions were not made timely. • Pennsylvania Infrastructure Investment Authority (PENNVEST): The time period for making a management decision on findings was over 15.9 months after the FAC acceptance date for one out of three audit reports with findings. For one out of three items selected for testing, PENNVEST had started but had not yet completed reconciling the SEFA to ensure the subrecipient SEFA was accurate so that major programs were properly determined and subject to audit. Criteria: 2 CFR Section 200.332, Requirements for pass-through entities, states in part: A pass-through entity must: (e) Monitor the activities of a subrecipient as necessary to ensure that the subrecipient complies with Federal statutes, regulations, and the terms and conditions of the subaward. The pass-through entity is responsible for monitoring the overall performance of a subrecipient to ensure that the goals and objectives of the subaward are achieved. In monitoring a subrecipient, a pass-through entity must: (2) Ensure that the subrecipient takes corrective action on all significant developments that negatively affect the subaward. Significant developments include Single Audit findings related to the subaward, other audit findings, site visits, and written notifications from a subrecipient of adverse conditions which will impact their ability to meet the milestones or the objectives of a subaward. When significant developments negatively impact the subaward, a subrecipient must provide the pass-through entity with information on their plan for corrective action and any assistance needed to resolve the situation. (3) Issue a management decision for audit findings pertaining only to the Federal award provided to the subrecipient from the pass-through entity as required by §200.521 [Management decision]. (g) Verify that a subrecipient is audited as required by Subpart F [Audit Requirements] of this part. (h) Consider whether the results of a subrecipient’s audit, site visits, or other monitoring necessitate adjustments to the pass-through entity’s records. Finding 2025 – 014: (continued) (i) Consider taking enforcement action against noncompliant subrecipients as described in §200.339 [Remedies for noncompliance] and in program regulations. In order to carry out these responsibilities properly, good internal control dictates that state pass-through agencies ensure subrecipient Single Audit SEFAs are representative of state payment records each year, and that the related federal programs have been properly subjected to Single Audit procedures. 2 CFR Section 200.512, Report submission, states in part: (a) General. (1) The audit, the data collection form, and the reporting package must be submitted within 30 calendar days after the auditee receives the auditor's report(s) or nine months after the end of the audit period (whichever is earlier). The cognizant agency for audit or oversight agency for audit (in the absence of a cognizant agency for audit) may authorize an extension when the nine-month timeframe would place an undue burden on the auditee. If the due date falls on a Saturday, Sunday, or Federal holiday, the reporting package is due the next business day. 2 CFR Section 200.521, Management decision, states in part: (a) General. The management decision must clearly state whether or not the finding is sustained, the reasons for the decision, and the expected auditee action to repay disallowed costs, make financial adjustments or take other action. (d) Time requirements. The Federal agency or pass-through entity responsible for issuing a management decision must do so within six months of the FAC’s acceptance of the audit report. The auditee must initiate and proceed with corrective action as rapidly as possible and corrective action should begin no later than upon receipt of the audit report. 2 CFR Section 200.505, Remedies for audit noncompliance, states: In cases of continued inability or unwillingness of a non-federal entity to have an audit conducted in accordance with this part, Federal agencies or pass-through entities must take appropriate action as provided in §200.339 [Remedies for noncompliance]. 2 CFR Section 200.339, Remedies for noncompliance, states in part: The Federal agency or pass-through entity may implement specific conditions if the recipient or subrecipient fails to comply with the U.S. Constitution, Federal statutes, regulations, or terms and conditions of the Federal award. See §200.208 for additional information on specific conditions. When the Federal agency or pass-through entity determines that noncompliance cannot be remedied by imposing specific conditions, the Federal agency or pass-through entity may take one or more of the following actions: (a) Temporarily withhold payments until the recipient or subrecipient takes corrective action. (b) Disallow costs for all or part of the activity associated with the noncompliance of the recipient or subrecipient. (c) Suspend or terminate the Federal award in part or in its entirety. (d) Initiate suspension or debarment proceedings as authorized in 2 CFR Part 180 and the Federal agency’s regulations, or for pass-through entities, recommend suspension or debarment proceedings be initiated by the Federal agency. (e) Withhold further Federal funds (new awards or continuation funding) for the project or program. (f) Pursue other legally available remedies. Finding 2025 – 014: (continued) To ensure Commonwealth enforcement of federal regulations for subrecipient noncompliance with audit requirements, Commonwealth Management Directive 325.08, Amended – Remedies for Recipient Noncompliance with Audit Requirements, Section 5 related to policy, states in part: (a) Agencies must develop and implement remedial action that reflects the unique requirements of each program… (b) The remedial action should be implemented within six months from the date the first remedial action is initiated. At the end of the six-month period, the recipient should take the appropriate corrective action or the final stage of remedial action should be imposed on the recipient. Examples of remedial action include, but are not limited to: (1) Meeting or calling the recipient to explain the importance and benefits of the audit and audit resolution processes, emphasizing the value of the audit as an administrative tool and the Commonwealth’s reliance on an acceptable audit and prompt resolution as evidence of the recipient’s ability to properly administer the program. (2) Encouraging the entity to establish an audit committee or designate an individual as the single point of contact to: (a) Communicate regarding the audit. (b) Arrange for and oversee the audit. (c) Direct and monitor audit resolution. (3) Providing technical assistance to the recipient in devising and implementing an appropriate plan to remedy the noncompliance. (4) Withholding a portion of assistance payments until the noncompliance is resolved. (5) Withholding or disallowing overhead costs until the noncompliance is resolved. (6) Suspending the assistance agreement until the noncompliance is resolved. (7) Terminating the assistance agreement with the recipient and, if necessary, seeking alternative entities to administer the program. Management Directive 325.09, Amended – Processing Subrecipient Single Audits of Federal Pass-Through Funds, Section 7 related to procedures, states in part: a. Agencies. (2) Evaluate single audit report submissions received from BAFM to determine program purpose acceptability by verifying, at a minimum, that all agency-funded programs are properly included on the applicable financial schedules; that findings affecting the agency contain sufficient information to facilitate a management decision; and that the subrecipient has submitted an adequate corrective action plan. (5) Issue management decisions relative to audit findings and crosscutting findings assigned to the agency for resolution, as required by 2 CFR §200.521. If responsible for the resolution of crosscutting findings, notify the affected agency or agencies upon resolution of such findings. (7) Impose or coordinate the imposition of remedial action in accordance with 2 CFR Part 200.339 and Management Directive 325.08 Amended, Remedies for Recipient Noncompliance with Audit Requirements, when subrecipients fail to comply with the provisions of Subpart F. Finding 2025 – 014: (continued) Management Directive 325.12, Amended – Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office’s, Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: One reason provided by Commonwealth management for untimely audit resolution in the various agencies, including making management decisions, approving corrective action, and performing procedures to ensure the accuracy of subrecipient SEFAs, was either a change in staff or a lack of staff to follow up and process subrecipient audit reports more timely. Regarding the late and outstanding audit report submission, PDA did not take timely remedial action steps in accordance with 2 CFR Section 200.339 and Commonwealth Management Directive 325.08 in order to ensure compliance with federal audit submission requirements. Effect: Since required management decisions were not made within six months to ensure appropriate corrective action was taken on audits received from subrecipients, the Commonwealth did not comply with federal regulations, and subrecipients were not made aware of acceptance or rejection of corrective action plans in a timely manner. Further, noncompliance may recur in future periods if control deficiencies are not corrected on a timely basis, and there is an increased risk of unallowable charges being made to federal programs if corrective action and recovery of questioned costs is not timely. Regarding the SEFA reviews or alternate procedures which are not being performed timely, there is an increased risk that subrecipients could be misspending and/or inappropriately tracking and reporting federal funds over multiple year periods, and these discrepancies may not be properly monitored, detected, and corrected by agency personnel on a timely basis as required. Finally, additional federal pass-through funds may be unaudited in the future without timely and effective remedial action from Commonwealth agencies to enforce compliance. Recommendation: We recommend that the above weaknesses that cause untimely subrecipient Single Audit resolution, including untimely management decisions on findings, and untimely review of the SEFA or alternate procedures be corrected to ensure compliance with federal requirements and Commonwealth Management Directives, and to better ensure timelier subrecipient compliance with program requirements. Commonwealth agencies should promptly pursue outstanding audits and implement remedial action steps on a timely basis in accordance with 2 CFR Section 200.339 and Commonwealth Management Directive 325.08. PDA Response: PDA agrees with the finding. PDOA Response: PDOA agrees with the finding. PDE Response: PDE agrees with the finding. PENNVEST Response: PENNVEST agrees with the finding. Questioned Costs: The amount of questioned costs cannot be determined.

Corrective Action Plan

PDA: PDA is creating mechanisms to fulfill the requirements for pass-through entities within 4 to 6 months after FAC acceptance date of the audit, which include: 1. Evaluation of single audit report submissions received from BAFM to determine program purpose acceptability by verifying, at a minimum, that all agency-funded programs are properly included on the applicable financial schedules; that findings affecting the agency contain sufficient information to facilitate a management decision; and that the subrecipient has submitted an adequate corrective action plan. 2. Issuance of management decisions relative to audit findings and crosscutting findings assigned to the agency for resolution, as required by 2 CFR §200.521. 3. To impose or coordinate the imposition of remedial action in accordance with 2 CFR Part 200.339 and Management Directive 325.08 Amended, Remedies for Recipient Noncompliance with Audit Requirements, when subrecipients fail to comply with the provisions of Subpart F. PDA has developed a SEFA reconciliation process that will ensure that the SEFA is accurate, allowing for major programs to be properly identified and subjected to audit. PDA is developing a procedure for all programs to follow for any entity that is in non-compliance with the audit requirements and is failing to comply with the provisions of Subpart F. Anticipated Completion Date: 06/30/2026 Contact Name: Nichole Nedinsky, Fiscal Management Specialist, PDA Audit Coordinator PDOA: 1. Strengthen written policies and procedures governing subrecipient monitoring and audit resolution. 2. Update the audit tracker to proactively ensure the six-month management decision due date is met. 3. Implement segregation of duties between reconciliation review and management decision issuance. 4. PDOA will develop and utilize a standardized SEFA Review Checklist. 5. Conduct annual Uniform Guidance training for fiscal staff. Anticipated Completion Date: 06/30/2026 Contact Names: Jason Kavulich, Secretary of Aging; Jennifer Beck, Fiscal Management Specialist & PDOA Audit Liaison PDE: Implemented 2/17/26: Audit Coordinator verifies finding status of all single audit packages uploaded to the PDE single audit SharePoint site. Implemented 7/1/25: PDE audit section has begun to enforce timely audit submission by using remedial action within its authority as granted by federal guidelines. Implemented 7/1/25: PDE has expanded the resources available through the use of the compliance office for audit finding review and resolution in an effort to resolve all audit findings timely. Anticipated Completion Date: Completed Contact Name: Clayton P. Carroll, II, Audit Coordinator PENNVEST: PENNVEST will maintain a comprehensive tracking list that contains all equivalency projects that have disbursed any funds during the audit period. All those projects will be reviewed and reconciled to ensure that the subrecipient complies with Federal statutes, regulations, and the terms and conditions of the subaward, including the timely submission of the single audit to the FAC. Once received, PENNVEST will reconcile the SEFA to ensure the information is accurate. PENNVEST will complete the reconciliation within six months of the FAC’s acceptance of the audit report and respond to the subrecipient with any adverse findings. Anticipated Completion Date: Completed Contact Names: Steven Anspach, Dep. Exec. Dir.; Heather Brookmyer, Loan Service Officer; Robert Boos, Exec. Dir.

Prior Finding References

2024-015

About Subrecipient Monitoring →

FY 2024-06-30

FAC accepted this audit on March 19, 2025 — management decision was due September 19, 2025.

2024-003
Subrecipient Monitoring
MATERIAL WEAKNESSREPEATQUESTIONED COSTS

Within the Aging Cluster, the Pennsylvania Department of Aging (PDOA) contracts with 52 Area Agency on Aging subrecipients to provide various services that include cares support, preventive health, and nutrition services, among others. Our audit testing disclosed that PDOA did not perform subrecipient monitoring on any of the subrecipients during the fiscal year ended June 30, 2024. The Aging Cluster subrecipients received $71.6 million out of Aging Cluster Program expenditures totaling $75.9 million reported on the Schedule of Expenditures of Federal Awards (SEFA). Criteria: 45 CFR Section 1321.9 State agency policies and procedures, states in part: (a) The State agency on aging shall develop policies and procedures governing all aspects of programs operated as set forth in this part… The State agency is responsible for implementing, monitoring, and enforcing policies and procedures, where: (1) The policies and procedures developed by the State agency shall address how the State agency will monitor the programmatic and fiscal performance of all programs and activities initiated under this part for compliance with all requirements, and for quality and effectiveness. 45 CFR Section 75.352, Requirements for pass-through entities, states: (d) Monitor the activities of the subrecipient as necessary to ensure that the subaward is used for authorized purposes, in compliance with Federal statutes, regulations, and the terms and conditions of the subaward; and that subaward performance goals are achieved. Pass-through entity monitoring of the subrecipient must include: (1) Reviewing financial and performance reports required by the pass-through entity. (2) Following-up and ensuring that the subrecipient takes timely and appropriate action on all deficiencies pertaining to the Federal award provided to the subrecipient from the pass-through entity detected through audits, on-site reviews, and other means. (3) Issuing a management decision for audit findings pertaining to the Federal award provided to the subrecipient from the pass-through entity… Finding 2024 – 003: (continued) (e) Depending upon the pass-through entity's assessment of risk posed by the subrecipient (as described in paragraph (b) of this section), the following monitoring tools may be useful for the pass-through entity to ensure proper accountability and compliance with program requirements and achievement of performance goals: (1) Providing subrecipients with training and technical assistance on program-related matters; and (2) Performing on-site reviews of the subrecipient's program operations; (3) Arranging for agreed-upon-procedures engagements as described in §75.425 (Audit services). Management Directive 325.12, Amended – Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office’s Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: While PDOA has subrecipient monitoring procedures in place, PDOA officials indicated that these procedures were not performed for Aging Cluster subrecipients due to staffing shortages. Effect: Without proper subrecipient monitoring, PDOA cannot ensure compliance with grant requirements and federal regulations, including allowable costs and other requirements. Recommendation: PDOA should perform risk based during-the-award monitoring procedures for all Aging Cluster subrecipients to ensure timely compliance with all applicable federal regulations. On-site monitoring visits by state officials should be supported by documentation to show the monitoring performed, areas examined, conclusions reached, and that the monitoring was performed in compliance with applicable regulations. Agency Response: PDOA agrees with the finding. Questioned Costs: The amount of questioned costs cannot be determined.

Show full finding ▾
Full finding narrative

Department of Aging Finding 2024 – 003: ALN 93.044, 93.045, and 93.053 – Aging Cluster (including COVID-19) A Material Weakness and Material Noncompliance Exist in the Department of Aging Related to Subrecipient Monitoring (A Similar Condition Was Noted in Prior Year Finding 2023-003) Federal Grant Number(s) and Year(s): 2101PACMC6 (4/01/2021 – 9/30/2024), 2101PAHDC6 (4/01/2021 – 9/30/2024), 2101PAPHC6 (4/01/2021 – 9/30/2024), 2101PASSC6 (4/01/2021 – 9/30/2024), 2201PAOASS (10/01/2021 – 9/30/2023), 2201PASTPH (1/01/2022 – 9/30/2024), 2301PAOACM (10/01/2022 – 9/30/2024), 2301PAOAHD (10/01/2022 – 9/30/2024), 2301PAOANS (10/01/2022 – 9/30/2024), 2301PAOASS (10/01/2022 – 9/30/2024), 2401PAOACM (10/01/2023 – 9/30/2025), 2401PAOAHD (10/01/2023 – 9/30/2025), 2401PAOANS (10/01/2023 – 9/30/2025), 2401PAOASS (10/01/2023 – 9/30/2025) Type of Finding: Material Weakness in Internal Control over Compliance, Material Noncompliance Compliance Requirement: Subrecipient Monitoring Condition: Within the Aging Cluster, the Pennsylvania Department of Aging (PDOA) contracts with 52 Area Agency on Aging subrecipients to provide various services that include cares support, preventive health, and nutrition services, among others. Our audit testing disclosed that PDOA did not perform subrecipient monitoring on any of the subrecipients during the fiscal year ended June 30, 2024. The Aging Cluster subrecipients received $71.6 million out of Aging Cluster Program expenditures totaling $75.9 million reported on the Schedule of Expenditures of Federal Awards (SEFA). Criteria: 45 CFR Section 1321.9 State agency policies and procedures, states in part: (a) The State agency on aging shall develop policies and procedures governing all aspects of programs operated as set forth in this part… The State agency is responsible for implementing, monitoring, and enforcing policies and procedures, where: (1) The policies and procedures developed by the State agency shall address how the State agency will monitor the programmatic and fiscal performance of all programs and activities initiated under this part for compliance with all requirements, and for quality and effectiveness. 45 CFR Section 75.352, Requirements for pass-through entities, states: (d) Monitor the activities of the subrecipient as necessary to ensure that the subaward is used for authorized purposes, in compliance with Federal statutes, regulations, and the terms and conditions of the subaward; and that subaward performance goals are achieved. Pass-through entity monitoring of the subrecipient must include: (1) Reviewing financial and performance reports required by the pass-through entity. (2) Following-up and ensuring that the subrecipient takes timely and appropriate action on all deficiencies pertaining to the Federal award provided to the subrecipient from the pass-through entity detected through audits, on-site reviews, and other means. (3) Issuing a management decision for audit findings pertaining to the Federal award provided to the subrecipient from the pass-through entity… Finding 2024 – 003: (continued) (e) Depending upon the pass-through entity's assessment of risk posed by the subrecipient (as described in paragraph (b) of this section), the following monitoring tools may be useful for the pass-through entity to ensure proper accountability and compliance with program requirements and achievement of performance goals: (1) Providing subrecipients with training and technical assistance on program-related matters; and (2) Performing on-site reviews of the subrecipient's program operations; (3) Arranging for agreed-upon-procedures engagements as described in §75.425 (Audit services). Management Directive 325.12, Amended – Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office’s Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: While PDOA has subrecipient monitoring procedures in place, PDOA officials indicated that these procedures were not performed for Aging Cluster subrecipients due to staffing shortages. Effect: Without proper subrecipient monitoring, PDOA cannot ensure compliance with grant requirements and federal regulations, including allowable costs and other requirements. Recommendation: PDOA should perform risk based during-the-award monitoring procedures for all Aging Cluster subrecipients to ensure timely compliance with all applicable federal regulations. On-site monitoring visits by state officials should be supported by documentation to show the monitoring performed, areas examined, conclusions reached, and that the monitoring was performed in compliance with applicable regulations. Agency Response: PDOA agrees with the finding. Questioned Costs: The amount of questioned costs cannot be determined.

Corrective Action Plan

A new monitoring component, consisting of fifteen measurable elements, has been developed to actively monitor compliance of the 52 Area Agencies on Aging (AAA) subrecipients through a revised Phase IX monitoring tool. The revised tool, used by three (3) Fiscal Field Representatives, includes questions regarding invoice verification, on-site monitoring, and checks that the monitoring tool the AAAs utilize adheres to all requirements. Citation documents point to the specific Chapter and Section of the Aging Service Policy and Procedure Manual for ease of reference. 1. Recognizing the need to formally document the process of monitoring, PDOA has drafted a AAA Fiscal Monitoring process map. 2. Actively working with Deloitte Consulting to finalize the process map with additional input by the Fiscal Field Representatives responsible for executing the annual requirement. 3. With the use of a monitoring log, PDOA has been working with the AAAs to correct reporting in preparation of the next round of monitoring. 4. A risk assessment has been developed to evaluate each subrecipient’s risk of noncompliance to proactively address any weaknesses in internal controls over Federal programs. 5. Pointed questions regarding the organization are included to gauge management’s ability to follow all terms and conditions of the contract. 6. General policies will be reviewed for adherence to all Federal and State regulations and the competence of personnel administering the programs. 7. Since multiple Federal funding streams are involved, a fiscal component will also be administered to review internal controls for financial issues. 8. The Risk Assessment tool has been distributed across the entire AAA Network and evaluations have been completed. 9. Performance Improvement Plans have been distributed to those found not in compliance. 10. The Comprehensive Aging Performance Evaluation (CAPE) is a new approach to PDOA’s evaluation of aging services provided by AAAs. It includes a review of programs such as Caregiver Support, OPTIONS, and Protective Services. A fiscal component is now included in the review which includes key fiscal performance measures. Part of the fiscal review is conducted virtually to evaluate the performance measures that can’t be completed off-site. 11. Performance Check-Ins previously launched in April 2024 as part of a Statewide Comprehensive Monitoring as a new form of regulatory measure to observe compliance with Older Adults Protective Services Act (OAPSA, 35 P.S. §§10225.101, et seq.), related 6 Pa. Code Chapter 15. regulations, and OAPSA Documentation Procedure Manual, Aging & Disability (A&D). Specific Fiscal components will relate to APD 05-01-09, APD 24-01-01, and the Cooperative Block Grant 2021-25 Agreement. 12. Despite PDOA recognizing time and insufficient staffing as a barrier to achieving the goal of performing a risk assessment for every AAA, we have surpassed our expectation of reaching half at a minimum by conducting a full assessment of all 52. 13. Follow-up procedures resulting from this finding will be reviewed and adjusted as needed to deliver optimal outcomes. Preliminary procedures will be directed to the agency’s audit review committee for resolution of completeness. 14. In the event the audit review committee determines additional steps beyond the monitoring efforts outlined above are insufficient, additional efforts will be communicated to the AAA network. Anticipated Completion Date: 06/30/2025 Contact Name: Jennifer Cave, Fiscal Management Specialist, PDOA Audit Liaison

Prior Finding References

2023-003

About Subrecipient Monitoring →
2024-004
Special Tests & Provisions
REPEAT

The Pennsylvania Department of Agriculture (PDA), Bureau of Food Assistance (BFA), is responsible for the accountability of USDA donated food under the National School Lunch Program (NSLP) and Summer Food Service Program for Children (SFSP) within the Child and Nutrition Cluster (CNC) and the Commodity Supplemental Food Program (CSFP) and the Emergency Food Assistance Program (Food Commodities) (TEFAP) within the Food Distribution Cluster (FDC). BFA utilizes a computer application as an inventory and distribution tracking system for donated food. The Agency Commodity Dollar Value Report, Agency Summary Reports, Commodity Inventory Report for Distributors, and Commodity Inventory Report for Processors are generated in the computer application to compile commodity expenditures reported on the Schedule of Expenditures of Federal Awards (SEFA). BFA performs reconciliations of the inventory, commodity receipts, and distributions in these reports to the distributor, processor, and recipient activity. BFA then provides commodity expenditures to the Pennsylvania Office of the Budget, Office of Comptroller Operations (OCO) for recording on the SEFA. We tested various reports generated by the system that were used by BFA to perform reconciliations and compile commodity expenditures to report on the SEFA as of June 30, 2024. We noted the following: Regarding the BFA year-end reconciliation provided in October 2024, our testing disclosed: • Commodities used in the Local Food Service (LFS) program were incorrectly included in NSLP reports used for posting to the SEFA, resulting in an overstatement of NSLP SEFA commodity expenditures of $26,697. Based on inquiry of the above error, BFA management performed further review of the reconciliation and supporting reports that resulted in BFA providing a revised reconciliation to the auditors in December 2024. Our testing of the revised reconciliation disclosed the following: • Commodities from the CSFP were uploaded to the system in late October, therefore excluded in the reports used for posting to the SEFA, resulting an understatement of CSFP commodity expenditures of $1,499,980. • Twenty-six transactions related to NSLP disbursements and credits of processors were made in November and excluded from reports used for posting to the SEFA, resulting in an overstatement of NSLP SEFA commodity expenditures of $23,442. Finding 2024 – 004: (continued) • One transaction resulting in a credit related to a Charitable Institution in NSLP was excluded from reports used for posting to the SEFA, resulting in an overstatement of NSLP SEFA commodity expenditures of $14,192 and beginning inventory being overstated by 226 cases. • Eight extra transactions were incorrectly included on the TEFAP reports used for posting to the SEFA, resulting in an overstatement of TEFAP SEFA commodity expenditures of $69,894. Regarding the Commodity Inventory Report for Processors, our testing disclosed: • A system glitch caused one processor’s beginning inventory to be set to zero, making inventory amounts for that processor off by 118,610 cases. Criteria: The 2024 OMB Uniform Guidance Compliance Supplement, Part 4 – Agency Program Requirements for the CNC Cluster, Special Tests and Provisions – N.1 Accountability for USDA – Donated Foods, states: a. Maintenance of Records: Distributing and subdistributing agencies (as defined at 7 CFR section 250.2) must maintain accurate and complete records with respect to the receipt, distribution, and inventory of USDA-donated foods, including end products processed from donated food. The 2024 OMB Uniform Guidance Compliance Supplement, Part 4 – Agency Program Requirements for the FDC Cluster, Special Tests and Provisions – N.1 Accountability for USDA Foods, states: Accurate and complete records must be maintained with respect to the receipt, distribution/use, and inventory of USDA Foods, including end products processed from USDA Foods in TEFAP. 7 CFR Section 250.19, Recordkeeping requirements, states: (a) Required records. Distributing agencies, recipient agencies, processors, and other entities must maintain records of agreements and contracts, reports, audits, and claim actions, funds obtained as an incident of donated food distribution, and other records specifically required in this part or in other Departmental regulations, as applicable. 7 CFR Section 247.29, Reports and recordkeeping, states: (a) State and local agencies must maintain accurate and complete records relating to the receipt, disposal, and inventory of USDA Foods, the receipt and disbursement of administrative funds and other funds, eligibility determinations, fair hearings, and other program activities. 7 CFR Section 251.10, Reports and recordkeeping, states: (a)(1) State agencies, subdistributing agencies, and eligible recipient agencies must maintain records to document the receipt, disposal, and inventory of USDA Foods received under this part that they, in turn, distribute to eligible recipient agencies. Management Directive 325.12, Amended – Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office’s Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Finding 2024 – 004: (continued) Cause: During testing of the year-end inventory reconciliations provided in October, the auditors identified the inclusion of LFS commodities in the NSLP commodity report and brought the error to the attention of BFA personnel. BFA personnel agreed that the amounts should not have been included in the reports used for NSLP SEFA reporting. This error prompted BFA to perform further review of the commodity reports that resulted in BFA making additional corrections and updating the year-end inventory reconciliation, the revised reconciliation was provided to the auditors in December. Audit procedures performed on the updated year-end reconciliation identified differences between both reconciliations as noted above in the condition. BFA personnel did not notify the OCO of these changes to evaluate the impact and record the necessary adjustments to the SEFA. Effect: Without direct intervention from the auditors, the reports for the CNC and FDC programs may not have been corrected. The discrepancies noted above related to inaccurate records could result in improper distribution of donated foods, misstatements in BFA’s inventory reconciliations, and did result in inaccurate commodity expenditures reported on the SEFA. A proposed audit adjustment of $1,499,980 was posted to the SEFA. Recommendation: PDA should maintain accurate and complete records with respect to the receipt, distribution, and inventory of USDA-donated foods, including end products processed from donated food. PDA should strengthen procedures for future periods to ensure errors are identified during the reconciliation process and are corrected timely in the system and communicated to the OCO for evaluation of impact on the SEFA. Agency Response: PDA agrees with this finding. Questioned Costs: None

Show full finding ▾
Full finding narrative

Department of Agriculture Finding 2024 –¬ 004: ALN 10.553, 10.555, 10.556, 10.559, and 10.582 – Child Nutrition Cluster (including COVID-19) ALN 10.565, 10.568, and 10.569 – Food Distribution Cluster Controls Over the Accountability of Donated Foods Need Improvement (A Similar Condition Was Noted in Prior Year Finding 2023-004) Federal Grant Number(s) and Year(s): 221PA365N8903 (10/01/22-9/30/2023), 221PA365N8903 (1/01/2022-9/30/2023), 231PA305N1099 (10/01/2022-9/30/2023), 231PA365N8903 (10/01/2022-9/30/2023), 231PA365N8903 (10/01/2022-9/30/2024), 241PA305N1099 (10/01/2023-9/30/2024), 231PA825Y8005 (10/01/2022-9/30/2023), 241PA825Y8005 (10/01/2023-9/30/2024), 228PA100I1003 (6/13/2022-6/30/2025), 231PA825Y8105 (10/01/22-9/30/2023), 231PA445Q2204 (10/01/2022-9/30/2023), 238PA000I1003 (5/25/2023 – 6/30/2025), 241PA825Y8105 (10/01/2023-9/30/2024) Type of Finding: Significant Deficiency in Internal Control over Compliance, Other Matters Compliance Requirement: Special Tests and Provisions related to Accountability for USDA - Donated Foods (CNC) and Special Tests and Provisions related to Accountability for USDA Foods (FDC) Condition: The Pennsylvania Department of Agriculture (PDA), Bureau of Food Assistance (BFA), is responsible for the accountability of USDA donated food under the National School Lunch Program (NSLP) and Summer Food Service Program for Children (SFSP) within the Child and Nutrition Cluster (CNC) and the Commodity Supplemental Food Program (CSFP) and the Emergency Food Assistance Program (Food Commodities) (TEFAP) within the Food Distribution Cluster (FDC). BFA utilizes a computer application as an inventory and distribution tracking system for donated food. The Agency Commodity Dollar Value Report, Agency Summary Reports, Commodity Inventory Report for Distributors, and Commodity Inventory Report for Processors are generated in the computer application to compile commodity expenditures reported on the Schedule of Expenditures of Federal Awards (SEFA). BFA performs reconciliations of the inventory, commodity receipts, and distributions in these reports to the distributor, processor, and recipient activity. BFA then provides commodity expenditures to the Pennsylvania Office of the Budget, Office of Comptroller Operations (OCO) for recording on the SEFA. We tested various reports generated by the system that were used by BFA to perform reconciliations and compile commodity expenditures to report on the SEFA as of June 30, 2024. We noted the following: Regarding the BFA year-end reconciliation provided in October 2024, our testing disclosed: • Commodities used in the Local Food Service (LFS) program were incorrectly included in NSLP reports used for posting to the SEFA, resulting in an overstatement of NSLP SEFA commodity expenditures of $26,697. Based on inquiry of the above error, BFA management performed further review of the reconciliation and supporting reports that resulted in BFA providing a revised reconciliation to the auditors in December 2024. Our testing of the revised reconciliation disclosed the following: • Commodities from the CSFP were uploaded to the system in late October, therefore excluded in the reports used for posting to the SEFA, resulting an understatement of CSFP commodity expenditures of $1,499,980. • Twenty-six transactions related to NSLP disbursements and credits of processors were made in November and excluded from reports used for posting to the SEFA, resulting in an overstatement of NSLP SEFA commodity expenditures of $23,442. Finding 2024 – 004: (continued) • One transaction resulting in a credit related to a Charitable Institution in NSLP was excluded from reports used for posting to the SEFA, resulting in an overstatement of NSLP SEFA commodity expenditures of $14,192 and beginning inventory being overstated by 226 cases. • Eight extra transactions were incorrectly included on the TEFAP reports used for posting to the SEFA, resulting in an overstatement of TEFAP SEFA commodity expenditures of $69,894. Regarding the Commodity Inventory Report for Processors, our testing disclosed: • A system glitch caused one processor’s beginning inventory to be set to zero, making inventory amounts for that processor off by 118,610 cases. Criteria: The 2024 OMB Uniform Guidance Compliance Supplement, Part 4 – Agency Program Requirements for the CNC Cluster, Special Tests and Provisions – N.1 Accountability for USDA – Donated Foods, states: a. Maintenance of Records: Distributing and subdistributing agencies (as defined at 7 CFR section 250.2) must maintain accurate and complete records with respect to the receipt, distribution, and inventory of USDA-donated foods, including end products processed from donated food. The 2024 OMB Uniform Guidance Compliance Supplement, Part 4 – Agency Program Requirements for the FDC Cluster, Special Tests and Provisions – N.1 Accountability for USDA Foods, states: Accurate and complete records must be maintained with respect to the receipt, distribution/use, and inventory of USDA Foods, including end products processed from USDA Foods in TEFAP. 7 CFR Section 250.19, Recordkeeping requirements, states: (a) Required records. Distributing agencies, recipient agencies, processors, and other entities must maintain records of agreements and contracts, reports, audits, and claim actions, funds obtained as an incident of donated food distribution, and other records specifically required in this part or in other Departmental regulations, as applicable. 7 CFR Section 247.29, Reports and recordkeeping, states: (a) State and local agencies must maintain accurate and complete records relating to the receipt, disposal, and inventory of USDA Foods, the receipt and disbursement of administrative funds and other funds, eligibility determinations, fair hearings, and other program activities. 7 CFR Section 251.10, Reports and recordkeeping, states: (a)(1) State agencies, subdistributing agencies, and eligible recipient agencies must maintain records to document the receipt, disposal, and inventory of USDA Foods received under this part that they, in turn, distribute to eligible recipient agencies. Management Directive 325.12, Amended – Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office’s Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Finding 2024 – 004: (continued) Cause: During testing of the year-end inventory reconciliations provided in October, the auditors identified the inclusion of LFS commodities in the NSLP commodity report and brought the error to the attention of BFA personnel. BFA personnel agreed that the amounts should not have been included in the reports used for NSLP SEFA reporting. This error prompted BFA to perform further review of the commodity reports that resulted in BFA making additional corrections and updating the year-end inventory reconciliation, the revised reconciliation was provided to the auditors in December. Audit procedures performed on the updated year-end reconciliation identified differences between both reconciliations as noted above in the condition. BFA personnel did not notify the OCO of these changes to evaluate the impact and record the necessary adjustments to the SEFA. Effect: Without direct intervention from the auditors, the reports for the CNC and FDC programs may not have been corrected. The discrepancies noted above related to inaccurate records could result in improper distribution of donated foods, misstatements in BFA’s inventory reconciliations, and did result in inaccurate commodity expenditures reported on the SEFA. A proposed audit adjustment of $1,499,980 was posted to the SEFA. Recommendation: PDA should maintain accurate and complete records with respect to the receipt, distribution, and inventory of USDA-donated foods, including end products processed from donated food. PDA should strengthen procedures for future periods to ensure errors are identified during the reconciliation process and are corrected timely in the system and communicated to the OCO for evaluation of impact on the SEFA. Agency Response: PDA agrees with this finding. Questioned Costs: None

Corrective Action Plan

PDA, Bureau of Food Assistance (BFA) has already or will put the following steps in place to address this deficiency and noncompliance finding. 1. BFA will communicate to our contractor, Hunger-Free Pennsylvania, that all required uploads of information related to the Commodity Supplemental Food Program (CSFP) must be entered in PAMeals by the final day of the month following the program month (i.e., data from May must be entered by June 30, data from June must be entered by July 31, etc.). BFA will also implement a monthly check in PAMeals to occur on the 1st of each month, to ensure that data from the previous reporting period has been entered into PAMeals timely (i.e., data from May should be entered by July 1, data from June should be entered by August 1, etc.). 2. In response to finding 2023-004, BFA cross-trained the NSLP Specialist on the process of completing the Monthly Processor Reports (MPRs) as a back up to the NSLP Processing & Procurement Specialist. The NSLP Specialist was then tasked with completing a monthly review of the completed MPRs to ensure accuracy. BFA has now added an additional layer to the process, with the Assistant Bureau Director serving as a backup to the NSLP Specialist, to ensure that should there be a vacancy in either of the two NSLP positions, there will always be a primary and a back-up to ensure accuracy. 3. BFA will add a validation step to the Distributor data import process for PAMeals to flag and disallow any transactions that are dated prior to the current fiscal year. BFA will also put in place a warning system on PAMeals to flag incorrect dates in any manual adjustments. 4. To ensure that processor inventories are accurate, BFA has programmed PAMeals to run a weekly check (on Sunday) to ensure that beginning processor inventories entered match the previous month and to ensure that ending inventories are accurate. BFA staff are also completing a 6-month periodic processor inventory review to ensure that records are accurate. 5. To ensure correct and timely data submissions from Share Food Program, one of our two contract distributors, PDA will require them to implement a corrective action plan detailing their plans to ensure that they provide timely and accurate reporting. This CAP will help to ensure that correct transactions are posted to PAMeals in a timely manner and will aid in addressing the issues with SEFA submission. Anticipated Completion Dates: 1. 06/30/2025, 2. Completed, 3. 06/30/2025, 4. Completed, 5. 06/30/2025 Contact Name: Caryn Long Earl, Director, Bureau of Food Assistance

Prior Finding References

2023-004

About Special Tests and Provisions →
2024-005
Subrecipient Monitoring
REPEATQUESTIONED COSTS

The Pennsylvania Department of Agriculture (PDA), Bureau of Food Assistance (BFA), administers the operations of the Food Distribution Cluster (FDC). During the fiscal year ended June 30, 2024, subrecipient expenditures accounted for $120.6 million or approximately 98.6 percent of total federal program expenditures of $122.3 million. PDA performs on-site monitoring of subrecipients to ensure compliance with federal program regulations. For The Emergency Food Assistance Program (TEFAP), PDA must perform annual reviews for at least 25 percent of subrecipients who have signed agreements with PDA and no less frequent than once every four years. For the Commodity Supplemental Food Program (CSFP), PDA must perform an on-site review of all subrecipients at least once every two years. As part of our testing of subrecipient monitoring, we selected 16 subrecipients out of 95 reviews conducted during the audit period to test PDA’s monitoring procedures. We also evaluated that PDA performed monitoring reviews within the required time periods. Our testing disclosed that PDA performed annual reviews for at least 25 percent of subrecipients but failed to monitor 47 out of a population of 94 TEFAP soup kitchen subrecipients in the required four-year review period. Criteria: 7 CFR Section 251.10 (e) (2) regarding TEFAP state monitoring system states: Unless specific exceptions are approved in writing by FNS, the State agency monitoring system must include: (i) An annual review of at least 25 percent of all eligible recipient agencies which have signed an agreement with the State agency pursuant to § 251.2(c), provided that each such agency must be reviewed no less frequently than once every four years; and (ii) An annual review of one-tenth or 20, whichever is fewer, of all eligible recipient agencies which receive TEFAP commodities and/or administrative funds pursuant to an agreement with another eligible recipient agency. Reviews must be conducted, to the maximum extent feasible, simultaneously with actual distribution of commodities and/or meal service, and eligibility determinations, if applicable. State agencies must develop a system for selecting eligible recipient agencies for review that ensures deficiencies in program administration are detected and resolved in an effective and efficient manner. Finding 2024 – 005: (continued) 7 CFR Section 247.34 (a) regarding CSFP management reviews states: The State agency must establish a management review system to ensure that local agencies, subdistributing agencies, and other agencies conducting program activities meet program requirements and objectives. As part of the system, the State agency must perform an on-site review of all local agencies, and of all storage facilities utilized by local agencies, at least once every two years. As part of the on-site review, the State agency must evaluate all aspects of program administration, including certification procedures, nutrition education, civil rights compliance, food storage practices, inventory controls, and financial management systems. In addition to conducting on-site reviews, the State agency must evaluate program administration on an ongoing basis by reviewing financial reports, audit reports, food orders, inventory reports, and other relevant information. Management Directive 325.12, Amended – Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office’s Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: PDA management stated that the agency was viewing TEFAP soup kitchen subrecipients as “recipient agencies” which are not subject to the four-year review requirement as opposed to lead agencies with direct agreements with PDA that are subject to the four-year review requirement. Soup kitchens have direct agreements with PDA. Effect: When subrecipients are not reviewed timely, subrecipients may continue to operate in noncompliance with program regulations. Recommendation: We recommend that PDA implement procedures necessary to ensure subrecipients are timely monitored in accordance with FDC program regulations. Agency Response: PDA agrees with this finding. Questioned Costs: The amount of questioned costs cannot be determined.

Show full finding ▾
Full finding narrative

Department of Agriculture Finding 2024 – 005: ALN 10.565, 10.568, and 10.569 – Food Distribution Cluster A Significant Deficiency and Noncompliance Exist in Pennsylvania Department of Agriculture Monitoring of Food Distribution Cluster Subrecipients (A Similar Condition Was Noted in Prior Year Finding 2023-005) Federal Grant Number(s) and Year(s): 231PA825Y8005 (10/01/2022 – 9/30/2023), 231PA445Q2204 (10/01/2022 – 9/30/2023), 231PA825Y8105 (10/01/2022 – 9/30/2023), 241PA825Y8005 (10/01/2023 – 9/30/2024), 241PA825Y8105 (10/01/2023 – 9/30/2024), 228PA100I1003 (6/13/2022 – 6/30/2025), 238PA000I1003 (5/25/2023 – 6/30/2025) Type of Finding: Significant Deficiency in Internal Control over Compliance, Other Matters Compliance Requirement: Subrecipient Monitoring Condition: The Pennsylvania Department of Agriculture (PDA), Bureau of Food Assistance (BFA), administers the operations of the Food Distribution Cluster (FDC). During the fiscal year ended June 30, 2024, subrecipient expenditures accounted for $120.6 million or approximately 98.6 percent of total federal program expenditures of $122.3 million. PDA performs on-site monitoring of subrecipients to ensure compliance with federal program regulations. For The Emergency Food Assistance Program (TEFAP), PDA must perform annual reviews for at least 25 percent of subrecipients who have signed agreements with PDA and no less frequent than once every four years. For the Commodity Supplemental Food Program (CSFP), PDA must perform an on-site review of all subrecipients at least once every two years. As part of our testing of subrecipient monitoring, we selected 16 subrecipients out of 95 reviews conducted during the audit period to test PDA’s monitoring procedures. We also evaluated that PDA performed monitoring reviews within the required time periods. Our testing disclosed that PDA performed annual reviews for at least 25 percent of subrecipients but failed to monitor 47 out of a population of 94 TEFAP soup kitchen subrecipients in the required four-year review period. Criteria: 7 CFR Section 251.10 (e) (2) regarding TEFAP state monitoring system states: Unless specific exceptions are approved in writing by FNS, the State agency monitoring system must include: (i) An annual review of at least 25 percent of all eligible recipient agencies which have signed an agreement with the State agency pursuant to § 251.2(c), provided that each such agency must be reviewed no less frequently than once every four years; and (ii) An annual review of one-tenth or 20, whichever is fewer, of all eligible recipient agencies which receive TEFAP commodities and/or administrative funds pursuant to an agreement with another eligible recipient agency. Reviews must be conducted, to the maximum extent feasible, simultaneously with actual distribution of commodities and/or meal service, and eligibility determinations, if applicable. State agencies must develop a system for selecting eligible recipient agencies for review that ensures deficiencies in program administration are detected and resolved in an effective and efficient manner. Finding 2024 – 005: (continued) 7 CFR Section 247.34 (a) regarding CSFP management reviews states: The State agency must establish a management review system to ensure that local agencies, subdistributing agencies, and other agencies conducting program activities meet program requirements and objectives. As part of the system, the State agency must perform an on-site review of all local agencies, and of all storage facilities utilized by local agencies, at least once every two years. As part of the on-site review, the State agency must evaluate all aspects of program administration, including certification procedures, nutrition education, civil rights compliance, food storage practices, inventory controls, and financial management systems. In addition to conducting on-site reviews, the State agency must evaluate program administration on an ongoing basis by reviewing financial reports, audit reports, food orders, inventory reports, and other relevant information. Management Directive 325.12, Amended – Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office’s Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: PDA management stated that the agency was viewing TEFAP soup kitchen subrecipients as “recipient agencies” which are not subject to the four-year review requirement as opposed to lead agencies with direct agreements with PDA that are subject to the four-year review requirement. Soup kitchens have direct agreements with PDA. Effect: When subrecipients are not reviewed timely, subrecipients may continue to operate in noncompliance with program regulations. Recommendation: We recommend that PDA implement procedures necessary to ensure subrecipients are timely monitored in accordance with FDC program regulations. Agency Response: PDA agrees with this finding. Questioned Costs: The amount of questioned costs cannot be determined.

Corrective Action Plan

PDA, BFA has already or will put the following steps in place to address this deficiency and noncompliance finding. 1. Upon identification of this finding, BFA directed our Field Representatives to immediately complete reviews of the 47 identified soup kitchens. As of 2/20/25, 18 of these soup kitchen reviews have been completed and 8 of these reviews are in-process or pending final review approval. 2. BFA Field Representatives have been advised that Soup Kitchen reviews must be completed once every four years, just like other TEFAP agencies with which we have direct agreements. This requirement is also being added to the Field Representative work manual. Anticipated Completion Date: 06/30/2025 Contact Name: Caryn Long Earl, Director, Bureau of Food Assistance

Prior Finding References

2023-005

About Subrecipient Monitoring →
2024-006
Activities Allowed or Unallowed / Cost Allowability

The Pennsylvania Department of Health (DOH) administers and monitors the WIC Special Supplemental Nutrition Program for Women, Infants, and Children (WIC) which provides assistance to low-income families for supplemental foods, education, and social services. WIC funds are received via federal grants from the United States Department of Agriculture (USDA) to meet these needs. The Pennsylvania DOH is responsible for ensuring that granted funds are used for allowable costs and grant provisions are followed. WIC administrative grant Y23172 closed on September 30, 2023. The audit procedures disclosed that the closed grant had federal revenues that exceeded federal expenditures by approximately $95 thousand. DOH indicated that a credit was identified and posted to the grant after the FNS-798 grant close out report was submitted in February 2024. The credit was largely due to overcharges of costs for a Software License Agreement that was not allowable to the grant. The adjustment to record the credit to the grant posted in June 2024. Although DOH had identified and recorded the adjustment, DOH did not update the FNS-798 grant close out report which was necessary to return the corresponding federal funds to the USDA. DOH indicated that it is in the process of generating an updated FNS-798 report to enable the funds to be returned. Criteria: 2 CFR Section 200.303, Internal controls, states: The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of the Sponsoring Organizations of the Treadway Commission (COSO). Management Directive 325.12, Amended – Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office’s Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. 2 CFR Section 200.405, Allowable costs, states: a) Allocable costs in general. A cost is allocable to a Federal award or other cost objective if the cost is assignable to that Federal award or other cost objective in accordance with the relative benefits received. This standard is met if the cost satisfies any of the following criteria: Finding 2024 ¬– 006: (continued) (1) Is incurred specifically for the Federal award; (2) Benefits both the Federal award and other work of the recipient or subrecipient and can be distributed in proportions that may be approximated using reasonable methods; or (3) Is necessary to the overall operation of the recipient or subrecipient and is assignable in part to the Federal award in accordance with these cost principles. 2 CFR Section 200.406, Applicable credits, states: (a) Applicable credits refer to transactions that offset or reduce direct or indirect costs allocable to a Federal award. Examples of such transactions are purchase discounts, rebates or allowances, recoveries or indemnities on losses, insurance refunds or rebates, and adjustments of overpayments or erroneous charges. To the extent that such credits accruing to or received by the recipient or subrecipient relate to allowable costs, they must be credited to the Federal award either as a cost reduction or cash refund, as appropriate. Cause: DOH was not aware of the overcharges at the time of grant closeout. Management subsequently became aware of the costs and credited the federal grant expenditures but did not recognize the FNS-798 report needed adjusted to facilitate the return of the federal funds. Effect: DOH had unallowable costs expended within grant Y23172 that were not identified until after the grant was closed. The unallowable costs were later credited to the grant causing cumulative revenues to exceed cumulative expenditures for the grant. The federal funds were not properly returned to the USDA. Recommendation: We recommend that DOH implement formal policies and procedures to prevent and detect any unallowable costs to ensure timely and accurate grant close out procedures. If adjustments are necessary after a grant is closed, procedures should include amending the FNS-798 report at the time of posting the adjustments. Furthermore, DOH should submit an updated FNS-798 report and return the $95 thousand of federal funds to USDA. Agency Response: DOH agrees with this finding. Questioned Costs: None

Show full finding ▾
Full finding narrative

Department of Health Finding 2024 ¬– 006: ALN 10.557 – WIC Special Supplemental Nutrition Program for Women, Infants, and Children (including COVID-19) A Significant Deficiency and Noncompliance Exist at the Department of Health Related to Activities Allowed or Unallowed, Allowable Costs/Costs Principles Federal Grant Number(s) and Year(s): 231PA705W1003 (10/01/2022-9/30/2023), 241PA705W1003 (10/01/2023-9/30/2024) Type of Finding: Significant Deficiency in Internal Control over Compliance, Other Matters Compliance Requirement: Activities Allowed or Unallowed, Allowable Costs/Cost Principles Condition: The Pennsylvania Department of Health (DOH) administers and monitors the WIC Special Supplemental Nutrition Program for Women, Infants, and Children (WIC) which provides assistance to low-income families for supplemental foods, education, and social services. WIC funds are received via federal grants from the United States Department of Agriculture (USDA) to meet these needs. The Pennsylvania DOH is responsible for ensuring that granted funds are used for allowable costs and grant provisions are followed. WIC administrative grant Y23172 closed on September 30, 2023. The audit procedures disclosed that the closed grant had federal revenues that exceeded federal expenditures by approximately $95 thousand. DOH indicated that a credit was identified and posted to the grant after the FNS-798 grant close out report was submitted in February 2024. The credit was largely due to overcharges of costs for a Software License Agreement that was not allowable to the grant. The adjustment to record the credit to the grant posted in June 2024. Although DOH had identified and recorded the adjustment, DOH did not update the FNS-798 grant close out report which was necessary to return the corresponding federal funds to the USDA. DOH indicated that it is in the process of generating an updated FNS-798 report to enable the funds to be returned. Criteria: 2 CFR Section 200.303, Internal controls, states: The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of the Sponsoring Organizations of the Treadway Commission (COSO). Management Directive 325.12, Amended – Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office’s Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. 2 CFR Section 200.405, Allowable costs, states: a) Allocable costs in general. A cost is allocable to a Federal award or other cost objective if the cost is assignable to that Federal award or other cost objective in accordance with the relative benefits received. This standard is met if the cost satisfies any of the following criteria: Finding 2024 ¬– 006: (continued) (1) Is incurred specifically for the Federal award; (2) Benefits both the Federal award and other work of the recipient or subrecipient and can be distributed in proportions that may be approximated using reasonable methods; or (3) Is necessary to the overall operation of the recipient or subrecipient and is assignable in part to the Federal award in accordance with these cost principles. 2 CFR Section 200.406, Applicable credits, states: (a) Applicable credits refer to transactions that offset or reduce direct or indirect costs allocable to a Federal award. Examples of such transactions are purchase discounts, rebates or allowances, recoveries or indemnities on losses, insurance refunds or rebates, and adjustments of overpayments or erroneous charges. To the extent that such credits accruing to or received by the recipient or subrecipient relate to allowable costs, they must be credited to the Federal award either as a cost reduction or cash refund, as appropriate. Cause: DOH was not aware of the overcharges at the time of grant closeout. Management subsequently became aware of the costs and credited the federal grant expenditures but did not recognize the FNS-798 report needed adjusted to facilitate the return of the federal funds. Effect: DOH had unallowable costs expended within grant Y23172 that were not identified until after the grant was closed. The unallowable costs were later credited to the grant causing cumulative revenues to exceed cumulative expenditures for the grant. The federal funds were not properly returned to the USDA. Recommendation: We recommend that DOH implement formal policies and procedures to prevent and detect any unallowable costs to ensure timely and accurate grant close out procedures. If adjustments are necessary after a grant is closed, procedures should include amending the FNS-798 report at the time of posting the adjustments. Furthermore, DOH should submit an updated FNS-798 report and return the $95 thousand of federal funds to USDA. Agency Response: DOH agrees with this finding. Questioned Costs: None

Corrective Action Plan

1. All offices will ensure timely and effective communication. The WIC Finance staff will meet with Budget Office (BO) Analysts monthly to review SAP forms, expenditure adjustments, Grant Status Reports and other fiscal items for accuracy and action. Program, budget and comptroller staff will meet at least quarterly to review expenditures, processes and needed actions for federal grants. BO and program office staff have agreed to the following verbally: Program staff will submit a final federal report three months after the end of the grant period. Program staff will monitor all active federal grant internal orders paying careful attention to expenditures that post after the close of federal grant budget period. If there is a late expenditure, program staff will revise the final report and submit it to the DOH BO for review using the BO workflow. The DOH BO will also monitor all active internal order numbers and alert the program office of any unusual transactions. The DOH BO will inform the program office of unusual transactions and add them to regular meeting agendas for further discussion and planning. DOH will create a bulletin to outline federal grant management policies and procedures and disseminate to all DOH program offices. 2. BO staff that made the error were notified and counseled on ways to minimize errors. BO shall update the workflow and expenditure adjustment instructions in coordination with the program office. 3. The credit was largely due to overcharges of costs for a Software License Agreement that was not allowed to be charged to the grant. The IT staff that initiated the overcharge and directed the program office to make the adjustment has been counseled on policy and procedures for charging expenditures to a federal source. All fiscal transactions for IT expenditures are reviewed by program staff as well as BO staff via the BO workflow. Policies and procedures specific to IT expenditures charged to a federal fund will be reviewed and updated to ensure information and instructions are robust and clear. Updated policies and procedures will be disseminated to all DOH staff with a responsibility in the process. Anticipated Completion Date: 05/31/2025 Contact Names: Steven Marsden, Audit Resolution Manager; Andrea Race, Chief Financial Officer

About Activities Allowed or Unallowed, Allowable Costs / Cost Principles →
2024-007
Special Tests & Provisions
MATERIAL WEAKNESSREPEATQUESTIONED COSTS

During our audit of the Supplemental Nutrition Assistance Program (SNAP) administered by the Department of Human Services (DHS), we evaluated the security over Electronic Benefits Transfer (EBT) cards, which includes both the physical security of EBT cards during the issuance process at County Assistance Offices (CAO), as well as the handling of EBT cards returned from the United States Postal Service as undeliverable, or those that have been lost or stolen. EBT cards are the method by which SNAP benefit payments are made available to recipients. Also, EBT cards are the primary method by which cash and special allowance benefit payments are made available to Temporary Assistance for Needy Families (TANF) recipients. Total benefit expenditures for SNAP for the fiscal year ended June 30, 2024, totaled $4.3 billion. Total benefit expenditures for TANF for the fiscal year ended June 30, 2024, totaled $99.6 million. Fourteen of the 88 CAO and district locations that issued EBT cards were selected for site testing in the current audit period. During our testing of the physical security over EBT cards, we noted exceptions at 12 CAO and district locations selected for testing. These exceptions included the following: 1) The Roles/Permissions Report from the EBT Card Tracking Database provided by the EBT Project Office and CAO/district offices did not reconcile (1 district office and 1 CAO location); 2) EBT cards were created outside of the hours of operations (1 district office and 1 CAO location); 3) Failure to perform the following: • Completion of paper Weekly EBT Inventory Log only in circumstances deemed an emergency (1 CAO location); • Ensure that upon receipt of each shipment of EBT cards and related supplies, the shipment is signed for and the shipping manifest is date stamped (1 CAO location); • Ensure unusable cards pulled from EBT Card inventory are shredded (1 CAO location); • Enter EBT card into the EBT Card Tracking Database at the same time that the card Primary Account Number (PAN) is created in the Electronic Payment Processing and Information Control (EPPIC) system (1 CAO location); • Mail locally created EBT cards directly to customers (1 district office); • Maintain adequate security of EBT cards (1 CAO location); • Maintain adequate security of pinning devices (1 CAO location); • Maintain adequate security of EBT card paper logs (1 CAO location); Finding 2024 –¬ 007: (continued) • Timely completion and submission of the EPPIC EBT Systems Application forms to the Office of Income Maintenance (OIM) EBT Security (3 district offices and 2 CAO locations); • Timely deactivation of user access in the EBT Card Tracking Database (5 CAO locations); • Timely enter a shipment received into the EBT Card Tracking Database (1 CAO location); • Timely mail locally created EBT cards on the same day as card creation (1 district office); and • Timely performance of the EBT Weekly Log Reconciliation and approval on Friday or last workday of the week during holidays (1 CAO location). Criteria: The 2024 OMB Uniform Guidance Compliance Supplement, Part 4 – Agency Program Requirements for the SNAP Cluster, Special Tests and Provisions – N.3 EBT Card Security, states: The state is required to maintain adequate security over, and documentation/records for, EBT cards to prevent their theft, embezzlement, loss, damage, destruction, unauthorized transfer, negotiation, or use (7 CFR Section 274.8(b)(3)). 7 CFR Section 274.5, Record retention and forms security, states: (c) Accountable Documents. (1) EBT cards shall be considered accountable documents. The State agency shall provide the following minimum security and control procedures for these documents: i. Secure storage; ii. Access limited to authorized personnel; iii. Bulk inventory control records; iv. Subsequent control records maintained through the point of issuance or use; and v. Periodic review and validation of inventory controls and records by parties not otherwise involved in maintaining control records. 45 CFR Section 75.302 applicable to TANF states: (b) The financial management system of each non-Federal entity must provide for the following (see also §75.361, 75.362, 75.363, 75.364, and 75.365): (4) Effective control over, and accountability for, all funds, property, and other assets. The non-Federal entity must adequately safeguard all assets and assure that they are used solely for authorized purposes. See §75.303. Management Directive 325.12, Amended – Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office’s Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: Established policies and procedures were not followed consistently across CAO and district locations, which resulted in ineffective internal controls over EBT card security. Effect: Without adequate security controls over EBT cards, there exists the possibility of misappropriation and/or abuse. Finding 2024 –¬ 007: (continued) Recommendation: We recommend that DHS monitor EBT card security at CAO and district locations on a regular basis to improve consistency in the execution of documented policies and procedures. Agency Response: DHS agrees with this finding. Questioned Costs: The amount of questioned costs cannot be determined.

Show full finding ▾
Full finding narrative

Department of Human Services Finding 2024 –¬ 007: ALN 10.551 and 10.561 – Supplemental Nutrition Assistance Program (SNAP) Cluster (including COVID-19) ALN 93.558 – Temporary Assistance for Needy Families A Material Weakness and Material Noncompliance Exist at the Department of Human Services Related to Electronic Benefits Transfer Card Security (A Similar Condition Was Noted in Prior Year Finding 2023-012) Federal Grant Number(s) and Year(s): 231PA405S2514 (10/01/2022 – 9/30/2023), 241PA405S2514 (10/01/2023 – 9/30/2024), 2301PATANF (10/01/2022 – 9/30/2023), 2401PATANF (10/01/2023 – 9/30/2024) Type of Finding: Material Weakness in Internal Control over Compliance, Material Noncompliance Compliance Requirement: Special Tests and Provisions related to EBT Card Security Condition: During our audit of the Supplemental Nutrition Assistance Program (SNAP) administered by the Department of Human Services (DHS), we evaluated the security over Electronic Benefits Transfer (EBT) cards, which includes both the physical security of EBT cards during the issuance process at County Assistance Offices (CAO), as well as the handling of EBT cards returned from the United States Postal Service as undeliverable, or those that have been lost or stolen. EBT cards are the method by which SNAP benefit payments are made available to recipients. Also, EBT cards are the primary method by which cash and special allowance benefit payments are made available to Temporary Assistance for Needy Families (TANF) recipients. Total benefit expenditures for SNAP for the fiscal year ended June 30, 2024, totaled $4.3 billion. Total benefit expenditures for TANF for the fiscal year ended June 30, 2024, totaled $99.6 million. Fourteen of the 88 CAO and district locations that issued EBT cards were selected for site testing in the current audit period. During our testing of the physical security over EBT cards, we noted exceptions at 12 CAO and district locations selected for testing. These exceptions included the following: 1) The Roles/Permissions Report from the EBT Card Tracking Database provided by the EBT Project Office and CAO/district offices did not reconcile (1 district office and 1 CAO location); 2) EBT cards were created outside of the hours of operations (1 district office and 1 CAO location); 3) Failure to perform the following: • Completion of paper Weekly EBT Inventory Log only in circumstances deemed an emergency (1 CAO location); • Ensure that upon receipt of each shipment of EBT cards and related supplies, the shipment is signed for and the shipping manifest is date stamped (1 CAO location); • Ensure unusable cards pulled from EBT Card inventory are shredded (1 CAO location); • Enter EBT card into the EBT Card Tracking Database at the same time that the card Primary Account Number (PAN) is created in the Electronic Payment Processing and Information Control (EPPIC) system (1 CAO location); • Mail locally created EBT cards directly to customers (1 district office); • Maintain adequate security of EBT cards (1 CAO location); • Maintain adequate security of pinning devices (1 CAO location); • Maintain adequate security of EBT card paper logs (1 CAO location); Finding 2024 –¬ 007: (continued) • Timely completion and submission of the EPPIC EBT Systems Application forms to the Office of Income Maintenance (OIM) EBT Security (3 district offices and 2 CAO locations); • Timely deactivation of user access in the EBT Card Tracking Database (5 CAO locations); • Timely enter a shipment received into the EBT Card Tracking Database (1 CAO location); • Timely mail locally created EBT cards on the same day as card creation (1 district office); and • Timely performance of the EBT Weekly Log Reconciliation and approval on Friday or last workday of the week during holidays (1 CAO location). Criteria: The 2024 OMB Uniform Guidance Compliance Supplement, Part 4 – Agency Program Requirements for the SNAP Cluster, Special Tests and Provisions – N.3 EBT Card Security, states: The state is required to maintain adequate security over, and documentation/records for, EBT cards to prevent their theft, embezzlement, loss, damage, destruction, unauthorized transfer, negotiation, or use (7 CFR Section 274.8(b)(3)). 7 CFR Section 274.5, Record retention and forms security, states: (c) Accountable Documents. (1) EBT cards shall be considered accountable documents. The State agency shall provide the following minimum security and control procedures for these documents: i. Secure storage; ii. Access limited to authorized personnel; iii. Bulk inventory control records; iv. Subsequent control records maintained through the point of issuance or use; and v. Periodic review and validation of inventory controls and records by parties not otherwise involved in maintaining control records. 45 CFR Section 75.302 applicable to TANF states: (b) The financial management system of each non-Federal entity must provide for the following (see also §75.361, 75.362, 75.363, 75.364, and 75.365): (4) Effective control over, and accountability for, all funds, property, and other assets. The non-Federal entity must adequately safeguard all assets and assure that they are used solely for authorized purposes. See §75.303. Management Directive 325.12, Amended – Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office’s Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: Established policies and procedures were not followed consistently across CAO and district locations, which resulted in ineffective internal controls over EBT card security. Effect: Without adequate security controls over EBT cards, there exists the possibility of misappropriation and/or abuse. Finding 2024 –¬ 007: (continued) Recommendation: We recommend that DHS monitor EBT card security at CAO and district locations on a regular basis to improve consistency in the execution of documented policies and procedures. Agency Response: DHS agrees with this finding. Questioned Costs: The amount of questioned costs cannot be determined.

Corrective Action Plan

Office of Income Maintenance (OIM) Bureau of Operations (BOO): BOO will take the following actions to address the finding: 1. All CAOs and district offices will be reminded of the EBT Coordinators’, alternates’, pinners’, and card makers’ responsibilities. The BOO will ensure users in the EBT Card Tracking Database know their responsibilities and segregation of duties. 2. The BOO will ensure offices know EBT cards are only to be made during business hours. BOO will work with the EBT Project Office to update the OIM EBT Procedure Manual for clarification. This will occur by April 1, 2025. 3. All CAOs and district offices will be reminded to update the EBT card tracking database within 24 hours of an individual’s status change. Clarification will be sent to the Area Managers to distribute to staff. This will occur by April 1, 2025. 4. All EBT Coordinators will be reminded to review the updates/changes to the OIM EBT Procedure Manual quarterly. Anticipated Completion Date: 04/01/2025 Contact Name: Jeanette Coulston, Staff Assistant to Director of Bureau of Operations OIM Bureau of Program Support (BPS)/EBT Project Office: BPS will take the following actions to address the finding: 1. The EBT Project Office will provide clarification and make updates to the OIM EBT Procedure Manual, in the Staff Security Section, for removing individuals from the EBT card tracking database. The updates will include screenshots for easier comprehension. This is expected to be completed by April 1, 2025. 2. The EBT Project Office will make updates to the OIM EBT Procedure Manual, in the EBT Security for Over the Counter (OTC) Card Mailing Section, to include “CAOs should not print OTC EBT Cards outside of normal business hours”. This is expected to be completed by April 1, 2025. 3. The OIM EBT Procedure Manual is updated quarterly. An email notification is sent to all EBT Coordinators, via a distribution list, notifying them of the updates/changes. This is expected to be completed by April 1, 2025. Anticipated Completion Date: 04/01/2025 Contact Name: Tonya Holloway, Division Director OIM Bureau of Program Evaluation (BPE)/Division of Corrective Action (DCA): BPE will take the following actions to address the finding: The Bureau of Program Evaluation, Division of Corrective Action conducts EBT Card Security reviews at every CAO and District Office that issues EBT cards. These reviews are completed on a three-year rotation to ensure compliance in the execution of documented policies and procedures. When needed, BPE/DCA will adjust the review criteria to incorporate any procedural changes implemented in the OIM EBT Procedure Manual. Annually, BPE/DCA EBT Headquarters staff provide training to DCA Income Maintenance Examiners in both field offices, to ensure awareness of any policy or procedure changes, prior to the start of the EBT reviews. The current rotation schedule spans FFY 2025- FFY 2027. The new three-year schedule began October 2024. Anticipated Completion Date:Completed Contact Name: Amira S. Milikin, Division Director

Prior Finding References

2023-012

About Special Tests and Provisions →
2024-008
Cash Management / Subrecipient Monitoring
MATERIAL WEAKNESSREPEATQUESTIONED COSTS

Our examination of the Department of Human Services’ (DHS) procedures for monitoring Social Services Block Grant (SSBG) subrecipients revealed that DHS did not adequately monitor the SSBG Mental Health, Homeless Services, and Child Welfare subrecipients to ensure that SSBG awards are used in compliance with laws and regulations, which include allowable costs, period of performance, and other requirements. DHS program personnel indicated that they performed on-site monitoring of nine subrecipients, however only three reports were issued to the subrecipients. The inadequately monitored subrecipients received $26.6 million (or approximately 29 percent) of total SSBG program expenditures of $91.7 million reported on the Schedule of Expenditures of Federal Awards (SEFA). While we did note that DHS adequately monitored three of the 55 Mental Health County/County Joinder subrecipients which included Mental Health, Homeless Services and Child Welfare services, this coverage is not adequate. In addition, our review of the risk assessments completed for all of the aforementioned subrecipients identified several instances where subrecipient monitoring was warranted but was not conducted. In addition, for the compliance requirement related to cash management, we noted that DHS advanced funds to SSBG subrecipients in four of nine program areas, representing $34.0 million (or approximately 37 percent) of SSBG program expenditures, without adequately monitoring the reasonableness of the subrecipient cash balances. In particular, for the program areas related to Mental Health, Intellectual Disabilities, Homeless Services, and Child Welfare, DHS advanced funds to subrecipients on a quarterly basis. Our inquiries with applicable DHS program administrators disclosed that DHS did not adequately monitor the four program areas’ subrecipients for cash management compliance either at the time of payment or at any other time during the fiscal year ended June 30, 2024. Furthermore, while Single Audits of SSBG subrecipients may be conducted each year, this auditing activity does not compensate for the lack of during-the-award program monitoring, since the timing, focus, and scope of subrecipient auditing activities after year end are different than compliance monitoring to be performed by program officials during the year. Criteria: 45 CFR Section 75.352, Requirements for pass-through entities, states: (d) Monitor the activities of the subrecipient as necessary to ensure that the subaward is used for authorized purposes, in compliance with Federal statutes, regulations, and the terms and conditions of the subaward; and that subaward performance goals are achieved. Pass-through entity monitoring of the subrecipient must include: (1) Reviewing financial and performance reports required by the pass-through entity. (2) Following-up and ensuring that the subrecipient takes timely and appropriate action on all deficiencies pertaining to the Federal award provided to the subrecipient from the pass-through entity detected through audits, on-site reviews, and other means. Finding 2024 – 008: (continued) (3) Issuing a management decision for audit findings pertaining to the Federal award provided to the subrecipient from the pass-through entity… (e) Depending upon the pass-through entity's assessment of risk posed by the subrecipient (as described in paragraph (b) of this section), the following monitoring tools may be useful for the pass-through entity to ensure proper accountability and compliance with program requirements and achievement of performance goals: (1) Providing subrecipients with training and technical assistance on program-related matters; and (2) Performing on-site reviews of the subrecipient's program operations; (3) Arranging for agreed-upon-procedures engagements as described in §75.425 (Audit services). 45 CFR Section 75.305(b)(1), applicable to payments to subrecipients, states in part: …Advance payments to a non-Federal entity must be limited to the minimum amounts needed and be timed to be in accordance with the actual, immediate cash requirements of the non-Federal entity in carrying out the purpose of the approved program or project. The timing and amount of advance payments must be as close as is administratively feasible to the actual disbursements by the non-Federal entity for direct program or project costs and the proportionate share of any allowable indirect costs. The non-Federal entity must make timely payment to contractors in accordance with the contract provisions. Management Directive 325.12, Amended – Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office’s Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: DHS management indicated that risk assessment and monitoring documents were created for use during on-site monitoring of SSBG subrecipients. However, due to staffing issues, on-site monitoring was not performed for all SSBG subrecipients. Consistent with prior year audits, DHS management noted that there have been no changes to the payment methodology for the Homeless Services, Mental Health, Intellectual Disabilities, and Child Welfare components of SSBG. These programs provide subrecipients with advances to comply with Commonwealth law and also to ensure that adequate funds are available to provide services to participants on a timely basis. DHS officials believe that their in-house payment review procedures for the SSBG program are as efficient as administratively feasible and that controls exist in each of the program areas. Without on-site program monitoring visits by funding agency officials, we consider DHS’s limited in-house reviews of subrecipient status reports or other documents to be insufficient to detect potential subrecipient noncompliance, including excess cash violations. DHS does not adjust payments to the subrecipients based on in-house reviews. Effect: Since DHS does not adequately perform during-the-award monitoring of subrecipients, including the monitoring of subrecipient cash on hand, subrecipients may not be complying with applicable grant requirements and federal regulations, including cash management standards. Recommendation: DHS should perform risk based during-the-award monitoring procedures for all SSBG subrecipients to ensure timely compliance with all applicable federal regulations. On-site monitoring visits by state officials should be supported by documentation to show the monitoring performed, areas examined, conclusions reached, and that the monitoring was performed in compliance with applicable regulations. Finding 2024 – 008: (continued) As recommended in previous Single Audits and supported by the United States Department of Health and Human Services, DHS should either consider changing their current subrecipient payment procedures from advancement basis to reimbursement basis or establish procedures to adequately monitor subrecipient cash on hand to ensure it is limited to immediate needs, but no longer than one month. The implementation and strengthening of these controls should provide DHS with reasonable assurance as to compliance with cash management requirements at the subrecipient level. Agency Response: DHS agrees with this finding. Questioned Costs: The amount of questioned costs cannot be determined.

Show full finding ▾
Full finding narrative

Department of Human Services Finding 2024 – 008: ALN 93.667 – Social Services Block Grant A Material Weakness and Material Noncompliance Exist in the Department of Human Services’ Program Monitoring of the Social Services Block Grant Subrecipients (A Similar Condition Was Noted in Prior Year Finding 2023-015) Federal Grant Number(s) and Year(s): 2401PASOSR (10/01/2023 – 9/30/2025), 2301PASOSR (10/01/2022 – 9/30/2024) Type of Finding: Material Weakness in Internal Control over Compliance, Material Noncompliance Compliance Requirements: Cash Management, Subrecipient Monitoring Condition: Our examination of the Department of Human Services’ (DHS) procedures for monitoring Social Services Block Grant (SSBG) subrecipients revealed that DHS did not adequately monitor the SSBG Mental Health, Homeless Services, and Child Welfare subrecipients to ensure that SSBG awards are used in compliance with laws and regulations, which include allowable costs, period of performance, and other requirements. DHS program personnel indicated that they performed on-site monitoring of nine subrecipients, however only three reports were issued to the subrecipients. The inadequately monitored subrecipients received $26.6 million (or approximately 29 percent) of total SSBG program expenditures of $91.7 million reported on the Schedule of Expenditures of Federal Awards (SEFA). While we did note that DHS adequately monitored three of the 55 Mental Health County/County Joinder subrecipients which included Mental Health, Homeless Services and Child Welfare services, this coverage is not adequate. In addition, our review of the risk assessments completed for all of the aforementioned subrecipients identified several instances where subrecipient monitoring was warranted but was not conducted. In addition, for the compliance requirement related to cash management, we noted that DHS advanced funds to SSBG subrecipients in four of nine program areas, representing $34.0 million (or approximately 37 percent) of SSBG program expenditures, without adequately monitoring the reasonableness of the subrecipient cash balances. In particular, for the program areas related to Mental Health, Intellectual Disabilities, Homeless Services, and Child Welfare, DHS advanced funds to subrecipients on a quarterly basis. Our inquiries with applicable DHS program administrators disclosed that DHS did not adequately monitor the four program areas’ subrecipients for cash management compliance either at the time of payment or at any other time during the fiscal year ended June 30, 2024. Furthermore, while Single Audits of SSBG subrecipients may be conducted each year, this auditing activity does not compensate for the lack of during-the-award program monitoring, since the timing, focus, and scope of subrecipient auditing activities after year end are different than compliance monitoring to be performed by program officials during the year. Criteria: 45 CFR Section 75.352, Requirements for pass-through entities, states: (d) Monitor the activities of the subrecipient as necessary to ensure that the subaward is used for authorized purposes, in compliance with Federal statutes, regulations, and the terms and conditions of the subaward; and that subaward performance goals are achieved. Pass-through entity monitoring of the subrecipient must include: (1) Reviewing financial and performance reports required by the pass-through entity. (2) Following-up and ensuring that the subrecipient takes timely and appropriate action on all deficiencies pertaining to the Federal award provided to the subrecipient from the pass-through entity detected through audits, on-site reviews, and other means. Finding 2024 – 008: (continued) (3) Issuing a management decision for audit findings pertaining to the Federal award provided to the subrecipient from the pass-through entity… (e) Depending upon the pass-through entity's assessment of risk posed by the subrecipient (as described in paragraph (b) of this section), the following monitoring tools may be useful for the pass-through entity to ensure proper accountability and compliance with program requirements and achievement of performance goals: (1) Providing subrecipients with training and technical assistance on program-related matters; and (2) Performing on-site reviews of the subrecipient's program operations; (3) Arranging for agreed-upon-procedures engagements as described in §75.425 (Audit services). 45 CFR Section 75.305(b)(1), applicable to payments to subrecipients, states in part: …Advance payments to a non-Federal entity must be limited to the minimum amounts needed and be timed to be in accordance with the actual, immediate cash requirements of the non-Federal entity in carrying out the purpose of the approved program or project. The timing and amount of advance payments must be as close as is administratively feasible to the actual disbursements by the non-Federal entity for direct program or project costs and the proportionate share of any allowable indirect costs. The non-Federal entity must make timely payment to contractors in accordance with the contract provisions. Management Directive 325.12, Amended – Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office’s Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: DHS management indicated that risk assessment and monitoring documents were created for use during on-site monitoring of SSBG subrecipients. However, due to staffing issues, on-site monitoring was not performed for all SSBG subrecipients. Consistent with prior year audits, DHS management noted that there have been no changes to the payment methodology for the Homeless Services, Mental Health, Intellectual Disabilities, and Child Welfare components of SSBG. These programs provide subrecipients with advances to comply with Commonwealth law and also to ensure that adequate funds are available to provide services to participants on a timely basis. DHS officials believe that their in-house payment review procedures for the SSBG program are as efficient as administratively feasible and that controls exist in each of the program areas. Without on-site program monitoring visits by funding agency officials, we consider DHS’s limited in-house reviews of subrecipient status reports or other documents to be insufficient to detect potential subrecipient noncompliance, including excess cash violations. DHS does not adjust payments to the subrecipients based on in-house reviews. Effect: Since DHS does not adequately perform during-the-award monitoring of subrecipients, including the monitoring of subrecipient cash on hand, subrecipients may not be complying with applicable grant requirements and federal regulations, including cash management standards. Recommendation: DHS should perform risk based during-the-award monitoring procedures for all SSBG subrecipients to ensure timely compliance with all applicable federal regulations. On-site monitoring visits by state officials should be supported by documentation to show the monitoring performed, areas examined, conclusions reached, and that the monitoring was performed in compliance with applicable regulations. Finding 2024 – 008: (continued) As recommended in previous Single Audits and supported by the United States Department of Health and Human Services, DHS should either consider changing their current subrecipient payment procedures from advancement basis to reimbursement basis or establish procedures to adequately monitor subrecipient cash on hand to ensure it is limited to immediate needs, but no longer than one month. The implementation and strengthening of these controls should provide DHS with reasonable assurance as to compliance with cash management requirements at the subrecipient level. Agency Response: DHS agrees with this finding. Questioned Costs: The amount of questioned costs cannot be determined.

Corrective Action Plan

Office of Administration (OA) – SSBG: The Bureau of Financial Operations (BFO) will continue conducting during-the-award subrecipient monitoring for the SSBG based on the results of the documented risk assessment. As it relates to the cash management portion of the finding, given the relatively small amount of funds involved and the number of counties affected, DHS has determined that it is not economically feasible to change the payment methodology at this time. Anticipated Completion Date: 06/30/2025 Contact Name: Kelly Graham, Director, Division of Financial Policy and Operations

Prior Finding References

2023-015

About Cash Management, Subrecipient Monitoring →
2024-009
Subrecipient Monitoring
REPEATQUESTIONED COSTS

During the fiscal year ended June 30, 2024, the Department of Human Services (DHS) paid $83.5 million (or 21.9 percent) in Temporary Assistance for Needy Families (TANF) funding to subrecipients within the New Directions, Cash Grants, and Alternatives to Abortion appropriations out of total federal TANF expenditures of $381.0 million reported on the June 30, 2024 Schedule of Expenditures of Federal Awards (SEFA). Our testing of DHS’s during-the-award monitoring of subrecipients for the fiscal year ended June 30, 2024, disclosed that DHS performed on-site monitoring for 16 out of 16 subrecipients selected for testing. The on-site monitoring that was performed consisted of reviews of program operations including design, data entry accuracy and timeliness, and case management analysis. The on-site monitoring also included a review of a sample of TANF recipient case files to ensure that the recipients’ TANF activities were documented and accurately entered in the Commonwealth’s Workforce Development System. However, DHS’s monitoring procedures for the 16 subrecipients were not adequate as they did not include a review or monitoring of subrecipient financial records, which would provide an assessment of a subrecipient’s compliance with applicable federal regulations. Although DHS’s monitoring procedures include reviewing subrecipient completed questionnaires for selected subrecipients that had questions related to financial matters, DHS’s monitoring personnel did not review subrecipient financial records. For example, DHS did not perform procedures to ensure subrecipient invoices agreed to the books and records of the subrecipient and that the records were adequate to support the allowability of costs paid by DHS during the award period. In addition, DHS’s monitoring procedures did not include an evaluation of the operating effectiveness of DHS subrecipients’ procedures to monitor Single Audits and any related findings. Our testing also included follow-up on one subrecipient identified in the prior year finding as not being on-site monitored by DHS when the risk assessment warranted on-site monitoring. Our follow-up during the current audit period disclosed that DHS did not conduct on-site monitoring for this subrecipient during the fiscal year ended June 30, 2024. Since the on-site monitoring was not completed, internal control weaknesses, noncompliance, and questioned costs may have existed and remained undetected during the current audit period. This subrecipient received $500 thousand of TANF funds during the fiscal year ended June 30, 2024. During the fiscal year ended June 30, 2024, the Department of Labor and Industry (L&I) paid $27.1 million in TANF funding to subrecipients within the Youth Employment and Training (E&T) appropriation (or 7.1 percent) out of total federal TANF expenditures of $381.0 million reported on the June 30, 2024 SEFA. Our testing of L&I’s during-the-award monitoring of subrecipients for the fiscal year ended June 30, 2024, disclosed that L&I did not perform on-site monitoring or desk reviews for seven out of seven subrecipients selected for testing. Finding 2024 –¬ 009: (continued) Criteria: 45 CFR Section 75.352, Requirements for pass-through entities, states: All pass-through entities must: (d) Monitor the activities of the subrecipient as necessary to ensure that the subaward is used for authorized purposes, in compliance with Federal statutes, regulations, and the terms and conditions of the subaward; and that subaward performance goals are achieved. Pass-through entity monitoring of the subrecipient must include: (1) Reviewing financial and performance reports required by the pass-through entity. (2) Following-up and ensuring that the subrecipient takes timely and appropriate action on all deficiencies pertaining to the Federal award provided to the subrecipient from the pass-through entity detected through audits, on-site reviews, and other means. (3) Issuing a management decision for audit findings pertaining to the Federal award provided to the subrecipient from the pass-through entity as required by § 75.521 [Management decision]. 2 CFR Section 200.332, Requirements for pass-through entities, states in part: A pass-through entity must: (f) Depending upon the pass-through entity's assessment of risk posed by the subrecipient (as described in paragraph (c) of this section), the following monitoring tools may be useful for the pass-through entity to ensure proper accountability and compliance with program requirements and achievement of performance goals: (1) Providing subrecipients with training and technical assistance on program-related matters; (2) Performing site visits to review the subrecipient's program operations; and (3) Arranging for agreed-upon-procedures engagements as described in §200.425 [Audit services]. Management Directive 325.12, Amended – Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office’s Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: DHS considered how financial monitoring might be incorporated into on-site monitoring procedures, but updated procedures were not in place for monitoring conducted during the fiscal year ended June 30, 2024. Therefore, DHS has not implemented adequate during-the-award monitoring procedures of subrecipients to include testing of the financial records and the subrecipients’ monitoring of Single Audits sufficient to ensure compliance with federal regulations. L&I recognized the need to perform during-the-award monitoring procedures for TANF funds passed through for the Youth E&T program, but the updated procedures were not in place for monitoring conducted during the fiscal year ended June 30, 2024. Effect: TANF subrecipients could be operating in noncompliance with federal regulations without timely detection and correction by DHS and L&I management. Recommendation: DHS and L&I should strengthen controls to ensure during-the-award monitoring is being performed for all TANF subrecipients and that the monitoring includes procedures to ensure that subrecipients are in compliance with applicable federal regulations. This should include examining subrecipients’ financial records and ensuring that all required Single Audits were obtained by DHS and L&I subrecipients. Finding 2024 –¬ 009: (continued) DHS Response: DHS agrees with this finding. L&I Response: L&I concurs with this finding. TANF Youth Development Program (TANF YDP) operations transitioned from the Bureau of Workforce Development Administration (BWDA) to the Bureau of Workforce Partnerships and Operations (BWPO) in January 2023. Due to this transition, BWPO did not conduct on site monitoring of the TANF YDP program in program year 2023. BWPO did begin on site monitoring in program year 2024 on a limited basis as a pilot with 3 local areas in September of 2024. BWPO plans to expand monitoring efforts in 2025. Questioned Costs: The amount of questioned costs cannot be determined.

Show full finding ▾
Full finding narrative

Department of Human Services Department of Labor and Industry Finding 2024 –¬ 009: ALN 93.558 – Temporary Assistance for Needy Families Department of Human Services Did Not Validate Financial Information as Part of Its On-Site Monitoring and the Department of Labor and Industry Did Not Perform Monitoring of Temporary Assistance for Needy Families Subrecipients (A Similar Condition Was Noted in Prior Year Finding 2023-014) Federal Grant Number(s) and Year(s): 2401PATANF (10/01/2023 – 9/30/2024), 2301PATANF (10/01/2022 – 9/30/2023), 2201PATANF (10/01/2021 – 9/30/2022), 2101PATANF (10/01/2020 – 9/30/2021) Type of Finding: Significant Deficiency in Internal Control over Compliance, Other Matters Compliance Requirement: Subrecipient Monitoring Condition: During the fiscal year ended June 30, 2024, the Department of Human Services (DHS) paid $83.5 million (or 21.9 percent) in Temporary Assistance for Needy Families (TANF) funding to subrecipients within the New Directions, Cash Grants, and Alternatives to Abortion appropriations out of total federal TANF expenditures of $381.0 million reported on the June 30, 2024 Schedule of Expenditures of Federal Awards (SEFA). Our testing of DHS’s during-the-award monitoring of subrecipients for the fiscal year ended June 30, 2024, disclosed that DHS performed on-site monitoring for 16 out of 16 subrecipients selected for testing. The on-site monitoring that was performed consisted of reviews of program operations including design, data entry accuracy and timeliness, and case management analysis. The on-site monitoring also included a review of a sample of TANF recipient case files to ensure that the recipients’ TANF activities were documented and accurately entered in the Commonwealth’s Workforce Development System. However, DHS’s monitoring procedures for the 16 subrecipients were not adequate as they did not include a review or monitoring of subrecipient financial records, which would provide an assessment of a subrecipient’s compliance with applicable federal regulations. Although DHS’s monitoring procedures include reviewing subrecipient completed questionnaires for selected subrecipients that had questions related to financial matters, DHS’s monitoring personnel did not review subrecipient financial records. For example, DHS did not perform procedures to ensure subrecipient invoices agreed to the books and records of the subrecipient and that the records were adequate to support the allowability of costs paid by DHS during the award period. In addition, DHS’s monitoring procedures did not include an evaluation of the operating effectiveness of DHS subrecipients’ procedures to monitor Single Audits and any related findings. Our testing also included follow-up on one subrecipient identified in the prior year finding as not being on-site monitored by DHS when the risk assessment warranted on-site monitoring. Our follow-up during the current audit period disclosed that DHS did not conduct on-site monitoring for this subrecipient during the fiscal year ended June 30, 2024. Since the on-site monitoring was not completed, internal control weaknesses, noncompliance, and questioned costs may have existed and remained undetected during the current audit period. This subrecipient received $500 thousand of TANF funds during the fiscal year ended June 30, 2024. During the fiscal year ended June 30, 2024, the Department of Labor and Industry (L&I) paid $27.1 million in TANF funding to subrecipients within the Youth Employment and Training (E&T) appropriation (or 7.1 percent) out of total federal TANF expenditures of $381.0 million reported on the June 30, 2024 SEFA. Our testing of L&I’s during-the-award monitoring of subrecipients for the fiscal year ended June 30, 2024, disclosed that L&I did not perform on-site monitoring or desk reviews for seven out of seven subrecipients selected for testing. Finding 2024 –¬ 009: (continued) Criteria: 45 CFR Section 75.352, Requirements for pass-through entities, states: All pass-through entities must: (d) Monitor the activities of the subrecipient as necessary to ensure that the subaward is used for authorized purposes, in compliance with Federal statutes, regulations, and the terms and conditions of the subaward; and that subaward performance goals are achieved. Pass-through entity monitoring of the subrecipient must include: (1) Reviewing financial and performance reports required by the pass-through entity. (2) Following-up and ensuring that the subrecipient takes timely and appropriate action on all deficiencies pertaining to the Federal award provided to the subrecipient from the pass-through entity detected through audits, on-site reviews, and other means. (3) Issuing a management decision for audit findings pertaining to the Federal award provided to the subrecipient from the pass-through entity as required by § 75.521 [Management decision]. 2 CFR Section 200.332, Requirements for pass-through entities, states in part: A pass-through entity must: (f) Depending upon the pass-through entity's assessment of risk posed by the subrecipient (as described in paragraph (c) of this section), the following monitoring tools may be useful for the pass-through entity to ensure proper accountability and compliance with program requirements and achievement of performance goals: (1) Providing subrecipients with training and technical assistance on program-related matters; (2) Performing site visits to review the subrecipient's program operations; and (3) Arranging for agreed-upon-procedures engagements as described in §200.425 [Audit services]. Management Directive 325.12, Amended – Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office’s Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: DHS considered how financial monitoring might be incorporated into on-site monitoring procedures, but updated procedures were not in place for monitoring conducted during the fiscal year ended June 30, 2024. Therefore, DHS has not implemented adequate during-the-award monitoring procedures of subrecipients to include testing of the financial records and the subrecipients’ monitoring of Single Audits sufficient to ensure compliance with federal regulations. L&I recognized the need to perform during-the-award monitoring procedures for TANF funds passed through for the Youth E&T program, but the updated procedures were not in place for monitoring conducted during the fiscal year ended June 30, 2024. Effect: TANF subrecipients could be operating in noncompliance with federal regulations without timely detection and correction by DHS and L&I management. Recommendation: DHS and L&I should strengthen controls to ensure during-the-award monitoring is being performed for all TANF subrecipients and that the monitoring includes procedures to ensure that subrecipients are in compliance with applicable federal regulations. This should include examining subrecipients’ financial records and ensuring that all required Single Audits were obtained by DHS and L&I subrecipients. Finding 2024 –¬ 009: (continued) DHS Response: DHS agrees with this finding. L&I Response: L&I concurs with this finding. TANF Youth Development Program (TANF YDP) operations transitioned from the Bureau of Workforce Development Administration (BWDA) to the Bureau of Workforce Partnerships and Operations (BWPO) in January 2023. Due to this transition, BWPO did not conduct on site monitoring of the TANF YDP program in program year 2023. BWPO did begin on site monitoring in program year 2024 on a limited basis as a pilot with 3 local areas in September of 2024. BWPO plans to expand monitoring efforts in 2025. Questioned Costs: The amount of questioned costs cannot be determined.

Corrective Action Plan

DHS: New Directions, Cash Grants The DHS Office of Income Maintenance (OIM) has implemented fiscal onsite monitoring starting October 1, 2024, which will be part of its regular program monitoring going forward. Anticipated Completion Date: 06/30/2025 Contact Name: Joel O’Donnell, Dir., Bureau of Prog. Support, OIM Alternatives to Abortion Despite repeated attempts and efforts by the DHS Office of Policy Development (OPD) to engage this subrecipient in monitoring activities, they were uncooperative and unresponsive to the requests and therefore regular monitoring was not completed. Effective December 31, 2023, the grant agreement with this subrecipient ended and was not renewed. Anticipated Completion Date: Completed Contact Name: Louie Marven, Executive Policy Specialist, OPD L&I: TANF Youth Development Program (TANF YDP) operations transitioned from the Bureau of Workforce Development Administration (BWDA) to the Bureau of Workforce Partnerships and Operations (BWPO) in January 2023. Due to this transition, BWPO did not conduct on-site monitoring of the TANF YDP program in program year 2023. BWPO did begin onsite monitoring in program year 2024 on a limited basis as a pilot with 3 local areas in September of 2024. BWPO plans to expand monitoring efforts in 2025 by aligning TANF YDP monitoring with the onsite WIOA Data Validation schedule. Larger areas will be monitored annually with smaller areas monitored on a 3-year rotating schedule concurrent with WIOA Data Validation which is expected to commence late summer or early fall 2025. BWPO intends to also facilitate exit meetings with each area monitored and provide a written communication within 45 days post monitoring to issue results, concerns, recommendations, and corrective actions as needed. The goal of monitoring activities is to ensure that TANF YDF funding is used for authorized purposes by subrecipients, in compliance with Federal statutes and regulations. Also, that the TANF YDP program is being implemented in accordance with current L&I policies and procedures. Anticipated Completion Date: 11/30/2025 Contact Name: Dorraine Rauch, Division Chief

Prior Finding References

2023-014

About Subrecipient Monitoring →
2024-010
Eligibility
QUESTIONED COSTS

The Pennsylvania Department of Labor and Industry (L&I) administers and monitors federal Unemployment Insurance (UI) funds to provide benefits for unemployed workers for periods of involuntary unemployment. L&I is responsible for establishing policy and procedure to comply with the requirements of federal UI laws including collecting UI contributions, determining claimant eligibility, and making UI benefit payments. L&I uses Pennsylvania CareerLink and the Unemployment Compensation Benefits System to aid in making eligibility determinations pursuant federal requirements. During the fiscal year ended June 30, 2024, testing revealed a claimant that was a union employee and claimed and received benefits was erroneously exempted from the work registration requirement. The work registration requirement is a condition of eligibility to receive benefits. L&I indicated that a programmatic error within the Unemployment Compensation Benefits System, which crossmatches against the Commonwealth Workforce Development System (CWDS), was not recognizing the workers with a union status as being required to register. Therefore, when the information came back from CWDS that claimants were not registered, the system incorrectly categorized these claimants as exempt. L&I performed an analysis to determine the potential number of union claimants that were erroneously exempt from the work registration requirement. After analyzing the data, L&I developed an estimate of possible overpayments to include 3,481 claimants totaling $22.5 million. The estimated numbers represent the maximum possible error and would require further investigation at the individual claimant level to specifically determine actual overpayments. L&I indicated that due to this being a programmatic error, not due to claimants’ action or inaction, in consultation with legal counsel, L&I elected to invoke the Secretary’s right to retroactively waive the registration requirement for these claimants. L&I acknowledged the programmatic issue prevented these individuals from knowing they would otherwise be denied for not registering. Furthermore, L&I stated it would be oppressive to inform the individuals now of requirements that needed to be met at the time of application, as well as burden them with unexpected overpayments. Criteria: 2 CFR Section 200.303, Internal controls, states: The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of the Sponsoring Organizations of the Treadway Commission (COSO). Finding 2024 –¬ 010: (continued) Management Directive 325.12, Amended – Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office’s Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. The 2024 OMB Uniform Guidance Compliance Supplement, Part 4 – Agency Program Requirements for the UI program, Eligibility, states: Regular Unemployment Compensation Program – Under state UC laws, a worker’s benefit rights depend on the amount of the worker’s wages and/or weeks of work in covered employment in a “base period.” While most states define the base period as the first four of the last five completed calendar quarters prior to the filing of the claim, other base periods may be used. To qualify for benefits, a claimant must have earned a certain number of wages or have worked a certain number of weeks or calendar quarters within the base period or meet some combination of wage and employment requirements. Some states require a waiting period of one week of total or partial unemployment before UC is payable. A “waiting period” is a non-compensable period of unemployment in which the worker is otherwise eligible for benefits. To be eligible to receive UC, all states provide that a claimant must have been separated from suitable work for non-disqualifying reasons under state law (i.e., not because of such acts as leaving voluntarily without good cause or discharge for misconduct connected with work). After separation, they must be able and available for work, actively seeking work, legally authorized to work in the United States and must not have refused an offer of suitable work. Pennsylvania UC Law booklet, states: ARTICLE IV COMPENSATION Section 401. Qualifications Required to Secure Compensation.— Compensation shall be payable to any employe who is or becomes unemployed, and who— (a) Satisfies both of the following requirements: (1) Has, within his base year, been paid wages for employment as required by section 404(c) of this act. (2) Except as provided in section 404(a)(3) and (e)(2)(v), not less than thirty-seven per centum (37%) of the employe's total base year wages have been paid in one or more quarters, other than the highest quarter in such employe's base year. ((2) amended June 30, 2021, P.L.173, No.30) ((a) amended Nov. 3, 2016, P.L.1100, No.144) (b) (1) Is making an active search for suitable employment. The requirements for "active search" shall be established by the department and shall include, at a minimum, all of the following: 106 PENNSYLVANIA UNEMPLOYMENT COMPENSATION LAW (i) Registration by a claimant for employment search services offered by the Pennsylvania CareerLink system or its successor agency within thirty (30) days after initial application for benefits. (ii) Posting a resume on the system's database, unless the claimant is seeking work in an employment sector in which resumes are not commonly used. (iii) Applying for positions that offer employment and wages similar to those the claimant had prior to his unemployment and which are within a forty-five (45) minute commuting distance. Cause: A programmatic error within the Unemployment Compensation Benefits System erroneously exempted claimants with a union status from the work registration requirement. Effect: Claimants with union status that were exempted from the work registration eligibility requirement possibly received UI benefit payments without meeting all the eligibility requirements, resulting in disallowed benefit payments. As indicated above in the condition, L&I has elected to invoke the Secretary’s right to retroactively waive the registration requirement for these claimants. Recommendation: We recommend that L&I strengthen policies and procedures to prevent and detect errors that could result in improper benefit payments. Finding 2024 –¬ 010: (continued) Agency Response: L&I agrees with this finding. Questioned Costs: The amount of questioned costs cannot be determined.

Show full finding ▾
Full finding narrative

Department of Labor and Industry Finding 2024 –¬ 010: ALN 17.225 – Unemployment Insurance (including COVID-19) A Significant Deficiency Exists at the Department of Labor and Industry Related to the Work Registration Requirement Federal Grant Number(s) and Year(s): C101064 (7/01/2023 - 6/30/2024) Type of Finding: Significant Deficiency in Internal Control over Compliance, Other Matters Compliance Requirement: Eligibility Condition: The Pennsylvania Department of Labor and Industry (L&I) administers and monitors federal Unemployment Insurance (UI) funds to provide benefits for unemployed workers for periods of involuntary unemployment. L&I is responsible for establishing policy and procedure to comply with the requirements of federal UI laws including collecting UI contributions, determining claimant eligibility, and making UI benefit payments. L&I uses Pennsylvania CareerLink and the Unemployment Compensation Benefits System to aid in making eligibility determinations pursuant federal requirements. During the fiscal year ended June 30, 2024, testing revealed a claimant that was a union employee and claimed and received benefits was erroneously exempted from the work registration requirement. The work registration requirement is a condition of eligibility to receive benefits. L&I indicated that a programmatic error within the Unemployment Compensation Benefits System, which crossmatches against the Commonwealth Workforce Development System (CWDS), was not recognizing the workers with a union status as being required to register. Therefore, when the information came back from CWDS that claimants were not registered, the system incorrectly categorized these claimants as exempt. L&I performed an analysis to determine the potential number of union claimants that were erroneously exempt from the work registration requirement. After analyzing the data, L&I developed an estimate of possible overpayments to include 3,481 claimants totaling $22.5 million. The estimated numbers represent the maximum possible error and would require further investigation at the individual claimant level to specifically determine actual overpayments. L&I indicated that due to this being a programmatic error, not due to claimants’ action or inaction, in consultation with legal counsel, L&I elected to invoke the Secretary’s right to retroactively waive the registration requirement for these claimants. L&I acknowledged the programmatic issue prevented these individuals from knowing they would otherwise be denied for not registering. Furthermore, L&I stated it would be oppressive to inform the individuals now of requirements that needed to be met at the time of application, as well as burden them with unexpected overpayments. Criteria: 2 CFR Section 200.303, Internal controls, states: The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of the Sponsoring Organizations of the Treadway Commission (COSO). Finding 2024 –¬ 010: (continued) Management Directive 325.12, Amended – Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office’s Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. The 2024 OMB Uniform Guidance Compliance Supplement, Part 4 – Agency Program Requirements for the UI program, Eligibility, states: Regular Unemployment Compensation Program – Under state UC laws, a worker’s benefit rights depend on the amount of the worker’s wages and/or weeks of work in covered employment in a “base period.” While most states define the base period as the first four of the last five completed calendar quarters prior to the filing of the claim, other base periods may be used. To qualify for benefits, a claimant must have earned a certain number of wages or have worked a certain number of weeks or calendar quarters within the base period or meet some combination of wage and employment requirements. Some states require a waiting period of one week of total or partial unemployment before UC is payable. A “waiting period” is a non-compensable period of unemployment in which the worker is otherwise eligible for benefits. To be eligible to receive UC, all states provide that a claimant must have been separated from suitable work for non-disqualifying reasons under state law (i.e., not because of such acts as leaving voluntarily without good cause or discharge for misconduct connected with work). After separation, they must be able and available for work, actively seeking work, legally authorized to work in the United States and must not have refused an offer of suitable work. Pennsylvania UC Law booklet, states: ARTICLE IV COMPENSATION Section 401. Qualifications Required to Secure Compensation.— Compensation shall be payable to any employe who is or becomes unemployed, and who— (a) Satisfies both of the following requirements: (1) Has, within his base year, been paid wages for employment as required by section 404(c) of this act. (2) Except as provided in section 404(a)(3) and (e)(2)(v), not less than thirty-seven per centum (37%) of the employe's total base year wages have been paid in one or more quarters, other than the highest quarter in such employe's base year. ((2) amended June 30, 2021, P.L.173, No.30) ((a) amended Nov. 3, 2016, P.L.1100, No.144) (b) (1) Is making an active search for suitable employment. The requirements for "active search" shall be established by the department and shall include, at a minimum, all of the following: 106 PENNSYLVANIA UNEMPLOYMENT COMPENSATION LAW (i) Registration by a claimant for employment search services offered by the Pennsylvania CareerLink system or its successor agency within thirty (30) days after initial application for benefits. (ii) Posting a resume on the system's database, unless the claimant is seeking work in an employment sector in which resumes are not commonly used. (iii) Applying for positions that offer employment and wages similar to those the claimant had prior to his unemployment and which are within a forty-five (45) minute commuting distance. Cause: A programmatic error within the Unemployment Compensation Benefits System erroneously exempted claimants with a union status from the work registration requirement. Effect: Claimants with union status that were exempted from the work registration eligibility requirement possibly received UI benefit payments without meeting all the eligibility requirements, resulting in disallowed benefit payments. As indicated above in the condition, L&I has elected to invoke the Secretary’s right to retroactively waive the registration requirement for these claimants. Recommendation: We recommend that L&I strengthen policies and procedures to prevent and detect errors that could result in improper benefit payments. Finding 2024 –¬ 010: (continued) Agency Response: L&I agrees with this finding. Questioned Costs: The amount of questioned costs cannot be determined.

Corrective Action Plan

L&I has taken the following steps to resolve the finding: - The system issue which caused the lack of denials was fixed in December 2024. - Maximum potential overpayment amount was estimated by getting a list of all those union hiring hall members since the launch of the new system and then removing the following from the list: - Those who registered for work. - Those exempt for other reasons. - Those denied benefits for other reasons. - Those with no payments for weeks beyond the 4th week of the claim. - The remaining individuals’ payments for the fifth week of the claim and later were totaled in January 2025: - 3,481 individuals - $22,597,596.92 - These amounts are described as “maximum” because only an individual review of each claim would reveal if the person was truly not properly registered and if weeks of benefits should be overpaid. - The Department is choosing to waive these individuals’ requirement to register based on UC law section 401(b)(6): The department may waive or alter the requirements of this subsection in cases or situations with respect to which the secretary finds that compliance with such requirements would be oppressive or which would be inconsistent with the purposes of this act. Since the individuals would currently be told of requirements they needed to meet in the past and, as a result, given debts to repay, this is oppressive in nature and inconsistent with the purpose behind the registration requirement. Anticipated Completion Date: Completed Contact Names: Stacy Walter, Management Analyst 2, Special Projects, Office of UC Service Centers; Rick Plesnarski, Management Supervisor, Special Projects Unit & Quality Assurance, Office of UC Service Centers

About Eligibility →
2024-011
Special Tests & Provisions

During the fiscal year ended June 30, 2024, the Department of Labor and Industry (L&I) was required to administer reemployment services for the Unemployment Insurance (UI) program. The Commonwealth of Pennsylvania elected to operate the Reemployment Services and Eligibility Assessments (RESEA) program to satisfy the Worker Profiling and Reemployment Services (WPRS) federal mandate which was permitted by federal requirements. The RESEA program enables claimants who are most likely to exhaust their benefits to access services that assist them to return to work or provide assistance in areas such as job search or placement, job markets, and testing. Claimant participants work with a case administrator (administrator) throughout the program, and the administrators are supervised by a case manager. L&I’s program procedures are outlined in the Labor and Industry RESEA Manual which details claimant selection, eligibility, and the intervention process performed by the administrator to assist participating claimants. The Commonwealth of Pennsylvania’s RESEA program uses a comprehensive checklist from the RESEA Manual to ensure that all elements of the program are being satisfied for each case. To test the RESEA requirements for the fiscal year ending June 30, 2024, a sample of 40 out of 22,774 claimant cases that completed the program during that time period was selected for testing. No noncompliance was identified. However, we were unable to test the operating effectiveness of certain internal control procedures at the case level, since supporting documentation for checklists was not maintained for eight of the 40 cases tested. Criteria: 2 CFR Section 200.303, Internal controls, states: The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Management Directive 325.12 Standards for Internal Control for Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office’s Standards for Internal Control in the Federal Government (Green Book), published in September 2014. The Green Book states in part: Finding 2024 –¬ 011: (continued) Management should design control activities to achieve objectives and respond to risks. Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: According to L&I management, the checklist was mandatory for use by the administrators. L&I indicated that the eight checklists which were unavailable to be reviewed were lost due to moving locations. Effect: The lack of adequate internal controls over compliance in the RESEA program could result in improper identification of claimants and insufficient services resulting in federal noncompliance. Although noncompliance was not identified by our audit procedures, fully operational controls would enable case administrators and managers to ensure compliance with program requirements and to timely prevent and detect instances of noncompliance. Recommendation: We recommend that L&I management ensure the use of the checklist to strengthen internal controls and to ensure verification of all elements of the RESEA program are occurring, accurate, and complete.  Also, L&I management should ensure that proper documentation of the use of these tools is maintained. Agency Response: L&I is in agreement with the recommendations and will ensure that the checklist will be completed for all RESEA recipients. Management will ensure that proper documentation of this tool is maintained. 1. Yearly RESEA case file reviews will be conducted by the Bureau of Workforce Partnership & Operations (BWPO) Central office staff. 2. Quarterly meetings with local office staff to reinforce the importance of utilizing the checklist. Questioned Costs: None

Show full finding ▾
Full finding narrative

Department of Labor and Industry Finding 2024 –¬ 011: ALN 17.225 – Unemployment Insurance (including COVID-19) A Significant Deficiency Exists at the Department of Labor and Industry Related to the Reemployment Services and Eligibility Assessments Program Federal Grant Number(s) and Year(s): C10164 (7/01/2023 – 6/30/2024) Type of Finding: Significant Deficiency in Internal Control over Compliance Compliance Requirement: Special Tests and Provisions related to Unemployment Insurance (UI) Reemployment Programs: Worker Profiling and Reemployment Services (WPRS) and Reemployment Services and Eligibility Assessments (RESEA) Condition: During the fiscal year ended June 30, 2024, the Department of Labor and Industry (L&I) was required to administer reemployment services for the Unemployment Insurance (UI) program. The Commonwealth of Pennsylvania elected to operate the Reemployment Services and Eligibility Assessments (RESEA) program to satisfy the Worker Profiling and Reemployment Services (WPRS) federal mandate which was permitted by federal requirements. The RESEA program enables claimants who are most likely to exhaust their benefits to access services that assist them to return to work or provide assistance in areas such as job search or placement, job markets, and testing. Claimant participants work with a case administrator (administrator) throughout the program, and the administrators are supervised by a case manager. L&I’s program procedures are outlined in the Labor and Industry RESEA Manual which details claimant selection, eligibility, and the intervention process performed by the administrator to assist participating claimants. The Commonwealth of Pennsylvania’s RESEA program uses a comprehensive checklist from the RESEA Manual to ensure that all elements of the program are being satisfied for each case. To test the RESEA requirements for the fiscal year ending June 30, 2024, a sample of 40 out of 22,774 claimant cases that completed the program during that time period was selected for testing. No noncompliance was identified. However, we were unable to test the operating effectiveness of certain internal control procedures at the case level, since supporting documentation for checklists was not maintained for eight of the 40 cases tested. Criteria: 2 CFR Section 200.303, Internal controls, states: The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Management Directive 325.12 Standards for Internal Control for Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office’s Standards for Internal Control in the Federal Government (Green Book), published in September 2014. The Green Book states in part: Finding 2024 –¬ 011: (continued) Management should design control activities to achieve objectives and respond to risks. Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: According to L&I management, the checklist was mandatory for use by the administrators. L&I indicated that the eight checklists which were unavailable to be reviewed were lost due to moving locations. Effect: The lack of adequate internal controls over compliance in the RESEA program could result in improper identification of claimants and insufficient services resulting in federal noncompliance. Although noncompliance was not identified by our audit procedures, fully operational controls would enable case administrators and managers to ensure compliance with program requirements and to timely prevent and detect instances of noncompliance. Recommendation: We recommend that L&I management ensure the use of the checklist to strengthen internal controls and to ensure verification of all elements of the RESEA program are occurring, accurate, and complete.  Also, L&I management should ensure that proper documentation of the use of these tools is maintained. Agency Response: L&I is in agreement with the recommendations and will ensure that the checklist will be completed for all RESEA recipients. Management will ensure that proper documentation of this tool is maintained. 1. Yearly RESEA case file reviews will be conducted by the Bureau of Workforce Partnership & Operations (BWPO) Central office staff. 2. Quarterly meetings with local office staff to reinforce the importance of utilizing the checklist. Questioned Costs: None

Corrective Action Plan

Guidance email was provided to program supervisors in February 2025, reiterating the requirement that all RESEA Checklists must be completed by staff and supervisors. Yearly file reviews – Bureau of Workforce Partnership and Operations (BWPO) is currently conducting case file reviews of the local offices. Once the review is completed, each area will get a results email with concerns and recommendations. These reviews started in September 2024 and will continue until they are completed. Anticipated completion is November 2025. Quarterly meetings were held for all local areas (2/4/25, 2/5/25 & 2/6/25). Next quarterly meetings will be held in May 2025. These meetings will reiterate the importance of following the RESEA process as detailed in the RESEA desk guide. Anticipated Completion Date: 11/30/2025 Contact Name: Dorraine Rauch, Division Chief

About Special Tests and Provisions →
2024-012
Other

As part of testing internal controls over the Workforce Innovation and Opportunity Act (WIOA) Cluster program, we performed certain tests of information technology (IT) general controls over a computer application used by the Department of Labor and Industry (L&I), Bureau of Workforce Development Administration (BWDA) and supported by the Office of Administration – Office for Information Technology (OA-OIT) – Employment, Banking and Revenue (EBR) Delivery Center. During our testing of privileged access, we noted the following control deficiencies in an application used to capture, track, and monitor WIOA program activities: 1. An inappropriate application administrator role was assigned to six users who did not require the role to perform their job duties. There was no documented logging or monitoring of the use of this elevated access. 2. Four users were not removed from the system within two weeks after separating employment. Details of this issue have been provided to the BWDA and the EBR Delivery Center for their information and corrective action. Criteria: Management Directive 325.12, Amended – Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office’s Standards for Internal Control in the Federal Government (Green Book). Green Book Principle 11 – Design Activities for the Information System, states in part: o 11.12 Management designs control activities over access to protect an entity from inappropriate access and unauthorized use of the system. These control activities support appropriate segregation of duties. By preventing unauthorized use of and changes to the system, data and program integrity are protected from malicious intent (e.g., someone breaking into the technology to commit fraud, vandalism, or terrorism) or error. o 11.14 Management designs control activities to limit user access to information technology through authorization control activities, such as providing a unique user identification or token to authorized users. These control activities may restrict authorized users to the applications or functions commensurate with their assigned responsibilities, supporting an appropriate segregation of duties. Management designs other control activities to promptly update access rights when employees change job functions or leave the entity. Finding 2024 –¬ 012: (continued) Information Technology Policy – OPD SEC007a – Configurations for IDs, Passwords, and Multi-Factor Authentication, revised July 12, 2022, section 3.7 states, in part: • Least privileged. By default, all accounts should be assigned the lowest level of permissions. If elevated permissions are required a change request should be submitted and approved before elevated permissions are granted to any account. Governor’s Office Executive Order 2016-06 Enterprise Information Technology Governance, amended October 27, 2020, establishes responsibility for all information technology (IT) services in the Commonwealth to the Office of Administration, Office for Information Technology (OA-OIT). Section 1 states: • Powers and Duties. The Governor’s Office of Administration, Office for Information Technology… (“OA/OIT”) led by the Commonwealth Chief Information Officer (“Commonwealth CIO”), has overall responsibility for the management and operation of IT services for all executive agencies under the Governor’s jurisdiction…. A well-designed system of internal controls dictates that effective IT general controls, which includes access controls to programs and data, be established and functioning to ensure that overall agency operations are conducted in accordance with management’s intent. Cause: Under Executive Order 2016-06, OA-OIT is responsible for management and operation of IT services for all executive agencies under the Governor’s jurisdiction. In practice, however, L&I, BWDA has taken responsibility for the following functions in local offices across Pennsylvania: 1) adding new local office users to the application; 2) performing periodic access reviews of the appropriateness of access to the application at the local level; and 3) removing terminated local users from the application. BWDA management approved an inappropriate application administrator role at the local offices because established procedures did not adequately describe appropriate application administrator roles that can be assigned to non-Commonwealth staff or adequately describe accurate assignment and approval of these roles. Additionally, user access request forms were designed inadequately. Some user access request forms explicitly stated that the role should only be assigned to Commonwealth staff, while other forms did not. Central staff periodic access reviews of local users also failed to identify these inappropriate roles because central staff reviewers only confirmed that the users were still employed, and did not verify that their level of access was appropriate. Further, the annual periodic access review was not documented for review or audit purposes. Central Staff removed the inappropriate roles from the users’ profiles after the audit period once the auditors pointed out the issue. Established policy and procedures to disable separated users were not followed, which required either the local office system administrator or a central office administrator to submit a request to the L&I resource account no later than the employees last day of work, or the first business day after. One user that was not removed timely after separation had left employment over four years ago. The three other users had separated employment approximately six to seven months ago. Furthermore, the annual periodic access reviews failed to identify these separated users. Effect: Inappropriate privileged access and untimely removal of terminated users contributes to the risk that system actions can occur that are not in accordance with management’s intent. Further, without properly functioning controls over terminated users and privileged access, management is precluded from reliance on computer controls in these agencies. Recommendation: We recommend that BWDA management: • Update the user access request form to clarify which privileged roles may be assigned to application users; • Revise policies and procedures for the creation of accounts and assignment of roles to non-Commonwealth users in accordance with the policy for least privilege; Finding 2024 –¬ 012: (continued) • Document the annual periodic access reviews of local privileged users to ensure that central staff confirm appropriate role assignments and retain for audit purposes; • Implement stronger controls to improve timely notifications of user separations; and • Provide training to personnel on creation of accounts, assignment of administrator roles, and timely notification of user separations. Agency Response: As previously communicated to the auditors, Bureau of Workforce Partnership & Operations (BWPO) acknowledges and accepts the six non-state users receiving the administrator role in error. BWPO accepts and acknowledges the four User Accounts which were not deactivated timely. One instance was a failure of Local Office staff to notify of a staff separation with the other three being staff members from the Apprenticeship and Training Office (ATO) who separated from that Bureau without the Customer Service Unit being notified. Questioned Costs: None

Show full finding ▾
Full finding narrative

Department of Labor and Industry Finding 2024 –¬ 012: ALN 17.258, 17.259, and 17.278 – Workforce Innovation and Opportunity Act (WIOA) Cluster A Significant Deficiency Exists at the Department of Labor and Industry Related to Inappropriate Privileged Access Federal Grant Number(s) and Year(s): 23A55AT000019 (7/01/2023 – 6/30/2026), 23A55AW000022 (7/01/2023 – 6/30/2026), 23A55AY000029 (4/01/2023 – 6/30/2026), AA347902055A42 (10/01/2019 – 6/30/2023), AA363422155A42 (4/01/2021 – 6/30/2024), AA385522255A42 (4/01/2022 – 6/30/2025) Type of Finding: Significant Deficiency in Internal Control over Compliance Compliance Requirement: Other Condition: As part of testing internal controls over the Workforce Innovation and Opportunity Act (WIOA) Cluster program, we performed certain tests of information technology (IT) general controls over a computer application used by the Department of Labor and Industry (L&I), Bureau of Workforce Development Administration (BWDA) and supported by the Office of Administration – Office for Information Technology (OA-OIT) – Employment, Banking and Revenue (EBR) Delivery Center. During our testing of privileged access, we noted the following control deficiencies in an application used to capture, track, and monitor WIOA program activities: 1. An inappropriate application administrator role was assigned to six users who did not require the role to perform their job duties. There was no documented logging or monitoring of the use of this elevated access. 2. Four users were not removed from the system within two weeks after separating employment. Details of this issue have been provided to the BWDA and the EBR Delivery Center for their information and corrective action. Criteria: Management Directive 325.12, Amended – Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office’s Standards for Internal Control in the Federal Government (Green Book). Green Book Principle 11 – Design Activities for the Information System, states in part: o 11.12 Management designs control activities over access to protect an entity from inappropriate access and unauthorized use of the system. These control activities support appropriate segregation of duties. By preventing unauthorized use of and changes to the system, data and program integrity are protected from malicious intent (e.g., someone breaking into the technology to commit fraud, vandalism, or terrorism) or error. o 11.14 Management designs control activities to limit user access to information technology through authorization control activities, such as providing a unique user identification or token to authorized users. These control activities may restrict authorized users to the applications or functions commensurate with their assigned responsibilities, supporting an appropriate segregation of duties. Management designs other control activities to promptly update access rights when employees change job functions or leave the entity. Finding 2024 –¬ 012: (continued) Information Technology Policy – OPD SEC007a – Configurations for IDs, Passwords, and Multi-Factor Authentication, revised July 12, 2022, section 3.7 states, in part: • Least privileged. By default, all accounts should be assigned the lowest level of permissions. If elevated permissions are required a change request should be submitted and approved before elevated permissions are granted to any account. Governor’s Office Executive Order 2016-06 Enterprise Information Technology Governance, amended October 27, 2020, establishes responsibility for all information technology (IT) services in the Commonwealth to the Office of Administration, Office for Information Technology (OA-OIT). Section 1 states: • Powers and Duties. The Governor’s Office of Administration, Office for Information Technology… (“OA/OIT”) led by the Commonwealth Chief Information Officer (“Commonwealth CIO”), has overall responsibility for the management and operation of IT services for all executive agencies under the Governor’s jurisdiction…. A well-designed system of internal controls dictates that effective IT general controls, which includes access controls to programs and data, be established and functioning to ensure that overall agency operations are conducted in accordance with management’s intent. Cause: Under Executive Order 2016-06, OA-OIT is responsible for management and operation of IT services for all executive agencies under the Governor’s jurisdiction. In practice, however, L&I, BWDA has taken responsibility for the following functions in local offices across Pennsylvania: 1) adding new local office users to the application; 2) performing periodic access reviews of the appropriateness of access to the application at the local level; and 3) removing terminated local users from the application. BWDA management approved an inappropriate application administrator role at the local offices because established procedures did not adequately describe appropriate application administrator roles that can be assigned to non-Commonwealth staff or adequately describe accurate assignment and approval of these roles. Additionally, user access request forms were designed inadequately. Some user access request forms explicitly stated that the role should only be assigned to Commonwealth staff, while other forms did not. Central staff periodic access reviews of local users also failed to identify these inappropriate roles because central staff reviewers only confirmed that the users were still employed, and did not verify that their level of access was appropriate. Further, the annual periodic access review was not documented for review or audit purposes. Central Staff removed the inappropriate roles from the users’ profiles after the audit period once the auditors pointed out the issue. Established policy and procedures to disable separated users were not followed, which required either the local office system administrator or a central office administrator to submit a request to the L&I resource account no later than the employees last day of work, or the first business day after. One user that was not removed timely after separation had left employment over four years ago. The three other users had separated employment approximately six to seven months ago. Furthermore, the annual periodic access reviews failed to identify these separated users. Effect: Inappropriate privileged access and untimely removal of terminated users contributes to the risk that system actions can occur that are not in accordance with management’s intent. Further, without properly functioning controls over terminated users and privileged access, management is precluded from reliance on computer controls in these agencies. Recommendation: We recommend that BWDA management: • Update the user access request form to clarify which privileged roles may be assigned to application users; • Revise policies and procedures for the creation of accounts and assignment of roles to non-Commonwealth users in accordance with the policy for least privilege; Finding 2024 –¬ 012: (continued) • Document the annual periodic access reviews of local privileged users to ensure that central staff confirm appropriate role assignments and retain for audit purposes; • Implement stronger controls to improve timely notifications of user separations; and • Provide training to personnel on creation of accounts, assignment of administrator roles, and timely notification of user separations. Agency Response: As previously communicated to the auditors, Bureau of Workforce Partnership & Operations (BWPO) acknowledges and accepts the six non-state users receiving the administrator role in error. BWPO accepts and acknowledges the four User Accounts which were not deactivated timely. One instance was a failure of Local Office staff to notify of a staff separation with the other three being staff members from the Apprenticeship and Training Office (ATO) who separated from that Bureau without the Customer Service Unit being notified. Questioned Costs: None

Corrective Action Plan

BWPO acknowledges that these errors were made, and the indicated accounts were updated immediately. The following steps will be taken to prevent this from happening again. 1. Desk Guides and Training Manuals for Central Offices CWDS Access Administrators will be updated to clearly define what roles are restricted to state staff. Completed February 2025. 2. The Access Forms will be updated with the AdministratorLO role being in the restricted roles section and marked as only available to state staff. Completed February 2025. 3. During future reviews of restricted roles CWDS Users with these roles will be checked against staffing lists to confirm their employment status and availability for these roles. To be completed at the next Annual Review of Restricted Roles. A supplementary Annual Restricted Role Audit being completed currently for Restricted Roles. Completed March 2025. Anticipated Completion Date: Completed Contact Name: Jeremy Bender, Customer Service Unit Workforce Development Supervisor BWPO acknowledges that these errors occurred. The accounts were immediately deactivated upon discovery that the staff were no longer with the Commonwealth. The following steps will be taken to prevent a re-occurrence of this issue. 1. Three of the accounts in question were originally BWPO staff who moved to ATO, still needing CWDS Access, and then left state employment at a later date. There is currently not a system in place to review ATO staff separations. Going forward, Monthly Account Deactivation reviews will be expanded to BWDA and ATO with those Bureaus having to attest to all separations during the prior month. This should help ensure the Customer Service Unit is notified timely of staff separations in the other Bureaus. To begin March 31, 2025. 2. During periodic review of deactivations, the Customer Service Unit will compare CWOPA accounts against state staffing lists provided by HR, to ensure separated staff have their accounts deactivated timely. This will likely have to be quarterly or semi-annually as it is unfeasible for HR to have to generate full staff complements monthly for the multiple Bureaus whose CWDS Access BWPO’s Customer Service Unit manages. This will catch any issues that step 1 doesn’t resolve. To begin March 31, 2025. Anticipated Completion Date: 03/31/2025 Contact Name: Jeremy Bender, Customer Service Unit Workforce Development Supervisor

About Other →
2024-013
Reporting
REPEAT

Two of four quarterly Project and Expenditure Reports were selected for testing. The Office of Budget Operations (OBO) reported incomplete capital project information in these quarterly reports. Specifically, the following exceptions were noted: • A project’s description allows capital expenditures by subrecipients, but OBO has reported it as a non-capital project on both the 9/30/2023 and 3/31/2024 quarterly Project and Expenditure reports. In addition, the Pennsylvania Emergency Management Agency (PEMA) did not require the subrecipients receiving funding under this project to report their capital expenditures to PEMA. Therefore, OBO is unable to determine the amount of capital expenditures obligated and expended for this project for the quarters tested. • A capital project in excess of $10 million was reported as a non-capital project on the 9/30/2023 quarterly report. • On the 9/30/2023 quarterly report, the project was correctly reported as a capital project and the required written justification was included, however, the justification did not include all required elements. Criteria: Per the Compliance and Reporting Guidance issued by the U.S. Department of the Treasury, recipients must report if a project includes capital expenditures, the type of capital expenditure, and the amount of capital expenditures obligated and expended. Per 31 CFR §35.6(b)(4), a recipient, other than a Tribal government, must prepare written justifications for capital projects with capital expenditures enumerated by Treasury in the final rule and with total capital expenditures greater than $10 million. Such written justifications must include the following elements: (i) Describe the harm or need to be addressed; (ii) Explain why a capital expenditure is appropriate; and (iii) Compare the proposed capital expenditure to at least two alternative capital expenditures and demonstrate why the proposed capital expenditure is superior. Management Directive 325.12, Amended – Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office’s Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: PEMA issued subawards to 666 local EMS companies and the subrecipients were allowed to expend the funds on a variety of uses, including capital expenditures. PEMA did not obtain detail of capital expenditures incurred from the subrecipients and was therefore unable to provide the information to OBO for inclusion on the Project and Expenditure Reports. Finding 2024 – 013: (continued) The required elements for capital project justifications are summarized on page 4390 of the Final Rule, but they are not mentioned in the Project and Expenditure Report User Guide nor in the Compliance and Reporting Guidance. Therefore, OBO was unaware that it was necessary to include specific elements in the justification. Effect: OBO did not properly identify and report capital projects. Errors included omitting capital project obligations and expenditures and incomplete justifications for a capital project greater than $10 million. Recommendation: We recommend that OBO ensures that all capital projects are properly reported and that justifications for capital projects greater than $10 million include all required elements. We further recommend that subrecipients are sufficiently monitored to allow OBO to correctly report capital expenditures obligated and expended. Agency Response: The Office of Budget Operations, formerly known as the Governor’s Budget Office or GBO, agrees with this finding. Through our Corrective Action Plan, we will document the work we’ve already done to resolve this finding. Questioned Costs: None

Show full finding ▾
Full finding narrative

Office of Budget Operations Finding 2024 – 013: ALN 21.027 – COVID 19 – Coronavirus State and Local Fiscal Recovery Funds A Significant Deficiency and Noncompliance Exist at the Office of Budget Operations Related to the Quarterly Project and Expenditure Report (A Similar Condition Was Noted in Prior Year Finding 2023-020) Federal Grant Number(s) and Year(s): TN75GJE1S7G3 (3/03/2021 – 12/31/2024) Type of Finding: Significant Deficiency in Internal Control over Compliance, Other Matters Compliance Requirement: Reporting Condition: Two of four quarterly Project and Expenditure Reports were selected for testing. The Office of Budget Operations (OBO) reported incomplete capital project information in these quarterly reports. Specifically, the following exceptions were noted: • A project’s description allows capital expenditures by subrecipients, but OBO has reported it as a non-capital project on both the 9/30/2023 and 3/31/2024 quarterly Project and Expenditure reports. In addition, the Pennsylvania Emergency Management Agency (PEMA) did not require the subrecipients receiving funding under this project to report their capital expenditures to PEMA. Therefore, OBO is unable to determine the amount of capital expenditures obligated and expended for this project for the quarters tested. • A capital project in excess of $10 million was reported as a non-capital project on the 9/30/2023 quarterly report. • On the 9/30/2023 quarterly report, the project was correctly reported as a capital project and the required written justification was included, however, the justification did not include all required elements. Criteria: Per the Compliance and Reporting Guidance issued by the U.S. Department of the Treasury, recipients must report if a project includes capital expenditures, the type of capital expenditure, and the amount of capital expenditures obligated and expended. Per 31 CFR §35.6(b)(4), a recipient, other than a Tribal government, must prepare written justifications for capital projects with capital expenditures enumerated by Treasury in the final rule and with total capital expenditures greater than $10 million. Such written justifications must include the following elements: (i) Describe the harm or need to be addressed; (ii) Explain why a capital expenditure is appropriate; and (iii) Compare the proposed capital expenditure to at least two alternative capital expenditures and demonstrate why the proposed capital expenditure is superior. Management Directive 325.12, Amended – Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office’s Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: PEMA issued subawards to 666 local EMS companies and the subrecipients were allowed to expend the funds on a variety of uses, including capital expenditures. PEMA did not obtain detail of capital expenditures incurred from the subrecipients and was therefore unable to provide the information to OBO for inclusion on the Project and Expenditure Reports. Finding 2024 – 013: (continued) The required elements for capital project justifications are summarized on page 4390 of the Final Rule, but they are not mentioned in the Project and Expenditure Report User Guide nor in the Compliance and Reporting Guidance. Therefore, OBO was unaware that it was necessary to include specific elements in the justification. Effect: OBO did not properly identify and report capital projects. Errors included omitting capital project obligations and expenditures and incomplete justifications for a capital project greater than $10 million. Recommendation: We recommend that OBO ensures that all capital projects are properly reported and that justifications for capital projects greater than $10 million include all required elements. We further recommend that subrecipients are sufficiently monitored to allow OBO to correctly report capital expenditures obligated and expended. Agency Response: The Office of Budget Operations, formerly known as the Governor’s Budget Office or GBO, agrees with this finding. Through our Corrective Action Plan, we will document the work we’ve already done to resolve this finding. Questioned Costs: None

Corrective Action Plan

The Office of Budget Operations has already completed the steps to correct the issues cited. OB-OBO's prior year CAP identified the following issues to be resolved as a result of the audit finding: Capital Project Justification Did Not Include All Required Elements - - The capital project justification was corrected to include all the required elements within the 3/31/2024 quarterly report to U.S. Treasury. Capital Project In Excess Of $10 million - - The capital project in excess of $10 million was correctly reported as a capital project within the 6/30/2023 quarterly report to U.S. Treasury. PEMA Capital Project Reporting - - After the audit finding was issued in February 2024, OBO worked with PEMA to create a survey to request additional capital expenditure information from the grant's beneficiaries. The survey responses were included, along with additional information from the agency pertaining to the capital project explanation and the capital project type in the 6/30/2024 quarterly report. - The additional capital project information was collected and reported within the 6/30/2024 quarterly report to U.S. Treasury. Anticipated Completion Date: Completed Contact Names: Colleen Kling, Division Manager, Program Analysis and Performance Improvement; Mike Wood, Bureau Director, Bureau of Performance, Revenue and Program Analysis

Prior Finding References

2023-020

About Reporting →
2024-014
Subrecipient Monitoring
REPEATQUESTIONED COSTS

The Uniform Guidance in 2 CFR Section 200 applies to the major programs listed above for the fiscal year ended June 30, 2024. Our testing disclosed that the Pennsylvania Department of Human Services (DHS), the Pennsylvania Department of Drug and Alcohol Programs (DDAP), and the Pennsylvania Department of Labor and Industry (L&I) did not identify the federal award information and applicable requirements in subrecipient award documents. Additionally, the Pennsylvania Department of Agriculture (PDA), Pennsylvania Department of Aging (PDOA), Pennsylvania Department of Health (DOH), and DHS did not adequately evaluate each subrecipient’s risk of noncompliance for the purpose of determining the appropriate subrecipient monitoring related to the subaward. This represents an internal control weakness which could cause subrecipients to be improperly informed of federal award information and may result in inadequate monitoring by the state agencies. Also, it could cause the omission or improper identification of program expenditures on subrecipients’ Schedules of Expenditures of Federal Awards (SEFAs). The following chart shows which federal award information required by 2 CFR Section 200 was omitted (as indicated by “No”) from the subrecipient award documents at the time of the subaward and which major programs did not have a state agency evaluation of each subrecipient’s risk of noncompliance. Finding 2024 –¬ 014: (continued) SEE SCHEDULE OF FINDINGS AND QUESTIONED COSTS FOR CHART/TABLE (The cells with a hyphen in the table indicate that the federal award information was included in the subrecipient award documents or was not applicable for the respective major program.) Criteria: 2 CFR Section 200.332, Requirements for pass-through entities, states in part: All pass-through entities must: (a) Ensure that every subaward is clearly identified to the subrecipient as a subaward and includes the following information at the time of the subaward and if any of these data elements change, include the changes in subsequent subaward modification. When some of this information is not available, the pass-through entity must provide the best information available to describe the Federal award and subaward. Required information includes: Finding 2024 –¬ 014: (continued) (1) Federal Award Identification. (iii) Federal Award Identification Number (FAIN); (iv) Federal Award Date (see the definition of Federal Award date in section 200.1) of award to the recipient by the Federal agency; (v) Subaward Period of Performance Start and End Date; (viii) Total Amount of Federal Funds Obligated to the subrecipient by the pass-through entity, including the current financial obligation; (ix) Total Amount of the Federal Award committed to the subrecipient by the pass-through entity; (xi) Name of Federal awarding agency, pass-through entity, and contact information for awarding official of the pass-through entity; (xii) Assistance Listings Number and Title; the pass-through entity must identify the dollar amount made available under each Federal award and the Assistance Listings Number at time of disbursement; (6) Appropriate terms and conditions concerning closeout of the subaward. (b) Evaluate each subrecipient’s risk of noncompliance with Federal statutes, regulations, and the terms and conditions of the subaward for purposes of determining the appropriate subrecipient monitoring described in paragraphs (d) and (e) of this section, which may include consideration of such factors as: (1) The subrecipient’s prior experience with the same or similar subawards; (2) The results of previous audits including whether or not the subrecipient receives a Single Audit in accordance with Subpart F [Audit Requirements] of this part, and the extent to which the same or similar subaward has been audited as a major program; (3) Whether the subrecipient has new personnel or new or substantially changed systems; and (4) The extent and results of Federal awarding agency monitoring (e.g., if the subrecipient also receives Federal awards directly from a Federal awarding agency) Management Directive 325.12, Amended – Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office’s Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should identify, analyze, and respond to risks related to achieving the defined objectives. Management should identify, analyze, and respond to significant changes that could impact the internal control system. Cause: In general, DHS’s, L&I’s, and DDAP’s processes for subrecipient award monitoring did not identify the omission of required elements from the grant awards. In addition, the risk assessments performed by PDA, PDOA, DOH, and DHS were not properly documented or not performed. Effect: Excluding the federal grant award information at the time of the subaward may cause subrecipients and their auditors to be uninformed about specific program and other regulations that apply to the funds they receive. There is also the potential for subrecipients to have incomplete SEFAs in their Single Audit reports submitted to the Commonwealth, and federal funds may not be properly audited at the subrecipient level in accordance with the Single Audit Act and Uniform Guidance. Not evaluating each subrecipient’s risk of noncompliance for purposes of determining the appropriate subrecipient monitoring related to the subaward may result in subrecipients using the subaward for unauthorized purposes or in violation of the terms and conditions of the subaward, and state agency monitoring would not detect this noncompliance and ensure it is corrected in a timely manner. Finding 2024 –¬ 014: (continued) Recommendation: DHS, L&I, and DDAP should develop policies and reporting mechanisms to ensure all required federal award information is disseminated to all subrecipients at the time of the subaward to ensure subrecipient compliance with the Uniform Guidance in 2 CFR Section 200 and other applicable federal regulations. In addition, DHS, DDAP, and L&I should correspond with applicable subrecipients to ensure they are aware of the correct federal award information and review applicable subaward documents prior to issuance to ensure federal information is complete and accurate. PDA, PDOA, DOH, and DHS should implement procedures to adequately document their evaluation of each subrecipient’s risk of noncompliance as cited in 2 CFR Section 200.332 for purposes of determining the appropriate subrecipient monitoring related to the subaward. DHS Response: DHS agrees with the finding. DOH Response: DOH agrees with the finding. PDA Response: PDA agrees with the finding. PDOA Response: PDOA agrees with the finding. DDAP Response: DDAP agrees with the concern indicated in this finding regarding not identifying the federal award information and applicable requirements in subrecipient award documents. The Department contracts with 47 Single County Authorities (SCAs) through 5-year grant agreements. These grant agreements may not have all of the required federal award information pursuant to 2 CFR 200.332 when the agreement is executed. DDAP understands the need to develop policies to ensure all required federal award information is disseminated to all subrecipients. Going forward, the Department will send a separate notification to all subrecipients once all federal award information has been identified to ensure subrecipient compliance with the Uniform Guidance in 2 CFR Section 200 and other applicable federal regulations. L&I Response: L&I considered the required elements outlined in 2 CFR Section 200.332 when designing the template for its subaward documents. The template included a specific section to list the Federal Awarding Agency; however, upon execution of the TANF subaward documents, L&I inadvertently entered incorrect data into this field. The result was that while a Federal Agency was listed in the contract, it was not the Federal Awarding Agency that provided the TANF funding. Upon being made aware of the error, L&I immediately corrected and disseminated the corrected information to the sub-recipients through the Commonwealth Workforce Development System. L&I agrees that at the time of award the name of the Federal Awarding Agency that provided the TANF funding was not included in the subaward documents. Questioned Costs: The amount of questioned costs cannot be determined.

Show full finding ▾
Full finding narrative

Various Agencies Finding 2024 –¬ 014: ALN 10.565, 10.568, 10.569 – Food Distribution Cluster ALN 93.044, 93.045, 93.053 – Aging Cluster (including COVID-19) ALN 93.323 – Epidemiology and Laboratory Capacity for Infectious Diseases (including COVID-19) ALN 93.558 – Temporary Assistance for Needy Families ALN 93.667 – Social Services Block Grant ALN 93.788 – Opioid STR State Agencies Did Not Identify the Federal Award Information and Applicable Requirements at the Time of the Subaward and Did Not Evaluate Each Subrecipient’s Risk of Noncompliance as Required by the Uniform Grant Guidance (A Similar Condition Was Noted in Prior Year Finding 2023-023) Federal Grant Number(s) and Year(s): 231PA825Y8005 (10/01/2022 – 9/30/2023), 231PA825Y8105 (10/01/2022 – 9/30/2023), 231PA445Q2204 (10/01/2022 – 9/30/2023), 241PA825Y8005 (10/01/2023 – 9/30/2024), 241PA825Y8105 (10/01/2023 – 9/30/2024), 228PA100I1003 (6/13/2022 – 6/30/2025), 238PA000I1003 (5/25/2023 – 6/30/2025), 2101PACMC6 (4/01/2021 – 9/30/2024), 2101PAHDC6 (4/01/2021 – 9/30/2024), 2101PAPHC6 (4/01/2021 – 9/30/2024), 2101PASSC6 (4/01/2021 – 9/30/2024), 2201PAOASS (10/01/2021 – 9/30/2023), 2201PASTPH (1/01/2022 – 9/30/2024), 2301PAOACM (10/01/2022 – 9/30/2024), 2301PAOAHD (10/01/2022 – 9/30/2024), 2301PAOANS (10/01/2022 – 9/30/2024), 2301PAOASS (10/01/2022 – 9/30/2024), 2401PAOACM (10/01/2023 – 9/30/2025), 2401PAOAHD (10/01/2023 – 9/30/2025), 2401PAOANS (10/01/2023 – 9/30/2025), 2401PAOASS (10/01/2023 – 9/30/2025), NU50CK000527 (8/01/2019 – 7/31/2026), 2401PATANF (10/01/2023 – 9/30/2024), 2301PATANF (10/01/2022 – 9/30/2023), 2201PATANF (10/01/2021-9/30/2022), 2101PATANF (10/01/2020 – 9/30/2021), 2301PASOSR (10/01/2022 – 9/30/2024), 2401PASOSR (10/01/2023 – 9/30/2025), H79TI083297 (9/30/2021 – 9/29/2023), H79TI085783 (9/30/2022 – 9/29/2024) Type of Finding: Significant Deficiency in Internal Control over Compliance, Other Matters Compliance Requirement: Subrecipient Monitoring Condition: The Uniform Guidance in 2 CFR Section 200 applies to the major programs listed above for the fiscal year ended June 30, 2024. Our testing disclosed that the Pennsylvania Department of Human Services (DHS), the Pennsylvania Department of Drug and Alcohol Programs (DDAP), and the Pennsylvania Department of Labor and Industry (L&I) did not identify the federal award information and applicable requirements in subrecipient award documents. Additionally, the Pennsylvania Department of Agriculture (PDA), Pennsylvania Department of Aging (PDOA), Pennsylvania Department of Health (DOH), and DHS did not adequately evaluate each subrecipient’s risk of noncompliance for the purpose of determining the appropriate subrecipient monitoring related to the subaward. This represents an internal control weakness which could cause subrecipients to be improperly informed of federal award information and may result in inadequate monitoring by the state agencies. Also, it could cause the omission or improper identification of program expenditures on subrecipients’ Schedules of Expenditures of Federal Awards (SEFAs). The following chart shows which federal award information required by 2 CFR Section 200 was omitted (as indicated by “No”) from the subrecipient award documents at the time of the subaward and which major programs did not have a state agency evaluation of each subrecipient’s risk of noncompliance. Finding 2024 –¬ 014: (continued) SEE SCHEDULE OF FINDINGS AND QUESTIONED COSTS FOR CHART/TABLE (The cells with a hyphen in the table indicate that the federal award information was included in the subrecipient award documents or was not applicable for the respective major program.) Criteria: 2 CFR Section 200.332, Requirements for pass-through entities, states in part: All pass-through entities must: (a) Ensure that every subaward is clearly identified to the subrecipient as a subaward and includes the following information at the time of the subaward and if any of these data elements change, include the changes in subsequent subaward modification. When some of this information is not available, the pass-through entity must provide the best information available to describe the Federal award and subaward. Required information includes: Finding 2024 –¬ 014: (continued) (1) Federal Award Identification. (iii) Federal Award Identification Number (FAIN); (iv) Federal Award Date (see the definition of Federal Award date in section 200.1) of award to the recipient by the Federal agency; (v) Subaward Period of Performance Start and End Date; (viii) Total Amount of Federal Funds Obligated to the subrecipient by the pass-through entity, including the current financial obligation; (ix) Total Amount of the Federal Award committed to the subrecipient by the pass-through entity; (xi) Name of Federal awarding agency, pass-through entity, and contact information for awarding official of the pass-through entity; (xii) Assistance Listings Number and Title; the pass-through entity must identify the dollar amount made available under each Federal award and the Assistance Listings Number at time of disbursement; (6) Appropriate terms and conditions concerning closeout of the subaward. (b) Evaluate each subrecipient’s risk of noncompliance with Federal statutes, regulations, and the terms and conditions of the subaward for purposes of determining the appropriate subrecipient monitoring described in paragraphs (d) and (e) of this section, which may include consideration of such factors as: (1) The subrecipient’s prior experience with the same or similar subawards; (2) The results of previous audits including whether or not the subrecipient receives a Single Audit in accordance with Subpart F [Audit Requirements] of this part, and the extent to which the same or similar subaward has been audited as a major program; (3) Whether the subrecipient has new personnel or new or substantially changed systems; and (4) The extent and results of Federal awarding agency monitoring (e.g., if the subrecipient also receives Federal awards directly from a Federal awarding agency) Management Directive 325.12, Amended – Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office’s Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should identify, analyze, and respond to risks related to achieving the defined objectives. Management should identify, analyze, and respond to significant changes that could impact the internal control system. Cause: In general, DHS’s, L&I’s, and DDAP’s processes for subrecipient award monitoring did not identify the omission of required elements from the grant awards. In addition, the risk assessments performed by PDA, PDOA, DOH, and DHS were not properly documented or not performed. Effect: Excluding the federal grant award information at the time of the subaward may cause subrecipients and their auditors to be uninformed about specific program and other regulations that apply to the funds they receive. There is also the potential for subrecipients to have incomplete SEFAs in their Single Audit reports submitted to the Commonwealth, and federal funds may not be properly audited at the subrecipient level in accordance with the Single Audit Act and Uniform Guidance. Not evaluating each subrecipient’s risk of noncompliance for purposes of determining the appropriate subrecipient monitoring related to the subaward may result in subrecipients using the subaward for unauthorized purposes or in violation of the terms and conditions of the subaward, and state agency monitoring would not detect this noncompliance and ensure it is corrected in a timely manner. Finding 2024 –¬ 014: (continued) Recommendation: DHS, L&I, and DDAP should develop policies and reporting mechanisms to ensure all required federal award information is disseminated to all subrecipients at the time of the subaward to ensure subrecipient compliance with the Uniform Guidance in 2 CFR Section 200 and other applicable federal regulations. In addition, DHS, DDAP, and L&I should correspond with applicable subrecipients to ensure they are aware of the correct federal award information and review applicable subaward documents prior to issuance to ensure federal information is complete and accurate. PDA, PDOA, DOH, and DHS should implement procedures to adequately document their evaluation of each subrecipient’s risk of noncompliance as cited in 2 CFR Section 200.332 for purposes of determining the appropriate subrecipient monitoring related to the subaward. DHS Response: DHS agrees with the finding. DOH Response: DOH agrees with the finding. PDA Response: PDA agrees with the finding. PDOA Response: PDOA agrees with the finding. DDAP Response: DDAP agrees with the concern indicated in this finding regarding not identifying the federal award information and applicable requirements in subrecipient award documents. The Department contracts with 47 Single County Authorities (SCAs) through 5-year grant agreements. These grant agreements may not have all of the required federal award information pursuant to 2 CFR 200.332 when the agreement is executed. DDAP understands the need to develop policies to ensure all required federal award information is disseminated to all subrecipients. Going forward, the Department will send a separate notification to all subrecipients once all federal award information has been identified to ensure subrecipient compliance with the Uniform Guidance in 2 CFR Section 200 and other applicable federal regulations. L&I Response: L&I considered the required elements outlined in 2 CFR Section 200.332 when designing the template for its subaward documents. The template included a specific section to list the Federal Awarding Agency; however, upon execution of the TANF subaward documents, L&I inadvertently entered incorrect data into this field. The result was that while a Federal Agency was listed in the contract, it was not the Federal Awarding Agency that provided the TANF funding. Upon being made aware of the error, L&I immediately corrected and disseminated the corrected information to the sub-recipients through the Commonwealth Workforce Development System. L&I agrees that at the time of award the name of the Federal Awarding Agency that provided the TANF funding was not included in the subaward documents. Questioned Costs: The amount of questioned costs cannot be determined.

Corrective Action Plan

DHS: TANF – Child Care All applicable federal Notice of Awards (NOAs), which include the Federal Award Identification Number, will be emailed to the grantees both prior to the spending period and as they become available for the spending as indicated on the NOA. They will also be included in the annual Audit Guidelines. Anticipated Completion Date: Completed Contact Names: Nia Harris, Dir, Bur. of Early Learning Res. Center Ops.; Adrienne Smyth, Human Service Prgm. Executive; Paula Piasecky, Human Serv. Prgm. Rep. TANF – Other The DHS Office of Policy Development (OPD) will perform risk assessments for all grantees annually. Anticipated Completion Date: 06/30/2025 The DHS Office of Income Maintenance (OIM) reestablished the completion of risk assessments in the fall of 2024 and has provisionally completed them for all subrecipients, including TANF – Other, for FY23-24. The risk assessments seek to test various financial controls of subrecipients based on their risk assessment scores and will also assist in ranking subrecipients across the risk continuum. Anticipated Completion Date: Completed Contact Names: Louie Marven, OPD, Exec. Policy Splst.; Sheldon Marcus, OIM, Dir., Div. of Mgmt. & Bgt.; Ron Seliga, OIM, Mgr., Fin. Planning; Judy Alfaro, OIM, Mgr., Financial Accountability; Laura Schlagnhaufer, OIM, Dir., Div. of Contr. Progs. & Sys. Social Services Block Grant (SSBG) OPD will provide all grantees receiving federal funding with a letter identifying federal award information and applicable requirements. OPD will provide this letter annually. Anticipated Completion Date: Completed Contact Name: Louie Marven, OPD, Exec. Policy Specialist DOH: DOH planned to develop and implement a robust subrecipient monitoring program which included establishing a new section within the Budget Office. The PA Legislature did not approve a budget with funding that could accommodate a new section. Alternatively, a consulting firm was engaged to perform a review of policies and procedures across the agency, including providing a gap analysis to determine compliance. A recommendation report is to be provided to DOH by March 31, 2025. DOH will initiate a comprehensive training plan for department staff based on the recommendation report. DOH will then develop training materials with an anticipated completion of June 30, 2025, with a goal to conduct training across the department by September 30, 2025. Anticipated Completion Date: 09/30/2025 Contact Name: Andrea Race, CFO PDA: PDA’s Bureau of Food Assistance (BFA) will develop a process to evaluate each subrecipient’s risk of noncompliance with federal statutes, regulations, and the terms and conditions of the subaward for purposes of determining the appropriate subrecipient monitoring. The evaluation will be based on Key Performance Indicators, such as leadership tenure; prior incidents of food spoilage; or qualitative feedback from clients served. If the evaluation determines that additional monitoring tools beyond the routine performance of on-site reviews of the subrecipient’s program operations are necessary, such conditions will be laid out in a separate letter communication to the sub-awardee. PDA will also develop and implement a system to document the evaluation of each subrecipients risk of noncompliance. Anticipated Completion Date: 09/30/2025 Contact Name: Caryn Long Earl, Director, Bureau of Food Assistance PDOA: Concerning the evaluation of each Subrecipient’s Risk of Noncompliance, PDOA has developed a new monitoring component, consisting of fifteen measurable elements, to actively monitor compliance of the 52 Area Agencies on Aging (AAA) subrecipients through a revised Phase IX monitoring tool. The revised tool, used by three Fiscal Field Representatives, includes a review of Program and Procurement, Contract Monitoring, Record Retention and Environmental Modifications. • Timelines have been established to evaluate each subrecipients risk of noncompliance with Federal statutes, regulations and the terms and conditions of their subaward. - The Bureau of Finance coordinated with the Bureau of Quality Assurance to ensure schedules do not conflict and become burdensome to the AAA network. - The Fiscal Representatives plan to follow-up on any Performance Issues identified within the succeeding 6-9 months as identified in the approved Cost Allocation Plan. - Prior to the start of a new State Fiscal Year, the Risk Assessment surveys are distributed to adequately evaluate each subrecipient’s risk of noncompliance timely. • PDOA has drafted a AAA Fiscal Monitoring process map to formally document the monitoring process which highlights the requirement to disseminate Risk Assessments. • PDOA has been working with the AAAs to correct reporting in preparation of the next round of monitoring to ensure accuracy of Financial Reporting requirements and Line-Item Budgets on record. • To avoid future deficiencies in compliance, revised risk assessments have been developed to evaluate each subrecipient’s risk of noncompliance to proactively address any weaknesses in internal controls over Federal programs. • Despite PDOA recognizing time and insufficient staffing as a barrier to achieving the goal of performing a risk assessment for every AAA, we have surpassed our expectation of reaching half at a minimum by conducting a full assessment of all 52 for fiscal year ending June 30, 2024. • PDOA confirmed the Comprehensive Aging Performance Evaluation (CAPE) approach to evaluations of aging services provided by AAAs a success and shifted it out of pilot status which features a fiscal component. • To best review internal controls for financial issues concerning the Aging Cluster, a fiscal component will be administered since multiple Federal funding streams are involved. • This finding has aided in our approach to the subrecipient section of contract language as the Cooperative Block Grants are actively being developed. The proposed policy addresses Subrecipient requirements in the Admin Chapter as opposed to the appendix as a result. Anticipated Completion Date: 06/30/2025 Contact Name: Jennifer Cave, Fiscal Management Specialist, PDOA Audit Liaison DDAP: DDAP understands the need to develop policies to ensure all required federal award information is disseminated to all subrecipients at the time of the subaward. DDAP currently includes the following federal award information in its grant agreements to subrecipients: • Subaward Period of Performance Start and End Date • Total amount of Federal funds obligated to the subrecipient • Total amount of the Federal award committed to the subrecipient • Name of Federal awarding agency, pass-through entity, and contact information for awarding official of pass-through entity • Assistance Listings Number (ALN) and title However, not all the required information is available at the time the grant agreements are executed, such as the Federal Award Identification Number (FAIN) and the Federal award date. To ensure subrecipients are compliant with the Uniform Guidance in 2 CFR Section 200 and other applicable federal regulations, DDAP will develop policies to ensure notification is sent to all subrecipients that includes all required federal award information once the information has been received through the Notice of Award from the Substance Abuse and Mental Health Services Administration (SAMHSA). • First draft of P&P and proposed letter to subrecipients: Person responsible - Ellie Stache and Tia Roebuck: Anticipated completion date - 03/28/2025 • Review of first draft and letter by Bureau Director: Person responsible - Marie Plumer, Director, Bureau of Administration: Anticipated completion date - 04/11/2025 • Revision to first drafts: Person responsible - Ellie Stache: Anticipated completion date - 04/25/2025 • Review of second drafts by Executive staff: Person responsible - Kelly Primus, Deputy Secretary: Anticipated completion date - 05/09/2025 • Revisions to second drafts: Person responsible - Ellie Stache: Anticipated completion date - 05/23/2025 • Final review by Bureau Director and Executive staff: Person responsible - Marie Plumer and Kelly Primus: Anticipated completion date - 06/06/2025 • Submission to auditor: Person responsible - Tia Roebuck: Anticipated completion date - 06/30/2025 Anticipated Completion Date: 06/30/2025 Contact Names: Tia Roebuck, Director, Division of Budget and Procurement; Ellie Stache, Section Chief, Fiscal Planning and Contractual Operations L&I: Once L&I’s Bureau of Workforce Development Administration (BWDA) identified that the incorrect funding source was listed on the Notice of Obligation (NOO) associated with the TANF Youth Development Program contract, BWDA updated the list of funding sources in the Commonwealth Workforce Development System to encompass ALN 93.558. This update was implemented on February 20, 2025, and the updated NOOs were disseminated through CWDS. This change ensures that all NOOs created under ALN 93.558 now and in the future will have the correct funding source listed for the subrecipient. Anticipated Completion Date: Completed Contact Names: Brenda Duppstadt, Director; Gordon Zook, Division Chief

Prior Finding References

2023-023

About Subrecipient Monitoring →
2024-015
Subrecipient Monitoring
MATERIAL WEAKNESSREPEATQUESTIONED COSTS

Under the Commonwealth of Pennsylvania's (Commonwealth) implementation of the Single Audit Act, review and resolution of subrecipient Single Audit reports is split into two stages. The Office of the Budget’s Bureau of Accounting and Financial Management (OB-BAFM) ensures the reports meet technical standards through a centralized desk review process. The various funding agencies in the Commonwealth are responsible for making a management decision on each finding within six months of the Federal Audit Clearinghouse’s (FAC) Acceptance date for audits subject to Uniform Guidance and to ensure appropriate corrective action is taken by the subrecipient (except for Uniform Guidance Finding 2024 ¬– 015: (continued) audits under U.S. Department of Labor programs which are permitted 12 months for management decisions in accordance with 2 CFR Section 2900.21). Each Commonwealth agency is also responsible for reviewing financial information in each audit report to determine whether the audit included all pass-through funding provided by the agency to ensure pass-through funds were subject to audit. Most agencies meet this requirement by performing Schedule of Expenditures of Federal Awards (SEFA) reconciliations. The agency is also required to adjust Commonwealth records, if necessary. Our fiscal year ended June 30, 2024 audit of the Commonwealth’s process for review and resolution of subrecipient Single Audits included an evaluation of the Commonwealth’s fiscal year ended June 30, 2023 subrecipient audit universe for audits due for submission to the FAC during the fiscal year ended June 30, 2024. We also evaluated the Commonwealth’s review of 45 subrecipient audit reports with findings in major programs/clusters which were identified on the Commonwealth agencies’ tracking lists during the fiscal year ended June 30, 2024 and required management decisions by Commonwealth agencies. Our testing disclosed the following audit exceptions regarding the Commonwealth agencies’ review of subrecipient audit reports: • Pennsylvania Department of Aging (PDOA): Our testing disclosed that PDOA did not have procedures in place to track audit reports including having an audit tracking list. The time period for making a management decision on findings was approximately 17.6 months to over 18 months after the FAC Acceptance date for two out of two audit reports with findings. There was also a delay in PDOA’s procedures to ensure the subrecipient SEFAs were accurate so that major programs were properly determined and subjected to audit. • Department of Agriculture (PDA): Our testing disclosed that PDA did not have procedures in place to track audit reports including having an audit tracking list. The time period for making a management decision on findings was approximately 8.7 months to over 16 months after the FAC Acceptance date for four out of four audit reports with findings. • Department of Education (PDE): The time period for making a management decision on findings was approximately 7.8 months to over 12 months after the FAC Acceptance date for seven out of 22 audit reports with findings. There were additional audit reports with findings listed on PDE’s audit tracking list where management decisions were not made timely. • Department of Environmental Protection (DEP): The time period for making a management decision on findings was approximately 11.6 months to over 12 months after the FAC Acceptance date for two out of two audit reports with findings. Our testing disclosed for the two late audit reports, DEP made management decisions timely. However, DEP did not notify the subrecipients of the management decisions within the required six month time period after the audit reports FAC Acceptance date. • Department of Human Services (DHS): The time period for making a management decision on findings was approximately 7.2 months after the FAC Acceptance date for one out of two audit reports with findings. Our testing disclosed for the one late audit report DHS made a management decision timely. However, DHS did not notify the subrecipient of the management decision within the required six month time period after the audit reports FAC Acceptance date. Criteria: 2 CFR §200.332, Requirements for pass-through entities, states in part: All pass-through entities must: (d) Monitor the activities of the subrecipient as necessary to ensure that the subaward is used for authorized purposes, in compliance with Federal statutes, regulations, and the terms and conditions of the subaward, and that subaward performance goals are achieved. Pass-through entity monitoring of the subrecipient must include: Finding 2024 ¬– 015: (continued) (2) Following-up and ensuring that the subrecipient takes timely and appropriate action on all deficiencies pertaining to the Federal award provided to the subrecipient from the pass-through entity detected through audits, on-site reviews, and written confirmation from the subrecipient, highlighting the status of actions planned or taken to address Single Audit findings related to the particular subaward. (3) Issuing a management decision for applicable audit findings pertaining only to the Federal award provided to the subrecipient from the pass-through entity as required by §200.521 [Management decision]. (f) Verify that every subrecipient is audited as required by Subpart F [Audit Requirements] of this part when it is expected that the subrecipient’s Federal awards expended during the respective fiscal year equaled or exceeded the threshold set forth in §200.501 [Audit requirements]. (g) Consider whether the results of the subrecipient’s audit, on-site review, or other monitoring indicate conditions that necessitate adjustments to the pass-through entity’s own records. (h) Consider taking enforcement action against noncompliant subrecipients as described in §200.339 [Remedies for noncompliance] of this part and in program regulations. In order to carry out these responsibilities properly, good internal control dictates that state pass-through agencies ensure subrecipient Single Audit SEFAs are representative of state payment records each year, and that the related federal programs have been properly subjected to Single Audit procedures. 2 CFR §200.512, Report submission, states in part: (a) General. (1) The audit must be completed and the data collection form described in paragraph (b) of this section and reporting package described in paragraph (c) of this section must be submitted within the earlier of 30 calendar days after receipt of the auditor’s report(s), or nine months after the end of the audit period. If the due date falls on a Saturday, Sunday, or Federal holiday, the reporting package is due the next business day. 2 CFR §200.521, Management decision, states in part: (a) General. The management decision must clearly state whether or not the finding is sustained, the reasons for the decision, and the expected auditee action to repay disallowed costs, make financial adjustments, or take other action. (d) Time requirements. The Federal awarding agency or pass-through entity responsible for issuing a management decision must do so within six months of acceptance of the audit report by the FAC. The auditee must initiate and proceed with corrective action as rapidly as possible and corrective action should begin no later than upon receipt of the audit report. 2 CFR §200.505, Sanctions, states: In cases of continued inability or unwillingness to have an audit conducted in accordance with this part, Federal agencies and pass-through entities must take appropriate action as provided in §200.339 [Remedies for noncompliance]. 2 CFR §200.339, Remedies for noncompliance, states in part: If a non-Federal entity fails to comply with the U.S. Constitution, Federal statutes, regulations or the terms and conditions of a Federal award, the Federal awarding agency or pass-through entity may impose additional conditions, as described in §200.208 [Specific conditions]. If the Federal awarding agency or pass-through entity determines that noncompliance cannot be remedied by imposing additional conditions, the federal awarding agency or pass-through entity may take one or more of the following actions, as appropriate in the circumstances. Finding 2024 ¬– 015: (continued) (a) Temporarily withhold cash payments pending correction of the deficiency by the non-Federal entity or more severe enforcement action by the Federal awarding agency or pass-through entity. (b) Disallow (that is, deny both use of funds and any applicable matching credit for) all or part of the cost of the activity or action not in compliance. (c) Wholly or partly suspend or terminate the Federal award. (d) Initiate suspension or debarment proceedings as authorized under 2 CFR Part 180 and Federal awarding agency regulations (or in the case of a pass-through entity, recommend such a proceeding be initiated by a Federal awarding agency). (e) Withhold further Federal awards for the project or program. (f) Take other remedies that may be legally available. To ensure Commonwealth enforcement of federal regulations for subrecipient noncompliance with audit requirements, Commonwealth Management Directive 325.08, Amended – Remedies for Recipient Noncompliance with Audit Requirements, Section 5 related to policy, states in part: (a) Agencies must develop and implement remedial action that reflects the unique requirements of each program… (b) The remedial action should be implemented within six months from the date the first remedial action is initiated. At the end of the six-month period, the recipient should take the appropriate corrective action or the final stage of remedial action should be imposed on the recipient. Examples of remedial action include, but are not limited to: (1) Meeting or calling the recipient to explain the importance and benefits of the audit and audit resolution processes, emphasizing the value of the audit as an administrative tool and the Commonwealth’s reliance on an acceptable audit and prompt resolution as evidence of the recipient’s ability to properly administer the program. (2) Encouraging the entity to establish an audit committee or designate an individual as the single point of contact to: (a) Communicate regarding the audit. (b) Arrange for and oversee the audit. (c) Direct and monitor audit resolution. (3) Providing technical assistance to the recipient in devising and implementing an appropriate plan to remedy the noncompliance. (4) Withholding a portion of assistance payments until the noncompliance is resolved. (5) Withholding or disallowing overhead costs until the noncompliance is resolved. (6) Suspending the assistance agreement until the noncompliance is resolved. (7) Terminating the assistance agreement with the recipient and, if necessary, seeking alternative entities to administer the program. Finding 2024 ¬– 015: (continued) Management Directive 325.09, Amended – Processing Subrecipient Single Audits of Federal Pass-Through Funds, Section 7 related to procedures, states in part: c. Agencies. (2) Evaluate single audit report submissions received from BAFM to determine program purpose acceptability by verifying, at a minimum, that all agency-funded programs are properly included on the applicable financial schedules; that findings affecting the agency contain sufficient information to facilitate a management decision; and that the subrecipient has submitted an adequate corrective action plan. (5) Issue management decisions relative to audit findings and crosscutting findings assigned to the agency for resolution, as required by 2 CFR §200.521. If responsible for the resolution of crosscutting findings, notify the affected agency or agencies upon resolution of such findings. (6) Impose or coordinate the imposition of remedial action in accordance with 2 CFR Part 200.339 and Management Directive 325.08 Amended, Remedies for Recipient Noncompliance with Audit Requirements, when subrecipients fail to comply with the provisions of Subpart F. Management Directive 325.12, Amended – Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office’s, Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: One reason provided by Commonwealth management for untimely audit resolution in the various agencies, including making management decisions, approving corrective action, and performing procedures to ensure the accuracy of subrecipient SEFAs, was either a change in staff or a lack of staff to follow up and process subrecipient audit reports more timely. Effect: Since required management decisions were not made within six months to ensure appropriate corrective action was taken on audits received from subrecipients, the Commonwealth did not comply with federal regulations, and subrecipients were not made aware of acceptance or rejection of corrective action plans in a timely manner. Further, noncompliance may recur in future periods if control deficiencies are not corrected on a timely basis, and there is an increased risk of unallowable charges being made to federal programs if corrective action and recovery of questioned costs is not timely. Regarding the SEFA reviews or alternate procedures which are not being performed timely, there is an increased risk that subrecipients could be misspending and/or inappropriately tracking and reporting federal funds over multiple year periods, and these discrepancies may not be properly monitored, detected, and corrected by agency personnel on a timely basis as required. Recommendation: We recommend that the above weaknesses that cause untimely subrecipient Single Audit resolution, including untimely management decisions on findings, and untimely review of the SEFA or alternate procedures be corrected to ensure compliance with federal requirements and Commonwealth Management Directives, and to better ensure timelier subrecipient compliance with program requirements. PDOA Response: PDOA agrees with the finding. PDA Response: PDA agrees with the finding. PDE Response: PDE agrees with the finding. DEP Response: DEP agrees with the finding. Finding 2024 ¬– 015: (continued) DHS Response: DHS agrees that there was an exception where human error caused a management decision on one single audit report to be issued untimely; in this instance, the decision itself was made timely but was not communicated in a timely manner. DHS disagrees that an isolated incident due to human error signifies a weakness in internal controls. This was not a systemic issue and therefore should not have been considered a significant deficiency in internal controls, and DHS should not have been included in this finding. Auditors’ Conclusion: The agency responses from PDOA, PDA, PDE, and DEP indicate agreement with the finding. DHS agrees that an error occurred resulting in untimely submission of one management decision, DHS disagrees that the error represents a significant deficiency. We acknowledge the error occurred due to an oversight and is not a systemic error, however, the error resulted in noncompliance with one of two audit reports that required timely management decisions. We will evaluate corrective action in the subsequent audit. The finding remains as stated. Questioned Costs: The amount of questioned costs cannot be determined.

Show full finding ▾
Full finding narrative

Various Agencies Finding 2024 ¬– 015: ALN 10.565, 10.568, 10.569 – Food Distribution Cluster ALN 15.252 – Abandoned Mine Land Reclamation (AMLR) ALN 21.027 – COVID 19 – Coronavirus State and Local Fiscal Recovery Funds ALN 84.425C – COVID 19 – Education Stabilization Fund – GEER Fund ALN 84.425D – COVID 19 – Education Stabilization Fund – ESSER Fund ALN 84.425R – COVID 19 – Education Stabilization Fund – CRRSA EANS Program ALN 84.425U – COVID 19 – Education Stabilization Fund – ARP ESSER ALN 84.425V – COVID 19 – Education Stabilization Fund – ARP EANS Program ALN 84.425W – COVID 19 – Education Stabilization Fund – ARP ESSER HCY ALN 93.044, 93.045, 93.053 – Aging Cluster (including COVID-19) ALN 93.558 – Temporary Assistance for Needy Families ALN 93.667 – Social Services Block Grant A Material Weakness and Material Noncompliance Exist in the Commonwealth’s Subrecipient Audit Resolution Process (A Similar Condition Was Noted in Prior Year Finding 2023-024) Federal Grant Number(s) and Year(s): 228PA100I1003 (6/13/2022 – 6/30/2025), 231PA445Q2204 (10/01/2022 – 9/30/2023), 231PA825Y8005 (10/01/2022 – 9/30/2023), 231PA825Y8105 (10/01/2022 – 9/30/2023), 241PA825Y8005 (10/01/2023 – 9/30/2024), 241PA825Y8105 (10/01/2023 – 9/30/2024), S18AF20004 (11/01/2017 – 10/31/2025), S19AF20004 (12/01/2018 – 11/30/2025), S21AF10015 (1/01/2021 – 12/31/2023), S22AF00017 (1/01/2022 – 12/31/2024), S23AF00002 (11/01/2022 – 10/31/2027), TN75GJE1S7G3 (3/03/2021 – 12/31/2024), S425W210039 (4/23/2021 – 9/30/2024), S425U210028 (3/24/2021– 9/30/2024), S425D210028 (1/05/2021 – 9/30/2024), S425C200013 (5/18/2020 – 4/01/2024), S425R210037 (3/13/2020 – 9/30/2024), S425V210037 (11/16/2021 – 9/30/2024), S425C210013 (3/13/2020 – 9/30/2024), 2101PACMC6 (4/01/2021 – 9/30/2024), 2101PAHDC6 (4/01/2021 – 9/30/2024), 2101PAPHC6 (4/01/2021 – 9/30/2024), 2101PASSC6 (4/01/2021 – 9/30/2024), 2201PAOASS (10/01/2021 – 9/30/2023), 2201PASTPH (1/01/2022 – 9/30/2024), 2301PAOACM (10/01/2022 – 9/30/2024), 2301PAOAHD (10/01/2022 – 9/30/2024), 2301PAOANS (10/01/2022 – 9/30/2024), 2301PAOASS (10/01/2022 – 9/30/2024), 2401PAOACM (10/01/2023 – 9/30/2025), 2401PAOAHD (10/01/2023 – 9/30/2025), 2401PAOANS (10/01/2023 – 9/30/2025), 2401PAOASS (10/01/2023 – 9/30/2025), 2101PATANF (10/01/2020 – 9/30/2021), 2201PATANF (10/01/2021 – 9/30/2022), 2301PATANF (10/01/2022 – 9/30/2023), 2401PATANF (10/01/2023 – 9/30/2024), 2301PASOSR (10/01/2022 – 9/30/2024), 2401PASOSR (10/01/2023 – 9/30/2025), 2301PATANF (10/01/2022 – 9/30/2024), 2401PATANF (10/01/2023 – 9/30/2025) Type of Finding: Significant Deficiency in Internal Control over Compliance, Other Matters for Abandoned Mine Land Reclamation (AMLR), Temporary Assistance for Needy Families, Coronavirus State and Local Fiscal Recovery Funds, and Social Services Block Grant Material Weakness in Internal Control over Compliance, Material Noncompliance for Food Distribution Cluster, Education Stabilization Fund, and Aging Cluster Compliance Requirement: Subrecipient Monitoring Condition: Under the Commonwealth of Pennsylvania's (Commonwealth) implementation of the Single Audit Act, review and resolution of subrecipient Single Audit reports is split into two stages. The Office of the Budget’s Bureau of Accounting and Financial Management (OB-BAFM) ensures the reports meet technical standards through a centralized desk review process. The various funding agencies in the Commonwealth are responsible for making a management decision on each finding within six months of the Federal Audit Clearinghouse’s (FAC) Acceptance date for audits subject to Uniform Guidance and to ensure appropriate corrective action is taken by the subrecipient (except for Uniform Guidance Finding 2024 ¬– 015: (continued) audits under U.S. Department of Labor programs which are permitted 12 months for management decisions in accordance with 2 CFR Section 2900.21). Each Commonwealth agency is also responsible for reviewing financial information in each audit report to determine whether the audit included all pass-through funding provided by the agency to ensure pass-through funds were subject to audit. Most agencies meet this requirement by performing Schedule of Expenditures of Federal Awards (SEFA) reconciliations. The agency is also required to adjust Commonwealth records, if necessary. Our fiscal year ended June 30, 2024 audit of the Commonwealth’s process for review and resolution of subrecipient Single Audits included an evaluation of the Commonwealth’s fiscal year ended June 30, 2023 subrecipient audit universe for audits due for submission to the FAC during the fiscal year ended June 30, 2024. We also evaluated the Commonwealth’s review of 45 subrecipient audit reports with findings in major programs/clusters which were identified on the Commonwealth agencies’ tracking lists during the fiscal year ended June 30, 2024 and required management decisions by Commonwealth agencies. Our testing disclosed the following audit exceptions regarding the Commonwealth agencies’ review of subrecipient audit reports: • Pennsylvania Department of Aging (PDOA): Our testing disclosed that PDOA did not have procedures in place to track audit reports including having an audit tracking list. The time period for making a management decision on findings was approximately 17.6 months to over 18 months after the FAC Acceptance date for two out of two audit reports with findings. There was also a delay in PDOA’s procedures to ensure the subrecipient SEFAs were accurate so that major programs were properly determined and subjected to audit. • Department of Agriculture (PDA): Our testing disclosed that PDA did not have procedures in place to track audit reports including having an audit tracking list. The time period for making a management decision on findings was approximately 8.7 months to over 16 months after the FAC Acceptance date for four out of four audit reports with findings. • Department of Education (PDE): The time period for making a management decision on findings was approximately 7.8 months to over 12 months after the FAC Acceptance date for seven out of 22 audit reports with findings. There were additional audit reports with findings listed on PDE’s audit tracking list where management decisions were not made timely. • Department of Environmental Protection (DEP): The time period for making a management decision on findings was approximately 11.6 months to over 12 months after the FAC Acceptance date for two out of two audit reports with findings. Our testing disclosed for the two late audit reports, DEP made management decisions timely. However, DEP did not notify the subrecipients of the management decisions within the required six month time period after the audit reports FAC Acceptance date. • Department of Human Services (DHS): The time period for making a management decision on findings was approximately 7.2 months after the FAC Acceptance date for one out of two audit reports with findings. Our testing disclosed for the one late audit report DHS made a management decision timely. However, DHS did not notify the subrecipient of the management decision within the required six month time period after the audit reports FAC Acceptance date. Criteria: 2 CFR §200.332, Requirements for pass-through entities, states in part: All pass-through entities must: (d) Monitor the activities of the subrecipient as necessary to ensure that the subaward is used for authorized purposes, in compliance with Federal statutes, regulations, and the terms and conditions of the subaward, and that subaward performance goals are achieved. Pass-through entity monitoring of the subrecipient must include: Finding 2024 ¬– 015: (continued) (2) Following-up and ensuring that the subrecipient takes timely and appropriate action on all deficiencies pertaining to the Federal award provided to the subrecipient from the pass-through entity detected through audits, on-site reviews, and written confirmation from the subrecipient, highlighting the status of actions planned or taken to address Single Audit findings related to the particular subaward. (3) Issuing a management decision for applicable audit findings pertaining only to the Federal award provided to the subrecipient from the pass-through entity as required by §200.521 [Management decision]. (f) Verify that every subrecipient is audited as required by Subpart F [Audit Requirements] of this part when it is expected that the subrecipient’s Federal awards expended during the respective fiscal year equaled or exceeded the threshold set forth in §200.501 [Audit requirements]. (g) Consider whether the results of the subrecipient’s audit, on-site review, or other monitoring indicate conditions that necessitate adjustments to the pass-through entity’s own records. (h) Consider taking enforcement action against noncompliant subrecipients as described in §200.339 [Remedies for noncompliance] of this part and in program regulations. In order to carry out these responsibilities properly, good internal control dictates that state pass-through agencies ensure subrecipient Single Audit SEFAs are representative of state payment records each year, and that the related federal programs have been properly subjected to Single Audit procedures. 2 CFR §200.512, Report submission, states in part: (a) General. (1) The audit must be completed and the data collection form described in paragraph (b) of this section and reporting package described in paragraph (c) of this section must be submitted within the earlier of 30 calendar days after receipt of the auditor’s report(s), or nine months after the end of the audit period. If the due date falls on a Saturday, Sunday, or Federal holiday, the reporting package is due the next business day. 2 CFR §200.521, Management decision, states in part: (a) General. The management decision must clearly state whether or not the finding is sustained, the reasons for the decision, and the expected auditee action to repay disallowed costs, make financial adjustments, or take other action. (d) Time requirements. The Federal awarding agency or pass-through entity responsible for issuing a management decision must do so within six months of acceptance of the audit report by the FAC. The auditee must initiate and proceed with corrective action as rapidly as possible and corrective action should begin no later than upon receipt of the audit report. 2 CFR §200.505, Sanctions, states: In cases of continued inability or unwillingness to have an audit conducted in accordance with this part, Federal agencies and pass-through entities must take appropriate action as provided in §200.339 [Remedies for noncompliance]. 2 CFR §200.339, Remedies for noncompliance, states in part: If a non-Federal entity fails to comply with the U.S. Constitution, Federal statutes, regulations or the terms and conditions of a Federal award, the Federal awarding agency or pass-through entity may impose additional conditions, as described in §200.208 [Specific conditions]. If the Federal awarding agency or pass-through entity determines that noncompliance cannot be remedied by imposing additional conditions, the federal awarding agency or pass-through entity may take one or more of the following actions, as appropriate in the circumstances. Finding 2024 ¬– 015: (continued) (a) Temporarily withhold cash payments pending correction of the deficiency by the non-Federal entity or more severe enforcement action by the Federal awarding agency or pass-through entity. (b) Disallow (that is, deny both use of funds and any applicable matching credit for) all or part of the cost of the activity or action not in compliance. (c) Wholly or partly suspend or terminate the Federal award. (d) Initiate suspension or debarment proceedings as authorized under 2 CFR Part 180 and Federal awarding agency regulations (or in the case of a pass-through entity, recommend such a proceeding be initiated by a Federal awarding agency). (e) Withhold further Federal awards for the project or program. (f) Take other remedies that may be legally available. To ensure Commonwealth enforcement of federal regulations for subrecipient noncompliance with audit requirements, Commonwealth Management Directive 325.08, Amended – Remedies for Recipient Noncompliance with Audit Requirements, Section 5 related to policy, states in part: (a) Agencies must develop and implement remedial action that reflects the unique requirements of each program… (b) The remedial action should be implemented within six months from the date the first remedial action is initiated. At the end of the six-month period, the recipient should take the appropriate corrective action or the final stage of remedial action should be imposed on the recipient. Examples of remedial action include, but are not limited to: (1) Meeting or calling the recipient to explain the importance and benefits of the audit and audit resolution processes, emphasizing the value of the audit as an administrative tool and the Commonwealth’s reliance on an acceptable audit and prompt resolution as evidence of the recipient’s ability to properly administer the program. (2) Encouraging the entity to establish an audit committee or designate an individual as the single point of contact to: (a) Communicate regarding the audit. (b) Arrange for and oversee the audit. (c) Direct and monitor audit resolution. (3) Providing technical assistance to the recipient in devising and implementing an appropriate plan to remedy the noncompliance. (4) Withholding a portion of assistance payments until the noncompliance is resolved. (5) Withholding or disallowing overhead costs until the noncompliance is resolved. (6) Suspending the assistance agreement until the noncompliance is resolved. (7) Terminating the assistance agreement with the recipient and, if necessary, seeking alternative entities to administer the program. Finding 2024 ¬– 015: (continued) Management Directive 325.09, Amended – Processing Subrecipient Single Audits of Federal Pass-Through Funds, Section 7 related to procedures, states in part: c. Agencies. (2) Evaluate single audit report submissions received from BAFM to determine program purpose acceptability by verifying, at a minimum, that all agency-funded programs are properly included on the applicable financial schedules; that findings affecting the agency contain sufficient information to facilitate a management decision; and that the subrecipient has submitted an adequate corrective action plan. (5) Issue management decisions relative to audit findings and crosscutting findings assigned to the agency for resolution, as required by 2 CFR §200.521. If responsible for the resolution of crosscutting findings, notify the affected agency or agencies upon resolution of such findings. (6) Impose or coordinate the imposition of remedial action in accordance with 2 CFR Part 200.339 and Management Directive 325.08 Amended, Remedies for Recipient Noncompliance with Audit Requirements, when subrecipients fail to comply with the provisions of Subpart F. Management Directive 325.12, Amended – Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office’s, Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: One reason provided by Commonwealth management for untimely audit resolution in the various agencies, including making management decisions, approving corrective action, and performing procedures to ensure the accuracy of subrecipient SEFAs, was either a change in staff or a lack of staff to follow up and process subrecipient audit reports more timely. Effect: Since required management decisions were not made within six months to ensure appropriate corrective action was taken on audits received from subrecipients, the Commonwealth did not comply with federal regulations, and subrecipients were not made aware of acceptance or rejection of corrective action plans in a timely manner. Further, noncompliance may recur in future periods if control deficiencies are not corrected on a timely basis, and there is an increased risk of unallowable charges being made to federal programs if corrective action and recovery of questioned costs is not timely. Regarding the SEFA reviews or alternate procedures which are not being performed timely, there is an increased risk that subrecipients could be misspending and/or inappropriately tracking and reporting federal funds over multiple year periods, and these discrepancies may not be properly monitored, detected, and corrected by agency personnel on a timely basis as required. Recommendation: We recommend that the above weaknesses that cause untimely subrecipient Single Audit resolution, including untimely management decisions on findings, and untimely review of the SEFA or alternate procedures be corrected to ensure compliance with federal requirements and Commonwealth Management Directives, and to better ensure timelier subrecipient compliance with program requirements. PDOA Response: PDOA agrees with the finding. PDA Response: PDA agrees with the finding. PDE Response: PDE agrees with the finding. DEP Response: DEP agrees with the finding. Finding 2024 ¬– 015: (continued) DHS Response: DHS agrees that there was an exception where human error caused a management decision on one single audit report to be issued untimely; in this instance, the decision itself was made timely but was not communicated in a timely manner. DHS disagrees that an isolated incident due to human error signifies a weakness in internal controls. This was not a systemic issue and therefore should not have been considered a significant deficiency in internal controls, and DHS should not have been included in this finding. Auditors’ Conclusion: The agency responses from PDOA, PDA, PDE, and DEP indicate agreement with the finding. DHS agrees that an error occurred resulting in untimely submission of one management decision, DHS disagrees that the error represents a significant deficiency. We acknowledge the error occurred due to an oversight and is not a systemic error, however, the error resulted in noncompliance with one of two audit reports that required timely management decisions. We will evaluate corrective action in the subsequent audit. The finding remains as stated. Questioned Costs: The amount of questioned costs cannot be determined.

Corrective Action Plan

PDOA: 1. Designing a means to follow-up and ensure timely action of deficiencies through an audit tracking log to monitor reporting submissions, document when they were received, initiated, findings requiring follow-up, and subsequent steps to finalize the audit. 2. Management decisions for applicable findings will be issued and tracked. 3. Improvements have been made with regards to regularity in reporting to more effectively monitor activities of subrecipients consistently with respect to Federal statutes and regulations. 4. PDOA is looking to fill a vacant position with a focus of tracking subrecipient expenditures in the aggregate and tracking single audit submissions on a Commonwealth-wide basis since the Aging Cluster program is material and has material sub-granted expenditures in NSIP and Title III. 5. It is PDOA’s impression that having increased oversight of the SEFA will allow for timely dissemination of management decision letters (MDL) in the six-month timeframe for making a management decision for federal award findings. 6. Discussions have started regarding considerations to take enforcement action against noncompliance by building language into the terms and conditions of the Cooperative Block Grant Agreements to exercise ability to withhold funding as approved in the Cost Allocation Plan. 7. PDOA has reached out to the BAFM to verify all outstanding audit items for PDOA since action is required within six months of receipt. 8. Follow-up procedures resulting from this finding will be reviewed and adjusted as needed to deliver optimal outcomes. Anticipated Completion Date: 06/30/2025 Contact Name: Jennifer Cave, Fiscal Management Specialist, PDOA Audit Liaison PDA: PDA has added a Financial Management Specialist 1 (FMS1) to its complement with the primary duty of agency audit liaison. The FMS1 will report to the PDA’s Budget Office. This is a new position and role within the department and has training and certification requirements to complete which will allow the position to: 1. Evaluate single audit report submissions received from BAFM to determine program purpose acceptability by verifying, at a minimum, that all agency-funded programs are properly included on the applicable financial schedules; that findings affecting the agency contain sufficient information to facilitate a management decision; and that the subrecipient has submitted an adequate corrective action plan. 2. Issue management decisions relative to audit findings and crosscutting findings assigned to the agency for resolution, as required by 2 CFR §200.521. If responsible for the resolution of crosscutting findings, notify the affected agency or agencies upon resolution of such findings. 3. Impose or coordinate the imposition of remedial action in accordance with 2 CFR Part 200.339 and Management Directive 325.08 Amended, Remedies for Recipient Noncompliance with Audit Requirements, when subrecipients fail to comply with the provisions of Subpart F. The new FMS1 will help ensure effective and efficient audit resolutions. This newly created position will also be responsible for the department wide audit tracking log that is in development. Anticipated Completion Date: 06/30/2025 Contact Name: Nichole Nedinsky, Fiscal Management Specialist, PDA Audit Coordinator PDE: The PDE Audit Section is working with divisions to develop processes to ensure timely responses. A training will be conducted by April 2025 on audit procedures, best practices, and federal regulations governing single audit management decisions. Anticipated Completion Date: 04/30/2025 Contact Names: Clayton P. Carroll II, Audit Coordinator; Jessica Sites, Director, Bureau Financial Operations DEP: DEP has updated the concur subrecipient letter to include the specific language related to the management decision that was previously in our non-concur letters. This ensures whichever template is used, the management decision and related finding information will be included in the subrecipient letter. Revised letters were sent to both subrecipients, in which DEP was the lead agency and had findings for in the audited timeframe. Staff are reviewing all the steps of our standard operating procedures to ensure we will be in compliance regardless of whether DEP is or is not the lead agency and regardless of whether we are preparing a concur or non-concur letter for the subrecipient. Anticipated Completion Date: 06/30/2025 Contact Names: Jennifer Brandt, Senior Fiscal Mgmt. Specialist; Kristen Szwajkowski, Lead Fiscal Mgmt. Specialist DHS: As stated in the DHS finding response, this was the result of human oversight, and not a systemic issue with internal controls. We have reminded staff to make sure that a management decision is timely communicated to subrecipients at the time of making the management decision. Anticipated Completion Date: Completed Contact Names: David Bryan, Mgr., Audit Res. Section; Alexander Matolyak, Dir., Div. of Audit & Rev.

Prior Finding References

2023-024

About Subrecipient Monitoring →

FY 2023-06-30

FAC accepted this audit on March 20, 2024 — management decision was due September 20, 2024.

2023-002
Matching, Level of Effort, Earmarking / Reporting
MATERIAL WEAKNESS

The Pennsylvania Department of Aging (PDOA) is required to spend at least the average amount of state funds for aging services and administration that it reported as spent under the state plan for these activities for the three previous fiscal years. The amount of state funds expended is subsequently required to be reported to the United States Department of Health and Human Services (HHS) on the Certification of Maintenance of Effort (MOE). Our testing confirmed that PDOA met the state spending requirement for the federal fiscal year (FFY) ended September 30, 2022, for Title III, Parts B and C applicable to the Aging Cluster. However, PDOA did not file the MOE Certification for the FFY ended September 30, 2022, as required. The certification includes other Title III Parts applicable to other, non-Aging Cluster, federal programs. Criteria: 45 CFR Section 1321.49, State agency maintenance of effort, states: In order to avoid a penalty, each fiscal year the State agency, to meet the required non-federal share applicable to its allotments under this part, shall spend under the State plan for both services and administration at least the average amount of State funds it spent under the plan for the three previous fiscal years. If the State agency spends less than this amount, the Commissioner reduces the State’s allotments for supportive and nutrition services under this part by a percentage equal to the percentage by which the State reduced its expenditures. Per Administration for Community Living reporting instructions, the Certification of Maintenance of Effort (form OMB 0985-0009) is required to be submitted annually by the State agency. Commonwealth Management Directive 325.12 Amended – Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office’s Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should design control activities to achieve objectives and respond to risk. Management should implement control activities through policies. Cause: PDOA officials indicated that the MOE Certification was not submitted to HHS due to staff turnover which resulted in an oversight of the reporting requirement. Effect: Since the PDOA did not submit the MOE Certification as required, PDOA is not in compliance with the Level of Effort reporting requirements. In addition, without the required MOE Certification, HHS has no documented assurance that PDOA met the state requirement for the FFY ended September 30, 2022. Finding 2023 – 002: (continued) Recommendation: We recommend that PDOA implement procedures to ensure the MOE Certification is submitted to HHS at the end of each FFY as required. Agency Response: PDOA agrees with this finding. Questioned Costs: None

Show full finding ▾
Full finding narrative

Department of Aging Finding 2023 – 002: ALN 93.044, 93.045, and 93.053 – Aging Cluster (including COVID-19) A Material Weakness and Material Noncompliance Exist in the Department of Aging’s Maintenance of Effort Certification Reporting Process Federal Grant Number(s) and Year(s): 2101PAOACM (10/01/2020 – 9/30/2023), 2101PAOAHD (10/01/2020 – 9/30/2023), 2201PAOACM (10/01/2021 – 9/30/2023), 2201PAOAHD (10/01/2021 – 9/30/2023), 2201PAOASS (10/01/2021 – 9/30/2023), 2301PAOACM (10/01/2022 – 9/30/2024), 2301PAOAHD (10/01/2022 – 9/30/2024) Type of Finding: Material Weakness in Internal Control over Compliance, Material Noncompliance Compliance Requirement: Matching, Level of Effort, Earmarking and Reporting Condition: The Pennsylvania Department of Aging (PDOA) is required to spend at least the average amount of state funds for aging services and administration that it reported as spent under the state plan for these activities for the three previous fiscal years. The amount of state funds expended is subsequently required to be reported to the United States Department of Health and Human Services (HHS) on the Certification of Maintenance of Effort (MOE). Our testing confirmed that PDOA met the state spending requirement for the federal fiscal year (FFY) ended September 30, 2022, for Title III, Parts B and C applicable to the Aging Cluster. However, PDOA did not file the MOE Certification for the FFY ended September 30, 2022, as required. The certification includes other Title III Parts applicable to other, non-Aging Cluster, federal programs. Criteria: 45 CFR Section 1321.49, State agency maintenance of effort, states: In order to avoid a penalty, each fiscal year the State agency, to meet the required non-federal share applicable to its allotments under this part, shall spend under the State plan for both services and administration at least the average amount of State funds it spent under the plan for the three previous fiscal years. If the State agency spends less than this amount, the Commissioner reduces the State’s allotments for supportive and nutrition services under this part by a percentage equal to the percentage by which the State reduced its expenditures. Per Administration for Community Living reporting instructions, the Certification of Maintenance of Effort (form OMB 0985-0009) is required to be submitted annually by the State agency. Commonwealth Management Directive 325.12 Amended – Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office’s Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should design control activities to achieve objectives and respond to risk. Management should implement control activities through policies. Cause: PDOA officials indicated that the MOE Certification was not submitted to HHS due to staff turnover which resulted in an oversight of the reporting requirement. Effect: Since the PDOA did not submit the MOE Certification as required, PDOA is not in compliance with the Level of Effort reporting requirements. In addition, without the required MOE Certification, HHS has no documented assurance that PDOA met the state requirement for the FFY ended September 30, 2022. Finding 2023 – 002: (continued) Recommendation: We recommend that PDOA implement procedures to ensure the MOE Certification is submitted to HHS at the end of each FFY as required. Agency Response: PDOA agrees with this finding. Questioned Costs: None

Corrective Action Plan

As pointed out in the conditions of the finding, audit testing confirmed that PDOA met the state spending requirement for the FFY ended September 30, 2022, for Title III, Parts B and C applicable to Aging Cluster. However, PDOA did not file the MOE Certification for the FFY ended September 30, 2022, as required. An extension was necessary due to the Area Agencies on Aging’s noncompliance with quarterly reporting into AccuFund. The certification includes other Title III Parts applicable to other, non-Aging Cluster, federal programs which are reported by the subrecipients. Once the records are reconciled by virtue of program income being confirmed as reported, totals ending through September 30, 2023, can be submitted. Accordingly, the extension was requested for FFY 2022 final Federal Financial Reports (FFRs/SF-425s) and HHS granted a new deadline of March 31, 2024, to include reported figures instead of predominately estimations. As a result, PDOA has developed and implemented the following remedial actions necessary to address the deficiency in the Maintenance of Effort Certification Reporting Process: - Increased communication between the Bureau of Finance and the Bureau of Accounting and Financial Management (BAFM) to collaboratively work toward producing accurate reports and meet annual requirements. - Standard Operating Procedures to be established in concert with BAFM projected for completion by June of 2024. - Transparency of calculations is one of the considerations being taken on the procedural documents being drafted to ensure the amount of state funds expended is appropriately reported on the MOE. - PDOA is working with HR to hire a vacant position responsible for standardizing the cycles of reporting and to closely monitor compliance. - Additional internal control framework initiated; BAFM has agreed to assist in the certification of state resources expended set forth by Title III of the Older Americans Act, under the approved state plan. - PDOA resolves to follow the recommendation to remit the Certification of MOE as required annually to HHS at the end of each FFY. - Follow-up procedures resulting from this finding will be reviewed and adjusted as needed to deliver optimal outcomes. Preliminary procedures will be directed to the agency’s audit review committee for resolution of completeness. - In the event the audit review committee determines additional steps beyond the monitoring efforts outlined above are insufficient, additional efforts will be communicated to the AAA network. Anticipated Completion Date: 06/30/2024 Contact Name: Jennifer Cave, Fiscal Management Specialist, PDOA Audit Liaison

About Matching, Level of Effort, Earmarking, Reporting →
2023-003
Subrecipient Monitoring
MATERIAL WEAKNESSQUESTIONED COSTS

Within the Aging Cluster, the Pennsylvania Department of Aging (PDOA) contracts with 52 Area Agency on Aging subrecipients to provide various services that include cares support, preventive health, and nutrition services, among others. Our audit testing disclosed that PDOA did not perform subrecipient monitoring on any of the subrecipients during the fiscal year ended June 30, 2023. The Aging Cluster subrecipients received $81.0 million out of Aging Cluster Program expenditures totaling $81.7 million reported on the Schedule of Expenditures of Federal Awards (SEFA). Criteria: 45 CFR Section 1321.11 State agencies policies, states in part: (a) The State agency on aging shall develop policies governing all aspects of programs operated under this part… The State agency is responsible for enforcement of these policies. (b) The policies developed by the State agency shall address the manner in which the State agency will monitor the performance of all programs and activities initiated under this part for quality and effectiveness. 45 CFR Section 75.352, Requirements for pass-through entities, states: (d) Monitor the activities of the subrecipient as necessary to ensure that the subaward is used for authorized purposes, in compliance with Federal statutes, regulations, and the terms and conditions of the subaward; and that subaward performance goals are achieved. Pass-through entity monitoring of the subrecipient must include: (1) Reviewing financial and performance reports required by the pass-through entity. (2) Following-up and ensuring that the subrecipient takes timely and appropriate action on all deficiencies pertaining to the Federal award provided to the subrecipient from the pass-through entity detected through audits, on-site reviews, and other means. (3) Issuing a management decision for audit findings pertaining to the Federal award provided to the subrecipient from the pass-through entity… Finding 2023 ¬– 003: (continued) (e) Depending upon the pass-through entity's assessment of risk posed by the subrecipient (as described in paragraph (b) of this section), the following monitoring tools may be useful for the pass-through entity to ensure proper accountability and compliance with program requirements and achievement of performance goals: (1) Providing subrecipients with training and technical assistance on program-related matters; and (2) Performing on-site reviews of the subrecipient's program operations; (3) Arranging for agreed-upon-procedures engagements as described in §75.425 (Audit services). Management Directive 325.12, Amended – Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office’s Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: While PDOA has subrecipient monitoring procedures in place, PDOA officials indicated that these procedures were not performed for Aging Cluster subrecipients due to staffing shortages. Effect: Without proper subrecipient monitoring, PDOA cannot ensure compliance with grant requirements and federal regulations, including allowable costs and other requirements. Recommendation: PDOA should perform risk based during-the-award monitoring procedures for all Aging Cluster subrecipients to ensure timely compliance with all applicable federal regulations. On-site monitoring visits by state officials should be supported by documentation to show the monitoring performed, areas examined, conclusions reached, and that the monitoring was performed in compliance with applicable regulations. Agency Response: PDOA agrees with this finding. Questioned Costs: The amount of questioned costs cannot be determined.

Show full finding ▾
Full finding narrative

Department of Aging Finding 2023 –¬ 003: ALN 93.044, 93.045, and 93.053 – Aging Cluster (including COVID-19) A Material Weakness and Material Noncompliance Exist in the Department of Aging Related to Subrecipient Monitoring Federal Grant Number(s) and Year(s): 2101PACMC6 (4/01/2021 – 9/30/2024), 2101PAHDC5 (12/27/2020 – 9/30/2023), 2101PAHDC6 (4/01/2021 – 9/30/2024), 2101PAOACM (10/01/2020 – 9/30/2023), 2101PAOAHD (10/01/2020 – 9/30/2023), 2101PAOANS (10/01/2020 – 9/30/2023), 2101PAOASS (10/01/2020 – 9/30/2023), 2101PAPHC6 (4/01/2021 – 9/30/2024), 2101PASSC6 (4/01/2021 – 9/30/2024), 2101PAVAC5 (4/01/2021 – 9/30/2023), 2201PAOACM (10/01/2021 – 9/30/2023), 2201PAOAHD (10/01/2021 – 9/30/2023), 2201PAOANS (10/01/2021 – 9/30/2023), 2201PAOASS (10/01/2021 – 9/30/2023), 2201PASTPH (1/01/2022 – 9/30/2024), 2301PAOACM (10/01/2022 – 9/30/2024), 2301PAOAHD (10/01/2022 – 9/30/2024), 2301PAOANS (10/01/2022 – 9/30/2024), 2301PAOASS (10/01/2022 – 9/30/2024) Type of Finding: Material Weakness in Internal Control over Compliance, Material Noncompliance Compliance Requirement: Subrecipient Monitoring Condition: Within the Aging Cluster, the Pennsylvania Department of Aging (PDOA) contracts with 52 Area Agency on Aging subrecipients to provide various services that include cares support, preventive health, and nutrition services, among others. Our audit testing disclosed that PDOA did not perform subrecipient monitoring on any of the subrecipients during the fiscal year ended June 30, 2023. The Aging Cluster subrecipients received $81.0 million out of Aging Cluster Program expenditures totaling $81.7 million reported on the Schedule of Expenditures of Federal Awards (SEFA). Criteria: 45 CFR Section 1321.11 State agencies policies, states in part: (a) The State agency on aging shall develop policies governing all aspects of programs operated under this part… The State agency is responsible for enforcement of these policies. (b) The policies developed by the State agency shall address the manner in which the State agency will monitor the performance of all programs and activities initiated under this part for quality and effectiveness. 45 CFR Section 75.352, Requirements for pass-through entities, states: (d) Monitor the activities of the subrecipient as necessary to ensure that the subaward is used for authorized purposes, in compliance with Federal statutes, regulations, and the terms and conditions of the subaward; and that subaward performance goals are achieved. Pass-through entity monitoring of the subrecipient must include: (1) Reviewing financial and performance reports required by the pass-through entity. (2) Following-up and ensuring that the subrecipient takes timely and appropriate action on all deficiencies pertaining to the Federal award provided to the subrecipient from the pass-through entity detected through audits, on-site reviews, and other means. (3) Issuing a management decision for audit findings pertaining to the Federal award provided to the subrecipient from the pass-through entity… Finding 2023 ¬– 003: (continued) (e) Depending upon the pass-through entity's assessment of risk posed by the subrecipient (as described in paragraph (b) of this section), the following monitoring tools may be useful for the pass-through entity to ensure proper accountability and compliance with program requirements and achievement of performance goals: (1) Providing subrecipients with training and technical assistance on program-related matters; and (2) Performing on-site reviews of the subrecipient's program operations; (3) Arranging for agreed-upon-procedures engagements as described in §75.425 (Audit services). Management Directive 325.12, Amended – Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office’s Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: While PDOA has subrecipient monitoring procedures in place, PDOA officials indicated that these procedures were not performed for Aging Cluster subrecipients due to staffing shortages. Effect: Without proper subrecipient monitoring, PDOA cannot ensure compliance with grant requirements and federal regulations, including allowable costs and other requirements. Recommendation: PDOA should perform risk based during-the-award monitoring procedures for all Aging Cluster subrecipients to ensure timely compliance with all applicable federal regulations. On-site monitoring visits by state officials should be supported by documentation to show the monitoring performed, areas examined, conclusions reached, and that the monitoring was performed in compliance with applicable regulations. Agency Response: PDOA agrees with this finding. Questioned Costs: The amount of questioned costs cannot be determined.

Corrective Action Plan

Compliance of the 52 Area Agencies on Aging (AAA) subrecipients is currently being monitored by three Fiscal Representatives using a Phase VIII monitoring tool. As the period of performance of evaluation comes to a close, a new tool will be drafted, taking into consideration the additional need for risk assessments. 1. With the use of a Monitoring log, PDOA plans to perform risk assessments systemically statewide for all Aging Cluster subrecipients. 2. A risk assessment is being developed to evaluate each subrecipient’s risk of noncompliance to proactively address any weaknesses in internal controls over federal programs. - Pointed questions regarding the Organization will be included to gauge management’s ability to follow all terms and conditions of the contract. - General Policies will be reviewed for adherence to all federal and state regulations and competence of personnel administering the programs. - Since multiple federal funding streams are involved, a fiscal component will also be administered to review internal controls for financial issues. 3. As a starting point, PDOA plans to prioritize the larger organizations which typically require more monitoring on an annual basis. 4. Subrecipient monitoring is projected to occur during the fiscal year ended June 30, 2024, for the Aging Cluster subrecipients to ensure timely compliance with all applicable federal regulations. 5. Performance check-ins are launching in April of 2024 as part of a statewide comprehensive monitoring as a new form of regulatory measure. 6. PDOA recognizes time and insufficient staffing as a barrier to achieving the goal of performing a risk assessment for every AAA, but has set an expectation of reaching half at a minimum. 7. Follow-Up procedures resulting from this finding will be reviewed and adjusted as needed to deliver optimal outcomes. Preliminary procedures will be directed to the agency’s audit review committee for resolution of completeness. 8. In the event the audit review committee determines additional steps beyond the monitoring efforts outlined above are insufficient, additional efforts will be communicated to the AAA network. Anticipated Completion Date: 06/30/2024 Contact Name: Jennifer Cave, Fiscal Management Specialist, PDOA Audit Liaison

About Subrecipient Monitoring →
2023-004
Special Tests & Provisions
REPEAT

The Pennsylvania Department of Agriculture (PDA), Bureau of Food Assistance (BFA), is responsible for the accountability of the United States Department of Agriculture (USDA) donated food under the National School Lunch Program (NSLP) and Summer Food Service Program for Children (SFSP) within the Child and Nutrition Cluster (CNC). BFA utilizes a computer application as an inventory and distribution tracking system for donated food. The Agency Summary Report, Commodity Inventory Report for Distributors, and Commodity Inventory Report for Processors are generated in the computer application to compile commodity expenditures reported on the Schedule of Expenditures of Federal Awards (SEFA). BFA performs reconciliations of the inventory, commodity receipts, and distributions in these reports to distributor, processor, and recipient activity. A monthly performance report (MPR) is submitted to BFA by processors to support commodity activity. We noted a discrepancy between a processor’s MPR and BFA’s Commodity Inventory Report. We noted the following discrepancy in this reconciliation: • Our testing of 40 processor MPRs disclosed that for one processor, BFA duplicated a receipt on their Commodity Inventory Report which was prepared from the inventory application. Criteria: The 2023 OMB Uniform Guidance Compliance Supplement, Part 4 – Agency Program Requirements for the CNC Cluster, Special Tests and Provisions – N.2 Accountability for USDA – Donated Foods, states: a. Maintenance of Records: Distributing and subdistributing agencies (as defined at 7 CFR section 250.3) must maintain accurate and complete records with respect to the receipt, distribution, and inventory of USDA-donated foods, including end products processed from donated food. 7 CFR Section 250.19, Recordkeeping requirements, states: (a) Required records. Distributing agencies, recipient agencies, processors, and other entities must maintain records of agreements and contracts, reports, audits, and claim actions, funds obtained as an incident of donated food distribution, and other records specifically required in this part or in other Departmental regulations, as applicable. Management Directive 325.12, Amended – Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office’s Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: PDA management stated that inventory received was erroneously duplicated for the processor indicated above. Finding 2023 – 004: (continued) Effect: The discrepancies noted above related to inaccurate records could result in improper distribution of donated foods and misstatements in BFA’s inventory reconciliations and commodity expenditures reported in the SEFA. Recommendation: PDA should maintain accurate and complete records with respect to the receipt, distribution, and inventory of USDA-donated foods, including end products processed from donated food. PDA should strengthen procedures for future periods to ensure errors identified during the reconciliation process are corrected timely in the system. Agency Response: PDA agrees with the facts of the finding. Questioned Costs: None

Show full finding ▾
Full finding narrative

Department of Agriculture Finding 2023 – 004: ALN 10.553, 10.555, 10.556, 10.559, and 10.582 – Child Nutrition Cluster (including COVID-19) Controls Over the Accountability of Donated Foods Need Improvement (A Similar Condition Was Noted in Prior Year Finding 2022-010) Federal Grant Number(s) and Year(s): 231PA305N1099 (10/01/2022 – 9/30/2023), 221PA305N1099 (10/01/2021 – 9/30/2022), 231PA365N8903 (10/01/2022 – 9/30/2024), 221PA365N8903 (10/01/2022 – 9/30/2023) Type of Finding: Significant Deficiency in Internal Control over Compliance, Other Matters Compliance Requirement: Special Tests and Provisions related to Accountability for USDA - Donated Foods Condition: The Pennsylvania Department of Agriculture (PDA), Bureau of Food Assistance (BFA), is responsible for the accountability of the United States Department of Agriculture (USDA) donated food under the National School Lunch Program (NSLP) and Summer Food Service Program for Children (SFSP) within the Child and Nutrition Cluster (CNC). BFA utilizes a computer application as an inventory and distribution tracking system for donated food. The Agency Summary Report, Commodity Inventory Report for Distributors, and Commodity Inventory Report for Processors are generated in the computer application to compile commodity expenditures reported on the Schedule of Expenditures of Federal Awards (SEFA). BFA performs reconciliations of the inventory, commodity receipts, and distributions in these reports to distributor, processor, and recipient activity. A monthly performance report (MPR) is submitted to BFA by processors to support commodity activity. We noted a discrepancy between a processor’s MPR and BFA’s Commodity Inventory Report. We noted the following discrepancy in this reconciliation: • Our testing of 40 processor MPRs disclosed that for one processor, BFA duplicated a receipt on their Commodity Inventory Report which was prepared from the inventory application. Criteria: The 2023 OMB Uniform Guidance Compliance Supplement, Part 4 – Agency Program Requirements for the CNC Cluster, Special Tests and Provisions – N.2 Accountability for USDA – Donated Foods, states: a. Maintenance of Records: Distributing and subdistributing agencies (as defined at 7 CFR section 250.3) must maintain accurate and complete records with respect to the receipt, distribution, and inventory of USDA-donated foods, including end products processed from donated food. 7 CFR Section 250.19, Recordkeeping requirements, states: (a) Required records. Distributing agencies, recipient agencies, processors, and other entities must maintain records of agreements and contracts, reports, audits, and claim actions, funds obtained as an incident of donated food distribution, and other records specifically required in this part or in other Departmental regulations, as applicable. Management Directive 325.12, Amended – Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office’s Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: PDA management stated that inventory received was erroneously duplicated for the processor indicated above. Finding 2023 – 004: (continued) Effect: The discrepancies noted above related to inaccurate records could result in improper distribution of donated foods and misstatements in BFA’s inventory reconciliations and commodity expenditures reported in the SEFA. Recommendation: PDA should maintain accurate and complete records with respect to the receipt, distribution, and inventory of USDA-donated foods, including end products processed from donated food. PDA should strengthen procedures for future periods to ensure errors identified during the reconciliation process are corrected timely in the system. Agency Response: PDA agrees with the facts of the finding. Questioned Costs: None

Corrective Action Plan

PDA strives to maintain accurate and complete records with respect to the receipt, distribution, and inventory of USDA donated foods, including end products processed from donated food. To that end, PDA has already or will put the following steps in place to strengthen procedures for future periods to ensure any errors are identified and corrected when reconciling the Bureau of Food Assistance’s (BFA’s) Commodity Inventory Report: 1. The finding noted in the audit with regards to the Commodity Inventory Report has been corrected and no known issues remain. 2. BFA will cross-train an additional staff member (the NSLP Specialist) on the process of completing the monthly Commodity Inventory Report. This staff member will then serve as a back-up to the Processing Specialist and will be able to complete a monthly review of the completed Commodity Inventory Report to ensure accuracy. 3. In the event that the numbers in BFA’s Monthly Commodity Inventory Report don’t balance, the Processing Specialist will consult with the Technical Specialist managing PA Meals, who can assist with a technical review of the raw numbers. 4. Sent an email communication to select commodity processors and brokers reiterating the process for submitting Monthly Processing Reports (MPRs) to BFA and reminding them of their responsibility to provide prompt responses should questions arise. Anticipated Completion Dates: 1, 3, 4 - Completed; 2 - 06/30/2024 Contact Name: Caryn Long Earl, Director, Bureau of Food Assistance

Prior Finding References

2022-010

About Special Tests and Provisions →
2023-005
Subrecipient Monitoring
QUESTIONED COSTS

The Pennsylvania Department of Agriculture (PDA), Bureau of Food Assistance (BFA), administers the operations of the Food Distribution Cluster (FDC). During the fiscal year ended June 30, 2023, subrecipient expenditures accounted for $78.9 million or approximately 95 percent of total federal program expenditures of $83.3 million. PDA performs on-site monitoring of subrecipients to ensure compliance with federal program regulations. For the Emergency Food Assistance Program (TEFAP), PDA must perform annual reviews for at least 25 percent of subrecipients who have signed agreements with PDA and no less frequent than once every four years. For the Commodity Supplemental Food Program (CSFP), PDA must perform an on-site review of all subrecipients at least once every two years. As part of our testing of subrecipient monitoring, we selected nine subrecipients to test PDA’s monitoring procedures. We verified that PDA performed monitoring reviews within the required period. Our testing disclosed that PDA failed to monitor one of the 17 CSFP subrecipients in the two-year period from July 1, 2021 through June 30, 2023. Criteria: 7 CFR Section 251.10 (e) (2) regarding TEFAP state monitoring system states: Unless specific exceptions are approved in writing by FNS, the State agency monitoring system must include: (i) An annual review of at least 25 percent of all eligible recipient agencies which have signed an agreement with the State agency pursuant to § 251.2(c), provided that each such agency must be reviewed no less frequently than once every four years; and (ii) An annual review of one-tenth or 20, whichever is fewer, of all eligible recipient agencies which receive TEFAP commodities and/or administrative funds pursuant to an agreement with another eligible recipient agency. Reviews must be conducted, to the maximum extent feasible, simultaneously with actual distribution of commodities and/or meal service, and eligibility determinations, if applicable. State agencies must develop a system for selecting eligible recipient agencies for review that ensures deficiencies in program administration are detected and resolved in an effective and efficient manner. 7 CFR Section 247.34 (a) regarding CSFP management reviews states: The State agency must establish a management review system to ensure that local agencies, subdistributing agencies, and other agencies conducting program activities meet program requirements and objectives. As part of the system, the State agency must perform an on-site review of all local agencies, and of all storage facilities utilized by local agencies, at least once every two years. As part of the on-site review, the State agency must evaluate all aspects of program administration, including certification procedures, nutrition education, civil rights compliance, food storage practices, inventory controls, and financial management systems. In addition to conducting on-site reviews, the State agency must evaluate program administration on an ongoing basis by reviewing financial reports, audit reports, food orders, inventory reports, and other relevant information. Finding 2023 –¬ 005: (continued) Management Directive 325.12, Amended – Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office’s Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Cause: PDA management stated that the subrecipient was to be reviewed in April 2023, but due to new staff assigned to the review, management decided to delay the review for a period of one year to April 2024. Effect: When subrecipients are not reviewed timely, subrecipients may continue to operate in noncompliance with program regulations. Recommendation: We recommend that PDA implement procedures necessary to ensure subrecipients are timely monitored in accordance with FDC program regulations. Agency Response: PDA agrees with this finding. Questioned Costs: The amount of questioned costs cannot be determined.

Show full finding ▾
Full finding narrative

Department of Agriculture Finding 2023 ¬– 005: ALN 10.565, 10.568, and 10.569 – Food Distribution Cluster A Significant Deficiency and Noncompliance Exist in Pennsylvania Department of Agriculture Monitoring of Food Distribution Cluster Subrecipients Federal Grant Number(s) and Year(s): 221PA825Y8005 (10/01/2021 – 9/30/2022), 221PA825Y8105 (10/01/2021 – 9/30/2022), 231PA825Y8005 (10/01/2022 – 9/30/2023) 231PA825Y8105 (10/01/2022 – 9/30/2023) Type of Finding: Significant Deficiency in Internal Control over Compliance, Other Matters Compliance Requirement: Subrecipient Monitoring Condition: The Pennsylvania Department of Agriculture (PDA), Bureau of Food Assistance (BFA), administers the operations of the Food Distribution Cluster (FDC). During the fiscal year ended June 30, 2023, subrecipient expenditures accounted for $78.9 million or approximately 95 percent of total federal program expenditures of $83.3 million. PDA performs on-site monitoring of subrecipients to ensure compliance with federal program regulations. For the Emergency Food Assistance Program (TEFAP), PDA must perform annual reviews for at least 25 percent of subrecipients who have signed agreements with PDA and no less frequent than once every four years. For the Commodity Supplemental Food Program (CSFP), PDA must perform an on-site review of all subrecipients at least once every two years. As part of our testing of subrecipient monitoring, we selected nine subrecipients to test PDA’s monitoring procedures. We verified that PDA performed monitoring reviews within the required period. Our testing disclosed that PDA failed to monitor one of the 17 CSFP subrecipients in the two-year period from July 1, 2021 through June 30, 2023. Criteria: 7 CFR Section 251.10 (e) (2) regarding TEFAP state monitoring system states: Unless specific exceptions are approved in writing by FNS, the State agency monitoring system must include: (i) An annual review of at least 25 percent of all eligible recipient agencies which have signed an agreement with the State agency pursuant to § 251.2(c), provided that each such agency must be reviewed no less frequently than once every four years; and (ii) An annual review of one-tenth or 20, whichever is fewer, of all eligible recipient agencies which receive TEFAP commodities and/or administrative funds pursuant to an agreement with another eligible recipient agency. Reviews must be conducted, to the maximum extent feasible, simultaneously with actual distribution of commodities and/or meal service, and eligibility determinations, if applicable. State agencies must develop a system for selecting eligible recipient agencies for review that ensures deficiencies in program administration are detected and resolved in an effective and efficient manner. 7 CFR Section 247.34 (a) regarding CSFP management reviews states: The State agency must establish a management review system to ensure that local agencies, subdistributing agencies, and other agencies conducting program activities meet program requirements and objectives. As part of the system, the State agency must perform an on-site review of all local agencies, and of all storage facilities utilized by local agencies, at least once every two years. As part of the on-site review, the State agency must evaluate all aspects of program administration, including certification procedures, nutrition education, civil rights compliance, food storage practices, inventory controls, and financial management systems. In addition to conducting on-site reviews, the State agency must evaluate program administration on an ongoing basis by reviewing financial reports, audit reports, food orders, inventory reports, and other relevant information. Finding 2023 –¬ 005: (continued) Management Directive 325.12, Amended – Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office’s Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Cause: PDA management stated that the subrecipient was to be reviewed in April 2023, but due to new staff assigned to the review, management decided to delay the review for a period of one year to April 2024. Effect: When subrecipients are not reviewed timely, subrecipients may continue to operate in noncompliance with program regulations. Recommendation: We recommend that PDA implement procedures necessary to ensure subrecipients are timely monitored in accordance with FDC program regulations. Agency Response: PDA agrees with this finding. Questioned Costs: The amount of questioned costs cannot be determined.

Corrective Action Plan

PDA, Bureau of Food Assistance (BFA) has already or will put the following steps in place to address this deficiency and noncompliance finding. 1. BFA, in coordination with our contractor, Hunger-Free Pennsylvania, has developed a mechanism to track the reviews of all 16 lead subrecipient agencies for the Commodity Supplemental Food Program (CSFP). This tracking mechanism will help to ensure that CSFP monitoring reviews are scheduled and completed in a timely manner, in accordance with federal regulations pertaining to CSFP. 2. BFA has scheduled a comprehensive monitoring review of Food Helpers (formerly known as Greater Washington County Food Bank). The review is scheduled to begin March 2024, and should be completed no later than April 30, 2024. Anticipated Completion Dates: 1 - Completed; 2 - 04/30/2024 Contact Name: Caryn Long Earl, Director, Bureau of Food Assistance

About Subrecipient Monitoring →
2023-006
Activities Allowed or Unallowed
MATERIAL WEAKNESSQUESTIONED COSTS

The Pennsylvania Department of Drug and Alcohol Programs (DDAP) administers and monitors funds to provide services for the State Opioid Response Grants (SOR) program. During the fiscal year ended June 30, 2023 the Commonwealth expended $79,631,874 for the SOR program. An allowable use of SOR funds is to procure medications that provide treatment of opioid disorder and smoking cessation to individuals within the Department of Corrections (DOC) system. To provide these treatment services to DOC, DDAP executed interagency agreements to subgrant funds to the DOC. The DOC has a contract with a sole pharmaceutical vendor to procure opioid treatment and smoking cessation medications. The DOC processes the invoices which are submitted by the pharmaceutical vendor to procure the medications. To ensure accurate and cost-effective medication pricing is being billed, DOC relies on the Department of Aging (PDOA) personnel that complete quarterly audits of medication pricing as part of the Pharmaceutical Assistance for the Elderly program. The PDOA quarterly audit reports are PDOA’s internal documents and are not typically provided to DOC unless significant anomalies are noted. The DOC does not perform any other independent review and approval of medication prices in which SOR funds are being expended. During the fiscal year ending on June 30, 2023, we tested the three United States Food and Drug Administration approved medications allowable under the SOR Grants procured by the DOC from the pharmaceutical vendor. Sublocade was one of the allowable medications tested which amounted to purchases totaling over $10 million for the fiscal year. However, this medication was not included in the PDOA quarterly audits during the fiscal year. The DOC was unable to provide any additional evidence of review or approval of Sublocade pricing. Criteria: 2 CFR Section 200.303, Internal controls, states: The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of the Sponsoring Organizations of the Treadway Commission (COSO). Management Directive 325.12, Amended – Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office’s Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Finding 2023 –¬ 006: (continued) 2 CFR Section 200.404, Reasonable costs, states: A cost is reasonable if, in its nature and amount, it does not exceed that which would be incurred by a prudent person under the circumstances prevailing at the time the decision was made to incur the cost. The question of reasonableness is particularly important when the non-Federal entity is predominantly federally-funded. In determining reasonableness of a given cost, consideration must be given to: (a) Whether the cost is of a type generally recognized as ordinary and necessary for the operation of the non-Federal entity or the proper and efficient performance of the Federal award. (b) The restraints or requirements imposed by such factors as: sound business practices; arm's-length bargaining; Federal, state, local, tribal, and other laws and regulations; and terms and conditions of the Federal award. (c) Market prices for comparable goods or services for the geographic area. (d) Whether the individuals concerned acted with prudence in the circumstances considering their responsibilities to the non-Federal entity, its employees, where applicable its students or membership, the public at large, and the Federal Government. (e) Whether the non-Federal entity significantly deviates from its established practices and policies regarding the incurrence of costs, which may unjustifiably increase the Federal award's cost. Cause: DOC did not implement policies and procedures to ensure billed medication prices are accurate and cost effective. Effect: Without review and validation of the prices, DOC may procure medications at higher rates than necessary or correct which would result in overbilling and improper use of SOR funds. Recommendation: We recommend that DOC implement formal policies and procedures to review and approve procured medications and services. Agency Response: DOC agrees with this finding. Questioned Costs: The amount of questioned costs cannot be determined.

Show full finding ▾
Full finding narrative

Department of Corrections Finding 2023 –¬ 006: ALN 93.788 – Opioid STR A Material Weakness and Material Noncompliance Exist at the Department of Corrections Related to the Review of Opioid Medication Costs Federal Grant Number(s) and Year(s): H79TI083297 (9/30/2020 – 9/29/2023) Type of Finding: Material Weakness in Internal Control over Compliance, Material Noncompliance Compliance Requirement: Activities Allowed or Unallowed Condition: The Pennsylvania Department of Drug and Alcohol Programs (DDAP) administers and monitors funds to provide services for the State Opioid Response Grants (SOR) program. During the fiscal year ended June 30, 2023 the Commonwealth expended $79,631,874 for the SOR program. An allowable use of SOR funds is to procure medications that provide treatment of opioid disorder and smoking cessation to individuals within the Department of Corrections (DOC) system. To provide these treatment services to DOC, DDAP executed interagency agreements to subgrant funds to the DOC. The DOC has a contract with a sole pharmaceutical vendor to procure opioid treatment and smoking cessation medications. The DOC processes the invoices which are submitted by the pharmaceutical vendor to procure the medications. To ensure accurate and cost-effective medication pricing is being billed, DOC relies on the Department of Aging (PDOA) personnel that complete quarterly audits of medication pricing as part of the Pharmaceutical Assistance for the Elderly program. The PDOA quarterly audit reports are PDOA’s internal documents and are not typically provided to DOC unless significant anomalies are noted. The DOC does not perform any other independent review and approval of medication prices in which SOR funds are being expended. During the fiscal year ending on June 30, 2023, we tested the three United States Food and Drug Administration approved medications allowable under the SOR Grants procured by the DOC from the pharmaceutical vendor. Sublocade was one of the allowable medications tested which amounted to purchases totaling over $10 million for the fiscal year. However, this medication was not included in the PDOA quarterly audits during the fiscal year. The DOC was unable to provide any additional evidence of review or approval of Sublocade pricing. Criteria: 2 CFR Section 200.303, Internal controls, states: The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of the Sponsoring Organizations of the Treadway Commission (COSO). Management Directive 325.12, Amended – Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office’s Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Finding 2023 –¬ 006: (continued) 2 CFR Section 200.404, Reasonable costs, states: A cost is reasonable if, in its nature and amount, it does not exceed that which would be incurred by a prudent person under the circumstances prevailing at the time the decision was made to incur the cost. The question of reasonableness is particularly important when the non-Federal entity is predominantly federally-funded. In determining reasonableness of a given cost, consideration must be given to: (a) Whether the cost is of a type generally recognized as ordinary and necessary for the operation of the non-Federal entity or the proper and efficient performance of the Federal award. (b) The restraints or requirements imposed by such factors as: sound business practices; arm's-length bargaining; Federal, state, local, tribal, and other laws and regulations; and terms and conditions of the Federal award. (c) Market prices for comparable goods or services for the geographic area. (d) Whether the individuals concerned acted with prudence in the circumstances considering their responsibilities to the non-Federal entity, its employees, where applicable its students or membership, the public at large, and the Federal Government. (e) Whether the non-Federal entity significantly deviates from its established practices and policies regarding the incurrence of costs, which may unjustifiably increase the Federal award's cost. Cause: DOC did not implement policies and procedures to ensure billed medication prices are accurate and cost effective. Effect: Without review and validation of the prices, DOC may procure medications at higher rates than necessary or correct which would result in overbilling and improper use of SOR funds. Recommendation: We recommend that DOC implement formal policies and procedures to review and approve procured medications and services. Agency Response: DOC agrees with this finding. Questioned Costs: The amount of questioned costs cannot be determined.

Corrective Action Plan

DOC will institute internal controls to review and monitor, on a quarterly basis, medical costs billed from the pharmaceutical vendor to ensure the billing is consistent with contract language. The review will be done by a Fiscal Management Specialist (FMS). The internal control will consist of the following: - Beginning with the December 2023 invoice, DOC will request fully executed procurement documents from the pharmaceutical contractor to verify acquisition costs. - The current contract language states that pharmaceuticals are billed at actual acquisition costs plus a dispensing fee. Therefore, the FMS will match the acquisition cost for the vendor for a sample of transactions to the invoices received from the vendor. - DOC will conduct this review on the pharmaceutical invoices for March, June, September, and December in each year continually. - DOC will document the review using an excel spreadsheet that has the universe of pharmacy orders by patient – matching the records and recording the date the review was done. All documents will be saved in an internal medical invoice folder. - Reviews will be completed by the last day of the month after the invoice is submitted. - Training on the new process will be done by March 31, 2024. Findings (or lack thereof) will be reported to DDAP by April 30th, July 31st, October 31st, and January 31st of each year via email. - If there are discrepancies, the vendor will be contacted immediately and a true-up will be requested in the next month’s invoices (either a credit or a debit depending on the discrepancy). DOC will continue to utilize PACE to complete full audits on reasonability of drug prices. DOC acknowledges, due to purchasing and distribution practices for the pharmaceutical vendor, Sublocade was not on prior reports. However, in the third and fourth quarter of 2023, Sublocade was added to the quarterly PACE audits for reasonability of drug prices. DOC has spoken with PACE and will now receive all quarterly audits and will be invited to all meetings between PACE and the contracted pharmaceutical vendor to discuss any findings. Anticipated Completion Date: 03/31/2024 Contact Names: Erica Benning, Director, Healthcare Services; Jodilynn Jacob-Byrd, Fiscal Management Specialist

About Activities Allowed or Unallowed →
2023-007
Reporting
QUESTIONED COSTS

The Pennsylvania Department of Drug and Alcohol Programs (DDAP) is required to submit biannual Performance Progress Reports (PPR) to the United States Department of Health and Human Services, Substance Abuse and Mental Health Services Administration (SAMHSA) for the components of State Opioid Response Grants (SOR) program. The PPR reports support the collection of data pertaining to the services provided by the 47 Single County Authorities (SCA) throughout the Commonwealth. SAMHSA awards Opioid grants to DDAP for the purpose of administration of the SOR program. The SOR program provides SCAs critical funding and support needed to address the opioid epidemic within the Commonwealth. SCAs must provide a variety of services to recipients including but not limited to treatment of opioid disorder, treatment of stimulant disorder, and recovery support services under the Public Health Services Act (42 U.S.C. 300x-21 et seq). During the fiscal year ended June 30, 2023, DDAP was required to submit year end PPRs for the SOR I and SOR II grants for the period September 30, 2021 through September 29, 2022. In addition, DDAP was required to submit mid-year PPRs for SOR II and SOR III grants for the period September 30, 2022 through March 31, 2023. As the direct recipient of SOR funds, DDAP is responsible for ensuring the timeliness and accuracy of the mid-year and final report submissions. DDAP obtained summary information from the SCAs to compile and submit the PPR reports which contained all required data elements. However, DDAP did not implement policies and procedures to ensure the accuracy of the information reported by the SCAs. Therefore, DDAP was unable to provide supporting documentation for amounts reported by SCAs on the PPR reports or to demonstrate that DDAP had reviewed and verified the accuracy of this information. Criteria: The SOR Program guidance for PPR published by SAMSHA states: • Recipients are required to report on their progress addressing the goals and objectives identified in the FOA. • Recipients are required to submit a Mid-Year and Annual Report on the progress achieved, barriers encountered and efforts to overcome these barriers. 2 CFR Section 200.303, Internal controls, states: The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of the Sponsoring Organizations of the Treadway Commission (COSO). Finding 2023 –¬ 007: (continued) Management Directive 325.12, Amended – Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office’s Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: DDAP did not implement policies and procedures to ensure the accuracy of information reported by SCAs which was included on the PPRs. Effect: Without review and validation of the detail supporting the summary information reported by SCAs, the PPRs may have contained inaccurate information. Recommendation: We recommend that DDAP implement formal policies and procedures to verify the information reported. Agency Response: DDAP agrees with the concern indicated in this finding regarding lack of policies and procedures to ensure the accuracy of information reported by SCAs, which is included on the PPRs. The Department contracts with 47 SCAs through 5-year grant agreements for the provision of prevention, intervention, treatment/treatment-related, and recovery support services throughout the Commonwealth. Each year, DDAP’s Division of Program Monitoring staff monitors all SCAs to assess compliance as well as evaluate the SCA’s performance. Although the Department has developed and implemented an extensive monitoring process as it relates to the SCAs, the process does not include steps to validate the accuracy of information requested from the SCAs for the PPRs as required by SAMHSA for the SOR program. The Department understands the necessity to establish policies and procedures to ensure the accuracy of information reported by SCAs. Going forward, DDAP will develop and implement a plan to validate SCA information being reported and will incorporate this process into the SCA monitoring. Questioned Costs: The amount of questioned costs cannot be determined.

Show full finding ▾
Full finding narrative

Department of Drug and Alcohol Programs Finding 2023 –¬ 007: ALN 93.788 – Opioid STR A Significant Deficiency and Noncompliance Exist at the Department of Drug and Alcohol Programs Related to Submission of Performance Progress Reports Federal Grant Number(s) and Year(s): H79TI083297 (9/30/2020 – 9/29/2023), H79TI085783 (9/30/2022 – 9/29/2024) Type of Finding: Significant Deficiency in Internal Control over Compliance, Other Matters Compliance Requirement: Reporting Condition: The Pennsylvania Department of Drug and Alcohol Programs (DDAP) is required to submit biannual Performance Progress Reports (PPR) to the United States Department of Health and Human Services, Substance Abuse and Mental Health Services Administration (SAMHSA) for the components of State Opioid Response Grants (SOR) program. The PPR reports support the collection of data pertaining to the services provided by the 47 Single County Authorities (SCA) throughout the Commonwealth. SAMHSA awards Opioid grants to DDAP for the purpose of administration of the SOR program. The SOR program provides SCAs critical funding and support needed to address the opioid epidemic within the Commonwealth. SCAs must provide a variety of services to recipients including but not limited to treatment of opioid disorder, treatment of stimulant disorder, and recovery support services under the Public Health Services Act (42 U.S.C. 300x-21 et seq). During the fiscal year ended June 30, 2023, DDAP was required to submit year end PPRs for the SOR I and SOR II grants for the period September 30, 2021 through September 29, 2022. In addition, DDAP was required to submit mid-year PPRs for SOR II and SOR III grants for the period September 30, 2022 through March 31, 2023. As the direct recipient of SOR funds, DDAP is responsible for ensuring the timeliness and accuracy of the mid-year and final report submissions. DDAP obtained summary information from the SCAs to compile and submit the PPR reports which contained all required data elements. However, DDAP did not implement policies and procedures to ensure the accuracy of the information reported by the SCAs. Therefore, DDAP was unable to provide supporting documentation for amounts reported by SCAs on the PPR reports or to demonstrate that DDAP had reviewed and verified the accuracy of this information. Criteria: The SOR Program guidance for PPR published by SAMSHA states: • Recipients are required to report on their progress addressing the goals and objectives identified in the FOA. • Recipients are required to submit a Mid-Year and Annual Report on the progress achieved, barriers encountered and efforts to overcome these barriers. 2 CFR Section 200.303, Internal controls, states: The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of the Sponsoring Organizations of the Treadway Commission (COSO). Finding 2023 –¬ 007: (continued) Management Directive 325.12, Amended – Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office’s Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: DDAP did not implement policies and procedures to ensure the accuracy of information reported by SCAs which was included on the PPRs. Effect: Without review and validation of the detail supporting the summary information reported by SCAs, the PPRs may have contained inaccurate information. Recommendation: We recommend that DDAP implement formal policies and procedures to verify the information reported. Agency Response: DDAP agrees with the concern indicated in this finding regarding lack of policies and procedures to ensure the accuracy of information reported by SCAs, which is included on the PPRs. The Department contracts with 47 SCAs through 5-year grant agreements for the provision of prevention, intervention, treatment/treatment-related, and recovery support services throughout the Commonwealth. Each year, DDAP’s Division of Program Monitoring staff monitors all SCAs to assess compliance as well as evaluate the SCA’s performance. Although the Department has developed and implemented an extensive monitoring process as it relates to the SCAs, the process does not include steps to validate the accuracy of information requested from the SCAs for the PPRs as required by SAMHSA for the SOR program. The Department understands the necessity to establish policies and procedures to ensure the accuracy of information reported by SCAs. Going forward, DDAP will develop and implement a plan to validate SCA information being reported and will incorporate this process into the SCA monitoring. Questioned Costs: The amount of questioned costs cannot be determined.

Corrective Action Plan

Beginning January 31, 2024, DDAP started having internal discussions to determine the most effective and efficient methodology to evaluate the internal controls of the SCAs' data being reported to DDAP during the federal grant period and in the PPRs. Steps currently being taken by DDAP include updating the SCAs' monitoring process for the next annual monitoring cycle for FY 2023-24. The goal is to have a sound methodology with formalized policies and procedures in place by April 2024 to ensure the data collected is sampled for accuracy going forward. To ensure accuracy of the information reported by the SCAs, which is included on the PPRs, DDAP will add verification of this data to the current SCA monitoring process. Specifically, the Project Officers who conduct SCA monitoring will: - Add a question to the SCA Pre-Submission packet: ‘How does your SCA track SOR-funded clients in order to accurately report them on the SOR Report?’ The SCA must specifically state how they are accounting for these clients and how they arrive at the data reported to DDAP. If DDAP determines the process is not acceptable, the SCA will be required to revise and resubmit. - During the virtual monitoring call, Project Officers will review the SCA’s written answer to the question, and ensure they have a full understanding of where the SCA keeps data on SOR-funded clients, and how they access this data to complete the SOR reports. - During the onsite monitoring visit, the Project Officers will take the most recently submitted SOR report and ask the SCA staff to duplicate the steps they used to arrive at the reported numbers. * If the SCA is able to demonstrate how clients are tracked and the steps used to determine the reported numbers produce results consistent with what was submitted in the report, the SCA’s submitted data will be considered verified. * If the SCA is unable to demonstrate how clients are tracked, and the steps used to determine the reported numbers do not produce results consistent with what was submitted in the report, the SCA will be required to implement a process by which they can accurately track this data and report client numbers. Any SCA required to implement a new client-tracking system will be required to submit backup documentation with their SOR reports, until such time as they are able to demonstrate to DDAP that they are accurately tracking clients and can demonstrate the steps used to determine their reported numbers. - This review process and results will be added to the Monitoring Report sent to the SCA at the end of the monitoring cycle, to reflect the SCA’s compliance status. Anticipated Completion Date: 09/30/2024 Contact Names: Susan Duff, Chief, Program Monitoring Division; Autumn Croasmun, Project Director for State Opioid Response III Grant; Tia Roebuck, Director, Division of Budget and Procurement

About Reporting →
2023-008
Subrecipient Monitoring
QUESTIONED COSTS

The Pennsylvania Department of Education (PDE), Division of Food and Nutrition, Bureau of Budget and Fiscal Management, administers the operations of the Child and Adult Care Food Program (CACFP). During the fiscal year ended June 30, 2023, subrecipient expenditures accounted for $117.9 million or approximately 99 percent of total federal program expenditures of $119 million. As part of our testing of subrecipient monitoring, we selected 40 subrecipients to test PDE’s monitoring procedures. PDE performs on-site monitoring of subrecipients to ensure compliance with federal program regulations. The United States Department of Agriculture waived the CACFP monitoring requirement included in 7 CFR Section 226.6 (m) (6) to be conducted on-site through June 30, 2023. However, state agencies that elected to use the waiver were still required to continue monitoring activities of program operations off-site. Independent centers and sponsoring organizations (subrecipients) of one to 100 facilities must be reviewed once every three years, and sponsoring organizations with more than 100 facilities must be reviewed once every two years. PDE uses standardized monitoring reports to document its review of each subrecipient, noting deficiencies and areas for improvement. PDE communicates any deficiencies noted and recommendations to the subrecipient and requires the subrecipient to submit corrective action documents (CAD) to PDE. PDE then reviews and evaluates responses submitted on the CAD for adequacy. 7 CFR Section 226.6 (o) requires PDE to ensure the corrective actions are approved within a time period specified by PDE. Applicable to the current audit period, PDE’s internal procedures in Standard Operating Procedure (SOP) #FS-RS-CACFP-05, state that the review must be closed within 180 days of the exit date. To close an administrative review, PDE must either approve the subrecipient’s response to the CAD or issue a notice of serious deficiency to the subrecipient if acceptable responses to the CAD are not received. PDE’s responsibility for financial management requires it to have a system in place for monitoring and reviewing subrecipients’ documentation of their nonprofit status. The resource management section of PDE’s monitoring instrument contains steps to ensure the subrecipients have a nonprofit status. We sampled 40 of PDE’s reviews of subrecipients out of a population of 317 reviews scheduled during program year October 2021 to September 2022. We audited this period because PDE tracks their subrecipient monitoring based on a federal fiscal year basis. We noted the following deficiencies in our monitoring testing: • For three reviews that were closed by PDE for the program year and had a final determination letter issued, PDE did not close the reviews within the required 180 days. These reviews did not include any complex findings that would have required more time to close. The number of days these reviews were closed beyond 180 days ranged from 28 to 33 days with an average of 30 days. • For one review completed by PDE for the program year, PDE identified a deficiency, that the sponsor did not maintain a nonprofit status as required; however, the reviewer did not write or issue a CAD to the sponsor. Also, it did not appear that the regional supervisor identified it while processing the review. Finding 2023 ¬– 008: (continued) Criteria: 7 CFR Section 226.6 (o) regarding child care standards for compliance states: The State agency shall, when conducting administrative reviews of child care centers, and day care homes approved by the State agency under paragraph (d)(3) of this section, determine compliance with the child care standards used to establish eligibility, and the institution shall ensure that all violations are corrected and the State shall ensure that the institution has corrected all violations. If violations are not corrected within the specified timeframe for corrective action, the State agency must issue a notice of serious deficiency… PDE’s CACFP procedures regarding the performance of CACFP reviews of subrecipients, as specified in SOP #FS-RS-CACFP-05, state only that the “Review must be closed by 180 days after exit date.” This 180 days includes the issuance of any necessary findings and follow-up on CADs. 7 CFR Section 226.7 (b) (1) (iii) regarding state agency responsibilities for financial management states: State agencies must also have a system in place for: Monitoring and reviewing the institutions' documentation of their nonprofit status to ensure that all Program reimbursement funds are used solely for the conduct of the food service operation or to improve food service operations, principally for the benefit of children or adult participants. Management Directive 325.12, Amended – Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office’s Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: PDE management does not believe that the agency has a regulatory requirement to specify a time period for closing a review. 7 CFR Section 226 (o) indicates that the state shall ensure the institution has corrected all violations within the specified timeframe. PDE’s procedures in SOP #FS-RS-CACFP-05 states that an administrative review must close within 180 days after exit date, which requires PDE to either approve the subrecipient’s CAD or issue a notice of serious deficiency, if necessary. However, PDE believes the 180-day requirement is an internal policy and allows for exceptions. PDE management further stated that the delays were due to staffing changes and shortages and failure to issue a CAD for sponsor noncompliance was due to reviewer oversight. Effect: When findings and CADs are not reviewed, approved, and closed by PDE timely, subrecipients may continue to operate in noncompliance with program regulations. Permitting subrecipients to operate in violation of program requirements for extended periods of time increases the likelihood that funds may not be spent for intended purposes or in accordance with program requirements. Furthermore, untimely closure of findings and CADs by PDE increases the likelihood that individuals served by the program are not receiving the benefits that are paid for with CACFP funds. PDE’s failure to ensure sponsors are operating in a nonprofit status can result in subrecipients operating in noncompliance with program regulations where program reimbursement funds may be used for non-food service operations. Recommendation: We recommend that PDE management increase its review and oversight efforts. PDE should implement procedures necessary to ensure subrecipients are timely monitored, and monitoring findings and CADs are prepared, presented, and timely followed up on in accordance with CACFP program regulations. Agency Response: PDE disagrees with the portion of the finding as it pertains to timeliness of closing review and agrees with the portion of the finding that pertains to a sponsor who was not provided a CAD in response to an identified deficiency. Finding 2023 –¬ 008: (continued) Auditors’ Conclusion: As stated in the criteria above, we believe 7 CFR Section 226.6 (o) clearly states that the state agency must establish a specified timeframe for ensuring subrecipient corrective action has taken place. PDE’s SOP #FS-RS-CACFP-05 states the period is 180 days to close a review. The finding remains as stated. Questioned Costs: The amount of questioned costs cannot be determined.

Show full finding ▾
Full finding narrative

Department of Education Finding 2023 –¬ 008: ALN 10.558 – Child and Adult Care Food Program A Significant Deficiency and Noncompliance Exist in Pennsylvania Department of Education Monitoring of Child and Adult Care Food Program Subrecipients Federal Grant Number(s) and Year(s): 231PA305N1099 (10/01/2022 – 9/30/2023), 221PA305N1099 (10/01/2021 – 9/30/2022) Type of Finding: Significant Deficiency in Internal Control over Compliance, Other Matters Compliance Requirement: Subrecipient Monitoring Condition: The Pennsylvania Department of Education (PDE), Division of Food and Nutrition, Bureau of Budget and Fiscal Management, administers the operations of the Child and Adult Care Food Program (CACFP). During the fiscal year ended June 30, 2023, subrecipient expenditures accounted for $117.9 million or approximately 99 percent of total federal program expenditures of $119 million. As part of our testing of subrecipient monitoring, we selected 40 subrecipients to test PDE’s monitoring procedures. PDE performs on-site monitoring of subrecipients to ensure compliance with federal program regulations. The United States Department of Agriculture waived the CACFP monitoring requirement included in 7 CFR Section 226.6 (m) (6) to be conducted on-site through June 30, 2023. However, state agencies that elected to use the waiver were still required to continue monitoring activities of program operations off-site. Independent centers and sponsoring organizations (subrecipients) of one to 100 facilities must be reviewed once every three years, and sponsoring organizations with more than 100 facilities must be reviewed once every two years. PDE uses standardized monitoring reports to document its review of each subrecipient, noting deficiencies and areas for improvement. PDE communicates any deficiencies noted and recommendations to the subrecipient and requires the subrecipient to submit corrective action documents (CAD) to PDE. PDE then reviews and evaluates responses submitted on the CAD for adequacy. 7 CFR Section 226.6 (o) requires PDE to ensure the corrective actions are approved within a time period specified by PDE. Applicable to the current audit period, PDE’s internal procedures in Standard Operating Procedure (SOP) #FS-RS-CACFP-05, state that the review must be closed within 180 days of the exit date. To close an administrative review, PDE must either approve the subrecipient’s response to the CAD or issue a notice of serious deficiency to the subrecipient if acceptable responses to the CAD are not received. PDE’s responsibility for financial management requires it to have a system in place for monitoring and reviewing subrecipients’ documentation of their nonprofit status. The resource management section of PDE’s monitoring instrument contains steps to ensure the subrecipients have a nonprofit status. We sampled 40 of PDE’s reviews of subrecipients out of a population of 317 reviews scheduled during program year October 2021 to September 2022. We audited this period because PDE tracks their subrecipient monitoring based on a federal fiscal year basis. We noted the following deficiencies in our monitoring testing: • For three reviews that were closed by PDE for the program year and had a final determination letter issued, PDE did not close the reviews within the required 180 days. These reviews did not include any complex findings that would have required more time to close. The number of days these reviews were closed beyond 180 days ranged from 28 to 33 days with an average of 30 days. • For one review completed by PDE for the program year, PDE identified a deficiency, that the sponsor did not maintain a nonprofit status as required; however, the reviewer did not write or issue a CAD to the sponsor. Also, it did not appear that the regional supervisor identified it while processing the review. Finding 2023 ¬– 008: (continued) Criteria: 7 CFR Section 226.6 (o) regarding child care standards for compliance states: The State agency shall, when conducting administrative reviews of child care centers, and day care homes approved by the State agency under paragraph (d)(3) of this section, determine compliance with the child care standards used to establish eligibility, and the institution shall ensure that all violations are corrected and the State shall ensure that the institution has corrected all violations. If violations are not corrected within the specified timeframe for corrective action, the State agency must issue a notice of serious deficiency… PDE’s CACFP procedures regarding the performance of CACFP reviews of subrecipients, as specified in SOP #FS-RS-CACFP-05, state only that the “Review must be closed by 180 days after exit date.” This 180 days includes the issuance of any necessary findings and follow-up on CADs. 7 CFR Section 226.7 (b) (1) (iii) regarding state agency responsibilities for financial management states: State agencies must also have a system in place for: Monitoring and reviewing the institutions' documentation of their nonprofit status to ensure that all Program reimbursement funds are used solely for the conduct of the food service operation or to improve food service operations, principally for the benefit of children or adult participants. Management Directive 325.12, Amended – Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office’s Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: PDE management does not believe that the agency has a regulatory requirement to specify a time period for closing a review. 7 CFR Section 226 (o) indicates that the state shall ensure the institution has corrected all violations within the specified timeframe. PDE’s procedures in SOP #FS-RS-CACFP-05 states that an administrative review must close within 180 days after exit date, which requires PDE to either approve the subrecipient’s CAD or issue a notice of serious deficiency, if necessary. However, PDE believes the 180-day requirement is an internal policy and allows for exceptions. PDE management further stated that the delays were due to staffing changes and shortages and failure to issue a CAD for sponsor noncompliance was due to reviewer oversight. Effect: When findings and CADs are not reviewed, approved, and closed by PDE timely, subrecipients may continue to operate in noncompliance with program regulations. Permitting subrecipients to operate in violation of program requirements for extended periods of time increases the likelihood that funds may not be spent for intended purposes or in accordance with program requirements. Furthermore, untimely closure of findings and CADs by PDE increases the likelihood that individuals served by the program are not receiving the benefits that are paid for with CACFP funds. PDE’s failure to ensure sponsors are operating in a nonprofit status can result in subrecipients operating in noncompliance with program regulations where program reimbursement funds may be used for non-food service operations. Recommendation: We recommend that PDE management increase its review and oversight efforts. PDE should implement procedures necessary to ensure subrecipients are timely monitored, and monitoring findings and CADs are prepared, presented, and timely followed up on in accordance with CACFP program regulations. Agency Response: PDE disagrees with the portion of the finding as it pertains to timeliness of closing review and agrees with the portion of the finding that pertains to a sponsor who was not provided a CAD in response to an identified deficiency. Finding 2023 –¬ 008: (continued) Auditors’ Conclusion: As stated in the criteria above, we believe 7 CFR Section 226.6 (o) clearly states that the state agency must establish a specified timeframe for ensuring subrecipient corrective action has taken place. PDE’s SOP #FS-RS-CACFP-05 states the period is 180 days to close a review. The finding remains as stated. Questioned Costs: The amount of questioned costs cannot be determined.

Corrective Action Plan

PDE agrees with the portion of the finding pertaining to the lack of required signature on an expenditure report. To address this error, PDE will retrain staff and update “Tool Tips” in PEARS so that it is clearer for field advisers. PDE disagrees with two of the conditions of the finding, as stated by the auditors. First, regulation 7 CFR 226.6 (o), cited and summarized by the auditors as requiring PDE to resolve and close reviews within a specific timeline, does not include this requirement in the text. The regulation requires that subrecipients resolve any issues with a timeframe specified in their corrective action. Second, the first bulleted condition, states that “these reviews did not include any complex findings that would have required more time to close.” PDE procedure for closing reviews states that “any exception must be communicated and approved by the Supervisor…” The procedure does not qualify or limit these exceptions to “complex findings.” Accordingly, PDE will continue to follow its procedures as written. Anticipated Completion Date: 06/30/2024 Contact Names: Vonda Ramp, Chief, Div. of Food & Nutr., Bur. of Bdgt. & Fiscal Management; Clayton Carroll, Audit Coord., Bur. of Bdgt. & Fiscal Management

About Subrecipient Monitoring →
2023-009
Activities Allowed or Unallowed / Cost Allowability
QUESTIONED COSTS

The Pennsylvania Department of Human Services (DHS) and the Pennsylvania Department of Education (PDE) have worked collaboratively to assist expectant and parenting youth through an initiative called Education Leading to Employment and Career Training (ELECT). ELECT works with expectant and parenting youth who qualify for assistance through Temporary Assistance for Needy Families (TANF), or are otherwise income-eligible, to support their continuation of or return to school to complete their secondary education. ELECT programs are operated by Local Education Agencies (LEA) that consist of school districts and Intermediate Units (IU). During the fiscal year ended June 30, 2023, PDE passed funding through to 27 LEAs for the operation of ELECT programs. TANF ELECT program payments made by PDE to its 27 subrecipients during the fiscal year ended June 30, 2023 were $14.1 million, or 3.1 percent of total TANF expenditures of $455.7 million reported on the June 30, 2023 Schedule of Expenditures of Federal Awards. As part of our testing of subrecipient expenditures, we selected three subrecipient expenditure reports to test PDE’s procedures for processing subgrantee requests for reimbursement. Our testing found that for one of the three ELECT Expenditure Reports selected for testing, the expenditure report was not certified by an authorized subgrantee official. Criteria: 2 CFR Section 200.415, Required certifications, states: Required certifications include: (a) To assure that expenditures are proper and in accordance with the terms and conditions of the Federal award and approved project budgets, the annual and final fiscal reports or vouchers requesting payment under the agreements must include a certification, signed by an official who is authorized to legally bind the non-Federal entity, which reads as follows: “By signing this report, I certify to the best of my knowledge and belief that the report is true, complete, and accurate, and the expenditures, disbursements and cash receipts are for the purposes and objectives set forth in the terms and conditions of the Federal award. I am aware that any false, fictitious, or fraudulent information, or the omission of any material fact, may subject me to criminal, civil or administrative penalties for fraud, false statements, false claims or otherwise. (U.S. Code Title 18, Section 1001 and Title 31, Sections 3729-3730 and 3801-3812).” Finding 2023 – 009: (continued) 2 CFR Section 200.303, Internal controls, states: The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of the Sponsoring Organizations of the Treadway Commission (COSO). 45 CFR Section 75.352, applicable to TANF states: All pass-through entities must: (d) Monitor the activities of the subrecipient as necessary to ensure that the subaward is used for authorized purposes, in compliance with Federal statutes, regulations, and the terms and conditions of the subaward; and that subaward performance goals are achieved. Management Directive 325.12 Amended – Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office’s Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. PDE’s Education Leading to Employment and Career Training (ELECT) Operational Guidelines states in part: Authorized Signature: An authorized signature is required on expenditure reports for grants with federal funds. The authorized signatory is taking responsibility for the federal funds; make sure that someone of authority is signing the report. It will not be processed without the signature. Cause: Although PDE requires subrecipients to utilize an ELECT Expenditure Report template that includes a box for an authorized subgrantee signatory to sign which states: By signing this report, I certify to the best of my knowledge and belief that the report is true, complete, and accurate, and the expenditures, disbursements and cash receipts are for the purposes and objectives set forth in the terms and conditions of the Federal award. I am aware that any false, fictitious, or fraudulent information, or the omission of any material fact, may subject me to criminal, civil or administrative penalties for fraud, false statements, false claims or otherwise. (U.S. Code Title 18, Section 1001 and Title 31, Sections 3729-3730 and 3801-3812). PDE’s review did not detect that the expenditure report was not certified by an authorized subgrantee official. PDE did not follow their written operational guidelines which state that PDE should ensure that someone of authority is signing the report and that the expenditure report will not be processed without the signature. PDE management indicated that they monitor subrecipients and request backup documentation for expenditures listed in the requests for reimbursement; however, without subrecipient certifications only limited assurance of the allowability of the activities and costs for which the subrecipient was requesting reimbursement can be obtained. Finding 2023 – 009: (continued) Effect: Without appropriate certifications, PDE cannot be assured that subrecipient expenditures are proper and in accordance with the terms and conditions of the Federal award and approved project budgets. Further, the subrecipient noted in the condition above may have received unallowable cost reimbursements from the TANF program. PDE is not in compliance with federal regulations relating to required certifications, and a significant deficiency exists. If not corrected, the processing of expenditure reports without certifications could result in the reimbursement of unallowable costs and result in future grant awards being reduced. Recommendation: PDE should strengthen its procedures and controls to ensure that required certifications are obtained prior to passing funding through to subrecipients. Further, PDE should request that subgrantees resubmit any expenditure reports from which the required certifications were missing. Agency Response: PDE agrees with this finding. Questioned Costs: The amount of questioned costs cannot be determined.

Show full finding ▾
Full finding narrative

Department of Education Finding 2023 – 009: ALN 93.558 – Temporary Assistance for Needy Families (including COVID-19) A Significant Deficiency and Noncompliance Exist in the Review and Approval of Subrecipient Education Leading to Employment and Career Training Expenditure Reports by the Pennsylvania Department of Education Federal Grant Number(s) and Year(s): 2301PATANF (10/01/2022 – 9/30/2023), 2201PATANF (10/01/2021 – 9/30/2022), 2101PATANF (10/01/2020 – 9/30/2021) Type of Finding: Significant Deficiency in Internal Control over Compliance, Other Matters Compliance Requirement: Activities Allowed or Unallowed, Allowable Costs/Cost Principles Condition: The Pennsylvania Department of Human Services (DHS) and the Pennsylvania Department of Education (PDE) have worked collaboratively to assist expectant and parenting youth through an initiative called Education Leading to Employment and Career Training (ELECT). ELECT works with expectant and parenting youth who qualify for assistance through Temporary Assistance for Needy Families (TANF), or are otherwise income-eligible, to support their continuation of or return to school to complete their secondary education. ELECT programs are operated by Local Education Agencies (LEA) that consist of school districts and Intermediate Units (IU). During the fiscal year ended June 30, 2023, PDE passed funding through to 27 LEAs for the operation of ELECT programs. TANF ELECT program payments made by PDE to its 27 subrecipients during the fiscal year ended June 30, 2023 were $14.1 million, or 3.1 percent of total TANF expenditures of $455.7 million reported on the June 30, 2023 Schedule of Expenditures of Federal Awards. As part of our testing of subrecipient expenditures, we selected three subrecipient expenditure reports to test PDE’s procedures for processing subgrantee requests for reimbursement. Our testing found that for one of the three ELECT Expenditure Reports selected for testing, the expenditure report was not certified by an authorized subgrantee official. Criteria: 2 CFR Section 200.415, Required certifications, states: Required certifications include: (a) To assure that expenditures are proper and in accordance with the terms and conditions of the Federal award and approved project budgets, the annual and final fiscal reports or vouchers requesting payment under the agreements must include a certification, signed by an official who is authorized to legally bind the non-Federal entity, which reads as follows: “By signing this report, I certify to the best of my knowledge and belief that the report is true, complete, and accurate, and the expenditures, disbursements and cash receipts are for the purposes and objectives set forth in the terms and conditions of the Federal award. I am aware that any false, fictitious, or fraudulent information, or the omission of any material fact, may subject me to criminal, civil or administrative penalties for fraud, false statements, false claims or otherwise. (U.S. Code Title 18, Section 1001 and Title 31, Sections 3729-3730 and 3801-3812).” Finding 2023 – 009: (continued) 2 CFR Section 200.303, Internal controls, states: The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of the Sponsoring Organizations of the Treadway Commission (COSO). 45 CFR Section 75.352, applicable to TANF states: All pass-through entities must: (d) Monitor the activities of the subrecipient as necessary to ensure that the subaward is used for authorized purposes, in compliance with Federal statutes, regulations, and the terms and conditions of the subaward; and that subaward performance goals are achieved. Management Directive 325.12 Amended – Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office’s Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. PDE’s Education Leading to Employment and Career Training (ELECT) Operational Guidelines states in part: Authorized Signature: An authorized signature is required on expenditure reports for grants with federal funds. The authorized signatory is taking responsibility for the federal funds; make sure that someone of authority is signing the report. It will not be processed without the signature. Cause: Although PDE requires subrecipients to utilize an ELECT Expenditure Report template that includes a box for an authorized subgrantee signatory to sign which states: By signing this report, I certify to the best of my knowledge and belief that the report is true, complete, and accurate, and the expenditures, disbursements and cash receipts are for the purposes and objectives set forth in the terms and conditions of the Federal award. I am aware that any false, fictitious, or fraudulent information, or the omission of any material fact, may subject me to criminal, civil or administrative penalties for fraud, false statements, false claims or otherwise. (U.S. Code Title 18, Section 1001 and Title 31, Sections 3729-3730 and 3801-3812). PDE’s review did not detect that the expenditure report was not certified by an authorized subgrantee official. PDE did not follow their written operational guidelines which state that PDE should ensure that someone of authority is signing the report and that the expenditure report will not be processed without the signature. PDE management indicated that they monitor subrecipients and request backup documentation for expenditures listed in the requests for reimbursement; however, without subrecipient certifications only limited assurance of the allowability of the activities and costs for which the subrecipient was requesting reimbursement can be obtained. Finding 2023 – 009: (continued) Effect: Without appropriate certifications, PDE cannot be assured that subrecipient expenditures are proper and in accordance with the terms and conditions of the Federal award and approved project budgets. Further, the subrecipient noted in the condition above may have received unallowable cost reimbursements from the TANF program. PDE is not in compliance with federal regulations relating to required certifications, and a significant deficiency exists. If not corrected, the processing of expenditure reports without certifications could result in the reimbursement of unallowable costs and result in future grant awards being reduced. Recommendation: PDE should strengthen its procedures and controls to ensure that required certifications are obtained prior to passing funding through to subrecipients. Further, PDE should request that subgrantees resubmit any expenditure reports from which the required certifications were missing. Agency Response: PDE agrees with this finding. Questioned Costs: The amount of questioned costs cannot be determined.

Corrective Action Plan

PDE will continue to follow regulations requiring expenditure report certifications. Internal controls will be strengthened where necessary, to ensure that staff perform reviews of expenditure reports to verify all necessary certification signatures have been obtained. Anticipated Completion Date: 06/30/2024 Contact Names: Carmen Medina, Chief, Student Svcs., Bur. of School Supp.; Clayton Carroll, Audit Coord., Bur. of Budget & Fiscal Mgmt.

About Activities Allowed or Unallowed, Allowable Costs / Cost Principles →
2023-010
Subrecipient Monitoring
MATERIAL WEAKNESSREPEATQUESTIONED COSTS

The Department of Environmental Protection (DEP) administers the Abandoned Mine Land Reclamation (AMLR) program funded by the United States Department of the Interior (DOI). During the fiscal year ended June 30, 2023, DEP expended $60,055,889 within the AMLR program, of which $6,478,271 was paid to 16 subrecipient entities to provide abandoned mine land reclamation repairs and services throughout Pennsylvania. Up until the fiscal year ended June 30, 2022 timeframe, DEP considered these entities to be contractors and not subrecipients. However, once the entities were determined to be subrecipients, DEP began implementing procedures to ensure federal monitoring requirements were met to include on-site monitoring of subrecipient projects with signed Grant Manager monitoring report forms evidencing visit results. DEP also implemented subrecipient requirements of minimum quarterly Work Progress Reports and annual subrecipient Financial and Performance Reports. Our testing found these procedures were not implemented fully nor timely to ensure compliance throughout the fiscal year ended June 30, 2023. For a sample of six of the sixteen subrecipients, we reviewed relevant project correspondence and documentation to determine if DEP adequately monitored subrecipient projects and documented the results in accordance with procedures. Our testing found three of the six had sufficient documentation of on-site visits evidencing DEP oversight of the projects. However, only one included the subrecipient Work Progress Report and DEP manager signed monitoring report form; both required per DEP procedures. Due to the timing of procedure implementation, no subrecipient Financial and Performance Reports were submitted during the period. One of the six tested had project deficiencies. Sufficient evidence was available to show appropriate DEP follow-up and resolution. While Single Audits of the AMLR subrecipients may be conducted each year, this auditing activity does not compensate for during-the-award program monitoring, since the timing, focus, and scope of subrecipient auditing activities after year end are different than compliance monitoring to be performed by program officials during the year. Criteria: As part of administering the AMLR program, DEP must have policies, procedures, and controls in place to ensure compliance with federal requirements regarding pass-through entity monitoring of subrecipients. 2 CFR Section 200.332, Requirements for pass-through entities, states in part: All pass-through entities must: (d) Monitor the activities of the subrecipient as necessary to ensure that the subaward is used for authorized purposes, in compliance with Federal statutes, regulations, and the terms and conditions of the subaward; and that subaward performance goals are achieved. Pass-through entity monitoring of the subrecipient must include: (1) Reviewing financial and performance reports required by the pass-through entity. Finding 2023 –¬ 010: (continued) (2) Following-up and ensuring that the subrecipient takes timely and appropriate action on all deficiencies pertaining to the Federal award provided to the subrecipient from the pass-through entity detected through audits, on-site reviews, and written confirmation from the subrecipient, highlighting the status of actions planned or taken to address Single Audit findings related to the particular subaward. (3) Issuing a management decision for audit findings pertaining to the Federal award provided to the subrecipient from the pass-through entity as required by § 200.521 [Management decision]. (e) Depending upon the pass-through entity's assessment of risk posed by the subrecipient (as described in paragraph (b) of this section), the following monitoring tools may be useful for the pass-through entity to ensure proper accountability and compliance with program requirements and achievement of performance goals: (1) Providing subrecipients with training and technical assistance on program-related matters; and (2) Performing on-site reviews of the subrecipient's program operations; (3) Arranging for agreed-upon-procedures engagements as described in §200.425 [Audit services]. The standard contract agreement between DEP and the local grantee states, in part: Audit/Compliance Review Requirements - The contractor must comply with all applicable federal and state grant requirements including the Single Audit Act Amendments of 1996; 2 CFR Part 200 as amended; and any other applicable law or regulation, and any amendment to such other applicable law or regulation that may be enacted or promulgated by the federal government. Management Directive 325.12, Amended – Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office’s Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: Once the determination was made that the contracts with these entities represented subrecipient agreements, DEP began implementing control procedures to ensure federal requirements were met and adequately documented. However, due to the transition time needed for implementation, we found these procedures were not fully or consistently implemented during the audit period. Effect: Without sufficient subrecipient monitoring, DEP cannot ensure compliance with federal statutes, regulations, and the terms and conditions of the subrecipient agreements. In addition, DEP cannot confirm that subrecipients are performing satisfactory work, ensure the efficient use of program resources, and minimize the risk for fraud and abuse. Completing on-site monitoring activities consistently and as designed is essential for DEP to determine whether the subrecipients are complying with federal regulations and spending grant funds appropriately. Recommendation: We recommend DEP continue to implement their written procedures for performing during-the-award subrecipient monitoring to ensure timely subrecipient compliance with federal regulations. On-site monitoring visits by DEP Grant Managers should be supported by documentation to show the monitoring performed, areas examined, conclusions reached, and that the monitoring was performed in compliance with applicable regulations. Agency Response: DEP agrees with the facts presented in this finding. Questioned Costs: The amount of questioned costs cannot be determined.

Show full finding ▾
Full finding narrative

Department of Environmental Protection Finding 2023 –¬ 010: ALN 15.252 – Abandoned Mine Land Reclamation A Material Weakness and Material Noncompliance Exist at the Department of Environmental Protection Related to Subrecipient Monitoring (A Similar Condition Was Noted in Prior Year Finding 2022-005) Federal Grant Number(s) and Year(s): S22AF00017 (1/01/2022 – 12/31/2024), S21AF10015 (1/01/2021 – 12/31/2023), S20AF20092 (10/01/2020 – 9/30/2023), S20AF20006 (1/01/2020 –¬ 12/31/2022), S19AF20004 (12/01/2018 – 11/30/2023), S18AF20004 (11/01/2017 – 10/31/2023) Type of Finding: Material Weakness in Internal Control over Compliance, Material Noncompliance Compliance Requirement: Subrecipient Monitoring Condition: The Department of Environmental Protection (DEP) administers the Abandoned Mine Land Reclamation (AMLR) program funded by the United States Department of the Interior (DOI). During the fiscal year ended June 30, 2023, DEP expended $60,055,889 within the AMLR program, of which $6,478,271 was paid to 16 subrecipient entities to provide abandoned mine land reclamation repairs and services throughout Pennsylvania. Up until the fiscal year ended June 30, 2022 timeframe, DEP considered these entities to be contractors and not subrecipients. However, once the entities were determined to be subrecipients, DEP began implementing procedures to ensure federal monitoring requirements were met to include on-site monitoring of subrecipient projects with signed Grant Manager monitoring report forms evidencing visit results. DEP also implemented subrecipient requirements of minimum quarterly Work Progress Reports and annual subrecipient Financial and Performance Reports. Our testing found these procedures were not implemented fully nor timely to ensure compliance throughout the fiscal year ended June 30, 2023. For a sample of six of the sixteen subrecipients, we reviewed relevant project correspondence and documentation to determine if DEP adequately monitored subrecipient projects and documented the results in accordance with procedures. Our testing found three of the six had sufficient documentation of on-site visits evidencing DEP oversight of the projects. However, only one included the subrecipient Work Progress Report and DEP manager signed monitoring report form; both required per DEP procedures. Due to the timing of procedure implementation, no subrecipient Financial and Performance Reports were submitted during the period. One of the six tested had project deficiencies. Sufficient evidence was available to show appropriate DEP follow-up and resolution. While Single Audits of the AMLR subrecipients may be conducted each year, this auditing activity does not compensate for during-the-award program monitoring, since the timing, focus, and scope of subrecipient auditing activities after year end are different than compliance monitoring to be performed by program officials during the year. Criteria: As part of administering the AMLR program, DEP must have policies, procedures, and controls in place to ensure compliance with federal requirements regarding pass-through entity monitoring of subrecipients. 2 CFR Section 200.332, Requirements for pass-through entities, states in part: All pass-through entities must: (d) Monitor the activities of the subrecipient as necessary to ensure that the subaward is used for authorized purposes, in compliance with Federal statutes, regulations, and the terms and conditions of the subaward; and that subaward performance goals are achieved. Pass-through entity monitoring of the subrecipient must include: (1) Reviewing financial and performance reports required by the pass-through entity. Finding 2023 –¬ 010: (continued) (2) Following-up and ensuring that the subrecipient takes timely and appropriate action on all deficiencies pertaining to the Federal award provided to the subrecipient from the pass-through entity detected through audits, on-site reviews, and written confirmation from the subrecipient, highlighting the status of actions planned or taken to address Single Audit findings related to the particular subaward. (3) Issuing a management decision for audit findings pertaining to the Federal award provided to the subrecipient from the pass-through entity as required by § 200.521 [Management decision]. (e) Depending upon the pass-through entity's assessment of risk posed by the subrecipient (as described in paragraph (b) of this section), the following monitoring tools may be useful for the pass-through entity to ensure proper accountability and compliance with program requirements and achievement of performance goals: (1) Providing subrecipients with training and technical assistance on program-related matters; and (2) Performing on-site reviews of the subrecipient's program operations; (3) Arranging for agreed-upon-procedures engagements as described in §200.425 [Audit services]. The standard contract agreement between DEP and the local grantee states, in part: Audit/Compliance Review Requirements - The contractor must comply with all applicable federal and state grant requirements including the Single Audit Act Amendments of 1996; 2 CFR Part 200 as amended; and any other applicable law or regulation, and any amendment to such other applicable law or regulation that may be enacted or promulgated by the federal government. Management Directive 325.12, Amended – Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office’s Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: Once the determination was made that the contracts with these entities represented subrecipient agreements, DEP began implementing control procedures to ensure federal requirements were met and adequately documented. However, due to the transition time needed for implementation, we found these procedures were not fully or consistently implemented during the audit period. Effect: Without sufficient subrecipient monitoring, DEP cannot ensure compliance with federal statutes, regulations, and the terms and conditions of the subrecipient agreements. In addition, DEP cannot confirm that subrecipients are performing satisfactory work, ensure the efficient use of program resources, and minimize the risk for fraud and abuse. Completing on-site monitoring activities consistently and as designed is essential for DEP to determine whether the subrecipients are complying with federal regulations and spending grant funds appropriately. Recommendation: We recommend DEP continue to implement their written procedures for performing during-the-award subrecipient monitoring to ensure timely subrecipient compliance with federal regulations. On-site monitoring visits by DEP Grant Managers should be supported by documentation to show the monitoring performed, areas examined, conclusions reached, and that the monitoring was performed in compliance with applicable regulations. Agency Response: DEP agrees with the facts presented in this finding. Questioned Costs: The amount of questioned costs cannot be determined.

Corrective Action Plan

On March 2, 2021, AMLR program representatives attended a Department of Interior, Office of Surface Mining Reclamation and Enforcement online training covering 2 CFR 200 and contractor or subrecipient determinations. DEP ceased issuing AMLR grants under Management Directive 305.20, Grant Administration. DEP management has determined the recipients with existing agreements are subrecipients and DEP will follow this determination consistently with future agreements and accounting. DEP has developed written policies and procedures for subrecipient monitoring and has notified grantees to implement the policies and procedures immediately to ensure timely subrecipient compliance with federal regulations. On July 28, 2023, an audit resolution letter was issued by the Department of Interior, Office of Surface Mining Reclamation and Enforcement. To further address deficiencies, training for DEP Grant Managers was held on January 24, 2024, and January 31, 2024, to provide details and instruction on reporting requirements and proper documentation to ensure subrecipient compliance with federal regulations and DEP’s role in this compliance. Anticipated Completion Date: Completed Contact Names: Patrick Webb, Director, Bureau of Abandoned Mine Reclamation; Tim Golding, Exec. Assist., Office of Admin. and Management

Prior Finding References

2022-005

About Subrecipient Monitoring →
2023-011
Cash Management
MATERIAL WEAKNESS

The Department of Environmental Protection (DEP) administers the Abandoned Mine Land Reclamation (AMLR) program funded by the United States Department of the Interior (DOI). During the fiscal year ended June 30, 2023, DEP expended $60,055,889 within the AMLR program, $8,900,470 or 14.8% of which was transferred to the Commonwealth Department of General Services (DGS) on July 6, 2022. DEP signed a Letter of Commitment (LOC) with DGS agreeing to transfer the funds as partial funding of a Capital Budget project for a third-party contractor to construct a new Acid Mine Drainage treatment facility estimated to cost approximately $26 million. Once transferred to DGS, these federal funds were combined with state Capital Budget funds and encumbered until project contractor payments began later in the fiscal year. Our review of transaction dates disclosed that DEP drew down $8,900,470 of AMLR federal funds on July 8, 2022; however, contractor payments did not begin until November 2022. A total of $9.1 million in contract payments were expended by the Commonwealth between November 2022 and June 30, 2023 fiscal year end. Therefore, DEP did not adequately limit the time between the drawdown of federal funds and the Commonwealth’s need for those funds, resulting in noncompliance with federal cash management regulations. Criteria: As part of administering the AMLR program, DEP must have policies, procedures, and controls in place to ensure compliance with federal cash management requirements and regulations. 2 CFR Section 200.305 (a), Federal Payment for pass through entities, states in part: a) For states, payments are governed by Treasury-State Cash Management Improvement Act (CMIA) agreements and default procedures codified at 31 CFR part 205. 31 CFR Section 205.33 (a) states in part: (a) A State must minimize the time between the drawdown of Federal funds from the Federal government and their disbursement for Federal program purposes. A Federal Program Agency must limit a funds transfer to a State to the minimum amounts needed by the State and must time the disbursement to be in accord with the actual, immediate cash requirements of the State in carrying out a Federal assistance program or project. The timing and amount of funds transfers must be as close as is administratively feasible to a State's actual cash outlay for direct program costs and the proportionate share of any allowable indirect costs. States should exercise sound cash management in funds transfers to subgrantees… Commonwealth Management Directive 325.12 Amended – Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office’s Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Finding 2023 –¬ 011: (continued) Management should design control activities to achieve objectives and respond to risk. Management should implement control activities through policies. Cause: DGS has sole oversight of Capital Budget projects, one of which was partially funded by AMLR funds under the LOC between DEP and DGS. To have funds available for timely contract award, it is DGS practice to bill the agency for the entirety of the funds committed, including federal funds in this case, when a LOC is executed. Once transferred from the agency, funds are encumbered and held until project contractor payments are made. DEP did not have procedures in place to minimize the time between the drawdown of federal funds and their disbursement by DGS for project purposes. Effect: DEP did not minimize the time elapsing between the drawdown of $8,900,470 in AMLR funds and the actual need for the funds, resulting in noncompliance with federal cash management regulations. Recommendation: We recommend DEP implement policies and procedures when a LOC is executed for any future Capital Budget projects to minimize the time federal funds are held by the Commonwealth. Agency Response: DEP agrees with the facts presented in this finding. Questioned Costs: None

Show full finding ▾
Full finding narrative

Department of Environmental Protection Finding 2023 –¬ 011: ALN 15.252 – Abandoned Mine Land Reclamation A Material Weakness and Material Noncompliance Exist at the Department of Environmental Protection Related to Cash Management of Federal Funds Federal Grant Number(s) and Year(s): S21AF10050 (6/01/2021 – 5/31/2024) Type of Finding: Material Weakness in Internal Control over Compliance, Material Noncompliance Compliance Requirement: Cash Management Condition: The Department of Environmental Protection (DEP) administers the Abandoned Mine Land Reclamation (AMLR) program funded by the United States Department of the Interior (DOI). During the fiscal year ended June 30, 2023, DEP expended $60,055,889 within the AMLR program, $8,900,470 or 14.8% of which was transferred to the Commonwealth Department of General Services (DGS) on July 6, 2022. DEP signed a Letter of Commitment (LOC) with DGS agreeing to transfer the funds as partial funding of a Capital Budget project for a third-party contractor to construct a new Acid Mine Drainage treatment facility estimated to cost approximately $26 million. Once transferred to DGS, these federal funds were combined with state Capital Budget funds and encumbered until project contractor payments began later in the fiscal year. Our review of transaction dates disclosed that DEP drew down $8,900,470 of AMLR federal funds on July 8, 2022; however, contractor payments did not begin until November 2022. A total of $9.1 million in contract payments were expended by the Commonwealth between November 2022 and June 30, 2023 fiscal year end. Therefore, DEP did not adequately limit the time between the drawdown of federal funds and the Commonwealth’s need for those funds, resulting in noncompliance with federal cash management regulations. Criteria: As part of administering the AMLR program, DEP must have policies, procedures, and controls in place to ensure compliance with federal cash management requirements and regulations. 2 CFR Section 200.305 (a), Federal Payment for pass through entities, states in part: a) For states, payments are governed by Treasury-State Cash Management Improvement Act (CMIA) agreements and default procedures codified at 31 CFR part 205. 31 CFR Section 205.33 (a) states in part: (a) A State must minimize the time between the drawdown of Federal funds from the Federal government and their disbursement for Federal program purposes. A Federal Program Agency must limit a funds transfer to a State to the minimum amounts needed by the State and must time the disbursement to be in accord with the actual, immediate cash requirements of the State in carrying out a Federal assistance program or project. The timing and amount of funds transfers must be as close as is administratively feasible to a State's actual cash outlay for direct program costs and the proportionate share of any allowable indirect costs. States should exercise sound cash management in funds transfers to subgrantees… Commonwealth Management Directive 325.12 Amended – Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office’s Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Finding 2023 –¬ 011: (continued) Management should design control activities to achieve objectives and respond to risk. Management should implement control activities through policies. Cause: DGS has sole oversight of Capital Budget projects, one of which was partially funded by AMLR funds under the LOC between DEP and DGS. To have funds available for timely contract award, it is DGS practice to bill the agency for the entirety of the funds committed, including federal funds in this case, when a LOC is executed. Once transferred from the agency, funds are encumbered and held until project contractor payments are made. DEP did not have procedures in place to minimize the time between the drawdown of federal funds and their disbursement by DGS for project purposes. Effect: DEP did not minimize the time elapsing between the drawdown of $8,900,470 in AMLR funds and the actual need for the funds, resulting in noncompliance with federal cash management regulations. Recommendation: We recommend DEP implement policies and procedures when a LOC is executed for any future Capital Budget projects to minimize the time federal funds are held by the Commonwealth. Agency Response: DEP agrees with the facts presented in this finding. Questioned Costs: None

Corrective Action Plan

DEP will ensure appropriate language as per 31 CFR Section 205.33 (a) of the Treasury-State Cash Management Improvement Act (CMIA) to be included in all Delegation Memorandum of Understandings (DMOU) and Letter of Commitments (LOC) for all future Capital Budget Projects to ensure the expenditure of federal monies is consistent with the progress of the project. Anticipated Completion Date: Completed Contact Names: Patrick Webb, Director, Bur. of Abandoned Mine Reclamation; Tim Golding, Exec. Assist., Office of Admin. and Management

About Cash Management →
2023-012
Special Tests & Provisions
MATERIAL WEAKNESSREPEATQUESTIONED COSTS

During our audit of the Supplemental Nutrition Assistance Program (SNAP) administered by the Department of Human Services (DHS), we evaluated the security over Electronic Benefits Transfer (EBT) cards, which includes both the physical security of EBT cards during the issuance process at County Assistance Offices (CAO), as well as the handling of EBT cards returned from the United States Postal Service as undeliverable, or those that have been lost or stolen. EBT cards are the method by which SNAP benefit payments are made available to recipients. Also, EBT cards are the primary method by which cash and special allowance benefit payments are made available to Temporary Assistance for Needy Families (TANF) recipients. Total benefit expenditures for SNAP for the fiscal year ended June 30, 2023 totaled $5.5 billion. Total benefit expenditures for TANF for the fiscal year ended June 30, 2023 totaled $116.8 million. Fourteen of the 87 CAO and district locations that issued EBT cards were selected for site testing in the current audit period. During our testing of the physical security over EBT cards, we noted exceptions at ten CAO and district locations selected for testing. These exceptions included the following: 1) The master list of cardmakers and pinners maintained by the EBT Project Office did not reconcile to the list provided by a CAO (1 location); 2) The Roles/Permissions Report from the EBT Card Tracking Database provided by the EBT Project Office and CAO/district offices did not reconcile (1 district office and 5 CAO locations); 3) EBT cards were created outside of the hours of operations (1 district office and 1 CAO location); 4) Failure to perform the following: • Completion of the witness fields on a Ribbon Log (1 CAO location); • Create adequate written internal procedures for EBT Security for over-the-counter card mailings (1 district office); • Ensure that coverage for card pinning is available until 5:00 PM each business day (2 locations); • Enter EBT cards into the EBT Card Tracking Database at the same time that the card Primary Account Number (PAN) is created in the Electronic Payment Processing and Information Control (EPPIC) system (1 CAO location); • Maintain adequate security of EBT cards (1 district office); • Maintain adequate security of pinning device (1 district office); • Maintain adequate security of EBT card printing device (1 district office); Finding 2023 – 012: (continued) • Maintain operational efficiency due to only having one PIN Select Device (1 CAO location); • Maintain Form HS 764 in the case record after the EBT card is created (1 CAO location); • Maintain an EPPIC EBT Systems Application form (1 CAO location); • Proper completion of the EPPIC EBT Systems Application form; the form requested the user be granted an EPPIC Admin role (inquiry-only access) as well as a PIN Select User role (1 CAO location); • Timely enter a shipment received into the EBT Card Tracking Database (1 CAO location); and • Timely completion and submission of the EPPIC EBT Systems Application forms to the Office of Income Maintenance (OIM) EBT Security (1 district office and 3 CAO locations). Forty of the 261 business days in the current audit period were selected to test the handling and destruction of returned EBT cards. During our testing of the handling and destruction of returned EBT cards, we noted exceptions on one of the 40 business days selected for testing. These exceptions included the following: 1) Failure to properly complete the EBT Headquarters Card Destruction Log. The "Approved by the Project Officer" column of the EBT Headquarters Card Destruction Log was signed and dated by the supervisor one day after the “Cards Destroyed by” column was signed and dated by the clerk. The cards were destroyed prior to the review/approval by the supervisor. 2) Failure to properly complete the EBT Headquarters Card Destruction Log. The "Number of Cards Received by the Project Officer” column of the EBT Headquarters Card Destruction Log was not completed by the supervisor. Criteria: The 2023 OMB Uniform Guidance Compliance Supplement, Part 4 – Agency Program Requirements for the SNAP Cluster, Special Tests and Provisions – N.3 EBT Card Security, states: The state is required to maintain adequate security over, and documentation/records for, EBT cards to prevent their theft, embezzlement, loss, damage, destruction, unauthorized transfer, negotiation, or use (7 CFR Section 274.8(b)(3)). 7 CFR Section 274.5, Record retention and forms security, states: (c) Accountable Documents. (1) EBT cards shall be considered accountable documents. The State agency shall provide the following minimum security and control procedures for these documents: i. Secure storage; ii. Access limited to authorized personnel; iii. Bulk inventory control records; iv. Subsequent control records maintained through the point of issuance or use; and v. Periodic review and validation of inventory controls and records by parties not otherwise involved in maintaining control records. 45 CFR Section 75.302 applicable to TANF states: (b) The financial management system of each non-Federal entity must provide for the following (see also §75.361, 75.362, 75.363, 75.364, and 75.365): (4) Effective control over, and accountability for, all funds, property, and other assets. The non-Federal entity must adequately safeguard all assets and assure that they are used solely for authorized purposes. See §75.303. Finding 2023 – 012: (continued) Management Directive 325.12, Amended – Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office’s Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: Established policies and procedures were not followed consistently across CAO and district locations, which resulted in ineffective internal controls over EBT card security. Effect: Without adequate security controls over EBT cards, there exists the possibility of misappropriation and/or abuse. Recommendation: We recommend that DHS monitor EBT card security at CAO and district locations on a regular basis to improve consistency in the execution of documented policies and procedures. Agency Response: DHS agrees with this finding. Questioned Costs: The amount of questioned costs cannot be determined.

Show full finding ▾
Full finding narrative

Department of Human Services Finding 2023 – 012: ALN 10.551 and 10.561 – Supplemental Nutrition Assistance Program (SNAP) Cluster (including COVID-19) ALN 93.558 – Temporary Assistance for Needy Families (including COVID-19) A Material Weakness and Material Noncompliance Exist at the Department of Human Services Related to Electronic Benefits Transfer Card Security (A Similar Condition Was Noted in Prior Year Finding 2022-006) Federal Grant Number(s) and Year(s): 221PA405S2514 (10/01/2021 – 9/30/2022), 231PA405S2514 (10/01/2022 – 9/30/2023), 1701PATANF (10/01/2016 – 9/30/2017), 2101PATANF (10/01/2020 – 9/30/2021), 2101PATANFC6 (10/01/2020 – 9/30/2022), 2201PATANF (10/01/2021 – 9/30/2022), 2301PATANF (10/01/2022 – 9/30/2023) Type of Finding: Material Weakness in Internal Control over Compliance, Material Noncompliance Compliance Requirement: Special Tests and Provisions related to EBT Card Security Condition: During our audit of the Supplemental Nutrition Assistance Program (SNAP) administered by the Department of Human Services (DHS), we evaluated the security over Electronic Benefits Transfer (EBT) cards, which includes both the physical security of EBT cards during the issuance process at County Assistance Offices (CAO), as well as the handling of EBT cards returned from the United States Postal Service as undeliverable, or those that have been lost or stolen. EBT cards are the method by which SNAP benefit payments are made available to recipients. Also, EBT cards are the primary method by which cash and special allowance benefit payments are made available to Temporary Assistance for Needy Families (TANF) recipients. Total benefit expenditures for SNAP for the fiscal year ended June 30, 2023 totaled $5.5 billion. Total benefit expenditures for TANF for the fiscal year ended June 30, 2023 totaled $116.8 million. Fourteen of the 87 CAO and district locations that issued EBT cards were selected for site testing in the current audit period. During our testing of the physical security over EBT cards, we noted exceptions at ten CAO and district locations selected for testing. These exceptions included the following: 1) The master list of cardmakers and pinners maintained by the EBT Project Office did not reconcile to the list provided by a CAO (1 location); 2) The Roles/Permissions Report from the EBT Card Tracking Database provided by the EBT Project Office and CAO/district offices did not reconcile (1 district office and 5 CAO locations); 3) EBT cards were created outside of the hours of operations (1 district office and 1 CAO location); 4) Failure to perform the following: • Completion of the witness fields on a Ribbon Log (1 CAO location); • Create adequate written internal procedures for EBT Security for over-the-counter card mailings (1 district office); • Ensure that coverage for card pinning is available until 5:00 PM each business day (2 locations); • Enter EBT cards into the EBT Card Tracking Database at the same time that the card Primary Account Number (PAN) is created in the Electronic Payment Processing and Information Control (EPPIC) system (1 CAO location); • Maintain adequate security of EBT cards (1 district office); • Maintain adequate security of pinning device (1 district office); • Maintain adequate security of EBT card printing device (1 district office); Finding 2023 – 012: (continued) • Maintain operational efficiency due to only having one PIN Select Device (1 CAO location); • Maintain Form HS 764 in the case record after the EBT card is created (1 CAO location); • Maintain an EPPIC EBT Systems Application form (1 CAO location); • Proper completion of the EPPIC EBT Systems Application form; the form requested the user be granted an EPPIC Admin role (inquiry-only access) as well as a PIN Select User role (1 CAO location); • Timely enter a shipment received into the EBT Card Tracking Database (1 CAO location); and • Timely completion and submission of the EPPIC EBT Systems Application forms to the Office of Income Maintenance (OIM) EBT Security (1 district office and 3 CAO locations). Forty of the 261 business days in the current audit period were selected to test the handling and destruction of returned EBT cards. During our testing of the handling and destruction of returned EBT cards, we noted exceptions on one of the 40 business days selected for testing. These exceptions included the following: 1) Failure to properly complete the EBT Headquarters Card Destruction Log. The "Approved by the Project Officer" column of the EBT Headquarters Card Destruction Log was signed and dated by the supervisor one day after the “Cards Destroyed by” column was signed and dated by the clerk. The cards were destroyed prior to the review/approval by the supervisor. 2) Failure to properly complete the EBT Headquarters Card Destruction Log. The "Number of Cards Received by the Project Officer” column of the EBT Headquarters Card Destruction Log was not completed by the supervisor. Criteria: The 2023 OMB Uniform Guidance Compliance Supplement, Part 4 – Agency Program Requirements for the SNAP Cluster, Special Tests and Provisions – N.3 EBT Card Security, states: The state is required to maintain adequate security over, and documentation/records for, EBT cards to prevent their theft, embezzlement, loss, damage, destruction, unauthorized transfer, negotiation, or use (7 CFR Section 274.8(b)(3)). 7 CFR Section 274.5, Record retention and forms security, states: (c) Accountable Documents. (1) EBT cards shall be considered accountable documents. The State agency shall provide the following minimum security and control procedures for these documents: i. Secure storage; ii. Access limited to authorized personnel; iii. Bulk inventory control records; iv. Subsequent control records maintained through the point of issuance or use; and v. Periodic review and validation of inventory controls and records by parties not otherwise involved in maintaining control records. 45 CFR Section 75.302 applicable to TANF states: (b) The financial management system of each non-Federal entity must provide for the following (see also §75.361, 75.362, 75.363, 75.364, and 75.365): (4) Effective control over, and accountability for, all funds, property, and other assets. The non-Federal entity must adequately safeguard all assets and assure that they are used solely for authorized purposes. See §75.303. Finding 2023 – 012: (continued) Management Directive 325.12, Amended – Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office’s Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: Established policies and procedures were not followed consistently across CAO and district locations, which resulted in ineffective internal controls over EBT card security. Effect: Without adequate security controls over EBT cards, there exists the possibility of misappropriation and/or abuse. Recommendation: We recommend that DHS monitor EBT card security at CAO and district locations on a regular basis to improve consistency in the execution of documented policies and procedures. Agency Response: DHS agrees with this finding. Questioned Costs: The amount of questioned costs cannot be determined.

Corrective Action Plan

Office of Income Maintenance (OIM) Bureau of Operations (BOO) BOO will take the following actions to address the finding: 1. All CAOs and district offices will be reminded of the EBT Coordinators’, alternates’, pinners’, and card makers’ responsibilities. The BOO will ensure users in the EBT Card Tracking Database know their responsibilities and segregation of duties and will ensure there is coverage for card pinning until 5:00 pm each business day. Also, reminders to be sent to review the OIM EBT Procedural Manual periodically and when updates occur. This will occur by April 1, 2024. 2. All CAOs and district offices will be reminded to maintain adequate security of the EBT cards, card inventory, pinning devices, and ribbons. The EBT office will ensure all offices have two pinning devices and that they are in working order. This will occur by April 1, 2024. 3. OIM mandates annual training for EBT personnel to be completed at the beginning of each year. The training includes reviewing the procedures that safeguard access to the EBT systems. Area managers and staff assistants monitor completion of the training. Also included are the following: a. Review of roles and responsibilities and who may hold a role b. Card maker and pinner coverage for all business hours c. Proper security for EBT cards and associated items d. Timeframes for submitting changes e. Retention timeframes Anticipated Completion Dates: 1, 2 - 04/01/2024; 3 - Completed Contact Name: Jeanette Coulston, Staff Assistant to Director, Bureau of Operations OIM Bureau of Program Support (BPS)/EBT Project Office BPS will take the following actions to address the finding: 1. The EBT Project Office will make updates to the EBT Procedures Manual (Manual) and OIM EPPIC EBT Systems Application form (application) as needed. Notification of updates will be sent to CAO staff via email. This is expected to occur by April 1, 2024. 2. The EBT Program office will provide guidelines for the CAOs to follow when reviewing/updating their written internal procedures for EBT security of card mailings. This is expected to occur by April 1, 2024. 3. The EBT Project Officer will start retraining parties that are responsible for the completion of the EBT Headquarters Card Destruction log. This is expected to occur by April 1, 2024. Anticipated Completion Date: 04/01/2024 Contact Name: Tonya Holloway, Division Director OIM Bureau of Program Evaluation (BPE)/Division of Corrective Action (DCA) BPE will take the following actions to address the finding: The Bureau of Program Evaluation, Division of Corrective Action conducts EBT Card Security reviews at every CAO and District Office that issues EBT cards. These reviews are completed on a 3-year rotation to ensure compliance in the execution of documented policies and procedures. BPE/DCA will adjust the review criteria to incorporate any procedural changes implemented in the Electronic Benefit Transfer Procedures Manual. The current rotation schedule spans FFY 2022- FFY 2024. The new 3-year schedule will begin October 2024. Anticipated Completion Date: October 2024 Contact Name: Amira S. Milikin, Division Director

Prior Finding References

2022-006

About Special Tests and Provisions →
2023-013
Reporting

The Pennsylvania Department of Human Services (DHS) is required to file the ACF-204, Annual Report including the Annual Report on State Maintenance-of-Effort Programs (ACF-204 Report) each federal fiscal year with the United States Department of Health and Human Services, Administration for Children and Families (ACF). The ACF-204 Report contains information on the Temporary Assistance for Needy Families (TANF) program and the State's Maintenance-of-Effort (MOE) programs for that year. DHS is also required to file the ACF-196R, State TANF Financial Report (ACF-196R Report) quarterly with ACF, 45 days after each quarter of the fiscal year. The quarterly ACF-196R Reports reflect expenditures cumulative through that quarter for the federal fiscal year for each open grant award and includes MOE expenditures. The sum of the MOE expenditure amounts claimed on the annual ACF-204 Report should equal the total MOE expenditure amounts claimed on the state’s 4th quarter ACF-196R Report. However, when we reviewed the ACF-204 Report and the 196R-Report filed for September 30, 2022 the reported MOE expenditures did not agree. We determined the ACF-204 Report was inaccurate because edits were made to the ACF-196R Report after submission to ACF and the edits were not updated on the ACF-204 Report. The ACF-204 Report is prepared by DHS program personnel and the ACF-196R Report is prepared by the Office of Comptroller’s Operations (OCO). The ACF-196R Report originally submitted in November 2022 had been revised and resubmitted in March 2023. We noted the following differences between the total state MOE expenditure amounts reported on the two reports: SEE SCHEDULE OF FINDINGS AND QUESTIONED COSTS FOR CHART/TABLE The MOE expenditure amounts reported on the original ACF-204 Report were overstated by a total of $3,980,250. Although the ACF-196R Report had been revised in March 2023, there was no subsequent revision to the ACF-204 Report to correct the MOE line items. After our 2023 audit inquiry, DHS program personnel subsequently revised and resubmitted the report to ACF in September 2023 with the correct MOE expenditure amounts. Finding 2023 –¬ 013: (continued) In addition, our procedures disclosed that the ACF-196P Report (TANF Pandemic Emergency Assistance Fund Report) was submitted late. The ACF-196P Report was due December 29, 2022, but was not submitted until January 6, 2023. Criteria: 45 CFR Section 265.9 (a) states: Each State must file an annual report containing information on the TANF program and the State’s MOE programs for that year. TANF-ACF-PI-2001-06, Clarification on Completing the Annual Reports on TANF Programs (Attachment A) and State Maintenance-of-Effort (MOE) Programs (Form ACF-204) (Attachment B) issued by ACF, recommends that State program and fiscal staff coordinate their efforts to complete the ACF-204 information. The sum of the MOE amounts claimed in this report should equal the total MOE amounts claimed under all programs on the State's 4th quarter financial reporting form ACF-196 Report. Management Directive 325.12, Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office’s Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should design control activities to achieve objectives and respond to risks. Management should externally communicate the necessary quality information to achieve the entity’s objectives. Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Pursuant to section 403(c) of the Social Security Act, states must use the ACF-196P form to report TANF PEAF (Pandemic Emergency Assistance Fund) expenditure data. TANF-ACF-PI-2021-08, Program Instructions for the Completion of the TANF Financial Form ACF-196P for the Pandemic Emergency Assistance Fund, states that each grantee must submit completed ACF-196P forms to ACF within 90 days of the end of each federal fiscal year, that is, the quarter ending (QE) September 30. Reports for the PEAF awards for QE September 30, 2022 were due December 29, 2022. Cause: The ACF-204 Report overstatement was discovered as a result of auditor inquiry. Although OCO personnel communicated that a revised ACF196R Report was filed, program personnel did not recognize the need to revise the ACF-204 Report. Regarding the untimely filing of the ACF-196P Report, DHS asked OCO to request an extension as DHS was waiting for guidance from ACF to finalize accounting and close out the grant. The grant must be closed before OCO can prepare and file the final report. However, ACF did not grant the extension. Effect: Inaccuracies on the ACF-204 Report, could lead to the federal government’s inability to determine if the Commonwealth met its MOE requirements for the fiscal year. Furthermore, inaccurate reporting on the ACF-204 Report and untimely reporting of the ACF-196P Report could subject the Commonwealth to penalties. Recommendation: We recommend that program personnel coordinate with OCO personnel to ensure the MOE amounts reported in the ACF-204 Report are correct and equal the form ACF-196R amounts, the ACF-196P is submitted timely, and that federal reports are in compliance with federal requirements. Agency Response: DHS agrees with this finding. Questioned Costs: None

Show full finding ▾
Full finding narrative

Department of Human Services Finding 2023 –¬ 013: ALN 93.558 – Temporary Assistance for Needy Families (including COVID-19) A Significant Deficiency and Noncompliance Exist Over the Preparation and Submission of the ACF-204 and ACF-196P Reports Federal Grant Number(s) and Year(s): 2301PATANF (10/01/2022 – 9/30/2023), 2201PATANF (10/01/2021 – 9/30/2022), 2101PATANF (10/01/2020 – 9/30/2021), 2001PATANF (10/01/2019 – 9/30/2020), 1901PATANF (10/01/2018 – 9/30/2019), 1801PATANF (10/01/2017 – 9/30/2018), 1701PATANF (10/01/2016 – 9/30/2017) Type of Finding: Significant Deficiency in Internal Control over Compliance, Other Matters Compliance Requirement: Reporting Condition: The Pennsylvania Department of Human Services (DHS) is required to file the ACF-204, Annual Report including the Annual Report on State Maintenance-of-Effort Programs (ACF-204 Report) each federal fiscal year with the United States Department of Health and Human Services, Administration for Children and Families (ACF). The ACF-204 Report contains information on the Temporary Assistance for Needy Families (TANF) program and the State's Maintenance-of-Effort (MOE) programs for that year. DHS is also required to file the ACF-196R, State TANF Financial Report (ACF-196R Report) quarterly with ACF, 45 days after each quarter of the fiscal year. The quarterly ACF-196R Reports reflect expenditures cumulative through that quarter for the federal fiscal year for each open grant award and includes MOE expenditures. The sum of the MOE expenditure amounts claimed on the annual ACF-204 Report should equal the total MOE expenditure amounts claimed on the state’s 4th quarter ACF-196R Report. However, when we reviewed the ACF-204 Report and the 196R-Report filed for September 30, 2022 the reported MOE expenditures did not agree. We determined the ACF-204 Report was inaccurate because edits were made to the ACF-196R Report after submission to ACF and the edits were not updated on the ACF-204 Report. The ACF-204 Report is prepared by DHS program personnel and the ACF-196R Report is prepared by the Office of Comptroller’s Operations (OCO). The ACF-196R Report originally submitted in November 2022 had been revised and resubmitted in March 2023. We noted the following differences between the total state MOE expenditure amounts reported on the two reports: SEE SCHEDULE OF FINDINGS AND QUESTIONED COSTS FOR CHART/TABLE The MOE expenditure amounts reported on the original ACF-204 Report were overstated by a total of $3,980,250. Although the ACF-196R Report had been revised in March 2023, there was no subsequent revision to the ACF-204 Report to correct the MOE line items. After our 2023 audit inquiry, DHS program personnel subsequently revised and resubmitted the report to ACF in September 2023 with the correct MOE expenditure amounts. Finding 2023 –¬ 013: (continued) In addition, our procedures disclosed that the ACF-196P Report (TANF Pandemic Emergency Assistance Fund Report) was submitted late. The ACF-196P Report was due December 29, 2022, but was not submitted until January 6, 2023. Criteria: 45 CFR Section 265.9 (a) states: Each State must file an annual report containing information on the TANF program and the State’s MOE programs for that year. TANF-ACF-PI-2001-06, Clarification on Completing the Annual Reports on TANF Programs (Attachment A) and State Maintenance-of-Effort (MOE) Programs (Form ACF-204) (Attachment B) issued by ACF, recommends that State program and fiscal staff coordinate their efforts to complete the ACF-204 information. The sum of the MOE amounts claimed in this report should equal the total MOE amounts claimed under all programs on the State's 4th quarter financial reporting form ACF-196 Report. Management Directive 325.12, Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office’s Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should design control activities to achieve objectives and respond to risks. Management should externally communicate the necessary quality information to achieve the entity’s objectives. Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Pursuant to section 403(c) of the Social Security Act, states must use the ACF-196P form to report TANF PEAF (Pandemic Emergency Assistance Fund) expenditure data. TANF-ACF-PI-2021-08, Program Instructions for the Completion of the TANF Financial Form ACF-196P for the Pandemic Emergency Assistance Fund, states that each grantee must submit completed ACF-196P forms to ACF within 90 days of the end of each federal fiscal year, that is, the quarter ending (QE) September 30. Reports for the PEAF awards for QE September 30, 2022 were due December 29, 2022. Cause: The ACF-204 Report overstatement was discovered as a result of auditor inquiry. Although OCO personnel communicated that a revised ACF196R Report was filed, program personnel did not recognize the need to revise the ACF-204 Report. Regarding the untimely filing of the ACF-196P Report, DHS asked OCO to request an extension as DHS was waiting for guidance from ACF to finalize accounting and close out the grant. The grant must be closed before OCO can prepare and file the final report. However, ACF did not grant the extension. Effect: Inaccuracies on the ACF-204 Report, could lead to the federal government’s inability to determine if the Commonwealth met its MOE requirements for the fiscal year. Furthermore, inaccurate reporting on the ACF-204 Report and untimely reporting of the ACF-196P Report could subject the Commonwealth to penalties. Recommendation: We recommend that program personnel coordinate with OCO personnel to ensure the MOE amounts reported in the ACF-204 Report are correct and equal the form ACF-196R amounts, the ACF-196P is submitted timely, and that federal reports are in compliance with federal requirements. Agency Response: DHS agrees with this finding. Questioned Costs: None

Corrective Action Plan

1. Upon receiving the annual 4th quarter ACF-196R from the Bureau of Financial Management, the Office of Income Maintenance (OIM) Bureau of Policy (BOP) replies with a confirmation receipt and a reminder to send any future revisions of the report with an email priority of important. 2. OIM, BOP updated the roles in the On-line Data Collections (OLDC) Grant Solutions portal. 3. OIM, BOP set up OLDC Grant Solutions to generate an email notification for any new submissions, revised submissions, or any previous submissions that are withdrawn. 4. OLDC Grant Solutions notifications received between the months of January and March will receive priority to ensure any necessary amendments to the TANF Annual report (ACF-204) are properly submitted by the March 31 deadline. Anticipated Completion Dates: 1 - 11/30/2024; 2, 3 - Completed; 4 - March 2024 Contact Name: Adam Riggs, Director, Division of Family Assistance, OIM, BOP

About Reporting →
2023-014
Subrecipient Monitoring
REPEATQUESTIONED COSTS

During the fiscal year ended June 30, 2023, the Department of Human Services (DHS) paid $82.4 million in Temporary Assistance for Needy Families (TANF) funding to subrecipients within the New Directions, Cash Grants, and Alternatives to Abortion appropriations (or 18.1 percent) out of total federal TANF expenditures of $455.7 million reported on the June 30, 2023 Schedule of Expenditures of Federal Awards. Our testing of DHS’s during-the-award monitoring of subrecipients for the fiscal year ended June 30, 2023 disclosed that DHS performed on-site monitoring for 13 out of 14 subrecipients selected for testing. The on-site monitoring that was performed consisted of reviews of program operations including design, data entry accuracy and timeliness, case management analysis, and program payment performance goals. The on-site monitoring also included a review of a sample of TANF recipient case files to ensure that the recipients’ TANF activities were documented and accurately entered in the Commonwealth’s Workforce Development System. However, DHS’s monitoring procedures for the 13 subrecipients were not adequate as they did not include a review or monitoring of subrecipient financial records, which would provide an assessment of a subrecipient’s compliance with applicable federal regulations. Although DHS’s monitoring procedures include reviewing subrecipient completed questionnaires for selected subrecipients that had questions related to financial matters, DHS’s monitoring personnel did not review subrecipient financial records. For example, DHS did not perform procedures to ensure subrecipient invoices agreed to the books and records of the subrecipient and that the records were adequate to support the allowability of costs paid by DHS during the award period. In addition, DHS’s monitoring procedures did not include an evaluation of the operating effectiveness of DHS subrecipients’ procedures to monitor Single Audits and any related findings. Our testing of the 14 subrecipients noted above included follow up on one subrecipient identified in the prior year finding as not being on-site monitored by DHS when the risk assessment warranted on-site monitoring. Our follow-up during the current audit period disclosed that DHS did not conduct on-site monitoring for this subrecipient during the fiscal year ended June 30, 2023. Since the on-site monitoring was not completed, internal control weaknesses, noncompliance, and questioned costs may have existed and remained undetected during the current audit period. This subrecipient received $1 million of TANF funds during the fiscal year ended June 30, 2023. Criteria: 45 CFR Section 75.352, Requirements for pass-through entities, states: All pass-through entities must: (d) Monitor the activities of the subrecipient as necessary to ensure that the subaward is used for authorized purposes, in compliance with Federal statutes, regulations, and the terms and conditions of the subaward; and that subaward performance goals are achieved. Pass-through entity monitoring of the subrecipient must include: (1) Reviewing financial and performance reports required by the pass-through entity. Finding 2023 –¬ 014: (continued) (2) Following-up and ensuring that the subrecipient takes timely and appropriate action on all deficiencies pertaining to the Federal award provided to the subrecipient from the pass-through entity detected through audits, on-site reviews, and other means. (3) Issuing a management decision for audit findings pertaining to the Federal award provided to the subrecipient from the pass-through entity as required by § 75.521 [Management decision]. 2 CFR Section 200.332, Requirements for pass-through entities, states in part: All pass-through entities must: (e) Depending upon the pass-through entity's assessment of risk posed by the subrecipient (as described in paragraph (b) of this section), the following monitoring tools may be useful for the pass-through entity to ensure proper accountability and compliance with program requirements and achievement of performance goals: (1) Providing subrecipients with training and technical assistance on program-related matters; (2) Performing on-site reviews of the subrecipient's program operations; and (3) Arranging for agreed-upon-procedures engagements as described in §200.425 [Audit services]. Management Directive 325.12, Amended – Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office’s Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: DHS provided new during-the-award monitoring procedures to be used for the on-site monitoring of subrecipients, but these procedures were not in place for monitoring conducted during the fiscal year ended June 30, 2023. Therefore, DHS has not implemented adequate during-the-award monitoring procedures of subrecipients to include testing of the financial records and the subrecipients’ monitoring of Single Audits sufficient to ensure compliance with federal regulations. Regarding the one subrecipient for which on-site monitoring was not completed, DHS personnel stated that they worked to obtain the necessary documentation to complete the on-site monitoring. However, the subrecipient had not cooperated. The grant agreement with the subrecipient expired on December 31, 2023 and the subrecipient has stopped all contact with DHS. Effect: TANF subrecipients could be operating in noncompliance with federal regulations without timely detection and correction by DHS management. Recommendation: DHS should strengthen its controls to ensure during-the-award monitoring of TANF subrecipients includes procedures to ensure that subrecipients are in compliance with applicable federal regulations. This should include examining subrecipients’ financial records and ensuring that all required Single Audits were obtained by DHS subrecipients. Agency Response: DHS agrees with this finding. Questioned Costs: The amount of questioned costs cannot be determined.

Show full finding ▾
Full finding narrative

Department of Human Services Finding 2023 ¬– 014: ALN 93.558 – Temporary Assistance for Needy Families (including COVID-19) Department of Human Services Did Not Validate Financial Information as Part of Its On-Site Monitoring of Temporary Assistance for Needy Families Subrecipients (A Similar Condition Was Noted in Prior Year Finding 2022-008) Federal Grant Number(s) and Year(s): 2301PATANF (10/01/2022 – 9/30/2023), 2201PATANF (10/01/2021 – 9/30/2022), 2101PATANF (10/01/2020 – 9/30/2021), 2001PATANF (10/01/2019 – 9/30/2020), 1901PATANF (10/01/2018 – 9/30/2019), 1801PATANF (10/01/2017 – 9/30/2018), 1701PATANF (10/01/2016 – 9/30/2017) Type of Finding: Significant Deficiency in Internal Control over Compliance, Other Matters Compliance Requirement: Subrecipient Monitoring Condition: During the fiscal year ended June 30, 2023, the Department of Human Services (DHS) paid $82.4 million in Temporary Assistance for Needy Families (TANF) funding to subrecipients within the New Directions, Cash Grants, and Alternatives to Abortion appropriations (or 18.1 percent) out of total federal TANF expenditures of $455.7 million reported on the June 30, 2023 Schedule of Expenditures of Federal Awards. Our testing of DHS’s during-the-award monitoring of subrecipients for the fiscal year ended June 30, 2023 disclosed that DHS performed on-site monitoring for 13 out of 14 subrecipients selected for testing. The on-site monitoring that was performed consisted of reviews of program operations including design, data entry accuracy and timeliness, case management analysis, and program payment performance goals. The on-site monitoring also included a review of a sample of TANF recipient case files to ensure that the recipients’ TANF activities were documented and accurately entered in the Commonwealth’s Workforce Development System. However, DHS’s monitoring procedures for the 13 subrecipients were not adequate as they did not include a review or monitoring of subrecipient financial records, which would provide an assessment of a subrecipient’s compliance with applicable federal regulations. Although DHS’s monitoring procedures include reviewing subrecipient completed questionnaires for selected subrecipients that had questions related to financial matters, DHS’s monitoring personnel did not review subrecipient financial records. For example, DHS did not perform procedures to ensure subrecipient invoices agreed to the books and records of the subrecipient and that the records were adequate to support the allowability of costs paid by DHS during the award period. In addition, DHS’s monitoring procedures did not include an evaluation of the operating effectiveness of DHS subrecipients’ procedures to monitor Single Audits and any related findings. Our testing of the 14 subrecipients noted above included follow up on one subrecipient identified in the prior year finding as not being on-site monitored by DHS when the risk assessment warranted on-site monitoring. Our follow-up during the current audit period disclosed that DHS did not conduct on-site monitoring for this subrecipient during the fiscal year ended June 30, 2023. Since the on-site monitoring was not completed, internal control weaknesses, noncompliance, and questioned costs may have existed and remained undetected during the current audit period. This subrecipient received $1 million of TANF funds during the fiscal year ended June 30, 2023. Criteria: 45 CFR Section 75.352, Requirements for pass-through entities, states: All pass-through entities must: (d) Monitor the activities of the subrecipient as necessary to ensure that the subaward is used for authorized purposes, in compliance with Federal statutes, regulations, and the terms and conditions of the subaward; and that subaward performance goals are achieved. Pass-through entity monitoring of the subrecipient must include: (1) Reviewing financial and performance reports required by the pass-through entity. Finding 2023 –¬ 014: (continued) (2) Following-up and ensuring that the subrecipient takes timely and appropriate action on all deficiencies pertaining to the Federal award provided to the subrecipient from the pass-through entity detected through audits, on-site reviews, and other means. (3) Issuing a management decision for audit findings pertaining to the Federal award provided to the subrecipient from the pass-through entity as required by § 75.521 [Management decision]. 2 CFR Section 200.332, Requirements for pass-through entities, states in part: All pass-through entities must: (e) Depending upon the pass-through entity's assessment of risk posed by the subrecipient (as described in paragraph (b) of this section), the following monitoring tools may be useful for the pass-through entity to ensure proper accountability and compliance with program requirements and achievement of performance goals: (1) Providing subrecipients with training and technical assistance on program-related matters; (2) Performing on-site reviews of the subrecipient's program operations; and (3) Arranging for agreed-upon-procedures engagements as described in §200.425 [Audit services]. Management Directive 325.12, Amended – Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office’s Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: DHS provided new during-the-award monitoring procedures to be used for the on-site monitoring of subrecipients, but these procedures were not in place for monitoring conducted during the fiscal year ended June 30, 2023. Therefore, DHS has not implemented adequate during-the-award monitoring procedures of subrecipients to include testing of the financial records and the subrecipients’ monitoring of Single Audits sufficient to ensure compliance with federal regulations. Regarding the one subrecipient for which on-site monitoring was not completed, DHS personnel stated that they worked to obtain the necessary documentation to complete the on-site monitoring. However, the subrecipient had not cooperated. The grant agreement with the subrecipient expired on December 31, 2023 and the subrecipient has stopped all contact with DHS. Effect: TANF subrecipients could be operating in noncompliance with federal regulations without timely detection and correction by DHS management. Recommendation: DHS should strengthen its controls to ensure during-the-award monitoring of TANF subrecipients includes procedures to ensure that subrecipients are in compliance with applicable federal regulations. This should include examining subrecipients’ financial records and ensuring that all required Single Audits were obtained by DHS subrecipients. Agency Response: DHS agrees with this finding. Questioned Costs: The amount of questioned costs cannot be determined.

Corrective Action Plan

New Directions, Cash Grants The Office of Income Maintenance (OIM) is determining how it can incorporate onsite financial monitoring into the monitoring that is currently being conducted. This includes consideration of the specific areas the financial monitoring should cover and the scope of the monitoring. After OIM develops the monitoring procedures, OIM will start the onsite monitoring. Anticipated Completion Date: 12/31/2024 Contact Name: Joel O’Donnell, Dir., Bureau of Program Support, OIM Real Alternatives Despite repeated attempts and efforts by the Office of Policy Development (OPD) to engage Real Alternatives in ongoing monitoring activities, as well as monitoring after the end of the grant for previous years, the grantee was uncooperative and unresponsive to our requests and therefore regular monitoring was not completed. Effective December 31, 2023, the Department of Human Services’ grant agreement with Real Alternatives ended and was not renewed. Anticipated Completion Date: Completed Contact Name: Jessica Schneider, Executive Policy Specialist I, Grants, OPD

Prior Finding References

2022-008

About Subrecipient Monitoring →
2023-015
Cash Management / Subrecipient Monitoring
MATERIAL WEAKNESSQUESTIONED COSTS

Our examination of the Department of Human Services’ (DHS) procedures for monitoring Social Services Block Grant (SSBG) subrecipients revealed that DHS did not adequately monitor the SSBG Mental Health, Homeless Services, Child Welfare, Domestic Violence, Rape Crisis, Legal Services, and Family Planning subrecipients to ensure that SSBG awards are used in compliance with laws and regulations, which include allowable costs, period of performance, and other requirements. The inadequately monitored subrecipients received $41.0 million (or approximately 44 percent) of total SSBG program expenditures of $92.7 million reported on the Schedule of Expenditures of Federal Awards (SEFA). While we did note that DHS adequately monitored six of the 55 Mental Health County/County Joinder subrecipients which included Mental Health, Homeless Services and Child Welfare services, this coverage is not adequate. In addition, our review of the risk assessments completed for all of the aforementioned subrecipients identified several instances where subrecipient monitoring was warranted but was not conducted. No monitoring was performed on the Domestic Violence, Rape Crisis, Legal Services and Family Planning subrecipients. In addition, for the compliance requirement related to cash management, we noted that DHS advanced funds to SSBG subrecipients in four of nine program areas, representing $34.0 million (or approximately 37 percent) of SSBG program expenditures, without adequately monitoring the reasonableness of the subrecipient cash balances. In particular, for the program areas related to Mental Health, Intellectual Disabilities, Homeless Services, and Child Welfare, DHS advanced funds to subrecipients on a quarterly basis. Our inquiries with applicable DHS program administrators disclosed that DHS did not adequately monitor the four program areas’ subrecipients for cash management compliance either at the time of payment or at any other time during the fiscal year ended June 30, 2023. Furthermore, while Single Audits of SSBG subrecipients may be conducted each year, this auditing activity does not compensate for the lack of during-the-award program monitoring, since the timing, focus, and scope of subrecipient auditing activities after year end are different than compliance monitoring to be performed by program officials during the year. Criteria: 45 CFR Section 75.352, Requirements for pass-through entities, states: (d) Monitor the activities of the subrecipient as necessary to ensure that the subaward is used for authorized purposes, in compliance with Federal statutes, regulations, and the terms and conditions of the subaward; and that subaward performance goals are achieved. Pass-through entity monitoring of the subrecipient must include: (1) Reviewing financial and performance reports required by the pass-through entity. (2) Following-up and ensuring that the subrecipient takes timely and appropriate action on all deficiencies pertaining to the Federal award provided to the subrecipient from the pass-through entity detected through audits, on-site reviews, and other means. (3) Issuing a management decision for audit findings pertaining to the Federal award provided to the subrecipient from the pass-through entity… Finding 2023 –¬ 015: (continued) (e) Depending upon the pass-through entity's assessment of risk posed by the subrecipient (as described in paragraph (b) of this section), the following monitoring tools may be useful for the pass-through entity to ensure proper accountability and compliance with program requirements and achievement of performance goals: (1) Providing subrecipients with training and technical assistance on program-related matters; and (2) Performing on-site reviews of the subrecipient's program operations; (3) Arranging for agreed-upon-procedures engagements as described in §75.425 (Audit services). 45 CFR Section 75.305(b)(1), applicable to payments to subrecipients, states in part: …Advance payments to a non-Federal entity must be limited to the minimum amounts needed and be timed to be in accordance with the actual, immediate cash requirements of the non-Federal entity in carrying out the purpose of the approved program or project. The timing and amount of advance payments must be as close as is administratively feasible to the actual disbursements by the non-Federal entity for direct program or project costs and the proportionate share of any allowable indirect costs. The non-Federal entity must make timely payment to contractors in accordance with the contract provisions. Management Directive 325.12, Amended – Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office’s Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: DHS management indicated that risk assessment and monitoring documents were created for use during on-site monitoring of SSBG subrecipients. However, due to staffing issues, on-site monitoring was not performed for all SSBG subrecipients. Consistent with prior year audits, DHS management noted that there have been no changes to the payment methodology for the Homeless Services, Mental Health, Intellectual Disabilities, and Child Welfare components of SSBG. These programs provide subrecipients with advances to comply with Commonwealth law and also to ensure that adequate funds are available to provide services to participants on a timely basis. DHS officials believe that their in-house payment review procedures for the SSBG program are as efficient as administratively feasible and that controls exist in each of the program areas. Without on-site program monitoring visits by funding agency officials, we consider DHS’s limited in-house reviews of subrecipient status reports or other documents to be insufficient to detect potential subrecipient noncompliance, including excess cash violations. DHS does not adjust payments to the subrecipients based on in-house reviews. Effect: Since DHS does not adequately perform during-the-award monitoring of subrecipients, including the monitoring of subrecipient cash on hand, subrecipients may not be complying with applicable grant requirements and federal regulations, including cash management standards. Recommendation: DHS should perform risk based during-the-award monitoring procedures and risk assessments for all SSBG subrecipients to ensure timely compliance with all applicable federal regulations. On-site monitoring visits by state officials should be supported by documentation to show the monitoring performed, areas examined, conclusions reached, and that the monitoring was performed in compliance with applicable regulations. Finding 2023 –¬ 015: (continued) As recommended in previous Single Audits and supported by the United States Department of Health and Human Services, DHS should either consider changing their current subrecipient payment procedures from advancement basis to reimbursement basis or establish procedures to adequately monitor subrecipient cash on hand to ensure it is limited to immediate needs, but no longer than one month. The implementation and strengthening of these controls should provide DHS with reasonable assurance as to compliance with cash management requirements at the subrecipient level. Agency Response: DHS agrees with this finding. Questioned Costs: The amount of questioned costs cannot be determined.

Show full finding ▾
Full finding narrative

Department of Human Services Finding 2023 –¬ 015: ALN 93.667 – Social Services Block Grant A Material Weakness and Material Noncompliance Exist in the Department of Human Services’ Program Monitoring of the Social Services Block Grant Subrecipients Federal Grant Number(s) and Year(s): 2301PASOSR (10/01/2022 – 9/30/2024), 2201PASOSR (10/01/2021 – 9/30/2023), 2101PASOSR (10/01/2020 – 9/30/2022) Type of Finding: Material Weakness in Internal Control over Compliance, Material Noncompliance Compliance Requirements: Cash Management, Subrecipient Monitoring Condition: Our examination of the Department of Human Services’ (DHS) procedures for monitoring Social Services Block Grant (SSBG) subrecipients revealed that DHS did not adequately monitor the SSBG Mental Health, Homeless Services, Child Welfare, Domestic Violence, Rape Crisis, Legal Services, and Family Planning subrecipients to ensure that SSBG awards are used in compliance with laws and regulations, which include allowable costs, period of performance, and other requirements. The inadequately monitored subrecipients received $41.0 million (or approximately 44 percent) of total SSBG program expenditures of $92.7 million reported on the Schedule of Expenditures of Federal Awards (SEFA). While we did note that DHS adequately monitored six of the 55 Mental Health County/County Joinder subrecipients which included Mental Health, Homeless Services and Child Welfare services, this coverage is not adequate. In addition, our review of the risk assessments completed for all of the aforementioned subrecipients identified several instances where subrecipient monitoring was warranted but was not conducted. No monitoring was performed on the Domestic Violence, Rape Crisis, Legal Services and Family Planning subrecipients. In addition, for the compliance requirement related to cash management, we noted that DHS advanced funds to SSBG subrecipients in four of nine program areas, representing $34.0 million (or approximately 37 percent) of SSBG program expenditures, without adequately monitoring the reasonableness of the subrecipient cash balances. In particular, for the program areas related to Mental Health, Intellectual Disabilities, Homeless Services, and Child Welfare, DHS advanced funds to subrecipients on a quarterly basis. Our inquiries with applicable DHS program administrators disclosed that DHS did not adequately monitor the four program areas’ subrecipients for cash management compliance either at the time of payment or at any other time during the fiscal year ended June 30, 2023. Furthermore, while Single Audits of SSBG subrecipients may be conducted each year, this auditing activity does not compensate for the lack of during-the-award program monitoring, since the timing, focus, and scope of subrecipient auditing activities after year end are different than compliance monitoring to be performed by program officials during the year. Criteria: 45 CFR Section 75.352, Requirements for pass-through entities, states: (d) Monitor the activities of the subrecipient as necessary to ensure that the subaward is used for authorized purposes, in compliance with Federal statutes, regulations, and the terms and conditions of the subaward; and that subaward performance goals are achieved. Pass-through entity monitoring of the subrecipient must include: (1) Reviewing financial and performance reports required by the pass-through entity. (2) Following-up and ensuring that the subrecipient takes timely and appropriate action on all deficiencies pertaining to the Federal award provided to the subrecipient from the pass-through entity detected through audits, on-site reviews, and other means. (3) Issuing a management decision for audit findings pertaining to the Federal award provided to the subrecipient from the pass-through entity… Finding 2023 –¬ 015: (continued) (e) Depending upon the pass-through entity's assessment of risk posed by the subrecipient (as described in paragraph (b) of this section), the following monitoring tools may be useful for the pass-through entity to ensure proper accountability and compliance with program requirements and achievement of performance goals: (1) Providing subrecipients with training and technical assistance on program-related matters; and (2) Performing on-site reviews of the subrecipient's program operations; (3) Arranging for agreed-upon-procedures engagements as described in §75.425 (Audit services). 45 CFR Section 75.305(b)(1), applicable to payments to subrecipients, states in part: …Advance payments to a non-Federal entity must be limited to the minimum amounts needed and be timed to be in accordance with the actual, immediate cash requirements of the non-Federal entity in carrying out the purpose of the approved program or project. The timing and amount of advance payments must be as close as is administratively feasible to the actual disbursements by the non-Federal entity for direct program or project costs and the proportionate share of any allowable indirect costs. The non-Federal entity must make timely payment to contractors in accordance with the contract provisions. Management Directive 325.12, Amended – Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office’s Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: DHS management indicated that risk assessment and monitoring documents were created for use during on-site monitoring of SSBG subrecipients. However, due to staffing issues, on-site monitoring was not performed for all SSBG subrecipients. Consistent with prior year audits, DHS management noted that there have been no changes to the payment methodology for the Homeless Services, Mental Health, Intellectual Disabilities, and Child Welfare components of SSBG. These programs provide subrecipients with advances to comply with Commonwealth law and also to ensure that adequate funds are available to provide services to participants on a timely basis. DHS officials believe that their in-house payment review procedures for the SSBG program are as efficient as administratively feasible and that controls exist in each of the program areas. Without on-site program monitoring visits by funding agency officials, we consider DHS’s limited in-house reviews of subrecipient status reports or other documents to be insufficient to detect potential subrecipient noncompliance, including excess cash violations. DHS does not adjust payments to the subrecipients based on in-house reviews. Effect: Since DHS does not adequately perform during-the-award monitoring of subrecipients, including the monitoring of subrecipient cash on hand, subrecipients may not be complying with applicable grant requirements and federal regulations, including cash management standards. Recommendation: DHS should perform risk based during-the-award monitoring procedures and risk assessments for all SSBG subrecipients to ensure timely compliance with all applicable federal regulations. On-site monitoring visits by state officials should be supported by documentation to show the monitoring performed, areas examined, conclusions reached, and that the monitoring was performed in compliance with applicable regulations. Finding 2023 –¬ 015: (continued) As recommended in previous Single Audits and supported by the United States Department of Health and Human Services, DHS should either consider changing their current subrecipient payment procedures from advancement basis to reimbursement basis or establish procedures to adequately monitor subrecipient cash on hand to ensure it is limited to immediate needs, but no longer than one month. The implementation and strengthening of these controls should provide DHS with reasonable assurance as to compliance with cash management requirements at the subrecipient level. Agency Response: DHS agrees with this finding. Questioned Costs: The amount of questioned costs cannot be determined.

Corrective Action Plan

Office of Admin.–SSBG: The Bureau of Financial Operations (BFO) will continue conducting during-the-award subrecipient monitoring for the SSBG based on the results of the documented risk assessment. As it relates to the cash management portion of the finding, given the relatively small amount of funds involved and the number of counties affected, DHS has determined that it is not economically feasible to change the payment methodology at this time. Anticipated Completion Date: 06/30/2024 Contact Name: Kelly Graham, Director, Div. of Financial Policy and Operations OPD-SSBG: Due to the COVID-19 global pandemic as well as staff turnover and vacancies in OPD, regular monitoring of SSBG grant recipients was not performed on schedule. However, with the hiring of a full complement of staff for the DHS Policy Office, including a Grant Administrator, we are in the process of creating and implementing a robust monitoring plan for all 19 of our grantees for calendar year 2024, including in-person monitoring, desk monitoring, data collection, and analysis. Anticipated Completion Date: 12/31/2024 Contact Name: Jessica Schneider, Exec. Policy Specialist I, Grants

About Cash Management, Subrecipient Monitoring →
2023-016
Special Tests & Provisions
REPEAT

The Pennsylvania Department of Human Services (DHS) is required by the United States Department of Health and Human Services (HHS), Centers for Medicare and Medicaid Services (CMS), to implement six required Medicaid NCCI methodologies. These methodologies include procedure-to-procedure and medically unlikely edits of Medicaid fee-for-service claims submitted for processing through DHS’s PROMISe system to ensure that only proper payments of Medicaid procedures are reimbursed. As part of this process, DHS is required to download quarterly NCCI edit tables from CMS which are subsequently uploaded into PROMISe by DHS’s PROMISe vendor. During the fiscal year ended June 30, 2023, DHS did not ensure that its contract and amendments with the PROMISe vendor included one of the seven elements of the NCCI Confidentiality Agreement required by the HHS/CMS Medicaid NCCI Technical Guidance Manual. The one element missing was: • Only a state Medicaid agency has the discretion to release additional information for selected individual edits or limited ranges of edits from the files posted on the secure RISSNET portal. Criteria: Management Directive 325.12, Amended – Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office’s Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should identify, analyze, and respond to significant changes that could impact the internal control system. The HHS/CMS Medicaid NCCI Technical Guidance Manual, Section 7.1.2, Sharing of State Medicaid NCCI Edit Files by States with Other Entities, states in part: A state Medicaid agency may share these quarterly state Medicaid NCCI edit files which are posted on the secure RISSNET [Regional Information Sharing System Network] portal with the contracted fiscal agent that processes its FFS [fee-for-service] claims or with any of its contracted Medicaid managed-care entities that is using the Medicaid NCCI methodologies in its processing of claims or encounter data, if appropriate confidentiality agreements are in place. The HHS/CMS Medicaid NCCI Technical Guidance Manual, Section 7.1.3, Confidentiality Agreements Requirements for Contracted Parties, states: At a minimum, the following elements must be included in the confidentiality agreements for any contracted party using the Medicaid NCCI files posted on the secure RISSNET portal: Disclosure shall be limited to only those responsible for the implementation of the quarterly state Medicaid NCCI edit files. Finding 2023 –¬ 016: (continued) After the start of the new calendar quarter, a contracted party may disclose only non-confidential information contained in the Medicaid NCCI edit files that is also available to the general public found on the NCCI Medicaid webpage. The contracted party agrees to use any non-public information from the quarterly state Medicaid NCCI edit files only for any business purposes directly related to the implementation of the Medicaid NCCI methodologies in the particular state. New, revised, or deleted Medicaid NCCI edits shall not be published or otherwise shared with individuals, medical societies, or any other entities unless it is a contracted party prior to the posting of the Medicaid NCCI edits on the NCCI Medicaid webpage. Implementation of new, revised, or deleted Medicaid NCCI edits shall not occur prior to the first day of the calendar quarter. Only a state Medicaid agency has the discretion to release additional information for selected individual edits or limited ranges of edits from the files posted on the secure RISSNET portal. State Medicaid agencies must impose penalties, up to and including loss of contract, for violations of any confidentiality agreement relating to use of the secure RISSNET portal edit files. Cause: In amendments in 2022 and 2023, DHS personnel added six of the seven confidentiality agreement elements required by the HHS/CMS Medicaid NCCI Technical Guidance Manual to the PROMISe vendor contract amendment but did not add the remaining one element in the 2023 amendment. DHS believed the 2023 amendment along with the existing contract included all of the missing elements. Effect: Since DHS did not ensure one of the seven elements of the required NCCI confidentiality agreement was included in its contract with the PROMISe vendor, DHS was not in compliance with federal regulations. Recommendation: DHS should ensure the one missing element of the required NCCI confidentiality agreement is included in an amendment to its contract with the PROMISe vendor. Agency Response: DHS agrees with this finding. Questioned Costs: None

Show full finding ▾
Full finding narrative

Department of Human Services Finding 2023 –¬ 016: ALN 93.775, 93.777, and 93.778 – Medicaid Cluster (including COVID-19) A Significant Deficiency and Noncompliance Exist at the Department of Human Services Related to the Medicaid National Correct Coding Initiative (A Similar Condition Was Noted in Prior Year Finding 2022-009) Federal Grant Number(s) and Year(s): 2205PA5MAP (10/01/2022 – 9/30/2023), 2205PA5ADM (10/01/2022 – 9/30/2023), 2105PA5MAP (10/01/2021 – 9/30/2022), 2105PA5ADM (10/01/2021 – 9/30/2022) Type of Finding: Significant Deficiency in Internal Control over Compliance, Other Matters Compliance Requirement: Special Tests and Provisions related to the Medicaid National Correct Coding Initiative (NCCI) Condition: The Pennsylvania Department of Human Services (DHS) is required by the United States Department of Health and Human Services (HHS), Centers for Medicare and Medicaid Services (CMS), to implement six required Medicaid NCCI methodologies. These methodologies include procedure-to-procedure and medically unlikely edits of Medicaid fee-for-service claims submitted for processing through DHS’s PROMISe system to ensure that only proper payments of Medicaid procedures are reimbursed. As part of this process, DHS is required to download quarterly NCCI edit tables from CMS which are subsequently uploaded into PROMISe by DHS’s PROMISe vendor. During the fiscal year ended June 30, 2023, DHS did not ensure that its contract and amendments with the PROMISe vendor included one of the seven elements of the NCCI Confidentiality Agreement required by the HHS/CMS Medicaid NCCI Technical Guidance Manual. The one element missing was: • Only a state Medicaid agency has the discretion to release additional information for selected individual edits or limited ranges of edits from the files posted on the secure RISSNET portal. Criteria: Management Directive 325.12, Amended – Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office’s Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should identify, analyze, and respond to significant changes that could impact the internal control system. The HHS/CMS Medicaid NCCI Technical Guidance Manual, Section 7.1.2, Sharing of State Medicaid NCCI Edit Files by States with Other Entities, states in part: A state Medicaid agency may share these quarterly state Medicaid NCCI edit files which are posted on the secure RISSNET [Regional Information Sharing System Network] portal with the contracted fiscal agent that processes its FFS [fee-for-service] claims or with any of its contracted Medicaid managed-care entities that is using the Medicaid NCCI methodologies in its processing of claims or encounter data, if appropriate confidentiality agreements are in place. The HHS/CMS Medicaid NCCI Technical Guidance Manual, Section 7.1.3, Confidentiality Agreements Requirements for Contracted Parties, states: At a minimum, the following elements must be included in the confidentiality agreements for any contracted party using the Medicaid NCCI files posted on the secure RISSNET portal: Disclosure shall be limited to only those responsible for the implementation of the quarterly state Medicaid NCCI edit files. Finding 2023 –¬ 016: (continued) After the start of the new calendar quarter, a contracted party may disclose only non-confidential information contained in the Medicaid NCCI edit files that is also available to the general public found on the NCCI Medicaid webpage. The contracted party agrees to use any non-public information from the quarterly state Medicaid NCCI edit files only for any business purposes directly related to the implementation of the Medicaid NCCI methodologies in the particular state. New, revised, or deleted Medicaid NCCI edits shall not be published or otherwise shared with individuals, medical societies, or any other entities unless it is a contracted party prior to the posting of the Medicaid NCCI edits on the NCCI Medicaid webpage. Implementation of new, revised, or deleted Medicaid NCCI edits shall not occur prior to the first day of the calendar quarter. Only a state Medicaid agency has the discretion to release additional information for selected individual edits or limited ranges of edits from the files posted on the secure RISSNET portal. State Medicaid agencies must impose penalties, up to and including loss of contract, for violations of any confidentiality agreement relating to use of the secure RISSNET portal edit files. Cause: In amendments in 2022 and 2023, DHS personnel added six of the seven confidentiality agreement elements required by the HHS/CMS Medicaid NCCI Technical Guidance Manual to the PROMISe vendor contract amendment but did not add the remaining one element in the 2023 amendment. DHS believed the 2023 amendment along with the existing contract included all of the missing elements. Effect: Since DHS did not ensure one of the seven elements of the required NCCI confidentiality agreement was included in its contract with the PROMISe vendor, DHS was not in compliance with federal regulations. Recommendation: DHS should ensure the one missing element of the required NCCI confidentiality agreement is included in an amendment to its contract with the PROMISe vendor. Agency Response: DHS agrees with this finding. Questioned Costs: None

Corrective Action Plan

Office of Medical Assistance Programs’ Bureau of Data and Claims Management (BDCM) is currently negotiating an amendment to the PROMISe contract with Gainwell Technologies. The amendment will modify the NCCI performance requirement to include a statement equivalent to “Only a state Medicaid agency has the discretion to release additional information for selected individual edits or limited ranges of edits from the files posted on the secure RISSNET portal.” Anticipated Completion Date: 06/30/2024 Contact Name: Toni Hoffecker, Dir., Div. of Systems, Monitoring and Oversight, BDCM

Prior Finding References

2022-009

About Special Tests and Provisions →
2023-017
Other

As part of testing internal controls over the Vocational Rehabilitation Grants to States program, we performed certain tests of information technology (IT) general controls over a computer application used by the Department of Labor and Industry, Office of Vocational Rehabilitation (OVR) and supported by the Office of Administration – Office for Information Technology (OA-OIT) – Employment, Banking and Revenue (EBR) Delivery Center. During our testing we noted that an inappropriate application administrator role was assigned to 19 users who did not require the role to perform their job duties. Details of this issue have been provided to OVR and the EBR Delivery Center for corrective action. Criteria: Management Directive 325.12, Amended – Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office’s Standards for Internal Control in the Federal Government (Green Book). • Green Book Principle 11 – Design Activities for the Information System, states in part: o 11.12 Management designs control activities over access to protect an entity from inappropriate access and unauthorized use of the system. These control activities support appropriate segregation of duties. By preventing unauthorized use of and changes to the system, data and program integrity are protected from malicious intent (e.g., someone breaking into the technology to commit fraud, vandalism, or terrorism) or error. o 11.14 Management designs control activities to limit user access to information technology through authorization control activities, such as providing a unique user identification or token to authorized users. These control activities may restrict authorized users to the applications or functions commensurate with their assigned responsibilities, supporting an appropriate segregation of duties. Management designs other control activities to promptly update access rights when employees change job functions or leave the entity. Information Technology Policy – OPD SEC007a – Configurations for IDs, Passwords, and Multi-Factor Authentication, revised July 12, 2022, section 3.7 states, in part, • Least privileged. By default, all accounts should be assigned the lowest level of permissions. If elevated permissions are required a change request should be submitted and approved before elevated permissions are granted to any account. A well-designed system of internal controls dictates that effective IT general controls, which includes access controls to programs and data, be established and functioning to ensure that overall agency operations are conducted in accordance with management’s intent. Finding 2023 –¬ 017: (continued) Cause: OVR management requested the privileged role be added to the profiles of the 19 users to allow the users to resolve an access issue. Rather than creating a new role designed to narrowly accommodate the access needs of the users, the existing process followed by an EBR Delivery Center Systems administrator granted an existing privileged role to the users that also gave them the ability to add and delete users from the application as well as assign other powerful roles. Further, OVR’s periodic review of user access performed during the audit period failed to identify the additional permissions granted by the use of the privileged role assignments. The inappropriate role was removed from the users’ profiles after the audit period once the auditors pointed out the issue. Effect: Assigning inappropriate access to users could result in unauthorized changes to the application and data, misuse of the application, or system actions outside management’s intent, which could result in noncompliance with federal laws and regulations. Further, without properly functioning IT general controls, the auditors are precluded from reliance on computer controls in the Rehabilitation Services program. Recommendation: We recommend that OVR management and EBR Delivery Center management work together to: • Update the user access request form to clarify the circumstances under which privileged roles may be assigned to application users; • Provide training to personnel on the Commonwealth policy noted above requiring least privilege; • Consider creating new privileged roles that allow administrators to assign the lowest level of permissions; • Consider creating a process to grant temporary access to administrative roles in special situations; and • Ensure the periodic access reviews of users include an assessment of the appropriateness of role assignments. Agency Response: Department of Labor and Industry – Office of Vocational Rehabilitation and the Office of Administration – Office for Information Technology – Employment, Banking and Revenue Delivery Center agree with the finding. Questioned Costs: None

Show full finding ▾
Full finding narrative

Department of Labor and Industry Office of Administration – Office for Information Technology – Employment, Banking and Revenue Delivery Center Finding 2023 –¬ 017: ALN 84.126 – Rehabilitation Services – Vocational Rehabilitation Grants to States Inappropriate Privileged Access Granted to Program Personnel Federal Grant Number(s) and Year(s): – H126A220056 (10/01/2020 – 9/30/2021), H126A230056 (10/01/2021 – 9/30/2022), H126A230056 (10/01/2022 – 9/30/2023) Type of Finding: Significant Deficiency in Internal Control over Compliance Compliance Requirement: Other Condition: As part of testing internal controls over the Vocational Rehabilitation Grants to States program, we performed certain tests of information technology (IT) general controls over a computer application used by the Department of Labor and Industry, Office of Vocational Rehabilitation (OVR) and supported by the Office of Administration – Office for Information Technology (OA-OIT) – Employment, Banking and Revenue (EBR) Delivery Center. During our testing we noted that an inappropriate application administrator role was assigned to 19 users who did not require the role to perform their job duties. Details of this issue have been provided to OVR and the EBR Delivery Center for corrective action. Criteria: Management Directive 325.12, Amended – Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office’s Standards for Internal Control in the Federal Government (Green Book). • Green Book Principle 11 – Design Activities for the Information System, states in part: o 11.12 Management designs control activities over access to protect an entity from inappropriate access and unauthorized use of the system. These control activities support appropriate segregation of duties. By preventing unauthorized use of and changes to the system, data and program integrity are protected from malicious intent (e.g., someone breaking into the technology to commit fraud, vandalism, or terrorism) or error. o 11.14 Management designs control activities to limit user access to information technology through authorization control activities, such as providing a unique user identification or token to authorized users. These control activities may restrict authorized users to the applications or functions commensurate with their assigned responsibilities, supporting an appropriate segregation of duties. Management designs other control activities to promptly update access rights when employees change job functions or leave the entity. Information Technology Policy – OPD SEC007a – Configurations for IDs, Passwords, and Multi-Factor Authentication, revised July 12, 2022, section 3.7 states, in part, • Least privileged. By default, all accounts should be assigned the lowest level of permissions. If elevated permissions are required a change request should be submitted and approved before elevated permissions are granted to any account. A well-designed system of internal controls dictates that effective IT general controls, which includes access controls to programs and data, be established and functioning to ensure that overall agency operations are conducted in accordance with management’s intent. Finding 2023 –¬ 017: (continued) Cause: OVR management requested the privileged role be added to the profiles of the 19 users to allow the users to resolve an access issue. Rather than creating a new role designed to narrowly accommodate the access needs of the users, the existing process followed by an EBR Delivery Center Systems administrator granted an existing privileged role to the users that also gave them the ability to add and delete users from the application as well as assign other powerful roles. Further, OVR’s periodic review of user access performed during the audit period failed to identify the additional permissions granted by the use of the privileged role assignments. The inappropriate role was removed from the users’ profiles after the audit period once the auditors pointed out the issue. Effect: Assigning inappropriate access to users could result in unauthorized changes to the application and data, misuse of the application, or system actions outside management’s intent, which could result in noncompliance with federal laws and regulations. Further, without properly functioning IT general controls, the auditors are precluded from reliance on computer controls in the Rehabilitation Services program. Recommendation: We recommend that OVR management and EBR Delivery Center management work together to: • Update the user access request form to clarify the circumstances under which privileged roles may be assigned to application users; • Provide training to personnel on the Commonwealth policy noted above requiring least privilege; • Consider creating new privileged roles that allow administrators to assign the lowest level of permissions; • Consider creating a process to grant temporary access to administrative roles in special situations; and • Ensure the periodic access reviews of users include an assessment of the appropriateness of role assignments. Agency Response: Department of Labor and Industry – Office of Vocational Rehabilitation and the Office of Administration – Office for Information Technology – Employment, Banking and Revenue Delivery Center agree with the finding. Questioned Costs: None

Corrective Action Plan

1. The role was removed from the users’ profiles after the audit period, once the auditors pointed out the issue. 2. Update the user access request form to clarify the circumstances under which privileged roles may be assigned to application users. 3. Evaluate if there is a need for a new role; and if there is not an existing role to accomplish existing job duties, then we can look to create new privileged roles that allow administrators to assign the lowest level of permission required. 4. The program area will perform quarterly periodic access reviews of privileged (admin) role users to include an assessment of the appropriateness of role assignments. 5. The program area will conduct a review of all OVR staff user roles to include an assessment of the appropriateness of role assignments on an annual basis. Anticipated Completion Dates: 1 - Completed; 2 - 06/30/2024; 3, 4, 5 - Ongoing Contact Name: William McLean Jr., Chief, Workforce Development and Information Division, OA-OIT

About Other →
2023-018
Period of Performance
QUESTIONED COSTS

During our audit of the Rehabilitation Services – Vocational Rehabilitation Grants to States (RS-VR) program, we tested internal control over and compliance with period of performance requirements for the grant awarded by the United States Department of Education that had a period of performance date ending during the fiscal year ended June 30, 2023 audit period. • Two of 55 expenditures tested that were charged to the federal fiscal year 2021 RS-VR grant that closed during the audit period, were incurred after the allowable period of performance. These expenditures included two rental payments totaling $8,763. Both payments were for November 2022 rental charges but were charged to the grant which had a period end date of September 30, 2022. Expenditures posted in the last month of the allowable period of performance and after (including the two rental payments) totaled $36,651,862. Management was unable to provide authorization from the federal awarding agency for allowance of the expenditures occurring outside of the period of performance. Criteria: 2 CFR Section 200.303(a), Internal controls, states: The non-Federal entity must: Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). 2 CFR Section 200.309, Period of performance, states: A non-Federal entity may charge to the Federal award only allowable costs incurred during the period of performance (except as described in §200.461 Publication and printing costs) and any costs incurred before the Federal awarding agency or pass-through entity made the award that were authorized by the Federal awarding agency or pass-through entity. Management Directive 325.12, Amended, Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office’s Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Finding 2023 – 018: (continued) Cause: Office of Vocational Rehabilitation (OVR), Pennsylvania Department of Labor and Industry personnel did not check service dates prior to submitting invoices for payment which were charged to the federal fiscal year 2021 grant. OVR personnel did not have adequate procedures in place to ensure that only costs incurred during the allowable period of performance were charged to the grant. Effect: Expenditures outside of the allowable period of performance were incorrectly charged to the grant without authorization by the federal awarding agency, resulting in noncompliance and questioned costs. Recommendation: We recommend that OVR personnel implement procedures to ensure that costs and adjustments being charged to a federal grant are incurred within the allowable period of performance of the grant to which they are being charged, or when necessary, obtain authorization from the federal awarding agency prior to charging costs that are outside the allowable period of performance. Agency Response: OVR agrees with this finding. Questioned Costs: Known questioned costs of $8,763 were determined, which represents the amount of transactions incurred and charged to the federal grant outside the allowable period of performance.

Show full finding ▾
Full finding narrative

Department of Labor and Industry Finding 2023 – 018: ALN 84.126 – Rehabilitation Services – Vocational Rehabilitation Grants to States A Significant Deficiency and Noncompliance Exist in the Department of Labor and Industry’s Procedures Related to Period of Performance Requirements Federal Grant Number(s) and Year(s): H126A210056 (10/01/2020 – 9/30/2022) Type of Finding: Significant Deficiency in Internal Control over Compliance, Other Matters Compliance Requirement: Period of Performance Condition: During our audit of the Rehabilitation Services – Vocational Rehabilitation Grants to States (RS-VR) program, we tested internal control over and compliance with period of performance requirements for the grant awarded by the United States Department of Education that had a period of performance date ending during the fiscal year ended June 30, 2023 audit period. • Two of 55 expenditures tested that were charged to the federal fiscal year 2021 RS-VR grant that closed during the audit period, were incurred after the allowable period of performance. These expenditures included two rental payments totaling $8,763. Both payments were for November 2022 rental charges but were charged to the grant which had a period end date of September 30, 2022. Expenditures posted in the last month of the allowable period of performance and after (including the two rental payments) totaled $36,651,862. Management was unable to provide authorization from the federal awarding agency for allowance of the expenditures occurring outside of the period of performance. Criteria: 2 CFR Section 200.303(a), Internal controls, states: The non-Federal entity must: Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). 2 CFR Section 200.309, Period of performance, states: A non-Federal entity may charge to the Federal award only allowable costs incurred during the period of performance (except as described in §200.461 Publication and printing costs) and any costs incurred before the Federal awarding agency or pass-through entity made the award that were authorized by the Federal awarding agency or pass-through entity. Management Directive 325.12, Amended, Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office’s Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Finding 2023 – 018: (continued) Cause: Office of Vocational Rehabilitation (OVR), Pennsylvania Department of Labor and Industry personnel did not check service dates prior to submitting invoices for payment which were charged to the federal fiscal year 2021 grant. OVR personnel did not have adequate procedures in place to ensure that only costs incurred during the allowable period of performance were charged to the grant. Effect: Expenditures outside of the allowable period of performance were incorrectly charged to the grant without authorization by the federal awarding agency, resulting in noncompliance and questioned costs. Recommendation: We recommend that OVR personnel implement procedures to ensure that costs and adjustments being charged to a federal grant are incurred within the allowable period of performance of the grant to which they are being charged, or when necessary, obtain authorization from the federal awarding agency prior to charging costs that are outside the allowable period of performance. Agency Response: OVR agrees with this finding. Questioned Costs: Known questioned costs of $8,763 were determined, which represents the amount of transactions incurred and charged to the federal grant outside the allowable period of performance.

Corrective Action Plan

The final report for the grant H126A210056 has already been submitted to the RSA. No changes can be made to the RSA report at this point. A reconciliation process has been introduced which will eliminate period of performance (POP) violations for the current/future grants. Currently, OVR is using this method to ensure correction of POP violations for the current VR grants (if any). Adjusting entries to correct the POP violation in SAP will be posted by 04/15/2024 subject to the approval of OB-OCO to open the closed internal orders of the grant. Anticipated Completion Date: 04/15/2024 Contact Name: Zulqarnain Nasir, Chief Financial Officer, OVR

About Period of Performance →
2023-019
Reporting

The Office of Vocational Rehabilitation (OVR), Pennsylvania Department of Labor and Industry, is required to submit an RSA-17, Vocational Rehabilitation Financial Report, for the Rehabilitation Services – Vocational Rehabilitation Grants to States (RS-VR) program to the United States Department of Education (USDE) on a quarterly basis. The RSA-17 report includes data related to the federal share of expenditures to date, the federal share of unliquidated obligations, the federal program income earned, the program income expended and unexpended, indirect charges to the grant, as well as other general information that is necessary to ensure compliance with program requirements. During the fiscal year ended June 30, 2023, we selected all RSA-17 reports submitted for two of the four quarters and the final report submitted for the grant that closed during the audit period for testing. As part of the report testing, we obtained supporting general ledger documentation to determine if the agency appropriately reported the data in the Rehabilitation Services Administration (RSA) system where the RSA-17 reports are submitted. Our testing disclosed that the Business Enterprise Program expenditures reported on the June 30, 2023 filing for Federal Grant H126A230056 were not correctly input into the RSA system. The amount reported was $26,409,010, when actual expenditures were $264,090 based on supporting documentation. Although the RSA-17 report was subjected to a documented supervisory review and approval, the incorrect reported amount remained undetected by Commonwealth management until notification by the auditor. Criteria: 2 CFR Section 200.303(a), Internal controls, states: The non-Federal entity must: Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the committee of the Sponsoring Organizations of the Treadway Commission (COSO). 34 CFR Section 361.40, Reports; Evaluation standards and performance indicators, states: (a) Reports. (1) The vocational rehabilitation services portion of the Unified or Combined State Plan must assure that the designated State agency will submit reports, including reports required under sections 13, 14, and 101(a)(10) of the Act – (i) In the form and level of detail and at the time required by the Secretary regarding applicants for and eligible individuals receiving services, including students receiving pre-employment transition services in accordance with section 361.48(a); and Finding 2023 – 019: (continued) (ii) In a manner that provides a complete count (other than the information obtained through sampling consistent with section 101(a)(10)(E) of the Act) of the applicants and eligible individuals to – (A) Permit the greatest possible cross-classification of data; and (B) Protect the confidentiality of the identity of each individual. (2) The designated State agency must comply with any requirements necessary to ensure the accuracy and verification of those reports. Management Directive 325.12, Amended, Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office’s Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: Bureau of Accounting and Financial Management personnel did not review the data input into the RSA system for errors prior to submission of the report. OVR did not have adequate procedures in place to ensure accurate report submissions as prepared by Bureau of Accounting and Financial Management. Effect: Since the report preparation and the supervisory review and approval process were not adequate, the Business Enterprise Program expenditures were incorrectly reported on the RSA-17 report submitted to USDE. OVR was not in compliance with federal regulations. Recommendation: OVR should ensure their written procedures for the review, approval, and submission of the RSA-17 reports are improved and fully implemented. The procedures should have sufficient detail to ensure the RSA-17 reports are prepared accurately and in accordance with federal regulations. In addition, OVR should correct the error and submit a revised RSA-17 report to USDE. OVR Response: OVR agrees with this finding. OCO Response: OCO agrees with this finding. Questioned Costs: None

Show full finding ▾
Full finding narrative

Department of Labor and Industry Office of the Budget – Office of Comptroller Operations Finding 2023 – 019: ALN 84.126 – Rehabilitation Services – Vocational Rehabilitation Grants to States A Significant Deficiency and Noncompliance Exist Related to the Preparation and Submission of the Quarterly RSA-17 Report Federal Grant Number(s) and Year(s): H126A230056 (10/01/2022 – 9/30/2023) Type of Finding: Significant Deficiency in Internal Control over Compliance, Other Matters Compliance Requirement: Reporting Condition: The Office of Vocational Rehabilitation (OVR), Pennsylvania Department of Labor and Industry, is required to submit an RSA-17, Vocational Rehabilitation Financial Report, for the Rehabilitation Services – Vocational Rehabilitation Grants to States (RS-VR) program to the United States Department of Education (USDE) on a quarterly basis. The RSA-17 report includes data related to the federal share of expenditures to date, the federal share of unliquidated obligations, the federal program income earned, the program income expended and unexpended, indirect charges to the grant, as well as other general information that is necessary to ensure compliance with program requirements. During the fiscal year ended June 30, 2023, we selected all RSA-17 reports submitted for two of the four quarters and the final report submitted for the grant that closed during the audit period for testing. As part of the report testing, we obtained supporting general ledger documentation to determine if the agency appropriately reported the data in the Rehabilitation Services Administration (RSA) system where the RSA-17 reports are submitted. Our testing disclosed that the Business Enterprise Program expenditures reported on the June 30, 2023 filing for Federal Grant H126A230056 were not correctly input into the RSA system. The amount reported was $26,409,010, when actual expenditures were $264,090 based on supporting documentation. Although the RSA-17 report was subjected to a documented supervisory review and approval, the incorrect reported amount remained undetected by Commonwealth management until notification by the auditor. Criteria: 2 CFR Section 200.303(a), Internal controls, states: The non-Federal entity must: Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the committee of the Sponsoring Organizations of the Treadway Commission (COSO). 34 CFR Section 361.40, Reports; Evaluation standards and performance indicators, states: (a) Reports. (1) The vocational rehabilitation services portion of the Unified or Combined State Plan must assure that the designated State agency will submit reports, including reports required under sections 13, 14, and 101(a)(10) of the Act – (i) In the form and level of detail and at the time required by the Secretary regarding applicants for and eligible individuals receiving services, including students receiving pre-employment transition services in accordance with section 361.48(a); and Finding 2023 – 019: (continued) (ii) In a manner that provides a complete count (other than the information obtained through sampling consistent with section 101(a)(10)(E) of the Act) of the applicants and eligible individuals to – (A) Permit the greatest possible cross-classification of data; and (B) Protect the confidentiality of the identity of each individual. (2) The designated State agency must comply with any requirements necessary to ensure the accuracy and verification of those reports. Management Directive 325.12, Amended, Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office’s Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: Bureau of Accounting and Financial Management personnel did not review the data input into the RSA system for errors prior to submission of the report. OVR did not have adequate procedures in place to ensure accurate report submissions as prepared by Bureau of Accounting and Financial Management. Effect: Since the report preparation and the supervisory review and approval process were not adequate, the Business Enterprise Program expenditures were incorrectly reported on the RSA-17 report submitted to USDE. OVR was not in compliance with federal regulations. Recommendation: OVR should ensure their written procedures for the review, approval, and submission of the RSA-17 reports are improved and fully implemented. The procedures should have sufficient detail to ensure the RSA-17 reports are prepared accurately and in accordance with federal regulations. In addition, OVR should correct the error and submit a revised RSA-17 report to USDE. OVR Response: OVR agrees with this finding. OCO Response: OCO agrees with this finding. Questioned Costs: None

Corrective Action Plan

L&I: A request has been made to RSA for the correction of the report. A correction will be made by OB-OCO once the report is open. To avoid typographical errors in the future, the CFO and the Division Chief of Budget and Admin will review the report after submission by OB-OCO to ensure the submission is correct. Anticipated Completion Date: 04/15/2024 Contact Name: Zulqarnain Nasir, Chief Financial Officer, OVR, L&I OB-OCO: • General Accounting revised our procedures to include having both the reviewer and preparer match the PDF output to the final Excel spreadsheet. • General Accounting discussed this finding and procedure change with the applicable staff on February 28, 2024 and February 29, 2024. • OVR has requested that the USDE unlock the RSA-17 Report for editing. General Accounting will submit a revised RSA-17 report to USDE once the report is unlocked. Anticipated Completion Date: 04/15/2024 Contact Names: Carson Buck, Commw. Accountant Manager; Kathleen Bolick, Accountant 3

About Reporting →
2023-020
Reporting

Two of 4 quarterly Project and Expenditure Reports were selected for testing. The Office of the Budget, Governor’s Budget Office (GBO) reported incomplete capital project information in these quarterly reports. Specifically, the following exceptions were noted: • A project’s description allows capital expenditures by beneficiaries, but GBO has reported it as a non-capital project on both quarterly Project and Expenditure reports. In addition, the Pennsylvania Emergency Management Agency (PEMA) does not require the beneficiaries receiving funding under this project to report their capital expenditures to PEMA. Therefore, GBO is unable to determine the amount of capital expenditures obligated and expended for this project. • A capital project in excess of $10 million was reported as a non-capital project on the March 31, 2023 quarterly report. GBO believes they correctly reported the project as a capital project, but the reporting portal incorrectly recorded their submission. However, GBO was unable to provide documentation that the project was identified as a capital project in their submission to the U.S. Treasury. • On the June 30, 2023 quarterly report, the project was correctly reported as a capital project and the required written justification was included, however, the justification did not include all required elements. Criteria: Per the Compliance and Reporting Guidance issued by the United States Department of the Treasury, recipients must report if a project includes capital expenditures, the type of capital expenditure, and the amount of capital expenditures obligated and expended. Per 31 CFR Section 35.6(b)(4), a recipient, other than a Tribal government, must prepare written justifications for capital projects with capital expenditures enumerated by Treasury in the final rule and with total capital expenditures greater than $10 million. Such written justifications must include the following elements: (i) Describe the harm or need to be addressed; (ii) Explain why a capital expenditure is appropriate; and (iii) Compare the proposed capital expenditure to at least two alternative capital expenditures and demonstrate why the proposed capital expenditure is superior. Management Directive 325.12, Amended – Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office’s Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Finding 2023 –¬ 020: (continued) Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: PEMA issued awards to 666 local Emergency Management Services (EMS) companies and the companies were allowed to expend the funds on a variety of uses, including capital expenditures. PEMA did not obtain detail of capital expenditures incurred from the companies and was therefore unable to provide the information to GBO for inclusion on the Project and Expenditure Reports. The required elements for capital project justifications are summarized on page 4390 of the Final Rule, but they are not mentioned in the Project and Expenditure Report User Guide nor in the Compliance and Reporting Guidance. Therefore, GBO was unaware that it was necessary to include specific elements in the justification. Effect: GBO did not properly identify and report capital projects. Errors included omitting capital project obligations and expenditures and incomplete justifications for a capital project greater than $10 million. Recommendation: We recommend that GBO ensures that all capital projects are properly reported and that justifications for capital projects greater than $10 million include all required elements. We further recommend that PEMA beneficiaries be required to submit expenditure detail to allow GBO to correctly report capital expenditures obligated and expended. Agency Response: GBO agrees with this finding. Limitations in the federal reporting portal, changing federal guidance, and the nature of programs being implemented which may be used for capital expenditures and a myriad of other non-capital uses complicates reporting compliance. Questioned Costs: None

Show full finding ▾
Full finding narrative

Office of the Budget – Governor’s Budget Office Finding 2023 –¬ 020: ALN 21.027 – COVID-19 – Coronavirus State and Local Fiscal Recovery Funds A Significant Deficiency and Noncompliance Exist at the Governor’s Budget Office Related to the Quarterly Project and Expenditure Report Federal Grant Number(s) and Year(s): TN75GJE1S7G3 (3/03/2021 – 12/31/2024) Type of Finding: Significant Deficiency in Internal Control over Compliance, Other Matters Compliance Requirement: Reporting Condition: Two of 4 quarterly Project and Expenditure Reports were selected for testing. The Office of the Budget, Governor’s Budget Office (GBO) reported incomplete capital project information in these quarterly reports. Specifically, the following exceptions were noted: • A project’s description allows capital expenditures by beneficiaries, but GBO has reported it as a non-capital project on both quarterly Project and Expenditure reports. In addition, the Pennsylvania Emergency Management Agency (PEMA) does not require the beneficiaries receiving funding under this project to report their capital expenditures to PEMA. Therefore, GBO is unable to determine the amount of capital expenditures obligated and expended for this project. • A capital project in excess of $10 million was reported as a non-capital project on the March 31, 2023 quarterly report. GBO believes they correctly reported the project as a capital project, but the reporting portal incorrectly recorded their submission. However, GBO was unable to provide documentation that the project was identified as a capital project in their submission to the U.S. Treasury. • On the June 30, 2023 quarterly report, the project was correctly reported as a capital project and the required written justification was included, however, the justification did not include all required elements. Criteria: Per the Compliance and Reporting Guidance issued by the United States Department of the Treasury, recipients must report if a project includes capital expenditures, the type of capital expenditure, and the amount of capital expenditures obligated and expended. Per 31 CFR Section 35.6(b)(4), a recipient, other than a Tribal government, must prepare written justifications for capital projects with capital expenditures enumerated by Treasury in the final rule and with total capital expenditures greater than $10 million. Such written justifications must include the following elements: (i) Describe the harm or need to be addressed; (ii) Explain why a capital expenditure is appropriate; and (iii) Compare the proposed capital expenditure to at least two alternative capital expenditures and demonstrate why the proposed capital expenditure is superior. Management Directive 325.12, Amended – Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office’s Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Finding 2023 –¬ 020: (continued) Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: PEMA issued awards to 666 local Emergency Management Services (EMS) companies and the companies were allowed to expend the funds on a variety of uses, including capital expenditures. PEMA did not obtain detail of capital expenditures incurred from the companies and was therefore unable to provide the information to GBO for inclusion on the Project and Expenditure Reports. The required elements for capital project justifications are summarized on page 4390 of the Final Rule, but they are not mentioned in the Project and Expenditure Report User Guide nor in the Compliance and Reporting Guidance. Therefore, GBO was unaware that it was necessary to include specific elements in the justification. Effect: GBO did not properly identify and report capital projects. Errors included omitting capital project obligations and expenditures and incomplete justifications for a capital project greater than $10 million. Recommendation: We recommend that GBO ensures that all capital projects are properly reported and that justifications for capital projects greater than $10 million include all required elements. We further recommend that PEMA beneficiaries be required to submit expenditure detail to allow GBO to correctly report capital expenditures obligated and expended. Agency Response: GBO agrees with this finding. Limitations in the federal reporting portal, changing federal guidance, and the nature of programs being implemented which may be used for capital expenditures and a myriad of other non-capital uses complicates reporting compliance. Questioned Costs: None

Corrective Action Plan

PEMA Capital Project Reporting: The PEMA Emergency Medical Services Recovery SLFRF Project (87374A) was reported to the federal government with $0 for capital expenditures because all recipients were beneficiaries. The SLFRF federal guidance states the following: 11. Subrecipient Monitoring. SLFRF recipients that are pass-through entities as described under 2 CFR 200.1 are required to manage and monitor their subrecipients to ensure compliance with requirements of the SLFRF award pursuant to 2 CFR 200.332 regarding requirements for pass-through entities. First, your organization must clearly identify to the subrecipient: (1) that the award is a subaward of SLFRF funds; (2) any and all compliance requirements for use of SLFRF funds; and (3) any and all reporting requirements for expenditures of SLFRF funds. Recipients should also note that subrecipients do not include individuals and organizations that received SLFRF funds as end users. Such individuals and organizations are beneficiaries and not subject to audit pursuant to the Single Audit Act and 2 C.F.R. Part 200, Subpart F. U.S. Treasury, Compliance and Reporting Guidance, State and Local Fiscal Recovery Funds, Version 5.14, December 14, 2023, Pages 12-13. (This is the current version) Additionally, the U.S. Treasury states in their Quarterly Reporting User Guide Frequently Asked Questions (page 165 of the current edition): 1.20. Who are beneficiaries and are recipients required to report for them? The terms and conditions of federal awards flow down to subawards to subrecipients, requiring subrecipients to comply with all requirements of recipients such as the treatment of eligible uses of funds, procurement, and reporting requirements. Beneficiaries are not subject to the requirements placed on subrecipients in the Uniform Guidance, including audit pursuant to the Single Audit Act and 2 CFR Part 200, Subpart F or subrecipient reporting requirements. OB-GBO interpreted this to mean that reporting was not necessary, but we are seeking clarification from U.S. Treasury. Meanwhile, we will collaborate with PEMA to review grant materials and address capital expenditure questions by July 31, 2024. Capital Project In Excess Of $10M: The Quarter 1 2023 Project and Expenditure Report submitted by the Commonwealth of Pennsylvania did not capture the DCNR State Parks and Outdoor Recreation Grants Program (87360B) as a capital project in excess of $10M. The federal reporting portal inaccurately recorded the submission, and unfortunately, we cannot verify if this was due to a technical issue (there have been several instances we found where information we entered into the portal was reported differently in the U.S. Treasury generated report summary and had to be corrected by the U.S. Treasury after submission) or human error since access to older reports is blocked, nor does the abridged PDF version of the submission from the U.S. Treasury portal contain that specific information. While the error was noted in the Quarter 1 2023 report, it had been corrected in the Quarter 2 report. Currently, there is no further action we can take regarding the Quarter 1 2023 report. We consider this issue resolved. Capital Project Justification Did Not Include All Required Elements: The DCNR State Parks and Outdoor Recreation Grants Program (87360B) has been reported as a capital project. OB-GBO acknowledges that the capital project justification did not include all the required elements below: (i) Describe the harm or need to be addressed; (ii) Explain why a capital expenditure is appropriate; and (iii) Compare the proposed capital expenditure to at least two alternative capital expenditures and demonstrate why the proposed capital expenditure is superior. OB-GBO plans to collaborate with DCNR to ensure future reports include all necessary elements by July 31, 2024. Anticipated Completion Date: 07/31/2024 Contact Names: Michael Wood, Bureau Director, Bureau of Performance, Revenue, and Program Analysis, OB-GBO; Colleen Kling, Division Manager, Division of Programs and Performance, OB-GBO; Samantha Lockhart, Executive Budget Specialist, OB-GBO; Evelyn Madenford, Volunteer Loan Program Administrator, Office of State Fire Commissioner, PEMA; Mark Hansford, Division Manager, Division of Community and Conservation, DCNR

About Reporting →
2023-021
Reporting
MATERIAL WEAKNESS

The Pennsylvania Department of Human Services (DHS) is required to submit the ACF-196R, State TANF Financial Report (ACF-196R Report), on a quarterly basis, for each grant year, to the United States Department of Health and Human Services (HHS) Administration for Children and Families (ACF). The ACF-196R Report includes data related to the cumulative transfers, expenditures, and unliquidated obligations through the end of the federal fiscal year. A state must submit a quarterly ACF-196R Report for each open grant year award. During the fiscal year ended June 30, 2023, we selected 10 out of 20 quarterly ACF-196R Reports for testing. The ACF-196R Reports submitted for the quarters ended September 30, 2022 and June 30, 2023 for grant award years 2020 and 2023, respectively, included federal unliquidated obligation amounts reported on Part 1 Expenditure Data, Line 27, which did not agree to the Commonwealth’s general ledger (SAP) as follows: SEE SCHEDULE OF FINDINGS AND QUESTIONED COSTS FOR CHART/TABLE We also analytically compared expenditures incurred during the fiscal year ended June 30, 2023 per the ACF-196R Reports to total Temporary Assistance for Needy Families (TANF) expenditures reported on the Schedule of Expenditures of Federal Awards (SEFA) noting a difference of $53,256,607. We requested that management provide a listing of reconciling items between the ACF-196R Reports and the SEFA which resulted in the identification of an understatement of aggregate expenditures reported in the ACF-196R Reports for the report quarter ending June 30, 2023 of $45,603,714. Although the ACF-196R Reports were subjected to a documented supervisory review and approval, the existence of the misstated federal unliquidated obligation and expenditure amounts indicates that the preparation and the supervisory review and approval processes were not adequate, and a material weakness exists over the preparation and submission of the ACF-196R Report. Finding 2023 – ¬021: (continued) Criteria: 45 CFR Section 75.302, Financial management and standards for financial management system, states: (b) The financial management system of each non-Federal entity must provide for the following: (2) Accurate, current, and complete disclosure of the financial results of each Federal award or program in accordance with the reporting requirements set forth in §75.341 and §75.342. 45 CFR Section 265.3, What reports must the State file on a quarterly basis?, states: (a) Quarterly reports. (1) Each State must collect on a monthly basis, and file on a quarterly basis, the data specified in the TANF Data Report and the TANF Financial Report (c) The TANF Financial Report. (1) Each State must file quarterly expenditure data on the State’s use of Federal TANF funds, State TANF expenditures, and State expenditures of MOE funds in separate State programs. (2) If a State is expending Federal TANF funds received in prior fiscal years, it must file a separate quarterly TANF Financial Report for each fiscal year that provides information on the expenditures of that year’s TANF funds. 2 CFR Section 200.303, Internal controls, states: The non-Federal entity must: (b) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of the Sponsoring Organizations of the Treadway Commission (COSO). Management Directive 325.12 Amended – Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office’s Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Further, adequate internal controls over report preparation would include detailed written report preparation procedures, a segregation of duties between the preparation and the review and approval of the report, and an adequate review and approval process which would detect errors in the report preparation and ensure that such errors are corrected. Finding 2023 –¬ 021: (continued) Cause: The Commonwealth’s Office of Comptroller Operations (OCO) personnel indicated that three internal orders were set up with incorrect order group attribute codes. These errors resulted in expenditures of $45,603,714 being improperly excluded from the order group reports that were used during the compilation of the expenditure data reported in the ACF-196R Reports for the quarter ending June 30, 2023. The $9,306,287 overstatement and $231,623 understatement noted above were the result of formula errors within OCO’s workbooks used to compile the reports that were not identified prior to the submission of the corresponding reports. OCO personnel stated there is a supervisory review and approval process in place but staff turnover and additional grant responsibilities has created internal time constraints for reporting which inherently has increased the potential risk of errors not being identified during the supervisory review. Effect: Since the preparation and the supervisory review and approval processes were not adequate to ensure the accuracy of expenditures and federal unliquidated obligations, various ACF-196R Reports were misstated for the quarters ended June 30, 2023 and September 30, 2022. DHS is not in compliance with federal regulations, and a material weakness exists. If not corrected, inaccurate reporting could result in future grant awards being reduced. Recommendation: OCO should ensure that the preparation and supervisory review and approval processes for the ACF-196R Report are improved and include all required information including cumulative transfers, expenditures, and unliquidated obligations. OCO should ensure their written procedures for the preparation, review, approval, and submission of the ACF-196R Report are sufficiently detailed to ensure the ACF-196R Report is prepared accurately in accordance with federal regulations. Finally, OCO should ensure the misstated ACF-196R expenditure amounts are corrected and the revised information is submitted to ACF, in accordance with ACF guidelines. OCO Response: OCO agrees with this finding. Questioned Costs: None

Show full finding ▾
Full finding narrative

Office of the Budget – Office of Comptroller Operations Finding 2023 –¬ 021: ALN 93.558 – Temporary Assistance for Needy Families (including COVID-19) A Material Weakness and Material Noncompliance Exist Over the Preparation and Submission of the Quarterly ACF-196R Reports Federal Grant Number(s) and Year(s): 2301PATANF (10/01/2022 – 9/30/2023), 2201PATANF (10/01/2021 – 9/30/2022), 2101PATANF (10/01/2020 – 9/30/2021), 2001PATANF (10/01/2019 – 9/30/2020), 1901PATANF (10/01/2018 – 9/30/2019), 1801PATANF (10/01/2017 – 9/30/2018), 1701PATANF (10/01/2016 – 9/30/2017) Type of Finding: Material Weakness in Internal Control over Compliance, Material Noncompliance Compliance Requirement: Reporting Condition: The Pennsylvania Department of Human Services (DHS) is required to submit the ACF-196R, State TANF Financial Report (ACF-196R Report), on a quarterly basis, for each grant year, to the United States Department of Health and Human Services (HHS) Administration for Children and Families (ACF). The ACF-196R Report includes data related to the cumulative transfers, expenditures, and unliquidated obligations through the end of the federal fiscal year. A state must submit a quarterly ACF-196R Report for each open grant year award. During the fiscal year ended June 30, 2023, we selected 10 out of 20 quarterly ACF-196R Reports for testing. The ACF-196R Reports submitted for the quarters ended September 30, 2022 and June 30, 2023 for grant award years 2020 and 2023, respectively, included federal unliquidated obligation amounts reported on Part 1 Expenditure Data, Line 27, which did not agree to the Commonwealth’s general ledger (SAP) as follows: SEE SCHEDULE OF FINDINGS AND QUESTIONED COSTS FOR CHART/TABLE We also analytically compared expenditures incurred during the fiscal year ended June 30, 2023 per the ACF-196R Reports to total Temporary Assistance for Needy Families (TANF) expenditures reported on the Schedule of Expenditures of Federal Awards (SEFA) noting a difference of $53,256,607. We requested that management provide a listing of reconciling items between the ACF-196R Reports and the SEFA which resulted in the identification of an understatement of aggregate expenditures reported in the ACF-196R Reports for the report quarter ending June 30, 2023 of $45,603,714. Although the ACF-196R Reports were subjected to a documented supervisory review and approval, the existence of the misstated federal unliquidated obligation and expenditure amounts indicates that the preparation and the supervisory review and approval processes were not adequate, and a material weakness exists over the preparation and submission of the ACF-196R Report. Finding 2023 – ¬021: (continued) Criteria: 45 CFR Section 75.302, Financial management and standards for financial management system, states: (b) The financial management system of each non-Federal entity must provide for the following: (2) Accurate, current, and complete disclosure of the financial results of each Federal award or program in accordance with the reporting requirements set forth in §75.341 and §75.342. 45 CFR Section 265.3, What reports must the State file on a quarterly basis?, states: (a) Quarterly reports. (1) Each State must collect on a monthly basis, and file on a quarterly basis, the data specified in the TANF Data Report and the TANF Financial Report (c) The TANF Financial Report. (1) Each State must file quarterly expenditure data on the State’s use of Federal TANF funds, State TANF expenditures, and State expenditures of MOE funds in separate State programs. (2) If a State is expending Federal TANF funds received in prior fiscal years, it must file a separate quarterly TANF Financial Report for each fiscal year that provides information on the expenditures of that year’s TANF funds. 2 CFR Section 200.303, Internal controls, states: The non-Federal entity must: (b) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of the Sponsoring Organizations of the Treadway Commission (COSO). Management Directive 325.12 Amended – Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office’s Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Further, adequate internal controls over report preparation would include detailed written report preparation procedures, a segregation of duties between the preparation and the review and approval of the report, and an adequate review and approval process which would detect errors in the report preparation and ensure that such errors are corrected. Finding 2023 –¬ 021: (continued) Cause: The Commonwealth’s Office of Comptroller Operations (OCO) personnel indicated that three internal orders were set up with incorrect order group attribute codes. These errors resulted in expenditures of $45,603,714 being improperly excluded from the order group reports that were used during the compilation of the expenditure data reported in the ACF-196R Reports for the quarter ending June 30, 2023. The $9,306,287 overstatement and $231,623 understatement noted above were the result of formula errors within OCO’s workbooks used to compile the reports that were not identified prior to the submission of the corresponding reports. OCO personnel stated there is a supervisory review and approval process in place but staff turnover and additional grant responsibilities has created internal time constraints for reporting which inherently has increased the potential risk of errors not being identified during the supervisory review. Effect: Since the preparation and the supervisory review and approval processes were not adequate to ensure the accuracy of expenditures and federal unliquidated obligations, various ACF-196R Reports were misstated for the quarters ended June 30, 2023 and September 30, 2022. DHS is not in compliance with federal regulations, and a material weakness exists. If not corrected, inaccurate reporting could result in future grant awards being reduced. Recommendation: OCO should ensure that the preparation and supervisory review and approval processes for the ACF-196R Report are improved and include all required information including cumulative transfers, expenditures, and unliquidated obligations. OCO should ensure their written procedures for the preparation, review, approval, and submission of the ACF-196R Report are sufficiently detailed to ensure the ACF-196R Report is prepared accurately in accordance with federal regulations. Finally, OCO should ensure the misstated ACF-196R expenditure amounts are corrected and the revised information is submitted to ACF, in accordance with ACF guidelines. OCO Response: OCO agrees with this finding. Questioned Costs: None

Corrective Action Plan

The Office of Comptroller Operations unit responsible for DHS grant reporting strives for accurate and complete records in respective to all grant reporting responsibilities, and to that end has implemented or is in the process of implementing the follow reporting improvements: - Report submissions: • Submitted corrected federal unliquidated obligations in the next cumulative quarterly ACF-196R report following the reporting error(s), in accordance with ACF guidance. • Revised the cumulative quarterly ACF-196R for the quarter-ending September 30, 2023, to accurately report the expenditures, in accordance with ACF guidance. - Reporting Preparation Control Improvements: • Improve spreadsheet controls by updating single cell references to “lookups” based on account code, wherever possible. • Include a reconciliation from the grant reports used for the ACF-196R to the reports used for the Commonwealth’s SEFA and/or other similar total federal expenditure reports. As the SEFA reports are designed to include all federal expenditures by ALN, it would assist in identifying if any internal orders were excluded from the grant reporting due to group order attribute system errors. • Update internal procedures for the above changes. - System Controls • As the three internal orders with group attributes system errors were all due to a missing digit in the group number attribute upon setup within the Commonwealth’s enterprise resource planning (ERP) software, work with the Commonwealth’s IT department overseeing the ERP system to determine if a system control can be added to warn and/or require the correct number of characters. Anticipated Completion Date: 06/30/2024 Contact Name: Emily College, Special Assistant

About Reporting →
2023-022
Reporting
REPEAT

The Federal Funding Accountability and Transparency Act (FFATA) requires the Commonwealth of Pennsylvania to report first-tier subawards of $30,000 or more to the FFATA Subaward Reporting System (FSRS). Necessary details including the contract amount, contract date, federal award identification number, internal order number, and other information are entered into the Commonwealth’s SAP accounting system when the Commonwealth agencies award subrecipient contracts in order to ensure compliance with the FFATA reporting requirements. Each month Commonwealth information technology personnel run an extract in SAP to populate a FFATA database and generate a report that summarizes the contract information required for that month’s FFATA reporting. The Office of the Budget, Bureau of Accounting and Financial Management (OB-BAFM), is responsible for overseeing FFATA reporting, to include reviewing the summary report to ensure the contract data is complete. Once reviewed, the information is uploaded into FSRS to meet FFATA reporting requirements. Our testing of the FFATA reporting requirements for 40 subaward transactions totaling $112.9 million from thirteen major programs disclosed that two transactions totaling approximately $11.9 million, or 11 percent of transactions tested, were not reported to FSRS. Specifically, the two transactions for which the FFATA information was not reported occurred within two of the 13 programs tested as follows: SEE SCHEDULE OF FINDINGS AND QUESTIONED COSTS FOR CHART/TABLE Finding 2023 –¬ 022: (continued) Criteria: 2 CFR Section 170, Appendix A to Part 170, Award Term, states in part: I. Reporting Subawards and Executive Compensation a. Reporting of first tier subawards. Applicability. Unless you are exempt as provided in paragraph d. of this award term, you must report each action that equals or exceeds $30,000 in Federal funds for a subaward to a non-Federal entity or Federal agency (see definitions in paragraph e. of this award term). 2. Where and when to report. i. The non-Federal entity or Federal agency must report each obligating action described in paragraph a.1. of this award term to http://www.fsrs.gov. ii. For subaward information, report no later than the end of the month following the month in which the obligation was made. (For example, if the obligation was made on November 7, 2010, the obligation must be reported by no later than December 31, 2010.) 3. What to report. You must report the information about each obligating action that the submission instructions posted at http://www.fsrs.gov specify. b. Reporting total compensation of recipient executives for non-Federal entities. 1. Applicability and what to report. You must report total compensation for each of your five most highly compensated executives for the preceding completed fiscal year, if - i. The total Federal funding authorized to date under this Federal award equals or exceeds $30,000 as defined in 2 CFR 170.320; ii. in the preceding fiscal year, you received - (A) 80 percent or more of your annual gross revenues from Federal procurement contracts (and subcontracts) and Federal financial assistance subject to the Transparency Act, as defined at 2 CFR 170.320 (and subawards), and (B) $25,000,000 or more in annual gross revenues from Federal procurement contracts (and subcontracts) and Federal financial assistance subject to the Transparency Act, as defined at 2 CFR 170.320 (and subawards); and, iii. The public does not have access to information about the compensation of the executives through periodic reports filed under section 13(a) or 15(d) of the Securities Exchange Act of 1934 (15 U.S.C. 78m(a), 78o(d)) or section 6104 of the Internal Revenue Code of 1986. (To determine if the public has access to the compensation information, see the U.S. Security and Exchange Commission total compensation filings at http://www.sec.gov/answers/execomp.htm.) Management Directive 325.12, Amended – Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office’s, Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Finding 2023 –¬ 022: (continued) Cause: Regarding the two transactions identified during our testing that were not reported in the FFATA database, OB-BAFM personnel indicated the awards were overlooked during the FFATA review. As a result of our inquiry, OB-BAFM Personnel indicated that these awards were subsequently uploaded to the FFATA database and FSRS as required. Effect: Since the subaward information for two transactions tested were not included in the FFATA database, the required subaward information was not reported to FSRS as required. Further, noncompliance with FFATA reporting requirements in FSRS may recur in future periods if control deficiencies are not corrected to ensure completeness of the FFATA database. Recommendation: We recommend that OB-BAFM follow their established procedures to ensure all subrecipient contract information is included in the FFATA database to ensure that FSRS is accurate and complete. Agency Response: OB-BAFM agrees with the finding. Questioned Costs: None

Show full finding ▾
Full finding narrative

Office of the Budget – Office of Comptroller Operations Finding 2023 –¬ 022: ALN 93.558 – Temporary Assistance for Needy Families (including COVID-19) ALN 93.788 – Opioid STR A Significant Deficiency and Noncompliance Exist in the Commonwealth’s FFATA Reporting Process (A Similar Condition Was Noted in Prior Year Finding 2022-012) Federal Grant Number(s) and Year(s): 2201PATANF (10/01/2021 – 9/30/2022), H79T1083297 (9/30/2020 – 9/29/2023) Type of Finding: Significant Deficiency in Internal Control over Compliance, Other Matters Compliance Requirement: Reporting Condition: The Federal Funding Accountability and Transparency Act (FFATA) requires the Commonwealth of Pennsylvania to report first-tier subawards of $30,000 or more to the FFATA Subaward Reporting System (FSRS). Necessary details including the contract amount, contract date, federal award identification number, internal order number, and other information are entered into the Commonwealth’s SAP accounting system when the Commonwealth agencies award subrecipient contracts in order to ensure compliance with the FFATA reporting requirements. Each month Commonwealth information technology personnel run an extract in SAP to populate a FFATA database and generate a report that summarizes the contract information required for that month’s FFATA reporting. The Office of the Budget, Bureau of Accounting and Financial Management (OB-BAFM), is responsible for overseeing FFATA reporting, to include reviewing the summary report to ensure the contract data is complete. Once reviewed, the information is uploaded into FSRS to meet FFATA reporting requirements. Our testing of the FFATA reporting requirements for 40 subaward transactions totaling $112.9 million from thirteen major programs disclosed that two transactions totaling approximately $11.9 million, or 11 percent of transactions tested, were not reported to FSRS. Specifically, the two transactions for which the FFATA information was not reported occurred within two of the 13 programs tested as follows: SEE SCHEDULE OF FINDINGS AND QUESTIONED COSTS FOR CHART/TABLE Finding 2023 –¬ 022: (continued) Criteria: 2 CFR Section 170, Appendix A to Part 170, Award Term, states in part: I. Reporting Subawards and Executive Compensation a. Reporting of first tier subawards. Applicability. Unless you are exempt as provided in paragraph d. of this award term, you must report each action that equals or exceeds $30,000 in Federal funds for a subaward to a non-Federal entity or Federal agency (see definitions in paragraph e. of this award term). 2. Where and when to report. i. The non-Federal entity or Federal agency must report each obligating action described in paragraph a.1. of this award term to http://www.fsrs.gov. ii. For subaward information, report no later than the end of the month following the month in which the obligation was made. (For example, if the obligation was made on November 7, 2010, the obligation must be reported by no later than December 31, 2010.) 3. What to report. You must report the information about each obligating action that the submission instructions posted at http://www.fsrs.gov specify. b. Reporting total compensation of recipient executives for non-Federal entities. 1. Applicability and what to report. You must report total compensation for each of your five most highly compensated executives for the preceding completed fiscal year, if - i. The total Federal funding authorized to date under this Federal award equals or exceeds $30,000 as defined in 2 CFR 170.320; ii. in the preceding fiscal year, you received - (A) 80 percent or more of your annual gross revenues from Federal procurement contracts (and subcontracts) and Federal financial assistance subject to the Transparency Act, as defined at 2 CFR 170.320 (and subawards), and (B) $25,000,000 or more in annual gross revenues from Federal procurement contracts (and subcontracts) and Federal financial assistance subject to the Transparency Act, as defined at 2 CFR 170.320 (and subawards); and, iii. The public does not have access to information about the compensation of the executives through periodic reports filed under section 13(a) or 15(d) of the Securities Exchange Act of 1934 (15 U.S.C. 78m(a), 78o(d)) or section 6104 of the Internal Revenue Code of 1986. (To determine if the public has access to the compensation information, see the U.S. Security and Exchange Commission total compensation filings at http://www.sec.gov/answers/execomp.htm.) Management Directive 325.12, Amended – Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office’s, Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Finding 2023 –¬ 022: (continued) Cause: Regarding the two transactions identified during our testing that were not reported in the FFATA database, OB-BAFM personnel indicated the awards were overlooked during the FFATA review. As a result of our inquiry, OB-BAFM Personnel indicated that these awards were subsequently uploaded to the FFATA database and FSRS as required. Effect: Since the subaward information for two transactions tested were not included in the FFATA database, the required subaward information was not reported to FSRS as required. Further, noncompliance with FFATA reporting requirements in FSRS may recur in future periods if control deficiencies are not corrected to ensure completeness of the FFATA database. Recommendation: We recommend that OB-BAFM follow their established procedures to ensure all subrecipient contract information is included in the FFATA database to ensure that FSRS is accurate and complete. Agency Response: OB-BAFM agrees with the finding. Questioned Costs: None

Corrective Action Plan

The following steps were taken to address this material weakness: - Finalize FFATA procedures to ensure a consistent FFATA review is being conducted in General Accounting. - Mangers will review FFATA preparer’s reports for completeness. - Review fiscal year end FFATA errors and make corrections needed so the FFATA reports are in FSRS and USAspending.gov. Anticipated Completion Date: 11/01/2024 Contact Names: Sandra Bruno, Integrated Financial Service Manager; Jamie Jerosky, Assistant Director

Prior Finding References

2022-012

About Reporting →
2023-023
Subrecipient Monitoring
REPEATQUESTIONED COSTS

The Uniform Guidance in 2 CFR Section 200 applies to the major programs listed above for the fiscal year ended June 30, 2023. Our testing disclosed that the Pennsylvania Department of Human Services (DHS) and the Pennsylvania Department of Agriculture (PDA) did not identify the federal award information and applicable requirements in subrecipient award documents. Additionally, DHS, PDA, the Pennsylvania Department of Health (DOH), and the Pennsylvania Department of Aging (PDOA) did not adequately evaluate each subrecipient’s risk of noncompliance for the purpose of determining the appropriate subrecipient monitoring related to the subaward. This represents an internal control weakness which could cause subrecipients to be improperly informed of federal award information and may result in inadequate monitoring by the state agencies. Also, it could cause the omission or improper identification of program expenditures on subrecipients’ Schedules of Expenditures of Federal Awards (SEFAs). The following chart shows which federal award information required by 2 CFR Section 200 was omitted (as indicated by “No”) from the subrecipient award documents at the time of the subaward and which major programs did not have a state agency evaluation of each subrecipient’s risk of noncompliance. Finding 2023 –¬ 023: (continued) SEE SCHEDULE OF FINDINGS AND QUESTIONED COSTS FOR CHART/TABLE Criteria: 2 CFR Section 200.332, Requirements for pass-through entities, states in part: All pass-through entities must: (a) Ensure that every subaward is clearly identified to the subrecipient as a subaward and includes the following information at the time of the subaward and if any of these data elements change, include the changes in subsequent subaward modification. When some of this information is not available, the pass-through entity must provide the best information available to describe the Federal award and subaward. Required information includes: Finding 2023 – 023: (continued) (1) Federal Award Identification. (iii) Federal Award Identification Number (FAIN); (iv) Federal Award Date (see the definition of Federal Award date in section 200.1) of award to the recipient by the Federal agency; (v) Subaward Period of Performance Start and End Date; (xi) Name of Federal awarding agency, pass-through entity, and contact information for awarding official of the pass-through entity; (xii) Assistance Listings Number and Title; the pass-through entity must identify the dollar amount made available under each Federal award and the Assistance Listings Number at time of disbursement; (6) Appropriate terms and conditions concerning closeout of the subaward. (b) Evaluate each subrecipient’s risk of noncompliance with Federal statutes, regulations, and the terms and conditions of the subaward for purposes of determining the appropriate subrecipient monitoring described in paragraphs (d) and (e) of this section, which may include consideration of such factors as: (1) The subrecipient’s prior experience with the same or similar subawards; (2) The results of previous audits including whether or not the subrecipient receives a Single Audit in accordance with Subpart F [Audit Requirements] of this part, and the extent to which the same or similar subaward has been audited as a major program; (3) Whether the subrecipient has new personnel or new or substantially changed systems; and (4) The extent and results of Federal awarding agency monitoring (e.g., if the subrecipient also receives Federal awards directly from a Federal awarding agency) Management Directive 325.12, Amended – Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office’s Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should identify, analyze, and respond to risks related to achieving the defined objectives. Management should identify, analyze, and respond to significant changes that could impact the internal control system. Cause: In general, DHS’s and PDA’s processes for subrecipient award monitoring did not identify the omission of required elements from the grant awards. In addition, the risk assessments performed by DHS, PDA, PDOA, and DOH were not properly documented or not performed. Effect: Excluding the federal grant award information at the time of the subaward may cause subrecipients and their auditors to be uninformed about specific program and other regulations that apply to the funds they receive. There is also the potential for subrecipients to have incomplete SEFAs in their Single Audit reports submitted to the Commonwealth, and federal funds may not be properly audited at the subrecipient level in accordance with the Single Audit Act and Uniform Guidance. Not evaluating each subrecipient’s risk of noncompliance for purposes of determining the appropriate subrecipient monitoring related to the subaward may result in subrecipients using the subaward for unauthorized purposes or in violation of the terms and conditions of the subaward, and state agency monitoring would not detect this noncompliance and ensure it is corrected in a timely manner. Finding 2023 ¬– 023: (continued) Recommendation: DHS and PDA should develop policies and reporting mechanisms to ensure all required federal award information is disseminated to all subrecipients at the time of the subaward to ensure subrecipient compliance with the Uniform Guidance in 2 CFR Section 200 and other applicable federal regulations. In addition, DHS and PDA should correspond with applicable subrecipients to ensure they are aware of the correct federal award information and review applicable subaward documents prior to issuance to ensure federal information is complete and accurate. DHS, PDA, PDOA, and DOH should implement procedures to adequately document their evaluation of each subrecipient’s risk of noncompliance as cited in 2 CFR Section 200.332 for purposes of determining the appropriate subrecipient monitoring related to the subaward. DHS Response: DHS agrees with the finding. DOH Response: DOH agrees with the finding. PDA Response: PDA agrees with the finding. PDOA Response: PDOA agrees with the finding. Questioned Costs: The amount of questioned costs cannot be determined.

Show full finding ▾
Full finding narrative

Various Agencies Finding 2023 –¬ 023: ALN 10.565, 10.568, and 10.569 – Food Distribution Cluster ALN 93.044, 93.045, and 93.053 – Aging Cluster (including COVID-19) ALN 93.323 – Epidemiology and Laboratory Capacity for Infectious Diseases (including COVID-19) ALN 93.558 – Temporary Assistance for Needy Families (including COVID-19) ALN 93.658 – Foster Care – Title IV-E (including COVID-19) ALN 93.667 – Social Services Block Grant State Agencies Did Not Identify the Federal Award Information and Applicable Requirements at the Time of the Subaward and Did Not Evaluate Each Subrecipient’s Risk of Noncompliance as Required by the Uniform Grant Guidance (A Similar Condition Was Noted in Prior Year Finding 2022-013) Federal Grant Number(s) and Year(s): 221PA825Y8005 (10/01/2021 – 9/30/2022), 221PA825Y8105 (10/01/2021 – 9/30/2022), 231PA825Y8005 (10/01/2022 – 9/30/2023) 231PA825Y8105 (10/01/2022 – 9/30/2023), 2101PACMC6 (4/01/2021 – 9/30/2024), 2101PAHDC5 (12/27/2020 – 9/30/2023), 2101PAHDC6 (4/01/2021 – 9/30/2024), 2101PAOACM (10/01/2020 – 9/30/2023), 2101PAOAHD (10/01/2020 – 9/30/2023), 2101PAOANS (10/01/2020 – 9/30/2023), 2101PAOASS (10/01/2020 – 9/30/2023), 2101PAPHC6 (4/01/2021 – 9/30/2024), 2101PASSC6 (4/01/2021 – 9/30/2024), 2101PAVAC5 (4/01/2021 – 9/30/2023), 2201PAOACM (10/01/2021 – 9/30/2023), 2201PAOAHD (10/01/2021 – 9/30/2023), 2201PAOANS (10/01/2021 – 9/30/2023), 2201PAOASS (10/01/2021 – 9/30/2023), 2201PASTPH (1/01/2022 – 9/30/2024), 2301PAOACM (10/01/2022 – 9/30/2024), 2301PAOAHD (10/01/2022 – 9/30/2024), 2301PAOANS (10/01/2022 – 9/30/2024), 2301PAOASS (10/01/2022 – 9/30/2024), NU50CK000527 (8/01/2019 – 7/31/2024), 2301PATANF (10/01/2022 – 9/30/2023), 2201PATANF (10/01/2021 – 9/30/2022), 2201PAFOST (10/01/2021 – 9/30/2022), 2301PAFOST (10/01/2022 – 9/30/2023), 2201PASOSR (10/01/2021 – 9/30/2023), 2301PASOSR (10/01/2022 – 9/30/2024) Type of Finding: Significant Deficiency in Internal Control over Compliance, Other Matters Compliance Requirement: Subrecipient Monitoring Condition: The Uniform Guidance in 2 CFR Section 200 applies to the major programs listed above for the fiscal year ended June 30, 2023. Our testing disclosed that the Pennsylvania Department of Human Services (DHS) and the Pennsylvania Department of Agriculture (PDA) did not identify the federal award information and applicable requirements in subrecipient award documents. Additionally, DHS, PDA, the Pennsylvania Department of Health (DOH), and the Pennsylvania Department of Aging (PDOA) did not adequately evaluate each subrecipient’s risk of noncompliance for the purpose of determining the appropriate subrecipient monitoring related to the subaward. This represents an internal control weakness which could cause subrecipients to be improperly informed of federal award information and may result in inadequate monitoring by the state agencies. Also, it could cause the omission or improper identification of program expenditures on subrecipients’ Schedules of Expenditures of Federal Awards (SEFAs). The following chart shows which federal award information required by 2 CFR Section 200 was omitted (as indicated by “No”) from the subrecipient award documents at the time of the subaward and which major programs did not have a state agency evaluation of each subrecipient’s risk of noncompliance. Finding 2023 –¬ 023: (continued) SEE SCHEDULE OF FINDINGS AND QUESTIONED COSTS FOR CHART/TABLE Criteria: 2 CFR Section 200.332, Requirements for pass-through entities, states in part: All pass-through entities must: (a) Ensure that every subaward is clearly identified to the subrecipient as a subaward and includes the following information at the time of the subaward and if any of these data elements change, include the changes in subsequent subaward modification. When some of this information is not available, the pass-through entity must provide the best information available to describe the Federal award and subaward. Required information includes: Finding 2023 – 023: (continued) (1) Federal Award Identification. (iii) Federal Award Identification Number (FAIN); (iv) Federal Award Date (see the definition of Federal Award date in section 200.1) of award to the recipient by the Federal agency; (v) Subaward Period of Performance Start and End Date; (xi) Name of Federal awarding agency, pass-through entity, and contact information for awarding official of the pass-through entity; (xii) Assistance Listings Number and Title; the pass-through entity must identify the dollar amount made available under each Federal award and the Assistance Listings Number at time of disbursement; (6) Appropriate terms and conditions concerning closeout of the subaward. (b) Evaluate each subrecipient’s risk of noncompliance with Federal statutes, regulations, and the terms and conditions of the subaward for purposes of determining the appropriate subrecipient monitoring described in paragraphs (d) and (e) of this section, which may include consideration of such factors as: (1) The subrecipient’s prior experience with the same or similar subawards; (2) The results of previous audits including whether or not the subrecipient receives a Single Audit in accordance with Subpart F [Audit Requirements] of this part, and the extent to which the same or similar subaward has been audited as a major program; (3) Whether the subrecipient has new personnel or new or substantially changed systems; and (4) The extent and results of Federal awarding agency monitoring (e.g., if the subrecipient also receives Federal awards directly from a Federal awarding agency) Management Directive 325.12, Amended – Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office’s Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should identify, analyze, and respond to risks related to achieving the defined objectives. Management should identify, analyze, and respond to significant changes that could impact the internal control system. Cause: In general, DHS’s and PDA’s processes for subrecipient award monitoring did not identify the omission of required elements from the grant awards. In addition, the risk assessments performed by DHS, PDA, PDOA, and DOH were not properly documented or not performed. Effect: Excluding the federal grant award information at the time of the subaward may cause subrecipients and their auditors to be uninformed about specific program and other regulations that apply to the funds they receive. There is also the potential for subrecipients to have incomplete SEFAs in their Single Audit reports submitted to the Commonwealth, and federal funds may not be properly audited at the subrecipient level in accordance with the Single Audit Act and Uniform Guidance. Not evaluating each subrecipient’s risk of noncompliance for purposes of determining the appropriate subrecipient monitoring related to the subaward may result in subrecipients using the subaward for unauthorized purposes or in violation of the terms and conditions of the subaward, and state agency monitoring would not detect this noncompliance and ensure it is corrected in a timely manner. Finding 2023 ¬– 023: (continued) Recommendation: DHS and PDA should develop policies and reporting mechanisms to ensure all required federal award information is disseminated to all subrecipients at the time of the subaward to ensure subrecipient compliance with the Uniform Guidance in 2 CFR Section 200 and other applicable federal regulations. In addition, DHS and PDA should correspond with applicable subrecipients to ensure they are aware of the correct federal award information and review applicable subaward documents prior to issuance to ensure federal information is complete and accurate. DHS, PDA, PDOA, and DOH should implement procedures to adequately document their evaluation of each subrecipient’s risk of noncompliance as cited in 2 CFR Section 200.332 for purposes of determining the appropriate subrecipient monitoring related to the subaward. DHS Response: DHS agrees with the finding. DOH Response: DOH agrees with the finding. PDA Response: PDA agrees with the finding. PDOA Response: PDOA agrees with the finding. Questioned Costs: The amount of questioned costs cannot be determined.

Corrective Action Plan

PDA: For federal programs within the Food Distribution Cluster (ALNs 10.565, 10.568, and 10.569), PDA will put the following steps in place for (1) identifying the federal award information and applicable requirements and (2) evaluating each subrecipient’s risk of noncompliance as Required by the Uniform Grant Guidance. 1) PDA will ensure that FAIN numbers are now included in all new subaward agreements. (For currently existing agreements, PDA will send letters by June 30 to provide the FAIN and reiterate Single Audit requirements.) 2) For those subaward agreements that are permanent and/or cover multiple funding years, PDA will develop procedures to ensure that annual notices are sent to each subrecipient notifying them of the updated FAIN for their agreement and reminding them of the Single Audit requirements that are laid out in the terms of their initial signed agreement. 3) PDA will develop a process to evaluate each subrecipient’s risk of noncompliance with federal statutes, regulations, and the terms and conditions of the subaward for purposes of determining the appropriate subrecipient monitoring. The evaluation will be based on Key Performance Indicators, such as leadership tenure; prior incidents of food spoilage; or qualitative feedback from clients served. If the evaluation determines that additional monitoring tools beyond the routine performance of on-site reviews of the subrecipient's program operations are necessary, such conditions will be laid out in a separate letter communication to the sub-awardee. Anticipated Completion Date: 06/30/2024 Contact Name: Caryn Long Earl, Director, Bureau of Food Assistance PDOA: PDOA will implement the following steps to evaluate each subrecipient’s risk of noncompliance as required by the uniform grant guidance. 1. Evaluation is ongoing for the impacted Aging Cluster programs. 2. A risk assessment is being developed to evaluate each subrecipient’s risk of noncompliance to proactively address any weaknesses in internal controls over federal programs. - Pointed questions regarding the Organization included to gauge management’s ability to follow all terms and conditions of the contract. - General Policies will be reviewed for adherence to all federal and state regulations and competence of personnel administering the programs. - Since multiple federal funding streams are involved, a fiscal component will also be administered to review internal controls for financial issues. 3. Performance check-ins are launching in April of 2024 as part of a statewide comprehensive monitoring as a new form of regulatory measure. 4. Follow-Up procedures resulting from this finding will be reviewed and adjusted as needed to deliver optimal outcomes. Preliminary procedures will be directed to the agency’s audit review committee for resolution of completeness. 5. In the event the audit review committee determines additional steps beyond the monitoring efforts outlined above are insufficient, additional efforts will be communicated to the AAA network. Anticipated Completion Date: 06/30/2024 Contact Name: Jennifer Cave, Fiscal Management Specialist, PDOA Audit Liaison DOH: DOH plans to develop and implement a robust subrecipient monitoring program which includes establishing a new section within the Budget Office pending enacted budget funds and complement to support the creation of the section. Initiative goals/milestones include: 1. Educate Department: Budget Office is developing a bulletin that will outline the subrecipient monitoring requirements with links to state and federal sources. The bulletin will be shared with all program office staff. The Budget Office will develop the following templates and provide to all program offices: - Determination of vendor status: Subrecipient or Contractor - Risk Assessment Form - Internal Control Self-Assessment for Subrecipient Template - Subrecipient Monitoring Template 2. Implementation of full compliance initiative: Recommendations provided in the assessment will be used to develop and implement comprehensive policies and procedures lead by a new section in the Budget Office. Anticipated Completion Dates: 1 - 03/31/2024; 2 - 03/31/2025 Contact Name: Andrea Race, CFO DHS: Foster Care 1. For the portion of the audit finding that indicates State Agencies Did Not Identify the Federal Award Information and Applicable Requirements at the Time of the Subaward. Beginning state fiscal year 2024-2025, OCYF will begin sending out the required information to the Foster Care non-profit contractor. 2. Separately, OCYF will be developing a risk assessment process for the Foster Care non-profit contractor in state fiscal year 2024-2025. Anticipated Completion Dates: 1 - 06/30/2024; 2 - 06/30/2025 Contact Name: Melissa Erazo, Director, Bureau of Budget and Fiscal Support TANF and SSBG Effective December 31, 2023, DHS’ grant contract with Real Alternatives ended. We have no contract for services with them going forward. Despite repeated attempts and efforts to engage this grantee in ongoing monitoring activities, as well as monitoring after the end of the grant for previous years, they were uncooperative and unresponsive to our requests and therefore regular monitoring was not completed. Due to the Covid-19 global pandemic as well as staff turnover and vacancies in the Office of Policy Development, regular monitoring of SSBG grant recipients was not performed on schedule. However, with the hiring of a full complement of staff for the DHS Policy Office, including a Grant Administrator, we are in the process of creating and implementing a robust monitoring plan for all 19 of our grantees for calendar year 2024, including risk assessments, in person monitoring, desk monitoring, data collection and analysis. Anticipated Completion Date: 12/31/2024 Contact Name: Jessica Schneider, Executive Policy Specialist I, Grants

Prior Finding References

2022-013

About Subrecipient Monitoring →
2023-024
Subrecipient Monitoring
MATERIAL WEAKNESSREPEATQUESTIONED COSTS

Under the Commonwealth of Pennsylvania's (Commonwealth) implementation of the Single Audit Act, review and resolution of subrecipient Single Audit reports is split into two stages. The Office of the Budget’s Bureau of Accounting and Financial Management (OB-BAFM) ensures the reports meet technical standards through a centralized desk review process. The various funding agencies in the Commonwealth are responsible for making a management decision on each finding within six months of the Federal Audit Clearinghouse’s (FAC) Management Decision Letter (MDL) start date for audits subject to Uniform Guidance and to ensure appropriate corrective action is taken by the subrecipient (except for Uniform Guidance audits under U.S. Department of Labor programs which are permitted 12 months for management decisions in accordance with 2 CFR Section 2900.21). Each Commonwealth agency is also responsible for reviewing financial information in each audit report to determine whether the audit included all pass-through funding provided by the agency in order to ensure pass-through funds were subject to audit. Most agencies meet this requirement by performing Schedule of Expenditures of Federal Awards (SEFA) reconciliations. The agency is also required to adjust Commonwealth records, if necessary. Our fiscal year ended June 30, 2023 audit of the Commonwealth’s process for review and resolution of subrecipient Single Audits included an evaluation of the Commonwealth’s fiscal year ended June 30, 2022 subrecipient audit universe for audits due for submission to the FAC during the fiscal year ended June 30, 2023. We also evaluated the Commonwealth’s review of 44 subrecipient audit reports with findings in major programs/clusters which were identified on the Commonwealth agencies’ tracking lists during the fiscal year ended June 30, 2023 and required management decisions by Commonwealth agencies. Our testing disclosed the following audit exceptions regarding the Commonwealth agencies’ review of subrecipient audit reports: • Pennsylvania Department of Aging (PDOA): Our testing disclosed that PDOA did not have procedures in place to track audit reports including having an audit tracking list. The time period for making a management decision on findings was approximately 10.5 months after the FAC MDL start date for the one audit report with findings. • Department of Agriculture (PDA): Our testing disclosed that PDA did not have procedures in place to track audit reports including having an audit tracking list. The time period for making a management decision on findings was approximately 12 months to over 18 months after the FAC MDL start date for three out of three audit reports with findings. There was also a delay in PDA’s procedures to ensure the subrecipient SEFAs were accurate so that major programs were properly determined and subjected to audit. Our testing disclosed one audit report submitted to the FAC over nine months late that included $19.4 million in subrecipient expenditures passed through PDA. In addition, our testing disclosed that PDA subgranted federal funds totaling approximately $4.8 million to five subrecipients during the fiscal year ended June 30, 2022, for which Single Audits were not submitted to the FAC as of our January 2024 testing date. This was over 16 or 10 months after the respective, September 30, 2022 or March 31, 2023 due dates. • Department of Education (PDE): The time period for making a management decision on findings was approximately 9.3 to over 16.9 months after the FAC MDL start date for 14 out of 22 audit reports with findings. One of the 14 audit reports was improperly classified on PDE’s audit tracking list as not having federal award findings. There were additional audit reports with findings listed on PDE’s audit tracking list where management decisions were not made timely. • Department of Health (DOH): The time period for making a management decision on findings was over 11 months after the FAC MDL start date for two out of two audit reports with findings. One audit report with the late management decision on findings was excluded from DOH’s tracking list. Finding 2023 – 024: (continued) Criteria: 2 CFR Section 200.332, Requirements for pass-through entities, states in part: All pass-through entities must: (d) Monitor the activities of the subrecipient as necessary to ensure that the subaward is used for authorized purposes, in compliance with Federal statutes, regulations, and the terms and conditions of the subaward, and that subaward performance goals are achieved. Pass-through entity monitoring of the subrecipient must include: (2) Following-up and ensuring that the subrecipient takes timely and appropriate action on all deficiencies pertaining to the Federal award provided to the subrecipient from the pass-through entity detected through audits, on-site reviews, and written confirmation from the subrecipient, highlighting the status of actions planned or taken to address Single Audit findings related to the particular subaward. (3) Issuing a management decision for applicable audit findings pertaining only to the Federal award provided to the subrecipient from the pass-through entity as required by §200.521 [Management decision]. (f) Verify that every subrecipient is audited as required by Subpart F [Audit Requirements] of this part when it is expected that the subrecipient’s Federal awards expended during the respective fiscal year equaled or exceeded the threshold set forth in §200.501 [Audit requirements]. (g) Consider whether the results of the subrecipient’s audit, on-site review, or other monitoring indicate conditions that necessitate adjustments to the pass-through entity’s own records. (h) Consider taking enforcement action against noncompliant subrecipients as described in §200.339 [Remedies for noncompliance] of this part and in program regulations. In order to carry out these responsibilities properly, good internal control dictates that state pass-through agencies ensure subrecipient Single Audit SEFAs are representative of state payment records each year, and that the related federal programs have been properly subjected to Single Audit procedures. 2 CFR Section 200.512, Report submission, states in part: (a) General. (1) The audit must be completed and the data collection form described in paragraph (b) of this section and reporting package described in paragraph (c) of this section must be submitted within the earlier of 30 calendar days after receipt of the auditor’s report(s), or nine months after the end of the audit period. If the due date falls on a Saturday, Sunday, or Federal holiday, the reporting package is due the next business day. 2 CFR Section 200.521, Management decision, states in part: (a) General. The management decision must clearly state whether or not the finding is sustained, the reasons for the decision, and the expected auditee action to repay disallowed costs, make financial adjustments, or take other action. (d) Time requirements. The Federal awarding agency or pass-through entity responsible for issuing a management decision must do so within six months of acceptance of the audit report by the FAC. The auditee must initiate and proceed with corrective action as rapidly as possible and corrective action should begin no later than upon receipt of the audit report. 2 CFR Section 200.505, Sanctions, states: In cases of continued inability or unwillingness to have an audit conducted in accordance with this part, Federal agencies and pass-through entities must take appropriate action as provided in §200.339 [Remedies for noncompliance]. Finding 2023 – 024: (continued) 2 CFR Section 200.339, Remedies for noncompliance, states in part: If a non-Federal entity fails to comply with the U.S. Constitution, Federal statutes, regulations or the terms and conditions of a Federal award, the Federal awarding agency or pass-through entity may impose additional conditions, as described in §200.208 [Specific conditions]. If the Federal awarding agency or pass-through entity determines that noncompliance cannot be remedied by imposing additional conditions, the federal awarding agency or pass-through entity may take one or more of the following actions, as appropriate in the circumstances. (a) Temporarily withhold cash payments pending correction of the deficiency by the non-Federal entity or more severe enforcement action by the Federal awarding agency or pass-through entity. (b) Disallow (that is, deny both use of funds and any applicable matching credit for) all or part of the cost of the activity or action not in compliance. (c) Wholly or partly suspend or terminate the Federal award. (d) Initiate suspension or debarment proceedings as authorized under 2 CFR Part 180 and Federal awarding agency regulations (or in the case of a pass-through entity, recommend such a proceeding be initiated by a Federal awarding agency). (e) Withhold further Federal awards for the project or program. (f) Take other remedies that may be legally available. To ensure Commonwealth enforcement of federal regulations for subrecipient noncompliance with audit requirements, Commonwealth Management Directive 325.08, Amended – Remedies for Recipient Noncompliance with Audit Requirements, Section 5 related to policy, states in part: (a) Agencies must develop and implement remedial action that reflects the unique requirements of each program… (b) The remedial action should be implemented within six months from the date the first remedial action is initiated. At the end of the six-month period, the recipient should take the appropriate corrective action or the final stage of remedial action should be imposed on the recipient. Examples of remedial action include, but are not limited to: (1) Meeting or calling the recipient to explain the importance and benefits of the audit and audit resolution processes, emphasizing the value of the audit as an administrative tool and the Commonwealth’s reliance on an acceptable audit and prompt resolution as evidence of the recipient’s ability to properly administer the program. (2) Encouraging the entity to establish an audit committee or designate an individual as the single point of contact to: (a) Communicate regarding the audit. (b) Arrange for and oversee the audit. (c) Direct and monitor audit resolution. (3) Providing technical assistance to the recipient in devising and implementing an appropriate plan to remedy the noncompliance. (4) Withholding a portion of assistance payments until the noncompliance is resolved. (5) Withholding or disallowing overhead costs until the noncompliance is resolved. (6) Suspending the assistance agreement until the noncompliance is resolved. Finding 2023 – 024: (continued) (7) Terminating the assistance agreement with the recipient and, if necessary, seeking alternative entities to administer the program. Management Directive 325.09, Amended – Processing Subrecipient Single Audits of Federal Pass-Through Funds, Section 7 related to procedures, states in part: c. Agencies. (2) Evaluate single audit report submissions received from BAFM to determine program purpose acceptability by verifying, at a minimum, that all agency-funded programs are properly included on the applicable financial schedules; that findings affecting the agency contain sufficient information to facilitate a management decision; and that the subrecipient has submitted an adequate corrective action plan. (5) Issue management decisions relative to audit findings and crosscutting findings assigned to the agency for resolution, as required by 2 CFR §200.521. If responsible for the resolution of crosscutting findings, notify the affected agency or agencies upon resolution of such findings. (7) Impose or coordinate the imposition of remedial action in accordance with 2 CFR Part 200.339 and Management Directive 325.08 Amended, Remedies for Recipient Noncompliance with Audit Requirements, when subrecipients fail to comply with the provisions of Subpart F. Management Directive 325.12, Amended – Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office’s, Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: One reason provided by Commonwealth management for untimely audit resolution in the various agencies, including making management decisions, approving corrective action, and performing procedures to ensure the accuracy of subrecipient SEFAs, was either a change in staff or a lack of staff to follow up and process subrecipient audit reports more timely. Regarding late and outstanding audit report submissions, the Commonwealth agencies did not appear to be timely implementing remedial action steps in accordance with 2 CFR Section 200.339 and Commonwealth Management Directive 325.08 in order to ensure compliance with federal audit submission requirements. Effect: Since required management decisions were not made within six months to ensure appropriate corrective action was taken on audits received from subrecipients, the Commonwealth did not comply with federal regulations, and subrecipients were not made aware of acceptance or rejection of corrective action plans in a timely manner. Further, noncompliance may recur in future periods if control deficiencies are not corrected on a timely basis, and there is an increased risk of unallowable charges being made to federal programs if corrective action and recovery of questioned costs is not timely. Regarding the SEFA reviews or alternate procedures which are not being performed timely and the late Single Audit report submissions, there is an increased risk that subrecipients could be misspending and/or inappropriately tracking and reporting federal funds over multiple year periods, and these discrepancies may not be properly monitored, detected, and corrected by agency personnel on a timely basis as required. Finally, additional federal pass-through funds may be unaudited in the future without timely and effective remedial action from Commonwealth agencies to enforce compliance. Finding 2023 – 024: (continued) Recommendation: We recommend that the above weaknesses that cause untimely subrecipient Single Audit resolution, including untimely management decisions on findings, untimely review of the SEFA or alternate procedures, and late audit report submissions be corrected to ensure compliance with federal requirements and Commonwealth Management Directives, and to better ensure timelier subrecipient compliance with program requirements. Commonwealth agencies should promptly pursue outstanding audits and implement remedial action steps on a timely basis in accordance with 2 CFR Section 200.339 and Commonwealth Management Directive 325.08. DOH Response: DOH agrees with the finding. PDOA Response: PDOA agrees with the finding. PDA Response: PDA agrees with the finding and will be hiring a complement position to ensure compliance in the future. PDE Response: PDE agrees with the finding. Questioned Costs: The amount of questioned costs cannot be determined.

Show full finding ▾
Full finding narrative

Various Agencies Finding 2023 – 024: ALN 10.553, 10.555, 10.556, 10.559, and 10.582 – Child Nutrition Cluster (including COVID-19) ALN 10.565, 10.568, and 10.569 – Food Distribution Cluster ALN 10.557 – WIC Special Supplemental Nutrition Program for Women, Infants, and Children ALN 10.558 – Child and Adult Care Food Program ALN 84.010 – Title I Grants to Local Educational Agencies ALN 84.027 and 84.173¬ – Special Education Cluster (IDEA) (including COVID-19) ALN 84.367 – Supporting Effective Instruction State Grants ALN 84.425C – COVID-19 – Education Stabilization Fund - GEER Fund ALN 84.425D – COVID-19 – Education Stabilization Fund - ESSER Fund ALN 84.425R – COVID-19 – Education Stabilization Fund - CRRSA EANS ALN 84.425U – COVID-19 – Education Stabilization Fund - ARP ESSER ALN 84.425V – COVID-19 – Education Stabilization Fund - ARP EANS ALN 93.044, 93.045, and 93.053 – Aging Cluster (including COVID-19) ALN 93.323 – Epidemiology and Laboratory Capacity for Infectious Diseases (including COVID-19) A Material Weakness and Material Noncompliance Exist in the Commonwealth’s Subrecipient Audit Resolution Process (A Similar Condition Was Noted in Prior Year Finding 2022-014) Federal Grant Number(s) and Year(s): 2101PACMC6 (4/01/2021 – 9/30/2024), 2101PAHDC5 (12/27/2020 – 9/30/2023), 2101PAHDC6 (4/01/2021 – 9/30/2024), 2101PAOACM (10/01/2020 – 9/30/2023), 2101PAOAHD (10/01/2020 – 9/30/2023), 2101PAOANS (10/01/2020 – 9/30/2023), 2101PAOASS (10/01/2020 – 9/30/2023), 2101PAPHC6 (4/01/2021 – 9/30/2024), 2101PASSC6 (4/01/2021 – 9/30/2024), 2101PAVAC5 (4/01/2021 – 9/30/2023), 2201PAOACM (10/01/2021 – 9/30/2023), 2201PAOAHD (10/01/2021 – 9/30/2023), 2201PAOANS (10/01/2021 – 9/30/2023), 2201PAOASS (10/01/2021 – 9/30/2023), 2201PASTPH (1/01/2022 – 9/30/2024), 2301PAOACM (10/01/2022 – 9/30/2024), 2301PAOAHD 10/01/2022 – 9/30/2024), 2301PAOANS (10/01/2022 – 9/30/2024), 2301PAOASS (10/01/2022 – 9/30/2024), 221PA305N1099 (10/01/2021 – 9/30/2022), 231PA305N1099 (10/01/2022 – 9/30/2023), 221PA365N8903 (1/01/2022 – 9/30/2023), 231PA365N8903 (10/01/2022 – 9/30/2024), 231PA305L1603 (10/01/2022 – 9/30/2023), 221PA305L1603 (10/01/2021 – 9/30/2022), 221PA825Y8005 (10/01/2021 – 9/30/2022), 231PA825Y8005 (10/01/2022 – 9/30/2023), 221PA825Y8105 (10/01/2021 – 9/30/2022), 231PA825Y8105 (10/01/2022 – 9/30/2023), 201PA715W5003 (10/01/2019 – 9/30/2023), 211PA715W5003 (10/01/2020 – 9/30/2024), 221PA705W1003 (10/01/2021 – 9/30/2022), 221PA705W1006 (10/01/2021 – 9/30/2022), 221PA715W5003 (10/01/2021 – 9/30/2024), 231PA705W1003 (10/01/2022 – 9/30/2023), 231PA705W1006 (10/01/2022 – 9/30/2023), 231PA715W5003 (10/01/2022 – 9/30/2025), 221PA305N1099 (10/01/2021 – 9/30/2022), 231PA305N1099 (10/01/2022 – 9/30/2023), 221PA315N1050 (10/01/2021 – 9/30/2023), 231PA315N1050 (10/01/2022 – 9/30/2024), 221PA305N2020 (10/01/2021 – 9/30/2022), 231PA305N2020 (10/01/2022 – 9/30/2023), S010A190038 (7/01/2019 – 9/30/2022), S010A200038 (7/01/2020 – 9/30/2022), S010A210038 (7/01/2021 – 9/30/2022), S010A220038 (7/01/2022 – 9/30/2024), S367A150051 (7/01/2015 – 9/30/2017), S367A190051 (7/01/2019 – 9/30/2021), S367A200051 (7/01/2020 – 9/30/2022), S367A210051 (7/01/2021 – 9/30/2023), S367A220051 (7/01/2022 – 9 /30/2024), H027A200093 (7/01/2020 – 9/30/2022), H027A210093 (7/01/2021 – 9/30/2023), H027A220093 (7/01/2022 – 9/30/2024), H027X210093 (7/01/2021 – 9/30/2023), H173A200090 (7/01/2020 – 9/30/2022), H173A210090 (7/01/2021 – 9/30/2023), H173A220090 (7/01/2022 – 9/30/2024), H173X210090 (7/01/2021 – 9/30/2023), S425W210039 (4/23/2021 – 9/30/2024), S425U210028 (3/24/2021 – 9/30/2023), S425D210028 (1/05/2021 – 9/30/2023), S425C200013 (5/18/2020 – 4/01/2024), S425R210037 (3/13/2020 – 9/30/2023), S425V210037 (11/16/2021 – 9/30/2023), S425C210013 (3/13/2020 – 9/30/2023), S425D200028 (3/13/2020 – 9/30/2022), NU50CK000527 (8/01/2019 – 7/31/2024) Finding 2023 – 024: (continued) Type of Finding: Material Weakness in Internal Control over Compliance, Material Noncompliance Compliance Requirement: Subrecipient Monitoring Condition: Under the Commonwealth of Pennsylvania's (Commonwealth) implementation of the Single Audit Act, review and resolution of subrecipient Single Audit reports is split into two stages. The Office of the Budget’s Bureau of Accounting and Financial Management (OB-BAFM) ensures the reports meet technical standards through a centralized desk review process. The various funding agencies in the Commonwealth are responsible for making a management decision on each finding within six months of the Federal Audit Clearinghouse’s (FAC) Management Decision Letter (MDL) start date for audits subject to Uniform Guidance and to ensure appropriate corrective action is taken by the subrecipient (except for Uniform Guidance audits under U.S. Department of Labor programs which are permitted 12 months for management decisions in accordance with 2 CFR Section 2900.21). Each Commonwealth agency is also responsible for reviewing financial information in each audit report to determine whether the audit included all pass-through funding provided by the agency in order to ensure pass-through funds were subject to audit. Most agencies meet this requirement by performing Schedule of Expenditures of Federal Awards (SEFA) reconciliations. The agency is also required to adjust Commonwealth records, if necessary. Our fiscal year ended June 30, 2023 audit of the Commonwealth’s process for review and resolution of subrecipient Single Audits included an evaluation of the Commonwealth’s fiscal year ended June 30, 2022 subrecipient audit universe for audits due for submission to the FAC during the fiscal year ended June 30, 2023. We also evaluated the Commonwealth’s review of 44 subrecipient audit reports with findings in major programs/clusters which were identified on the Commonwealth agencies’ tracking lists during the fiscal year ended June 30, 2023 and required management decisions by Commonwealth agencies. Our testing disclosed the following audit exceptions regarding the Commonwealth agencies’ review of subrecipient audit reports: • Pennsylvania Department of Aging (PDOA): Our testing disclosed that PDOA did not have procedures in place to track audit reports including having an audit tracking list. The time period for making a management decision on findings was approximately 10.5 months after the FAC MDL start date for the one audit report with findings. • Department of Agriculture (PDA): Our testing disclosed that PDA did not have procedures in place to track audit reports including having an audit tracking list. The time period for making a management decision on findings was approximately 12 months to over 18 months after the FAC MDL start date for three out of three audit reports with findings. There was also a delay in PDA’s procedures to ensure the subrecipient SEFAs were accurate so that major programs were properly determined and subjected to audit. Our testing disclosed one audit report submitted to the FAC over nine months late that included $19.4 million in subrecipient expenditures passed through PDA. In addition, our testing disclosed that PDA subgranted federal funds totaling approximately $4.8 million to five subrecipients during the fiscal year ended June 30, 2022, for which Single Audits were not submitted to the FAC as of our January 2024 testing date. This was over 16 or 10 months after the respective, September 30, 2022 or March 31, 2023 due dates. • Department of Education (PDE): The time period for making a management decision on findings was approximately 9.3 to over 16.9 months after the FAC MDL start date for 14 out of 22 audit reports with findings. One of the 14 audit reports was improperly classified on PDE’s audit tracking list as not having federal award findings. There were additional audit reports with findings listed on PDE’s audit tracking list where management decisions were not made timely. • Department of Health (DOH): The time period for making a management decision on findings was over 11 months after the FAC MDL start date for two out of two audit reports with findings. One audit report with the late management decision on findings was excluded from DOH’s tracking list. Finding 2023 – 024: (continued) Criteria: 2 CFR Section 200.332, Requirements for pass-through entities, states in part: All pass-through entities must: (d) Monitor the activities of the subrecipient as necessary to ensure that the subaward is used for authorized purposes, in compliance with Federal statutes, regulations, and the terms and conditions of the subaward, and that subaward performance goals are achieved. Pass-through entity monitoring of the subrecipient must include: (2) Following-up and ensuring that the subrecipient takes timely and appropriate action on all deficiencies pertaining to the Federal award provided to the subrecipient from the pass-through entity detected through audits, on-site reviews, and written confirmation from the subrecipient, highlighting the status of actions planned or taken to address Single Audit findings related to the particular subaward. (3) Issuing a management decision for applicable audit findings pertaining only to the Federal award provided to the subrecipient from the pass-through entity as required by §200.521 [Management decision]. (f) Verify that every subrecipient is audited as required by Subpart F [Audit Requirements] of this part when it is expected that the subrecipient’s Federal awards expended during the respective fiscal year equaled or exceeded the threshold set forth in §200.501 [Audit requirements]. (g) Consider whether the results of the subrecipient’s audit, on-site review, or other monitoring indicate conditions that necessitate adjustments to the pass-through entity’s own records. (h) Consider taking enforcement action against noncompliant subrecipients as described in §200.339 [Remedies for noncompliance] of this part and in program regulations. In order to carry out these responsibilities properly, good internal control dictates that state pass-through agencies ensure subrecipient Single Audit SEFAs are representative of state payment records each year, and that the related federal programs have been properly subjected to Single Audit procedures. 2 CFR Section 200.512, Report submission, states in part: (a) General. (1) The audit must be completed and the data collection form described in paragraph (b) of this section and reporting package described in paragraph (c) of this section must be submitted within the earlier of 30 calendar days after receipt of the auditor’s report(s), or nine months after the end of the audit period. If the due date falls on a Saturday, Sunday, or Federal holiday, the reporting package is due the next business day. 2 CFR Section 200.521, Management decision, states in part: (a) General. The management decision must clearly state whether or not the finding is sustained, the reasons for the decision, and the expected auditee action to repay disallowed costs, make financial adjustments, or take other action. (d) Time requirements. The Federal awarding agency or pass-through entity responsible for issuing a management decision must do so within six months of acceptance of the audit report by the FAC. The auditee must initiate and proceed with corrective action as rapidly as possible and corrective action should begin no later than upon receipt of the audit report. 2 CFR Section 200.505, Sanctions, states: In cases of continued inability or unwillingness to have an audit conducted in accordance with this part, Federal agencies and pass-through entities must take appropriate action as provided in §200.339 [Remedies for noncompliance]. Finding 2023 – 024: (continued) 2 CFR Section 200.339, Remedies for noncompliance, states in part: If a non-Federal entity fails to comply with the U.S. Constitution, Federal statutes, regulations or the terms and conditions of a Federal award, the Federal awarding agency or pass-through entity may impose additional conditions, as described in §200.208 [Specific conditions]. If the Federal awarding agency or pass-through entity determines that noncompliance cannot be remedied by imposing additional conditions, the federal awarding agency or pass-through entity may take one or more of the following actions, as appropriate in the circumstances. (a) Temporarily withhold cash payments pending correction of the deficiency by the non-Federal entity or more severe enforcement action by the Federal awarding agency or pass-through entity. (b) Disallow (that is, deny both use of funds and any applicable matching credit for) all or part of the cost of the activity or action not in compliance. (c) Wholly or partly suspend or terminate the Federal award. (d) Initiate suspension or debarment proceedings as authorized under 2 CFR Part 180 and Federal awarding agency regulations (or in the case of a pass-through entity, recommend such a proceeding be initiated by a Federal awarding agency). (e) Withhold further Federal awards for the project or program. (f) Take other remedies that may be legally available. To ensure Commonwealth enforcement of federal regulations for subrecipient noncompliance with audit requirements, Commonwealth Management Directive 325.08, Amended – Remedies for Recipient Noncompliance with Audit Requirements, Section 5 related to policy, states in part: (a) Agencies must develop and implement remedial action that reflects the unique requirements of each program… (b) The remedial action should be implemented within six months from the date the first remedial action is initiated. At the end of the six-month period, the recipient should take the appropriate corrective action or the final stage of remedial action should be imposed on the recipient. Examples of remedial action include, but are not limited to: (1) Meeting or calling the recipient to explain the importance and benefits of the audit and audit resolution processes, emphasizing the value of the audit as an administrative tool and the Commonwealth’s reliance on an acceptable audit and prompt resolution as evidence of the recipient’s ability to properly administer the program. (2) Encouraging the entity to establish an audit committee or designate an individual as the single point of contact to: (a) Communicate regarding the audit. (b) Arrange for and oversee the audit. (c) Direct and monitor audit resolution. (3) Providing technical assistance to the recipient in devising and implementing an appropriate plan to remedy the noncompliance. (4) Withholding a portion of assistance payments until the noncompliance is resolved. (5) Withholding or disallowing overhead costs until the noncompliance is resolved. (6) Suspending the assistance agreement until the noncompliance is resolved. Finding 2023 – 024: (continued) (7) Terminating the assistance agreement with the recipient and, if necessary, seeking alternative entities to administer the program. Management Directive 325.09, Amended – Processing Subrecipient Single Audits of Federal Pass-Through Funds, Section 7 related to procedures, states in part: c. Agencies. (2) Evaluate single audit report submissions received from BAFM to determine program purpose acceptability by verifying, at a minimum, that all agency-funded programs are properly included on the applicable financial schedules; that findings affecting the agency contain sufficient information to facilitate a management decision; and that the subrecipient has submitted an adequate corrective action plan. (5) Issue management decisions relative to audit findings and crosscutting findings assigned to the agency for resolution, as required by 2 CFR §200.521. If responsible for the resolution of crosscutting findings, notify the affected agency or agencies upon resolution of such findings. (7) Impose or coordinate the imposition of remedial action in accordance with 2 CFR Part 200.339 and Management Directive 325.08 Amended, Remedies for Recipient Noncompliance with Audit Requirements, when subrecipients fail to comply with the provisions of Subpart F. Management Directive 325.12, Amended – Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office’s, Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: One reason provided by Commonwealth management for untimely audit resolution in the various agencies, including making management decisions, approving corrective action, and performing procedures to ensure the accuracy of subrecipient SEFAs, was either a change in staff or a lack of staff to follow up and process subrecipient audit reports more timely. Regarding late and outstanding audit report submissions, the Commonwealth agencies did not appear to be timely implementing remedial action steps in accordance with 2 CFR Section 200.339 and Commonwealth Management Directive 325.08 in order to ensure compliance with federal audit submission requirements. Effect: Since required management decisions were not made within six months to ensure appropriate corrective action was taken on audits received from subrecipients, the Commonwealth did not comply with federal regulations, and subrecipients were not made aware of acceptance or rejection of corrective action plans in a timely manner. Further, noncompliance may recur in future periods if control deficiencies are not corrected on a timely basis, and there is an increased risk of unallowable charges being made to federal programs if corrective action and recovery of questioned costs is not timely. Regarding the SEFA reviews or alternate procedures which are not being performed timely and the late Single Audit report submissions, there is an increased risk that subrecipients could be misspending and/or inappropriately tracking and reporting federal funds over multiple year periods, and these discrepancies may not be properly monitored, detected, and corrected by agency personnel on a timely basis as required. Finally, additional federal pass-through funds may be unaudited in the future without timely and effective remedial action from Commonwealth agencies to enforce compliance. Finding 2023 – 024: (continued) Recommendation: We recommend that the above weaknesses that cause untimely subrecipient Single Audit resolution, including untimely management decisions on findings, untimely review of the SEFA or alternate procedures, and late audit report submissions be corrected to ensure compliance with federal requirements and Commonwealth Management Directives, and to better ensure timelier subrecipient compliance with program requirements. Commonwealth agencies should promptly pursue outstanding audits and implement remedial action steps on a timely basis in accordance with 2 CFR Section 200.339 and Commonwealth Management Directive 325.08. DOH Response: DOH agrees with the finding. PDOA Response: PDOA agrees with the finding. PDA Response: PDA agrees with the finding and will be hiring a complement position to ensure compliance in the future. PDE Response: PDE agrees with the finding. Questioned Costs: The amount of questioned costs cannot be determined.

Corrective Action Plan

PDA: PDA will be hiring a complement position to develop and maintain an audit tracking report to ensure that all single audits are properly logged and processed. In addition, this position will review the financial information in each audit report to determine if all pass-through funding is properly included and subject to audit. This position will coordinate with the bureaus within PDA to ensure all required follow-up is completed in a timely manner. Anticipated Completion Date: 06/30/2024 Contact Name: Tracee Gotwalt, Audit Coordinator PDOA: The PDOA is looking to improve management decision communications in addition to more thorough evaluations as a new Comprehensive Monitoring Process pilot is starting in April 2024 to address the noncompliance of subrecipient monitoring. This has resulted in management designing control activities to achieve timely submissions in the future by initiating the following: 1. An audit tracking log has been established to track report submissions, document when they were received, initiated, findings requiring follow-up, and subsequent steps to finalize the audit. 2. A separate tracking mechanism is in place to ensure the monitoring of subrecipient activities for compliance with federal statutes, regulations, and the terms and conditions of the Agreement for the 52 Area Agency on Aging subrecipients. 3. PDOA is looking to fill a vacant position with a focus of tracking subrecipient expenditures in the aggregate and tracks Single Audit submissions on a Commonwealth wide basis since the Aging Cluster is material and has material sub-granted expenditures. 4. Since receiving the finding, PDOA has reached out to the resource account where Subrecipient Single Audit reports are received by the Federal Audit Clearinghouse (FAC) to verify all outstanding audit items for PDOA, as action is required within six months of receipt. 5. It is PDOAs impression that having increased oversight of the Schedule of Expenditures of Federal Awards (SEFA) will allow for timely dissemination of Management Decision Letters (MDL) in the six-month timeframe for making a management decision for federal award findings. 6. Additionally, PDOA will confirm a closure letter was sent to the Philadelphia Corporation for Aging documenting PDOA’s management decision regarding federal award findings, as included in their FYE 06/30/2021 Single Audit report. 7. Follow-Up procedures resulting from this finding will be reviewed and adjusted as needed to deliver optimal outcomes. Preliminary procedures will be directed to the agency’s audit review committee for resolution of completeness. 8. In the event the audit review committee determines additional steps beyond the monitoring efforts outlined above are insufficient, additional efforts will be communicated to the AAA network. Anticipated Completion Date: 06/30/2024 Contact Name: Jennifer Cave, Fiscal Management Specialist, PDOA Audit Liaison DOH: DOH’s subrecipient single audit tracking report now includes a mechanism to monitor management decision deadlines related to each entity’s FAC submission date. The process for tracking subrecipient audit reports with findings has been updated to include and highlight subrecipients’ audit reports where DOH is the lead agency for finding resolution or the report contains findings that relate to the Department. Anticipated Completion Date: 03/31/2024 Contact Name: Steven Marsden, Chief, Audit Resolution Section PDE: PDE has implemented weekly, monthly and quarterly checks to ensure that all single audits are properly logged and processed. The clerk typist will conduct a weekly review and provide confirmation to the audit coordinator by signature. Bi-weekly, the clerk typist will follow up on any single audits that remain open. Anticipated Completion Date: Completed Contact Names: Clayton Carroll, Audit Coordinator, Bureau of Budget & Fiscal Management; Jessica Sites, Director, Bureau of Budget & Fiscal Management

Prior Finding References

2022-014

About Subrecipient Monitoring →

FY 2022-06-30

FAC accepted this audit on March 16, 2023 — management decision was due September 16, 2023.

2022-004
Reporting
REPEATQUESTIONED COSTS

As the State Educational Agency (SEA), the Pennsylvania Department of Education (PDE) is required to submit annual data reports to the United States Department of Education (USDE) for the components of the Education Stabilization Fund (ESF) program. These reports support the annual collection of data pertaining to the uses of funds under the Governor?s Emergency Education Relief (GEER) Fund, Elementary and Secondary School Emergency Relief (ESSER) Fund, Coronavirus Response and Relief Supplemental Appropriations Act, 2021 ? Emergency Assistance to Non-Public Schools (CRRSA EANS) Program, and the American Rescue Plan ? Elementary and Secondary School Emergency Relief (ARP ESSER). USDE awards ESF grants to SEAs for the purpose of providing local educational agencies (LEAs), including charter schools that are LEAs, with emergency relief funds to address the impact of the Novel Coronavirus Disease 2019 (COVID-19) on elementary and secondary schools across the nation. LEAs must provide equitable services to students and teachers in non-public schools as required under the Coronavirus Aid, Relief, and Economic Security Act (CARES Act). During the fiscal year ended June 30, 2022, PDE was required to submit the ESSER and ARP ESSER annual report for the period October 1, 2020 through June 30, 2021 and the GEER and CRRSA EANS annual reports for the period July 1, 2020 through June 30, 2021. As the direct recipient of ESSER, ARP ESSER, GEER, and CRRSA EANS funds, PDE is responsible for ensuring the timeliness and accuracy of the annual report submissions. PDE obtained summary information from the LEAs to compile and submit the reports which contained all required data elements. However, PDE did not implement policies and procedures to ensure the accuracy of the information reported by the LEAs. Therefore, PDE was unable to provide supporting documentation for amounts reported by LEAs on the annual reports or to demonstrate that they had reviewed and verified the accuracy of this information. Criteria: The 2022 OMB Uniform Guidance Compliance Supplement, Part 4 ? Agency Program Requirements for the Education Stabilization Fund, Section L.3.a, Reporting ? Special Reporting ? Annual Reporting ? SEA/Governor, states in part: ESSER, GEER, and [CRRSA] EANS grantees must submit an annual performance report (OMB No. 1810-0749 for ESSER; 1810-0748 for GEER; and 1810-0765 for EANS) with data on expenditures, planned expenditures, subrecipients, and uses of funds, including for mandatory reservations. Finding 2022 ? 004: (continued) 2 CFR Section 200.303, Internal controls, states: The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in ?Standards for Internal Control in the Federal Government? issued by the Comptroller General of the United States or the ?Internal Control Integrated Framework?, issued by the Committee of the Sponsoring Organizations of the Treadway Commission (COSO). Management Directive 325.12, Amended ? Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: PDE did not implement policies and procedures to ensure the accuracy of information reported by LEAs which was included on the Annual Reports. Effect: Without review and validation of the detail supporting the summary information reported by LEAs, the Annual Reports may have contained inaccurate information. Recommendation: We recommend that PDE implement formal policies and procedures to verify the information reported by LEAs to be included on the Annual Reports. Reported amounts should be reviewed for accuracy before reports are submitted to USDE to ensure that reports filed are complete and accurate. Agency Response: PDE agrees with this finding. Questioned Costs: The amount of questioned costs cannot be determined. The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Show full finding ▾
Full finding narrative

Department of Education Finding 2022 ? 004: ALN 84.425C ? COVID 19 ? Education Stabilization Fund - GEER Fund ALN 84.425D ? COVID 19 ? Education Stabilization Fund - ESSER Fund ALN 84.425R ? COVID 19 ? Education Stabilization Fund - CRRSA EANS ALN 84.425U ? COVID 19 ? Education Stabilization Fund - ARP ESSER A Significant Deficiency and Noncompliance Exist at the Department of Education Related to Submission of GEER, ESSER, and CRRSA EANS Annual Reporting (A Similar Condition Was Noted in Prior Year Finding 2021-003) Federal Grant Number(s) and Year(s): S425D200028 (3/13/2020 ? 9/30/2024), S425D210028 (3/13/2020 ? 9/30/2024), S425U210028 (3/13/2020 ? 9/30/2024) Type of Finding: Significant Deficiency, Noncompliance Compliance Requirement: Reporting Condition: As the State Educational Agency (SEA), the Pennsylvania Department of Education (PDE) is required to submit annual data reports to the United States Department of Education (USDE) for the components of the Education Stabilization Fund (ESF) program. These reports support the annual collection of data pertaining to the uses of funds under the Governor?s Emergency Education Relief (GEER) Fund, Elementary and Secondary School Emergency Relief (ESSER) Fund, Coronavirus Response and Relief Supplemental Appropriations Act, 2021 ? Emergency Assistance to Non-Public Schools (CRRSA EANS) Program, and the American Rescue Plan ? Elementary and Secondary School Emergency Relief (ARP ESSER). USDE awards ESF grants to SEAs for the purpose of providing local educational agencies (LEAs), including charter schools that are LEAs, with emergency relief funds to address the impact of the Novel Coronavirus Disease 2019 (COVID-19) on elementary and secondary schools across the nation. LEAs must provide equitable services to students and teachers in non-public schools as required under the Coronavirus Aid, Relief, and Economic Security Act (CARES Act). During the fiscal year ended June 30, 2022, PDE was required to submit the ESSER and ARP ESSER annual report for the period October 1, 2020 through June 30, 2021 and the GEER and CRRSA EANS annual reports for the period July 1, 2020 through June 30, 2021. As the direct recipient of ESSER, ARP ESSER, GEER, and CRRSA EANS funds, PDE is responsible for ensuring the timeliness and accuracy of the annual report submissions. PDE obtained summary information from the LEAs to compile and submit the reports which contained all required data elements. However, PDE did not implement policies and procedures to ensure the accuracy of the information reported by the LEAs. Therefore, PDE was unable to provide supporting documentation for amounts reported by LEAs on the annual reports or to demonstrate that they had reviewed and verified the accuracy of this information. Criteria: The 2022 OMB Uniform Guidance Compliance Supplement, Part 4 ? Agency Program Requirements for the Education Stabilization Fund, Section L.3.a, Reporting ? Special Reporting ? Annual Reporting ? SEA/Governor, states in part: ESSER, GEER, and [CRRSA] EANS grantees must submit an annual performance report (OMB No. 1810-0749 for ESSER; 1810-0748 for GEER; and 1810-0765 for EANS) with data on expenditures, planned expenditures, subrecipients, and uses of funds, including for mandatory reservations. Finding 2022 ? 004: (continued) 2 CFR Section 200.303, Internal controls, states: The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in ?Standards for Internal Control in the Federal Government? issued by the Comptroller General of the United States or the ?Internal Control Integrated Framework?, issued by the Committee of the Sponsoring Organizations of the Treadway Commission (COSO). Management Directive 325.12, Amended ? Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: PDE did not implement policies and procedures to ensure the accuracy of information reported by LEAs which was included on the Annual Reports. Effect: Without review and validation of the detail supporting the summary information reported by LEAs, the Annual Reports may have contained inaccurate information. Recommendation: We recommend that PDE implement formal policies and procedures to verify the information reported by LEAs to be included on the Annual Reports. Reported amounts should be reviewed for accuracy before reports are submitted to USDE to ensure that reports filed are complete and accurate. Agency Response: PDE agrees with this finding. Questioned Costs: The amount of questioned costs cannot be determined. The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Corrective Action Plan

PDE uses its eGrants system to collect all LEA required records under ESSER I and ESSER II. The eGrants system is designed to allow licensed educational agencies and certain community-based programs within the Commonwealth, access to PDE grants. Through this system, the LEA can submit applications for funding, e-sign contracting documents, upload back-up documentation, submit program quarterly reports, and file final expenditure reports. PDE Division of Federal Programs also utilizes Pennsylvania's Information Management System (PIMS) to collect and verify LEA data. PIMS has business rules built in to ensure valid data collection. The eGrants system makes it possible for records pertaining to the ESSER awards to be retained separately from other grant funds, including funds that an SEA or LEA receives under the CARES Act and CRRSA. This follows the requirements under 2 C.F.R. ? 200.334 and 34 C.F.R. ? 76.730, including financial records related to the use of grant funds. Through quarterly financial reporting, LEAs are required to report the amount of cash received, expended, and on hand. If the amount of cash-on-hand reported is determined to be too high, or the quarterly report is not submitted, monthly payments will be suspended until the next quarterly report is due. Current monitoring to verify data and ensure compliance with existing federal guidelines, typically occurs from January through May. LEAs receive a unique username and password to access Fedmonitor and complete an online self-assessment. Beginning in October 2022, all LEAs were placed on a four-year monitoring cycle and were monitored in the 2021?22 fiscal year and will be monitored again in the 2024?25 fiscal year. Data collected in eGrants, PIMS and Fedmonitor is verified during these monitoring visits. Anticipated Completion Date: Completed Contact Person and Title: Susan McCrone, Division Manager, Federal Programs; Brian Campbell, Director, Bureau of Curriculum, Assessment, and Instruction

Prior Finding References

2021-003

About Reporting →
2022-005
Subrecipient Monitoring
MATERIAL WEAKNESSREPEATQUESTIONED COSTS

The Department of Environmental Protection (DEP) administers the Abandoned Mine Land Reclamation (AMLR) program funded by the United States Department of the Interior (DOI). During the fiscal year ended June 30, 2022, DEP expended $49,400,302 within the AMLR program, of which $13,270,381 was paid to 18 subrecipients with whom DEP executed subrecipient agreements to provide abandoned mine land reclamation repairs and services throughout Pennsylvania. Our audit testing disclosed that DEP did not conduct risk assessments or program monitoring of these subrecipient expenditures during the fiscal year ended June 30, 2022, since DEP considered these entities to be contractors and not subrecipients. Based on a recent determination made by DEP, these entities should be categorized as subrecipients. As such, DEP began implementing procedures to ensure federal regulations are met regarding subrecipient agreements. However, these procedures were implemented subsequent to the fiscal year ended June 30, 2022. While Single Audits of the AMLR subrecipients may be conducted each year, this auditing activity does not compensate for the lack of during-the-award program monitoring, since the timing, focus, and scope of subrecipient auditing activities after year end are different than compliance monitoring to be performed by program officials during the year. Criteria: As part of administering the AMLR program, DEP must have policies, procedures, and controls in place to ensure compliance with federal requirements within contract requirements and regulations. 2 CFR Section 200.332, Requirements for pass through entities, states in part: All pass-through entities must: (d) Monitor the activities of the subrecipient as necessary to ensure that the subaward is used for authorized purposes, in compliance with Federal statutes, regulations, and the terms and conditions of the subaward; and that subaward performance goals are achieved. Pass-through entity monitoring of the subrecipient must include: (1) Reviewing financial and performance reports required by the pass-through entity. (2) Following-up and ensuring that the subrecipient takes timely and appropriate action on all deficiencies pertaining to the Federal award provided to the subrecipient from the pass-through entity detected through audits, on-site reviews, and written confirmation from the subrecipient, highlighting the status of actions planned or taken to address Single Audit findings related to the particular subaward. (3) Issuing a management decision for audit findings pertaining to the Federal award provided to the subrecipient from the pass-through entity as required by ? 200.521 [Management decision]. Finding 2022 ? 005: (continued) (e) Depending upon the pass-through entity's assessment of risk posed by the subrecipient (as described in paragraph (b) of this section), the following monitoring tools may be useful for the pass-through entity to ensure proper accountability and compliance with program requirements and achievement of performance goals: (1) Providing subrecipients with training and technical assistance on program-related matters; and (2) Performing on-site reviews of the subrecipient's program operations; (3) Arranging for agreed-upon-procedures engagements as described in ?200.425 [Audit services]. The standard contract agreement between DEP and the local grantee states, in part: Audit/Compliance Review Requirements - The contractor must comply with all applicable federal and state grant requirements including the Single Audit Act Amendments of 1996; 2 CFR Part 200 as amended; and any other applicable law or regulation, and any amendment to such other applicable law or regulation that may be enacted or promulgated by the federal government. Management Directive 325.12, Amended ? Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: In previous years, DEP management considered these entities as contractors for whom subrecipient monitoring requirements were not applicable. However, based on recent determinations, DEP acknowledges these entities as subrecipients, not contractors, subject to federal subrecipient requirements. Effect: Without the completion of risk assessments and subrecipient monitoring, DEP cannot ensure compliance with federal statutes, regulations, and the terms and conditions of the subrecipient contracts, confirm that local subrecipients are performing satisfactory work, ensure the efficient use of program resources, and minimize the risk for fraud and abuse. Completing monitoring activities is essential for DEP to determine whether the local agencies are complying with federal regulations and spending grant funds appropriately. Recommendation: We recommend that DEP continue to develop and implement written policies and procedures for performing risk based during-the-award subrecipient monitoring and implement them immediately to ensure timely subrecipient compliance with federal regulations. On-site monitoring visits by state officials should be supported by documentation to show the monitoring performed, areas examined, conclusions reached, and that the monitoring was performed in compliance with applicable regulations. Agency Response: The Department of Environmental Protection agrees with the facts as presented in this finding. Questioned Costs: The amount of questioned costs cannot be determined. The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Show full finding ▾
Full finding narrative

Department of Environmental Protection Finding 2022 ? 005: ALN 15.252 ? Abandoned Mine Land Reclamation A Material Weakness and Material Noncompliance Exist at the Department of Environmental Protection Related to Subrecipient Monitoring (A Similar Condition Was Noted in Prior Year Finding 2021-004) Federal Grant Number(s) and Year(s): S21AF10015 (01/01/2021 ? 12/31/2023), S20AF20092 (10/01/2020 ? 09/30/2023), S20AF20006 (01/01/2020 ?? 12/31/2022), S19AF20006 (01/01/2019 ? 12/31/2021), S19AF20004 (12/01/2018 ? 11/30/2022), S18AF20004 (11/01/2017 ?10/31/2023) Type of Finding: Material Weakness, Material Noncompliance Compliance Requirement: Subrecipient Monitoring Condition: The Department of Environmental Protection (DEP) administers the Abandoned Mine Land Reclamation (AMLR) program funded by the United States Department of the Interior (DOI). During the fiscal year ended June 30, 2022, DEP expended $49,400,302 within the AMLR program, of which $13,270,381 was paid to 18 subrecipients with whom DEP executed subrecipient agreements to provide abandoned mine land reclamation repairs and services throughout Pennsylvania. Our audit testing disclosed that DEP did not conduct risk assessments or program monitoring of these subrecipient expenditures during the fiscal year ended June 30, 2022, since DEP considered these entities to be contractors and not subrecipients. Based on a recent determination made by DEP, these entities should be categorized as subrecipients. As such, DEP began implementing procedures to ensure federal regulations are met regarding subrecipient agreements. However, these procedures were implemented subsequent to the fiscal year ended June 30, 2022. While Single Audits of the AMLR subrecipients may be conducted each year, this auditing activity does not compensate for the lack of during-the-award program monitoring, since the timing, focus, and scope of subrecipient auditing activities after year end are different than compliance monitoring to be performed by program officials during the year. Criteria: As part of administering the AMLR program, DEP must have policies, procedures, and controls in place to ensure compliance with federal requirements within contract requirements and regulations. 2 CFR Section 200.332, Requirements for pass through entities, states in part: All pass-through entities must: (d) Monitor the activities of the subrecipient as necessary to ensure that the subaward is used for authorized purposes, in compliance with Federal statutes, regulations, and the terms and conditions of the subaward; and that subaward performance goals are achieved. Pass-through entity monitoring of the subrecipient must include: (1) Reviewing financial and performance reports required by the pass-through entity. (2) Following-up and ensuring that the subrecipient takes timely and appropriate action on all deficiencies pertaining to the Federal award provided to the subrecipient from the pass-through entity detected through audits, on-site reviews, and written confirmation from the subrecipient, highlighting the status of actions planned or taken to address Single Audit findings related to the particular subaward. (3) Issuing a management decision for audit findings pertaining to the Federal award provided to the subrecipient from the pass-through entity as required by ? 200.521 [Management decision]. Finding 2022 ? 005: (continued) (e) Depending upon the pass-through entity's assessment of risk posed by the subrecipient (as described in paragraph (b) of this section), the following monitoring tools may be useful for the pass-through entity to ensure proper accountability and compliance with program requirements and achievement of performance goals: (1) Providing subrecipients with training and technical assistance on program-related matters; and (2) Performing on-site reviews of the subrecipient's program operations; (3) Arranging for agreed-upon-procedures engagements as described in ?200.425 [Audit services]. The standard contract agreement between DEP and the local grantee states, in part: Audit/Compliance Review Requirements - The contractor must comply with all applicable federal and state grant requirements including the Single Audit Act Amendments of 1996; 2 CFR Part 200 as amended; and any other applicable law or regulation, and any amendment to such other applicable law or regulation that may be enacted or promulgated by the federal government. Management Directive 325.12, Amended ? Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: In previous years, DEP management considered these entities as contractors for whom subrecipient monitoring requirements were not applicable. However, based on recent determinations, DEP acknowledges these entities as subrecipients, not contractors, subject to federal subrecipient requirements. Effect: Without the completion of risk assessments and subrecipient monitoring, DEP cannot ensure compliance with federal statutes, regulations, and the terms and conditions of the subrecipient contracts, confirm that local subrecipients are performing satisfactory work, ensure the efficient use of program resources, and minimize the risk for fraud and abuse. Completing monitoring activities is essential for DEP to determine whether the local agencies are complying with federal regulations and spending grant funds appropriately. Recommendation: We recommend that DEP continue to develop and implement written policies and procedures for performing risk based during-the-award subrecipient monitoring and implement them immediately to ensure timely subrecipient compliance with federal regulations. On-site monitoring visits by state officials should be supported by documentation to show the monitoring performed, areas examined, conclusions reached, and that the monitoring was performed in compliance with applicable regulations. Agency Response: The Department of Environmental Protection agrees with the facts as presented in this finding. Questioned Costs: The amount of questioned costs cannot be determined. The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Corrective Action Plan

AMLR program representatives attended Department of Interior, Office of Surface Mining Reclamation and Enforcement online training covering 2 CFR 200 and contractor or subrecipient determinations. DEP ceased issuing AMLR grants under Management Directive 305.20, Grant Administration. DEP management has determined the recipients with existing agreements are subrecipients and DEP will follow this determination consistently with future agreements and accounting. DEP has developed written policies and procedures for subrecipient monitoring and has notified grantees to implement the policies and procedures immediately to ensure timely subrecipient compliance with federal regulations. Anticipated Completion Date: Completed Contact Person and Title: Patrick Webb, Acting Dir., Bureau of AMLR; Tim Golding, Executive Assistant, Office of Admin. and Management

Prior Finding References

2021-004

About Subrecipient Monitoring →
2022-006
Special Tests & Provisions
MATERIAL WEAKNESSREPEATQUESTIONED COSTS

During our audit of the Supplemental Nutrition Assistance Program (SNAP) administered by the Department of Human Services (DHS), we evaluated the security over Electronic Benefits Transfer (EBT) cards, which includes both the physical security of EBT cards during the issuance process at County Assistance Offices (CAO), as well as the handling of EBT cards returned from the United States Postal Service as undeliverable, or those that have been lost or stolen. EBT cards are the method by which SNAP benefit payments are made available to recipients. Also, EBT cards are the primary method by which cash and special allowance benefit payments are made available to Temporary Assistance for Needy Families (TANF) recipients. Total benefit expenditures for SNAP for the fiscal year ended June 30, 2022 totaled $5.6 billion. Total benefit expenditures for TANF for the fiscal year ended June 30, 2022 totaled $129.7 million. Fourteen of the 87 CAO and district locations that issued EBT cards were selected for site testing in the current audit period. During our review of the physical security over EBT cards, we noted exceptions at all CAO and district locations selected for testing. These exceptions included the following: 1) The ending inventory count of EBT cards at June 30, 2022 which was calculated using the weekly log including July 1, 2021, the daily logs for the fiscal year ended June 30, 2022, and the EBT shipment logs for the fiscal year ended June 30, 2022 did not reconcile to the inventory count on the weekly log including June 30, 2022 in the EBT Card Tracking Database (1 location); 2) The master list of cardmakers and pinners maintained by the EBT Project Office did not reconcile to the list provided by a district office. The master list includes five cardmakers and zero pinners. The district office list includes one pinner who is listed as a cardmaker on the master list (1 district office); 3) EBT cards were created outside of the hours of operations (2 district offices); 4) The Weekly Log was completed and closed prior to close of business (1 location); 5) The Electronic Payment Processing and Information Control (EPPIC) EBT Systems Application forms provided by a district office did not match the forms provided by the EBT Project Office (1 district office); 6) Failure to perform the following: ? Completion of the witness field on an EBT Shipment Verification Log (1 district); ? Completion of the weekly approver field on the Weekly Log (1 district office); ? Completion of the EBT Card Paper Logs daily instead of only in an emergency situation (1 location); ? Completion of the requestor field on the EPPIC EBT Systems Application forms (1 district office); ? Completion of the exceptions, approved, and approver fields on the Daily Log when a Form HS 764 was completed (2 district offices); ? Create adequate written internal procedures for EBT Security for over-the-counter card mailings (1 location); ? Designate a manager or supervisor to the EBT Coordinator role (1 location); Finding 2022 ? 006: (continued) ? Ensure that coverage for card pinning is available until 5:00 PM each business day (3 district offices and 1 location); ? Ensure EBT Card Tracking Database users are assigned the appropriate role responsibilities within the database. An employee has two active user accounts with different assigned staff roles to each account (1 district office); ? Ensure users no longer using the EBT Card Tracking Database are deactivated (1 district office and 1 location); ? Maintain adequate security of EBT cards (1 district office and 5 locations); ? Maintain adequate security of pinning device (1 district office and 4 locations); ? Maintain adequate security of EBT card printing device (1 location); ? Maintain adequate security of ribbons (1 district office and 4 locations); ? Maintain adequate security of paper EBT logs (3 locations); ? Maintain accurate EBT card inventory in the EBT Card Tracking Database (1 location); ? Maintain operational efficiency due to only having one PIN Select Device (1 district office); ? Maintain operational efficiency due to having an inoperable EBT Card Printer for a portion of the fiscal year (1 district office); ? Proper completion of Form HS 764 (1 district office and 1 location); ? Proper destruction of damaged EBT cards (1 district office); ? Proper format of the EPPIC EBT Systems Application form files sent to the Office of Income Maintenance (OIM) EBT Security Administrator (1 location); ? Scan Form HS 764 to case record after the EBT card is created (1 location); ? Provide the Ribbon Installation and Destruction Log from the EBT Card Tracking Database (1 district office); ? Retain EPPIC EBT Systems Application forms electronically (1 district office); ? Timely enter a shipment received into the EBT Card Tracking Database (1 location); ? Timely completion and submission of the EPPIC EBT Systems Application forms to OIM EBT Security (3 locations). Criteria: The 2022 OMB Uniform Guidance Compliance Supplement, Part 4 ? Agency Program Requirements for the SNAP Cluster, Special Tests and Provisions ? N.3 EBT Card Security, states: The state is required to maintain adequate security over, and documentation/records for, EBT cards to prevent their theft, embezzlement, loss, damage, destruction, unauthorized transfer, negotiation, or use (7 CFR Section 274.8(b)(3)). 7 CFR Section 274.5, Record retention and forms security, states: (c) Accountable Documents. (1) EBT cards shall be considered accountable documents. The State agency shall provide the following minimum security and control procedures for these documents: i. Secure storage; ii. Access limited to authorized personnel; iii. Bulk inventory control records; iv. Subsequent control records maintained through the point of issuance or use; and v. Periodic review and validation of inventory controls and records by parties not otherwise involved in maintaining control records. 45 CFR Section 75.302 applicable to TANF states: (b) The financial management system of each non-Federal entity must provide for the following (see also ?75.361, 75.362, 75.363, 75.364, and 75.365): Finding 2022 ? 006: (continued) (4) Effective control over, and accountability for, all funds, property, and other assets. The non-Federal entity must adequately safeguard all assets and assure that they are used solely for authorized purposes. See ?75.303. Management Directive 325.12, Amended ? Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: Established policies and procedures were not followed consistently across CAO and district locations, which resulted in ineffective internal controls over EBT card security. Effect: Without adequate security controls over EBT cards, there exists the possibility of misappropriation and/or abuse. Recommendation: We recommend that DHS monitor EBT card security at CAO and district locations on a regular basis to improve consistency in the execution of documented policies and procedures. Agency Response: DHS agrees with this finding. Questioned Costs: The amount of questioned costs cannot be determined. The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Show full finding ▾
Full finding narrative

Department of Human Services Finding 2022 ? 006: ALN 10.551 and 10.561 ? Supplemental Nutrition Assistance Program (SNAP) Cluster (including COVID-19) ALN 93.558 ? Temporary Assistance for Needy Families (including COVID-19) A Material Weakness and Material Noncompliance Exist at the Department of Human Services Related to Electronic Benefits Transfer Card Security (A Similar Condition Was Noted in Prior Year Finding 2021-005) Federal Grant Number(s) and Year(s): 221PA405S2514 (10/01/2021 ? 9/30/2022), 211PA405S2514 (10/01/2020 ? 9/30/2021), 2201PATANF (10/01/2021 ? 9/30/2022), 2101PATANF (10/01/2020 ? 9/30/2021), 2101PATANFC6 (10/01/2020 ? 9/30/2022) Type of Finding: Material Weakness, Material Noncompliance Compliance Requirement: Special Tests and Provisions related to EBT Card Security Condition: During our audit of the Supplemental Nutrition Assistance Program (SNAP) administered by the Department of Human Services (DHS), we evaluated the security over Electronic Benefits Transfer (EBT) cards, which includes both the physical security of EBT cards during the issuance process at County Assistance Offices (CAO), as well as the handling of EBT cards returned from the United States Postal Service as undeliverable, or those that have been lost or stolen. EBT cards are the method by which SNAP benefit payments are made available to recipients. Also, EBT cards are the primary method by which cash and special allowance benefit payments are made available to Temporary Assistance for Needy Families (TANF) recipients. Total benefit expenditures for SNAP for the fiscal year ended June 30, 2022 totaled $5.6 billion. Total benefit expenditures for TANF for the fiscal year ended June 30, 2022 totaled $129.7 million. Fourteen of the 87 CAO and district locations that issued EBT cards were selected for site testing in the current audit period. During our review of the physical security over EBT cards, we noted exceptions at all CAO and district locations selected for testing. These exceptions included the following: 1) The ending inventory count of EBT cards at June 30, 2022 which was calculated using the weekly log including July 1, 2021, the daily logs for the fiscal year ended June 30, 2022, and the EBT shipment logs for the fiscal year ended June 30, 2022 did not reconcile to the inventory count on the weekly log including June 30, 2022 in the EBT Card Tracking Database (1 location); 2) The master list of cardmakers and pinners maintained by the EBT Project Office did not reconcile to the list provided by a district office. The master list includes five cardmakers and zero pinners. The district office list includes one pinner who is listed as a cardmaker on the master list (1 district office); 3) EBT cards were created outside of the hours of operations (2 district offices); 4) The Weekly Log was completed and closed prior to close of business (1 location); 5) The Electronic Payment Processing and Information Control (EPPIC) EBT Systems Application forms provided by a district office did not match the forms provided by the EBT Project Office (1 district office); 6) Failure to perform the following: ? Completion of the witness field on an EBT Shipment Verification Log (1 district); ? Completion of the weekly approver field on the Weekly Log (1 district office); ? Completion of the EBT Card Paper Logs daily instead of only in an emergency situation (1 location); ? Completion of the requestor field on the EPPIC EBT Systems Application forms (1 district office); ? Completion of the exceptions, approved, and approver fields on the Daily Log when a Form HS 764 was completed (2 district offices); ? Create adequate written internal procedures for EBT Security for over-the-counter card mailings (1 location); ? Designate a manager or supervisor to the EBT Coordinator role (1 location); Finding 2022 ? 006: (continued) ? Ensure that coverage for card pinning is available until 5:00 PM each business day (3 district offices and 1 location); ? Ensure EBT Card Tracking Database users are assigned the appropriate role responsibilities within the database. An employee has two active user accounts with different assigned staff roles to each account (1 district office); ? Ensure users no longer using the EBT Card Tracking Database are deactivated (1 district office and 1 location); ? Maintain adequate security of EBT cards (1 district office and 5 locations); ? Maintain adequate security of pinning device (1 district office and 4 locations); ? Maintain adequate security of EBT card printing device (1 location); ? Maintain adequate security of ribbons (1 district office and 4 locations); ? Maintain adequate security of paper EBT logs (3 locations); ? Maintain accurate EBT card inventory in the EBT Card Tracking Database (1 location); ? Maintain operational efficiency due to only having one PIN Select Device (1 district office); ? Maintain operational efficiency due to having an inoperable EBT Card Printer for a portion of the fiscal year (1 district office); ? Proper completion of Form HS 764 (1 district office and 1 location); ? Proper destruction of damaged EBT cards (1 district office); ? Proper format of the EPPIC EBT Systems Application form files sent to the Office of Income Maintenance (OIM) EBT Security Administrator (1 location); ? Scan Form HS 764 to case record after the EBT card is created (1 location); ? Provide the Ribbon Installation and Destruction Log from the EBT Card Tracking Database (1 district office); ? Retain EPPIC EBT Systems Application forms electronically (1 district office); ? Timely enter a shipment received into the EBT Card Tracking Database (1 location); ? Timely completion and submission of the EPPIC EBT Systems Application forms to OIM EBT Security (3 locations). Criteria: The 2022 OMB Uniform Guidance Compliance Supplement, Part 4 ? Agency Program Requirements for the SNAP Cluster, Special Tests and Provisions ? N.3 EBT Card Security, states: The state is required to maintain adequate security over, and documentation/records for, EBT cards to prevent their theft, embezzlement, loss, damage, destruction, unauthorized transfer, negotiation, or use (7 CFR Section 274.8(b)(3)). 7 CFR Section 274.5, Record retention and forms security, states: (c) Accountable Documents. (1) EBT cards shall be considered accountable documents. The State agency shall provide the following minimum security and control procedures for these documents: i. Secure storage; ii. Access limited to authorized personnel; iii. Bulk inventory control records; iv. Subsequent control records maintained through the point of issuance or use; and v. Periodic review and validation of inventory controls and records by parties not otherwise involved in maintaining control records. 45 CFR Section 75.302 applicable to TANF states: (b) The financial management system of each non-Federal entity must provide for the following (see also ?75.361, 75.362, 75.363, 75.364, and 75.365): Finding 2022 ? 006: (continued) (4) Effective control over, and accountability for, all funds, property, and other assets. The non-Federal entity must adequately safeguard all assets and assure that they are used solely for authorized purposes. See ?75.303. Management Directive 325.12, Amended ? Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: Established policies and procedures were not followed consistently across CAO and district locations, which resulted in ineffective internal controls over EBT card security. Effect: Without adequate security controls over EBT cards, there exists the possibility of misappropriation and/or abuse. Recommendation: We recommend that DHS monitor EBT card security at CAO and district locations on a regular basis to improve consistency in the execution of documented policies and procedures. Agency Response: DHS agrees with this finding. Questioned Costs: The amount of questioned costs cannot be determined. The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Corrective Action Plan

Bureau of Operations (BOO): BOO will take the following actions to address the finding: 1. All CAOs and district offices will be reminded of the EBT Coordinators?, alternates?, pinners?, and card makers? responsibilities. The BOO will ensure users in the EBT Card Tracking Database know their responsibilities and segregation of duties and will ensure there is coverage for card pinning until 5:00 pm each business day. Also, reminders to be sent to review the OIM EBT Procedural Manual periodically and when updates occur. This has already taken place on October 7, 2022. 2. All CAOs and district offices will be reminded to maintain adequate security of the EBT cards, card inventory, pinning devices, and ribbons. The EBT office will ensure all offices have two pinning devices and that they are in working order. This has already taken place on October 7, 2022. 3. OIM mandates annual training for EBT personnel to be completed at the beginning of each year. The training includes reviewing the procedures that safeguard access to the EBT systems. Also included are the following: a. Review of roles and responsibilities and who may hold a role b. Card maker and pinner coverage for all business hours c. Proper security for EBT cards and associated items d. Timeframes for submitting changes e. Retention timeframes Training was completed in January 2023. Area managers and staff assistants monitor completion of the training. Bureau of Program Support (BPS)/EBT Project Office: BPS will take the following actions to address the finding: 1. The EBT Project Office will make updates to the EBT Procedures Manual (Manual) and OIM EPPIC EBT Systems Application form (application) as needed. Notification of updates will be sent to CAO staff via email. This is expected to occur by April 30, 2023. 2. The EBT Program office will provide guidelines for the CAOs to follow when reviewing/updating their written internal procedures for EBT security of card mailings. This is expected to occur by April 30, 2023. 3. The EBT Project Officer will start retraining parties that are responsible for the completion of the EBT Headquarters Card Destruction log. This is expected to occur by May 1, 2023. Bureau of Program Evaluation (BPE), Division of Corrective Action (DCA) will take the following actions to address the finding: BPE, DCA conducts EBT Card Security reviews at every CAO and District Office that issues EBT cards. These reviews are completed on a consistent basis, and in the future will be completed annually on a 3-year rotation basis, to ensure the improvement of the execution of documented policies and procedures. BPE/DCA will adjust the review criteria to incorporate any procedural changes implemented in the Electronic Benefit Transfer Handbook. Current rotation schedule spans FFY 2022- FFY 2024. The annual reviews for this cycle started October 2022. Anticipated Completion Date: BOO 1,2, 3- Completed; BPS 1, 2- 04/30/2023; BPS 3- 05/01/2023; BPE- Completed Contact Person and Title: BOO- Jeanette Coulston, Staff Assistant to Director of Bureau of Operations; BPS- Tonya Holloway, Division Director; BPE- Amira S. Milikin, Division Director

Prior Finding References

2021-005

About Special Tests and Provisions →
2022-007
Reporting / Special Tests & Provisions
REPEATQUESTIONED COSTS

Emergency Rental Assistance (ERA) 1 and ERA 2 state, local, and territorial recipients were required to submit monthly and quarterly reports to the United States Department of the Treasury (US Treasury). The monthly reports are brief two-question updates through which ERA recipients provide US Treasury with very high-level counts of the numbers of households receiving assistance and the amounts of ERA funds distributed. The quarterly reports are in-depth reports with data on an array of programmatic and financial information to provide transparency in the use and progress of ERA funds. Monthly reports were required for each month of the fiscal year ended June 30, 2022 and were due 15 days after the end of the month. Quarterly reports were required for each quarter of the fiscal year ended June 30, 2022 and were due October 29, 2021, February 1, 2022, April 15, 2022, and July 15, 2022. As the direct recipient of ERA funds, the Department of Human Services (DHS) is responsible for ensuring the timeliness and accuracy of the report submissions. DHS obtained report information from subrecipients which was compiled and included in the submitted reports. The reports contained all required data elements, however, DHS did not implement policies and procedures to ensure the accuracy of the information reported by the counties. Therefore, DHS was unable to provide supporting documentation for amounts reported by county subrecipients on the reports or to demonstrate that they had reviewed and verified the accuracy of this information. In addition, DHS was unable to provide support for timely submission of monthly reports. Criteria: The Emergency Rental Assistance Program Reporting Guidance published by the US Treasury identifies several steps in the reporting process: ? Recipients gather and maintain required information such as counts of applicants and participants; amounts paid directly or indirectly to tenants, landlords, and utility/home energy providers; amounts paid to subrecipients and contractors; and administrative expenses. ? Recipients will need to communicate with and gather required information from their subrecipients and contractors, if applicable. ? After manually entering or uploading the report information, Recipients must review the information entered or submitted to the online reporting forms for any errors and completeness. Following completion of the report in Treasury?s portal, the Recipient?s designated Authorized Representative for Reporting must certify to the authenticity and accuracy of the information provided and formally submit the report to Treasury. Finding 2022 ? 007: (continued) The 2022 OMB Uniform Guidance Compliance Supplement, Part 4 ? Agency Program Requirements for the Emergency Rental Assistance Program, Special Tests and Provisions ? N. ERA Funds Reallocations, states in part: ? Financial information certified by grantees used by Treasury to make reallocation determinations must be accurate and excess funds that are subject to involuntary recapture must be returned to Treasury in accordance with Treasury?s confirmation letter. ? The financial information certified as part of reallocation includes monthly expenditure and cumulative obligations levels, as described in the Treasury reallocation guidance. ERA 1 expenditures reported monthly by the grantee are inputs to Treasury?s reallocation expenditure ratio. ERA1 obligations certified in the Request for Reallocated Funds form (1505-0266), including in the Request for Voluntarily Reallocated Funds, are inputs into determining eligibility to receive reallocated funds. ? Pursuant to section 501(d) of the Consolidated Appropriations Act, 2021, Treasury is required to reallocate ?excess? ERA 1 award funds. Treasury?s objective in reallocations is to ensure ERA 1 award funds remain available to grantees in accordance with their jurisdictional needs and demonstrated capacity to deliver assistance while the ERA appropriations remain available. 2 CFR Section 200.303, Internal controls, states: The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in ?Standards for Internal Control in the Federal Government? issued by the Comptroller General of the United States or the ?Internal Control Integrated Framework?, issued by the Committee of the Sponsoring Organizations of the Treadway Commission (COSO). Management Directive 325.12, Amended ? Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: DHS did not implement policies and procedures to ensure the accuracy of information reported by counties which was included on the reports. DHS also did not implement policies and procedures to ensure that it maintained documentation of timely submission. Effect: Without review and validation of the detail supporting the summary information reported by counties, the reports may have contained inaccurate information. Inaccurate and/or untimely submission of monthly reports could impact the US Treasury?s ability to reallocate ERA 1 award funds pursuant to section 501(d) of the 2021 Consolidated Appropriations Act. Recommendation: We recommend that DHS implement formal policies and procedures to verify the information reported by counties to be included on the reports. Reported amounts should be reviewed for accuracy before reports are submitted to US Treasury to ensure that reports filed are complete and accurate. We further recommend that DHS retains documentation supporting when reports are submitted, and that this documentation is available for audit. Finding 2022 ? 007: (continued) Agency Response: DHS agrees with this finding. Pennsylvania legislation directed DHS funds to all 67 counties including 18 counties that received direct federal funds. Each subgrantee reported information regarding metrics outlined by the 10th of the month for the prior month. DHS reconciles various metrics in order to comply with US Treasury?s deadline to report monthly on the 15th of the month for the prior month. Similar to other DHS programs, DHS has implemented an after-action review of information submitted, using a contracted vendor. DHS faced challenges implementing a program with 67 counties and no central eligibility determination system. DHS has learned that standing up the supportive services and multi-sector partnerships was challenging in the context of the global pandemic workforce shortages. This made DHS dependent on local county reports to maintain program oversight and compile statewide data for submission to US Treasury. DHS will strengthen this control as we plan for future emergency or pandemic programs related to rental assistance. Questioned Costs: The amount of questioned costs cannot be determined. The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Show full finding ▾
Full finding narrative

Department of Human Services Finding 2022 ? 007: ALN 21.023 ? COVID 19 ? Emergency Rental Assistance Program A Significant Deficiency and Noncompliance Exist at the Department of Human Services Related to Submission of Emergency Rental Assistance Monthly and Quarterly Reporting and Special Tests and Provisions Related to ERA Funds Reallocation (A Similar Condition Was Noted in Prior Year Finding 2021-006) Federal Grant Number(s) and Year(s): G019649899 (3/13/2020 ? 9/30/2025), G017649899 (3/13/2020 ? 9/30/2025) Type of Finding: Significant Deficiency, Noncompliance Compliance Requirements: Reporting and Special Tests and Provisions related to ERA Funds Reallocation Condition: Emergency Rental Assistance (ERA) 1 and ERA 2 state, local, and territorial recipients were required to submit monthly and quarterly reports to the United States Department of the Treasury (US Treasury). The monthly reports are brief two-question updates through which ERA recipients provide US Treasury with very high-level counts of the numbers of households receiving assistance and the amounts of ERA funds distributed. The quarterly reports are in-depth reports with data on an array of programmatic and financial information to provide transparency in the use and progress of ERA funds. Monthly reports were required for each month of the fiscal year ended June 30, 2022 and were due 15 days after the end of the month. Quarterly reports were required for each quarter of the fiscal year ended June 30, 2022 and were due October 29, 2021, February 1, 2022, April 15, 2022, and July 15, 2022. As the direct recipient of ERA funds, the Department of Human Services (DHS) is responsible for ensuring the timeliness and accuracy of the report submissions. DHS obtained report information from subrecipients which was compiled and included in the submitted reports. The reports contained all required data elements, however, DHS did not implement policies and procedures to ensure the accuracy of the information reported by the counties. Therefore, DHS was unable to provide supporting documentation for amounts reported by county subrecipients on the reports or to demonstrate that they had reviewed and verified the accuracy of this information. In addition, DHS was unable to provide support for timely submission of monthly reports. Criteria: The Emergency Rental Assistance Program Reporting Guidance published by the US Treasury identifies several steps in the reporting process: ? Recipients gather and maintain required information such as counts of applicants and participants; amounts paid directly or indirectly to tenants, landlords, and utility/home energy providers; amounts paid to subrecipients and contractors; and administrative expenses. ? Recipients will need to communicate with and gather required information from their subrecipients and contractors, if applicable. ? After manually entering or uploading the report information, Recipients must review the information entered or submitted to the online reporting forms for any errors and completeness. Following completion of the report in Treasury?s portal, the Recipient?s designated Authorized Representative for Reporting must certify to the authenticity and accuracy of the information provided and formally submit the report to Treasury. Finding 2022 ? 007: (continued) The 2022 OMB Uniform Guidance Compliance Supplement, Part 4 ? Agency Program Requirements for the Emergency Rental Assistance Program, Special Tests and Provisions ? N. ERA Funds Reallocations, states in part: ? Financial information certified by grantees used by Treasury to make reallocation determinations must be accurate and excess funds that are subject to involuntary recapture must be returned to Treasury in accordance with Treasury?s confirmation letter. ? The financial information certified as part of reallocation includes monthly expenditure and cumulative obligations levels, as described in the Treasury reallocation guidance. ERA 1 expenditures reported monthly by the grantee are inputs to Treasury?s reallocation expenditure ratio. ERA1 obligations certified in the Request for Reallocated Funds form (1505-0266), including in the Request for Voluntarily Reallocated Funds, are inputs into determining eligibility to receive reallocated funds. ? Pursuant to section 501(d) of the Consolidated Appropriations Act, 2021, Treasury is required to reallocate ?excess? ERA 1 award funds. Treasury?s objective in reallocations is to ensure ERA 1 award funds remain available to grantees in accordance with their jurisdictional needs and demonstrated capacity to deliver assistance while the ERA appropriations remain available. 2 CFR Section 200.303, Internal controls, states: The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in ?Standards for Internal Control in the Federal Government? issued by the Comptroller General of the United States or the ?Internal Control Integrated Framework?, issued by the Committee of the Sponsoring Organizations of the Treadway Commission (COSO). Management Directive 325.12, Amended ? Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: DHS did not implement policies and procedures to ensure the accuracy of information reported by counties which was included on the reports. DHS also did not implement policies and procedures to ensure that it maintained documentation of timely submission. Effect: Without review and validation of the detail supporting the summary information reported by counties, the reports may have contained inaccurate information. Inaccurate and/or untimely submission of monthly reports could impact the US Treasury?s ability to reallocate ERA 1 award funds pursuant to section 501(d) of the 2021 Consolidated Appropriations Act. Recommendation: We recommend that DHS implement formal policies and procedures to verify the information reported by counties to be included on the reports. Reported amounts should be reviewed for accuracy before reports are submitted to US Treasury to ensure that reports filed are complete and accurate. We further recommend that DHS retains documentation supporting when reports are submitted, and that this documentation is available for audit. Finding 2022 ? 007: (continued) Agency Response: DHS agrees with this finding. Pennsylvania legislation directed DHS funds to all 67 counties including 18 counties that received direct federal funds. Each subgrantee reported information regarding metrics outlined by the 10th of the month for the prior month. DHS reconciles various metrics in order to comply with US Treasury?s deadline to report monthly on the 15th of the month for the prior month. Similar to other DHS programs, DHS has implemented an after-action review of information submitted, using a contracted vendor. DHS faced challenges implementing a program with 67 counties and no central eligibility determination system. DHS has learned that standing up the supportive services and multi-sector partnerships was challenging in the context of the global pandemic workforce shortages. This made DHS dependent on local county reports to maintain program oversight and compile statewide data for submission to US Treasury. DHS will strengthen this control as we plan for future emergency or pandemic programs related to rental assistance. Questioned Costs: The amount of questioned costs cannot be determined. The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Corrective Action Plan

Similar to other DHS programs, DHS has implemented an after-action review of information submitted, using a contracted vendor. DHS faced challenges implementing a program with 67 counties and no central eligibility determination system. DHS has learned that implementing the supportive services and multi-sector partnerships was challenging in the context of the global pandemic and workforce shortages. This made DHS dependent on local county reports to maintain program oversight and compile statewide data for submission to US Treasury. DHS plans to strengthen this control as we plan for future emergency or pandemic programs related to rental assistance. Anticipated Completion Date: 06/30/2023 Contact Person and Title: Joel O?Donnell, Director, Bureau of Program Support, OIM

Prior Finding References

2021-006

About Reporting, Special Tests and Provisions →
2022-008
Subrecipient Monitoring
REPEATQUESTIONED COSTS

During the fiscal year ended June 30, 2022, the Department of Human Services (DHS) paid $79.5 million in Temporary Assistance for Needy Families (TANF) funding to subrecipients within the New Directions, Cash Grants, and Alternatives to Abortion appropriations (or 22.1 percent) out of total federal TANF expenditures of $360.2 million reported on the June 30, 2022 Schedule of Expenditures of Federal Awards. Our testing of DHS?s during-the-award monitoring of subrecipients for the fiscal year ended June 30, 2022 disclosed that DHS performed on-site monitoring for 20 out of 21 subrecipients selected for testing. The on-site monitoring that was performed consisted of reviews of program operations including design, data entry accuracy and timeliness, case management analysis, and program payment performance goals. The on-site monitoring also included a review of a sample of TANF recipient case files to ensure that the recipients? TANF activities were documented and accurately entered in the Commonwealth?s Workforce Development System. However, DHS?s monitoring procedures for the 20 subrecipients were not adequate as they did not include a review or monitoring of subrecipient financial records, which would provide an assessment of a subrecipient?s compliance with applicable federal regulations. Although DHS?s monitoring procedures include reviewing subrecipient completed questionnaires for selected subrecipients that had questions related to financial matters, DHS?s monitoring personnel did not review subrecipient financial records. For example, DHS did not perform procedures to ensure subrecipient invoices agreed to the books and records of the subrecipient and that the records were adequate to support the allowability of costs paid by DHS during the award period. In addition, DHS?s monitoring procedures did not include an evaluation of the operating effectiveness of DHS subrecipients? procedures to monitor Single Audits and any related findings. Our testing of the 21 subrecipients noted above included follow up on one subrecipient identified in the prior year finding as not being on-site monitored by DHS when the risk assessment warranted on-site monitoring. Our follow-up during the current audit period disclosed that DHS did not conduct on-site monitoring for this subrecipient during the fiscal year ended June 30, 2022. Since the on-site monitoring was not completed, internal control weaknesses, noncompliance, and questioned costs may have existed and remained undetected during the current audit period. This subrecipient received $980,923 of TANF funds during the fiscal year ended June 30, 2022. Criteria: 45 CFR Section 75.352, Requirements for pass-through entities, states: All pass-through entities must: (d) Monitor the activities of the subrecipient as necessary to ensure that the subaward is used for authorized purposes, in compliance with Federal statutes, regulations, and the terms and conditions of the subaward; and that subaward performance goals are achieved. Pass-through entity monitoring of the subrecipient must include: (1) Reviewing financial and performance reports required by the pass-through entity. Finding 2022 ? 008: (continued) (2) Following-up and ensuring that the subrecipient takes timely and appropriate action on all deficiencies pertaining to the Federal award provided to the subrecipient from the pass-through entity detected through audits, on-site reviews, and other means. (3) Issuing a management decision for audit findings pertaining to the Federal award provided to the subrecipient from the pass-through entity as required by ? 75.521 [Management decision]. 2 CFR Section 200.332, Requirements for pass-through entities, states in part: All pass-through entities must: (e) Depending upon the pass-through entity's assessment of risk posed by the subrecipient (as described in paragraph (b) of this section), the following monitoring tools may be useful for the pass-through entity to ensure proper accountability and compliance with program requirements and achievement of performance goals: (1) Providing subrecipients with training and technical assistance on program-related matters; and (2) Performing on-site reviews of the subrecipient's program operations; (3) Arranging for agreed-upon-procedures engagements as described in ?200.425 [Audit services]. Management Directive 325.12, Amended ? Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: DHS planned to implement new during-the-award monitoring procedures to be used for the on-site monitoring of subrecipients, but these procedures were not in place for monitoring conducted during the fiscal year ended June 30, 2022. Therefore, DHS has not implemented adequate during-the-award monitoring procedures of subrecipients to include testing of the financial records and the subrecipients? monitoring of Single Audits sufficient to ensure compliance with federal regulations. Regarding the one subrecipient for which on-site monitoring was not completed, DHS personnel stated that they are working with the subrecipient to obtain the necessary documentation to complete the on-site monitoring. Effect: TANF subrecipients could be operating in noncompliance with federal regulations without timely detection and correction by DHS management. Recommendation: DHS should strengthen its controls to ensure during-the-award monitoring of TANF subrecipients includes procedures to ensure that subrecipients are in compliance with applicable federal regulations. This should include examining subrecipients? financial records and ensuring that all required Single Audits were obtained by DHS subrecipients. Agency Response: DHS agrees with this finding. Questioned Costs: The amount of questioned costs cannot be determined. The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Show full finding ▾
Full finding narrative

Department of Human Services Finding 2022 ? 008: ALN 93.558 ? Temporary Assistance for Needy Families (including COVID-19) Department of Human Services Did Not Validate Financial Information as Part of Its On-Site Monitoring of Temporary Assistance for Needy Families Subrecipients (A Similar Condition Was Noted in Prior Year Finding 2021-007) Federal Grant Number(s) and Year(s): 2201PATANF (10/01/2021 ? 9/30/2022), 2101PATANF (10/01/2020 ? 9/30/2021), 2001PATANF (10/01/2019 ? 9/30/2020), 1801PATANF (10/01/2017 ? 9/30/2018), 1701PATANF (10/01/2016 ? 9/30/2017) Type of Finding: Significant Deficiency, Noncompliance Compliance Requirement: Subrecipient Monitoring Condition: During the fiscal year ended June 30, 2022, the Department of Human Services (DHS) paid $79.5 million in Temporary Assistance for Needy Families (TANF) funding to subrecipients within the New Directions, Cash Grants, and Alternatives to Abortion appropriations (or 22.1 percent) out of total federal TANF expenditures of $360.2 million reported on the June 30, 2022 Schedule of Expenditures of Federal Awards. Our testing of DHS?s during-the-award monitoring of subrecipients for the fiscal year ended June 30, 2022 disclosed that DHS performed on-site monitoring for 20 out of 21 subrecipients selected for testing. The on-site monitoring that was performed consisted of reviews of program operations including design, data entry accuracy and timeliness, case management analysis, and program payment performance goals. The on-site monitoring also included a review of a sample of TANF recipient case files to ensure that the recipients? TANF activities were documented and accurately entered in the Commonwealth?s Workforce Development System. However, DHS?s monitoring procedures for the 20 subrecipients were not adequate as they did not include a review or monitoring of subrecipient financial records, which would provide an assessment of a subrecipient?s compliance with applicable federal regulations. Although DHS?s monitoring procedures include reviewing subrecipient completed questionnaires for selected subrecipients that had questions related to financial matters, DHS?s monitoring personnel did not review subrecipient financial records. For example, DHS did not perform procedures to ensure subrecipient invoices agreed to the books and records of the subrecipient and that the records were adequate to support the allowability of costs paid by DHS during the award period. In addition, DHS?s monitoring procedures did not include an evaluation of the operating effectiveness of DHS subrecipients? procedures to monitor Single Audits and any related findings. Our testing of the 21 subrecipients noted above included follow up on one subrecipient identified in the prior year finding as not being on-site monitored by DHS when the risk assessment warranted on-site monitoring. Our follow-up during the current audit period disclosed that DHS did not conduct on-site monitoring for this subrecipient during the fiscal year ended June 30, 2022. Since the on-site monitoring was not completed, internal control weaknesses, noncompliance, and questioned costs may have existed and remained undetected during the current audit period. This subrecipient received $980,923 of TANF funds during the fiscal year ended June 30, 2022. Criteria: 45 CFR Section 75.352, Requirements for pass-through entities, states: All pass-through entities must: (d) Monitor the activities of the subrecipient as necessary to ensure that the subaward is used for authorized purposes, in compliance with Federal statutes, regulations, and the terms and conditions of the subaward; and that subaward performance goals are achieved. Pass-through entity monitoring of the subrecipient must include: (1) Reviewing financial and performance reports required by the pass-through entity. Finding 2022 ? 008: (continued) (2) Following-up and ensuring that the subrecipient takes timely and appropriate action on all deficiencies pertaining to the Federal award provided to the subrecipient from the pass-through entity detected through audits, on-site reviews, and other means. (3) Issuing a management decision for audit findings pertaining to the Federal award provided to the subrecipient from the pass-through entity as required by ? 75.521 [Management decision]. 2 CFR Section 200.332, Requirements for pass-through entities, states in part: All pass-through entities must: (e) Depending upon the pass-through entity's assessment of risk posed by the subrecipient (as described in paragraph (b) of this section), the following monitoring tools may be useful for the pass-through entity to ensure proper accountability and compliance with program requirements and achievement of performance goals: (1) Providing subrecipients with training and technical assistance on program-related matters; and (2) Performing on-site reviews of the subrecipient's program operations; (3) Arranging for agreed-upon-procedures engagements as described in ?200.425 [Audit services]. Management Directive 325.12, Amended ? Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: DHS planned to implement new during-the-award monitoring procedures to be used for the on-site monitoring of subrecipients, but these procedures were not in place for monitoring conducted during the fiscal year ended June 30, 2022. Therefore, DHS has not implemented adequate during-the-award monitoring procedures of subrecipients to include testing of the financial records and the subrecipients? monitoring of Single Audits sufficient to ensure compliance with federal regulations. Regarding the one subrecipient for which on-site monitoring was not completed, DHS personnel stated that they are working with the subrecipient to obtain the necessary documentation to complete the on-site monitoring. Effect: TANF subrecipients could be operating in noncompliance with federal regulations without timely detection and correction by DHS management. Recommendation: DHS should strengthen its controls to ensure during-the-award monitoring of TANF subrecipients includes procedures to ensure that subrecipients are in compliance with applicable federal regulations. This should include examining subrecipients? financial records and ensuring that all required Single Audits were obtained by DHS subrecipients. Agency Response: DHS agrees with this finding. Questioned Costs: The amount of questioned costs cannot be determined. The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Corrective Action Plan

New Directions DHS is exploring different possibilities to satisfy the audit finding to include the contracting of a certified public accounting firm to assist in conducting the financial portion of our subrecipient monitoring. Alternatives to Abortion Office of Policy Development (OPD) initiated numerous conversations with the Alternatives to Abortion grantee regarding receiving the requested documentation for monitoring (communication occurred regularly from April 2021 through January 2023). The grantee disagrees that the disclosure of this information is a requirement of the grant agreement and as such has not provided the documentation needed to complete the monitoring. On October 27, 2022, DHS sent a letter to the grantee outlining specific action steps to establish compliance with their grant agreement. The grantee responded on November 28, 2022, disputing the claims of DHS and asserting that they are not out of compliance with their grant agreement. OPD will be scheduling time to visit the grantee to review documents required by the terms of their grant agreement in order to complete the monitoring. Monitoring will occur by June 30, 2023. Anticipated Completion Date: New Directions- 03/01/2024; Alternatives to Abortion- 06/30/2023 Contact Person and Title: New Directions- Joel O?Donnell, Director, Bureau of Program Support, OIM; Alternatives to Abortion- Ana Arcs, Acting Policy Director, OPD

Prior Finding References

2021-007

About Subrecipient Monitoring →
2022-009
Special Tests & Provisions
REPEAT

The Pennsylvania Department of Human Services (DHS) is required by the United States Department of Health and Human Services (HHS), Centers for Medicare and Medicaid Services (CMS), to implement six required Medicaid National Correct Coding Initiative (NCCI) methodologies. These methodologies include procedure-to-procedure and medically unlikely edits of Medicaid fee-for-service claims submitted for processing through DHS?s PROMISe system to ensure that only proper payments of Medicaid procedures are reimbursed. As part of this process, DHS is required to download quarterly NCCI edit tables from CMS which are subsequently uploaded into PROMISe by DHS?s PROMISe vendor. During the fiscal year ended June 30, 2022, DHS did not ensure that its contract and amendments with the PROMISe vendor included two out of seven elements of the NCCI Confidentiality Agreement required by the HHS/CMS Medicaid NCCI Technical Guidance Manual. The two missing elements included: ? Disclosure shall be limited to only those responsible for the implementation of the quarterly state Medicaid NCCI edit files. ? Only a state Medicaid agency has the discretion to release additional information for selected individual edits or limited ranges of edits from the files posted on the secure RISSNET portal. Criteria: Management Directive 325.12, Amended ? Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should identify, analyze, and respond to significant changes that could impact the internal control system. The HHS/CMS Medicaid NCCI Technical Guidance Manual, Section 7.1.2, Sharing of State Medicaid NCCI Edit Files by States with Other Entities, states in part: A state Medicaid agency may share these quarterly state Medicaid NCCI edit files which are posted on the secure RISSNET [Regional Information Sharing System Network] portal with the contracted fiscal agent that processes its FFS [fee-for-service] claims or with any of its contracted Medicaid managed-care entities that is using the Medicaid NCCI methodologies in its processing of claims or encounter data, if appropriate confidentiality agreements are in place. Finding 2022 ? 009: (continued) The HHS/CMS Medicaid NCCI Technical Guidance Manual, Section 7.1.3, Confidentiality Agreements Requirements for Contracted Parties, states: At a minimum, the following elements must be included in the confidentiality agreements for any contracted party using the Medicaid NCCI files posted on the secure RISSNET portal: Disclosure shall be limited to only those responsible for the implementation of the quarterly state Medicaid NCCI edit files. After the start of the new calendar quarter, a contracted party may disclose only non-confidential information contained in the Medicaid NCCI edit files that is also available to the general public found on the NCCI Medicaid webpage. The contracted party agrees to use any non-public information from the quarterly state Medicaid NCCI edit files only for any business purposes directly related to the implementation of the Medicaid NCCI methodologies in the particular state. New, revised, or deleted Medicaid NCCI edits shall not be published or otherwise shared with individuals, medical societies, or any other entities unless it is a contracted party prior to the posting of the Medicaid NCCI edits on the NCCI Medicaid webpage. Implementation of new, revised, or deleted Medicaid NCCI edits shall not occur prior to the first day of the calendar quarter. Only a state Medicaid agency has the discretion to release additional information for selected individual edits or limited ranges of edits from the files posted on the secure RISSNET portal. State Medicaid agencies must impose penalties, up to and including loss of contract, for violations of any confidentiality agreement relating to use of the secure RISSNET portal edit files. Cause: DHS personnel added five of the seven confidentiality agreement elements required by the HHS/CMS Medicaid NCCI Technical Guidance Manual to a PROMISe vendor contract amendment in 2022 but did not add the remaining two elements because they believed the elements were already covered by existing contract terms. Effect: Since DHS did not ensure two of the seven elements of the required NCCI Confidentiality Agreement were included in its contract with the PROMISe vendor, DHS was not in compliance with federal regulations. Recommendation: DHS should ensure the two missing elements of the required NCCI Confidentiality Agreement are included in an amendment to its contract with the PROMISe vendor. Agency Response: DHS agrees with this finding. Questioned Costs: None The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Show full finding ▾
Full finding narrative

Department of Human Services Finding 2022 ? 009: ALN 93.775, 93.777, and 93.778 ? Medicaid Cluster (including COVID-19) A Significant Deficiency and Noncompliance Exist at the Department of Human Services Related to the Medicaid National Correct Coding Initiative (A Similar Condition Was Noted in Prior Year Finding 2021-009) Federal Grant Number(s) and Year(s): 2205PA5MAP (10/01/2021 ? 9/30/2022), 2205PA5ADM (10/01/2021 ? 9/30/2022), 2105PA5MAP (10/01/2020 ? 9/30/2021), 2105PA5ADM (10/01/2020 ? 9/30/2021) Type of Finding: Significant Deficiency, Noncompliance Compliance Requirement: Special Tests and Provisions related to the Medicaid National Correct Coding Initiative (NCCI) Condition: The Pennsylvania Department of Human Services (DHS) is required by the United States Department of Health and Human Services (HHS), Centers for Medicare and Medicaid Services (CMS), to implement six required Medicaid National Correct Coding Initiative (NCCI) methodologies. These methodologies include procedure-to-procedure and medically unlikely edits of Medicaid fee-for-service claims submitted for processing through DHS?s PROMISe system to ensure that only proper payments of Medicaid procedures are reimbursed. As part of this process, DHS is required to download quarterly NCCI edit tables from CMS which are subsequently uploaded into PROMISe by DHS?s PROMISe vendor. During the fiscal year ended June 30, 2022, DHS did not ensure that its contract and amendments with the PROMISe vendor included two out of seven elements of the NCCI Confidentiality Agreement required by the HHS/CMS Medicaid NCCI Technical Guidance Manual. The two missing elements included: ? Disclosure shall be limited to only those responsible for the implementation of the quarterly state Medicaid NCCI edit files. ? Only a state Medicaid agency has the discretion to release additional information for selected individual edits or limited ranges of edits from the files posted on the secure RISSNET portal. Criteria: Management Directive 325.12, Amended ? Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should identify, analyze, and respond to significant changes that could impact the internal control system. The HHS/CMS Medicaid NCCI Technical Guidance Manual, Section 7.1.2, Sharing of State Medicaid NCCI Edit Files by States with Other Entities, states in part: A state Medicaid agency may share these quarterly state Medicaid NCCI edit files which are posted on the secure RISSNET [Regional Information Sharing System Network] portal with the contracted fiscal agent that processes its FFS [fee-for-service] claims or with any of its contracted Medicaid managed-care entities that is using the Medicaid NCCI methodologies in its processing of claims or encounter data, if appropriate confidentiality agreements are in place. Finding 2022 ? 009: (continued) The HHS/CMS Medicaid NCCI Technical Guidance Manual, Section 7.1.3, Confidentiality Agreements Requirements for Contracted Parties, states: At a minimum, the following elements must be included in the confidentiality agreements for any contracted party using the Medicaid NCCI files posted on the secure RISSNET portal: Disclosure shall be limited to only those responsible for the implementation of the quarterly state Medicaid NCCI edit files. After the start of the new calendar quarter, a contracted party may disclose only non-confidential information contained in the Medicaid NCCI edit files that is also available to the general public found on the NCCI Medicaid webpage. The contracted party agrees to use any non-public information from the quarterly state Medicaid NCCI edit files only for any business purposes directly related to the implementation of the Medicaid NCCI methodologies in the particular state. New, revised, or deleted Medicaid NCCI edits shall not be published or otherwise shared with individuals, medical societies, or any other entities unless it is a contracted party prior to the posting of the Medicaid NCCI edits on the NCCI Medicaid webpage. Implementation of new, revised, or deleted Medicaid NCCI edits shall not occur prior to the first day of the calendar quarter. Only a state Medicaid agency has the discretion to release additional information for selected individual edits or limited ranges of edits from the files posted on the secure RISSNET portal. State Medicaid agencies must impose penalties, up to and including loss of contract, for violations of any confidentiality agreement relating to use of the secure RISSNET portal edit files. Cause: DHS personnel added five of the seven confidentiality agreement elements required by the HHS/CMS Medicaid NCCI Technical Guidance Manual to a PROMISe vendor contract amendment in 2022 but did not add the remaining two elements because they believed the elements were already covered by existing contract terms. Effect: Since DHS did not ensure two of the seven elements of the required NCCI Confidentiality Agreement were included in its contract with the PROMISe vendor, DHS was not in compliance with federal regulations. Recommendation: DHS should ensure the two missing elements of the required NCCI Confidentiality Agreement are included in an amendment to its contract with the PROMISe vendor. Agency Response: DHS agrees with this finding. Questioned Costs: None The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Corrective Action Plan

Office of Medical Assistance Programs? Bureau of Data and Claims Management (BDCM) is currently negotiating an amendment to the PROMISe contract with Gainwell Technologies which will bolster the NCCI performance requirement to explicitly include the elements identified in the finding. Anticipated Completion Date: 05/01/2023 Contact Person and Title: Toni Hoffecker, Dir., Div. of Systems, Monitoring and Oversight, BDCM

Prior Finding References

2021-009

About Special Tests and Provisions →
2022-010
Special Tests & Provisions

The Pennsylvania Department of Agriculture (PDA), Bureau of Food Assistance (BFA), is responsible for the accountability of the United States Department of Agriculture (USDA) donated food under the National School Lunch Program (NSLP) and Summer Food Service Program for Children (SFSP) within the Child and Nutrition Cluster (CNC). BFA utilizes a computer application as an inventory and distribution tracking system for donated food. The Agency Summary Report and the Commodity Inventory Summary for Distributors and Processors generated in the computer application are used to compile commodity expenditures reported on the Schedule of Expenditures of Federal Awards (SEFA). BFA performs reconciliations of the inventory, commodity receipts, and distributions in these reports to distributor, processor, and recipient activity. As part of our audit procedures, we performed certain tests of information technology (IT) general controls for the fiscal year ended June 30, 2022. Our IT procedures for the CNC inventory application included a review of the controls over the migration of data, as well as a review of user acceptance testing of certain reports during a system upgrade to a new application platform in June 2022. Our procedures disclosed significant deficiencies in internal controls over testing of reports and the migration of inventory data from the old application platform to the new application platform by the Conservation and Environment (C&E) Delivery Center in the Office of Administration, Office for Information Technology (OA-OIT), that supports the IT systems used by BFA. Specifically, we found that migration of the data from the old application database to the new application database was not performed in accordance with established OA-OIT policy as follows: ? A migration audit plan checklist was not completed. ? A testing strategy and plan was not prepared and/or maintained to document the following: o What was to be tested and by whom; o Test environment requirements, configurations, and preparations; o Test pass/fail criteria; o Test and validation checklists; and o Test result reviews and approvals. ? Reports that were used in the side-by-side comparison of the old system to the new system after migration were not retained for audit purposes. Further, we found that, while there was evidence of some user acceptance testing prior to system implementation, certain reports significant to the audit and to the preparation and reconciliation of the SEFA were subjected to user acceptance testing in October 2022 and December 2022, after ?go live? and after completion of the year-end inventory reconciliations. A detailed schedule of IT issues has been provided to OA-OIT for corrective action. Finding 2022 ? 010: (continued) In addition to testing the IT general controls described above, we also tested various reports generated by the system that were used by BFA to perform reconciliations and compile commodity expenditures reported in the SEFA as of June 30, 2022. We noted the following: Regarding the Commodity Processors Inventory Report which contained a total of 66 processors, some of which were inactive and not part of our testing population: ? For ten processors, when the report was generated for the entire year, and the beginning inventory for the commodity was zero, the report doubled the ending inventory. ? For three processors, the report displayed the wrong name for the related processor number. ? For five processors, when the report was generated for the entire year, the report displayed the processor as inactive despite having an ending inventory balance. BFA had to activate these processors in order to obtain the individual processor report activity. Regarding the Commodity Distributor Inventory Report: ? Inventory balances continue to be displayed on this report for three inactive distributors. Although all inventory was transferred to a new distributor, the transfer was not accounted for under the inactive distributors. ? Inventory balances for the two active distributors did not agree to the year-end physical inventory counts when the report was generated in October 2022. One distributor had a discrepancy of 1,794 cases and the other distributor had a discrepancy of 9,835 cases out of a total of 191,796 cases in year-end inventory. Reports generated in January 2023 displayed the ending balance that agreed to the year-end physical inventory counts. Regarding the Agency Summary Report: ? For one of the 25 recipients selected for testing from the Agency Summary Report, one month?s distribution activity for a selected commodity did not agree to the recipient?s records. We noted a difference of 29.22 more pounds received per the recipient?s invoices than was shown on the agency usage report that neither the recipient nor BFA could explain. We also noted discrepancies with BFA?s processor monthly performance reports (MPR), distributor monthly reconciliations, and year-end inventory reconciliations. We noted the following discrepancies in these reconciliations: ? Our testing of 25 processors? MPRs disclosed that for two processors BFA could not provide an MPR that agreed to the Commodity Processors Inventory Report which was prepared from the inventory application. ? Our testing of 15 receipt dates from three distributor monthly reconciliations disclosed a difference of 12 cases between USDA?s receipts and BFA?s receipts for one of the dates tested. BFA?s records were reconciled to the distributor?s records, and the difference was adjusted to agree to the distributor?s records without resolving the differences with USDA?s receipts. ? Our testing of BFA?s year-end reconciliation provided in October 2022 disclosed differences between distributor beginning inventory, receipts, distributions, and ending inventory balances and commodity inventory report balances. These differences impacted the commodity balances reported on the SEFA. The NSLP commodity amount was overstated by $248,640, and the SFSP commodity amount was understated by $107,616, for a net immaterial overstatement of $141,024 for the Child Nutrition Cluster. Criteria: Management Directive 325.12, Amended ? Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book). Finding 2022 ? 010: (continued) ? Green Book Principle 11 ? Design Activities for the Information System, states in part: o 11.09 Management designs control activities over the information technology infrastructure to support the completeness, accuracy, and validity of information processing by information technology. ? Management evaluates the objectives of the entity and related risks in designing control activities for the information technology infrastructure. OA-OIT issued the following Information Technology Policy (ITP) and Operational Document (OPD) to provide governance and guidance to agencies during implementation of new systems and placement of servers in the Enterprise Data Center: ? ITP-INF000 ? Enterprise Data and Information Management Policy, provides direction for effectively managing data and information life cycles including establishing data migration controls for data sets to be accessed from their original sources and efficiently moved from source to target destinations in an effective and secure manner. ? OPD-INF000A ? Migration Audit Checklist Template, which agencies must use to facilitate data migration as delineated in ITP-INF000. The 2022 OMB Uniform Guidance Compliance Supplement, Part 4 ? Agency Program Requirements for the CNC Cluster, Special Tests and Provisions ? N.2 Accountability for USDA ? Donated Foods, states: a. Maintenance of Records: Distributing and subdistributing agencies (as defined at 7 CFR section 250.3) must maintain accurate and complete records with respect to the receipt, distribution, and inventory of USDA-donated foods, including end products processed from donated food. 7 CFR Section 250.19, Recordkeeping requirements, states: (a) Required records. Distributing agencies, recipient agencies, processors, and other entities must maintain records of agreements and contracts, reports, audits, and claim actions, funds obtained as an incident of donated food distribution, and other records specifically required in this part or in other Departmental regulations, as applicable. Cause: Data migration occurred for this application as part of an upgrade to a new platform in June 2022. Due to the age of the application, it was no longer being supported by existing Enterprise Data Center infrastructure and technology. The C&E Delivery Center development team indicated that they were unaware that the ITP-INF000 ? Enterprise Data and Information Management Policy existed at the time of the data conversion. They indicated that while the web application was rewritten to utilize newer Microsoft technologies, large portions of the database utilized the same data structure as the previous system. Data queries were used to move data from one database to the other, and the data queries were written and tested. After the scripts were run, reports were compared side-by-side using the old system and the new system. When we requested additional evidence, management provided copies of the data queries and the change advisory board approval for the implementation of the new system but could not provide evidence of successful testing or evidence that reports comparing the old system and new system reconciled. During testing of the year-end inventory reconciliations, the auditors attempted to tie to reports they downloaded from the system and found the errors noted above. Once the identified errors in the downloaded reports were communicated to management, contracted personnel from the C&E Delivery Center corrected some, but not all, of the reports listed above. The C&E Delivery Center contractor represented that the issues identified during the audit were the result of how the reports were generated in the new system and were not issues with the underlying data, but no evidence to support this statement was provided. Further, certain issues, such as inactive distributors included on the system reports, had not been corrected as of our testing date in January 2023. Finding 2022 ? 010: (continued) While PDA provided a one-page document entitled Acceptance of Project Deliverable signed by BFA personnel on June 3, 2022, the emails documenting completion of user acceptance testing of the specific incorrect reports listed were dated October 2022 and December 2022, after ?go live? and after completion of the year-end inventory reconciliations. PDA management stated that issues were encountered with inventory reports after the inventory system was upgraded in June 2022 where fixes needed to be made as errors were being discovered. Also, a new distributor was added during the audit period that failed to submit complete files which resulted in reconciliation issues. PDA management erroneously believes that all discrepancies in inventory reports have been resolved and ending inventory balances are correct. Effect: The C&E Delivery Center?s failure to follow OA-OIT?s Enterprise Data and Information Management Policy resulted in the lack of certain controls over data migration including adequate planning, execution, and validation. The lack of evidence of successful, planned testing and comparisons of before and after snapshots of the data and inventory balances may have led to data migration errors that may have impacted the integrity, accuracy, and security of the data. Therefore, PDA management had little assurance prior to the audit that inventory balances transferred over completely and accurately. The lack of user acceptance testing prior to implementation of the new system (known as ?go live?) contributed to the inaccurate reports that failed to support the reconciliations provided for audit. Without direct intervention from the auditors, the inventory reports for the CNC program may not have been corrected, and similar reports generated for nonmajor programs may still contain errors. The discrepancies noted above related to inaccurate records could result in improper distribution of donated foods and misstatements in BFA?s inventory reconciliations and commodity expenditures reported in the SEFA. Recommendation: PDA should maintain accurate and complete records with respect to the receipt, distribution, and inventory of USDA-donated foods, including end products processed from donated food. PDA should strengthen procedures for future periods to ensure errors identified during the reconciliation process are corrected timely in the system. OA-OIT and the C&E Delivery Center should perform the following: ? Work with BFA personnel to ensure all inventory reports generated from the new system are correct, tie to actual inventory balances on hand, and include the correct distribution centers. This should be done for CNC as well as for any nonmajor programs that utilize the same inventory application. ? Ensure that all system development personnel are aware of the data migration requirements detailed in Commonwealth policy prior to future system upgrades. ? Ensure adequate user acceptance testing is performed for all key reports prior to ?go live? in future system upgrades. OA-OIT Response: OA-OIT and the C&E Delivery Center agree with the facts of the finding. PDA Response: PDA agrees with the facts of the finding. Questioned Costs: None The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Show full finding ▾
Full finding narrative

Office of Administration ? Office for Information Technology Department of Agriculture Finding 2022 ? 010: ALN 10.553, 10.555, 10.556, 10.559, and 10.582 ? Child Nutrition Cluster (including COVID-19) Controls Over Information Technology System Migration and Controls Over the Accountability of Donated Foods Need Improvement Federal Grant Number(s) and Year(s): 1PA300365 (01/01/2022 ? 9/30/2023), 1PA310305 (10/01/2021 ? 9/30/2022), 1PA310305 (10/01/2020 ? 9/30/2021), 1PA300305 (10/01/2021 ? 9/30/2022), 1PA300305 (10/01/2020 ? 9/30/2021), 1PA320305 (12/27/2020 ? 9/30/2021) Type of Finding: Significant Deficiency, Noncompliance Compliance Requirement: Special Tests and Provisions related to Accountability for USDA - Donated Foods Condition: The Pennsylvania Department of Agriculture (PDA), Bureau of Food Assistance (BFA), is responsible for the accountability of the United States Department of Agriculture (USDA) donated food under the National School Lunch Program (NSLP) and Summer Food Service Program for Children (SFSP) within the Child and Nutrition Cluster (CNC). BFA utilizes a computer application as an inventory and distribution tracking system for donated food. The Agency Summary Report and the Commodity Inventory Summary for Distributors and Processors generated in the computer application are used to compile commodity expenditures reported on the Schedule of Expenditures of Federal Awards (SEFA). BFA performs reconciliations of the inventory, commodity receipts, and distributions in these reports to distributor, processor, and recipient activity. As part of our audit procedures, we performed certain tests of information technology (IT) general controls for the fiscal year ended June 30, 2022. Our IT procedures for the CNC inventory application included a review of the controls over the migration of data, as well as a review of user acceptance testing of certain reports during a system upgrade to a new application platform in June 2022. Our procedures disclosed significant deficiencies in internal controls over testing of reports and the migration of inventory data from the old application platform to the new application platform by the Conservation and Environment (C&E) Delivery Center in the Office of Administration, Office for Information Technology (OA-OIT), that supports the IT systems used by BFA. Specifically, we found that migration of the data from the old application database to the new application database was not performed in accordance with established OA-OIT policy as follows: ? A migration audit plan checklist was not completed. ? A testing strategy and plan was not prepared and/or maintained to document the following: o What was to be tested and by whom; o Test environment requirements, configurations, and preparations; o Test pass/fail criteria; o Test and validation checklists; and o Test result reviews and approvals. ? Reports that were used in the side-by-side comparison of the old system to the new system after migration were not retained for audit purposes. Further, we found that, while there was evidence of some user acceptance testing prior to system implementation, certain reports significant to the audit and to the preparation and reconciliation of the SEFA were subjected to user acceptance testing in October 2022 and December 2022, after ?go live? and after completion of the year-end inventory reconciliations. A detailed schedule of IT issues has been provided to OA-OIT for corrective action. Finding 2022 ? 010: (continued) In addition to testing the IT general controls described above, we also tested various reports generated by the system that were used by BFA to perform reconciliations and compile commodity expenditures reported in the SEFA as of June 30, 2022. We noted the following: Regarding the Commodity Processors Inventory Report which contained a total of 66 processors, some of which were inactive and not part of our testing population: ? For ten processors, when the report was generated for the entire year, and the beginning inventory for the commodity was zero, the report doubled the ending inventory. ? For three processors, the report displayed the wrong name for the related processor number. ? For five processors, when the report was generated for the entire year, the report displayed the processor as inactive despite having an ending inventory balance. BFA had to activate these processors in order to obtain the individual processor report activity. Regarding the Commodity Distributor Inventory Report: ? Inventory balances continue to be displayed on this report for three inactive distributors. Although all inventory was transferred to a new distributor, the transfer was not accounted for under the inactive distributors. ? Inventory balances for the two active distributors did not agree to the year-end physical inventory counts when the report was generated in October 2022. One distributor had a discrepancy of 1,794 cases and the other distributor had a discrepancy of 9,835 cases out of a total of 191,796 cases in year-end inventory. Reports generated in January 2023 displayed the ending balance that agreed to the year-end physical inventory counts. Regarding the Agency Summary Report: ? For one of the 25 recipients selected for testing from the Agency Summary Report, one month?s distribution activity for a selected commodity did not agree to the recipient?s records. We noted a difference of 29.22 more pounds received per the recipient?s invoices than was shown on the agency usage report that neither the recipient nor BFA could explain. We also noted discrepancies with BFA?s processor monthly performance reports (MPR), distributor monthly reconciliations, and year-end inventory reconciliations. We noted the following discrepancies in these reconciliations: ? Our testing of 25 processors? MPRs disclosed that for two processors BFA could not provide an MPR that agreed to the Commodity Processors Inventory Report which was prepared from the inventory application. ? Our testing of 15 receipt dates from three distributor monthly reconciliations disclosed a difference of 12 cases between USDA?s receipts and BFA?s receipts for one of the dates tested. BFA?s records were reconciled to the distributor?s records, and the difference was adjusted to agree to the distributor?s records without resolving the differences with USDA?s receipts. ? Our testing of BFA?s year-end reconciliation provided in October 2022 disclosed differences between distributor beginning inventory, receipts, distributions, and ending inventory balances and commodity inventory report balances. These differences impacted the commodity balances reported on the SEFA. The NSLP commodity amount was overstated by $248,640, and the SFSP commodity amount was understated by $107,616, for a net immaterial overstatement of $141,024 for the Child Nutrition Cluster. Criteria: Management Directive 325.12, Amended ? Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book). Finding 2022 ? 010: (continued) ? Green Book Principle 11 ? Design Activities for the Information System, states in part: o 11.09 Management designs control activities over the information technology infrastructure to support the completeness, accuracy, and validity of information processing by information technology. ? Management evaluates the objectives of the entity and related risks in designing control activities for the information technology infrastructure. OA-OIT issued the following Information Technology Policy (ITP) and Operational Document (OPD) to provide governance and guidance to agencies during implementation of new systems and placement of servers in the Enterprise Data Center: ? ITP-INF000 ? Enterprise Data and Information Management Policy, provides direction for effectively managing data and information life cycles including establishing data migration controls for data sets to be accessed from their original sources and efficiently moved from source to target destinations in an effective and secure manner. ? OPD-INF000A ? Migration Audit Checklist Template, which agencies must use to facilitate data migration as delineated in ITP-INF000. The 2022 OMB Uniform Guidance Compliance Supplement, Part 4 ? Agency Program Requirements for the CNC Cluster, Special Tests and Provisions ? N.2 Accountability for USDA ? Donated Foods, states: a. Maintenance of Records: Distributing and subdistributing agencies (as defined at 7 CFR section 250.3) must maintain accurate and complete records with respect to the receipt, distribution, and inventory of USDA-donated foods, including end products processed from donated food. 7 CFR Section 250.19, Recordkeeping requirements, states: (a) Required records. Distributing agencies, recipient agencies, processors, and other entities must maintain records of agreements and contracts, reports, audits, and claim actions, funds obtained as an incident of donated food distribution, and other records specifically required in this part or in other Departmental regulations, as applicable. Cause: Data migration occurred for this application as part of an upgrade to a new platform in June 2022. Due to the age of the application, it was no longer being supported by existing Enterprise Data Center infrastructure and technology. The C&E Delivery Center development team indicated that they were unaware that the ITP-INF000 ? Enterprise Data and Information Management Policy existed at the time of the data conversion. They indicated that while the web application was rewritten to utilize newer Microsoft technologies, large portions of the database utilized the same data structure as the previous system. Data queries were used to move data from one database to the other, and the data queries were written and tested. After the scripts were run, reports were compared side-by-side using the old system and the new system. When we requested additional evidence, management provided copies of the data queries and the change advisory board approval for the implementation of the new system but could not provide evidence of successful testing or evidence that reports comparing the old system and new system reconciled. During testing of the year-end inventory reconciliations, the auditors attempted to tie to reports they downloaded from the system and found the errors noted above. Once the identified errors in the downloaded reports were communicated to management, contracted personnel from the C&E Delivery Center corrected some, but not all, of the reports listed above. The C&E Delivery Center contractor represented that the issues identified during the audit were the result of how the reports were generated in the new system and were not issues with the underlying data, but no evidence to support this statement was provided. Further, certain issues, such as inactive distributors included on the system reports, had not been corrected as of our testing date in January 2023. Finding 2022 ? 010: (continued) While PDA provided a one-page document entitled Acceptance of Project Deliverable signed by BFA personnel on June 3, 2022, the emails documenting completion of user acceptance testing of the specific incorrect reports listed were dated October 2022 and December 2022, after ?go live? and after completion of the year-end inventory reconciliations. PDA management stated that issues were encountered with inventory reports after the inventory system was upgraded in June 2022 where fixes needed to be made as errors were being discovered. Also, a new distributor was added during the audit period that failed to submit complete files which resulted in reconciliation issues. PDA management erroneously believes that all discrepancies in inventory reports have been resolved and ending inventory balances are correct. Effect: The C&E Delivery Center?s failure to follow OA-OIT?s Enterprise Data and Information Management Policy resulted in the lack of certain controls over data migration including adequate planning, execution, and validation. The lack of evidence of successful, planned testing and comparisons of before and after snapshots of the data and inventory balances may have led to data migration errors that may have impacted the integrity, accuracy, and security of the data. Therefore, PDA management had little assurance prior to the audit that inventory balances transferred over completely and accurately. The lack of user acceptance testing prior to implementation of the new system (known as ?go live?) contributed to the inaccurate reports that failed to support the reconciliations provided for audit. Without direct intervention from the auditors, the inventory reports for the CNC program may not have been corrected, and similar reports generated for nonmajor programs may still contain errors. The discrepancies noted above related to inaccurate records could result in improper distribution of donated foods and misstatements in BFA?s inventory reconciliations and commodity expenditures reported in the SEFA. Recommendation: PDA should maintain accurate and complete records with respect to the receipt, distribution, and inventory of USDA-donated foods, including end products processed from donated food. PDA should strengthen procedures for future periods to ensure errors identified during the reconciliation process are corrected timely in the system. OA-OIT and the C&E Delivery Center should perform the following: ? Work with BFA personnel to ensure all inventory reports generated from the new system are correct, tie to actual inventory balances on hand, and include the correct distribution centers. This should be done for CNC as well as for any nonmajor programs that utilize the same inventory application. ? Ensure that all system development personnel are aware of the data migration requirements detailed in Commonwealth policy prior to future system upgrades. ? Ensure adequate user acceptance testing is performed for all key reports prior to ?go live? in future system upgrades. OA-OIT Response: OA-OIT and the C&E Delivery Center agree with the facts of the finding. PDA Response: PDA agrees with the facts of the finding. Questioned Costs: None The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Corrective Action Plan

IT - PDA?s PA Meals team will incorporate appropriate migration strategies within the policy of ITP_INF000, along with providing a migration audit plan checklist for any future data migrations. Additionally, the INF000 will be incorporated into the Delivery Center?s development framework, where appropriate. PDA added a Business Analyst to the team for assisting with future application testing and documentation. This individual will be directly involved in helping develop and orchestrate a testing strategy based on delivery center standards to include, but not limited to: - Determine appropriate criteria to be tested. - Assist in establishing a test group of qualified testers. - Coordinate with technical team on pass/fail criteria. - Utilize standard testing tasks/checklists ensuring consistency. - Assist the team, key business users and the technical team in reviewing testing results. The reports were reviewed electronically (100s of report pages) checking for various scenarios. As a result, these complete reports are similar and difficult to distinguish between without an associated checklist and specific report criteria. In the future, full test plans and execution results capturing pass/fail of the defined tests will be retained in pdf (or similar) format. The team will continue with best practices and delivery center standards, utilizing a Business Analyst as part of the testing and review process. The SEFA report had extensive testing, however, there is a timing issue that will always exist if the expectation is to provide the data in both January and September. The January report will be accurate for when it is run, along with what transactions were sent by the warehouse vendor. Subsequently, changes can and will occur to those commodities being reported on over the next 6 months. Additionally, it is reliant upon the warehouse vendor to report all transactions timely. As a result, running the same report after June 30th will consistently vary due to a physical inventory review in June, along with additional transactions being updated as part of the inventory review. PDA is recommending a one-time annual report in September, which will include all the adjustments from a June physical inventory and updated transactions. A January report is fine to run but should not be considered a fully accurate assessment due to the timing and missing data. Program - PDA strives to maintain accurate and complete records with respect to the receipt, distribution, and inventory of USDA donated foods, including end products processed from donated food. To that end, PDA has already or will put the following steps in place to strengthen procedures for future periods to ensure errors identified during the reconciliation process are corrected timely in the system: 1) All findings noted with regards to the Commodity Processors Inventory Report have been corrected and no known issues remain. 2) No further inventory balances remain on record with inactive distributors, as all product was previously transferred to active distributors. 3) Processor monthly performance reports (MPRs) will be completed and filed in accordance with USDA?s prescribed schedule (90 days after completion of month). 4) BFA will work with the Commodity Distributors and USDA to mutually resolve discrepancies and achieve reconciliation with USDA receipts. 5) Moving forward, all Commodity Distributor Inventory Reports will be reconciled by the beginning of a new federal fiscal year (October 1), and inventory balances at commodity distributors will agree with year-end physical inventory counts. Anticipated Completion Date: IT - 09/30/2023; Program 1-Completed; 2-Completed; 3-09/30/2023; 4-09/30/2023; 5-09/30/2023 Contact Person and Title: Caryn Long Earl, PDA, Director, Bureau of Food Assistance (BFA)

About Special Tests and Provisions →
2022-011
Reporting

The Coronavirus State and Local Fiscal Recovery Funds (SLFRF) program was established under the American Rescue Plan Act to provide support to state, territorial, local, and tribal governments in responding to the economic and public health impacts of the COVID-19 pandemic. The Commonwealth of Pennsylvania, as a recipient of SLFRF funding, was required to submit a one-time Interim Report with expenditures by expenditure category, which provides an overview of the status and use of program funds. The Office of the Budget, Governor?s Budget Office (GBO), excluded $14,481,522 from the Interim Report which represents expenditures that had been approved but not paid as of July 31, 2021. These transactions were included as expenditures in the Commonwealth?s accounting system as of July 31, 2021, but payment had not yet been issued. Per the United States Department of the Treasury?s (US Treasury) reporting guidance, this amount should have been included on the Interim Report as an obligation for the period ending July 31, 2021. Criteria: The SLFRF Compliance and Reporting Guidance, issued by the US Treasury on June 17, 2022, states in part: States ? were required to submit a one-time interim report with expenditures by Expenditure Category from the date of award to July 31, 2021, by August 31, 2021 or sixty (60) days after first receiving funding if the recipient?s date of award was between July 15, 2021 and October 15, 2021. The recipient was required to enter obligations and expenditures and, for each, select the specific expenditure category from the available options. The report is required to be submitted to the US Treasury?s SLFRF portal, and for reporting purposes, an expenditure is the amount that has been incurred as a liability of the entity (the service has been rendered or the good has been delivered to the entity), and an obligation is an order placed for property and services, contracts and subawards made, and similar transactions that require payment. Management Directive 325.12, Amended ? Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: When the Interim Report was prepared, GBO interpreted program reporting requirements to be that the expenditures and obligations reported should match the Non-Entitlement Units (NEU) reports the Commonwealth had on file with US Treasury. Therefore, GBO reported only disbursements issued by the Pennsylvania Treasury by July 31, 2021 and excluded expenditures incurred in the accounting system that had not yet been issued as of July 31, 2021. Effect: GBO did not fully report program obligations on the Interim Report as of July 31, 2021. Recommendation: We recommend that GBO report all transactions that have been expended and/or approved for payment in accordance with program reporting requirements. Finding 2022 ? 011: (continued) Agency Response: GBO agrees with this finding. Questioned Costs: None noted as the expenditures were subsequently reported to US Treasury in Project and Expenditure Reports. The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Show full finding ▾
Full finding narrative

Office of the Budget ? Governor?s Budget Office Finding 2022 ? 011: ALN 21.027 ? COVID 19 ? Coronavirus State and Local Fiscal Recovery Funds A Significant Deficiency and Noncompliance Exist Related to Preparation of the Interim Report Federal Grant Number(s) and Year(s): TN75GJE1S7G3 (3/03/2021 ? 12/31/2024) Type of Finding: Significant Deficiency, Noncompliance Compliance Requirement: Reporting Condition: The Coronavirus State and Local Fiscal Recovery Funds (SLFRF) program was established under the American Rescue Plan Act to provide support to state, territorial, local, and tribal governments in responding to the economic and public health impacts of the COVID-19 pandemic. The Commonwealth of Pennsylvania, as a recipient of SLFRF funding, was required to submit a one-time Interim Report with expenditures by expenditure category, which provides an overview of the status and use of program funds. The Office of the Budget, Governor?s Budget Office (GBO), excluded $14,481,522 from the Interim Report which represents expenditures that had been approved but not paid as of July 31, 2021. These transactions were included as expenditures in the Commonwealth?s accounting system as of July 31, 2021, but payment had not yet been issued. Per the United States Department of the Treasury?s (US Treasury) reporting guidance, this amount should have been included on the Interim Report as an obligation for the period ending July 31, 2021. Criteria: The SLFRF Compliance and Reporting Guidance, issued by the US Treasury on June 17, 2022, states in part: States ? were required to submit a one-time interim report with expenditures by Expenditure Category from the date of award to July 31, 2021, by August 31, 2021 or sixty (60) days after first receiving funding if the recipient?s date of award was between July 15, 2021 and October 15, 2021. The recipient was required to enter obligations and expenditures and, for each, select the specific expenditure category from the available options. The report is required to be submitted to the US Treasury?s SLFRF portal, and for reporting purposes, an expenditure is the amount that has been incurred as a liability of the entity (the service has been rendered or the good has been delivered to the entity), and an obligation is an order placed for property and services, contracts and subawards made, and similar transactions that require payment. Management Directive 325.12, Amended ? Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: When the Interim Report was prepared, GBO interpreted program reporting requirements to be that the expenditures and obligations reported should match the Non-Entitlement Units (NEU) reports the Commonwealth had on file with US Treasury. Therefore, GBO reported only disbursements issued by the Pennsylvania Treasury by July 31, 2021 and excluded expenditures incurred in the accounting system that had not yet been issued as of July 31, 2021. Effect: GBO did not fully report program obligations on the Interim Report as of July 31, 2021. Recommendation: We recommend that GBO report all transactions that have been expended and/or approved for payment in accordance with program reporting requirements. Finding 2022 ? 011: (continued) Agency Response: GBO agrees with this finding. Questioned Costs: None noted as the expenditures were subsequently reported to US Treasury in Project and Expenditure Reports. The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Corrective Action Plan

While the Governor?s Budget Office agrees with the fact cited in finding, it is not possible to correct the situation and the error had no impact on the implementation of the federal program. No corrective action is necessary, nor would it have any discernable impact. The Interim Report was a one-time progress report required by U.S. Treasury to document our state?s progress in spending State and Local Fiscal Recovery Funds and distributing, on the behalf of the U.S. Treasury, payments from the Treasury to Non-Entitlement Units (NEU) of local government as of July 31, 2021. The Interim Report also required states to provide revenue replacement calculations for calendar year 2020. This report was due on August 31, 2021. There were no follow up reports using the same format as the Interim Report. The figures reported as transfers to NEUs in the Interim Report accurately reflected the total dollars that had been electronically transferred to local governments as of July 31, 2021, as that was how we interpreted the federal guidance at the time. It was our interpretation that U.S. Treasury wanted information on how much had been distributed and received by NEUs as of July 31, 2021, rather than how many payments we had approved in our accounting system and were in the process of being paid. After filing the Interim Report, the Office of the Budget continued to report updates of distributions to NEUs both using a U.S. Treasury portal, and ultimately by exchanging spreadsheets of NEU data with the US Treasury to painstakingly ensure the data the U.S. Treasury had was correct. The Office of the Budget will continue to file compliance reports in accordance with U.S. Treasury?s guidance. At no time did the U.S. Treasury indicate there were issues with the composition or acceptability of our filed Interim Report. At this time, all NEU funds received from the federal government have been either distributed to NEUs or have been returned to the U.S. Treasury and this program is complete. Therefore, we are currently not required to, nor do we have plans to report on the progress of NEU distributions to the federal government in the future. Anticipated Completion Date: N/A Contact Person and Title: Mike Wood, Bureau Director, Bureau of Performance, Revenue, and Program Analysis; Colleen Kling, Division Manager, Division of Program Analysis and Performance Improvement

About Reporting →
2022-012
Reporting
MATERIAL WEAKNESS

The Federal Funding Accountability and Transparency Act (FFATA) requires the Commonwealth of Pennsylvania to report first-tier subawards of $30,000 or more to the FFATA Subaward Reporting System (FSRS). Necessary details including the contract amount, contract date, federal award identification number, internal order number, and other information are entered into the Commonwealth?s SAP accounting system when the Commonwealth agencies award subrecipient contracts in order to ensure compliance with the FFATA reporting requirements. Each month Commonwealth information technology personnel run an extract in SAP to populate a FFATA database and generate a report that summarizes the contract information required for that month?s FFATA reporting. The Office of the Budget, Bureau of Accounting and Financial Management (OB-BAFM), is responsible for overseeing FFATA reporting, to include reviewing the summary report to ensure the contract data is complete. Once reviewed, the information is uploaded into FSRS to meet FFATA reporting requirements. Our testing of the FFATA reporting requirements for 40 subaward transactions totaling $113.1 million from ten major programs disclosed that 13 transactions totaling $29.2 million, or 33 percent of transactions tested, were not reported to FSRS. Specifically, the 13 transactions for which the FFATA information was not reported occurred within three of the ten programs tested as follows: SEE SCHEDULE OF FINDINGS AND QUESTIONED COSTS FOR CHART/TABLE (1) Not all subrecipient awards within total subrecipient expenditures (program total) may meet the criteria for FFATA reporting. Finding 2022 ? 012: (continued) Criteria: 2 CFR Section 170, Appendix A to Part 170, Award Term, states in part: I. Reporting Subawards and Executive Compensation a. Reporting of first tier subawards. Applicability. Unless you are exempt as provided in paragraph d. of this award term, you must report each action that equals or exceeds $30,000 in Federal funds for a subaward to a non-Federal entity or Federal agency (see definitions in paragraph e. of this award term). 2. Where and when to report. i. The non-Federal entity or Federal agency must report each obligating action described in paragraph a.1. of this award term to http://www.fsrs.gov. ii. For subaward information, report no later than the end of the month following the month in which the obligation was made. (For example, if the obligation was made on November 7, 2010, the obligation must be reported by no later than December 31, 2010.) 3. What to report. You must report the information about each obligating action that the submission instructions posted at http://www.fsrs.gov specify. b. Reporting total compensation of recipient executives for non-Federal entities. 1. Applicability and what to report. You must report total compensation for each of your five most highly compensated executives for the preceding completed fiscal year, if - i. The total Federal funding authorized to date under this Federal award equals or exceeds $30,000 as defined in 2 CFR 170.320; ii. in the preceding fiscal year, you received - (A) 80 percent or more of your annual gross revenues from Federal procurement contracts (and subcontracts) and Federal financial assistance subject to the Transparency Act, as defined at 2 CFR 170.320 (and subawards), and (B) $25,000,000 or more in annual gross revenues from Federal procurement contracts (and subcontracts) and Federal financial assistance subject to the Transparency Act, as defined at 2 CFR 170.320 (and subawards); and, iii. The public does not have access to information about the compensation of the executives through periodic reports filed under section 13(a) or 15(d) of the Securities Exchange Act of 1934 (15 U.S.C. 78m(a), 78o(d)) or section 6104 of the Internal Revenue Code of 1986. (To determine if the public has access to the compensation information, see the U.S. Security and Exchange Commission total compensation filings at http://www.sec.gov/answers/execomp.htm.) Management Directive 325.12, Amended ? Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s, Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Finding 2022 ? 012: (continued) Cause: OB-BAFM personnel indicated that due to staff turnover, certain subawards were not reported to FSRS because the award dates were not being entered for the internal order number in SAP. The award dates identify the contracts that are extracted from SAP for the upload to the FFATA database and the subsequent upload to FSRS. As a result of our testing, OB-BAFM personnel indicated they have established and implemented procedures to ensure award dates are entered into SAP for all internal orders so that the required subawards are properly reported in FSRS. The new procedures also include review of the FFATA information to ensure the data is consistent and correct before being uploaded to FSRS. Regarding the 13 transactions identified during our testing that were not reported to the FFATA database, OB-BAFM personnel indicated they subsequently identified and entered award dates for subawards that were missing an award date, allowing the award information to upload to the FFATA database and FSRS as required. Effect: Since the award dates for 13 internal order numbers were not entered in SAP, the awards failed to upload to the FFATA database and were not reported to FSRS as required. Further, noncompliance with FFATA reporting requirements may recur in future periods if control deficiencies are not corrected to ensure completeness of the upload to FSRS. Recommendation: We recommend that OB-BAFM continue to implement their established procedures to ensure all subrecipient contract information is properly recorded in SAP and the upload into the FFATA database, and FSRS is accurate and complete. Agency Response: OB-BAFM agrees with the finding. Questioned Costs: None The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Show full finding ▾
Full finding narrative

Office of the Budget ? Office of Comptroller Operations Finding 2022 ? 012: ALN 93.323 ? Epidemiology and Laboratory Capacity for Infectious Diseases (including COVID-19) ALN 93.558 ? Temporary Assistance for Needy Families (including COVID-19) ALN 93.575 and 93.596 ? Child Care and Development Fund (CCDF) Cluster (including COVID-19) A Material Weakness and Material Noncompliance Exist in the Commonwealth?s FFATA Reporting Process Federal Grant Number(s) and Year(s): NU50CK000527 (8/01/2019 ? 7/31/2024), 2201PATANF (10/01/2021 ? 9/30/2022), 2101PATANF (10/01/2020 ? 9/30/2021), G2201PACCDF (10/01/2021 ? 9/30/2022), G2101PACCDF (10/01/2020 ? 9/30/2021) Type of Finding: Material Weakness, Material Noncompliance Compliance Requirement: Reporting Condition: The Federal Funding Accountability and Transparency Act (FFATA) requires the Commonwealth of Pennsylvania to report first-tier subawards of $30,000 or more to the FFATA Subaward Reporting System (FSRS). Necessary details including the contract amount, contract date, federal award identification number, internal order number, and other information are entered into the Commonwealth?s SAP accounting system when the Commonwealth agencies award subrecipient contracts in order to ensure compliance with the FFATA reporting requirements. Each month Commonwealth information technology personnel run an extract in SAP to populate a FFATA database and generate a report that summarizes the contract information required for that month?s FFATA reporting. The Office of the Budget, Bureau of Accounting and Financial Management (OB-BAFM), is responsible for overseeing FFATA reporting, to include reviewing the summary report to ensure the contract data is complete. Once reviewed, the information is uploaded into FSRS to meet FFATA reporting requirements. Our testing of the FFATA reporting requirements for 40 subaward transactions totaling $113.1 million from ten major programs disclosed that 13 transactions totaling $29.2 million, or 33 percent of transactions tested, were not reported to FSRS. Specifically, the 13 transactions for which the FFATA information was not reported occurred within three of the ten programs tested as follows: SEE SCHEDULE OF FINDINGS AND QUESTIONED COSTS FOR CHART/TABLE (1) Not all subrecipient awards within total subrecipient expenditures (program total) may meet the criteria for FFATA reporting. Finding 2022 ? 012: (continued) Criteria: 2 CFR Section 170, Appendix A to Part 170, Award Term, states in part: I. Reporting Subawards and Executive Compensation a. Reporting of first tier subawards. Applicability. Unless you are exempt as provided in paragraph d. of this award term, you must report each action that equals or exceeds $30,000 in Federal funds for a subaward to a non-Federal entity or Federal agency (see definitions in paragraph e. of this award term). 2. Where and when to report. i. The non-Federal entity or Federal agency must report each obligating action described in paragraph a.1. of this award term to http://www.fsrs.gov. ii. For subaward information, report no later than the end of the month following the month in which the obligation was made. (For example, if the obligation was made on November 7, 2010, the obligation must be reported by no later than December 31, 2010.) 3. What to report. You must report the information about each obligating action that the submission instructions posted at http://www.fsrs.gov specify. b. Reporting total compensation of recipient executives for non-Federal entities. 1. Applicability and what to report. You must report total compensation for each of your five most highly compensated executives for the preceding completed fiscal year, if - i. The total Federal funding authorized to date under this Federal award equals or exceeds $30,000 as defined in 2 CFR 170.320; ii. in the preceding fiscal year, you received - (A) 80 percent or more of your annual gross revenues from Federal procurement contracts (and subcontracts) and Federal financial assistance subject to the Transparency Act, as defined at 2 CFR 170.320 (and subawards), and (B) $25,000,000 or more in annual gross revenues from Federal procurement contracts (and subcontracts) and Federal financial assistance subject to the Transparency Act, as defined at 2 CFR 170.320 (and subawards); and, iii. The public does not have access to information about the compensation of the executives through periodic reports filed under section 13(a) or 15(d) of the Securities Exchange Act of 1934 (15 U.S.C. 78m(a), 78o(d)) or section 6104 of the Internal Revenue Code of 1986. (To determine if the public has access to the compensation information, see the U.S. Security and Exchange Commission total compensation filings at http://www.sec.gov/answers/execomp.htm.) Management Directive 325.12, Amended ? Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s, Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Finding 2022 ? 012: (continued) Cause: OB-BAFM personnel indicated that due to staff turnover, certain subawards were not reported to FSRS because the award dates were not being entered for the internal order number in SAP. The award dates identify the contracts that are extracted from SAP for the upload to the FFATA database and the subsequent upload to FSRS. As a result of our testing, OB-BAFM personnel indicated they have established and implemented procedures to ensure award dates are entered into SAP for all internal orders so that the required subawards are properly reported in FSRS. The new procedures also include review of the FFATA information to ensure the data is consistent and correct before being uploaded to FSRS. Regarding the 13 transactions identified during our testing that were not reported to the FFATA database, OB-BAFM personnel indicated they subsequently identified and entered award dates for subawards that were missing an award date, allowing the award information to upload to the FFATA database and FSRS as required. Effect: Since the award dates for 13 internal order numbers were not entered in SAP, the awards failed to upload to the FFATA database and were not reported to FSRS as required. Further, noncompliance with FFATA reporting requirements may recur in future periods if control deficiencies are not corrected to ensure completeness of the upload to FSRS. Recommendation: We recommend that OB-BAFM continue to implement their established procedures to ensure all subrecipient contract information is properly recorded in SAP and the upload into the FFATA database, and FSRS is accurate and complete. Agency Response: OB-BAFM agrees with the finding. Questioned Costs: None The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Corrective Action Plan

The following steps were taken to address this material weakness: ? FFATA procedures will be updated to populate the award date in the grant internal order (IO) when the grant is set up in SAP instead of when the grant is in FSRS. ? General Accounting will review their IOs to ensure the award date is populated. ? A procedure workgroup will be established to ensure a consistent FFATA review in General Accounting. Anticipated Completion Date: 05/31/2023 Contact Person and Title: Sandra Bruno, Integrated Financial Service Manager; Jamie Jerosky, Assistant Director

About Reporting →
2022-013
Subrecipient Monitoring
REPEATQUESTIONED COSTS

The Uniform Guidance in 2 CFR Section 200 applies to the major programs listed above for the fiscal year ended June 30, 2022. Our testing disclosed that the Pennsylvania Department of Human Services (DHS) did not identify the federal award information and applicable requirements in subrecipient award documents. Additionally, the DHS and the Pennsylvania Department of Health (DOH) did not adequately evaluate each subrecipient?s risk of noncompliance for the purpose of determining the appropriate subrecipient monitoring related to the subaward. This represents an internal control weakness which could cause subrecipients to be improperly informed of federal award information and may result in inadequate monitoring by the state agencies. Also, it could cause the omission or improper identification of program expenditures on subrecipients? Schedules of Expenditures of Federal Awards (SEFAs). The following chart shows which federal award information required by 2 CFR Section 200 was omitted (as indicated by ?No?) from the subrecipient award documents at the time of the subaward and which major programs did not have a state agency evaluation of each subrecipient?s risk of noncompliance. SEE SCHEDULE OF FINDINGS AND QUESTIONED COSTS FOR CHART/TABLE Finding 2022 ? 013: (continued) SEE SCHEDULE OF FINDINGS AND QUESTIONED COSTS FOR CHART/TABLE (The cells with a hyphen in the table indicate that the federal award information was included in the subrecipient award documents or was not applicable for the respective major program.) (1) Although an evaluation of subrecipient risk was conducted, the only risk factor used in the evaluation was the error rate detected for the county subrecipients. The evaluation is deemed inadequate since there was no written evidence that the risk assessment considered other risk factors, such as the risk factors identified in 2 CFR Section 200.332. Criteria: 2 CFR Section 200.332, Requirements for pass-through entities, states in part: All pass-through entities must: (a) Ensure that every subaward is clearly identified to the subrecipient as a subaward and includes the following information at the time of the subaward and if any of these data elements change, include the changes in subsequent subaward modification. When some of this information is not available, the pass-through entity must provide the best information available to describe the Federal award and subaward. Required information includes: (1) Federal Award Identification. (iii) Federal Award Identification Number (FAIN); (iv) Federal Award Date (see the definition of Federal Award date in section 200.1) of award to the recipient by the Federal agency; (v) Subaward Period of Performance Start and End Date; (xi) Name of Federal awarding agency, pass-through entity, and contact information for awarding official of the pass-through entity; (xii) Assistance Listings Number and Title; the pass-through entity must identify the dollar amount made available under each Federal award and the Assistance Listings Number at time of disbursement; (6) Appropriate terms and conditions concerning closeout of the subaward. (b) Evaluate each subrecipient?s risk of noncompliance with Federal statutes, regulations, and the terms and conditions of the subaward for purposes of determining the appropriate subrecipient monitoring described in paragraphs (d) and (e) of this section, which may include consideration of such factors as: (1) The subrecipient?s prior experience with the same or similar subawards; (2) The results of previous audits including whether or not the subrecipient receives a Single Audit in accordance with Subpart F [Audit Requirements] of this part, and the extent to which the same or similar subaward has been audited as a major program; (3) Whether the subrecipient has new personnel or new or substantially changed systems; and (4) The extent and results of Federal awarding agency monitoring (e.g., if the subrecipient also receives Federal awards directly from a Federal awarding agency) Finding 2022 ? 013: (continued) Management Directive 325.12, Amended ? Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should identify, analyze, and respond to risks related to achieving the defined objectives. Management should identify, analyze, and respond to significant changes that could impact the internal control system. Cause: In general, DHS?s process for subrecipient award monitoring did not identify the omission of required elements from the grant awards. In addition, the risk assessments performed by DHS and DOH were not properly documented. Effect: Excluding the federal grant award information at the time of the subaward may cause subrecipients and their auditors to be uninformed about specific program and other regulations that apply to the funds they receive. There is also the potential for subrecipients to have incomplete SEFAs in their Single Audit reports submitted to the Commonwealth, and federal funds may not be properly audited at the subrecipient level in accordance with the Single Audit Act and Uniform Guidance. Not evaluating each subrecipient?s risk of noncompliance for purposes of determining the appropriate subrecipient monitoring related to the subaward may result in subrecipients using the subaward for unauthorized purposes or in violation of the terms and conditions of the subaward, and state agency monitoring would not detect this noncompliance and ensure it is corrected in a timely manner. Recommendation: DHS should develop policies and reporting mechanisms to ensure all required federal award information is disseminated to all subrecipients at the time of the subaward to ensure subrecipient compliance with the Uniform Guidance in 2 CFR Section 200 and other applicable federal regulations. In addition, DHS should correspond with applicable subrecipients to ensure they are aware of the correct federal award information and review applicable subaward documents prior to issuance to ensure federal information is complete and accurate. DHS and DOH should implement procedures to adequately document their evaluation of each subrecipient?s risk of noncompliance as cited in 2 CFR Section 200.332 for purposes of determining the appropriate subrecipient monitoring related to the subaward. DHS Response: DHS agrees with this finding. DOH Response: DOH agrees with this finding. Questioned Costs: The amount of questioned costs cannot be determined. The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Show full finding ▾
Full finding narrative

Various Agencies Finding 2022 ? 013: ALN 93.323 ? Epidemiology and Laboratory Capacity for Infectious Diseases (including COVID-19) ALN 93.558 ? Temporary Assistance for Needy Families (including COVID-19) ALN 93.658 ? Foster Care ? Title IV-E (including COVID-19) ALN 93.659 ? Adoption Assistance (including COVID-19) State Agencies Did Not Identify the Federal Award Information and Applicable Requirements at the Time of the Subaward and Did Not Evaluate Each Subrecipient?s Risk of Noncompliance as Required by the Uniform Grant Guidance (A Similar Condition Was Noted in Prior Year Finding 2021-014) Federal Grant Number(s) and Year(s): NU50CK000527 (8/01/2019 ? 7/31/2024), 2101PATANF (10/01/2020 ? 9/30/2021), 2001PATANF (10/01/2019 ? 9/30/2020), 1901PATANF (10/01/2018 ? 9/30/2019), 2101PAADPT (10/01/2020 ? 9/30/2021), 2201PAADPT (10/01/2021 ? 9/30/2022), 2101PAFOST (10/01/2020 ? 9/30/2021), 2201PAFOST (10/01/2021 ? 9/30/2022) Type of Finding: Significant Deficiency, Noncompliance Compliance Requirement: Subrecipient Monitoring Condition: The Uniform Guidance in 2 CFR Section 200 applies to the major programs listed above for the fiscal year ended June 30, 2022. Our testing disclosed that the Pennsylvania Department of Human Services (DHS) did not identify the federal award information and applicable requirements in subrecipient award documents. Additionally, the DHS and the Pennsylvania Department of Health (DOH) did not adequately evaluate each subrecipient?s risk of noncompliance for the purpose of determining the appropriate subrecipient monitoring related to the subaward. This represents an internal control weakness which could cause subrecipients to be improperly informed of federal award information and may result in inadequate monitoring by the state agencies. Also, it could cause the omission or improper identification of program expenditures on subrecipients? Schedules of Expenditures of Federal Awards (SEFAs). The following chart shows which federal award information required by 2 CFR Section 200 was omitted (as indicated by ?No?) from the subrecipient award documents at the time of the subaward and which major programs did not have a state agency evaluation of each subrecipient?s risk of noncompliance. SEE SCHEDULE OF FINDINGS AND QUESTIONED COSTS FOR CHART/TABLE Finding 2022 ? 013: (continued) SEE SCHEDULE OF FINDINGS AND QUESTIONED COSTS FOR CHART/TABLE (The cells with a hyphen in the table indicate that the federal award information was included in the subrecipient award documents or was not applicable for the respective major program.) (1) Although an evaluation of subrecipient risk was conducted, the only risk factor used in the evaluation was the error rate detected for the county subrecipients. The evaluation is deemed inadequate since there was no written evidence that the risk assessment considered other risk factors, such as the risk factors identified in 2 CFR Section 200.332. Criteria: 2 CFR Section 200.332, Requirements for pass-through entities, states in part: All pass-through entities must: (a) Ensure that every subaward is clearly identified to the subrecipient as a subaward and includes the following information at the time of the subaward and if any of these data elements change, include the changes in subsequent subaward modification. When some of this information is not available, the pass-through entity must provide the best information available to describe the Federal award and subaward. Required information includes: (1) Federal Award Identification. (iii) Federal Award Identification Number (FAIN); (iv) Federal Award Date (see the definition of Federal Award date in section 200.1) of award to the recipient by the Federal agency; (v) Subaward Period of Performance Start and End Date; (xi) Name of Federal awarding agency, pass-through entity, and contact information for awarding official of the pass-through entity; (xii) Assistance Listings Number and Title; the pass-through entity must identify the dollar amount made available under each Federal award and the Assistance Listings Number at time of disbursement; (6) Appropriate terms and conditions concerning closeout of the subaward. (b) Evaluate each subrecipient?s risk of noncompliance with Federal statutes, regulations, and the terms and conditions of the subaward for purposes of determining the appropriate subrecipient monitoring described in paragraphs (d) and (e) of this section, which may include consideration of such factors as: (1) The subrecipient?s prior experience with the same or similar subawards; (2) The results of previous audits including whether or not the subrecipient receives a Single Audit in accordance with Subpart F [Audit Requirements] of this part, and the extent to which the same or similar subaward has been audited as a major program; (3) Whether the subrecipient has new personnel or new or substantially changed systems; and (4) The extent and results of Federal awarding agency monitoring (e.g., if the subrecipient also receives Federal awards directly from a Federal awarding agency) Finding 2022 ? 013: (continued) Management Directive 325.12, Amended ? Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should identify, analyze, and respond to risks related to achieving the defined objectives. Management should identify, analyze, and respond to significant changes that could impact the internal control system. Cause: In general, DHS?s process for subrecipient award monitoring did not identify the omission of required elements from the grant awards. In addition, the risk assessments performed by DHS and DOH were not properly documented. Effect: Excluding the federal grant award information at the time of the subaward may cause subrecipients and their auditors to be uninformed about specific program and other regulations that apply to the funds they receive. There is also the potential for subrecipients to have incomplete SEFAs in their Single Audit reports submitted to the Commonwealth, and federal funds may not be properly audited at the subrecipient level in accordance with the Single Audit Act and Uniform Guidance. Not evaluating each subrecipient?s risk of noncompliance for purposes of determining the appropriate subrecipient monitoring related to the subaward may result in subrecipients using the subaward for unauthorized purposes or in violation of the terms and conditions of the subaward, and state agency monitoring would not detect this noncompliance and ensure it is corrected in a timely manner. Recommendation: DHS should develop policies and reporting mechanisms to ensure all required federal award information is disseminated to all subrecipients at the time of the subaward to ensure subrecipient compliance with the Uniform Guidance in 2 CFR Section 200 and other applicable federal regulations. In addition, DHS should correspond with applicable subrecipients to ensure they are aware of the correct federal award information and review applicable subaward documents prior to issuance to ensure federal information is complete and accurate. DHS and DOH should implement procedures to adequately document their evaluation of each subrecipient?s risk of noncompliance as cited in 2 CFR Section 200.332 for purposes of determining the appropriate subrecipient monitoring related to the subaward. DHS Response: DHS agrees with this finding. DOH Response: DOH agrees with this finding. Questioned Costs: The amount of questioned costs cannot be determined. The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Corrective Action Plan

DHS: The Office of Children, Youth, and Families (OCYF) is sending out a Restrictions and Requirements document with each tentative and final allocation letter. This document lists all OCYF?s grants, the federal agency granting the fund and where to find the rules and regulations guiding the usage of the funds. For the State fiscal year 2021-2022, Tentative Allocation Letters were sent out on April 1, 2021, with Federal Award Identification Numbers (FAIN) and funding amounts. Final Allocation Letters were sent out August 12, 2021, with the Amount, FAIN and Name. OCYF has a risk assessment process in place for Title IV-E and TANF awards. During the Quality Assurance reviews, which occur twice a year at a minimum, OCYF reviews a sample of Title IV-E eligible foster care cases, Title IV-E ineligible foster care cases, Title IV-E eligible adoption assistance cases, and TANF eligible cases. Depending on the number of eligibility and claiming errors identified during the review, OCYF schedules more frequent visits as the risk of repeated and continued errors in these County Children and Youth Agencies (CCYAs) is higher. Inaccurate eligibility determinations lead to inaccurate federal claiming, so basing the review schedule on a CCYA?s eligibility review outcome allows OCYF to target those CCYAs where inaccurate claiming is a higher risk. However, to further address this finding, the risk assessment now includes documentation. Anticipated Completion Date: Completed Contact Person and Title: TinaMarie Petrovitz, Director of County Support DOH: The Department plans to develop and implement a robust subrecipient monitoring program which includes establishing a new section within the Budget Office pending enacted budget funds and complement to support the creation of the section. Initiative goals/milestones include: - Assessment: Comprehensive assessment of all current federal grants and subawards and their processes. This assessment will document best practices and identify gaps within the agency?s processes. It will also provide an evaluation of current operational and technological resources that can be leveraged to facilitate compliance. Target start date: February 27, 2023. Target completion date: June 30, 2023. - Educate Department: Budget Office is developing a bulletin that will outline the subrecipient monitoring requirements with links to State and Federal Sources. The bulletin will be shared with all program office staff. The Budget Office will develop the following templates and provide to all program offices: - Determination of vendor status: Subrecipient or Contractor - Risk Assessment Form - Internal Control Self-Assessment for Subrecipient Template - Subrecipient Monitoring Template All materials will be updated with any additional information gained during the assessment. Start date: February 3, 2023. Target Completion Date: June 30, 2023 - Implementation of full compliance initiative: Recommendations provided in the assessment will be used to develop and implement comprehensive policies and procedures led by a new section in the Budget Office. Target start date July 1, 2023. Target fully operational date: June 30, 2024. Anticipated Completion Date: 06/30/2024 Contact Person and Title: Andrea Race, CFO

Prior Finding References

2021-014

About Subrecipient Monitoring →
2022-014
Subrecipient Monitoring
MATERIAL WEAKNESSREPEATQUESTIONED COSTS

Under the Commonwealth of Pennsylvania's (Commonwealth) implementation of the Single Audit Act, review and resolution of subrecipient Single Audit reports is split into two stages. The Office of the Budget?s Bureau of Accounting and Financial Management (OB-BAFM) ensures the reports meet technical standards through a centralized desk review process. The various funding agencies in the Commonwealth are responsible for making a management decision on each finding within six months of the Federal Audit Clearinghouse?s (FAC) Management Decision Letter (MDL) start date for audits subject to Uniform Guidance and to ensure appropriate corrective action is taken by the subrecipient (except for Uniform Guidance audits under U.S. Department of Labor programs which are permitted 12 months for management decisions in accordance with 2 CFR Section 2900.21). Each Commonwealth agency is also responsible for reviewing financial information in each audit report to determine whether the audit included all pass-through funding provided by the agency in order to ensure pass-through funds were subject to audit. Most agencies meet this requirement by performing Schedule of Expenditures of Federal Awards (SEFA) reconciliations. The agency is also required to adjust Commonwealth records, if necessary. Our fiscal year ended June 30, 2022 audit of the Commonwealth?s process for review and resolution of subrecipient Single Audits included an evaluation of the Commonwealth?s fiscal year ended June 30, 2021 subrecipient audit universe for audits due for submission to the FAC during the fiscal year ended June 30, 2022. We also evaluated the Commonwealth?s review of 44 subrecipient audit reports with findings in major programs/clusters which were identified on the Commonwealth agencies? tracking lists during the fiscal year ended June 30, 2022 and required management decisions by Commonwealth agencies. Our testing disclosed the following audit exceptions regarding the Commonwealth agencies? review of subrecipient audit reports: ? Department of Education (PDE): The time period for making a management decision on findings was approximately 6.5 to over 13 months after the FAC MDL start date for 14 out of 25 audit reports with findings. Three of the 14 audit reports were improperly classified on PDE?s audit tracking list as not having federal award findings. ? Department of Environmental Protection (DEP): The time period for making a management decision on findings was approximately 16.2 months after the FAC MDL start date for one out of three audit reports with findings. In addition, our review disclosed that DEP subgranted federal funds totaling $10,338,570 to one subrecipient during the fiscal year ended December 31, 2020, for which a Single Audit was not submitted to the FAC as of our January 2023 testing date. This was over 9.5 months after the March 31, 2022 due date, which had been extended due to the COVID-19 pandemic in accordance with the Office of Management and Budget?s (OMB) Memorandum M-21-20, Appendix 3. ? Department of Health (DOH): Our review disclosed that DOH subgranted federal funds totaling $8,103,407 to one subrecipient during the fiscal year ended September 30, 2020, for which a Single Audit was not submitted to the FAC as of our January 2023 testing date. This was over 12.5 months after the December 31, 2021 due date, which had been extended in accordance with OMB?s Memorandum M-21-20, Appendix 3. ? Department of Human Services (DHS): The time period for making a management decision on findings ranged from approximately 6.6 months to over 19.6 months after the FAC MDL start date for 12 out of 14 subrecipient audit reports with findings. There was also a delay in DHS?s procedures to ensure the subrecipient SEFAs were accurate so that major programs were properly determined and subjected to audit. Finding 2022 ? 014: (continued) As a follow-up to the prior year finding, we noted that the Commonwealth subgranted federal funds totaling $327,988,063 to the City of Philadelphia during the fiscal year ended June 30, 2021, for which a Single Audit was not submitted to the FAC as of our January 2023 testing date. This was over 3.5 months after the September 30, 2022 due date, which had been extended in accordance with OMB?s Memorandum M-21-20, Appendix 3. Our testing disclosed that DHS?s subgrants to the City of Philadelphia were material for five of the 16 major programs/clusters with material subgranted funds. Our follow-up on the prior year finding also disclosed that the Commonwealth subgranted federal funds totaling $28,725,212 to Bucks County during the fiscal year ended December 31, 2020, for which a Single Audit was not submitted to the FAC as of our January 2023 testing date. This was over 9.5 months after the March 31, 2022 due date, which had been extended in accordance with OMB?s Memorandum M-21-20, Appendix 3. DHS was the lead agency for the City of Philadelphia and Bucks County audits. Criteria: 2 CFR ?200.332, Requirements for pass-through entities, states in part: All pass-through entities must: (d) Monitor the activities of the subrecipient as necessary to ensure that the subaward is used for authorized purposes, in compliance with Federal statutes, regulations, and the terms and conditions of the subaward, and that subaward performance goals are achieved. Pass-through entity monitoring of the subrecipient must include: (2) Following-up and ensuring that the subrecipient takes timely and appropriate action on all deficiencies pertaining to the Federal award provided to the subrecipient from the pass-through entity detected through audits, on-site reviews, and written confirmation from the subrecipient, highlighting the status of actions planned or taken to address Single Audit findings related to the particular subaward. (3) Issuing a management decision for applicable audit findings pertaining only to the Federal award provided to the subrecipient from the pass-through entity as required by ?200.521 [Management decision]. (f) Verify that every subrecipient is audited as required by Subpart F [Audit Requirements] of this part when it is expected that the subrecipient?s Federal awards expended during the respective fiscal year equaled or exceeded the threshold set forth in ?200.501 [Audit requirements]. (g) Consider whether the results of the subrecipient?s audit, on-site review, or other monitoring indicate conditions that necessitate adjustments to the pass-through entity?s own records. (h) Consider taking enforcement action against noncompliant subrecipients as described in ?200.339 [Remedies for noncompliance] of this part and in program regulations. In order to carry out these responsibilities properly, good internal control dictates that state pass-through agencies ensure subrecipient Single Audit SEFAs are representative of state payment records each year, and that the related federal programs have been properly subjected to Single Audit procedures. 2 CFR ?200.512, Report submission, states in part: (a) General. (1) The audit must be completed and the data collection form described in paragraph (b) of this section and reporting package described in paragraph (c) of this section must be submitted within the earlier of 30 calendar days after receipt of the auditor?s report(s), or nine months after the end of the audit period. If the due date falls on a Saturday, Sunday, or Federal holiday, the reporting package is due the next business day. Finding 2022 ? 014: (continued) 2 CFR ?200.521, Management decision, states in part: (a) General. The management decision must clearly state whether or not the finding is sustained, the reasons for the decision, and the expected auditee action to repay disallowed costs, make financial adjustments, or take other action. (d) Time requirements. The Federal awarding agency or pass-through entity responsible for issuing a management decision must do so within six months of acceptance of the audit report by the FAC. The auditee must initiate and proceed with corrective action as rapidly as possible and corrective action should begin no later than upon receipt of the audit report. 2 CFR ?200.505, Sanctions, states: In cases of continued inability or unwillingness to have an audit conducted in accordance with this part, Federal agencies and pass-through entities must take appropriate action as provided in ?200.339 [Remedies for noncompliance]. 2 CFR ?200.339, Remedies for noncompliance, states in part: If a non-Federal entity fails to comply with the U.S. Constitution, Federal statutes, regulations or the terms and conditions of a Federal award, the Federal awarding agency or pass-through entity may impose additional conditions, as described in ?200.208 [Specific conditions]. If the Federal awarding agency or pass-through entity determines that noncompliance cannot be remedied by imposing additional conditions, the federal awarding agency or pass-through entity may take one or more of the following actions, as appropriate in the circumstances. (a) Temporarily withhold cash payments pending correction of the deficiency by the non-Federal entity or more severe enforcement action by the Federal awarding agency or pass-through entity. (b) Disallow (that is, deny both use of funds and any applicable matching credit for) all or part of the cost of the activity or action not in compliance. (c) Wholly or partly suspend or terminate the Federal award. (d) Initiate suspension or debarment proceedings as authorized under 2 CFR Part 180 and Federal awarding agency regulations (or in the case of a pass-through entity, recommend such a proceeding be initiated by a Federal awarding agency). (e) Withhold further Federal awards for the project or program. (f) Take other remedies that may be legally available. To ensure Commonwealth enforcement of federal regulations for subrecipient noncompliance with audit requirements, Commonwealth Management Directive 325.08, Amended ? Remedies for Recipient Noncompliance with Audit Requirements, Section 5 related to policy, states in part: (a) Agencies must develop and implement remedial action that reflects the unique requirements of each program? (b) The remedial action should be implemented within six months from the date the first remedial action is initiated. At the end of the six-month period, the recipient should take the appropriate corrective action or the final stage of remedial action should be imposed on the recipient. Examples of remedial action include, but are not limited to: Finding 2022 ? 014: (continued) (1) Meeting or calling the recipient to explain the importance and benefits of the audit and audit resolution processes, emphasizing the value of the audit as an administrative tool and the Commonwealth?s reliance on an acceptable audit and prompt resolution as evidence of the recipient?s ability to properly administer the program. (2) Encouraging the entity to establish an audit committee or designate an individual as the single point of contact to: (a) Communicate regarding the audit. (b) Arrange for and oversee the audit. (c) Direct and monitor audit resolution. (3) Providing technical assistance to the recipient in devising and implementing an appropriate plan to remedy the noncompliance. (4) Withholding a portion of assistance payments until the noncompliance is resolved. (5) Withholding or disallowing overhead costs until the noncompliance is resolved. (6) Suspending the assistance agreement until the noncompliance is resolved. (7) Terminating the assistance agreement with the recipient and, if necessary, seeking alternative entities to administer the program. Management Directive 325.09, Amended ? Processing Subrecipient Single Audits of Federal Pass-Through Funds, Section 7 related to procedures, states in part: c. Agencies. (1) Evaluate single audit report submissions received from BAFM to determine program purpose acceptability by verifying, at a minimum, that all agency-funded programs are properly included on the applicable financial schedules; that findings affecting the agency contain sufficient information to facilitate a management decision; and that the subrecipient has submitted an adequate corrective action plan. (6) Issue management decisions relative to audit findings and crosscutting findings assigned to the agency for resolution, as required by 2 CFR ?200.521. If responsible for the resolution of crosscutting findings, notify the affected agency or agencies upon resolution of such findings. (7) Impose or coordinate the imposition of remedial action in accordance with 2 CFR Part 200.339 and Management Directive 325.08 Amended, Remedies for Recipient Noncompliance with Audit Requirements, when subrecipients fail to comply with the provisions of Subpart F. Management Directive 325.12, Amended ? Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s, Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: One reason provided by Commonwealth management for untimely audit resolution in the various agencies, including making management decisions, approving corrective action, and performing procedures to ensure the accuracy of subrecipient SEFAs, was either a change in staff or a lack of staff to follow up and process subrecipient audit reports more timely. The late management decision at DEP appeared to be the result of a subrecipient being treated as a contractor as described in current year Single Audit Finding #2022-005, despite having a subrecipient Single Audit requirement clause in its contract with DEP. Regarding late and outstanding audit report submissions, the Commonwealth agencies did not appear to be timely implementing remedial action steps in accordance with 2 CFR ?200.339 and Commonwealth Management Directive 325.8 in order to ensure compliance with federal audit submission requirements. Finding 2022 ? 014: (continued) Effect: Since required management decisions were not made within six months to ensure appropriate corrective action was taken on audits received from subrecipients, the Commonwealth did not comply with federal regulations, and subrecipients were not made aware of acceptance or rejection of corrective action plans in a timely manner. Further, noncompliance may recur in future periods if control deficiencies are not corrected on a timely basis, and there is an increased risk of unallowable charges being made to federal programs if corrective action and recovery of questioned costs is not timely. Regarding the SEFA reviews or alternate procedures which are not being performed timely and the late Single Audit report submissions, there is an increased risk that subrecipients could be misspending and/or inappropriately tracking and reporting federal funds over multiple year periods, and these discrepancies may not be properly monitored, detected, and corrected by agency personnel on a timely basis as required. Finally, additional federal pass-through funds may be unaudited in the future without timely and effective remedial action from Commonwealth agencies to enforce compliance. Recommendation: We recommend that the above weaknesses that cause untimely subrecipient Single Audit resolution, including untimely management decisions on findings, untimely review of the SEFA or alternate procedures, and late audit report submissions be corrected to ensure compliance with federal requirements and Commonwealth Management Directives, and to better ensure timelier subrecipient compliance with program requirements. Commonwealth agencies should promptly pursue outstanding audits and implement remedial action steps on a timely basis in accordance with 2 CFR ?200.339 and Commonwealth Management Directive 325.08. PDE Response: PDE agrees with the finding. DEP Response: DEP agrees with the finding. DOH Response: DOH agrees with the finding. DHS Response: While DHS agrees with this finding, we believe we are in compliance with 2 CFR ?200.339 and Commonwealth Management Directive 325.08 related to outstanding audits. We continue to work with counties and their independent auditors to obtain any late Single Audit reports, and albeit late, we do receive them which is the ultimate goal. Questioned Costs: The amount of questioned costs cannot be determined. The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Show full finding ▾
Full finding narrative

Various Agencies Finding 2022 ? 014: ALN 10.553, 10.555, 10.556, 10.559, and 10.582 ? Child Nutrition Cluster (including COVID-19) ALN 10.557 ? WIC Special Supplemental Nutrition Program for Women, Infants, and Children (including COVID-19) ALN 10.558 ? Child and Adult Care Food Program (including COVID-19) ALN 15.252 ? Abandoned Mine Land Reclamation ALN 21.023 ? COVID-19 ? Emergency Rental Assistance Program ALN 84.010 ? Title I Grants to Local Educational Agencies ALN 84.027 and 84.173 ? ? Special Education Cluster (IDEA) (including COVID-19) ALN 84.425C ? COVID 19 ? Education Stabilization Fund - GEER Fund ALN 84.425D ? COVID 19 ? Education Stabilization Fund - ESSER Fund ALN 84.425R ? COVID 19 ? Education Stabilization Fund - CRRSA EANS ALN 84.425U ? COVID 19 ? Education Stabilization Fund - ARP ESSER ALN 84.425W ? COVID 19 ? Education Stabilization Fund - ARP ESSER HCY ALN 93.558 ? Temporary Assistance for Needy Families (including COVID-19) ALN 93.563 ? Child Support Enforcement ALN 93.575 and 93.596 ? Child Care and Development Fund (CCDF) Cluster (including COVID-19) ALN 93.658 ? Foster Care ? Title IV-E (including COVID-19) ALN 93.659 ? Adoption Assistance (including COVID-19) ALN 93.775, 93.777, and 93.778 ? Medicaid Cluster (including COVID-19) A Material Weakness and Material Noncompliance Exist in the Commonwealth?s Subrecipient Audit Resolution Process (A Similar Condition Was Noted in Prior Year Finding 2021-015) Federal Grant Number(s) and Year(s): 1PA300365 (1/01/2022 ? 9/30/2023), 1PA310305 (10/01/2021 ? 9/30/2022), 1PA310305 (10/01/2020 ? 9/30/2021), 1PA300305 (10/01/2021 ? 9/30/2022), 1PA300305 (10/01/2020 ? 9/30/2021), 1PA320305 (12/27/2020 ? 9/30/2021), Y22174 (10/01/2021 ? 9/30/2024), Y13194 (10/01/2020 ? 9/30/2023), Y03194 (10/01/2019 ? 9/30/2023), Y03191 (10/01/2019 ? 9/30/2020), Y22173 (10/01/2021 ? 9/30/2022), Y22172 (10/01/2021 ? 9/30/2022, Y13191 (10/01/2020 ? 9/30/2021), Y13061 (10/01/2020 ? 9/30/2021), S22AF00017 (1/01/2022 ? 12/31/2024), S21AF10050 (6/01/2021 ? 5/31/2024), S21AF10015 (1/01/2021 ? 12/31/2023), S20AF20092 (10/01/2020 ? 9/30/2023), S20AF20006 (1/01/2020 ? 12/31/2022), S19AF20006 (1/01/2019 ? 12/31/2021), S19AF20004 (12/01/2018 ? 11/30/2023), S18AF20004 (11/01/2017 ? 10/31/2023), ERAE0131 (1/19/2021 ? 12/29/2022), ERAE0333 (5/11/2021 ? 12/30/2025), S010A210038 (7/01/2021 ? 9/30/2022), S010A200038 (7/01/2020 ? 9/30/2021), H027A210093 (7/01/2021 ? 9/30/2022), H027A200093 (7/01/2020 ? 9/30/2021), S425D200028 (3/13/2020 ? 9/30/2022), S425D210028 (3/13/2020 ? 9/30/2022), 2201PATANF (10/01/2021 ? 9/30/2022), 2101PATANF (10/01/2020 ? 9/30/2021), 2001PATANF (10/01/2019 ? 9/30/2020), 2201PACSES (10/01/2021 ? 9/30/2022), 2101PACSES (10/01/2020 ? 9/30/2021), G2201PACCDF (10/01/2021 ? 9/30/2022), G2101PACCDF (10/01/2020 ? 9/30/2021), 2201PAFOST (10/01/2021 ? 9/30/2022), 2101PAFOST (10/01/2020 ? 9/30/2021), 2001PAFOST (10/01/2019 ? 9/30/2020), 2201PAADPT (10/01/2021 ? 9/30/2022), 2101PAADPT (10/01/2020 ? 9/30/2021), 2205PA5MAP (10/01/2021 ? 9/30/2022), 2105PA5MAP (10/01/2020 ? 9/30/2021) Finding 2022 ? 014: (continued) Type of Finding: Significant Deficiency, Noncompliance for Medicaid Cluster Material Weakness, Material Noncompliance for Other Programs Compliance Requirement: Subrecipient Monitoring Condition: Under the Commonwealth of Pennsylvania's (Commonwealth) implementation of the Single Audit Act, review and resolution of subrecipient Single Audit reports is split into two stages. The Office of the Budget?s Bureau of Accounting and Financial Management (OB-BAFM) ensures the reports meet technical standards through a centralized desk review process. The various funding agencies in the Commonwealth are responsible for making a management decision on each finding within six months of the Federal Audit Clearinghouse?s (FAC) Management Decision Letter (MDL) start date for audits subject to Uniform Guidance and to ensure appropriate corrective action is taken by the subrecipient (except for Uniform Guidance audits under U.S. Department of Labor programs which are permitted 12 months for management decisions in accordance with 2 CFR Section 2900.21). Each Commonwealth agency is also responsible for reviewing financial information in each audit report to determine whether the audit included all pass-through funding provided by the agency in order to ensure pass-through funds were subject to audit. Most agencies meet this requirement by performing Schedule of Expenditures of Federal Awards (SEFA) reconciliations. The agency is also required to adjust Commonwealth records, if necessary. Our fiscal year ended June 30, 2022 audit of the Commonwealth?s process for review and resolution of subrecipient Single Audits included an evaluation of the Commonwealth?s fiscal year ended June 30, 2021 subrecipient audit universe for audits due for submission to the FAC during the fiscal year ended June 30, 2022. We also evaluated the Commonwealth?s review of 44 subrecipient audit reports with findings in major programs/clusters which were identified on the Commonwealth agencies? tracking lists during the fiscal year ended June 30, 2022 and required management decisions by Commonwealth agencies. Our testing disclosed the following audit exceptions regarding the Commonwealth agencies? review of subrecipient audit reports: ? Department of Education (PDE): The time period for making a management decision on findings was approximately 6.5 to over 13 months after the FAC MDL start date for 14 out of 25 audit reports with findings. Three of the 14 audit reports were improperly classified on PDE?s audit tracking list as not having federal award findings. ? Department of Environmental Protection (DEP): The time period for making a management decision on findings was approximately 16.2 months after the FAC MDL start date for one out of three audit reports with findings. In addition, our review disclosed that DEP subgranted federal funds totaling $10,338,570 to one subrecipient during the fiscal year ended December 31, 2020, for which a Single Audit was not submitted to the FAC as of our January 2023 testing date. This was over 9.5 months after the March 31, 2022 due date, which had been extended due to the COVID-19 pandemic in accordance with the Office of Management and Budget?s (OMB) Memorandum M-21-20, Appendix 3. ? Department of Health (DOH): Our review disclosed that DOH subgranted federal funds totaling $8,103,407 to one subrecipient during the fiscal year ended September 30, 2020, for which a Single Audit was not submitted to the FAC as of our January 2023 testing date. This was over 12.5 months after the December 31, 2021 due date, which had been extended in accordance with OMB?s Memorandum M-21-20, Appendix 3. ? Department of Human Services (DHS): The time period for making a management decision on findings ranged from approximately 6.6 months to over 19.6 months after the FAC MDL start date for 12 out of 14 subrecipient audit reports with findings. There was also a delay in DHS?s procedures to ensure the subrecipient SEFAs were accurate so that major programs were properly determined and subjected to audit. Finding 2022 ? 014: (continued) As a follow-up to the prior year finding, we noted that the Commonwealth subgranted federal funds totaling $327,988,063 to the City of Philadelphia during the fiscal year ended June 30, 2021, for which a Single Audit was not submitted to the FAC as of our January 2023 testing date. This was over 3.5 months after the September 30, 2022 due date, which had been extended in accordance with OMB?s Memorandum M-21-20, Appendix 3. Our testing disclosed that DHS?s subgrants to the City of Philadelphia were material for five of the 16 major programs/clusters with material subgranted funds. Our follow-up on the prior year finding also disclosed that the Commonwealth subgranted federal funds totaling $28,725,212 to Bucks County during the fiscal year ended December 31, 2020, for which a Single Audit was not submitted to the FAC as of our January 2023 testing date. This was over 9.5 months after the March 31, 2022 due date, which had been extended in accordance with OMB?s Memorandum M-21-20, Appendix 3. DHS was the lead agency for the City of Philadelphia and Bucks County audits. Criteria: 2 CFR ?200.332, Requirements for pass-through entities, states in part: All pass-through entities must: (d) Monitor the activities of the subrecipient as necessary to ensure that the subaward is used for authorized purposes, in compliance with Federal statutes, regulations, and the terms and conditions of the subaward, and that subaward performance goals are achieved. Pass-through entity monitoring of the subrecipient must include: (2) Following-up and ensuring that the subrecipient takes timely and appropriate action on all deficiencies pertaining to the Federal award provided to the subrecipient from the pass-through entity detected through audits, on-site reviews, and written confirmation from the subrecipient, highlighting the status of actions planned or taken to address Single Audit findings related to the particular subaward. (3) Issuing a management decision for applicable audit findings pertaining only to the Federal award provided to the subrecipient from the pass-through entity as required by ?200.521 [Management decision]. (f) Verify that every subrecipient is audited as required by Subpart F [Audit Requirements] of this part when it is expected that the subrecipient?s Federal awards expended during the respective fiscal year equaled or exceeded the threshold set forth in ?200.501 [Audit requirements]. (g) Consider whether the results of the subrecipient?s audit, on-site review, or other monitoring indicate conditions that necessitate adjustments to the pass-through entity?s own records. (h) Consider taking enforcement action against noncompliant subrecipients as described in ?200.339 [Remedies for noncompliance] of this part and in program regulations. In order to carry out these responsibilities properly, good internal control dictates that state pass-through agencies ensure subrecipient Single Audit SEFAs are representative of state payment records each year, and that the related federal programs have been properly subjected to Single Audit procedures. 2 CFR ?200.512, Report submission, states in part: (a) General. (1) The audit must be completed and the data collection form described in paragraph (b) of this section and reporting package described in paragraph (c) of this section must be submitted within the earlier of 30 calendar days after receipt of the auditor?s report(s), or nine months after the end of the audit period. If the due date falls on a Saturday, Sunday, or Federal holiday, the reporting package is due the next business day. Finding 2022 ? 014: (continued) 2 CFR ?200.521, Management decision, states in part: (a) General. The management decision must clearly state whether or not the finding is sustained, the reasons for the decision, and the expected auditee action to repay disallowed costs, make financial adjustments, or take other action. (d) Time requirements. The Federal awarding agency or pass-through entity responsible for issuing a management decision must do so within six months of acceptance of the audit report by the FAC. The auditee must initiate and proceed with corrective action as rapidly as possible and corrective action should begin no later than upon receipt of the audit report. 2 CFR ?200.505, Sanctions, states: In cases of continued inability or unwillingness to have an audit conducted in accordance with this part, Federal agencies and pass-through entities must take appropriate action as provided in ?200.339 [Remedies for noncompliance]. 2 CFR ?200.339, Remedies for noncompliance, states in part: If a non-Federal entity fails to comply with the U.S. Constitution, Federal statutes, regulations or the terms and conditions of a Federal award, the Federal awarding agency or pass-through entity may impose additional conditions, as described in ?200.208 [Specific conditions]. If the Federal awarding agency or pass-through entity determines that noncompliance cannot be remedied by imposing additional conditions, the federal awarding agency or pass-through entity may take one or more of the following actions, as appropriate in the circumstances. (a) Temporarily withhold cash payments pending correction of the deficiency by the non-Federal entity or more severe enforcement action by the Federal awarding agency or pass-through entity. (b) Disallow (that is, deny both use of funds and any applicable matching credit for) all or part of the cost of the activity or action not in compliance. (c) Wholly or partly suspend or terminate the Federal award. (d) Initiate suspension or debarment proceedings as authorized under 2 CFR Part 180 and Federal awarding agency regulations (or in the case of a pass-through entity, recommend such a proceeding be initiated by a Federal awarding agency). (e) Withhold further Federal awards for the project or program. (f) Take other remedies that may be legally available. To ensure Commonwealth enforcement of federal regulations for subrecipient noncompliance with audit requirements, Commonwealth Management Directive 325.08, Amended ? Remedies for Recipient Noncompliance with Audit Requirements, Section 5 related to policy, states in part: (a) Agencies must develop and implement remedial action that reflects the unique requirements of each program? (b) The remedial action should be implemented within six months from the date the first remedial action is initiated. At the end of the six-month period, the recipient should take the appropriate corrective action or the final stage of remedial action should be imposed on the recipient. Examples of remedial action include, but are not limited to: Finding 2022 ? 014: (continued) (1) Meeting or calling the recipient to explain the importance and benefits of the audit and audit resolution processes, emphasizing the value of the audit as an administrative tool and the Commonwealth?s reliance on an acceptable audit and prompt resolution as evidence of the recipient?s ability to properly administer the program. (2) Encouraging the entity to establish an audit committee or designate an individual as the single point of contact to: (a) Communicate regarding the audit. (b) Arrange for and oversee the audit. (c) Direct and monitor audit resolution. (3) Providing technical assistance to the recipient in devising and implementing an appropriate plan to remedy the noncompliance. (4) Withholding a portion of assistance payments until the noncompliance is resolved. (5) Withholding or disallowing overhead costs until the noncompliance is resolved. (6) Suspending the assistance agreement until the noncompliance is resolved. (7) Terminating the assistance agreement with the recipient and, if necessary, seeking alternative entities to administer the program. Management Directive 325.09, Amended ? Processing Subrecipient Single Audits of Federal Pass-Through Funds, Section 7 related to procedures, states in part: c. Agencies. (1) Evaluate single audit report submissions received from BAFM to determine program purpose acceptability by verifying, at a minimum, that all agency-funded programs are properly included on the applicable financial schedules; that findings affecting the agency contain sufficient information to facilitate a management decision; and that the subrecipient has submitted an adequate corrective action plan. (6) Issue management decisions relative to audit findings and crosscutting findings assigned to the agency for resolution, as required by 2 CFR ?200.521. If responsible for the resolution of crosscutting findings, notify the affected agency or agencies upon resolution of such findings. (7) Impose or coordinate the imposition of remedial action in accordance with 2 CFR Part 200.339 and Management Directive 325.08 Amended, Remedies for Recipient Noncompliance with Audit Requirements, when subrecipients fail to comply with the provisions of Subpart F. Management Directive 325.12, Amended ? Standards for Enterprise Risk Management in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s, Standards for Internal Control in the Federal Government (Green Book). The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: One reason provided by Commonwealth management for untimely audit resolution in the various agencies, including making management decisions, approving corrective action, and performing procedures to ensure the accuracy of subrecipient SEFAs, was either a change in staff or a lack of staff to follow up and process subrecipient audit reports more timely. The late management decision at DEP appeared to be the result of a subrecipient being treated as a contractor as described in current year Single Audit Finding #2022-005, despite having a subrecipient Single Audit requirement clause in its contract with DEP. Regarding late and outstanding audit report submissions, the Commonwealth agencies did not appear to be timely implementing remedial action steps in accordance with 2 CFR ?200.339 and Commonwealth Management Directive 325.8 in order to ensure compliance with federal audit submission requirements. Finding 2022 ? 014: (continued) Effect: Since required management decisions were not made within six months to ensure appropriate corrective action was taken on audits received from subrecipients, the Commonwealth did not comply with federal regulations, and subrecipients were not made aware of acceptance or rejection of corrective action plans in a timely manner. Further, noncompliance may recur in future periods if control deficiencies are not corrected on a timely basis, and there is an increased risk of unallowable charges being made to federal programs if corrective action and recovery of questioned costs is not timely. Regarding the SEFA reviews or alternate procedures which are not being performed timely and the late Single Audit report submissions, there is an increased risk that subrecipients could be misspending and/or inappropriately tracking and reporting federal funds over multiple year periods, and these discrepancies may not be properly monitored, detected, and corrected by agency personnel on a timely basis as required. Finally, additional federal pass-through funds may be unaudited in the future without timely and effective remedial action from Commonwealth agencies to enforce compliance. Recommendation: We recommend that the above weaknesses that cause untimely subrecipient Single Audit resolution, including untimely management decisions on findings, untimely review of the SEFA or alternate procedures, and late audit report submissions be corrected to ensure compliance with federal requirements and Commonwealth Management Directives, and to better ensure timelier subrecipient compliance with program requirements. Commonwealth agencies should promptly pursue outstanding audits and implement remedial action steps on a timely basis in accordance with 2 CFR ?200.339 and Commonwealth Management Directive 325.08. PDE Response: PDE agrees with the finding. DEP Response: DEP agrees with the finding. DOH Response: DOH agrees with the finding. DHS Response: While DHS agrees with this finding, we believe we are in compliance with 2 CFR ?200.339 and Commonwealth Management Directive 325.08 related to outstanding audits. We continue to work with counties and their independent auditors to obtain any late Single Audit reports, and albeit late, we do receive them which is the ultimate goal. Questioned Costs: The amount of questioned costs cannot be determined. The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Corrective Action Plan

PDE: Audits retrieved from the Federal Audit Clearinghouse are now reviewed after entry into PDE?s SharePoint website, to ensure PDE remains compliant with federal guidelines to respond to any and all findings pertaining to federal dollars it passes to subrecipients. Likewise, PDE Audit Section continues to improve upon its processes for timely determinations of those single audits with findings by multiple means, including periodic SharePoint enhancements designed to aid in timely review of single audit packages, working closely with PDE program areas to assist in timely responses and quickly addressing SharePoint access issues as they arise. Anticipated Completion Date: 06/30/2023 Contact Person and Title: Clayton P. Carroll, II, Audit Coordinator; Jessica Sites, Director, Bur. of Budget and Fiscal Mgmt DEP: BAFM now provides agencies with single audit reporting packages that have findings each week that have been accepted by the Federal Audit Clearinghouse (FAC). This allows for us to start our management decision process in a timelier manner and meet the six-month deadline for issuing our decision. This information first appeared in our notifications starting April 30, 2021. In addition, the DEP program that had been previously identifying agreements as contracts rather than subrecipient agreements has corrected this issue and all subrecipients have been notified in writing of this correction and provided the information for submitting their single audits (if necessary). The letters were sent to subrecipients on approximately May 31, 2022. DEP Fiscal Management staff will continue to monitor the BAFM SharePoint site and FAC for additional filings to attempt to avoid this issue in the future. DEP is also hiring additional staff for the oversight and monitoring of the subrecipient single audits to ensure compliance with all requirements. These positions are currently in the filing process, and we are hopeful that they will be filled, and staff trained by September 30, 2023. Anticipated Completion Date: 09/30/2023 Contact Person and Title: Jennifer L. Brandt, Senior Fiscal Management Specialist, Federal Grants and Audits DOH: NORTH Inc.?s Single Audit report for the period ending 9/30/2020 was officially submitted and showing on the FAC on 2/9/2023. Bureau of WIC staff reached out to the Director and CFO of NORTH Inc. by phone and email. Emails were sent with instructions on how to submit the report as well as the importance of submitting the report timely per their grant agreement. Each follow-up phone call included discussion on the importance of submitting their single audit as soon as possible. Moving forward the Bureau of WIC will implement the following procedure: 1 .Three months after the end of the audit period (Federal Fiscal Year), Project Officers will send an email that outlines the process for submitting a single audit reporting package to the FAC to their respective WIC local agencies. This email will provide a date that the single audit is due to be submitted to the FAC in order to stay in compliance with their current WIC grant agreement. 2. Six months after the end of the audit period (three months from the due date of the single audit reporting package) an official letter from the Bureau Director will go out to the WIC local agencies that are due to submit a single audit. The letters will include instructions on how to submit the single audit in FAC and the Audit Requirements link referenced in their grant agreement. 3. If the WIC local agency notifies the Bureau of WIC that their auditor will not be able to submit their agency?s single audit by the due date, then the Project Officer will work with the local agency to get a projected date of completion and a timeline on when the local agency?s auditor is able to finalize the audit and submit it to the FAC. The Bureau of WIC will then notify DOH?s Audit Coordinator and OB-BAFM of this information, so they are able to track it. 4. If the WIC local agency does not submit the report by the due date and fails to notify their project officer; a notice to cure letter will be sent to the agency. Concerning NORTH Inc.?s Single Audit report for the period ending September 30, 2021: 1. The Bureau of WIC will contact NORTH Inc. and request a meeting with their auditor. 2. Following the meeting with NORTH Inc.?s auditor, the Bureau Director will send an official letter to NORTH Inc. The letter will include the instructions on how to submit the single audit in the FAC and the Audit Requirements link referenced in their grant agreement. They will also be made aware of the actions that could result from them not submitting this audit by the agreed upon date. 3. If the single audit is not received by the agreed upon date, then the Bureau of WIC will send a notice to cure letter. Anticipated Completion Date: 03/24/2023 Contact Person and Title: Sally Zubairu-Cofield, Director, Bureau of WIC DHS: Regarding the timeliness of finding resolution and procedures related to the SEFA reviews, the Audit Resolution Section (ARS) hired an additional staff member in August 2021 and hired two additional staff members in February 2022, and an additional staff member in January 2023. Finally, the ARS worked with Office of the Budget, Bureau of Accounting and Financial Management to develop a risk-based approach for single audit reviews, which will greatly streamline the process of single audit reviews to gain substantial efficiencies. Regarding late audit report submissions, we will continue to follow the requirements of 2 CFR ?200.339 and Commonwealth Management Directive 325.8. We will continue to work with counties and their independent auditors to obtain any late Single Audit reports. Anticipated Completion Date: 06/30/2023 Contact Person and Title: David Bryan, Manager, ARS; Alexander Matolyak, Director, Division of Audit & Review

Prior Finding References

2021-015

About Subrecipient Monitoring →

FY 2021-06-30

FAC accepted this audit on March 17, 2022 — management decision was due September 17, 2022.

2021-003
Reporting
QUESTIONED COSTS

As the State Educational Agency (SEA), the Pennsylvania Department of Education (PDE) is required to submit an annual data report to the United States Department of Education (USDE). This report supports the annual collection of data pertaining to the uses of funds under the Elementary and Secondary School Emergency Relief Fund (ESSER). USDE awards ESSER grants to SEAs for the purpose of providing local educational agencies (LEAs), including charter schools that are LEAs, with emergency relief funds to address the impact of the Novel Coronavirus Disease 2019 (COVID-19) on elementary and secondary schools across the nation. LEAs must provide equitable services to students and teachers in non-public schools as required under the Coronavirus Aid, Relief, and Economic Security Act (CARES Act). During the fiscal year ended June 30, 2021, PDE was required to submit an annual report for the period March 13, 2020 to September 30, 2020 by February 1, 2021. As the direct recipient of ESSER funds, PDE is responsible for ensuring the timeliness and accuracy of the annual report submission. PDE worked with USDE?s contractor and obtained summary information from the LEAs to compile and submit the report. The report contained all required data elements. However, PDE did not implement policies and procedures to ensure the accuracy of the information reported by the LEAs. Therefore, PDE was unable to provide supporting documentation for amounts reported by LEAs on the annual report or to demonstrate that they had reviewed and verified the accuracy of this information. Criteria: The July 2021 OMB Compliance Supplement, Part 4, Section L.3.c, Reporting ? Special Reporting ? Annual Reporting, states in part: Direct recipients of ESSER I and ESSER II grants must submit an annual report [OMB No. 1810-0749] with data for the following categories: ? Overall ESSER I and ESSER II Fund Grant for SEA; ? SEA Reserve (up to 10 percent of total allocation); ? Mandatory Subgrants to LEAs, Section 18003(c) of the CARES Act and Section 313(c) of the CRRSA Act? ? Student Participation and Engagement; and ? Full-Time Equivalent (FTE) Positions. 2 CFR Section 200.303, Internal controls, states: The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in ?Standards for Internal Control in the Federal Government? issued by the Comptroller General of the United States or the ?Internal Control Integrated Framework?, issued by the Committee of the Sponsoring Organizations of the Treadway Commission (COSO). Finding 2021 ? 003: (continued) Management Directive 325.12, Standards for Internal Control for Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book), published in September 2014. The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: PDE did not implement policies and procedures to ensure the accuracy of information reported by LEAs which was included on the Annual Report. Effect: Without review and validation of the detail supporting the summary information reported by LEAs, the Annual Report may have contained inaccurate information. Recommendation: We recommend that PDE implement formal policies and procedures to verify the information reported by LEAs to be included on the Annual Report. Reported amounts should be reviewed for accuracy before reports are submitted to USDE to ensure that reports filed are complete and accurate. Agency Response: PDE agrees with the finding as written. Questioned Costs: The amount of questioned costs cannot be determined. The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Show full finding ▾
Full finding narrative

Department of Education Finding 2021 ? 003: ALN 84.425 ? COVID 19 ? Education Stabilization Fund A Significant Deficiency and Noncompliance Exist at the Department of Education Related to Submission of Elementary and Secondary School Emergency Relief Fund Annual Reporting Federal Grant Number(s) and Year(s): S425D2 (3/13/2020 ? 9/30/2022) Type of Finding: Significant Deficiency, Noncompliance Compliance Requirement: Reporting Condition: As the State Educational Agency (SEA), the Pennsylvania Department of Education (PDE) is required to submit an annual data report to the United States Department of Education (USDE). This report supports the annual collection of data pertaining to the uses of funds under the Elementary and Secondary School Emergency Relief Fund (ESSER). USDE awards ESSER grants to SEAs for the purpose of providing local educational agencies (LEAs), including charter schools that are LEAs, with emergency relief funds to address the impact of the Novel Coronavirus Disease 2019 (COVID-19) on elementary and secondary schools across the nation. LEAs must provide equitable services to students and teachers in non-public schools as required under the Coronavirus Aid, Relief, and Economic Security Act (CARES Act). During the fiscal year ended June 30, 2021, PDE was required to submit an annual report for the period March 13, 2020 to September 30, 2020 by February 1, 2021. As the direct recipient of ESSER funds, PDE is responsible for ensuring the timeliness and accuracy of the annual report submission. PDE worked with USDE?s contractor and obtained summary information from the LEAs to compile and submit the report. The report contained all required data elements. However, PDE did not implement policies and procedures to ensure the accuracy of the information reported by the LEAs. Therefore, PDE was unable to provide supporting documentation for amounts reported by LEAs on the annual report or to demonstrate that they had reviewed and verified the accuracy of this information. Criteria: The July 2021 OMB Compliance Supplement, Part 4, Section L.3.c, Reporting ? Special Reporting ? Annual Reporting, states in part: Direct recipients of ESSER I and ESSER II grants must submit an annual report [OMB No. 1810-0749] with data for the following categories: ? Overall ESSER I and ESSER II Fund Grant for SEA; ? SEA Reserve (up to 10 percent of total allocation); ? Mandatory Subgrants to LEAs, Section 18003(c) of the CARES Act and Section 313(c) of the CRRSA Act? ? Student Participation and Engagement; and ? Full-Time Equivalent (FTE) Positions. 2 CFR Section 200.303, Internal controls, states: The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in ?Standards for Internal Control in the Federal Government? issued by the Comptroller General of the United States or the ?Internal Control Integrated Framework?, issued by the Committee of the Sponsoring Organizations of the Treadway Commission (COSO). Finding 2021 ? 003: (continued) Management Directive 325.12, Standards for Internal Control for Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book), published in September 2014. The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: PDE did not implement policies and procedures to ensure the accuracy of information reported by LEAs which was included on the Annual Report. Effect: Without review and validation of the detail supporting the summary information reported by LEAs, the Annual Report may have contained inaccurate information. Recommendation: We recommend that PDE implement formal policies and procedures to verify the information reported by LEAs to be included on the Annual Report. Reported amounts should be reviewed for accuracy before reports are submitted to USDE to ensure that reports filed are complete and accurate. Agency Response: PDE agrees with the finding as written. Questioned Costs: The amount of questioned costs cannot be determined. The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Corrective Action Plan

The Pennsylvania Department of Education (PDE) recognizes that backup documentation for the reporting monitoring was not provided. However, PDE does not believe it was out of compliance. The information submitted to the United States Department of Education (USDE) contained information collected and reviewed by several programmatic and administrative levels at PDE. The monitoring and record keeping procedures provided reasonable assurance, to the best of PDE?s ability at that time, to ensure the information collected and submitted with the annual report was accurate. Current reporting procedures: PDE used its eGrants system to collect all LEA required records under ESSER I and ESSER II. The eGrants system is designed to allow licensed educational agencies and certain community-based programs within the commonwealth access to PDE grants. Through this system, the LEA can submit applications for funding, e-sign contracting documents, upload back-up documentation, submit program quarterly reports, and file final expenditure reports. The eGrants system makes it possible for records pertaining to the ESSER awards to be retained separately from other grant funds, including funds that an SEA or LEA receives under the CARES Act and CRRSA. This follows the requirements under 2 C.F.R. ? 200.334 and 34 C.F.R. ? 76.730, including financial records related to the use of grant funds. Only an eGrants authorized user that is associated with an Agency or LEA that has an active Program/Project and the role of Agency Project Writer can upload documents to the project. The SEA staff then reviews and investigates the documents. Projects advance if the documents are complete and correct. The grant process is as follows: ? PDE announces and releases grant application in eGrants; ? LEA designated individual completes application in eGrants; ? Prior to submission, LEA?s board-approved designee signs off electronically on application (typically Superintendent or Chief Executive Officer); ? The program area reviews the grant application and returns it for corrections (if necessary). Otherwise, an approvable application goes to the division chief for electronic signature; ? Chief Counsel reviews and approves application for form and legality; ? The Office of Comptroller Operations completes the review of the application and fully executes the contract; and ? LEA receives its first monthly payment. Payments for grants processed through eGrants are made monthly through PDE?s Financial Accounting Information (FAI) System. The FAI system interfaces with PDE?s financial accounting records system, SAP. Monthly payments to LEAs are continuous and automatic based on quarterly financial reports collected through the FAI System. Through quarterly financial reporting, LEAs are required to report the amount of cash received, expended, and on hand. If the amount of cash-on-hand reported is determined to be too high, or the quarterly report is not submitted, monthly payments will be suspended until the next quarterly report is due. Current monitoring procedures: Monitoring to ensure compliance with existing federal guidelines typically occurs from January through May annually. LEAs complete an online self-assessment available within Pennsylvania?s federal monitoring online system, Fedmonitor. All LEAs receive a unique username and password to access Fedmonitor. LEAs are monitored cyclically or as needed based on risk. Beginning in 2021?22, all LEAs were placed on a four-year monitoring cycle and will be monitored once between 2021?22 and 2024?25. Additionally, all LEAs are annually assessed for risk to prevent fraud, waste, and abuse. Those deemed to be medium or high risk on the LEA Risk Assessment will be monitored every year. Points range from 1?20, and most LEAs fall in the low-risk category, with a score of nine and under. Annually, the categories and points are evaluated to determine compliance with Uniform Grant Guidance. LEAs are assigned points for the following factors to determine risk: ? Failure to submit federal grant applications by established deadlines; ? Failure to submit reports/plans by established deadlines which include: o Pennsylvania Information Management System data collection; o Performance Goal Output Reports; and Schoolwide plan(s); ? Previous year monitor/audit findings; ? Excessive federal program carryover Title I allocation. All LEAs receive at least one point for allocation; the higher the allocation, the higher the points; ? New entity; ? New federal program coordinators, business managers, and/or superintendent/chief executive officer; and ? New accounting software at the LEA. A risk assessment, conducted by an outside, contracted entity stated that PDE?s risk is heightened due to the four-year monitoring cycle. Therefore, PDE is working to hire an outside contractor to monitor LEA funds distributed through ESSER I and ESSER II by September 2022. PDE has also self-identified gaps in procedures and internal controls and taken steps to correct them. As stated above, policies and procedures are present but are currently being revised, to support the influx of federal dollars over such a short period of time. Due to capacity issues, PDE does take responsibility for the delay in revising its monitoring and internal control policy. However, PDE has been working to mitigate risks in several areas based on an assessment of risk performed by an outside contractor. For the second phase of the risk assessment and internal controls process, PDE is working to secure an outside contractor to assist with monitoring and establish corrected internal policies and procedures. Anticipated Completion Date: 09/01/2022 Contact Person and Title: Susan McCrone, Division Manager, Federal Programs, PDE

About Reporting →
2021-004
Subrecipient Monitoring
MATERIAL WEAKNESSREPEATQUESTIONED COSTS

The Department of Environmental Protection (DEP) administers the Abandoned Mine Land Reclamation (AMLR) program funded by the United States Department of the Interior (DOI). During the fiscal year ended June 30, 2021, DEP expended $57,711,525 for the AMLR program, of which $8,783,233 was paid to 23 entities with whom DEP executed subrecipient agreements to provide abandoned mine land reclamation repairs and services throughout Pennsylvania. These subrecipient agreements included clauses requiring subrecipient Single Audits. Also, as a result of the expenditures being recorded as subrecipient expenditures in the SAP accounting system, the expenditures were reported as subrecipient expenditures to the federal government when they were automatically uploaded to the federal USASpending system. Our audit testing disclosed that DEP did not conduct program monitoring of these subrecipient expenditures during the fiscal year ended June 30, 2021. Criteria: As part of administering the AMLR program, DEP must have policies, procedures, and controls in place to ensure compliance with federal requirements within contract requirements and regulations. 2 CFR Section 200.332, Requirements for pass through entities, states in part: All pass-through entities must: (d) Monitor the activities of the subrecipient as necessary to ensure that the subaward is used for authorized purposes, in compliance with Federal statutes, regulations, and the terms and conditions of the subaward; and that subaward performance goals are achieved. The standard contract agreement between DEP and the local grantee states, in part: Audit/Compliance Review Requirements - The contractor must comply with all applicable federal and state grant requirements including the Single Audit Act Amendments of 1996; 2 CFR Part 200 as amended; and any other applicable law or regulation, and any amendment to such other applicable law or regulation that may be enacted or promulgated by the federal government. Management Directive 325.12, Standards for Internal Control for Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book), published in September 2014. The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Finding 2021 ? 004: (continued) Cause: DEP management indicated that the 23 entities were contractors for whom subrecipient monitoring requirements were not applicable, and the related expenditures were erroneously recorded in the SAP accounting system and on the Commonwealth?s SEFA as subrecipient expenditures. DEP management stated that their policies and procedures are not significantly different between the entities recorded as subrecipients and those recorded as contractors. However, as noted in the finding condition, our audit disclosed that DEP executed subrecipient agreements with the 23 entities, some of whom had Single Audits conducted, with the AMLR expenditures reported on the Single Audit SEFAs as required for subrecipients. In December 2019, DEP?s Bureau of Abandoned Mine Reclamation management decided that DEP would not approve any additional agreements until the issue is resolved at both the federal and state levels. However, DEP management stated that the agreements that were already in place would continue as executed. DEP did charge expenditures against the previously executed agreements but did not execute any new agreements during the current audit period. Effect: Without the timely completion of AMLR program subrecipient monitoring, DEP cannot ensure compliance with federal statutes, regulations, and the terms and conditions of the subaward contracts, confirm that local subgrantees are performing satisfactory work, ensure the efficient use of program resources, and minimize the risk for fraud and abuse. Completing monitoring activities is essential for DEP to determine whether the local agencies are complying with federal regulations and spending grant funds appropriately. If contractors are misrepresented as subrecipients in the agreements and SAP accounting system, expenditures may be incorrectly reported and unnecessary Single Audit burden has been created at the subrecipient level. Recommendation: We recommend that DEP management make a determination of whether recipients with existing agreements are contractors or subrecipients, and if changes are necessary, amend the agreements and correct the accounting system to record subrecipient and contractor expenditures accurately. DEP should seek formal federal DOI approval to revise any existing agreements to contractor agreements. DEP should also follow this determination consistently with future agreements and accounting treatment. DEP should also develop written policies and procedures for subrecipient monitoring and implement them immediately to ensure timely subrecipient compliance with federal regulations. Agency Response: DEP agrees with the facts as presented in the finding. Questioned Costs: The amount of questioned costs cannot be determined. The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Show full finding ▾
Full finding narrative

Department of Environmental Protection Finding 2021 ? 004: ALN 15.252 ? Abandoned Mine Land Reclamation A Material Weakness and Material Noncompliance Exist at the Department of Environmental Protection Related to Subrecipient Monitoring (A Similar Condition Was Noted in Prior Year Finding 2020-004) Federal Grant Number(s) and Year(s): S21AF10015 (4/01/2021 ? 12/31/2021), S21AF10015 (1/01/2021 ? 12/31/2023), S20AF20092 (10/01/2020 ? 09/30/2023), S20AF20006 (1/01/2020 ?? 12/31/2022), S19AF20006 (1/01/2019 ? 12/31/2021), S19AF20004 (12/01/2018 ? 11/30/2021), S18AF20006 2018 (4/01/2018 ? 12/31/2020), S18AF20004 (11/01/2017 ?10/31/2020), S16AF20042 (6/01/2016 ? 5/31/2021) Type of Finding: Material Weakness, Material Noncompliance Compliance Requirement: Subrecipient Monitoring Condition: The Department of Environmental Protection (DEP) administers the Abandoned Mine Land Reclamation (AMLR) program funded by the United States Department of the Interior (DOI). During the fiscal year ended June 30, 2021, DEP expended $57,711,525 for the AMLR program, of which $8,783,233 was paid to 23 entities with whom DEP executed subrecipient agreements to provide abandoned mine land reclamation repairs and services throughout Pennsylvania. These subrecipient agreements included clauses requiring subrecipient Single Audits. Also, as a result of the expenditures being recorded as subrecipient expenditures in the SAP accounting system, the expenditures were reported as subrecipient expenditures to the federal government when they were automatically uploaded to the federal USASpending system. Our audit testing disclosed that DEP did not conduct program monitoring of these subrecipient expenditures during the fiscal year ended June 30, 2021. Criteria: As part of administering the AMLR program, DEP must have policies, procedures, and controls in place to ensure compliance with federal requirements within contract requirements and regulations. 2 CFR Section 200.332, Requirements for pass through entities, states in part: All pass-through entities must: (d) Monitor the activities of the subrecipient as necessary to ensure that the subaward is used for authorized purposes, in compliance with Federal statutes, regulations, and the terms and conditions of the subaward; and that subaward performance goals are achieved. The standard contract agreement between DEP and the local grantee states, in part: Audit/Compliance Review Requirements - The contractor must comply with all applicable federal and state grant requirements including the Single Audit Act Amendments of 1996; 2 CFR Part 200 as amended; and any other applicable law or regulation, and any amendment to such other applicable law or regulation that may be enacted or promulgated by the federal government. Management Directive 325.12, Standards for Internal Control for Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book), published in September 2014. The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Finding 2021 ? 004: (continued) Cause: DEP management indicated that the 23 entities were contractors for whom subrecipient monitoring requirements were not applicable, and the related expenditures were erroneously recorded in the SAP accounting system and on the Commonwealth?s SEFA as subrecipient expenditures. DEP management stated that their policies and procedures are not significantly different between the entities recorded as subrecipients and those recorded as contractors. However, as noted in the finding condition, our audit disclosed that DEP executed subrecipient agreements with the 23 entities, some of whom had Single Audits conducted, with the AMLR expenditures reported on the Single Audit SEFAs as required for subrecipients. In December 2019, DEP?s Bureau of Abandoned Mine Reclamation management decided that DEP would not approve any additional agreements until the issue is resolved at both the federal and state levels. However, DEP management stated that the agreements that were already in place would continue as executed. DEP did charge expenditures against the previously executed agreements but did not execute any new agreements during the current audit period. Effect: Without the timely completion of AMLR program subrecipient monitoring, DEP cannot ensure compliance with federal statutes, regulations, and the terms and conditions of the subaward contracts, confirm that local subgrantees are performing satisfactory work, ensure the efficient use of program resources, and minimize the risk for fraud and abuse. Completing monitoring activities is essential for DEP to determine whether the local agencies are complying with federal regulations and spending grant funds appropriately. If contractors are misrepresented as subrecipients in the agreements and SAP accounting system, expenditures may be incorrectly reported and unnecessary Single Audit burden has been created at the subrecipient level. Recommendation: We recommend that DEP management make a determination of whether recipients with existing agreements are contractors or subrecipients, and if changes are necessary, amend the agreements and correct the accounting system to record subrecipient and contractor expenditures accurately. DEP should seek formal federal DOI approval to revise any existing agreements to contractor agreements. DEP should also follow this determination consistently with future agreements and accounting treatment. DEP should also develop written policies and procedures for subrecipient monitoring and implement them immediately to ensure timely subrecipient compliance with federal regulations. Agency Response: DEP agrees with the facts as presented in the finding. Questioned Costs: The amount of questioned costs cannot be determined. The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Corrective Action Plan

This issue was first identified in the last single audit. The corrective actions are ongoing. AMLR program representatives attended an online training on March 2, 2021, covering 2 CFR 200 and contractor or subrecipient determinations. The training was being provided by the Department of the Interior, Office of Surface Mining Reclamation and Enforcement (DOI/OSM). The DEP has ceased issuing AMLR grants under Management Directive 305.20, Grant Administration and will not resume issuing them until the AMLR program has subrecipient monitoring procedures in place. DEP management has determined the recipients with existing agreements are subrecipients. DEP will follow this determination consistently with future agreements and accounting treatment. DEP is developing written policies and procedures for subrecipient monitoring and will notify grantees to implement them immediately to ensure timely subrecipient compliance with federal regulations. Anticipated Completion Date: 06/30/2022 Contact Person and Title: Brian Bradley, Director, Bureau of Abandoned Mine Reclamation; Tim Golding, Executive Assistant, Office of Administration and Management

Prior Finding References

2020-004

About Subrecipient Monitoring →
2021-005
Special Tests & Provisions
MATERIAL WEAKNESSREPEATQUESTIONED COSTS

During our audit of the Supplemental Nutrition Assistance Program (SNAP) administered by the Department of Human Services (DHS), we evaluated the security over Electronic Benefits Transfer (EBT) cards, which includes both the physical security of EBT cards during the issuance process at County Assistance Offices (CAO), as well as the handling of EBT cards returned from the United States Postal Service as undeliverable, or those that have been lost or stolen. EBT cards are the method by which SNAP benefit payments are made available to recipients. Also, EBT cards are the primary method by which cash and special allowance benefit payments are made available to Temporary Assistance for Needy Families (TANF) recipients. Total benefit expenditures for SNAP for the fiscal year ended June 30, 2021 totaled $4.9 billion. Total benefit expenditures for TANF for the fiscal year ended June 30, 2021 totaled $111.2 million. Fourteen of the 87 CAO and district locations that issued EBT cards were selected for site testing in the current audit period. During our review of the physical security over EBT cards, we noted exceptions at all CAO and district locations selected for testing. These exceptions included the following: 1) Certain EBT personnel interviewed were unable to adequately answer all questions regarding EBT Security policies and procedures (1 district office and 4 locations); 2) The ending inventory count of EBT cards at June 30, 2021 which was calculated using the weekly log including July 1, 2020, the daily logs for the fiscal year ended June 30, 2021, and the EBT shipment logs for the fiscal year ended June 30, 2021 did not reconcile to the inventory count on the weekly log including June 30, 2021 in the EBT Card Tracking Database (2 district offices and 9 locations); 3) The EBT card issuance total on the Over the Counter (OTC) Card Reconciliation Report for the fiscal year ended June 30, 2021 provided by the EBT Project Office did not reconcile to the daily logs for the fiscal year ended June 30, 2021 in the EBT Card Tracking Database (2 district offices and 8 locations); 4) Failure to perform the following: ? Appoint an Alternate EBT Coordinator (1 district office and 1 location); ? Completion of the witness field on an EBT Shipment Verification Log (1 location); ? Completion of the witness field on a Ribbon Installation and Destruction Log (1 location); ? Create adequate written internal procedures for EBT Security for over the counter card mailings (6 locations); ? Designate a manager or supervisor to the Alternate EBT Coordinator role (1 location); ? Destroy paper EBT logs after four years (2 locations); ? Ensure that coverage for card pinning is available until 5:00 PM each business day (1 location); ? Locate shipping manifest to support the EBT Shipments Verification Log (1 location); Finding 2021 ? 005: (continued) ? Maintain adequate segregation of duties when completing the Weekly Log in the EBT Card Tracking Database. A user edited the Weekly Log after it was approved (1 location); ? Maintain adequate security of EBT Cards (5 locations); ? Maintain adequate security of pinning device (4 locations); ? Maintain adequate security of ribbons, paper EBT logs, and Electronic Payment Processing and Information Control (EPPIC) EBT Systems Application forms (2 locations); ? Proper completion of the date field on the EBT Shipment Verification Log (1 location); ? Proper completion of the requestor field on the EPPIC EBT Systems Application forms (2 district offices and 9 locations); ? Retain paper EBT logs for four years (1 location); ? Retain EPPIC EBT Systems Application forms electronically (2 district offices and 1 location); ? Timely completion and submission of the EPPIC EBT Systems Application forms to the Office of Income Maintenance EBT Security (1 location). Forty of the 261 business days in the current audit period were selected to review the handling and destruction of returned EBT cards. During our review of the handling and destruction of returned EBT cards, we noted exceptions on two of the forty business days selected for testing. These exceptions included the following: 1) Failure to properly complete the EBT Headquarters Card Destruction Log. The "Cards Destroyed By" column of the EBT Headquarters Card Destruction Log was signed and dated by the clerk two days prior to the daily log date. 2) Failure to properly complete the EBT Headquarters Card Destruction Log. The "Approved by Project Office" column of the EBT Headquarters Card Destruction Log was signed and dated by the supervisor one year earlier than the daily log date. Criteria: The 2021 OMB Compliance Supplement, Part 4 ? Agency Program Requirements for the SNAP Cluster, Special Tests and Provisions ? N.3 EBT Card Security, states: The state is required to maintain adequate security over, and documentation/records for, EBT cards to prevent their theft, embezzlement, loss, damage, destruction, unauthorized transfer, negotiation, or use (7 CFR Section 274.8(b)(3)). 7 CFR Section 274.5, Record retention and forms security, states: (c) Accountable Documents. (1) EBT cards shall be considered accountable documents. The State agency shall provide the following minimum security and control procedures for these documents: i. Secure storage; ii. Access limited to authorized personnel; iii. Bulk inventory control records; iv. Subsequent control records maintained through the point of issuance or use; and v. Periodic review and validation of inventory controls and records by parties not otherwise involved in maintaining control records. 45 CFR Section 75.302 applicable to TANF states: (b) The financial management system of each non-Federal entity must provide for the following (see also ?75.361, 75.362, 75.363, 75.364, and 75.365): Finding 2021 ? 005: (continued) (4) Effective control over, and accountability for, all funds, property, and other assets. The non-Federal entity must adequately safeguard all assets and assure that they are used solely for authorized purposes. See ?75.303. Management Directive 325.12, Standards for Internal Control for Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book), published in September 2014. The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: Established policies and procedures were not followed consistently across CAO and district locations, which resulted in ineffective internal controls over EBT card security. Effect: Without adequate security controls over EBT cards, there exists the possibility of misappropriation and/or abuse. Recommendation: We recommend that DHS monitor EBT card security at CAO and district locations on a regular basis to improve consistency in the execution of documented policies and procedures. Agency Response: DHS agrees with this finding. Questioned Costs: The amount of questioned costs cannot be determined. The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Show full finding ▾
Full finding narrative

Department of Human Services Finding 2021 ? 005: ALN 10.551 and 10.561 ? Supplemental Nutrition Assistance Program (SNAP) Cluster (including COVID-19) ALN 93.558 ? Temporary Assistance for Needy Families A Material Weakness and Material Noncompliance Exist at the Department of Human Services Related to Electronic Benefits Transfer Card Security (A Similar Condition Was Noted in Prior Year Finding 2020-005) Federal Grant Number(s) and Year(s): 211PA405S2514 (10/01/2020 ? 9/30/2021), 201PA405S2514 (10/01/2019 ? 9/30/2020), 2101PATANF (10/01/2020 ? 9/30/2021), 2001PATANF (10/01/2019 ? 9/30/2020) Type of Finding: Material Weakness, Material Noncompliance Compliance Requirement: Special Tests and Provisions related to EBT Card Security Condition: During our audit of the Supplemental Nutrition Assistance Program (SNAP) administered by the Department of Human Services (DHS), we evaluated the security over Electronic Benefits Transfer (EBT) cards, which includes both the physical security of EBT cards during the issuance process at County Assistance Offices (CAO), as well as the handling of EBT cards returned from the United States Postal Service as undeliverable, or those that have been lost or stolen. EBT cards are the method by which SNAP benefit payments are made available to recipients. Also, EBT cards are the primary method by which cash and special allowance benefit payments are made available to Temporary Assistance for Needy Families (TANF) recipients. Total benefit expenditures for SNAP for the fiscal year ended June 30, 2021 totaled $4.9 billion. Total benefit expenditures for TANF for the fiscal year ended June 30, 2021 totaled $111.2 million. Fourteen of the 87 CAO and district locations that issued EBT cards were selected for site testing in the current audit period. During our review of the physical security over EBT cards, we noted exceptions at all CAO and district locations selected for testing. These exceptions included the following: 1) Certain EBT personnel interviewed were unable to adequately answer all questions regarding EBT Security policies and procedures (1 district office and 4 locations); 2) The ending inventory count of EBT cards at June 30, 2021 which was calculated using the weekly log including July 1, 2020, the daily logs for the fiscal year ended June 30, 2021, and the EBT shipment logs for the fiscal year ended June 30, 2021 did not reconcile to the inventory count on the weekly log including June 30, 2021 in the EBT Card Tracking Database (2 district offices and 9 locations); 3) The EBT card issuance total on the Over the Counter (OTC) Card Reconciliation Report for the fiscal year ended June 30, 2021 provided by the EBT Project Office did not reconcile to the daily logs for the fiscal year ended June 30, 2021 in the EBT Card Tracking Database (2 district offices and 8 locations); 4) Failure to perform the following: ? Appoint an Alternate EBT Coordinator (1 district office and 1 location); ? Completion of the witness field on an EBT Shipment Verification Log (1 location); ? Completion of the witness field on a Ribbon Installation and Destruction Log (1 location); ? Create adequate written internal procedures for EBT Security for over the counter card mailings (6 locations); ? Designate a manager or supervisor to the Alternate EBT Coordinator role (1 location); ? Destroy paper EBT logs after four years (2 locations); ? Ensure that coverage for card pinning is available until 5:00 PM each business day (1 location); ? Locate shipping manifest to support the EBT Shipments Verification Log (1 location); Finding 2021 ? 005: (continued) ? Maintain adequate segregation of duties when completing the Weekly Log in the EBT Card Tracking Database. A user edited the Weekly Log after it was approved (1 location); ? Maintain adequate security of EBT Cards (5 locations); ? Maintain adequate security of pinning device (4 locations); ? Maintain adequate security of ribbons, paper EBT logs, and Electronic Payment Processing and Information Control (EPPIC) EBT Systems Application forms (2 locations); ? Proper completion of the date field on the EBT Shipment Verification Log (1 location); ? Proper completion of the requestor field on the EPPIC EBT Systems Application forms (2 district offices and 9 locations); ? Retain paper EBT logs for four years (1 location); ? Retain EPPIC EBT Systems Application forms electronically (2 district offices and 1 location); ? Timely completion and submission of the EPPIC EBT Systems Application forms to the Office of Income Maintenance EBT Security (1 location). Forty of the 261 business days in the current audit period were selected to review the handling and destruction of returned EBT cards. During our review of the handling and destruction of returned EBT cards, we noted exceptions on two of the forty business days selected for testing. These exceptions included the following: 1) Failure to properly complete the EBT Headquarters Card Destruction Log. The "Cards Destroyed By" column of the EBT Headquarters Card Destruction Log was signed and dated by the clerk two days prior to the daily log date. 2) Failure to properly complete the EBT Headquarters Card Destruction Log. The "Approved by Project Office" column of the EBT Headquarters Card Destruction Log was signed and dated by the supervisor one year earlier than the daily log date. Criteria: The 2021 OMB Compliance Supplement, Part 4 ? Agency Program Requirements for the SNAP Cluster, Special Tests and Provisions ? N.3 EBT Card Security, states: The state is required to maintain adequate security over, and documentation/records for, EBT cards to prevent their theft, embezzlement, loss, damage, destruction, unauthorized transfer, negotiation, or use (7 CFR Section 274.8(b)(3)). 7 CFR Section 274.5, Record retention and forms security, states: (c) Accountable Documents. (1) EBT cards shall be considered accountable documents. The State agency shall provide the following minimum security and control procedures for these documents: i. Secure storage; ii. Access limited to authorized personnel; iii. Bulk inventory control records; iv. Subsequent control records maintained through the point of issuance or use; and v. Periodic review and validation of inventory controls and records by parties not otherwise involved in maintaining control records. 45 CFR Section 75.302 applicable to TANF states: (b) The financial management system of each non-Federal entity must provide for the following (see also ?75.361, 75.362, 75.363, 75.364, and 75.365): Finding 2021 ? 005: (continued) (4) Effective control over, and accountability for, all funds, property, and other assets. The non-Federal entity must adequately safeguard all assets and assure that they are used solely for authorized purposes. See ?75.303. Management Directive 325.12, Standards for Internal Control for Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book), published in September 2014. The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: Established policies and procedures were not followed consistently across CAO and district locations, which resulted in ineffective internal controls over EBT card security. Effect: Without adequate security controls over EBT cards, there exists the possibility of misappropriation and/or abuse. Recommendation: We recommend that DHS monitor EBT card security at CAO and district locations on a regular basis to improve consistency in the execution of documented policies and procedures. Agency Response: DHS agrees with this finding. Questioned Costs: The amount of questioned costs cannot be determined. The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Corrective Action Plan

1. The EBT Project Office will make updates to the EBT Procedures Manual (Manual) and OIM EPPIC EBT Systems Application form (application). The manual will be updated to provide one link to the application. The application will be updated to properly identify signature requirements. Notification of updates will be sent to CAO staff via the End of the Week publication. 2. All CAOs and district offices will be reminded of the EBT Coordinators?, alternates?, pinners?, and card makers? responsibilities and will ensure users in the EBT Card Tracking Database know their responsibilities and segregation of duties. A reminder will be sent to review the OIM EBT Procedural Manual. 3. OIM mandates annual training for EBT personnel to be completed at the beginning of each year. The training reviews the procedures that safeguard access to the EBT systems. Also included is the following: a. Review of roles and responsibilities and who may hold a role b. Card maker and pinner coverage for all business hours c. Proper security for EBT cards and associated items d. Timeframes for submitting changes e. Retention timeframes Area managers and Staff assistants monitor completion of the training. 4. The EBT Program office will provide guidelines for the CAOs to follow when reviewing/updating their written internal procedures for EBT security for card mailings. 5. The EBT Project Officer will start retraining of parties that are responsible for the completion of the EBT Headquarters Card Destruction log. Anticipated Completion Date: 1. 03/30/2022; 2. 04/01/2022; 3. Completed; 4. 07/01/2022; 5. Completed Contact Person and Title: Jeanette Coulston, OIM Income Maintenance Program Representative

Prior Finding References

2020-005

About Special Tests and Provisions →
2021-006
Reporting
QUESTIONED COSTS

Emergency Rental Assistance (ERA) 1 and ERA 2 state, local, and territorial recipients were required to submit monthly and quarterly reports to the United States Department of the Treasury (US Treasury). The monthly reports are brief two-question updates through which ERA recipients provide US Treasury with very high-level counts of the numbers of households receiving assistance and the amounts of ERA funds distributed. The quarterly reports are in-depth reports with data on an array of programmatic and financial information to provide transparency in the use and progress of ERA funds. Monthly reports were required beginning with the month ending April 30, 2021, and quarterly reports were required beginning with Quarter 1, covering the period of award date through March 30, 2021, and for Quarter 2, covering the period of April 1 through June 30, 2021. As the direct recipient of ERA funds, the Department of Human Services (DHS) is responsible for ensuring the timeliness and accuracy of the report submissions. DHS obtained report information from subrecipients which was compiled and submitted by the due dates. The reports contained all required data elements, however, DHS did not implement policies and procedures to ensure the accuracy of the information reported by the counties. Therefore, DHS was unable to provide supporting documentation for amounts reported by county subrecipients on the reports or to demonstrate that they had reviewed and verified the accuracy of this information. Criteria: The Emergency Rental Assistance Program Reporting Guidance published by the US Treasury identifies several steps in the reporting process: ? Recipients gather and maintain required information such as counts of applicants and participants; amounts paid directly or indirectly to tenants, landlords, and utility/home energy providers; amounts paid to subrecipients and contractors; and administrative expenses. ? Recipients will need to communicate with and gather required information from their subrecipients and contractors, if applicable. ? After manually entering or uploading the report information, Recipients must review the information entered or submitted to the online reporting forms for any errors and completeness. Following completion of the report in Treasury?s portal, the Recipient?s designated Authorized Representative for Reporting must certify to the authenticity and accuracy of the information provided and formally submit the report to Treasury. 2 CFR Section 200.303, Internal controls, states: The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in ?Standards for Internal Control in the Federal Government? issued by the Comptroller General of the United States or the ?Internal Control Integrated Framework?, issued by the Committee of the Sponsoring Organizations of the Treadway Commission (COSO). Finding 2021 ? 006: (continued) Management Directive 325.12, Standards for Internal Control for Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book), published in September 2014. The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: DHS did not implement policies and procedures to ensure the accuracy of information reported by counties which was included on the reports. Effect: Without review and validation of the detail supporting the summary information reported by counties, the reports may have contained inaccurate information. Recommendation: We recommend that DHS implement formal policies and procedures to verify the information reported by counties to be included on the reports. Reported amounts should be reviewed for accuracy before reports are submitted to US Treasury to ensure that reports filed are complete and accurate. Agency Response: DHS agrees with this finding. DHS is working to validate information provided by counties for federal submission. Given the urgent nature of this program, delay in receiving federal guidance, and state legislated reporting, DHS has not yet validated county submittals for the payments made during the period from March 2021 through June 30, 2021, as this new program was in response to a global health pandemic. Questioned Costs: The amount of questioned costs cannot be determined. The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Show full finding ▾
Full finding narrative

Department of Human Services Finding 2021 ? 006: ALN 21.023 ? COVID 19 ? Emergency Rental Assistance Program A Significant Deficiency and Noncompliance Exist at the Department of Human Services Related to Submission of Emergency Rental Assistance Monthly and Quarterly Reporting Federal Grant Number(s) and Year(s): G019649899 (3/13/2020 ? 9/30/2021) Type of Finding: Significant Deficiency, Noncompliance Compliance Requirement: Reporting Condition: Emergency Rental Assistance (ERA) 1 and ERA 2 state, local, and territorial recipients were required to submit monthly and quarterly reports to the United States Department of the Treasury (US Treasury). The monthly reports are brief two-question updates through which ERA recipients provide US Treasury with very high-level counts of the numbers of households receiving assistance and the amounts of ERA funds distributed. The quarterly reports are in-depth reports with data on an array of programmatic and financial information to provide transparency in the use and progress of ERA funds. Monthly reports were required beginning with the month ending April 30, 2021, and quarterly reports were required beginning with Quarter 1, covering the period of award date through March 30, 2021, and for Quarter 2, covering the period of April 1 through June 30, 2021. As the direct recipient of ERA funds, the Department of Human Services (DHS) is responsible for ensuring the timeliness and accuracy of the report submissions. DHS obtained report information from subrecipients which was compiled and submitted by the due dates. The reports contained all required data elements, however, DHS did not implement policies and procedures to ensure the accuracy of the information reported by the counties. Therefore, DHS was unable to provide supporting documentation for amounts reported by county subrecipients on the reports or to demonstrate that they had reviewed and verified the accuracy of this information. Criteria: The Emergency Rental Assistance Program Reporting Guidance published by the US Treasury identifies several steps in the reporting process: ? Recipients gather and maintain required information such as counts of applicants and participants; amounts paid directly or indirectly to tenants, landlords, and utility/home energy providers; amounts paid to subrecipients and contractors; and administrative expenses. ? Recipients will need to communicate with and gather required information from their subrecipients and contractors, if applicable. ? After manually entering or uploading the report information, Recipients must review the information entered or submitted to the online reporting forms for any errors and completeness. Following completion of the report in Treasury?s portal, the Recipient?s designated Authorized Representative for Reporting must certify to the authenticity and accuracy of the information provided and formally submit the report to Treasury. 2 CFR Section 200.303, Internal controls, states: The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in ?Standards for Internal Control in the Federal Government? issued by the Comptroller General of the United States or the ?Internal Control Integrated Framework?, issued by the Committee of the Sponsoring Organizations of the Treadway Commission (COSO). Finding 2021 ? 006: (continued) Management Directive 325.12, Standards for Internal Control for Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book), published in September 2014. The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: DHS did not implement policies and procedures to ensure the accuracy of information reported by counties which was included on the reports. Effect: Without review and validation of the detail supporting the summary information reported by counties, the reports may have contained inaccurate information. Recommendation: We recommend that DHS implement formal policies and procedures to verify the information reported by counties to be included on the reports. Reported amounts should be reviewed for accuracy before reports are submitted to US Treasury to ensure that reports filed are complete and accurate. Agency Response: DHS agrees with this finding. DHS is working to validate information provided by counties for federal submission. Given the urgent nature of this program, delay in receiving federal guidance, and state legislated reporting, DHS has not yet validated county submittals for the payments made during the period from March 2021 through June 30, 2021, as this new program was in response to a global health pandemic. Questioned Costs: The amount of questioned costs cannot be determined. The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Corrective Action Plan

DHS Office of Income Maintenance has hired a contractor to assist in developing monitoring procedures to ensure the accuracy of ERAP reporting. Once those procedures are developed, the contractor will also assist with the validation of the information from the counties. Anticipated Completion Date: 09/30/2022 Contact Person and Title: Joel O'Donnell, Dir., Bur. of Prog. Support

About Reporting →
2021-007
Subrecipient Monitoring
REPEATQUESTIONED COSTS

During the fiscal year ended June 30, 2021, the Department of Human Services (DHS) paid $69.2 million in Temporary Assistance for Needy Families (TANF) funding to subrecipients within the New Directions, Cash Grants, and Alternatives to Abortion appropriations (or 17.6 percent) out of total federal TANF expenditures of $391.4 million reported on the June 30, 2021 Schedule of Expenditures of Federal Awards. Our testing of DHS?s during-the-award monitoring of subrecipients for the fiscal year ended June 30, 2021 disclosed that DHS performed on-site monitoring for all 15 subrecipients selected for testing. The on-site monitoring that was performed consisted of reviews of program operations including design, data entry accuracy and timeliness, case management analysis, and program payment performance goals. The on-site monitoring also included a review of a sample of TANF recipient case files to ensure that the recipients? TANF activities were documented and accurately entered in the Commonwealth?s Workforce Development System. However, DHS?s monitoring procedures for the 15 subrecipients were not adequate as they did not include a review or monitoring of subrecipient financial records, which would provide an assessment of a subrecipient?s compliance with applicable federal regulations. Although DHS?s monitoring procedures include reviewing subrecipient completed questionnaires for selected subrecipients that had questions related to financial matters, DHS?s monitoring personnel did not review subrecipient financial records. For example, DHS did not perform procedures to ensure subrecipient invoices agreed to the books and records of the subrecipient and that the records were adequate to support the allowability of costs paid by DHS during the award period. In addition, DHS?s monitoring procedures did not include an evaluation of the operating effectiveness of DHS subrecipients? procedures to monitor Single Audits and any related findings. In addition to the 15 subrecipients noted above, we followed up on one subrecipient identified in the prior year finding as not being on-site monitored by DHS when the risk assessment warranted on-site monitoring. Our follow-up on DHS?s monitoring of this subrecipient during the current audit period disclosed that DHS personnel began to perform on-site monitoring on this subrecipient. However, the on-site monitoring was not completed at the time we completed our on-site monitoring testing. Since the on-site monitoring was not completed, internal control weaknesses, noncompliance, and questioned costs may have existed and remained undetected during the current audit period. This subrecipient received approximately $815,000 of TANF funds during the fiscal year ended June 30, 2021. Criteria: 45 CFR Section 75.352, Requirements for pass-through entities, states: (d) Monitor the activities of the subrecipient as necessary to ensure that the subaward is used for authorized purposes, in compliance with Federal statutes, regulations, and the terms and conditions of the subaward; and that subaward performance goals are achieved. Pass-through entity monitoring of the subrecipient must include: (1) Reviewing financial and performance reports required by the pass-through entity. Finding 2021 ? 007: (continued) (2) Following-up and ensuring that the subrecipient takes timely and appropriate action on all deficiencies pertaining to the Federal award provided to the subrecipient from the pass-through entity detected through audits, on-site reviews, and other means. (3) Issuing a management decision for audit findings pertaining to the Federal award provided to the subrecipient... 2 CFR Section 200.332, Requirements for Pass-through Entities, states in part: All pass-through entities must: (e) Depending upon the pass-through entity's assessment of risk posed by the subrecipient (as described in paragraph (b) of this section), the following monitoring tools may be useful for the pass-through entity to ensure proper accountability and compliance with program requirements and achievement of performance goals: (1) Providing subrecipients with training and technical assistance on program-related matters; and (2) Performing on-site reviews of the subrecipient's program operations; (3) Arranging for agreed-upon-procedures engagements as described in ?200.425 [Audit services]. Management Directive 325.12, Standards for Internal Control for Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book), published in September 2014. The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: DHS has not implemented adequate during-the-award monitoring procedures of subrecipients to include testing of the financial records and the subrecipients? monitoring of Single Audits sufficient to ensure compliance with federal regulations. In addition, as indicated in DHS?s corrective action plan for the prior year finding, DHS planned to implement new procedures to be used for the on-site monitoring performed during the current audit period. However, as indicated above, the updated procedures were not implemented for the current audit period. Regarding the aforementioned subrecipient for which on-site monitoring was not completed, DHS personnel stated that they are working with the subrecipient to obtain the necessary documentation to complete the on-site monitoring. Effect: TANF subrecipients could be operating in noncompliance with federal regulations without timely detection and correction by DHS management. Recommendation: DHS should strengthen its controls to ensure during-the-award monitoring of TANF subrecipients includes procedures to ensure that subrecipients are in compliance with applicable federal regulations, including ensuring that all required Single Audits were obtained by all DHS subrecipients. Agency Response: DHS agrees with this finding. Questioned Costs: The amount of questioned costs cannot be determined. The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Show full finding ▾
Full finding narrative

Department of Human Services Finding 2021 ? 007: ALN 93.558 ? Temporary Assistance for Needy Families Department of Human Services Did Not Validate Financial Information as Part of Its On-Site Monitoring of Temporary Assistance for Needy Families Subrecipients (A Similar Condition Was Noted in Prior Year Finding 2020-006) Federal Grant Number(s) and Year(s): 2101PATANF (10/01/2020 ? 9/30/2021), 2001PATANF (10/01/2019 ? 9/30/2020) Type of Finding: Significant Deficiency, Noncompliance Compliance Requirement: Subrecipient Monitoring Condition: During the fiscal year ended June 30, 2021, the Department of Human Services (DHS) paid $69.2 million in Temporary Assistance for Needy Families (TANF) funding to subrecipients within the New Directions, Cash Grants, and Alternatives to Abortion appropriations (or 17.6 percent) out of total federal TANF expenditures of $391.4 million reported on the June 30, 2021 Schedule of Expenditures of Federal Awards. Our testing of DHS?s during-the-award monitoring of subrecipients for the fiscal year ended June 30, 2021 disclosed that DHS performed on-site monitoring for all 15 subrecipients selected for testing. The on-site monitoring that was performed consisted of reviews of program operations including design, data entry accuracy and timeliness, case management analysis, and program payment performance goals. The on-site monitoring also included a review of a sample of TANF recipient case files to ensure that the recipients? TANF activities were documented and accurately entered in the Commonwealth?s Workforce Development System. However, DHS?s monitoring procedures for the 15 subrecipients were not adequate as they did not include a review or monitoring of subrecipient financial records, which would provide an assessment of a subrecipient?s compliance with applicable federal regulations. Although DHS?s monitoring procedures include reviewing subrecipient completed questionnaires for selected subrecipients that had questions related to financial matters, DHS?s monitoring personnel did not review subrecipient financial records. For example, DHS did not perform procedures to ensure subrecipient invoices agreed to the books and records of the subrecipient and that the records were adequate to support the allowability of costs paid by DHS during the award period. In addition, DHS?s monitoring procedures did not include an evaluation of the operating effectiveness of DHS subrecipients? procedures to monitor Single Audits and any related findings. In addition to the 15 subrecipients noted above, we followed up on one subrecipient identified in the prior year finding as not being on-site monitored by DHS when the risk assessment warranted on-site monitoring. Our follow-up on DHS?s monitoring of this subrecipient during the current audit period disclosed that DHS personnel began to perform on-site monitoring on this subrecipient. However, the on-site monitoring was not completed at the time we completed our on-site monitoring testing. Since the on-site monitoring was not completed, internal control weaknesses, noncompliance, and questioned costs may have existed and remained undetected during the current audit period. This subrecipient received approximately $815,000 of TANF funds during the fiscal year ended June 30, 2021. Criteria: 45 CFR Section 75.352, Requirements for pass-through entities, states: (d) Monitor the activities of the subrecipient as necessary to ensure that the subaward is used for authorized purposes, in compliance with Federal statutes, regulations, and the terms and conditions of the subaward; and that subaward performance goals are achieved. Pass-through entity monitoring of the subrecipient must include: (1) Reviewing financial and performance reports required by the pass-through entity. Finding 2021 ? 007: (continued) (2) Following-up and ensuring that the subrecipient takes timely and appropriate action on all deficiencies pertaining to the Federal award provided to the subrecipient from the pass-through entity detected through audits, on-site reviews, and other means. (3) Issuing a management decision for audit findings pertaining to the Federal award provided to the subrecipient... 2 CFR Section 200.332, Requirements for Pass-through Entities, states in part: All pass-through entities must: (e) Depending upon the pass-through entity's assessment of risk posed by the subrecipient (as described in paragraph (b) of this section), the following monitoring tools may be useful for the pass-through entity to ensure proper accountability and compliance with program requirements and achievement of performance goals: (1) Providing subrecipients with training and technical assistance on program-related matters; and (2) Performing on-site reviews of the subrecipient's program operations; (3) Arranging for agreed-upon-procedures engagements as described in ?200.425 [Audit services]. Management Directive 325.12, Standards for Internal Control for Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book), published in September 2014. The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: DHS has not implemented adequate during-the-award monitoring procedures of subrecipients to include testing of the financial records and the subrecipients? monitoring of Single Audits sufficient to ensure compliance with federal regulations. In addition, as indicated in DHS?s corrective action plan for the prior year finding, DHS planned to implement new procedures to be used for the on-site monitoring performed during the current audit period. However, as indicated above, the updated procedures were not implemented for the current audit period. Regarding the aforementioned subrecipient for which on-site monitoring was not completed, DHS personnel stated that they are working with the subrecipient to obtain the necessary documentation to complete the on-site monitoring. Effect: TANF subrecipients could be operating in noncompliance with federal regulations without timely detection and correction by DHS management. Recommendation: DHS should strengthen its controls to ensure during-the-award monitoring of TANF subrecipients includes procedures to ensure that subrecipients are in compliance with applicable federal regulations, including ensuring that all required Single Audits were obtained by all DHS subrecipients. Agency Response: DHS agrees with this finding. Questioned Costs: The amount of questioned costs cannot be determined. The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Corrective Action Plan

New Directions The Office of Income Maintenance (OIM) updated agency monitoring personnel checklists in FY 2019-20 to include testing various financial controls of select grantees based on their Risk Assessment scores. OIM had planned to move forward with a portion of on-site monitoring during the year ended June 30, 2020, however, since March 13, 2020, agency personnel have been restricted from travel, making on-site monitoring not feasible. OIM is currently operating under a public health emergency. Once the state provides travel guidance at the conclusion of the health emergency and there is a recovery plan in place as an agency, OIM will be able to perform this monitoring. Alternatives to Abortion The Office of Policy Development (OPD) initiated numerous conversations with the Alternatives to Abortion grantee regarding receiving the requested documentation for monitoring (communication occurred regularly from April 2021 through January 2022). The grantee disagrees that the disclosure of this information is a requirement of the grant agreement and as such has not provided the documentation needed to complete the monitoring. On January 27, 2022, DHS sent a letter to the grantee requesting a response to determine the next steps for this monitoring review. On January 28, 2022, the grantee requested to meet with DHS's Office of General Counsel to discuss the issue and find a solution. The Office of General Counsel and the Alternatives to Abortion grantee are in the process of scheduling a meeting to discuss this situation and come to a resolution. In addition, OPD completed risk assessments for FY 21-22. Monitoring will prioritize subrecipients receiving a ?high risk? designation and/or who have not been monitored in the past 5 years. Monitoring will occur by June 30, 2022 Anticipated Completion Date: 06/30/2022 Contact Person and Title: Joel O?Donnell, Director, Bureau of Program Support; Jazmin Cartwright, Grants and Policy Specialist

Prior Finding References

2020-006

About Subrecipient Monitoring →
2021-008
Subrecipient Monitoring
MATERIAL WEAKNESSREPEATQUESTIONED COSTS

The Department of Human Services? (DHS) Office of Children, Youth, and Families (OCYF) performs two types of during-the-award monitoring of its 67 subrecipient County Children and Youth Agencies (CCYAs). One group within OCYF performs on-site inspections to support its reissuance of licenses for all 67 CCYAs to whom DHS subgrants funds to perform Foster Care, Adoption Assistance services, and Temporary Assistance for Needy Families (TANF) Child Welfare. These inspections primarily focus on health, safety, and performance issues, and each on-site inspection is documented on an Annual Survey and Evaluation Summary. A license, or certificate of compliance, is issued for a period of one year if the results of the on-site inspection determine the entity is in compliance with statutes, ordinances, and regulations. In addition, a separate group within DHS?s OCYF performs Title IV-E Quality Assurance Compliance Reviews which primarily focus on eligibility and allowability. These two types of on-site monitoring visits are not performed at the same time. To test DHS?s licensing/inspections and Quality Assurance Compliance Reviews in the current year, we selected 13 of the 67 CCYAs receiving Foster Care, Adoption Assistance, and TANF funds. Our current year testing of the on-site licensing inspections disclosed the following exceptions: ? On-site inspections of two of the 13 CCYAs tested were not completed within 12 months of the completion of the prior on-site inspection. One of the current year inspections was completed four months late and one of the current year inspections was completed 5 months late. ? On-site inspections of three of the 13 CCYAs tested were either not reviewed and approved timely, or not reviewed and approved at all by a supervisor and a regional director. The inspections were approved between 1 and 207 days after the expiration of the prior license. Also, as part of our testing of monitoring, we noted that DHS did not have adequate procedures in place to determine if CCYAs were monitoring their subrecipients. Specifically, DHS did not perform procedures to determine if CCYAs were monitoring Single Audits of subrecipients and evaluating the follow-up of any findings, or that CCYAs were only paying for allowable services. Foster Care program payments made by DHS to its 67 CCYA subrecipients during the fiscal year ended June 30, 2021 were $204.5 million, or 89.8 percent of total Foster Care expenditures of $227.8 million reported on the June 30, 2021 Schedule of Expenditures of Federal Awards (SEFA). Adoption Assistance program payments made by DHS to its Finding 2021 ? 008: (continued) 67 CCYA subrecipients during the fiscal year ended June 30, 2021 were $118.6 million, or 75.9 percent of total Adoption Assistance expenditures of $156.3 million reported on the June 30, 2021 SEFA. TANF Child Welfare program payments made by DHS to its 67 CCYA subrecipients during the fiscal year ended June 30, 2021 were $48.6 million, or 12.4 percent of total TANF expenditures of $391.4 million reported on the June 30, 2021 SEFA. Criteria: 45 CFR Section 75.352, applicable to TANF, Foster Care, and Adoption Assistance states: (d) Monitor the activities of the subrecipient as necessary to ensure that the subaward is used for authorized purposes, in compliance with Federal statutes, regulations, and the terms and conditions of the subaward; and that subaward performance goals are achieved. Pass-through entity monitoring of the subrecipient must include: (1) Reviewing financial and performance reports required by the pass-through entity. (2) Following-up and ensuring that the subrecipient takes timely and appropriate action on all deficiencies pertaining to the Federal award provided to the subrecipient from the pass-through entity detected through audits, on-site reviews, and other means. (3) Issuing a management decision for audit findings pertaining to the Federal award provided to the subrecipient? Pennsylvania Code Title 55, Chapter 20, Licensure or Approval of Facilities and Agencies, Section 20.51 states: A certificate of compliance will be issued to the legal entity by the Department if, after an inspection by an authorized agent of the Department, it is determined that requirements for a certificate of compliance are met. In addition, Pennsylvania Code Title 55, Chapter 20, Section 20.52 states: If, during an inspection, authorized agents of the Department observe items of noncompliance with licensure or approval regulations, the legal entity shall submit an acceptable written plan to correct each noncompliance item and shall establish an acceptable period of time to correct these items. Management Directive 325.12, Standards for Internal Control for Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book), published in September 2014. The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: DHS personnel indicated that the two on-site inspections that were not completed within 12 months of the prior inspection and the three inspections that were not timely reviewed and approved by a supervisor or a regional director were due to the COVID-19 pandemic, which caused a delay in scheduling the on-site inspections, as well as the subsequent review and approvals. DHS believes that its current monitoring procedures to determine subrecipient eligibility, monitor programmatic operations, review subrecipient audits, and review subrecipient agreed-upon-procedure reports are sufficient to effectively monitor its subrecipients or contractors. Finding 2021 ? 008: (continued) Effect: DHS OCYF?s failure to perform timely on-site inspections and the subsequent reviews and approvals of the inspection reports before the expiration of the prior license allowed the CCYAs to operate without a proper license for an extended period of time. Also, since DHS did not determine if CCYAs were monitoring their subrecipients, CCYAs could be operating in noncompliance with federal regulations without timely detection and correction by DHS management. Recommendation: DHS?s OCYF should strengthen its controls to ensure monitoring and inspections of Foster Care, Adoption Assistance, and TANF subrecipients are performed and reviewed by management on a timely basis and include procedures to ensure CCYAs are monitoring their subrecipients or contractors. Agency Response: DHS agrees with this finding, Questioned Costs: The amount of questioned costs cannot be determined. The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Show full finding ▾
Full finding narrative

Department of Human Services Finding 2021 ? 008: ALN 93.558 ? Temporary Assistance for Needy Families ALN 93.658 ? Foster Care ? Title IV-E (including COVID-19) ALN 93.659 ? Adoption Assistance (including COVID-19) Material Weaknesses and Material Noncompliance Exist in Monitoring of Foster Care, Adoption Assistance, and Temporary Assistance for Needy Families Subrecipients by the Department of Human Services? Office of Children, Youth, and Families (A Similar Condition Was Noted in Prior Year Finding 2020-007) Federal Grant Number(s) and Year(s): 2101PATANF (10/01/2020 ? 9/30/2021), 2001PATANF (10/01/2019 ? 9/30/2020), 1901PATANF (10/01/2018 ? 9/30/2019), 1801PATANF (10/01/2017 ? 9/30/2018), 2101PAFOST (10/01/2020 ? 9/30/2021), 2001PAFOST (10/01/2019 ? 9/30/2020), 2101PAADPT (10/01/2020 ? 9/30/2021), 2001PAADPT (10/01/2019 ? 9/30/2020) Type of Finding: Material Weakness, Material Noncompliance Compliance Requirement: Subrecipient Monitoring Condition: The Department of Human Services? (DHS) Office of Children, Youth, and Families (OCYF) performs two types of during-the-award monitoring of its 67 subrecipient County Children and Youth Agencies (CCYAs). One group within OCYF performs on-site inspections to support its reissuance of licenses for all 67 CCYAs to whom DHS subgrants funds to perform Foster Care, Adoption Assistance services, and Temporary Assistance for Needy Families (TANF) Child Welfare. These inspections primarily focus on health, safety, and performance issues, and each on-site inspection is documented on an Annual Survey and Evaluation Summary. A license, or certificate of compliance, is issued for a period of one year if the results of the on-site inspection determine the entity is in compliance with statutes, ordinances, and regulations. In addition, a separate group within DHS?s OCYF performs Title IV-E Quality Assurance Compliance Reviews which primarily focus on eligibility and allowability. These two types of on-site monitoring visits are not performed at the same time. To test DHS?s licensing/inspections and Quality Assurance Compliance Reviews in the current year, we selected 13 of the 67 CCYAs receiving Foster Care, Adoption Assistance, and TANF funds. Our current year testing of the on-site licensing inspections disclosed the following exceptions: ? On-site inspections of two of the 13 CCYAs tested were not completed within 12 months of the completion of the prior on-site inspection. One of the current year inspections was completed four months late and one of the current year inspections was completed 5 months late. ? On-site inspections of three of the 13 CCYAs tested were either not reviewed and approved timely, or not reviewed and approved at all by a supervisor and a regional director. The inspections were approved between 1 and 207 days after the expiration of the prior license. Also, as part of our testing of monitoring, we noted that DHS did not have adequate procedures in place to determine if CCYAs were monitoring their subrecipients. Specifically, DHS did not perform procedures to determine if CCYAs were monitoring Single Audits of subrecipients and evaluating the follow-up of any findings, or that CCYAs were only paying for allowable services. Foster Care program payments made by DHS to its 67 CCYA subrecipients during the fiscal year ended June 30, 2021 were $204.5 million, or 89.8 percent of total Foster Care expenditures of $227.8 million reported on the June 30, 2021 Schedule of Expenditures of Federal Awards (SEFA). Adoption Assistance program payments made by DHS to its Finding 2021 ? 008: (continued) 67 CCYA subrecipients during the fiscal year ended June 30, 2021 were $118.6 million, or 75.9 percent of total Adoption Assistance expenditures of $156.3 million reported on the June 30, 2021 SEFA. TANF Child Welfare program payments made by DHS to its 67 CCYA subrecipients during the fiscal year ended June 30, 2021 were $48.6 million, or 12.4 percent of total TANF expenditures of $391.4 million reported on the June 30, 2021 SEFA. Criteria: 45 CFR Section 75.352, applicable to TANF, Foster Care, and Adoption Assistance states: (d) Monitor the activities of the subrecipient as necessary to ensure that the subaward is used for authorized purposes, in compliance with Federal statutes, regulations, and the terms and conditions of the subaward; and that subaward performance goals are achieved. Pass-through entity monitoring of the subrecipient must include: (1) Reviewing financial and performance reports required by the pass-through entity. (2) Following-up and ensuring that the subrecipient takes timely and appropriate action on all deficiencies pertaining to the Federal award provided to the subrecipient from the pass-through entity detected through audits, on-site reviews, and other means. (3) Issuing a management decision for audit findings pertaining to the Federal award provided to the subrecipient? Pennsylvania Code Title 55, Chapter 20, Licensure or Approval of Facilities and Agencies, Section 20.51 states: A certificate of compliance will be issued to the legal entity by the Department if, after an inspection by an authorized agent of the Department, it is determined that requirements for a certificate of compliance are met. In addition, Pennsylvania Code Title 55, Chapter 20, Section 20.52 states: If, during an inspection, authorized agents of the Department observe items of noncompliance with licensure or approval regulations, the legal entity shall submit an acceptable written plan to correct each noncompliance item and shall establish an acceptable period of time to correct these items. Management Directive 325.12, Standards for Internal Control for Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book), published in September 2014. The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: DHS personnel indicated that the two on-site inspections that were not completed within 12 months of the prior inspection and the three inspections that were not timely reviewed and approved by a supervisor or a regional director were due to the COVID-19 pandemic, which caused a delay in scheduling the on-site inspections, as well as the subsequent review and approvals. DHS believes that its current monitoring procedures to determine subrecipient eligibility, monitor programmatic operations, review subrecipient audits, and review subrecipient agreed-upon-procedure reports are sufficient to effectively monitor its subrecipients or contractors. Finding 2021 ? 008: (continued) Effect: DHS OCYF?s failure to perform timely on-site inspections and the subsequent reviews and approvals of the inspection reports before the expiration of the prior license allowed the CCYAs to operate without a proper license for an extended period of time. Also, since DHS did not determine if CCYAs were monitoring their subrecipients, CCYAs could be operating in noncompliance with federal regulations without timely detection and correction by DHS management. Recommendation: DHS?s OCYF should strengthen its controls to ensure monitoring and inspections of Foster Care, Adoption Assistance, and TANF subrecipients are performed and reviewed by management on a timely basis and include procedures to ensure CCYAs are monitoring their subrecipients or contractors. Agency Response: DHS agrees with this finding, Questioned Costs: The amount of questioned costs cannot be determined. The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Corrective Action Plan

OCYF Regional Director staff have verified that OCYF Regional Offices are issuing the Licensing Inspection Summary (LIS) within 15 days of the close of the inspection, as is considered timely. If applicable, counties have ten calendar days to respond to the plan of correction (POC) and that POC needs to be reviewed by the regional office within ten business days for compliance. This LIS will be sent to Harrisburg for processing. Concerning the monitoring of subrecipients: Counties are required to maintain a written contract with each provider to which clients are referred. The provider agency must submit to the county children and youth agency (CCYA) quarterly progress reports, discharge summaries, billing statements, and other written reports as required by the CCYA and/or in accordance with DHS regulations or guidance. The CCYA must monitor provider adherence to the Child Protective Services Law (CPSL) background check requirements to assure the safety of children receiving prevention, reunification, and aftercare services (coded as ?in-home?). Counties have primary oversight of their service providers by the fiscal office, quality assurance staff or their contract monitors. The CCYA must document these efforts and report them to DHS. As part of the county single audit reporting package, all counties are required to include a supplemental schedule, which is subjected to an Agreed-Upon Procedures engagement. The schedule documents CCYA monitoring of providers? adherence to the requirements of the CPSL for children in in-home providers. The schedule includes a list of all providers, date of most recent monitoring, if there were exceptions, submission of a corrective action plan (CAP), and acceptance, implementation, and follow-up on the CAP. The county?s independent auditor is required to test the list for completeness and analyze the CCYA?s documentation of monitoring activities for adequacy, obtaining necessary corrective action plans, and timely follow-up on corrective action plans, and adequacy and accuracy of monitoring documentation. As single audit reports are received in DHS, a copy is transmitted to OCYF for review by the Bureau of Budget and Fiscal Support and use in QA reviews, including the supplemental information and any applicable findings contained. In addition, the Pennsylvania Department of the Auditor General (AG) conducts annual engagements of the CCYAs to ascertain and certify actual expenditures on behalf of children residing within the County and to determine compliance with regulations. During these engagements, the AG reviews the county policies and procedures of in-home purchased services billings and CPSL adherence. Any issued findings and/or observations included in these reports are also considered in Licensing Inspections and QA reviews. Anticipated Completion Date: 06/30/2022 Contact Person and Title: TinaMarie Petrovitz, Director, County Support

Prior Finding References

2020-007

About Subrecipient Monitoring →
2021-009
Special Tests & Provisions
REPEAT

The Pennsylvania Department of Human Services (DHS) is required by the United States Department of Health and Human Services (HHS), Centers for Medicare and Medicaid Services (CMS), to implement six required Medicaid National Correct Coding Initiative (NCCI) methodologies. These methodologies include procedure-to-procedure and medically unlikely edits of Medicaid fee-for-service claims submitted for processing through DHS?s PROMISe system to ensure that only proper payments of Medicaid procedures are reimbursed. As part of this process, DHS is required to download quarterly NCCI edit tables from CMS which are subsequently uploaded into PROMISe by DHS?s PROMISe vendor. During the fiscal year ended June 30, 2021, DHS did not ensure that its contract with the PROMISe vendor included the NCCI Confidentiality Agreement required by the HHS/CMS Medicaid NCCI Technical Guidance Manual. Criteria: Management Directive 325.12, Standards for Internal Control for Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book), published in September 2014. The Green Book states in part: Management should identify, analyze, and respond to significant changes that could impact the internal control system. The HHS/CMS Medicaid NCCI Technical Guidance Manual, Section 7.1.2, Sharing of State Medicaid NCCI Edit Files by States with Other Entities, states in part: A state Medicaid agency may share these quarterly state Medicaid NCCI edit files which are posted on the secure RISSNET [Regional Information Sharing System Network] portal with the contracted fiscal agent that processes its fee-for-service claims or with any of its contracted Medicaid managed-care entities that is using the Medicaid NCCI methodologies in its processing of claims or encounter data, if appropriate confidentiality agreements are in place. The HHS/CMS Medicaid NCCI Technical Guidance Manual, Section 7.1.3, Confidentiality Agreements Requirements for Contracted Parties, states: At a minimum, the following elements must be included in the confidentiality agreements for any contracted party using the Medicaid NCCI files posted on the secure RISSNET portal: Disclosure shall be limited to only those responsible for the implementation of the quarterly state Medicaid NCCI edit files. Finding 2021 ? 009: (continued) After the start of the new calendar quarter, a contracted party may disclose only non-confidential information contained in the Medicaid NCCI edit files that is also available to the general public found on the Medicaid NCCI webpage. The contracted party agrees to use any non-public information from the quarterly state Medicaid NCCI edit files only for any business purposes directly related to the implementation of the Medicaid NCCI methodologies in the particular state. New, revised, or deleted Medicaid NCCI edits shall not be published or otherwise shared with individuals, medical societies, or any other entities unless it is a contracted party prior to the posting of the Medicaid NCCI edits on the Medicaid NCCI webpage. Implementation of new, revised, or deleted Medicaid NCCI edits shall not occur prior to the first day of the calendar quarter. Only a state Medicaid agency has the discretion to release additional information for selected individual edits or limited ranges of edits from the files posted on the secure RISSNET portal. State Medicaid agencies must impose penalties, up to and including loss of contract, for violations of any confidentiality agreement relating to use of the secure RISSNET portal edit files. Cause: DHS personnel stated that the confidentiality agreement required by the HHS/CMS Medicaid NCCI Technical Guidance Manual was not included in the PROMISe contract, since the contract was finalized prior to the HHS issuance of the NCCI requirements. Effect: Since DHS did not ensure the required NCCI Confidentiality Agreement was included in its contract with the PROMISe vendor, DHS was not in compliance with federal regulations. Recommendation: DHS should ensure the required NCCI Confidentiality Agreement is included in an amendment to its contract with the PROMISe vendor. Agency Response: DHS agrees with this finding. Questioned Costs: None The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Show full finding ▾
Full finding narrative

Department of Human Services Finding 2021 ? 009: ALN 93.775, 93.777, and 93.778 ? Medicaid Cluster (including COVID-19) A Significant Deficiency and Noncompliance Exist at the Department of Human Services Related to the Medicaid National Correct Coding Initiative (A Similar Condition Was Noted in Prior Year Finding 2020-010) Federal Grant Number(s) and Year(s): 2105PA5MAP (10/01/2020 ? 9/30/2021), 2105PA5ADM (10/01/2020 ? 9/30/2021), 2005PA5MAP (10/01/2019 ? 9/30/2020), 2005PA5ADM (10/01/2019 ? 9/30/2020) Type of Finding: Significant Deficiency, Noncompliance Compliance Requirement: Special Tests and Provisions related to the Medicaid National Correct Coding Initiative (NCCI) Condition: The Pennsylvania Department of Human Services (DHS) is required by the United States Department of Health and Human Services (HHS), Centers for Medicare and Medicaid Services (CMS), to implement six required Medicaid National Correct Coding Initiative (NCCI) methodologies. These methodologies include procedure-to-procedure and medically unlikely edits of Medicaid fee-for-service claims submitted for processing through DHS?s PROMISe system to ensure that only proper payments of Medicaid procedures are reimbursed. As part of this process, DHS is required to download quarterly NCCI edit tables from CMS which are subsequently uploaded into PROMISe by DHS?s PROMISe vendor. During the fiscal year ended June 30, 2021, DHS did not ensure that its contract with the PROMISe vendor included the NCCI Confidentiality Agreement required by the HHS/CMS Medicaid NCCI Technical Guidance Manual. Criteria: Management Directive 325.12, Standards for Internal Control for Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book), published in September 2014. The Green Book states in part: Management should identify, analyze, and respond to significant changes that could impact the internal control system. The HHS/CMS Medicaid NCCI Technical Guidance Manual, Section 7.1.2, Sharing of State Medicaid NCCI Edit Files by States with Other Entities, states in part: A state Medicaid agency may share these quarterly state Medicaid NCCI edit files which are posted on the secure RISSNET [Regional Information Sharing System Network] portal with the contracted fiscal agent that processes its fee-for-service claims or with any of its contracted Medicaid managed-care entities that is using the Medicaid NCCI methodologies in its processing of claims or encounter data, if appropriate confidentiality agreements are in place. The HHS/CMS Medicaid NCCI Technical Guidance Manual, Section 7.1.3, Confidentiality Agreements Requirements for Contracted Parties, states: At a minimum, the following elements must be included in the confidentiality agreements for any contracted party using the Medicaid NCCI files posted on the secure RISSNET portal: Disclosure shall be limited to only those responsible for the implementation of the quarterly state Medicaid NCCI edit files. Finding 2021 ? 009: (continued) After the start of the new calendar quarter, a contracted party may disclose only non-confidential information contained in the Medicaid NCCI edit files that is also available to the general public found on the Medicaid NCCI webpage. The contracted party agrees to use any non-public information from the quarterly state Medicaid NCCI edit files only for any business purposes directly related to the implementation of the Medicaid NCCI methodologies in the particular state. New, revised, or deleted Medicaid NCCI edits shall not be published or otherwise shared with individuals, medical societies, or any other entities unless it is a contracted party prior to the posting of the Medicaid NCCI edits on the Medicaid NCCI webpage. Implementation of new, revised, or deleted Medicaid NCCI edits shall not occur prior to the first day of the calendar quarter. Only a state Medicaid agency has the discretion to release additional information for selected individual edits or limited ranges of edits from the files posted on the secure RISSNET portal. State Medicaid agencies must impose penalties, up to and including loss of contract, for violations of any confidentiality agreement relating to use of the secure RISSNET portal edit files. Cause: DHS personnel stated that the confidentiality agreement required by the HHS/CMS Medicaid NCCI Technical Guidance Manual was not included in the PROMISe contract, since the contract was finalized prior to the HHS issuance of the NCCI requirements. Effect: Since DHS did not ensure the required NCCI Confidentiality Agreement was included in its contract with the PROMISe vendor, DHS was not in compliance with federal regulations. Recommendation: DHS should ensure the required NCCI Confidentiality Agreement is included in an amendment to its contract with the PROMISe vendor. Agency Response: DHS agrees with this finding. Questioned Costs: None The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Corrective Action Plan

OMAP?s Bureau of Data and Claims Management (BDCM) is currently negotiating an amendment to the PROMISe contract which will include the necessary NCCI Confidentiality Agreement. Anticipated Completion Date: 06/30/2022 Contact Person and Title: Sandra Marcella, Dir., BDCM

Prior Finding References

2020-010

About Special Tests and Provisions →
2021-010
Special Tests & Provisions

The Pennsylvania Department of Human Services (DHS) administers the Medicaid Cluster for which expenditures reported on the fiscal year ended June 30, 2021 Schedule of Expenditures of Federal Awards totaled $23,828,691,242. DHS is required by the United States Department of Health and Human Services (HHS), Centers for Medicare and Medicaid Services (CMS), to obtain two types of audits for Medicaid Cluster managed care: annual audited financial reports and periodic audits. The periodic audits concern the accuracy, truthfulness, and completeness of the encounter and financial data submitted by, or on behalf of, each managed care organization (MCO), and the periodic audit results are required to be posted on DHS?s website. During the fiscal year ended June 30, 2021, periodic audits were required for MCOs used for behavioral health, long-term care, and physical health. Periodic audit reports for behavioral health were obtained, and the results were properly posted to DHS?s website. DHS?s Office of Long-Term Living (OLTL) obtained all three required periodic audit reports for the long-term care MCOs, but OLTL did not ensure the periodic audit reports? results were posted on DHS?s website as required by HHS. DHS?s Office of Medical Assistance Programs (OMAP) did not obtain one required periodic audit report for the physical health MCOs, so the periodic audit?s results were not available to be posted on DHS?s website as required by HHS. Criteria: 42 CFR Section 438.602, State responsibilities, states: (e) Periodic audits. The State must periodically, but no less frequently than once every 3 years, conduct, or contract for the conduct of, an independent audit of the accuracy, truthfulness, and completeness of the encounter and financial data submitted by, or on behalf of, each MCO, PIHP [Prepaid Inpatient Health Plan], or PAHP [Prepaid Ambulatory Health Plan]. (g) Transparency. The State must post on its website, as required in ?438.10(c)(3), the following documents and reports: (4) The results of any audits under paragraph (e) of this section. Management Directive 325.12, Standards for Internal Control for Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book), published in September 2014. The Green Book states in part: Management should identify, analyze, and respond to significant changes that could impact the internal control system. Finding 2021 ? 010: (continued) Cause: DHS?s OLTL personnel stated that the periodic audit reports? results were not posted to DHS?s website due to an oversight. DHS?s OMAP personnel represented the periodic audit was in process but the audit report was not complete, so there were no results available to post to DHS?s website. Effect: Since DHS did not ensure all periodic audit reports were completed, and the periodic audit report results were not all posted to DHS?s website, DHS was not in compliance with federal regulations. Recommendation: DHS?s OMAP should implement procedures to timely obtain the required periodic audit reports. OLTL and OMAP should implement procedures to post the periodic audit reports? results to the DHS website. Agency Response: DHS agrees with this finding. Questioned Costs: None The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Show full finding ▾
Full finding narrative

Department of Human Services Finding 2021 ? 010: ALN 93.775, 93.777, and 93.778 ? Medicaid Cluster (including COVID-19) A Significant Deficiency and Noncompliance Exist at the Department of Human Services Related to the Managed Care Financial Audit Federal Grant Number(s) and Year(s): 2105PA5MAP (10/01/2020 ? 9/30/2021), 2105PA5ADM (10/01/2020 ? 9/30/2021), 2005PA5MAP (10/01/2019 ? 9/30/2020), 2005PA5ADM (10/01/2019 ? 9/30/2020) Type of Finding: Significant Deficiency, Noncompliance Compliance Requirement: Special Tests and Provisions related to the Managed Care Financial Audit Condition: The Pennsylvania Department of Human Services (DHS) administers the Medicaid Cluster for which expenditures reported on the fiscal year ended June 30, 2021 Schedule of Expenditures of Federal Awards totaled $23,828,691,242. DHS is required by the United States Department of Health and Human Services (HHS), Centers for Medicare and Medicaid Services (CMS), to obtain two types of audits for Medicaid Cluster managed care: annual audited financial reports and periodic audits. The periodic audits concern the accuracy, truthfulness, and completeness of the encounter and financial data submitted by, or on behalf of, each managed care organization (MCO), and the periodic audit results are required to be posted on DHS?s website. During the fiscal year ended June 30, 2021, periodic audits were required for MCOs used for behavioral health, long-term care, and physical health. Periodic audit reports for behavioral health were obtained, and the results were properly posted to DHS?s website. DHS?s Office of Long-Term Living (OLTL) obtained all three required periodic audit reports for the long-term care MCOs, but OLTL did not ensure the periodic audit reports? results were posted on DHS?s website as required by HHS. DHS?s Office of Medical Assistance Programs (OMAP) did not obtain one required periodic audit report for the physical health MCOs, so the periodic audit?s results were not available to be posted on DHS?s website as required by HHS. Criteria: 42 CFR Section 438.602, State responsibilities, states: (e) Periodic audits. The State must periodically, but no less frequently than once every 3 years, conduct, or contract for the conduct of, an independent audit of the accuracy, truthfulness, and completeness of the encounter and financial data submitted by, or on behalf of, each MCO, PIHP [Prepaid Inpatient Health Plan], or PAHP [Prepaid Ambulatory Health Plan]. (g) Transparency. The State must post on its website, as required in ?438.10(c)(3), the following documents and reports: (4) The results of any audits under paragraph (e) of this section. Management Directive 325.12, Standards for Internal Control for Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book), published in September 2014. The Green Book states in part: Management should identify, analyze, and respond to significant changes that could impact the internal control system. Finding 2021 ? 010: (continued) Cause: DHS?s OLTL personnel stated that the periodic audit reports? results were not posted to DHS?s website due to an oversight. DHS?s OMAP personnel represented the periodic audit was in process but the audit report was not complete, so there were no results available to post to DHS?s website. Effect: Since DHS did not ensure all periodic audit reports were completed, and the periodic audit report results were not all posted to DHS?s website, DHS was not in compliance with federal regulations. Recommendation: DHS?s OMAP should implement procedures to timely obtain the required periodic audit reports. OLTL and OMAP should implement procedures to post the periodic audit reports? results to the DHS website. Agency Response: DHS agrees with this finding. Questioned Costs: None The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Corrective Action Plan

Office of Long-Term Living (OLTL): OLTL posted the annual Community Health Choices MCO audits to the DHS website on January 31, 2022. In addition, OLTL will post these audits or a summary of them on the DHS website every year. Office of Medical Assistance Programs (OMAP): OMAP conducted most recent encounter and financial data audit between September and December 2021. The audit work is complete; however, OMAP is currently reviewing the draft audit report. For this reason, a final audit report was not published to the website in December 2021. OMAP intends to post the final audit report on DHS? website in the spring of 2022. In order to be in compliance with the encounter and financial data audit requirement in subsequent periods, OMAP will start the next required encounter data audit in time to publish the report by December 31, 2024 Anticipated Completion Date: OLTL- Completed; OMAP - 05/31/2022 Contact Person and Title: Michael Penney, Dir., Div. of Rate Setting and Auditing; Maranatha Perez, Dir., Bur. of Fiscal Mgmt. (BFM); Maki Traynor, Dir., Div. of HealthChoices Rates, BFM

About Special Tests and Provisions →
2021-011
Eligibility
QUESTIONED COSTS

During the fiscal year ended June 30, 2021, several presidential acts including the Coronavirus Aid, Relief, and Economic Securities Act of 2020, the Continued Assistance for Unemployed Workers Act of 2020, and the American Rescue Plan Act of 2021 were in effect or signed into law authorizing additional funding under both the Unemployment Insurance program and the Presidential Declared Disaster Assistance to Individuals and Households ? Other Needs program. This federal funding administered by the Pennsylvania Department of Labor and Industry (L&I) was significant and expanded program eligibility to include individuals affected by changes in employment status resulting from the COVID-19 pandemic. In accordance with the federal guidance in the Unemployment Insurance Program Letter (UIPL) 16-20, dated April 5, 2020, L&I management implemented a self-attestation strategy through January 2021 to expedite the disbursement of funds to the individuals with the greatest need. Federal guidance on self-attestation did not change until the issuance of UIPL 16-20, Change 4, dated January 8, 2021, when L&I management implemented additional changes in procedures. UIPL 16-20, Change 4, introduced the requirement to obtain documentation of employment/self-employment or the planned commencement of employment/self-employment. During the period under self-attestation, several states, including Pennsylvania, experienced significant fraudulent claims. As a result, the United States Department of Labor (USDOL) and L&I, as well as other federal and state authorities, have partnered to investigate the extent and methods used to perpetuate the fraud and to identify program improvements. L&I management implemented ID.me in October 2020 to strengthen verification procedures to authenticate claimants in the Pandemic Unemployment Assistance (PUA) system. Through January 2021, eligibility determinations made by L&I?s management followed the existing policies and procedures for this COVID-19 pandemic funding. However, in order to meet federal and state expectations of timely disbursement, the policies and procedures by design did not include adequate verification procedures for eligibility throughout the fiscal year under audit. The procedures and policies accommodations contributed to vulnerabilities within the unemployment programs. We also performed certain tests of information technology (IT) general controls as part of our audit of the Annual Comprehensive Financial Report, which included tests of applications that supported activities which were material to the Commonwealth?s financial statements. Basic Financial Statement Finding 2021 ? 002, which was reported for the Commonwealth for the fiscal year ended June 30, 2021, disclosed internal control deficiencies in applications supporting the unemployment major programs. Criteria: 2 CFR Section 200.303, Internal controls, states: Finding 2021 ? 011: (continued) The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in ?Standards for Internal Control in the Federal Government? issued by the Comptroller General of the United States or the ?Internal Control Integrated Framework?, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). 29 CFR 97.20(b), Standards for financial management systems, states in part: (3) Internal Control. Effective control and accountability must be maintained for all grant and subgrant cash, real and personal property, and other assets. Grantees and subgrantees must adequately safeguard all such property and must assure that it is used solely for authorized purposes. Management Directive 325.12, Standards for Internal Control for Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book), published in September 2014. The Green Book states in part: Management should consider the potential for fraud when identifying, analyzing, and responding to risks. Management should identify, analyze, and respond to significant changes that could impact the internal control system. The July 2021 OMB Compliance Supplement, Part 4, states: State Workforce Agencies (SWA) responsibilities include: (1) establishing specific, detailed policies and operating procedures which comply with the requirements of federal laws and regulations; (2) determining the state UI tax structure; (3) collecting state UI contributions from employers (commonly called ?unemployment taxes?); (4) determining claimant eligibility and disqualification provisions; (5) making payment of UI benefits to claimants; (6) managing the program?s revenue and benefit administrative functions; (7) administering the programs in accordance with established policies and procedures; and (8) enacting state UC law that conforms with federal UC law and that state law and operations substantially comply with federal law. Cause: Pennsylvania experienced unprecedented claims volume with increased funding and additional program requirements with a priority for efficient distribution from both the USDOL and Commonwealth officials. Commonwealth management made decisions to relax verification procedures to meet demand and program expectations. During the fiscal year several verification procedures including ID.me and data cross checks were implemented to assist in determining the extent of fraudulent activity, and to detect and prevent the filing of further fraudulent claims. Effect: The unemployment programs became more vulnerable to fraudulent claims due to the relaxing of verification procedures. Recommendation: We recommend that L&I management implement additional internal controls to efficiently verify program eligibility while providing timely payment to program beneficiaries. Finding 2021 ? 011: (continued) Agency Response: The Department acknowledges the issuance of this finding. Pennsylvania is tasked with following federal guidelines in the processing of all types of unemployment insurance. Questioned Costs: Undetermined and under investigation by federal and state authorities. The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Show full finding ▾
Full finding narrative

Department of Labor and Industry Finding 2021 ? 011: ALN 17.225 ? Unemployment Insurance (including COVID-19) ALN 97.050 ? COVID-19 ? Presidential Declared Disaster Assistance to Individuals and Households ? Other Needs A Significant Deficiency and Noncompliance Exist Related to Eligibility of Unemployment Recipients Federal Grant Number(s) and Year(s): C10164 (7/1/2020 ? 6/30/2021), C29020 (7/1/2020 ? 6/30/2021), C29120 (7/1/2020 ? 6/30/2021), C29420 (7/1/2020 ? 6/30/2021), C28420 (7/1/2020 ? 6/30/2021) Type of Finding: Significant Deficiency, Noncompliance Compliance Requirement: Eligibility Condition: During the fiscal year ended June 30, 2021, several presidential acts including the Coronavirus Aid, Relief, and Economic Securities Act of 2020, the Continued Assistance for Unemployed Workers Act of 2020, and the American Rescue Plan Act of 2021 were in effect or signed into law authorizing additional funding under both the Unemployment Insurance program and the Presidential Declared Disaster Assistance to Individuals and Households ? Other Needs program. This federal funding administered by the Pennsylvania Department of Labor and Industry (L&I) was significant and expanded program eligibility to include individuals affected by changes in employment status resulting from the COVID-19 pandemic. In accordance with the federal guidance in the Unemployment Insurance Program Letter (UIPL) 16-20, dated April 5, 2020, L&I management implemented a self-attestation strategy through January 2021 to expedite the disbursement of funds to the individuals with the greatest need. Federal guidance on self-attestation did not change until the issuance of UIPL 16-20, Change 4, dated January 8, 2021, when L&I management implemented additional changes in procedures. UIPL 16-20, Change 4, introduced the requirement to obtain documentation of employment/self-employment or the planned commencement of employment/self-employment. During the period under self-attestation, several states, including Pennsylvania, experienced significant fraudulent claims. As a result, the United States Department of Labor (USDOL) and L&I, as well as other federal and state authorities, have partnered to investigate the extent and methods used to perpetuate the fraud and to identify program improvements. L&I management implemented ID.me in October 2020 to strengthen verification procedures to authenticate claimants in the Pandemic Unemployment Assistance (PUA) system. Through January 2021, eligibility determinations made by L&I?s management followed the existing policies and procedures for this COVID-19 pandemic funding. However, in order to meet federal and state expectations of timely disbursement, the policies and procedures by design did not include adequate verification procedures for eligibility throughout the fiscal year under audit. The procedures and policies accommodations contributed to vulnerabilities within the unemployment programs. We also performed certain tests of information technology (IT) general controls as part of our audit of the Annual Comprehensive Financial Report, which included tests of applications that supported activities which were material to the Commonwealth?s financial statements. Basic Financial Statement Finding 2021 ? 002, which was reported for the Commonwealth for the fiscal year ended June 30, 2021, disclosed internal control deficiencies in applications supporting the unemployment major programs. Criteria: 2 CFR Section 200.303, Internal controls, states: Finding 2021 ? 011: (continued) The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in ?Standards for Internal Control in the Federal Government? issued by the Comptroller General of the United States or the ?Internal Control Integrated Framework?, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). 29 CFR 97.20(b), Standards for financial management systems, states in part: (3) Internal Control. Effective control and accountability must be maintained for all grant and subgrant cash, real and personal property, and other assets. Grantees and subgrantees must adequately safeguard all such property and must assure that it is used solely for authorized purposes. Management Directive 325.12, Standards for Internal Control for Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book), published in September 2014. The Green Book states in part: Management should consider the potential for fraud when identifying, analyzing, and responding to risks. Management should identify, analyze, and respond to significant changes that could impact the internal control system. The July 2021 OMB Compliance Supplement, Part 4, states: State Workforce Agencies (SWA) responsibilities include: (1) establishing specific, detailed policies and operating procedures which comply with the requirements of federal laws and regulations; (2) determining the state UI tax structure; (3) collecting state UI contributions from employers (commonly called ?unemployment taxes?); (4) determining claimant eligibility and disqualification provisions; (5) making payment of UI benefits to claimants; (6) managing the program?s revenue and benefit administrative functions; (7) administering the programs in accordance with established policies and procedures; and (8) enacting state UC law that conforms with federal UC law and that state law and operations substantially comply with federal law. Cause: Pennsylvania experienced unprecedented claims volume with increased funding and additional program requirements with a priority for efficient distribution from both the USDOL and Commonwealth officials. Commonwealth management made decisions to relax verification procedures to meet demand and program expectations. During the fiscal year several verification procedures including ID.me and data cross checks were implemented to assist in determining the extent of fraudulent activity, and to detect and prevent the filing of further fraudulent claims. Effect: The unemployment programs became more vulnerable to fraudulent claims due to the relaxing of verification procedures. Recommendation: We recommend that L&I management implement additional internal controls to efficiently verify program eligibility while providing timely payment to program beneficiaries. Finding 2021 ? 011: (continued) Agency Response: The Department acknowledges the issuance of this finding. Pennsylvania is tasked with following federal guidelines in the processing of all types of unemployment insurance. Questioned Costs: Undetermined and under investigation by federal and state authorities. The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Corrective Action Plan

Since the implementation of ID.me in the PUA system in October 2020, and in the Ben Mod system in July 2021, Pennsylvania continues to monitor and address system vulnerabilities as needed. The chart below documents Pennsylvania?s improvements to this fraud preventative measure in the Ben Mod system: - 7/16/2021 - ID.me goes live for initial claims. - 7/22/2021 - ID.me goes live for anyone filing weekly certifications on claims with an effective date after March 1, 2021. - 7/30/2021 - ID.me goes live for any time a claimant changes his/her Keystone ID (all claim types). - 10/11/2021 - ID.me goes live for any time a claimant changes his/her payment method (all claim types). A request has been made to Geographic Solutions (GSI), Pennsylvania?s system vendor, to establish a web service connection to the National Association of State Workforce Agency?s (NAWSA?s) Integrity Data Hub. The hub is comprised of a unique set of tools that, when actively utilized by all U.S. states and territories, forms a powerful mechanism for detecting and preventing UI fraud in one robust system. - Integrity Data Hub - Designed by the Integrity Center?s leading UI experts, the hub provides critical cross-matching functionality to combat the challenges and urgencies of UI fraud. - Suspicious Actor Repository - Participating states match current claims against this state-populated database of fraudulent and suspicious claims data. The repository leverages the investigative power of all states for the benefit of each state. Plans are also under way to add multi-factor authentication, a two-step process that will add an extra layer of protection against fraud and identity theft. Pennsylvania will be using NASWA's online training resources to train staff on: - Properly identifying a caller (identity theft). - Increasing listening skills to assist staff in identifying conflicting information between claimants' statements. - Knowing what questions to ask and when to clarify or verify information. - Educating claimants on their rights, responsibilities, and requirements for eligibility. - Identifying potential fictitious employer schemes or multi-claimant schemes. Pennsylvania is also working with a U.S. Department of Labor Tiger Team, specifically designed to analyze state systems and processes and, following recommendations by the Tiger Team, to implement any recommendations using federal grant funds. One of the focuses of the Tiger Team grant is to prevent, detect, and recover fraudulent UI overpayments. The Tiger Team is in the process of reviewing current processes and will be making recommendations to improve the fraud measures. Anticipated Completion Date: 12/31/2022 Contact Person and Title: Rebecca Keen, Acting Director, Office of UC Benefits Policy

About Eligibility →
2021-012
Special Tests & Provisions

During the fiscal year ended June 30, 2021, the Department of Labor and Industry (L&I) was required to administer reemployment services for the Unemployment Insurance (UI) program. The Commonwealth of Pennsylvania elected to operate the Reemployment Services and Eligibility Assessments (RESEA) program to satisfy the Worker Profiling and Reemployment Services (WPRS) federal mandate which was permitted by federal requirements. The RESEA program enables claimants who are most likely to exhaust their benefits to access services that assist them to return to work or provide assistance in areas such as job search or placement, job markets, and testing. Claimant participants work with a case administrator (administrator) throughout the program, and the administrators are supervised by a case manager. L&I?s program procedures are outlined in the Labor and Industry RESEA Manual which details claimant selection, eligibility, and the intervention process performed by the administrator to assist participating claimants. The Commonwealth of Pennsylvania?s RESEA program was suspended for the first half of the 2021 fiscal year due to the COVID-19 pandemic and became operational again in January 2021. L&I management indicated that case managers can use reporting tools to monitor that cases are proceeding and being completed as required. Additionally, administrators can use a comprehensive checklist from the RESEA Manual to ensure that all elements of the program are being satisfied for each case. In order to test the RESEA requirements for the period of January 2021 until the fiscal year end of June 30, 2021, a sample of 40 out of 4,087 claimant cases that completed the program during that time period was selected for testing. No noncompliance was identified. However, we were unable to test the operating effectiveness of certain internal control procedures at the case level, since supporting documentation for reporting tools and checklists was not maintained for 31 of the 40 cases tested. Criteria: 2 CFR Section 200.303, Internal controls, states: The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in ?Standards for Internal Control in the Federal Government? issued by the Comptroller General of the United States or the ?Internal Control Integrated Framework?, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Management Directive 325.12, Standards for Internal Control for Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book), published in September 2014. The Green Book states in part: Finding 2021 ? 012: (continued) Management should design control activities to achieve objectives and respond to risks. Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: According to L&I management, the reporting tools and checklist were optional and could be used by administrators and case managers at their discretion. As a result, these control measures were not being applied and/or documented consistently from case to case. Effect: The lack of adequate internal controls over compliance in the RESEA program could result in improper identification of claimants and insufficient services resulting in federal noncompliance. Although noncompliance was not identified by our audit procedures, fully operational controls would enable case administrators and managers to ensure compliance with program requirements and to timely prevent and detect instances of noncompliance. Recommendation: We recommend that L&I management require the use of the checklist and/or reporting tools to strengthen internal controls and to ensure verification of all elements of the RESEA program are occurring, accurate, and complete. Also, L&I management should ensure that proper documentation of the use of these tools is maintained. Agency Response: In the recent Single Audit conducted on the RESEA program for the fiscal year ended June 30, 2021, it was determined that the program was lacking internal controls. It was recommended through the audit that the staff checklist for the RESEA program provided in the RESEA Policy and Procedures Desk Guide be a mandatory requirement. The L&I management team agrees that this checklist become mandatory. The updated RESEA staff checklist will be completed for each RESEA participant. The supervisor will review each RESEA participant?s file to ensure all portions of the program have been completed, and both the staff member and the supervisor will sign off, acknowledging their review. The RESEA Checklist has been sent to all Pennsylvania CareerLink Program Supervisors and Career Advisors/Trainees to notify them of this new mandatory requirement and the requirement to retain the checklist in the participant?s file. In addition, the RESEA Policy and Procedures Desk Guide will be updated to reflect this mandatory new requirement for staff. Questioned Costs: None The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Show full finding ▾
Full finding narrative

Department of Labor and Industry Finding 2021 ? 012: ALN 17.225 ? Unemployment Insurance (including COVID-19) A Significant Deficiency Exists at the Department of Labor and Industry Related to the Reemployment Services and Eligibility Assessments Program Federal Grant Number(s) and Year(s): C10164 (7/1/2020 ? 6/30/2021), C29020 (7/1/2020 ? 6/30/2021), C29120 (7/1/2020 ? 6/30/2021), C29420 (7/1/2020 ? 6/30/2021) Type of Finding: Significant Deficiency Compliance Requirement: Special Tests and Provisions related to Unemployment Insurance (UI) Reemployment Programs: Worker Profiling and Reemployment Services (WPRS) and Reemployment Services and Eligibility Assessments (RESEA) Condition: During the fiscal year ended June 30, 2021, the Department of Labor and Industry (L&I) was required to administer reemployment services for the Unemployment Insurance (UI) program. The Commonwealth of Pennsylvania elected to operate the Reemployment Services and Eligibility Assessments (RESEA) program to satisfy the Worker Profiling and Reemployment Services (WPRS) federal mandate which was permitted by federal requirements. The RESEA program enables claimants who are most likely to exhaust their benefits to access services that assist them to return to work or provide assistance in areas such as job search or placement, job markets, and testing. Claimant participants work with a case administrator (administrator) throughout the program, and the administrators are supervised by a case manager. L&I?s program procedures are outlined in the Labor and Industry RESEA Manual which details claimant selection, eligibility, and the intervention process performed by the administrator to assist participating claimants. The Commonwealth of Pennsylvania?s RESEA program was suspended for the first half of the 2021 fiscal year due to the COVID-19 pandemic and became operational again in January 2021. L&I management indicated that case managers can use reporting tools to monitor that cases are proceeding and being completed as required. Additionally, administrators can use a comprehensive checklist from the RESEA Manual to ensure that all elements of the program are being satisfied for each case. In order to test the RESEA requirements for the period of January 2021 until the fiscal year end of June 30, 2021, a sample of 40 out of 4,087 claimant cases that completed the program during that time period was selected for testing. No noncompliance was identified. However, we were unable to test the operating effectiveness of certain internal control procedures at the case level, since supporting documentation for reporting tools and checklists was not maintained for 31 of the 40 cases tested. Criteria: 2 CFR Section 200.303, Internal controls, states: The non-Federal entity must: (a) Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in ?Standards for Internal Control in the Federal Government? issued by the Comptroller General of the United States or the ?Internal Control Integrated Framework?, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Management Directive 325.12, Standards for Internal Control for Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book), published in September 2014. The Green Book states in part: Finding 2021 ? 012: (continued) Management should design control activities to achieve objectives and respond to risks. Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: According to L&I management, the reporting tools and checklist were optional and could be used by administrators and case managers at their discretion. As a result, these control measures were not being applied and/or documented consistently from case to case. Effect: The lack of adequate internal controls over compliance in the RESEA program could result in improper identification of claimants and insufficient services resulting in federal noncompliance. Although noncompliance was not identified by our audit procedures, fully operational controls would enable case administrators and managers to ensure compliance with program requirements and to timely prevent and detect instances of noncompliance. Recommendation: We recommend that L&I management require the use of the checklist and/or reporting tools to strengthen internal controls and to ensure verification of all elements of the RESEA program are occurring, accurate, and complete. Also, L&I management should ensure that proper documentation of the use of these tools is maintained. Agency Response: In the recent Single Audit conducted on the RESEA program for the fiscal year ended June 30, 2021, it was determined that the program was lacking internal controls. It was recommended through the audit that the staff checklist for the RESEA program provided in the RESEA Policy and Procedures Desk Guide be a mandatory requirement. The L&I management team agrees that this checklist become mandatory. The updated RESEA staff checklist will be completed for each RESEA participant. The supervisor will review each RESEA participant?s file to ensure all portions of the program have been completed, and both the staff member and the supervisor will sign off, acknowledging their review. The RESEA Checklist has been sent to all Pennsylvania CareerLink Program Supervisors and Career Advisors/Trainees to notify them of this new mandatory requirement and the requirement to retain the checklist in the participant?s file. In addition, the RESEA Policy and Procedures Desk Guide will be updated to reflect this mandatory new requirement for staff. Questioned Costs: None The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Corrective Action Plan

It was recommended through the audit that an existing staff checklist from the RESEA Policy and Procedures Desk Guide be used as a mandatory control of the program. Based on that recommendation, the agency took the checklist, updated it and made it a fillable PDF. There are signature requirements for the staff case manager to sign off on, certifying that all steps have been completed. The checklist is then provided to the supervisor who is then required to review the participant?s activity and sign off, acknowledging that all steps were completed. On February 11, 2022 an email along with the fillable checklist was sent to all PA CareerLink? staff working in the RESEA program notifying them of the new requirement to complete and sign the checklist, effective February 14, 2022. Anticipated Completion Date: Completed Contact Person and Title: Dorraine Rauch, Workforce Dev. Super.; Crystal Houser, Division Chief, Quality Assurance

About Special Tests and Provisions →
2021-013
Other
REPEAT

As part of testing internal controls over major programs, we performed certain tests of information technology (IT) general controls, including procedures to determine the status of prior year Single Audit Finding 2020 ? 015. Our procedures disclosed the following control deficiencies in an application supported by the Public Safety Delivery Center that impacted the Crime Victim Assistance program: 1. As noted in the prior year, we found a lack of segregation of duties between application development and promotion of code to production. 2. Five administrator accounts on servers managed by the Enterprise Data Center (EDC) were not removed timely after the users separated employment. These five accounts had full administrative access rights to the major program?s application and database servers. A detailed schedule of issues has been provided to the Office of Administration, Office for Information Technology (OA-OIT), for corrective action. Criteria: Management Directive 325.12, Standards for Internal Control for Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book), published in September 2014. ? Green Book Principle 11 ? Design Activities for the Information System, states in part: o 11.04 Management designs the entity?s information system and the use of information technology? Additionally, information technology may enhance internal control over security and confidentiality of information by appropriately restricting access. o 11.12 Management designs control activities over access to protect an entity from inappropriate access and unauthorized use of the system. These control activities support appropriate segregation of duties. By preventing unauthorized use of and changes to the system, data and program integrity are protected from malicious intent (e.g., someone breaking into the technology to commit fraud, vandalism, or terrorism) or error. o 11.14 Management designs control activities to limit user access to information technology through authorization control activities such as providing a unique user identification or token to authorized users. These control activities may restrict authorized users to the applications or functions commensurate with their assigned responsibilities, supporting an appropriate segregation of duties. Management designs other control activities to promptly update access rights when employees change job functions or leave the entity. Finding 2021 ? 013: (continued) A well-designed system of internal controls dictates that effective general computer controls, which include adequate segregation of duties, access controls to programs and data, appropriate monitoring, and controls to update access rights, be established and functioning to ensure that overall agency operations are conducted in accordance with management?s intent. Cause: As noted in the prior year finding, developers continued to have administrative access to the change management software tool. Although the tool was configured to log activity and send an automated email to a third party when a developer approved code to production, no documentation was maintained as evidence that the logs or the email notifications were monitored. As for the separated users whose accounts were not removed, the control to remove the accounts at the time of separation failed, and the bi-annual access reviews performed by EDC administrators did not identify these inappropriate accounts. When EDC moved to a quarterly review, the separated users? accounts were identified and removed prior to the end of the audit. Effect: The deficiencies noted above in IT general controls could result in unauthorized changes to the software and noncompliance with federal laws and regulations. Segregation of duties weaknesses and untimely removal of access when no longer needed contribute to the risk that system activity can occur that is not in accordance with management?s intent. Finally, without properly functioning controls over segregation of duties and separated users, the auditors are precluded from reliance on computer controls in the Crime Victim Assistance program. Separately, not deleting accounts with administrative access after the user separates employment increases the risk that accounts could be misused, intentionally or unintentionally either by authorized users, or by unauthorized external entities that have compromised the account. Recommendation: We recommend that OA-OIT continue its efforts to resolve the general computer control deficiencies noted above. Specific consideration should be given to: ? Segregating the development of programs from promotion to the production environment; ? When segregation of duties is not possible, performing documented monitoring of the activities of developers who have the ability to implement code to production; ? Removing server administrator accounts timely upon user separation; and ? Conducting effective periodic access reviews of privileged users. Agency Response: Office of Administration, Office for Information Technology (OA-OIT), agrees with this finding. Questioned Costs: None The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Show full finding ▾
Full finding narrative

Office of Administration ? Office for Information Technology Finding 2021 ? 013: ALN 16.575 ? Crime Victim Assistance Information Technology General Controls Need Improvement (A Similar Condition Was Noted in Prior Year Finding 2020-015) Federal Grant Number(s) and Year(s): 2020-V2-GX-0063 (10/01/2019 ? 9/30/2023), 2019-V2-GX-0026 (10/01/2018 ? 9/30/2022), 2018-V2-GX-0068 (10/01/2017 ? 9/30/2021), 2017-VA-GX-0069 (10/01/2016 ? 9/30/2020) Type of Finding: Significant Deficiency Compliance Requirement: Other Condition: As part of testing internal controls over major programs, we performed certain tests of information technology (IT) general controls, including procedures to determine the status of prior year Single Audit Finding 2020 ? 015. Our procedures disclosed the following control deficiencies in an application supported by the Public Safety Delivery Center that impacted the Crime Victim Assistance program: 1. As noted in the prior year, we found a lack of segregation of duties between application development and promotion of code to production. 2. Five administrator accounts on servers managed by the Enterprise Data Center (EDC) were not removed timely after the users separated employment. These five accounts had full administrative access rights to the major program?s application and database servers. A detailed schedule of issues has been provided to the Office of Administration, Office for Information Technology (OA-OIT), for corrective action. Criteria: Management Directive 325.12, Standards for Internal Control for Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book), published in September 2014. ? Green Book Principle 11 ? Design Activities for the Information System, states in part: o 11.04 Management designs the entity?s information system and the use of information technology? Additionally, information technology may enhance internal control over security and confidentiality of information by appropriately restricting access. o 11.12 Management designs control activities over access to protect an entity from inappropriate access and unauthorized use of the system. These control activities support appropriate segregation of duties. By preventing unauthorized use of and changes to the system, data and program integrity are protected from malicious intent (e.g., someone breaking into the technology to commit fraud, vandalism, or terrorism) or error. o 11.14 Management designs control activities to limit user access to information technology through authorization control activities such as providing a unique user identification or token to authorized users. These control activities may restrict authorized users to the applications or functions commensurate with their assigned responsibilities, supporting an appropriate segregation of duties. Management designs other control activities to promptly update access rights when employees change job functions or leave the entity. Finding 2021 ? 013: (continued) A well-designed system of internal controls dictates that effective general computer controls, which include adequate segregation of duties, access controls to programs and data, appropriate monitoring, and controls to update access rights, be established and functioning to ensure that overall agency operations are conducted in accordance with management?s intent. Cause: As noted in the prior year finding, developers continued to have administrative access to the change management software tool. Although the tool was configured to log activity and send an automated email to a third party when a developer approved code to production, no documentation was maintained as evidence that the logs or the email notifications were monitored. As for the separated users whose accounts were not removed, the control to remove the accounts at the time of separation failed, and the bi-annual access reviews performed by EDC administrators did not identify these inappropriate accounts. When EDC moved to a quarterly review, the separated users? accounts were identified and removed prior to the end of the audit. Effect: The deficiencies noted above in IT general controls could result in unauthorized changes to the software and noncompliance with federal laws and regulations. Segregation of duties weaknesses and untimely removal of access when no longer needed contribute to the risk that system activity can occur that is not in accordance with management?s intent. Finally, without properly functioning controls over segregation of duties and separated users, the auditors are precluded from reliance on computer controls in the Crime Victim Assistance program. Separately, not deleting accounts with administrative access after the user separates employment increases the risk that accounts could be misused, intentionally or unintentionally either by authorized users, or by unauthorized external entities that have compromised the account. Recommendation: We recommend that OA-OIT continue its efforts to resolve the general computer control deficiencies noted above. Specific consideration should be given to: ? Segregating the development of programs from promotion to the production environment; ? When segregation of duties is not possible, performing documented monitoring of the activities of developers who have the ability to implement code to production; ? Removing server administrator accounts timely upon user separation; and ? Conducting effective periodic access reviews of privileged users. Agency Response: Office of Administration, Office for Information Technology (OA-OIT), agrees with this finding. Questioned Costs: None The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Corrective Action Plan

Public Safety Delivery Center will monitor and document the review of email notifications and code production logs to verify that developers are not pushing unauthorized code to production. EDC now performs quarterly review of privileged user accounts to ensure former employees do not continue to have server access. Anticipated Completion Date: Completed Contact Person and Title: Derin Myers, PCCD, Director, OFMA

Prior Finding References

2020-015

About Other →
2021-014
Subrecipient Monitoring
REPEATQUESTIONED COSTS

The Uniform Guidance in 2 CFR Section 200 applies to the major programs listed above for the fiscal year ended June 30, 2021. Our testing disclosed that the state agencies did not identify the federal award information and applicable requirements in subrecipient award documents. Additionally, the state agencies did not evaluate each subrecipient?s risk of noncompliance for the purpose of determining the appropriate subrecipient monitoring related to the subaward. This represents an internal control weakness which causes subrecipients to be improperly informed of federal award information and not adequately monitored by the state agencies. Also, it could cause the omission or improper identification of program expenditures on subrecipients? Schedules of Expenditures of Federal Awards (SEFAs). The following chart shows which federal award information required by 2 CFR Section 200 was omitted (as indicated by ?No?) from the subrecipient award documents at the time of the subaward and which major programs did not have a state agency evaluation of each subrecipient?s risk of noncompliance. SEE SCHEDULE OF FINDINGS AND QUESTIONED COSTS FOR CHART/TABLE (The cells with a hyphen in the table indicate that the federal award information was included in the subrecipient award documents or was not applicable for the respective major program.) (1) Although an evaluation of subrecipient risk was conducted, the only risk factor used in the evaluation was the error rate detected for the county subrecipients. The evaluation is deemed inadequate since there was no written evidence that the risk assessment considered other risk factors, such as the risk factors identified in 2 CFR Section 200.332. Criteria: 2 CFR Section 200.332, Requirements for pass-through entities, states in part: All pass-through entities must: (a) Ensure that every subaward is clearly identified to the subrecipient as a subaward and includes the following information at the time of the subaward and if any of these data elements change, include the changes in subsequent subaward modification. When some of this information is not available, the pass-through entity must provide the best information available to describe the Federal award and subaward. Required information includes: (1) Federal Award Identification. (iii) Federal Award Identification Number (FAIN); (iv) Federal Award Date (see the definition of Federal Award date in section 200.1) of award to the recipient by the Federal agency; (v) Subaward Period of Performance Start and End Date; (xi) Name of Federal awarding agency, pass-through entity, and contact information for awarding official of the pass-through entity; (xii) Assistance Listings Number and Title; the pass-through entity must identify the dollar amount made available under each Federal award and the Assistance Listings Number at time of disbursement; (6) Appropriate terms and conditions concerning closeout of the subaward. (b) Evaluate each subrecipient?s risk of noncompliance with Federal statutes, regulations, and the terms and conditions of the subaward for purposes of determining the appropriate subrecipient monitoring described in paragraphs (d) and (e) of this section, which may include consideration of such factors as: (1) The subrecipient?s prior experience with the same or similar subawards; (2) The results of previous audits including whether or not the subrecipient receives a Single Audit in accordance with Subpart F [Audit Requirements] of this part, and the extent to which the same or similar subaward has been audited as a major program; Finding 2021 ? 014: (continued) (3) Whether the subrecipient has new personnel or new or substantially changed systems; and (4) The extent and results of Federal awarding agency monitoring (e.g., if the subrecipient also receives Federal awards directly from a Federal awarding agency). Management Directive 325.12, Standards for Internal Control for Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book), published in September 2014. The Green Book states in part: Management should identify, analyze, and respond to risks related to achieving the defined objectives. Management should identify, analyze, and respond to significant changes that could impact the internal control system. Cause: In general, the state agencies? process for subrecipient award monitoring did not identify the omission of required elements from the grant awards. In addition, the risk assessments performed by the agencies were not properly documented. Effect: Excluding the federal grant award information at the time of the subaward may cause subrecipients and their auditors to be uninformed about specific program and other regulations that apply to the funds they receive. There is also the potential for subrecipients to have incomplete SEFAs in their Single Audit reports submitted to the Commonwealth, and federal funds may not be properly audited at the subrecipient level in accordance with the Single Audit Act and Uniform Guidance. Not evaluating each subrecipient?s risk of noncompliance for purposes of determining the appropriate subrecipient monitoring related to the subaward may result in subrecipients using the subaward for unauthorized purposes or in violation of the terms and conditions of the subaward, and state agency monitoring would not detect this noncompliance and ensure it is corrected in a timely manner. Recommendation: State agencies should develop policies and reporting mechanisms to ensure all required federal award information is disseminated to all subrecipients at the time of the subaward to ensure subrecipient compliance with the Uniform Guidance in 2 CFR Section 200 and other applicable federal regulations. In addition, state agencies should correspond with applicable subrecipients to ensure they are aware of the correct federal award information and review applicable subaward documents prior to issuance to ensure federal information is complete and accurate. State agencies should also implement procedures to adequately document their evaluation of each subrecipient?s risk of noncompliance as cited in 2 CFR Section 200.332 for purposes of determining the appropriate subrecipient monitoring related to the subaward. PennDOT Response: PennDOT agrees with the finding. DHS Response: DHS agrees with the finding. Questioned Costs: The amount of questioned costs cannot be determined. The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Show full finding ▾
Full finding narrative

Various Agencies Finding 2021 ? 014: ALN 20.205 and 20.219 ? Highway Planning and Construction Cluster (including COVID-19) ALN 93.558 ? Temporary Assistance for Needy Families ALN 93.658 ? Foster Care ? Title IV-E (including COVID-19) ALN 93.659 ? Adoption Assistance (including COVID-19) State Agencies Did Not Identify the Federal Award Information and Applicable Requirements at the Time of the Subaward and Did Not Evaluate Each Subrecipient?s Risk of Noncompliance as Required by the Uniform Grant Guidance (A Similar Condition Was Noted in Prior Year Finding 2020-020) Federal Grant Number(s) and Year(s): N78000 (7/01/2020 ? 6/30/2021), 2101PATANF (10/01/2020 ? 9/30/2021), 2001PATANF (10/01/2019 ? 9/30/2020), 1901PATANF (10/01/2018 ? 9/30/2019), 1801PATANF (10/01/2017 ? 9/30/2018), 2101PAFOST (10/01/2020 ? 9/30/2021), 2001PAFOST (10/01/2019 ? 9/30/2020), 2101PAADPT (10/01/2020 ? 9/30/2021), 2001PAADPT (10/01/2019 ? 9/30/2020) Type of Finding: Significant Deficiency, Noncompliance Compliance Requirement: Subrecipient Monitoring Condition: The Uniform Guidance in 2 CFR Section 200 applies to the major programs listed above for the fiscal year ended June 30, 2021. Our testing disclosed that the state agencies did not identify the federal award information and applicable requirements in subrecipient award documents. Additionally, the state agencies did not evaluate each subrecipient?s risk of noncompliance for the purpose of determining the appropriate subrecipient monitoring related to the subaward. This represents an internal control weakness which causes subrecipients to be improperly informed of federal award information and not adequately monitored by the state agencies. Also, it could cause the omission or improper identification of program expenditures on subrecipients? Schedules of Expenditures of Federal Awards (SEFAs). The following chart shows which federal award information required by 2 CFR Section 200 was omitted (as indicated by ?No?) from the subrecipient award documents at the time of the subaward and which major programs did not have a state agency evaluation of each subrecipient?s risk of noncompliance. SEE SCHEDULE OF FINDINGS AND QUESTIONED COSTS FOR CHART/TABLE (The cells with a hyphen in the table indicate that the federal award information was included in the subrecipient award documents or was not applicable for the respective major program.) (1) Although an evaluation of subrecipient risk was conducted, the only risk factor used in the evaluation was the error rate detected for the county subrecipients. The evaluation is deemed inadequate since there was no written evidence that the risk assessment considered other risk factors, such as the risk factors identified in 2 CFR Section 200.332. Criteria: 2 CFR Section 200.332, Requirements for pass-through entities, states in part: All pass-through entities must: (a) Ensure that every subaward is clearly identified to the subrecipient as a subaward and includes the following information at the time of the subaward and if any of these data elements change, include the changes in subsequent subaward modification. When some of this information is not available, the pass-through entity must provide the best information available to describe the Federal award and subaward. Required information includes: (1) Federal Award Identification. (iii) Federal Award Identification Number (FAIN); (iv) Federal Award Date (see the definition of Federal Award date in section 200.1) of award to the recipient by the Federal agency; (v) Subaward Period of Performance Start and End Date; (xi) Name of Federal awarding agency, pass-through entity, and contact information for awarding official of the pass-through entity; (xii) Assistance Listings Number and Title; the pass-through entity must identify the dollar amount made available under each Federal award and the Assistance Listings Number at time of disbursement; (6) Appropriate terms and conditions concerning closeout of the subaward. (b) Evaluate each subrecipient?s risk of noncompliance with Federal statutes, regulations, and the terms and conditions of the subaward for purposes of determining the appropriate subrecipient monitoring described in paragraphs (d) and (e) of this section, which may include consideration of such factors as: (1) The subrecipient?s prior experience with the same or similar subawards; (2) The results of previous audits including whether or not the subrecipient receives a Single Audit in accordance with Subpart F [Audit Requirements] of this part, and the extent to which the same or similar subaward has been audited as a major program; Finding 2021 ? 014: (continued) (3) Whether the subrecipient has new personnel or new or substantially changed systems; and (4) The extent and results of Federal awarding agency monitoring (e.g., if the subrecipient also receives Federal awards directly from a Federal awarding agency). Management Directive 325.12, Standards for Internal Control for Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book), published in September 2014. The Green Book states in part: Management should identify, analyze, and respond to risks related to achieving the defined objectives. Management should identify, analyze, and respond to significant changes that could impact the internal control system. Cause: In general, the state agencies? process for subrecipient award monitoring did not identify the omission of required elements from the grant awards. In addition, the risk assessments performed by the agencies were not properly documented. Effect: Excluding the federal grant award information at the time of the subaward may cause subrecipients and their auditors to be uninformed about specific program and other regulations that apply to the funds they receive. There is also the potential for subrecipients to have incomplete SEFAs in their Single Audit reports submitted to the Commonwealth, and federal funds may not be properly audited at the subrecipient level in accordance with the Single Audit Act and Uniform Guidance. Not evaluating each subrecipient?s risk of noncompliance for purposes of determining the appropriate subrecipient monitoring related to the subaward may result in subrecipients using the subaward for unauthorized purposes or in violation of the terms and conditions of the subaward, and state agency monitoring would not detect this noncompliance and ensure it is corrected in a timely manner. Recommendation: State agencies should develop policies and reporting mechanisms to ensure all required federal award information is disseminated to all subrecipients at the time of the subaward to ensure subrecipient compliance with the Uniform Guidance in 2 CFR Section 200 and other applicable federal regulations. In addition, state agencies should correspond with applicable subrecipients to ensure they are aware of the correct federal award information and review applicable subaward documents prior to issuance to ensure federal information is complete and accurate. State agencies should also implement procedures to adequately document their evaluation of each subrecipient?s risk of noncompliance as cited in 2 CFR Section 200.332 for purposes of determining the appropriate subrecipient monitoring related to the subaward. PennDOT Response: PennDOT agrees with the finding. DHS Response: DHS agrees with the finding. Questioned Costs: The amount of questioned costs cannot be determined. The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Corrective Action Plan

DHS: OCYF is sending out a Restrictions and Requirements document with each FY 21-22 Tentative and Final Allocation letter. The document lists all OCYF?s grants, the federal agency granting the fund and where to find the rules and regulations guiding the usage of the funds. FY 21-22 Tentative Allocation Letters are being sent in March 2022. The Final Allocation Letters will be sent out once the budget passes. FY 20-21 Tentative Allocation Letters were sent on April 1, 2021, with Assistance Listing Numbers (ALN) and funding amounts. Final Allocation Letters were sent July 31, 2021, with an attachment including all Federal Award information: ALN and Name, Amount, Federal Award Identification Number (FAIN); Federal Award Date; Subaward Period of Performance Start and End Date; Name of Federal awarding agency, pass-through entity, and contact information for awarding official. OCYF has a risk assessment process in place for Title IV-E and TANF awards. During the Quality Assurance reviews, which occur twice a year at a minimum, OCYF reviews a sample of Title IV-E eligible foster care cases, Title IV-E ineligible foster care cases, Title IV-E eligible adoption assistance cases, and TANF eligible cases. Depending on the number of eligibility and claiming errors identified during the review, OCYF schedules more frequent visits as the risk of repeated and continued errors in these CCYAs is higher. Inaccurate eligibility determinations lead to inaccurate federal claiming, so basing the review schedule on a CCYA?s eligibility review outcome allows OCYF to target those CCYAs where inaccurate claiming is a higher risk. However, to further address this finding, the risk assessment now includes documentation of other risk factors, such as: submission of a single audit report, prior experience, and new personnel. The corrective actions are considered complete. Anticipated Completion Date: Completed Contact Person and Title: TinaMarie Petrovitz, Director of County Support PennDOT: PennDOT will continue to include the ALN in all RAS agreements. PennDOT is developing further guidance to ensure that Federal & State Assistance Program Names and Numbers are identified correctly and populated in agreements. PennDOT will continue to reinforce the need for a notice provision in RAS agreements. Any RAS agreement that does not contain a notice provision within its body will have an attachment uploaded with party contacts to satisfy the notice requirement and further guidance to remind PennDOT personnel of this approach is forthcoming. Anticipated Completion Date: 06/30/2022 Contact Person and Title: Ryan Shiffler, Project Dev. Engineerl Jeffrey Spotts, Acting Deputy Chief Counsel; Nick Balzer, Asst. Counsel; Dougie Chon, Asst. Counsel

Prior Finding References

2020-020

About Subrecipient Monitoring →
2021-015
Subrecipient Monitoring
MATERIAL WEAKNESSREPEATQUESTIONED COSTS

Under the Commonwealth of Pennsylvania's (Commonwealth) implementation of the Single Audit Act, review and resolution of subrecipient Single Audit reports is split into two stages. The Office of the Budget?s Bureau of Accounting and Financial Management (OB-BAFM) ensures the reports meet technical standards through a centralized desk review process. The various funding agencies in the Commonwealth are responsible for making a management decision on each finding within six months of the Federal Audit Clearinghouse?s (FAC) Management Decision Letter (MDL) start date for audits subject to Uniform Guidance and to ensure appropriate corrective action is taken by the subrecipient (except for Uniform Guidance audits under U.S. Department of Labor programs which are permitted 12 months for management decisions in accordance with 2 CFR Section 2900.21). Each Commonwealth agency is also responsible for reviewing financial information in each audit report to determine whether the audit included all pass-through funding provided by the agency in order to ensure pass-through funds were subject to audit. Most agencies meet this requirement by performing Schedule of Expenditures of Federal Awards (SEFA) reconciliations. The agency is also required to adjust Commonwealth records, if necessary. Finding 2021 ? 015: (continued) Our fiscal year ended June 30, 2021 audit of the Commonwealth?s process for review and resolution of subrecipient Single Audits included an evaluation of the Commonwealth?s fiscal year ended June 30, 2020 subrecipient audit universe for audits due for submission to the FAC during the fiscal year ended June 30, 2021. We also evaluated the Commonwealth?s review of 33 subrecipient audit reports with findings in major programs/clusters which were identified on the Commonwealth agencies? tracking lists during the fiscal year ended June 30, 2021, and required management decisions by Commonwealth agencies. Our testing disclosed the following audit exceptions regarding the Commonwealth agencies? review of subrecipient audit reports: ? Department of Environmental Protection (DEP): The time period for making a management decision on findings was approximately 8.6 months after the FAC MDL start date for one out of two audit reports with findings. ? Department of Human Services (DHS): The time period for making a management decision on findings ranged from approximately 7.2 months to 20.3 months after the FAC MDL start date for 22 out of 23 subrecipient audit reports with findings. There was also a delay in DHS?s procedures to ensure the subrecipient SEFAs were accurate so that major programs were properly determined and subject to audit. In addition, our review disclosed that three subrecipient audit reports with findings for which DHS was the lead agency were submitted late to the FAC, with FAC acceptance dates ranging from approximately 3.6 months to 10.8 months after the Single Audit due date. ? Pennsylvania Commission on Crime and Delinquency (PCCD): The time period for making a management decision on findings was approximately 10.3 months after the FAC MDL start date for one out of two subrecipient audit reports with findings. ? Pennsylvania Emergency Management Agency (PEMA): The time period for making a management decision on findings was approximately 12 months after the FAC MDL start date for one subrecipient audit report with findings. In addition, our review disclosed the one subrecipient audit report with findings for which PEMA was the lead agency was submitted approximately 16 months late to the FAC and was excluded from PEMA?s tracking list. As a follow-up to the prior year finding, we noted that the Commonwealth subgranted federal funds totaling $285,634,900 to the City of Philadelphia during the fiscal year ended June 30, 2020, for which a Single Audit was not submitted to the FAC as of our January 2022 testing date. This was over 3.5 months after the September 30, 2021 due date, which had been extended due to the COVID-19 pandemic in accordance with the Office of Management and Budget?s Memorandum M-21-20, Appendix 3. Our testing disclosed that DHS?s subgrants to the City of Philadelphia were material for four of the 14 major programs/clusters with material subgranted funds. Our follow-up on the prior year finding also disclosed that the Commonwealth subgranted federal funds totaling $30,158,167 to Bucks County during the fiscal year ended December 31, 2019. The audit was submitted to the FAC on February 24, 2021, which was nearly two months after the December 31, 2020 due date, which had been extended in accordance with the Office of Management and Budget?s Memorandum M-20-26, Appendix A. DHS was the lead agency for the City of Philadelphia and Bucks County audits. Criteria: 2 CFR ?200.332, Requirements for pass-through entities, states in part: All pass-through entities must: (d) Monitor the activities of the subrecipient as necessary to ensure that the subaward is used for authorized purposes, in compliance with Federal statutes, regulations, and the terms and conditions of the subaward, and that subaward performance goals are achieved. Pass-through entity monitoring of the subrecipient must include: Finding 2021 ? 015: (continued) (2) Following-up and ensuring that the subrecipient takes timely and appropriate action on all deficiencies pertaining to the Federal award provided to the subrecipient from the pass-through entity detected through audits, on-site reviews, and written confirmation from the subrecipient, highlighting the status of actions planned or taken to address Single Audit findings related to the particular subaward. (3) Issuing a management decision for applicable audit findings pertaining only to the Federal award provided to the subrecipient from the pass-through entity as required by ?200.521 [Management decision]. (f) Verify that every subrecipient is audited as required by Subpart F [Audit Requirements] of this part when it is expected that the subrecipient?s Federal awards expended during the respective fiscal year equaled or exceeded the threshold set forth in ?200.501 [Audit requirements]. (g) Consider whether the results of the subrecipient?s audit, on-site review, or other monitoring indicate conditions that necessitate adjustments to the pass-through entity?s own records. (h) Consider taking enforcement action against noncompliant subrecipients as described in ?200.339 [Remedies for noncompliance] of this part and in program regulations. In order to carry out these responsibilities properly, good internal control dictates that state pass-through agencies ensure subrecipient Single Audit SEFAs are representative of state payment records each year, and that the related federal programs have been properly subjected to Single Audit procedures. 2 CFR ?200.512, Report submission, states in part: (a) General. (1) The audit must be completed and the data collection form described in paragraph (b) of this section and reporting package described in paragraph (c) of this section must be submitted within the earlier of 30 calendar days after receipt of the auditor?s report(s), or nine months after the end of the audit period. If the due date falls on a Saturday, Sunday, or Federal holiday, the reporting package is due the next business day. 2 CFR ?200.521, Management decision, states in part: (a) General. The management decision must clearly state whether or not the finding is sustained, the reasons for the decision, and the expected auditee action to repay disallowed costs, make financial adjustments, or take other action. (d) Time requirements. The Federal awarding agency or pass-through entity responsible for issuing a management decision must do so within six months of acceptance of the audit report by the FAC. The auditee must initiate and proceed with corrective action as rapidly as possible and corrective action should begin no later than upon receipt of the audit report. 2 CFR ?200.505, Sanctions, states: In cases of continued inability or unwillingness to have an audit conducted in accordance with this part, Federal agencies and pass-through entities must take appropriate action as provided in ?200.339 [Remedies for noncompliance]. 2 CFR ?200.339, Remedies for noncompliance, states in part: If a non-Federal entity fails to comply with the U.S. Constitution, Federal statutes, regulations or the terms and conditions of a Federal award, the Federal awarding agency or pass-through entity may impose additional conditions, as described in ?200.208 [Specific conditions]. If the Federal awarding agency or pass-through entity determines that noncompliance cannot be remedied by imposing additional conditions, the federal awarding agency or pass-through entity may take one or more of the following actions, as appropriate in the circumstances. (a) Temporarily withhold cash payments pending correction of the deficiency by the non-Federal entity or more severe enforcement action by the Federal awarding agency or pass-through entity. Finding 2021 ? 015: (continued) (b) Disallow (that is, deny both use of funds and any applicable matching credit for) all or part of the cost of the activity or action not in compliance. (c) Wholly or partly suspend or terminate the Federal award. (d) Initiate suspension or debarment proceedings as authorized under 2 CFR Part 180 and Federal awarding agency regulations (or in the case of a pass-through entity, recommend such a proceeding be initiated by a Federal awarding agency). (e) Withhold further Federal awards for the project or program. (f) Take other remedies that may be legally available. To ensure Commonwealth enforcement of federal regulations for subrecipient noncompliance with audit requirements, Commonwealth Management Directive 325.8, Remedies for Recipient Noncompliance with Audit Requirements, Section 5 related to policy, states in part: (a) Agencies must develop and implement remedial action that reflects the unique requirements of each program? (b) Overall periods for the implementation of remedial action should not exceed six months from the date the first remedial action is initiated. At the end of the six-month period, the recipient should take the appropriate corrective action or the final stage of remedial action should be imposed on the recipient. Examples of remedial action include, but are not limited to: (1) Meeting or calling the recipient to explain the importance and benefits of the audit and audit resolution processes, emphasizing the value of the audit as an administrative tool and the Commonwealth?s reliance on an acceptable audit and prompt resolution as evidence of the recipient?s ability to properly administer the program. (2) Encouraging the entity to establish an audit committee or designate an individual as the single point of contact to: (a) Communicate regarding the audit. (b) Arrange for and oversee the audit. (c) Direct and monitor audit resolution. (3) Providing technical assistance to the recipient in devising and implementing an appropriate plan to remedy the noncompliance. (4) Withholding a portion of assistance payments until the noncompliance is resolved. (5) Withholding or disallowing overhead costs until the noncompliance is resolved. (6) Suspending the assistance agreement until the noncompliance is resolved. (7) Terminating the assistance agreement with the recipient and, if necessary, seeking alternative entities to administer the program. Management Directive 325.9, Processing Audits of Federal Pass-Through Funds, Section 7 related to procedures, states in part: c. Agencies. (1) Evaluate single audit report submissions received from BOA [now OB-BAFM] to determine program purpose acceptability by verifying, at a minimum, that all agency-funded programs are properly included on the applicable financial schedules; that findings affecting the agency contain sufficient information to facilitate a management decision; and that the subrecipient has submitted an adequate corrective action plan. (6) Impose or coordinate the imposition of remedial action in accordance with 2 CFR Part 200.338 [now 200.339] and Management Directive 325.8, Remedies for Recipient Noncompliance with Audit Requirements, when subrecipients fail to comply with the provisions of Subpart F. Finding 2021 ? 015: (continued) Management Directive 325.12, Standards for Internal Control for Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s, Standards for Internal Control in the Federal Government (Green Book), published in September 2014. The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: One reason provided by Commonwealth management for untimely audit resolution in the various agencies, including making management decisions, approving corrective action, and performing procedures to ensure the accuracy of subrecipient SEFAs, and for the exclusion of an audit from a tracking list, was either a change in staff or a lack of staff to follow up and process subrecipient audit reports more timely. DEP personnel stated the late management decision resulted from late notification of FAC audit receipt by OB-BAFM. PCCD personnel indicated the management decision was not completed due to an oversight. Regarding late and outstanding audit report submissions, the Commonwealth agencies did not appear to be timely implementing remedial action steps in accordance with 2 CFR ?200.339 and Commonwealth Management Directive 325.8 in order to ensure compliance with federal audit submission requirements. Effect: Since required management decisions were not made within six months to ensure appropriate corrective action was taken on audits received from subrecipients, the Commonwealth did not comply with federal regulations, and subrecipients were not made aware of acceptance or rejection of corrective action plans in a timely manner. Further, noncompliance may recur in future periods if control deficiencies are not corrected on a timely basis, and there is an increased risk of unallowable charges being made to federal programs if corrective action and recovery of questioned costs is not timely. Regarding the SEFA reviews or alternate procedures which are not being performed timely and the late Single Audit report submissions, there is an increased risk that subrecipients could be misspending and/or inappropriately tracking and reporting federal funds over multiple year periods, and these discrepancies may not be properly monitored, detected, and corrected by agency personnel on a timely basis as required. Finally, additional federal pass-through funds may be unaudited in the future without timely and effective remedial action from Commonwealth agencies to enforce compliance. Recommendation: We recommend that the above weaknesses that cause untimely subrecipient Single Audit resolution, including untimely management decisions on findings, untimely review of the SEFA or alternate procedures, and late audit report submissions be corrected to ensure compliance with federal requirements and Commonwealth Management Directives, and to better ensure more timely subrecipient compliance with program requirements. Commonwealth agencies should promptly pursue outstanding audits and implement remedial action steps on a timely basis in accordance with 2 CFR ?200.339 and Commonwealth Management Directive 325.8. DEP Response: DEP agrees with the finding. DHS Response: While DHS agrees with this finding, we believe we are in compliance with 2 CFR ?200.339 and Commonwealth Management Directive 325.8 related to outstanding audits. We continue to work with counties and their independent auditors to obtain any late Single Audit reports, and albeit late, we do receive them which is the ultimate goal. PCCD Response: PCCD is in agreement with the finding. PEMA Response: PEMA agrees with this finding. The subrecipient was inadvertently excluded from PEMA?s audit tracking list due to failure of our new employee to enter the information into the Single Audit database. As soon as we became aware of the omission, and having previously reviewed the audit report, a management decision letter was issued to the subrecipient on January 21, 2022. In addition, please note that PEMA had been in constant communication with this subrecipient to resolve its noncompliance due to failure to submit the Single Audit reporting package within nine months of its year end date of December 31, 2018, and BAFM and the Bureau of State and Federal Audits have been provided documentary evidence of these communications. Questioned Costs: The amount of questioned costs cannot be determined. The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Show full finding ▾
Full finding narrative

Various Agencies Finding 2021 ? 015: ALN 15.252 ? Abandoned Mine Land Reclamation ALN 16.575 ? Crime Victim Assistance ALN 93.558 ? Temporary Assistance for Needy Families ALN 93.563 ? Child Support Enforcement ALN 93.575 and 93.596 ? Child Care and Development Fund (CCDF) Cluster (including COVID-19) ALN 93.658 ? Foster Care ? Title IV-E (including COVID-19) ALN 93.659 ? Adoption Assistance (including COVID-19) ALN 93.775, 93.777, and 93.778 ? Medicaid Cluster (including COVID-19) ALN 97.036 ? Disaster Grants ? Public Assistance (Presidentially Declared Disasters) (including COVID-19) A Material Weakness and Material Noncompliance Exist in the Commonwealth?s Subrecipient Audit Resolution Process (A Similar Condition Was Noted in Prior Year Finding 2020-021) Federal Grant Number(s) and Year(s): S21AF10015 (1/01/2021 ? 12/31/2023), S20AF20092 (10/01/2020 ? 9/30/2023), S20AF20006 (1/01/2020 ? 12/31/2022), S19AF20006 (1/01/2019 ? 12/31/2021), S19AF20004 (12/01/2018 ? 11/30/2021), S18AF20004 (11/01/2017 ? 10/31/2020), S18AF20006 (4/01/2018 ? 12/31/2020), S16AF20042 (6/01/2016 ? 5/31/2021), 2020-V2-GX-0063 (10/01/2019 ? 9/30/2023), 2019-V2-GX-0026 (10/01/2018 ? 9/30/2022), 2018-V2-GX-0068 (10/01/2017 ? 9/30/2021), 2017-VA-GX-0069 (10/01/2016 ? 9/30/2020), 2101PATANF (10/01/2020 ? 9/30/2021), 2001PATANF (10/01/2019 ? 9/30/2020), 2101PACSES (10/01/2020 ? 9/30/2021), 2001PACSES (10/01/2019 ? 9/30/2020), G2101PACCDF (10/01/2020 ? 9/30/2021), G2001PACCDF (10/01/2019 ? 9/30/2020), 2101PAFOST (10/01/2020 ? 9/30/2021), 2001PAFOST (10/01/2019 ? 9/30/2020), 2101PAADPT (10/01/2020 ? 9/30/2021), 2001PAADPT (10/01/2019 ? 9/30/2020), 2105PA5MAP (10/01/2020 ? 9/30/2021), 2005PA5MAP (10/01/2019 ? 9/30/2020), 4506DRPA (1/20/2020 ? 3/02/2024), 3441DRPA (1/20/2020 ? 1/20/2025), 4408DRPA (11/27/2018 ? 11/27/2022) Type of Finding: Significant Deficiency, Noncompliance for Medicaid Cluster Material Weakness, Material Noncompliance for Other Programs Compliance Requirement: Subrecipient Monitoring Condition: Under the Commonwealth of Pennsylvania's (Commonwealth) implementation of the Single Audit Act, review and resolution of subrecipient Single Audit reports is split into two stages. The Office of the Budget?s Bureau of Accounting and Financial Management (OB-BAFM) ensures the reports meet technical standards through a centralized desk review process. The various funding agencies in the Commonwealth are responsible for making a management decision on each finding within six months of the Federal Audit Clearinghouse?s (FAC) Management Decision Letter (MDL) start date for audits subject to Uniform Guidance and to ensure appropriate corrective action is taken by the subrecipient (except for Uniform Guidance audits under U.S. Department of Labor programs which are permitted 12 months for management decisions in accordance with 2 CFR Section 2900.21). Each Commonwealth agency is also responsible for reviewing financial information in each audit report to determine whether the audit included all pass-through funding provided by the agency in order to ensure pass-through funds were subject to audit. Most agencies meet this requirement by performing Schedule of Expenditures of Federal Awards (SEFA) reconciliations. The agency is also required to adjust Commonwealth records, if necessary. Finding 2021 ? 015: (continued) Our fiscal year ended June 30, 2021 audit of the Commonwealth?s process for review and resolution of subrecipient Single Audits included an evaluation of the Commonwealth?s fiscal year ended June 30, 2020 subrecipient audit universe for audits due for submission to the FAC during the fiscal year ended June 30, 2021. We also evaluated the Commonwealth?s review of 33 subrecipient audit reports with findings in major programs/clusters which were identified on the Commonwealth agencies? tracking lists during the fiscal year ended June 30, 2021, and required management decisions by Commonwealth agencies. Our testing disclosed the following audit exceptions regarding the Commonwealth agencies? review of subrecipient audit reports: ? Department of Environmental Protection (DEP): The time period for making a management decision on findings was approximately 8.6 months after the FAC MDL start date for one out of two audit reports with findings. ? Department of Human Services (DHS): The time period for making a management decision on findings ranged from approximately 7.2 months to 20.3 months after the FAC MDL start date for 22 out of 23 subrecipient audit reports with findings. There was also a delay in DHS?s procedures to ensure the subrecipient SEFAs were accurate so that major programs were properly determined and subject to audit. In addition, our review disclosed that three subrecipient audit reports with findings for which DHS was the lead agency were submitted late to the FAC, with FAC acceptance dates ranging from approximately 3.6 months to 10.8 months after the Single Audit due date. ? Pennsylvania Commission on Crime and Delinquency (PCCD): The time period for making a management decision on findings was approximately 10.3 months after the FAC MDL start date for one out of two subrecipient audit reports with findings. ? Pennsylvania Emergency Management Agency (PEMA): The time period for making a management decision on findings was approximately 12 months after the FAC MDL start date for one subrecipient audit report with findings. In addition, our review disclosed the one subrecipient audit report with findings for which PEMA was the lead agency was submitted approximately 16 months late to the FAC and was excluded from PEMA?s tracking list. As a follow-up to the prior year finding, we noted that the Commonwealth subgranted federal funds totaling $285,634,900 to the City of Philadelphia during the fiscal year ended June 30, 2020, for which a Single Audit was not submitted to the FAC as of our January 2022 testing date. This was over 3.5 months after the September 30, 2021 due date, which had been extended due to the COVID-19 pandemic in accordance with the Office of Management and Budget?s Memorandum M-21-20, Appendix 3. Our testing disclosed that DHS?s subgrants to the City of Philadelphia were material for four of the 14 major programs/clusters with material subgranted funds. Our follow-up on the prior year finding also disclosed that the Commonwealth subgranted federal funds totaling $30,158,167 to Bucks County during the fiscal year ended December 31, 2019. The audit was submitted to the FAC on February 24, 2021, which was nearly two months after the December 31, 2020 due date, which had been extended in accordance with the Office of Management and Budget?s Memorandum M-20-26, Appendix A. DHS was the lead agency for the City of Philadelphia and Bucks County audits. Criteria: 2 CFR ?200.332, Requirements for pass-through entities, states in part: All pass-through entities must: (d) Monitor the activities of the subrecipient as necessary to ensure that the subaward is used for authorized purposes, in compliance with Federal statutes, regulations, and the terms and conditions of the subaward, and that subaward performance goals are achieved. Pass-through entity monitoring of the subrecipient must include: Finding 2021 ? 015: (continued) (2) Following-up and ensuring that the subrecipient takes timely and appropriate action on all deficiencies pertaining to the Federal award provided to the subrecipient from the pass-through entity detected through audits, on-site reviews, and written confirmation from the subrecipient, highlighting the status of actions planned or taken to address Single Audit findings related to the particular subaward. (3) Issuing a management decision for applicable audit findings pertaining only to the Federal award provided to the subrecipient from the pass-through entity as required by ?200.521 [Management decision]. (f) Verify that every subrecipient is audited as required by Subpart F [Audit Requirements] of this part when it is expected that the subrecipient?s Federal awards expended during the respective fiscal year equaled or exceeded the threshold set forth in ?200.501 [Audit requirements]. (g) Consider whether the results of the subrecipient?s audit, on-site review, or other monitoring indicate conditions that necessitate adjustments to the pass-through entity?s own records. (h) Consider taking enforcement action against noncompliant subrecipients as described in ?200.339 [Remedies for noncompliance] of this part and in program regulations. In order to carry out these responsibilities properly, good internal control dictates that state pass-through agencies ensure subrecipient Single Audit SEFAs are representative of state payment records each year, and that the related federal programs have been properly subjected to Single Audit procedures. 2 CFR ?200.512, Report submission, states in part: (a) General. (1) The audit must be completed and the data collection form described in paragraph (b) of this section and reporting package described in paragraph (c) of this section must be submitted within the earlier of 30 calendar days after receipt of the auditor?s report(s), or nine months after the end of the audit period. If the due date falls on a Saturday, Sunday, or Federal holiday, the reporting package is due the next business day. 2 CFR ?200.521, Management decision, states in part: (a) General. The management decision must clearly state whether or not the finding is sustained, the reasons for the decision, and the expected auditee action to repay disallowed costs, make financial adjustments, or take other action. (d) Time requirements. The Federal awarding agency or pass-through entity responsible for issuing a management decision must do so within six months of acceptance of the audit report by the FAC. The auditee must initiate and proceed with corrective action as rapidly as possible and corrective action should begin no later than upon receipt of the audit report. 2 CFR ?200.505, Sanctions, states: In cases of continued inability or unwillingness to have an audit conducted in accordance with this part, Federal agencies and pass-through entities must take appropriate action as provided in ?200.339 [Remedies for noncompliance]. 2 CFR ?200.339, Remedies for noncompliance, states in part: If a non-Federal entity fails to comply with the U.S. Constitution, Federal statutes, regulations or the terms and conditions of a Federal award, the Federal awarding agency or pass-through entity may impose additional conditions, as described in ?200.208 [Specific conditions]. If the Federal awarding agency or pass-through entity determines that noncompliance cannot be remedied by imposing additional conditions, the federal awarding agency or pass-through entity may take one or more of the following actions, as appropriate in the circumstances. (a) Temporarily withhold cash payments pending correction of the deficiency by the non-Federal entity or more severe enforcement action by the Federal awarding agency or pass-through entity. Finding 2021 ? 015: (continued) (b) Disallow (that is, deny both use of funds and any applicable matching credit for) all or part of the cost of the activity or action not in compliance. (c) Wholly or partly suspend or terminate the Federal award. (d) Initiate suspension or debarment proceedings as authorized under 2 CFR Part 180 and Federal awarding agency regulations (or in the case of a pass-through entity, recommend such a proceeding be initiated by a Federal awarding agency). (e) Withhold further Federal awards for the project or program. (f) Take other remedies that may be legally available. To ensure Commonwealth enforcement of federal regulations for subrecipient noncompliance with audit requirements, Commonwealth Management Directive 325.8, Remedies for Recipient Noncompliance with Audit Requirements, Section 5 related to policy, states in part: (a) Agencies must develop and implement remedial action that reflects the unique requirements of each program? (b) Overall periods for the implementation of remedial action should not exceed six months from the date the first remedial action is initiated. At the end of the six-month period, the recipient should take the appropriate corrective action or the final stage of remedial action should be imposed on the recipient. Examples of remedial action include, but are not limited to: (1) Meeting or calling the recipient to explain the importance and benefits of the audit and audit resolution processes, emphasizing the value of the audit as an administrative tool and the Commonwealth?s reliance on an acceptable audit and prompt resolution as evidence of the recipient?s ability to properly administer the program. (2) Encouraging the entity to establish an audit committee or designate an individual as the single point of contact to: (a) Communicate regarding the audit. (b) Arrange for and oversee the audit. (c) Direct and monitor audit resolution. (3) Providing technical assistance to the recipient in devising and implementing an appropriate plan to remedy the noncompliance. (4) Withholding a portion of assistance payments until the noncompliance is resolved. (5) Withholding or disallowing overhead costs until the noncompliance is resolved. (6) Suspending the assistance agreement until the noncompliance is resolved. (7) Terminating the assistance agreement with the recipient and, if necessary, seeking alternative entities to administer the program. Management Directive 325.9, Processing Audits of Federal Pass-Through Funds, Section 7 related to procedures, states in part: c. Agencies. (1) Evaluate single audit report submissions received from BOA [now OB-BAFM] to determine program purpose acceptability by verifying, at a minimum, that all agency-funded programs are properly included on the applicable financial schedules; that findings affecting the agency contain sufficient information to facilitate a management decision; and that the subrecipient has submitted an adequate corrective action plan. (6) Impose or coordinate the imposition of remedial action in accordance with 2 CFR Part 200.338 [now 200.339] and Management Directive 325.8, Remedies for Recipient Noncompliance with Audit Requirements, when subrecipients fail to comply with the provisions of Subpart F. Finding 2021 ? 015: (continued) Management Directive 325.12, Standards for Internal Control for Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s, Standards for Internal Control in the Federal Government (Green Book), published in September 2014. The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: One reason provided by Commonwealth management for untimely audit resolution in the various agencies, including making management decisions, approving corrective action, and performing procedures to ensure the accuracy of subrecipient SEFAs, and for the exclusion of an audit from a tracking list, was either a change in staff or a lack of staff to follow up and process subrecipient audit reports more timely. DEP personnel stated the late management decision resulted from late notification of FAC audit receipt by OB-BAFM. PCCD personnel indicated the management decision was not completed due to an oversight. Regarding late and outstanding audit report submissions, the Commonwealth agencies did not appear to be timely implementing remedial action steps in accordance with 2 CFR ?200.339 and Commonwealth Management Directive 325.8 in order to ensure compliance with federal audit submission requirements. Effect: Since required management decisions were not made within six months to ensure appropriate corrective action was taken on audits received from subrecipients, the Commonwealth did not comply with federal regulations, and subrecipients were not made aware of acceptance or rejection of corrective action plans in a timely manner. Further, noncompliance may recur in future periods if control deficiencies are not corrected on a timely basis, and there is an increased risk of unallowable charges being made to federal programs if corrective action and recovery of questioned costs is not timely. Regarding the SEFA reviews or alternate procedures which are not being performed timely and the late Single Audit report submissions, there is an increased risk that subrecipients could be misspending and/or inappropriately tracking and reporting federal funds over multiple year periods, and these discrepancies may not be properly monitored, detected, and corrected by agency personnel on a timely basis as required. Finally, additional federal pass-through funds may be unaudited in the future without timely and effective remedial action from Commonwealth agencies to enforce compliance. Recommendation: We recommend that the above weaknesses that cause untimely subrecipient Single Audit resolution, including untimely management decisions on findings, untimely review of the SEFA or alternate procedures, and late audit report submissions be corrected to ensure compliance with federal requirements and Commonwealth Management Directives, and to better ensure more timely subrecipient compliance with program requirements. Commonwealth agencies should promptly pursue outstanding audits and implement remedial action steps on a timely basis in accordance with 2 CFR ?200.339 and Commonwealth Management Directive 325.8. DEP Response: DEP agrees with the finding. DHS Response: While DHS agrees with this finding, we believe we are in compliance with 2 CFR ?200.339 and Commonwealth Management Directive 325.8 related to outstanding audits. We continue to work with counties and their independent auditors to obtain any late Single Audit reports, and albeit late, we do receive them which is the ultimate goal. PCCD Response: PCCD is in agreement with the finding. PEMA Response: PEMA agrees with this finding. The subrecipient was inadvertently excluded from PEMA?s audit tracking list due to failure of our new employee to enter the information into the Single Audit database. As soon as we became aware of the omission, and having previously reviewed the audit report, a management decision letter was issued to the subrecipient on January 21, 2022. In addition, please note that PEMA had been in constant communication with this subrecipient to resolve its noncompliance due to failure to submit the Single Audit reporting package within nine months of its year end date of December 31, 2018, and BAFM and the Bureau of State and Federal Audits have been provided documentary evidence of these communications. Questioned Costs: The amount of questioned costs cannot be determined. The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Corrective Action Plan

DEP: During an audit in December 2020, DEP Fiscal Management became aware of staff not completing the necessary steps for the management decision process that is included in the instructions for handling single audit reviews. DEP Fiscal Management staff immediately contacted the DEP Program Grant Officers for a review of these findings and the submitted corrective action plans. At that time, there was also a thorough review of all single audits received with findings for the calendar year to ensure these steps were not missed on any other submissions. DEP Fiscal Management staff participated in a mandatory review of department and Commonwealth policies focusing on these steps January 21, 2021. DEP Fiscal Management updated the internal procedures to highlight these steps to ensure they are not missed on any future single audit review on February 1, 2021. DEP Fiscal Management staff participated in a high-level training held by OB-BAFM on March 30, 2021. All staff attended the session, including staff who previously worked on single audits and new staff that had recently come on board. OB-BAFM provides agencies with single audit reporting packages that have findings each week that have been accepted by the Federal Audit Clearinghouse. This allows to start the management decision process in a timelier manner and meet the six-month deadline for issuing a decision. Anticipated Completion Date: Completed Contact Person and Title: Jennifer L. Brandt, Senior Fiscal Management Specialist, Federal Grants and Audits DHS: Regarding the timeliness of finding resolution and procedures related to the SEFA reviews, the Audit Resolution Section (ARS) hired an additional staff member in August 2021 and is currently in the process of hiring another staff member as of February 2022. In addition, ARS is continuing to have staff from other areas in the Division of Audit and Review assist with these reviews to make them timelier. Finally, the ARS is working with Office of the Budget, Bureau of Accounting and Financial Management to develop a risk-based approach for single audit reviews, which will greatly streamline the process of single audit reviews to gain substantial efficiencies. Regarding late audit report submissions, DHS will continue to follow the requirements of 2 CFR ?200.339 and Commonwealth Management Directive 325.8. DHS will continue to work with counties and their independent auditors to obtain any late Single Audit reports. Anticipated Completion Date: 06/30/2022 Contact Person and Title: David Bryan, Manager, Audit Res. Section; Alexander Matolyak, Director, Division of Audit and Review PCCD: Internal operating procedures have been revised to include the following corrective actions: PCCD will monitor the ?Agency Finding Responsibility Spreadsheet? provided by OB-BAFM on a weekly basis. Once OB-BAFM determines PCCD is the Lead/Responsible agency, PCCD will document the start date on issuing a management decision. PCCD will issue the Management Decision within six months of acceptance of the audit report by the Federal Audit Clearinghouse (FAC). Anticipated Completion Date: Completed Contact Person and Title: Chris Epoca, Deputy Director, OFMA PEMA: The FAC Weekly Listing and Agency Finding Responsibility Spreadsheet provided by OB-BAFM are now reviewed by a more senior staff to ensure the OB-BAFM routine upload emails are being entered correctly into the single audit database by the designated staff. Anticipated Completion Date: Completed Contact Person and Title: Anne N. Ofili, Grants Comp. Division Chief

Prior Finding References

2020-021

About Subrecipient Monitoring →

FY 2020-06-30

FAC accepted this audit on March 18, 2021 — management decision was due September 18, 2021.

2020-003
Subrecipient Monitoring
REPEATQUESTIONED COSTS

During the fiscal year ended June 30, 2020, the Department of Community and Economic Development (DCED) reported subrecipient expenditures for the United States Department of Housing and Urban Development (HUD), Community Development Block Grants (CDBG) ? State?s Program (including Neighborhood Stabilization Program and CDBG-Disaster Recovery Programs), of $40,100,301, which represented approximately 97 percent of total CDBG cluster expenditures of $41,354,168 on the Schedule of Expenditures of Federal Awards. DCED is required to maintain internal controls that ensure subrecipient grant funds are utilized within the established contract period. The grant managers monitor the subrecipient contracts and the progress of projects through review of expenditure reports, written and verbal communications, desk reviews, and site visits. In accordance with Fiscal Directive 2014-04, the Financial Management Center of DCED has performed a review of invoices submitted by CDBG subrecipients prior to the disbursement of federal funds through HUD?s Integrated Disbursement & Information System (IDIS) for compliance with the following: ? Contract amount; ? Budget category; ? Activity period; ? IDIS project number; ? Environmental clearance date; and ? Expenditure being incurred within the first 3 years of the grant. The monitoring policies and procedures applicable to the fiscal years 2014 through 2016 required a Risk Analysis Evaluation (RAE) to be conducted upon the receipt of a grant application. The RAE resulted in a score used to rank the subrecipient according to risk. The policy stated that subrecipients whose score was among the top 20, thus presenting the highest risk, will receive on-site monitoring, as well as remote monitoring, which required the quarterly submission of a Monitoring Activity Performance Report (MAPR). Remaining subrecipients were subject to remote monitoring and were required to submit a MAPR on a semi-annual basis. In addition, per the policy and risk analysis, management was required to select a sample of invoices on a quarterly basis, including at least one invoice from all subrecipients drawing funds during that quarter, to conduct a review. Finding 2020 ? 003: (continued) We reviewed support for the following subrecipients for the fiscal years 2014 through 2016 and identified the following: SEE SCHEDULE OF FINDINGS AND QUESTIONED COSTS FOR CHART/TABLE. In addition to the above exceptions, only 19 subgrantees were categorized as high risk. Monitoring policies and procedures in place require at least 20 high risk subgrantees to be identified. The monitoring policies and procedures applicable to the fiscal year 2017 and going forward (new policy) require a RAE to be completed upon receipt and review of a CDBG entitlement grant application. In addition, the RAE will determine the level of risk associated with the applicable program year. Every four years, these scores are used to determine the monitoring schedule for the next four years as follows: High Risk ? All OBOs (counties administering funds on behalf of smaller jurisdictions) with five or more small jurisdictions will automatically be categorized as high risk. Following these, the highest scoring subrecipients will be rated high risk until the total of high risk grantees is 20. Subrecipients deemed high risk will submit the MAPR semi-annually. In addition, grant managers will conduct on-site monitoring annually based on the four year monitoring schedule. The schedule will ensure that all subrecipients receive an on-site visit at least once every four years. Medium Risk ? The next 20 subrecipients based on score will be rated as medium risk. CDBG subrecipients will submit the MAPR at least annually. Low Risk ? Those subrecipients not rated as high or medium risk will be rated as low risk. CDBG subrecipients will submit the MAPR at least annually. We reviewed supporting documentation for six of the 20 high risk subrecipients and ten of the 66 remaining subrecipients for the fiscal year 2017 and forward and identified the following: SEE SCHEDULE OF FINDINGS AND QUESTIONED COSTS FOR CHART/TABLE. Criteria: Regarding subrecipient monitoring, 2 CFR Section 200.331 states: All pass-through entities must: (b) Evaluate each subrecipient's risk of noncompliance with Federal statutes, regulations, and the terms and conditions of the subaward for purposes of determining the appropriate subrecipient monitoring described in paragraphs (d) and (e) of this section. (d) Monitor the activities of the subrecipient as necessary to ensure that the subaward is used for authorized purposes, in compliance with Federal statutes, regulations, and the terms and conditions of the subaward; and that subaward performance goals are achieved. Pass-through entity monitoring of the subrecipient must include: Finding 2020 ? 003: (continued) (1) Reviewing financial and performance reports required by the pass-through entity. (2) Following-up and ensuring that the subrecipient takes timely and appropriate action on all deficiencies pertaining to the Federal award provided to the subrecipient from the pass-through entity detected through audits, on-site reviews, and other means. (3) Issuing a management decision for audit findings pertaining to the Federal award provided to the subrecipient from the pass-through entity as required by ?200.521 Management decision. Management Directive 325.12, Standards for Internal Control for Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book), published in September 2014. The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: Management identified operational inefficiencies in the implementation of the monitoring plans. Effect: Adequate risk assessment and timely completion of on-site visits and required MAPR reporting is vital in providing DCED with information necessary to determine whether the program?s subrecipients are complying with federal regulations. A material number of subrecipients expended individually less than $750,000 in total federal awards from the Commonwealth during the fiscal year ended June 30, 2019, and as a result would not have been required to submit a Single Audit under the Uniform Guidance to the Commonwealth during the fiscal year ended June 30, 2020. Therefore, these subrecipients were only subject to fiscal monitoring by the program. Recommendation: We recommend that DCED ensure that all on-site visits are completed along with all required reporting documentation, within the scheduled monitoring cycle, to provide reasonable assurance that subrecipients administer the federal awards in compliance with laws, regulations, and the provisions of contracts and/or grant agreements. We also recommend that DCED ensure the results of all monitoring visits are communicated to the subrecipients in a timely manner, and that DCED perform follow-up procedures to ensure appropriate corrective action is implemented by the subrecipients. Agency Response: DCED agrees with the finding. Questioned Costs: The amount of questioned costs cannot be determined. The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Show full finding ▾
Full finding narrative

Department of Community and Economic Development Finding 2020 ? 003: CFDA #14.228 ? Community Development Block Grants ? State?s Program The Department of Community and Economic Development Did Not Perform Adequate During-the-Award Monitoring of Subrecipients (A Similar Condition Was Noted in Prior Year Finding 2019-004) Federal Grant Number(s) and Year(s): B-19-DC-42-001 (1/01/2019 ? 9/30/2026), B-18-DC-42-0001 (1/01/2018 ? 9/30/2025), B-17-DC-42-0001 (1/01/2017 ? 9/30/2024), B-16-DC-42-0001 (1/01/2016 ? 12/31/2023), B-15-DC-42-0001 (1/01/2015 ? 9/30/2022), B-14-DC-42-0001 (1/01/2014 ? 9/30/2021) Type of Finding: Significant Deficiency, Noncompliance Compliance Requirement: Subrecipient Monitoring Condition: During the fiscal year ended June 30, 2020, the Department of Community and Economic Development (DCED) reported subrecipient expenditures for the United States Department of Housing and Urban Development (HUD), Community Development Block Grants (CDBG) ? State?s Program (including Neighborhood Stabilization Program and CDBG-Disaster Recovery Programs), of $40,100,301, which represented approximately 97 percent of total CDBG cluster expenditures of $41,354,168 on the Schedule of Expenditures of Federal Awards. DCED is required to maintain internal controls that ensure subrecipient grant funds are utilized within the established contract period. The grant managers monitor the subrecipient contracts and the progress of projects through review of expenditure reports, written and verbal communications, desk reviews, and site visits. In accordance with Fiscal Directive 2014-04, the Financial Management Center of DCED has performed a review of invoices submitted by CDBG subrecipients prior to the disbursement of federal funds through HUD?s Integrated Disbursement & Information System (IDIS) for compliance with the following: ? Contract amount; ? Budget category; ? Activity period; ? IDIS project number; ? Environmental clearance date; and ? Expenditure being incurred within the first 3 years of the grant. The monitoring policies and procedures applicable to the fiscal years 2014 through 2016 required a Risk Analysis Evaluation (RAE) to be conducted upon the receipt of a grant application. The RAE resulted in a score used to rank the subrecipient according to risk. The policy stated that subrecipients whose score was among the top 20, thus presenting the highest risk, will receive on-site monitoring, as well as remote monitoring, which required the quarterly submission of a Monitoring Activity Performance Report (MAPR). Remaining subrecipients were subject to remote monitoring and were required to submit a MAPR on a semi-annual basis. In addition, per the policy and risk analysis, management was required to select a sample of invoices on a quarterly basis, including at least one invoice from all subrecipients drawing funds during that quarter, to conduct a review. Finding 2020 ? 003: (continued) We reviewed support for the following subrecipients for the fiscal years 2014 through 2016 and identified the following: SEE SCHEDULE OF FINDINGS AND QUESTIONED COSTS FOR CHART/TABLE. In addition to the above exceptions, only 19 subgrantees were categorized as high risk. Monitoring policies and procedures in place require at least 20 high risk subgrantees to be identified. The monitoring policies and procedures applicable to the fiscal year 2017 and going forward (new policy) require a RAE to be completed upon receipt and review of a CDBG entitlement grant application. In addition, the RAE will determine the level of risk associated with the applicable program year. Every four years, these scores are used to determine the monitoring schedule for the next four years as follows: High Risk ? All OBOs (counties administering funds on behalf of smaller jurisdictions) with five or more small jurisdictions will automatically be categorized as high risk. Following these, the highest scoring subrecipients will be rated high risk until the total of high risk grantees is 20. Subrecipients deemed high risk will submit the MAPR semi-annually. In addition, grant managers will conduct on-site monitoring annually based on the four year monitoring schedule. The schedule will ensure that all subrecipients receive an on-site visit at least once every four years. Medium Risk ? The next 20 subrecipients based on score will be rated as medium risk. CDBG subrecipients will submit the MAPR at least annually. Low Risk ? Those subrecipients not rated as high or medium risk will be rated as low risk. CDBG subrecipients will submit the MAPR at least annually. We reviewed supporting documentation for six of the 20 high risk subrecipients and ten of the 66 remaining subrecipients for the fiscal year 2017 and forward and identified the following: SEE SCHEDULE OF FINDINGS AND QUESTIONED COSTS FOR CHART/TABLE. Criteria: Regarding subrecipient monitoring, 2 CFR Section 200.331 states: All pass-through entities must: (b) Evaluate each subrecipient's risk of noncompliance with Federal statutes, regulations, and the terms and conditions of the subaward for purposes of determining the appropriate subrecipient monitoring described in paragraphs (d) and (e) of this section. (d) Monitor the activities of the subrecipient as necessary to ensure that the subaward is used for authorized purposes, in compliance with Federal statutes, regulations, and the terms and conditions of the subaward; and that subaward performance goals are achieved. Pass-through entity monitoring of the subrecipient must include: Finding 2020 ? 003: (continued) (1) Reviewing financial and performance reports required by the pass-through entity. (2) Following-up and ensuring that the subrecipient takes timely and appropriate action on all deficiencies pertaining to the Federal award provided to the subrecipient from the pass-through entity detected through audits, on-site reviews, and other means. (3) Issuing a management decision for audit findings pertaining to the Federal award provided to the subrecipient from the pass-through entity as required by ?200.521 Management decision. Management Directive 325.12, Standards for Internal Control for Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book), published in September 2014. The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: Management identified operational inefficiencies in the implementation of the monitoring plans. Effect: Adequate risk assessment and timely completion of on-site visits and required MAPR reporting is vital in providing DCED with information necessary to determine whether the program?s subrecipients are complying with federal regulations. A material number of subrecipients expended individually less than $750,000 in total federal awards from the Commonwealth during the fiscal year ended June 30, 2019, and as a result would not have been required to submit a Single Audit under the Uniform Guidance to the Commonwealth during the fiscal year ended June 30, 2020. Therefore, these subrecipients were only subject to fiscal monitoring by the program. Recommendation: We recommend that DCED ensure that all on-site visits are completed along with all required reporting documentation, within the scheduled monitoring cycle, to provide reasonable assurance that subrecipients administer the federal awards in compliance with laws, regulations, and the provisions of contracts and/or grant agreements. We also recommend that DCED ensure the results of all monitoring visits are communicated to the subrecipients in a timely manner, and that DCED perform follow-up procedures to ensure appropriate corrective action is implemented by the subrecipients. Agency Response: DCED agrees with the finding. Questioned Costs: The amount of questioned costs cannot be determined. The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Corrective Action Plan

During the year under review DCED continued to implement the multi-year monitoring approach developed in its subrecipient monitoring plan update. The framework addresses on-site and remote oversight of grantee compliance in all areas of program delivery, environmental review, labor standards, fair housing and equal opportunity and financial management. DCED successfully completed the monitoring of 97 CDBG entitlement, competitive and disaster recovery contracts during the audit period. This accomplishment is especially monumental given that on March 16, 2020, staff began working from home and more than 10 scheduled on-site monitoring visits were cancelled and have yet to be rescheduled as a result of the pandemic. DCED continues to use and improve upon tracking tools to log and track submission of MAPR reports and staff review of submissions. Additionally, DCED is working with IT staff to create an on-line submission platform for MAPRs that will assist in long term tracking and cataloguing of reports. Per the corrective action identified in 2018 and continued in 2019, DCED continues to prioritize completion of the outstanding pre-2014 CDBG entitlement contracts ? with specific attention to the grantees whose CDBG entitlement contracts are now being administered by their respective County. DCED has placed a temporary hold on on-site reviews through June 30, 2021 of CDBG contracts. Where possible, Grant Managers have and will continue to identify activities that may be monitored remotely. Those remote reviews are contingent on grantee access to records and information and their ability to complete a review remotely as well. DCED is continuing to actively engage with grantees in their response to the coronavirus pandemic and staff are working actively to review the CDBG monitoring plan and identify opportunities to improve upon processes outlined in the plan and account for potential needs for remote review during situations like we are currently facing. DCED has continued to complete remote environmental review, labor standards and fair housing and equal opportunity monitoring during the pandemic. Anticipated Completion Date: 06/30/2022 Contact Person: Kathy Possinger, Director, Center for Community and Housing Development

Prior Finding References

2019-004

About Subrecipient Monitoring →
2020-004
Subrecipient Monitoring
MATERIAL WEAKNESSQUESTIONED COSTS

The Department of Environmental Protection (DEP) administers the Abandoned Mine Land Reclamation (AMLR) program funded by the United States Department of the Interior (DOI). During the fiscal year ended June 30, 2020, DEP expended $54,468,352 for the AMLR program, of which $11,142,804 was paid to 17 entities with whom DEP executed subrecipient agreements to provide abandoned mine land reclamation repairs and services throughout Pennsylvania. These subrecipient agreements included clauses requiring subrecipient Single Audits. Also, as a result of the expenditures being recorded as subrecipient expenditures in the SAP accounting system, the expenditures were reported as subrecipient expenditures to the federal government when they were automatically uploaded to the federal USAspending system. Our audit testing disclosed that DEP did not conduct program monitoring of these subrecipient expenditures during the fiscal year ended June 30, 2020. Criteria: As part of administering the AMLR program, DEP must have policies, procedures, and controls in place to ensure compliance with federal requirements within contract requirements and regulations. 2 CFR Section 200.331, Requirements for pass through entities, states in part: All pass-through entities must: (d) Monitor the activities of the subrecipient as necessary to ensure that the subaward is used for authorized purposes, in compliance with Federal statutes, regulations, and the terms and conditions of the subaward; and that subaward performance goals are achieved. The standard contract agreement between DEP and the local grantee states, in part: Audit/Compliance Review Requirements - The contractor must comply with all applicable federal and state grant requirements including the Single Audit Act Amendments of 1996; 2 CFR Part 200 as amended; and any other applicable law or regulation, and any amendment to such other applicable law or regulation that may be enacted or promulgated by the federal government. Management Directive 325.12, Standards for Internal Control for Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book), published in September 2014. The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Finding 2020 ? 004: (continued) Cause: DEP management indicated that the 17 entities were contractors for whom subrecipient monitoring requirements were not applicable, and the related expenditures were erroneously recorded in the SAP accounting system and on the Commonwealth?s SEFA as subrecipient expenditures. DEP management stated that their policies and procedures are not significantly different between the entities recorded as subrecipients and those recorded as contractors. However, as noted in the finding condition, our audit disclosed that DEP executed subrecipient agreements with the 17 entities, some of whom had Single Audits conducted, with the AMLR expenditures reported on the Single Audit SEFAs as required for subrecipients. In December 2019, DEP?s Bureau of Abandoned Mine Reclamation management decided that DEP would not approve any additional agreements until the issue is resolved at both the federal and state levels. However, DEP management stated that the agreements that were already in place would continue as executed. Effect: Without the timely completion of AMLR program subrecipient monitoring, DEP cannot ensure compliance with federal statutes, regulations, and the terms and conditions of the subaward contracts, confirm that local subgrantees are performing satisfactory work, ensure the efficient use of program resources, and minimize the risk for fraud and abuse. Completing monitoring activities is essential for DEP to determine whether the local agencies are complying with federal regulations and spending grant funds appropriately. If contractors are misrepresented as subrecipients in the agreements and SAP accounting system, expenditures may be incorrectly reported and unnecessary Single Audit burden has been created at the subrecipient level. Recommendation: We recommend that DEP management make an immediate determination of whether recipients with existing agreements are contractors or subrecipients, and if changes are necessary, amend the agreements and correct the accounting system to record subrecipient and contractor expenditures accurately. DEP should seek formal federal DOI approval to revise any existing agreements to contractor agreements. DEP should follow this determination consistently with future agreements and accounting treatment. DEP should also develop written policies and procedures for subrecipient monitoring and implement them immediately to ensure timely subrecipient compliance with federal regulations. Agency Response: DEP agrees with the finding. Questioned Costs: The amount of questioned costs cannot be determined. The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Show full finding ▾
Full finding narrative

Department of Environmental Protection Finding 2020 ? 004: CFDA #15.252 ? Abandoned Mine Land Reclamation A Material Weakness and Material Noncompliance Exist at the Department of Environmental Protection Related to Subrecipient Monitoring Federal Grant Number(s) and Year(s): S20AF20006 (1/01/2020 ?? 12/31/2022), S19AF20006 (1/01/2019 ? ? 12/31/2021), S19AF20004 (12/01/2019 ? 11/30/2021), S18AF20004 (11/01/2018 ? 10/31/2020), S17AF20008 (1/01/2017 ? 12/31/2019) Type of Finding: Material Weakness, Material Noncompliance Compliance Requirement: Subrecipient Monitoring Condition: The Department of Environmental Protection (DEP) administers the Abandoned Mine Land Reclamation (AMLR) program funded by the United States Department of the Interior (DOI). During the fiscal year ended June 30, 2020, DEP expended $54,468,352 for the AMLR program, of which $11,142,804 was paid to 17 entities with whom DEP executed subrecipient agreements to provide abandoned mine land reclamation repairs and services throughout Pennsylvania. These subrecipient agreements included clauses requiring subrecipient Single Audits. Also, as a result of the expenditures being recorded as subrecipient expenditures in the SAP accounting system, the expenditures were reported as subrecipient expenditures to the federal government when they were automatically uploaded to the federal USAspending system. Our audit testing disclosed that DEP did not conduct program monitoring of these subrecipient expenditures during the fiscal year ended June 30, 2020. Criteria: As part of administering the AMLR program, DEP must have policies, procedures, and controls in place to ensure compliance with federal requirements within contract requirements and regulations. 2 CFR Section 200.331, Requirements for pass through entities, states in part: All pass-through entities must: (d) Monitor the activities of the subrecipient as necessary to ensure that the subaward is used for authorized purposes, in compliance with Federal statutes, regulations, and the terms and conditions of the subaward; and that subaward performance goals are achieved. The standard contract agreement between DEP and the local grantee states, in part: Audit/Compliance Review Requirements - The contractor must comply with all applicable federal and state grant requirements including the Single Audit Act Amendments of 1996; 2 CFR Part 200 as amended; and any other applicable law or regulation, and any amendment to such other applicable law or regulation that may be enacted or promulgated by the federal government. Management Directive 325.12, Standards for Internal Control for Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book), published in September 2014. The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Finding 2020 ? 004: (continued) Cause: DEP management indicated that the 17 entities were contractors for whom subrecipient monitoring requirements were not applicable, and the related expenditures were erroneously recorded in the SAP accounting system and on the Commonwealth?s SEFA as subrecipient expenditures. DEP management stated that their policies and procedures are not significantly different between the entities recorded as subrecipients and those recorded as contractors. However, as noted in the finding condition, our audit disclosed that DEP executed subrecipient agreements with the 17 entities, some of whom had Single Audits conducted, with the AMLR expenditures reported on the Single Audit SEFAs as required for subrecipients. In December 2019, DEP?s Bureau of Abandoned Mine Reclamation management decided that DEP would not approve any additional agreements until the issue is resolved at both the federal and state levels. However, DEP management stated that the agreements that were already in place would continue as executed. Effect: Without the timely completion of AMLR program subrecipient monitoring, DEP cannot ensure compliance with federal statutes, regulations, and the terms and conditions of the subaward contracts, confirm that local subgrantees are performing satisfactory work, ensure the efficient use of program resources, and minimize the risk for fraud and abuse. Completing monitoring activities is essential for DEP to determine whether the local agencies are complying with federal regulations and spending grant funds appropriately. If contractors are misrepresented as subrecipients in the agreements and SAP accounting system, expenditures may be incorrectly reported and unnecessary Single Audit burden has been created at the subrecipient level. Recommendation: We recommend that DEP management make an immediate determination of whether recipients with existing agreements are contractors or subrecipients, and if changes are necessary, amend the agreements and correct the accounting system to record subrecipient and contractor expenditures accurately. DEP should seek formal federal DOI approval to revise any existing agreements to contractor agreements. DEP should follow this determination consistently with future agreements and accounting treatment. DEP should also develop written policies and procedures for subrecipient monitoring and implement them immediately to ensure timely subrecipient compliance with federal regulations. Agency Response: DEP agrees with the finding. Questioned Costs: The amount of questioned costs cannot be determined. The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Corrective Action Plan

AMLR program representatives attended an online training in March 2021 that covered 2 CFR 200 and contractor or subrecipient determinations. The training was provided by the Department of the Interior, Office of Surface Mining Reclamation and Enforcement (DOI/OSM) and it is expected to specifically address the AMLR program funded under CFDA 15.252. The DEP has ceased issuing AMLR grants under Management Directive 305.20, Grant Administration, and will not resume issuing them until there is a final determination whether recipients are considered contractors or subrecipients. Following the DOI/OSM training on 2 CFR 200, DEP management will make a determination of whether recipients with existing agreements are contractors or subrecipients, and if changes are necessary, amend the agreements and correct the accounting system to record subrecipient and contractor expenditures accurately. All agreements associated with a contractor determination will comply with the Commonwealth Procurement Code and associated Commonwealth policies. DEP will amend or substitute agreements as necessary to comply with federal and state requirements. DEP will follow this determination consistently with future agreements and accounting treatment. If existing agreements are determined as subrecipients, DEP will develop written policies and procedures for subrecipient monitoring and implement them immediately to ensure timely subrecipient compliance with federal regulations. Anticipated Completion Date: 12/30/2021 Contact People: Brian Bradley, Director, Bureau of Abandoned Mine Reclamation; Tim Golding, Executive Assistant, Office of Administration and Management

About Subrecipient Monitoring →
2020-005
Special Tests & Provisions
MATERIAL WEAKNESSREPEATQUESTIONED COSTS

During our audit of the Supplemental Nutrition Assistance Program (SNAP) administered by the Department of Human Services (DHS), we evaluated the security over Electronic Benefits Transfer (EBT) cards, which includes both the physical security of EBT cards during the issuance process at County Assistance Offices (CAO), as well as the handling of EBT cards returned from the United States Postal Service as undeliverable, or those that have been lost or stolen. EBT cards are the method by which SNAP benefit payments are made available to recipients. Also, EBT cards are the primary method by which cash and special allowance benefit payments are made available to Temporary Assistance for Needy Families (TANF) recipients. Total benefit expenditures for SNAP for the fiscal year ended June 30, 2020 totaled $2.9 billion. Total benefit expenditures for TANF for the fiscal year ended June 30, 2020 totaled $151.7 million. Thirteen of the 86 CAO and district locations that issued EBT cards were selected for site testing in the current audit period. During our review of the physical security over EBT cards, we noted exceptions at twelve of the thirteen CAO and district locations selected for testing. These exceptions included the following: 1) The physical inventory count of EBT cards conducted did not reconcile to the inventory count in the EBT Card Tracking Database (1 location). 2) An employee without card creation access to the Electronic Payment Processing and Information Control (EPPIC) System created EBT cards according to the Daily Log from the EBT Card Tracking Database (3 district offices). 3) An employee listed on DHS?s Project Office master list as a card pinner for a site had not worked at the site during the fiscal year ended June 30, 2020 (1 district office). 4) EBT cards were created during non-business hours (2 district offices). 5) Failure to perform the following: ? Destroy used printer ribbon on the same day as new printer ribbon installation (2 locations); ? Maintain adequate segregation of duties when completing the Weekly Log in the EBT Card Tracking Database. The same employee returned the EBT cards and approved the Weekly Log (2 district offices and 2 locations); ? Retain legible EPPIC EBT Systems Application forms (paper and/or electronic copies) (1 district office); ? Create adequate written internal procedures for EBT Security for over the counter card mailings (3 district offices and 3 locations); ? Locate shipping manifest to support the EBT Shipments Verification Log (1 district office and 3 locations); ? Designate a manager or supervisor to the Alternate EBT Coordinator role (1 location); ? Ensure that coverage for card pinning and card creation is available until 5:00 PM each business day (1 district office and 2 locations); ? Only utilize the EBT card paper logs during an emergency (1 district office); ? Timely completion and submission of the EPPIC EBT Systems Application forms to the Office of Income Maintenance EBT Security (1 district office); Finding 2020 ? 005: (continued) ? Completion of the weekly approver entry field in the Weekly Log (2 district offices); ? Ensure the Form HS-764 Authorized Signatures field was completed with the caseworker?s and supervisor?s signatures (2 district offices); ? Maintain adequate security of pinning device (1 location). Criteria: The 2020 OMB Compliance Supplement, Part 4 ? Agency Program Requirements for the SNAP Cluster, Special Tests and Provisions ? N.3 EBT Card Security, states: The state is required to maintain adequate security over, and documentation/records for, EBT cards to prevent their theft, embezzlement, loss, damage, destruction, unauthorized transfer, negotiation, or use (7 CFR Section 274.8(b)(3)). 7 CFR Section 274.5, Record retention and forms security, states: (c) Accountable Documents. (1) EBT cards shall be considered accountable documents. The State agency shall provide the following minimum security and control procedures for these documents: i. Secure storage; ii. Access limited to authorized personnel; iii. Bulk inventory control records; iv. Subsequent control records maintained through the point of issuance or use; and v. Periodic review and validation of inventory controls and records by parties not otherwise involved in maintaining control records. 45 CFR Section 75.302 applicable to TANF states: (b) The financial management system of each non-Federal entity must provide for the following (see also ?75.361, 75.362, 75.363, 75.364, and 75.365): (4) Effective control over, and accountability for, all funds, property, and other assets. The non-Federal entity must adequately safeguard all assets and assure that they are used solely for authorized purposes. See ?75.303. Management Directive 325.12, Standards for Internal Control for Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book), published in September 2014. The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: Established policies and procedures were not followed consistently across CAO and district locations, which resulted in ineffective internal controls over EBT card security. Effect: Without adequate security controls over EBT cards, there exists the possibility of misappropriation and/or abuse. Finding 2020 ? 005: (continued) Recommendation: We recommend that DHS monitor EBT card security at CAO and district locations on a regular basis to improve consistency in the execution of documented policies and procedures. Agency Response: DHS agrees with the finding. Questioned Costs: The amount of questioned costs cannot be determined. The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Show full finding ▾
Full finding narrative

Department of Human Services Finding 2020 ? 005: CFDA #10.551 and 10.561 ? Supplemental Nutrition Assistance Program (SNAP) Cluster CFDA #93.558 ? Temporary Assistance for Needy Families A Material Weakness and Material Noncompliance Exist at the Department of Human Services Related to Electronic Benefits Transfer Card Security (A Similar Condition Was Noted in Prior Year Finding 2019-007) Federal Grant Number(s) and Year(s): 201PA405S2514 (10/01/2019 ? 9/30/2020), 191PA405S2514 (10/01/2018 ? 9/30/2019), 2001PATANF (10/01/2019 ? 9/30/2020), 1901PATANF (10/01/2018 ? 9/30/2019) Type of Finding: Material Weakness, Material Noncompliance Compliance Requirement: Special Tests and Provisions related to EBT Card Security Condition: During our audit of the Supplemental Nutrition Assistance Program (SNAP) administered by the Department of Human Services (DHS), we evaluated the security over Electronic Benefits Transfer (EBT) cards, which includes both the physical security of EBT cards during the issuance process at County Assistance Offices (CAO), as well as the handling of EBT cards returned from the United States Postal Service as undeliverable, or those that have been lost or stolen. EBT cards are the method by which SNAP benefit payments are made available to recipients. Also, EBT cards are the primary method by which cash and special allowance benefit payments are made available to Temporary Assistance for Needy Families (TANF) recipients. Total benefit expenditures for SNAP for the fiscal year ended June 30, 2020 totaled $2.9 billion. Total benefit expenditures for TANF for the fiscal year ended June 30, 2020 totaled $151.7 million. Thirteen of the 86 CAO and district locations that issued EBT cards were selected for site testing in the current audit period. During our review of the physical security over EBT cards, we noted exceptions at twelve of the thirteen CAO and district locations selected for testing. These exceptions included the following: 1) The physical inventory count of EBT cards conducted did not reconcile to the inventory count in the EBT Card Tracking Database (1 location). 2) An employee without card creation access to the Electronic Payment Processing and Information Control (EPPIC) System created EBT cards according to the Daily Log from the EBT Card Tracking Database (3 district offices). 3) An employee listed on DHS?s Project Office master list as a card pinner for a site had not worked at the site during the fiscal year ended June 30, 2020 (1 district office). 4) EBT cards were created during non-business hours (2 district offices). 5) Failure to perform the following: ? Destroy used printer ribbon on the same day as new printer ribbon installation (2 locations); ? Maintain adequate segregation of duties when completing the Weekly Log in the EBT Card Tracking Database. The same employee returned the EBT cards and approved the Weekly Log (2 district offices and 2 locations); ? Retain legible EPPIC EBT Systems Application forms (paper and/or electronic copies) (1 district office); ? Create adequate written internal procedures for EBT Security for over the counter card mailings (3 district offices and 3 locations); ? Locate shipping manifest to support the EBT Shipments Verification Log (1 district office and 3 locations); ? Designate a manager or supervisor to the Alternate EBT Coordinator role (1 location); ? Ensure that coverage for card pinning and card creation is available until 5:00 PM each business day (1 district office and 2 locations); ? Only utilize the EBT card paper logs during an emergency (1 district office); ? Timely completion and submission of the EPPIC EBT Systems Application forms to the Office of Income Maintenance EBT Security (1 district office); Finding 2020 ? 005: (continued) ? Completion of the weekly approver entry field in the Weekly Log (2 district offices); ? Ensure the Form HS-764 Authorized Signatures field was completed with the caseworker?s and supervisor?s signatures (2 district offices); ? Maintain adequate security of pinning device (1 location). Criteria: The 2020 OMB Compliance Supplement, Part 4 ? Agency Program Requirements for the SNAP Cluster, Special Tests and Provisions ? N.3 EBT Card Security, states: The state is required to maintain adequate security over, and documentation/records for, EBT cards to prevent their theft, embezzlement, loss, damage, destruction, unauthorized transfer, negotiation, or use (7 CFR Section 274.8(b)(3)). 7 CFR Section 274.5, Record retention and forms security, states: (c) Accountable Documents. (1) EBT cards shall be considered accountable documents. The State agency shall provide the following minimum security and control procedures for these documents: i. Secure storage; ii. Access limited to authorized personnel; iii. Bulk inventory control records; iv. Subsequent control records maintained through the point of issuance or use; and v. Periodic review and validation of inventory controls and records by parties not otherwise involved in maintaining control records. 45 CFR Section 75.302 applicable to TANF states: (b) The financial management system of each non-Federal entity must provide for the following (see also ?75.361, 75.362, 75.363, 75.364, and 75.365): (4) Effective control over, and accountability for, all funds, property, and other assets. The non-Federal entity must adequately safeguard all assets and assure that they are used solely for authorized purposes. See ?75.303. Management Directive 325.12, Standards for Internal Control for Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book), published in September 2014. The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: Established policies and procedures were not followed consistently across CAO and district locations, which resulted in ineffective internal controls over EBT card security. Effect: Without adequate security controls over EBT cards, there exists the possibility of misappropriation and/or abuse. Finding 2020 ? 005: (continued) Recommendation: We recommend that DHS monitor EBT card security at CAO and district locations on a regular basis to improve consistency in the execution of documented policies and procedures. Agency Response: DHS agrees with the finding. Questioned Costs: The amount of questioned costs cannot be determined. The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Corrective Action Plan

To comply with the OIM EBT Procedures Manual, County Assistance Offices (CAOs) and District Offices will review and update their internal procedures for over the counter card mailings as needed. Findings will be reported to each area?s Staff Assistant. CAOs and district offices will be instructed to review their pinning list and card creator list to ensure the names are correct and ensure there is adequate coverage from opening to close, including lunch and breaks. Findings will be reported to each area?s Staff Assistant. A message will be communicated via the End of the Week email reminding CAOs that EBT cards are only to be made until 5:00 pm. CAOs and district offices will be instructed to only use EBT card paper logs in cases of emergency. All card information should be recorded in the EBT card tracking database. CAOs and district offices will be instructed to review EBT manual Executive Director Responsibility; when an EBT staff separates from the CAO, the staff must be removed from the EBT list within 24 hours. The Division of Corrective Action (DCA) continues to monitor EBT security including the following: ? Correct count procedures of cards ? Secure storage of card and card machines ? Interviewing EBT coordinators ? Interviewing EBT card makers ? Conduct monitoring both announce and unannounced CAOs are required to complete the mandated annual EBT card security overview, a web-based training. The EBT Project officer will send out a yearly reminder to ensure all staff have completed the training. The training covers all aspects of EBT cards including but not limited to physical inventory count, card creation availability, who signs the HS764, ribbon destruction, segregation of duties for completing the weekly log, and approving the weekly log. The OIM EBT Procedure Manual will be updated to reflect that EBT card receipts should be maintained for four years in a secure location at the CAO and easily accessible and available during an audit or review. The staff assistant to the Director of Operations will email the area staff assistants the list of exceptions. The area staff assistants will address each exception with the CAO to take the necessary actions to ensure safeguards are in place to prevent future exceptions. The necessary action includes trainings, review of EBT manual and internal reviews, as needed. Anticipated Completion Date: 04/30/2021 Contact Person: Jeanette Coulston, Income Maintenance Program Representative

Prior Finding References

2019-007

About Special Tests and Provisions →
2020-006
Subrecipient Monitoring
REPEATQUESTIONED COSTS

During the fiscal year ended June 30, 2020, the Department of Human Services (DHS) paid $74.8 million in Temporary Assistance for Needy Families (TANF) funding to subrecipients within the New Directions, Cash Grants, and Alternatives to Abortion appropriations (or 14.9 percent) out of total federal TANF expenditures of $501.9 million reported on the June 30, 2020 Schedule of Expenditures of Federal Awards. Our testing of DHS?s during-the-award monitoring of subrecipients for the fiscal year ended June 30, 2020 disclosed that DHS performed on-site monitoring for all 12 subrecipients selected for testing. The on-site monitoring that was performed consisted of reviews of program operations including design, data entry accuracy and timeliness, case management analysis, and program payment performance goals. The on-site monitoring also included a review of a sample of TANF recipient case files to ensure that the recipients? TANF activities were documented and accurately entered in the Commonwealth?s Workforce Development System. However, DHS?s monitoring procedures for the 12 subrecipients were not adequate as they did not include a review or monitoring of subrecipient financial records, which would provide an assessment of a subrecipient?s compliance with applicable federal regulations. Although DHS?s monitoring procedures include reviewing subrecipient completed questionnaires for selected subrecipients that had questions related to financial matters, DHS monitors did not review subrecipient financial records. For example, DHS did not perform procedures to ensure subrecipient invoices agreed to the books and records of the subrecipient and that the records were adequate to support the allowability of costs paid by DHS during the award period. In addition, DHS?s monitoring procedures did not include an evaluation of the operating effectiveness of DHS subrecipient procedures to monitor Single Audits and any related findings. In addition to the 12 subrecipients noted above, we followed up on one subrecipient identified in the prior year finding as not being on-site monitored by DHS when the risk assessment warranted on-site monitoring. Our follow-up on DHS?s monitoring of this subrecipient during the current audit period disclosed that DHS personnel prepared a risk assessment but did not conduct any on-site monitoring of this subrecipient. Since no on-site monitoring occurred, internal control weaknesses, noncompliance, and questioned costs may have existed and remained undetected during the current audit period. This subrecipient received approximately $1.0 million of TANF funds during the fiscal year ended June 30, 2020. Criteria: 45 CFR Section 75.352, Requirements for pass-through entities, states: (d) Monitor the activities of the subrecipient as necessary to ensure that the subaward is used for authorized purposes, in compliance with Federal statutes, regulations, and the terms and conditions of the subaward; and that subaward performance goals are achieved. Pass-through entity monitoring of the subrecipient must include: (1) Reviewing financial and programmatic reports required by the pass-through entity. Finding 2020 ? 006: (continued) (2) Following-up and ensuring that the subrecipient takes timely and appropriate action on all deficiencies pertaining to the Federal award provided to the subrecipient from the pass-through entity detected through audits, on-site reviews, and other means. (3) Issuing a management decision for audit findings pertaining to the Federal award provided to the subrecipient... 2 CFR Section 200.331, Requirements for Pass-through Entities, states in part: Pass-through entity monitoring of the subrecipient must include: (e) Depending upon the pass-through entity's assessment of risk posed by the subrecipient (as described in paragraph (b) of this section), the following monitoring tools may be useful for the pass-through entity to ensure proper accountability and compliance with program requirements and achievement of performance goals: (1) Providing subrecipients with training and technical assistance on program-related matters; and (2) Performing on-site reviews of the subrecipient's program operations; (3) Arranging for agreed-upon-procedures engagements as described in ?200.425 Audit services. Management Directive 325.12, Standards for Internal Control for Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book), published in September 2014. The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: DHS has not implemented adequate during-the-award monitoring procedures of subrecipients to include testing of the financial records and the subrecipients? monitoring of Single Audits sufficient to ensure compliance with federal regulations. In addition, as indicated in DHS?s corrective action plan for the prior year finding, DHS planned to implement new procedures to be used during the on-site monitoring performed during the current audit period. However, as indicated above, the updated procedures were not implemented for the current audit period. Regarding the aforementioned subrecipient that was not subject to on-site monitoring, DHS personnel stated that no on-site monitoring was performed on this subrecipient due to staffing issues. Effect: TANF subrecipients could be operating in noncompliance with federal regulations without timely detection and correction by DHS management. Recommendation: DHS should strengthen its controls to ensure during-the-award monitoring of TANF subrecipients includes procedures to ensure that subrecipients are in compliance with applicable federal regulations, including ensuring that all required Single Audits were obtained by all DHS subrecipients. Agency Response: DHS agrees with the finding. Questioned Costs: The amount of questioned costs cannot be determined. The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Show full finding ▾
Full finding narrative

Department of Human Services Finding 2020 ? 006: CFDA #93.558 ? Temporary Assistance for Needy Families Department of Human Services Did Not Validate Financial Information as Part of Its On-Site Monitoring of Temporary Assistance for Needy Families Subrecipients (A Similar Condition Was Noted in Prior Year Finding 2019-008) Federal Grant Number(s) and Year(s): 2001PATANF (10/01/2019 ? 9/30/2020), 1901PATANF (10/01/2018 ? 9/30/2019) Type of Finding: Significant Deficiency, Noncompliance Compliance Requirement: Subrecipient Monitoring Condition: During the fiscal year ended June 30, 2020, the Department of Human Services (DHS) paid $74.8 million in Temporary Assistance for Needy Families (TANF) funding to subrecipients within the New Directions, Cash Grants, and Alternatives to Abortion appropriations (or 14.9 percent) out of total federal TANF expenditures of $501.9 million reported on the June 30, 2020 Schedule of Expenditures of Federal Awards. Our testing of DHS?s during-the-award monitoring of subrecipients for the fiscal year ended June 30, 2020 disclosed that DHS performed on-site monitoring for all 12 subrecipients selected for testing. The on-site monitoring that was performed consisted of reviews of program operations including design, data entry accuracy and timeliness, case management analysis, and program payment performance goals. The on-site monitoring also included a review of a sample of TANF recipient case files to ensure that the recipients? TANF activities were documented and accurately entered in the Commonwealth?s Workforce Development System. However, DHS?s monitoring procedures for the 12 subrecipients were not adequate as they did not include a review or monitoring of subrecipient financial records, which would provide an assessment of a subrecipient?s compliance with applicable federal regulations. Although DHS?s monitoring procedures include reviewing subrecipient completed questionnaires for selected subrecipients that had questions related to financial matters, DHS monitors did not review subrecipient financial records. For example, DHS did not perform procedures to ensure subrecipient invoices agreed to the books and records of the subrecipient and that the records were adequate to support the allowability of costs paid by DHS during the award period. In addition, DHS?s monitoring procedures did not include an evaluation of the operating effectiveness of DHS subrecipient procedures to monitor Single Audits and any related findings. In addition to the 12 subrecipients noted above, we followed up on one subrecipient identified in the prior year finding as not being on-site monitored by DHS when the risk assessment warranted on-site monitoring. Our follow-up on DHS?s monitoring of this subrecipient during the current audit period disclosed that DHS personnel prepared a risk assessment but did not conduct any on-site monitoring of this subrecipient. Since no on-site monitoring occurred, internal control weaknesses, noncompliance, and questioned costs may have existed and remained undetected during the current audit period. This subrecipient received approximately $1.0 million of TANF funds during the fiscal year ended June 30, 2020. Criteria: 45 CFR Section 75.352, Requirements for pass-through entities, states: (d) Monitor the activities of the subrecipient as necessary to ensure that the subaward is used for authorized purposes, in compliance with Federal statutes, regulations, and the terms and conditions of the subaward; and that subaward performance goals are achieved. Pass-through entity monitoring of the subrecipient must include: (1) Reviewing financial and programmatic reports required by the pass-through entity. Finding 2020 ? 006: (continued) (2) Following-up and ensuring that the subrecipient takes timely and appropriate action on all deficiencies pertaining to the Federal award provided to the subrecipient from the pass-through entity detected through audits, on-site reviews, and other means. (3) Issuing a management decision for audit findings pertaining to the Federal award provided to the subrecipient... 2 CFR Section 200.331, Requirements for Pass-through Entities, states in part: Pass-through entity monitoring of the subrecipient must include: (e) Depending upon the pass-through entity's assessment of risk posed by the subrecipient (as described in paragraph (b) of this section), the following monitoring tools may be useful for the pass-through entity to ensure proper accountability and compliance with program requirements and achievement of performance goals: (1) Providing subrecipients with training and technical assistance on program-related matters; and (2) Performing on-site reviews of the subrecipient's program operations; (3) Arranging for agreed-upon-procedures engagements as described in ?200.425 Audit services. Management Directive 325.12, Standards for Internal Control for Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book), published in September 2014. The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: DHS has not implemented adequate during-the-award monitoring procedures of subrecipients to include testing of the financial records and the subrecipients? monitoring of Single Audits sufficient to ensure compliance with federal regulations. In addition, as indicated in DHS?s corrective action plan for the prior year finding, DHS planned to implement new procedures to be used during the on-site monitoring performed during the current audit period. However, as indicated above, the updated procedures were not implemented for the current audit period. Regarding the aforementioned subrecipient that was not subject to on-site monitoring, DHS personnel stated that no on-site monitoring was performed on this subrecipient due to staffing issues. Effect: TANF subrecipients could be operating in noncompliance with federal regulations without timely detection and correction by DHS management. Recommendation: DHS should strengthen its controls to ensure during-the-award monitoring of TANF subrecipients includes procedures to ensure that subrecipients are in compliance with applicable federal regulations, including ensuring that all required Single Audits were obtained by all DHS subrecipients. Agency Response: DHS agrees with the finding. Questioned Costs: The amount of questioned costs cannot be determined. The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Corrective Action Plan

New Directions The Office of Income Maintenance (OIM) updated agency monitoring personnel checklists in FY 2019-20 to include testing various financial controls of select grantees based on their Risk Assessment scores. We had planned to move forward with a portion of on-site monitoring last year, however, since March 16, 2020, agency personnel have been restricted from travel, making on-site monitoring not feasible. Once the state provides travel guidance at the conclusion of the health emergency and we have a recovery plan in place as an agency, we will be able to perform this monitoring. Anticipated Completion Date: 06/30/2021 Contact People: Michael Varleta, Dir., Div. of Mgmt. and Budget, OIM; Joel O?Donnell, Dir., Bureau of Prgm. Support, OIM Alternatives to Abortion The Office of Policy Development (OPD) completed the risk assessments for FY 20-21. Monitoring will prioritize subrecipients receiving a ?high risk? designation and/or those who did not receive monitoring during the last fiscal year. Alternatives to Abortion was again identified to receive monitoring. Due to COVID-19, monitoring will be conducted virtually. Anticipated Completion Date: 03/31/2021 Contact Person: Jazmin Cartwright, Grants and Policy Splst., OPD

Prior Finding References

2019-008

About Subrecipient Monitoring →
2020-007
Subrecipient Monitoring
MATERIAL WEAKNESSREPEATQUESTIONED COSTS

The Department of Human Services? (DHS) Office of Children, Youth, and Families (OCYF) performs two types of during-the-award monitoring of its 67 subrecipient County Children and Youth Agencies (CCYAs). One group within OCYF performs on-site inspections to support its reissuance of licenses for all 67 CCYAs to whom DHS subgrants funds to perform Foster Care, Adoption Assistance services, and Temporary Assistance for Needy Families (TANF) Child Welfare. These inspections primarily focus on health, safety, and performance issues, and each on-site inspection is documented on an Annual Survey and Evaluation Summary. A license, or certificate of compliance, is issued for a period of one year if the results of the on-site inspection determine the entity is in compliance with statutes, ordinances, and regulations. In addition, a separate group within DHS?s OCYF performs Title IV-E Quality Assurance Compliance Reviews which primarily focus on eligibility and allowability. These two types of on-site monitoring visits are not performed at the same time. To test DHS?s licensing/inspections and Quality Assurance Compliance Reviews in the current year, we selected 13 of the 67 CCYAs receiving Foster Care, Adoption Assistance, and TANF funds. Our current year testing of the on-site licensing inspections disclosed the following exceptions: ? Four of the 13 on-site inspections of the 13 CCYAs tested were either not reviewed and approved timely, or not reviewed and approved at all, by a supervisor and a regional director. Three of the inspections were approved between 1 and 89 days after the expiration of the prior license, and the other inspection was not reviewed and approved by a supervisor or regional director. Also, as part of our testing of monitoring, we noted that DHS did not have adequate procedures in place to determine if CCYAs were monitoring their subrecipients. Specifically, DHS did not perform procedures to determine if CCYAs were monitoring Single Audits of its subrecipients and evaluating the follow-up of any findings, or that CCYAs were only paying for allowable services. Foster Care program payments made by DHS to its 67 CCYA subrecipients during the fiscal year ended June 30, 2020 were $216.1 million, or 90.8 percent of total Foster Care expenditures of $238.1 million reported on the June 30, 2020 Schedule of Expenditures of Federal Awards (SEFA). Adoption Assistance program payments made by DHS to its Finding 2020 ? 007: (continued) 67 CCYA subrecipients during the fiscal year ended June 30, 2020 were $95.0 million, or 74.4 percent of total Adoption Assistance expenditures of $127.7 million reported on the June 30, 2020 SEFA. TANF Child Welfare program payments made by DHS to its 67 CCYA subrecipients during the fiscal year ended June 30, 2020 were $35.6 million, or 7.1 percent of total TANF expenditures of $501.9 million reported on the June 30, 2020 SEFA. Criteria: 45 CFR Section 75.352, applicable to TANF, Foster Care, and Adoption Assistance states: (d) Monitor the activities of the subrecipient as necessary to ensure that the subaward is used for authorized purposes, in compliance with Federal statutes, regulations, and the terms and conditions of the subaward; and that subaward performance goals are achieved. Pass-through entity monitoring of the subrecipient must include: (1) Reviewing financial and programmatic reports required by the pass-through entity. (2) Following-up and ensuring that the subrecipient takes timely and appropriate action on all deficiencies pertaining to the Federal award provided to the subrecipient from the pass-through entity detected through audits, on-site reviews, and other means. (3) Issuing a management decision for audit findings pertaining to the Federal award provided to the subrecipient? PA Code Title 55, Chapter 20, Licensure or Approval of Facilities and Agencies, Section 20.51 states: A certificate of compliance will be issued to the legal entity by the Department if, after an inspection by an authorized agent of the Department, it is determined that requirements for a certificate of compliance are met. In addition, PA Code Title 55, Chapter 20, Section 20.52 states: If, during an inspection, authorized agents of the Department observe items of noncompliance with licensure or approval regulations, the legal entity shall submit an acceptable written plan to correct each noncompliance item and shall establish an acceptable period of time to correct these items. Management Directive 325.12, Standards for Internal Control for Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book), published in September 2014. The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: As noted in the Corrective Action Plan for prior year Finding 2019 ? 009, DHS started tracking the timeliness of the annual on-site licensing inspections to ensure that inspections were timely completed, reviewed, and approved. However, as noted above, the on-site inspections were not reviewed and approved by a supervisor or regional director prior to the expiration of the prior license. DHS personnel indicated that the four on-site inspections were not timely reviewed and approved by a supervisor or a regional director due to staffing issues, the COVID-19 pandemic, as well as an oversight by DHS regarding the completion of the on-site inspections. DHS believes that its current monitoring procedures to determine subrecipient eligibility, monitor programmatic operations, review subrecipient audits, and review subrecipient agreed-upon-procedure reports are sufficient to effectively monitor its subrecipients or contractors. Finding 2020 ? 007: (continued) Effect: DHS OCYF?s failure to timely review and approve inspection reports before the expiration of the prior license allowed the CCYAs to operate without a proper license for an extended period of time. Also, since DHS did not determine if CCYAs were monitoring their subrecipients, CCYAs could be operating in noncompliance with federal regulations without timely detection and correction by DHS management. Recommendation: DHS?s OCYF should strengthen its controls to ensure monitoring and inspections of Foster Care, Adoption Assistance, and TANF subrecipients are performed and reviewed by management on a timely basis and include procedures to ensure CCYAs are monitoring their subrecipients or contractors. Agency Response: DHS agrees with the finding. Questioned Costs: The amount of questioned costs cannot be determined. The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Show full finding ▾
Full finding narrative

Department of Human Services Finding 2020 ? 007: CFDA #93.558 ? Temporary Assistance for Needy Families CFDA #93.658 ? Foster Care ? Title IV-E (including COVID-19) CFDA #93.659 ? Adoption Assistance (including COVID-19) Material Weaknesses and Material Noncompliance Exist in Monitoring of Foster Care, Adoption Assistance, and Temporary Assistance for Needy Families Subrecipients by the Department of Human Services? Office of Children, Youth, and Families (A Similar Condition Was Noted in Prior Year Finding 2019-009) Federal Grant Number(s) and Year(s): 2001PATANF (10/01/2019 ? 9/30/2020), 1901PATANF (10/01/2018 ? 9/30/2019), 2001PAFOST (10/01/2019 ? 9/30/2020), 1901PAFOST (10/01/2018 ? 9/30/2019), 2001PAADPT (10/01/2019 ? 9/30/2020), 1901PAADPT (10/01/2018 ? 9/30/2019) Type of Finding: Material Weakness, Material Noncompliance Compliance Requirement: Subrecipient Monitoring Condition: The Department of Human Services? (DHS) Office of Children, Youth, and Families (OCYF) performs two types of during-the-award monitoring of its 67 subrecipient County Children and Youth Agencies (CCYAs). One group within OCYF performs on-site inspections to support its reissuance of licenses for all 67 CCYAs to whom DHS subgrants funds to perform Foster Care, Adoption Assistance services, and Temporary Assistance for Needy Families (TANF) Child Welfare. These inspections primarily focus on health, safety, and performance issues, and each on-site inspection is documented on an Annual Survey and Evaluation Summary. A license, or certificate of compliance, is issued for a period of one year if the results of the on-site inspection determine the entity is in compliance with statutes, ordinances, and regulations. In addition, a separate group within DHS?s OCYF performs Title IV-E Quality Assurance Compliance Reviews which primarily focus on eligibility and allowability. These two types of on-site monitoring visits are not performed at the same time. To test DHS?s licensing/inspections and Quality Assurance Compliance Reviews in the current year, we selected 13 of the 67 CCYAs receiving Foster Care, Adoption Assistance, and TANF funds. Our current year testing of the on-site licensing inspections disclosed the following exceptions: ? Four of the 13 on-site inspections of the 13 CCYAs tested were either not reviewed and approved timely, or not reviewed and approved at all, by a supervisor and a regional director. Three of the inspections were approved between 1 and 89 days after the expiration of the prior license, and the other inspection was not reviewed and approved by a supervisor or regional director. Also, as part of our testing of monitoring, we noted that DHS did not have adequate procedures in place to determine if CCYAs were monitoring their subrecipients. Specifically, DHS did not perform procedures to determine if CCYAs were monitoring Single Audits of its subrecipients and evaluating the follow-up of any findings, or that CCYAs were only paying for allowable services. Foster Care program payments made by DHS to its 67 CCYA subrecipients during the fiscal year ended June 30, 2020 were $216.1 million, or 90.8 percent of total Foster Care expenditures of $238.1 million reported on the June 30, 2020 Schedule of Expenditures of Federal Awards (SEFA). Adoption Assistance program payments made by DHS to its Finding 2020 ? 007: (continued) 67 CCYA subrecipients during the fiscal year ended June 30, 2020 were $95.0 million, or 74.4 percent of total Adoption Assistance expenditures of $127.7 million reported on the June 30, 2020 SEFA. TANF Child Welfare program payments made by DHS to its 67 CCYA subrecipients during the fiscal year ended June 30, 2020 were $35.6 million, or 7.1 percent of total TANF expenditures of $501.9 million reported on the June 30, 2020 SEFA. Criteria: 45 CFR Section 75.352, applicable to TANF, Foster Care, and Adoption Assistance states: (d) Monitor the activities of the subrecipient as necessary to ensure that the subaward is used for authorized purposes, in compliance with Federal statutes, regulations, and the terms and conditions of the subaward; and that subaward performance goals are achieved. Pass-through entity monitoring of the subrecipient must include: (1) Reviewing financial and programmatic reports required by the pass-through entity. (2) Following-up and ensuring that the subrecipient takes timely and appropriate action on all deficiencies pertaining to the Federal award provided to the subrecipient from the pass-through entity detected through audits, on-site reviews, and other means. (3) Issuing a management decision for audit findings pertaining to the Federal award provided to the subrecipient? PA Code Title 55, Chapter 20, Licensure or Approval of Facilities and Agencies, Section 20.51 states: A certificate of compliance will be issued to the legal entity by the Department if, after an inspection by an authorized agent of the Department, it is determined that requirements for a certificate of compliance are met. In addition, PA Code Title 55, Chapter 20, Section 20.52 states: If, during an inspection, authorized agents of the Department observe items of noncompliance with licensure or approval regulations, the legal entity shall submit an acceptable written plan to correct each noncompliance item and shall establish an acceptable period of time to correct these items. Management Directive 325.12, Standards for Internal Control for Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book), published in September 2014. The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: As noted in the Corrective Action Plan for prior year Finding 2019 ? 009, DHS started tracking the timeliness of the annual on-site licensing inspections to ensure that inspections were timely completed, reviewed, and approved. However, as noted above, the on-site inspections were not reviewed and approved by a supervisor or regional director prior to the expiration of the prior license. DHS personnel indicated that the four on-site inspections were not timely reviewed and approved by a supervisor or a regional director due to staffing issues, the COVID-19 pandemic, as well as an oversight by DHS regarding the completion of the on-site inspections. DHS believes that its current monitoring procedures to determine subrecipient eligibility, monitor programmatic operations, review subrecipient audits, and review subrecipient agreed-upon-procedure reports are sufficient to effectively monitor its subrecipients or contractors. Finding 2020 ? 007: (continued) Effect: DHS OCYF?s failure to timely review and approve inspection reports before the expiration of the prior license allowed the CCYAs to operate without a proper license for an extended period of time. Also, since DHS did not determine if CCYAs were monitoring their subrecipients, CCYAs could be operating in noncompliance with federal regulations without timely detection and correction by DHS management. Recommendation: DHS?s OCYF should strengthen its controls to ensure monitoring and inspections of Foster Care, Adoption Assistance, and TANF subrecipients are performed and reviewed by management on a timely basis and include procedures to ensure CCYAs are monitoring their subrecipients or contractors. Agency Response: DHS agrees with the finding. Questioned Costs: The amount of questioned costs cannot be determined. The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Corrective Action Plan

The OCYF Regional Director is currently meeting with the Regional Offices involved to address and correct the situation. OCYF Regional Offices would be adhering to the DHS policy when a licensing inspection summary (LIS) is written within 15 business days of the last day of the inspection. Counties will have 10 calendar days to respond to our plan of correction (POC) and that POC needs reviewed by the regional office within 10 business days for compliance. This LIS will be sent to Harrisburg for processing. OCYF Regional Director staff will be doing periodic checks on a quarterly basis to verify the documentation is submitted timely. Concerning the monitoring of subrecipients: OCYF is working on a strategy to strengthen controls to ensure CCYAs are monitoring their subrecipients and contractors. Updated policies and procedures have been identified and implemented effective September 30, 2020. Quality Assurance reviews are planned to resume using alternative techniques as well. Anticipated Completion Date: 06/30/2021 Contact Person: Tia Petrovitz, Fiscal Management Specialist 4

Prior Finding References

2019-009

About Subrecipient Monitoring →
2020-008
Activities Allowed or Unallowed / Cost Allowability
QUESTIONED COSTS

The Temporary Assistance for Needy Families (TANF) Program, administered by the Department of Human Services? (DHS) Office of Children, Youth, and Families (OCYF), provides funding to each of its 67 subrecipient County Children and Youth Agencies (CCYAs) for Child Welfare services. The annual financial audit of the Commonwealth of Pennsylvania?s Comprehensive Annual Financial Report for the fiscal year ended June 30, 2020, included testing of a TANF Child Welfare invoice submitted to DHS by a CCYA for reimbursement of Child Welfare services. Our review of the invoice disclosed that the CCYA overcharged DHS $2,200 for the Child Welfare services provided, and this overcharge was not identified during the DHS review, approval, and payment of the invoice. TANF Child Welfare program payments made by DHS to its 67 CCYA subrecipients during the fiscal year ended June 30, 2020 were $35.6 million, or 7.1 percent of total TANF expenditures of $501.9 million reported on the June 30, 2020 Schedule of Expenditures of Federal Awards. Criteria: 45 CFR Section 75.303(a), Internal controls, states: The non-Federal entity must: Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in ?Standards for Internal Control in the Federal Government? issued by the Comptroller General of the United States or the ?Internal Control Integrated Framework?, issued by the Committee of the Sponsoring Organizations of the Treadway Commission (COSO). 45 CFR Section 75.352, applicable to TANF states: (d) Monitor the activities of the subrecipient as necessary to ensure that the subaward is used for authorized purposes, in compliance with Federal statutes, regulations, and the terms and conditions of the subaward; and that subaward performance goals are achieved. Management Directive 325.12, Standards for Internal Control for Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book), published in September 2014. The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Finding 2020 ? 008: (continued) Cause: DHS did not have adequate procedures in place to ensure that the Child Welfare services reimbursements paid by DHS to the CCYAs were accurate. DHS personnel indicated that the overpayment made by DHS was due to a key entry error of the rate on the invoice prepared by CCYA personnel for the service provided. The error was not detected by CCYA personnel prior to submitting the invoice to DHS for reimbursement, or by DHS personnel prior to DHS reimbursing the CCYA for the invoice. Effect: Since DHS?s procedures were not adequate to ensure that the services billed by the CCYAs were properly reimbursed by DHS for the correct amount of Child Welfare services provided, DHS was overcharged, resulting in noncompliance and questioned costs of $2,200. Recommendation: We recommend that DHS?s OCYF should strengthen its procedures and controls to ensure that reimbursements made for services billed by the CCYAs for Child Welfare services are accurate and include the correct rate. Controls should ensure that any errors on invoices submitted for reimbursement are timely detected by DHS employees in the normal course of their review, approval, and payment of invoices. Agency Response: DHS agrees with the finding. Questioned Costs: $2,200 for CFDA #93.558 The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Show full finding ▾
Full finding narrative

Department of Human Services Finding 2020 ? 008: CFDA #93.558 ? Temporary Assistance for Needy Families A Significant Deficiency and Noncompliance Exist in the Review and Approval of Temporary Assistance for Needy Families Subrecipient Invoices by the Department of Human Services? Office of Children, Youth, and Families Federal Grant Number(s) and Year(s): 1901PATANF (10/01/2018 ? 9/30/2019) Type of Finding: Significant Deficiency, Noncompliance Compliance Requirements: Activities Allowed or Unallowed, Allowable Costs/Cost Principles Condition: The Temporary Assistance for Needy Families (TANF) Program, administered by the Department of Human Services? (DHS) Office of Children, Youth, and Families (OCYF), provides funding to each of its 67 subrecipient County Children and Youth Agencies (CCYAs) for Child Welfare services. The annual financial audit of the Commonwealth of Pennsylvania?s Comprehensive Annual Financial Report for the fiscal year ended June 30, 2020, included testing of a TANF Child Welfare invoice submitted to DHS by a CCYA for reimbursement of Child Welfare services. Our review of the invoice disclosed that the CCYA overcharged DHS $2,200 for the Child Welfare services provided, and this overcharge was not identified during the DHS review, approval, and payment of the invoice. TANF Child Welfare program payments made by DHS to its 67 CCYA subrecipients during the fiscal year ended June 30, 2020 were $35.6 million, or 7.1 percent of total TANF expenditures of $501.9 million reported on the June 30, 2020 Schedule of Expenditures of Federal Awards. Criteria: 45 CFR Section 75.303(a), Internal controls, states: The non-Federal entity must: Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in ?Standards for Internal Control in the Federal Government? issued by the Comptroller General of the United States or the ?Internal Control Integrated Framework?, issued by the Committee of the Sponsoring Organizations of the Treadway Commission (COSO). 45 CFR Section 75.352, applicable to TANF states: (d) Monitor the activities of the subrecipient as necessary to ensure that the subaward is used for authorized purposes, in compliance with Federal statutes, regulations, and the terms and conditions of the subaward; and that subaward performance goals are achieved. Management Directive 325.12, Standards for Internal Control for Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book), published in September 2014. The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Finding 2020 ? 008: (continued) Cause: DHS did not have adequate procedures in place to ensure that the Child Welfare services reimbursements paid by DHS to the CCYAs were accurate. DHS personnel indicated that the overpayment made by DHS was due to a key entry error of the rate on the invoice prepared by CCYA personnel for the service provided. The error was not detected by CCYA personnel prior to submitting the invoice to DHS for reimbursement, or by DHS personnel prior to DHS reimbursing the CCYA for the invoice. Effect: Since DHS?s procedures were not adequate to ensure that the services billed by the CCYAs were properly reimbursed by DHS for the correct amount of Child Welfare services provided, DHS was overcharged, resulting in noncompliance and questioned costs of $2,200. Recommendation: We recommend that DHS?s OCYF should strengthen its procedures and controls to ensure that reimbursements made for services billed by the CCYAs for Child Welfare services are accurate and include the correct rate. Controls should ensure that any errors on invoices submitted for reimbursement are timely detected by DHS employees in the normal course of their review, approval, and payment of invoices. Agency Response: DHS agrees with the finding. Questioned Costs: $2,200 for CFDA #93.558 The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Corrective Action Plan

OCYF will reiterate to staff to review the amount of allowable expenditures on the TANF invoices prior to payment. OCYF staff review every TANF invoice that comes into the resource account for accuracy. This entails looking at the children?s names, service dates, type of service and allowable TANF expenditures. Calculations on the spreadsheet are verified to find errors and ensure accurate totals. Once the review is complete, the fiscal staff enters the completed invoice into a spreadsheet and shared files to ensure there are no duplications. On a quarterly basis, OCYF completes Quality Assurance (QA) onsite audits of TANF cases. The QA team selects a random sample of cases from the list of TANF children invoiced and makes plans with the county to go onsite and review supporting documentation. The baseline is to look at five children from the approved TANF invoices and look at them for a six-month period (Period Under Review - PUR). However, if the compliance rate in the prior review was 80% or less, an additional five cases are selected for testing. Placement services are prioritized above In-Home services due to the amount of money involved. Detailed procedures are available upon request. Anticipated Completion Date: 03/31/2021 Contact Person: Tia Petrovitz, Fiscal Management Specialist 4

About Activities Allowed or Unallowed, Allowable Costs / Cost Principles →
2020-009
Cash Management / Subrecipient Monitoring
MATERIAL WEAKNESSREPEATQUESTIONED COSTS

Our examination of the Department of Human Services? (DHS) procedures for monitoring Social Services Block Grant (SSBG) subrecipients revealed that DHS did not adequately monitor the SSBG Mental Health, Homeless Services, Child Welfare, Domestic Violence, Rape Crisis, Legal Services, and Family Planning subrecipients to ensure that SSBG awards are used in compliance with laws and regulations, which include allowable costs, period of performance, and other requirements. The inadequately monitored subrecipients received $39.6 million (or approximately 43 percent) of total SSBG program expenditures of $91.4 million on the Schedule of Expenditures of Federal Awards (SEFA). While we did note that DHS adequately monitored three of the 48 Mental Health County/County Joinder subrecipients which included Mental Health and Child Welfare services, this coverage is not adequate. In addition, our review of the risk assessments completed for all of the aforementioned subrecipients identified several instances where subrecipient monitoring was warranted but was not conducted. We also determined that the Homeless Services program subrecipients that received SSBG funding and were not adequately monitored by DHS personnel also received $1,983,000 in Block Grants for Prevention and Treatment of Substance Abuse (SABG) funding during the fiscal year ended June 30, 2020. Total SABG expenditures on the current SEFA were $72.8 million. In addition, for the compliance requirement related to cash management, we noted that DHS advanced funds to SSBG subrecipients in five of nine program areas, representing $39.6 million (or approximately 43 percent) of SSBG program expenditures, without adequately monitoring the reasonableness of the subrecipient cash balances. In particular, for the Legal Services components of the SSBG program, DHS advanced funds to subrecipients on a monthly basis. For program areas related to Mental Health, Intellectual Disabilities, Homeless Services, and Child Welfare, DHS advanced funds to subrecipients on a quarterly basis. Also, we noted $1,983,000 of SABG funds were advanced under the Homeless Services program area without adequately monitoring the reasonableness of the subrecipient cash balances. Our inquiries with applicable DHS program administrators disclosed that DHS did not adequately monitor the five program areas? subrecipients for cash management compliance either at the time of payment or at any other time during the fiscal year ended June 30, 2020. Furthermore, while Single Audits of SSBG and SABG subrecipients are to be conducted each year, this auditing activity does not compensate for the lack of during-the-award program monitoring, since the timing, focus, and scope of subrecipient auditing activities after year end are different than compliance monitoring to be performed by program officials during the year. Criteria: 45 CFR Section 75.352, Requirements for pass-through entities, states: (d) Monitor the activities of the subrecipient as necessary to ensure that the subaward is used for authorized purposes, in compliance with Federal statutes, regulations, and the terms and conditions of the subaward; and that subaward performance goals are achieved. Pass-through entity monitoring of the subrecipient must include: Finding 2020 ? 009: (continued) (1) Reviewing financial and performance reports required by the pass-through entity. (2) Following-up and ensuring that the subrecipient takes timely and appropriate action on all deficiencies pertaining to the Federal award provided to the subrecipient from the pass-through entity detected through audits, on-site reviews, and other means. (3) Issuing a management decision for audit findings pertaining to the Federal award provided to the subrecipient from the pass-through entity? (e) Depending upon the pass-through entity's assessment of risk posed by the subrecipient (as described in paragraph (b) of this section), the following monitoring tools may be useful for the pass-through entity to ensure proper accountability and compliance with program requirements and achievement of performance goals: (1) Providing subrecipients with training and technical assistance on program-related matters; and (2) Performing on-site reviews of the subrecipient's program operations; (3) Arranging for agreed-upon-procedures engagements as described in ?75.425 (Audit services). 45 CFR Section 75.305(b)(1), applicable to payments to subrecipients, states in part: ?Advance payments to a non-Federal entity must be limited to the minimum amounts needed and be timed to be in accordance with the actual, immediate cash requirements of the non-Federal entity in carrying out the purpose of the approved program or project. The timing and amount of advance payments must be as close as is administratively feasible to the actual disbursements by the non-Federal entity for direct program or project costs and the proportionate share of any allowable indirect costs. The non-Federal entity must make timely payment to contractors in accordance with the contract provisions. Management Directive 325.12, Standards for Internal Control in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book), published in September 2014. The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: DHS management indicated that risk assessment and monitoring documents were created for use during on-site monitoring of SSBG and SABG subrecipients. However, due to staffing issues and the COVID-19 pandemic, on-site monitoring was not performed for all SSBG and SABG subrecipients. Consistent with prior year audits, DHS management noted that there have been no changes to the payment methodology for the Legal Services, Homeless Services, Mental Health, Intellectual Disabilities, and Child Welfare components of SSBG. These programs provide subrecipients with advances to comply with Commonwealth law and also to ensure that adequate funds are available to provide services to participants on a timely basis. DHS officials believe that their in-house payment review procedures for the SSBG and SABG programs are as efficient as administratively feasible and that controls exist in each of the program areas. Without on-site program monitoring visits by funding agency officials, we consider DHS?s limited in-house reviews of subrecipient status reports or other documents to be insufficient to detect potential subrecipient noncompliance, including excess cash violations. DHS does not adjust payments to the subrecipients based on in-house reviews. Effect: Since DHS does not adequately perform during-the-award monitoring of subrecipients, including the monitoring of subrecipient cash on hand, subrecipients may not be complying with applicable grant requirements and federal regulations, including cash management standards. Finding 2020 ? 009: (continued) Recommendation: DHS should perform risk based during-the-award monitoring procedures for SSBG and SABG subrecipients to ensure timely compliance with all applicable federal regulations. On-site monitoring visits by state officials should be supported by documentation to show the monitoring performed, areas examined, conclusions reached, and that the monitoring was performed in compliance with applicable regulations. Also, we suggest that DHS should coordinate the monitoring of SSBG subrecipients with other program funding received by the same subrecipients. As recommended in previous Single Audits and supported by the United States Department of Health and Human Services, DHS should either consider changing their current subrecipient payment procedures from advancement basis to reimbursement basis or establish procedures to adequately monitor subrecipient cash on hand to ensure it is limited to immediate needs, but no longer than one month. The implementation and strengthening of these controls should provide DHS with reasonable assurance as to compliance with cash management requirements at the subrecipient level. Agency Response: DHS agrees with this finding. Questioned Costs: The amount of questioned costs cannot be determined. The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Show full finding ▾
Full finding narrative

Department of Human Services Finding 2020 ? 009: CFDA #93.667 ? Social Services Block Grant CFDA #93.959 ? Block Grants for Prevention and Treatment of Substance Abuse Noncompliance and Weaknesses Exist in the Department of Human Services? Program Monitoring of the Social Services Block Grant and the Block Grants for Prevention and Treatment of Substance Abuse Subrecipients (A Similar Condition Was Noted in Prior Year Finding 2019-010) Federal Grant Number(s) and Year(s): 2001PASOSR (10/01/2019 ? 9/30/2020), 1901PASOSR (10/01/2018 ? 9/30/2019), 3B08TI010044-19 (10/01/2018 ? 9/30/2020), 2B08TI010044-18 (10/01/2017 ? 9/30/2018) Type of Finding: Material Weakness, Material Noncompliance for SSBG Significant Deficiency, Noncompliance for SABG Compliance Requirements: Cash Management, Subrecipient Monitoring Condition: Our examination of the Department of Human Services? (DHS) procedures for monitoring Social Services Block Grant (SSBG) subrecipients revealed that DHS did not adequately monitor the SSBG Mental Health, Homeless Services, Child Welfare, Domestic Violence, Rape Crisis, Legal Services, and Family Planning subrecipients to ensure that SSBG awards are used in compliance with laws and regulations, which include allowable costs, period of performance, and other requirements. The inadequately monitored subrecipients received $39.6 million (or approximately 43 percent) of total SSBG program expenditures of $91.4 million on the Schedule of Expenditures of Federal Awards (SEFA). While we did note that DHS adequately monitored three of the 48 Mental Health County/County Joinder subrecipients which included Mental Health and Child Welfare services, this coverage is not adequate. In addition, our review of the risk assessments completed for all of the aforementioned subrecipients identified several instances where subrecipient monitoring was warranted but was not conducted. We also determined that the Homeless Services program subrecipients that received SSBG funding and were not adequately monitored by DHS personnel also received $1,983,000 in Block Grants for Prevention and Treatment of Substance Abuse (SABG) funding during the fiscal year ended June 30, 2020. Total SABG expenditures on the current SEFA were $72.8 million. In addition, for the compliance requirement related to cash management, we noted that DHS advanced funds to SSBG subrecipients in five of nine program areas, representing $39.6 million (or approximately 43 percent) of SSBG program expenditures, without adequately monitoring the reasonableness of the subrecipient cash balances. In particular, for the Legal Services components of the SSBG program, DHS advanced funds to subrecipients on a monthly basis. For program areas related to Mental Health, Intellectual Disabilities, Homeless Services, and Child Welfare, DHS advanced funds to subrecipients on a quarterly basis. Also, we noted $1,983,000 of SABG funds were advanced under the Homeless Services program area without adequately monitoring the reasonableness of the subrecipient cash balances. Our inquiries with applicable DHS program administrators disclosed that DHS did not adequately monitor the five program areas? subrecipients for cash management compliance either at the time of payment or at any other time during the fiscal year ended June 30, 2020. Furthermore, while Single Audits of SSBG and SABG subrecipients are to be conducted each year, this auditing activity does not compensate for the lack of during-the-award program monitoring, since the timing, focus, and scope of subrecipient auditing activities after year end are different than compliance monitoring to be performed by program officials during the year. Criteria: 45 CFR Section 75.352, Requirements for pass-through entities, states: (d) Monitor the activities of the subrecipient as necessary to ensure that the subaward is used for authorized purposes, in compliance with Federal statutes, regulations, and the terms and conditions of the subaward; and that subaward performance goals are achieved. Pass-through entity monitoring of the subrecipient must include: Finding 2020 ? 009: (continued) (1) Reviewing financial and performance reports required by the pass-through entity. (2) Following-up and ensuring that the subrecipient takes timely and appropriate action on all deficiencies pertaining to the Federal award provided to the subrecipient from the pass-through entity detected through audits, on-site reviews, and other means. (3) Issuing a management decision for audit findings pertaining to the Federal award provided to the subrecipient from the pass-through entity? (e) Depending upon the pass-through entity's assessment of risk posed by the subrecipient (as described in paragraph (b) of this section), the following monitoring tools may be useful for the pass-through entity to ensure proper accountability and compliance with program requirements and achievement of performance goals: (1) Providing subrecipients with training and technical assistance on program-related matters; and (2) Performing on-site reviews of the subrecipient's program operations; (3) Arranging for agreed-upon-procedures engagements as described in ?75.425 (Audit services). 45 CFR Section 75.305(b)(1), applicable to payments to subrecipients, states in part: ?Advance payments to a non-Federal entity must be limited to the minimum amounts needed and be timed to be in accordance with the actual, immediate cash requirements of the non-Federal entity in carrying out the purpose of the approved program or project. The timing and amount of advance payments must be as close as is administratively feasible to the actual disbursements by the non-Federal entity for direct program or project costs and the proportionate share of any allowable indirect costs. The non-Federal entity must make timely payment to contractors in accordance with the contract provisions. Management Directive 325.12, Standards for Internal Control in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book), published in September 2014. The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: DHS management indicated that risk assessment and monitoring documents were created for use during on-site monitoring of SSBG and SABG subrecipients. However, due to staffing issues and the COVID-19 pandemic, on-site monitoring was not performed for all SSBG and SABG subrecipients. Consistent with prior year audits, DHS management noted that there have been no changes to the payment methodology for the Legal Services, Homeless Services, Mental Health, Intellectual Disabilities, and Child Welfare components of SSBG. These programs provide subrecipients with advances to comply with Commonwealth law and also to ensure that adequate funds are available to provide services to participants on a timely basis. DHS officials believe that their in-house payment review procedures for the SSBG and SABG programs are as efficient as administratively feasible and that controls exist in each of the program areas. Without on-site program monitoring visits by funding agency officials, we consider DHS?s limited in-house reviews of subrecipient status reports or other documents to be insufficient to detect potential subrecipient noncompliance, including excess cash violations. DHS does not adjust payments to the subrecipients based on in-house reviews. Effect: Since DHS does not adequately perform during-the-award monitoring of subrecipients, including the monitoring of subrecipient cash on hand, subrecipients may not be complying with applicable grant requirements and federal regulations, including cash management standards. Finding 2020 ? 009: (continued) Recommendation: DHS should perform risk based during-the-award monitoring procedures for SSBG and SABG subrecipients to ensure timely compliance with all applicable federal regulations. On-site monitoring visits by state officials should be supported by documentation to show the monitoring performed, areas examined, conclusions reached, and that the monitoring was performed in compliance with applicable regulations. Also, we suggest that DHS should coordinate the monitoring of SSBG subrecipients with other program funding received by the same subrecipients. As recommended in previous Single Audits and supported by the United States Department of Health and Human Services, DHS should either consider changing their current subrecipient payment procedures from advancement basis to reimbursement basis or establish procedures to adequately monitor subrecipient cash on hand to ensure it is limited to immediate needs, but no longer than one month. The implementation and strengthening of these controls should provide DHS with reasonable assurance as to compliance with cash management requirements at the subrecipient level. Agency Response: DHS agrees with this finding. Questioned Costs: The amount of questioned costs cannot be determined. The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Corrective Action Plan

Office of Administration (OA)-SSBG: The Bureau of Financial Operations (BFO) will continue conducting during-the-award subrecipient monitoring for SSBG and SABG, using the results of the documented risk assessment. As it relates to the cash management portion of the finding, given the relatively small amounts of money involved and the number of counties affected, DHS has determined that it is not economically feasible to change the payment methodology at this time. Anticipated Completion Date: 03/31/2021 Contact Person: Kelly Leighty, Director, Div. of Financial Policy and Operations Office of Policy Development (OPD)-SSBG: Risk assessments for the fiscal year ending June 30, 2021 have been completed. Monitoring will prioritize subrecipients receiving a ?high risk? designation and/or those who did not receive monitoring during the last fiscal year. Due to COVID-19, monitoring will be conducted virtually. Monitoring will be scheduled to occur by March 31, 2021. Anticipated Completion Date: 03/31/2021 Contact Person: Jazmin Cartwright, Grants and Policy Spclist.

Prior Finding References

2019-010

About Cash Management, Subrecipient Monitoring →
2020-010
Special Tests & Provisions

The Pennsylvania Department of Human Services (DHS) is required by the United States Department of Health and Human Services (HHS), Centers for Medicare and Medicaid Services (CMS), to implement six required Medicaid National Correct Coding Initiative (NCCI) methodologies. These methodologies include procedure-to-procedure and medically unlikely edits of Medicaid fee-for-service claims submitted for processing through DHS?s PROMISe system to ensure that only proper payments of Medicaid procedures are reimbursed. As part of this process, DHS is required to download quarterly NCCI edit tables from CMS which are subsequently uploaded into PROMISe by DHS?s PROMISe vendor. During the fiscal year ended June 30, 2020, an information technology internal control weakness was noted as there was no documented evidence of DHS management?s authorization to ensure the PROMISe vendor followed a formal documented change control process when uploading the quarterly NCCI tables into PROMISe. In addition, DHS did not ensure that its contract with the PROMISe vendor included the NCCI Confidentiality Agreement required by the HHS/CMS Medicaid NCCI Technical Guidance Manual. Criteria: Management Directive 325.12, Standards for Internal Control for Commonwealth Agencies, effective July 1, 2015, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book), published in September 2014. Green Book Principle 11 ? Design Activities for the Information System, states in part: 11.15 ?Management designs control activities over changes to technology. This may involve requiring authorization of change requests; reviewing the changes, approvals, and testing results; and designing protocols to determine whether changes are made properly? 11.16 ?Control activities for the development, maintenance, and change of application software prevent unauthorized programs or modifications to existing programs. Finding 2020 ? 010: (continued) Additionally, the Commonwealth?s Information Technology Policy (ITP) ? SFT000, Software Development Life Cycle Policy, states in part, ?Agencies shall incorporate separation of duties to maintain continuity and integrity throughout the execution of the procedures and processes associated with the SDLC [Software Development Life Cycle] framework and affiliated software development projects. Careful consideration should be given to: Establishing access controls granting permissions to Commonwealth employees and/or outside contractors performing multiple roles within the various environments (i.e., development, production, system integration, testing, staging, etc.) to add, modify, delete, and migrate application code, data sets, and/or make configuration changes to systems in these environments? Finally, general control activities over technology are integral to the overall internal control structure of the Commonwealth. A well-designed system of internal controls dictates that information technology general controls be established and functioning to ensure that federal programs are administered in accordance with management?s intent. The HHS/CMS Medicaid NCCI Technical Guidance Manual, Section 7.1.1, Sharing of State Medicaid NCCI Edit Files by States with Other Entities, states in part: A state Medicaid agency may share these quarterly state Medicaid NCCI edit files which are posted on the MII [Medicaid Integrity Institute] on the RISSNET [Regional Information Sharing System Network] portal with the contracted fiscal agent that processes its fee-for-service claims or with any of its contracted Medicaid managed-care entities that is using the Medicaid NCCI methodologies in its processing of claims or encounter data, if appropriate confidentiality agreements are in place. The HHS/CMS Medicaid NCCI Technical Guidance Manual, Section 7.1.2, Confidentiality Agreements Requirements for Contracted Parties, states: At a minimum, the following elements must be included in the confidentiality agreements for any contracted party using the Medicaid NCCI files posted on the MII: Disclosure shall be limited to only those responsible for the implementation of the quarterly state Medicaid NCCI edit files. Disclosure shall not be made prior to the start of the new calendar quarter. After the start of the new calendar quarter, a contracted party may disclose only non-confidential information contained in the Medicaid NCCI edit files that is also available to the general public found on the Medicaid NCCI webpage. The contracted party agrees to use any non-public information from the quarterly state Medicaid NCCI edit files only for any business purposes directly related to the implementation of the Medicaid NCCI methodologies in the particular state. New, revised, or deleted Medicaid NCCI edits shall not be published or otherwise shared with individuals, medical societies, or any other entities unless it is a contracted party prior to the posting of the Medicaid NCCI edits on the Medicaid NCCI webpage. Implementation of new, revised, or deleted Medicaid NCCI edits shall not occur prior to the first day of the calendar quarter. Only a state Medicaid agency has the discretion to release additional information for selected individual edits or limited ranges of edits from the files posted on the MII. State Medicaid agencies must impose penalties, up to and including loss of contract, for violations of any confidentiality agreement relating to use of the MII edit files. Finding 2020 ? 010: (continued) Cause: Regarding the lack of documented change management procedures when applying code updates within PROMISe, DHS personnel stated this was an oversight. DHS personnel also stated the responsibility for the NCCI work was transferred internally within the bureau, with the focus placed on the downloading of the NCCI files along with the review of codes. DHS personnel stated that the confidentiality agreement required by the HHS/CMS Medicaid NCCI Technical Guidance Manual was not included in the PROMISe contract, since the contract was finalized prior to the HHS issuance of the NCCI requirements. Effect: Since DHS could not demonstrate that the PROMISe vendor followed a formal documented change control process when uploading the quarterly NCCI tables, DHS could not provide evidence that the correct NCCI tables were uploaded in compliance with NCCI requirements. Further, the significant deficiency related to change control procedures could result in unauthorized changes to PROMISe if not corrected. Since DHS did not ensure the required NCCI Confidentiality Agreement was included in its contract with the PROMISe vendor, DHS was not in compliance with federal regulations. Recommendation: DHS management should maintain documentation of its authorization to initiate application changes, testing of changes, and final approval of each PROMISe change before deployment to the production environment, in order to ensure that the PROMISe vendor follows a formal documented change control process when uploading the quarterly NCCI tables. DHS should ensure the required NCCI Confidentiality Agreement is included in an amendment to its contract with the PROMISe vendor. Agency Response: DHS agrees with the finding. Questioned Costs: None The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Show full finding ▾
Full finding narrative

Department of Human Services Finding 2020 ? 010: CFDA #93.775, 93.777, and 93.778 ? Medicaid Cluster (including COVID-19) A Significant Deficiency and Noncompliance Exist at the Department of Human Services Related to the Medicaid National Correct Coding Initiative Federal Grant Number(s) and Year(s): 2005PA5MAP (10/01/2019 ? 9/30/2020), 2005PA5ADM (10/01/2019 ? 9/30/2020), 1905PA5MAP (10/01/2018 ? 9/30/2019), 1905PA5ADM (10/01/2018 ? 9/30/2019) Type of Finding: Significant Deficiency, Noncompliance Compliance Requirement: Special Tests and Provisions related to the Medicaid National Correct Coding Initiative (NCCI) Condition: The Pennsylvania Department of Human Services (DHS) is required by the United States Department of Health and Human Services (HHS), Centers for Medicare and Medicaid Services (CMS), to implement six required Medicaid National Correct Coding Initiative (NCCI) methodologies. These methodologies include procedure-to-procedure and medically unlikely edits of Medicaid fee-for-service claims submitted for processing through DHS?s PROMISe system to ensure that only proper payments of Medicaid procedures are reimbursed. As part of this process, DHS is required to download quarterly NCCI edit tables from CMS which are subsequently uploaded into PROMISe by DHS?s PROMISe vendor. During the fiscal year ended June 30, 2020, an information technology internal control weakness was noted as there was no documented evidence of DHS management?s authorization to ensure the PROMISe vendor followed a formal documented change control process when uploading the quarterly NCCI tables into PROMISe. In addition, DHS did not ensure that its contract with the PROMISe vendor included the NCCI Confidentiality Agreement required by the HHS/CMS Medicaid NCCI Technical Guidance Manual. Criteria: Management Directive 325.12, Standards for Internal Control for Commonwealth Agencies, effective July 1, 2015, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book), published in September 2014. Green Book Principle 11 ? Design Activities for the Information System, states in part: 11.15 ?Management designs control activities over changes to technology. This may involve requiring authorization of change requests; reviewing the changes, approvals, and testing results; and designing protocols to determine whether changes are made properly? 11.16 ?Control activities for the development, maintenance, and change of application software prevent unauthorized programs or modifications to existing programs. Finding 2020 ? 010: (continued) Additionally, the Commonwealth?s Information Technology Policy (ITP) ? SFT000, Software Development Life Cycle Policy, states in part, ?Agencies shall incorporate separation of duties to maintain continuity and integrity throughout the execution of the procedures and processes associated with the SDLC [Software Development Life Cycle] framework and affiliated software development projects. Careful consideration should be given to: Establishing access controls granting permissions to Commonwealth employees and/or outside contractors performing multiple roles within the various environments (i.e., development, production, system integration, testing, staging, etc.) to add, modify, delete, and migrate application code, data sets, and/or make configuration changes to systems in these environments? Finally, general control activities over technology are integral to the overall internal control structure of the Commonwealth. A well-designed system of internal controls dictates that information technology general controls be established and functioning to ensure that federal programs are administered in accordance with management?s intent. The HHS/CMS Medicaid NCCI Technical Guidance Manual, Section 7.1.1, Sharing of State Medicaid NCCI Edit Files by States with Other Entities, states in part: A state Medicaid agency may share these quarterly state Medicaid NCCI edit files which are posted on the MII [Medicaid Integrity Institute] on the RISSNET [Regional Information Sharing System Network] portal with the contracted fiscal agent that processes its fee-for-service claims or with any of its contracted Medicaid managed-care entities that is using the Medicaid NCCI methodologies in its processing of claims or encounter data, if appropriate confidentiality agreements are in place. The HHS/CMS Medicaid NCCI Technical Guidance Manual, Section 7.1.2, Confidentiality Agreements Requirements for Contracted Parties, states: At a minimum, the following elements must be included in the confidentiality agreements for any contracted party using the Medicaid NCCI files posted on the MII: Disclosure shall be limited to only those responsible for the implementation of the quarterly state Medicaid NCCI edit files. Disclosure shall not be made prior to the start of the new calendar quarter. After the start of the new calendar quarter, a contracted party may disclose only non-confidential information contained in the Medicaid NCCI edit files that is also available to the general public found on the Medicaid NCCI webpage. The contracted party agrees to use any non-public information from the quarterly state Medicaid NCCI edit files only for any business purposes directly related to the implementation of the Medicaid NCCI methodologies in the particular state. New, revised, or deleted Medicaid NCCI edits shall not be published or otherwise shared with individuals, medical societies, or any other entities unless it is a contracted party prior to the posting of the Medicaid NCCI edits on the Medicaid NCCI webpage. Implementation of new, revised, or deleted Medicaid NCCI edits shall not occur prior to the first day of the calendar quarter. Only a state Medicaid agency has the discretion to release additional information for selected individual edits or limited ranges of edits from the files posted on the MII. State Medicaid agencies must impose penalties, up to and including loss of contract, for violations of any confidentiality agreement relating to use of the MII edit files. Finding 2020 ? 010: (continued) Cause: Regarding the lack of documented change management procedures when applying code updates within PROMISe, DHS personnel stated this was an oversight. DHS personnel also stated the responsibility for the NCCI work was transferred internally within the bureau, with the focus placed on the downloading of the NCCI files along with the review of codes. DHS personnel stated that the confidentiality agreement required by the HHS/CMS Medicaid NCCI Technical Guidance Manual was not included in the PROMISe contract, since the contract was finalized prior to the HHS issuance of the NCCI requirements. Effect: Since DHS could not demonstrate that the PROMISe vendor followed a formal documented change control process when uploading the quarterly NCCI tables, DHS could not provide evidence that the correct NCCI tables were uploaded in compliance with NCCI requirements. Further, the significant deficiency related to change control procedures could result in unauthorized changes to PROMISe if not corrected. Since DHS did not ensure the required NCCI Confidentiality Agreement was included in its contract with the PROMISe vendor, DHS was not in compliance with federal regulations. Recommendation: DHS management should maintain documentation of its authorization to initiate application changes, testing of changes, and final approval of each PROMISe change before deployment to the production environment, in order to ensure that the PROMISe vendor follows a formal documented change control process when uploading the quarterly NCCI tables. DHS should ensure the required NCCI Confidentiality Agreement is included in an amendment to its contract with the PROMISe vendor. Agency Response: DHS agrees with the finding. Questioned Costs: None The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Corrective Action Plan

The Claims and Reference Unit will utilize PROMISe Change Control Process to document, formally request, apply, and validate updates enacted to the NCCI code sets for both quarterly and annual updates. The Claims and Reference Unit supervisor reinforced the NCCI File Update Process with unit staff, and implemented calendar reminders to monitor the download site for new NCCI files quarterly. As CMS publishes NCCI edit files, the Claims and Reference Unit will submit a work item to the vendor according to the PROMISe Change Control Process to upload the latest code set to PROMISe. Utilizing the PROMISe Change Control Process will allow trackability of the NCCI code set updates for business use and auditing purposes. The Claims and Reference Unit submitted a Data Maintenance Request (DMR) on 01/27/2021 requesting the vendor add the NCCI code set to PROMISe for the first quarter 2021. The BDCM anticipates the code set validation will occur on or before 2/15/2021. The Claims and Reference Unit will repeat the NCCI code set update process quarterly beginning the next code set release anticipated in April 2021. Anticipated Completion Date: Completed Contact People: David Valvo, Human Services Prgm. Specialist Super., MMIS Monitoring; Jeremy Pahl, Section Chief, Monitoring; Tina Dorsey, Division Dir., Systems, Monitoring and Oversight Additionally, the current PROMISe contract does not include the NCCI Confidentiality Agreement required by the HHS/CMS Medicaid NCCI Technical Guidance Manual. BDCM will add the NCCI Confidentiality Agreement to the forthcoming vendor contract amendment. Anticipated Completion Date: 08/31/2021 Contact People: David Valvo, Human Services Prgm. Specialist Super., MMIS Monitoring; Jeremy Pahl, Section Chief, Monitoring; Tina Dorsey, Division Dir., Systems, Monitoring and Oversight

About Special Tests and Provisions →
2020-011
Reporting
REPEAT

The Office of Vocational Rehabilitation (OVR), Pennsylvania Department of Labor and Industry, is required to submit an SF-425, Federal Financial Report, for the Rehabilitation Services ? Vocational Rehabilitation Grants to States (RS-VR) program to the United States Department of Education (USDE) on a semi-annual basis. The SF-425 report includes data related to the federal share of expenditures to date, the federal share of unliquidated obligations, the federal program income earned, the program income expended and unexpended, indirect charges to the grant, as well as other general information that is necessary to ensure compliance with program requirements. During the fiscal year ended June 30, 2020, we selected all four of the submitted semi-annual SF-425 reports for testing. As part of the report testing, we used supporting documentation to determine if the agency appropriately reported the data in the Rehabilitation Services Administration (RSA) system where the SF-425 reports are submitted. Our procedures disclosed that the recipient share of expenditures reported on the March 31, 2020 filing for federal grant H126A190056 was not adequately input into the RSA system. The amount reported was $44,202,006, when actual expenditures were $44,204,647 based on supporting documentation from the Commonwealth?s general ledger, SAP, resulting in an understatement of $2,641. Although the SF-425 report was subjected to a documented supervisory review and approval, the inaccurate reported amount remained undetected by Commonwealth management until notification by the auditor. Our procedures also determined that three of the four SF-425 reports tested were not timely filed in the RSA system. Per Policy Directive RSA-PD-11-03, a final SF-425 reports must be submitted no later than 90 days after the end of the grant period. During our testing we noted the final SF-425 report for federal grant H126A180056 was submitted January 9, 2020, which was not within the 90-day reporting requirement. Per the reporting requirements, the March 31st semi-annual SF-425 reports are due 30 days after the quarter end. During our testing we noted the March 31, 2020 SF-425 reports for federal grant numbers H126A190056 and H126A200056 were filed on May 1, 2020, which was not within the 30-day reporting requirement. Criteria: 2 CFR Section 200.303(a), Internal controls, states: The non-Federal entity must: Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in ?Standards for Internal Control in the Federal Government? issued by the Comptroller General of the United States or the ?Internal Control Integrated Framework?, issued by the Committee of the Sponsoring Organizations of the Treadway Commission (COSO). USDE?s Office of Special Education and Rehabilitative Services Policy Directive RSA-PD-15-05, states: The Office of Management and Budget (OMB) requires that grantees use the SF-425 to report financial data for grant awards. RSA uses the SF-425 data to monitor the financial status of the VR program and to assess grantee compliance with the fiscal requirements contained in the Rehabilitation Act of 1973 (Rehabilitation Act). Finding 2020 ? 011: (continued) 34 CFR Section 361.40, Reports; Evaluation standards and performance indicators, states: (a) Reports. (1) The vocational rehabilitation services portion of the Unified or Combined State Plan must assure that the designated State agency will submit reports, including reports required under sections 13, 14, and 101(a)(10) of the Act ? (i) In the form and level of detail and at the time required by the Secretary regarding applicants for and eligible individuals receiving services, including students receiving pre-employment transition services in accordance with section 361.48(a); and (ii) In a manner that provides a complete count (other than the information obtained through sampling consistent with section 101(a)(10)(E) of the Act) of the applicants and eligible individuals to ? (A) Permit the greatest possible cross-classification of data; and (B) Protect the confidentiality of the identity of each individual. (2) The designated State agency must comply with any requirements necessary to ensure the accuracy and verification of those reports. Management Directive 325.12, Standards for Internal Control for Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book), published in September 2014. The Green Book states in part: Management should design control activities to achieve objectives and respond to risks. Management should implement control activities through policies. Cause: Bureau of Accounting and Financial Management personnel indicated the data input error of the recipient share of expenditures into the RSA system occurred due to user access limitations which did not allow for an appropriate review of the information that was entered into the RSA system. They also indicated the late filing of the March 31, 2020 SF-425 reports was due to a system access issue. The reports were entered into the system on April 30, 2020, but the individual that needed to sign the form did not have the appropriate access to the RSA system to sign and submit the form. The access issue was resolved and the report was submitted May 1, 2020. The late submission of the final SF-425 report for federal grant H126A180056 was due to adjustments that the Office of Vocational Rehabilitation wanted to make to the report which resulted in the delayed filing. Effect: Since the report preparation and the supervisory review and approval process were not adequate, the recipient share of expenditures were incorrectly reported on the SF-425 report submitted to USDE. Due to system access issues and adjustments that needed to be completed, the SF-425 reports were not timely submitted to USDE. OVR was not in compliance with federal regulations. Recommendation: OVR should ensure their written procedures for the review, approval, submission, and system access of the SF-425 reports are improved and fully implemented. The procedures should have sufficient detail to ensure the SF-425 reports are prepared accurately and in accordance with federal regulations and submitted timely. In addition, OVR should correct the error and submit a revised SF-425 report to USDE. Agency Response: OVR agrees with the finding. Questioned Costs: None The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Show full finding ▾
Full finding narrative

Department of Labor and Industry Finding 2020 ? 011: CFDA #84.126 ? Rehabilitation Services ? Vocational Rehabilitation Grants to States Significant Deficiency and Noncompliance Related to the Department of Labor and Industry?s Preparation and Submission of the Semi-Annual SF-425 Report (A Similar Condition Was Noted in Prior Year Finding 2019-013) Federal Grant Number(s) and Year(s): H126A200056 (10/01/2019 ? 09/30/2020), H126A190056 (10/01/2018 ? 09/30/2019), H126A180056 (10/01/2017 ? 09/30/2018) Type of Finding: Significant Deficiency, Noncompliance Compliance Requirement: Reporting Condition: The Office of Vocational Rehabilitation (OVR), Pennsylvania Department of Labor and Industry, is required to submit an SF-425, Federal Financial Report, for the Rehabilitation Services ? Vocational Rehabilitation Grants to States (RS-VR) program to the United States Department of Education (USDE) on a semi-annual basis. The SF-425 report includes data related to the federal share of expenditures to date, the federal share of unliquidated obligations, the federal program income earned, the program income expended and unexpended, indirect charges to the grant, as well as other general information that is necessary to ensure compliance with program requirements. During the fiscal year ended June 30, 2020, we selected all four of the submitted semi-annual SF-425 reports for testing. As part of the report testing, we used supporting documentation to determine if the agency appropriately reported the data in the Rehabilitation Services Administration (RSA) system where the SF-425 reports are submitted. Our procedures disclosed that the recipient share of expenditures reported on the March 31, 2020 filing for federal grant H126A190056 was not adequately input into the RSA system. The amount reported was $44,202,006, when actual expenditures were $44,204,647 based on supporting documentation from the Commonwealth?s general ledger, SAP, resulting in an understatement of $2,641. Although the SF-425 report was subjected to a documented supervisory review and approval, the inaccurate reported amount remained undetected by Commonwealth management until notification by the auditor. Our procedures also determined that three of the four SF-425 reports tested were not timely filed in the RSA system. Per Policy Directive RSA-PD-11-03, a final SF-425 reports must be submitted no later than 90 days after the end of the grant period. During our testing we noted the final SF-425 report for federal grant H126A180056 was submitted January 9, 2020, which was not within the 90-day reporting requirement. Per the reporting requirements, the March 31st semi-annual SF-425 reports are due 30 days after the quarter end. During our testing we noted the March 31, 2020 SF-425 reports for federal grant numbers H126A190056 and H126A200056 were filed on May 1, 2020, which was not within the 30-day reporting requirement. Criteria: 2 CFR Section 200.303(a), Internal controls, states: The non-Federal entity must: Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in ?Standards for Internal Control in the Federal Government? issued by the Comptroller General of the United States or the ?Internal Control Integrated Framework?, issued by the Committee of the Sponsoring Organizations of the Treadway Commission (COSO). USDE?s Office of Special Education and Rehabilitative Services Policy Directive RSA-PD-15-05, states: The Office of Management and Budget (OMB) requires that grantees use the SF-425 to report financial data for grant awards. RSA uses the SF-425 data to monitor the financial status of the VR program and to assess grantee compliance with the fiscal requirements contained in the Rehabilitation Act of 1973 (Rehabilitation Act). Finding 2020 ? 011: (continued) 34 CFR Section 361.40, Reports; Evaluation standards and performance indicators, states: (a) Reports. (1) The vocational rehabilitation services portion of the Unified or Combined State Plan must assure that the designated State agency will submit reports, including reports required under sections 13, 14, and 101(a)(10) of the Act ? (i) In the form and level of detail and at the time required by the Secretary regarding applicants for and eligible individuals receiving services, including students receiving pre-employment transition services in accordance with section 361.48(a); and (ii) In a manner that provides a complete count (other than the information obtained through sampling consistent with section 101(a)(10)(E) of the Act) of the applicants and eligible individuals to ? (A) Permit the greatest possible cross-classification of data; and (B) Protect the confidentiality of the identity of each individual. (2) The designated State agency must comply with any requirements necessary to ensure the accuracy and verification of those reports. Management Directive 325.12, Standards for Internal Control for Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book), published in September 2014. The Green Book states in part: Management should design control activities to achieve objectives and respond to risks. Management should implement control activities through policies. Cause: Bureau of Accounting and Financial Management personnel indicated the data input error of the recipient share of expenditures into the RSA system occurred due to user access limitations which did not allow for an appropriate review of the information that was entered into the RSA system. They also indicated the late filing of the March 31, 2020 SF-425 reports was due to a system access issue. The reports were entered into the system on April 30, 2020, but the individual that needed to sign the form did not have the appropriate access to the RSA system to sign and submit the form. The access issue was resolved and the report was submitted May 1, 2020. The late submission of the final SF-425 report for federal grant H126A180056 was due to adjustments that the Office of Vocational Rehabilitation wanted to make to the report which resulted in the delayed filing. Effect: Since the report preparation and the supervisory review and approval process were not adequate, the recipient share of expenditures were incorrectly reported on the SF-425 report submitted to USDE. Due to system access issues and adjustments that needed to be completed, the SF-425 reports were not timely submitted to USDE. OVR was not in compliance with federal regulations. Recommendation: OVR should ensure their written procedures for the review, approval, submission, and system access of the SF-425 reports are improved and fully implemented. The procedures should have sufficient detail to ensure the SF-425 reports are prepared accurately and in accordance with federal regulations and submitted timely. In addition, OVR should correct the error and submit a revised SF-425 report to USDE. Agency Response: OVR agrees with the finding. Questioned Costs: None The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Corrective Action Plan

The SF-425 review process will be detailed in instructions that require a multi-level review in both the Comptroller?s office as well as within the program office to ensure that all information is reported correctly on the report. A checklist was created that includes all internal order numbers that were in use for the specific grant and indicates which portion of the grant the expenditures are to be reported under. The instructions will provide details as to where the information contained within the report can be located within SAP reports. Revised SF-425 reports have been delayed due to the COVID-19 pandemic and the restructuring of the RSA website which has restricted access to previous reports at this time. No changes can be submitted to the previous reports until they are available on the RSA website. Current SF-425s are being completed and all revised and corrected SF-425s will be submitted by the end of April 2021. L&I staff will continue to make every effort to ensure accuracy of the reports prior to submission. Procedures have been revised, created, and implemented to make sure the resubmitted and future SF- 425s are accurate. Anticipated Completion Date: 04/30/2021 Contact Person: Nichole Nedinsky, Div. Chief of Fin. Mgmt. and Admin. Services

Prior Finding References

2019-013

About Reporting →
2020-012
Eligibility
REPEAT

As part of the Rehabilitation Services ? Vocational Rehabilitation Grants to States (RS-VR) program, the Office of Vocational Rehabilitation (OVR), Pennsylvania Department of Labor and Industry, purchases vocational rehabilitation services from vendors to be provided to OVR clients. We selected a sample of 10 participants in the RS-VR program for benefits totaling $13,349 of the $22.6 million charged to the program during the fiscal year ended June 30, 2020. Our review of the 10 OVR client case files disclosed the following: ? For four of the 10 OVR participants tested for whom RS-VR program payments were made, OVR personnel did not make the eligibility determinations within 60 days after the RS-VR program application date or by the agreed upon extension date as required by federal regulations. The eligibility determinations were completed 16 to 115 days after the eligibility determination period expired. Criteria: The United States Department of Education?s Regulation 34 CFR Section 361 regarding the State Vocational Rehabilitation Services Program states in part: Section 361.41 Processing referrals and applications. (a) Referrals. The designated State unit must establish and implement standards for the prompt and equitable handling of referrals of individuals for vocational rehabilitation services, including referrals of individuals made through the One-Stop service delivery systems established under section 121 of the Workforce Innovation and Opportunity Act. The standards must include timelines for making good faith efforts to inform these individuals of application requirements and to gather information necessary to initiate an assessment for determining eligibility and priority for services. (b) Applications. (1) Once an individual has submitted an application for vocational rehabilitation services, including applications made through common intake procedures in One-Stop centers established under section 121 of the Workforce Innovation and Opportunity Act, an eligibility determination must be made within 60 days, unless- (i) Exceptional and unforeseen circumstances beyond the control of the designated State unit preclude making an eligibility determination within 60 days and the designated State unit and the individual agree to a specific extension of time; or (ii) An exploration of the individual?s abilities, capabilities, and capacity to perform in work situations is carried out in accordance with section 361.42(e). Management Directive 325.12, Standards for Internal Control for Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book), published in September 2014. The Green Book states in part: Finding 2020 ? 012: (continued) Management should design control activities to achieve objectives and respond to risks. Management should implement control activities through policies. Cause: OVR personnel indicated that the untimely eligibility determinations were due to inadequate administrative and employee oversight. Effect: Since OVR personnel did not have adequate procedures in place to ensure that client eligibility determinations were completed within 60 days of the application date or within the specific time period extension agreed upon by the client, OVR was not in compliance with federal regulations and a control deficiency exists. Also, OVR clients may not receive necessary RS-VR program services timely. Our sample contained no ineligible OVR clients for whom case service costs were incurred, so no costs are questioned. Recommendation: We recommend that OVR personnel have procedures in place to timely identify and follow up on incomplete eligibility determinations and to ensure that all client eligibility determinations are completed within the 60-day period subsequent to the application date or within the specific time period extension agreed upon by the client to ensure compliance with federal regulations. Agency Response: OVR agrees with the finding. Questioned Costs: None The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Show full finding ▾
Full finding narrative

Department of Labor and Industry Finding 2020 ? 012: CFDA #84.126 ? Rehabilitation Services ? Vocational Rehabilitation Grants to States A Significant Deficiency and Noncompliance Exist in the Department of Labor and Industry?s Procedures for Performing Eligibility Determinations (A Similar Condition Was Noted in Prior Year Finding 2019-011) Federal Grant Number(s) and Year(s): H126A200056 (10/01/2019 ? 9/30/2020), H126A190056 (10/01/2018 ? 9/30/2019), H126A180056 (10/01/2017 ? 9/30/2018) Type of Finding: Significant Deficiency, Noncompliance Compliance Requirement: Eligibility Condition: As part of the Rehabilitation Services ? Vocational Rehabilitation Grants to States (RS-VR) program, the Office of Vocational Rehabilitation (OVR), Pennsylvania Department of Labor and Industry, purchases vocational rehabilitation services from vendors to be provided to OVR clients. We selected a sample of 10 participants in the RS-VR program for benefits totaling $13,349 of the $22.6 million charged to the program during the fiscal year ended June 30, 2020. Our review of the 10 OVR client case files disclosed the following: ? For four of the 10 OVR participants tested for whom RS-VR program payments were made, OVR personnel did not make the eligibility determinations within 60 days after the RS-VR program application date or by the agreed upon extension date as required by federal regulations. The eligibility determinations were completed 16 to 115 days after the eligibility determination period expired. Criteria: The United States Department of Education?s Regulation 34 CFR Section 361 regarding the State Vocational Rehabilitation Services Program states in part: Section 361.41 Processing referrals and applications. (a) Referrals. The designated State unit must establish and implement standards for the prompt and equitable handling of referrals of individuals for vocational rehabilitation services, including referrals of individuals made through the One-Stop service delivery systems established under section 121 of the Workforce Innovation and Opportunity Act. The standards must include timelines for making good faith efforts to inform these individuals of application requirements and to gather information necessary to initiate an assessment for determining eligibility and priority for services. (b) Applications. (1) Once an individual has submitted an application for vocational rehabilitation services, including applications made through common intake procedures in One-Stop centers established under section 121 of the Workforce Innovation and Opportunity Act, an eligibility determination must be made within 60 days, unless- (i) Exceptional and unforeseen circumstances beyond the control of the designated State unit preclude making an eligibility determination within 60 days and the designated State unit and the individual agree to a specific extension of time; or (ii) An exploration of the individual?s abilities, capabilities, and capacity to perform in work situations is carried out in accordance with section 361.42(e). Management Directive 325.12, Standards for Internal Control for Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book), published in September 2014. The Green Book states in part: Finding 2020 ? 012: (continued) Management should design control activities to achieve objectives and respond to risks. Management should implement control activities through policies. Cause: OVR personnel indicated that the untimely eligibility determinations were due to inadequate administrative and employee oversight. Effect: Since OVR personnel did not have adequate procedures in place to ensure that client eligibility determinations were completed within 60 days of the application date or within the specific time period extension agreed upon by the client, OVR was not in compliance with federal regulations and a control deficiency exists. Also, OVR clients may not receive necessary RS-VR program services timely. Our sample contained no ineligible OVR clients for whom case service costs were incurred, so no costs are questioned. Recommendation: We recommend that OVR personnel have procedures in place to timely identify and follow up on incomplete eligibility determinations and to ensure that all client eligibility determinations are completed within the 60-day period subsequent to the application date or within the specific time period extension agreed upon by the client to ensure compliance with federal regulations. Agency Response: OVR agrees with the finding. Questioned Costs: None The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Corrective Action Plan

OVR?s previous CAP continues to be implemented however it is subject to change due to the changing conditions necessitated by COVID-19, including the Governor?s order to telework. The previous plan was contingent on operations, staffing, and platforms prior to March 2020. The following reasons significantly impacted the full execution of the previous CAP to address audit finding 2020-012 during the audit period of 7/1/2019 to 6/30/2020: ? COVID-19 Pandemic impacted the full execution of the standard operating procedure. o Staff?s ability to perform timely determinations was restricted by the implementation of temporary telework. ? Significant Turnover within the agency impacted the monitoring and reinforcement. o The Executive, Statewide Management, and Direct Staff experienced retirements, separations, and transfers between 12/1/2019 to 6/30/2020. While portions of the previous CAP were not fully executed. The following items were fully executed and will be amended to include additional action items in accordance with the Rehabilitative Services Administration. Effective 3/1/2020, all district offices received a statewide monthly report about the progress of Status 02?s and Status 10?s. a. As part of the CAP, monthly Status 02 and 10 reports continue to be sent out to each District Office management team by a central office designated individual. Reports are housed in the CWDS unit. b. Offices with a case review timeliness rating of 80% or lower were required to implement a local CAP and training on timeliness to address office wide and individual employee progress towards compliance. All local CAP?s and trainings were completed prior to 6/30/2020. c. Local Management was informed of the new requirement at the March 2020 Executive Director meeting, which allowed 3 months for offices to work on compliance issues, train staff, or otherwise address the situation prior to the ongoing and regular monitoring that would take effect on 7/1/2020. Offices continued to refer to OVR Back to Basics or other resources for retraining resources. The modified CAP will be implemented to further address the single audit finding 2020-012. Standard to be met and method of evaluation: As part of assessing and evaluating the timely eligibility determination process, the following corrective and preventive actions will be implemented: OVR will assess and evaluate VR counselor performance and identify effective practices that ensure timely eligibility determinations are made within 60 days from the date of application, including the use of case management tools for, and supervisory review of, timely eligibility determinations. Anticipated Completion Date: Completed Contact People: Stephanie Perry, Director, Bureau of Vocational Rehabilitation Services; Rod Alcidonis, Director, Bureau of Blindness and Visual Services 1. To assess and evaluate agency performance on eligibility requirements, OVR will develop a survey to assess case processing challenges relating to performance and identify best practices to meet regulatory requirements for determining eligibility within 60 days from the date of application. The survey will be distributed to counselors, supervisors, and local management. Anticipated Completion Date: 03/31/2021 Contact People: Stephanie Perry, Director, Bureau of Vocational Rehabilitation Services; Rod Alcidonis, Director, Bureau of Blindness and Visual Services 2. OVR will develop an internal monthly report within its case management database to help preempt case processing delays related to the 60-day regulatory requirement to determine eligibility. The monthly report will provide actionable data to alert staff of the upcoming eligibility determination timeline (30 days and 45 days) before the 60th day to determine eligibility. OVR leadership will ensure the utilization of the report as an internal control element to monitor compliance through staff supervision. Anticipated Completion Date: 07/01/2021 Contact People: Stephanie Perry, Director, Bureau of Vocational Rehabilitation Services; Rod Alcidonis, Director, Bureau of Blindness and Visual Services 3. OVR leadership will strengthen the supervisory staff's capacity to ensure proper oversight and monitoring regarding eligibility determination deadlines as part of the case management process. OVR will implement an annual statewide training structure at the beginning of each performance year to review policy, procedural, and regulatory requirements related to case processing activities' timeliness. Additionally, OVR will require local management to provide training proceeding the six months after the annual statewide training to reinforce topics covered during the annual training. Anticipated Completion Date: 12/31/2021 Contact People: Stephanie Perry, Director, Bureau of Vocational Rehabilitation Services; Rod Alcidonis, Director, Bureau of Blindness and Visual Services

Prior Finding References

2019-011

About Eligibility →
2020-013
Period of Performance
REPEATQUESTIONED COSTS

During our audit of the Rehabilitation Services ? Vocational Rehabilitation Grants to States (RS-VR) program, we evaluated internal control over and tested compliance with period of performance requirements for the grant awarded by the United States Department of Education that began during the fiscal year ended June 30, 2020 audit period. ? Per review of supporting invoice service dates, one of the 40 expenditures tested that were charged in the first month of the federal fiscal year 2020 RS-VR grant was incurred prior to the allowable period of performance. This expenditure included general charges totaling $239. Total expenditures posted to the federal fiscal year 2020 RS-VR grant in the first month of the allowable period of performance were $2,856,134. Management was unable to provide authorization from the federal awarding agency for allowance of the expenditures occurring outside of the period of performance. Criteria: 2 CFR Section 200.303(a), Internal controls, states: The non-Federal entity must: Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in ?Standards for Internal Control in the Federal Government? issued by the Comptroller General of the United States or the ?Internal Control Integrated Framework?, issued by the Committee of the Sponsoring Organizations of the Treadway Commission (COSO). 2 CFR Section 200.309, Period of performance, states: A non-Federal entity may charge to the Federal award only allowable costs incurred during the period of performance (except as described in ?200.461 Publication and printing costs) and any costs incurred before the Federal awarding agency or pass-through entity made the award that were authorized by the Federal awarding agency or pass-through entity. Management Directive 325.12, Standards for Internal Control for Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book), published in September 2014. The Green Book states in part: Management should design control activities to achieve objectives and respond to risks. Management should implement control activities through policies. Finding 2020 ? 013: (continued) Cause: Office of Vocational Rehabilitation (OVR), Pennsylvania Department of Labor and Industry, personnel did not review service dates prior to submitting invoices for payment which were charged to the federal fiscal year 2020 grant. OVR personnel did not have adequate procedures in place to ensure that only costs incurred during the allowable period of performance were charged to the federal fiscal year 2020 RS-VR grant. Effect: Expenditures outside of the allowable period of performance were incorrectly charged to the federal fiscal year 2020 RS-VR grant without authorization by the federal awarding agency, resulting in noncompliance and questioned costs. Recommendation: We recommend that OVR personnel implement procedures to ensure that costs and adjustments being charged to a federal grant are incurred within the allowable period of performance of the grant to which they are being charged, or when necessary, obtain authorization from the federal awarding agency prior to charging costs that are outside the allowable period of performance. Agency Response: OVR agrees with the finding. Questioned Costs: Known questioned costs for CFDA #84.126 of $239 were determined, which represent the amount of transactions incurred and charged to the federal grant outside the allowable period of performance. The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Show full finding ▾
Full finding narrative

Department of Labor and Industry Finding 2020 ? 013: CFDA #84.126 ? Rehabilitation Services ? Vocational Rehabilitation Grants to States A Significant Deficiency and Noncompliance Exist in the Department of Labor and Industry?s Procedures Related to Period of Performance Requirements (A Similar Condition Was Noted in Prior Year Finding 2019-012) Federal Grant Number(s) and Year(s): H126A200056 (10/01/2019 ? 9/30/2020) Type of Finding: Significant Deficiency, Noncompliance Compliance Requirement: Period of Performance Condition: During our audit of the Rehabilitation Services ? Vocational Rehabilitation Grants to States (RS-VR) program, we evaluated internal control over and tested compliance with period of performance requirements for the grant awarded by the United States Department of Education that began during the fiscal year ended June 30, 2020 audit period. ? Per review of supporting invoice service dates, one of the 40 expenditures tested that were charged in the first month of the federal fiscal year 2020 RS-VR grant was incurred prior to the allowable period of performance. This expenditure included general charges totaling $239. Total expenditures posted to the federal fiscal year 2020 RS-VR grant in the first month of the allowable period of performance were $2,856,134. Management was unable to provide authorization from the federal awarding agency for allowance of the expenditures occurring outside of the period of performance. Criteria: 2 CFR Section 200.303(a), Internal controls, states: The non-Federal entity must: Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in ?Standards for Internal Control in the Federal Government? issued by the Comptroller General of the United States or the ?Internal Control Integrated Framework?, issued by the Committee of the Sponsoring Organizations of the Treadway Commission (COSO). 2 CFR Section 200.309, Period of performance, states: A non-Federal entity may charge to the Federal award only allowable costs incurred during the period of performance (except as described in ?200.461 Publication and printing costs) and any costs incurred before the Federal awarding agency or pass-through entity made the award that were authorized by the Federal awarding agency or pass-through entity. Management Directive 325.12, Standards for Internal Control for Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book), published in September 2014. The Green Book states in part: Management should design control activities to achieve objectives and respond to risks. Management should implement control activities through policies. Finding 2020 ? 013: (continued) Cause: Office of Vocational Rehabilitation (OVR), Pennsylvania Department of Labor and Industry, personnel did not review service dates prior to submitting invoices for payment which were charged to the federal fiscal year 2020 grant. OVR personnel did not have adequate procedures in place to ensure that only costs incurred during the allowable period of performance were charged to the federal fiscal year 2020 RS-VR grant. Effect: Expenditures outside of the allowable period of performance were incorrectly charged to the federal fiscal year 2020 RS-VR grant without authorization by the federal awarding agency, resulting in noncompliance and questioned costs. Recommendation: We recommend that OVR personnel implement procedures to ensure that costs and adjustments being charged to a federal grant are incurred within the allowable period of performance of the grant to which they are being charged, or when necessary, obtain authorization from the federal awarding agency prior to charging costs that are outside the allowable period of performance. Agency Response: OVR agrees with the finding. Questioned Costs: Known questioned costs for CFDA #84.126 of $239 were determined, which represent the amount of transactions incurred and charged to the federal grant outside the allowable period of performance. The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Corrective Action Plan

Instructions are being created to ensure that personnel review each invoice for the service start date and make sure the proper funding is used. Once created, it will be distributed to staff and training will be conducted. Anticipated Completion Date: 03/30/2021 Contact Person: Nichole Nedinsky, Div. Chief of Fin. Mgmt. and Admin. Services

Prior Finding References

2019-012

About Period of Performance →
2020-014
Subrecipient Monitoring
QUESTIONED COSTS

The Department of Transportation (PennDOT) administers the Highway Planning and Construction (HPC) Cluster which is funded by the United States Department of Transportation. Our audit of PennDOT?s monitoring of HPC Cluster subrecipient local projects to evaluate compliance with subrecipient monitoring requirements disclosed that the monitoring was not adequate for the fiscal year ended June 30, 2020. HPC Cluster subrecipient expenditures were $124.5 million (7.3 percent) out of total HPC Cluster expenditures of $1.7 billion reported on the June 30, 2020 Schedule of Expenditures of Federal Awards. A local project typically exists when a construction project is located on a street or highway for which PennDOT does not have legal jurisdiction. In such cases, PennDOT may arrange for the local public agency to perform contract work with its own forces or by outside contract. However, it should be noted that PennDOT is responsible for the construction of all federally aided projects and is not relieved of its responsibility by authorizing performance of the work by a local public agency. PennDOT developed Publication 740, Local Project Delivery Manual, to provide guidance on managing local projects to agency personnel in PennDOT?s 11 engineering district offices. The publication is a compilation of PennDOT policies and procedures relating to the letting, inspection, and management of local construction contracts. In particular, the publication covers the staffing requirements of local municipalities, as well as PennDOT?s on-site monitoring and oversight in the form of review checklists. Publication 740 requires that PennDOT personnel complete the review checklists maintained in Publication 2, Project Office Manual, at least quarterly. The review checklists are important documents which provide evidence of PennDOT?s district offices? on-site monitoring of local subrecipient projects for compliance with various federal regulations, including allowability of project activity costs, materials certifications and control, wage compliance, and other requirements. We selected a sample of 10 federally funded locally sponsored projects to evaluate the adequacy of PennDOT?s subrecipient monitoring. Our review of the 10 locally sponsored projects totaling $31.1 million consisted of projects in 3 engineering districts. Documented evidence of properly completed project checklists could not be provided for the one project tested in District 01 with expenditures totaling $736.7 thousand. Criteria: 2 CFR Section 200.331, Requirements for pass through entities, states in part: All pass-through entities must: (d) Monitor the activities of the subrecipient as necessary to ensure that the subaward is used for authorized purposes, in compliance with Federal statutes, regulations, and the terms and conditions of the subaward; and that subaward performance goals are achieved. Management Directive 325.12, Standards for Internal Control for Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book), published in September 2014. The Green Book states in part: Finding 2020 ? 014: (continued) Management should design control activities to achieve objectives and respond to risks. Management should implement control activities through policies. Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. PennDOT Publication 740, Local Project Delivery Manual, Chapter 7, Construction Phase, states: The Contractor?s work and the Local Project Sponsor?s inspection are to be reviewed by the District. The Assistant District Executive for Construction is to assign an ACE to monitor and oversee the project. The ACE or a designee is to visit the project as frequently as needed to maintain an intimate knowledge of current activities and ensure that the work is being inspected and the contract administered in accordance with the terms of the agreement, the requirements of FHWA, and the procedures outlined herein. During each visit to the project or at least quarterly when the project control meetings are being attended on a regular basis, the ACE or designee is to document, in writing, the project status and any outstanding issues. To assist the Districts with their project oversight responsibilities, a checklist has been developed and incorporated into Publication 2, Project Office Manual, Section C.1.18, Checklist for the Administration of Locally Sponsored Federal-Aid Projects. This checklist must be utilized when visiting a Locally Sponsored Federal-Aid project for monitoring and oversight purposes. The checklist is intended to provide uniformity in reviews, as well as documentation that required oversight is being performed. Completed checklists may be requested during annual federal audits. Cause: PennDOT has established subrecipient monitoring procedures for locally sponsored projects which require adequate documentation in the form of timely and properly completed checklists. However, PennDOT stated that a vacancy in the District 01 manager position responsible for checklist completion and oversights contributed to the checklist in question not being completed. Effect: Many of the requirements in Publication 740 are designed to ensure compliance with federal regulations related to locally sponsored projects, including the timely and adequate completion of the checklists described in Publication 2. Lack of sufficient adherence to the policy can result in inadequate oversight for local projects within the districts. Federal funds may be used improperly or not in compliance with federal regulations, and noncompliance may not be timely detected and corrected without adequate oversight. Recommendation: PennDOT should ensure that the established procedures within Publication 740 are adhered to and the checklists described in Publication 2 are adequately and timely completed in order to prevent control deficiencies related to local project oversight and to ensure documented compliance with federal regulations. Agency Response: PennDOT agrees with the finding. Questioned Costs: The amount of questioned costs cannot be determined. The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Show full finding ▾
Full finding narrative

Department of Transportation Finding 2020 ? 014: CFDA #20.205 and 20.219 ? Highway Planning and Construction Cluster A Significant Deficiency and Noncompliance Exist Related to Monitoring of Locally Sponsored Projects Federal Grant Number(s) and Year(s): N78000 (7/01/2019 ? 6/30/2020) Type of Finding: Significant Deficiency, Noncompliance Compliance Requirement: Subrecipient Monitoring Condition: The Department of Transportation (PennDOT) administers the Highway Planning and Construction (HPC) Cluster which is funded by the United States Department of Transportation. Our audit of PennDOT?s monitoring of HPC Cluster subrecipient local projects to evaluate compliance with subrecipient monitoring requirements disclosed that the monitoring was not adequate for the fiscal year ended June 30, 2020. HPC Cluster subrecipient expenditures were $124.5 million (7.3 percent) out of total HPC Cluster expenditures of $1.7 billion reported on the June 30, 2020 Schedule of Expenditures of Federal Awards. A local project typically exists when a construction project is located on a street or highway for which PennDOT does not have legal jurisdiction. In such cases, PennDOT may arrange for the local public agency to perform contract work with its own forces or by outside contract. However, it should be noted that PennDOT is responsible for the construction of all federally aided projects and is not relieved of its responsibility by authorizing performance of the work by a local public agency. PennDOT developed Publication 740, Local Project Delivery Manual, to provide guidance on managing local projects to agency personnel in PennDOT?s 11 engineering district offices. The publication is a compilation of PennDOT policies and procedures relating to the letting, inspection, and management of local construction contracts. In particular, the publication covers the staffing requirements of local municipalities, as well as PennDOT?s on-site monitoring and oversight in the form of review checklists. Publication 740 requires that PennDOT personnel complete the review checklists maintained in Publication 2, Project Office Manual, at least quarterly. The review checklists are important documents which provide evidence of PennDOT?s district offices? on-site monitoring of local subrecipient projects for compliance with various federal regulations, including allowability of project activity costs, materials certifications and control, wage compliance, and other requirements. We selected a sample of 10 federally funded locally sponsored projects to evaluate the adequacy of PennDOT?s subrecipient monitoring. Our review of the 10 locally sponsored projects totaling $31.1 million consisted of projects in 3 engineering districts. Documented evidence of properly completed project checklists could not be provided for the one project tested in District 01 with expenditures totaling $736.7 thousand. Criteria: 2 CFR Section 200.331, Requirements for pass through entities, states in part: All pass-through entities must: (d) Monitor the activities of the subrecipient as necessary to ensure that the subaward is used for authorized purposes, in compliance with Federal statutes, regulations, and the terms and conditions of the subaward; and that subaward performance goals are achieved. Management Directive 325.12, Standards for Internal Control for Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book), published in September 2014. The Green Book states in part: Finding 2020 ? 014: (continued) Management should design control activities to achieve objectives and respond to risks. Management should implement control activities through policies. Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. PennDOT Publication 740, Local Project Delivery Manual, Chapter 7, Construction Phase, states: The Contractor?s work and the Local Project Sponsor?s inspection are to be reviewed by the District. The Assistant District Executive for Construction is to assign an ACE to monitor and oversee the project. The ACE or a designee is to visit the project as frequently as needed to maintain an intimate knowledge of current activities and ensure that the work is being inspected and the contract administered in accordance with the terms of the agreement, the requirements of FHWA, and the procedures outlined herein. During each visit to the project or at least quarterly when the project control meetings are being attended on a regular basis, the ACE or designee is to document, in writing, the project status and any outstanding issues. To assist the Districts with their project oversight responsibilities, a checklist has been developed and incorporated into Publication 2, Project Office Manual, Section C.1.18, Checklist for the Administration of Locally Sponsored Federal-Aid Projects. This checklist must be utilized when visiting a Locally Sponsored Federal-Aid project for monitoring and oversight purposes. The checklist is intended to provide uniformity in reviews, as well as documentation that required oversight is being performed. Completed checklists may be requested during annual federal audits. Cause: PennDOT has established subrecipient monitoring procedures for locally sponsored projects which require adequate documentation in the form of timely and properly completed checklists. However, PennDOT stated that a vacancy in the District 01 manager position responsible for checklist completion and oversights contributed to the checklist in question not being completed. Effect: Many of the requirements in Publication 740 are designed to ensure compliance with federal regulations related to locally sponsored projects, including the timely and adequate completion of the checklists described in Publication 2. Lack of sufficient adherence to the policy can result in inadequate oversight for local projects within the districts. Federal funds may be used improperly or not in compliance with federal regulations, and noncompliance may not be timely detected and corrected without adequate oversight. Recommendation: PennDOT should ensure that the established procedures within Publication 740 are adhered to and the checklists described in Publication 2 are adequately and timely completed in order to prevent control deficiencies related to local project oversight and to ensure documented compliance with federal regulations. Agency Response: PennDOT agrees with the finding. Questioned Costs: The amount of questioned costs cannot be determined. The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Corrective Action Plan

An email will be sent to the Assistant District Engineer (ADE) for each district explaining the issue. The email will contain guidelines for new project review requirements for federal funded local projects. The new requirements will be that a checklist review will be done on the projects at the beginning of every month until project completion and will be required to be attached in ECMS. The new requirement will be in place for the next 12 months. An email will also be sent on the first of every month to the ADE in all the districts to remind them that a checklist review is needed for federal funded local projects and will need to be attached in ECMS within seven days. These new review requirements will be in place for the next 12 months. Anticipated Completion Date: 02/28/2022 Contact People: James Goodrich, Trans. Constr. Mgr. 2; Michele Harter, Contr. Mgmt. Section Chief; Tom Miller, Civil Eng. Mgr., Trans.

About Subrecipient Monitoring →
2020-015
Other
REPEAT

As part of testing internal controls over major programs, we performed certain tests of information technology (IT) general controls, including procedures to determine the status of prior year Single Audit Finding 2019 ? 014. Our procedures disclosed the following control deficiencies in applications supported by the Public Safety Delivery Center and the Employment, Banking, and Revenue (EBR) Delivery Center: 1. In the Crime Victim Assistance program, as noted in the prior year, we found a lack of segregation of duties between application development and promotion of code to production. 2. In the Rehabilitation Services ? Vocational Rehabilitation Grants to States program, we noted administrative/privileged accounts that could be accessed by unauthorized individuals. A detailed schedule of issues has been provided to the Office of Administration, Office for information Technology (OA-OIT), for corrective action. Criteria: Management Directive 325.12, Standards for Internal Control for Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book), published in September 2014. ? Green Book Principle 11 ? Design Activities for the Information System, states in part: o 11.04 Management designs the entity?s information system and the use of information technology? Additionally, information technology may enhance internal control over security and confidentiality of information by appropriately restricting access. o 11.12 Management designs control activities over access to protect an entity from inappropriate access and unauthorized use of the system. These control activities support appropriate segregation of duties. By preventing unauthorized use of and changes to the system, data and program integrity are protected from malicious intent (e.g., someone breaking into the technology to commit fraud, vandalism, or terrorism) or error. o 11.14 Management designs control activities to limit user access to information technology through authorization control activities such as providing a unique user identification or token to authorized users. These control activities may restrict authorized users to the applications or functions commensurate with their assigned responsibilities, supporting an appropriate segregation of duties. Management designs other control activities to promptly update access rights when employees change job functions or leave the entity. Finding 2020 ? 015: (continued) A well-designed system of internal controls dictates that effective general computer controls, which include adequate segregation of duties, access controls to programs and data, appropriate monitoring, and controls to update access rights, be established and functioning to ensure that overall agency operations are conducted in accordance with management?s intent. Cause: In the Crime Victim Assistance program, corrective action to remediate the prior year segregation of duties weakness was not implemented until December 2020. Further, in the current audit year, we noted that both developers were granted administrative access to the change management software tool. Although the tool was configured to send an automated email to a third party when a developer approved code to production, no process had been implemented to document monitoring of the notification emails. As for the weakness noted in the Rehabilitation Services program, while OA-OIT has implemented an automated process to remove inactive Commonwealth network accounts, no process has been implemented to remove inactive accounts from individual applications. Further, when users transferred to other duties within the Commonwealth, system administrators were not notified promptly to update access rights. Effect: The deficiencies noted above in IT general controls could result in unauthorized changes to the software and noncompliance with federal laws and regulations. Segregation of duties weaknesses, inappropriate privileged access, as well as untimely deletion of access when no longer needed, all contribute to the risk that system actions can occur that are not in accordance with management?s intent. Further, unauthorized accounts with administrative access increases the risk that accounts could be misused, either intentionally or unintentionally by authorized users, or by unauthorized external entities that have compromised the accounts. Finally, without properly functioning controls over segregation of duties, privileged access, and updating access rights, the auditors are precluded from reliance on computer controls in these agencies. Recommendation: We recommend that OA-OIT continue its efforts to resolve the general computer control deficiencies noted above. Specific consideration should be given to: ? Segregating the development of programs from promotion to the production environment; ? When segregation of duties is not possible, developing formal processes to document monitoring of developers who have the ability to implement code to production; ? Implementing a process to remove inactive accounts from individual applications; and ? Designing controls to notify systems administrators when users change duties or no longer require access to allow for prompt updating of access rights. Agency Response: OA-OIT agrees with the finding. Questioned Costs: None The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Show full finding ▾
Full finding narrative

Office of Administration ? Office for Information Technology Finding 2020 ? 015: CFDA #16.575 ? Crime Victim Assistance CFDA #84.126 ? Rehabilitation Services ? Vocational Rehabilitation Grants to States Information Technology General Controls Need Improvement (A Similar Condition Was Noted in Prior Year Finding 2019-014) Federal Grant Number(s) and Year(s): 2018-V2-GX-0068 (10/01/2017 ? 9/30/2021), 2017-VA-GX-0069 (10/01/2016 ? 9/30/2020), 2016-VA-GX-0048 (10/01/2015 ? 9/30/2019), H126A200056 (10/01/2019 ? 9/30/2020), H126A190056 (10/01/2018 ? 9/30/2019) Type of Finding: Significant Deficiency Compliance Requirement: Other Condition: As part of testing internal controls over major programs, we performed certain tests of information technology (IT) general controls, including procedures to determine the status of prior year Single Audit Finding 2019 ? 014. Our procedures disclosed the following control deficiencies in applications supported by the Public Safety Delivery Center and the Employment, Banking, and Revenue (EBR) Delivery Center: 1. In the Crime Victim Assistance program, as noted in the prior year, we found a lack of segregation of duties between application development and promotion of code to production. 2. In the Rehabilitation Services ? Vocational Rehabilitation Grants to States program, we noted administrative/privileged accounts that could be accessed by unauthorized individuals. A detailed schedule of issues has been provided to the Office of Administration, Office for information Technology (OA-OIT), for corrective action. Criteria: Management Directive 325.12, Standards for Internal Control for Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book), published in September 2014. ? Green Book Principle 11 ? Design Activities for the Information System, states in part: o 11.04 Management designs the entity?s information system and the use of information technology? Additionally, information technology may enhance internal control over security and confidentiality of information by appropriately restricting access. o 11.12 Management designs control activities over access to protect an entity from inappropriate access and unauthorized use of the system. These control activities support appropriate segregation of duties. By preventing unauthorized use of and changes to the system, data and program integrity are protected from malicious intent (e.g., someone breaking into the technology to commit fraud, vandalism, or terrorism) or error. o 11.14 Management designs control activities to limit user access to information technology through authorization control activities such as providing a unique user identification or token to authorized users. These control activities may restrict authorized users to the applications or functions commensurate with their assigned responsibilities, supporting an appropriate segregation of duties. Management designs other control activities to promptly update access rights when employees change job functions or leave the entity. Finding 2020 ? 015: (continued) A well-designed system of internal controls dictates that effective general computer controls, which include adequate segregation of duties, access controls to programs and data, appropriate monitoring, and controls to update access rights, be established and functioning to ensure that overall agency operations are conducted in accordance with management?s intent. Cause: In the Crime Victim Assistance program, corrective action to remediate the prior year segregation of duties weakness was not implemented until December 2020. Further, in the current audit year, we noted that both developers were granted administrative access to the change management software tool. Although the tool was configured to send an automated email to a third party when a developer approved code to production, no process had been implemented to document monitoring of the notification emails. As for the weakness noted in the Rehabilitation Services program, while OA-OIT has implemented an automated process to remove inactive Commonwealth network accounts, no process has been implemented to remove inactive accounts from individual applications. Further, when users transferred to other duties within the Commonwealth, system administrators were not notified promptly to update access rights. Effect: The deficiencies noted above in IT general controls could result in unauthorized changes to the software and noncompliance with federal laws and regulations. Segregation of duties weaknesses, inappropriate privileged access, as well as untimely deletion of access when no longer needed, all contribute to the risk that system actions can occur that are not in accordance with management?s intent. Further, unauthorized accounts with administrative access increases the risk that accounts could be misused, either intentionally or unintentionally by authorized users, or by unauthorized external entities that have compromised the accounts. Finally, without properly functioning controls over segregation of duties, privileged access, and updating access rights, the auditors are precluded from reliance on computer controls in these agencies. Recommendation: We recommend that OA-OIT continue its efforts to resolve the general computer control deficiencies noted above. Specific consideration should be given to: ? Segregating the development of programs from promotion to the production environment; ? When segregation of duties is not possible, developing formal processes to document monitoring of developers who have the ability to implement code to production; ? Implementing a process to remove inactive accounts from individual applications; and ? Designing controls to notify systems administrators when users change duties or no longer require access to allow for prompt updating of access rights. Agency Response: OA-OIT agrees with the finding. Questioned Costs: None The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Corrective Action Plan

OA-OIT will remove write access from developers and have database administrators as the only staff with write access to databases. Developers can retain read access for troubleshooting and debugging. Additionally, OA-OIT will implement quarterly reviews of the groups/users to help ensure more timely and accurate user access rights. Anticipated Completion Date: 08/01/2021 Contact People: Joseph Centurione,Business Relationship Manager; Josh Williams, Solutions Mgr.; Brandon Sarzynski, Del. Center Info. Sec. Off.; Bill McLean, Chief, Workforce Development & Info. Div.

Prior Finding References

2019-014

About Other →
2020-016
Reporting

The Pennsylvania Department of Human Services (DHS) is required to submit the CMS-64, Quarterly Statement of Expenditures for the Medical Assistance Program (CMS-64 Report), on a quarterly basis to the United States Department of Health and Human Services (HHS). The CMS-64 Report includes data related to the Medicaid Cluster expenditures, recoveries, and other items that reduce expenditures for the quarter and prior period expenditures, including donations, taxes, fees, and assessments. During the fiscal year ended June 30, 2020, we selected two out of four quarterly CMS-64 Reports for testing. The CMS-64 Report submitted for the quarter ended June 30, 2020 excluded an assessments amount from the Summary Total of Receipts from Form CMS 64.11, Line 5, which should have been included per the Commonwealth?s general ledger (SAP) as follows: Assessments amount per the CMS-64 Report $734,784,714 Assessments amount per SAP $752,531,494 CMS-64 Report Understatement ($17,746,780) Although the CMS-64 Report was subjected to a documented supervisory review and approval, the existence of the understated assessments amount indicates that the preparation and the supervisory review and approval processes were not adequate, and a significant deficiency exists over the preparation and submission of the CMS-64 Report. In addition, our procedures disclosed that the Commonwealth?s reconciliation of federal grant awards, revenue, and expenditures for the federal Medicaid grants which closed September 30, 2019 have not been performed as of our January 2021 test date, which is not timely. Criteria: 45 CFR Section 75.302, Financial management and standards for financial management systems, states: (b) The financial management system of each non-Federal entity must provide for the following: (2) Accurate, current, and complete disclosure of the financial results of each Federal award or program in accordance with the reporting requirements set forth in ?75.341 and 75.342. 42 CFR Section 431.16, Reports, states: A State plan must provide that the Medicaid agency will ? (a) Submit all reports required by the Secretary; (b) Follow the Secretary?s instructions with regard to the form and content of those reports; and (c) Comply with any provisions that the Secretary finds necessary to verify and assure the correctness of the reports. Finding 2020 ? 016: (continued) 42 CFR Section 433.74, Reporting requirements, states: (a) Beginning with the first quarter of Federal fiscal year 1993, each State must submit to CMS quarterly summary information on the source and use of all provider-related donations (including all bona fide and presumed-to-be bona fide donations) received by the State or unit of local government, and health care-related taxes collected. Each State must also provide any additional information requested by the Secretary related to any other donations made by, or any taxes imposed on, health care providers. States? reports must present a complete, accurate, and full disclosure of all of their donation and tax programs and expenditures. (d) If a State fails to comply with the reporting requirements contained in this section, future grant awards will be reduced by the amount of FFP CMS estimates is attributable to the sums raised by tax and donation programs as to which the State has not reported properly, until such time as the State complies with the reporting requirements. Deferrals and/or disallowances of equivalent amounts may also be imposed with respect to quarters for which the State has failed to report properly. Unless otherwise prohibited by law, FFP for those expenditures will be released when the State complies with all reporting requirements. Further, adequate internal controls over report submission would include detailed written report preparation procedures, a segregation of duties between the preparation and the review and approval of the report, and an adequate review and approval process which would detect errors in the report preparation and ensure that such errors are corrected on a timely basis. Management Directive 325.12, Standards for Internal Control for Commonwealth Agencies, effective July 1, 2015, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book), published in September 2014. The Green Book states in part: Management should design control activities to achieve objectives and respond to risks. Management should externally communicate the necessary quality information to achieve the entity?s objectives. Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: The understatement was discovered as a result of auditor inquiry, and the Commonwealth?s Office of Comptroller Operations (OCO) personnel stated they corrected the error by including the $17,746,780 assessments amount in the subsequent quarter ending September 30, 2020 CMS-64 Report. OCO personnel represented that they implemented a reconciliation process covering the federal fiscal year ending September 30 to ensure all assessments had been accounted for in the final CMS-64 Report (quarter ending September 30, 2020). However, the timing of this federal fiscal year reconciliation was not sufficient to ensure the accuracy of the quarter ending June 30, 2020 CMS-64 Report assessments amounts. Regarding the untimely grant reconciliations, OCO personnel indicated that they are currently working with CMS in order to reconcile the grant awards. Effect: Since the preparation and the supervisory review and approval processes were not adequate to ensure the accurate reporting of assessments, the CMS-64 Report was misstated for the quarter ended June 30, 2020. DHS was not in compliance with federal regulations, and a significant deficiency exists. If the significant deficiency is not corrected, inaccurate reporting could result in future grant awards being reduced. The untimely grant reconciliations could result in errors not being detected or corrected on a timely basis. Finding 2020 ? 016: (continued) Recommendation: OCO should ensure that the preparation and supervisory review and approval processes for the CMS-64 Report are improved, include all required information including assessments, and any reconciliations are performed on a quarterly basis to ensure accurate quarterly reporting. OCO should ensure their written procedures for the preparation, review, approval, and submission of the CMS-64 Report are sufficiently detailed to ensure the CMS-64 Report is prepared accurately in accordance with federal regulations each quarter. OCO should ensure federal grant reconciliations are performed on a timely basis in order to promptly identify and investigate any discrepancies and ensure compliance with federal requirements. Agency Response: OCO agrees with the finding. Questioned Costs: None The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Show full finding ▾
Full finding narrative

Office of the Budget ? Office of Comptroller Operations Finding 2020 ? 016: CFDA #93.775, 93.777, and 93.778 ? Medicaid Cluster (including COVID-19) A Significant Deficiency and Noncompliance Exist Over the Preparation and Submission of the Quarterly CMS-64 Report Federal Grant Number(s) and Year(s): 2005PA5MAP (10/01/2019 ? 9/30/2020), 2005PA5ADM (10/01/2019 ? 9/30/2020), 1905PA5MAP (10/01/2018 ? 9/30/2019), 1905PA5ADM (10/01/2018 ? 9/30/2019) Type of Finding: Significant Deficiency, Noncompliance Compliance Requirement: Reporting Condition: The Pennsylvania Department of Human Services (DHS) is required to submit the CMS-64, Quarterly Statement of Expenditures for the Medical Assistance Program (CMS-64 Report), on a quarterly basis to the United States Department of Health and Human Services (HHS). The CMS-64 Report includes data related to the Medicaid Cluster expenditures, recoveries, and other items that reduce expenditures for the quarter and prior period expenditures, including donations, taxes, fees, and assessments. During the fiscal year ended June 30, 2020, we selected two out of four quarterly CMS-64 Reports for testing. The CMS-64 Report submitted for the quarter ended June 30, 2020 excluded an assessments amount from the Summary Total of Receipts from Form CMS 64.11, Line 5, which should have been included per the Commonwealth?s general ledger (SAP) as follows: Assessments amount per the CMS-64 Report $734,784,714 Assessments amount per SAP $752,531,494 CMS-64 Report Understatement ($17,746,780) Although the CMS-64 Report was subjected to a documented supervisory review and approval, the existence of the understated assessments amount indicates that the preparation and the supervisory review and approval processes were not adequate, and a significant deficiency exists over the preparation and submission of the CMS-64 Report. In addition, our procedures disclosed that the Commonwealth?s reconciliation of federal grant awards, revenue, and expenditures for the federal Medicaid grants which closed September 30, 2019 have not been performed as of our January 2021 test date, which is not timely. Criteria: 45 CFR Section 75.302, Financial management and standards for financial management systems, states: (b) The financial management system of each non-Federal entity must provide for the following: (2) Accurate, current, and complete disclosure of the financial results of each Federal award or program in accordance with the reporting requirements set forth in ?75.341 and 75.342. 42 CFR Section 431.16, Reports, states: A State plan must provide that the Medicaid agency will ? (a) Submit all reports required by the Secretary; (b) Follow the Secretary?s instructions with regard to the form and content of those reports; and (c) Comply with any provisions that the Secretary finds necessary to verify and assure the correctness of the reports. Finding 2020 ? 016: (continued) 42 CFR Section 433.74, Reporting requirements, states: (a) Beginning with the first quarter of Federal fiscal year 1993, each State must submit to CMS quarterly summary information on the source and use of all provider-related donations (including all bona fide and presumed-to-be bona fide donations) received by the State or unit of local government, and health care-related taxes collected. Each State must also provide any additional information requested by the Secretary related to any other donations made by, or any taxes imposed on, health care providers. States? reports must present a complete, accurate, and full disclosure of all of their donation and tax programs and expenditures. (d) If a State fails to comply with the reporting requirements contained in this section, future grant awards will be reduced by the amount of FFP CMS estimates is attributable to the sums raised by tax and donation programs as to which the State has not reported properly, until such time as the State complies with the reporting requirements. Deferrals and/or disallowances of equivalent amounts may also be imposed with respect to quarters for which the State has failed to report properly. Unless otherwise prohibited by law, FFP for those expenditures will be released when the State complies with all reporting requirements. Further, adequate internal controls over report submission would include detailed written report preparation procedures, a segregation of duties between the preparation and the review and approval of the report, and an adequate review and approval process which would detect errors in the report preparation and ensure that such errors are corrected on a timely basis. Management Directive 325.12, Standards for Internal Control for Commonwealth Agencies, effective July 1, 2015, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book), published in September 2014. The Green Book states in part: Management should design control activities to achieve objectives and respond to risks. Management should externally communicate the necessary quality information to achieve the entity?s objectives. Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: The understatement was discovered as a result of auditor inquiry, and the Commonwealth?s Office of Comptroller Operations (OCO) personnel stated they corrected the error by including the $17,746,780 assessments amount in the subsequent quarter ending September 30, 2020 CMS-64 Report. OCO personnel represented that they implemented a reconciliation process covering the federal fiscal year ending September 30 to ensure all assessments had been accounted for in the final CMS-64 Report (quarter ending September 30, 2020). However, the timing of this federal fiscal year reconciliation was not sufficient to ensure the accuracy of the quarter ending June 30, 2020 CMS-64 Report assessments amounts. Regarding the untimely grant reconciliations, OCO personnel indicated that they are currently working with CMS in order to reconcile the grant awards. Effect: Since the preparation and the supervisory review and approval processes were not adequate to ensure the accurate reporting of assessments, the CMS-64 Report was misstated for the quarter ended June 30, 2020. DHS was not in compliance with federal regulations, and a significant deficiency exists. If the significant deficiency is not corrected, inaccurate reporting could result in future grant awards being reduced. The untimely grant reconciliations could result in errors not being detected or corrected on a timely basis. Finding 2020 ? 016: (continued) Recommendation: OCO should ensure that the preparation and supervisory review and approval processes for the CMS-64 Report are improved, include all required information including assessments, and any reconciliations are performed on a quarterly basis to ensure accurate quarterly reporting. OCO should ensure their written procedures for the preparation, review, approval, and submission of the CMS-64 Report are sufficiently detailed to ensure the CMS-64 Report is prepared accurately in accordance with federal regulations each quarter. OCO should ensure federal grant reconciliations are performed on a timely basis in order to promptly identify and investigate any discrepancies and ensure compliance with federal requirements. Agency Response: OCO agrees with the finding. Questioned Costs: None The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Corrective Action Plan

Assessment 1. The assessment amount that was not reported on the quarter ending June 30, 2020 (QE0620) CMS-64 report was discovered during a federal fiscal year (FFY) end reconciliation of assessments before closeout of the grant which occurs on the September 30 CMS-64 report. The omitted assessment amount was included on the quarter ending September 30, 2020 (QE0920) CMS-64 report which is acceptable by CMS. Anticipated Completion Date: Completed Contact Person: Tammy S. Miller, Administrative Officer 4 2. A variant has been established in Business Warehouse (BW) for extraction of the assessment amounts by general ledger (GL) each quarter. Anticipated Completion Date: Completed Contact Person: Tammy S. Miller, Administrative Officer 4 3. As a further validation step (as mentioned in 1. above), the Department of Human Services (DHS) General Accounting team performs an annual reconciliation to ensure all assessments have been reported correctly, and any differences are reported on the quarter ending September 30 report. Anticipated Completion Date: Completed Contact Person: Tammy S. Miller, Administrative Officer 4 4. The DHS General Accounting team maintains a procedure and checklist for the reporting of assessments on the CMS-64, which includes managerial review and approval each quarter prior to certification of the report. Anticipated Completion Date: Completed Contact Person: Tammy S. Miller, Administrative Officer 4 Grant Reconciliation The grant award reconciliations are in process. The goal is to have the grant award analysis complete and reconciled within six months after quarter end so when the CMS finalization award is received, the Department of Human Services (DHS) General Accounting Unit can validate CMS' grant award analysis timely. Enhancements have been made to the grant award reconciliation process over the past two years which have resulted in more timely reconciling of current grant awards. The grant award resulting in this finding is from federal fiscal year (FFY) 2018. For this particular reconciliation, the DHS General Accounting team did not receive the finalization award from CMS until 11 months after quarter end. The finalization award is typically received within six months after quarter end. The SAP expenditures were reconciled to the grant award and to the CMS-64 report prior to receiving the finalization. However, as a result of two disallowances reflected in the FFY18 grant award from prior grants years (FFY13 and FFY17) being reduced in duplicate on the finalization award, the grant award allotment in PMS was deficient. The DHS General Accounting Unit continues to work with CMS to resolve the grant award. Follow-up requests have been sent to CMS and we continue to await a response. Anticipated Completion Date: 03/31/2021 Contact Person: Tammy S. Miller, Administrative Officer 4

About Reporting →
2020-017
Period of Performance
REPEATQUESTIONED COSTS

During our audit of the Crime Victim Assistance (CVA) program funded by the United States Department of Justice, we evaluated and tested the Pennsylvania Commission on Crime and Delinquency?s (PCCD) internal control and compliance with period of performance requirements for the grant award that closed during the fiscal year ended June 30, 2020. Our procedures disclosed $179,816 of CVA expenditures were incurred and charged subsequent to the end of the federal grant period that closed on September 30, 2019, which was in violation of period of performance requirements. CVA expenditures reported on the Schedule of Expenditures of Federal Awards for the fiscal year ended June 30, 2020 totaled $81.6 million, and $78 million of that total was passed through to subrecipients. Criteria: 2 CFR Section 200.303(a), Internal controls, states: The non-Federal entity must: Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in ?Standards for Internal Control in the Federal Government? issued by the Comptroller General of the United States or the ?Internal Control Integrated Framework?, issued by the committee of the Sponsoring Organizations of the Treadway Commission (COSO). 2 CFR Section 200.309, Period of performance, states: A non-Federal entity may charge to the Federal award only allowable costs incurred during the period of performance (except as described in ?200.461 Publication and printing costs) and any costs incurred before the Federal awarding agency or pass-through entity made the Federal award that were authorized by the Federal awarding agency or pass-through entity. Management Directive 325.12, Standards for Internal Control for Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book), published in September 2014. The Green Book states in part: Finding 2020 ? 017: (continued) Management should design control activities to achieve objectives and respond to risks. Management should implement control activities through policies. Cause: PCCD personnel did not have adequate procedures in place to ensure that costs incurred were charged within the period of performance. Effect: Expenditures passed through to subrecipients were improperly charged to the federal grant subsequent to the period of performance without authorization by the federal awarding agency, resulting in noncompliance and $179,816 in questioned costs. Recommendation: We recommend that PCCD personnel implement procedures to ensure that subrecipient costs are incurred and charged within the proper period of performance or to obtain prior federal authorization for any costs charged outside the period of performance. Agency Response: PCCD has reviewed the preliminary finding related to the administration of the Crime Victim Assistance Program funded by the Department of Justice and agrees with the facts of this finding. Questioned Costs: Known questioned costs for CFDA #16.575 of $179,816 were determined, which represent subrecipient expenditures incurred and charged subsequent to the period of performance. The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Show full finding ▾
Full finding narrative

Pennsylvania Commission on Crime and Delinquency Finding 2020 ? 017: CFDA #16.575 ? Crime Victim Assistance A Significant Deficiency and Noncompliance Exist in the Pennsylvania Commission on Crime and Delinquency?s Procedures Related to Period of Performance Requirements (A Similar Condition Was Noted in Prior Year Finding 2019-017) Federal Grant Number(s) and Year(s): 2016-VA-GX-0048 (10/01/2015 ? 9/30/2019) Type of Finding: Significant Deficiency, Noncompliance Compliance Requirement: Period of Performance Condition: During our audit of the Crime Victim Assistance (CVA) program funded by the United States Department of Justice, we evaluated and tested the Pennsylvania Commission on Crime and Delinquency?s (PCCD) internal control and compliance with period of performance requirements for the grant award that closed during the fiscal year ended June 30, 2020. Our procedures disclosed $179,816 of CVA expenditures were incurred and charged subsequent to the end of the federal grant period that closed on September 30, 2019, which was in violation of period of performance requirements. CVA expenditures reported on the Schedule of Expenditures of Federal Awards for the fiscal year ended June 30, 2020 totaled $81.6 million, and $78 million of that total was passed through to subrecipients. Criteria: 2 CFR Section 200.303(a), Internal controls, states: The non-Federal entity must: Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in ?Standards for Internal Control in the Federal Government? issued by the Comptroller General of the United States or the ?Internal Control Integrated Framework?, issued by the committee of the Sponsoring Organizations of the Treadway Commission (COSO). 2 CFR Section 200.309, Period of performance, states: A non-Federal entity may charge to the Federal award only allowable costs incurred during the period of performance (except as described in ?200.461 Publication and printing costs) and any costs incurred before the Federal awarding agency or pass-through entity made the Federal award that were authorized by the Federal awarding agency or pass-through entity. Management Directive 325.12, Standards for Internal Control for Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book), published in September 2014. The Green Book states in part: Finding 2020 ? 017: (continued) Management should design control activities to achieve objectives and respond to risks. Management should implement control activities through policies. Cause: PCCD personnel did not have adequate procedures in place to ensure that costs incurred were charged within the period of performance. Effect: Expenditures passed through to subrecipients were improperly charged to the federal grant subsequent to the period of performance without authorization by the federal awarding agency, resulting in noncompliance and $179,816 in questioned costs. Recommendation: We recommend that PCCD personnel implement procedures to ensure that subrecipient costs are incurred and charged within the proper period of performance or to obtain prior federal authorization for any costs charged outside the period of performance. Agency Response: PCCD has reviewed the preliminary finding related to the administration of the Crime Victim Assistance Program funded by the Department of Justice and agrees with the facts of this finding. Questioned Costs: Known questioned costs for CFDA #16.575 of $179,816 were determined, which represent subrecipient expenditures incurred and charged subsequent to the period of performance. The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Corrective Action Plan

Internal operating procedures have been revised to include an additional level of review of transactions posted within the liquidation period after the end of the federal award period. The period of performance of the expenditures and the termination date of the federal award have been cross-referenced to ensure that federal grant(s) are charged correctly. A revised Federal Financial Report will be submitted for the 2016-VA-GX-0048 award that removes the charges where the period of performance was verified to have been outside of the grant period. The amount charged to the federal grant for activities conducted outside the grant period will be refunded to the United States Department of Justice. Anticipated Completion Date: Completed Contact Person: Chris Epoca, Manager, Grants Management

Prior Finding References

2019-017

About Period of Performance →
2020-018
Subrecipient Monitoring
MATERIAL WEAKNESSREPEATQUESTIONED COSTS

During the fiscal year ended June 30, 2020, the Pennsylvania Commission on Crime and Delinquency (PCCD) paid $78 million in Crime Victim Assistance (CVA) program funding to subrecipients, which represented over 95 percent of the total federal CVA expenditures of $81.6 million reported on the Schedule of Expenditures of Federal Awards. United States Department of Justice (USDOJ) regulations in effect during our audit period require PCCD to conduct on-site monitoring at least once every two years on all subrecipients that receive federal funding for providing crime victim services. PCCD?s monitoring procedures specify tracking subrecipients that received federal funds on a calendar year basis and require on-site monitoring of subrecipients at least once every two years. Our audit identified 157 subrecipients that received federal funding during both years of the two year period ending December 31, 2019. PCCD did not conduct the required on-site monitoring at least once during this period for 40 of these subrecipients. Along with the remaining 117 subrecipients that were monitored, there were 7 additional subrecipients that received funding during the one year period ending December 31, 2019. These 7 subrecipients were on-site monitored by PCCD in 2019, bringing the total of on-site monitored subrecipients to 124 during the two year period. We tested a sample of 20 subrecipients out of the 124 subrecipients which were on-site monitored in order to evaluate the adequacy of the monitoring procedures performed by PCCD. Our testing disclosed that for 16 of the 20 subrecipients selected, PCCD did not issue the monitoring report to the subrecipient within eight weeks (56 days) after the on-site visit as required by PCCD?s internal monitoring procedures. The 16 monitoring reports were issued from 71 to 448 days after the on-site visit, with an average of 186 days after the date of the on-site visit. Further, PCCD?s supervisory review and approval of the subrecipient monitoring reports did not occur timely for the same 16 subrecipients plus one additional subrecipient, or 17 total, after the on-site reports were issued to the subrecipient and any corrective actions, if necessary, were made. Criteria: 28 CFR Section 94.106, Monitoring Requirements, states: (a) Monitoring plan. Unless the Director grants a waiver, SAAs [State Administering Agencies] shall develop and implement a monitoring plan in accordance with the requirements of this section and 2 CFR 200.331. The monitoring plan must include a risk assessment plan. (b) Monitoring frequency. SAAs shall conduct regular desk monitoring of all sub-recipients. In addition, SAAs shall conduct on-site monitoring of all subrecipients at least once every two years during the award period, unless a different frequency based on risk assessment is set out in the monitoring plan. (c) Recordkeeping. SAAs shall maintain a copy of site visit results and other documents related to compliance. Finding 2020 ? 018: (continued) 2 CFR Section 200.331, Requirements for Pass-through Entities, states in part: Pass-through entity monitoring of the subrecipient must include: (e) Depending upon the pass-through entity's assessment of risk posed by the subrecipient (as described in paragraph (b) of this section), the following monitoring tools may be useful for the pass-through entity to ensure proper accountability and compliance with program requirements and achievement of performance goals: (1) Providing subrecipients with training and technical assistance on program-related matters; and (2) Performing on-site reviews of the subrecipient's program operations; (3) Arranging for agreed-upon-procedures engagements as described in ?200.425 Audit services Management Directive 325.12, Standards for Internal Control for Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book), published in September 2014. The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: PCCD management indicated they have experienced a substantial increase in federal funding for the CVA program over the past several years which required more on-site visits. In addition, the revised federal monitoring guidelines issued in July 2016 changed the requirement for on-site visits from every four years to every two years. PCCD management also stated that there are no federally mandated guidelines or internal procedures to determine the timeliness of supervisory review and approval of the on-site monitoring report, whether corrective actions are necessary or not. Effect: PCCD did not comply with federal regulations in effect during our audit period. As a result, CVA subrecipients could be operating in noncompliance with federal regulations without timely detection and correction. A significant number of subrecipients expended individually less than $750,000 in total federal awards from the Commonwealth during the fiscal year ended June 30, 2019, and as a result would not have been required by Uniform Guidance to have a Single Audit performed. Therefore, these subrecipients were only subject to on-site monitoring by the program. The timely completion of these on-site visits, supervisory review and approval, and issuance of the monitoring reports is vital in providing PCCD with information necessary to determine whether the program?s subrecipients are complying with federal regulations. Recommendation: PCCD should strengthen its procedures to ensure on-site monitoring of all CVA subrecipients is performed in accordance with the applicable USDOJ monitoring regulations. PCCD should also ensure that the monitoring reports are issued to subrecipients within eight weeks after the on-site visit to allow subrecipients time to implement corrective actions. Furthermore, after the monitoring report is sent to the subrecipient and, if necessary, any corrective actions are taken, the report should be timely reviewed and approved by a PCCD supervisor. Agency Response: PCCD agrees with the facts of this finding with exception to the statement that supervisory review and approval of the monitoring reports was not timely. PCCD policy requires that only newly hired staff are required to submit their initial monitoring reports for review prior to issuance to the recipient agency. Supervisory review and approval occurs prior to the closure of the monitoring event and includes the recipient agencies? responses to the monitoring report conclusions. Finding 2020 ? 018: (continued) Auditors? Conclusion: The agency response from PCCD acknowledged the finding. During our current year inquiry about monitoring procedures, PCCD did not bring to our attention any change in their procedures regarding only newly hired staff being required to submit their initial monitoring reports for review prior to issuance to the recipient agency. A similar condition was noted in our prior year finding related to monitoring and there was no mention of this policy for newly hired staff noted in the prior year or in our current year update inquiry. We will evaluate PCCD?s corrective action in our subsequent audit. Questioned Costs: The amount of questioned costs cannot be determined. The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Show full finding ▾
Full finding narrative

Pennsylvania Commission on Crime and Delinquency Finding 2020 ? 018: CFDA #16.575 ? Crime Victim Assistance Material Weakness and Material Noncompliance Exist in the Pennsylvania Commission on Crime and Delinquency Monitoring of Crime Victim Assistance Program Subrecipients (A Similar Condition Was Noted in Prior Year Finding 2019-018) Federal Grant Number(s) and Year(s): 2018-V2-GX-0068 (10/01/2017 ? 9/30/2021), 2017-VA-GX-0069 (10/01/2016 ? 9/30/2020), 2016-VA-GX-0048 (10/01/2015 ? 9/30/2019) Type of Finding: Material Weakness, Material Noncompliance Compliance Requirement: Subrecipient Monitoring Condition: During the fiscal year ended June 30, 2020, the Pennsylvania Commission on Crime and Delinquency (PCCD) paid $78 million in Crime Victim Assistance (CVA) program funding to subrecipients, which represented over 95 percent of the total federal CVA expenditures of $81.6 million reported on the Schedule of Expenditures of Federal Awards. United States Department of Justice (USDOJ) regulations in effect during our audit period require PCCD to conduct on-site monitoring at least once every two years on all subrecipients that receive federal funding for providing crime victim services. PCCD?s monitoring procedures specify tracking subrecipients that received federal funds on a calendar year basis and require on-site monitoring of subrecipients at least once every two years. Our audit identified 157 subrecipients that received federal funding during both years of the two year period ending December 31, 2019. PCCD did not conduct the required on-site monitoring at least once during this period for 40 of these subrecipients. Along with the remaining 117 subrecipients that were monitored, there were 7 additional subrecipients that received funding during the one year period ending December 31, 2019. These 7 subrecipients were on-site monitored by PCCD in 2019, bringing the total of on-site monitored subrecipients to 124 during the two year period. We tested a sample of 20 subrecipients out of the 124 subrecipients which were on-site monitored in order to evaluate the adequacy of the monitoring procedures performed by PCCD. Our testing disclosed that for 16 of the 20 subrecipients selected, PCCD did not issue the monitoring report to the subrecipient within eight weeks (56 days) after the on-site visit as required by PCCD?s internal monitoring procedures. The 16 monitoring reports were issued from 71 to 448 days after the on-site visit, with an average of 186 days after the date of the on-site visit. Further, PCCD?s supervisory review and approval of the subrecipient monitoring reports did not occur timely for the same 16 subrecipients plus one additional subrecipient, or 17 total, after the on-site reports were issued to the subrecipient and any corrective actions, if necessary, were made. Criteria: 28 CFR Section 94.106, Monitoring Requirements, states: (a) Monitoring plan. Unless the Director grants a waiver, SAAs [State Administering Agencies] shall develop and implement a monitoring plan in accordance with the requirements of this section and 2 CFR 200.331. The monitoring plan must include a risk assessment plan. (b) Monitoring frequency. SAAs shall conduct regular desk monitoring of all sub-recipients. In addition, SAAs shall conduct on-site monitoring of all subrecipients at least once every two years during the award period, unless a different frequency based on risk assessment is set out in the monitoring plan. (c) Recordkeeping. SAAs shall maintain a copy of site visit results and other documents related to compliance. Finding 2020 ? 018: (continued) 2 CFR Section 200.331, Requirements for Pass-through Entities, states in part: Pass-through entity monitoring of the subrecipient must include: (e) Depending upon the pass-through entity's assessment of risk posed by the subrecipient (as described in paragraph (b) of this section), the following monitoring tools may be useful for the pass-through entity to ensure proper accountability and compliance with program requirements and achievement of performance goals: (1) Providing subrecipients with training and technical assistance on program-related matters; and (2) Performing on-site reviews of the subrecipient's program operations; (3) Arranging for agreed-upon-procedures engagements as described in ?200.425 Audit services Management Directive 325.12, Standards for Internal Control for Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book), published in September 2014. The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: PCCD management indicated they have experienced a substantial increase in federal funding for the CVA program over the past several years which required more on-site visits. In addition, the revised federal monitoring guidelines issued in July 2016 changed the requirement for on-site visits from every four years to every two years. PCCD management also stated that there are no federally mandated guidelines or internal procedures to determine the timeliness of supervisory review and approval of the on-site monitoring report, whether corrective actions are necessary or not. Effect: PCCD did not comply with federal regulations in effect during our audit period. As a result, CVA subrecipients could be operating in noncompliance with federal regulations without timely detection and correction. A significant number of subrecipients expended individually less than $750,000 in total federal awards from the Commonwealth during the fiscal year ended June 30, 2019, and as a result would not have been required by Uniform Guidance to have a Single Audit performed. Therefore, these subrecipients were only subject to on-site monitoring by the program. The timely completion of these on-site visits, supervisory review and approval, and issuance of the monitoring reports is vital in providing PCCD with information necessary to determine whether the program?s subrecipients are complying with federal regulations. Recommendation: PCCD should strengthen its procedures to ensure on-site monitoring of all CVA subrecipients is performed in accordance with the applicable USDOJ monitoring regulations. PCCD should also ensure that the monitoring reports are issued to subrecipients within eight weeks after the on-site visit to allow subrecipients time to implement corrective actions. Furthermore, after the monitoring report is sent to the subrecipient and, if necessary, any corrective actions are taken, the report should be timely reviewed and approved by a PCCD supervisor. Agency Response: PCCD agrees with the facts of this finding with exception to the statement that supervisory review and approval of the monitoring reports was not timely. PCCD policy requires that only newly hired staff are required to submit their initial monitoring reports for review prior to issuance to the recipient agency. Supervisory review and approval occurs prior to the closure of the monitoring event and includes the recipient agencies? responses to the monitoring report conclusions. Finding 2020 ? 018: (continued) Auditors? Conclusion: The agency response from PCCD acknowledged the finding. During our current year inquiry about monitoring procedures, PCCD did not bring to our attention any change in their procedures regarding only newly hired staff being required to submit their initial monitoring reports for review prior to issuance to the recipient agency. A similar condition was noted in our prior year finding related to monitoring and there was no mention of this policy for newly hired staff noted in the prior year or in our current year update inquiry. We will evaluate PCCD?s corrective action in our subsequent audit. Questioned Costs: The amount of questioned costs cannot be determined. The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Corrective Action Plan

1. PCCD implemented the USDOJ Office for Victims of Crime (OVC) Approved Alternative Monitoring Plan that allowed for risk-based monitoring on January 1, 2020. All required monitorings based on this risk-based level were conducted in 2020. 2. Office of Victim Services (OVS) will ensure staff continue to release monitoring reports within 8-weeks of the monitoring date. In 2020, OVS released all monitoring reports within 8-weeks. 3. OVS staff will modify the OVS Monitoring Guidelines to provide a specific number of days in which a supervisor must review and take action (approve or return) on a monitoring report submitted for compliance by the employee. Anticipated Completion Date: Completed Contact Person: Kathleen Buckley, Director, OVS; Jeffrey Blystone, Deputy Director, OVS

Prior Finding References

2019-018

About Subrecipient Monitoring →
2020-019
Reporting

During our audit of the Crime Victim Assistance (CVA) program funded by the United States Department of Justice (USDOJ), we evaluated and tested the Pennsylvania Commission on Crime and Delinquency?s (PCCD) internal controls and compliance with annual performance reporting requirements. We reviewed the annual performance report covering the period October 1, 2018 through September 30, 2019, which was submitted during December 2019. The annual performance report includes a compilation of various data that is electronically reported to PCCD quarterly by subrecipients that received pass-through funds from PCCD during the annual period. The annual performance report is then submitted by PCCD to USDOJ electronically. Our testing of the annual report disclosed discrepancies related to the number of reported victims served within 15 of the 26 different victimization types for the quarter ended September 30, 2019 between the PCCD quarterly reports and the quarterly information contained in the annual report. Specifically, we noted differences ranging from 1 to 115, both positive and negative differences. Criteria: The Special Conditions sections of the grant awards issued each year by the USDOJ Office for Victims of Crime (OVC) require performance reports. Specifically, grant award 2018-V2-GX-0068 states the following in special condition number 37: The recipient agrees to submit (and, as necessary, requires subrecipients to submit) quarterly performance reports on the performance metrics identified by OVC, and in the manner required by OVC. This information on the activities supported by the award funding will assist in assessing the effects that VOCA [Victims of Crime Act] Victim Assistance funds have had on services to crime victims within the jurisdiction. 28 CFR Section 94.105(a) and (b), Reporting requirements, states: (a) Subgrant award reports. SAAs [state administering agencies] shall submit, at such times and in such form and manner as OVC may specify from time to time, subgrant award reports to OVC for each project that receives VOCA funds. If an SAA awards funds to a pass-through entity, the SAA also shall submit a report on the pass-through entity, at such times and in such form and manner as OVC may specify from time to time. (b) Performance report. SAAs shall submit, in such form and manner as OVC may specify from time to time, performance reports to OVC on a quarterly basis. Finding 2020 ? 019: (continued) 2 CFR Section 200.303(a), Internal controls, states: The non-Federal entity must: Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in ?Standards for Internal Control in the Federal Government? issued by the Comptroller General of the United States or the ?Internal Control Integrated Framework?, issued by the committee of the Sponsoring Organizations of the Treadway Commission (COSO). Management Directive 325.12, Standards for Internal Control for Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book), published in September 2014. The Green Book states in part: Management should design control activities to achieve objectives and respond to risks. Management should externally communicate the necessary quality information to achieve the entity?s objectives. Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: PCCD officials stated that the vendor of the PCCD Efforts to Outcome (ETO) system did not complete work on the Victims of Crimes Act (VOCA) report on time, which resulted in subrecipients being late in entering the September 30, 2019 quarterly performance reports into the ETO system. Also, the submission of the quarterly reports by PCCD was handled differently that quarter, because PCCD personnel had to manually enter the data into the federal Performance Measurement Tool (PMT) due to the batch upload feature not functioning properly. PCCD officials also stated that some reporting discrepancies identified were related to the erroneous data in the reports of four subrecipients? Victim Service Programs. The subrecipients addressed these discrepancies and were required to resubmit their reports; however, the resubmitted reports were never updated in the federal PMT system. Furthermore, two instances where a subrecipient?s quarterly report did not match the information reported in the federal PMT system were attributed to data entry errors on the part of PCCD staff. Effect: The performance data was not accurately reported for the quarter ended September 30, 2019, and resulted in inaccurate information being reported to USDOJ in the state annual performance report. As a result, PCCD was not in compliance with annual performance reporting requirements. Recommendation: Although PCCD has procedures in place to review subrecipient performance information submitted and to compile the subrecipient information into overall performance reports which are submitted to USDOJ, PCCD should ensure these procedures are adequately designed and functioning properly to verify the accuracy of the subrecipient information reported and to ensure the accuracy of the overall performance reports. Agency Response: PCCD has reviewed the finding related to the administration of the Crime Victim Assistance Program funded by the Department of Justice and agrees with the facts of the finding. Questioned Costs: None The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Show full finding ▾
Full finding narrative

Pennsylvania Commission on Crime and Delinquency Finding 2020 ? 019: CFDA #16.575 ? Crime Victim Assistance A Significant Deficiency and Noncompliance Exist in the Pennsylvania Commission on Crime and Delinquency?s Procedures Related to Performance Reporting Requirements Federal Grant Number(s) and Year(s): 2019-V2-GX-0026 (10/01/2018 ? 9/30/2022), 2018-V2-GX-0068 (10/01/2017 ? 9/30/2021), 2017-VA-GX-0069 (10/01/2016 ? 9/30/2020), 2016-VA-GX-0048 (10/01/2015 ? 9/30/2019) Type of Finding: Significant Deficiency, Noncompliance Compliance Requirement: Reporting Condition: During our audit of the Crime Victim Assistance (CVA) program funded by the United States Department of Justice (USDOJ), we evaluated and tested the Pennsylvania Commission on Crime and Delinquency?s (PCCD) internal controls and compliance with annual performance reporting requirements. We reviewed the annual performance report covering the period October 1, 2018 through September 30, 2019, which was submitted during December 2019. The annual performance report includes a compilation of various data that is electronically reported to PCCD quarterly by subrecipients that received pass-through funds from PCCD during the annual period. The annual performance report is then submitted by PCCD to USDOJ electronically. Our testing of the annual report disclosed discrepancies related to the number of reported victims served within 15 of the 26 different victimization types for the quarter ended September 30, 2019 between the PCCD quarterly reports and the quarterly information contained in the annual report. Specifically, we noted differences ranging from 1 to 115, both positive and negative differences. Criteria: The Special Conditions sections of the grant awards issued each year by the USDOJ Office for Victims of Crime (OVC) require performance reports. Specifically, grant award 2018-V2-GX-0068 states the following in special condition number 37: The recipient agrees to submit (and, as necessary, requires subrecipients to submit) quarterly performance reports on the performance metrics identified by OVC, and in the manner required by OVC. This information on the activities supported by the award funding will assist in assessing the effects that VOCA [Victims of Crime Act] Victim Assistance funds have had on services to crime victims within the jurisdiction. 28 CFR Section 94.105(a) and (b), Reporting requirements, states: (a) Subgrant award reports. SAAs [state administering agencies] shall submit, at such times and in such form and manner as OVC may specify from time to time, subgrant award reports to OVC for each project that receives VOCA funds. If an SAA awards funds to a pass-through entity, the SAA also shall submit a report on the pass-through entity, at such times and in such form and manner as OVC may specify from time to time. (b) Performance report. SAAs shall submit, in such form and manner as OVC may specify from time to time, performance reports to OVC on a quarterly basis. Finding 2020 ? 019: (continued) 2 CFR Section 200.303(a), Internal controls, states: The non-Federal entity must: Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in ?Standards for Internal Control in the Federal Government? issued by the Comptroller General of the United States or the ?Internal Control Integrated Framework?, issued by the committee of the Sponsoring Organizations of the Treadway Commission (COSO). Management Directive 325.12, Standards for Internal Control for Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book), published in September 2014. The Green Book states in part: Management should design control activities to achieve objectives and respond to risks. Management should externally communicate the necessary quality information to achieve the entity?s objectives. Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: PCCD officials stated that the vendor of the PCCD Efforts to Outcome (ETO) system did not complete work on the Victims of Crimes Act (VOCA) report on time, which resulted in subrecipients being late in entering the September 30, 2019 quarterly performance reports into the ETO system. Also, the submission of the quarterly reports by PCCD was handled differently that quarter, because PCCD personnel had to manually enter the data into the federal Performance Measurement Tool (PMT) due to the batch upload feature not functioning properly. PCCD officials also stated that some reporting discrepancies identified were related to the erroneous data in the reports of four subrecipients? Victim Service Programs. The subrecipients addressed these discrepancies and were required to resubmit their reports; however, the resubmitted reports were never updated in the federal PMT system. Furthermore, two instances where a subrecipient?s quarterly report did not match the information reported in the federal PMT system were attributed to data entry errors on the part of PCCD staff. Effect: The performance data was not accurately reported for the quarter ended September 30, 2019, and resulted in inaccurate information being reported to USDOJ in the state annual performance report. As a result, PCCD was not in compliance with annual performance reporting requirements. Recommendation: Although PCCD has procedures in place to review subrecipient performance information submitted and to compile the subrecipient information into overall performance reports which are submitted to USDOJ, PCCD should ensure these procedures are adequately designed and functioning properly to verify the accuracy of the subrecipient information reported and to ensure the accuracy of the overall performance reports. Agency Response: PCCD has reviewed the finding related to the administration of the Crime Victim Assistance Program funded by the Department of Justice and agrees with the facts of the finding. Questioned Costs: None The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Corrective Action Plan

OVS will update its existing procedures to include: 1. Data entered into PMT manually will be verified at the end of every quarter. 2. Quarterly data will be reconciled with the VOCA Annual Report from PMT every year. 3. Resubmission of data in PMT when discrepancies are found after the quarterly PMT has been submitted. (This will need to be discussed with OVC to determine if PMT can actually be updated after the fact, and the effects these changes will have on the annual report. Further guidance from OVC will be needed.) Anticipated Completion Date: 04/30/2021 Contact People: Kathleen Buckley, Director, OVS; Jeffrey Blystone, Deputy Director, OVS

About Reporting →
2020-020
Subrecipient Monitoring
REPEATQUESTIONED COSTS

The Uniform Guidance in 2 CFR Section 200 applies to the major programs listed above for the fiscal year ended June 30, 2020. Our testing disclosed that the state agencies did not identify the federal award information and applicable requirements in subrecipient award documents. Additionally, the state agencies did not evaluate each subrecipient?s risk of noncompliance for the purpose of determining the appropriate subrecipient monitoring related to the subaward. This represents an internal control weakness which causes subrecipients to be improperly informed of federal award information and not adequately monitored by the state agencies. Also, it could cause the omission or improper identification of program expenditures on subrecipients? Schedules of Expenditures of Federal Awards (SEFAs). The following chart shows which federal award information required by 2 CFR Section 200 was omitted (as indicated by ?No?) from the subrecipient award documents at the time of the subaward and which major programs did not have a state agency evaluation of each subrecipient?s risk of noncompliance. SEE SCHEDULE OF FINDINGS AND QUESTIONED COSTS FOR CHART/TABLE. Finding 2020 ? 020: (continued) SEE SCHEDULE OF FINDINGS AND QUESTIONED COSTS FOR CHART/TABLE. (The cells with a hyphen in the table indicate that the federal award information was included in the subrecipient award documents or was not applicable for the respective major program.) (1) Although an evaluation of subrecipient risk was conducted, the only risk factor used in the evaluation was the error rate detected for the county subrecipients. The evaluation is deemed inadequate since there was no written evidence that the risk assessment considered other risk factors, such as the risk factors identified in 2 CFR Section 200.331. Criteria: 2 CFR Section 200.331, Requirements for Pass-through Entities, states in part: All pass-through entities must: (a) Ensure that every subaward is clearly identified to the subrecipient as a subaward and includes the following information at the time of the subaward and if any of these data elements change, include the changes in subsequent subaward modification. When some of this information is not available, the pass-through entity must provide the best information available to describe the Federal award and subaward. Required information includes: (1) Federal Award Identification. (iii) Federal Award Identification Number (FAIN); (iv) Federal Award Date (see section 200.39 Federal award date) of award to the recipient by the Federal agency; (v) Subaward Period of Performance Start and End Date; (x) Name of Federal awarding agency, pass-through entity, and contact information for awarding official of the pass-through entity; (xi) CFDA Number and Name; the pass-through entity must identify the dollar amount made available under each Federal award and the CFDA number at time of disbursement; (6) Appropriate terms and conditions concerning closeout of the subaward. (b) Evaluate each subrecipient?s risk of noncompliance with Federal statutes, regulations, and the terms and conditions of the subaward for purposes of determining the appropriate subrecipient monitoring described in paragraphs (d) and (e) of this section, which may include consideration of such factors as: (1) The subrecipient?s prior experience with the same or similar subawards; Finding 2020 ? 020: (continued) (2) The results of previous audits including whether or not the subrecipient receives a Single Audit in accordance with Subpart F?Audit Requirements of this part, and the extent to which the same or similar subaward has been audited as a major program; (3) Whether the subrecipient has new personnel or new or substantially changed systems; and (4) The extent and results of Federal awarding agency monitoring (e.g., if the subrecipient also receives Federal awards directly from a Federal awarding agency). Management Directive 325.12, Standards for Internal Control for Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book), published in September 2014. The Green Book states in part: Management should identify, analyze, and respond to risks related to achieving the defined objectives. Management should identify, analyze, and respond to significant changes that could impact the internal control system. Cause: In general, the state agencies? process for subrecipient award monitoring did not identify the omission of required elements from the grant awards. In addition, the risk assessments performed by the agencies were not properly documented. Effect: Excluding the federal grant award information at the time of the subaward may cause subrecipients and their auditors to be uninformed about specific program and other regulations that apply to the funds they receive. There is also the potential for subrecipients to have incomplete SEFAs in their Single Audit reports submitted to the Commonwealth, and federal funds may not be properly audited at the subrecipient level in accordance with the Single Audit Act and Uniform Guidance. Not evaluating each subrecipient?s risk of noncompliance for purposes of determining the appropriate subrecipient monitoring related to the subaward may result in subrecipients using the subaward for unauthorized purposes or in violation of the terms and conditions of the subaward, and state agency monitoring would not detect this noncompliance and ensure it is corrected in a timely manner. Recommendation: State agencies should develop policies and reporting mechanisms to ensure all required federal award information is disseminated to all subrecipients at the time of the subaward to ensure subrecipient compliance with the Uniform Guidance in 2 CFR Section 200 and other applicable federal regulations. In addition, state agencies should correspond with applicable subrecipients to ensure they are aware of the correct federal award information and review applicable subaward documents prior to issuance to ensure federal information is complete and accurate. State agencies should also implement procedures to adequately document their evaluation of each subrecipient?s risk of noncompliance as cited in 2 CFR Section 200.331 for purposes of determining the appropriate subrecipient monitoring related to the subaward. PennDOT Response: PennDOT agrees with the finding. DHS Response: DHS agrees with the finding. Questioned Costs: The amount of questioned costs cannot be determined. The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Show full finding ▾
Full finding narrative

Various Agencies Finding 2020 ? 020: CFDA #20.205 and 20.219 ? Highway Planning and Construction Cluster CFDA #93.558 ? Temporary Assistance for Needy Families CFDA #93.658 ? Foster Care ? Title IV-E (including COVID-19) CFDA #93.659 ? Adoption Assistance (including COVID-19) State Agencies Did Not Identify the Federal Award Information and Applicable Requirements at the Time of the Subaward and Did Not Evaluate Each Subrecipient?s Risk of Noncompliance as Required by the Uniform Grant Guidance (A Similar Condition Was Noted in Prior Year Finding 2019-019) Federal Grant Number(s) and Year(s): N78000 (7/01/2019 ? 6/30/2020), 2001PATANF (10/01/2019 ? 9/30/2020), 1901PATANF (10/01/2018 ? 9/30/2019), 2001PAFOST (10/01/2019 ? 9/30/2020), 1901PAFOST (10/01/2018 ? 9/30/2019), 1801PAFOST (10/01/2017 ? 9/30/2018), 2001PAADPT (10/01/2019 ? 9/30/2020), 1901PAADPT (10/01/2018 ? 9/30/2019) Type of Finding: Significant Deficiency, Noncompliance Compliance Requirement: Subrecipient Monitoring Condition: The Uniform Guidance in 2 CFR Section 200 applies to the major programs listed above for the fiscal year ended June 30, 2020. Our testing disclosed that the state agencies did not identify the federal award information and applicable requirements in subrecipient award documents. Additionally, the state agencies did not evaluate each subrecipient?s risk of noncompliance for the purpose of determining the appropriate subrecipient monitoring related to the subaward. This represents an internal control weakness which causes subrecipients to be improperly informed of federal award information and not adequately monitored by the state agencies. Also, it could cause the omission or improper identification of program expenditures on subrecipients? Schedules of Expenditures of Federal Awards (SEFAs). The following chart shows which federal award information required by 2 CFR Section 200 was omitted (as indicated by ?No?) from the subrecipient award documents at the time of the subaward and which major programs did not have a state agency evaluation of each subrecipient?s risk of noncompliance. SEE SCHEDULE OF FINDINGS AND QUESTIONED COSTS FOR CHART/TABLE. Finding 2020 ? 020: (continued) SEE SCHEDULE OF FINDINGS AND QUESTIONED COSTS FOR CHART/TABLE. (The cells with a hyphen in the table indicate that the federal award information was included in the subrecipient award documents or was not applicable for the respective major program.) (1) Although an evaluation of subrecipient risk was conducted, the only risk factor used in the evaluation was the error rate detected for the county subrecipients. The evaluation is deemed inadequate since there was no written evidence that the risk assessment considered other risk factors, such as the risk factors identified in 2 CFR Section 200.331. Criteria: 2 CFR Section 200.331, Requirements for Pass-through Entities, states in part: All pass-through entities must: (a) Ensure that every subaward is clearly identified to the subrecipient as a subaward and includes the following information at the time of the subaward and if any of these data elements change, include the changes in subsequent subaward modification. When some of this information is not available, the pass-through entity must provide the best information available to describe the Federal award and subaward. Required information includes: (1) Federal Award Identification. (iii) Federal Award Identification Number (FAIN); (iv) Federal Award Date (see section 200.39 Federal award date) of award to the recipient by the Federal agency; (v) Subaward Period of Performance Start and End Date; (x) Name of Federal awarding agency, pass-through entity, and contact information for awarding official of the pass-through entity; (xi) CFDA Number and Name; the pass-through entity must identify the dollar amount made available under each Federal award and the CFDA number at time of disbursement; (6) Appropriate terms and conditions concerning closeout of the subaward. (b) Evaluate each subrecipient?s risk of noncompliance with Federal statutes, regulations, and the terms and conditions of the subaward for purposes of determining the appropriate subrecipient monitoring described in paragraphs (d) and (e) of this section, which may include consideration of such factors as: (1) The subrecipient?s prior experience with the same or similar subawards; Finding 2020 ? 020: (continued) (2) The results of previous audits including whether or not the subrecipient receives a Single Audit in accordance with Subpart F?Audit Requirements of this part, and the extent to which the same or similar subaward has been audited as a major program; (3) Whether the subrecipient has new personnel or new or substantially changed systems; and (4) The extent and results of Federal awarding agency monitoring (e.g., if the subrecipient also receives Federal awards directly from a Federal awarding agency). Management Directive 325.12, Standards for Internal Control for Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book), published in September 2014. The Green Book states in part: Management should identify, analyze, and respond to risks related to achieving the defined objectives. Management should identify, analyze, and respond to significant changes that could impact the internal control system. Cause: In general, the state agencies? process for subrecipient award monitoring did not identify the omission of required elements from the grant awards. In addition, the risk assessments performed by the agencies were not properly documented. Effect: Excluding the federal grant award information at the time of the subaward may cause subrecipients and their auditors to be uninformed about specific program and other regulations that apply to the funds they receive. There is also the potential for subrecipients to have incomplete SEFAs in their Single Audit reports submitted to the Commonwealth, and federal funds may not be properly audited at the subrecipient level in accordance with the Single Audit Act and Uniform Guidance. Not evaluating each subrecipient?s risk of noncompliance for purposes of determining the appropriate subrecipient monitoring related to the subaward may result in subrecipients using the subaward for unauthorized purposes or in violation of the terms and conditions of the subaward, and state agency monitoring would not detect this noncompliance and ensure it is corrected in a timely manner. Recommendation: State agencies should develop policies and reporting mechanisms to ensure all required federal award information is disseminated to all subrecipients at the time of the subaward to ensure subrecipient compliance with the Uniform Guidance in 2 CFR Section 200 and other applicable federal regulations. In addition, state agencies should correspond with applicable subrecipients to ensure they are aware of the correct federal award information and review applicable subaward documents prior to issuance to ensure federal information is complete and accurate. State agencies should also implement procedures to adequately document their evaluation of each subrecipient?s risk of noncompliance as cited in 2 CFR Section 200.331 for purposes of determining the appropriate subrecipient monitoring related to the subaward. PennDOT Response: PennDOT agrees with the finding. DHS Response: DHS agrees with the finding. Questioned Costs: The amount of questioned costs cannot be determined. The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Corrective Action Plan

PENNDOT: PennDOT has included the CFDA title and number in all agreements in the system. PennDOT is reviewing all agreements to ensure they contain a notice provision. Any agreement in the system that does not contain a notice provision will have an attachment uploaded with party contacts to satisfy the notice requirement. Based on a meeting with Auditor General staff, PennDOT?s Office of Chief Counsel (OCC) staff members believe these steps will correct the issues cited in the audit finding. Anticipated Completion Date: 12/31/2021 Contact People: Nick Balzer, Asst. Counsel,OCC; Dougie Chon, Asst. Counsel, OCC; Ryan Shiffler, Project Dev. Eng., Bur. of Proj. Delivery DHS: Temporary Assistance for Needy Families, Foster Care and Adoption Assistance: Fiscal year 2020-2021 Tentative Allocation Letters were issued by March 5, 2021. Federal Award Information for FY20-21 will be shared with Counties and Child Welfare agencies prior to March 31st and will include the Amount, CFDA Number and Title. The Final Allocation Letters that go out in July 2021 will have an attachment with all the Federal Award information. This will include the Amount, Federal Award Identification Number (FAIN); Federal Award Date; Subaward Period of Performance Start and End Date; Name of Federal awarding agency, pass-through entity, and contact information for awarding official; CFDA Number and Title. OCYF has a risk assessment process in place for Title IV-E and TANF awards. During the Quality Assurance reviews, which occur twice a year at a minimum, OCYF reviews a sample of Title IV-E eligible foster care cases, Title IV-E ineligible foster care cases, Title IV-E eligible adoption assistance cases, and TANF eligible cases. Depending on the number of eligibility and claiming errors identified during the review, OCYF schedules more frequent visits as the risk of repeated and continued errors in these CCYAs is higher. Inaccurate eligibility determinations lead to inaccurate federal claiming, so basing the review schedule on a CCYA?s eligibility review outcome allows OCYF to target those CCYAs where inaccurate claiming is a higher risk. However, to address this finding, we will include written evidence that the risk assessment considers other risk factors, such as the risk factors identified in 2 CFR Section 200.331 in future risk assessments. OCYF is in the process of working with DHS? Bureau of Financial Operations to develop a more substantial risk assessment tool and for developing a letter with all of the required subrecipient information for the federal awards. Anticipated Completion Date: 06/30/2021 Contact Person: Tia Petrovitz, Fiscal Management Specialist 4

Prior Finding References

2019-019

About Subrecipient Monitoring →
2020-021
Subrecipient Monitoring
MATERIAL WEAKNESSREPEATQUESTIONED COSTS

Under the Commonwealth of Pennsylvania's (Commonwealth) implementation of the Single Audit Act, review and resolution of subrecipient Single Audit reports is split into two stages. The Office of the Budget?s Bureau of Accounting and Financial Management (OB-BAFM) ensures the reports meet technical standards through a centralized desk review process. The various funding agencies in the Commonwealth are responsible for making a management decision on each finding within six months of the Federal Audit Clearinghouse?s (FAC) Management Decision Letter (MDL) start date for audits subject to Uniform Guidance and to ensure appropriate corrective action is taken by the subrecipient (except for Uniform Guidance audits under U.S. Department of Labor programs which are permitted 12 months for management decisions in accordance with 2 CFR Section 2900.21). Each Commonwealth agency is also Finding 2020 ? 021: (continued) responsible for reviewing financial information in each audit report to determine whether the audit included all pass-through funding provided by the agency in order to ensure pass-through funds were subject to audit. Most agencies meet this requirement by performing Schedule of Expenditures of Federal Awards (SEFA) reconciliations. The agency is also required to adjust Commonwealth records, if necessary. Our fiscal year ended June 30, 2020 audit of the Commonwealth?s process for review and resolution of subrecipient Single Audits included an evaluation of the Commonwealth?s fiscal year ended June 30, 2019 subrecipient audit universe for audits due for submission to the FAC during the fiscal year ended June 30, 2020. We also evaluated the Commonwealth?s review of 39 subrecipient audit reports with findings in major programs/clusters which were identified on the Commonwealth agencies? tracking lists during the fiscal year ended June 30, 2020, and required management decisions by Commonwealth agencies. Our testing disclosed the following audit exceptions regarding the Commonwealth agencies? review of subrecipient audit reports: ? Department of Community and Economic Development (DCED): The time period for making a management decision on findings was approximately 7.7 months and 8.1 months after the MDL start date for two out of five subrecipient audit reports with findings. ? Department of Drug and Alcohol Programs (DDAP): The time period for making a management decision on findings was approximately 9.7 months after the FAC MDL start date for one subrecipient audit report with findings. There was also a delay in the completion of the SEFA reconciliation for the subrecipient audit report in question. ? Department of Environmental Protection (DEP): The time period for making a management decision on findings was approximately 7.4 months and 16.9 months after the FAC MDL start date for two audit reports with findings. ? Department of Human Services (DHS): The time period for making a management decision on findings ranged from approximately 8.1 months to 22.9 months after the FAC MDL start date for 16 out of 23 subrecipient audit reports with findings. There was also a delay in DHS?s procedures to ensure the subrecipient SEFAs were accurate so that major programs were properly determined and subject to audit. In addition, our review disclosed that four subrecipient audit reports with findings for which DHS was the lead agency were submitted late to the FAC, with FAC acceptance dates ranging from approximately 5.4 months to 10.8 months after the Single Audit due date. ? Department of Transportation (PennDOT): The time period for making a management decision on findings was approximately 13 months after the FAC MDL start date for one out of six subrecipient audit reports with findings. ? Pennsylvania Commission on Crime and Delinquency (PCCD): The time period for making a management decision on findings was approximately 10.4 months after the FAC MDL start date for one out of five subrecipient audit reports with findings. As a follow-up to the prior year finding, we noted that the Commonwealth subgranted federal funds totaling $243,508,881 to the City of Philadelphia during the fiscal year ended June 30, 2019, for which a Single Audit was submitted to the FAC on January 31, 2021. This was 4 months after the September 30, 2020 due date, which had been extended due to the COVID-19 pandemic in accordance with the Office of Management and Budget?s Memorandum M-20-26, Appendix A. Our testing disclosed that DHS?s and DDAP?s subgrants to the City of Philadelphia were material for five of the 12 major programs/clusters with material subgranted funds. Our follow-up on the prior year finding also disclosed that the Commonwealth subgranted federal funds totaling $30,413,828 to Bucks County during the fiscal year ended December 31, 2018. The audit was submitted to the FAC on October 31, 2019, which was one month after the September 30, 2019 due date. Finding 2020 ? 021: (continued) DHS was the lead agency for the City of Philadelphia and Bucks County audits. Criteria: 2 CFR ?200.331, Requirements for pass-through entities, states in part: All pass-through entities must: (d) Monitor the activities of the subrecipient as necessary to ensure that the subaward is used for authorized purposes, in compliance with Federal statutes, regulations, and the terms and conditions of the subaward, and that subaward performance goals are achieved. Pass-through entity monitoring of the subrecipient must include: (2) Following-up and ensuring that the subrecipient takes timely and appropriate action on all deficiencies pertaining to the Federal award provided to the subrecipient from the pass-through entity detected through audits, on-site reviews, and other means. (3) Issuing a management decision for audit findings pertaining to the Federal award provided to the subrecipient from the pass-through entity as required by ? 200.521 Management decision. (f) Verify that every subrecipient is audited as required by Subpart F ? Audit Requirements of this part when it is expected that the subrecipient?s Federal awards expended during the respective fiscal year equaled or exceeded the threshold set forth in ? 200.501 Audit requirements. (g) Consider whether the results of the subrecipient?s audit, on-site review, or other monitoring indicate conditions that necessitate adjustments to the pass-through entity?s own records. (h) Consider taking enforcement action against noncompliant subrecipients as described in ?200.338 Remedies for noncompliance of this part and in program regulations. In order to carry out these responsibilities properly, good internal control dictates that state pass-through agencies ensure subrecipient Single Audit SEFAs are representative of state payment records each year, and that the related federal programs have been properly subjected to Single Audit procedures. 2 CFR ?200.512, Report submission, states in part: (a) General. (1) The audit must be completed and the data collection form described in paragraph (b) of this section and reporting package described in paragraph (c) of this section must be submitted within the earlier of 30 calendar days after receipt of the auditor?s report(s), or nine months after the end of the audit period. 2 CFR ?200.521, Management decision, states in part: (a) General. The management decision must clearly state whether or not the finding is sustained, the reasons for the decision, and the expected auditee action to repay disallowed costs, make financial adjustments, or take other action. (d) Time requirements. The Federal awarding agency or pass-through entity responsible for issuing a management decision must do so within six months of acceptance of the audit report by the FAC. The auditee must initiate and proceed with corrective action as rapidly as possible and corrective action should begin no later than upon receipt of the audit report. 2 CFR ?200.505, Sanctions, states: In cases of continued inability or unwillingness to have an audit conducted in accordance with this part, Federal agencies and pass-through entities must take appropriate action as provided in ?200.338 Remedies for noncompliance. Finding 2020 ? 021: (continued) 2 CFR ?200.338, Remedies for noncompliance, states in part: If a non-Federal entity fails to comply with Federal statutes, regulations or the terms and conditions of a Federal award, the Federal awarding agency or pass-through entity may impose additional conditions, as described in ?200.207 Specific conditions. If the Federal awarding agency or pass-through entity determines that noncompliance cannot be remedied by imposing additional conditions, the federal awarding agency or pass-through entity may take one or more of the following actions, as appropriate in the circumstances. (a) Temporarily withhold cash payments pending correction of the deficiency by the non-Federal entity or more severe enforcement action by the Federal awarding agency or pass-through entity. (b) Disallow (that is, deny both use of funds and any applicable matching credit for) all or part of the cost of the activity or action not in compliance. (c) Wholly or partly suspend or terminate the Federal award. (d) Initiate suspension or debarment proceedings as authorized under 2 CFR Part 180 and Federal awarding agency regulations (or in the case of a pass-through entity, recommend such a proceeding be initiated by a Federal awarding agency). (e) Withhold further Federal awards for the project or program. (f) Take other remedies that may be legally available. To ensure Commonwealth enforcement of federal regulations for subrecipient noncompliance with audit requirements, Commonwealth Management Directive 325.8, Remedies for Recipient Noncompliance with Audit Requirements, Section 5 related to policy, states in part: (a) Agencies must develop and implement remedial action that reflects the unique requirements of each program? (b) Overall periods for the implementation of remedial action should not exceed six months from the date the first remedial action is initiated. At the end of the six-month period, the recipient should take the appropriate corrective action or the final stage of remedial action should be imposed on the recipient. Examples of remedial action include, but are not limited to: (4) Withholding a portion of assistance payments until the noncompliance is resolved. (5) Withholding or disallowing overhead costs until the noncompliance is resolved. (6) Suspending the assistance agreement until the noncompliance is resolved. (7) Terminating the assistance agreement with the recipient and, if necessary, seeking alternative entities to administer the program. Management Directive 325.9, Processing Audits of Federal Pass-Through Funds, Section 7 related to procedures, states in part: c. Agencies. (1) Evaluate single audit report submissions received from BOA to determine program purpose acceptability by verifying, at a minimum, that all agency-funded programs are properly included on the applicable financial schedules; that findings affecting the agency contain sufficient information to facilitate a management decision; and that the subrecipient has submitted an adequate corrective action plan. Finding 2020 ? 021: (continued) (6) Impose or coordinate the imposition of remedial action in accordance with 2 CFR Part 200.338 and Management Directive 325.8, Remedies for Recipient Noncompliance with Audit Requirements, when subrecipients fail to comply with the provisions of Subpart F. Management Directive 325.12, Standards for Internal Control for Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s, Standards for Internal Control in the Federal Government (Green Book), published in September 2014. The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: One reason provided by Commonwealth management for untimely audit resolution in the various agencies, including making management decisions, approving corrective action, and performing procedures to ensure the accuracy of subrecipient SEFAs was either a change in staff or a lack of staff to follow up and process subrecipient audit reports more timely. Late management decisions also occurred because some agencies did not use OB-BAFM?s weekly notifications of audit reports with federal findings available on the FAC website to identify audits requiring management decisions. Instead, agencies waited until OB-BAFM personnel completed their desk review of subrecipient audits before starting the management decision process. PCCD personnel indicated the management decision was performed as part of program monitoring of the subrecipient but was not formally documented. Regarding late and outstanding audit report submissions, the Commonwealth agencies did not appear to be timely implementing remedial action steps in accordance with 2 CFR ?200.338 and Commonwealth Management Directive 325.8, Section 5 (a) and (b), in order to ensure compliance with federal audit submission requirements. DHS indicated that Commonwealth Management Directive 325.8, Section 5 (f), Policy, makes the federal cognizant agency which provided direct funding to Philadelphia City responsible for remedial action to comply with Subpart F of 2 CFR ?200. Effect: Since required management decisions were not made within six months to ensure appropriate corrective action was taken on audits received from subrecipients, the Commonwealth did not comply with federal regulations, and subrecipients were not made aware of acceptance or rejection of corrective action plans in a timely manner. Further, noncompliance may recur in future periods if control deficiencies are not corrected on a timely basis, and there is an increased risk of unallowable charges being made to federal programs if corrective action and recovery of questioned costs is not timely. Regarding the SEFA reviews or alternate procedures which are not being performed timely and the late Single Audit report submissions, there is an increased risk that subrecipients could be misspending and/or inappropriately tracking and reporting federal funds over multiple year periods, and these discrepancies may not be properly monitored, detected, and corrected by agency personnel on a timely basis as required. Finally, additional federal pass-through funds may be unaudited in the future without timely and effective remedial action from Commonwealth agencies to enforce compliance. Recommendation: We recommend that the above weaknesses that cause untimely subrecipient Single Audit resolution, including untimely management decisions on findings, untimely review of the SEFA or alternate procedures, and late audit report submissions be corrected to ensure compliance with federal requirements and Commonwealth Management Directives, and to better ensure more timely subrecipient compliance with program requirements. Commonwealth agencies should promptly pursue outstanding audits and implement remedial action steps in accordance with 2 CFR ?200.338 and Commonwealth Management Directive 325.8, Section 5 (a) and (b) on a timely basis, including withholding funding from subrecipients which do not comply with audit submission requirements. Questioned Costs: The amount of questioned costs cannot be determined. SEE SCHEDULE OF FINDINGS AND QUESTIONED COSTS FOR REMAINDER OF FINDING INCLUDING AGENCY REPSONSES AND AUDITORS' CONCLUSION.

Show full finding ▾
Full finding narrative

Various Agencies Finding 2020 ? 021: CFDA #14.228 ? Community Development Block Grants ? State?s Program CFDA #15.252 ? Abandoned Mine Land Reclamation CFDA #16.575 ? Crime Victim Assistance CFDA #20.205 and 20.219 ? Highway Planning and Construction Cluster CFDA #93.558 ? Temporary Assistance for Needy Families CFDA #93.563 ? Child Support Enforcement CFDA #93.575 and 93.596 ? Child Care and Development Fund (CCDF) Cluster (including COVID-19) CFDA #93.658 ? Foster Care ? Title IV-E (including COVID-19) CFDA #93.659 ? Adoption Assistance (including COVID-19) CFDA #93.667 ? Social Services Block Grant CFDA #93.767 ? Children?s Health Insurance Program (including COVID-19) CFDA #93.775, 93.777, and 93.778 ? Medicaid Cluster (including COVID-19) CFDA #93.959 ? Block Grants for Prevention and Treatment of Substance Abuse A Material Weakness and Material Noncompliance Exist in the Commonwealth?s Subrecipient Audit Resolution Process (A Similar Condition Was Noted in Prior Year Finding 2019-020) Federal Grant Number(s) and Year(s): B-19-DC-42-0001 (1/01/2019 ? 9/30/2026), B-18-DC-42-0001 (1/01/2018 ? 9/30/2025), B-17-DC-42-0001 (1/01/2017 ? 9/30/2024), B-16-DC-42-0001 (1/01/2016 ? 12/31/2023), B-15-DC-42-0001 (1/01/2015 ? 9/30/2022), B-14-DC-42-0001 (1/01/2014 ? 9/30/2021), S20AF20006 (1/01/2020 ? 12/31/2022), S19AF20006 (01/01/2019 ? 12/31/2021), S19AF20004 (2/01/2018 ? 11/30/2021), S18AF20004 (11/01/2017 ? 10/31/2020), S18AF20006 (4/01/2018 ? 12/31/2020), S17AF20008 (1/01/2017 ? 12/31/2019), 2018-V2-GX-0068 (10/01/2017 ? 9/30/2021), 2017-VA-GX-0069 (10/01/2016 ? 9/30/2020), 2016-VA-GX-0048 (10/01/2015 ? 9/30/2019), N78000 (7/01/2019 ? 6/30/2020), 2001PATANF (10/01/2019 ? 9/30/2020), 1901PATANF (10/01/2018 ? 9/30/2019), 2001PACSES (10/01/2019 ? 9/30/2020), 1901PACSES (10/01/2018 ? 9/30/2019), G12001PACCDF (10/01/2019 ? 9/30/2020), G1901PACCDF (10/01/2018 ? 9/30/2019), 2001PAFOST (10/01/2019 ? 9/30/2020), 1901PAFOST (10/01/2018 ? 9/30/2019), 2001PAADPT (10/01/2019 ? 9/30/2020), 1901PAADPT (10/01/2018 ? 9/30/2019), 2001PASOSR (10/01/2019 ? 9/30/2020), 1901PASOSR (10/01/2018 ? 9/30/2019), 2005PA5021 (10/01/2019 ? 9/30/2021), 1905PA5021 (10/01/2018 ? 9/30/2020), 2005PA5MAP (10/01/2019 ? 9/30/2020), 1905PA5MAP (10/01/2018 ? 9/30/2019), 3B08TI010044-19 (10/01/2018 ? 9/30/2020), 2B08TI010044-18 (10/01/2017 ? 9/30/2019) Type of Finding: Significant Deficiency, Noncompliance for Medicaid Cluster Material Weakness, Material Noncompliance for Other Programs Compliance Requirement: Subrecipient Monitoring Condition: Under the Commonwealth of Pennsylvania's (Commonwealth) implementation of the Single Audit Act, review and resolution of subrecipient Single Audit reports is split into two stages. The Office of the Budget?s Bureau of Accounting and Financial Management (OB-BAFM) ensures the reports meet technical standards through a centralized desk review process. The various funding agencies in the Commonwealth are responsible for making a management decision on each finding within six months of the Federal Audit Clearinghouse?s (FAC) Management Decision Letter (MDL) start date for audits subject to Uniform Guidance and to ensure appropriate corrective action is taken by the subrecipient (except for Uniform Guidance audits under U.S. Department of Labor programs which are permitted 12 months for management decisions in accordance with 2 CFR Section 2900.21). Each Commonwealth agency is also Finding 2020 ? 021: (continued) responsible for reviewing financial information in each audit report to determine whether the audit included all pass-through funding provided by the agency in order to ensure pass-through funds were subject to audit. Most agencies meet this requirement by performing Schedule of Expenditures of Federal Awards (SEFA) reconciliations. The agency is also required to adjust Commonwealth records, if necessary. Our fiscal year ended June 30, 2020 audit of the Commonwealth?s process for review and resolution of subrecipient Single Audits included an evaluation of the Commonwealth?s fiscal year ended June 30, 2019 subrecipient audit universe for audits due for submission to the FAC during the fiscal year ended June 30, 2020. We also evaluated the Commonwealth?s review of 39 subrecipient audit reports with findings in major programs/clusters which were identified on the Commonwealth agencies? tracking lists during the fiscal year ended June 30, 2020, and required management decisions by Commonwealth agencies. Our testing disclosed the following audit exceptions regarding the Commonwealth agencies? review of subrecipient audit reports: ? Department of Community and Economic Development (DCED): The time period for making a management decision on findings was approximately 7.7 months and 8.1 months after the MDL start date for two out of five subrecipient audit reports with findings. ? Department of Drug and Alcohol Programs (DDAP): The time period for making a management decision on findings was approximately 9.7 months after the FAC MDL start date for one subrecipient audit report with findings. There was also a delay in the completion of the SEFA reconciliation for the subrecipient audit report in question. ? Department of Environmental Protection (DEP): The time period for making a management decision on findings was approximately 7.4 months and 16.9 months after the FAC MDL start date for two audit reports with findings. ? Department of Human Services (DHS): The time period for making a management decision on findings ranged from approximately 8.1 months to 22.9 months after the FAC MDL start date for 16 out of 23 subrecipient audit reports with findings. There was also a delay in DHS?s procedures to ensure the subrecipient SEFAs were accurate so that major programs were properly determined and subject to audit. In addition, our review disclosed that four subrecipient audit reports with findings for which DHS was the lead agency were submitted late to the FAC, with FAC acceptance dates ranging from approximately 5.4 months to 10.8 months after the Single Audit due date. ? Department of Transportation (PennDOT): The time period for making a management decision on findings was approximately 13 months after the FAC MDL start date for one out of six subrecipient audit reports with findings. ? Pennsylvania Commission on Crime and Delinquency (PCCD): The time period for making a management decision on findings was approximately 10.4 months after the FAC MDL start date for one out of five subrecipient audit reports with findings. As a follow-up to the prior year finding, we noted that the Commonwealth subgranted federal funds totaling $243,508,881 to the City of Philadelphia during the fiscal year ended June 30, 2019, for which a Single Audit was submitted to the FAC on January 31, 2021. This was 4 months after the September 30, 2020 due date, which had been extended due to the COVID-19 pandemic in accordance with the Office of Management and Budget?s Memorandum M-20-26, Appendix A. Our testing disclosed that DHS?s and DDAP?s subgrants to the City of Philadelphia were material for five of the 12 major programs/clusters with material subgranted funds. Our follow-up on the prior year finding also disclosed that the Commonwealth subgranted federal funds totaling $30,413,828 to Bucks County during the fiscal year ended December 31, 2018. The audit was submitted to the FAC on October 31, 2019, which was one month after the September 30, 2019 due date. Finding 2020 ? 021: (continued) DHS was the lead agency for the City of Philadelphia and Bucks County audits. Criteria: 2 CFR ?200.331, Requirements for pass-through entities, states in part: All pass-through entities must: (d) Monitor the activities of the subrecipient as necessary to ensure that the subaward is used for authorized purposes, in compliance with Federal statutes, regulations, and the terms and conditions of the subaward, and that subaward performance goals are achieved. Pass-through entity monitoring of the subrecipient must include: (2) Following-up and ensuring that the subrecipient takes timely and appropriate action on all deficiencies pertaining to the Federal award provided to the subrecipient from the pass-through entity detected through audits, on-site reviews, and other means. (3) Issuing a management decision for audit findings pertaining to the Federal award provided to the subrecipient from the pass-through entity as required by ? 200.521 Management decision. (f) Verify that every subrecipient is audited as required by Subpart F ? Audit Requirements of this part when it is expected that the subrecipient?s Federal awards expended during the respective fiscal year equaled or exceeded the threshold set forth in ? 200.501 Audit requirements. (g) Consider whether the results of the subrecipient?s audit, on-site review, or other monitoring indicate conditions that necessitate adjustments to the pass-through entity?s own records. (h) Consider taking enforcement action against noncompliant subrecipients as described in ?200.338 Remedies for noncompliance of this part and in program regulations. In order to carry out these responsibilities properly, good internal control dictates that state pass-through agencies ensure subrecipient Single Audit SEFAs are representative of state payment records each year, and that the related federal programs have been properly subjected to Single Audit procedures. 2 CFR ?200.512, Report submission, states in part: (a) General. (1) The audit must be completed and the data collection form described in paragraph (b) of this section and reporting package described in paragraph (c) of this section must be submitted within the earlier of 30 calendar days after receipt of the auditor?s report(s), or nine months after the end of the audit period. 2 CFR ?200.521, Management decision, states in part: (a) General. The management decision must clearly state whether or not the finding is sustained, the reasons for the decision, and the expected auditee action to repay disallowed costs, make financial adjustments, or take other action. (d) Time requirements. The Federal awarding agency or pass-through entity responsible for issuing a management decision must do so within six months of acceptance of the audit report by the FAC. The auditee must initiate and proceed with corrective action as rapidly as possible and corrective action should begin no later than upon receipt of the audit report. 2 CFR ?200.505, Sanctions, states: In cases of continued inability or unwillingness to have an audit conducted in accordance with this part, Federal agencies and pass-through entities must take appropriate action as provided in ?200.338 Remedies for noncompliance. Finding 2020 ? 021: (continued) 2 CFR ?200.338, Remedies for noncompliance, states in part: If a non-Federal entity fails to comply with Federal statutes, regulations or the terms and conditions of a Federal award, the Federal awarding agency or pass-through entity may impose additional conditions, as described in ?200.207 Specific conditions. If the Federal awarding agency or pass-through entity determines that noncompliance cannot be remedied by imposing additional conditions, the federal awarding agency or pass-through entity may take one or more of the following actions, as appropriate in the circumstances. (a) Temporarily withhold cash payments pending correction of the deficiency by the non-Federal entity or more severe enforcement action by the Federal awarding agency or pass-through entity. (b) Disallow (that is, deny both use of funds and any applicable matching credit for) all or part of the cost of the activity or action not in compliance. (c) Wholly or partly suspend or terminate the Federal award. (d) Initiate suspension or debarment proceedings as authorized under 2 CFR Part 180 and Federal awarding agency regulations (or in the case of a pass-through entity, recommend such a proceeding be initiated by a Federal awarding agency). (e) Withhold further Federal awards for the project or program. (f) Take other remedies that may be legally available. To ensure Commonwealth enforcement of federal regulations for subrecipient noncompliance with audit requirements, Commonwealth Management Directive 325.8, Remedies for Recipient Noncompliance with Audit Requirements, Section 5 related to policy, states in part: (a) Agencies must develop and implement remedial action that reflects the unique requirements of each program? (b) Overall periods for the implementation of remedial action should not exceed six months from the date the first remedial action is initiated. At the end of the six-month period, the recipient should take the appropriate corrective action or the final stage of remedial action should be imposed on the recipient. Examples of remedial action include, but are not limited to: (4) Withholding a portion of assistance payments until the noncompliance is resolved. (5) Withholding or disallowing overhead costs until the noncompliance is resolved. (6) Suspending the assistance agreement until the noncompliance is resolved. (7) Terminating the assistance agreement with the recipient and, if necessary, seeking alternative entities to administer the program. Management Directive 325.9, Processing Audits of Federal Pass-Through Funds, Section 7 related to procedures, states in part: c. Agencies. (1) Evaluate single audit report submissions received from BOA to determine program purpose acceptability by verifying, at a minimum, that all agency-funded programs are properly included on the applicable financial schedules; that findings affecting the agency contain sufficient information to facilitate a management decision; and that the subrecipient has submitted an adequate corrective action plan. Finding 2020 ? 021: (continued) (6) Impose or coordinate the imposition of remedial action in accordance with 2 CFR Part 200.338 and Management Directive 325.8, Remedies for Recipient Noncompliance with Audit Requirements, when subrecipients fail to comply with the provisions of Subpart F. Management Directive 325.12, Standards for Internal Control for Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s, Standards for Internal Control in the Federal Government (Green Book), published in September 2014. The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: One reason provided by Commonwealth management for untimely audit resolution in the various agencies, including making management decisions, approving corrective action, and performing procedures to ensure the accuracy of subrecipient SEFAs was either a change in staff or a lack of staff to follow up and process subrecipient audit reports more timely. Late management decisions also occurred because some agencies did not use OB-BAFM?s weekly notifications of audit reports with federal findings available on the FAC website to identify audits requiring management decisions. Instead, agencies waited until OB-BAFM personnel completed their desk review of subrecipient audits before starting the management decision process. PCCD personnel indicated the management decision was performed as part of program monitoring of the subrecipient but was not formally documented. Regarding late and outstanding audit report submissions, the Commonwealth agencies did not appear to be timely implementing remedial action steps in accordance with 2 CFR ?200.338 and Commonwealth Management Directive 325.8, Section 5 (a) and (b), in order to ensure compliance with federal audit submission requirements. DHS indicated that Commonwealth Management Directive 325.8, Section 5 (f), Policy, makes the federal cognizant agency which provided direct funding to Philadelphia City responsible for remedial action to comply with Subpart F of 2 CFR ?200. Effect: Since required management decisions were not made within six months to ensure appropriate corrective action was taken on audits received from subrecipients, the Commonwealth did not comply with federal regulations, and subrecipients were not made aware of acceptance or rejection of corrective action plans in a timely manner. Further, noncompliance may recur in future periods if control deficiencies are not corrected on a timely basis, and there is an increased risk of unallowable charges being made to federal programs if corrective action and recovery of questioned costs is not timely. Regarding the SEFA reviews or alternate procedures which are not being performed timely and the late Single Audit report submissions, there is an increased risk that subrecipients could be misspending and/or inappropriately tracking and reporting federal funds over multiple year periods, and these discrepancies may not be properly monitored, detected, and corrected by agency personnel on a timely basis as required. Finally, additional federal pass-through funds may be unaudited in the future without timely and effective remedial action from Commonwealth agencies to enforce compliance. Recommendation: We recommend that the above weaknesses that cause untimely subrecipient Single Audit resolution, including untimely management decisions on findings, untimely review of the SEFA or alternate procedures, and late audit report submissions be corrected to ensure compliance with federal requirements and Commonwealth Management Directives, and to better ensure more timely subrecipient compliance with program requirements. Commonwealth agencies should promptly pursue outstanding audits and implement remedial action steps in accordance with 2 CFR ?200.338 and Commonwealth Management Directive 325.8, Section 5 (a) and (b) on a timely basis, including withholding funding from subrecipients which do not comply with audit submission requirements. Questioned Costs: The amount of questioned costs cannot be determined. SEE SCHEDULE OF FINDINGS AND QUESTIONED COSTS FOR REMAINDER OF FINDING INCLUDING AGENCY REPSONSES AND AUDITORS' CONCLUSION.

Corrective Action Plan

DCED: DCED is in disagreement with this finding. See Agency Response in the body of the finding for details regarding the disagreement. Anticipated Completion Date: N/A Contact Person: Brad Shover, Director of Compliance Monitoring DDAP: DDAP has faced personnel challenges which made processing the backlog of audits extremely difficult. Recently, the Department has filled two key positions responsible for performing these auditing functions. The Department has developed and implemented procedures to streamline the process. In addition, staff training on the subrecipient audit process has begun. The review of current audits has commenced, and staff are addressing auditing issues related to funds distributed by DDAP. The Department understands the necessity to establish methods to address reconciliation of SEFA submissions in a timelier manner, as well as to seek and finalize corrective action to audit findings of subrecipients, should such findings occur. Anticipated Completion Date: 06/30/2021 Contact Person: Tia J. Roebuck, Director, Division of Budget and Procurement DEP: In December 2020, DEP Fiscal Management became aware of staff not completing the necessary steps for the management decision process that is included in our instructions for handling single audit reviews. DEP Fiscal Management staff immediately contacted our DEP Program Grant Officers for a review of the findings cited and the submitted corrective action plans. At that time, there was also a thorough review of all single audits received with findings for the calendar year to ensure these steps were not missed on any other submissions. In addition, DEP Fiscal Management staff participated in a mandatory review of DEP and Commonwealth policies focusing on these steps on January 21, 2021. DEP Fiscal Management updated the internal procedures on February 1, 2021, to highlight these steps to ensure they are not missed on any future single audit review. DEP staff contacted OB-OCO, Bureau of Accounting & Financial Management to request high level training for all staff as a refresher and for new staff that have recently been hired. The training is anticipated to occur by the end of April 2021. Anticipated Completion Date: 04/30/2021 Contact Person: Jennifer L. Brandt, Senior Fiscal Management Specialist, Federal Grants and Audits DHS: Regarding the timeliness of finding resolution and procedures related to the SEFA reviews, the Audit Resolution Section is continuing to explore ways to further streamline the process of single audit reviews to gain efficiencies. We are continuing to have meetings with OB-BAFM to discuss ways of streamlining the process further. Additionally, we are having staff from other areas in the Division of Audit and Review assist with these reviews to make them more timely. Anticipated Completion Date: 06/30/2021 Contact People: David Bryan, Manager, Audit Resolution Section; Alexander Matolyak, Director, Division of Audit and Review Regarding enforcement of the subrecipients? submission deadlines, we disagree with this part of the finding for the reasons stated in our response to this finding. Additionally, the auditor?s conclusion raised some issues that we will address here. The auditors state that ?the overall intent of the federal regulations is that agencies which pass through federal funding to subrecipients are responsible for properly administering the funds and monitoring the subrecipients to ensure that the subrecipients comply with federal regulations and the terms and conditions of the grant awards, including timely compliance with Single Audit report submission requirements. In addition to enforcing subrecipient Single Audit report submission, other pass-through agency responsibilities include assessing subrecipient risk and conducting subrecipient program monitoring.? We understand this intent, and risk assessment and monitoring are not a part of this finding ? this part of the finding solely relates to enforcing subrecipients? submissions deadlines. The auditors also state that ?DHS erroneously asserts that terminology in 2 CFR ?200 including ?may? or ?consider? absolves the pass-through agencies from their responsibility for conducting a series of progressive remedial action steps to ensure subrecipient compliance with Single Audit reporting requirements.? We are not asserting that this terminology absolves us of anything, but rather are pointing out that the Uniform Guidance provides examples of what a pass-through entity may do to enforce submission deadlines but does not specifically require any of those examples to be implemented. Our intent is to obtain the required audit reports, which we do. Finally, the auditors state that ?the evidence DHS provided for remedial action for these subrecipients with chronic noncompliance appeared to consist of sporadic communication with these subrecipients, as opposed to frequent, on-going, and documented follow up and evidence of progressive remedial action steps taken.? We believe the actions we are taking are sufficient, in compliance with the Uniform Guidance, and get the results we need (as stated above we do get the reports). As a practical matter, if an audit is underway, frequent communication is not going to get it completed any faster. Anticipated Completion Date: N/A Contact People: David Bryan, Manager, Audit Resolution Section; Alexander Matolyak, Director, Division of Audit and Review PENNDOT: PennDOT will review the Federal Audit Clearinghouse (FAC) transmittal received from the Office of Budget?s Desk Review Unit. If there are audits with findings assigned to PennDOT, they will be downloaded from the FAC website for processing. A closure letter will be completed and sent out to the subrecipient within the six-month turnaround period. This objective will be completed by June 30, 2021. Anticipated Completion Date: 06/30/2021 Contact People: David Maynard, Administrative Officer 1; Kathryn Tartaglia, Administrative Officer 2 PCCD: PCCD will formally document all management decisions on subrecipient audit reports with findings within six months of the Federal Audit Clearinghouse acceptance notification according to our written procedure. PCCD will not incorporate monitoring activities with the single audit review. Anticipated Completion Date: Completed Contact Person: Chris Epoca, Manager, Grants Management

Prior Finding References

2019-020

About Subrecipient Monitoring →

FY 2019-06-30

FAC accepted this audit on March 18, 2020 — management decision was due September 18, 2020.

2019-004
Subrecipient Monitoring
REPEATQUESTIONED COSTS

During the fiscal year ended June 30, 2019, the Department of Community and Economic Development (DCED) reported subrecipient expenditures for the United States Department of Housing and Urban Development (HUD), Community Development Block Grants (CDBG) ? State?s Program (including Neighborhood Stabilization Program and CDBG-Disaster Recovery Programs) of $39,492,235, which represented approximately 96 percent of total CDBG cluster expenditures of $41,034,302 on the Schedule of Expenditures of Federal Awards. DCED is required to maintain internal controls that ensure subrecipient grant funds are utilized within the established contract period. The grant managers monitor the subrecipient contracts and the progress of projects through review of expenditure reports, written and verbal communications, desk reviews, and site visits. In accordance with Fiscal Directive 2014-04, the Financial Management Center of DCED has performed a review of invoices submitted by CDBG subrecipients prior to the disbursement of federal funds through HUD?s Integrated Disbursement & Information System (IDIS) for compliance with the following: ? Contract amount; ? Budget category; ? Activity period; ? IDIS project number; ? Environmental clearance date; and ? Expenditure being incurred within the first 3 years of the grant. DCED remains behind in monitoring of its pre-2014 subrecipients in accordance with its monitoring schedule. The table below highlights the number of awarded subrecipients by grant year and the outstanding monitoring activities that have not been conducted as of June 30, 2019. See Schedule of Findings and Questioned Costs for chart/table. Finding 2019 ? 004: (continued) The monitoring policies and procedures applicable to the fiscal years 2014 through 2016 required a Risk Analysis Evaluation (RAE) to be conducted upon the receipt of a grant application. The RAE resulted in a score used to rank the subrecipient according to risk. The policy stated that subrecipients whose score was among the top 20, thus presenting the highest risk, will receive on-site monitoring, as well as remote monitoring, which required the quarterly submission of a Monitoring Activity Performance Report (MAPR). Remaining subrecipients were subject to remote monitoring and were required to submit a MAPR on a semi-annual basis. In addition, per the policy and risk analysis, management was required to select a sample of invoices on a quarterly basis, including at least one invoice from all subrecipients drawing funds during that quarter, to conduct a review. We reviewed support for the following subrecipients for the fiscal years 2014 through 2016 and identified the following: See Schedule of Findings and Questioned Costs for chart/table. The monitoring policies and procedures applicable to the fiscal year 2017 and going forward (new policy) require a RAE to be completed upon receipt and review of a CDBG entitlement grant application. In addition, the RAE will determine the level of risk associated with the applicable program year. Every four years, these scores are used to determine the monitoring schedule for the next four years as follows: High Risk ? All OBOs (counties administering funds on behalf of smaller jurisdictions) with five or more small jurisdictions will automatically be categorized as high risk. Following these, the highest scoring subrecipients will be rated high risk until the total of high risk grantees is 20. Subrecipients deemed high risk will submit the MAPR semi-annually. In addition, grant managers will conduct on-site monitoring annually based on the four year monitoring schedule. The schedule will ensure that all subrecipients receive an on-site visit at least once every four years. Medium Risk ? The next 20 subrecipients based on score will be rated as medium risk. CDBG subrecipients will submit the MAPR at least annually. Low Risk ? Those subrecipients not rated as high or medium risk will be rated as low risk. CDBG subrecipients will submit the MAPR at least annually. We reviewed supporting documentation for six of the 20 high risk subrecipients and eleven of the 70 remaining subrecipients for the fiscal year 2017 and forward and no exceptions were identified. Criteria: Regarding subrecipient monitoring, 2 CFR Section 200.331 states: All pass-through entities must: (b) Evaluate each subrecipient's risk of noncompliance with Federal statutes, regulations, and the terms and conditions of the subaward for purposes of determining the appropriate subrecipient monitoring described in paragraphs (d) and (e) of this section. (d) Monitor the activities of the subrecipient as necessary to ensure that the subaward is used for authorized purposes, in compliance with Federal statutes, regulations, and the terms and conditions of the subaward; and that subaward performance goals are achieved. Pass-through entity monitoring of the subrecipient must include: (1) Reviewing financial and performance reports required by the pass-through entity. Finding 2019 ? 004: (continued) (2) Following-up and ensuring that the subrecipient takes timely and appropriate action on all deficiencies pertaining to the Federal award provided to the subrecipient from the pass-through entity detected through audits, on-site reviews, and other means. (3) Issuing a management decision for audit findings pertaining to the Federal award provided to the subrecipient from the pass-through entity as required by ?200.521 Management decision. Management Directive 325.12, Standards for Internal Control for Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book), published in September 2014. The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: DCED experienced a significant increase in volume of activity during 2011 in providing direct response to Hurricane Irene and Tropical Storm Lee with no additional staff support to manage the increased number of contracts. On-site monitoring activities for subrecipients in that time fell behind, and DCED engaged a contractor in 2015 and 2016 to assist in completion of the backlog of monitoring. In 2015, management reduced the number of overall contracts by requiring small grantees to be administered by their respective counties, reducing the overall number of subrecipients to manage, and management is working to address the current period subrecipient reviews through its monitoring plan. Additionally, management identified operational inefficiencies in the implementation of the 2014 monitoring plan and, in 2017, following a full staff reorganization, made structural updates to the monitoring plan, assessment of risk, and identification of subrecipients subject to monitoring over a multi-year period. Effect: While DCED is still working aggressively to ensure that all contracts are monitored, they have implemented other during-the-award tools to monitor performance of subrecipients. For the fiscal years 2014 through 2016, DCED did not adequately perform on-site monitoring of the CDBG subrecipients. A material number of subrecipients expended individually less than $750,000 in total federal awards from the Commonwealth during the fiscal year ended June 30, 2018, and as a result would not have been required to submit a Single Audit under the Uniform Guidance to the Commonwealth during the fiscal year ended June 30, 2019. Therefore, these subrecipients were only subject to fiscal monitoring by the program. The timely completion of these on-site visits is vital in providing DCED with information necessary to determine whether the program?s subrecipients are complying with federal regulations. Recommendation: We recommend that DCED ensure that all on-site visits are completed along with all required documentation, within the scheduled monitoring cycle, to provide reasonable assurance that subrecipients administer the federal awards in compliance with laws, regulations, and the provisions of contracts and/or grant agreements. We also recommend that DCED ensure the results of all monitoring visits are communicated to the subrecipients in a timely manner, and that DCED perform follow-up procedures to ensure appropriate corrective action is implemented by the subrecipients. Agency Response: DCED agrees with the finding. Questioned Costs: The amount of questioned costs cannot be determined. The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Show full finding ▾
Full finding narrative

Department of Community and Economic Development Finding 2019 ? 004: CFDA #14.228 ? Community Development Block Grants ? State?s Program The Department of Community and Economic Development Did Not Perform Adequate During-the-Award Monitoring of Subrecipients (A Similar Condition Was Noted in Prior Year Finding 2018-003) Federal Grant Number(s) and Year(s): B-12-DT-42-0001 (9/03/2011 Until Expensed), B-14-DC-42-0001 (1/01/2014 ? 9/30/2021), B-15-DC-42-0001 (1/01/2015 ? 9/30/2022), B-16-DC-42-0001 (1/01/2016 ? 12/31/2023), B-17-DC-42-0001 (1/01/2017 ? 9/30/2024), B-18-DC-42-0001 (1/01/2018 ? 9/30/2025) Type of Finding: Significant Deficiency, Noncompliance Compliance Requirement: Subrecipient Monitoring Condition: During the fiscal year ended June 30, 2019, the Department of Community and Economic Development (DCED) reported subrecipient expenditures for the United States Department of Housing and Urban Development (HUD), Community Development Block Grants (CDBG) ? State?s Program (including Neighborhood Stabilization Program and CDBG-Disaster Recovery Programs) of $39,492,235, which represented approximately 96 percent of total CDBG cluster expenditures of $41,034,302 on the Schedule of Expenditures of Federal Awards. DCED is required to maintain internal controls that ensure subrecipient grant funds are utilized within the established contract period. The grant managers monitor the subrecipient contracts and the progress of projects through review of expenditure reports, written and verbal communications, desk reviews, and site visits. In accordance with Fiscal Directive 2014-04, the Financial Management Center of DCED has performed a review of invoices submitted by CDBG subrecipients prior to the disbursement of federal funds through HUD?s Integrated Disbursement & Information System (IDIS) for compliance with the following: ? Contract amount; ? Budget category; ? Activity period; ? IDIS project number; ? Environmental clearance date; and ? Expenditure being incurred within the first 3 years of the grant. DCED remains behind in monitoring of its pre-2014 subrecipients in accordance with its monitoring schedule. The table below highlights the number of awarded subrecipients by grant year and the outstanding monitoring activities that have not been conducted as of June 30, 2019. See Schedule of Findings and Questioned Costs for chart/table. Finding 2019 ? 004: (continued) The monitoring policies and procedures applicable to the fiscal years 2014 through 2016 required a Risk Analysis Evaluation (RAE) to be conducted upon the receipt of a grant application. The RAE resulted in a score used to rank the subrecipient according to risk. The policy stated that subrecipients whose score was among the top 20, thus presenting the highest risk, will receive on-site monitoring, as well as remote monitoring, which required the quarterly submission of a Monitoring Activity Performance Report (MAPR). Remaining subrecipients were subject to remote monitoring and were required to submit a MAPR on a semi-annual basis. In addition, per the policy and risk analysis, management was required to select a sample of invoices on a quarterly basis, including at least one invoice from all subrecipients drawing funds during that quarter, to conduct a review. We reviewed support for the following subrecipients for the fiscal years 2014 through 2016 and identified the following: See Schedule of Findings and Questioned Costs for chart/table. The monitoring policies and procedures applicable to the fiscal year 2017 and going forward (new policy) require a RAE to be completed upon receipt and review of a CDBG entitlement grant application. In addition, the RAE will determine the level of risk associated with the applicable program year. Every four years, these scores are used to determine the monitoring schedule for the next four years as follows: High Risk ? All OBOs (counties administering funds on behalf of smaller jurisdictions) with five or more small jurisdictions will automatically be categorized as high risk. Following these, the highest scoring subrecipients will be rated high risk until the total of high risk grantees is 20. Subrecipients deemed high risk will submit the MAPR semi-annually. In addition, grant managers will conduct on-site monitoring annually based on the four year monitoring schedule. The schedule will ensure that all subrecipients receive an on-site visit at least once every four years. Medium Risk ? The next 20 subrecipients based on score will be rated as medium risk. CDBG subrecipients will submit the MAPR at least annually. Low Risk ? Those subrecipients not rated as high or medium risk will be rated as low risk. CDBG subrecipients will submit the MAPR at least annually. We reviewed supporting documentation for six of the 20 high risk subrecipients and eleven of the 70 remaining subrecipients for the fiscal year 2017 and forward and no exceptions were identified. Criteria: Regarding subrecipient monitoring, 2 CFR Section 200.331 states: All pass-through entities must: (b) Evaluate each subrecipient's risk of noncompliance with Federal statutes, regulations, and the terms and conditions of the subaward for purposes of determining the appropriate subrecipient monitoring described in paragraphs (d) and (e) of this section. (d) Monitor the activities of the subrecipient as necessary to ensure that the subaward is used for authorized purposes, in compliance with Federal statutes, regulations, and the terms and conditions of the subaward; and that subaward performance goals are achieved. Pass-through entity monitoring of the subrecipient must include: (1) Reviewing financial and performance reports required by the pass-through entity. Finding 2019 ? 004: (continued) (2) Following-up and ensuring that the subrecipient takes timely and appropriate action on all deficiencies pertaining to the Federal award provided to the subrecipient from the pass-through entity detected through audits, on-site reviews, and other means. (3) Issuing a management decision for audit findings pertaining to the Federal award provided to the subrecipient from the pass-through entity as required by ?200.521 Management decision. Management Directive 325.12, Standards for Internal Control for Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book), published in September 2014. The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: DCED experienced a significant increase in volume of activity during 2011 in providing direct response to Hurricane Irene and Tropical Storm Lee with no additional staff support to manage the increased number of contracts. On-site monitoring activities for subrecipients in that time fell behind, and DCED engaged a contractor in 2015 and 2016 to assist in completion of the backlog of monitoring. In 2015, management reduced the number of overall contracts by requiring small grantees to be administered by their respective counties, reducing the overall number of subrecipients to manage, and management is working to address the current period subrecipient reviews through its monitoring plan. Additionally, management identified operational inefficiencies in the implementation of the 2014 monitoring plan and, in 2017, following a full staff reorganization, made structural updates to the monitoring plan, assessment of risk, and identification of subrecipients subject to monitoring over a multi-year period. Effect: While DCED is still working aggressively to ensure that all contracts are monitored, they have implemented other during-the-award tools to monitor performance of subrecipients. For the fiscal years 2014 through 2016, DCED did not adequately perform on-site monitoring of the CDBG subrecipients. A material number of subrecipients expended individually less than $750,000 in total federal awards from the Commonwealth during the fiscal year ended June 30, 2018, and as a result would not have been required to submit a Single Audit under the Uniform Guidance to the Commonwealth during the fiscal year ended June 30, 2019. Therefore, these subrecipients were only subject to fiscal monitoring by the program. The timely completion of these on-site visits is vital in providing DCED with information necessary to determine whether the program?s subrecipients are complying with federal regulations. Recommendation: We recommend that DCED ensure that all on-site visits are completed along with all required documentation, within the scheduled monitoring cycle, to provide reasonable assurance that subrecipients administer the federal awards in compliance with laws, regulations, and the provisions of contracts and/or grant agreements. We also recommend that DCED ensure the results of all monitoring visits are communicated to the subrecipients in a timely manner, and that DCED perform follow-up procedures to ensure appropriate corrective action is implemented by the subrecipients. Agency Response: DCED agrees with the finding. Questioned Costs: The amount of questioned costs cannot be determined. The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Corrective Action Plan

During the year under review DCED continued to implement the multi-year monitoring approach developed in its subrecipient monitoring plan update in July 2017. The framework addresses on-site and remote oversight of grantee compliance in all areas of program delivery, environmental review, labor standards, fair housing and equal opportunity and financial management. DCED successfully completed the monitoring of 175 contracts, including 63 on-site visits during the audit period. DCED has also developed and implemented a new tracking tool to log and track submission of MAPR reports and staff review of submissions. Per the corrective action identified in 2018, DCED continues to prioritize completion of the outstanding pre-2014 CDBG entitlement contracts, with specific attention to the 46 grantees whose CDBG entitlement contracts are now being administered by their respective county. In 2019-2020, DCED will complete on-site monitoring of 34 grantees per the monitoring schedule. Additionally, DCED will complete 20 remote environmental review monitorings, 20 labor standards monitorings and 20 fair housing and equal opportunity monitorings. Anticipated Completion Date: 06/30/2020 Contact Person: Kathy Possinger, Director, Center for Community and Housing Development

Prior Finding References

2018-003

About Subrecipient Monitoring →
2019-005
Period of Performance
QUESTIONED COSTS

The Department of Drug and Alcohol Programs (DDAP) operates the Block Grants for Prevention and Treatment of Substance Abuse (SABG) program. Our audit of the SABG program included procedures to evaluate compliance with period of performance requirements for the federal fiscal year 2017 SABG grant award that closed during the fiscal year ended June 30, 2019 audit period. Our procedures disclosed that expenditures totaling $12,049 were charged to the 2017 SABG grant after the grant period closed on September 30, 2018. DDAP did not provide evidence of authorization from the United States Department of Health and Human Services to allow charges subsequent to the end of the period of performance. The expenses charged to the grant for services that occurred after the grant period closed included: ? Telecommunication expenses totaling $3,725 incurred in October 2018; ? Telecommunication and fleet card expenses totaling $3,637 incurred in October and November 2018; and ? Telecommunication and fleet card expenses totaling $4,687 incurred in November and December 2018. SABG expenditures reported on the Schedule of Expenditures of Federal Awards for the fiscal year ended June 30, 2019 totaled $49.8 million. Criteria: 2 CFR Section 200.303(a), Internal controls, states: The non-Federal entity must: Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in ?Standards for Internal Control in the Federal Government? issued by the Comptroller General of the United States or the ?Internal Control Integrated Framework?, issued by the committee of the Sponsoring Organizations of the Treadway Commission (COSO). 2 CFR Section 200.309, Period of performance, states: A non-Federal entity may charge to the Federal award only allowable costs incurred during the period of performance (except as described in ?200.461 Publication and printing costs) and any costs incurred before the Federal awarding agency or pass-through entity made the Federal award that were authorized by the Federal awarding agency or pass-through entity. Management Directive 325.12, Standards for Internal Control for Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book), published in September 2014. The Green Book states in part: Finding 2019 ? 005: (continued) Management should design control activities to achieve objectives and respond to risks. Management should implement control activities through policies. Cause: DDAP personnel did not have adequate procedures in place to ensure costs incurred were within the period of performance and did not verify that service dates were within the period of performance prior to submitting invoices for payment. Effect: Expenditures were improperly charged to the federal fiscal year 2017 grant subsequent to the period of performance without authorization by the federal awarding agency, resulting in noncompliance and questioned costs. Recommendation: We recommend that DDAP personnel implement procedures to ensure that costs are incurred and charged within the proper period of performance or to obtain prior federal authorization for any costs charged outside the period of performance. Agency Response: The Department of Drug and Alcohol Programs agrees with the concern indicated by the Auditor General regarding expenditures being improperly charged to the federal fiscal year 2017 SABG grant subsequent to the period of performance. Telecommunication and fleet card billings are direct charges against the grant; therefore, invoices are not received at the department to manually process for payment. The reconciliation of the block grant occurs when the department is preparing the SABG reports for the Substance Abuse and Mental Health Services Administration, typically a year after the grant ends. It was during this reconciliation that the improperly charged expenditures were discovered and adjustments were in process to correct the error. Expenditure adjustments have since been completed to correct this error. The department continues to develop and implement procedures to address auditing issues related to funds received by the Department of Drug and Alcohol Programs. The department understands the necessity to establish and implement procedures to ensure costs are incurred and charged within the proper period of performance. Going forward, the department will reconcile the block grant on a monthly basis to ensure costs incurred are within the period of performance. Questioned Costs: Known questioned costs for CFDA #93.959 of $12,049 were identified, which represent the amount of transactions incurred and charged to the federal grant subsequent to the end of the period of performance. The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Show full finding ▾
Full finding narrative

Department of Drug and Alcohol Programs Finding 2019 ? 005: CFDA #93.959 ? Block Grants for Prevention and Treatment of Substance Abuse A Significant Deficiency and Noncompliance Exist in the Department of Drug and Alcohol Programs Related to Period of Performance Requirements Federal Grant Number(s) and Year(s): 2B08TI010044-17 (10/01/2016 ? 9/30/2018) Type of Finding: Significant Deficiency, Noncompliance Compliance Requirement: Period of Performance Condition: The Department of Drug and Alcohol Programs (DDAP) operates the Block Grants for Prevention and Treatment of Substance Abuse (SABG) program. Our audit of the SABG program included procedures to evaluate compliance with period of performance requirements for the federal fiscal year 2017 SABG grant award that closed during the fiscal year ended June 30, 2019 audit period. Our procedures disclosed that expenditures totaling $12,049 were charged to the 2017 SABG grant after the grant period closed on September 30, 2018. DDAP did not provide evidence of authorization from the United States Department of Health and Human Services to allow charges subsequent to the end of the period of performance. The expenses charged to the grant for services that occurred after the grant period closed included: ? Telecommunication expenses totaling $3,725 incurred in October 2018; ? Telecommunication and fleet card expenses totaling $3,637 incurred in October and November 2018; and ? Telecommunication and fleet card expenses totaling $4,687 incurred in November and December 2018. SABG expenditures reported on the Schedule of Expenditures of Federal Awards for the fiscal year ended June 30, 2019 totaled $49.8 million. Criteria: 2 CFR Section 200.303(a), Internal controls, states: The non-Federal entity must: Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in ?Standards for Internal Control in the Federal Government? issued by the Comptroller General of the United States or the ?Internal Control Integrated Framework?, issued by the committee of the Sponsoring Organizations of the Treadway Commission (COSO). 2 CFR Section 200.309, Period of performance, states: A non-Federal entity may charge to the Federal award only allowable costs incurred during the period of performance (except as described in ?200.461 Publication and printing costs) and any costs incurred before the Federal awarding agency or pass-through entity made the Federal award that were authorized by the Federal awarding agency or pass-through entity. Management Directive 325.12, Standards for Internal Control for Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book), published in September 2014. The Green Book states in part: Finding 2019 ? 005: (continued) Management should design control activities to achieve objectives and respond to risks. Management should implement control activities through policies. Cause: DDAP personnel did not have adequate procedures in place to ensure costs incurred were within the period of performance and did not verify that service dates were within the period of performance prior to submitting invoices for payment. Effect: Expenditures were improperly charged to the federal fiscal year 2017 grant subsequent to the period of performance without authorization by the federal awarding agency, resulting in noncompliance and questioned costs. Recommendation: We recommend that DDAP personnel implement procedures to ensure that costs are incurred and charged within the proper period of performance or to obtain prior federal authorization for any costs charged outside the period of performance. Agency Response: The Department of Drug and Alcohol Programs agrees with the concern indicated by the Auditor General regarding expenditures being improperly charged to the federal fiscal year 2017 SABG grant subsequent to the period of performance. Telecommunication and fleet card billings are direct charges against the grant; therefore, invoices are not received at the department to manually process for payment. The reconciliation of the block grant occurs when the department is preparing the SABG reports for the Substance Abuse and Mental Health Services Administration, typically a year after the grant ends. It was during this reconciliation that the improperly charged expenditures were discovered and adjustments were in process to correct the error. Expenditure adjustments have since been completed to correct this error. The department continues to develop and implement procedures to address auditing issues related to funds received by the Department of Drug and Alcohol Programs. The department understands the necessity to establish and implement procedures to ensure costs are incurred and charged within the proper period of performance. Going forward, the department will reconcile the block grant on a monthly basis to ensure costs incurred are within the period of performance. Questioned Costs: Known questioned costs for CFDA #93.959 of $12,049 were identified, which represent the amount of transactions incurred and charged to the federal grant subsequent to the end of the period of performance. The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Corrective Action Plan

DDAP is in the process of developing and implementing procedures surrounding the reconciliation of the Substance Abuse Block Grant (SABG). Generally, the SABG reconciliation occurs when the Department is preparing the SABG reports for the Substance Abuse and Mental Health Services Administration (SAMHSA), typically a year after the grant ends. Moving forward, DDAP will be working to reconcile the block grant on a monthly basis. By performing a monthly reconciliation, the Department will be able to ensure costs are incurred within the proper period of performance and/or complete any necessary adjustments to correct costs inadvertently incurred outside of the period of performance. In addition, the Department will work with other agencies to ensure that any direct costs are applied to the applicable grant performance period. Anticipated Completion Date: 07/01/2020 Contact Person: Tia J. Roebuck, Director, Division of Budget and Grants Management

About Period of Performance →
2019-006
Reporting

Under the Title I Grants to Local Educational Agencies (Title I) program which is authorized under the Elementary and Secondary Education Act (ESEA), as amended by the Every Student Succeeds Act, and administered by the Pennsylvania Department of Education (PDE), PDE is required to annually submit its average state per pupil expenditure (SPPE) amount to the National Center for Education Statistics. The United States Department of Education (USDE) uses this SPPE data to make allocations under several ESEA programs, including the Title I program. The SPPE data reported by PDE on the National Public Education Finance Survey (NPEFS) comprises PDE?s annual current expenditures for free public education, less certain designated exclusions, divided by the state?s average daily attendance (ADA). ADA generally represents the aggregate number of days of attendance of all students during a school year divided by the number of days that school is in session during the school year and is reported by Local Educational Agencies (LEAs) to PDE via PDE?s Pennsylvania Information Management System (PIMS) which is maintained by an outside vendor. During the fiscal year ended June 30, 2019, PDE obtained the 2017-2018 school year ADA data from PIMS, and this ADA data was used to calculate PDE?s SPPE amount which was reported on the 2018 NPEFS in August 2019. The underlying expenditures used in the SPPE calculation appeared to be accurately reported by PDE. However, PDE has a manual compensating control requiring that the ADA be reported on the Accuracy Certification Statement (ACS) which is to be submitted to PDE with each LEA?s upload of PIMS child accounting data and certified for accuracy by each LEA?s chief administrator. We selected a sample of 40 LEAs? ADA data as reported by PDE in the SPPE calculation and compared it to the LEAs? ACS forms, noting that for 2 of the 40 LEAs, the ADA reported by PDE did not agree to the ADA reported by the LEAs on the ACS forms as follows: See Schedule of Findings and Questioned Costs for chart/table. Finding 2019 ? 006: (continued) Criteria: The Uniform Guidance Compliance Supplement, Department of Education (ED) Cross-Cutting Section, Part L, Reporting, applicable to the Title I program, states: Each year, an SEA [State Educational Agency] must submit its average State per pupil expenditure (SPPE) data to the National Center for Education Statistics. These SPPE data are used by ED to make allocations under several ESEA programs, including Title I, Part A? 20 USC ? 7801 states: (1) Average daily attendance (A) In general Except as provided otherwise by State law or this paragraph, the term ?average daily attendance? means ? (i) The aggregate number of days of attendance of all students during a school year; divided by (ii) The number of days school is in session during that year. (2) Average per pupil expenditure The term ?average per-pupil expenditure? means, in the case of a State or of the United States ? (A) Without regard to the source of funds ? (i) The aggregate current expenditures, during the third fiscal year preceding the fiscal year for which the determination is made (or, if satisfactory data for that year are not available, during the most recent preceding fiscal year for which satisfactory data are available) of all local educational agencies in the State or, in the case of the United States, for all States?; plus (ii) Any direct current expenditures by the State for the operations of those agencies; divided by (B) The aggregate number of children in average daily attendance to whom those agencies provided free public education during that preceding year. Management Directive 325.12, Standards for Internal Control for Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book), published in September 2014. The Green Book states in part: Management should design control activities to achieve objectives and respond to risks. Management should implement control activities through policies. Cause: PDE personnel indicated the differences were due to PDE reporting revised ADA data which was submitted by the LEAs without the corresponding revised ACS. PDE?s manual compensating control to ensure the accuracy of the ADA was not operating effectively. When the LEAs submitted revised ADA data, they did not submit the revised ACS to certify the accuracy of the revised ADA as instructed. PDE does not have adequate procedures to identify individual LEA?s ADA revisions prior to use in the SPPE calculation and to follow up with the LEAs to enforce the submission of the corresponding revised ACS. Effect: Since the ADA data used in the SPPE was not properly certified as accurate, PDE may have reported an incorrect SPPE amount to the federal government which could result in an inaccurate allocation of federal funds to PDE. Recommendation: PDE should check the accuracy of the LEAs? ADA which did not agree to the ACS and make any necessary corrections. PDE management should ensure that manual compensating controls are adequately designed and operating effectively to make certain that the ADA data used in the calculation of the SPPE amount on the NPEFS is accurate and supported by the ACS. PDE should implement procedures to identify any ADA revisions made by LEAs prior to use in the SPPE calculation and require the LEAs to submit the revised ACS which supports the revised ADA. Finding 2019 ? 006: (continued) Agency Response: While PDE agrees that two out of the forty ACS the auditors examined did not match the data file containing the ADA data, it does not believe that constitutes a ?significant deficiency?. First, the lack of a matching ACS does not mean that the ADA data are incorrect. PDE maintains several other manual compensating controls that ensure it receives accurate data from the LEAs. These procedures include verifying the end-of-year attendance and membership data used to calculate ADA by: ? Annually reviewing the accuracy of the data submitted by LEAs that pose the greatest risk for having data errors. ? Tracking potential errors and resolving them with the LEAs. ? Providing manuals, checklists and validation reports to help LEAs identify inaccuracies in the data before it is submitted. Therefore, the ACS is not the only control limiting the risk that data could be incorrect. PDE had previously taken corrective action to address the LEAs? failure to provide an ACS when they submit data through PIMS. Specifically, PDE had revised both its PIMS Override Request and Data Maintenance Request forms, which LEAs must complete to upload new or revised child accounting data after the initial submission window closes, to include the explicit statement that LEAs must also submit a revised ACS. Even though USDE approved the adequacy of these controls in its August 2016 program determination letter, PDE will also institute one additional procedure. This step will enable it to determine which LEAs have not submitted a revised ACS when revised attendance or membership data has been uploaded in PIMS. This new manual compensating control will enable PDE to compare one set of ADA with a newer set to determine if data for any LEAs changed. Then PDE will cross-reference that comparison with the ACS received from each LEA to determine if a new report is required and will contact an LEA accordingly. As stated in 2016, if at any time PDE is provided with a mechanism for forcing LEAs to submit the ACS form, or is given the authority to levy a penalty against those LEAs that fail to comply, PDE will use those powers with fidelity. Auditors? Conclusion: Our testing disclosed that two LEAs? ADA out of a sample of 40 items tested did not agree to the LEAs? ACS, which represents an error rate of five percent applied to a population of over 600 LEAs? ADA. There was no verifiable documentation that the ADA data PDE used in the SPPE ADA calculation was accurate for the two items in question, and PDE did not provide any additional information or documentation which would mitigate this finding. The finding remains as stated. We will evaluate any corrective action in the subsequent audit. Questioned Costs: None ? no direct effect on program expenditures. The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Show full finding ▾
Full finding narrative

Department of Education Finding 2019 ? 006: CFDA #84.010 ? Title I Grants to Local Educational Agencies A Significant Deficiency and Noncompliance Exist Over the Pennsylvania Department of Education?s Reporting of the Annual State Per Pupil Expenditure Amount Federal Grant Number(s) and Year(s): S010A180038 (7/01/2018 ? 12/30/2020), S010A170038 (7/01/2017 ? 12/30/2019), S010A160038 (7/01/2016 ? 12/30/2018) Type of Finding: Significant Deficiency, Noncompliance Compliance Requirement: Reporting Condition: Under the Title I Grants to Local Educational Agencies (Title I) program which is authorized under the Elementary and Secondary Education Act (ESEA), as amended by the Every Student Succeeds Act, and administered by the Pennsylvania Department of Education (PDE), PDE is required to annually submit its average state per pupil expenditure (SPPE) amount to the National Center for Education Statistics. The United States Department of Education (USDE) uses this SPPE data to make allocations under several ESEA programs, including the Title I program. The SPPE data reported by PDE on the National Public Education Finance Survey (NPEFS) comprises PDE?s annual current expenditures for free public education, less certain designated exclusions, divided by the state?s average daily attendance (ADA). ADA generally represents the aggregate number of days of attendance of all students during a school year divided by the number of days that school is in session during the school year and is reported by Local Educational Agencies (LEAs) to PDE via PDE?s Pennsylvania Information Management System (PIMS) which is maintained by an outside vendor. During the fiscal year ended June 30, 2019, PDE obtained the 2017-2018 school year ADA data from PIMS, and this ADA data was used to calculate PDE?s SPPE amount which was reported on the 2018 NPEFS in August 2019. The underlying expenditures used in the SPPE calculation appeared to be accurately reported by PDE. However, PDE has a manual compensating control requiring that the ADA be reported on the Accuracy Certification Statement (ACS) which is to be submitted to PDE with each LEA?s upload of PIMS child accounting data and certified for accuracy by each LEA?s chief administrator. We selected a sample of 40 LEAs? ADA data as reported by PDE in the SPPE calculation and compared it to the LEAs? ACS forms, noting that for 2 of the 40 LEAs, the ADA reported by PDE did not agree to the ADA reported by the LEAs on the ACS forms as follows: See Schedule of Findings and Questioned Costs for chart/table. Finding 2019 ? 006: (continued) Criteria: The Uniform Guidance Compliance Supplement, Department of Education (ED) Cross-Cutting Section, Part L, Reporting, applicable to the Title I program, states: Each year, an SEA [State Educational Agency] must submit its average State per pupil expenditure (SPPE) data to the National Center for Education Statistics. These SPPE data are used by ED to make allocations under several ESEA programs, including Title I, Part A? 20 USC ? 7801 states: (1) Average daily attendance (A) In general Except as provided otherwise by State law or this paragraph, the term ?average daily attendance? means ? (i) The aggregate number of days of attendance of all students during a school year; divided by (ii) The number of days school is in session during that year. (2) Average per pupil expenditure The term ?average per-pupil expenditure? means, in the case of a State or of the United States ? (A) Without regard to the source of funds ? (i) The aggregate current expenditures, during the third fiscal year preceding the fiscal year for which the determination is made (or, if satisfactory data for that year are not available, during the most recent preceding fiscal year for which satisfactory data are available) of all local educational agencies in the State or, in the case of the United States, for all States?; plus (ii) Any direct current expenditures by the State for the operations of those agencies; divided by (B) The aggregate number of children in average daily attendance to whom those agencies provided free public education during that preceding year. Management Directive 325.12, Standards for Internal Control for Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book), published in September 2014. The Green Book states in part: Management should design control activities to achieve objectives and respond to risks. Management should implement control activities through policies. Cause: PDE personnel indicated the differences were due to PDE reporting revised ADA data which was submitted by the LEAs without the corresponding revised ACS. PDE?s manual compensating control to ensure the accuracy of the ADA was not operating effectively. When the LEAs submitted revised ADA data, they did not submit the revised ACS to certify the accuracy of the revised ADA as instructed. PDE does not have adequate procedures to identify individual LEA?s ADA revisions prior to use in the SPPE calculation and to follow up with the LEAs to enforce the submission of the corresponding revised ACS. Effect: Since the ADA data used in the SPPE was not properly certified as accurate, PDE may have reported an incorrect SPPE amount to the federal government which could result in an inaccurate allocation of federal funds to PDE. Recommendation: PDE should check the accuracy of the LEAs? ADA which did not agree to the ACS and make any necessary corrections. PDE management should ensure that manual compensating controls are adequately designed and operating effectively to make certain that the ADA data used in the calculation of the SPPE amount on the NPEFS is accurate and supported by the ACS. PDE should implement procedures to identify any ADA revisions made by LEAs prior to use in the SPPE calculation and require the LEAs to submit the revised ACS which supports the revised ADA. Finding 2019 ? 006: (continued) Agency Response: While PDE agrees that two out of the forty ACS the auditors examined did not match the data file containing the ADA data, it does not believe that constitutes a ?significant deficiency?. First, the lack of a matching ACS does not mean that the ADA data are incorrect. PDE maintains several other manual compensating controls that ensure it receives accurate data from the LEAs. These procedures include verifying the end-of-year attendance and membership data used to calculate ADA by: ? Annually reviewing the accuracy of the data submitted by LEAs that pose the greatest risk for having data errors. ? Tracking potential errors and resolving them with the LEAs. ? Providing manuals, checklists and validation reports to help LEAs identify inaccuracies in the data before it is submitted. Therefore, the ACS is not the only control limiting the risk that data could be incorrect. PDE had previously taken corrective action to address the LEAs? failure to provide an ACS when they submit data through PIMS. Specifically, PDE had revised both its PIMS Override Request and Data Maintenance Request forms, which LEAs must complete to upload new or revised child accounting data after the initial submission window closes, to include the explicit statement that LEAs must also submit a revised ACS. Even though USDE approved the adequacy of these controls in its August 2016 program determination letter, PDE will also institute one additional procedure. This step will enable it to determine which LEAs have not submitted a revised ACS when revised attendance or membership data has been uploaded in PIMS. This new manual compensating control will enable PDE to compare one set of ADA with a newer set to determine if data for any LEAs changed. Then PDE will cross-reference that comparison with the ACS received from each LEA to determine if a new report is required and will contact an LEA accordingly. As stated in 2016, if at any time PDE is provided with a mechanism for forcing LEAs to submit the ACS form, or is given the authority to levy a penalty against those LEAs that fail to comply, PDE will use those powers with fidelity. Auditors? Conclusion: Our testing disclosed that two LEAs? ADA out of a sample of 40 items tested did not agree to the LEAs? ACS, which represents an error rate of five percent applied to a population of over 600 LEAs? ADA. There was no verifiable documentation that the ADA data PDE used in the SPPE ADA calculation was accurate for the two items in question, and PDE did not provide any additional information or documentation which would mitigate this finding. The finding remains as stated. We will evaluate any corrective action in the subsequent audit. Questioned Costs: None ? no direct effect on program expenditures. The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Corrective Action Plan

PDE does not believe that this finding constitutes a ?significant deficiency.? Although USDE approved the adequacy of existing controls in its August 2016 program determination letter, PDE will also institute an additional procedure. The added step will enable PDE to determine which LEAs have not submitted a revised ACS form when revised attendance or membership data have been uploaded into the system. This new manual compensating control will enable PDE to compare one set of ADA with a newer set to determine if data for any LEAs changed. PDE will then cross-reference that comparison with the ACS received from each LEA to determine if a new report is required and will contact the LEA accordingly. As stated in 2016, if at any time PDE is provided with a mechanism for forcing LEAs to submit a revised ACS form, or is given the authority to levy a penalty against those LEAs that fail to comply, PDE will use those powers with fidelity. Anticipated Completion Date: 06/30/2021 Contact Person: Benjamin Hanft, Division Chief, Division of Subsidy Administration

About Reporting →
2019-007
Special Tests & Provisions
MATERIAL WEAKNESSREPEATQUESTIONED COSTS

During our audit of the Supplemental Nutrition Assistance Program (SNAP), we evaluated the security over Electronic Benefits Transfer (EBT) cards, which includes both the physical security of EBT cards during the issuance process at County Assistance Offices (CAO), as well as the handling of EBT cards returned from the United States Postal Service as undeliverable, or those that have been lost or stolen. EBT cards are the method by which SNAP benefit payments are made available to recipients. Also, EBT cards are the primary method by which cash and special allowance benefit payments are made available to Temporary Assistance for Needy Families (TANF) recipients. Total benefit expenditures for SNAP for the fiscal year ended June 30, 2019 totaled $2.5 billion. Total benefit expenditures for TANF for the fiscal year ended June 30, 2019 totaled $166.1 million. Eleven of the 87 CAO and district locations that the system shows issued EBT cards were selected for site visits in the current audit period. During our review of the physical security over EBT cards, we noted exceptions at ten of the eleven CAO and district locations selected for testing. These exceptions included the following: 1) An employee had dual-access to the Electronic Payment Processing and Information Control (EPPIC) System. The employee was a card pinner and card maker for three business days (1 location). 2) EBT Cards were created during non-business hours (2 district offices). 3) Failure to perform the following: ? Destroy used printer ribbon on the same day as new printer ribbon installation (1 district office); ? Maintain adequate segregation of duties when completing the Ribbon Log. The ribbon installer/destroyer and the witness were the same person on the Ribbon Log (1 district office and 2 locations); ? Maintain adequate segregation of duties when completing the Weekly Log in the EBT Card Tracking Database. The same employee returned the EBT cards and approved the Weekly Log (2 district offices and 2 locations); ? Retain EBT card paper logs for four years (1 district office); ? Retain EPPIC EBT Systems Application forms (paper and/or electronic copies) (1 location); ? Create written internal procedures for EBT Security for over the counter card mailings (1 district office and 1 location); ? Locate shipping manifest to support the EBT Shipments Verification Log (1 district office and 2 locations); ? Designate a manager or supervisor to the Alternate EBT Coordinator role (1 location); ? Completion of all required fields on the EPPIC EBT Systems Application forms for four employees (1 location); ? Maintain adequate segregation of duties when completing the EBT Shipments Verification Log. The Project Office does not require a witness of manual adjustments made to the EBT Card Inventory (all district offices and locations tested); ? Timely completion and submission of the EPPIC EBT Systems Application forms to the Office of Income Maintenance EBT Security (1 district office); Finding 2019 ? 007: (continued) ? Proper completion of the exception type entry field in the Daily Log (1 location); ? Maintain adequate security of card making and pinning devices (3 locations); ? Maintain adequate security of EBT card inventory (2 locations); ? Maintain adequate security of printer ribbon (1 location); ? Maintain adequate security of EBT paper logs (2 locations); and ? Maintain adequate security of EPPIC EBT Systems Application forms (1 location). Criteria: The State is required to maintain adequate security over, and documentation/records for, EBT cards to prevent theft, embezzlement, loss, damage, destruction, unauthorized transfer, negotiation, or use (7 CFR Section 274.8(b)(3)). 7 CFR Section 274.5, Record retention and forms security, states: (c) Accountable Documents. (1) EBT cards shall be considered accountable documents. The State agency shall provide the following minimum security and control procedures for these documents: i. Secure storage; ii. Access limited to authorized personnel; iii. Bulk inventory control records; iv. Subsequent control records maintained through the point of issuance or use; and v. Periodic review and validation of inventory controls and records by parties not otherwise involved in maintaining control records. 45 CFR Section 75.302 applicable to TANF states: (b) The financial management system of each non-Federal entity must provide for the following (see also ?75.361, 75.362, 75.363, 75.364, and 75.365): (4) Effective control over, and accountability for, all funds, property, and other assets. The non-Federal entity must adequately safeguard all assets and assure that they are used solely for authorized purposes. See ?75.303. Management Directive 325.12, Standards for Internal Control for Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office, Standards for Internal Control in the Federal Government (Green Book), published in September 2014. The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: Established policies and procedures were not followed consistently across CAO and district locations, which resulted in ineffective internal controls over EBT card security. Effect: Without adequate security controls over EBT cards, there exists the possibility of misappropriation and/or abuse. Recommendation: We recommend that the Department of Human Services (DHS) monitor EBT card security at CAO and district locations on a regular basis to improve consistency in the execution of documented policies and procedures. Finding 2019 ? 007: (continued) Agency Response: DHS agrees with the finding. Questioned Costs: The amount of questioned costs cannot be determined. The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Show full finding ▾
Full finding narrative

Department of Human Services Finding 2019 ? 007: CFDA #10.551 and 10.561 ? Supplemental Nutrition Assistance Program (SNAP) Cluster CFDA #93.558 ? Temporary Assistance for Needy Families A Material Weakness and Material Noncompliance Exist at the Department of Human Services Related to Electronic Benefits Transfer Card Security (A Similar Condition Was Noted in Prior Year Finding 2018-007) Federal Grant Number(s) and Year(s): 191PA405S2514 (10/01/2018 ? 9/30/2019), 1801PATANF (10/01/2017 ? 9/30/2018), 1901PATANF (10/01/2018 ? 9/30/2019) Type of Finding: Material Weakness, Material Noncompliance Compliance Requirement: Special Tests and Provisions related to EBT Card Security Condition: During our audit of the Supplemental Nutrition Assistance Program (SNAP), we evaluated the security over Electronic Benefits Transfer (EBT) cards, which includes both the physical security of EBT cards during the issuance process at County Assistance Offices (CAO), as well as the handling of EBT cards returned from the United States Postal Service as undeliverable, or those that have been lost or stolen. EBT cards are the method by which SNAP benefit payments are made available to recipients. Also, EBT cards are the primary method by which cash and special allowance benefit payments are made available to Temporary Assistance for Needy Families (TANF) recipients. Total benefit expenditures for SNAP for the fiscal year ended June 30, 2019 totaled $2.5 billion. Total benefit expenditures for TANF for the fiscal year ended June 30, 2019 totaled $166.1 million. Eleven of the 87 CAO and district locations that the system shows issued EBT cards were selected for site visits in the current audit period. During our review of the physical security over EBT cards, we noted exceptions at ten of the eleven CAO and district locations selected for testing. These exceptions included the following: 1) An employee had dual-access to the Electronic Payment Processing and Information Control (EPPIC) System. The employee was a card pinner and card maker for three business days (1 location). 2) EBT Cards were created during non-business hours (2 district offices). 3) Failure to perform the following: ? Destroy used printer ribbon on the same day as new printer ribbon installation (1 district office); ? Maintain adequate segregation of duties when completing the Ribbon Log. The ribbon installer/destroyer and the witness were the same person on the Ribbon Log (1 district office and 2 locations); ? Maintain adequate segregation of duties when completing the Weekly Log in the EBT Card Tracking Database. The same employee returned the EBT cards and approved the Weekly Log (2 district offices and 2 locations); ? Retain EBT card paper logs for four years (1 district office); ? Retain EPPIC EBT Systems Application forms (paper and/or electronic copies) (1 location); ? Create written internal procedures for EBT Security for over the counter card mailings (1 district office and 1 location); ? Locate shipping manifest to support the EBT Shipments Verification Log (1 district office and 2 locations); ? Designate a manager or supervisor to the Alternate EBT Coordinator role (1 location); ? Completion of all required fields on the EPPIC EBT Systems Application forms for four employees (1 location); ? Maintain adequate segregation of duties when completing the EBT Shipments Verification Log. The Project Office does not require a witness of manual adjustments made to the EBT Card Inventory (all district offices and locations tested); ? Timely completion and submission of the EPPIC EBT Systems Application forms to the Office of Income Maintenance EBT Security (1 district office); Finding 2019 ? 007: (continued) ? Proper completion of the exception type entry field in the Daily Log (1 location); ? Maintain adequate security of card making and pinning devices (3 locations); ? Maintain adequate security of EBT card inventory (2 locations); ? Maintain adequate security of printer ribbon (1 location); ? Maintain adequate security of EBT paper logs (2 locations); and ? Maintain adequate security of EPPIC EBT Systems Application forms (1 location). Criteria: The State is required to maintain adequate security over, and documentation/records for, EBT cards to prevent theft, embezzlement, loss, damage, destruction, unauthorized transfer, negotiation, or use (7 CFR Section 274.8(b)(3)). 7 CFR Section 274.5, Record retention and forms security, states: (c) Accountable Documents. (1) EBT cards shall be considered accountable documents. The State agency shall provide the following minimum security and control procedures for these documents: i. Secure storage; ii. Access limited to authorized personnel; iii. Bulk inventory control records; iv. Subsequent control records maintained through the point of issuance or use; and v. Periodic review and validation of inventory controls and records by parties not otherwise involved in maintaining control records. 45 CFR Section 75.302 applicable to TANF states: (b) The financial management system of each non-Federal entity must provide for the following (see also ?75.361, 75.362, 75.363, 75.364, and 75.365): (4) Effective control over, and accountability for, all funds, property, and other assets. The non-Federal entity must adequately safeguard all assets and assure that they are used solely for authorized purposes. See ?75.303. Management Directive 325.12, Standards for Internal Control for Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office, Standards for Internal Control in the Federal Government (Green Book), published in September 2014. The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: Established policies and procedures were not followed consistently across CAO and district locations, which resulted in ineffective internal controls over EBT card security. Effect: Without adequate security controls over EBT cards, there exists the possibility of misappropriation and/or abuse. Recommendation: We recommend that the Department of Human Services (DHS) monitor EBT card security at CAO and district locations on a regular basis to improve consistency in the execution of documented policies and procedures. Finding 2019 ? 007: (continued) Agency Response: DHS agrees with the finding. Questioned Costs: The amount of questioned costs cannot be determined. The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Corrective Action Plan

The EBT Project Officer makes quarterly updates to the manual. The EBT Project Officer will send updates directly to the Executive Directors and the EBT Coordinators to ensure dissemination of information reaches staff timely. The Division of Corrective Action (DCA) continue to monitor EBT security including the following: ? Correct count procedures of cards ? Secure storage of card and card machines ? Interviewing EBT coordinators ? Interviewing EBT card makers ? Conduct audits both announced and unannounced Staff Development completed new EBT Security training module and it was provided to LSO on 11/26/19. The training was available to staff on 12/2/19. Training will be completed each year. A section will be added to the Director of Operations end of the week report, detailing where the EBT manual can be found on the OIM home page. Card printer and card maker responsibilities can be found in the manual. A link to the manual was provided to the CAO showing Executive Director responsibilities concerning ensuring staff members have a single role when issuing EBT cards. No staff member should have dual access to the PIN Select Device and the card creation process. Anticipated Completion Date: 03/31/2020 Contact Person: Jeanette Coulston, Income Maintenance Program Representative

Prior Finding References

2018-007

About Special Tests and Provisions →
2019-008
Subrecipient Monitoring
REPEATQUESTIONED COSTS

During the fiscal year ended June 30, 2019, the Department of Human Services (DHS) paid $70.8 million in Temporary Assistance for Needy Families (TANF) funding to subrecipients within the New Directions, Cash Grants, and Alternatives to Abortion appropriations (or 13.8 percent) out of total federal TANF expenditures of $513.1 million reported on the June 30, 2019 Schedule of Expenditures of Federal Awards. Our testing of DHS?s during-the-award monitoring of subrecipients for the fiscal year ended June 30, 2019 disclosed that DHS performed on-site monitoring for all 12 subrecipients selected for testing. The on-site monitoring that was performed consisted of reviews of program operations including design, data entry accuracy and timeliness, case management analysis, and program payment performance goals. The on-site monitoring also included a review of a sample of TANF recipient case files to ensure that the recipients? TANF activities were documented and accurately entered in the Commonwealth?s Workforce Development System. However, DHS?s monitoring procedures for the 12 subrecipients were not adequate as they did not include a review or monitoring of subrecipient financial records, which would provide an assessment of a subrecipient?s compliance with applicable federal regulations. Although DHS?s monitoring procedures include reviewing subrecipient completed questionnaires for selected subrecipients that had questions related to financial matters, DHS monitors did not review subrecipient financial records. For example, DHS did not perform procedures to ensure subrecipient invoices agreed to the books and records of the subrecipient and that the records were adequate to support the allowability of costs paid by DHS during the award period. In addition, DHS?s monitoring procedures did not include an evaluation of the operating effectiveness of DHS subrecipient procedures to monitor Single Audits and any related findings. In addition to the 12 subrecipients tested above, we followed up on one subrecipient identified in the prior year finding as not being on-site monitored by DHS when the risk assessment warranted on-site monitoring. Our follow-up on DHS?s monitoring of this subrecipient during the current audit period disclosed that DHS personnel did not prepare a risk assessment or conduct any on-site monitoring of this subrecipient. Since no risk assessment or on-site monitoring occurred, internal control weaknesses, noncompliance, and questioned costs may have existed and remained undetected during the current audit period. This subrecipient received approximately $1.5 million of TANF funds during the fiscal year ended June 30, 2019. Criteria: 45 CFR Section 75.352, Requirements for pass-through entities, states: (d) Monitor the activities of the subrecipient as necessary to ensure that the subaward is used for authorized purposes, in compliance with Federal statutes, regulations, and the terms and conditions of the subaward; and that subaward performance goals are achieved. Pass-through entity monitoring of the subrecipient must include: (1) Reviewing financial and programmatic reports required by the pass-through entity. Finding 2019 ? 008: (continued) (2) Following-up and ensuring that the subrecipient takes timely and appropriate action on all deficiencies pertaining to the Federal award provided to the subrecipient from the pass-through entity detected through audits, on-site reviews, and other means. (3) Issuing a management decision for audit findings pertaining to the Federal award provided to the subrecipient... 2 CFR Section 200.331, Requirements for Pass-through Entities, states in part: Pass-through entity monitoring of the subrecipient must include: (e) Depending upon the pass-through entity's assessment of risk posed by the subrecipient (as described in paragraph (b) of this section), the following monitoring tools may be useful for the pass-through entity to ensure proper accountability and compliance with program requirements and achievement of performance goals: (1) Providing subrecipients with training and technical assistance on program-related matters; and (2) Performing on-site reviews of the subrecipient's program operations; (3) Arranging for agreed-upon-procedures engagements as described in ?200.425 Audit services. Management Directive 325.12, Standards for Internal Control for Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book), published in September 2014. The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: DHS has not implemented adequate during-the-award monitoring procedures of DHS subrecipients to include testing of the financial records and the subrecipients? monitoring of Single Audits sufficient to ensure compliance with federal regulations. In addition, as indicated in DHS?s corrective action plan for the prior year finding, DHS personnel planned to explore options regarding the best approach for conducting the financial portion of the required on-site subrecipient monitoring but did not revise the procedures used during the current audit period. Regarding the aforementioned subrecipient that was not subject to on-site monitoring, DHS personnel stated that no on-site monitoring was performed on this subrecipient due to staffing issues. Effect: TANF subrecipients could be operating in noncompliance with federal regulations without timely detection and correction by DHS management. Recommendation: DHS should strengthen its controls to ensure during-the-award monitoring of TANF subrecipients includes procedures to ensure that subrecipients are in compliance with applicable federal regulations, including ensuring that all required Single Audits were obtained by all DHS subrecipients. Agency Response: DHS agrees with the finding. Questioned Costs: The amount of questioned costs cannot be determined. The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Show full finding ▾
Full finding narrative

Department of Human Services Finding 2019 ? 008: CFDA #93.558 ? Temporary Assistance for Needy Families Department of Human Services Did Not Validate Financial Information as Part of Its On-Site Monitoring of Temporary Assistance for Needy Families Subrecipients (A Similar Condition Was Noted in Prior Year Finding 2018-008) Federal Grant Number(s) and Year(s): 1801PATANF (10/01/2017 ? 9/30/2018), 1901PATANF (10/01/2018 ? 9/30/2019) Type of Finding: Significant Deficiency, Noncompliance Compliance Requirement: Subrecipient Monitoring Condition: During the fiscal year ended June 30, 2019, the Department of Human Services (DHS) paid $70.8 million in Temporary Assistance for Needy Families (TANF) funding to subrecipients within the New Directions, Cash Grants, and Alternatives to Abortion appropriations (or 13.8 percent) out of total federal TANF expenditures of $513.1 million reported on the June 30, 2019 Schedule of Expenditures of Federal Awards. Our testing of DHS?s during-the-award monitoring of subrecipients for the fiscal year ended June 30, 2019 disclosed that DHS performed on-site monitoring for all 12 subrecipients selected for testing. The on-site monitoring that was performed consisted of reviews of program operations including design, data entry accuracy and timeliness, case management analysis, and program payment performance goals. The on-site monitoring also included a review of a sample of TANF recipient case files to ensure that the recipients? TANF activities were documented and accurately entered in the Commonwealth?s Workforce Development System. However, DHS?s monitoring procedures for the 12 subrecipients were not adequate as they did not include a review or monitoring of subrecipient financial records, which would provide an assessment of a subrecipient?s compliance with applicable federal regulations. Although DHS?s monitoring procedures include reviewing subrecipient completed questionnaires for selected subrecipients that had questions related to financial matters, DHS monitors did not review subrecipient financial records. For example, DHS did not perform procedures to ensure subrecipient invoices agreed to the books and records of the subrecipient and that the records were adequate to support the allowability of costs paid by DHS during the award period. In addition, DHS?s monitoring procedures did not include an evaluation of the operating effectiveness of DHS subrecipient procedures to monitor Single Audits and any related findings. In addition to the 12 subrecipients tested above, we followed up on one subrecipient identified in the prior year finding as not being on-site monitored by DHS when the risk assessment warranted on-site monitoring. Our follow-up on DHS?s monitoring of this subrecipient during the current audit period disclosed that DHS personnel did not prepare a risk assessment or conduct any on-site monitoring of this subrecipient. Since no risk assessment or on-site monitoring occurred, internal control weaknesses, noncompliance, and questioned costs may have existed and remained undetected during the current audit period. This subrecipient received approximately $1.5 million of TANF funds during the fiscal year ended June 30, 2019. Criteria: 45 CFR Section 75.352, Requirements for pass-through entities, states: (d) Monitor the activities of the subrecipient as necessary to ensure that the subaward is used for authorized purposes, in compliance with Federal statutes, regulations, and the terms and conditions of the subaward; and that subaward performance goals are achieved. Pass-through entity monitoring of the subrecipient must include: (1) Reviewing financial and programmatic reports required by the pass-through entity. Finding 2019 ? 008: (continued) (2) Following-up and ensuring that the subrecipient takes timely and appropriate action on all deficiencies pertaining to the Federal award provided to the subrecipient from the pass-through entity detected through audits, on-site reviews, and other means. (3) Issuing a management decision for audit findings pertaining to the Federal award provided to the subrecipient... 2 CFR Section 200.331, Requirements for Pass-through Entities, states in part: Pass-through entity monitoring of the subrecipient must include: (e) Depending upon the pass-through entity's assessment of risk posed by the subrecipient (as described in paragraph (b) of this section), the following monitoring tools may be useful for the pass-through entity to ensure proper accountability and compliance with program requirements and achievement of performance goals: (1) Providing subrecipients with training and technical assistance on program-related matters; and (2) Performing on-site reviews of the subrecipient's program operations; (3) Arranging for agreed-upon-procedures engagements as described in ?200.425 Audit services. Management Directive 325.12, Standards for Internal Control for Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book), published in September 2014. The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: DHS has not implemented adequate during-the-award monitoring procedures of DHS subrecipients to include testing of the financial records and the subrecipients? monitoring of Single Audits sufficient to ensure compliance with federal regulations. In addition, as indicated in DHS?s corrective action plan for the prior year finding, DHS personnel planned to explore options regarding the best approach for conducting the financial portion of the required on-site subrecipient monitoring but did not revise the procedures used during the current audit period. Regarding the aforementioned subrecipient that was not subject to on-site monitoring, DHS personnel stated that no on-site monitoring was performed on this subrecipient due to staffing issues. Effect: TANF subrecipients could be operating in noncompliance with federal regulations without timely detection and correction by DHS management. Recommendation: DHS should strengthen its controls to ensure during-the-award monitoring of TANF subrecipients includes procedures to ensure that subrecipients are in compliance with applicable federal regulations, including ensuring that all required Single Audits were obtained by all DHS subrecipients. Agency Response: DHS agrees with the finding. Questioned Costs: The amount of questioned costs cannot be determined. The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Corrective Action Plan

1. New Directions The Office of Income Maintenance (OIM) will be updating agency monitoring personnel checklists in FY 2019-20 to include testing various financial controls of select grantees based on their risk assessment scores. The updates to the checklist began on March 1, 2020 and should be completed by March 31, 2020. Anticipated Completion Date: 6/30/2020 Contact People: Michael Varleta, Dir., Div. of Mgmt. & Budget, OIM; Joel O?Donnell, Dir., Bur. of Program Support, OIM 2.Alternatives to Abortion The Office of Policy Development (OPD) completed the risk assessment for FY 18-19 in August 2019. The risk assessment identified the Alternatives to Abortion program as one of the grantees who would receive an on-site monitoring visit in FY 19-20. OPD plans on scheduling the subrecipient on-site monitoring visit for the third quarter of the fiscal year. This monitoring will be completed by May 2020 Anticipated Completion Date: 05/31/2020 Contact Person:Cassie Hourlland, Grants and Policy Specialist, OPD

Prior Finding References

2018-008

About Subrecipient Monitoring →
2019-009
Subrecipient Monitoring
MATERIAL WEAKNESSREPEATQUESTIONED COSTS

The Department of Human Services? (DHS) Office of Children, Youth, and Families (OCYF) performs two types of during-the-award monitoring of its 67 subrecipient County Children and Youth Agencies (CCYAs). One group within OCYF performs on-site inspections to support its reissuance of licenses for all 67 CCYAs to whom DHS subgrants funds to perform Foster Care, Adoption Assistance services, and Temporary Assistance for Needy Families (TANF) Child Welfare. These inspections primarily focus on health, safety, and performance issues, and each on-site inspection is documented on an Annual Survey and Evaluation Summary. A license, or certificate of compliance, is issued for a period of one year if the results of the on-site inspection determine the entity is in compliance with statutes, ordinances, and regulations. In addition, a separate group within DHS?s OCYF performs Title IV-E Quality Assurance Compliance Reviews which primarily focus on eligibility and allowability. These two types of on-site monitoring visits are not performed at the same time. To test DHS?s licensing/inspections and Quality Assurance Compliance Reviews in the current year, we selected 13 of the 67 CCYAs receiving Foster Care, Adoption Assistance, and TANF funds. Our current year testing of the on-site licensing inspections disclosed the following exceptions: ? Four of the 13 on-site inspections of the 13 CCYAs tested were either not reviewed and approved timely, or not reviewed and approved at all, by a supervisor and a regional director. One of the inspections was approved 292 days after the expiration of the prior license, and the other three inspections were not reviewed and approved by a supervisor and a regional director. Also, as part of our testing of monitoring, we noted that DHS did not have adequate procedures in place to determine if CCYAs were monitoring their subrecipients. Specifically, DHS did not perform procedures to determine if CCYAs were monitoring Single Audits of its subrecipients and evaluating the follow-up of any findings, or that CCYAs were only paying for allowable services. Foster Care program payments made by DHS to its 67 CCYA subrecipients during the fiscal year ended June 30, 2019 were $201.5 million, or 90.2 percent of total Foster Care expenditures of $223.4 million reported on the June 30, 2019 Schedule of Expenditures of Federal Awards (SEFA). Adoption Assistance program payments made by DHS to its 67 CCYA subrecipients during the fiscal year ended June 30, 2019 were $89.4 million, or 71.9 percent of total Adoption Assistance expenditures of $124.3 million reported on the June 30, 2019 SEFA. TANF Child Welfare program payments made by DHS to its 67 CCYA subrecipients during the fiscal year ended June 30, 2019 were $49.7 million, or 9.7 percent of total TANF expenditures of $513.1 million reported on the June 30, 2019 SEFA. Finding 2019 ? 009: (continued) Criteria: 45 CFR Section 75.352, applicable to TANF, Foster Care, and Adoption Assistance states: (d) Monitor the activities of the subrecipient as necessary to ensure that the subaward is used for authorized purposes, in compliance with Federal statutes, regulations, and the terms and conditions of the subaward; and that subaward performance goals are achieved. Pass-through entity monitoring of the subrecipient must include: (1) Reviewing financial and programmatic reports required by the pass-through entity. (2) Following-up and ensuring that the subrecipient takes timely and appropriate action on all deficiencies pertaining to the Federal award provided to the subrecipient from the pass-through entity detected through audits, on-site reviews, and other means. (3) Issuing a management decision for audit findings pertaining to the Federal award provided to the subrecipient? PA Code Title 55, Chapter 20, Licensure or Approval of Facilities and Agencies, Section 20.51 states: A certificate of compliance will be issued to the legal entity by the Department if, after an inspection by an authorized agent of the Department, it is determined that requirements for a certificate of compliance are met. In addition, PA Code Title 55, Chapter 20, Section 20.52 states: If, during an inspection, authorized agents of the Department observe items of noncompliance with licensure or approval regulations, the legal entity shall submit an acceptable written plan to correct each noncompliance item and shall establish an acceptable period of time to correct these items. Management Directive 325.12, Standards for Internal Control for Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book), published in September 2014. The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: As noted in the Corrective Action Plan for prior year Finding 2018 ? 010, DHS started tracking the timeliness of the annual on-site licensing inspections to ensure that inspections were timely completed, reviewed, and approved. However, as noted above, the on-site inspections were not reviewed and approved by a supervisor or regional director prior to the expiration of the prior license. DHS personnel indicated that the four on-site inspections were not timely reviewed and approved by a supervisor or a regional director due to on-going discussions between the applicable CCYAs and DHS, as well as oversight by DHS regarding the completion of the on-site inspections. DHS believes that its current monitoring procedures to determine subrecipient eligibility, monitor programmatic operations, review subrecipient audits, and review subrecipient agreed-upon-procedure reports are sufficient to effectively monitor its subrecipients or contractors. Effect: DHS OCYF?s failure to timely review and approve inspection reports before the expiration of the prior license allowed the CCYAs to operate without a proper license for an extended period of time. Also, since DHS did not determine if CCYAs were monitoring their subrecipients, CCYAs could be operating in noncompliance with federal regulations without timely detection and correction by DHS management. Finding 2019 ? 009: (continued) Recommendation: DHS?s OCYF should strengthen its controls to ensure monitoring and inspections of Foster Care, Adoption Assistance, and TANF subrecipients are performed and reviewed by management on a timely basis and include procedures to ensure CCYAs are monitoring their subrecipients or contractors. Agency Response: DHS agrees with this finding. Questioned Costs: The amount of questioned costs cannot be determined. The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Show full finding ▾
Full finding narrative

Department of Human Services Finding 2019 ? 009: CFDA #93.558 ? Temporary Assistance for Needy Families CFDA #93.658 ? Foster Care ? Title IV-E CFDA #93.659 ? Adoption Assistance Material Weaknesses and Material Noncompliance Exist in Monitoring of Foster Care, Adoption Assistance, and Temporary Assistance for Needy Families Subrecipients by the Department of Human Services? Office of Children, Youth, and Families (A Similar Condition Was Noted in Prior Year Finding 2018-010) Federal Grant Number(s) and Year(s): 1801PATANF (10/01/2017 ? 9/30/2018), 1901PATANF (10/01/2018 ? 9/30/2019), 1801PAFOST (10/01/2017 ? 9/30/2018), 1901PAFOST (10/01/2018 ? 9/30/2019), 1801PAADPT (10/01/2017 ? 9/30/2018), 1901PAADPT (10/01/2018 ? 9/30/2019) Type of Finding: Material Weakness, Material Noncompliance Compliance Requirement: Subrecipient Monitoring Condition: The Department of Human Services? (DHS) Office of Children, Youth, and Families (OCYF) performs two types of during-the-award monitoring of its 67 subrecipient County Children and Youth Agencies (CCYAs). One group within OCYF performs on-site inspections to support its reissuance of licenses for all 67 CCYAs to whom DHS subgrants funds to perform Foster Care, Adoption Assistance services, and Temporary Assistance for Needy Families (TANF) Child Welfare. These inspections primarily focus on health, safety, and performance issues, and each on-site inspection is documented on an Annual Survey and Evaluation Summary. A license, or certificate of compliance, is issued for a period of one year if the results of the on-site inspection determine the entity is in compliance with statutes, ordinances, and regulations. In addition, a separate group within DHS?s OCYF performs Title IV-E Quality Assurance Compliance Reviews which primarily focus on eligibility and allowability. These two types of on-site monitoring visits are not performed at the same time. To test DHS?s licensing/inspections and Quality Assurance Compliance Reviews in the current year, we selected 13 of the 67 CCYAs receiving Foster Care, Adoption Assistance, and TANF funds. Our current year testing of the on-site licensing inspections disclosed the following exceptions: ? Four of the 13 on-site inspections of the 13 CCYAs tested were either not reviewed and approved timely, or not reviewed and approved at all, by a supervisor and a regional director. One of the inspections was approved 292 days after the expiration of the prior license, and the other three inspections were not reviewed and approved by a supervisor and a regional director. Also, as part of our testing of monitoring, we noted that DHS did not have adequate procedures in place to determine if CCYAs were monitoring their subrecipients. Specifically, DHS did not perform procedures to determine if CCYAs were monitoring Single Audits of its subrecipients and evaluating the follow-up of any findings, or that CCYAs were only paying for allowable services. Foster Care program payments made by DHS to its 67 CCYA subrecipients during the fiscal year ended June 30, 2019 were $201.5 million, or 90.2 percent of total Foster Care expenditures of $223.4 million reported on the June 30, 2019 Schedule of Expenditures of Federal Awards (SEFA). Adoption Assistance program payments made by DHS to its 67 CCYA subrecipients during the fiscal year ended June 30, 2019 were $89.4 million, or 71.9 percent of total Adoption Assistance expenditures of $124.3 million reported on the June 30, 2019 SEFA. TANF Child Welfare program payments made by DHS to its 67 CCYA subrecipients during the fiscal year ended June 30, 2019 were $49.7 million, or 9.7 percent of total TANF expenditures of $513.1 million reported on the June 30, 2019 SEFA. Finding 2019 ? 009: (continued) Criteria: 45 CFR Section 75.352, applicable to TANF, Foster Care, and Adoption Assistance states: (d) Monitor the activities of the subrecipient as necessary to ensure that the subaward is used for authorized purposes, in compliance with Federal statutes, regulations, and the terms and conditions of the subaward; and that subaward performance goals are achieved. Pass-through entity monitoring of the subrecipient must include: (1) Reviewing financial and programmatic reports required by the pass-through entity. (2) Following-up and ensuring that the subrecipient takes timely and appropriate action on all deficiencies pertaining to the Federal award provided to the subrecipient from the pass-through entity detected through audits, on-site reviews, and other means. (3) Issuing a management decision for audit findings pertaining to the Federal award provided to the subrecipient? PA Code Title 55, Chapter 20, Licensure or Approval of Facilities and Agencies, Section 20.51 states: A certificate of compliance will be issued to the legal entity by the Department if, after an inspection by an authorized agent of the Department, it is determined that requirements for a certificate of compliance are met. In addition, PA Code Title 55, Chapter 20, Section 20.52 states: If, during an inspection, authorized agents of the Department observe items of noncompliance with licensure or approval regulations, the legal entity shall submit an acceptable written plan to correct each noncompliance item and shall establish an acceptable period of time to correct these items. Management Directive 325.12, Standards for Internal Control for Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book), published in September 2014. The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: As noted in the Corrective Action Plan for prior year Finding 2018 ? 010, DHS started tracking the timeliness of the annual on-site licensing inspections to ensure that inspections were timely completed, reviewed, and approved. However, as noted above, the on-site inspections were not reviewed and approved by a supervisor or regional director prior to the expiration of the prior license. DHS personnel indicated that the four on-site inspections were not timely reviewed and approved by a supervisor or a regional director due to on-going discussions between the applicable CCYAs and DHS, as well as oversight by DHS regarding the completion of the on-site inspections. DHS believes that its current monitoring procedures to determine subrecipient eligibility, monitor programmatic operations, review subrecipient audits, and review subrecipient agreed-upon-procedure reports are sufficient to effectively monitor its subrecipients or contractors. Effect: DHS OCYF?s failure to timely review and approve inspection reports before the expiration of the prior license allowed the CCYAs to operate without a proper license for an extended period of time. Also, since DHS did not determine if CCYAs were monitoring their subrecipients, CCYAs could be operating in noncompliance with federal regulations without timely detection and correction by DHS management. Finding 2019 ? 009: (continued) Recommendation: DHS?s OCYF should strengthen its controls to ensure monitoring and inspections of Foster Care, Adoption Assistance, and TANF subrecipients are performed and reviewed by management on a timely basis and include procedures to ensure CCYAs are monitoring their subrecipients or contractors. Agency Response: DHS agrees with this finding. Questioned Costs: The amount of questioned costs cannot be determined. The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Corrective Action Plan

The OCYF Regional Director is currently meeting with the Regional Offices involved to address and correct the situation. The OCYF Regional Offices would be adhering to the DHS policy when a licensing inspection summary will be written within 15 business days of the last day of the inspection, the counties will have 10 calendar days to respond to our plan of correction (POC). That POC needs to be reviewed by the regional office within 10 business days for compliance. The licensing inspection summary will be sent to Harrisburg for processing. The OCYF Regional Director staff will be doing periodic checks on a quarterly basis to verify the documentation is submitted timely. Concerning the monitoring of subrecipients, OCYF is working on a strategy to strengthen controls to ensure CCYAs are monitoring their subrecipients and contractors. Updated policies and procedures will be identified by June 30, 2020; and implemented in July 2020. Anticipated Completion Date: 07/31/2020 Contact Person: Tia Petrovitz, Fiscal Management Specialist 4

Prior Finding References

2018-010

About Subrecipient Monitoring →
2019-010
Cash Management / Subrecipient Monitoring
MATERIAL WEAKNESSREPEATQUESTIONED COSTS

Our examination of the Department of Human Services? (DHS) procedures for monitoring Social Services Block Grant (SSBG) subrecipients revealed that DHS did not adequately monitor the SSBG Mental Health, Homeless Services, Child Welfare, Domestic Violence, Rape Crisis, Legal Services, and Family Planning subrecipients to ensure that SSBG awards are used in compliance with laws and regulations, which include allowable costs, period of performance, and other requirements. The inadequately monitored subrecipients received $40.8 million (or approximately 45 percent) of total SSBG program expenditures of $91.4 million on the Schedule of Expenditures of Federal Awards (SEFA). In addition, we determined that the Homeless Services program subrecipients that received SSBG funding and were not adequately monitored by DHS personnel also received $1,983,000 in Block Grants for Prevention and Treatment of Substance Abuse (SABG) funding during the fiscal year ended June 30, 2019. Total SABG expenditures on the current SEFA were $49.8 million. In addition, for the compliance requirement related to cash management, we noted that DHS advanced funds to SSBG subrecipients in five of nine program areas, representing $38.6 million (or approximately 42 percent) of SSBG program expenditures, without adequately monitoring the reasonableness of the subrecipient cash balances. In particular, for the Legal Services components of the SSBG program, DHS advanced funds to subrecipients on a monthly basis. For program areas related to Mental Health, Intellectual Disabilities, Homeless Services, and Child Welfare, DHS advanced funds to subrecipients on a quarterly basis. Also, we noted $1,983,000 of SABG funds were advanced under the Homeless Services program area without adequately monitoring the reasonableness of the subrecipient cash balances. Our inquiries with applicable DHS program administrators disclosed that DHS did not adequately monitor the five program areas? subrecipients for cash management compliance either at the time of payment or at any other time during the fiscal year ended June 30, 2019. Furthermore, while Single Audits of SSBG and SABG subrecipients are to be conducted each year, this auditing activity does not compensate for the lack of during-the-award program monitoring, since the timing, focus, and scope of subrecipient auditing activities after year end are different than compliance monitoring to be performed by program officials during the year. Criteria: 45 CFR Section 75.352, Requirements for pass-through entities, states: (d) Monitor the activities of the subrecipient as necessary to ensure that the subaward is used for authorized purposes, in compliance with Federal statutes, regulations, and the terms and conditions of the subaward; and that subaward performance goals are achieved. Pass-through entity monitoring of the subrecipient must include: Finding 2019 ? 010: (continued) (1) Reviewing financial and performance reports required by the pass-through entity. (2) Following-up and ensuring that the subrecipient takes timely and appropriate action on all deficiencies pertaining to the Federal award provided to the subrecipient from the pass-through entity detected through audits, on-site reviews, and other means. (3) Issuing a management decision for audit findings pertaining to the Federal award provided to the subrecipient from the pass-through entity? (e) Depending upon the pass-through entity's assessment of risk posed by the subrecipient (as described in paragraph (b) of this section), the following monitoring tools may be useful for the pass-through entity to ensure proper accountability and compliance with program requirements and achievement of performance goals: (1) Providing subrecipients with training and technical assistance on program-related matters; and (2) Performing on-site reviews of the subrecipient's program operations; (3) Arranging for agreed-upon-procedures engagements as described in ?75.425 (Audit services). 45 CFR Section 75.305(b)(1), applicable to payments to subrecipients, states in part: ?Advance payments to a non-Federal entity must be limited to the minimum amounts needed and be timed to be in accordance with the actual, immediate cash requirements of the non-Federal entity in carrying out the purpose of the approved program or project. The timing and amount of advance payments must be as close as is administratively feasible to the actual disbursements by the non-Federal entity for direct program or project costs and the proportionate share of any allowable indirect costs. The non-Federal entity must make timely payment to contractors in accordance with the contract provisions. Management Directive 325.12, Standards for Internal Control in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book), published in September 2014. The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: DHS management indicated that risk assessment and monitoring documents were created for use during on-site monitoring of SSBG and SABG subrecipients. However, due to staffing issues, on-site monitoring was not performed for all SSBG and SABG subrecipients. Consistent with prior year audits, DHS management noted that there have been no changes to the payment methodology for the Legal Services, Homeless Services, Mental Health, Intellectual Disabilities, and Child Welfare components of SSBG. These programs provide subrecipients with advances to comply with Commonwealth law and also to ensure that adequate funds are available to provide services to participants on a timely basis. DHS officials believe that their in-house payment review procedures for the SSBG and SABG programs are as efficient as administratively feasible and that controls exist in each of the program areas. Without on-site program monitoring visits by funding agency officials, we consider DHS?s limited in-house reviews of subrecipient status reports or other documents to be insufficient to detect potential subrecipient noncompliance, including excess cash violations. DHS does not adjust payments to the subrecipients based on in-house reviews. Finding 2019 ? 010: (continued) Effect: Since DHS does not adequately perform during-the-award monitoring of subrecipients, including the monitoring of subrecipient cash on hand, subrecipients may not be complying with applicable grant requirements and federal regulations, including cash management standards. Recommendation: DHS should perform risk based during-the-award monitoring procedures for SSBG and SABG subrecipients to ensure timely compliance with all applicable federal regulations. On-site monitoring visits by state officials should be supported by documentation to show the monitoring performed, areas examined, conclusions reached, and that the monitoring was performed in compliance with applicable regulations. Also, we suggest that DHS should coordinate the monitoring of SSBG subrecipients with other program funding received by the same subrecipients. As recommended in previous Single Audits and supported by the United States Department of Health and Human Services, DHS should either consider changing their current subrecipient payment procedures from advancement basis to reimbursement basis or establish procedures to adequately monitor subrecipient cash on hand to ensure it is limited to immediate needs, but no longer than one month. The implementation and strengthening of these controls should provide DHS with reasonable assurance as to compliance with cash management requirements at the subrecipient level. Agency Response: DHS agrees with this finding. Questioned Costs: The amount of questioned costs cannot be determined. The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Show full finding ▾
Full finding narrative

Department of Human Services Finding 2019 ? 010: CFDA #93.667 ? Social Services Block Grant CFDA #93.959 ? Block Grants for Prevention and Treatment of Substance Abuse Noncompliance and Weaknesses Exist in the Department of Human Services? Program Monitoring of the Social Services Block Grant and the Block Grants for Prevention and Treatment of Substance Abuse Subrecipients (A Similar Condition Was Noted in Prior Year Finding 2018-011) Federal Grant Number(s) and Year(s): 1801PASOSR (10/01/2017 ? 9/30/2018), 1901PASOSR (10/01/2018 ? 9/30/2019), 2B08TI010044-18 (10/01/2017 ? 9/30/2018), 3B08TI010044-19 (10/01/2018 ? 9/30/2020) Type of Finding: Material Weakness, Material Noncompliance for SSBG Significant Deficiency, Noncompliance for SABG Compliance Requirement: Cash Management, Subrecipient Monitoring Condition: Our examination of the Department of Human Services? (DHS) procedures for monitoring Social Services Block Grant (SSBG) subrecipients revealed that DHS did not adequately monitor the SSBG Mental Health, Homeless Services, Child Welfare, Domestic Violence, Rape Crisis, Legal Services, and Family Planning subrecipients to ensure that SSBG awards are used in compliance with laws and regulations, which include allowable costs, period of performance, and other requirements. The inadequately monitored subrecipients received $40.8 million (or approximately 45 percent) of total SSBG program expenditures of $91.4 million on the Schedule of Expenditures of Federal Awards (SEFA). In addition, we determined that the Homeless Services program subrecipients that received SSBG funding and were not adequately monitored by DHS personnel also received $1,983,000 in Block Grants for Prevention and Treatment of Substance Abuse (SABG) funding during the fiscal year ended June 30, 2019. Total SABG expenditures on the current SEFA were $49.8 million. In addition, for the compliance requirement related to cash management, we noted that DHS advanced funds to SSBG subrecipients in five of nine program areas, representing $38.6 million (or approximately 42 percent) of SSBG program expenditures, without adequately monitoring the reasonableness of the subrecipient cash balances. In particular, for the Legal Services components of the SSBG program, DHS advanced funds to subrecipients on a monthly basis. For program areas related to Mental Health, Intellectual Disabilities, Homeless Services, and Child Welfare, DHS advanced funds to subrecipients on a quarterly basis. Also, we noted $1,983,000 of SABG funds were advanced under the Homeless Services program area without adequately monitoring the reasonableness of the subrecipient cash balances. Our inquiries with applicable DHS program administrators disclosed that DHS did not adequately monitor the five program areas? subrecipients for cash management compliance either at the time of payment or at any other time during the fiscal year ended June 30, 2019. Furthermore, while Single Audits of SSBG and SABG subrecipients are to be conducted each year, this auditing activity does not compensate for the lack of during-the-award program monitoring, since the timing, focus, and scope of subrecipient auditing activities after year end are different than compliance monitoring to be performed by program officials during the year. Criteria: 45 CFR Section 75.352, Requirements for pass-through entities, states: (d) Monitor the activities of the subrecipient as necessary to ensure that the subaward is used for authorized purposes, in compliance with Federal statutes, regulations, and the terms and conditions of the subaward; and that subaward performance goals are achieved. Pass-through entity monitoring of the subrecipient must include: Finding 2019 ? 010: (continued) (1) Reviewing financial and performance reports required by the pass-through entity. (2) Following-up and ensuring that the subrecipient takes timely and appropriate action on all deficiencies pertaining to the Federal award provided to the subrecipient from the pass-through entity detected through audits, on-site reviews, and other means. (3) Issuing a management decision for audit findings pertaining to the Federal award provided to the subrecipient from the pass-through entity? (e) Depending upon the pass-through entity's assessment of risk posed by the subrecipient (as described in paragraph (b) of this section), the following monitoring tools may be useful for the pass-through entity to ensure proper accountability and compliance with program requirements and achievement of performance goals: (1) Providing subrecipients with training and technical assistance on program-related matters; and (2) Performing on-site reviews of the subrecipient's program operations; (3) Arranging for agreed-upon-procedures engagements as described in ?75.425 (Audit services). 45 CFR Section 75.305(b)(1), applicable to payments to subrecipients, states in part: ?Advance payments to a non-Federal entity must be limited to the minimum amounts needed and be timed to be in accordance with the actual, immediate cash requirements of the non-Federal entity in carrying out the purpose of the approved program or project. The timing and amount of advance payments must be as close as is administratively feasible to the actual disbursements by the non-Federal entity for direct program or project costs and the proportionate share of any allowable indirect costs. The non-Federal entity must make timely payment to contractors in accordance with the contract provisions. Management Directive 325.12, Standards for Internal Control in Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book), published in September 2014. The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: DHS management indicated that risk assessment and monitoring documents were created for use during on-site monitoring of SSBG and SABG subrecipients. However, due to staffing issues, on-site monitoring was not performed for all SSBG and SABG subrecipients. Consistent with prior year audits, DHS management noted that there have been no changes to the payment methodology for the Legal Services, Homeless Services, Mental Health, Intellectual Disabilities, and Child Welfare components of SSBG. These programs provide subrecipients with advances to comply with Commonwealth law and also to ensure that adequate funds are available to provide services to participants on a timely basis. DHS officials believe that their in-house payment review procedures for the SSBG and SABG programs are as efficient as administratively feasible and that controls exist in each of the program areas. Without on-site program monitoring visits by funding agency officials, we consider DHS?s limited in-house reviews of subrecipient status reports or other documents to be insufficient to detect potential subrecipient noncompliance, including excess cash violations. DHS does not adjust payments to the subrecipients based on in-house reviews. Finding 2019 ? 010: (continued) Effect: Since DHS does not adequately perform during-the-award monitoring of subrecipients, including the monitoring of subrecipient cash on hand, subrecipients may not be complying with applicable grant requirements and federal regulations, including cash management standards. Recommendation: DHS should perform risk based during-the-award monitoring procedures for SSBG and SABG subrecipients to ensure timely compliance with all applicable federal regulations. On-site monitoring visits by state officials should be supported by documentation to show the monitoring performed, areas examined, conclusions reached, and that the monitoring was performed in compliance with applicable regulations. Also, we suggest that DHS should coordinate the monitoring of SSBG subrecipients with other program funding received by the same subrecipients. As recommended in previous Single Audits and supported by the United States Department of Health and Human Services, DHS should either consider changing their current subrecipient payment procedures from advancement basis to reimbursement basis or establish procedures to adequately monitor subrecipient cash on hand to ensure it is limited to immediate needs, but no longer than one month. The implementation and strengthening of these controls should provide DHS with reasonable assurance as to compliance with cash management requirements at the subrecipient level. Agency Response: DHS agrees with this finding. Questioned Costs: The amount of questioned costs cannot be determined. The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Corrective Action Plan

1. The DHS expends Social Services Block Grant (SSBG) funds through several program offices, and directly on certain contracts. Office of Administration (OA): Counties are chosen for monitoring based on a risk assessment tool including allocation amount, findings in the county?s single audit report, and timely submission. Counties receiving a ?high risk? designation are prioritized. A subrecipient risk assessment has been conducted for fiscal year 2019-2020. The first review for the year began in October 2019. The monitoring procedures have been streamlined to an extent and the results of the streamlining will be evaluated on an on-going basis to determine if changes are needed. As it relates to cash management, given the relatively small amounts of money involved and the number of counties affected, DHS has determined that it is not economically feasible to change the payment methodology at this time. Anticipated Completion Date: 06/30/2020 Contact Person: Kelly Leighty, Director, Division of Financial Policy and Operations 2. Office of Policy Development (OPD): Risk assessments have been completed for fiscal year 2019-2020 for the grant programs managed. Monitoring will occur in the 3rd quarter of the fiscal year. Anticipated Completion Date: May 2020 Contact Person: Cassie Hourlland, Grants & Policy Specialist, OPD

Prior Finding References

2018-011

About Cash Management, Subrecipient Monitoring →
2019-011
Eligibility / Special Tests & Provisions
MATERIAL WEAKNESSREPEAT

As part of the Rehabilitation Services ? Vocational Rehabilitation Grants to States (RS-VR) program, the Office of Vocational Rehabilitation (OVR), Pennsylvania Department of Labor and Industry, purchases vocational rehabilitation services from vendors to be provided to OVR clients. We selected a sample of 10 participants in the RS-VR program for benefits totaling $27,347 of the $56.2 million charged to the program during the fiscal year ended June 30, 2019. Our review of the 10 OVR client case files disclosed the following: ? For 2 of the 10 OVR clients tested for whom RS-VR program payments were made, OVR personnel did not make the eligibility determinations within 60 days after the RS-VR program application date or by the agreed upon extension date as required by federal regulations. The eligibility determinations were completed 80 and 83 days, respectively, after the eligibility determination period expired. ? For 2 of the 9 OVR clients tested for whom RS-VR payments were made and for whom Individual Plans for Employment (IPE) were required, OVR personnel did not complete an IPE within 90 days after the RS-VR eligibility was determined or by the agreed upon extension as required by federal regulations. The IPEs that were not completed timely were completed 18 and 76 days, respectively, after the 90 day IPE completion deadline expired. Criteria: The United States Department of Education?s Regulation 34 CFR Section 361 regarding the State Vocational Rehabilitation Services Program states in part: Section 361.41 Processing referrals and applications. (a) Referrals. The designated State unit must establish and implement standards for the prompt and equitable handling of referrals of individuals for vocational rehabilitation services, including referrals of individuals made through the One-Stop service delivery systems established under section 121 of the Workforce Investment Act of 1998. The standards must include timelines for making good faith efforts to inform these individuals of application requirements and to gather information necessary to initiate an assessment for determining eligibility and priority for services. (b) Applications. (1) Once an individual has submitted an application for vocational rehabilitation services, including applications made through common intake procedures in One-Stop centers established under section 121 of the Workforce Investment Act of 1998, an eligibility determination must be made within 60 days, unless- (i) Exceptional and unforeseen circumstances beyond the control of the designated State unit preclude making an eligibility determination within 60 days and the designated State unit and the individual agree to a specific extension of time; or Finding 2019 ? 011: (continued) (ii) An exploration of the individual?s abilities, capabilities, and capacity to perform in work situations is carried out in accordance with section 361.42(e) or, if appropriate, an extended evaluation is carried out in accordance with section 361.42(f). In addition, Section 361.45 states in part: Section 361.45 Developing of the individualized plan for employment. (a) General requirements. The State plan must assure that? (1) An individualized plan for employment (IPE) meeting the requirements of this section and Section 361.46 is developed and implemented in a timely manner for each individual determined to be eligible for vocational rehabilitation services? Further, 29 USC 722(b)(3)(F) states in part: (F) Timeframe for completing the individualized plan for employment. The individualized plan for employment shall be developed as soon as possible, but not later than a deadline of 90 days after the date of the determination of eligibility described in paragraph (1), unless the designated State unit and the eligible individual agree to an extension of that deadline to a specific date by which the individualized plan for employment shall be completed. Management Directive 325.12, Standards for Internal Control for Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book), published in September 2014. The Green Book states in part: Management should design control activities to achieve objectives and respond to risks. Management should implement control activities through policies. Cause: OVR personnel indicated that the untimely eligibility determinations and IPE completions were due to inadequate administrative and employee oversight. Effect: Since OVR personnel did not have adequate procedures in place to ensure that client eligibility determinations were completed within 60 days of the application date or within the specific time period extension agreed upon by the client, or that IPEs were completed within 90 days of the eligibility determination or within the specific time period extension agreed upon by the client, OVR was not in compliance with federal regulations and a control deficiency exists. Also, OVR clients may not receive necessary RS-VR program services timely. Our sample contained no ineligible OVR clients for whom case service costs were incurred, so no costs are questioned. Recommendation: We recommend that OVR personnel have procedures in place to timely identify and follow up on incomplete eligibility determinations and to ensure that all client eligibility determinations are completed within the 60 day period subsequent to the application date or within the specific time period extension agreed upon by the client to ensure compliance with federal regulations. In addition, OVR personnel should have procedures in place to ensure that IPEs are completed within 90 days of the eligibility determination. Agency Response: OVR agrees with the finding. Questioned Costs: None The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Show full finding ▾
Full finding narrative

Department of Labor and Industry Finding 2019 ? 011: CFDA #84.126 ? Rehabilitation Services ? Vocational Rehabilitation Grants to States A Material Weakness and Material Noncompliance Exist in the Department of Labor and Industry?s Procedures for Performing Eligibility Determinations and Completing Individualized Plans for Employment (A Similar Condition Was Noted in Prior Year Finding 2018-014) Federal Grant Number(s) and Year(s): H126A170056 (10/01/2016 ? 9/30/2017), H126A180056 (10/01/2017 ? 9/30/2018), H126A190056 (10/01/2018 ? 9/30/2019) Type of Finding: Material Weakness, Material Noncompliance Compliance Requirement: Eligibility, Special Tests and Provisions related to Completion of Individualized Plans for Employment (IPEs) Condition: As part of the Rehabilitation Services ? Vocational Rehabilitation Grants to States (RS-VR) program, the Office of Vocational Rehabilitation (OVR), Pennsylvania Department of Labor and Industry, purchases vocational rehabilitation services from vendors to be provided to OVR clients. We selected a sample of 10 participants in the RS-VR program for benefits totaling $27,347 of the $56.2 million charged to the program during the fiscal year ended June 30, 2019. Our review of the 10 OVR client case files disclosed the following: ? For 2 of the 10 OVR clients tested for whom RS-VR program payments were made, OVR personnel did not make the eligibility determinations within 60 days after the RS-VR program application date or by the agreed upon extension date as required by federal regulations. The eligibility determinations were completed 80 and 83 days, respectively, after the eligibility determination period expired. ? For 2 of the 9 OVR clients tested for whom RS-VR payments were made and for whom Individual Plans for Employment (IPE) were required, OVR personnel did not complete an IPE within 90 days after the RS-VR eligibility was determined or by the agreed upon extension as required by federal regulations. The IPEs that were not completed timely were completed 18 and 76 days, respectively, after the 90 day IPE completion deadline expired. Criteria: The United States Department of Education?s Regulation 34 CFR Section 361 regarding the State Vocational Rehabilitation Services Program states in part: Section 361.41 Processing referrals and applications. (a) Referrals. The designated State unit must establish and implement standards for the prompt and equitable handling of referrals of individuals for vocational rehabilitation services, including referrals of individuals made through the One-Stop service delivery systems established under section 121 of the Workforce Investment Act of 1998. The standards must include timelines for making good faith efforts to inform these individuals of application requirements and to gather information necessary to initiate an assessment for determining eligibility and priority for services. (b) Applications. (1) Once an individual has submitted an application for vocational rehabilitation services, including applications made through common intake procedures in One-Stop centers established under section 121 of the Workforce Investment Act of 1998, an eligibility determination must be made within 60 days, unless- (i) Exceptional and unforeseen circumstances beyond the control of the designated State unit preclude making an eligibility determination within 60 days and the designated State unit and the individual agree to a specific extension of time; or Finding 2019 ? 011: (continued) (ii) An exploration of the individual?s abilities, capabilities, and capacity to perform in work situations is carried out in accordance with section 361.42(e) or, if appropriate, an extended evaluation is carried out in accordance with section 361.42(f). In addition, Section 361.45 states in part: Section 361.45 Developing of the individualized plan for employment. (a) General requirements. The State plan must assure that? (1) An individualized plan for employment (IPE) meeting the requirements of this section and Section 361.46 is developed and implemented in a timely manner for each individual determined to be eligible for vocational rehabilitation services? Further, 29 USC 722(b)(3)(F) states in part: (F) Timeframe for completing the individualized plan for employment. The individualized plan for employment shall be developed as soon as possible, but not later than a deadline of 90 days after the date of the determination of eligibility described in paragraph (1), unless the designated State unit and the eligible individual agree to an extension of that deadline to a specific date by which the individualized plan for employment shall be completed. Management Directive 325.12, Standards for Internal Control for Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book), published in September 2014. The Green Book states in part: Management should design control activities to achieve objectives and respond to risks. Management should implement control activities through policies. Cause: OVR personnel indicated that the untimely eligibility determinations and IPE completions were due to inadequate administrative and employee oversight. Effect: Since OVR personnel did not have adequate procedures in place to ensure that client eligibility determinations were completed within 60 days of the application date or within the specific time period extension agreed upon by the client, or that IPEs were completed within 90 days of the eligibility determination or within the specific time period extension agreed upon by the client, OVR was not in compliance with federal regulations and a control deficiency exists. Also, OVR clients may not receive necessary RS-VR program services timely. Our sample contained no ineligible OVR clients for whom case service costs were incurred, so no costs are questioned. Recommendation: We recommend that OVR personnel have procedures in place to timely identify and follow up on incomplete eligibility determinations and to ensure that all client eligibility determinations are completed within the 60 day period subsequent to the application date or within the specific time period extension agreed upon by the client to ensure compliance with federal regulations. In addition, OVR personnel should have procedures in place to ensure that IPEs are completed within 90 days of the eligibility determination. Agency Response: OVR agrees with the finding. Questioned Costs: None The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Corrective Action Plan

All offices will receive a statewide Status 02 and Status 10 Accountability plan (Standard Operating Procedure [SOP]) that they will begin to follow upon release. 1. Stephanie Perry and Stan Swaintek will write and implement the SOP by COB March 2020. 2. As part of the SOP, monthly Status 02 and Status 10 reports will be sent out by CO to each District Office management team by a central office designated individual. Reports will be saved in the T-Drive for reference and will be stored for no more than 2 years. 3. Offices will have until 7/1/2020 to implement the SOP and to address compliance of any outstanding cases related to 02 or 10. 4. Effective 7/1/2020 offices will be monitored for ongoing compliance of the Accountability Plan and for statistical compliance for all Status 02 and Status 10 cases by OVR Central Office (Compliance Officer). a. The Compliance Officer will document all offices standing and submit a report to the OVR Executive Director and Executive Leadership Team on compliance performance with these cases. i. Monitoring will occur by quarter. ii. If by the end of each quarter an office is not compliant with their Status 02 or Status 10 the District Manager will receive a Memorandum of Instruction (MOI), as well as, technical assistance from their supervisor (Bureau Director/Regional Manager, etc.) and the compliance specialist(s) that will result in the development of a CAP for their office to address the compliance issues with the standards as outlined in the SOP/Back to Basics, etc. iii. If a Manager receives two consecutive MOI?s related to the Status 02 or Status 10, they will receive an interim EPR with a needs improvement in the work results section. 1. Other sections' ratings will be up to the manager's supervisor per existing protocols/expectations. iv. If compliance is reached prior to the end of the interim EPR quarter, the interim EPR will be removed from the record and will not be held against the manager at their annual EPR unless there are other areas of improvement documented and necessary per their supervisor/reviewing officer discretion. 1. Bureau Directors or their designee will have discretion regarding the issuance of MOIs or Interim EPRs if extenuating circumstances warrant it (ex: excessive vacancies, staff on Performance Improvement Plans, etc.) b. District Managers will be informed of this new requirement at the March 2020 Executive Director meeting, which will allow 3 months for offices to work on compliance issues, train staff, or otherwise address the situation prior to the ongoing and regular monitoring that will take effect on 7/1/2020. 5. Offices will continue to refer to OVR Back to Basics or other resources for additional information. Anticipated Completion Date: July 2020 Contact People: Stan Swaintek, Acting Director, Bureau of Blindness and Visual Services; Stephanie Perry, Acting Director, Bureau of Vocational Rehabilitation Services

Prior Finding References

2018-014

About Eligibility, Special Tests and Provisions →
2019-012
Period of Performance
MATERIAL WEAKNESSREPEATQUESTIONED COSTS

During our audit of the Rehabilitation Services ? Vocational Rehabilitation Grants to States (RS-VR) program, we evaluated internal control over and tested compliance with period of performance requirements for the grant awarded by the United States Department of Education that began during the fiscal year ended June 30, 2019 audit period. ? Per review of supporting invoice service dates, 21 of the 40 expenditures tested that were charged in the first month of the federal fiscal year 2019 RS-VR grant were incurred prior to the allowable period of performance. These expenditures included mileage reimbursements and other general charges totaling $208,756. Total expenditures posted to the federal fiscal year 2019 RS-VR grant in the first month of the allowable period of performance were $7,300,632. Management was unable to provide authorization from the federal awarding agency for allowance of the expenditures occurring outside of the period of performance. Criteria: 2 CFR Section 200.303(a), Internal controls, states: The non-Federal entity must: Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in ?Standards for Internal Control in the Federal Government? issued by the Comptroller General of the United States or the ?Internal Control Integrated Framework?, issued by the committee of the Sponsoring Organizations of the Treadway Commission (COSO). 2 CFR Section 200.309, Period of performance, states: A non-Federal entity may charge to the Federal award only allowable costs incurred during the period of performance (except as described in ?200.461 Publication and printing costs) and any costs incurred before the Federal awarding agency or pass-through entity made the award that were authorized by the Federal awarding agency or pass-through entity. Management Directive 325.12, Standards for Internal Control for Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book), published in September 2014. The Green Book states in part: Management should design control activities to achieve objectives and respond to risks. Management should implement control activities through policies. Finding 2019 ? 012: (continued) Cause: Office of Vocational Rehabilitation (OVR), Pennsylvania Department of Labor and Industry, personnel did not check service dates prior to submitting invoices for payment which were charged to the federal fiscal year 2019 grant. In addition, staff submitting claims for mileage reimbursement and those reviewing the claims did not ensure that reimbursed costs were charged to the correct federal grant year. OVR personnel did not have adequate procedures in place to ensure that only costs incurred during the allowable period of performance were charged to the federal fiscal year 2019 RS-VR grant. Effect: Expenditures outside of the allowable period of performance were incorrectly charged to the federal fiscal year 2019 RS-VR grant without authorization by the federal awarding agency, resulting in noncompliance and questioned costs. Recommendation: We recommend that OVR personnel implement procedures to ensure that costs and adjustments being charged to a federal grant are incurred within the allowable period of performance of the grant to which they are being charged, or when necessary, obtain authorization from the federal awarding agency prior to charging costs that are outside the allowable period of performance. Agency Response: OVR agrees with the finding. Questioned Costs: Known questioned costs for CFDA #84.126 of $208,756 were determined, which represent the amount of transactions incurred and charged to the federal grant outside the allowable period of performance. The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Show full finding ▾
Full finding narrative

Department of Labor and Industry Finding 2019 ? 012: CFDA #84.126 ? Rehabilitation Services ? Vocational Rehabilitation Grants to States A Material Weakness and Material Noncompliance Exist in the Department of Labor and Industry?s Procedures Related to Period of Performance Requirements (A Similar Condition Was Noted in Prior Year Finding 2018-015) Federal Grant Number(s) and Year(s): H126A190056 (10/01/2018 ? 9/30/2019) Type of Finding: Material Weakness, Material Noncompliance Compliance Requirement: Period of Performance Condition: During our audit of the Rehabilitation Services ? Vocational Rehabilitation Grants to States (RS-VR) program, we evaluated internal control over and tested compliance with period of performance requirements for the grant awarded by the United States Department of Education that began during the fiscal year ended June 30, 2019 audit period. ? Per review of supporting invoice service dates, 21 of the 40 expenditures tested that were charged in the first month of the federal fiscal year 2019 RS-VR grant were incurred prior to the allowable period of performance. These expenditures included mileage reimbursements and other general charges totaling $208,756. Total expenditures posted to the federal fiscal year 2019 RS-VR grant in the first month of the allowable period of performance were $7,300,632. Management was unable to provide authorization from the federal awarding agency for allowance of the expenditures occurring outside of the period of performance. Criteria: 2 CFR Section 200.303(a), Internal controls, states: The non-Federal entity must: Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in ?Standards for Internal Control in the Federal Government? issued by the Comptroller General of the United States or the ?Internal Control Integrated Framework?, issued by the committee of the Sponsoring Organizations of the Treadway Commission (COSO). 2 CFR Section 200.309, Period of performance, states: A non-Federal entity may charge to the Federal award only allowable costs incurred during the period of performance (except as described in ?200.461 Publication and printing costs) and any costs incurred before the Federal awarding agency or pass-through entity made the award that were authorized by the Federal awarding agency or pass-through entity. Management Directive 325.12, Standards for Internal Control for Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book), published in September 2014. The Green Book states in part: Management should design control activities to achieve objectives and respond to risks. Management should implement control activities through policies. Finding 2019 ? 012: (continued) Cause: Office of Vocational Rehabilitation (OVR), Pennsylvania Department of Labor and Industry, personnel did not check service dates prior to submitting invoices for payment which were charged to the federal fiscal year 2019 grant. In addition, staff submitting claims for mileage reimbursement and those reviewing the claims did not ensure that reimbursed costs were charged to the correct federal grant year. OVR personnel did not have adequate procedures in place to ensure that only costs incurred during the allowable period of performance were charged to the federal fiscal year 2019 RS-VR grant. Effect: Expenditures outside of the allowable period of performance were incorrectly charged to the federal fiscal year 2019 RS-VR grant without authorization by the federal awarding agency, resulting in noncompliance and questioned costs. Recommendation: We recommend that OVR personnel implement procedures to ensure that costs and adjustments being charged to a federal grant are incurred within the allowable period of performance of the grant to which they are being charged, or when necessary, obtain authorization from the federal awarding agency prior to charging costs that are outside the allowable period of performance. Agency Response: OVR agrees with the finding. Questioned Costs: Known questioned costs for CFDA #84.126 of $208,756 were determined, which represent the amount of transactions incurred and charged to the federal grant outside the allowable period of performance. The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Corrective Action Plan

Due to the timing of the receipt of the initial period of performance audit finding, OVR had administered the start of 10/1/2018 the same as the year prior, resulting in some of the continued issues. OVR has endeavored to make significant changes to how we administer funds in the system, how services are coded to the correct period of performance and has made multiple communications to staff to address issues associated to the period of performance requirements. OVR continues to evaluate the internal controls associated with period of performance requirements and we are looking for additional ways to ensure that staff are adhering to the requirements and that the system is updated to prevent period of performance violations when possible. The following outlines, at a high level, what has already been done and additional actions that are being planned associated with period of performance changes within the program: OVR implemented updated fiscal procedures on 7/1/2019 that added information about period of performance. As part of the updated fiscal procedures, a separate period of performance guidance document (also dated 7/1/2019) was issued to explain to staff the issues associated with period of performance. Both documents can be provided upon request. A training was held related to the changes associated with period of performance and end of year fiscal management was presented to OVR supervisors and managers on 8/28/2019. A document was made available that summarized the changes to the fiscal procedures, etc. An overview was also provided to OVR fiscal assistants on 9/19/2019. In the fall of 2019, OVR changed the way it disbursed funds through the system to limit the issues associated with period of performance. Fall college costs were estimated and reserved out of funds that were ending and authorized prior to the start of the new FFY, with the intent that the majority of all fall college/training costs would be purchased using FFY funds that were ending on 9/30/2019. New funds were then held until 10/1/2019 for all additional services and a several day moratorium that started on 9/20/2019 was implemented. During this moratorium, all POs were reviewed and either maintained, reduced, or canceled. The unused funds in the system were swept to create a clear delineation between the end and start of the two FFY in the two systems used. This was implemented at the end of the FFY to allow offices to clear up their outstanding balances and plan for the usage of the new funds that would be awarded following 10/1/2019. A series of communications also began on 8/28/2019, providing instructions for the end of the year and included information on period of performance. An additional series of communications went out on 1/23/2020 providing additional instructions on fiscal processing, etc., including information on period of performance. Additional communications will be provided to all OVR staff through the remainder of the existing FFY to help ensure that offices are monitoring open commitments and processing items accordingly. In January and February of 2020 offices were asked to review all open commitments prior to 10/1/2019 that remained open and to maintain, reduce, or cancel them as appropriate. Several changes were also made to the case management system to update business rules and internal controls related to period of performance issues. The updated business rules were input prior to 10/1/2019 to better track and ensure that the system is applying the correct financial coding to invoices based on the obligation FFY. Additional internal controls are scheduled to be implemented in the system before June 2020. OVR continues to reevaluate the rules associated to period of performance and we have had several conversations with RSA regarding how to best implement additional internal controls around these requirements. OVR anticipates issuing new guidance in April 2020 related to period of performance and is reviewing the existing business rules to determine if additional actions are necessary prior to the end of the current FFY. OVR will continue to manage the disbursement of new funds in a similar manner to fall 2019 to ensure that services are not authorized prior to the start of the new FFY using the new grant. Additional changes were also made to how invoices and coding have been applied outside of the system for things like rent, utilities, etc. Those practices will be maintained moving forward to ensure better compliance with the period of performance rules. The internal orders associated with the new federal funds will not be opened by the Comptroller to receive expenditures prior to the receipt of the grant award notice or October 1st (whichever is later) in order to ensure no expenditures will be charged to the grant before the period of performance starts. If circumstances do not allow for changes within the system, written guidelines and procedures are being put into place to ensure processes are not compromised if there is a change in staff. Anticipated Compledtion Date: 10/01/2020 Contact People: Ryan Hyde, Director Central Operations; Nichole Nedinsky, Division Chief, Financial Management & Administrative Services; Nat Raney, Systems and Evaluation Supervisor

Prior Finding References

2018-015

About Period of Performance →
2019-013
Reporting

The Office of Vocational Rehabilitation (OVR), Pennsylvania Department of Labor and Industry, is required to submit an SF-425, Federal Financial Report, for the Rehabilitation Services ? Vocational Rehabilitation Grants to States (RS-VR) program to the United States Department of Education (USDE) on a semi-annual basis. The SF-425 report includes data related to the federal share of expenditures to date, the federal share of unliquidated obligations, the federal program income earned, the program income expended and unexpended, indirect charges to the grant, as well as other general information that is necessary to ensure compliance with program requirements. During the fiscal year ended June 30, 2019, we selected all four of the submitted semi-annual SF-425 reports for testing. As part of the report testing, we used the other general information to determine if the agency was in compliance with the 15 percent Pre-Employment Transition Services (PETS) earmarking requirement. Our procedures disclosed that the PETS amount reported on the final report for the 2017 RS-VR grant was understated by $141,674. The amount reported was $19,592,771, when actual PETS expenditure general ledger support reported an amount of $19,734,445. Although the SF-425 report was subjected to a documented supervisory review and approval, the understatement remained undetected by Commonwealth management until notification by the auditor. Criteria: 2 CFR Section 200.303(a), Internal controls, states: The non-Federal entity must: Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in ?Standards for Internal Control in the Federal Government? issued by the Comptroller General of the United States or the ?Internal Control Integrated Framework?, issued by the committee of the Sponsoring Organizations of the Treadway Commission (COSO). USDE?s Office of Special Education and Rehabilitative Services Policy Directive RSA-PD-15-05, states: The Office of Management and Budget (OMB) requires that grantees use the SF-425 to report financial data for grant awards. RSA uses the SF-425 data to monitor the financial status of the VR program and to assess grantee compliance with the fiscal requirements contained in the Rehabilitation Act of 1973 (Rehabilitation Act). 34 CFR Section 361.40, Reports; Evaluation standards and performance indicators, states: (a) Reports. (1) The vocational rehabilitation services portion of the Unified or Combined State Plan must assure that the designated State agency will submit reports, including reports required under sections 13, 14, and 101(a)(10) of the Act ? Finding 2019 ? 013: (continued) (i) In the form and level of detail and at the time required by the Secretary regarding applicants for and eligible individuals receiving services, including students receiving pre-employment transition services in accordance with section 361.48(a); and (ii) In a manner that provides a complete count (other than the information obtained through sampling consistent with section 101(a)(10)(E) of the Act) of the applicants and eligible individuals to ? (A) Permit the greatest possible cross-classification of data; and (B) Protect the confidentiality of the identity of each individual. (2) The designated State agency must comply with any requirements necessary to ensure the accuracy and verification of those reports. Management Directive 325.12, Standards for Internal Control for Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book), published in September 2014. The Green Book states in part: Management should design control activities to achieve objectives and respond to risks. Management should implement control activities through policies. Cause: OVR personnel indicated that a proper review of the report was not completed in a timely manner. The error occurred due to incorrect information being pulled for the report. Effect: Since the report preparation and the supervisory review and approval process were not adequate, the PETS expenditures were understated on the SF-425 final report submitted to USDE. OVR was not in compliance with federal regulations. Recommendation: OVR should ensure their written procedures for the review, approval, and submission of the SF-425 reports are improved and fully implemented. The procedures should have sufficient detail to ensure the SF-425 reports are prepared accurately and in accordance with federal regulations. In addition, OVR should correct the error and submit a revised SF-425 report to USDE. Agency Response: OVR agrees with the finding. Questioned Costs: None The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Show full finding ▾
Full finding narrative

Department of Labor and Industry Finding 2019 ? 013: CFDA #84.126 ? Rehabilitation Services ? Vocational Rehabilitation Grants to States Significant Deficiency and Noncompliance Related to the Department of Labor and Industry?s Preparation and Submission of the Semi-Annual SF-425 Report Federal Grant Number(s) and Year(s): H126A170056 (10/01/2016 ? 9/30/2017) Type of Finding: Significant Deficiency, Noncompliance Compliance Requirement: Reporting Condition: The Office of Vocational Rehabilitation (OVR), Pennsylvania Department of Labor and Industry, is required to submit an SF-425, Federal Financial Report, for the Rehabilitation Services ? Vocational Rehabilitation Grants to States (RS-VR) program to the United States Department of Education (USDE) on a semi-annual basis. The SF-425 report includes data related to the federal share of expenditures to date, the federal share of unliquidated obligations, the federal program income earned, the program income expended and unexpended, indirect charges to the grant, as well as other general information that is necessary to ensure compliance with program requirements. During the fiscal year ended June 30, 2019, we selected all four of the submitted semi-annual SF-425 reports for testing. As part of the report testing, we used the other general information to determine if the agency was in compliance with the 15 percent Pre-Employment Transition Services (PETS) earmarking requirement. Our procedures disclosed that the PETS amount reported on the final report for the 2017 RS-VR grant was understated by $141,674. The amount reported was $19,592,771, when actual PETS expenditure general ledger support reported an amount of $19,734,445. Although the SF-425 report was subjected to a documented supervisory review and approval, the understatement remained undetected by Commonwealth management until notification by the auditor. Criteria: 2 CFR Section 200.303(a), Internal controls, states: The non-Federal entity must: Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in ?Standards for Internal Control in the Federal Government? issued by the Comptroller General of the United States or the ?Internal Control Integrated Framework?, issued by the committee of the Sponsoring Organizations of the Treadway Commission (COSO). USDE?s Office of Special Education and Rehabilitative Services Policy Directive RSA-PD-15-05, states: The Office of Management and Budget (OMB) requires that grantees use the SF-425 to report financial data for grant awards. RSA uses the SF-425 data to monitor the financial status of the VR program and to assess grantee compliance with the fiscal requirements contained in the Rehabilitation Act of 1973 (Rehabilitation Act). 34 CFR Section 361.40, Reports; Evaluation standards and performance indicators, states: (a) Reports. (1) The vocational rehabilitation services portion of the Unified or Combined State Plan must assure that the designated State agency will submit reports, including reports required under sections 13, 14, and 101(a)(10) of the Act ? Finding 2019 ? 013: (continued) (i) In the form and level of detail and at the time required by the Secretary regarding applicants for and eligible individuals receiving services, including students receiving pre-employment transition services in accordance with section 361.48(a); and (ii) In a manner that provides a complete count (other than the information obtained through sampling consistent with section 101(a)(10)(E) of the Act) of the applicants and eligible individuals to ? (A) Permit the greatest possible cross-classification of data; and (B) Protect the confidentiality of the identity of each individual. (2) The designated State agency must comply with any requirements necessary to ensure the accuracy and verification of those reports. Management Directive 325.12, Standards for Internal Control for Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book), published in September 2014. The Green Book states in part: Management should design control activities to achieve objectives and respond to risks. Management should implement control activities through policies. Cause: OVR personnel indicated that a proper review of the report was not completed in a timely manner. The error occurred due to incorrect information being pulled for the report. Effect: Since the report preparation and the supervisory review and approval process were not adequate, the PETS expenditures were understated on the SF-425 final report submitted to USDE. OVR was not in compliance with federal regulations. Recommendation: OVR should ensure their written procedures for the review, approval, and submission of the SF-425 reports are improved and fully implemented. The procedures should have sufficient detail to ensure the SF-425 reports are prepared accurately and in accordance with federal regulations. In addition, OVR should correct the error and submit a revised SF-425 report to USDE. Agency Response: OVR agrees with the finding. Questioned Costs: None The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Corrective Action Plan

The SF-425 review process will be detailed in instructions that require a multi-level review in both the Comptroller?s office as well as within the program office to ensure that all information is reported correctly on the report. A checklist was created that includes all internal order numbers that were in use for the specific grant and indicates which portion of the grant the expenditures are to be reported under. The instructions will provide details as to where the information contained within the report can be located within SAP reports. A revised SF-425 report will be submitted to by the end of April 2020 to correct all misstatements. Anticipated Completion Date: 04/30/2020 Contact Person: Nichole Nedinsky, Division Chief, Financial Management & Administrative Services

About Reporting →
2019-014
Other
REPEAT

As part of testing internal controls over major programs, we performed certain tests of information technology (IT) general controls, including procedures to determine the status of prior year Single Audit Finding 2018 ? 017. Our procedures disclosed the following control deficiencies in applications administered by the Office of Administration, Office for Information Technology (OA-OIT): 1. There was a lack of segregation of duties between application development and promotion of code to production in certain applications. Individuals who developed code were granted administrative access with the ability to promote code to production. 2. There were large numbers of users with administrative access to production servers where computer applications supporting major programs resided. There was no documented monitoring of the use of elevated access. 3. In one application, access for several users with administrative rights was not revoked timely after the users separated employment. Control deficiencies in IT general controls were identified in the following major programs: Child Nutrition Cluster, Child and Adult Care Food Program, Food Distribution Cluster, Community Development Block Grants ? State?s Program, Crime Victim Assistance, Title I Grants to Local Educational Agencies, Special Education Cluster (IDEA), and Supporting Effective Instruction State Grants. Finding 2019 ? 014: (continued) Further, we also performed certain tests of IT general controls as part of our audit of the Comprehensive Annual Financial Report, which included tests of applications supporting activities material to the Commonwealth?s financial statements. Basic Financial Statement Finding 2019 ? 001, which was reported for the Commonwealth for the fiscal year ended June 30, 2019, disclosed IT general control deficiencies in applications supporting the following major programs: Child Nutrition Cluster, Child and Adult Care Food Program, Highway Planning and Construction Cluster, Title I Grants to Local Educational Agencies, Special Education Cluster (IDEA), and Supporting Effective Instruction State Grants. A detailed schedule of issues has been provided to OA-OIT for corrective action. Criteria: Management Directive 325.12, Standards for Internal Control for Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book), published in September 2014. ? Green Book Principle 11 ? Design Activities for the Information System, states in part: o 11.04 Management designs the entity?s information system and the use of information technology? Additionally, information technology may enhance internal control over security and confidentiality of information by appropriately restricting access. o 11.12 Management designs control activities over access to protect an entity from inappropriate access and unauthorized use of the system. These control activities support appropriate segregation of duties. By preventing unauthorized use of and changes to the system, data and program integrity are protected from malicious intent (e.g., someone breaking into the technology to commit fraud, vandalism, or terrorism) or error. o 11.14 Management designs control activities to limit user access to information technology through authorization control activities such as providing a unique user identification or token to authorized users. These control activities may restrict authorized users to the applications or functions commensurate with their assigned responsibilities, supporting an appropriate segregation of duties. Management designs other control activities to promptly update access rights when employees change job functions or leave the entity. A well-designed system of internal controls dictates that effective general computer controls, which include adequate segregation of duties, access controls to programs and data, appropriate monitoring, and controls to update access rights, be established and functioning to ensure that overall agency operations are conducted in accordance with management?s intent. Cause: In 2017 most Commonwealth IT services were consolidated into six delivery centers within OA-OIT. Management within certain delivery centers has addressed some of the general computer control deficiencies noted in prior years. However, due to system limitations, upgrade needs, or limited staffing, some of the deficiencies persist. Further, movement of agency applications to virtual servers at a shared location caused an increase in the number of users with administrative access to certain applications. No solutions have been implemented, such as a privileged user management system, to perform documented monitoring of the use of the privileged accounts. However, OA-OIT plans to implement an automated process to remove inactive accounts which they believe may reduce the number of administrators on the servers. As for timely removal of users, the control system designed to notify system administrators of user terminations or transfers did not operate effectively in that administrative rights to the local server were not removed. Finally, system administrators did not perform periodic access reviews of privileged users which would have identified the users who no longer required access to the servers due to separation or transfer. Effect: The deficiencies noted above in IT general controls could result in unauthorized changes to the software and noncompliance with federal laws and regulations. Segregation of duties weaknesses, inappropriate and unmonitored privileged access, as well as untimely deletion of separated employees? access, all contribute to the risk that system actions can occur that are not in accordance with management?s intent. Further, large numbers of accounts with administrative Finding 2019 ? 014: (continued) access whose use is not monitored increases the risk that accounts could be misused, either intentionally or unintentionally by authorized users, or by unauthorized external entities that have compromised the accounts. Finally, without properly functioning controls over segregation of duties, privileged access, and terminated users, the auditors are precluded from reliance on computer controls in these agencies. Recommendation: We recommend that OA-OIT continue its efforts to resolve the general computer control deficiencies noted above. Specific consideration should be given to: ? Segregating the development of programs from promotion to the production environment; ? Preventing developers from having access to the production environment and administrative rights; ? Reducing, where possible, the number of users with privileged and administrative access to servers, databases, and applications based on the principle of least privilege; ? Developing policies to govern the granting of privileged/administrative access; ? Monitoring of the use of privileged accounts and/or implementing privileged access management systems to control the use of privileged/administrative accounts and facilitate logging and monitoring of their use; ? Implementing the planned system to remove access from inactive accounts; ? Designing controls to notify systems administrators to allow for prompt removal of access rights when users separate employment, change duties, or no longer require access; and ? Instituting policies requiring periodic access reviews of all privileged users to ensure all user accounts are appropriate and current. Agency Response: OA-OIT agrees with the finding. Questioned Costs: None The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Show full finding ▾
Full finding narrative

Office of Administration ? Office for Information Technology Finding 2019 ? 014: CFDA #10.553, 10.555, 10.556, and 10.559 ? Child Nutrition Cluster CFDA #10.558 ? Child and Adult Care Food Program CFDA #10.565, 10.568, and 10.569 ? Food Distribution Cluster CFDA #14.228 ? Community Development Block Grants ? State?s Program CFDA #16.575 ? Crime Victim Assistance CFDA #20.205 and 20.219 ? Highway Planning and Construction Cluster CFDA #84.010 ? Title I Grants to Local Educational Agencies CFDA #84.027 and 84.173 ? Special Education Cluster (IDEA) CFDA #84.367 ? Supporting Effective Instruction State Grants Information Technology General Controls Need Improvement (A Similar Condition Was Noted in Prior Year Finding 2018-017) Federal Grant Number(s) and Year(s): 2019-1PA300305 (10/01/2018 ? 9/30/2019), 2018-1PA300305 (10/01/2017 ? 9/30/2018), 181PA825Y800 (10/01/2017 ? 9/30/2018), 191PA825Y8005 (10/01/2018 ? 9/30/2019), 181PA825Y8105 (10/01/2017 ? 9/30/2018), 191PA825Y8105 (10/01/2018 ? 9/30/2019), B-08-DN-42-0001 (12/29/2008 until expensed), B-12-DT-42-0001 (9/03/2011 until expensed), B-13-DC-42-0001 (1/01/2013 ? 12/31/2020), B-14-DC-42-0001 (1/01/2014 ? 9/30/2021), B-15-DC-42-0001 (1/02/2015 ? 9/30/2022), B-16-DC-42-0001 (1/02/2016 ? 9/30/2023), B-17-DC-42-0001 (1/02/2017 ? 9/30/2024), B-18-DC-42-0001 (1/01/2018 ? 9/30/2025), 2015-VA-GX-0037 (10/01/2014 ? 9/30/2018), 2016-VA-GX-0048 (10/01/2015 ? 9/30/2019), 2017-VA-GX-0069 (10/01/2016 ? 9/30/2020), 2018-VA-GX-0068 (10/01/2017 ? 9/30/2021), N78000 (7/01/2018 ? 6/30/2019), S010A160038 (7/01/2016 ? 12/30/2018), S010A170038 (7/01/2017 ? 12/30/2019), S010A180038 (7/01/2018 ? 12/30/2020), H027A170093 (9/01/2017 ? 9/30/2019), H027A180093 (9/01/2018 ? 9/30/2019), H027A190093 (7/01/2018 ? 9/30/2020), H173A170090 (7/01/2017 ? 9/30/2019), H173A180090 (7/01/2018 ? 9/30/2020), S367A180051 (7/01/2018 ? 9/30/2020), S367A160051 (7/01/2016 ? 12/30/2018), S367A170051 (7/01/2017 ? 12/30/2019), S367B160033 (7/01/2016 ? 12/30/2018) Type of Finding: Significant Deficiency Compliance Requirement: Other Condition: As part of testing internal controls over major programs, we performed certain tests of information technology (IT) general controls, including procedures to determine the status of prior year Single Audit Finding 2018 ? 017. Our procedures disclosed the following control deficiencies in applications administered by the Office of Administration, Office for Information Technology (OA-OIT): 1. There was a lack of segregation of duties between application development and promotion of code to production in certain applications. Individuals who developed code were granted administrative access with the ability to promote code to production. 2. There were large numbers of users with administrative access to production servers where computer applications supporting major programs resided. There was no documented monitoring of the use of elevated access. 3. In one application, access for several users with administrative rights was not revoked timely after the users separated employment. Control deficiencies in IT general controls were identified in the following major programs: Child Nutrition Cluster, Child and Adult Care Food Program, Food Distribution Cluster, Community Development Block Grants ? State?s Program, Crime Victim Assistance, Title I Grants to Local Educational Agencies, Special Education Cluster (IDEA), and Supporting Effective Instruction State Grants. Finding 2019 ? 014: (continued) Further, we also performed certain tests of IT general controls as part of our audit of the Comprehensive Annual Financial Report, which included tests of applications supporting activities material to the Commonwealth?s financial statements. Basic Financial Statement Finding 2019 ? 001, which was reported for the Commonwealth for the fiscal year ended June 30, 2019, disclosed IT general control deficiencies in applications supporting the following major programs: Child Nutrition Cluster, Child and Adult Care Food Program, Highway Planning and Construction Cluster, Title I Grants to Local Educational Agencies, Special Education Cluster (IDEA), and Supporting Effective Instruction State Grants. A detailed schedule of issues has been provided to OA-OIT for corrective action. Criteria: Management Directive 325.12, Standards for Internal Control for Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book), published in September 2014. ? Green Book Principle 11 ? Design Activities for the Information System, states in part: o 11.04 Management designs the entity?s information system and the use of information technology? Additionally, information technology may enhance internal control over security and confidentiality of information by appropriately restricting access. o 11.12 Management designs control activities over access to protect an entity from inappropriate access and unauthorized use of the system. These control activities support appropriate segregation of duties. By preventing unauthorized use of and changes to the system, data and program integrity are protected from malicious intent (e.g., someone breaking into the technology to commit fraud, vandalism, or terrorism) or error. o 11.14 Management designs control activities to limit user access to information technology through authorization control activities such as providing a unique user identification or token to authorized users. These control activities may restrict authorized users to the applications or functions commensurate with their assigned responsibilities, supporting an appropriate segregation of duties. Management designs other control activities to promptly update access rights when employees change job functions or leave the entity. A well-designed system of internal controls dictates that effective general computer controls, which include adequate segregation of duties, access controls to programs and data, appropriate monitoring, and controls to update access rights, be established and functioning to ensure that overall agency operations are conducted in accordance with management?s intent. Cause: In 2017 most Commonwealth IT services were consolidated into six delivery centers within OA-OIT. Management within certain delivery centers has addressed some of the general computer control deficiencies noted in prior years. However, due to system limitations, upgrade needs, or limited staffing, some of the deficiencies persist. Further, movement of agency applications to virtual servers at a shared location caused an increase in the number of users with administrative access to certain applications. No solutions have been implemented, such as a privileged user management system, to perform documented monitoring of the use of the privileged accounts. However, OA-OIT plans to implement an automated process to remove inactive accounts which they believe may reduce the number of administrators on the servers. As for timely removal of users, the control system designed to notify system administrators of user terminations or transfers did not operate effectively in that administrative rights to the local server were not removed. Finally, system administrators did not perform periodic access reviews of privileged users which would have identified the users who no longer required access to the servers due to separation or transfer. Effect: The deficiencies noted above in IT general controls could result in unauthorized changes to the software and noncompliance with federal laws and regulations. Segregation of duties weaknesses, inappropriate and unmonitored privileged access, as well as untimely deletion of separated employees? access, all contribute to the risk that system actions can occur that are not in accordance with management?s intent. Further, large numbers of accounts with administrative Finding 2019 ? 014: (continued) access whose use is not monitored increases the risk that accounts could be misused, either intentionally or unintentionally by authorized users, or by unauthorized external entities that have compromised the accounts. Finally, without properly functioning controls over segregation of duties, privileged access, and terminated users, the auditors are precluded from reliance on computer controls in these agencies. Recommendation: We recommend that OA-OIT continue its efforts to resolve the general computer control deficiencies noted above. Specific consideration should be given to: ? Segregating the development of programs from promotion to the production environment; ? Preventing developers from having access to the production environment and administrative rights; ? Reducing, where possible, the number of users with privileged and administrative access to servers, databases, and applications based on the principle of least privilege; ? Developing policies to govern the granting of privileged/administrative access; ? Monitoring of the use of privileged accounts and/or implementing privileged access management systems to control the use of privileged/administrative accounts and facilitate logging and monitoring of their use; ? Implementing the planned system to remove access from inactive accounts; ? Designing controls to notify systems administrators to allow for prompt removal of access rights when users separate employment, change duties, or no longer require access; and ? Instituting policies requiring periodic access reviews of all privileged users to ensure all user accounts are appropriate and current. Agency Response: OA-OIT agrees with the finding. Questioned Costs: None The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Corrective Action Plan

1. Remove write access from developers and have database administrators be the only staff with write access to databases. Developers can retain read access for troubleshooting and debugging. Anticipated Completion Date: 12/31/2020 Contact Person: Dustin Rhoads, CIO, Public Safety Delivery Center 2. OA-OIT EISO has implemented special accounts to use as a temporary stop gap until a system solution can be procured and implemented. Anticipated Completion Date: 12/31/2020 Contact Person: Frank Morrow, Program Manager, EISO 3. OA-OIT is in the process of implementing automated controls that will automatically notify the account holders? supervisor after a set number of days and will then revoke the account access after a set number of days from that notification if no action taken. Anticipated Completion Date: 06/30/2020 Contact Person: Kevin Mace, Computer Service Delivery Manager

Prior Finding References

2018-017

About Other →
2019-015
Period of Performance
MATERIAL WEAKNESSQUESTIONED COSTS

The Department of Human Services operates the Foster Care program and the Adoption Assistance program which are funded by the United States Department of Health and Human Services. Our audit of the Foster Care program and the Adoption Assistance program included procedures to evaluate compliance with period of performance requirements for both programs? federal fiscal year 2018 grant awards that closed during the fiscal year ended June 30, 2019. Our procedures disclosed that expenditures totaling $4.4 million and $20.3 million were charged to the 2018 Foster Care and Adoption Assistance grants, respectively, after the grant periods closed on September 30, 2018. While we historically note minor adjustments to the expenditures to adjust estimated cost allocated expenditures to actual during October, expenditures were charged to the 2018 grants through May 31, 2019, or for eight months after the end of the grant period of September 30, 2018. Foster Care and Adoption Assistance expenditures reported on the Schedule of Expenditures of Federal Awards for the fiscal year ended June 30, 2019 totaled $223.4 million and $124.3 million, respectively. Criteria: 45 CFR Section 75.303(a), Internal controls, states: The non-Federal entity must: Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in ?Standards for Internal Control in the Federal Government? issued by the Comptroller General of the United States or the ?Internal Control Integrated Framework?, issued by the committee of the Sponsoring Organizations of the Treadway Commission (COSO). 45 CFR Section 75.309, Period of performance, states: A non-Federal entity may charge to the Federal award only allowable costs incurred during the period of performance (except as described in ?75.461 Publication and printing costs) and any costs incurred before the HHS awarding agency or pass-through entity made the Federal award that were authorized by the Federal awarding agency or pass-through entity. Management Directive 325.12, Standards for Internal Control for Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book), published in September 2014. The Green Book states in part: Finding 2019 ? 015: (continued) Management should design control activities to achieve objectives and respond to risks. Management should implement control activities through policies. Cause: The Commonwealth?s Office of Comptroller Operations (OCO) personnel indicated that they did not close the internal order numbers on the SAP accounting system at the end of the grant period for the 2018 grants. As a result, expenditures continued to be charged to the 2018 grants after the end of the grant period. Effect: The OCO?s internal control procedures were not operating effectively to ensure expenditures charged were within the period of performance. As a result, $4.4 million of Foster Care expenditures and $20.3 million of Adoption Assistance expenditures were improperly charged to the respective programs? 2018 grants after the end of the grant period. Recommendation: We recommend that the OCO strengthen procedures to ensure that expenditures are incurred and charged to the correct grants within the proper period of performance. Agency Response: OCO agrees with the finding. Questioned Costs: The amount of questioned costs cannot be determined. The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Show full finding ▾
Full finding narrative

Office of the Budget ? Office of Comptroller Operations Finding 2019 ? 015: CFDA #93.658 ? Foster Care ? Title IV-E CFDA #93.659 ? Adoption Assistance Control Weaknesses and Noncompliance Exist in Foster Care and Adoption Assistance Related to Period of Performance Requirements Federal Grant Number(s) and Year(s): 1801PAFOST (10/01/2017 ? 9/30/2018), 1801PAADPT (10/01/2017 ? 9/30/2018) Type of Finding: Significant Deficiency, Noncompliance for Foster Care Material Weakness, Material Noncompliance for Adoption Assistance Compliance Requirement: Period of Performance Condition: The Department of Human Services operates the Foster Care program and the Adoption Assistance program which are funded by the United States Department of Health and Human Services. Our audit of the Foster Care program and the Adoption Assistance program included procedures to evaluate compliance with period of performance requirements for both programs? federal fiscal year 2018 grant awards that closed during the fiscal year ended June 30, 2019. Our procedures disclosed that expenditures totaling $4.4 million and $20.3 million were charged to the 2018 Foster Care and Adoption Assistance grants, respectively, after the grant periods closed on September 30, 2018. While we historically note minor adjustments to the expenditures to adjust estimated cost allocated expenditures to actual during October, expenditures were charged to the 2018 grants through May 31, 2019, or for eight months after the end of the grant period of September 30, 2018. Foster Care and Adoption Assistance expenditures reported on the Schedule of Expenditures of Federal Awards for the fiscal year ended June 30, 2019 totaled $223.4 million and $124.3 million, respectively. Criteria: 45 CFR Section 75.303(a), Internal controls, states: The non-Federal entity must: Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in ?Standards for Internal Control in the Federal Government? issued by the Comptroller General of the United States or the ?Internal Control Integrated Framework?, issued by the committee of the Sponsoring Organizations of the Treadway Commission (COSO). 45 CFR Section 75.309, Period of performance, states: A non-Federal entity may charge to the Federal award only allowable costs incurred during the period of performance (except as described in ?75.461 Publication and printing costs) and any costs incurred before the HHS awarding agency or pass-through entity made the Federal award that were authorized by the Federal awarding agency or pass-through entity. Management Directive 325.12, Standards for Internal Control for Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book), published in September 2014. The Green Book states in part: Finding 2019 ? 015: (continued) Management should design control activities to achieve objectives and respond to risks. Management should implement control activities through policies. Cause: The Commonwealth?s Office of Comptroller Operations (OCO) personnel indicated that they did not close the internal order numbers on the SAP accounting system at the end of the grant period for the 2018 grants. As a result, expenditures continued to be charged to the 2018 grants after the end of the grant period. Effect: The OCO?s internal control procedures were not operating effectively to ensure expenditures charged were within the period of performance. As a result, $4.4 million of Foster Care expenditures and $20.3 million of Adoption Assistance expenditures were improperly charged to the respective programs? 2018 grants after the end of the grant period. Recommendation: We recommend that the OCO strengthen procedures to ensure that expenditures are incurred and charged to the correct grants within the proper period of performance. Agency Response: OCO agrees with the finding. Questioned Costs: The amount of questioned costs cannot be determined. The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Corrective Action Plan

1. The amounts that were posted in Foster Care (FC) Federal Fiscal Year (FFY) 18 and Adoption Assistance (AA) FFY18 after the close of the FFY i.e., September 30, 2018 have been transferred to FC FFY19 and AA FFY19 through SAP adjustments. The FFY18 FC and AA internal orders (IOs) were closed upon completion of SAP adjustments. 2. OCO has created a FFY checklist that includes a step to close the prior FFY IOs and open the new FFY IOs effective on close of business September 30th. In the future, the checklist and manager review will serve as the controls to ensure the FC and AA IOs are closed in SAP immediately after the close of FFY. This will prevent expenditure postings in the new FFY using prior FFY IOs, except for cost allocations and any other adjusting entries that are necessary to accurately complete federal financial reporting. 3. As a further validation step, the OCO Department of Human Services General Accounting team is maintaining a federal financial report tracking schedule. This tracking sheet contains all the grants, reporting frequency, reporting system, and due dates. The tracking sheet is routinely monitored by the manager to ensure timely submission of reports. Upon submission of the final federal financial report to the manager, staff will inform the manager via email that all IOs have been closed. The manager will review and certify the final report. Anticipated Completion Date: 1. Completed; 2. Completed; 3. 10/31/2020 Contact Person: Tammy S. Miller, Administrative Officer 4

About Period of Performance →
2019-016
Reporting
MATERIAL WEAKNESS

The Pennsylvania Department of Human Services (DHS) is required to submit the Title IV-E Programs Quarterly Financial Report (CB-496 Report) to the United States Department of Health and Human Services (HHS). Part 1 of the CB-496 Report includes expenditures and estimates, with Foster Care expenditures and estimates reported in Section A, and Adoption Assistance expenditures and estimates reported in Section B. Part 2 of the CB-496 Report includes prior quarter expenditure adjustments for both programs, and Part 3 includes Demonstration Project expenditures applicable to Foster Care only, since there are no demonstration projects within the Adoption Assistance program. During the fiscal year ended June 30, 2019 audit period, we selected and tested two of the four quarterly CB-496 Reports for the Foster Care and Adoption Assistance programs, and we reconciled all four quarterly reports for each program to the respective Schedule of Expenditures of Federal Awards (SEFA) amounts. Our procedures disclosed that the CB-496 Report expenditures for both Foster Care and Adoption Assistance were understated for the period ended June 30, 2019 as follows: See Schedule of Findings and Questioned Costs for chart/table. In addition, within Part 3 of the CB-496 Report for Foster Care, we noted that cumulative Demonstration Project expenditures were improperly reported as of June 30, 2019 as follows: See Schedule of Findings and Questioned Costs for chart/table. Finding 2019 ? 016: (continued) Although the CB-496 Reports were subjected to a documented supervisory review and approval, the misstatements identified above were not detected prior to the submission of the quarterly reports to HHS. This indicates that the preparation and the supervisory review and approval processes were not adequate. Criteria: 45 CFR Section 75.302, Financial management and standards for financial management systems, states: (b) The financial management system of each non-Federal entity must provide for the following: (2) Accurate, current, and complete disclosure of the financial results of each Federal award or program in accordance with the reporting requirements set forth in ?75.341 and 75.342. 45 CFR Section 201.5(a), Grant requirements, states: (3) The State agency must also submit a quarterly statement of expenditures for each of the public assistance programs under the Act. Further, adequate internal controls over report preparation would include detailed written report preparation procedures, a segregation of duties between the preparation and the review and approval of the report, and an adequate review and approval process which would detect errors in the report preparation and ensure that such errors are corrected on a timely basis. Management Directive 325.12, Standards for Internal Control for Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book), published in September 2014. The Green Book states in part: Management should design control activities to achieve objectives and respond to risks. Management should externally communicate the necessary quality information to achieve the entity?s objectives. Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: The Commonwealth?s Office of Comptroller Operations (OCO) personnel indicated that they did not close the internal order numbers on the SAP accounting system at the end of the grant period for the 2018 Foster Care and Adoption Assistance grants. As a result, expenditures continued to be charged to the 2018 grants after the end of the grant period. When OCO personnel prepared the CB-496 Reports, the internal order numbers for the 2018 grants were not included within the expenditure calculations. OCO personnel indicated that the variances noted within the cumulative Demonstration Project expenditures for Foster Care were due to a calculation error. Effect: Since the CB-496 Report preparation and the supervisory review and approval processes were not adequate, the expenditure amounts were materially misstated on the CB-496 Reports for the fiscal year ended June 30, 2019. In addition, DHS was not in compliance with federal reporting regulations. Recommendation: OCO personnel should strengthen their existing procedures for the preparation, review, and approval of the CB-496 Reports to ensure expenditures are properly calculated and reported to HHS. In addition, OCO should consider submitting revised CB-496 Reports to HHS to reflect the actual expenditures incurred during the fiscal year ended June 30, 2019. Finding 2019 ? 016: (continued) Agency Response: OCO agrees with the finding. Questioned Costs: None The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Show full finding ▾
Full finding narrative

Office of the Budget ? Office of Comptroller Operations Finding 2019 ? 016: CFDA #93.658 ? Foster Care ? Title IV-E CFDA #93.659 ? Adoption Assistance Control Weaknesses and Noncompliance Exist Over the Preparation and Submission of the Quarterly CB-496 Reports Federal Grant Number(s) and Year(s): 1801PAFOST (10/01/2017 ? 9/30/2018), 1801PAADPT (10/01/2017 ?9/30/2018) Type of Finding: Significant Deficiency, Noncompliance for Foster Care Material Weakness, Material Noncompliance for Adoption Assistance Compliance Requirement: Reporting Condition: The Pennsylvania Department of Human Services (DHS) is required to submit the Title IV-E Programs Quarterly Financial Report (CB-496 Report) to the United States Department of Health and Human Services (HHS). Part 1 of the CB-496 Report includes expenditures and estimates, with Foster Care expenditures and estimates reported in Section A, and Adoption Assistance expenditures and estimates reported in Section B. Part 2 of the CB-496 Report includes prior quarter expenditure adjustments for both programs, and Part 3 includes Demonstration Project expenditures applicable to Foster Care only, since there are no demonstration projects within the Adoption Assistance program. During the fiscal year ended June 30, 2019 audit period, we selected and tested two of the four quarterly CB-496 Reports for the Foster Care and Adoption Assistance programs, and we reconciled all four quarterly reports for each program to the respective Schedule of Expenditures of Federal Awards (SEFA) amounts. Our procedures disclosed that the CB-496 Report expenditures for both Foster Care and Adoption Assistance were understated for the period ended June 30, 2019 as follows: See Schedule of Findings and Questioned Costs for chart/table. In addition, within Part 3 of the CB-496 Report for Foster Care, we noted that cumulative Demonstration Project expenditures were improperly reported as of June 30, 2019 as follows: See Schedule of Findings and Questioned Costs for chart/table. Finding 2019 ? 016: (continued) Although the CB-496 Reports were subjected to a documented supervisory review and approval, the misstatements identified above were not detected prior to the submission of the quarterly reports to HHS. This indicates that the preparation and the supervisory review and approval processes were not adequate. Criteria: 45 CFR Section 75.302, Financial management and standards for financial management systems, states: (b) The financial management system of each non-Federal entity must provide for the following: (2) Accurate, current, and complete disclosure of the financial results of each Federal award or program in accordance with the reporting requirements set forth in ?75.341 and 75.342. 45 CFR Section 201.5(a), Grant requirements, states: (3) The State agency must also submit a quarterly statement of expenditures for each of the public assistance programs under the Act. Further, adequate internal controls over report preparation would include detailed written report preparation procedures, a segregation of duties between the preparation and the review and approval of the report, and an adequate review and approval process which would detect errors in the report preparation and ensure that such errors are corrected on a timely basis. Management Directive 325.12, Standards for Internal Control for Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book), published in September 2014. The Green Book states in part: Management should design control activities to achieve objectives and respond to risks. Management should externally communicate the necessary quality information to achieve the entity?s objectives. Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: The Commonwealth?s Office of Comptroller Operations (OCO) personnel indicated that they did not close the internal order numbers on the SAP accounting system at the end of the grant period for the 2018 Foster Care and Adoption Assistance grants. As a result, expenditures continued to be charged to the 2018 grants after the end of the grant period. When OCO personnel prepared the CB-496 Reports, the internal order numbers for the 2018 grants were not included within the expenditure calculations. OCO personnel indicated that the variances noted within the cumulative Demonstration Project expenditures for Foster Care were due to a calculation error. Effect: Since the CB-496 Report preparation and the supervisory review and approval processes were not adequate, the expenditure amounts were materially misstated on the CB-496 Reports for the fiscal year ended June 30, 2019. In addition, DHS was not in compliance with federal reporting regulations. Recommendation: OCO personnel should strengthen their existing procedures for the preparation, review, and approval of the CB-496 Reports to ensure expenditures are properly calculated and reported to HHS. In addition, OCO should consider submitting revised CB-496 Reports to HHS to reflect the actual expenditures incurred during the fiscal year ended June 30, 2019. Finding 2019 ? 016: (continued) Agency Response: OCO agrees with the finding. Questioned Costs: None The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Corrective Action Plan

1. The amounts that were posted in Foster Care (FC) Federal Fiscal Year (FFY) 18 and Adoption Assistance (AA) FFY18 after the close of the FFY i.e., September 30, 2018 have been transferred to FC FFY19 and AA FFY19 through SAP adjustments. The FFY18 FC and AA internal orders (IOs) were closed upon completion of SAP adjustments. 2. OCO has created a FFY checklist that includes a step to close the prior FFY IOs and open the new FFY IOs effective on close of business September 30th. In the future, the checklist and manager review will serve as the controls to ensure the FC and AA IOs are closed in SAP immediately after the close of FFY. This will prevent expenditure postings in the new FFY using prior FFY IOs, except for cost allocations and any other adjusting entries that are necessary to accurately complete federal financial reporting. 3. As a further validation step, the OCO Department of Human Services General Accounting team is maintaining a federal financial report tracking schedule. This tracking sheet contains all the grants, reporting frequency, reporting system, and due dates. The tracking sheet is routinely monitored by the manager to ensure timely submission of reports. Upon submission of the final federal financial report to the manager, staff will inform the manager via email that all IOs have been closed. The manager will review and certify the final report. 4. The difference between the CB-496 and actual expenses will be reported in the next quarterly report submission. Prior reports can only be corrected within 90 days after submission. 5. OCO has created a reconciliation report to keep track of any differences between the actual expense for the period and the amounts reported on the CB-496 report. In the future, the reconciliation report and manager review will serve as the controls to ensure the FC and AA expenses are correctly reported. This will prevent reporting an overstatement or understatement of expenditures in the CB-496 report. Anticipated Completion Date: 1. Completed; 2. Completed; 3. 10/31/2020; 4. 04/30/2020; 5. Completed Contact Person: Tammy S. Miller, Administrative Officer 4

About Reporting →
2019-017
Period of Performance
QUESTIONED COSTS

During our audit of the Crime Victim Assistance (CVA) program funded by the United States Department of Justice, we evaluated and tested the Pennsylvania Commission on Crime and Delinquency?s (PCCD) internal control and compliance with period of performance requirements for the grant award that closed during the fiscal year ended June 30, 2019. Our procedures disclosed that expenditures totaling $2,500 for peer review services rendered by two subcontractors as part of the grant application review process in October 2018 were erroneously charged to the CVA grant after the grant period closed on September 30, 2018. Our review of the invoices supporting the $2,500 disclosed an additional $225 which was charged to the grant and lacked adequate documentation to support the period of performance. CVA expenditures reported on the Schedule of Expenditures of Federal Awards for the fiscal year ended June 30, 2019 totaled $56.6 million. Criteria: 2 CFR Section 200.303(a), Internal controls, states: The non-Federal entity must: Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in ?Standards for Internal Control in the Federal Government? issued by the Comptroller General of the United States or the ?Internal Control Integrated Framework?, issued by the committee of the Sponsoring Organizations of the Treadway Commission (COSO). 2 CFR Section 200.309, Period of performance, states: A non-Federal entity may charge to the Federal award only allowable costs incurred during the period of performance (except as described in ?200.461 Publication and printing costs) and any costs incurred before the Federal awarding agency or pass-through entity made the Federal award that were authorized by the Federal awarding agency or pass-through entity. Management Directive 325.12, Standards for Internal Control for Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book), published in September 2014. The Green Book states in part: Management should design control activities to achieve objectives and respond to risks. Management should implement control activities through policies. Finding 2019 ? 017: (continued) Cause: PCCD personnel did not have adequate procedures in place to ensure that costs incurred were within the period of performance and did not verify that service dates were within the period of performance prior to submitting invoices for payment. Effect: Expenditures were improperly charged to the federal grant for services incurred subsequent to the period of performance without authorization by the federal awarding agency, resulting in noncompliance and questioned costs. Recommendation: We recommend that PCCD personnel implement procedures to ensure that costs are incurred and charged within the proper period of performance or to obtain prior federal authorization for any costs charged outside the period of performance. Agency Response: During the period of review, PCCD initiated a pilot project that involved the selection and utilization of paid grant reviewers in order to enhance the overall level of qualification and expertise involved in the review of competitively submitted grant applications. As part of the pilot project, controls were established that involved multiple levels of review of reviewer submitted invoices to verify that charges were appropriate and in compliance with established agreements. In determining the grant award to be used to reimburse for these costs, an assessment of the period of activity was conducted, and funding was coded to utilize the funding that would be expiring the soonest. The period that reviewers were involved exceeded the timeframe that was anticipated, and a portion of two of the twenty-two reviewers? time was mistakenly attributed to the expired grant award. We concur that $2,500 was attributed after the established period of performance, and the necessary adjustments have been made to the procedure and will be made to the final federal fiscal report based on lessons learned from this initial effort. Additionally, we agree that there was an invoice submitted that included a calculation error that resulted in a payment being made that did not reconcile. We are further reviewing whether there was eligible time spent by the reviewer that was included on the invoice but did not include a request for reimbursement. If it is determined that an overpayment of approximately $225 was made, a reimbursement will be sought. In conclusion, PCCD agrees with the facts associated with the finding that $2,725 of the $56.6 million in expenditures under this grant program are to be rectified. Questioned Costs: Known questioned costs for CFDA #16.575 of $2,725 were determined, which represent $2,500 of transactions incurred and charged subsequent to the period of performance and $225 for which the period of performance could not be determined. The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Show full finding ▾
Full finding narrative

Pennsylvania Commission on Crime and Delinquency Finding 2019 ? 017: CFDA #16.575 ? Crime Victim Assistance A Significant Deficiency and Noncompliance Exist in the Pennsylvania Commission on Crime and Delinquency?s Procedures Related to Period of Performance Requirements Federal Grant Number(s) and Year(s): 2015-VA-GX-0037 (10/01/2014 ? 9/30/2018) Type of Finding: Significant Deficiency, Noncompliance Compliance Requirement: Period of Performance Condition: During our audit of the Crime Victim Assistance (CVA) program funded by the United States Department of Justice, we evaluated and tested the Pennsylvania Commission on Crime and Delinquency?s (PCCD) internal control and compliance with period of performance requirements for the grant award that closed during the fiscal year ended June 30, 2019. Our procedures disclosed that expenditures totaling $2,500 for peer review services rendered by two subcontractors as part of the grant application review process in October 2018 were erroneously charged to the CVA grant after the grant period closed on September 30, 2018. Our review of the invoices supporting the $2,500 disclosed an additional $225 which was charged to the grant and lacked adequate documentation to support the period of performance. CVA expenditures reported on the Schedule of Expenditures of Federal Awards for the fiscal year ended June 30, 2019 totaled $56.6 million. Criteria: 2 CFR Section 200.303(a), Internal controls, states: The non-Federal entity must: Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in ?Standards for Internal Control in the Federal Government? issued by the Comptroller General of the United States or the ?Internal Control Integrated Framework?, issued by the committee of the Sponsoring Organizations of the Treadway Commission (COSO). 2 CFR Section 200.309, Period of performance, states: A non-Federal entity may charge to the Federal award only allowable costs incurred during the period of performance (except as described in ?200.461 Publication and printing costs) and any costs incurred before the Federal awarding agency or pass-through entity made the Federal award that were authorized by the Federal awarding agency or pass-through entity. Management Directive 325.12, Standards for Internal Control for Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book), published in September 2014. The Green Book states in part: Management should design control activities to achieve objectives and respond to risks. Management should implement control activities through policies. Finding 2019 ? 017: (continued) Cause: PCCD personnel did not have adequate procedures in place to ensure that costs incurred were within the period of performance and did not verify that service dates were within the period of performance prior to submitting invoices for payment. Effect: Expenditures were improperly charged to the federal grant for services incurred subsequent to the period of performance without authorization by the federal awarding agency, resulting in noncompliance and questioned costs. Recommendation: We recommend that PCCD personnel implement procedures to ensure that costs are incurred and charged within the proper period of performance or to obtain prior federal authorization for any costs charged outside the period of performance. Agency Response: During the period of review, PCCD initiated a pilot project that involved the selection and utilization of paid grant reviewers in order to enhance the overall level of qualification and expertise involved in the review of competitively submitted grant applications. As part of the pilot project, controls were established that involved multiple levels of review of reviewer submitted invoices to verify that charges were appropriate and in compliance with established agreements. In determining the grant award to be used to reimburse for these costs, an assessment of the period of activity was conducted, and funding was coded to utilize the funding that would be expiring the soonest. The period that reviewers were involved exceeded the timeframe that was anticipated, and a portion of two of the twenty-two reviewers? time was mistakenly attributed to the expired grant award. We concur that $2,500 was attributed after the established period of performance, and the necessary adjustments have been made to the procedure and will be made to the final federal fiscal report based on lessons learned from this initial effort. Additionally, we agree that there was an invoice submitted that included a calculation error that resulted in a payment being made that did not reconcile. We are further reviewing whether there was eligible time spent by the reviewer that was included on the invoice but did not include a request for reimbursement. If it is determined that an overpayment of approximately $225 was made, a reimbursement will be sought. In conclusion, PCCD agrees with the facts associated with the finding that $2,725 of the $56.6 million in expenditures under this grant program are to be rectified. Questioned Costs: Known questioned costs for CFDA #16.575 of $2,725 were determined, which represent $2,500 of transactions incurred and charged subsequent to the period of performance and $225 for which the period of performance could not be determined. The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Corrective Action Plan

Internal operating procedures have been revised to include additional verification that the period of performance and the lapse date of the federal award have been cross-referenced to ensure that federal grants are charged correctly. The procedure includes a multi-person review and documentation of the result confirming eligibility of the expenditures. Anticipated Completion Date: Completed Contact People: Derin Myers, Dir., OFMA; Elizabeth Romero, Mgr., Fin. Admin.

About Period of Performance →
2019-018
Subrecipient Monitoring
MATERIAL WEAKNESSQUESTIONED COSTS

During the fiscal year ended June 30, 2019, the Pennsylvania Commission on Crime and Delinquency (PCCD) paid $53.4 million in Crime Victim Assistance (CVA) program funding to subrecipients, which represented over 94 percent of the total federal CVA expenditures of $56.6 million reported on the Schedule of Expenditures of Federal Awards. United States Department of Justice (USDOJ) regulations require PCCD to conduct on-site monitoring at least once every two years on all subrecipients that receive federal funding for providing crime victim services. PCCD?s monitoring procedures specify tracking subrecipients that received federal funds on a calendar year basis and require on-site monitoring of subrecipients at least once every two years. Our audit identified 142 subrecipients which received federal funding during the two years ending December 31, 2018, but PCCD did not conduct the required on-site monitoring at least once during this period for 23 of these subrecipients. We tested a sample of 20 subrecipients out of the remaining 119 subrecipients which were monitored in order to evaluate the adequacy of the on-site monitoring procedures performed by PCCD. Our testing disclosed that for all 20 subrecipients selected, PCCD did not issue the on-site reports to the subrecipients within eight weeks as required by PCCD?s internal monitoring procedures. The 20 monitoring reports were issued from 97 to 578 days after the date of on-site visit, with an average of 357 days after the date of the on-site visit. Further, PCCD?s supervisory review and approval of the 20 subrecipient monitoring reports did not occur until after the on-site inspection reports were sent to the subrecipients. Criteria: 28 CFR Section 94.106, Monitoring Requirements, states: (a) Monitoring plan. Unless the Director grants a waiver, SAAs [State Administering Agencies] shall develop and implement a monitoring plan in accordance with the requirements of this section and 2 CFR 200.331. The monitoring plan must include a risk assessment plan. (b) Monitoring frequency. SAAs shall conduct regular desk monitoring of all sub-recipients. In addition, SAAs shall conduct on-site monitoring of all sub-recipients at least once every two years during the award period, unless a different frequency based on risk assessment is set out in the monitoring plan. (c) Recordkeeping. SAAs shall maintain a copy of site visit results and other documents related to compliance. 2 CFR Section 200.331, Requirements for Pass-through Entities, states in part: Pass-through entity monitoring of the subrecipient must include: (e) Depending upon the pass-through entity's assessment of risk posed by the subrecipient (as described in paragraph (b) of this section), the following monitoring tools may be useful for the pass-through entity to ensure proper accountability and compliance with program requirements and achievement of performance goals: Finding 2019 ? 018: (continued) (1) Providing subrecipients with training and technical assistance on program-related matters; and (2) Performing on-site reviews of the subrecipient's program operations; (3) Arranging for agreed-upon-procedures engagements as described in ?200.425 Audit services Management Directive 325.12, Standards for Internal Control for Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book), published in September 2014. The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: PCCD management indicated they have experienced a substantial increase in federal funding for the CVA program over the past several years which required more on-site visits. In addition, the revised federal monitoring guidelines issued in July 2016 changed the requirement for on-site visits from every four years to every two years. Effect: PCCD did not comply with federal regulations, and CVA subrecipients could be operating in noncompliance with federal regulations without timely detection and correction. A material number of subrecipients expended individually less than $750,000 in total federal awards from the Commonwealth during the fiscal year ended June 30, 2018, and as a result would not have been required to submit a Single Audit under the Uniform Guidance to the Commonwealth during the fiscal year ended June 30, 2019. Therefore, these subrecipients were only subject to on-site monitoring by the program. The timely completion of these on-site visits and issuance of the monitoring reports is vital in providing PCCD with information necessary to determine whether the program?s subrecipients are complying with federal regulations. Recommendation: PCCD should strengthen its procedures to ensure on-site monitoring of all CVA subrecipients is performed at least once every two years. PCCD should conduct the supervisory review and approval of the monitoring reports prior to issuance to subrecipients, and report issuance should occur within eight weeks after the on-site visit to allow subrecipients to implement corrective action more timely. Agency Response: PCCD acknowledges the finding during the audit period, however, PCCD has taken corrective action based on: (1) The USDOJ has approved our risked-based monitoring plan for the CVA program beginning January 1, 2020, which only requires that high-risk subrecipients be monitored every two years and lower risk subrecipients less frequently; and (2) PCCD has hired complement dedicated to the CVA program and monitoring tasks in response to the substantial increase in CVA funding and monitoring requirement changes that happened in 2016, which increased the requirement to monitor subrecipients from every four years to every two years. Auditors? Conclusion: The agency response from PCCD indicated acknowledgement of the finding. No new information was provided which would mitigate the finding. The finding remains as stated. We will evaluate any corrective action in the subsequent audit. Questioned Costs: The amount of questioned costs cannot be determined. The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Show full finding ▾
Full finding narrative

Pennsylvania Commission on Crime and Delinquency Finding 2019 ? 018: CFDA #16.575 ? Crime Victim Assistance Material Weakness and Material Noncompliance Exist in the Pennsylvania Commission on Crime and Delinquency Monitoring of Crime Victim Assistance Program Subrecipients Federal Grant Number(s) and Year(s): 2015-VA-GX-0037 (10/01/2014 ? 9/30/2018), 2016-VA-GX-0048 (10/01/2015 ? 9/30/2019), 2017-VA-GX-0069 (10/01/2016 ? 9/30/2020), 2018-VA-GX-0068 (10/01/2017 ? 9/30/2021) Type of Finding: Material Weakness, Material Noncompliance Compliance Requirement: Subrecipient Monitoring Condition: During the fiscal year ended June 30, 2019, the Pennsylvania Commission on Crime and Delinquency (PCCD) paid $53.4 million in Crime Victim Assistance (CVA) program funding to subrecipients, which represented over 94 percent of the total federal CVA expenditures of $56.6 million reported on the Schedule of Expenditures of Federal Awards. United States Department of Justice (USDOJ) regulations require PCCD to conduct on-site monitoring at least once every two years on all subrecipients that receive federal funding for providing crime victim services. PCCD?s monitoring procedures specify tracking subrecipients that received federal funds on a calendar year basis and require on-site monitoring of subrecipients at least once every two years. Our audit identified 142 subrecipients which received federal funding during the two years ending December 31, 2018, but PCCD did not conduct the required on-site monitoring at least once during this period for 23 of these subrecipients. We tested a sample of 20 subrecipients out of the remaining 119 subrecipients which were monitored in order to evaluate the adequacy of the on-site monitoring procedures performed by PCCD. Our testing disclosed that for all 20 subrecipients selected, PCCD did not issue the on-site reports to the subrecipients within eight weeks as required by PCCD?s internal monitoring procedures. The 20 monitoring reports were issued from 97 to 578 days after the date of on-site visit, with an average of 357 days after the date of the on-site visit. Further, PCCD?s supervisory review and approval of the 20 subrecipient monitoring reports did not occur until after the on-site inspection reports were sent to the subrecipients. Criteria: 28 CFR Section 94.106, Monitoring Requirements, states: (a) Monitoring plan. Unless the Director grants a waiver, SAAs [State Administering Agencies] shall develop and implement a monitoring plan in accordance with the requirements of this section and 2 CFR 200.331. The monitoring plan must include a risk assessment plan. (b) Monitoring frequency. SAAs shall conduct regular desk monitoring of all sub-recipients. In addition, SAAs shall conduct on-site monitoring of all sub-recipients at least once every two years during the award period, unless a different frequency based on risk assessment is set out in the monitoring plan. (c) Recordkeeping. SAAs shall maintain a copy of site visit results and other documents related to compliance. 2 CFR Section 200.331, Requirements for Pass-through Entities, states in part: Pass-through entity monitoring of the subrecipient must include: (e) Depending upon the pass-through entity's assessment of risk posed by the subrecipient (as described in paragraph (b) of this section), the following monitoring tools may be useful for the pass-through entity to ensure proper accountability and compliance with program requirements and achievement of performance goals: Finding 2019 ? 018: (continued) (1) Providing subrecipients with training and technical assistance on program-related matters; and (2) Performing on-site reviews of the subrecipient's program operations; (3) Arranging for agreed-upon-procedures engagements as described in ?200.425 Audit services Management Directive 325.12, Standards for Internal Control for Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book), published in September 2014. The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: PCCD management indicated they have experienced a substantial increase in federal funding for the CVA program over the past several years which required more on-site visits. In addition, the revised federal monitoring guidelines issued in July 2016 changed the requirement for on-site visits from every four years to every two years. Effect: PCCD did not comply with federal regulations, and CVA subrecipients could be operating in noncompliance with federal regulations without timely detection and correction. A material number of subrecipients expended individually less than $750,000 in total federal awards from the Commonwealth during the fiscal year ended June 30, 2018, and as a result would not have been required to submit a Single Audit under the Uniform Guidance to the Commonwealth during the fiscal year ended June 30, 2019. Therefore, these subrecipients were only subject to on-site monitoring by the program. The timely completion of these on-site visits and issuance of the monitoring reports is vital in providing PCCD with information necessary to determine whether the program?s subrecipients are complying with federal regulations. Recommendation: PCCD should strengthen its procedures to ensure on-site monitoring of all CVA subrecipients is performed at least once every two years. PCCD should conduct the supervisory review and approval of the monitoring reports prior to issuance to subrecipients, and report issuance should occur within eight weeks after the on-site visit to allow subrecipients to implement corrective action more timely. Agency Response: PCCD acknowledges the finding during the audit period, however, PCCD has taken corrective action based on: (1) The USDOJ has approved our risked-based monitoring plan for the CVA program beginning January 1, 2020, which only requires that high-risk subrecipients be monitored every two years and lower risk subrecipients less frequently; and (2) PCCD has hired complement dedicated to the CVA program and monitoring tasks in response to the substantial increase in CVA funding and monitoring requirement changes that happened in 2016, which increased the requirement to monitor subrecipients from every four years to every two years. Auditors? Conclusion: The agency response from PCCD indicated acknowledgement of the finding. No new information was provided which would mitigate the finding. The finding remains as stated. We will evaluate any corrective action in the subsequent audit. Questioned Costs: The amount of questioned costs cannot be determined. The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Corrective Action Plan

1. As part of the Victims of Crime Act (VOCA) Federal Guidelines of 2016, State Administering Agencies (SAA) of VOCA funding must conduct on-site monitoring of all subrecipients at least every two years, unless a different frequency, based on a risk assessment, is set out in a monitoring plan. PCCD submitted a risk-based monitoring plan to the federal Office of Victims of Crime in 2018 which was subsequently approved in 2019 and is being implemented with the 2020 monitoring schedule. The approved monitoring plan is based on a scored risk assessment that determines the appropriate financial and programmatic monitoring, including the frequency of on-site visits. The results of risk-based monitoring plan will help guide PCCD to make the appropriate financial and programmatic monitoring schedules for each organization. The results of the scored risk assessment will determine the agency?s risk level of either high, medium or low risk. ? Newly funded and high-risk agencies will have an on-site monitoring visit every 2 years. ? Medium-risk agencies will have an on-site monitoring visit every 3 years. ? Low-risk agencies will have an on-site monitoring visit every 4 years. 2. PCCD has increased staffing to specifically address the increased monitoring workload that resulted from the quadrupling of VOCA funds. This increase in staff has enabled PCCD to address the increased volume of work by allowing for a more reasonable assignment of duties to staff members, including the number of on-site monitoring visits that each staff member will need to conduct annually. 3. All existing staff within the Office of Victim Services (OVS) will receive updated training on monitoring activities in 2020, to include the PCCD policy on monitoring deadlines. Newly hired staff will receive training on monitoring within three (3) months of hire. Anticipated Completion Date: 1. Completed; 2. Completed; 3. 06/01/2020 Contact People: Kathleen Buckley, Director, Office of Victim Services; Jeffrey Blystone, Deputy Director, Office of Victim Services

About Subrecipient Monitoring →
2019-019
Subrecipient Monitoring
REPEATQUESTIONED COSTS

The Uniform Guidance in 2 CFR Section 200 applies to the major programs listed above for the fiscal year ended June 30, 2019. Our testing disclosed that the state agencies did not identify the federal award information and applicable requirements in subrecipient award documents. Additionally, the state agencies did not evaluate each subrecipient?s risk of noncompliance for the purpose of determining the appropriate subrecipient monitoring related to the subaward. This represents an internal control weakness which causes subrecipients to be improperly informed of federal award information and not adequately monitored by the state agencies. Also, it could cause the omission or improper identification of program expenditures on subrecipients? Schedules of Expenditures of Federal Awards (SEFAs). The following chart shows which federal award information required by 2 CFR Section 200 was missing or incorrect (as indicated by ?No?) from the subrecipient award documents at the time of the subaward and which major programs did not have a state agency evaluation of each subrecipient?s risk of noncompliance. Finding 2019 ? 019: (continued) See Schedule of Findings and Questioned Costs for chart/table. Finding 2019 ? 019: (continued) See Schedule of Findings and Questioned Costs for chart/table. (The cells with a hyphen in the table indicate that the federal award information was included in the subrecipient award documents or was not applicable for the respective major program.) (1) Although an evaluation of subrecipient risk was conducted, the only risk factor used in the evaluation was the error rate detected for the county subrecipients. The evaluation is deemed inadequate since there was no written evidence that the risk assessment considered other risk factors, such as the risk factors identified in 2 CFR Section 200.331. (2) The incorrect federal award identification number was included in the subrecipient?s award documents for three out of 17 subrecipients tested. Finding 2019 ? 019: (continued) Criteria: 2 CFR Section 200.331, Requirements for Pass-through Entities, states in part: All pass-through entities must: (a) Ensure that every subaward is clearly identified to the subrecipient as a subaward and includes the following information at the time of the subaward and if any of these data elements change, include the changes in subsequent subaward modification. When some of this information is not available, the pass-through entity must provide the best information available to describe the Federal award and subaward. Required information includes: (1) Federal Award Identification. (iii) Federal Award Identification Number (FAIN); (iv) Federal Award Date (see section 200.39 Federal award date) of award to the recipient by the Federal agency; (v) Subaward Period of Performance Start and End Date; (x) Name of Federal awarding agency, pass-through entity, and contact information for awarding official of the pass-through entity; (xi) CFDA Number and Name; the pass-through entity must identify the dollar amount made available under each Federal award and the CFDA number at time of disbursement; (6) Appropriate terms and conditions concerning closeout of the subaward. (b) Evaluate each subrecipient?s risk of noncompliance with Federal statutes, regulations, and the terms and conditions of the subaward for purposes of determining the appropriate subrecipient monitoring described in paragraphs (d) and (e) of this section, which may include consideration of such factors as: (1) The subrecipient?s prior experience with the same or similar subawards; (2) The results of previous audits including whether or not the subrecipient receives a Single Audit in accordance with Subpart F?Audit Requirements of this part, and the extent to which the same or similar subaward has been audited as a major program; (3) Whether the subrecipient has new personnel or new or substantially changed systems; and (4) The extent and results of Federal awarding agency monitoring (e.g., if the subrecipient also receives Federal awards directly from a Federal awarding agency). Management Directive 325.12, Standards for Internal Control for Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book), published in September 2014. The Green Book states in part: Management should identify, analyze, and respond to risks related to achieving the defined objectives. Management should identify, analyze, and respond to significant changes that could impact the internal control system. Cause: In general, the state agencies? procedures for timely identifying federal requirements and implementing policies and procedures to ensure compliance need improvement. Effect: Excluding the federal grant award information at the time of the subaward may cause subrecipients and their auditors to be uninformed about specific program and other regulations that apply to the funds they receive. There is also the potential for subrecipients to have incomplete SEFAs in their Single Audit reports submitted to the Commonwealth, and federal funds may not be properly audited at the subrecipient level in accordance with the Single Audit Act and Uniform Guidance. Finding 2019 ? 019: (continued) Not evaluating each subrecipient?s risk of noncompliance for purposes of determining the appropriate subrecipient monitoring related to the subaward may result in subrecipients using the subaward for unauthorized purposes or in violation of the terms and conditions of the subaward, and state agency monitoring would not detect this noncompliance and ensure it is corrected in a timely manner. Recommendation: State agencies should develop policies and reporting mechanisms to ensure all required federal award information is disseminated to all subrecipients at the time of the subaward to ensure subrecipient compliance with the Uniform Guidance in 2 CFR Section 200 and other applicable federal regulations. In addition, state agencies should correspond with applicable subrecipients to ensure they are aware of the correct federal award information and review applicable subaward documents prior to issuance to ensure federal information is complete and accurate. State agencies should also implement procedures to adequately document their evaluation of each subrecipient?s risk of noncompliance as cited in 2 CFR Section 200.331 for purposes of determining the appropriate subrecipient monitoring related to the subaward. PennDOT Response: PennDOT agrees with the finding. PDE Response: PDE agrees with the finding. DHS Response: DHS agrees with the finding. Questioned Costs: The amount of questioned costs cannot be determined. The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Show full finding ▾
Full finding narrative

Various Agencies Finding 2019 ? 019: CFDA #20.205 and 20.219 ? Highway Planning and Construction Cluster CFDA #84.287 ? Twenty-First Century Community Learning Centers CFDA #93.558 ? Temporary Assistance for Needy Families CFDA #93.658 ? Foster Care ? Title IV-E CFDA #93.659 ? Adoption Assistance CFDA #93.667 ? Social Services Block Grant CFDA #93.959 ? Block Grants for Prevention and Treatment of Substance Abuse State Agencies Did Not Identify the Federal Award Information and Applicable Requirements at the Time of the Subaward and Did Not Evaluate Each Subrecipient?s Risk of Noncompliance as Required by the Uniform Grant Guidance (A Similar Condition Was Noted in Prior Year Finding 2018-020) Federal Grant Number(s) and Year(s): N78000 (7/01/2018 ? 6/30/2019), S287C180038 (7/01/2018 ? 12/30/2020), S287C170038 (7/01/2017 ? 12/30/2019), S287C160038 (7/01/2016 ? 12/30/2018), S287C140038 (7/01/2014 ? 12/30/2016), 1901PATANF (10/01/2018 ? 9/30/2019), 1801PATANF (10/01/2017 ? 9/30/2018), 1901PAFOST (10/01/2018 ? 9/30/2019), 1801PAFOST (10/01/2017 ? 9/30/2018), 1901PADPT (10/01/2018 ? 9/30/2019), 1801PAADPT (10/01/2017 ? 9/30/2018), 1901PASOSR (10/01/2018 ? 9/30/2019), 1801PASOSR (10/01/2017 ? 9/30/2018), 3B08TI010044-19 (10/01/2018 ? 9/30/2020), 2B08TI010044-18 (10/01/2017 ? 9/30/2019), 2B08TI010044-17 (10/01/2016 ? 9/30/2018) Type of Finding: Significant Deficiency, Noncompliance Compliance Requirement: Subrecipient Monitoring Condition: The Uniform Guidance in 2 CFR Section 200 applies to the major programs listed above for the fiscal year ended June 30, 2019. Our testing disclosed that the state agencies did not identify the federal award information and applicable requirements in subrecipient award documents. Additionally, the state agencies did not evaluate each subrecipient?s risk of noncompliance for the purpose of determining the appropriate subrecipient monitoring related to the subaward. This represents an internal control weakness which causes subrecipients to be improperly informed of federal award information and not adequately monitored by the state agencies. Also, it could cause the omission or improper identification of program expenditures on subrecipients? Schedules of Expenditures of Federal Awards (SEFAs). The following chart shows which federal award information required by 2 CFR Section 200 was missing or incorrect (as indicated by ?No?) from the subrecipient award documents at the time of the subaward and which major programs did not have a state agency evaluation of each subrecipient?s risk of noncompliance. Finding 2019 ? 019: (continued) See Schedule of Findings and Questioned Costs for chart/table. Finding 2019 ? 019: (continued) See Schedule of Findings and Questioned Costs for chart/table. (The cells with a hyphen in the table indicate that the federal award information was included in the subrecipient award documents or was not applicable for the respective major program.) (1) Although an evaluation of subrecipient risk was conducted, the only risk factor used in the evaluation was the error rate detected for the county subrecipients. The evaluation is deemed inadequate since there was no written evidence that the risk assessment considered other risk factors, such as the risk factors identified in 2 CFR Section 200.331. (2) The incorrect federal award identification number was included in the subrecipient?s award documents for three out of 17 subrecipients tested. Finding 2019 ? 019: (continued) Criteria: 2 CFR Section 200.331, Requirements for Pass-through Entities, states in part: All pass-through entities must: (a) Ensure that every subaward is clearly identified to the subrecipient as a subaward and includes the following information at the time of the subaward and if any of these data elements change, include the changes in subsequent subaward modification. When some of this information is not available, the pass-through entity must provide the best information available to describe the Federal award and subaward. Required information includes: (1) Federal Award Identification. (iii) Federal Award Identification Number (FAIN); (iv) Federal Award Date (see section 200.39 Federal award date) of award to the recipient by the Federal agency; (v) Subaward Period of Performance Start and End Date; (x) Name of Federal awarding agency, pass-through entity, and contact information for awarding official of the pass-through entity; (xi) CFDA Number and Name; the pass-through entity must identify the dollar amount made available under each Federal award and the CFDA number at time of disbursement; (6) Appropriate terms and conditions concerning closeout of the subaward. (b) Evaluate each subrecipient?s risk of noncompliance with Federal statutes, regulations, and the terms and conditions of the subaward for purposes of determining the appropriate subrecipient monitoring described in paragraphs (d) and (e) of this section, which may include consideration of such factors as: (1) The subrecipient?s prior experience with the same or similar subawards; (2) The results of previous audits including whether or not the subrecipient receives a Single Audit in accordance with Subpart F?Audit Requirements of this part, and the extent to which the same or similar subaward has been audited as a major program; (3) Whether the subrecipient has new personnel or new or substantially changed systems; and (4) The extent and results of Federal awarding agency monitoring (e.g., if the subrecipient also receives Federal awards directly from a Federal awarding agency). Management Directive 325.12, Standards for Internal Control for Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s Standards for Internal Control in the Federal Government (Green Book), published in September 2014. The Green Book states in part: Management should identify, analyze, and respond to risks related to achieving the defined objectives. Management should identify, analyze, and respond to significant changes that could impact the internal control system. Cause: In general, the state agencies? procedures for timely identifying federal requirements and implementing policies and procedures to ensure compliance need improvement. Effect: Excluding the federal grant award information at the time of the subaward may cause subrecipients and their auditors to be uninformed about specific program and other regulations that apply to the funds they receive. There is also the potential for subrecipients to have incomplete SEFAs in their Single Audit reports submitted to the Commonwealth, and federal funds may not be properly audited at the subrecipient level in accordance with the Single Audit Act and Uniform Guidance. Finding 2019 ? 019: (continued) Not evaluating each subrecipient?s risk of noncompliance for purposes of determining the appropriate subrecipient monitoring related to the subaward may result in subrecipients using the subaward for unauthorized purposes or in violation of the terms and conditions of the subaward, and state agency monitoring would not detect this noncompliance and ensure it is corrected in a timely manner. Recommendation: State agencies should develop policies and reporting mechanisms to ensure all required federal award information is disseminated to all subrecipients at the time of the subaward to ensure subrecipient compliance with the Uniform Guidance in 2 CFR Section 200 and other applicable federal regulations. In addition, state agencies should correspond with applicable subrecipients to ensure they are aware of the correct federal award information and review applicable subaward documents prior to issuance to ensure federal information is complete and accurate. State agencies should also implement procedures to adequately document their evaluation of each subrecipient?s risk of noncompliance as cited in 2 CFR Section 200.331 for purposes of determining the appropriate subrecipient monitoring related to the subaward. PennDOT Response: PennDOT agrees with the finding. PDE Response: PDE agrees with the finding. DHS Response: DHS agrees with the finding. Questioned Costs: The amount of questioned costs cannot be determined. The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Corrective Action Plan

PennDOT: PennDOT is working on updating its reimbursement agreements. PennDOT and PennDOT?s Office of Chief Counsel (OCC) will work to ensure that the federally funded templates currently in the agreement system (system) and those to be uploaded include: the CDFA number and title, the awarding official contact information and close out procedures. This will require the following steps: 1. Review all existing reimbursement agreement templates to determine what federal requirements need to be added and make the necessary updates, which will be completed by July 31, 2020. This will entail making sure all reimbursement agreements contain a place for the CFDA on the signature page, updating the notice provisions contained in the reimbursement agreements and adding language to the reimbursement agreements that address closeout requirements. 2. After revisions are made to the agreement templates, the Department and OCC will request form approval from the Office of General Counsel and Office of Attorney General if appropriate. 3. Completed templates will be uploaded into the agreement testing system following completion of the template updates. It is anticipated that testing would be completed on or before November 30, 2020. 4. After testing, the updated templates will be loaded into the system for use by PennDOT personnel. 5. Certain completed reimbursement agreement templates, updated to include the required federal award information, have already been uploaded into the system. These include transportation alternatives set-aside and bridge inventory and inspection agreements. Because of detailed effort involved in updating a template in the system?the templates cannot simply be modified to incorporate the required federal award information not currently included?updating other templates is dependent on making substantive revisions to those templates. Those substantive revisions are currently underway but will require approval from various stakeholders before proceeding to completion. 6. Efforts are also underway, with the assistance of PennDOT IT personnel, to implement modifications to the system itself that will streamline making template changes in the future. On or before December 31, 2020, PennDOT will require the use of the system by users utilizing the templates that are covered by PennDOT Publication 740. Besides uploading many of PennDOT?s reimbursement agreements into the system, the following actions will be taken: 1. OCC attorneys who assist in the drafting and reviewing of reimbursement agreements (including paper versions executed outside of the system) will be made aware of the federal requirements and will make sure agreements they draft or review have the required information. 2. PennDOT persons who are responsible for reimbursement agreements (including paper agreements executed outside of the system) will be made aware of the federal requirements and will make sure agreements they draft or review have the required information. Anticipated Completion Date: PennDOT: 12/31/2020 Contact People: Allen Melley, Civil Engineer Manager, Bureau of Project Delivery, Highway Administration ; P. Oliver Kerwin, Deputy Chief Counsel; Michael H. Kline, Senior Counsel, Office of Chief Counsel PDE: 1.Twenty-First Century: PDE will maintain the correct award identification number documents on hand when processing grants to avoid using incorrect numbers. PDE will pre proof documents before sending out final contracts. 2. TANF ? PDE Teen Parenting: The risk assessments were completed for all grantees for the July 1, 2019 through June 30, 2020 period on June 5, 2019. Going forward, the risk assessments will be completed before each program year. Anticipated Completion Date: 1. Completed; 2. Completed Contact People: 1. Maribel Martinez, Fiscal Mgmt. Specialist 1; 2. Andrew Hansrote, Fiscal Technician DHS: 1.OA-SSBG: The SSBG-Homeless and SABG will be added to the risk assessment tool. Philadelphia is the only county that receives SABG dollars through OIM for housing services. The money is passed-through DHS-OIM from the Department of Health. The monitoring of the SABG funds is included in the OA-BFO review of Philadelphia, but it was not documented. 2.OPD-SSBG: Grant Programs under the Office of Policy and Development (OPD) are provided federal restrictions and requirements under the Office of Management and Budget?s Uniform Guidance once per year. Procedures for the evaluation of subrecipient risk were implemented in October 2017. Risk assessments for FY 19-20 were completed in August 2019. Monitoring will prioritize subrecipients receiving a ?high risk? designation and/or those who have not had monitoring in the past year. Monitoring for FY 19-20 will occur in the Spring 2020. Monitoring visits are currently being scheduled with grantees. 3. OCYF-Foster Care and Adoption Assistance: The fiscal year 19-20 allocation letters were issued August 8, 2019. Federal award information will be shared by March 31, 2020. OCYF has a risk assessment process in place for Title IV-E and TANF awards. During the quality assurance reviews, which occur twice a year at a minimum, OCYF reviews a sample of Title IV-E eligible foster care cases, Title IV-E ineligible foster care cases, Title IV-E eligible adoption assistance cases, and TANF eligible cases. Depending on the number of eligibility and claiming errors identified during the review, OCYF schedules more frequent visits as the risk of repeated and continued errors in these CCYAs is higher. Inaccurate eligibility determinations lead to inaccurate federal claiming so basing the review schedule on a CCYA?s eligibility review outcomes allows OCYF to target those CCYAs where inaccurate claiming is a higher risk. Anticipated Completion Date: 1. 03/31/2020; 2. 06/30/2020; 3. 03/31/2020 Contact People: 1. Kelly Leighty, Director, Division of Financial Policy and Operations; 2. Cassie Hourlland, Grants and Policy Specialist, OPD; 3. Tia Petrovitz, Fiscal Management Specialist 4

Prior Finding References

2018-020

About Subrecipient Monitoring →
2019-020
Subrecipient Monitoring
MATERIAL WEAKNESSREPEATQUESTIONED COSTS

Under the Commonwealth of Pennsylvania's (Commonwealth) implementation of the Single Audit Act, review and resolution of subrecipient Single Audit reports is split into two stages. The Office of the Budget?s Bureau of Audits (OB-BOA) ensures the reports meet technical standards through a centralized desk review process. The various funding agencies in the Commonwealth are responsible for making a management decision on each finding within six months of the Federal Audit Clearinghouse (FAC) acceptance date for audits subject to Uniform Guidance and to ensure appropriate corrective action is taken by the subrecipient (except for Uniform Guidance audits under U.S. Department of Labor programs which are permitted 12 months for management decisions in accordance with 2 CFR Section 2900.21). Each Commonwealth agency is also responsible for reviewing financial information in each audit report to determine whether the audit included all pass-through funding provided by the agency in order to ensure pass-through funds were audited. Most agencies meet this requirement by performing Schedule of Expenditures of Federal Awards (SEFA) reconciliations. The agency is also required to adjust Commonwealth records, if necessary. Our fiscal year ended June 30, 2019 audit of the Commonwealth?s process for review and resolution of subrecipient Single Audits included an evaluation of the Commonwealth?s fiscal year ended June 30, 2018 subrecipient audit universe for audits due for submission to the FAC during the fiscal year ended June 30, 2019. We also evaluated the Commonwealth?s review of 106 subrecipient audit reports with findings in major programs/clusters which were identified on the Commonwealth agencies? tracking lists as submitted to the FAC during the fiscal year ended June 30, 2019, and required management decisions by Commonwealth agencies. Finding 2019 ? 020: (continued) Our testing disclosed the following audit exceptions regarding the Commonwealth agencies? review of subrecipient audit reports: ? Department of Drug and Alcohol Programs (DDAP): The time period for making a management decision on findings ranged from approximately 8.7 months to 29.5 months after the FAC acceptance date for three out of six subrecipient audit reports with findings. There was also a delay in the completion of the SEFA reconciliation for one of the three subrecipient audit reports. ? Department of Human Services (DHS): The time period for making a management decision on findings ranged from approximately 7.6 months to 16.1 months after the FAC acceptance date for 22 out of the 26 subrecipient audit reports with findings. There was also a delay in DHS?s procedures to ensure the subrecipient SEFAs were accurate so that major programs were properly determined and subject to audit. In addition, our review disclosed that eight subrecipient audit reports with findings for which DHS was the lead agency were submitted late to the FAC, with FAC acceptance dates ranging from approximately one month to 10.8 months after the nine month Single Audit due date. ? Pennsylvania Infrastructure Investment Authority (PENNVEST): Our review disclosed that material unaudited dollars in the amount of $3,831,514 existed for the Clean Water State Revolving Funds program, since one out of 13 required subrecipient audit reports for equivalency loans in the fiscal year ended June 30, 2018 subrecipient audit universe had not been submitted to the FAC as of our January 2020 test date, over 16 months after the September 30, 2018 Single Audit due date. ? Department of Transportation (PennDOT): The time period for making a management decision on findings ranged from approximately 6.1 months to 9.1 months after the FAC acceptance date for 13 out of the 20 subrecipient audit reports with findings. In addition, our review disclosed that five subrecipient audit reports with findings for which PennDOT was the lead agency were submitted late to the FAC, with FAC acceptance dates ranging from approximately three weeks to 3.6 months after the nine month Single Audit due date. As a follow-up to the prior year finding, we noted that the Commonwealth subgranted federal funds totaling $255,926,922 to the City of Philadelphia during the fiscal year ended June 30, 2018, for which a Single Audit was not submitted to the FAC until December 10, 2019, over 8.4 months after the March 31, 2019 due date. Our testing disclosed that DHS?s and DDAP?s subgrants to the City of Philadelphia were material for six of the 21 major programs/clusters with material subgranted funds. Our follow-up on the prior year finding also disclosed that the Commonwealth subgranted federal funds totaling $30,305,441 to Bucks County during the fiscal year ended December 31, 2017. The audit was not submitted to the FAC until March 14, 2019, which was 5.5 months after the September 30, 2018 due date. DHS was the lead agency for the City of Philadelphia and Bucks County audits. Criteria: 2 CFR ?200.331, Requirements for pass-through entities, states in part: All pass-through entities must: (d) Monitor the activities of the subrecipient as necessary to ensure that the subaward is used for authorized purposes, in compliance with Federal statutes, regulations, and the terms and conditions of the subaward, and that subaward performance goals are achieved. Pass-through entity monitoring of the subrecipient must include: (2) Following-up and ensuring that the subrecipient takes timely and appropriate action on all deficiencies pertaining to the Federal award provided to the subrecipient from the pass-through entity detected through audits, on-site review, and other means. (3) Issuing a management decision for audit findings pertaining to the Federal award provided to the subrecipient from the pass-through entity as required by ? 200.521 Management decision. Finding 2019 ? 020: (continued) (f) Verify that every subrecipient is audited as required by Subpart F ? Audit Requirements of this part when it is expected that the subrecipient?s Federal awards expended during the respective fiscal year equaled or exceeded the threshold set forth in ? 200.501 Audit requirements. (g) Consider whether the results of the subrecipient?s audit, on-site review, or other monitoring indicate conditions that necessitate adjustments to the pass-through entity?s own records. (h) Consider taking enforcement action against noncompliant subrecipients as described in ?200.338 Remedies for noncompliance of this part and in program regulations. In order to carry out these responsibilities properly, good internal control dictates that state pass-through agencies ensure subrecipient Single Audit SEFAs are representative of state payment records each year, and that the related federal programs have been properly subjected to Single Audit procedures. 2 CFR ?200.512, Report submission, states in part: (a) General. (1) The audit must be completed and the data collection form described in paragraph (b) of this section and reporting package described in paragraph (c) of this section must be submitted within the earlier of 30 calendar days after receipt of the auditor?s report(s), or nine months after the end of the audit period. 2 CFR ?200.521, Management decision, states in part: (a) General. The management decision must clearly state whether or not the finding is sustained, the reasons for the decision, and the expected auditee action to repay disallowed costs, make financial adjustments, or take other action. (d) Time requirements. The Federal awarding agency or pass-through entity responsible for issuing a management decision must do so within six months of acceptance of the audit report by the FAC. The auditee must initiate and proceed with corrective action as rapidly as possible and corrective action should begin no later than upon receipt of the audit report. 2 CFR ?200.505, Sanctions, states: In cases of continued inability or unwillingness to have an audit conducted in accordance with this part, Federal agencies and pass-through entities must take appropriate action as provided in ?200.338 Remedies for noncompliance. 2 CFR ?200.338, Remedies for noncompliance, states in part: If a non-Federal entity fails to comply with Federal statutes, regulations or the terms and conditions of a Federal award, the Federal awarding agency or pass-through entity may impose additional conditions, as described in ?200.207 Specific conditions. If the Federal awarding agency or pass-through entity determines that noncompliance cannot be remedied by imposing additional conditions, the federal awarding agency or pass-through entity may take one or more of the following actions, as appropriate in the circumstances. (a) Temporarily withhold cash payments pending correction of the deficiency by the non-Federal entity or more severe enforcement action by the Federal awarding agency or pass-through entity. (b) Disallow (that is, deny both use of funds and any applicable matching credit for) all or part of the cost of the activity or action not in compliance. (c) Wholly or partly suspend or terminate the Federal award. (d) Initiate suspension or debarment proceedings as authorized under 2 CFR Part 180 and Federal awarding agency regulations (or in the case of a pass-through entity, recommend such a proceeding be initiated by a Federal awarding agency). Finding 2019 ? 020: (continued) (e) Withhold further Federal awards for the project or program. (f) Take other remedies that may be legally available. To ensure Commonwealth enforcement of federal regulations for subrecipient noncompliance with audit requirements, Commonwealth Management Directive 325.8, Remedies for Recipient Noncompliance with Audit Requirements, Section 5 related to policy, states in part: (a) Agencies must develop and implement remedial action that reflects the unique requirements of each program? (b) Overall periods for the implementation of remedial action should not exceed six months from the date the first remedial action is initiated. At the end of the six-month period, the recipient should take the appropriate corrective action or the final stage of remedial action should be imposed on the recipient. Examples of remedial action include, but are not limited to: (4) Withholding a portion of assistance payments until the noncompliance is resolved. (5) Withholding or disallowing overhead costs until the noncompliance is resolved. (6) Suspending the assistance agreement until the noncompliance is resolved. (7) Terminating the assistance agreement with the recipient and, if necessary, seeking alternative entities to administer the program. Management Directive 325.9, Processing Audits of Federal Pass-Through Funds, Section 7 related to procedures, states in part: c. Agencies. (1) Evaluate single audit report submissions received from BOA to determine program purpose acceptability by verifying, at a minimum, that all agency-funded programs are properly included on the applicable financial schedules; that findings affecting the agency contain sufficient information to facilitate a management decision; and that the subrecipient has submitted an adequate corrective action plan. (6) Impose or coordinate the imposition of remedial action in accordance with 2 CFR Part 200.338 and Management Directive 325.8, Remedies for Recipient Noncompliance with Audit Requirements when subrecipients fail to comply with the provisions of Subpart F. Management Directive 325.12, Standards for Internal Control for Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s, Standards for Internal Control in the Federal Government (Green Book), published in September 2014. The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: The common reason provided by Commonwealth management for untimely audit resolution in the various agencies, including making management decisions, approving corrective action, and performing procedures to ensure the accuracy of subrecipient SEFAs was either a change in staff or a lack of staff to follow up and process subrecipient audit reports more timely. PennDOT personnel indicated a misunderstanding existed with respect to the FAC acceptance date being the start of the six month period for making management decisions. Regarding late and outstanding audit report submissions, the Commonwealth agencies did not appear to be timely implementing remedial action steps in accordance with 2 CFR ?200.338 and Commonwealth Management Directive 325.8 in order to ensure compliance with federal audit submission requirements. Finding 2019 ? 020: (continued) Effect: Since required management decisions were not made within six months to ensure appropriate corrective action was taken on audits received from subrecipients, the Commonwealth did not comply with federal regulations, and subrecipients were not made aware of acceptance or rejection of corrective action plans in a timely manner. Further, noncompliance may recur in future periods if control deficiencies are not corrected on a timely basis, and there is an increased risk of unallowable charges being made to federal programs if corrective action and recovery of questioned costs is not timely. Regarding the SEFA reviews or alternate procedures which are not being performed timely and the late Single Audit report submissions, there is an increased risk that subrecipients could be misspending and/or inappropriately tracking and reporting federal funds over multiple year periods, and these discrepancies may not be properly monitored, detected, and corrected by agency personnel on a timely basis as required. Finally, additional federal pass-through funds may be unaudited in the future without timely and effective remedial action from Commonwealth agencies to enforce compliance. Recommendation: We recommend that the above weaknesses that cause untimely subrecipient Single Audit resolution, including untimely management decisions on findings, untimely review of the SEFA or alternate procedures, and late audit report submissions be corrected to ensure compliance with federal requirements and Commonwealth Management Directives, and to better ensure more timely subrecipient compliance with program requirements. Commonwealth agencies should promptly pursue outstanding audits and implement remedial action steps in accordance with 2 CFR ?200.338 and Commonwealth Management Directive 325.8 on a timely basis, including withholding funding from subrecipients which do not comply with audit submission requirements. DDAP Response: DDAP agrees with the finding. DHS Response: DHS agrees with the finding. PENNVEST Response: PENNVEST recognizes that material unaudited dollars in the amount of $3,831,514 existed for the Clean Water State Revolving Funds program for 2018. McKeesport Municipal Authority was purchased by Pennsylvania American Water on or about December 18, 2017, but the Single Audit was not yet due at the time of the sale. The PENNVEST SEFA coordinator began to request the Single Audit filing on or about October 11, 2018 and followed up each month with the City of McKeesport. PENNVEST did not impose remedial action in this case because the City of McKeesport, on behalf of Pennsylvania American Water, continued to provide updates each month. It should also be noted that PENNVEST reviewed the itemized, final payment request prior to releasing the final payment in the amount $3,831,514 as well as the final inspection produced by the PA Department of Environmental Protection, which indicated that the construction was complete according to approved plans and specifications. This was an extraordinary circumstance due to the timing of the sale of the entity. PENNVEST will review its policies and procedures to ensure that a contact is in place when an entity is purchased prior to a Single Audit being filed. PennDOT Response: PennDOT agrees with the finding. Finding 2019 ? 020: (continued) Auditors? Conclusion: The agency responses from DDAP, DHS, and PennDOT indicated agreement with the finding, and the PENNVEST response acknowledged the finding. No new information was provided which would mitigate the finding. The finding remains as stated. We will evaluate any corrective action in the subsequent audit. Questioned Costs: The amount of questioned costs cannot be determined. The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Show full finding ▾
Full finding narrative

Various Agencies Finding 2019 ? 020: CFDA #20.205 and 20.219 ? Highway Planning and Construction Cluster CFDA #66.458 ? Capitalization Grants for Clean Water State Revolving Funds CFDA #93.558 ? Temporary Assistance for Needy Families CFDA #93.563 ? Child Support Enforcement CFDA #93.575 and 93.596 ? Child Care and Development Fund (CCDF) Cluster CFDA #93.658 ? Foster Care ? Title IV-E CFDA #93.659 ? Adoption Assistance CFDA #93.667 ? Social Services Block Grant CFDA #93.767 ? Children?s Health Insurance Program CFDA #93.775, 93.777, and 93.778 ? Medicaid Cluster CFDA #93.959 ? Block Grants for Prevention and Treatment of Substance Abuse A Material Weakness and Material Noncompliance Exist in the Commonwealth?s Subrecipient Audit Resolution Process (A Similar Condition Was Noted in Prior Year Finding 2018-021) Federal Grant Number(s) and Year(s): N78000 (7/01/2018 ? 6/30/2019), CS-420001-18 (7/01/2018 ? 6/30/2025), 1901PATANF (10/01/2018 ? 9/30/2019), 1801PATANF (10/01/2017 ? 9/30/2018), 1901PACSES (10/01/2018 ? 9/30/2019), 1804PACSES (10/01/2017 ? 9/30/2018), G1901PACCDF (10/01/2018 ? 9/30/2019), G1801PACCDF (10/01/2017 ? 9/30/2018), 1901PAFOST (10/01/2018 ? 9/30/2019), 1801PAFOST (10/01/2017 ? 9/30/2018), 1901PAADPT (10/01/2018 ? 9/30/2019), 1801PAADPT (10/01/2017 ? 9/30/2018), 1901PASOSR (10/01/2018 ? 9/30/2019), 1801PASOSR (10/01/2017 ? 9/30/2018), 1905PA5021 (10/01/2018 ? 9/30/2020), 1805PA5021 (10/01/2017 ? 9/30/2019), 1905PA5MAP (10/01/2018 ? 9/30/2019), 1805PA5MAP (10/01/2017 ? 9/30/2018), 3B08TI010044-19 (10/01/2018 ? 9/30/2020), 2B08TI010044-18 (10/01/2017 ? 9/30/2019), 2B08TI010044-17 (10/01/2016 ? 9/30/2018) Type of Finding: Significant Deficiency, Noncompliance for Medicaid Cluster Material Weakness, Material Noncompliance for Other Programs Compliance Requirement: Subrecipient Monitoring Condition: Under the Commonwealth of Pennsylvania's (Commonwealth) implementation of the Single Audit Act, review and resolution of subrecipient Single Audit reports is split into two stages. The Office of the Budget?s Bureau of Audits (OB-BOA) ensures the reports meet technical standards through a centralized desk review process. The various funding agencies in the Commonwealth are responsible for making a management decision on each finding within six months of the Federal Audit Clearinghouse (FAC) acceptance date for audits subject to Uniform Guidance and to ensure appropriate corrective action is taken by the subrecipient (except for Uniform Guidance audits under U.S. Department of Labor programs which are permitted 12 months for management decisions in accordance with 2 CFR Section 2900.21). Each Commonwealth agency is also responsible for reviewing financial information in each audit report to determine whether the audit included all pass-through funding provided by the agency in order to ensure pass-through funds were audited. Most agencies meet this requirement by performing Schedule of Expenditures of Federal Awards (SEFA) reconciliations. The agency is also required to adjust Commonwealth records, if necessary. Our fiscal year ended June 30, 2019 audit of the Commonwealth?s process for review and resolution of subrecipient Single Audits included an evaluation of the Commonwealth?s fiscal year ended June 30, 2018 subrecipient audit universe for audits due for submission to the FAC during the fiscal year ended June 30, 2019. We also evaluated the Commonwealth?s review of 106 subrecipient audit reports with findings in major programs/clusters which were identified on the Commonwealth agencies? tracking lists as submitted to the FAC during the fiscal year ended June 30, 2019, and required management decisions by Commonwealth agencies. Finding 2019 ? 020: (continued) Our testing disclosed the following audit exceptions regarding the Commonwealth agencies? review of subrecipient audit reports: ? Department of Drug and Alcohol Programs (DDAP): The time period for making a management decision on findings ranged from approximately 8.7 months to 29.5 months after the FAC acceptance date for three out of six subrecipient audit reports with findings. There was also a delay in the completion of the SEFA reconciliation for one of the three subrecipient audit reports. ? Department of Human Services (DHS): The time period for making a management decision on findings ranged from approximately 7.6 months to 16.1 months after the FAC acceptance date for 22 out of the 26 subrecipient audit reports with findings. There was also a delay in DHS?s procedures to ensure the subrecipient SEFAs were accurate so that major programs were properly determined and subject to audit. In addition, our review disclosed that eight subrecipient audit reports with findings for which DHS was the lead agency were submitted late to the FAC, with FAC acceptance dates ranging from approximately one month to 10.8 months after the nine month Single Audit due date. ? Pennsylvania Infrastructure Investment Authority (PENNVEST): Our review disclosed that material unaudited dollars in the amount of $3,831,514 existed for the Clean Water State Revolving Funds program, since one out of 13 required subrecipient audit reports for equivalency loans in the fiscal year ended June 30, 2018 subrecipient audit universe had not been submitted to the FAC as of our January 2020 test date, over 16 months after the September 30, 2018 Single Audit due date. ? Department of Transportation (PennDOT): The time period for making a management decision on findings ranged from approximately 6.1 months to 9.1 months after the FAC acceptance date for 13 out of the 20 subrecipient audit reports with findings. In addition, our review disclosed that five subrecipient audit reports with findings for which PennDOT was the lead agency were submitted late to the FAC, with FAC acceptance dates ranging from approximately three weeks to 3.6 months after the nine month Single Audit due date. As a follow-up to the prior year finding, we noted that the Commonwealth subgranted federal funds totaling $255,926,922 to the City of Philadelphia during the fiscal year ended June 30, 2018, for which a Single Audit was not submitted to the FAC until December 10, 2019, over 8.4 months after the March 31, 2019 due date. Our testing disclosed that DHS?s and DDAP?s subgrants to the City of Philadelphia were material for six of the 21 major programs/clusters with material subgranted funds. Our follow-up on the prior year finding also disclosed that the Commonwealth subgranted federal funds totaling $30,305,441 to Bucks County during the fiscal year ended December 31, 2017. The audit was not submitted to the FAC until March 14, 2019, which was 5.5 months after the September 30, 2018 due date. DHS was the lead agency for the City of Philadelphia and Bucks County audits. Criteria: 2 CFR ?200.331, Requirements for pass-through entities, states in part: All pass-through entities must: (d) Monitor the activities of the subrecipient as necessary to ensure that the subaward is used for authorized purposes, in compliance with Federal statutes, regulations, and the terms and conditions of the subaward, and that subaward performance goals are achieved. Pass-through entity monitoring of the subrecipient must include: (2) Following-up and ensuring that the subrecipient takes timely and appropriate action on all deficiencies pertaining to the Federal award provided to the subrecipient from the pass-through entity detected through audits, on-site review, and other means. (3) Issuing a management decision for audit findings pertaining to the Federal award provided to the subrecipient from the pass-through entity as required by ? 200.521 Management decision. Finding 2019 ? 020: (continued) (f) Verify that every subrecipient is audited as required by Subpart F ? Audit Requirements of this part when it is expected that the subrecipient?s Federal awards expended during the respective fiscal year equaled or exceeded the threshold set forth in ? 200.501 Audit requirements. (g) Consider whether the results of the subrecipient?s audit, on-site review, or other monitoring indicate conditions that necessitate adjustments to the pass-through entity?s own records. (h) Consider taking enforcement action against noncompliant subrecipients as described in ?200.338 Remedies for noncompliance of this part and in program regulations. In order to carry out these responsibilities properly, good internal control dictates that state pass-through agencies ensure subrecipient Single Audit SEFAs are representative of state payment records each year, and that the related federal programs have been properly subjected to Single Audit procedures. 2 CFR ?200.512, Report submission, states in part: (a) General. (1) The audit must be completed and the data collection form described in paragraph (b) of this section and reporting package described in paragraph (c) of this section must be submitted within the earlier of 30 calendar days after receipt of the auditor?s report(s), or nine months after the end of the audit period. 2 CFR ?200.521, Management decision, states in part: (a) General. The management decision must clearly state whether or not the finding is sustained, the reasons for the decision, and the expected auditee action to repay disallowed costs, make financial adjustments, or take other action. (d) Time requirements. The Federal awarding agency or pass-through entity responsible for issuing a management decision must do so within six months of acceptance of the audit report by the FAC. The auditee must initiate and proceed with corrective action as rapidly as possible and corrective action should begin no later than upon receipt of the audit report. 2 CFR ?200.505, Sanctions, states: In cases of continued inability or unwillingness to have an audit conducted in accordance with this part, Federal agencies and pass-through entities must take appropriate action as provided in ?200.338 Remedies for noncompliance. 2 CFR ?200.338, Remedies for noncompliance, states in part: If a non-Federal entity fails to comply with Federal statutes, regulations or the terms and conditions of a Federal award, the Federal awarding agency or pass-through entity may impose additional conditions, as described in ?200.207 Specific conditions. If the Federal awarding agency or pass-through entity determines that noncompliance cannot be remedied by imposing additional conditions, the federal awarding agency or pass-through entity may take one or more of the following actions, as appropriate in the circumstances. (a) Temporarily withhold cash payments pending correction of the deficiency by the non-Federal entity or more severe enforcement action by the Federal awarding agency or pass-through entity. (b) Disallow (that is, deny both use of funds and any applicable matching credit for) all or part of the cost of the activity or action not in compliance. (c) Wholly or partly suspend or terminate the Federal award. (d) Initiate suspension or debarment proceedings as authorized under 2 CFR Part 180 and Federal awarding agency regulations (or in the case of a pass-through entity, recommend such a proceeding be initiated by a Federal awarding agency). Finding 2019 ? 020: (continued) (e) Withhold further Federal awards for the project or program. (f) Take other remedies that may be legally available. To ensure Commonwealth enforcement of federal regulations for subrecipient noncompliance with audit requirements, Commonwealth Management Directive 325.8, Remedies for Recipient Noncompliance with Audit Requirements, Section 5 related to policy, states in part: (a) Agencies must develop and implement remedial action that reflects the unique requirements of each program? (b) Overall periods for the implementation of remedial action should not exceed six months from the date the first remedial action is initiated. At the end of the six-month period, the recipient should take the appropriate corrective action or the final stage of remedial action should be imposed on the recipient. Examples of remedial action include, but are not limited to: (4) Withholding a portion of assistance payments until the noncompliance is resolved. (5) Withholding or disallowing overhead costs until the noncompliance is resolved. (6) Suspending the assistance agreement until the noncompliance is resolved. (7) Terminating the assistance agreement with the recipient and, if necessary, seeking alternative entities to administer the program. Management Directive 325.9, Processing Audits of Federal Pass-Through Funds, Section 7 related to procedures, states in part: c. Agencies. (1) Evaluate single audit report submissions received from BOA to determine program purpose acceptability by verifying, at a minimum, that all agency-funded programs are properly included on the applicable financial schedules; that findings affecting the agency contain sufficient information to facilitate a management decision; and that the subrecipient has submitted an adequate corrective action plan. (6) Impose or coordinate the imposition of remedial action in accordance with 2 CFR Part 200.338 and Management Directive 325.8, Remedies for Recipient Noncompliance with Audit Requirements when subrecipients fail to comply with the provisions of Subpart F. Management Directive 325.12, Standards for Internal Control for Commonwealth Agencies, adopted the internal control framework outlined in the United States Government Accountability Office?s, Standards for Internal Control in the Federal Government (Green Book), published in September 2014. The Green Book states in part: Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. Management should remediate identified internal control deficiencies on a timely basis. Cause: The common reason provided by Commonwealth management for untimely audit resolution in the various agencies, including making management decisions, approving corrective action, and performing procedures to ensure the accuracy of subrecipient SEFAs was either a change in staff or a lack of staff to follow up and process subrecipient audit reports more timely. PennDOT personnel indicated a misunderstanding existed with respect to the FAC acceptance date being the start of the six month period for making management decisions. Regarding late and outstanding audit report submissions, the Commonwealth agencies did not appear to be timely implementing remedial action steps in accordance with 2 CFR ?200.338 and Commonwealth Management Directive 325.8 in order to ensure compliance with federal audit submission requirements. Finding 2019 ? 020: (continued) Effect: Since required management decisions were not made within six months to ensure appropriate corrective action was taken on audits received from subrecipients, the Commonwealth did not comply with federal regulations, and subrecipients were not made aware of acceptance or rejection of corrective action plans in a timely manner. Further, noncompliance may recur in future periods if control deficiencies are not corrected on a timely basis, and there is an increased risk of unallowable charges being made to federal programs if corrective action and recovery of questioned costs is not timely. Regarding the SEFA reviews or alternate procedures which are not being performed timely and the late Single Audit report submissions, there is an increased risk that subrecipients could be misspending and/or inappropriately tracking and reporting federal funds over multiple year periods, and these discrepancies may not be properly monitored, detected, and corrected by agency personnel on a timely basis as required. Finally, additional federal pass-through funds may be unaudited in the future without timely and effective remedial action from Commonwealth agencies to enforce compliance. Recommendation: We recommend that the above weaknesses that cause untimely subrecipient Single Audit resolution, including untimely management decisions on findings, untimely review of the SEFA or alternate procedures, and late audit report submissions be corrected to ensure compliance with federal requirements and Commonwealth Management Directives, and to better ensure more timely subrecipient compliance with program requirements. Commonwealth agencies should promptly pursue outstanding audits and implement remedial action steps in accordance with 2 CFR ?200.338 and Commonwealth Management Directive 325.8 on a timely basis, including withholding funding from subrecipients which do not comply with audit submission requirements. DDAP Response: DDAP agrees with the finding. DHS Response: DHS agrees with the finding. PENNVEST Response: PENNVEST recognizes that material unaudited dollars in the amount of $3,831,514 existed for the Clean Water State Revolving Funds program for 2018. McKeesport Municipal Authority was purchased by Pennsylvania American Water on or about December 18, 2017, but the Single Audit was not yet due at the time of the sale. The PENNVEST SEFA coordinator began to request the Single Audit filing on or about October 11, 2018 and followed up each month with the City of McKeesport. PENNVEST did not impose remedial action in this case because the City of McKeesport, on behalf of Pennsylvania American Water, continued to provide updates each month. It should also be noted that PENNVEST reviewed the itemized, final payment request prior to releasing the final payment in the amount $3,831,514 as well as the final inspection produced by the PA Department of Environmental Protection, which indicated that the construction was complete according to approved plans and specifications. This was an extraordinary circumstance due to the timing of the sale of the entity. PENNVEST will review its policies and procedures to ensure that a contact is in place when an entity is purchased prior to a Single Audit being filed. PennDOT Response: PennDOT agrees with the finding. Finding 2019 ? 020: (continued) Auditors? Conclusion: The agency responses from DDAP, DHS, and PennDOT indicated agreement with the finding, and the PENNVEST response acknowledged the finding. No new information was provided which would mitigate the finding. The finding remains as stated. We will evaluate any corrective action in the subsequent audit. Questioned Costs: The amount of questioned costs cannot be determined. The corrective action plan for this finding, if any, has not been reviewed by the auditors. See Corrective Action Plans located elsewhere in this Report.

Corrective Action Plan

DDAP: DDAP continues to face personnel challenges which makes processing the backlog of audits extremely difficult. In addition, current staff have limited knowledge of performing these auditing functions. The Department is working with the Department of Human Services (DHS) Shared Services to develop and implement procedures to streamline the process as well as address auditing issues related to funds distributed by DDAP. The Department will continue to work with the DHS Shared Services to assist staff with instruction on the completion of these auditing tasks. DDAP understands the necessity to establish methods to address reconciliation of SEFA submissions in a timelier manner, as well as to seek and finalize corrective action to audit findings of subrecipients, should such findings occur. Anticipated Completion Date: 12/31/2020 Contact Person: Tia J. Roebuck, Director, Division of Budget and Grants Management DHS: Regarding the timeliness of finding resolution and procedures related to the SEFA reviews, the Audit Resolution Section is continuing to explore ways to further streamline the process of single audit reviews to gain efficiencies. We are continuing to have meetings with OB-BOA to discuss ways of streamlining the process further. Regarding enforcement of the subrecipients? submission deadlines, we will continue to monitor the status of audit reports and follow our remedial action plans, which is to consider withholding a percentage of State funding. We continue to have discussions within DHS and within the Commonwealth regarding this consideration. DHS will continue to monitor the status of, and work with the City of Philadelphia and Bucks County, to assist them to become compliant with audit submission requirements. We continue to have conversations with the City of Philadelphia and their independent auditors. Their goal is still to submit the June 30, 2019 single audit timely. Anticipated Completion Date: 06/30/2020 Contact People: David Bryan, Manager, Audit Resolution Section; Alexander Matolyak, Director, Division of Audit and Review PENNVEST: PENNVEST reviewed and revised its policies and procedures to ensure that a contact is in place when a subrecipient is purchased by a third party, prior to a single audit being filed. Anticipated Completion Date: Completed Contact Person: Heather Brookmyer, Loan Servicing Officer, SEFA Coordinator PennDOT implemented changes in the audit report resolution process after the last auditor testing period that went into effect the end of 2019 Additional changes PennDOT plans on completing: 1. Adding a column for the Federal Audit Clearinghouse (FAC) date to the Subrecipient Case File Database. 2. Sending out an acknowledgement and reminder letter for current and future subrecipients who provide a single audit report past their deadline. Anticipated Completion Date: 03/31/2020 Contact People: David Maynard, Administrative Officer 1; Kathryn Tartaglia, Administrative Officer 2

Prior Finding References

2018-021

About Subrecipient Monitoring →

FY 2018-06-30

FAC accepted this audit on March 18, 2019 — management decision was due September 18, 2019.

2018-003
Subrecipient Monitoring
REPEATQUESTIONED COSTS

GSA_MIGRATION

Show full finding ▾
Full finding narrative

GSA_MIGRATION

Corrective Action Plan

GSA_MIGRATION

Prior Finding References

2017-006

About Subrecipient Monitoring →
2018-004
Activities Allowed or Unallowed / Cost Allowability / Eligibility / Subrecipient Monitoring
MATERIAL WEAKNESSREPEATQUESTIONED COSTS

GSA_MIGRATION

Show full finding ▾
Full finding narrative

GSA_MIGRATION

Corrective Action Plan

GSA_MIGRATION

Prior Finding References

2017-008

About Activities Allowed or Unallowed, Allowable Costs / Cost Principles, Eligibility, Subrecipient Monitoring →
2018-005
Subrecipient Monitoring
MATERIAL WEAKNESSREPEATQUESTIONED COSTS

GSA_MIGRATION

Show full finding ▾
Full finding narrative

GSA_MIGRATION

Corrective Action Plan

GSA_MIGRATION

Prior Finding References

2017-009

About Subrecipient Monitoring →
2018-006
Activities Allowed or Unallowed
MATERIAL WEAKNESS

GSA_MIGRATION

Show full finding ▾
Full finding narrative

GSA_MIGRATION

Corrective Action Plan

GSA_MIGRATION

About Activities Allowed or Unallowed →
2018-007
Special Tests & Provisions
MATERIAL WEAKNESSREPEATQUESTIONED COSTS

GSA_MIGRATION

Show full finding ▾
Full finding narrative

GSA_MIGRATION

Corrective Action Plan

GSA_MIGRATION

Prior Finding References

2017-011

About Special Tests and Provisions →
2018-008
Subrecipient Monitoring
REPEATQUESTIONED COSTS

GSA_MIGRATION

Show full finding ▾
Full finding narrative

GSA_MIGRATION

Corrective Action Plan

GSA_MIGRATION

Prior Finding References

2017-013

About Subrecipient Monitoring →
2018-009
Matching, Level of Effort, Earmarking
MATERIAL WEAKNESSREPEATQUESTIONED COSTS

GSA_MIGRATION

Show full finding ▾
Full finding narrative

GSA_MIGRATION

Corrective Action Plan

GSA_MIGRATION

Prior Finding References

2017-014

About Matching, Level of Effort, Earmarking →
2018-010
Subrecipient Monitoring
MATERIAL WEAKNESSREPEATQUESTIONED COSTS

GSA_MIGRATION

Show full finding ▾
Full finding narrative

GSA_MIGRATION

Corrective Action Plan

GSA_MIGRATION

Prior Finding References

2017-012

About Subrecipient Monitoring →
2018-011
Cash Management / Subrecipient Monitoring
MATERIAL WEAKNESSREPEATQUESTIONED COSTS

GSA_MIGRATION

Show full finding ▾
Full finding narrative

GSA_MIGRATION

Corrective Action Plan

GSA_MIGRATION

Prior Finding References

2017-017

About Cash Management, Subrecipient Monitoring →
2018-012
Special Tests & Provisions
REPEATQUESTIONED COSTS

GSA_MIGRATION

Show full finding ▾
Full finding narrative

GSA_MIGRATION

Corrective Action Plan

GSA_MIGRATION

Prior Finding References

2017-018

About Special Tests and Provisions →
2018-013
Subrecipient Monitoring
QUESTIONED COSTS

GSA_MIGRATION

Show full finding ▾
Full finding narrative

GSA_MIGRATION

Corrective Action Plan

GSA_MIGRATION

About Subrecipient Monitoring →
2018-014
Eligibility / Special Tests & Provisions
MATERIAL WEAKNESSREPEAT

GSA_MIGRATION

Show full finding ▾
Full finding narrative

GSA_MIGRATION

Corrective Action Plan

GSA_MIGRATION

Prior Finding References

2017-019

About Eligibility, Special Tests and Provisions →
2018-015
Period of Performance
MATERIAL WEAKNESSQUESTIONED COSTS

GSA_MIGRATION

Show full finding ▾
Full finding narrative

GSA_MIGRATION

Corrective Action Plan

GSA_MIGRATION

About Period of Performance →
2018-016
Procurement & Suspension/Debarment
QUESTIONED COSTS

GSA_MIGRATION

Show full finding ▾
Full finding narrative

GSA_MIGRATION

Corrective Action Plan

GSA_MIGRATION

About Procurement and Suspension and Debarment →
2018-017
Other
REPEAT

GSA_MIGRATION

Show full finding ▾
Full finding narrative

GSA_MIGRATION

Corrective Action Plan

GSA_MIGRATION

Prior Finding References

2017-004

About Other →
2018-018
Other
REPEAT

GSA_MIGRATION

Show full finding ▾
Full finding narrative

GSA_MIGRATION

Corrective Action Plan

GSA_MIGRATION

Prior Finding References

2017-003

About Other →
2018-019
Reporting
MATERIAL WEAKNESS

GSA_MIGRATION

Show full finding ▾
Full finding narrative

GSA_MIGRATION

Corrective Action Plan

GSA_MIGRATION

About Reporting →
2018-020
Subrecipient Monitoring
REPEATQUESTIONED COSTS

GSA_MIGRATION

Show full finding ▾
Full finding narrative

GSA_MIGRATION

Corrective Action Plan

GSA_MIGRATION

Prior Finding References

2017-020

About Subrecipient Monitoring →
2018-021
Subrecipient Monitoring
MATERIAL WEAKNESSREPEATQUESTIONED COSTS

GSA_MIGRATION

Show full finding ▾
Full finding narrative

GSA_MIGRATION

Corrective Action Plan

GSA_MIGRATION

Prior Finding References

2017-021

About Subrecipient Monitoring →

FY 2017-06-30

FAC accepted this audit on March 18, 2018 — management decision was due September 18, 2018.

2017-003
Other

GSA_MIGRATION

Show full finding ▾
Full finding narrative

GSA_MIGRATION

Corrective Action Plan

GSA_MIGRATION

About Other →
2017-004
Other
REPEAT

GSA_MIGRATION

Show full finding ▾
Full finding narrative

GSA_MIGRATION

Corrective Action Plan

GSA_MIGRATION

Prior Finding References

2016-006

About Other →
2017-005
Other
REPEAT

GSA_MIGRATION

Show full finding ▾
Full finding narrative

GSA_MIGRATION

Corrective Action Plan

GSA_MIGRATION

Prior Finding References

2016-009

About Other →
2017-006
Subrecipient Monitoring
MATERIAL WEAKNESSREPEATQUESTIONED COSTS

GSA_MIGRATION

Show full finding ▾
Full finding narrative

GSA_MIGRATION

Corrective Action Plan

GSA_MIGRATION

Prior Finding References

2016-010

About Subrecipient Monitoring →
2017-007
Subrecipient Monitoring
REPEATQUESTIONED COSTS

GSA_MIGRATION

Show full finding ▾
Full finding narrative

GSA_MIGRATION

Corrective Action Plan

GSA_MIGRATION

Prior Finding References

2016-011

About Subrecipient Monitoring →
2017-008
Activities Allowed or Unallowed / Cost Allowability / Eligibility / Subrecipient Monitoring
MATERIAL WEAKNESSREPEATQUESTIONED COSTS

GSA_MIGRATION

Show full finding ▾
Full finding narrative

GSA_MIGRATION

Corrective Action Plan

GSA_MIGRATION

Prior Finding References

2016-012

About Activities Allowed or Unallowed, Allowable Costs / Cost Principles, Eligibility, Subrecipient Monitoring →
2017-009
Subrecipient Monitoring
MATERIAL WEAKNESSQUESTIONED COSTS

GSA_MIGRATION

Show full finding ▾
Full finding narrative

GSA_MIGRATION

Corrective Action Plan

GSA_MIGRATION

About Subrecipient Monitoring →
2017-010
Special Tests & Provisions
MATERIAL WEAKNESSREPEAT

GSA_MIGRATION

Show full finding ▾
Full finding narrative

GSA_MIGRATION

Corrective Action Plan

GSA_MIGRATION

Prior Finding References

2016-013

About Special Tests and Provisions →
2017-011
Special Tests & Provisions
MATERIAL WEAKNESSREPEATQUESTIONED COSTS

GSA_MIGRATION

Show full finding ▾
Full finding narrative

GSA_MIGRATION

Corrective Action Plan

GSA_MIGRATION

Prior Finding References

2016-016

About Special Tests and Provisions →
2017-012
Subrecipient Monitoring
MATERIAL WEAKNESSREPEATQUESTIONED COSTS

GSA_MIGRATION

Show full finding ▾
Full finding narrative

GSA_MIGRATION

Corrective Action Plan

GSA_MIGRATION

Prior Finding References

2016-017

About Subrecipient Monitoring →
2017-013
Subrecipient Monitoring
REPEATQUESTIONED COSTS

GSA_MIGRATION

Show full finding ▾
Full finding narrative

GSA_MIGRATION

Corrective Action Plan

GSA_MIGRATION

Prior Finding References

2016-018

About Subrecipient Monitoring →
2017-014
Matching, Level of Effort, Earmarking / Reporting
MATERIAL WEAKNESSQUESTIONED COSTS

GSA_MIGRATION

Show full finding ▾
Full finding narrative

GSA_MIGRATION

Corrective Action Plan

GSA_MIGRATION

About Matching, Level of Effort, Earmarking, Reporting →
2017-015
Special Tests & Provisions
MATERIAL WEAKNESSREPEATQUESTIONED COSTS

GSA_MIGRATION

Show full finding ▾
Full finding narrative

GSA_MIGRATION

Corrective Action Plan

GSA_MIGRATION

Prior Finding References

2016-020

About Special Tests and Provisions →
2017-016
Special Tests & Provisions
REPEATQUESTIONED COSTS

GSA_MIGRATION

Show full finding ▾
Full finding narrative

GSA_MIGRATION

Corrective Action Plan

GSA_MIGRATION

Prior Finding References

2016-021

About Special Tests and Provisions →
2017-017
Cash Management / Subrecipient Monitoring
MATERIAL WEAKNESSREPEATQUESTIONED COSTS

GSA_MIGRATION

Show full finding ▾
Full finding narrative

GSA_MIGRATION

Corrective Action Plan

GSA_MIGRATION

Prior Finding References

2016-022

About Cash Management, Subrecipient Monitoring →
2017-018
Special Tests & Provisions
QUESTIONED COSTS

GSA_MIGRATION

Show full finding ▾
Full finding narrative

GSA_MIGRATION

Corrective Action Plan

GSA_MIGRATION

About Special Tests and Provisions →
2017-019
Eligibility / Special Tests & Provisions
MATERIAL WEAKNESSREPEAT

GSA_MIGRATION

Show full finding ▾
Full finding narrative

GSA_MIGRATION

Corrective Action Plan

GSA_MIGRATION

Prior Finding References

2016-026

About Eligibility, Special Tests and Provisions →
2017-020
Subrecipient Monitoring
MATERIAL WEAKNESSREPEATQUESTIONED COSTS

GSA_MIGRATION

Show full finding ▾
Full finding narrative

GSA_MIGRATION

Corrective Action Plan

GSA_MIGRATION

Prior Finding References

2016-027

About Subrecipient Monitoring →
2017-021
Subrecipient Monitoring
MATERIAL WEAKNESSREPEATQUESTIONED COSTS

GSA_MIGRATION

Show full finding ▾
Full finding narrative

GSA_MIGRATION

Corrective Action Plan

GSA_MIGRATION

Prior Finding References

2016-028

About Subrecipient Monitoring →

FY 2016-06-30

FAC accepted this audit on March 16, 2017 — management decision was due September 16, 2017.

2016-006
Other

GSA_MIGRATION

Show full finding ▾
Full finding narrative

GSA_MIGRATION

Corrective Action Plan

GSA_MIGRATION

About Other →
2016-007
Cash Management
REPEATQUESTIONED COSTS

GSA_MIGRATION

Show full finding ▾
Full finding narrative

GSA_MIGRATION

Corrective Action Plan

GSA_MIGRATION

Prior Finding References

2015-038

About Cash Management →
2016-008
Reporting

GSA_MIGRATION

Show full finding ▾
Full finding narrative

GSA_MIGRATION

Corrective Action Plan

GSA_MIGRATION

About Reporting →
2016-009
Other

GSA_MIGRATION

Show full finding ▾
Full finding narrative

GSA_MIGRATION

Corrective Action Plan

GSA_MIGRATION

About Other →
2016-010
Subrecipient Monitoring
MATERIAL WEAKNESSREPEATQUESTIONED COSTS

GSA_MIGRATION

Show full finding ▾
Full finding narrative

GSA_MIGRATION

Corrective Action Plan

GSA_MIGRATION

Prior Finding References

2015-007

About Subrecipient Monitoring →
2016-011
Subrecipient Monitoring
MATERIAL WEAKNESSQUESTIONED COSTS

GSA_MIGRATION

Show full finding ▾
Full finding narrative

GSA_MIGRATION

Corrective Action Plan

GSA_MIGRATION

About Subrecipient Monitoring →
2016-012
Activities Allowed or Unallowed / Cost Allowability / Eligibility / Subrecipient Monitoring
MATERIAL WEAKNESSQUESTIONED COSTS

GSA_MIGRATION

Show full finding ▾
2016-013
Special Tests & Provisions
MATERIAL WEAKNESSREPEAT

GSA_MIGRATION

Show full finding ▾
Full finding narrative

GSA_MIGRATION

Corrective Action Plan

GSA_MIGRATION

Prior Finding References

2015-012

About Special Tests and Provisions →
2016-014
Special Tests & Provisions
REPEATQUESTIONED COSTS

GSA_MIGRATION

Show full finding ▾
Full finding narrative

GSA_MIGRATION

Corrective Action Plan

GSA_MIGRATION

Prior Finding References

2015-015

About Special Tests and Provisions →
2016-015
Activities Allowed or Unallowed / Cost Allowability
QUESTIONED COSTS

GSA_MIGRATION

Show full finding ▾
Full finding narrative

GSA_MIGRATION

Corrective Action Plan

GSA_MIGRATION

About Activities Allowed or Unallowed, Allowable Costs / Cost Principles →
2016-016
Special Tests & Provisions
MATERIAL WEAKNESSREPEATQUESTIONED COSTS

GSA_MIGRATION

Show full finding ▾
Full finding narrative

GSA_MIGRATION

Corrective Action Plan

GSA_MIGRATION

Prior Finding References

2015-017

About Special Tests and Provisions →
2016-017
Subrecipient Monitoring
MATERIAL WEAKNESSREPEATQUESTIONED COSTS

GSA_MIGRATION

Show full finding ▾
Full finding narrative

GSA_MIGRATION

Corrective Action Plan

GSA_MIGRATION

Prior Finding References

2015-020

About Subrecipient Monitoring →
2016-018
Subrecipient Monitoring
REPEATQUESTIONED COSTS

GSA_MIGRATION

Show full finding ▾
Full finding narrative

GSA_MIGRATION

Corrective Action Plan

GSA_MIGRATION

Prior Finding References

2015-019

About Subrecipient Monitoring →
2016-019
Reporting
REPEAT

GSA_MIGRATION

Show full finding ▾
Full finding narrative

GSA_MIGRATION

Corrective Action Plan

GSA_MIGRATION

Prior Finding References

2015-018

About Reporting →
2016-020
Special Tests & Provisions
MATERIAL WEAKNESSREPEATQUESTIONED COSTS

GSA_MIGRATION

Show full finding ▾
Full finding narrative

GSA_MIGRATION

Corrective Action Plan

GSA_MIGRATION

Prior Finding References

2015-022

About Special Tests and Provisions →
2016-021
Special Tests & Provisions
QUESTIONED COSTS

GSA_MIGRATION

Show full finding ▾
Full finding narrative

GSA_MIGRATION

Corrective Action Plan

GSA_MIGRATION

About Special Tests and Provisions →
2016-022
Cash Management / Subrecipient Monitoring
MATERIAL WEAKNESSREPEATQUESTIONED COSTS

GSA_MIGRATION

Show full finding ▾
Full finding narrative

GSA_MIGRATION

Corrective Action Plan

GSA_MIGRATION

Prior Finding References

2015-023

About Cash Management, Subrecipient Monitoring →
2016-023
Activities Allowed or Unallowed / Cost Allowability / Eligibility
REPEATQUESTIONED COSTS

GSA_MIGRATION

Show full finding ▾
Full finding narrative

GSA_MIGRATION

Corrective Action Plan

GSA_MIGRATION

Prior Finding References

2015-024

About Activities Allowed or Unallowed, Allowable Costs / Cost Principles, Eligibility →
2016-024
Other
REPEAT

GSA_MIGRATION

Show full finding ▾
Full finding narrative

GSA_MIGRATION

Corrective Action Plan

GSA_MIGRATION

Prior Finding References

2015-026

About Other →
2016-025
Subrecipient Monitoring
MATERIAL WEAKNESSREPEATQUESTIONED COSTS

GSA_MIGRATION

Show full finding ▾
Full finding narrative

GSA_MIGRATION

Corrective Action Plan

GSA_MIGRATION

Prior Finding References

2015-027

About Subrecipient Monitoring →
2016-026
Eligibility / Special Tests & Provisions
MATERIAL WEAKNESSREPEAT

GSA_MIGRATION

Show full finding ▾
Full finding narrative

GSA_MIGRATION

Corrective Action Plan

GSA_MIGRATION

Prior Finding References

2015-028

About Eligibility, Special Tests and Provisions →
2016-027
Subrecipient Monitoring
MATERIAL WEAKNESSREPEATQUESTIONED COSTS

GSA_MIGRATION

Show full finding ▾
Full finding narrative

GSA_MIGRATION

Corrective Action Plan

GSA_MIGRATION

Prior Finding References

2015-036

About Subrecipient Monitoring →
2016-028
Subrecipient Monitoring
MATERIAL WEAKNESSREPEATQUESTIONED COSTS

GSA_MIGRATION

Show full finding ▾
Full finding narrative

GSA_MIGRATION

Corrective Action Plan

GSA_MIGRATION

Prior Finding References

2015-037

About Subrecipient Monitoring →

Data source: This information comes from the Federal Audit Clearinghouse, the official repository of Single Audit data. All data is public domain. Verify this organization's audit history at fac.gov.

Are you this organization?

Track your findings and corrective action plans across audit cycles.

Start tracking findings →

Do you fund this organization?

Monitor subrecipient audit findings and compliance status.

Start monitoring →

Product

Resources

Legal

Single Audit Intelligence is an independent tool powered by Federal Audit Clearinghouse data. Not affiliated with GSA, OMB, or any federal agency.

© 2026 Single Audit Intelligence. All data is public domain.