← Back to home

Southern New Hampshire UniversityHigher Education

EIN: 020274509

UEI: FF41YLW75DH6

Audited by: KPMG LLP

Cognizant agency: 84 [Department of Education]

View federal awards & risk assessment →

Data as of August 28, 2026

Southern New Hampshire University9 audit years1 findings
9
Audit Years
1
Total Findings
0
Repeat Findings
$1.3B
Federal Awards Expended (FY 2024)

FY 2024-06-30

LOW-RISK AUDITEE$1,304,131,156 federal awards expendedNo findings recorded this year

Management decision deadline — for entities that funded this organization

The FAC accepted this audit on March 31, 2025. Under 2 CFR 200.521(d), a pass-through entity that provided federal funds to this organization for this audit period must issue a management decision on these findings by October 1, 2025 (334 days ago).

What is a management decision? →

FY 2023-06-30

LOW-RISK AUDITEE$1,133,199,776 federal awards expendedNo findings recorded this year

FAC accepted this audit on March 29, 2024 — management decision was due September 29, 2024.

FY 2022-06-30

$1,118,533,772 federal awards expendedNo findings recorded this year

FAC accepted this audit on March 30, 2023 — management decision was due September 30, 2023.

FY 2021-06-30

$997,382,296 federal awards expendedNo findings recorded this year

FAC accepted this audit on August 24, 2022 — management decision was due February 24, 2023.

FY 2020-06-30

LOW-RISK AUDITEE$848,659,630 federal awards expended

FAC accepted this audit on August 25, 2021 — management decision was due February 25, 2022.

2020-001
Eligibility / Special Tests & Provisions
MATERIAL WEAKNESS

Finding Number: 2020-001 Program Information: Student Financial Assistance Cluster: Federal Supplemental Educational Opportunity Grants Federal Work-Study Program Federal Perkins Loans Federal Pell Grant Program Federal Direct Student Loans Federal Agency: U.S. Department of Education CFDA Numbers: 84.007, 84.033, 84.038, 84.063, 84.268 Federal Award Year: July 1, 2019 to June 30, 2020 Compliance Requirements: Eligibility, Special Tests and Provisions Condition or Requirement: Per 2 CFR Part 200.303, non-Federal entities receiving Federal awards must establish and maintain effective internal controls over Federal awards that provide reasonable assurance that they are managing Federal awards in compliance with Federal statutes, regulations and the provisions of contracts or grant agreements that could have a material effect on each of its Federal programs. One of the many University responsibilities includes establishing a system of internal controls in determining eligibility for student aid, disbursing funds to students. Condition Found: Southern New Hampshire University uses the Colleague application for student financial aid functions. As a result of testing performed over the Colleague application certain General Information Technology Controls related to Colleague were ineffective. There was a total of 71 Colleague admin accounts. Out of these 15 are service accounts, 14 do not have a production access as their corresponding UNIX accounts are disabled and 1 Colleague admin account is locked. As such, we noted that there was a total of 41 active Colleague admin accounts. Per discussion with management and inspection of user titles, we noted that 10 of the 41 active accounts are provisioned to users who do not require this access as part of their job responsibilities (the users are developers and quality assurance staff) and as such, are not appropriate to have system admin access to Colleague. Identification of Questioned Costs: Not applicable SOUTHERN NEW HAMPSHIRE UNIVERSITY Schedule of Findings and Questioned Costs June 30, 2020 Statistical Sampling: The sample was not intended to be, and was not, a statistically valid sample. Repeat Finding: This was not a finding in the prior year. Possible Asserted Cause and Effect: Inappropriate administrative access existing within the system could result in unauthorized and/or malicious activity being performed. We determined through inquiry with management that activity audit logging for all administrator activity does not appear to be enabled within the Colleague application to be able to determine whether individuals that are inappropriate for this level of access have used these access levels. As such, we are unable to determine whether inappropriate and/or malicious activity was performed as a result of the levels of administrative access existing in the system. Application controls as well as other general IT controls are not able to be relied upon as it cannot be determined whether configuration changes over the application controls occurred, or whether user access was inappropriately added, modified, or removed within the audit period. Management removed access for the 10 admin users noted as inappropriate after year end. Recommendation: We recommend that management perform the following: ? Evaluate each user with this level of access to determine whether the access is appropriate for the individual based upon job function and responsibilities. Any access that is deemed to be inappropriate should be immediately removed from user accounts. ? Establish a control to periodically review the logged activity of administrative users to determine if any unauthorized actions were performed. Views of Responsible Officials: This condition has been remediated as of December 15, 2020. Of the 71 user accounts identified to have had Admin privileges, 14 are service accounts. Two accounts are no longer in use and have been locked. Of the 55 remaining accounts, 14 of the users never had a production Unix account which limits the access of these 14 users to access profiles for refresh purposes only. Admin access was removed from all additional accounts except the following where Admin access is limited by role: ? Only four users on the application support team can create/change user access ? The other seven users on the application support team do regular application management but cannot create/change user access ? Eight users do application management and have access to promote code (AppOps) but cannot create/change user access. Therefore, of the 71 users, only four users retain true administrator access to Colleague. SNHU is working with the vendor to evaluate improved audit logging for administrator activity. SOUTHERN NEW HAMPSHIRE UNIVERSITY Schedule of Findings and Questioned Costs June 30, 2020 In general, SNHU leadership agrees with the condition found as written. SNHU would like to make clear that although the condition exists and SNHU agrees with the condition as found, the application is not Software-as-a-Service (SaaS) or externally facing like most financial systems these days. Consideration should be given to additional details: first, that Colleague resides within an active directory access-controlled environment, therefore, Colleague access is a secondary log-in after the active directory access is granted; second, due to the nature of the application, limited administrative privleges are required for all roles in Colleague. These limited administrative privileges are actively managed by our ITS staff; and third, Virtual Private Network (VPN) access is required for remote log in. These controls provide additional layers of security around Colleague. SNHU has invested significantly in a new Student Information System that will replace Colleague in phases beginning in Autumn 2021 and continuing over the next two years.

Show full finding ▾
Full finding narrative

Finding Number: 2020-001 Program Information: Student Financial Assistance Cluster: Federal Supplemental Educational Opportunity Grants Federal Work-Study Program Federal Perkins Loans Federal Pell Grant Program Federal Direct Student Loans Federal Agency: U.S. Department of Education CFDA Numbers: 84.007, 84.033, 84.038, 84.063, 84.268 Federal Award Year: July 1, 2019 to June 30, 2020 Compliance Requirements: Eligibility, Special Tests and Provisions Condition or Requirement: Per 2 CFR Part 200.303, non-Federal entities receiving Federal awards must establish and maintain effective internal controls over Federal awards that provide reasonable assurance that they are managing Federal awards in compliance with Federal statutes, regulations and the provisions of contracts or grant agreements that could have a material effect on each of its Federal programs. One of the many University responsibilities includes establishing a system of internal controls in determining eligibility for student aid, disbursing funds to students. Condition Found: Southern New Hampshire University uses the Colleague application for student financial aid functions. As a result of testing performed over the Colleague application certain General Information Technology Controls related to Colleague were ineffective. There was a total of 71 Colleague admin accounts. Out of these 15 are service accounts, 14 do not have a production access as their corresponding UNIX accounts are disabled and 1 Colleague admin account is locked. As such, we noted that there was a total of 41 active Colleague admin accounts. Per discussion with management and inspection of user titles, we noted that 10 of the 41 active accounts are provisioned to users who do not require this access as part of their job responsibilities (the users are developers and quality assurance staff) and as such, are not appropriate to have system admin access to Colleague. Identification of Questioned Costs: Not applicable SOUTHERN NEW HAMPSHIRE UNIVERSITY Schedule of Findings and Questioned Costs June 30, 2020 Statistical Sampling: The sample was not intended to be, and was not, a statistically valid sample. Repeat Finding: This was not a finding in the prior year. Possible Asserted Cause and Effect: Inappropriate administrative access existing within the system could result in unauthorized and/or malicious activity being performed. We determined through inquiry with management that activity audit logging for all administrator activity does not appear to be enabled within the Colleague application to be able to determine whether individuals that are inappropriate for this level of access have used these access levels. As such, we are unable to determine whether inappropriate and/or malicious activity was performed as a result of the levels of administrative access existing in the system. Application controls as well as other general IT controls are not able to be relied upon as it cannot be determined whether configuration changes over the application controls occurred, or whether user access was inappropriately added, modified, or removed within the audit period. Management removed access for the 10 admin users noted as inappropriate after year end. Recommendation: We recommend that management perform the following: ? Evaluate each user with this level of access to determine whether the access is appropriate for the individual based upon job function and responsibilities. Any access that is deemed to be inappropriate should be immediately removed from user accounts. ? Establish a control to periodically review the logged activity of administrative users to determine if any unauthorized actions were performed. Views of Responsible Officials: This condition has been remediated as of December 15, 2020. Of the 71 user accounts identified to have had Admin privileges, 14 are service accounts. Two accounts are no longer in use and have been locked. Of the 55 remaining accounts, 14 of the users never had a production Unix account which limits the access of these 14 users to access profiles for refresh purposes only. Admin access was removed from all additional accounts except the following where Admin access is limited by role: ? Only four users on the application support team can create/change user access ? The other seven users on the application support team do regular application management but cannot create/change user access ? Eight users do application management and have access to promote code (AppOps) but cannot create/change user access. Therefore, of the 71 users, only four users retain true administrator access to Colleague. SNHU is working with the vendor to evaluate improved audit logging for administrator activity. SOUTHERN NEW HAMPSHIRE UNIVERSITY Schedule of Findings and Questioned Costs June 30, 2020 In general, SNHU leadership agrees with the condition found as written. SNHU would like to make clear that although the condition exists and SNHU agrees with the condition as found, the application is not Software-as-a-Service (SaaS) or externally facing like most financial systems these days. Consideration should be given to additional details: first, that Colleague resides within an active directory access-controlled environment, therefore, Colleague access is a secondary log-in after the active directory access is granted; second, due to the nature of the application, limited administrative privleges are required for all roles in Colleague. These limited administrative privileges are actively managed by our ITS staff; and third, Virtual Private Network (VPN) access is required for remote log in. These controls provide additional layers of security around Colleague. SNHU has invested significantly in a new Student Information System that will replace Colleague in phases beginning in Autumn 2021 and continuing over the next two years.

Corrective Action Plan

August 5, 2021 Management Response and Corrective Action Plan: This condition has been remediated as of December 15, 2020. Of the 71 user accounts identified to have had Admin privileges, 14 are service accounts. Two accounts are no longer in use and have been locked. Of the 55 remaining accounts, 14 of the users never had a production Unix account which limits the access of these 14 users to access profiles for refresh purposes only. Admin access was removed from all additional accounts except the following where Admin access is limited by role: ? Only four users on the application support team can create/change user access ? The other seven users on the application support team do regular application management but cannot create/change user access ? Eight users do application management and have access to promote code (AppOps) but cannot create/change user access. Therefore, of the 71 users, only four users retain true administrator access to Colleague. SNHU is working with the vendor to evaluate improved audit logging for administrator activity. In general, SNHU leadership agrees with the condition found as written. SNHU would like to make clear that although the condition exists and SNHU agrees with the condition as found, the application is not Software-as-a-Service (SaaS) or externally facing like most financial systems these days. Consideration should be given to additional details: first, that Colleague resides within an active directory access-controlled environment, therefore, Colleague access is a secondary log-in after the active directory access is granted; second, due to the nature of the application, limited administrative privileges are required for all roles in Colleague. These limited administrative privileges are actively managed by our ITS staff; and third, Virtual Private Network (VPN) access is required for remote log in. These controls provide additional layers of security around Colleague. SNHU has invested significantly in a new Student Information System that will replace Colleague in phases beginning in Autumn 2021 and continuing over the next two years. 1. Anticipated Date of Completion ?December 15, 2020 2. Contact Person Responsible ? Julie Cavicchio, Director ITS Security GRC

About Eligibility, Special Tests and Provisions →

FY 2019-06-30

LOW-RISK AUDITEE$849,933,511 federal awards expendedNo findings recorded this year

FAC accepted this audit on March 30, 2020 — management decision was due September 30, 2020.

FY 2018-06-30

LOW-RISK AUDITEE$762,803,668 federal awards expendedNo findings recorded this year

FAC accepted this audit on March 31, 2019 — management decision was due October 1, 2019.

FY 2017-06-30

LOW-RISK AUDITEE$605,400,393 federal awards expendedNo findings recorded this year

FAC accepted this audit on March 21, 2018 — management decision was due September 21, 2018.

FY 2016-06-30

$598,216,059 federal awards expendedNo findings recorded this year

FAC accepted this audit on March 23, 2017 — management decision was due September 23, 2017.

Data source: This information comes from the Federal Audit Clearinghouse, the official repository of Single Audit data. All data is public domain. Verify this organization's audit history at fac.gov.

Browse other Single Audit organizations in New Hampshire

Are you this organization?

Track your findings and corrective action plans across audit cycles.

Start tracking findings →

Do you fund this organization?

Monitor subrecipient audit findings and filing records.

Start monitoring →

Product

Resources

Legal

Single Audit Intelligence is an independent tool powered by Federal Audit Clearinghouse data. Not affiliated with GSA, OMB, or any federal agency.

© 2026 Single Audit Intelligence. All data is public domain.