Boston Medical Center Corporation

EIN: 043314093

UEI: JZ8RQC4EMDZ5

Data as of August 23, 2026

Boston Medical Center Corporation10 audit years5 findings1 repeat
10
Audit Years
5
Total Findings
1
Repeat Findings

FY 2023-09-30

Management decision deadline — for entities that funded this organization

The FAC accepted this audit on July 1, 2024. Under 2 CFR 200.521(d), a pass-through entity that provided federal funds to this organization for this audit period must issue a management decision on these findings by January 1, 2025 (599 days ago).

What is a management decision? →
2023-001
Activities Allowed or Unallowed / Period of Performance / Special Tests & Provisions

Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Workday, a cloud based system, to provide human resources and payroll applications. BMC’s management of Workday includes maintaining the application system layer of the information technology (IT)control environment and relies on the Workday vendor to support infrastructure layers through Service Organization Control (SOC) Type 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Workday IT application controls. During our testing, we noted the following deficiencies operating effectiveness of the Workday general IT controls: 1) BMC did not perform and document a Workday change review during the fiscal year, such a control would enable management to detect inappropriate changes to the Workday application. Such a report detailing changes to Workday was generated as part of the Uniform Guidance audit, however management did not formally perform and document its review over the report. Upon audit inquiry, the review was subsequently performed by management and we observed no inappropriate changes were made during the year that would impact the IT application controls relied upon. 2) For 1 of 13 employee new or modified Workday access provisioning samples, BMC did not maintain adequate documentation of the access request and approval. Upon audit inquiry, it was determined that access was provided as part of a promotion and was appropriate; however, was not formally documented. Cause The conditions above related to the following: 1) Management did not formally perform and document their review over the report due to a lack of knowledge of performance and documentation requirements by the control operators. 2) The exception occurred due to delays in supervisors’ timely reporting of terminations in Infor which delayed the de provisioning process performed by IT. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access and change management may result in unauthorized changes being made to Workday, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the change management policies and procedures with key personnel to help ensure that the Workday change Review is performed to address change management risks for the system. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for requesting and provisioning access to help ensure that requests for both new and modified access are appropriately obtained and documented for approval of access needed for job responsibilities. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.

Show full finding ▾
Full finding narrative

Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D and Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (PRF) (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 001 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Workday, a cloud based system, to provide human resources and payroll applications. BMC’s management of Workday includes maintaining the application system layer of the information technology (IT)control environment and relies on the Workday vendor to support infrastructure layers through Service Organization Control (SOC) Type 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Workday IT application controls. During our testing, we noted the following deficiencies operating effectiveness of the Workday general IT controls: 1) BMC did not perform and document a Workday change review during the fiscal year, such a control would enable management to detect inappropriate changes to the Workday application. Such a report detailing changes to Workday was generated as part of the Uniform Guidance audit, however management did not formally perform and document its review over the report. Upon audit inquiry, the review was subsequently performed by management and we observed no inappropriate changes were made during the year that would impact the IT application controls relied upon. 2) For 1 of 13 employee new or modified Workday access provisioning samples, BMC did not maintain adequate documentation of the access request and approval. Upon audit inquiry, it was determined that access was provided as part of a promotion and was appropriate; however, was not formally documented. Cause The conditions above related to the following: 1) Management did not formally perform and document their review over the report due to a lack of knowledge of performance and documentation requirements by the control operators. 2) The exception occurred due to delays in supervisors’ timely reporting of terminations in Infor which delayed the de provisioning process performed by IT. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access and change management may result in unauthorized changes being made to Workday, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the change management policies and procedures with key personnel to help ensure that the Workday change Review is performed to address change management risks for the system. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for requesting and provisioning access to help ensure that requests for both new and modified access are appropriately obtained and documented for approval of access needed for job responsibilities. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.

Corrective Action Plan

Corrective Action Plan – Workday Fiscal Year Ended September 30, 2023 Program name: Research and Development Cluster (R&D) and Provider Relief Fund (PRF) (93.498) Audit Contact: Matthew O’Connor Title: Senior Director, Human Resources Operations & Analytics Telephone: 617-638-8495 E-mail address: Matthew.OConnor@bmc.org Audit Report Reference: 2023-001 Anticipated Completion Date: December 31, 2024 Corrective Action Planned: 1) For the Workday change review, management has been re-educated on the importance of this review as well as how to complete it completely and timely. Management will perform this review for the fiscal year ended September 30, 2024 and each subsequent fiscal year. Additionally, this review will be timely reviewed by somebody separate from the preparer and the documentation of the review and subsequent approval will be retained in BMC’s records. 2) For the access provisioning deficiency, management has been re-educated on the importance of following policy with respect to granting new access to Workday, including that this granting of access be appropriately documented and approved prior to the date of provisioning said access. Additionally, documentation of the approval of access will be properly retained in the company’s records.

About Activities Allowed or Unallowed, Period of Performance, Special Tests and Provisions →
2023-002
Activities Allowed or Unallowed / Period of Performance / Procurement & Suspension/Debarment / Subrecipient Monitoring

Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D Provider Relief Fund Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 002 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Infor, a could based system, as the entity’s general ledger. BMC management of Infor includes maintaining the application system layer of the IT control environment and relies on the Infor vendor to support infrastructure layers through SOC 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Infor IT application controls. During our test work, we noted the following deficiencies operating effectiveness of the general IT controls: 1) BMC did not have a process in place to perform and document a Infor User Access Review during the fiscal year. Upon audit inquiry, a review was performed to confirm there were no impacts to IT application controls configurations or processes. 2) For 4 of 15 employee termination access samples to the Infor system, it was determined the samples were not removed in a timely basis following the employee’s termination date. Upon audit inquiry, we obtained system documentation for the 4 users identified as exceptions indicating the related users did not logon to the system past their termination date. Cause The conditions above related to the following: 1) Management did not formally implement a process or policy to review user access due to reliance on preventative access controls and no established review requirements as of the fiscal year. 2) The exceptions occurred due to human oversight during the execution of the de provisioning process. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access may result in unauthorized changes being made to Infor, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the access management policies and procedures with key personnel to help ensure that an Infor User Access Review is performed. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for the timely communication and removal of de provisioning of users. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.

Show full finding ▾
Full finding narrative

Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D Provider Relief Fund Provider Relief Fund and American Rescue Plan (ARP) Rural Distribution (93.498) Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 002 Criteria Internal Controls Title 2 U.S. Code of Federal Regulations Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements of Federal Awards, (2 CFR 200) section 200.303(a) states, the non federal entity must establish and maintain effective internal control over the federal award that provides reasonable assurance that the non federal entity is managing the federal award in compliance with federal statues, regulations, and the terms and conditions of the federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Condition BMC utilizes Infor, a could based system, as the entity’s general ledger. BMC management of Infor includes maintaining the application system layer of the IT control environment and relies on the Infor vendor to support infrastructure layers through SOC 1 reporting. Processes that support compliance and administration of the PRF and R&D programs rely on Infor IT application controls. During our test work, we noted the following deficiencies operating effectiveness of the general IT controls: 1) BMC did not have a process in place to perform and document a Infor User Access Review during the fiscal year. Upon audit inquiry, a review was performed to confirm there were no impacts to IT application controls configurations or processes. 2) For 4 of 15 employee termination access samples to the Infor system, it was determined the samples were not removed in a timely basis following the employee’s termination date. Upon audit inquiry, we obtained system documentation for the 4 users identified as exceptions indicating the related users did not logon to the system past their termination date. Cause The conditions above related to the following: 1) Management did not formally implement a process or policy to review user access due to reliance on preventative access controls and no established review requirements as of the fiscal year. 2) The exceptions occurred due to human oversight during the execution of the de provisioning process. Possible Asserted Effect Failure to have a reliable general IT control environment over logical access may result in unauthorized changes being made to Infor, which may result in erroneous reliance on the operating effectiveness of automated IT controls, over allowability. Failure to have effective internal controls over allowability may result in federal awards being utilized for unallowable expenditures not in accordance with the federal statues, regulations, and terms and conditions of federal awards. Questioned Costs Not applicable Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend that management review and emphasize the access management policies and procedures with key personnel to help ensure that an Infor User Access Review is performed. Additionally, we recommend that management review and emphasize the logical access policies and procedures with key personnel responsible for the timely communication and removal of de provisioning of users. Views of Responsible Officials Recommendation accepted. Please refer to corrective action plan.

Corrective Action Plan

Corrective Action Plan – Infor Fiscal Year Ended September 30, 2023 Program name: Research and Development Audit Contact: Marley Crowell Title: Senior Director, Finance Systems Telephone: 617-780-6400 E-mail address: marley.crowell@bmc.org Audit Report Reference: 2023-002 Anticipated Completion Date: September 30, 2025 Corrective Action Planned: 1) For the Infor user access review deficiency: a. Management has scoped and performed limited access reviews in FY2024 related to privileged administrative access. b. Management has worked to identify financially significant Infor user security roles in order to properly scope and implement business user access reviews starting in FY2024, noting that the implementation timeframe will span FY2024 and FY2025. c. IT management will be working with operational management to educate as to how to properly perform access reviews, and then to implement those reviews starting in FY2024 and FY2025. d. Once reviews have been performed, IT management will assess the results and terminate any access deemed to be unnecessary. As part of this process IT management will perform risk assessment procedures for these users if deemed necessary (e.g. if no other controls are in place to mitigate the perceived risk, etc.). 2) For the access termination deficiency: a. Management completed an education session for BMC leaders in FY24 which included the importance of the termination process including timeliness of employee terminations by the business to HR and IT via the established pathways of communication of these items. b. The established process would automatically allow for very timely termination of access provided that initial notification was timely. c. Communication and/or education about timely termination of employees will be repeated at intervals throughout the year in order to reinforce the message and account for changes in management personnel, who are tasked with this process.

About Activities Allowed or Unallowed, Period of Performance, Procurement and Suspension and Debarment, Subrecipient Monitoring →
2023-003
Subrecipient Monitoring

Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D Cluster Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 003 Criteria In accordance with 2 CFR 200.332, a pass through entity (PTE) must: (a) Ensure that every subaward is clearly identified to the subrecipient as a subaward and includes the following information at the time of the subaward and if any of these data elements change, include the changes in subsequent subaward modification. When some of this information is not available, the pass through entity must provide the best information available to describe the Federal award and subaward. Required information includes: (xii) Assistance Listings number and Title; the pass through entity must identify the dollar amount made available under each Federal award and the Assistance Listings Number at time of disbursement; (2 CFE section 200.332xxi) (b) Evaluate each subrecipient’s risk of noncompliance with Federal statutes, regulations, and the terms and conditions of the subaward for purposes of determining the appropriate subrecipient monitoring described in paragraphs (d) and (e) of this section, which may include consideration of such factors as: (1) The subrecipient’s prior experience with the same or similar subawards; (2) The results of previous audits including whether or not the subrecipient receives a Single Audit in accordance with Subpart F of this part, and the extent to which the same or similar subaward has been audited as a major program; (3) Whether the subrecipient has new personnel or new or substantially changed systems; and (4) The extent and results of Federal awarding agency monitoring (e.g., if the subrecipient also receives Federal awards directly from a Federal awarding agency). Additionally, 45 CFR section 75 303(a) states the non Federal entity must establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. Condition When subawards are made to subrecipients, the pass through entities are required to communicate the dollar amount made available under each Federal award and the Assistance Listings Number (ALN) at time of disbursement. BMC does not have system in place to provide the ALN at the time of disbursement of funds. During the year ended September 30, 2023, the BMC passed through $18,031,446 of federal funding to subrecipients. In order to assess the subrecipient’s risk of non compliance, BMC has subrecipient monitoring policies and procedures in place which include the use of a risk assessment questionnaire. The risk assessment questionnaire includes considerations consistent with 2 CFR 200.332(b), including the entity’s prior experience and results of Single Audits, in addition to other factors. As part of our testing related subrecipient monitoring, we identified the following: 1. For 4 of 16 subrecipients selected for testwork BMC did not perform a risk assessment of the entity for purposes of determining the appropriate subrecipient monitoring related to the subaward. However, for these subrecipients, BMC did perform monitoring procedures, including review of invoices for reimbursement, review of Research Performance Progress Reports and review of Single Audit reports. Cause The condition found was primarily due to the monitoring procedures implemented by BMC do not include a review to ensure that a risk assessment is performed for each active subrecipient and BMC does not have a mechanism in place to provide the ALN at the time of disbursement of funds to the subrecipient. Possible Asserted Effect Failure to perform an annual risk assessment to determine appropriate subrecipient monitoring procedures may result in insufficient monitoring procedures being performed to detect subrecipient noncompliance with Federal statutes, regulations, and the terms and conditions of the award. Failure to adequately communicate award identification information could result in the subrecipient not being able to adequately track and report the subawards received resulting in errors being reported on the schedule of expenditures of federal awards within a subrecipient’s annual single audit report and not being able to comply with required terms and conditions of the federal award. Questioned Costs None. Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend BMC implement policies, procedures, and internal controls to ensure subrecipient risk assessments are performed for each subrecipient to determine the appropriate subrecipient monitoring is performed in accordance with 45 CFR 75.352(d) and 45 CFR 75.352(e). We recommend that BMC enhance its processes and internal controls over its reporting to the subrecipients of the federal program to ensure all award identification information required under 45 CFR 75.352(a) is provided to the subrecipients.

Show full finding ▾
Full finding narrative

Federal Agency: United States Department of Health and Human Services (HHS) Federal Program: R&D Cluster Federal Award Numbers: Various Federal Award Years: Various Reference: 2023 003 Criteria In accordance with 2 CFR 200.332, a pass through entity (PTE) must: (a) Ensure that every subaward is clearly identified to the subrecipient as a subaward and includes the following information at the time of the subaward and if any of these data elements change, include the changes in subsequent subaward modification. When some of this information is not available, the pass through entity must provide the best information available to describe the Federal award and subaward. Required information includes: (xii) Assistance Listings number and Title; the pass through entity must identify the dollar amount made available under each Federal award and the Assistance Listings Number at time of disbursement; (2 CFE section 200.332xxi) (b) Evaluate each subrecipient’s risk of noncompliance with Federal statutes, regulations, and the terms and conditions of the subaward for purposes of determining the appropriate subrecipient monitoring described in paragraphs (d) and (e) of this section, which may include consideration of such factors as: (1) The subrecipient’s prior experience with the same or similar subawards; (2) The results of previous audits including whether or not the subrecipient receives a Single Audit in accordance with Subpart F of this part, and the extent to which the same or similar subaward has been audited as a major program; (3) Whether the subrecipient has new personnel or new or substantially changed systems; and (4) The extent and results of Federal awarding agency monitoring (e.g., if the subrecipient also receives Federal awards directly from a Federal awarding agency). Additionally, 45 CFR section 75 303(a) states the non Federal entity must establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. Condition When subawards are made to subrecipients, the pass through entities are required to communicate the dollar amount made available under each Federal award and the Assistance Listings Number (ALN) at time of disbursement. BMC does not have system in place to provide the ALN at the time of disbursement of funds. During the year ended September 30, 2023, the BMC passed through $18,031,446 of federal funding to subrecipients. In order to assess the subrecipient’s risk of non compliance, BMC has subrecipient monitoring policies and procedures in place which include the use of a risk assessment questionnaire. The risk assessment questionnaire includes considerations consistent with 2 CFR 200.332(b), including the entity’s prior experience and results of Single Audits, in addition to other factors. As part of our testing related subrecipient monitoring, we identified the following: 1. For 4 of 16 subrecipients selected for testwork BMC did not perform a risk assessment of the entity for purposes of determining the appropriate subrecipient monitoring related to the subaward. However, for these subrecipients, BMC did perform monitoring procedures, including review of invoices for reimbursement, review of Research Performance Progress Reports and review of Single Audit reports. Cause The condition found was primarily due to the monitoring procedures implemented by BMC do not include a review to ensure that a risk assessment is performed for each active subrecipient and BMC does not have a mechanism in place to provide the ALN at the time of disbursement of funds to the subrecipient. Possible Asserted Effect Failure to perform an annual risk assessment to determine appropriate subrecipient monitoring procedures may result in insufficient monitoring procedures being performed to detect subrecipient noncompliance with Federal statutes, regulations, and the terms and conditions of the award. Failure to adequately communicate award identification information could result in the subrecipient not being able to adequately track and report the subawards received resulting in errors being reported on the schedule of expenditures of federal awards within a subrecipient’s annual single audit report and not being able to comply with required terms and conditions of the federal award. Questioned Costs None. Statistical Sampling The sample was not intended to be, and was not, a statistically valid sample. Recommendation We recommend BMC implement policies, procedures, and internal controls to ensure subrecipient risk assessments are performed for each subrecipient to determine the appropriate subrecipient monitoring is performed in accordance with 45 CFR 75.352(d) and 45 CFR 75.352(e). We recommend that BMC enhance its processes and internal controls over its reporting to the subrecipients of the federal program to ensure all award identification information required under 45 CFR 75.352(a) is provided to the subrecipients.

Corrective Action Plan

Corrective Action Plan – Subrecipient Risk Assessment Fiscal Year Ended September 30, 2023 Program name: Research and Development Audit Contact: Jennifer Kennedy Title: Director, Sponsored Programs Finance Telephone: 617-638-2852 E-mail address: Jennifer.Kennedy@bmc.org Audit Report Reference: 2023-003 Anticipated Completion Date: September 30, 2024 Corrective Action Planned: The primary cause of the identified issue was due to personnel changes within Sponsored Programs Administration (SPA). This turnover led to a gap in recording and establishing the subrecipient risk assessment process before finalizing subaward agreements. However, SPA reviewed subrecipient single audit reports prior to issuing subaward agreements. 1) Review of Risk Assessments for current active subawards: SPA will conduct a review of all current subrecipients and document a risk assessment for each by the end of FY24. All new active subawards beginning October 1, 2024, will follow the updated SOPs and policies to ensure compliance and consistency. 2) Updating SOPs: SPA will update the Standard Operating Procedures (SOPs) pertaining to Subaward Issuance (Risk Assessments, Monitoring, Reporting, etc.) to ensure continuity and consistency, regardless of personnel changes. The updated SOPs will include specific steps for subaward issuance and will be reviewed and updated annually as necessary. In addition to the above actions, SPA is in the process of opening a new role for a Subaward Specialist who will be a dedicated FTE for subaward management. The new employee will pair with the SPA Associate Director as they onboard. This role will oversee subrecipient risk assessments, subaward issuance, and FFATA reporting. A centralized role will allow for consistency and expertise on all subrecipient management pre-award and non-financial post-award processes. This role will contribute to maintaining and updating current SOPs pertaining to subaward management and monitoring. By implementing these measures, we are confident in our ability to manage personnel changes effectively and ensure that critical functions, such as subrecipient risk assessments, are carried out with the highest level of accuracy and compliance.

About Subrecipient Monitoring →

FY 2020-09-30

FAC accepted this audit on November 21, 2021 — management decision was due May 21, 2022.

2020-001
Activities Allowed or Unallowed / Cost Allowability / Special Tests & Provisions
REPEAT

Requirement Support the distribution of the employee?s salary or wages among specific activities or cost objectives if the employee works on more than one Federal award; a Federal award and non-Federal award; an indirect cost activity and a direct cost activity; two or more indirect activities that are allocated using different allocation bases; or an unallowable activity and a direct or indirect cost activity. The Consolidated Appropriations Act, 2017, restricts the amount of direct salary for individuals working on NIH grants, cooperative agreement awards, and extramural research and development contracts. The salary limitation rate, determined twice a year, applies to any individual whose salary is charged directly to awards from these agencies. The rates in effect during fiscal year 2020 were $192,300 for the period October 1, 2019 through January 4, 2020 and $197,300 for the period January 5, 2020 through September 30, 2020. The limitation is not on the number of dollars that can be charged to an NIH grant. Rather, it is on the monthly pay rate that can be charged to an NIH grant. The non-Federal entity may change the staffing mix and level of involvement within limits specified by agency policy or in the award, but may be required to obtain Federal awarding agency approval of changes in key personnel (as identified in the award, which may differ from the non-Federal entity?s designation in the application/proposal) and changes in the principal investigator?s/project director?s time commitment/level of participation in the project. For grants and cooperative agreements, this may include not only a change in the principal investigator or project director but also the disengagement from the project for more than 3 months, or a 25 percent reduction in time devoted to the project, by the approved project director or principal investigator (OMB Circular A-110 ??_.25(c)(2) and (3)/2 CFR sections 200.308(c)(1) (ii) and (iii)). For cost-reimbursement contracts under the FAR, specific key personnel requirements are included in the contract (or task order). In accordance with 2 CFR section 200.303(a), non-Federal entities must establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in ?Standards for Internal Control in the Federal Government? issued by the Comptroller General of the United States or the ?Internal Control Integrated Framework?, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Finding BMC is responsible for maintaining accurate records of personnel time and effort to substantiate salary and wage costs associated with its federal and other sponsored projects, including BMC affiliates that participate in such federally sponsored programs. Due to the integrated nature of certain aspects of its operations, BMC has implemented various control activities to ensure it remains in compliance with the above requirements, which include: 1. Supervisory approval of timesheets 2. Semi-annual employee effort certifications, which are reviewed by the respective Department Research Administrator and BMC?s Central Research Office 3. All changes to an employee?s time charged to a grant must be reviewed by Research Finance prior to further grant accounting or close-out Employee effort certifications are used to support the time and effort worked on a grant, in instances where a BMC affiliate participates in the grant, they also capture both the amount of time and the rate that both BMC and the affiliate must pay due to salary caps and other researcher time commitments. In connection with our payroll allowability procedures, we tested 50 transactions and identified 2 instances in which BMC affiliated personnel did not initially fill out their effort certifications accurately and which required a recertification to support the effort and cost share charged. In each of these instances, the recertification occurred several months after the initial certification was prepared. In connection with our key personnel work we tested 40 such employee certifications and noted 2 instances in which BMC affiliated personnel did not initially fill out their effort certifications accurately which required a recertification to support the effort and cost that was ultimately charged as a grant. In each of these instances, the recertification occurred months after the initial certification was prepared. Cause Employee certifications for affiliates are not consistently reviewed on a timely basis to detect and correct errors. Effect Not preparing employee certifications accurately or timely or effectively reviewing such certifications could result in an incorrect amount of effort documented or costs charged to the grant. Recommendation We recommend BMC continue to implement procedures to ensure effort certifications are filled out accurately and timely and also develop a more thorough and timely review procedure for BMC affiliates. Questioned Costs None.

Show full finding ▾
Full finding narrative

Requirement Support the distribution of the employee?s salary or wages among specific activities or cost objectives if the employee works on more than one Federal award; a Federal award and non-Federal award; an indirect cost activity and a direct cost activity; two or more indirect activities that are allocated using different allocation bases; or an unallowable activity and a direct or indirect cost activity. The Consolidated Appropriations Act, 2017, restricts the amount of direct salary for individuals working on NIH grants, cooperative agreement awards, and extramural research and development contracts. The salary limitation rate, determined twice a year, applies to any individual whose salary is charged directly to awards from these agencies. The rates in effect during fiscal year 2020 were $192,300 for the period October 1, 2019 through January 4, 2020 and $197,300 for the period January 5, 2020 through September 30, 2020. The limitation is not on the number of dollars that can be charged to an NIH grant. Rather, it is on the monthly pay rate that can be charged to an NIH grant. The non-Federal entity may change the staffing mix and level of involvement within limits specified by agency policy or in the award, but may be required to obtain Federal awarding agency approval of changes in key personnel (as identified in the award, which may differ from the non-Federal entity?s designation in the application/proposal) and changes in the principal investigator?s/project director?s time commitment/level of participation in the project. For grants and cooperative agreements, this may include not only a change in the principal investigator or project director but also the disengagement from the project for more than 3 months, or a 25 percent reduction in time devoted to the project, by the approved project director or principal investigator (OMB Circular A-110 ??_.25(c)(2) and (3)/2 CFR sections 200.308(c)(1) (ii) and (iii)). For cost-reimbursement contracts under the FAR, specific key personnel requirements are included in the contract (or task order). In accordance with 2 CFR section 200.303(a), non-Federal entities must establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in ?Standards for Internal Control in the Federal Government? issued by the Comptroller General of the United States or the ?Internal Control Integrated Framework?, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Finding BMC is responsible for maintaining accurate records of personnel time and effort to substantiate salary and wage costs associated with its federal and other sponsored projects, including BMC affiliates that participate in such federally sponsored programs. Due to the integrated nature of certain aspects of its operations, BMC has implemented various control activities to ensure it remains in compliance with the above requirements, which include: 1. Supervisory approval of timesheets 2. Semi-annual employee effort certifications, which are reviewed by the respective Department Research Administrator and BMC?s Central Research Office 3. All changes to an employee?s time charged to a grant must be reviewed by Research Finance prior to further grant accounting or close-out Employee effort certifications are used to support the time and effort worked on a grant, in instances where a BMC affiliate participates in the grant, they also capture both the amount of time and the rate that both BMC and the affiliate must pay due to salary caps and other researcher time commitments. In connection with our payroll allowability procedures, we tested 50 transactions and identified 2 instances in which BMC affiliated personnel did not initially fill out their effort certifications accurately and which required a recertification to support the effort and cost share charged. In each of these instances, the recertification occurred several months after the initial certification was prepared. In connection with our key personnel work we tested 40 such employee certifications and noted 2 instances in which BMC affiliated personnel did not initially fill out their effort certifications accurately which required a recertification to support the effort and cost that was ultimately charged as a grant. In each of these instances, the recertification occurred months after the initial certification was prepared. Cause Employee certifications for affiliates are not consistently reviewed on a timely basis to detect and correct errors. Effect Not preparing employee certifications accurately or timely or effectively reviewing such certifications could result in an incorrect amount of effort documented or costs charged to the grant. Recommendation We recommend BMC continue to implement procedures to ensure effort certifications are filled out accurately and timely and also develop a more thorough and timely review procedure for BMC affiliates. Questioned Costs None.

Corrective Action Plan

View of Responsible Officials and Corrective Actions Management agrees that additional review of effort needs to happen centrally, and will implement and document an internal control. Training and re-training of central research administration happened February 11, 2020. Additionally, guidance documents with specific examples will be provided to department research leadership to discuss correct documentation of effort. The development of departmental training guides and tools was rolled out by the Fall of 2020. Management has provided several effort reporting trainings to the departments and central research office. ? On-site Effort Training provided by Huron Consulting group and central research operations managers for internal grant administrators and research financial analysts on February 11, 2020. Effort training focused on internal controls, effort reporting and salary allocations/cost transfers. This session was both didactic and hands on case study exercise. ? Research Operations provide time and effort training to all research departments administrators (80 plus attendees) on March 17, 2021. We are currently working to develop retraining opportunities for departmental and central office employees, as well as resources for new hires. We have been delayed due to COVID-19 and a new financial system implementation. New anticipated completion date is Spring 2022. Responsible Official(s) Executive Director of Research Operations Senior Director of Grants and Contracts Implementation Date: Spring 2022

Prior Finding References

2019-002

About Activities Allowed or Unallowed, Allowable Costs / Cost Principles, Special Tests and Provisions →

FY 2016-09-30

FAC accepted this audit on March 15, 2017 — management decision was due September 15, 2017.

2016-001
Other

GSA_MIGRATION

Show full finding ▾
Full finding narrative

GSA_MIGRATION

Corrective Action Plan

GSA_MIGRATION

About Other →

Data source: This information comes from the Federal Audit Clearinghouse, the official repository of Single Audit data. All data is public domain. Verify this organization's audit history at fac.gov.

Are you this organization?

Track your findings and corrective action plans across audit cycles.

Start tracking findings →

Do you fund this organization?

Monitor subrecipient audit findings and compliance status.

Start monitoring →

Product

Resources

Legal

Single Audit Intelligence is an independent tool powered by Federal Audit Clearinghouse data. Not affiliated with GSA, OMB, or any federal agency.

© 2026 Single Audit Intelligence. All data is public domain.