EIN: 050258956
UEI: TXXKJMJ4TLC1
Data as of August 25, 2026
Management decision deadline — for entities that funded this organization
The FAC accepted this audit on March 30, 2023. Under 2 CFR 200.521(d), a pass-through entity that provided federal funds to this organization for this audit period must issue a management decision on these findings by September 30, 2023 (1061 days ago).
What is a management decision? →For three of the four quarters during the year, institutional reports were not completed and submitted and therefore, also not publicly posted to the School's website. For all four quarters of the year, student quarterly reports were not completed and publicly posted to the School's website. The annual report was completed, but not publicly posted to the School's website. Cause: The School noted there was a misunderstanding of the HEERF reporting requirements, as only one draw down occurred for each of the student and institutional expenditures during the year. The drawdowns occurred in the last month of the fiscal year. Effect: The School is out of compliance with the Department's reporting requirements. Questioned Costs: None. Recommendation: The School should ensure it keeps up to date on the Department?s HEERF guidance and ensure that reporting is done accurately and timely. Management Response: Management agrees with the recommendation and plans to post all reports and put in place procedures to remain in compliance with reporting timeliness.
Show full finding ▾Hide full finding ▴Finding 2022-001 - Higher Education Emergency Relief Funds (HEERF) Reporting ALN No.: 84.425E Education Stabilization Fund - Student Aid Portion and 84.425F Education Stabilization Fund - Institutional Portion Award Year: July 1, 2021 - June 30, 2022 Federal Agency: U.S. Department of Education Pass Through Entity: Not applicable Criteria: The U.S. Department of Education (the Department) has issued guidance for the Education Stabilization Funds (ESF) HEERF for quarterly reporting for all sections (a)(1), (a)(2), (a)(3) and (a)(4) that specifies the information to be reported and also that the deadline to submit all quarterly reports, student and institutional, is within 10 days of the end of the calendar quarter. The guidance also required these reports to be publicly posted on the institution's website within 30 days after the publication of the notice or 30 days after the date the Department first obligated the funds under HEERF I, II, or III to the institution for Emergency Financial Aid Grants to Students, whichever comes later. Condition: For three of the four quarters during the year, institutional reports were not completed and submitted and therefore, also not publicly posted to the School's website. For all four quarters of the year, student quarterly reports were not completed and publicly posted to the School's website. The annual report was completed, but not publicly posted to the School's website. Cause: The School noted there was a misunderstanding of the HEERF reporting requirements, as only one draw down occurred for each of the student and institutional expenditures during the year. The drawdowns occurred in the last month of the fiscal year. Effect: The School is out of compliance with the Department's reporting requirements. Questioned Costs: None. Recommendation: The School should ensure it keeps up to date on the Department?s HEERF guidance and ensure that reporting is done accurately and timely. Management Response: Management agrees with the recommendation and plans to post all reports and put in place procedures to remain in compliance with reporting timeliness.
Finding 2022-001: Higher Education Emergency Relief Funds (HEERF) Reporting 84.425E Education Stabilization Fund ? Student Aid Portion and 84.425F Education Stabilization Fund ? Institutional Portion Recommendation: The School should ensure it keeps up to date on the Department?s HEERF guidance and ensure that reporting is done accurately and timely. Action Taken: The School has posted the required reports on the school website as of March 31, 2023. The School has filed the required annual report on time, it was submitted on March 21, 2023 with a due date of March 24,2023. Name(s) of Contact Person(s) Responsible for Corrective Action: Anticipated Completion Date: If there are any questions regarding this corrective action plan please contact Thomas Mattos AVP of Finance/Controller at tmattos@risd.edu or 401-454-6649
FAC accepted this audit on June 22, 2021 — management decision was due December 22, 2021.
The change in student status for 2 of 25 students tested was not reported to the National Student Loan Data System (NSLDS) within 30 days or included in a response to a roster file within 60 days. However, the students were ultimately reported to the NSLDS. The sample was not a statistically valid sample. Cause: The School's procedures for reporting all students were not designed appropriately in order to allow for timely reporting to the NSLDS. Effect: The accuracy of Title IV student loan records depends heavily on the accuracy of the enrollment information reported by schools. If an institution does not review, update, and verify student enrollment statuses, effective dates of the enrollment status, and the anticipated completion dates, then the Title IV student loan records will be inaccurate. Questioned costs: None. Recommendation: The School should revise its procedures to ensure accurate enrollment information is sent to the NSLDS within the required timeframe. Views of Responsible Officials and Planned Corrective Actions: Management concurs with the findings and has determined that the Assistant Registrar responsible for enrollment reporting will conduct a manual review of any students with financial aid who leave the institution between the end of fall and during the month of January. The School will continue to send a degree verify file for any students who graduate as of the Fall conferral date. For any non-graduating students with financial aid who leave the institution or who are administratively withdrawn between the end of fall and during the month of January, the Assistant Registrar will manually review and update the student record as appropriate on the NSC enrollment site using the `Student Lookup?.
Show full finding ▾Hide full finding ▴Finding 2020-001 - Enrollment Reporting Federal Program - Student Financial Assistance Cluster Federal Agency - U.S. Department of Education Pass-Through Entity - Not Applicable CFDA Number - 84.063, 84.268 Federal Award Year - June 30, 2020 Criteria: Title IV regulations (34 CFR 685.309(b)) require that upon receipt of an enrollment report from the Secretary, Schools must update all information included in the report and return the report to the Secretary: (i) in the manner and format prescribed by the Secretary; and (ii) within the timeframe prescribed by the Secretary. Unless it expects to submit its next updated enrollment report to the Secretary within the next 60 days, an institution must notify the Secretary within 30 days after the date the institution discovers that: (i) a loan under Title IV of the Act was made to or on behalf of a student who was enrolled or accepted for enrollment at the institution, and the student has ceased to be enrolled on at least a half-time basis or failed to enroll on at least a half-time basis for the period for which the loan was intended; or (ii) a student who is enrolled at the institution and who received a loan under Title IV of the Act has changed his or her permanent address. Condition: The change in student status for 2 of 25 students tested was not reported to the National Student Loan Data System (NSLDS) within 30 days or included in a response to a roster file within 60 days. However, the students were ultimately reported to the NSLDS. The sample was not a statistically valid sample. Cause: The School's procedures for reporting all students were not designed appropriately in order to allow for timely reporting to the NSLDS. Effect: The accuracy of Title IV student loan records depends heavily on the accuracy of the enrollment information reported by schools. If an institution does not review, update, and verify student enrollment statuses, effective dates of the enrollment status, and the anticipated completion dates, then the Title IV student loan records will be inaccurate. Questioned costs: None. Recommendation: The School should revise its procedures to ensure accurate enrollment information is sent to the NSLDS within the required timeframe. Views of Responsible Officials and Planned Corrective Actions: Management concurs with the findings and has determined that the Assistant Registrar responsible for enrollment reporting will conduct a manual review of any students with financial aid who leave the institution between the end of fall and during the month of January. The School will continue to send a degree verify file for any students who graduate as of the Fall conferral date. For any non-graduating students with financial aid who leave the institution or who are administratively withdrawn between the end of fall and during the month of January, the Assistant Registrar will manually review and update the student record as appropriate on the NSC enrollment site using the `Student Lookup?.
Finding 2020-001 Condition The change in student status for 2 of 25 students tested was not reported to the National Student Loan Data System (NSLDS) within 30 days or included in a response to a roster file within 60 days. However, the students were ultimately reported to the NSLDS. The sample was not a statistically valid sample. Corrective Action Plan Corrective Action Planned: RISD management agrees with the finding related to Title IV regulations (CFR 314.1 (b)) and the following actions will be taken. RISD will continue to follow the published parameters for reporting to the NSC. The Assistant Registrar responsible for enrollment reporting will need to conduct a manual review of any students with financial aid who leave the institution between the end of fall and during the month of January. RISD will continue to send a degree verify file for any students who graduate as of the Fall conferral date. For any non-graduating students with financial aid who leave the institution or who are administratively withdrawn between the end of fall and during the month of January, the Assistant Registrar will manually review and update the student record as appropriate on the NSC enrollment site using the `Student Lookup?. A report of students with financial aid who go on leave will need to be developed and shared with the Assistant Registrar. Any students who withdraw in February are excluded from the manual review as they will be reported within the 60-day requirement in RISD?s First of Term submission for spring. Name(s) of Contact Person(s) Responsible for Corrective Action: Alison Sherman, Registrar, and Kasey Kniffin, Assistant Registrar Anticipated Completion Date: Beginning academic year 2021-2022, the Assistant Registrar responsible for enrollment reporting will conduct a manual review of any students with financial aid who leave the institution between the end of fall and during the month of January.
FAC accepted this audit on November 19, 2019 — management decision was due May 19, 2020.
The Institution has not designated an individual responsible for coordinating an information security program, nor has the Institution performed a risk assessment to address employee training and management related to information security as required by the Gramm-Leach Bliley Act ("GLBA"). Cause: The Institution does not have a designator coordinator nor has procedures and processes in place specific to GLBA. Effect: Failure to comply with the requirements of GLBA standards puts the Institution at risk of compromising consumer nonpublic personal information. Questioned costs: None. Recommendation: The institution should designate an individual responsible for coordinating the information security program. Additionally, the Institution should perform and document an annual risk assessment to determine the institution's specific risks relevant to protecting consumer nonpublic personal information. At a minimum, the Institution should have at least one risk statement aligned or referenced to each of the three required areas noted in the GLBA law at 16 CFR 314.4 (b). Finally, the Institution should identify and document at least one safeguard (i.e., control) for each of the risks identified and documented in the risk assessment. Each control should be aligned or referenced to the risk(s) to which the safeguard applies. Views of Responsible Officials and Planned Corrective Actions: RISD management agrees with the finding related to Title IV regulations (CFR 314.1 (b)) and the following actions will be taken. We will coordinate a team of relevant individuals at RISD to modify and document RISD's Information Security Program to include specifications of the Gramm-Leach Bliley Act (GLBA). The modified Information Security Program will include at least one risk statement aligned to each of the three required areas noted in the GLBA law at 16 CFR 314.4 (b) and a plan for an annual risk assessment of consumer nonpublic personal information. It will also include the identification and documentation of safeguards for each of the risks identified in the risk assessment and delegate an individual responsible for coordinating the Information Security program. RISD will complete the plan by June 2020. In the interim, the Director of Network Services will continue to act as the information security officer and be the individual responsible for coordinating the information security program. We will be completing the statement of work for an external risk assessment that will begin in the fall of 2019. We continue to contract with CI Security for managed detection and response services.
Show full finding ▾Hide full finding ▴Finding 2019-001 ? Gramm-Leach Bliley Act Federal Program - Student Financial Assistance Cluster Federal Agency - U.S. Department of Education Pass-Through Entity - Not Applicable CFDA Number - 84.007, 84.033, 84,038, 84.064, 84.268 Federal Award Year - June 30, 2019 Criteria: In accordance with Title IV regulations (CFR 314.1 (b)), an Institution is required to designate an individual to coordinate the information security program, perform a risk assessment that addresses (1) employee training and management; (2) information systems, including network and software design, as well as information processing, storage, transmission and disposal; and (3) detecting, preventing and responding to attacks, intrusions, or other systems failures, and document safeguards for identified risks. Condition: The Institution has not designated an individual responsible for coordinating an information security program, nor has the Institution performed a risk assessment to address employee training and management related to information security as required by the Gramm-Leach Bliley Act ("GLBA"). Cause: The Institution does not have a designator coordinator nor has procedures and processes in place specific to GLBA. Effect: Failure to comply with the requirements of GLBA standards puts the Institution at risk of compromising consumer nonpublic personal information. Questioned costs: None. Recommendation: The institution should designate an individual responsible for coordinating the information security program. Additionally, the Institution should perform and document an annual risk assessment to determine the institution's specific risks relevant to protecting consumer nonpublic personal information. At a minimum, the Institution should have at least one risk statement aligned or referenced to each of the three required areas noted in the GLBA law at 16 CFR 314.4 (b). Finally, the Institution should identify and document at least one safeguard (i.e., control) for each of the risks identified and documented in the risk assessment. Each control should be aligned or referenced to the risk(s) to which the safeguard applies. Views of Responsible Officials and Planned Corrective Actions: RISD management agrees with the finding related to Title IV regulations (CFR 314.1 (b)) and the following actions will be taken. We will coordinate a team of relevant individuals at RISD to modify and document RISD's Information Security Program to include specifications of the Gramm-Leach Bliley Act (GLBA). The modified Information Security Program will include at least one risk statement aligned to each of the three required areas noted in the GLBA law at 16 CFR 314.4 (b) and a plan for an annual risk assessment of consumer nonpublic personal information. It will also include the identification and documentation of safeguards for each of the risks identified in the risk assessment and delegate an individual responsible for coordinating the Information Security program. RISD will complete the plan by June 2020. In the interim, the Director of Network Services will continue to act as the information security officer and be the individual responsible for coordinating the information security program. We will be completing the statement of work for an external risk assessment that will begin in the fall of 2019. We continue to contract with CI Security for managed detection and response services.
Finding 2019-001 Condition The Institution has not designated an individual responsible for coordinating an information security program, nor has the Institution performed a risk assessment to address employee training and management related to information security as required by the Gramm- Leach Bliley Act ("GLBA"). Corrective Action Plan Corrective Action Planned: RISD management agrees with the finding related to Title IV regulations (CFR 314.1 (b)) and the following actions will be taken. We will coordinate a team of relevant individuals at RISD to modify and document RISD's Information Security Program to include specifications of the Gramm-Leach Bliley Act (GLBA). The modified Information Security Program will include at least one risk statement aligned to each of the three required areas noted in the GLBA law at 16 CFR 314.4 (b) and a plan for an annual risk assessment of consumer nonpublic personal information. It will also include the identification and documentation of safeguards for each of the risks identified in the risk assessment and delegate an individual responsible for coordinating the Information Security program. Name(s) of Contact Person(s) Responsible for Corrective Action: Richard Mickool, Chief Information Officer. Anticipated Completion Date: RISD will complete the plan by June 2020. In the interim, the Director of Network Services will continue to act as the information security officer and be the individual responsible for coordinating the information security program. We will be completing the statement of work for an external risk assessment that will begin in the fall of 2019. We continue to contract with CI Security for managed detection and response services.
FAC accepted this audit on November 13, 2017 — management decision was due May 13, 2018.
GSA_MIGRATION
Show full finding ▾Hide full finding ▴FAC accepted this audit on November 21, 2016 — management decision was due May 21, 2017.
GSA_MIGRATION
Show full finding ▾Hide full finding ▴Data source: This information comes from the Federal Audit Clearinghouse, the official repository of Single Audit data. All data is public domain. Verify this organization's audit history at fac.gov.
Track your findings and corrective action plans across audit cycles.
Start tracking findings →Monitor subrecipient audit findings and compliance status.
Start monitoring →© 2026 Single Audit Intelligence. All data is public domain.